Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I Have Been Seriously Infected


  • Please log in to reply
3 replies to this topic

#1 kindchin

kindchin

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:43 PM

Posted 15 August 2007 - 04:59 AM

Something has infected my computer...... wacko.gif
It has caused several programs to stop working and.... sad.gif
My computer has slowed down to almost a trickle.... ohmy.gif
System restore does not work, USB ports do not work, I have no audio.... w00t.gif
Everything that does work takes forever and a day to load.... mad.gif
Please help me! huh.gif
Thank you in advance! thumbup2.gif


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:59:01 AM, on 15/08/07
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.intergate.com/startpage/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {33331111-1131-1111-1111-611111193428} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{5EDB0822-3D9F-409B-931A-1B00AA835FBF}: NameServer = 216.70.16.10,216.70.0.2
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 5428 bytes

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:43 AM

Posted 15 August 2007 - 05:10 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum kindchin :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

Download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#3 kindchin

kindchin
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:43 PM

Posted 17 August 2007 - 01:50 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum kindchin :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

Download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.

Also post a new Hijackthis log please.



I sure hope I'm doing this right! Here's ComboFix:

ComboFix 07-08-16 - "Carolyn" 2007-08-17 1:41:25.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.169 [GMT -5:00]


((((((((((((((((((((((((( Files Created from 2007-07-17 to 2007-08-17 )))))))))))))))))))))))))))))))


2007-08-15 22:29 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-15 17:48 57,856 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-08-15 17:48 57,344 --a------ C:\WINDOWS\system32\wzcdlg.dll
2007-08-15 17:48 44,416 --a------ C:\WINDOWS\system32\drivers\stream.sys
2007-08-15 17:48 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-08-15 17:48 31,232 --a------ C:\WINDOWS\system32\wzcsapi.dll
2007-08-15 17:48 281,088 --a------ C:\WINDOWS\system32\wzcsvc.dll
2007-08-15 17:48 134,272 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2007-08-15 17:48 131,712 --a------ C:\WINDOWS\system32\drivers\ks.sys
2007-08-15 17:48 1,630,208 --a------ C:\WINDOWS\system32\netshell.dll
2007-08-15 15:03 <DIR> d-------- C:\Program Files\Japanese Blackjack
2007-08-14 03:30 50,176 --a------ C:\WINDOWS\system32\dpwsockx.dll
2007-08-14 03:30 214,528 --a--c--- C:\WINDOWS\system32\dllcache\dplayx.dll
2007-08-14 03:30 214,528 --a------ C:\WINDOWS\system32\dplayx.dll
2007-08-14 03:26 831,519 --a--c--- C:\WINDOWS\system32\dllcache\mswdat10.dll
2007-08-14 03:26 831,519 --a------ C:\WINDOWS\system32\mswdat10.dll
2007-08-14 03:26 614,431 --a--c--- C:\WINDOWS\system32\dllcache\mswstr10.dll
2007-08-14 03:26 614,431 --a------ C:\WINDOWS\system32\mswstr10.dll
2007-08-14 03:26 561,179 --a--c--- C:\WINDOWS\system32\dllcache\dao360.dll
2007-08-14 03:26 552,989 --a------ C:\WINDOWS\system32\msrepl40.dll
2007-08-14 03:26 552,989 -----c--- C:\WINDOWS\system32\dllcache\msrepl40.dll
2007-08-14 03:26 53,279 --a--c--- C:\WINDOWS\system32\dllcache\msjter40.dll
2007-08-14 03:26 53,279 --a------ C:\WINDOWS\system32\msjter40.dll
2007-08-14 03:26 512,029 --a------ C:\WINDOWS\system32\msexch40.dll
2007-08-14 03:26 512,029 -----c--- C:\WINDOWS\system32\dllcache\msexch40.dll
2007-08-14 03:26 421,919 --a------ C:\WINDOWS\system32\msrd2x40.dll
2007-08-14 03:26 421,919 -----c--- C:\WINDOWS\system32\dllcache\msrd2x40.dll
2007-08-14 03:26 380,957 --a------ C:\WINDOWS\system32\expsrv.dll
2007-08-14 03:26 380,957 -----c--- C:\WINDOWS\system32\dllcache\expsrv.dll
2007-08-14 03:26 358,976 --a------ C:\WINDOWS\system32\msjetoledb40.dll
2007-08-14 03:26 358,976 -----c--- C:\WINDOWS\system32\dllcache\msjetol1.dll
2007-08-14 03:26 348,189 --a------ C:\WINDOWS\system32\msxbde40.dll
2007-08-14 03:26 348,189 --a------ C:\WINDOWS\system32\mspbde40.dll
2007-08-14 03:26 348,189 -----c--- C:\WINDOWS\system32\dllcache\msxbde40.dll
2007-08-14 03:26 348,189 -----c--- C:\WINDOWS\system32\dllcache\mspbde40.dll
2007-08-14 03:26 32,256 --a--c--- C:\WINDOWS\system32\dllcache\msgsvc.dll
2007-08-14 03:26 32,256 --a------ C:\WINDOWS\system32\msgsvc.dll
2007-08-14 03:26 319,517 --a------ C:\WINDOWS\system32\msexcl40.dll
2007-08-14 03:26 319,517 -----c--- C:\WINDOWS\system32\dllcache\msexcl40.dll
2007-08-14 03:26 315,423 --a--c--- C:\WINDOWS\system32\dllcache\msrd3x40.dll
2007-08-14 03:26 315,423 --a------ C:\WINDOWS\system32\msrd3x40.dll
2007-08-14 03:26 30,749 --a--c--- C:\WINDOWS\system32\dllcache\vbajet32.dll
2007-08-14 03:26 30,749 --a------ C:\WINDOWS\system32\vbajet32.dll
2007-08-14 03:26 258,077 --a------ C:\WINDOWS\system32\mstext40.dll
2007-08-14 03:26 258,077 -----c--- C:\WINDOWS\system32\dllcache\mstext40.dll
2007-08-14 03:26 241,693 --a------ C:\WINDOWS\system32\msjtes40.dll
2007-08-14 03:26 241,693 -----c--- C:\WINDOWS\system32\dllcache\msjtes40.dll
2007-08-14 03:26 213,023 --a------ C:\WINDOWS\system32\msltus40.dll
2007-08-14 03:26 213,023 -----c--- C:\WINDOWS\system32\dllcache\msltus40.dll
2007-08-14 03:26 151,583 --a--c--- C:\WINDOWS\system32\dllcache\msjint40.dll
2007-08-14 03:26 151,583 --a------ C:\WINDOWS\system32\msjint40.dll
2007-08-14 03:26 1,507,356 --a------ C:\WINDOWS\system32\msjet40.dll
2007-08-14 03:26 1,507,356 -----c--- C:\WINDOWS\system32\dllcache\msjet40.dll
2007-08-13 12:08 260,096 --a------ C:\WINDOWS\system32\mstask.dll
2007-08-13 12:08 172,544 --a------ C:\WINDOWS\system32\schedsvc.dll
2007-08-13 12:08 10,752 --a------ C:\WINDOWS\system32\mstinit.exe
2007-08-12 00:04 593,408 --a--c--- C:\WINDOWS\system32\dllcache\h323msp.dll
2007-08-12 00:04 593,408 --a------ C:\WINDOWS\system32\h323msp.dll
2007-08-12 00:04 593,408 -----c--- C:\WINDOWS\system32\dllcache\xpsp2res.dll
2007-08-12 00:04 548,352 --a------ C:\WINDOWS\system32\rtcdll.dll
2007-08-12 00:04 439,808 --a------ C:\WINDOWS\system32\ipnathlp.dll
2007-08-12 00:04 40,960 --a--c--- C:\WINDOWS\system32\dllcache\evtgprov.dll
2007-08-11 18:49 971,264 --a------ C:\WINDOWS\system32\msgina.dll
2007-08-11 18:49 681,984 --------- C:\WINDOWS\system32\lsasrv.dll
2007-08-11 18:49 51,712 --a--c--- C:\WINDOWS\system32\dllcache\msasn1.dll
2007-08-11 18:49 51,712 --a------ C:\WINDOWS\system32\msasn1.dll
2007-08-11 18:49 136,704 --a------ C:\WINDOWS\system32\schannel.dll
2007-08-11 18:33 8,192 --a--c--- C:\WINDOWS\system32\dllcache\tsbyuv.dll
2007-08-11 18:33 8,192 --a------ C:\WINDOWS\system32\tsbyuv.dll
2007-08-11 18:33 49,664 --a--c--- C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2007-08-11 18:33 49,664 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-08-11 18:33 45,568 --a--c--- C:\WINDOWS\system32\dllcache\iyuv_32.dll
2007-08-11 18:33 45,568 --a------ C:\WINDOWS\system32\iyuv_32.dll
2007-08-11 18:33 44,416 --a--c--- C:\WINDOWS\system32\dllcache\stream.sys
2007-08-11 18:33 4,096 --a--c--- C:\WINDOWS\system32\dllcache\ksuser.dll
2007-08-11 18:33 131,712 --a--c--- C:\WINDOWS\system32\dllcache\ks.sys
2007-08-11 10:42 991,232 --a------ C:\WINDOWS\system32\esent.dll
2007-08-11 10:39 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-08-11 10:25 7,680 -----c--- C:\WINDOWS\system32\dllcache\bitsprx2.dll
2007-08-11 10:25 7,168 -----c--- C:\WINDOWS\system32\dllcache\bitsprx3.dll
2007-08-11 10:25 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-08-11 07:37 <DIR> d-------- C:\WINDOWS\Prefetch
2007-08-11 07:23 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-08-11 07:10 9,216 --a------ C:\WINDOWS\system32\wuauserv.dll
2007-08-11 07:10 86,016 --a------ C:\WINDOWS\system32\xactsrv.dll
2007-08-11 07:10 53,080 --a--c--- C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-08-11 07:10 53,080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-08-11 07:10 446,464 --a------ C:\WINDOWS\system32\wmvdmoe.dll
2007-08-11 07:10 38,912 --a------ C:\WINDOWS\system32\wsnmp32.dll
2007-08-11 07:10 311,327 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2007-08-11 07:10 296,448 --a------ C:\WINDOWS\system32\wmstream.dll
2007-08-11 07:10 247,808 --a------ C:\WINDOWS\system32\wow32.dll
2007-08-11 07:10 172,664 --a------ C:\WINDOWS\system32\xenroll.dll
2007-08-11 07:10 17,408 --a------ C:\WINDOWS\system32\wtsapi32.dll
2007-08-11 07:10 118,784 --a------ C:\WINDOWS\system32\wmsdmoe.dll
2007-08-11 07:10 1,710,936 --a--c--- C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-08-11 07:10 1,710,936 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-08-11 07:09 86,528 --a------ C:\WINDOWS\system32\wlnotify.dll
2007-08-11 07:09 77,824 --a------ C:\WINDOWS\system32\wmpstub.exe
2007-08-11 07:09 60,416 --a------ C:\WINDOWS\system32\wextract.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-15 17:41 29828 --a------ C:\WINDOWS\pchealth\HELPCTR\PackageStore\SkuStore.bin
2007-08-15 00:08 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-13 11:07 --------- d-------- C:\Program Files\Mightyfax
2007-08-11 07:45 --------- d--h----- C:\Program Files\WindowsUpdate
2007-08-11 07:23 --------- d-------- C:\Program Files\Movie Maker
2007-08-11 07:23 --------- d-------- C:\Program Files\Messenger
2007-08-11 06:17 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-11 05:40 8972 --a------ C:\WINDOWS\pchealth\HELPCTR\Config\Cntstore.bin
2007-08-11 04:09 --------- d-------- C:\Program Files\Online Services
2007-08-11 01:57 846132 --a--c--- C:\Program Files\run_en_21.exe
2007-08-11 01:57 69120 --ahs---- C:\Program Files\Thumbs.db
2007-08-09 02:49 1364 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-08-09 02:49 1316 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-08-07 07:24 --------- d-------- C:\Program Files\Windows NT
2007-08-06 11:36 --------- d-------- C:\Program Files\Common Files\ScanSoft Shared
2007-08-04 12:30 --------- d-------- C:\DOCUME~1\Carolyn\APPLIC~1\Uniblue
2007-07-19 02:38 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-07-19 02:38 8014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-07-13 19:10 --------- d-------- C:\Program Files\Common Files\xing shared
2007-07-13 19:10 --------- d-------- C:\Program Files\Common Files\Real
2007-06-29 14:49 --------- d-------- C:\Program Files\exPressit S.E. 2.2
2007-06-26 09:45 --------- d-------- C:\Program Files\MSXML 4.0
2007-06-23 00:05 --------- d-------- C:\Program Files\Screensavers
2007-06-18 13:52 --------- d-------- C:\Program Files\OLYMPUS
2007-06-17 21:19 --------- d-------- C:\Program Files\Avery Dennison
2007-06-12 06:45 29184 --a--c--- C:\WINDOWS\system32\sstunins.exe
2007-06-04 03:08 4 --a--c--- C:\WINDOWS\system32\proc1795523372.bin
2007-05-31 19:30 266088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2007-05-31 19:29 18280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
2007-02-06 07:33 13170312 --a--c--- C:\Program Files\jre-6-windows-i586.exe
2006-11-28 03:21 8704 --ahsc--- C:\Program Files\Common Files\Thumbs.db


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-03-03 12:44]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-05 20:22]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-06-12 13:19]
"Cmaudio"="cmicnfg.cpl" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSharedDocuments"=00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MightyFAX Controller.lnk]
backup=C:\WINDOWS\pss\MightyFAX Controller.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Handy Backup 5.6]
C:\Program Files\Novosoft\Handy Backup\hbagent.exe -logon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\I&F Viewer toolbar]
"C:\Program Files\Photo Toolkit\ivbar\phototoolkitmem.exe" -start

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Program Files\Ahead\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
"C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Omnipage]
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCRescue]
C:\Program Files\PCRescue4.0\PCR96\PCRescue.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pviever]
"C:\Program Files\Gay-Lesbian-Photo\Gay-Lesbian-Photo.exe" hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RAM Idle Professional]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
"C:\Program Files\Spyware Doctor\SDTrayApp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
"C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

R0 BsStor;InCD Storage Helper Driver;C:\WINDOWS\System32\DRIVERS\bsstor.sys
R2 BsUDF;InCD UDF Driver;C:\WINDOWS\System32\drivers\BsUDF.sys
R2 IOPort;IOPort;\??\C:\WINDOWS\System32\DRIVERS\IOPORT.SYS
R2 MSMQ;Message Queuing;C:\WINDOWS\System32\mqsvc.exe
R2 MSMQTriggers;Message Queuing Triggers;C:\WINDOWS\System32\mqtgsvc.exe
R2 nvcap;nVidia WDM Video Capture (universal);C:\WINDOWS\System32\DRIVERS\nvcap.sys
R2 nvTUNEP;nVidia WDM TVTuner;C:\WINDOWS\System32\DRIVERS\nvtunep.sys
R2 nvtvSND;nVidia WDM TVAudio Crossbar;C:\WINDOWS\System32\DRIVERS\nvtvsnd.sys
R2 NVXBAR;nVidia WDM A/V Crossbar;C:\WINDOWS\System32\DRIVERS\NVxbar.sys
R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\System32\inetsrv\inetinfo.exe
R3 IntelS51;Intel® 536EP Modem;C:\WINDOWS\System32\DRIVERS\IntelS51.sys
R3 MQAC;Message Queuing access control;\??\C:\WINDOWS\System32\drivers\mqac.sys
R3 RMCAST;Reliable Multicast Protocol driver;\??\C:\WINDOWS\System32\drivers\RMCast.sys
R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\System32\DRIVERS\usbprint.sys
S2 ousbehci;NEC PCI to USB Enhanced Host Controller;C:\WINDOWS\System32\Drivers\ousbehci.sys
S3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\System32\drivers\av5flt.sys
S3 GMSIPCI;GMSIPCI;\??\D:\INSTALL\GMSIPCI.SYS
S3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;C:\WINDOWS\System32\DRIVERS\ousb2hub.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6bfb8b12-e597-11db-84cd-806d6172696f}]
AutoRun\command- D:\setup.exe


Contents of the 'Scheduled Tasks' folder
2007-08-11 22:28:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-08-17 06:04:09 C:\WINDOWS\Tasks\MP Scheduled Scan.job
2007-08-04 04:03:53 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Carolyn.job - C:\PROGRA~1\NORTON~1\Navw32.exe
2007-07-20 20:31:07 C:\WINDOWS\Tasks\Norton Security Scan.job - C:\Program Files\Norton Security Scan\Nss.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-17 01:43:37
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-17 1:45:31
C:\ComboFix-quarantined-files.txt ... 2007-08-17 01:45
C:\ComboFix2.txt ... 2007-08-16 13:43
C:\ComboFix3.txt ... 2007-08-16 00:41

--- E O F ---

Here's HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:46:07 AM, on 17/08/07
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...html?p=ZNfox000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {33331111-1131-1111-1111-611111193428} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{5EDB0822-3D9F-409B-931A-1B00AA835FBF}: NameServer = 216.70.16.10,216.70.0.2
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 5339 bytes

I look forward to hearing from you. Thank you!

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:43 AM

Posted 17 August 2007 - 04:09 AM

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...html?p=ZNfox000
O16 - DPF: {33331111-1131-1111-1111-611111193428} -

Exit Hijackthis.

Start SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.

Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users