Shortly after Thanksgiving, I was having issues with the Ping.exe running my CPU usage up to 100% and freezing my computer. I ran my Avira Antivirus and it said it had found a Trojan, and quarantined it. However, after this, I was still having issues with the Ping.exe issue.

I then tried to do a system restore to "undo" these issues, but it told me that it was unable to complete the restore, and left me still having issues. As I was looking for resolutions online, I found PhilliePhan's thread helping out another person with similar issues. He referred him back to a previous thread, and I followed those steps.

I ran the newest MalwareBytes AntiMalware version previously, and Avira both claimed to find 1 threat, and quarantine it. I can get you a screen shot of the message if it would help. I was still not able to run my system restore function and have it complete successfully. I read another forum that suggested turning off the system restore > rebooting > re-activating system restore. I did that already, however I have not tried it out yet.

I have also lost connectivity on my wireless adapter (however that might not be related)? It is telling me that I am connected to my network, and authenticated however it never assigns an address, and then tells me that I have limited or no connectivity. For this I have tried to reset the wireless adapter, the router, and even checked a few of the forums looking for other suggestions.

I am way over my head here, and getting frustrated. I just had my computer repaired back in April by a guy in my church.

I was hoping someone could take a look thru the files that PhilliePhan requested, and help me out with my issues.
Thanks in advance for any help!

Here are the requested files
I thought I could find the logs folder from the avira antivirus and so far cant find it. I can view them thru the interface but I'm not sure how to put them into a notepad document or anything. It's midnight EST and I've got to run - will look at the logs as soon as I can and get back to you. Judy may beat me to it. Cheers :) PP EDIT: Never mind that last bit about Avira - I just saw it in the logs: Error - 12/7/2011 4:12:25 AM | Computer Name = OWNER-0FE07171A | Source = Service Control Manager | ID = 7003 Description = The DHCP Client service depends on the following nonexistent service: NetBT When I post back, we can repair NetBT and try to get the machine back online and hopefully make the cleaning process a bit easier.... Edited by PhilliePhan: n/a ComboFix is running right now. It said it found a RootKit Virus, and sat there for a bit, then asked me to restart the computer. It is now restarted and ComboFix is running again. I took a quick screen shot of the actual message to get the name of the virus. (If it helps?) It also said that I didn't have an active System Restore program running, however I had just created a restore point, shortly after I turned it on. Maybe the virus had infected that along with the wireless adapter I use. The ComboFix auto scan is now telling me that it has "Completed Stage 4" will post up the results after I run the TDSSKiller Here is the ComboFix Log: ComboFix 11-12-08.01 - Owner 12/08/2011 22:26:45.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.219 [GMT -5:00] Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7} . WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Search Toolbar c:\program files\Search Toolbar\icon.ico c:\program files\Search Toolbar\SearchToolbar.dll c:\program files\Search Toolbar\SearchToolbarUninstall.exe c:\program files\Search Toolbar\SearchToolbarUpdater.exe c:\windows\$NtUninstallKB25972$c:\windows\$NtUninstallKB25972$\2319490435 c:\windows\$NtUninstallKB25972$\3449333996\@ c:\windows\$NtUninstallKB25972$\3449333996\bckfg.tmp c:\windows\$NtUninstallKB25972$\3449333996\cfg.ini c:\windows\$NtUninstallKB25972$\3449333996\Desktop.ini c:\windows\$NtUninstallKB25972$\3449333996\keywords c:\windows\$NtUninstallKB25972$\3449333996\kwrd.dll c:\windows\$NtUninstallKB25972$\3449333996\L\okybosud c:\windows\$NtUninstallKB25972$\3449333996\lsflt7.ver c:\windows\$NtUninstallKB25972$\3449333996\U\00000001.@ c:\windows\$NtUninstallKB25972$\3449333996\U\00000002.@ c:\windows\$NtUninstallKB25972$\3449333996\U\00000004.@ c:\windows\$NtUninstallKB25972$\3449333996\U\80000000.@ c:\windows\$NtUninstallKB25972$\3449333996\U\80000004.@ c:\windows\$NtUninstallKB25972$\3449333996\U\80000032.$
c:\windows\$NtUninstallKB25972$\3449333996\U\80000032.@
c:\windows\CSC\d6
c:\windows\system32\Packet.dll
c:\windows\system32\wpcap.dll
G:\autorun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_NPF
.
.
((((((((((((((((((((((((( Files Created from 2011-11-09 to 2011-12-09 )))))))))))))))))))))))))))))))
.
.
2011-12-04 01:55 . 2011-12-04 01:55 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2011-12-03 22:45 . 2011-12-03 22:45 -------- d-----w- c:\windows\system32\wbem\Repository
2011-12-03 22:44 . 2011-12-07 08:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-03 20:02 . 2011-12-03 20:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-01 02:15 . 2011-12-05 03:44 -------- d-----w- c:\documents and settings\Administrator
2011-11-30 18:29 . 2011-12-04 21:57 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-11-30 18:13 . 2011-11-30 18:13 50704 ----a-w- c:\windows\system32\drivers\npf.sys
2011-11-09 05:08 . 2011-11-09 05:08 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\AOL
2011-11-09 05:04 . 2011-12-05 18:06 -------- d-----w- c:\program files\Common Files\AOL
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-08 01:39 . 2011-08-11 00:41 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-10 18:43 . 2011-10-21 06:02 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768]
"NWCU"="c:\program files\Wireless\NT-USB150M Wireless N Client Utility\NWCU.exe" [2009-11-18 557152]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
.
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
.
2002-04-10 20:44 679936 ----a-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
.
.
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-01-26 19:31 2144088 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
2011-06-09 17:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
2010-11-11 17:55 159472 ----a-w- c:\program files\Zune\ZuneLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ZuneWlanCfgSvc"=3 (0x3)
"ZuneNetworkSvc"=3 (0x3)
"ZuneBusEnum"=2 (0x2)
"WMZuneComm"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Red Storm Entertainment\\Ghost Recon\\GhostRecon.exe"=
"c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=
"g:\\Games\\RavenShield\\system\\ravenshield.exe"=
"c:\\SRB CUSTOMS\\Switch\\switch.exe"=
"c:\\Program Files\\Wireless\\NT-USB150M Wireless N Client Utility\\NWCU.exe"=
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [4/19/2011 11:55 AM 136360]
R3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [4/19/2011 10:55 PM 1668352]
S4 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [11/11/2010 12:57 PM 268528]
.
Contents of the 'Scheduled Tasks' folder
.
.
.
.
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\wvpwlq2l.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-MozillaAgent - c:\windows\Temp\_ex-68.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-08 22:40
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(4336)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\acs.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\BCMSMMSG.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2011-12-08 22:46:20 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-09 03:46
.
Pre-Run: 32,934,670,336 bytes free
Post-Run: 32,969,920,512 bytes free
.
- - End Of File - - 23F91997C5D34B2B43F9089D7AD0A66E

Ok, It ran for 17 seconds, went thru 199 objects and found 0 threats.

ComboFix is running right now. It said it found a RootKit Virus, and sat there for a bit, then asked me to restart the computer. It is now restarted and ComboFix is running again. I took a quick screen shot of the actual message to get the name of the virus. (If it helps?)

--- Yeah screenshot would be cool - what rootkit did it identify?

-- I imagine you are still offline? Let's try this:
Click START > CONTROL PANEL > PERFORMANCE & MAINTAINANCE > ADMINISTRATIVE TOOLS > SERVICES
- RightClick DHCP Client and select STOP
- Navigate to C:\Windows\System32\Drivers and DELETE NetBT.sys (if it remains).
- Then go to C:\Windows\servicepackfiles\i386 and locate NetBT.sys.
Copy and Paste NetBT.sys from servicepackfiles\i386 into the C:\Windows\System32\Drivers Folder.
- Then, go back to Services and RightClick DHCP Client and select START

Reboot the computer for good measure and see if the connection is restored. If so, Update MBAM and run a full scan.

Let us know how you fare and we'll work from there.

Cheers :)
PP

Edited by PhilliePhan: clarification

It also said that I didn't have an active System Restore program running,

It isn't System Restore, it is the Recovery Console. Don't worry about it.
Plus, you are going to have to clean out System Restore once this is clean anyway.

Edited by jholland1964: n/a

--- Yeah screenshot would be cool - what rootkit did it identify?
PP

"Rootkit.ZeroAccess inserted itself into the tcp/ip stack"

ok I am at the DHCP Client and it is already stopped. If I click on 'Start' it tells me that it can not be started. Error 1075: The dependency service does not exist or has been marked for deletion.

Hopefully this means we're getting somewhere. Should I continue the steps you recommended and see what happens?

Ok, I walked thru the steps PP gave me, still no change.

Ok, I walked thru the steps PP gave me, still no change.

So, you were able to copy and paste the driver with no problem?

-- OK, let's try this. You'll need to open a command prompt:
START > RUN > Type cmd ENTER

Then, type or copy & paste the following and hit Enter:
netsh int ip reset c:\resetlog.txt

Note:
It is netsh<space>int<space> ip<space> reset<space> c:\resetlog.txt
Make sure to type it accurately or you'll get an error.

REBOOT the ill computer and see if that does the trick.

I will try to check back tomorrow PM EST.

Cheers :)
PP

Edited by PhilliePhan: n/a

OK, I just tried the above steps and it seems to have completely deactivated the wireless adapter. the gui is opening however everything is grayed out (un selectable).

I am wondering if re-installing the wireless software would resolve this?

I looked thru the files that Avira had quarrentined, and the rest all looked like they were restore points, compaired to the netbt.sys that you were focusing on.. Let me know and I can make a list of everything that Avira has set aside. I doubt I'll be on much this weekend, I have a few jobs lined up and helping the GF move too. Should be back Sunday night for sure..

Edited by CustomChevyGuy: n/a

I am wondering if re-installing the wireless software would resolve this?

Yeah - give that a try. Uninstall it and then reinstall it. Also check to make sure the DHCP Client is started - we may have to revisit that.

Resetting TCP/IP should correct the damage you noted from the malware.

-- Avira logs should be available to print or copy and paste.
I imagine you've got a number of infected restore points and, as Judy mentioned, we'll need to flush those after we complete the cleaning procedures.

I'll be around over the weekend - hopefully weather will be good and I can have another crack at those Camaro T-Tops....:)

PP

Yeah - give that a try. Uninstall it and then reinstall it. Also check to make sure the DHCP Client is started - we may have to revisit that.

Resetting TCP/IP should correct the damage you noted from the malware.

-- Avira logs should be available to print or copy and paste.
I imagine you've got a number of infected restore points and, as Judy mentioned, we'll need to flush those after we complete the cleaning procedures.

I'll be around over the weekend - hopefully weather will be good and I can have another crack at those Camaro T-Tops....:)

PP

So my two jobs I had lined up cancelled on me. I figure I'd jump back on here and keep cracking on this.

I uninstalled and reinstalled the wireless program. It is still doing the same thing, saying I'm connected and have full strenght connection, however it never gives me an address.

I went back and tried to start the DHCP, and got the same message as before. If I click on 'Start' it tells me that it can not be started. Error 1075: The dependency service does not exist or has been marked for deletion.
If I double click on it it brings up a new window showing 4 tabs: General, Log On, Recovery, and Dependencies. Under the General tab it states that
The file it is pointed to is c:\WINDOWS\system32\svchost.exe<SPACE>-k<SPACE>netsvcs

I uninstalled and reinstalled the wireless program. It is still doing the same thing, saying I'm connected and have full strenght connection, however it never gives me an address.

All right - let's throw the kitchen sink at it and see what happens:

Open a command prompt again and enter each of the following commands one by one:
sc start dhcp
sc start netbt
sc start ipsec
sc start tcpip
sc start afd
netsh int ip reset C:\resetlog.txt
netsh winsock reset
ipconfig /flushdns
ipconfig /all

REBOOT for good measure and see if that helps.

-- Check Include All Files and hit scan. It should produce a log. Please post the FSS.txt for me. That should show us what we are missing.

PP:)

Edited by PhilliePhan: Brain Cramp

All right - let's throw the kitchen sink at it and see what happens:

Open a command prompt again and enter each of the following commands one by one:
sc start dhcp
sc start netbt
sc start ipsec
sc start tcpip
sc start afd
netsh int ip reset C:\resetlog.txt
netsh winsock reset
ipconfig /flushdns
ipconfig /all

REBOOT for good measure and see if that helps.

-- Check Include All Files and hit scan. It should produce a log. Please post the FSS.txt for me. That should show us what we are missing.

PP:)

Here are the results from the above steps:

sc start dhcp
[sc] StartService FAILED 1075:
The dependency service does not exist or has been marked for deletion.

sc start netbt
[sc] StartService: OpenService FAILED 1060:
THe specified service does not exist as an installed service.

sc start ipsec
[sc] startservice FAILED 1056:
An instance of the service is already running.

sc start tcpip
[sc] StartService FAILED 1056:
An instance of the service is already running.

sc start afd
[sc] startservice FAILED 1056:
An instance of the service is already running.

netsh int ip reset c:\resetlog.txt
after pressing enter it jumped back to c:\

netsh winsock reset
Successfully reset the Winsock Catalog. You Must restart the machine in order to complete the rest.

ipconfig /flushdns
Windows IP Configuration
Successfully flished the DNS Resolver Cache.

ipconfig /all
(see Screenshot)

Attachments

Ok, after I re-booted, it looks like my wireless adapter's software is not running. It has not popped up in the task bar, and when I opened the program manually everything is grayed out (unselectable).

I am going to run the FABAR Scanner now and see what happens.

Hey PP, your comment about the kitchen sink made me LOL. I spent all day Saturday, helping my gf and her sister move! That was about the only thing I actually didnt have to touch all weekend. It was a longggg moving day to say the least.

Any progress on those t-tops?

Edited by CustomChevyGuy: n/a

FSS.txt

Farbar Service Scanner
Ran by Owner (administrator) on 11-12-2011 at 22:31:53
Microsoft Windows XP Professional Service Pack 3 (X86)
********************************************************

Service Check:
==============
Dhcp Service is not running. Checking service configuration:
The start type of Dhcp service is OK.
The ImagePath of Dhcp service is OK.
The ServiceDll of Dhcp service is OK.

NetBt Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to retrieve start type of NetBt. The value does not exist.
Checking ImagePath: Attention! Unable to retrieve ImagePath of NetBt. The value does not exist.

File Check:
===========
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit

Connection Status:
==================
Localhost is accessible.
There is no connection to network.
Attempt to access Yahoo IP returend error: Yahoo IP is unreachable

**** End of log ****

Hey CCG,

Too cold for the T-tops. Was going to try a little silicone sealant, but will probably have to wait until spring. No worries, I suppose - after all, it is a 17 year old car.

-- As for the ill computer, let's try an oldie but goodie from Option^Explicit ---> Winsock XP Fix

Run that and hit fix - that ought to automatically repair the registry damage so we don't have to do it manually. If we have to do it manually then it becomes dicey.

Let me know how that shakes out.

PP:)

Edited by PhilliePhan: n/a

Hey CCG,

Too cold for the T-tops. Was going to try a little silicone sealant, but will probably have to wait until spring. No worries, I suppose - after all, it is a 17 year old car.

-- As for the ill computer, let's try an oldie but goodie from Option^Explicit ---> Winsock XP Fix

Run that and hit fix - that ought to automatically repair the registry damage so we don't have to do it manually. If we have to do it manually then it becomes dicey.

Let me know how that shakes out.

PP:)

I keep forgetting that up north, winter is starting to set in.

I just ran the Winsock XP Fix and am rebooting it now. Keeping my fingers crossed, and prayers being said.

I have rebooted, and logged in. The wireless connection is still listes as Disabled under the Network Connections. I can not select "Enable". I tried to click on the "Repair" option, and it sits there doing its diagnostics only to tell me that a connection can not be established to the network.

I have connected a wire to see if it was the wireless connection, and it is still searching for an address as well.

Ok - let's try to repair the registry damage done by the malware. I thought winsock fix might do it for us, but I guess not.

Anyhoo - first I suggest backing up the registry with a tool such as ERUNT
It is simple and quick and good to have as a "fallback" in the event we need it.

-- RENAME it to FixNetBT.reg

On the ill machine, DoubleClick FixNetBT.reg and allow it to merge into the registry.
REBOOT and see if that fixes the connection.

--- If not, run Farbar Service Scanner again and post those results.

PP:)

Edited by PhilliePhan: It'd be nice if I actually attached the fix....

Ok - let's try to repair the registry damage done by the malware. I thought winsock fix might do it for us, but I guess not.

Anyhoo - first I suggest backing up the registry with a tool such as ERUNT
It is simple and quick and good to have as a "fallback" in the event we need it.