The aplication or dll C:\WINNT\system32 is not a valid windows image
Actualy, another of my friend's computer gets this message at strat up "The aplication or dll C:\WINNT\system32\__c00798B8.dat is not a valid windows image. Please check this against your installation diskette." and when we hit the "ok" button it cycles through an endless list of applications,here are some of them:
manhattan:SBTV.exe
ctfmon.exe
hpcmpmgr.exe
Yahoo!Messenger:YAHOOM~1.EXE
HideWindow:devcheck.exe
hpotdd01.exe
BJCFD:CFD.exe
The computer takes almost literally hours to finish the startup process while many pop up windows show:
Spyware Doctor
Malicious Action Blocked
Spyware Doctor has blocked an application ***.exe attempting to access a file.
Path: C:\WINNT\system32\__c00798B8.dat
Threat: Trojan.Virtumode
Rissk: Elevated
His active desktop is gone, but we get that screen saying "Active desktop recovery>Restore my Active Desktop<"
It also takes years to shut down
I noticed he's got Live AntiSpy and Privacy Watch runing during the time of start up. I brought his computer to my home to see what I could do about it. I am still searchig for possible solutions. Do y'all think spybot and hijck this could do some good to his infected machine? What could be the nastie responsible for this problem?
ANy suggestions?
It seems to have worked fine!!
I read your other post about Vundo, I downloaded Combofix to my laptop and copied it to my friend's infected machine with a USB drive. After I made a bootable floppy diskette I tried it and worked. So far no other IE has opened on me. I will re-install HJT (with other name) and run it (or maybe not. It's too late, I have to give him his computer back 2morrow).
Anyhow, here's the Combofix log
ComboFix 08-04-24.1 - Medina 04/25/2008 20:38:32.1 - NTFSx86 NETWORK
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.663 [GMT -5:00]
Running from: C:\Documents and Settings\Medina\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Medina\Application Data\Install.dat
C:\Documents and Settings\Medina\Application Data\ShoppingReport
C:\Documents and Settings\Medina\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Medina\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Medina\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Medina\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Medina\Application Data\ShoppingReport\cs\persist.dbs
C:\Documents and Settings\Medina\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Medina\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Medina\Application Data\ShoppingReport\cs\res2\WhiteList.dbs
C:\Documents and Settings\Medina\Application Data\SpamBlockerUtility_Icons
C:\Documents and Settings\Medina\Application Data\SpamBlockerUtility_Icons\Software_Online_8.ic o
C:\Program Files\ShoppingReport
C:\Program Files\ShoppingReport\cs\persist.dbs
C:\Program Files\ShoppingReport\Uninst.exe
C:\WINNT\system32\__c00663A8.exe
C:\WINNT\system32\__c00853FF.exe
C:\WINNT\system32\__c00A930A.exe
C:\WINNT\system32\drmgs.sys
C:\WINNT\system32\eMnonnpo.ini
C:\WINNT\system32\eMnonnpo.ini2
C:\WINNT\system32\Indt2.sys
C:\WINNT\system32\mcrh.tmp
C:\WINNT\system32\routing.exe
C:\WINNT\Web\default.htt
C:\xcrashdump.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_PERFMONS
-------\Legacy_ROUTING
-------\Service_perfmons
-------\Service_Routing
((((((((((((((((((((((((( Files Created from 2008-03-26 to 2008-04-26 )))))))))))))))))))))))))))))))
.
2008-04-25 20:19 . 08-04-25 20:19 127 --a------ C:\WINNT\system32\MRT.INI
2008-04-25 20:18 . 08-04-25 20:20 1,429 --a------ C:\WINNT\imsins.BAK
2008-04-25 20:09 . 08-04-25 20:32 554,278 ---h----- C:\WINNT\ShellIconCache
2008-04-25 20:03 . 08-04-25 20:03 126 --a------ C:\WINNT\system32\g73.reg
2008-04-24 20:55 . 08-04-24 20:55 <DIR> d-------- C:\VundoFix Backups
2008-04-24 13:50 . 08-04-24 13:56 44,058 --a------ C:\WINNT\wininit.ini
2008-04-24 13:32 . 08-04-25 20:02 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-24 07:56 . 03-06-19 14:05 30,768 --a------ C:\WINNT\system32\drivers\disk.sys
2008-04-22 20:44 . 08-04-22 21:02 16,384 --a------ C:\WINNT\Active Setup Log.BAK
2008-04-17 12:04 . 08-04-25 15:37 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-17 12:03 . 02-05-15 15:16 462,848 --a------ C:\WINNT\system32\msaatext.dll
2008-04-17 12:03 . 02-05-15 15:16 360,448 --a------ C:\WINNT\system32\oleacc.dll
2008-04-17 12:03 . 02-05-15 15:16 356,352 --a------ C:\WINNT\system32\oleaccrc.dll
2008-04-17 12:03 . 02-05-15 15:16 356,352 --a--c--- C:\WINNT\system32\dllcache\oleaccrc.dll
2008-04-10 17:29 . 08-04-24 22:03 <DIR> d-------- C:\Program Files\Privacy Watcher
2008-04-10 09:58 . 08-04-10 09:58 <DIR> d-------- C:\Documents and Settings\Medina\Application Data\Motive
2008-04-10 00:01 . 08-04-24 21:05 <DIR> d-------- C:\Program Files\LiveAntispy
2008-04-05 00:09 . 08-04-05 00:09 194 --a------ C:\WINNT\system32\nthk77446.bat
2008-04-02 23:41 . 08-04-02 23:41 145 --a------ C:\WINNT\system32\1.tsk
2008-04-01 18:50 . 08-04-01 18:50 183 --a------ C:\WINNT\system32\nthk7653.bat
2008-04-01 16:43 . 08-04-01 16:43 194 --a------ C:\WINNT\system32\nthk89370.bat
2008-03-27 22:09 . 08-03-27 22:09 <DIR> d-------- C:\Program Files\Scholastic
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-03-30 09:54 --------- d-----w C:\Documents and Settings\Medina\Application Data\Yahoo!
2008-03-28 03:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-26 04:15 --------- d-----w C:\Program Files\MSXML 4.0
2008-03-18 18:39 --------- d-----w C:\Program Files\Scholastic's Clifford
2008-03-16 03:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-08-15 16:41 271 ---h--w C:\Program Files\desktop.ini
2007-08-15 16:41 21,952 ---h--w C:\Program Files\folder.htt
1999-12-06 21:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
.
------- Sigcheck -------
99-12-06 16:00 7952 9e64ad53cfd9da2d22e8a924f8c6e62c C:\WINNT\system32\svchost.exe
99-12-06 16:00 7952 9e64ad53cfd9da2d22e8a924f8c6e62c C:\WINNT\system32\dllcache\svchost.exe
03-06-19 14:05 403216 11ed538db87d8cf38017a63a82aa805d C:\WINNT\$NtUpdateRollupPackUninstall$\user32.dll
03-06-19 14:05 403216 11ed538db87d8cf38017a63a82aa805d C:\WINNT\ServicePackFiles\i386\user32.dll
07-03-06 06:17 381200 40023a7103796b1af6ca41a6dbc54775 C:\WINNT\system32\USER32.DLL
07-03-06 06:17 381200 40023a7103796b1af6ca41a6dbc54775 C:\WINNT\system32\dllcache\USER32.DLL
03-06-19 14:05 69904 0190c62de42396d78db9be771cf2403e C:\WINNT\ServicePackFiles\i386\ws2_32.dll
03-06-19 14:05 69904 0190c62de42396d78db9be771cf2403e C:\WINNT\system32\ws2_32.dll
03-06-19 14:05 181008 3980c28d116d438bbb36fb38526fde1a C:\WINNT\$NtUpdateRollupPackUninstall$\winlogon.ex e
03-06-19 14:05 181008 3980c28d116d438bbb36fb38526fde1a C:\WINNT\ServicePackFiles\i386\winlogon.exe
05-04-08 06:51 186640 bb1daf6a5737652646d52665251a0265 C:\WINNT\system32\WINLOGON.EXE
05-04-08 06:51 186640 bb1daf6a5737652646d52665251a0265 C:\WINNT\system32\dllcache\WINLOGON.EXE
03-06-19 14:05 170928 fb4f2d0595bd3546a4dd915e4a9b4809 C:\WINNT\ServicePackFiles\i386\ndis.sys
03-06-19 14:05 170928 fb4f2d0595bd3546a4dd915e4a9b4809 C:\WINNT\system32\drivers\ndis.sys
03-06-19 14:05 1694080 541daef38c9c82541690aa7e6f52f654 C:\WINNT\$NtUpdateRollupPackUninstall$\ntkrnlpa.ex e
07-03-05 10:52 1713536 d63ccca44ab92d8b819054e2af6202ae C:\WINNT\Driver Cache\i386\ntkrnlpa.exe
03-06-19 14:05 1694080 541daef38c9c82541690aa7e6f52f654 C:\WINNT\ServicePackFiles\i386\ntkrnlpa.exe
07-03-05 10:52 1713536 d63ccca44ab92d8b819054e2af6202ae C:\WINNT\system32\NTKRNLPA.EXE
07-03-05 10:52 1713536 d63ccca44ab92d8b819054e2af6202ae C:\WINNT\system32\dllcache\ntkrnlpa.exe
03-06-19 14:05 1719056 61a2dcfce1abf5340d2128e45b5f52b7 C:\WINNT\$NtUpdateRollupPackUninstall$\ntoskrnl.ex e
07-03-05 10:51 1690880 a9b95a62c4f298aadd3bec2fdf49fcbe C:\WINNT\Driver Cache\i386\ntoskrnl.exe
03-06-19 14:05 1719056 61a2dcfce1abf5340d2128e45b5f52b7 C:\WINNT\ServicePackFiles\i386\ntoskrnl.exe
07-03-05 10:51 1690880 a9b95a62c4f298aadd3bec2fdf49fcbe C:\WINNT\system32\NTOSKRNL.EXE
07-03-05 10:51 1690880 a9b95a62c4f298aadd3bec2fdf49fcbe C:\WINNT\system32\dllcache\ntoskrnl.exe
03-06-19 14:05 243472 59cf2b7dced9111f48f51b4b570e672d C:\WINNT\explorer.exe
03-06-19 14:05 243472 59cf2b7dced9111f48f51b4b570e672d C:\WINNT\ServicePackFiles\i386\explorer.exe
05-03-21 15:13 11264 ab176f2171db704d51b8809e8a5c38bd C:\WINNT\system32\CTFMON.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="ctfmon.exe" [05-03-21 15:13 11264 C:\WINNT\system32\CTFMON.EXE]