Name: shalee89 Date: October 3, 2007 at 09:36:44 Pacific Subject: Possible Virus? OS: Windows XP Home SP2 CPU/Ram: P4 3.20GHz/504MB RAM Model/Manufacturer: Pavilion a820n
Comment:
Ok I recently received a file transfer through Windows messenger from a friend. Withi in 5 minuted of unzipping it my Norton started alerting me to a High risk, nvsvc64.exe trying to connect (outbound upd packet port 0) to 208.180.42.68, domain (53) I have blocked it even though I believe nvsvc64.exe could be nvidia since i not sure if I am using nvidia on this computer. This friend told me next day not to open the file it was a virus. Would have been nice of him to answer me the times i tried to ask him before i dl and opened it. Anyway Housecall online scans come up clean and norton scans come up clean. Searches for the nvsvc64.exe come up clean except for in prefetch. But after removing from prefetch and everytime i start or restart my computer i get the same alert from norton. I dl and ran hijackthis and have logfile. Just not sure how to read it. Could just be me worrying over much. But I don't want to take any chances. Any ideas or help would be greatly appreciated.
Please download and install the latest version of HijackThis v2.0.2:
Download the HijackThis Installer from this link: HijackThis
1. Save " HJTInstall.exe" to your desktop. 2. Double click on HJTInstall.exe to run the program. 3. By default it will install to C:\Program Files\Trend Micro\HijackThis. 4. Accept the license agreement by clicking the "I Accept" button. 5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log. 6. Click "Save log" to save the log file and then the log will open in Notepad. 7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log. 8. Paste the log in your next reply. 9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:28:13 PM, on 10/3/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Boot mode: Normal
Empty the restore folder. Go to start>control panel>system>system restore tab>check the box beside "turn off system restore>apply (takes a minute)>ok. Go back and uncheck the box to turn system restore back on>apply>ok.
Next, please reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
Run ATF-Cleaner from safe mode.Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button.
Reboot to normal mode
Please download ComboFix to the desktop from this link:
Ok reran hijackthis and removed specified items. DL and ran ATFCleaner in safe mode. Cannot get to the combofix website. Internet Explorer webpage not available. Currently have Internet security set to block traffic on that computer since a few minutes ago norton popped up alert boxes (5 of them) win32.ircbot (1, auto deleted. 2, repair failed. 3, access denied. 4,auto deleted. 5, after reboot auto deleted. (Things just keep getting funner and funner. Sorry have to find some humor somewhere.) have tried googling for combo fix but the link there wouldn't work either.
The site came back up just before you posted back :) Following is the logfile for combofix:
ComboFix 07-10-04.5 - HP_Owner 2007-10-03 23:30:23.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.182 [GMT -5:00] Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe * Created a new restore point .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
C:\WINDOWS\hosts D:\Autorun.inf
. ((((((((((((((((((((((((( Files Created from 2007-09-04 to 2007-10-04 ))))))))))))))))))))))))))))))) .
Hi again, I want to thank you for your time and help on this. It seems to be doing ok. I shut it down last night after running the combofix. Since I had not had the chance to make sure the W32.IRCBot had been eliminated. Currently I am using my tv for a monitor on it. Am scanning with Norton now the folders in which it shows the virus was at (C:Windows/system32/nvsvc64.exe (still can't figure out what it is since it the first time in 4 years that has tried to access the net and can't even find that specific file or folder) and the C:Documents and settings files) If norton does not find those files and I can find them myself would it be safe to manually delete them? Any way I will try a restart after Norton finishes scanning and see how slow the reload takes. It had gotten noticable slower but I figured i have several processes loading at start up that probly slow it down. Am still a bit worried about hooking it back up to the network and letting it online if it might still have a virus. Could the virus get to the other computers on my network through that network?
Please download SDFix by AndyManchesta and save it to your desktop.
Please then reboot your computer in Safe Mode by doing the following: Restart your computer. After hearing your computer beep once during startup, but just before the Windows icon appears, tap the F8 key continually. Instead of Windows loading as normal, a menu with options should appear. Select the first option, to run Windows in "Safe Mode", then press "Enter". Choose your usual account.
Once in Safe Mode, please do the following: In Safe Mode, right-click the SDFix.zip folder and choose Extract All. Open the extracted folder and double-click RunThis.bat to start the script. Type Y to begin the script. It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot. Press any Key and it will restart the PC. Your system will take longer that normal to restart as the fixtool will be running and removing files. When the desktop loads the fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons. Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt
Run this free online scan from Kaspersky http://kaspersky.com/kos/english/kavwebscan.html Click Accept When the updates are finished downloading, click Next, Scan Settings Under Scan using the following antivirus database:, select extended Make sure the Scan Archives and Scan Mail Bases options are selected as well. Click OK Click My Computer and wait for the scan to finish Click Save Report As. Under Save as type:, select Text file. Save this log to your Desktop and post a copy of it here.
Scan Statistics: Total number of scanned objects: 74667 Number of viruses found: 2 Number of infected objects: 5 Number of suspicious objects: 0 Duration of the scan process: 00:58:39
Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\LightScribe\log\loglsburnwatcher.exe_2592.xml Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-10-04_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped C:\Documents and Settings\HP_Owner\Cookies\index.dat Object is locked skipped C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Ahead\Nero Home\is2.db Object is locked skipped C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\HP_Owner\Local Settings\Temp\hpodvd09.log Object is locked skipped C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\HP_Owner\NTUSER.DAT Object is locked skipped C:\Documents and Settings\HP_Owner\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped C:\Program Files\Common Files\Symantec Shared\AntiSpam\Log\Spam.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPStop.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\43E43399.exe Infected: Trojan-Downloader.Win32.Injecter.n skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4FFD3098.exe Infected: Trojan-Downloader.Win32.Injecter.n skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\61B82915.exe Infected: Trojan-Downloader.Win32.Injecter.n skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\chandir.dat Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\chandir.idx Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\chn.dat Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\chn.idx Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\D0000000.FCS Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\inuse.txt Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\L0000001.FCS Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\main.log Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\prs.dat Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\prs.idx Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_die.dat Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_die.idx Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_dnd.dat Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_dnd.idx Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_ext.dat Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_ext.idx Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_rcv.dat Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_rcv.idx Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\storydb.dat Object is locked skipped C:\Program Files\Updates from HP\309731\Users\Default\Data\storydb.idx Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{8F7A5040-9305-4BDA-A5EE-E7EE68E6A93B}\RP391\A0034040.exe Infected: Trojan-Downloader.Win32.Injecter.n skipped C:\System Volume Information\_restore{8F7A5040-9305-4BDA-A5EE-E7EE68E6A93B}\RP392\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Empty the restore folder. Go to start>control panel>system>system restore tab>check the box beside "turn off system restore>apply (takes a minute)>ok. Go back and uncheck the box to turn system restore back on>apply>ok.
Navigate to and delete the contents of this folder:
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:44:08 AM, on 10/5/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Boot mode: Normal
I suspect that nvsvc64.exe is a trojan so lets remove it and see what happens.
If you have any adverse effects to retrieve it run Hijack This> click "open the misc. tolls section> click "backup" and highlight " 04 - HKLM\..\Run: [nVidia Display Driver] "> then click restore.
Run Hijack This from safe mode, close all windows except Hijack This, place a check to the left of the following items and press "fix checked":
Set up the computer to view hidden files by going to start>control panel>folder options>view tab>tick the circle beside "show hidden files and folders" and untick the box beside "hide extensions of known file types" and "hide protected system operating files">apply>ok.
Next, navigate and delete this file
C:\WINDOWS\system32\nvsvc64.exe
Leave it in the recycle bin for a day or two then if everything seems to run ok you can delete it from the recycle bin.
Set up the computer to view hidden files by going to start>control panel>folder options>view tab>tick the circle beside "show hidden files and folders" and untick the box beside "hide extensions of known file types" and "hide protected system operating files">apply>ok.
Navigate to delete this file
C:\WINDOWS\system32\nvsvc64.exe
It still didn't show up. That one of the things that kept bothering me when it started trying to access the net was becuase I could not find it.
Ok here goes... Got up this morning and started the computer. Windows installer pops up..Please wait while windows configures Norton Antivirus 2005. then... Norton Antivirus does not support the Repair feature, please uninstall and reinstall. clicked ok got the same message clicked ok and it closed. Opened Norton and it seems fine no red flag warning that anything turned off. Shows that everything is on.
Have I just moved into the paranoid stage now? lol
Ah thank you. I really appreciate your time and help. One last question...Was thinking of switching from Norton Internet security back to Trend Micro, but I see Kaspersky has one. I'm sure it is good but how is it for ease of use?
I use AVG free antivirus. You can get it Here When you install it uncheck "run scan at start up" to reduce startup time.
You should consider adding "Spywareblaster" to your arsenol of antispyware tools, just do a google search for spywareblaster, download it,install it, and update it. Its free and runs in the background, so you don't actually run it, and re-writes malicious script before it can install on your computer. Look for updates weekly as there is no auto-update on the free version.
The information on Computing.Net is the opinions of its users. Such
opinions may not be accurate and they are to be used at your own risk.
Computing.Net cannot verify the validity of the statements made on this site. Computing.Net and Computing.Net, LLC hereby disclaim all responsibility and liability for the content of Computing.Net and its accuracy.
PLEASE READ THE FULL DISCLAIMER AND LEGAL TERMS BY CLICKING HERE