Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
![]() ![]() |
Jan 6 2009, 02:07 AM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 7 Joined: 5-January 09 Member No.: 278,497 |
It kept popping up in Malwarebytes scans, until two of the files were left which the program said that it would get rid of them upon restart. I restarted into safe mode, did a few quick Malwarebytes scan, then a Spybot-Search and Destroy. The Malwarebytes scan came up with nothing, and Spybot found something, and fixed it. I then restarted. After multiple scans of Malwarebytes (many quick scans and a full one) and Spybot-Search and Destroy, and a full AVG, I've come up with nothing. But, I'm still paranoid about this, as it's my first major run-in with a trojan. So it would be great if someone could look at my logs and see if I'm as clean as my scans say I am. Here is my DDS log and attached log. DDS (Version 1.1.0) - NTFSx86 Run by Owner at 23:01:53.40 on Mon 01/05/2009 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_07 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2047.1103 [GMT -8:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\CyberLink\PowerCinema\PCMService.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Razer\DeathAdder\razerhid.exe C:\Program Files\Microsoft LifeChat\LifeChat.exe C:\Program Files\Saitek\SD6\Software\ProfilerU.exe C:\Program Files\Saitek\SD6\Software\SaiMfd.exe C:\Program Files\Saitek\SD6\Software\SaiVolume.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe C:\Program Files\Cyberlink\Shared Files\brs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AIM\aim.exe C:\Program Files\Razer\DeathAdder\razertra.exe C:\Program Files\Razer\DeathAdder\razerofa.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\MSI\Common\RaUI.exe C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe C:\Program Files\Netropa\Onscreen Display\OSD.exe C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Ventrilo\Ventrilo.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe C:\Program Files\TortoiseSVN\bin\TSVNCache.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Steam\Steam.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\AVG\AVG8\avgui.exe C:\Documents and Settings\Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.talti.com uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [AIM] c:\program files\aim\aim.exe -cnetwait.odl uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background uRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033 uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [PCMService] "c:\program files\cyberlink\powercinema\PCMService.exe" mRun: [NWEReboot] mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [MULTIMEDIA KEYBOARD] c:\program files\netropa\multimedia keyboard\MMKeybd.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [DeathAdder] c:\program files\razer\deathadder\razerhid.exe mRun: [LifeChat] "c:\program files\microsoft lifechat\LifeChat.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [ProfilerU] c:\program files\saitek\sd6\software\ProfilerU.exe mRun: [SaiMfd] c:\program files\saitek\sd6\software\SaiMfd.exe mRun: [SaiVolume] c:\program files\saitek\sd6\software\SaiVolume.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [basicsmssmenu] "c:\program files\seagate\basics\basics status\MaxMenuMgrBasics.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [RemoteControl8] "c:\program files\cyberlink\powerdvd8\PDVD8Serv.exe" mRun: [PDVD8LanguageShortcut] "c:\program files\cyberlink\powerdvd8\language\Language.exe" mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\docume~1\owner\startm~1\programs\startup\gamesp~1.lnk - c:\program files\gamespot\GameSpotDownloadManager_Win32.exe StartupFolder: c:\docume~1\owner\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\msiwir~1.lnk - c:\program files\msi\common\RaUI.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Save Flash - c:\program files\unh solutions\flash saving plugin\FlashSButton.dll/210 IE: Sothink SWF Catcher - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: awtqnmLf - awtqnmLf.dll AppInit_DLLs: avgrsstx.dll,c:\windows\system32\nusumidi.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL LSA: Notification Packages = scecli c:\windows\system32\nusumidi.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\f97884yg.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-7-3 97928] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-8-30 26824] R1 msikbd2k;Multimedia Keyboard Filter Driver;c:\windows\system32\drivers\Msikbd2k.sys [2007-7-31 6656] R3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2007-8-9 22144] R3 SaiH0728;SaiH0728;c:\windows\system32\drivers\SaiH0728.sys [2008-5-26 136448] R4 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\cyberlink\powerdvd8\000.fcl [2008-5-15 61424] R4 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-3 231704] R4 nhksrv;Netropa NHK Server;c:\program files\netropa\multimedia keyboard\nhksrv.exe [2007-7-31 28672] S0 ojzvb;ojzvb;c:\windows\system32\drivers\rjqb.sys --> c:\windows\system32\drivers\rjqb.sys [?] S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2008-5-19 16512] S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;c:\windows\system32\drivers\libusb0.sys [2008-12-7 29184] S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?] S4 aawservice;Ad-Aware 2007 Service;c:\program files\lavasoft\ad-aware 2007\aawservice.exe [2007-7-6 574808] =============== Created Last 30 ================ ==================== Find3M ==================== 2008-11-24 17:58 22,328 a------- c:\windows\system32\drivers\PnkBstrK.sys 2008-11-24 17:58 22,328 a------- c:\docume~1\owner\applic~1\PnkBstrK.sys 2008-11-24 17:58 107,832 a------- c:\windows\system32\PnkBstrB.exe 2008-11-24 17:58 2,246,144 a------- c:\windows\system32\pbsvc.exe 2008-11-24 17:49 66,872 a------- c:\windows\system32\PnkBstrA.exe 2008-10-23 05:01 283,648 a------- c:\windows\system32\gdi32.dll 2008-10-16 02:37 659,456 a------- c:\windows\system32\wininet.dll 2008-10-15 20:11 60,416 a------- c:\windows\ALCFDRTM.EXE 2008-10-14 09:00 505,128 a------- c:\windows\system32\msvcp71.dll 2007-10-12 23:35 5,760 a------- c:\program files\install.log ============= FINISH: 23:02:33.23 ===============
Attached File(s)
|
|
|
|
Jan 13 2009, 03:47 PM
Post
#2
|
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 6,883 Joined: 10-March 08 Member No.: 195,473 |
Hello. I am PropagandaPanda (Panda or PP for short), and I will be helping you with your log.
I apologize for the delay in response. We get overwhelmed with logs at times, but we are trying our best to keep up. If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following so I can have a look at the current condition of your machine. You may want to keep the link to this topic in your favourites. Alternatively, you can click the button at the top bar of this topic and Track this Topic, where you can choose email notifications. The topics you are tracking are shown here.Download and Run DDS If you already have a copy of DDS, there is not need to download a new one. Download DDS by sUBs from any of the links below: DDS.com, DDS.scr, DDS.pif Double click its icon to run it. If you are using Windows Vista, right click it and select "Run as Administrator". When the scan is finished, two logs will open. Post DDS.txt directly into your reply. Attach Attach.txt. Download and Run Scan with GMER We will use GMER to scan for rootkits. Please download GMER.zip to your desktop from any of the links below: LINK1, LINK2
Please tell me what changes have been made to the computer since your topic was started. Also give me an update on any symptoms. With Regards, The Panda -------------------- |
|
|
|
Jan 13 2009, 08:13 PM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 7 Joined: 5-January 09 Member No.: 278,497 |
No problem about the wait, and thanks for the help. I just want to make sure that this thing is gone.
Since my last thread, I did a lot more scans with various anti-virus/malware/spyware programs to make sure that I was still clean, and every day or so did some quick scans with Malwarebytes. With no problems showing up, I started using my computer again for normal activities (downloading things, games, music, etc) The only symptom I've had so far has been lag spikes in a game, but that could just be my internet acting up. Here's the updated DDS log ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\TortoiseSVN\bin\TSVNCache.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Razer\DeathAdder\razerhid.exe C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe C:\Program Files\Microsoft LifeChat\LifeChat.exe C:\Program Files\Netropa\Onscreen Display\OSD.exe C:\Program Files\Saitek\SD6\Software\ProfilerU.exe C:\Program Files\Saitek\SD6\Software\SaiMfd.exe C:\Program Files\Saitek\SD6\Software\SaiVolume.exe C:\Program Files\Razer\DeathAdder\razertra.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Razer\DeathAdder\razerofa.exe C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe C:\Program Files\Cyberlink\Shared Files\brs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\MSI\Common\RaUI.exe C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Ventrilo\Ventrilo.exe C:\Program Files\Steam\Steam.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\AIM\aim.exe C:\Documents and Settings\Owner\Desktop\Desktop\Utorrent\utorrent.exe C:\Documents and Settings\Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.talti.com uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [AIM] c:\program files\aim\aim.exe -cnetwait.odl uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background uRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033 uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [PCMService] "c:\program files\cyberlink\powercinema\PCMService.exe" mRun: [NWEReboot] mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [MULTIMEDIA KEYBOARD] c:\program files\netropa\multimedia keyboard\MMKeybd.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [DeathAdder] c:\program files\razer\deathadder\razerhid.exe mRun: [LifeChat] "c:\program files\microsoft lifechat\LifeChat.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [ProfilerU] c:\program files\saitek\sd6\software\ProfilerU.exe mRun: [SaiMfd] c:\program files\saitek\sd6\software\SaiMfd.exe mRun: [SaiVolume] c:\program files\saitek\sd6\software\SaiVolume.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [basicsmssmenu] "c:\program files\seagate\basics\basics status\MaxMenuMgrBasics.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [RemoteControl8] "c:\program files\cyberlink\powerdvd8\PDVD8Serv.exe" mRun: [PDVD8LanguageShortcut] "c:\program files\cyberlink\powerdvd8\language\Language.exe" mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe StartupFolder: c:\docume~1\owner\startm~1\programs\startup\gamesp~1.lnk - c:\program files\gamespot\GameSpotDownloadManager_Win32.exe StartupFolder: c:\docume~1\owner\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\msiwir~1.lnk - c:\program files\msi\common\RaUI.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Save Flash - c:\program files\unh solutions\flash saving plugin\FlashSButton.dll/210 IE: Sothink SWF Catcher - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: awtqnmLf - awtqnmLf.dll AppInit_DLLs: avgrsstx.dll,c:\windows\system32\nusumidi.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL LSA: Notification Packages = scecli c:\windows\system32\nusumidi.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\f97884yg.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-7-3 97928] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-8-30 26824] R1 msikbd2k;Multimedia Keyboard Filter Driver;c:\windows\system32\drivers\Msikbd2k.sys [2007-7-31 6656] R3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2007-8-9 22144] R3 SaiH0728;SaiH0728;c:\windows\system32\drivers\SaiH0728.sys [2008-5-26 136448] R4 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\cyberlink\powerdvd8\000.fcl [2008-5-15 61424] R4 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-3 231704] R4 nhksrv;Netropa NHK Server;c:\program files\netropa\multimedia keyboard\nhksrv.exe [2007-7-31 28672] S0 ojzvb;ojzvb;c:\windows\system32\drivers\rjqb.sys --> c:\windows\system32\drivers\rjqb.sys [?] S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2008-5-19 16512] S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;c:\windows\system32\drivers\libusb0.sys [2008-12-7 29184] S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?] =============== Created Last 30 ================ 2009-01-12 22:47 <DIR> --d----- c:\program files\MetaGeek 2009-01-06 15:24 410,984 a------- c:\windows\system32\deploytk.dll 2009-01-04 17:02 <DIR> --d----- c:\docume~1\owner\applic~1\Auslogics 2009-01-04 17:02 <DIR> --d----- c:\program files\Auslogics 2009-01-04 15:29 664 a------- c:\windows\system32\d3d9caps.dat 2009-01-04 14:23 <DIR> --d----- c:\program files\Trend Micro 2009-01-04 14:01 <DIR> --d----- c:\program files\TeaTimer (Spybot - Search & Destroy) 2009-01-04 14:01 <DIR> --d----- c:\program files\Misc. Support Library (Spybot - Search & Destroy) 2009-01-04 14:01 <DIR> --d----- c:\program files\SDHelper (Spybot - Search & Destroy) 2009-01-04 14:01 <DIR> --d----- c:\program files\File Scanner Library (Spybot - Search & Destroy) 2009-01-04 02:00 <DIR> --d----- c:\program files\Audacity 2009-01-03 17:21 <DIR> --d----- c:\docume~1\owner\applic~1\Malwarebytes 2009-01-03 17:20 15,504 a------- c:\windows\system32\drivers\mbam.sys 2009-01-03 17:20 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-03 17:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-01-03 17:20 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware 2008-12-26 12:08 159,232 a------- c:\windows\system32\ptpusd.dll 2008-12-26 12:08 5,632 a------- c:\windows\system32\ptpusb.dll 2008-12-26 12:08 15,104 a------- c:\windows\system32\drivers\usbscan.sys ==================== Find3M ==================== 2008-11-24 17:58 22,328 a------- c:\windows\system32\drivers\PnkBstrK.sys 2008-11-24 17:58 22,328 a------- c:\docume~1\owner\applic~1\PnkBstrK.sys 2008-11-24 17:58 107,832 a------- c:\windows\system32\PnkBstrB.exe 2008-11-24 17:58 2,246,144 a------- c:\windows\system32\pbsvc.exe 2008-11-24 17:49 66,872 a------- c:\windows\system32\PnkBstrA.exe 2008-10-23 05:01 283,648 a------- c:\windows\system32\gdi32.dll 2008-10-16 02:37 659,456 a------- c:\windows\system32\wininet.dll 2008-10-15 20:11 60,416 a------- c:\windows\ALCFDRTM.EXE 2007-10-12 23:35 5,760 a------- c:\program files\install.log ============= FINISH: 19:40:55.68 =============== And here's the GMER log GMER 1.0.14.14536 - http://www.gmer.net Rootkit scan 2009-01-13 20:12:05 Windows 5.1.2600 Service Pack 2 ---- System - GMER 1.0.14 ---- SSDT sptd.sys ZwCreateKey [0xBA6BE0D0] SSDT sptd.sys ZwEnumerateKey [0xBA6C3FB2] SSDT sptd.sys ZwEnumerateValueKey [0xBA6C4340] SSDT sptd.sys ZwOpenKey [0xBA6BE0B0] SSDT sptd.sys ZwQueryKey [0xBA6C4418] SSDT sptd.sys ZwQueryValueKey [0xBA6C4298] SSDT sptd.sys ZwSetValueKey [0xBA6C44AA] ---- Kernel code sections - GMER 1.0.14 ---- ? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process. .text USBPORT.SYS!DllUnload B923562C 5 Bytes JMP 89B822D8 ? System32\Drivers\a9udu6n4.SYS The system cannot find the file specified. ! ---- User code sections - GMER 1.0.14 ---- .text C:\Program Files\MSN Messenger\MsnMsgr.Exe[2384] kernel32.dll!SetUnhandledExceptionFilter 7C84467D 5 Bytes JMP 004DE392 C:\Program Files\MSN Messenger\MsnMsgr.Exe (Messenger/Microsoft Corporation) ---- Kernel IAT/EAT - GMER 1.0.14 ---- IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [BA6BEAD4] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [BA6BEC1A] sptd.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [BA6BEB9C] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [BA6BF748] sptd.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [BA6BF61E] sptd.sys ---- Devices - GMER 1.0.14 ---- Device \FileSystem\Ntfs \Ntfs 89D561E8 Device \FileSystem\Fastfat \FatCdrom 8907B1E8 Device \Driver\usbohci \Device\USBPDO-0 89B8B5A8 Device \Driver\usbehci \Device\USBPDO-1 89BAC580 Device \Driver\NetBT \Device\NetBT_Tcpip_{E6D3B222-AE4A-41F3-9FC4-128E7482BB04} 8909F790 Device \Driver\PCI_NTPNP2656 \Device\00000047 sptd.sys Device \Driver\NetBT \Device\NetBT_Tcpip_{BFBE4A0D-23C8-4162-B22A-E1EEBFDD16A8} 8909F790 Device \Driver\Ftdisk \Device\HarddiskVolume1 89D581E8 Device \Driver\Cdrom \Device\CdRom0 89BA1790 Device \Driver\Ftdisk \Device\HarddiskVolume3 89D581E8 Device \Driver\Cdrom \Device\CdRom1 89BA1790 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 89DC81E8 Device \Driver\atapi \Device\Ide\IdePort0 89DC81E8 Device \Driver\atapi \Device\Ide\IdePort1 89DC81E8 Device \Driver\nvata \Device\00000068 89D571E8 Device \Driver\USBSTOR \Device\00000081 8857E1E8 Device \Driver\USBSTOR \Device\00000082 8857E1E8 Device \Driver\USBSTOR \Device\00000083 8857E1E8 Device \Driver\NetBT \Device\NetBt_Wins_Export 8909F790 Device \Driver\USBSTOR \Device\00000084 8857E1E8 Device \Driver\NetBT \Device\NetbiosSmb 8909F790 Device \Driver\usbohci \Device\USBFDO-0 89B8B5A8 Device \Driver\nvata \Device\NvAta0 89D571E8 Device \Driver\usbehci \Device\USBFDO-1 89BAC580 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 890761E8 Device \Driver\nvata \Device\NvAta1 89D571E8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 890761E8 Device \Driver\Ftdisk \Device\FtControl 89D581E8 Device \Driver\a9udu6n4 \Device\Scsi\a9udu6n41Port4Path0Target0Lun0 89B391E8 Device \Driver\a9udu6n4 \Device\Scsi\a9udu6n41 89B391E8 Device \FileSystem\Fastfat \Fat 8907B1E8 AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) Device \FileSystem\Cdfs \Cdfs 890201E8 ---- Registry - GMER 1.0.14 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xD1 0x5B 0xF3 0x89 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x5B 0x38 0xC4 0xFD ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x21 0x82 0x77 0x58 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xD1 0x5B 0xF3 0x89 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x5B 0x38 0xC4 0xFD ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x21 0x82 0x77 0x58 ... ---- EOF - GMER 1.0.14 ----
Attached File(s)
|
|
|
|
Jan 13 2009, 08:46 PM
Post
#4
|
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 6,883 Joined: 10-March 08 Member No.: 195,473 |
Hello.
Looks like the infection was taken care of. I see some leftovers. Let's remove those. Disable Realtime Protection Antimalware programs can interfere with the tools we need to run. Please temporarily disable all realtime protections you have enabled. Refer to this page, if you are unsure how. To disable AVG:
To disable SpyBot's TeaTimer: You can find instructions with visuals here.
Install ERUNT This tool will create a complete backup of your registry. After every reboot, a new backup is created to ensure we have a safety net after each step. Do not delete these backups until we are finished.
http://www.larshederer.homepage.t-online.de/erunt/erunt.txt When we are finished with fixing your computer (I will make it clear when we are), you can uninstall ERUNT through Add/Remove Programs. The backups will be stored at C:\WINDOWS\erdnt, and will not be deleted when ERUNT is uninstalled. Download and Run OTMoveIT
F-Secure Online Scan Please run F-Secure Online Scanner. This scan is for Internet Explorer only.
Please post back with: -the OTMoveIt log -the F-Secure scan log -a new DDS log (just DDS.txt is fine) With Regards, The Panda -------------------- |
|
|
|
Jan 13 2009, 10:34 PM
Post
#5
|
|
|
New Member ![]() Group: Members Posts: 7 Joined: 5-January 09 Member No.: 278,497 |
Thanks again for the help, and I'm glad to hear that the main infection is gone.
The F-Secure scanner wasn't working too well for me. I tried a few times and it would get hung up about 1400 files into the scan. I still post the other two logs. Here is the OTMoveIt log ========== SERVICES/DRIVERS ========== Service ojzvb stopped successfully. Service ojzvb deleted successfully. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqnmLf\\ deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLs"|"avgrsstx.dll" /E : value set successfully! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\"Notification Packages"|hex(7):"scecli" /E : value set successfully! ========== FILES ========== File/Folder c:\windows\system32\nusumidi.dll not found. File/Folder c:\windows\system32\drivers\rjqb.sys not found. File/Folder c:\windows\system32\awtqnmLf.dll not found. ========== COMMANDS ========== OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01132009_215346 And the DDS log DDS (Version 1.1.0) - NTFSx86 Run by Owner at 22:33:35.23 on Tue 01/13/2009 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_11 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2047.1402 [GMT -8:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\TortoiseSVN\bin\TSVNCache.exe C:\Program Files\CyberLink\PowerCinema\PCMService.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Razer\DeathAdder\razerhid.exe C:\Program Files\Microsoft LifeChat\LifeChat.exe C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe C:\Program Files\Netropa\Onscreen Display\OSD.exe C:\Program Files\Saitek\SD6\Software\ProfilerU.exe C:\Program Files\Razer\DeathAdder\razertra.exe C:\Program Files\Saitek\SD6\Software\SaiMfd.exe C:\Program Files\Razer\DeathAdder\razerofa.exe C:\Program Files\Saitek\SD6\Software\SaiVolume.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe C:\Program Files\Cyberlink\Shared Files\brs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AIM\aim.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\MSI\Common\RaUI.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\AVG\AVG8\avgui.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Documents and Settings\Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.talti.com uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [AIM] c:\program files\aim\aim.exe -cnetwait.odl uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background uRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033 mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [PCMService] "c:\program files\cyberlink\powercinema\PCMService.exe" mRun: [NWEReboot] mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [MULTIMEDIA KEYBOARD] c:\program files\netropa\multimedia keyboard\MMKeybd.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [DeathAdder] c:\program files\razer\deathadder\razerhid.exe mRun: [LifeChat] "c:\program files\microsoft lifechat\LifeChat.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [ProfilerU] c:\program files\saitek\sd6\software\ProfilerU.exe mRun: [SaiMfd] c:\program files\saitek\sd6\software\SaiMfd.exe mRun: [SaiVolume] c:\program files\saitek\sd6\software\SaiVolume.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [basicsmssmenu] "c:\program files\seagate\basics\basics status\MaxMenuMgrBasics.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [RemoteControl8] "c:\program files\cyberlink\powerdvd8\PDVD8Serv.exe" mRun: [PDVD8LanguageShortcut] "c:\program files\cyberlink\powerdvd8\language\Language.exe" mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe StartupFolder: c:\docume~1\owner\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\owner\startm~1\programs\startup\gamesp~1.lnk - c:\program files\gamespot\GameSpotDownloadManager_Win32.exe StartupFolder: c:\docume~1\owner\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\msiwir~1.lnk - c:\program files\msi\common\RaUI.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Save Flash - c:\program files\unh solutions\flash saving plugin\FlashSButton.dll/210 IE: Sothink SWF Catcher - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll AppInit_DLLs: avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\f97884yg.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-7-3 97928] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-8-30 26824] R1 msikbd2k;Multimedia Keyboard Filter Driver;c:\windows\system32\drivers\Msikbd2k.sys [2007-7-31 6656] R3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2007-8-9 22144] R3 SaiH0728;SaiH0728;c:\windows\system32\drivers\SaiH0728.sys [2008-5-26 136448] R4 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\cyberlink\powerdvd8\000.fcl [2008-5-15 61424] R4 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-3 231704] R4 nhksrv;Netropa NHK Server;c:\program files\netropa\multimedia keyboard\nhksrv.exe [2007-7-31 28672] S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2008-5-19 16512] S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;c:\windows\system32\drivers\libusb0.sys [2008-12-7 29184] S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?] =============== Created Last 30 ================ 2009-01-13 22:05 <DIR> --d----- C:\fsaua.data 2009-01-13 21:53 <DIR> --d----- C:\_OTMoveIt 2009-01-13 19:43 250 a------- c:\windows\gmer.ini 2009-01-12 22:47 <DIR> --d----- c:\program files\MetaGeek 2009-01-06 15:24 410,984 a------- c:\windows\system32\deploytk.dll 2009-01-04 17:02 <DIR> --d----- c:\docume~1\owner\applic~1\Auslogics 2009-01-04 17:02 <DIR> --d----- c:\program files\Auslogics 2009-01-04 15:29 664 a------- c:\windows\system32\d3d9caps.dat 2009-01-04 14:23 <DIR> --d----- c:\program files\Trend Micro 2009-01-04 14:01 <DIR> --d----- c:\program files\TeaTimer (Spybot - Search & Destroy) 2009-01-04 14:01 <DIR> --d----- c:\program files\Misc. Support Library (Spybot - Search & Destroy) 2009-01-04 14:01 <DIR> --d----- c:\program files\SDHelper (Spybot - Search & Destroy) 2009-01-04 14:01 <DIR> --d----- c:\program files\File Scanner Library (Spybot - Search & Destroy) 2009-01-04 02:00 <DIR> --d----- c:\program files\Audacity 2009-01-03 17:21 <DIR> --d----- c:\docume~1\owner\applic~1\Malwarebytes 2009-01-03 17:20 15,504 a------- c:\windows\system32\drivers\mbam.sys 2009-01-03 17:20 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-01-03 17:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-01-03 17:20 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware 2008-12-26 12:08 159,232 a------- c:\windows\system32\ptpusd.dll 2008-12-26 12:08 5,632 a------- c:\windows\system32\ptpusb.dll 2008-12-26 12:08 15,104 a------- c:\windows\system32\drivers\usbscan.sys ==================== Find3M ==================== 2008-11-24 17:58 22,328 a------- c:\windows\system32\drivers\PnkBstrK.sys 2008-11-24 17:58 22,328 a------- c:\docume~1\owner\applic~1\PnkBstrK.sys 2008-11-24 17:58 107,832 a------- c:\windows\system32\PnkBstrB.exe 2008-11-24 17:58 2,246,144 a------- c:\windows\system32\pbsvc.exe 2008-11-24 17:49 66,872 a------- c:\windows\system32\PnkBstrA.exe 2008-10-23 05:01 283,648 a------- c:\windows\system32\gdi32.dll 2008-10-16 02:37 659,456 a------- c:\windows\system32\wininet.dll 2007-10-12 23:35 5,760 a------- c:\program files\install.log ============= FINISH: 22:34:13.43 =============== |
|
|
|
Jan 14 2009, 08:13 AM
Post
#6
|
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 6,883 Joined: 10-March 08 Member No.: 195,473 |
Hello.
QUOTE The F-Secure scanner wasn't working too well for me. I tried a few times and it would get hung up about 1400 files into the scan. No problem.Looks clean. Unless you have any problems, we can wrap up. Run Cleanup! with OTMoveIt Let's clear out the tools we've used.
Set New System Restore Point Now you should set a Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, tools cannot access it to delete these bad files, which sometimes can reinfect your system. Setting a new restore point after cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state. The easiest and safest way to do this is:
Please take some time to look at the following links, giving some advice and suggestions for preventing future infections: For general slowness problems that you may have, take a look at Slow Computer/browser? It May Not Be Malware. Read How to use the Startup Database to identify and disable uneeded processes and increase the amount of available resources. Do you have any further questions or concerns? With Regards, The Panda -------------------- |
|
|
|
Jan 14 2009, 08:46 AM
Post
#7
|
|
|
New Member ![]() Group: Members Posts: 7 Joined: 5-January 09 Member No.: 278,497 |
All right, I used the CleanUp!, made the new restore point, and deleted all the old ones.
Is there anything else you'd like me to do? |
|
|
|
Jan 14 2009, 12:04 PM
Post
#8
|
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 6,883 Joined: 10-March 08 Member No.: 195,473 |
That's it
The Panda -------------------- |
|
|
|
Jan 14 2009, 12:18 PM
Post
#9
|
|
|
New Member ![]() Group: Members Posts: 7 Joined: 5-January 09 Member No.: 278,497 |
Thanks a lot! If anything like this ever happens again (and I sure hope it won't) I'll know where to come for help :D
And I'm ok to uninstall ERUNT now, right? |
|
|
|
Jan 14 2009, 12:19 PM
Post
#10
|
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 6,883 Joined: 10-March 08 Member No.: 195,473 |
Yes, you can uninstall ERUNT (sorry forgot about that).
You should remove all the backups that ERUNT has made. Those backups may contain old registry keys, possibly those created by malware. Delete everything under: C:\WINDOWS\erdnt\ ERUNT will automatically remove backups older than 30 days, so there is no need to clear that folder manually in the future. It is a good idea to have ERUNT installed, even when you are not infected. Tasks like installing programs and changing settings, which involve working with the registry, can cause problems that can be quickly undone by reverting to a backup. However, if you wish to uninstall the program, do so using Add/Remove Programs. With Regards, The Panda -------------------- |
|
|
|
Jan 14 2009, 12:56 PM
Post
#11
|
|
|
New Member ![]() Group: Members Posts: 7 Joined: 5-January 09 Member No.: 278,497 |
All right then, I'll keep it installed. I deleted the folder, too.
Thanks again, I really appreciate it. I can stop being so paranoid now :D |
|
|
|
Jan 14 2009, 03:14 PM
Post
#12
|
|
![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 6,883 Joined: 10-March 08 Member No.: 195,473 |
Glad I could help
Since this issue appears to be resolved, this topic is now closed. If you are the topic starter and need this topic reopened, send me a message. Everyone else, please begin a new topic. With Regards, The Panda -------------------- |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 8th November 2009 - 07:35 AM |