Ive just got myself an infection which no scanner is
stopping or even detecting up to now (MSAS, Ewido, Trend,
CAeTrust, Adaware, Spybot) but its abit similar to what
your seeing I remember seeing your messages awhile ago
but cannot remember the malware involved so visited afew
common sites for this junk but have a beast now
I dont think yours is as serious as this but if it
remains Download Hijack This & Post a log if the ewido &
trend scan doesnt kill it and we can try help you out
I get a message now in the system tray which says this :
"Warning: Your Computer is infected
Windows has detected a spyware infection
It is recommended to use special antispyware tools to
prevent data loss, Windows will now download and install
the most up to date antispyware for you"
It then installs SpySheriff
There seems to be a serious infection here with files
using genuine sounding names, This is just a test setup
but I advise you to stay away from these pop ups and use
other scanners to clear the problem, All this has passed
by MSAS without being noticed but ewido and antivirus
scans has missed most of this too so this must be new,
Ive just rebooted and now have a nice Red spyware Warning
desktop wallpaper which Ive not seen before Its abit like
the smitfraud/AV Gold infection.
Here's the hijack log and the detections from ewido, I'll
just list the malware entries:
Logfile of HijackThis v1.99.1
Scan saved at 15:14:11, on 23/08/2005
R1 -
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyServer = http=
http://127.0.0.1:80
O4 - HKLM\..\Run: [Microsoft Internet Acceleration
Utility] C:\WINDOWS\iau.exe
O4 - HKLM\..\Run: [Internet Connection Wizard] stisvsq.exe
O4 - HKLM\..\Run: [Games Acceleration] svshost.exe
O4 - HKLM\..\Run: [Internet Mail and News] msqdevl.exe
O4 - HKLM\..\Run: [Microsoft Management Console] lssas.exe
O4 - HKLM\..\Run: [Multimedia extensions] mservice.exe
O4 - HKLM\..\Run: [1aad606c2ca] C:\WINDOWS\System32
\1aad606c2ca.exe
O4 - HKCU\..\Run: [Microsoft Internet Acceleration
Utility] C:\WINDOWS\iau.exe
O4 - HKCU\..\Run: [Internet Connection Wizard] stisvsq.exe
O4 - HKCU\..\Run: [Games Acceleration] svshost.exe
O4 - HKCU\..\Run: [Internet Mail and News] msqdevl.exe
O4 - HKCU\..\Run: [Microsoft Management Console] lssas.exe
O4 - HKCU\..\Run: [Multimedia extensions] mservice.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [SpySheriff] C:\Program
Files\SpySheriff\SpySheriff.exe
O4 - HKCU\..\Run: [SNInstall] C:\WINDOWS\msras.exe
O4 - HKCU\..\Run: [1aad606c2ca] C:\WINDOWS\System32
\1aad606c2ca.exe
O16 - DPF: {10000000-1000-0000-0000-000000000000} -
file://C:\\Recycler\\Q678341.exe
O23 - Service: WindowInstallSystem (1aad606c2casvr) -
Unknown owner - C:\WINDOWS\1aad606c2ca.exe
Ewido Scan :
Created on: 15:24:35, 23/08/2005
C:Temporary Internet Files\Content\0DE3SH6V\loader7
[1].htm -> TrojanDownloader.VBS.Psyme.ap
C:Temporary Internet Files\Content\0H6301YN\file_0
[1].exe -> TrojanDownloader.Small.uv :
C;Temporary Internet Files\Content\0H6301YN\on[1].exe ->
TrojanDropper.Vidro.u
C:\Documents and Settings\Andy Manchesta\Start
Menu\Programs\SpySheriff -> Spyware.SpySheriff
C:\p.exe -> TrojanDownloader.Small.uv
C:\q.exe -> TrojanDownloader.Small.ar
C:\WINDOWS\msras.exe -> Not-A-Virus.Hoax.Renos.m :
C:\winstall.exe -> Not-A-Virus.Hoax.Renos.m
Not sure how malware can be described as not a virus.hoax
but its not helped things anyway, Im really not sure what
Im looking at here yet so need to do some more work on it
if I can kill enough to get online and get rid of the
proxy loopback with the infected machine, I cannot open
IE/Regedit/TaskManager or MSAS anymore everything I try
says the application failed to initialize properly, Click
OK to terminate
If I try MSAS it says :
c:\ProgramFiles\MicrosoftAntispyware\GiantAntispywareMain.
exe
Attempt to access invalid address
Im not concerned on my system I'm just interested what's
causing all this damage and why none of it is being
detected so Im happy to play around with it, This is
really just to show you that the messages may be bogus
and potentially very dangerous if you follow them or even
click on them.At this stage its well and truly killed my
test pc
(
Let us know how you get on with yours
Andy