Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Avg Picking Up Trojan Horse Lop.dn


  • Please log in to reply
8 replies to this topic

#1 chucker

chucker

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:21 AM

Posted 17 September 2007 - 01:30 PM

Over the last 2 days AVG has been picking up several Trojan Horse viruses. These are appearing in both system folders and private user folders which are all 5 characters long followed by .dll. Examples: pmkhi.dll , gebcc.dll , vtutr.dll , sstqr.dll etc etc . All the file sizes are 239Kb . All my antivirus software and windows updates are current and I am also running Spybot Search and Destroy and Ad-Aware SE Personal. I have quarantined all the files as they appear but not sure iif this is going to affect system stability as some of them are system32 files. They seem to be popping up in batches as quickly as I can delete / quarantine them. have run a Hijack This and attached the log . Any asistance would be greatfully appreaciated.

Attached Files



BC AdBot (Login to Remove)

 


m

#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:02:21 AM

Posted 18 September 2007 - 04:47 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum chucker :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u2'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java versions.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.


*NOTE*
If you have previously downloaded ComboFix,please delete that version and download it again from below.

Download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.

Also post a new Hijackthis log please.

*Note*
Post all reports/logs directly into this topic,not as attachments,thanks.
Posted Image
Posted Image

#3 chucker

chucker
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:21 AM

Posted 18 September 2007 - 12:58 PM

New HijackThis log with latest version:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:55:16, on 18/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\NEALJO~1\LOCALS~1\Temp\Temporary Directory 2 for HiJackThis.zip\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi...fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi...arch.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/?.home=msgr
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi...arch.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ioloDelayModule] C:\Program Files\iolo\System Mechanic 6\delay.exe
O4 - HKLM\..\Run: [btbb_McciTrayApp] C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1161006755078
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD...ap/PhtPkMSN.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.broadbandassist.com/bbdesktop/...tivePreQual.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 5924 bytes

#4 chucker

chucker
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:21 AM

Posted 18 September 2007 - 12:59 PM

log from ComboFix

ComboFix 07-09-18.4 - "Neal Johnson" 2007-09-18 18:28:09.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.216 [GMT 1:00]
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\Olly\Desktop\internet.lnk
C:\DOCUME~1\Sandra\Desktop\internet.lnk
C:\WINDOWS\system32\byxxxvv.dll
C:\WINDOWS\system32\gebyv.dll
C:\WINDOWS\system32\khfecca.dll
C:\WINDOWS\system32\rk.bin
C:\WINDOWS\wr.txt

.
((((((((((((((((((((((((( Files Created from 2007-08-18 to 2007-09-18 )))))))))))))))))))))))))))))))
.

2007-09-18 18:26 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-16 10:42 4,388 --a------ C:\WINDOWS\smflt.dll
2007-09-15 16:49 <DIR> d-------- C:\WINDOWS\PILSOUND
2007-09-15 16:40 <DIR> d-------- C:\PILSOUND
2007-09-12 17:02 <DIR> d-------- C:\04cf40ca5cd642c2565147b1ba

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-16 19:17 --------- d-------- C:\Program Files\EA GAMES
2007-09-16 09:04 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-09-16 09:04 --------- d-------- C:\Program Files\Auran
2007-09-15 19:04 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\BVRP Software
2007-09-15 18:40 --------- d-------- C:\Program Files\MSN Messenger
2007-09-12 20:12 --------- d-------- C:\DOCUME~1\Olly\APPLIC~1\V-Safe
2007-07-21 17:09 --------- d-------- C:\Program Files\Common Files\Motive
2007-07-20 17:30 --------- d-------- C:\DOCUME~1\Olly\APPLIC~1\Nikon
2007-07-18 10:29 --------- d-------- C:\Program Files\Common Files\ScanSoft Shared
2007-07-18 10:27 --------- d-------- C:\Program Files\AltoMP3 Gold
2007-06-15 13:10 7248 --a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\ypinfo.bin
2007-05-12 10:02 24192 --a------ C:\DOCUME~1\NEALJO~1\usbsermptxp.sys
2007-05-12 10:02 22768 --a------ C:\DOCUME~1\NEALJO~1\usbsermpt.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-09-13 15:59]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
"ioloDelayModule"="C:\Program Files\iolo\System Mechanic 6\delay.exe" [2005-06-08 13:31]
"btbb_McciTrayApp"="C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll,nViewLoadHook" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-12-20 12:38]
"eyeBeam SIP Client"="" []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableClock"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSetFolders"=0 (0x0)
"NoSetTaskbar"=0 (0x0)
"NoMultiIE"=0 (0x0)
"LWA"=0 (0x0)
"LWB"=0 (0x0)
"LWC"=0 (0x0)
"LWD"=0 (0x0)
"LWE"=0 (0x0)
"LWF"=0 (0x0)
"LWG"=0 (0x0)
"LWH"=0 (0x0)
"LWI"=0 (0x0)
"LWJ"=0 (0x0)
"LWK"=0 (0x0)
"LWL"=0 (0x0)
"LWM"=0 (0x0)
"LWN"=0 (0x0)
"LWO"=0 (0x0)
"LWP"=0 (0x0)
"LWQ"=0 (0x0)
"LWR"=0 (0x0)
"LWS"=0 (0x0)
"LWT"=0 (0x0)
"LWU"=0 (0x0)
"LWV"=0 (0x0)
"LWW"=0 (0x0)
"LWX"=0 (0x0)
"LWY"=0 (0x0)
"LWZ"=0 (0x0)

S3 BTNetFilter;Bluetooth Network Filter;\??\C:\WINDOWS\system32\drivers\BTNetFilter.sys
S3 DCamUSBPremier;V3780s Digital Camera;C:\WINDOWS\system32\Drivers\mpixvid.sys
S3 FreshIO;FreshIO;\??\C:\Program Files\FreshDevices\FreshDiagnose\FreshIO.sys
S3 GcKernel;Microsoft SideWinder Value Add - Filter Driver;C:\WINDOWS\system32\DRIVERS\GcKernel.sys
S3 HIDSwvd;Microsoft SideWinder Virtual HID Device Mini-Driver;C:\WINDOWS\system32\DRIVERS\HIDSwvd.sys
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-07-25 15:23:14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-18 18:43:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-18 18:46:11 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-18 18:45
.
--- E O F ---

#5 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:02:21 AM

Posted 18 September 2007 - 03:46 PM

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi...fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi...arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi...arch.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

Exit Hijackthis.

Start SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.


Please run this online virus scan:Activescan using Internet Explorer.
Once you are on the Panda site click the Scan your PC button
A new window will open...click the Check Now button
Enter your Country
Enter your State/Province
Enter your e-mail address and click send
Select either Home User or Company
Click the big Scan Now button
If it wants to install an ActiveX component allow it
It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
When download is complete, click on Local Disks to start the scan
When the scan completes,click the See Report button, then Save Report, and save it to your desktop.

Post the Activescan report into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.

Posted Image
Posted Image

#6 chucker

chucker
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:21 AM

Posted 19 September 2007 - 01:51 PM

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/19/2007 at 07:27 PM

Application Version : 3.9.1008

Core Rules Database Version : 3309
Trace Rules Database Version: 1314

Scan type : Complete Scan
Total Scan Time : 01:23:06

Memory items scanned : 364
Memory threats detected : 0
Registry items scanned : 6463
Registry threats detected : 0
File items scanned : 35498
File threats detected : 55

Adware.Tracking Cookie
C:\Documents and Settings\user1\Cookies\user1@new-pcp[1].txt
C:\Documents and Settings\user1\Cookies\user1@tribalfusion[1].txt
C:\Documents and Settings\user1\Cookies\user1@hitbox[2].txt
C:\Documents and Settings\user1\Cookies\user1@ehg-bbcworldwide.hitbox[1].txt
C:\Documents and Settings\user1\Cookies\user1@2o7[1].txt
C:\Documents and Settings\user1\Cookies\user1@1070548007[1].txt
C:\Documents and Settings\user1\Cookies\user1@tracking.summitmedia.co[1].txt
C:\Documents and Settings\user2\Cookies\user2@a.websponsors[2].txt
C:\Documents and Settings\user2\Cookies\user2@ad.accelerator-media[2].txt
C:\Documents and Settings\user2\Cookies\user2@ad.zanox[1].txt
C:\Documents and Settings\user2\Cookies\user2@adrevenue[2].txt
C:\Documents and Settings\user2\Cookies\user2@ads.ak.facebook[1].txt
C:\Documents and Settings\user2\Cookies\user2@ads.as4x.tmcs.ticketmaster[1].txt
C:\Documents and Settings\user2\Cookies\user2@anad.tacoda[2].txt
C:\Documents and Settings\user2\Cookies\user2@anat.tacoda[1].txt
C:\Documents and Settings\user2\Cookies\user2@mediauk[1].txt
C:\Documents and Settings\user2\Cookies\user2@monstersandcritics.advertserve[1].txt
C:\Documents and Settings\user2\Cookies\user2@track.searchignite[1].txt
C:\Documents and Settings\user2\Cookies\user2@vhost.oddcast[2].txt
C:\Documents and Settings\user2\Cookies\user2@vhost.oddcast[3].txt
C:\Documents and Settings\user2\Cookies\user2@xiti[1].txt
C:\Documents and Settings\user3\Cookies\user3@247realmedia[1].txt
C:\Documents and Settings\user3\Cookies\user3@3.adbrite[2].txt
C:\Documents and Settings\user3\Cookies\user3@ad.yieldmanager[1].txt
C:\Documents and Settings\user3\Cookies\user3@adbrite[2].txt
C:\Documents and Settings\user3\Cookies\user3@adecn[2].txt
C:\Documents and Settings\user3\Cookies\user3@adopt.euroclick[2].txt
C:\Documents and Settings\user3\Cookies\user3@adrevenue[2].txt
C:\Documents and Settings\user3\Cookies\user3@advertising[1].txt
C:\Documents and Settings\user3\Cookies\user3@atdmt[2].txt
C:\Documents and Settings\user3\Cookies\user3@bs.serving-sys[2].txt
C:\Documents and Settings\user3\Cookies\user3@carphonewarehouse.112.2o7[1].txt
C:\Documents and Settings\user3\Cookies\user3@casalemedia[1].txt
C:\Documents and Settings\user3\Cookies\user3@cz6.clickzs[2].txt
C:\Documents and Settings\user3\Cookies\user3@doubleclick[1].txt
C:\Documents and Settings\user3\Cookies\user3@fastclick[1].txt
C:\Documents and Settings\user3\Cookies\user3@haynet.adbureau[2].txt
C:\Documents and Settings\user3\Cookies\user3@ilead.itrack[1].txt
C:\Documents and Settings\user3\Cookies\user3@mediaplex[1].txt
C:\Documents and Settings\user3\Cookies\user3@optimost[2].txt
C:\Documents and Settings\user3\Cookies\user3@questionmarket[2].txt
C:\Documents and Settings\user3\Cookies\user3@serving-sys[1].txt
C:\Documents and Settings\user3\Cookies\user3@stats.channel4[1].txt
C:\Documents and Settings\user3\Cookies\user3@tracking.summitmedia.co[1].txt
C:\Documents and Settings\user3\Cookies\user3@tradedoubler[2].txt
C:\Documents and Settings\user3\Cookies\user3@tribalfusion[1].txt
C:\Documents and Settings\user3\Cookies\user3@virginmedia[2].txt
C:\Documents and Settings\user3\Cookies\user3@www.ppctracking[1].txt
C:\Documents and Settings\user3\Cookies\user3@www.virginmedia[2].txt
C:\Documents and Settings\user3\Cookies\user3@zedo[1].txt
C:\Documents and Settings\user4\Cookies\user4@adv.webmd[1].txt
C:\Documents and Settings\user4\Cookies\user4@eas.apm.emediate[2].txt
C:\Documents and Settings\user4\Cookies\user4@tracking.summitmedia.co[1].txt
C:\Documents and Settings\user4\Cookies\user4@www3.addfreestats[1].txt

Trojan.XDUD
C:\WINDOWS\SYSTEM32\FK.DLL

#7 chucker

chucker
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:21 AM

Posted 19 September 2007 - 05:17 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:15:16, on 19/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\DOCUME~1\NEALJO~1\LOCALS~1\Temp\Temporary Directory 4 for HiJackThis.zip\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/?.home=msgr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ioloDelayModule] C:\Program Files\iolo\System Mechanic 6\delay.exe
O4 - HKLM\..\Run: [btbb_McciTrayApp] C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1161006755078
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppD...ap/PhtPkMSN.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.broadbandassist.com/bbdesktop/...tivePreQual.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 5555 bytes

#8 chucker

chucker
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:02:21 AM

Posted 19 September 2007 - 05:18 PM

Incident Status Location

Adware:adware/cws Not disinfected C:\Documents and Settings\Neal Johnson\Favorites\Health
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\Ashley\Cookies\ashley@anm.co[1].txt
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Neal Johnson\Desktop\ComboFix.exe[nircmd.exe]
Virus:Trj/WmaDownloader.E Disinfected C:\Documents and Settings\Neal Johnson\Shared\Top of Charts - 2003.wma
Spyware:Cookie/Adviva Not disinfected C:\Documents and Settings\Olly\Cookies\olly@adviva[1].txt
Spyware:Spyware/Virtumonde Not disinfected C:\qoobox\Quarantine\C\WINDOWS\system32\khfecca.dll.vir
Spyware:Spyware/MarketScore Not disinfected C:\qoobox\Quarantine\C\WINDOWS\system32\rk.bin.vir
Spyware:Spyware/Virtumonde Not disinfected C:\qoobox\Quarantine\catchme2007-09-18_184348.53.zip[byxxxvv.dll]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\NirCmd.exe

#9 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:02:21 AM

Posted 19 September 2007 - 05:33 PM

Your log is clean :thumbsup:
If all's ok,please do the following.
Find and delete:
Combofix.exe
C:\qoobox
C:\Documents and Settings\Neal Johnson\Favorites\Health

Clean out your temporary internet files:
Close all open windows before you start.
Go to Start>Control Panel>Internet Options>General tab.
Click the Delete Cookies button.
Next to it, click the Delete Files button.
When prompted, place a check in: 'Delete all offline content', click OK

If you have Firefox installed,you need to clean out these temporary files as well:
Go to Tools>Options.
Click Privacy.
Press the Clear button located to the right of each option (History, Cookies, Cache).
Click OK to finish, before closing it.
Alternatively, you can clear all information stored while browsing by clicking Clear All.
A confirmation dialog box will be shown before clearing the information.

Now clean other temporary files and your Recycle Bin:
Go to Start>Run,type: cleanmgr then press OK.
Let it scan your system for files to remove.
Make sure 'Temporary Files', 'Temporary Internet Files', and 'Recycle Bin' are the only things checked.
Press OK to remove them.

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
'How to prevent Malware' by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users