Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Mal-ware?


  • Please log in to reply
10 replies to this topic

#1 mgeorgevich

mgeorgevich

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:02:25 PM

Posted 16 August 2007 - 08:02 PM

Oleae help. Every tim I try to use Ad-Aware and start to scan, the PC , using XP, reboots itself. Attached is the HJT log:

BC AdBot (Login to Remove)

 


m

#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:25 PM

Posted 17 August 2007 - 05:43 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum mgeorgevich :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

Download SDFix.exe and save it to your desktop:
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

* Double click on SDFix on your desktop,and install the fix to C:\

Please then reboot your computer into Safe Mode by doing the following:

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.

* In Safe Mode,go to and open the C:\SDFix folder,then double click on RunThis.bat to start the script.
* Type Y to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt into your next reply.


Download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.

Also post a new Hijackthis log please.

*Note*
Post all reports/logs directly into this topic,not as attachments,thanks.
Posted Image
Posted Image

#3 mgeorgevich

mgeorgevich
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:02:25 PM

Posted 17 August 2007 - 12:02 PM

Thank you Richie, I will do as you say and repost, not as an attachment.

Mark

#4 mgeorgevich

mgeorgevich
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:02:25 PM

Posted 17 August 2007 - 03:49 PM

Richie,

Here is the results: First is SD Fix, second is Combofix and last is HiJack this. Can you tell me what is the best prventtive spyware blocker? I would like to tell this customer what to use. He has Norton Anti-Virus 2004, but I don't know if it is up-to-date.



SDFix: Version 1.98

Run by Administrator on Fri 08/17/2007 at 04:00 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
Client IP-IPX
DomainService

ImagePath:
"" -e mc-110-12-0000478
C:\WINDOWS\system32\hysrnmbo.exe /service

Client IP-IPX - Deleted
DomainService - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\system32\b02FdUe\b02FdUe1065.exe - Deleted
C:\WINDOWS\wr.txt - Deleted


Folder C:\WINDOWS\system32\b02FdUe - Removed

Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\system32\\LEXPPS.EXE:*:Enabled:LEXPPS.EXE"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\WINDOWS\\system32\\hysrnmbo.exe"="C:\\WINDOWS\\system32\\hys"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files:
---------------

Backups Folder: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

C:\Documents and Settings\Owner\My Documents\?racle\?canregw.exe
C:\Documents and Settings\THE BOSSES\Local Settings\Temp\ebajrmor.exe
C:\Documents and Settings\THE BOSSES\Local Settings\Temp\utgmvexa.exe
C:\Documents and Settings\THE BOSSES\Local Settings\Temp\wxdbgxkc.exe
C:\Program Files\America Online 9.0\aolphx.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\America Online 9.0\RBM.exe

Finished



ComboFix 07-08-17.2 - "THE BOSSES" 2007-08-17 16:33:09.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.51 [GMT -4:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Owner\APPLIC~1\SpamBlocker
C:\DOCUME~1\Owner\APPLIC~1\SpamBlocker\{DC140E8F-0390-44A6-90AA-2F659E41083F}.dat
C:\DOCUME~1\Owner\APPLIC~1\SpamBlockerUtility_Icons
C:\DOCUME~1\Owner\APPLIC~1\SpamBlockerUtility_Icons\MobileSidewalk_2.ico
C:\DOCUME~1\Owner\APPLIC~1\SpamBlockerUtility_Icons\Software_Online_8.ico
C:\DOCUME~1\Owner\APPLIC~1\SpamBlockerUtility_Icons\wallpapere1.ico
C:\DOCUME~1\THEBOS~1\Desktop.\Free PC Wallpapers.lnk
C:\Program Files\Common Files\{341B5~1
C:\Program Files\Common Files\{341B5~1\Bar888.dll
C:\Program Files\Common Files\{341B5~1\UnInstall.exe
C:\Program Files\Common Files\{A41B5~1
C:\Program Files\Common Files\{A41B5~1\system.dll
C:\Program Files\Common Files\{A41B5~2
C:\Program Files\Common Files\{A41B5~2\system.dll
C:\Program Files\Common Files\{A41B5~3
C:\Program Files\Common Files\{A41B5~3\system.dll
C:\Program Files\download plugin
C:\Program Files\download plugin\DlPlugin-MSIE_1.5.0.0\axdlplug.inf
C:\Program Files\folder.js\
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\temp\0c2
C:\temp\0c2\tmpFF.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\WINDOWS\DOWNLO~1.\Quarantine
C:\WINDOWS\ecurit~1
C:\WINDOWS\system32\hlpawomo.exe
C:\WINDOWS\system32\hysrnmbo.exe
C:\WINDOWS\system32\kylepxqy.exe
C:\WINDOWS\system32\L1
C:\WINDOWS\system32\L11
C:\WINDOWS\system32\L3
C:\WINDOWS\system32\L3\wr716.exe
C:\WINDOWS\system32\L5
C:\WINDOWS\system32\L7
C:\WINDOWS\system32\L9
C:\WINDOWS\system32\lgqvddbj.exe
C:\WINDOWS\system32\pwquqeai.exe
C:\WINDOWS\system32\win
C:\WINDOWS\system32\wintsvtr.exe
C:\WINDOWS\wnsxs~1
C:\WINDOWS\wnsxs~1\W?nSxS\


((((((((((((((((((((((((( Files Created from 2007-07-17 to 2007-08-17 )))))))))))))))))))))))))))))))


2007-08-17 16:32 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-17 15:59 <DIR> d-------- C:\WINDOWS\ERUNT
2007-08-17 15:57 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-08-17 15:57 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver
2007-08-17 15:57 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-08-17 15:57 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
2007-08-17 15:57 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
2007-08-17 07:16 <DIR> d-------- C:\VundoFix Backups
2007-08-16 22:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-16 22:18 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-08-16 21:33 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-08-16 21:03 <DIR> d-------- C:\DOCUME~1\THEBOS~1\.housecall6.6
2007-08-16 19:07 2,050 --a------ C:\WINDOWS\system32\ilyioogf.dll
2007-08-16 18:37 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-08-16 18:36 <DIR> d-------- C:\Program Files\CCleaner
2007-08-16 18:03 <DIR> d-------- C:\Program Files\Lavasoft
2007-08-16 18:03 <DIR> d-------- C:\DOCUME~1\THEBOS~1\APPLIC~1\Lavasoft
2007-08-16 18:00 <DIR> d-------- C:\DOCUME~1\THEBOS~1\APPLIC~1\Inside Cast
2007-08-06 11:35 <DIR> d-------- C:\Program Files\Inside Cast
2007-08-06 11:35 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Blue live drv active
2007-08-06 11:35 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\active move body safe
2007-07-22 11:32 <DIR> d-------- C:\Temp


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-16 21:35 47 ---h----- C:\dosldr.bin
2007-08-16 18:17 --------- d-------- C:\Program Files\BigFix
2007-07-09 16:14 --------- d-------- C:\Program Files\AIM6
2007-07-09 16:13 --------- d-------- C:\Program Files\Common Files\AOL
2007-07-08 11:43 --------- d-------- C:\Program Files\AIM
2007-07-04 12:23 --------- d-------- C:\Program Files\AOD
2007-06-14 05:22 2231 --a------ C:\Program Files\folder.js


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6CD9F4C8-652E-4889-2F00-35B60B4FF0EA}]
C:\WINDOWS\system32\ordtg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CB0D36B4-99A9-49F9-878A-A9D119BED1AF}]
C:\WINDOWS\system32\awtss.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-03-19 17:17]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 22:42]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-09 12:47]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-03-11 18:18]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-01-29 22:13]
"SoundMan"="SOUNDMAN.EXE" [2004-01-09 06:54 C:\WINDOWS\SOUNDMAN.EXE]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2006-11-14 18:06]
"AIMPro"="C:\Program Files\AIM\AIM Pro\aimpro.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-24 15:36]
"MEDIC"="C:\Program Files\MEDIC\bin\sprtcmd.exe" [2006-12-27 20:04]
"ddhelper"="C:\WINDOWS\W815DM.EXE" [2006-12-07 17:17]
"mediaadmineachmore"="C:\Documents and Settings\All Users\Application Data\third option media admin\DupeBait.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 11:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-02 16:24]
"body safe tool drv"="C:\Documents and Settings\All Users\Application Data\active move body safe\Debug Barb.exe" [2007-08-17 15:54]
"CLOCK EXIT NEW DRV"="C:\Documents and Settings\All Users\Application Data\Blue live drv active\Vc Stupid Acid.exe" [2007-08-16 17:54]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"enuff_temp"="C:\Program Files\Akrontech\enuff\ENUFF.exe" [2006-12-07 17:16]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-27 15:29]
"Download"="C:\Documents and Settings\THE BOSSES\Local Settings\Application Data\SupportSoft\medic\THE BOSSES\exec\SSGet.exe" [2007-06-01 18:59]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"sdaemon"=C:\WINDOWS\sdaemon.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2004-08-09 18:03:42]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"=0 (0x0)
"DisableTaskMgr"=0 (0x0)
"DisableRegistryTools"=0 (0x0)

R3 IPN2120;Wireless-B PCI Adapter Driver;C:\WINDOWS\system32\DRIVERS\LSIPNDS.sys
R3 odysseyIM3;Odyssey Network Services Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM3.sys
S3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\System32\CBTNDIS5.SYS


Contents of the 'Scheduled Tasks' folder
2007-08-17 19:00:00 C:\WINDOWS\Tasks\ABE649FC9189FC70.job - c:\docume~1\owner\applic~1\inside~1\WAYROADCDROM.exe
2007-08-17 13:42:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2006-11-14 02:25:06 C:\WINDOWS\Tasks\ISP signup reminder 2.job - C:\WINDOWS\System32\OOBE\oobebaln.exe
2007-07-07 00:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job - C:\PROGRA~1\NORTON~1\Navw32.exe
2007-08-17 20:41:00 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-17 16:39:39
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-17 16:42:37 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-17 16:42

--- E O F ---




Logfile of HijackThis v1.99.1
Scan saved at 4:44:46 PM, on 8/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\CVSEXPSS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SXPESVC.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MEDIC\bin\sprtcmd.exe
C:\WINDOWS\W815DM.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Akrontech\enuff\ENUFF.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\THE BOSSES\Local Settings\Application Data\SupportSoft\medic\THE BOSSES\exec\SSGet.exe
C:\Program Files\BigFix\BigFix.exe
C:\Documents and Settings\THE BOSSES\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\PROGRA~1\NETSCA~1\NETSCA~1\pbhelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {6CD9F4C8-652E-4889-2F00-35B60B4FF0EA} - C:\WINDOWS\system32\ordtg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {CB0D36B4-99A9-49F9-878A-A9D119BED1AF} - C:\WINDOWS\system32\awtss.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MEDIC] "C:\Program Files\MEDIC\bin\sprtcmd.exe" /P MEDIC
O4 - HKLM\..\Run: [ddhelper] "C:\WINDOWS\W815DM.EXE"
O4 - HKLM\..\Run: [mediaadmineachmore] C:\Documents and Settings\All Users\Application Data\third option media admin\DupeBait.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [body safe tool drv] C:\Documents and Settings\All Users\Application Data\active move body safe\Debug Barb.exe
O4 - HKLM\..\Run: [CLOCK EXIT NEW DRV] C:\Documents and Settings\All Users\Application Data\Blue live drv active\Vc Stupid Acid.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [enuff_temp] C:\Program Files\Akrontech\enuff\ENUFF.exe
O4 - HKLM\..\RunOnce: [sdaemon] C:\WINDOWS\sdaemon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Download] "C:\Documents and Settings\THE BOSSES\Local Settings\Application Data\SupportSoft\medic\THE BOSSES\exec\SSGet.exe" 120 "http://medic.rr.com/sdccommon/download/medic6.exe" "medic6.exe" Log ""
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone: *.impregnable.net
O15 - Trusted Zone: *.torrentcommander.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.my-etrust.com/Extern/RoadRunner...an/pestscan.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ENUFF XP Service (ENXPSVC) - Akrontech - C:\WINDOWS\System32\CVSEXPSS.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

There you have it. Please help as soon as you can.
Mark

#5 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:25 PM

Posted 17 August 2007 - 05:24 PM

Copy and paste ALL the following blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\system32\ilyioogf.dll
C:\WINDOWS\Tasks\ABE649FC9189FC70.job
Folder::
C:\DOCUME~1\THEBOS~1\APPLIC~1\Inside Cast
C:\Program Files\Inside Cast
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Blue live drv active
C:\DOCUME~1\ALLUSE~1\APPLIC~1\active move body safe
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6CD9F4C8-652E-4889-2F00-35B60B4FF0EA}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CB0D36B4-99A9-49F9-878A-A9D119BED1AF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mediaadmineachmore"=-
"body safe tool drv"=-
"CLOCK EXIT NEW DRV"=-

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image
Posted Image

#6 mgeorgevich

mgeorgevich
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:02:25 PM

Posted 17 August 2007 - 08:17 PM

Richie, here is the combo and the hjt. Can you tell me what you are seeing?

ComboFix 07-08-17.2 - "THE BOSSES" 2007-08-17 20:59:59.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.70 [GMT -4:00]
Command switches used :: C:\Documents and Settings\THE BOSSES\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\system32\ilyioogf.dll
C:\WINDOWS\Tasks\ABE649FC9189FC70.job


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1\active move body safe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\active move body safe\Debug Barb.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Blue live drv active
C:\DOCUME~1\THEBOS~1\APPLIC~1\Inside Cast
C:\Program Files\folder.js\
C:\Program Files\Inside Cast
C:\WINDOWS\system32\ilyioogf.dll
C:\WINDOWS\Tasks\ABE649FC9189FC70.job


((((((((((((((((((((((((( Files Created from 2007-07-18 to 2007-08-18 )))))))))))))))))))))))))))))))


2007-08-17 20:05 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-08-17 19:37 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
2007-08-17 19:23 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-17 16:32 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-17 15:59 <DIR> d-------- C:\WINDOWS\ERUNT
2007-08-17 15:57 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-08-17 15:57 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver
2007-08-17 15:57 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-08-17 15:57 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
2007-08-17 15:57 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
2007-08-17 07:16 <DIR> d-------- C:\VundoFix Backups
2007-08-16 22:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-16 22:18 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-08-16 21:33 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-08-16 21:03 <DIR> d-------- C:\DOCUME~1\THEBOS~1\.housecall6.6
2007-08-16 18:37 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-08-16 18:36 <DIR> d-------- C:\Program Files\CCleaner
2007-08-16 18:03 <DIR> d-------- C:\Program Files\Lavasoft
2007-08-16 18:03 <DIR> d-------- C:\DOCUME~1\THEBOS~1\APPLIC~1\Lavasoft
2007-07-22 11:32 <DIR> d-------- C:\Temp


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-16 21:35 47 ---h----- C:\dosldr.bin
2007-08-16 18:17 --------- d-------- C:\Program Files\BigFix
2007-07-09 16:14 --------- d-------- C:\Program Files\AIM6
2007-07-09 16:13 --------- d-------- C:\Program Files\Common Files\AOL
2007-07-08 11:43 --------- d-------- C:\Program Files\AIM
2007-07-04 12:23 --------- d-------- C:\Program Files\AOD
2007-06-26 02:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 09:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-14 05:22 2231 --a------ C:\Program Files\folder.js
2007-06-13 06:23 1033216 --a------ C:\WINDOWS\explorer.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-03-19 17:17]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 22:42]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-09 12:47]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-03-11 18:18]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-01-29 22:13]
"SoundMan"="SOUNDMAN.EXE" [2004-01-09 06:54 C:\WINDOWS\SOUNDMAN.EXE]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2006-11-14 18:06]
"AIMPro"="C:\Program Files\AIM\AIM Pro\aimpro.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-24 15:36]
"MEDIC"="C:\Program Files\MEDIC\bin\sprtcmd.exe" [2006-12-27 20:04]
"ddhelper"="C:\WINDOWS\W815DM.EXE" [2006-12-07 17:17]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 11:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-02 16:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"enuff_temp"="C:\Program Files\Akrontech\enuff\ENUFF.exe" [2006-12-07 17:16]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"Download"="C:\Documents and Settings\THE BOSSES\Local Settings\Application Data\SupportSoft\medic\THE BOSSES\exec\SSGet.exe" [2007-06-01 18:59]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"sdaemon"=C:\WINDOWS\sdaemon.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2004-08-09 18:03:42]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"=0 (0x0)
"DisableTaskMgr"=0 (0x0)
"DisableRegistryTools"=0 (0x0)

R3 IPN2120;Wireless-B PCI Adapter Driver;C:\WINDOWS\system32\DRIVERS\LSIPNDS.sys
R3 odysseyIM3;Odyssey Network Services Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM3.sys
S3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\System32\CBTNDIS5.SYS


Contents of the 'Scheduled Tasks' folder
2007-08-17 13:42:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2006-11-14 02:25:06 C:\WINDOWS\Tasks\ISP signup reminder 2.job - C:\WINDOWS\System32\OOBE\oobebaln.exe
2007-08-18 00:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job - C:\PROGRA~1\NORTON~1\Navw32.exe
2007-08-18 01:12:11 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-17 21:12:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-17 21:13:58 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-17 21:13
C:\ComboFix2.txt ... 2007-08-17 16:42

--- E O F ---


Logfile of HijackThis v1.99.1
Scan saved at 9:15:02 PM, on 8/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\CVSEXPSS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\SXPESVC.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MEDIC\bin\sprtcmd.exe
C:\WINDOWS\W815DM.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\THE BOSSES\Local Settings\Application Data\SupportSoft\medic\THE BOSSES\exec\SSGet.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Akrontech\enuff\ENUFF.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\THE BOSSES\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\PROGRA~1\NETSCA~1\NETSCA~1\pbhelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MEDIC] "C:\Program Files\MEDIC\bin\sprtcmd.exe" /P MEDIC
O4 - HKLM\..\Run: [ddhelper] "C:\WINDOWS\W815DM.EXE"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [enuff_temp] C:\Program Files\Akrontech\enuff\ENUFF.exe
O4 - HKLM\..\RunOnce: [sdaemon] C:\WINDOWS\sdaemon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Download] "C:\Documents and Settings\THE BOSSES\Local Settings\Application Data\SupportSoft\medic\THE BOSSES\exec\SSGet.exe" 120 "http://medic.rr.com/sdccommon/download/medic6.exe" "medic6.exe" Log ""
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone: *.impregnable.net
O15 - Trusted Zone: *.torrentcommander.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.my-etrust.com/Extern/RoadRunner...an/pestscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ENUFF XP Service (ENXPSVC) - Akrontech - C:\WINDOWS\System32\CVSEXPSS.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

#7 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:25 PM

Posted 17 August 2007 - 08:27 PM

Download DelDomains.zip and extract/unzip it to your desktop:
Now right click on Deldomains.inf then click on 'Install'.
After right clicking on Deldomains.inf 'Install' it will have appeared nothing happened,this is normal.

Make sure all hidden files are showing:
* Click 'Start'.
* Open 'My Computer'.
* Select the 'Tools' menu and click 'Folder Options'.
* Select the 'View' tab.
* Under the 'Hidden files and folders' heading select 'Show hidden files and folders'.
* Uncheck the 'Hide file extensions for known types' option.
* Uncheck the 'Hide protected operating system files (recommended)' option.
* Click Yes to confirm.
* Click OK.

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
Exit Hijackthis.

Find and delete:
C:\Program Files\folder.js

Start SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.

Posted Image
Posted Image

#8 mgeorgevich

mgeorgevich
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:02:25 PM

Posted 17 August 2007 - 08:50 PM

I right-clicked on the DellDomain and now my mouse is gone

#9 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:25 PM

Posted 17 August 2007 - 08:55 PM

Restart your pc,let me know what happens.
Posted Image
Posted Image

#10 mgeorgevich

mgeorgevich
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:02:25 PM

Posted 17 August 2007 - 09:34 PM

nevermind, it cam back. Here is the logs:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/17/2007 at 10:25 PM

Application Version : 3.9.1008

Core Rules Database Version : 3289
Trace Rules Database Version: 1300

Scan type : Complete Scan
Total Scan Time : 00:26:09

Memory items scanned : 394
Memory threats detected : 0
Registry items scanned : 4648
Registry threats detected : 0
File items scanned : 32683
File threats detected : 155

Adware.Tracking Cookie
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@pandasoftware.112.2o7[1].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@burstnet[2].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@ehg-pcsecurityshield.hitbox[1].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@stat.errclean[1].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@tribalfusion[1].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@cpvfeed[2].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@doubleclick[1].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@h.starware[1].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@tacoda[2].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@login.tracking101[2].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@azjmp[1].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@mediatraffic[1].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@hitbox[2].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@ad[1].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@www.burstnet[1].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@fastclick[1].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@ads.pointroll[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[4].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[5].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[6].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[7].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[8].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.outerinfo[9].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[4].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.specificclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.adbrite[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.buddy4u[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.monster[1].txt
C:\Documents and Settings\Owner\Cookies\owner@aff.primaryads[1].txt
C:\Documents and Settings\Owner\Cookies\owner@anad.tacoda[1].txt
C:\Documents and Settings\Owner\Cookies\owner@angleinteractive.directtrack[2].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[1].txt
C:\Documents and Settings\Owner\Cookies\owner@azjmp[1].txt
C:\Documents and Settings\Owner\Cookies\owner@azjmp[3].txt
C:\Documents and Settings\Owner\Cookies\owner@azoogleads[2].txt
C:\Documents and Settings\Owner\Cookies\owner@azoogleads[3].txt
C:\Documents and Settings\Owner\Cookies\owner@banners.battleon[1].txt
C:\Documents and Settings\Owner\Cookies\owner@beachsidecompanies.directtrack[1].txt
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[2].txt
C:\Documents and Settings\Owner\Cookies\owner@clicksor[1].txt
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[2].txt
C:\Documents and Settings\Owner\Cookies\owner@dalenetwork.directtrack[2].txt
C:\Documents and Settings\Owner\Cookies\owner@directtrack[1].txt
C:\Documents and Settings\Owner\Cookies\owner@eas.apm.emediate[1].txt
C:\Documents and Settings\Owner\Cookies\owner@exitexchange[2].txt
C:\Documents and Settings\Owner\Cookies\owner@h.starware[1].txt
C:\Documents and Settings\Owner\Cookies\owner@h.starware[3].txt
C:\Documents and Settings\Owner\Cookies\owner@i.screensavers[1].txt
C:\Documents and Settings\Owner\Cookies\owner@interclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@linkstattrack[1].txt
C:\Documents and Settings\Owner\Cookies\owner@login.tracking101[1].txt
C:\Documents and Settings\Owner\Cookies\owner@mediatraffic[2].txt
C:\Documents and Settings\Owner\Cookies\owner@nfm.directtrack[2].txt
C:\Documents and Settings\Owner\Cookies\owner@partners.agamimedia[2].txt
C:\Documents and Settings\Owner\Cookies\owner@publishers.clickbooth[1].txt
C:\Documents and Settings\Owner\Cookies\owner@publishers.clickbooth[2].txt
C:\Documents and Settings\Owner\Cookies\owner@redorbit.us.intellitxt[1].txt
C:\Documents and Settings\Owner\Cookies\owner@redorbit[1].txt
C:\Documents and Settings\Owner\Cookies\owner@screensavers[2].txt
C:\Documents and Settings\Owner\Cookies\owner@server.cpmstar[1].txt
C:\Documents and Settings\Owner\Cookies\owner@toseeka[2].txt
C:\Documents and Settings\Owner\Cookies\owner@track.adrevolver[1].txt
C:\Documents and Settings\Owner\Cookies\owner@try.starware[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstbeacon[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.clash-media[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.screensavers[1].txt
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@ads.realtechnetwork[2].txt
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@burstnet[2].txt
C:\Documents and Settings\THE BOSSES\Cookies\the bosses@azoogleads[3].txt

Adware.HotBar/SpamBlockerUtility (Low Risk)
C:\WINDOWS\Downloaded Program Files\SpamBlockerUtility.inf

Adware.Lop-Gen
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\FACEWARNPHONEPEAK\TOOL INTRA.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\THIRD OPTION MEDIA ADMIN\BIKE STORE.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\INSIDE CAST\ADIKPZZV.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\INSIDE CAST\GSOJKPTC.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\INSIDE CAST\ZFUTOCMT.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMP\STA3.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMP\STAC.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP235\A0027212.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP235\A0027213.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP274\A0057820.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP274\A0057821.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0062874.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0062875.EXE

Adware.Lop-Variant
C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\INSIDE CAST\IDPCWTPR.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\INSIDE CAST\LHTBHJGX.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\INSIDE CAST\LINK FIRST TWO.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMP\STA27.EXE
C:\QOOBOX\QUARANTINE\C\DOCUME~1\ALLUSE~1\APPLIC~1\ACTIVE MOVE BODY SAFE\DEBUG BARB.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP275\A0057827.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP276\A0058821.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP277\A0059822.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP278\A0060820.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP279\A0061819.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP279\A0062824.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP279\A0062831.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP279\A0062840.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP279\A0062854.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP279\A0062861.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0062870.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063874.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0064873.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0065897.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP281\A0066000.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP282\A0066001.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP284\A0066517.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP284\A0066536.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP284\A0066544.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP285\A0066568.EXE

Adware.ClickSpring
C:\Documents and Settings\Owner\My Documents\RACLE~1\CANREG~1.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0062862.EXE

Adware.eZula
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\HLPAWOMO.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\HYSRNMBO.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\KYLEPXQY.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\LGQVDDBJ.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\PWQUQEAI.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP283\A0066058.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP283\A0066059.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP283\A0066060.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP283\A0066061.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP283\A0066062.EXE

Trojan.Unknown Origin
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WINTSVTR.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP273\A0056823.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP283\A0066057.EXE

Adware.WebBuying Assistant-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP269\A0052735.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0062882.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063867.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0064865.EXE

Adware.Mirar/NetNucleus
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP269\A0052741.DLL

Adware.ClickSpring/Resident
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP273\A0056820.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0062863.DLL

Adware.Vundo/Traff-2
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063097.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063098.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063099.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063100.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063101.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063102.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063105.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063109.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063111.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063113.EXE

Trojan.Downloader-Gen/HitItQuitIt
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063115.DLL

Adware.Vundo Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063116.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0064881.DLL
C:\VUNDOFIX BACKUPS\LJJGGHG.DLL.BAD

Unclassified.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0063866.DLL

Trojan.Downloader-Gen/TStamp
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0064882.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{4C6E9B3C-F1BE-4527-8708-5AE69FD346FA}\RP280\A0064886.EXE
C:\VUNDOFIX BACKUPS\LVWJNSSU.EXE.BAD
C:\VUNDOFIX BACKUPS\SKIBJQUT.EXE.BAD

Trace.Known Threat Sources
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\K72CP4IM\campaigns7[1].encrypted
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\05SVUXU1\client_settings_3[1].bin
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\Q5WX4XK1\_affvm[1]
C:\Documents and Settings\THE BOSSES\Local Settings\Temporary Internet Files\Content.IE5\AJWDUTY1\style[1].css


Logfile of HijackThis v1.99.1
Scan saved at 10:31:09 PM, on 8/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\CVSEXPSS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\SXPESVC.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MEDIC\bin\sprtcmd.exe
C:\WINDOWS\W815DM.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\THE BOSSES\Local Settings\Application Data\SupportSoft\medic\THE BOSSES\exec\SSGet.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Akrontech\enuff\ENUFF.exe
C:\Program Files\BigFix\BigFix.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\THE BOSSES\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\PROGRA~1\NETSCA~1\NETSCA~1\pbhelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MEDIC] "C:\Program Files\MEDIC\bin\sprtcmd.exe" /P MEDIC
O4 - HKLM\..\Run: [ddhelper] "C:\WINDOWS\W815DM.EXE"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [enuff_temp] C:\Program Files\Akrontech\enuff\ENUFF.exe
O4 - HKLM\..\RunOnce: [sdaemon] C:\WINDOWS\sdaemon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Download] "C:\Documents and Settings\THE BOSSES\Local Settings\Application Data\SupportSoft\medic\THE BOSSES\exec\SSGet.exe" 120 "http://medic.rr.com/sdccommon/download/medic6.exe" "medic6.exe" Log ""
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.my-etrust.com/Extern/RoadRunner...an/pestscan.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187400211218
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ENUFF XP Service (ENXPSVC) - Akrontech - C:\WINDOWS\System32\CVSEXPSS.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

The PC is working faster but I lost my Norton icon on status bar

Thank you

#11 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:25 PM

Posted 18 August 2007 - 09:40 AM

Your log is clean :thumbsup:
If all's ok,please do the following.

Find and delete:
SDFix.exe
DelDomains.zip
DelDomains.inf
Combofix

C:\SDFix
C:\Qoobox
C:\VundoFix Backups

* Click 'Start'.
* Open 'My Computer'.
* Select the 'Tools' menu and click 'Folder Options'.
* Select the 'View' tab.
* Under the 'Hidden files and folders' heading unselect 'Show hidden files and folders'.
* Re-check the 'Hide file extensions for known types' option.
* Re-check the 'Hide protected operating system files (recommended)' option.
* Click Yes to confirm.
* Click OK.

Download ATF Cleaner by Atribune:
http://www.atribune.org/ccount/click.php?id=1

Double-click ATF-Cleaner.exe to run the program.
Click 'Select All' found at the bottom of the list.
Click the 'Empty Selected' button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

If you use Opera browser,do this also:
Click Opera at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

Click 'Exit' on the Main menu to close the program.

------------------------------------------------------

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
'How to prevent Malware' by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users