Hi all. New to the forum and need some help/suggestions. I am running a Dell 6500Latitude/WinXPsp3 with a relatively clean install (system built 01/15/2010) and NIS2010. I connect to a small business server ever day with file synchronization and a roaming profile.
Background scan 2/7 5:38PM showed no major problems, "SafeStrip" is removed (I see this one every few days and have never tracked down the cause). However, on 2/8 at 3:34AM there are suddenly 134 (that's right--one hundred thirty four) different pieces of MalWare and SpyWare on the machine. Something had definitely changed because my homepage was now MSN.com vs. Google.com. Here is the NIS2010 log:
---
2/8/2010 10:03 AM,Low,Movieland detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 10:03 AM,Low,Adware.AntiSpamBoy detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 10:02 AM,Low,SpyOnThis detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 10:02 AM,High,Spyware.SpyMyPC detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 10:02 AM,Low,Trackware.WebGuardian detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 10:02 AM,Low,Adware.Eurobarre detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 10:02 AM,Medium,Adware.Henbang detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:47 AM,Medium,VirusBlast detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:47 AM,High,Spyware.RealSpy detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:47 AM,Medium,RegistryCleanFix detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:47 AM,Medium,UnSpyPC detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:47 AM,Medium,SafeStrip detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:46 AM,Medium,OSBodyGuard detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:46 AM,High,Spyware.SpyArsenalLog detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:46 AM,High,Spyware.LocalKeylog detected by Virus scanner,Quarantined,Resolved - No Action
2/8/2010 3:46 AM,Medium,CrisysTecSentry detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:46 AM,Medium,SpyGuarder detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:46 AM,Medium,Spyware.Borzoi detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:46 AM,Medium,AdvancedCleaner detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:46 AM,Medium,Spyware.SpyKy detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:46 AM,Medium,TitanShield detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:46 AM,Medium,Awola detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:46 AM,Medium,KvmSecure detected by Virus scanner,Quarantined,Resolved - No Action
2/8/2010 3:46 AM,Medium,Spyware.SpyMan detected by Virus scanner,Quarantined,Resolved - No Action
2/8/2010 3:46 AM,Medium,AntiVirGear detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:46 AM,High,Spyware.KeyCollect detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:46 AM,Medium,Spyware.Track4Win detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:45 AM,Medium,ErrorProtector detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:45 AM,Medium,IEAntivirus detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:45 AM,High,Spyware.PCTattletale detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:45 AM,Medium,Spyware.SpyMail detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:45 AM,Medium,WinZix detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:45 AM,Medium,MalwareWipe detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:45 AM,Medium,SpyShredder detected by Virus scanner,Quarantined,Resolved - No Action
2/8/2010 3:45 AM,High,MagicAntiSpy detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:45 AM,Medium,SpyBlocs detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:45 AM,Medium,Torrent101 detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:44 AM,High,Spyware.ActualSpy detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:44 AM,Medium,WinXDefender detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:44 AM,High,Spyware.QuickKeylogger detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:44 AM,High,Spyware.ActiveKeylog detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:44 AM,Medium,AntiSpywareExpert detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:44 AM,High,Spyware.AceScreenSpy detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:44 AM,Medium,SecurityToolFraud detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:44 AM,High,Adware.AdRoar detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:44 AM,Medium,Spyware.MSNSpyMonitor detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:43 AM,Medium,Spyware.FreeKeylogger detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:43 AM,Medium,SpywarePro detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:43 AM,Medium,RealAV detected by Virus scanner,Quarantined,Resolved - No Action
2/8/2010 3:43 AM,High,Spyware.ChilyEMon detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:43 AM,Medium,007AntiSpyware detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:43 AM,High,Spyware.NSKeyLogger detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:43 AM,High,Spyware.SuperKeylogger detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:43 AM,Medium,SpyKillerPro detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:43 AM,Medium,Spyware.TinyKeylogger detected by Virus scanner,Quarantined,Resolved - No Action
2/8/2010 3:43 AM,High,SpyDeface detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:43 AM,Medium,LiveKill detected by Virus scanner,Quarantined,Resolved - No Action
2/8/2010 3:42 AM,High,Spyware.Sa_PCSpy detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:42 AM,High,Spyware.PCSpy detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:42 AM,High,Spyware.SolidKeyLogger detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:42 AM,Medium,PrivacyProtector detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:42 AM,Medium,3wPlayer detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:42 AM,Medium,SpyShield detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:42 AM,Medium,SpyReaper detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:42 AM,Medium,Spyware.ISnake detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:42 AM,Medium,VirusProtectPro detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:42 AM,Medium,SpywareIsolator detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:42 AM,Medium,VirusLocker detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:42 AM,Medium,Spyware.AllInOne detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:41 AM,Medium,Softstop detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:41 AM,High,Spyware.RedPill detected by Virus scanner,Quarantined,Resolved - No Action
2/8/2010 3:41 AM,High,Spyware.NeoSpy detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:41 AM,Medium,AgentSpyware detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:41 AM,Medium,AntiSpyZone detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:41 AM,Medium,MalwarePro detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:41 AM,Medium,AntiVermins detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:41 AM,Medium,WinXProtector detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:41 AM,Medium,SpyCrush detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:41 AM,Medium,PCClean detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:41 AM,Medium,Punisher detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:40 AM,Medium,SpyDawn detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:40 AM,High,Spyware.KeyProwler detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:40 AM,Medium,SpyDestroy detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:40 AM,Medium,SpyLocked detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:40 AM,Medium,ErrorSafe detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:40 AM,Medium,PcTurboPro detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:40 AM,Medium,1stAntiVirus detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:40 AM,Medium,WinAntiSpyware detected by Virus scanner,Quarantined,Resolved - No Action
2/8/2010 3:39 AM,Medium,RegSort detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:39 AM,Medium,AntiSpywareGuard detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:39 AM,Medium,SuperSpywareKiller detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:39 AM,Medium,Spyware.CyberSpy detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:37 AM,Medium,Fixiter detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:37 AM,Medium,Spyware.Redhanded detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:37 AM,Medium,Spyware.IMMonitor detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:37 AM,Medium,SpyKill detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:37 AM,Medium,Spyware.SmartKeylogger detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:37 AM,Medium,RazeSpyware detected by Virus scanner,Quarantined,Resolved - No Action
2/8/2010 3:37 AM,High,Spyware.Systemsurv detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:37 AM,Medium,VirusResponseLab detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,Cleaner2009 detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,SpyDevastator detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,EasySpywareKiller detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,TheRegistrySentinel detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,SpywareQuake detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,SpyHeal detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,AntiVirusGold detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,TraceSweeper detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,PCPrivacyCleaner detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,SpyLax detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,High,Spyware.EasyKeyLogger detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,IEDefender detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,PyroAntiSpy detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,High,Spyware.MSNChatSniffer detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:36 AM,Medium,RegistryDoctor2008 detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:35 AM,Medium,MySpyProtector detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:35 AM,Medium,VirusRemover2008 detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:35 AM,Medium,VirusBurst detected by Virus scanner,Removed,Resolved - No Action
2/8/2010 3:34 AM,Medium,WinDefender detected by Virus scanner,Quarantined,Resolved - No Action
2/7/2010 5:18 PM,Medium,SafeStrip detected by Virus scanner,Removed,Resolved - No Action
2/5/2010 11:15 PM,Medium,SafeStrip detected by Virus scanner,Removed,Resolved - No Action
---
NIS2010 removed all threats with a few quarantines and then asks to restart. During the reboot process after the WinXP splash screen the monitor goes dark and there is HDD access for about 1.5 minutes until the blue windows logon screen loads (as if new files are being written to the registry) and I am prompted to log in. Upon login and rescanning with NIS2010, the same 134 threats are detected again. After NIS cleans up the system, I am able to reboot into SafeMode and perform a NIS Fullscan (with limited feature in safemode) and see zero (0) threats. Subsequenly loading Windows normally results in the boot delay and re-installation of the Malware/SpyWare; again with 134 instances. So there is some service or startup item corrupted and set to install registry/files during boot.
When I got to work this morning, a colleague with a simliar Dell Latitude 6500 also reported having some problems. We looked at his NIS2010 and it also had 134 instances of Malware/Spyware with the same names and difficulties for removal. Interestingly, his first fullscan report of the problem was on 02/04 from last week (3 days before mine). A few other people on our small business network run NIS2010 but report no problems.
Suggestions? I am thinking clean-wipe and re-install... but I do not know what the initial problem was or the vector? Also I do not know what was taken/compromized? Passwords, files, etc. Given that there are 2 people on the same small business server with the problem, will it come back?
Help is appreciated!
Brian