Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan-downloader.win32.conhook.bg


  • Please log in to reply
11 replies to this topic

#1 chinner

chinner

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 05 September 2007 - 05:27 AM

hi i seem to have this trojan that won't go away even though f-secure seems to delete it but when i restart it comes back everytime, here is my hijack this log anyway please please help
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:26:49, on 05/09/2007
Platform: Windows XP SP2, v.2096 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2096)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
F:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
F:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
F:\WINDOWS\system32\CTHELPER.EXE
F:\Program Files\HP\hpcoretech\hpcmpmgr.exe
F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
F:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
F:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
F:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
F:\WINDOWS\system32\CTsvcCDA.exe
F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Documents and Settings\Anna&David\Application Data\tmp262.tmp.exe
F:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
F:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
F:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
F:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
F:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
F:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
F:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
F:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
F:\WINDOWS\system32\svchost.exe
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
F:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
F:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
F:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
F:\WINDOWS\system32\MsPMSPSv.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
F:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
F:\WINDOWS\system32\wscntfy.exe
F:\WINDOWS\system32\wuauclt.exe
F:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
F:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
F:\Program Files\Webroot\Spy Sweeper\SSU.EXE
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Documents and Settings\Anna&David\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.blueyonder.co.uk/search/search.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by blueyonder
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CTSysVol] "F:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTDVDDET] "F:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] "F:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" /r
O4 - HKLM\..\Run: [UpdReg] F:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [HP Component Manager] "F:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "F:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "F:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "F:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "F:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [NeroFilterCheck] "F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SystemOptimizer] "rundll32.exe" "F:\WINDOWS\vturrp.dll",forkonce
O4 - HKLM\..\Run: [SpySweeper] F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RemoteCenter] "F:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: blueyonder Instant Support Tool.lnk = F:\Program Files\blueyonder IST\bin\matcli.exe
O4 - Global Startup: F-Secure 2006.lnk = F:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Block this popup - F:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - F:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - F:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - F:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - F:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - F:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra button: PacificPoker - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - F:\PROGRA~1\PACIFI~1\pacificpoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - F:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O20 - Winlogon Notify: cmmcat - F:\WINDOWS\SYSTEM32\cmmcat.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - F:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DomainService - Unknown owner - F:\Documents and Settings\Anna&David\Application Data\tmp262.tmp.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - F:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
O23 - Service: FSMA - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - F:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: PostgreSQL Database Server (pgsql-8.0) - PostgreSQL Global Development Group - F:\Program Files\PostgreSQL\8.0\bin\pg_ctl.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - F:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 11496 bytes

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 05 September 2007 - 06:55 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum chinner :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

You have F-Secure Internet Security and Norton AntiVirus installed.
Its definitely not a good idea to have more than one antivirus program installed on your computer.
Each program may interpret the actions of the other as viral, therefore giving you false virus warnings about virus-related activities.
It could also lead to system slowdowns and other problems within the operating system,due to the two conflicting with each other.
You should uninstall one of them now,then restart your pc.

If you decide to uninstall Norton,if there’s no uninstaller available in Add\Remove Programs then you’’ll need to download and run the Norton Removal Tool:
http://service1.symantec.com/SUPPORT/tsgen...005033108162039
*Please Note:*
The Norton Removal Tool will remove all Norton/Symantec products from your pc.

Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u2'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java versions.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.

Download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#3 chinner

chinner
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 05 September 2007 - 07:14 PM

here is the hijackthis log after what you've said to do
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:16:43, on 06/09/2007
Platform: Windows XP SP2, v.2096 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2096)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
F:\WINDOWS\system32\CTsvcCDA.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
F:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
F:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
F:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
F:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
F:\WINDOWS\system32\svchost.exe
F:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
F:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
F:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
F:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
F:\WINDOWS\system32\MsPMSPSv.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
F:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
F:\WINDOWS\system32\wscntfy.exe
F:\WINDOWS\system32\wuauclt.exe
F:\WINDOWS\explorer.exe
F:\WINDOWS\system32\notepad.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Documents and Settings\Anna&David\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [CTSysVol] "F:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTDVDDET] "F:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] "F:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" /r
O4 - HKLM\..\Run: [UpdReg] F:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [HP Component Manager] "F:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "F:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "F:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "F:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "F:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [NeroFilterCheck] "F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] "F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RemoteCenter] "F:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: blueyonder Instant Support Tool.lnk = F:\Program Files\blueyonder IST\bin\matcli.exe
O4 - Global Startup: F-Secure 2006.lnk = F:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Block this popup - F:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - F:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - F:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - F:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - F:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - F:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra button: PacificPoker - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - F:\PROGRA~1\PACIFI~1\pacificpoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - F:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O20 - Winlogon Notify: cmmcat - cmmcat.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - F:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - F:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
O23 - Service: FSMA - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: PostgreSQL Database Server (pgsql-8.0) - PostgreSQL Global Development Group - F:\Program Files\PostgreSQL\8.0\bin\pg_ctl.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - F:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 8821 bytes

Edited by chinner, 05 September 2007 - 07:18 PM.


#4 chinner

chinner
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 06 September 2007 - 04:33 AM

ComboFix 07-09-06.3 - "Anna&David" 2007-09-06 0:54:48.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.203 [GMT 1:00]


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


F:\DOCUME~1\ANNA&D~1\APPLIC~1\tmp1AD.tmp.exe
F:\DOCUME~1\ANNA&D~1\APPLIC~1\tmp1B7.tmp.exe
F:\DOCUME~1\ANNA&D~1\APPLIC~1\tmp1F9.tmp.exe
F:\DOCUME~1\ANNA&D~1\APPLIC~1\tmp1FC.tmp.exe
F:\DOCUME~1\ANNA&D~1\APPLIC~1\tmp1FD.tmp.exe
F:\DOCUME~1\ANNA&D~1\APPLIC~1\tmp262.tmp.exe
F:\DOCUME~1\ANNA&D~1\APPLIC~1\tmp38.tmp.exe
F:\DOCUME~1\ANNA&D~1\APPLIC~1\tmp40.tmp.exe
F:\DOCUME~1\ANNA&D~1\APPLIC~1\tmpD7.tmp.exe
F:\DOCUME~1\ANNA&D~1\APPLIC~1\tmpEC.tmp.exe
F:\WINDOWS\cookies.ini
F:\WINDOWS\system32\tmp1B7.tmp.dll
F:\WINDOWS\system32\tmpEC.tmp.dll


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_DOMAINSERVICE
-------\DomainService


((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 )))))))))))))))))))))))))))))))


2007-09-06 00:47 51,200 --a------ F:\WINDOWS\NirCmd.exe
2007-08-31 20:59 <DIR> d-------- F:\DOCUME~1\NETWOR~1\APPLIC~1\Webroot
2007-08-31 20:30 131,464 --a------ F:\WINDOWS\vturrp.dll
2007-08-31 20:12 22,080 --a------ F:\WINDOWS\system32\drivers\sshrmd.sys
2007-08-31 20:12 21,056 --a------ F:\WINDOWS\system32\drivers\sskbfd.sys
2007-08-31 20:12 20,544 --a------ F:\WINDOWS\system32\drivers\SSFS0509.sys
2007-08-31 20:12 144,960 --a------ F:\WINDOWS\system32\drivers\ssidrv.sys
2007-08-31 20:12 <DIR> d-------- F:\Program Files\Webroot
2007-08-31 20:12 <DIR> d-------- F:\DOCUME~1\LOCALS~1\APPLIC~1\Webroot
2007-08-31 20:12 <DIR> d-------- F:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
2007-08-31 20:10 <DIR> d-------- F:\DOCUME~1\ANNA&D~1\APPLIC~1\Webroot
2007-08-27 20:34 <DIR> d-------- F:\VundoFix Backups
2007-08-27 20:31 <DIR> d-------- F:\Program Files\CCleaner
2007-08-26 20:44 131,465 --a------ F:\WINDOWS\cbbcaa.dll
2007-08-25 18:58 <DIR> d-------- F:\Program Files\ScanSpyware v3.8
2007-08-24 18:15 10,872 --a------ F:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-24 15:06 612,656 --a------ F:\WINDOWS\system32\dn7c5337b7.dat
2007-08-23 15:07 131,458 --------- F:\WINDOWS\rqoomj.dll
2007-08-23 15:05 94,713 --------- F:\WINDOWS\system32\cmmcat.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-06 00:04 --------- d-------- F:\Program Files\Common Files\Symantec Shared
2007-09-06 00:01 --------- d-------- F:\Program Files\Norton AntiVirus
2007-09-04 19:02 --------- d-------- F:\DOCUME~1\ANNA&D~1\APPLIC~1\uTorrent
2007-09-03 13:34 --------- d-------- F:\Program Files\Giganews Binary Newsreader
2007-09-02 16:32 --------- d-------- F:\DOCUME~1\ANNA&D~1\APPLIC~1\.BitTornado
2007-08-31 21:09 --------- d-------- F:\Program Files\SpacialAudio
2007-08-31 21:08 --------- d-------- F:\Program Files\Yahoo!
2007-08-27 21:23 --------- d-------- F:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-21 17:38 --------- d-------- F:\Program Files\PacificPoker
2007-07-26 11:27 --------- d-------- F:\Program Files\PartyGaming
2007-07-19 20:01 --------- d-------- F:\Program Files\dvdSanta
2007-07-11 13:30 --------- d-------- F:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
2007-07-03 19:37 434688 --a------ F:\WINDOWS\system32\ss2uinst.exe
2007-06-06 18:03 49152 -ra------ F:\WINDOWS\system32\inetwh32.dll
2007-06-06 18:03 1044480 -ra------ F:\WINDOWS\system32\roboex32.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="F:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 10:43]
"CTDVDDET"="F:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" [2003-06-18 01:00]
"CTHelper"="CTHELPER.EXE" [2003-10-06 07:57 F:\WINDOWS\system32\CTHELPER.EXE]
"SBDrvDet"="F:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 18:06]
"UpdReg"="F:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00]
"HP Component Manager"="F:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38]
"HPDJ Taskbar Utility"="F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 15:46]
"HP Software Update"="F:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 18:55]
"F-Secure Manager"="F:\Program Files\F-Secure Internet Security\Common\FSM32.exe" [2005-06-02 23:37]
"F-Secure TNB"="F:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" [2005-07-18 15:51]
"F-Secure Startup Wizard"="F:\Program Files\F-Secure Internet Security\FSGUI\FSSW.exe" [2005-08-23 14:38]
"RegistryMechanic"="" []
"NeroFilterCheck"="F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"TkBellExe"="F:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-09-09 22:53]
"Adobe Reader Speed Launcher"="F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"!AVG Anti-Spyware"="F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"SpySweeper"="F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-03-01 20:09]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\system32\ctfmon.exe" [2004-03-12 01:18]
"RemoteCenter"="F:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE" [2003-10-08 16:35]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=F:\Program Files\MySpace\IM\MySpaceIM.exe

F:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
blueyonder Instant Support Tool.lnk - F:\Program Files\blueyonder IST\bin\matcli.exe [2006-08-29 15:12:18]
F-Secure 2006.lnk - F:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe [2006-08-29 17:31:43]
Microsoft Office.lnk - F:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cmmcat]
cmmcat.dll 2007-08-23 15:05 94713 F:\WINDOWS\system32\cmmcat.dll

R0 FSFW;F-Secure Firewall Driver;F:\WINDOWS\system32\drivers\fsdfw.sys
R2 BackWeb Plug-in - 4476822;F-Secure 2006;F:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
R2 F-Secure Filter;F-Secure File System Filter;\??\F:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;\??\F:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSgk.sys
R2 F-Secure Recognizer;F-Secure File System Recognizer;\??\F:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys
R2 PfDetNT;PfDetNT;\??\F:\WINDOWS\system32\drivers\PfModNT.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bc69e882-9820-11db-a514-806d6172696f}]
Auto\command- fun.xls.exe
AutoRun\command- F:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe


Contents of the 'Scheduled Tasks' folder
"2007-09-06 00:02:32 F:\WINDOWS\Tasks\Scheduled scanning task.job"

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-06 01:02:52
Windows 5.1.2600 Service Pack 2, v.2096 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-06 1:04:14 - machine was rebooted
F:\ComboFix-quarantined-files.txt ... 2007-09-06 01:04

--- E O F ---

#5 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 06 September 2007 - 05:41 AM

First of all you have a topic running here:
http://www.techsupportforum.com/security-c...downloader.html
I suggest you mention in that topic you're being helped here,along with any other forums you might have topics running.

Copy and paste the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fix.bat to your desktop.
Then double click on the fix.bat file on your desktopPosted Image
You'll see a black screen flash,thats normal.

@echo off
sc stop Symantec Core LC
sc delete Symantec Core LC

Restart your pc.

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
F:\WINDOWS\vturrp.dll
F:\WINDOWS\cbbcaa.dll
F:\WINDOWS\rqoomj.dll
F:\WINDOWS\system32\cmmcat.dll

Folder::
F:\Program Files\Common Files\Symantec Shared
F:\Program Files\Norton AntiVirus

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cmmcat]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bc69e882-9820-11db-a514-806d6172696f}]

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image
Posted Image

#6 chinner

chinner
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 06 September 2007 - 07:24 AM

ComboFix 07-09-06.3 - "Anna&David" 2007-09-06 13:04:28.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.162 [GMT 1:00]

FILE::
F:\WINDOWS\vturrp.dll
F:\WINDOWS\cbbcaa.dll
F:\WINDOWS\rqoomj.dll
F:\WINDOWS\system32\cmmcat.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


F:\DOCUME~1\ANNA&D~1\APPLIC~1\tmp1C4.tmp.exe
F:\Program Files\Common Files\Symantec Shared
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\ez_log.html
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlctnk.dll
F:\Program Files\Norton AntiVirus
F:\Program Files\Norton AntiVirus\ActRes.DLL
F:\Program Files\Norton AntiVirus\AVSTE.dll
F:\Program Files\Norton AntiVirus\comms.txt
F:\Program Files\Norton AntiVirus\LRSend.exe
F:\Program Files\Norton AntiVirus\SymLCUI.dll
F:\Program Files\Norton AntiVirus\SymUIHlp.dll
F:\WINDOWS\cbbcaa.dll
F:\WINDOWS\rqoomj.dll
F:\WINDOWS\vturrp.dll


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_DOMAINSERVICE
-------\DomainService


((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 )))))))))))))))))))))))))))))))


2007-09-06 00:47 51,200 --a------ F:\WINDOWS\NirCmd.exe
2007-08-31 20:59 <DIR> d-------- F:\DOCUME~1\NETWOR~1\APPLIC~1\Webroot
2007-08-31 20:12 22,080 --a------ F:\WINDOWS\system32\drivers\sshrmd.sys
2007-08-31 20:12 21,056 --a------ F:\WINDOWS\system32\drivers\sskbfd.sys
2007-08-31 20:12 20,544 --a------ F:\WINDOWS\system32\drivers\SSFS0509.sys
2007-08-31 20:12 144,960 --a------ F:\WINDOWS\system32\drivers\ssidrv.sys
2007-08-31 20:12 <DIR> d-------- F:\Program Files\Webroot
2007-08-31 20:12 <DIR> d-------- F:\DOCUME~1\LOCALS~1\APPLIC~1\Webroot
2007-08-31 20:12 <DIR> d-------- F:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
2007-08-31 20:10 <DIR> d-------- F:\DOCUME~1\ANNA&D~1\APPLIC~1\Webroot
2007-08-27 20:34 <DIR> d-------- F:\VundoFix Backups
2007-08-27 20:31 <DIR> d-------- F:\Program Files\CCleaner
2007-08-25 18:58 <DIR> d-------- F:\Program Files\ScanSpyware v3.8
2007-08-24 18:15 10,872 --a------ F:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-24 15:06 612,656 --a------ F:\WINDOWS\system32\dn7c5337b7.dat
2007-08-23 15:05 94,713 --------- F:\WINDOWS\system32\cmmcat.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-06 12:48 --------- d-------- F:\DOCUME~1\ANNA&D~1\APPLIC~1\uTorrent
2007-09-03 13:34 --------- d-------- F:\Program Files\Giganews Binary Newsreader
2007-09-02 16:32 --------- d-------- F:\DOCUME~1\ANNA&D~1\APPLIC~1\.BitTornado
2007-08-31 21:09 --------- d-------- F:\Program Files\SpacialAudio
2007-08-31 21:08 --------- d-------- F:\Program Files\Yahoo!
2007-08-27 21:23 --------- d-------- F:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-21 17:38 --------- d-------- F:\Program Files\PacificPoker
2007-07-26 11:27 --------- d-------- F:\Program Files\PartyGaming
2007-07-19 20:01 --------- d-------- F:\Program Files\dvdSanta
2007-07-11 13:30 --------- d-------- F:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
2007-07-03 19:37 434688 --a------ F:\WINDOWS\system32\ss2uinst.exe
2007-06-06 18:03 49152 -ra------ F:\WINDOWS\system32\inetwh32.dll
2007-06-06 18:03 1044480 -ra------ F:\WINDOWS\system32\roboex32.dll


((((((((((((((((((((((((((((( snapshot_2007-09-06_ 10330.76 )))))))))))))))))))))))))))))))))))))))))

----a-w 262,144 2007-09-06 12:00:24 F:\WINDOWS\system32\config\systemprofile\ntuser.dat

----a-w 262,144 2007-09-05 23:48:08 F:\WINDOWS\system32\config\systemprofile\ntuser.dat

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="F:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 10:43]
"CTDVDDET"="F:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" [2003-06-18 01:00]
"CTHelper"="CTHELPER.EXE" [2003-10-06 07:57 F:\WINDOWS\system32\CTHELPER.EXE]
"SBDrvDet"="F:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 18:06]
"UpdReg"="F:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00]
"HP Component Manager"="F:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38]
"HPDJ Taskbar Utility"="F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 15:46]
"HP Software Update"="F:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 18:55]
"F-Secure Manager"="F:\Program Files\F-Secure Internet Security\Common\FSM32.exe" [2005-06-02 23:37]
"F-Secure TNB"="F:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" [2005-07-18 15:51]
"F-Secure Startup Wizard"="F:\Program Files\F-Secure Internet Security\FSGUI\FSSW.exe" [2005-08-23 14:38]
"RegistryMechanic"="" []
"NeroFilterCheck"="F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"TkBellExe"="F:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-09-09 22:53]
"Adobe Reader Speed Launcher"="F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"!AVG Anti-Spyware"="F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"SpySweeper"="F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-03-01 20:09]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\system32\ctfmon.exe" [2004-03-12 01:18]
"RemoteCenter"="F:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE" [2003-10-08 16:35]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=F:\Program Files\MySpace\IM\MySpaceIM.exe

F:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
blueyonder Instant Support Tool.lnk - F:\Program Files\blueyonder IST\bin\matcli.exe [2006-08-29 15:12:18]
F-Secure 2006.lnk - F:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe [2006-08-29 17:31:43]
Microsoft Office.lnk - F:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"=0 (0x0)

R0 FSFW;F-Secure Firewall Driver;F:\WINDOWS\system32\drivers\fsdfw.sys
R2 BackWeb Plug-in - 4476822;F-Secure 2006;F:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
R2 F-Secure Filter;F-Secure File System Filter;\??\F:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;\??\F:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSgk.sys
R2 F-Secure Recognizer;F-Secure File System Recognizer;\??\F:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys
R2 PfDetNT;PfDetNT;\??\F:\WINDOWS\system32\drivers\PfModNT.sys


Contents of the 'Scheduled Tasks' folder
"2007-09-06 00:02:32 F:\WINDOWS\Tasks\Scheduled scanning task.job"

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-06 13:12:30
Windows 5.1.2600 Service Pack 2, v.2096 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-06 13:16:44 - machine was rebooted
F:\ComboFix-quarantined-files.txt ... 2007-09-06 13:16
F:\ComboFix2.txt ... 2007-09-06 01:04

--- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:24:08, on 06/09/2007
Platform: Windows XP SP2, v.2096 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2096)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
F:\WINDOWS\system32\CTsvcCDA.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
F:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
F:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
F:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
F:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
F:\WINDOWS\system32\svchost.exe
F:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
F:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
F:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
F:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
F:\WINDOWS\system32\MsPMSPSv.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
F:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
F:\WINDOWS\system32\wscntfy.exe
F:\WINDOWS\system32\wuauclt.exe
F:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
F:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
F:\WINDOWS\system32\CTHELPER.EXE
F:\Program Files\HP\hpcoretech\hpcmpmgr.exe
F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
F:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
F:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
F:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
F:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
F:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
F:\Program Files\blueyonder IST\bin\mpbtn.exe
F:\Program Files\Webroot\Spy Sweeper\SSU.EXE
F:\WINDOWS\system32\notepad.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Documents and Settings\Anna&David\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.blueyonder.co.uk/search/search.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [CTSysVol] "F:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTDVDDET] "F:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] "F:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" /r
O4 - HKLM\..\Run: [UpdReg] F:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [HP Component Manager] "F:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "F:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "F:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "F:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "F:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [NeroFilterCheck] "F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RemoteCenter] "F:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: blueyonder Instant Support Tool.lnk = F:\Program Files\blueyonder IST\bin\matcli.exe
O4 - Global Startup: F-Secure 2006.lnk = F:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Block this popup - F:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - F:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - F:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - F:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - F:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - F:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra button: PacificPoker - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - F:\PROGRA~1\PACIFI~1\pacificpoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - F:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - F:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - F:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
O23 - Service: FSMA - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: PostgreSQL Database Server (pgsql-8.0) - PostgreSQL Global Development Group - F:\Program Files\PostgreSQL\8.0\bin\pg_ctl.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - F:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Unknown owner - F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 9722 bytes

#7 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 06 September 2007 - 08:09 AM

Make sure all hidden files are showing:
* Click 'Start'.
* Open 'My Computer'.
* Select the 'Tools' menu and click 'Folder Options'.
* Select the 'View' tab.
* Under the 'Hidden files and folders' heading select 'Show hidden files and folders'.
* Uncheck the 'Hide file extensions for known types' option.
* Uncheck the 'Hide protected operating system files (recommended)' option.
* Click Yes to confirm.
* Click OK.

Click on Start>Run and type Services.msc then hit Ok.
Scroll down and find the service called:
Symantec Core LC
When you find it, double-click on it.
In the next window that opens, click the 'Stop' button.
Then change the 'Startup Type:' to 'Disabled'.
Now press Apply and then Ok and close any open windows.

Click Start>Run and type regedit then click OK.
Navigate to HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet>Services
Scroll down the left pane,locate the service name:
Symantec Core LC
Right click on it 'Delete'.
Then reboot.

Go here:http://virusscan.jotti.org/
Using the 'Browse' button,browse to:
F:\WINDOWS\system32\cmmcat.dll
Then press the 'Submit' button.
Wait while the file is scanned.
Post the results into your next reply.

If Jotti's too busy,try here:
http://www.virustotal.com/en/virustotalf.html
Click on the 'Analysis' tab.
Using the 'Browse' button,browse to:
F:\WINDOWS\system32\cmmcat.dll
Then click on 'Send File'.
Post the results into your next reply.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#8 chinner

chinner
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 06 September 2007 - 05:58 PM

Scan taken on 06 Sep 2007 22:57:11 (GMT)
A-Squared
Found nothing
AntiVir
Found TR/Trash.Gen
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing

#9 chinner

chinner
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 06 September 2007 - 05:59 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:59:18, on 06/09/2007
Platform: Windows XP SP2, v.2096 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2096)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
F:\WINDOWS\system32\CTsvcCDA.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
F:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
F:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
F:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
F:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
F:\WINDOWS\system32\svchost.exe
F:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
F:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
F:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
F:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
F:\WINDOWS\system32\MsPMSPSv.exe
F:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
F:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
F:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
F:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
F:\WINDOWS\system32\CTHELPER.EXE
F:\WINDOWS\system32\wscntfy.exe
F:\Program Files\HP\hpcoretech\hpcmpmgr.exe
F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
F:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
F:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
F:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
F:\WINDOWS\system32\wuauclt.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
F:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
F:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
F:\Program Files\Webroot\Spy Sweeper\SSU.EXE
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Documents and Settings\Anna&David\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.blueyonder.co.uk/search/search.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [CTSysVol] "F:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTDVDDET] "F:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] "F:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" /r
O4 - HKLM\..\Run: [UpdReg] F:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [HP Component Manager] "F:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] F:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "F:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "F:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "F:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "F:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [NeroFilterCheck] "F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] "F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RemoteCenter] "F:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: blueyonder Instant Support Tool.lnk = F:\Program Files\blueyonder IST\bin\matcli.exe
O4 - Global Startup: F-Secure 2006.lnk = F:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Block this popup - F:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - F:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - F:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - F:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - F:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - F:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra button: PacificPoker - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - F:\PROGRA~1\PACIFI~1\pacificpoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - F:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - F:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - F:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
O23 - Service: FSMA - F-Secure Corporation - F:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: PostgreSQL Database Server (pgsql-8.0) - PostgreSQL Global Development Group - F:\Program Files\PostgreSQL\8.0\bin\pg_ctl.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - F:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 9511 bytes

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 07 September 2007 - 03:54 AM

Your log is clean,hows your pc running now.
Posted Image
Posted Image

#11 chinner

chinner
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 07 September 2007 - 07:19 AM

My computer seems fine thanks for all of your help i will donate as soon as i get paid, really i cant thank you enough richie

#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:12:11 PM

Posted 07 September 2007 - 07:42 AM

If all's ok,please do the following.

Find and delete:
Combofix.exe
fix.bat

F:\Qoobox
F:\VundoFix Backups

* Click 'Start'.
* Open 'My Computer'.
* Select the 'Tools' menu and click 'Folder Options'.
* Select the 'View' tab.
* Under the 'Hidden files and folders' heading unselect 'Show hidden files and folders'.
* Re-check the 'Hide file extensions for known types' option.
* Re-check the 'Hide protected operating system files (recommended)' option.
* Click Yes to confirm.
* Click OK.

Download ATF Cleaner by Atribune:
http://www.atribune.org/ccount/click.php?id=1

Double-click ATF-Cleaner.exe to run the program.
Click 'Select All' found at the bottom of the list.
Click the 'Empty Selected' button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

If you use Opera browser,do this also:
Click Opera at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.
Click 'Exit' on the Main menu to close the program.


Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
'How to prevent Malware' by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users