It is currently Tue Sep 01, 2026 2:51 pm


ISIVRSSV.EXE error help please!!!

All versions of Windows 7, 2008 and Vista including 32 bit and 64 bit

Moderator: icecube

ISIVRSSV.EXE error help please!!!

Postby Josh24_15 » Wed Mar 07, 2007 4:58 pm

One of my customers computers I take care of has an error every time it starts up. The PC is running XP Home SP2, has AOL 9.0 SE...(i hate AOL), no viruses found, no spyware found. The error is as follows:

ISIVRSSV.EXE has encountered a problem and needs to stop. We are sorry for any inconvice.

There is a button to click ok. After clicking ok everything work as normal. I search google and came up with 0 results for ISIVRSSV.EXE, I searched her PC (looking in hidden files and folders) to try and find where the file is located but came back with no results, I searched her registry and again found nothing, and there is nothing in msconfig. It doesn't appear to be affecting performance or anything else on her PC but she wants the error to stop showing up, understandably so. Anyone have any ideas as to where to turn next?
Josh24_15
Newbie
Newbie
 
Posts: 6
Joined: Wed Mar 07, 2007 4:42 pm
Location: Gainesville, FL

Thanks given:0
Thanks received:0
Top

Postby icecube » Wed Mar 07, 2007 7:22 pm

Try installing Microsoft Defender and do a full scan not the quick one. It could be spyware. Some of them create random executable names.

I don't know how AOL's antivirus works, but if you can run it in safe mode, it may surprise you on what you will find. A lot of systems can appear clean, but aren't. Safemode will give you a better picture.

Norton takes about 2 hours on my system to run and the surprising thing, a full scan with Defender took over 8 hours.
User avatar
icecube
Moderator
Moderator
 
Posts: 1209
Joined: Wed Mar 10, 2004 1:00 am
Location: San Marcos Ca

Thanks given:0
Thanks received:0
Top

Postby Josh24_15 » Wed Mar 14, 2007 9:52 pm

Didn't work. ran scan with 0 results. supposedly the file is located in C:\WINDOWS\system32 but with even with "show hidden files" marked it's not there. event veiwer is giving me an application error for it with a verison # 0.0.0.0 and address of 0x00000000; event id is 1000. any other clues?

thanks for any help anyone gives,

Josh
Josh24_15
Newbie
Newbie
 
Posts: 6
Joined: Wed Mar 07, 2007 4:42 pm
Location: Gainesville, FL

Thanks given:0
Thanks received:0
Top

Postby icecube » Wed Mar 14, 2007 11:15 pm

Its probably a residual left in the registry without a home

Go to this page

and download Startup.exe.

Put it on the desktop and run it from there. Go to the different folders and look for that file. It's probably in the HKKM/run section. This program is easier than editing the registry, because you can't really back yourself into a corner with it. Uncheck the stuff you don't want running and reboot. You can always change your mind and run the program again and put a check mark back in the box. Through trial and error you should be able to kill it.

I use the program to keep things from automatically starting on boot.
User avatar
icecube
Moderator
Moderator
 
Posts: 1209
Joined: Wed Mar 10, 2004 1:00 am
Location: San Marcos Ca

Thanks given:0
Thanks received:0
Top

Postby Josh24_15 » Thu Mar 15, 2007 3:35 pm

Josh24_15
Newbie
Newbie
 
Posts: 6
Joined: Wed Mar 07, 2007 4:42 pm
Location: Gainesville, FL

Thanks given:0
Thanks received:0
Top

Postby Gecko » Thu Mar 15, 2007 8:35 pm

Josh24_15,

From what I have read has to do with connection issues, group policies and server errors.
The fact that you can't find any reference to ISIVRSSV.EXE in the registry makes me think you might have the remnants of a trojan/rootkit combo.
It sounds like this program is trying to connect to something and fails therefore giving the error.

Might I suggest that you download extract it to your root like this:
C:\rkr\ RootkitRevealer.exe

Close all other programs, windows and disable your screen saver before you start RootkitRevealer.
While RootkitRevealer is running, you shouldn't do anything at all with the PC.
Put down the mouse, back away slowly, and let the program do its work.


Start RootkitRevealer.exe and press the Scan button.
It will take some time to finish an hour is common so just wait it out.
Once the scanning is finished RootkitRevealer will create a log, please copy the contents of that log into you reply.

If there is anything being hidden from windows, RootkitRevealer will find it.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Josh24_15 » Thu Mar 15, 2007 9:48 pm

Thanks, I'll try it. Let you know tomorrow what happens....

Josh
Josh24_15
Newbie
Newbie
 
Posts: 6
Joined: Wed Mar 07, 2007 4:42 pm
Location: Gainesville, FL

Thanks given:0
Thanks received:0
Top

Postby Josh24_15 » Fri Mar 16, 2007 3:33 pm

Here is the Rootkit log:


HKU\S-1-5-21-1431624998-622498443-2734738325-1003\Software\C6iR9AHthQmm 10/20/2005 5:52 AM 0 bytes Hidden from Windows API.
HKLM\SECURITY\Policy\Secrets\SAC* 1/24/2003 2:20 AM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 1/24/2003 2:20 AM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\C6iR9AHthQmm 3/16/2007 10:15 AM 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\Classes\webcal\URL Protocol 3/11/2006 3:11 PM 13 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_WANARP 1/24/2003 2:03 AM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_WANFAX 1/13/2006 9:27 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\wanatw 3/16/2007 9:30 AM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\WANFax 3/16/2007 10:09 AM 0 bytes Hidden from Windows API.
C:\Program Files\Quianion 3/16/2007 12:28 AM 0 bytes Hidden from Windows API.
C:\Program Files\Quianion\ace.dll 1/13/2006 9:27 PM 568.00 KB Hidden from Windows API.
C:\Program Files\Quianion\AI_10-03-2007.log 3/10/2007 2:46 PM 3 bytes Hidden from Windows API.
C:\Program Files\Quianion\AI_11-03-2007.log 3/11/2007 4:42 PM 3 bytes Hidden from Windows API.
C:\Program Files\Quianion\AI_12-03-2007.log 3/12/2007 4:04 AM 3 bytes Hidden from Windows API.
C:\Program Files\Quianion\AI_13-03-2007.log 3/13/2007 8:09 AM 3 bytes Hidden from Windows API.
C:\Program Files\Quianion\AI_14-03-2007.log 3/14/2007 12:02 AM 3 bytes Hidden from Windows API.
C:\Program Files\Quianion\AI_15-03-2007.log 3/15/2007 12:00 AM 3 bytes Hidden from Windows API.
C:\Program Files\Quianion\AI_16-03-2007.log 3/16/2007 12:28 AM 3 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache 3/15/2007 10:27 PM 0 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000029_45f6dc13_0007a120 3/15/2007 11:35 PM 6.27 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000029_45f6ffbe_0005b8d8 3/13/2007 2:47 PM 1.53 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000029_45f9bfb8_0004c4b4 3/15/2007 9:27 PM 12.06 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000029_45f9cc96_000dd40a 3/15/2007 5:45 PM 148 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000029_45fa0e85_00098968 3/15/2007 10:27 PM 3.53 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000099_45f6e837_00039387 3/13/2007 1:06 PM 774 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000099_45f9a607_00016e36 3/15/2007 3:01 PM 3.45 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000099_45fa1cd1_000af79e 3/15/2007 11:28 PM 28.28 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000120_45fa2062_00098968 3/15/2007 11:43 PM 50.85 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000124_45f6e873_0000b71b 3/13/2007 1:07 PM 19.19 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000124_45f9a633_000a4083 3/15/2007 3:01 PM 276 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000124_45fa1d1c_000501bd 3/15/2007 11:29 PM 26.14 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000001eb_45f9a3d4_000d9701 3/15/2007 2:51 PM 12.06 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000001eb_45fa1c99_0005b8d8 3/15/2007 11:27 PM 6.06 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000030a_45fa1fbe_000dd40a 3/15/2007 11:40 PM 6.06 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000074d_45f6e88e_000b34a7 3/13/2007 1:08 PM 833 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000074d_45fa1dae_000501bd 3/15/2007 11:31 PM 4.33 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000bb3_45fa1c99_0009c671 3/15/2007 11:27 PM 11.30 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000bdb_45fa1fc0_00031975 3/15/2007 11:40 PM 8.74 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000f3e_45f6e837_0001312d 3/13/2007 1:06 PM 681 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000f3e_45f9a5e9_000baeb9 3/15/2007 3:00 PM 5.36 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00000f3e_45fa1c9f_0005f5e1 3/15/2007 11:27 PM 8.74 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00001238_45fa1e8d_00031975 3/15/2007 11:36 PM 57.33 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000012db_45f6e82c_0004c4b4 3/13/2007 1:06 PM 57.25 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000012db_45fa1c9a_0005f5e1 3/15/2007 11:27 PM 596 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000153c_45f6e836_000aba95 3/13/2007 1:06 PM 833 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000153c_45f9a48c_000d9701 3/15/2007 2:54 PM 3.52 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000153c_45fa1c9b_000e8b25 3/15/2007 11:40 PM 88.61 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00001547_45f6e886_000ca2dd 3/13/2007 1:08 PM 833 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00001547_45fa1dac_000e4e1c 3/15/2007 11:31 PM 8.75 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00001649_45f6dcc5_000e1113 3/13/2007 12:17 PM 8.38 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00001649_45f9a288_000ec82e 3/15/2007 11:56 PM 3.04 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00001649_45f9e363_0003567e 3/15/2007 11:56 PM 5.58 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00001649_45fa1c95_000aba95 3/15/2007 11:31 PM 1.55 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000018be_45f6dc60_000d9701 3/16/2007 8:07 AM 41.59 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000018be_45f9a26a_00057bcf 3/15/2007 11:56 PM 218 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\000018be_45f9e35c_000d59f8 3/15/2007 11:56 PM 218 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\000018be_45fa1c83_0006acfc 3/15/2007 11:26 PM 68.85 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00001ad4_45fa1eef_0004c4b4 3/15/2007 11:37 PM 54.74 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00002213_45fa1f28_00053ec6 3/16/2007 8:07 AM 53.11 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000260d_45fa1fbe_000487ab 3/15/2007 11:40 PM 8.72 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000026e9_45f6dcd5_0000f424 3/13/2007 12:18 PM 3.92 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00002cd6_45f6dcbd_00003d09 3/13/2007 12:17 PM 9.49 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00002cd6_45f9a273_00081b32 3/15/2007 11:56 PM 3.12 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00002cd6_45f9e360_0008d24d 3/15/2007 11:56 PM 218 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00002cd6_45fa1c90_000d9701 3/15/2007 11:26 PM 844 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00002cd6_45fa9687_000dd40a 3/16/2007 8:07 AM 276 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00002d12_45f6e887_00016e36 3/13/2007 1:08 PM 774 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00002d12_45fa1dae_00000000 3/15/2007 11:31 PM 6.18 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00002ea6_45f6e6df_000e4e1c 3/13/2007 1:01 PM 26.56 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00002ea6_45fa1c9a_0000b71b 3/15/2007 11:27 PM 1.07 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000301c_45fa1fbf_0007270e 3/15/2007 11:40 PM 11.24 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000305e_45f6e873_0002dc6c 3/13/2007 1:07 PM 833 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000305e_45fa1d1f_0000b71b 3/15/2007 11:30 PM 48.41 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000390c_45f6e837_00007a12 3/13/2007 1:06 PM 66.42 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000390c_45fa1c9e_0000b71b 3/15/2007 11:27 PM 2.15 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000039b3_45f6e887_00003d09 3/13/2007 1:08 PM 681 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\000039b3_45fa1dad_000c28cb 3/15/2007 11:31 PM 6.02 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00003b25_45fa1e92_00039387 3/15/2007 11:35 PM 40.92 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00003d6c_45f6dca0_000af79e 3/13/2007 12:17 PM 5.85 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00003d6c_45f9ff9a_00098968 3/15/2007 9:23 PM 7.28 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00003d6c_45fa1c90_000ca2dd 3/15/2007 11:26 PM 581 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00003d6c_45fa75bc_0001ab3f 3/16/2007 5:47 AM 0 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\000041bb_45f6dcd4_000e8b25 3/13/2007 12:18 PM 8.38 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000041bb_45fa1c98_0004c4b4 3/15/2007 11:27 PM 6.20 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000428b_45f6e890_0006acfc 3/13/2007 1:08 PM 55.87 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000440d_45f6e873_00039387 3/13/2007 1:07 PM 771 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000440d_45fa1d45_000d1cef 3/15/2007 11:29 PM 83.84 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004509_45fa1dc3_0007a120 3/15/2007 11:32 PM 522 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004823_45f6dc21_000cdfe6 3/13/2007 12:15 PM 55.17 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004823_45f7072f_00090f56 3/13/2007 3:18 PM 20 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004823_45f9e35a_0007de29 3/15/2007 11:56 PM 3.16 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004823_45fa1c4d_0003d090 3/15/2007 11:25 PM 36.53 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004823_45fa9611_0003d090 3/16/2007 8:05 AM 0 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000491c_45f6e873_000501bd 3/13/2007 1:07 PM 681 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\0000491c_45fa1d9d_000baeb9 3/15/2007 11:31 PM 64.63 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004ae1_45f6dc96_0006acfc 3/13/2007 12:17 PM 53.89 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004ae1_45f9a273_00007a12 3/15/2007 11:56 PM 6.07 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004ae1_45fa1c90_0003d090 3/15/2007 11:40 PM 80.90 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004d06_45f6e873_00057bcf 3/13/2007 1:07 PM 774 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004d06_45fa1da9_0007a120 3/15/2007 11:31 PM 581 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004db7_45f6e886_000baeb9 3/13/2007 1:08 PM 19.35 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004db7_45fa1da9_00081b32 3/15/2007 11:31 PM 844 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004dc8_45f6e88e_000e1113 3/13/2007 1:08 PM 771 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00004e45_45fa1f1e_000487ab 3/15/2007 11:37 PM 57.56 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000054de_45f6e886_000ec82e 3/13/2007 1:08 PM 771 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\000054de_45fa1dad_00098968 3/15/2007 11:31 PM 3.79 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00005af1_45f6dccb_0006ea05 3/13/2007 12:18 PM 3.77 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00005af1_45f9a2fb_0008d24d 3/15/2007 9:35 PM 44.42 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00005af1_45fa1c96_000af79e 3/15/2007 11:27 PM 7.01 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00005f90_45f6dcc5_0002625a 3/13/2007 12:17 PM 4.84 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00005f90_45f9a285_00000000 3/15/2007 11:56 PM 18.26 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00005f90_45fa076a_0009c671 3/15/2007 9:56 PM 2.36 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00005f90_45fa1c95_0002625a 3/15/2007 11:31 PM 6.22 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00005f90_45fa9696_000f0537 3/16/2007 8:07 AM 52.84 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000063cb_45fa1ef0_00066ff3 3/15/2007 11:37 PM 8.75 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006443_45f6e88f_0001e848 3/13/2007 1:08 PM 681 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\000066bb_45f6e88f_00040d99 3/13/2007 1:08 PM 774 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\000066bb_45fa1db9_0006acfc 3/15/2007 11:31 PM 68.85 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006784_45f9a26b_00003d09 3/15/2007 11:56 PM 83 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006784_45fa1c8f_000d1cef 3/15/2007 11:31 PM 22.90 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006952_45f6dcbe_00089544 3/13/2007 12:17 PM 9.26 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006952_45f9a277_000e1113 3/15/2007 11:56 PM 355 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006952_45fa1c93_0002625a 3/15/2007 11:26 PM 330 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006952_45fa968b_00090f56 3/16/2007 8:07 AM 0 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006b89_45fa1fbe_000aba95 3/15/2007 11:40 PM 3.79 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006bfc_45fa1ef0_0006acfc 3/15/2007 11:37 PM 8.74 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006df1_45f6dcc6_00016e36 3/13/2007 12:17 PM 3.92 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006df1_45f9a2df_00098968 3/15/2007 2:47 PM 22.47 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006df1_45fa1c96_000501bd 3/15/2007 11:32 PM 79.05 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00006e5d_45fa1eed_0006ea05 3/15/2007 11:37 PM 68.68 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000072ae_45f6dcbe_0003d090 3/13/2007 12:17 PM 5.25 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000072ae_45f9a273_0008d24d 3/15/2007 11:56 PM 4.83 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000072ae_45f9e360_000bebc2 3/15/2007 11:56 PM 83 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\000072ae_45fa0179_0002dc6c 3/15/2007 9:31 PM 57.64 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\000072ae_45fa1c90_000f0537 3/15/2007 11:31 PM 1.10 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00007a5a_45fa1dc3_00044aa2 3/15/2007 11:32 PM 1.07 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00007e87_45f6e836_000e1113 3/13/2007 1:06 PM 769 bytes Hidden from Windows API.
C:\Program Files\Quianion\Cache\00007e87_45f9a5c7_000d1cef 3/15/2007 3:00 PM 52.12 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00007e87_45fa1c9d_00066ff3 3/15/2007 11:27 PM 4.54 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\00007ff5_45fa1ef9_00094c5f 3/15/2007 11:37 PM 57.03 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\dns 3/16/2007 10:14 AM 27.10 KB Hidden from Windows API.
C:\Program Files\Quianion\Cache\index 3/16/2007 8:07 AM 26.29 KB Hidden from Windows API.
C:\Program Files\Quianion\csdnscfg.exe 1/13/2006 9:27 PM 164.00 KB Hidden from Windows API.
C:\Program Files\Quianion\data.bin 1/13/2006 9:27 PM 114.94 KB Hidden from Windows API.
C:\Program Files\Quianion\msyicmui.exe 1/13/2006 9:27 PM 912.00 KB Hidden from Windows API.
C:\Program Files\Quianion\WinGenerics.dll 1/13/2006 9:27 PM 576.00 KB Hidden from Windows API.
C:\WINDOWS\system32\drivers\flppdate.sys 1/13/2006 9:27 PM 12.00 KB Hidden from Windows API.
C:\WINDOWS\system32\isivrssv.exe 1/13/2006 9:27 PM 488.00 KB Hidden from Windows API.
D: 0 bytes Error mounting volume



and this is a Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 10:29:40 AM, on 3/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hijack This\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: Shell=Explorer.exe
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\6f93fv1s.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 2121912312
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe

--
End of file - 4265 bytes


Thanks again for any help,
Josh
Josh24_15
Newbie
Newbie
 
Posts: 6
Joined: Wed Mar 07, 2007 4:42 pm
Location: Gainesville, FL

Thanks given:0
Thanks received:0
Top

Postby Gecko » Fri Mar 16, 2007 8:49 pm

Hi Josh24_15,

Yes you do have a rootkit :(

Please copy this to Notepad and print it. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.
You should not have any open windows when you are following the procedures below.

Please download AVG Anti-Spyware 7.5 from and save that file to your desktop.
This is a 30 day trial of the program

1. Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
2. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
3. On the main screen select the icon "Update" then select the "Update now" link.
Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
4. Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
6. Under "Reports"
* Select "Automatically generate report after every scan"
* Un-Select "Only if threats were found"

Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.

Next download the FREE Swandog46 Apropos Fix from here -
http://swandog46.geekstogo.com/aproposfix.exe

Save to your desktop but DON'T run it just yet.

Reboot your computer into SafeMode:
Restart Windows after you see the BIOS screen and before Windows starts to load.
Start tapping the F8 key. The Windows Advanced Options Menu appears.
Use the Arrow key to ensure that the Safe Mode option is selected.
Press Enter. The computer then begins to start in Safe mode.

Now double click the aproposfix.exe on your desktop and Unzip the WinRar aproposfix.exe to your desktop.
From inside the new folder run the RunThis.bat and follow the prompts.


IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning:
1. Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
2. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
3. AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
Once the scan is complete do the following:
4. If you have any infections you will prompted, then select "Apply all actions"
5. Next select the "Reports" icon at the top.
6. Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
7. Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the results of the AVG Anti-Spyware report scan and a new hijackthis log in your reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Josh24_15 » Mon Mar 19, 2007 4:13 pm

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 9:25:42 AM, on 3/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Common Files\AOL\1174071503\ee\AOLSoftware.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hijack This\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: Shell=Explorer.exe
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\6f93fv1s.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1174071503\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 2121912312
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe

--
End of file - 5453 bytes


RootKit Scan

HKLM\SECURITY\Policy\Secrets\SAC* 1/24/2003 2:20 AM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 1/24/2003 2:20 AM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\webcal\URL Protocol 3/11/2006 3:11 PM 13 bytes Data mismatch between Windows API and raw hive data.
C:\Documents and Settings\Owner\Local Settings\Temp\pcf4.tmp 3/19/2007 9:00 AM 793 bytes Visible in Windows API, but not in MFT or directory index.
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb 3/19/2007 9:01 AM 64.00 KB Visible in Windows API, but not in MFT or directory index.
D: 0 bytes Error mounting volume


Spyware Scan

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 10:06:51 AM 3/19/2007

+ Scan result:



Nothing found.


::Report end

That fixed the problem. I also ran a virus scan and found nothing. Thank you again for all your help

Josh
Josh24_15
Newbie
Newbie
 
Posts: 6
Joined: Wed Mar 07, 2007 4:42 pm
Location: Gainesville, FL

Thanks given:0
Thanks received:0
Top

Postby Gecko » Mon Mar 19, 2007 8:17 pm

Josh24_15,




Please download and unzip to a convenient location such as C:\Qoofix.
Navigate to the folder you unzipped the files to and double click on the file named Qoofix.exe.
Finally, select Begin Removal and the removal process will commence.

After the reboot, post a new HiJackThis log in your reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top


Return to Windows 7, 2008 and Vista

Who is online

Users browsing this forum: No registered users and 1 guest

cron