Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan Vundo (cant Remove)


  • This topic is locked This topic is locked
11 replies to this topic

#1 Lukepd

Lukepd

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:49 AM

Posted 21 February 2008 - 06:58 AM

Trojan vundo keeps making its way back onto my computer here is my hijackthis log.

I have tried VundoFix.exe and VirtumundoBeGone.exe

both found files and removed files but they come back

norton has picked it up and "removed" it more than once as well

norton also sometimes will pick up and "remove" a virus called downloader

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:55:05 PM, on 21/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 7054 bytes

BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:49 PM

Posted 21 February 2008 - 01:17 PM

Hello Lukepd,

We will run ComboFix.

You need to disable your Symnatec/Norton Antivirus before running ComboFix, as it will prevent it from running.


To disable Norton Antivirus:
Please navigate to the system tray on the bottom right hand corner and look for a Posted Image sign.
  • right-click it -> chose "Disable Auto-Protect."
  • select a duration of 5 hours (this assures no interference with the cleanup of your pc)
  • click "Ok."
  • a popup will warn that protection will now be disabled and the sign will now look like this: Posted Image
You succesfully disabled the Norton Antivirus Guard.



Please visit this webpage for instructions for downloading and running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Be sure to install the Windows XP Recovery Console in case you have not installed it yet. <== IMPORTANT

Post the ComboFix log.

Edited by SifuMike, 21 February 2008 - 01:17 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 Lukepd

Lukepd
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:49 AM

Posted 21 February 2008 - 09:26 PM

ComboFix 08-02-22 - Luke 2008-02-22 13:00:52.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1587 [GMT 11:00]
Running from: C:\Documents and Settings\Luke\My Documents\Downloads\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\qtstv.ini
C:\WINDOWS\system32\qtstv.ini2

.
((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.

2008-02-22 12:41 . 2008-02-22 12:41 <DIR> d-------- C:\Program Files\Date Cracker 2000
2008-02-22 12:41 . 2008-02-22 12:41 249,856 --------- C:\WINDOWS\Setup1.exe
2008-02-22 12:41 . 2008-02-22 12:41 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2008-02-17 13:01 . 2006-11-15 11:29 1,712,128 --a------ C:\WINDOWS\system32\GDIPLUS.DLL
2008-02-17 13:01 . 2003-04-21 16:11 1,230,336 --a------ C:\WINDOWS\system32\msxml4.dll
2008-02-17 13:01 . 2005-07-12 14:25 401,408 --a------ C:\WINDOWS\system32\pvmjpg30.dll
2008-02-17 13:01 . 2003-04-21 16:11 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2008-02-17 13:01 . 2003-04-21 16:11 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-02-17 12:56 . 2008-02-17 12:57 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-02-17 12:56 . 2004-07-02 17:28 84,992 --a------ C:\WINDOWS\system32\ATL70.DLL
2008-02-17 12:55 . 2007-01-26 02:04 196,096 --a------ C:\WINDOWS\system32\macd32.dll
2008-02-17 12:55 . 2007-01-26 02:04 138,752 --a------ C:\WINDOWS\system32\mase32.dll
2008-02-17 12:55 . 2007-01-26 02:04 136,192 --a------ C:\WINDOWS\system32\mamc32.dll
2008-02-17 12:55 . 2007-01-26 02:04 57,856 --a------ C:\WINDOWS\system32\masd32.dll
2008-02-17 12:55 . 2007-01-26 02:04 27,648 --a------ C:\WINDOWS\system32\ma32.dll
2008-02-17 12:52 . 2008-02-17 13:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
2008-02-17 12:49 . 2008-02-17 13:00 <DIR> d-------- C:\Program Files\Pinnacle
2008-02-17 12:49 . 2008-02-17 13:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle
2008-02-17 12:45 . 2008-02-17 12:45 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\InstallShield
2008-02-16 19:40 . 2008-02-16 19:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LightScribe
2008-02-16 17:19 . 2004-08-03 22:41 1,041,536 --a------ C:\WINDOWS\system32\drivers\HSFDPSP2.sys
2008-02-16 17:19 . 2004-08-03 22:41 1,041,536 --a--c--- C:\WINDOWS\system32\dllcache\hsfdpsp2.sys
2008-02-16 17:19 . 2004-08-03 22:41 685,056 --a------ C:\WINDOWS\system32\drivers\HSFCXTS2.sys
2008-02-16 17:19 . 2004-08-03 22:41 685,056 --a--c--- C:\WINDOWS\system32\dllcache\hsfcxts2.sys
2008-02-16 17:19 . 2004-08-03 22:41 220,032 --a------ C:\WINDOWS\system32\drivers\HSFBS2S2.sys
2008-02-16 17:19 . 2004-08-03 22:41 220,032 --a--c--- C:\WINDOWS\system32\dllcache\hsfbs2s2.sys
2008-02-16 17:19 . 2004-07-17 22:55 129,045 --a------ C:\WINDOWS\system32\drivers\cxthsfS2.cty
2008-02-16 17:19 . 2004-08-04 00:56 86,016 --a------ C:\WINDOWS\system32\mdmxsdk.dll
2008-02-16 17:19 . 2004-08-04 00:56 32,285 --a------ C:\WINDOWS\system32\HSFCISP2.dll
2008-02-16 17:19 . 2004-08-04 00:56 32,285 --a--c--- C:\WINDOWS\system32\dllcache\hsfcisp2.dll
2008-02-16 17:19 . 2004-08-03 22:41 11,868 --a------ C:\WINDOWS\system32\drivers\mdmxsdk.sys
2008-02-15 21:50 . 2008-02-17 03:11 <DIR> d-------- C:\Program Files\World of Warcraft
2008-02-15 21:50 . 2008-02-15 21:50 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-02-15 20:19 . 2008-02-15 20:19 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-15 19:15 . 2008-02-15 19:15 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-02-14 12:58 . 2008-02-21 22:32 <DIR> d-------- C:\VundoFix Backups
2008-02-13 21:44 . 2008-02-13 21:44 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-13 17:13 . 2008-02-13 19:54 620 --a------ C:\WINDOWS\eReg.dat
2008-02-13 17:02 . 2008-02-13 19:42 <DIR> d-------- C:\Program Files\EA Games
2008-02-13 15:40 . 2008-02-13 15:40 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\InstallShield Installation Information
2008-02-13 15:24 . 2008-02-13 15:24 <DIR> d-------- C:\Program Files\Unreal Tournament 3
2008-02-13 15:09 . 2008-02-13 15:10 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-02-13 01:23 . 2008-02-13 01:23 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-13 01:23 . 2008-02-13 15:09 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-13 01:23 . 2008-02-13 01:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-12 21:56 . 2008-02-12 23:16 1,074 ---hs---- C:\WINDOWS\system32\naytqhvt.ini
2008-02-12 15:52 . 2008-02-12 16:03 894 ---hs---- C:\WINDOWS\system32\auxtsore.ini
2008-02-09 22:41 . 2008-02-09 22:41 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-02-09 22:41 . 2003-12-21 17:24 140,800 --a------ C:\WINDOWS\system32\drivers\xmasbus.sys
2008-02-09 22:41 . 2003-12-23 02:15 5,248 --a------ C:\WINDOWS\system32\drivers\xmasscsi.sys
2008-02-09 22:37 . 2008-02-10 00:17 147 --a------ C:\WINDOWS\wininit.ini
2008-02-09 18:40 . 2008-02-10 21:06 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-09 18:40 . 2008-02-10 21:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-09 16:38 . 2008-02-12 15:48 774 ---hs---- C:\WINDOWS\system32\pdrusspj.ini
2008-02-08 23:19 . 2008-02-16 21:29 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-02-08 23:01 . 2008-02-08 23:19 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-02-08 23:00 . 2008-02-08 23:19 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-02-08 23:00 . 2008-02-08 23:00 <DIR> d-------- C:\Program Files\Zone Labs
2008-02-08 21:14 . 2008-02-08 21:14 38,400 --a------ C:\WINDOWS\system32\urqqnnl.dll.vir
2008-02-08 21:08 . 2008-02-08 21:08 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-02-08 21:07 . 2008-02-08 21:08 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-02-08 20:59 . 2008-02-08 20:59 368 --a------ C:\WINDOWS\photohse.INI
2008-02-08 20:47 . 2008-02-08 20:47 <DIR> d-------- C:\Program Files\Borland
2008-02-08 20:46 . 2008-02-08 20:46 <DIR> d-------- C:\WINDOWS\COREL
2008-02-08 20:46 . 1997-07-17 16:54 133,904 --a------ C:\WINDOWS\system32\mfcans32.dll
2008-02-08 20:46 . 1997-07-17 16:54 108,032 --a------ C:\WINDOWS\system32\mfcuia32.dll
2008-02-08 16:52 . 2008-02-08 16:52 <DIR> d-------- C:\Program Files\uTorrent
2008-02-08 16:52 . 2008-02-22 03:58 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\uTorrent
2008-02-08 16:42 . 2008-02-22 03:27 <DIR> d-------- C:\Program Files\VstPlugins
2008-02-08 16:42 . 2002-07-08 09:14 1,294,336 --a------ C:\WINDOWS\system32\vorbis.acm
2008-02-08 16:42 . 2005-04-13 02:21 225,280 --a------ C:\WINDOWS\system32\rewire.dll
2008-02-08 16:41 . 2008-02-22 03:27 <DIR> d-------- C:\Program Files\Image-Line
2008-02-07 18:13 . 2008-02-21 01:03 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-02-07 17:49 . 2008-02-07 17:49 <DIR> d-------- C:\Program Files\DVD Decrypter
2008-02-07 16:27 . 2008-01-12 18:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-02-07 16:27 . 2008-01-15 09:54 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-02-07 16:27 . 2008-01-15 05:28 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-02-06 14:22 . 2008-02-06 14:22 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-02-05 16:47 . 2008-02-05 16:38 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-02-05 16:15 . 2008-02-05 16:15 <DIR> d-------- C:\Program Files\Rockstar Games
2008-02-05 13:45 . 2008-02-05 13:45 <DIR> d-------- C:\Program Files\Avanquest update
2008-02-05 13:45 . 2003-12-26 13:22 24,192 -ra------ C:\WINDOWS\system32\drivers\OLD137.tmp
2008-02-05 13:44 . 2008-02-05 13:45 <DIR> d-------- C:\Program Files\Motorola Phone Tools
2008-02-05 13:44 . 2008-02-05 13:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-02-05 13:44 . 2008-02-05 13:44 92,064 --a------ C:\Documents and Settings\Luke\mqdmmdm.sys
2008-02-05 13:44 . 2008-02-05 13:44 79,328 --a------ C:\Documents and Settings\Luke\mqdmserd.sys
2008-02-05 13:44 . 2008-02-05 13:44 66,656 --a------ C:\Documents and Settings\Luke\mqdmbus.sys
2008-02-05 13:44 . 2008-02-05 13:44 25,600 --a------ C:\WINDOWS\system32\drivers\usbsermptxp.sys
2008-02-05 13:44 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-02-05 13:44 . 2004-08-03 23:08 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-02-05 13:44 . 2008-02-05 13:44 25,600 --a------ C:\Documents and Settings\Luke\usbsermptxp.sys
2008-02-05 13:44 . 2008-02-05 13:44 22,768 --a------ C:\Documents and Settings\Luke\usbsermpt.sys
2008-02-05 13:44 . 2008-02-05 13:44 9,232 --a------ C:\Documents and Settings\Luke\mqdmmdfl.sys
2008-02-05 13:44 . 2008-02-05 13:44 6,208 --a------ C:\Documents and Settings\Luke\mqdmcmnt.sys
2008-02-05 13:44 . 2008-02-05 13:44 5,936 --a------ C:\Documents and Settings\Luke\mqdmwhnt.sys
2008-02-05 13:44 . 2008-02-05 13:44 4,048 --a------ C:\Documents and Settings\Luke\mqdmcr.sys
2008-02-05 12:57 . 2008-02-06 13:01 <DIR> d-------- C:\Documents and Settings\Luke\Contacts
2008-02-05 12:25 . 2008-02-05 12:25 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-02-05 12:24 . 2008-02-05 12:24 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-02-05 12:24 . 2008-02-05 12:24 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-13 06:15 12,464 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2008-02-02 00:32 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-14 00:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23:00 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 18:05 143360]
"LaunchList"="C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 15:41 145496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-11-07 10:00 8523776]
"nwiz"="nwiz.exe" [2007-11-07 10:00 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-11-07 10:00 81920]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 19:08 16380416 C:\WINDOWS\RTHDCPL.exe]
"JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 17:36 36864]
"36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [2007-03-28 18:25 1953792]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 10:04 84640]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-06 04:22 26248]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 23:00 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-19 12:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\b466176c]
C:\WINDOWS\system32\ainhmglt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 01:06 1667584 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe

R0 xmasbus;xmasbus;C:\WINDOWS\system32\DRIVERS\xmasbus.sys [2003-12-21 17:24]
R0 xmasscsi;xmasscsi;C:\WINDOWS\system32\Drivers\xmasscsi.sys [2003-12-23 02:15]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-15 09:00:19 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Luke.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-22 13:01:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-22 13:01:58
ComboFix-quarantined-files.txt 2008-02-22 02:01:56

#4 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:49 PM

Posted 21 February 2008 - 09:43 PM

Lukepd,

Running from: C:\Documents and Settings\Luke\My Documents\Downloads\ComboFix.exe



I see you did not follow the directions in the instructions for downloading and running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix :thumbsup:

You were supposed to download and run ComboFix from the Desktop and no where else.

Delete the version of ComboFix you just ran, as it is useless.

Then go here http://www.bleepingcomputer.com/combofix/how-to-use-combofix and follow the directions. Post a fresh ComboFix log.

Edited by SifuMike, 21 February 2008 - 09:44 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 Lukepd

Lukepd
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:49 AM

Posted 21 February 2008 - 11:28 PM

sorry i thought they may have just been using the desktop as an example location :thumbsup:


ComboFix 08-02-22 - Luke 2008-02-22 15:24:48.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1573 [GMT 11:00]
Running from: C:\Documents and Settings\Luke\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.

2008-02-22 12:41 . 2008-02-22 12:41 <DIR> d-------- C:\Program Files\Date Cracker 2000
2008-02-22 12:41 . 2008-02-22 12:41 249,856 --------- C:\WINDOWS\Setup1.exe
2008-02-22 12:41 . 2008-02-22 12:41 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2008-02-17 13:01 . 2006-11-15 11:29 1,712,128 --a------ C:\WINDOWS\system32\GDIPLUS.DLL
2008-02-17 13:01 . 2003-04-21 16:11 1,230,336 --a------ C:\WINDOWS\system32\msxml4.dll
2008-02-17 13:01 . 2005-07-12 14:25 401,408 --a------ C:\WINDOWS\system32\pvmjpg30.dll
2008-02-17 13:01 . 2003-04-21 16:11 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2008-02-17 13:01 . 2003-04-21 16:11 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-02-17 12:56 . 2008-02-17 12:57 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-02-17 12:56 . 2004-07-02 17:28 84,992 --a------ C:\WINDOWS\system32\ATL70.DLL
2008-02-17 12:55 . 2007-01-26 02:04 196,096 --a------ C:\WINDOWS\system32\macd32.dll
2008-02-17 12:55 . 2007-01-26 02:04 138,752 --a------ C:\WINDOWS\system32\mase32.dll
2008-02-17 12:55 . 2007-01-26 02:04 136,192 --a------ C:\WINDOWS\system32\mamc32.dll
2008-02-17 12:55 . 2007-01-26 02:04 57,856 --a------ C:\WINDOWS\system32\masd32.dll
2008-02-17 12:55 . 2007-01-26 02:04 27,648 --a------ C:\WINDOWS\system32\ma32.dll
2008-02-17 12:52 . 2008-02-17 13:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
2008-02-17 12:49 . 2008-02-17 13:00 <DIR> d-------- C:\Program Files\Pinnacle
2008-02-17 12:49 . 2008-02-17 13:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle
2008-02-17 12:45 . 2008-02-17 12:45 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\InstallShield
2008-02-16 19:40 . 2008-02-16 19:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LightScribe
2008-02-16 17:19 . 2004-08-03 22:41 1,041,536 --a------ C:\WINDOWS\system32\drivers\HSFDPSP2.sys
2008-02-16 17:19 . 2004-08-03 22:41 1,041,536 --a--c--- C:\WINDOWS\system32\dllcache\hsfdpsp2.sys
2008-02-16 17:19 . 2004-08-03 22:41 685,056 --a------ C:\WINDOWS\system32\drivers\HSFCXTS2.sys
2008-02-16 17:19 . 2004-08-03 22:41 685,056 --a--c--- C:\WINDOWS\system32\dllcache\hsfcxts2.sys
2008-02-16 17:19 . 2004-08-03 22:41 220,032 --a------ C:\WINDOWS\system32\drivers\HSFBS2S2.sys
2008-02-16 17:19 . 2004-08-03 22:41 220,032 --a--c--- C:\WINDOWS\system32\dllcache\hsfbs2s2.sys
2008-02-16 17:19 . 2004-07-17 22:55 129,045 --a------ C:\WINDOWS\system32\drivers\cxthsfS2.cty
2008-02-16 17:19 . 2004-08-04 00:56 86,016 --a------ C:\WINDOWS\system32\mdmxsdk.dll
2008-02-16 17:19 . 2004-08-04 00:56 32,285 --a------ C:\WINDOWS\system32\HSFCISP2.dll
2008-02-16 17:19 . 2004-08-04 00:56 32,285 --a--c--- C:\WINDOWS\system32\dllcache\hsfcisp2.dll
2008-02-16 17:19 . 2004-08-03 22:41 11,868 --a------ C:\WINDOWS\system32\drivers\mdmxsdk.sys
2008-02-15 21:50 . 2008-02-17 03:11 <DIR> d-------- C:\Program Files\World of Warcraft
2008-02-15 21:50 . 2008-02-15 21:50 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-02-15 20:19 . 2008-02-15 20:19 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-15 19:15 . 2008-02-15 19:15 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-02-14 12:58 . 2008-02-21 22:32 <DIR> d-------- C:\VundoFix Backups
2008-02-13 21:44 . 2008-02-13 21:44 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-13 17:13 . 2008-02-13 19:54 620 --a------ C:\WINDOWS\eReg.dat
2008-02-13 17:02 . 2008-02-13 19:42 <DIR> d-------- C:\Program Files\EA Games
2008-02-13 15:40 . 2008-02-13 15:40 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\InstallShield Installation Information
2008-02-13 15:24 . 2008-02-13 15:24 <DIR> d-------- C:\Program Files\Unreal Tournament 3
2008-02-13 15:09 . 2008-02-13 15:10 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-02-13 01:23 . 2008-02-13 01:23 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-13 01:23 . 2008-02-13 15:09 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-13 01:23 . 2008-02-13 01:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-12 21:56 . 2008-02-12 23:16 1,074 ---hs---- C:\WINDOWS\system32\naytqhvt.ini
2008-02-12 15:52 . 2008-02-12 16:03 894 ---hs---- C:\WINDOWS\system32\auxtsore.ini
2008-02-09 22:41 . 2008-02-09 22:41 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-02-09 22:41 . 2003-12-21 17:24 140,800 --a------ C:\WINDOWS\system32\drivers\xmasbus.sys
2008-02-09 22:41 . 2003-12-23 02:15 5,248 --a------ C:\WINDOWS\system32\drivers\xmasscsi.sys
2008-02-09 22:37 . 2008-02-10 00:17 147 --a------ C:\WINDOWS\wininit.ini
2008-02-09 18:40 . 2008-02-10 21:06 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-09 18:40 . 2008-02-10 21:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-09 16:38 . 2008-02-12 15:48 774 ---hs---- C:\WINDOWS\system32\pdrusspj.ini
2008-02-08 23:19 . 2008-02-16 21:29 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-02-08 23:01 . 2008-02-08 23:19 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-02-08 23:00 . 2008-02-08 23:19 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-02-08 23:00 . 2008-02-08 23:00 <DIR> d-------- C:\Program Files\Zone Labs
2008-02-08 21:14 . 2008-02-08 21:14 38,400 --a------ C:\WINDOWS\system32\urqqnnl.dll.vir
2008-02-08 21:08 . 2008-02-08 21:08 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-02-08 21:07 . 2008-02-08 21:08 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-02-08 20:59 . 2008-02-08 20:59 368 --a------ C:\WINDOWS\photohse.INI
2008-02-08 20:47 . 2008-02-08 20:47 <DIR> d-------- C:\Program Files\Borland
2008-02-08 20:46 . 2008-02-08 20:46 <DIR> d-------- C:\WINDOWS\COREL
2008-02-08 20:46 . 1997-07-17 16:54 133,904 --a------ C:\WINDOWS\system32\mfcans32.dll
2008-02-08 20:46 . 1997-07-17 16:54 108,032 --a------ C:\WINDOWS\system32\mfcuia32.dll
2008-02-08 16:52 . 2008-02-08 16:52 <DIR> d-------- C:\Program Files\uTorrent
2008-02-08 16:52 . 2008-02-22 03:58 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\uTorrent
2008-02-08 16:42 . 2008-02-22 03:27 <DIR> d-------- C:\Program Files\VstPlugins
2008-02-08 16:42 . 2002-07-08 09:14 1,294,336 --a------ C:\WINDOWS\system32\vorbis.acm
2008-02-08 16:42 . 2005-04-13 02:21 225,280 --a------ C:\WINDOWS\system32\rewire.dll
2008-02-08 16:41 . 2008-02-22 03:27 <DIR> d-------- C:\Program Files\Image-Line
2008-02-07 18:13 . 2008-02-21 01:03 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-02-07 17:49 . 2008-02-07 17:49 <DIR> d-------- C:\Program Files\DVD Decrypter
2008-02-07 16:27 . 2008-01-12 18:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-02-07 16:27 . 2008-01-15 09:54 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-02-07 16:27 . 2008-01-15 05:28 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-02-06 14:22 . 2008-02-06 14:22 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-02-05 16:47 . 2008-02-05 16:38 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-02-05 16:15 . 2008-02-05 16:15 <DIR> d-------- C:\Program Files\Rockstar Games
2008-02-05 13:45 . 2008-02-05 13:45 <DIR> d-------- C:\Program Files\Avanquest update
2008-02-05 13:45 . 2003-12-26 13:22 24,192 -ra------ C:\WINDOWS\system32\drivers\OLD137.tmp
2008-02-05 13:44 . 2008-02-05 13:45 <DIR> d-------- C:\Program Files\Motorola Phone Tools
2008-02-05 13:44 . 2008-02-05 13:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-02-05 13:44 . 2008-02-05 13:44 92,064 --a------ C:\Documents and Settings\Luke\mqdmmdm.sys
2008-02-05 13:44 . 2008-02-05 13:44 79,328 --a------ C:\Documents and Settings\Luke\mqdmserd.sys
2008-02-05 13:44 . 2008-02-05 13:44 66,656 --a------ C:\Documents and Settings\Luke\mqdmbus.sys
2008-02-05 13:44 . 2008-02-05 13:44 25,600 --a------ C:\WINDOWS\system32\drivers\usbsermptxp.sys
2008-02-05 13:44 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-02-05 13:44 . 2004-08-03 23:08 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-02-05 13:44 . 2008-02-05 13:44 25,600 --a------ C:\Documents and Settings\Luke\usbsermptxp.sys
2008-02-05 13:44 . 2008-02-05 13:44 22,768 --a------ C:\Documents and Settings\Luke\usbsermpt.sys
2008-02-05 13:44 . 2008-02-05 13:44 9,232 --a------ C:\Documents and Settings\Luke\mqdmmdfl.sys
2008-02-05 13:44 . 2008-02-05 13:44 6,208 --a------ C:\Documents and Settings\Luke\mqdmcmnt.sys
2008-02-05 13:44 . 2008-02-05 13:44 5,936 --a------ C:\Documents and Settings\Luke\mqdmwhnt.sys
2008-02-05 13:44 . 2008-02-05 13:44 4,048 --a------ C:\Documents and Settings\Luke\mqdmcr.sys
2008-02-05 12:57 . 2008-02-06 13:01 <DIR> d-------- C:\Documents and Settings\Luke\Contacts
2008-02-05 12:25 . 2008-02-05 12:25 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-02-05 12:24 . 2008-02-05 12:24 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-02-05 12:24 . 2008-02-05 12:24 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-13 06:15 12,464 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2008-02-02 00:32 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-14 00:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23:00 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 18:05 143360]
"LaunchList"="C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 15:41 145496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-11-07 10:00 8523776]
"nwiz"="nwiz.exe" [2007-11-07 10:00 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-11-07 10:00 81920]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 19:08 16380416 C:\WINDOWS\RTHDCPL.exe]
"JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 17:36 36864]
"36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [2007-03-28 18:25 1953792]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 10:04 84640]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-06 04:22 26248]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 23:00 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-19 12:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\b466176c]
C:\WINDOWS\system32\ainhmglt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 01:06 1667584 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe

R0 xmasbus;xmasbus;C:\WINDOWS\system32\DRIVERS\xmasbus.sys [2003-12-21 17:24]
R0 xmasscsi;xmasscsi;C:\WINDOWS\system32\Drivers\xmasscsi.sys [2003-12-23 02:15]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-15 09:00:19 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Luke.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-22 15:26:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-22 15:26:22
ComboFix-quarantined-files.txt 2008-02-22 04:26:20
ComboFix2.txt 2008-02-22 02:01:58

#6 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:49 PM

Posted 22 February 2008 - 12:14 AM

sorry i thought they may have just been using the desktop as an example location


If you read the thread you would have seen this:

Click on the Save button and then when it asks you where to save it, make sure you save it directly to your Windows Desktop. An image showing this is below.


Edited by SifuMike, 22 February 2008 - 12:15 AM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:49 PM

Posted 22 February 2008 - 12:32 PM

Hello Lukepd,

Click Start, then Run and type Notepad and click OK.
Open notepad - don't use any other text editor than notepad or the script will fail.
Copy/paste the text in the code box below into notepad:

File:: 
C:\WINDOWS\system32\naytqhvt.ini
C:\WINDOWS\system32\auxtsore.ini
C:\WINDOWS\wininit.ini
C:\WINDOWS\system32\pdrusspj.ini
C:\WINDOWS\system32\urqqnnl.dll.vir
C:\WINDOWS\system32\ainhmglt.dll

Folder:: 
C:\VundoFix Backups

Registry:: 
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\b466176c]


Name the Notepad file CFScript.txt and Save it to your desktop.

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#8 Lukepd

Lukepd
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:49 AM

Posted 23 February 2008 - 02:58 AM

ComboFix 08-02-22 - Luke 2008-02-23 18:48:08.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1555 [GMT 11:00]
Running from: C:\Documents and Settings\Luke\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Luke\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\system32\ainhmglt.dll
C:\WINDOWS\system32\auxtsore.ini
C:\WINDOWS\system32\naytqhvt.ini
C:\WINDOWS\system32\pdrusspj.ini
C:\WINDOWS\system32\urqqnnl.dll.vir
C:\WINDOWS\wininit.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\VundoFix Backups
C:\VundoFix Backups\awvtu.dll.bad
C:\VundoFix Backups\awvvw.dll.bad
C:\VundoFix Backups\rqstv.ini.bad
C:\VundoFix Backups\rqstv.ini2.bad
C:\VundoFix Backups\stuelhhq.dll.bad
C:\VundoFix Backups\tlgmhnia.ini.bad
C:\VundoFix Backups\utvwa.ini.bad
C:\VundoFix Backups\utvwa.ini2.bad
C:\VundoFix Backups\vtsqr.dll.bad
C:\VundoFix Backups\wvvwa.ini.bad
C:\VundoFix Backups\wvvwa.ini2.bad
C:\WINDOWS\system32\auxtsore.ini
C:\WINDOWS\system32\naytqhvt.ini
C:\WINDOWS\system32\pdrusspj.ini
C:\WINDOWS\system32\urqqnnl.dll.vir
C:\WINDOWS\wininit.ini

.
((((((((((((((((((((((((( Files Created from 2008-01-23 to 2008-02-23 )))))))))))))))))))))))))))))))
.

2008-02-22 12:41 . 2008-02-22 12:41 <DIR> d-------- C:\Program Files\Date Cracker 2000
2008-02-22 12:41 . 2008-02-22 12:41 249,856 --------- C:\WINDOWS\Setup1.exe
2008-02-22 12:41 . 2008-02-22 12:41 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2008-02-17 13:01 . 2006-11-15 11:29 1,712,128 --a------ C:\WINDOWS\system32\GDIPLUS.DLL
2008-02-17 13:01 . 2003-04-21 16:11 1,230,336 --a------ C:\WINDOWS\system32\msxml4.dll
2008-02-17 13:01 . 2005-07-12 14:25 401,408 --a------ C:\WINDOWS\system32\pvmjpg30.dll
2008-02-17 13:01 . 2003-04-21 16:11 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2008-02-17 13:01 . 2003-04-21 16:11 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-02-17 12:56 . 2008-02-17 12:57 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-02-17 12:56 . 2004-07-02 17:28 84,992 --a------ C:\WINDOWS\system32\ATL70.DLL
2008-02-17 12:55 . 2007-01-26 02:04 196,096 --a------ C:\WINDOWS\system32\macd32.dll
2008-02-17 12:55 . 2007-01-26 02:04 138,752 --a------ C:\WINDOWS\system32\mase32.dll
2008-02-17 12:55 . 2007-01-26 02:04 136,192 --a------ C:\WINDOWS\system32\mamc32.dll
2008-02-17 12:55 . 2007-01-26 02:04 57,856 --a------ C:\WINDOWS\system32\masd32.dll
2008-02-17 12:55 . 2007-01-26 02:04 27,648 --a------ C:\WINDOWS\system32\ma32.dll
2008-02-17 12:52 . 2008-02-17 13:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
2008-02-17 12:49 . 2008-02-17 13:00 <DIR> d-------- C:\Program Files\Pinnacle
2008-02-17 12:49 . 2008-02-17 13:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle
2008-02-17 12:45 . 2008-02-17 12:45 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\InstallShield
2008-02-16 19:40 . 2008-02-16 19:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LightScribe
2008-02-16 17:19 . 2004-08-03 22:41 1,041,536 --a------ C:\WINDOWS\system32\drivers\HSFDPSP2.sys
2008-02-16 17:19 . 2004-08-03 22:41 1,041,536 --a--c--- C:\WINDOWS\system32\dllcache\hsfdpsp2.sys
2008-02-16 17:19 . 2004-08-03 22:41 685,056 --a------ C:\WINDOWS\system32\drivers\HSFCXTS2.sys
2008-02-16 17:19 . 2004-08-03 22:41 685,056 --a--c--- C:\WINDOWS\system32\dllcache\hsfcxts2.sys
2008-02-16 17:19 . 2004-08-03 22:41 220,032 --a------ C:\WINDOWS\system32\drivers\HSFBS2S2.sys
2008-02-16 17:19 . 2004-08-03 22:41 220,032 --a--c--- C:\WINDOWS\system32\dllcache\hsfbs2s2.sys
2008-02-16 17:19 . 2004-07-17 22:55 129,045 --a------ C:\WINDOWS\system32\drivers\cxthsfS2.cty
2008-02-16 17:19 . 2004-08-04 00:56 86,016 --a------ C:\WINDOWS\system32\mdmxsdk.dll
2008-02-16 17:19 . 2004-08-04 00:56 32,285 --a------ C:\WINDOWS\system32\HSFCISP2.dll
2008-02-16 17:19 . 2004-08-04 00:56 32,285 --a--c--- C:\WINDOWS\system32\dllcache\hsfcisp2.dll
2008-02-16 17:19 . 2004-08-03 22:41 11,868 --a------ C:\WINDOWS\system32\drivers\mdmxsdk.sys
2008-02-15 21:50 . 2008-02-17 03:11 <DIR> d-------- C:\Program Files\World of Warcraft
2008-02-15 21:50 . 2008-02-15 21:50 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-02-15 20:19 . 2008-02-15 20:19 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-15 19:15 . 2008-02-15 19:15 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-02-13 21:44 . 2008-02-13 21:44 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-13 17:13 . 2008-02-13 19:54 620 --a------ C:\WINDOWS\eReg.dat
2008-02-13 17:02 . 2008-02-13 19:42 <DIR> d-------- C:\Program Files\EA Games
2008-02-13 15:40 . 2008-02-13 15:40 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\InstallShield Installation Information
2008-02-13 15:24 . 2008-02-13 15:24 <DIR> d-------- C:\Program Files\Unreal Tournament 3
2008-02-13 15:09 . 2008-02-13 15:10 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-02-13 01:23 . 2008-02-13 01:23 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-13 01:23 . 2008-02-13 15:09 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-13 01:23 . 2008-02-13 01:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-09 22:41 . 2008-02-09 22:41 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-02-09 22:41 . 2003-12-21 17:24 140,800 --a------ C:\WINDOWS\system32\drivers\xmasbus.sys
2008-02-09 22:41 . 2003-12-23 02:15 5,248 --a------ C:\WINDOWS\system32\drivers\xmasscsi.sys
2008-02-09 18:40 . 2008-02-10 21:06 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-09 18:40 . 2008-02-10 21:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-08 23:19 . 2008-02-16 21:29 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-02-08 23:01 . 2008-02-08 23:19 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-02-08 23:00 . 2008-02-08 23:19 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-02-08 23:00 . 2008-02-08 23:00 <DIR> d-------- C:\Program Files\Zone Labs
2008-02-08 21:08 . 2008-02-08 21:08 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-02-08 21:07 . 2008-02-08 21:08 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-02-08 20:59 . 2008-02-08 20:59 368 --a------ C:\WINDOWS\photohse.INI
2008-02-08 20:47 . 2008-02-08 20:47 <DIR> d-------- C:\Program Files\Borland
2008-02-08 20:46 . 2008-02-08 20:46 <DIR> d-------- C:\WINDOWS\COREL
2008-02-08 20:46 . 1997-07-17 16:54 133,904 --a------ C:\WINDOWS\system32\mfcans32.dll
2008-02-08 20:46 . 1997-07-17 16:54 108,032 --a------ C:\WINDOWS\system32\mfcuia32.dll
2008-02-08 16:52 . 2008-02-08 16:52 <DIR> d-------- C:\Program Files\uTorrent
2008-02-08 16:52 . 2008-02-22 03:58 <DIR> d-------- C:\Documents and Settings\Luke\Application Data\uTorrent
2008-02-08 16:42 . 2008-02-22 03:27 <DIR> d-------- C:\Program Files\VstPlugins
2008-02-08 16:42 . 2002-07-08 09:14 1,294,336 --a------ C:\WINDOWS\system32\vorbis.acm
2008-02-08 16:42 . 2005-04-13 02:21 225,280 --a------ C:\WINDOWS\system32\rewire.dll
2008-02-08 16:41 . 2008-02-22 03:27 <DIR> d-------- C:\Program Files\Image-Line
2008-02-07 18:13 . 2008-02-21 01:03 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-02-07 17:49 . 2008-02-07 17:49 <DIR> d-------- C:\Program Files\DVD Decrypter
2008-02-07 16:27 . 2008-01-12 18:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-02-07 16:27 . 2008-01-15 09:54 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-02-07 16:27 . 2008-01-15 05:28 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-02-06 14:22 . 2008-02-06 14:22 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-02-05 16:47 . 2008-02-05 16:38 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-02-05 16:15 . 2008-02-05 16:15 <DIR> d-------- C:\Program Files\Rockstar Games
2008-02-05 13:45 . 2008-02-05 13:45 <DIR> d-------- C:\Program Files\Avanquest update
2008-02-05 13:45 . 2003-12-26 13:22 24,192 -ra------ C:\WINDOWS\system32\drivers\OLD137.tmp
2008-02-05 13:44 . 2008-02-05 13:45 <DIR> d-------- C:\Program Files\Motorola Phone Tools
2008-02-05 13:44 . 2008-02-05 13:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-02-05 13:44 . 2008-02-05 13:44 92,064 --a------ C:\Documents and Settings\Luke\mqdmmdm.sys
2008-02-05 13:44 . 2008-02-05 13:44 79,328 --a------ C:\Documents and Settings\Luke\mqdmserd.sys
2008-02-05 13:44 . 2008-02-05 13:44 66,656 --a------ C:\Documents and Settings\Luke\mqdmbus.sys
2008-02-05 13:44 . 2008-02-05 13:44 25,600 --a------ C:\WINDOWS\system32\drivers\usbsermptxp.sys
2008-02-05 13:44 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-02-05 13:44 . 2004-08-03 23:08 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-02-05 13:44 . 2008-02-05 13:44 25,600 --a------ C:\Documents and Settings\Luke\usbsermptxp.sys
2008-02-05 13:44 . 2008-02-05 13:44 22,768 --a------ C:\Documents and Settings\Luke\usbsermpt.sys
2008-02-05 13:44 . 2008-02-05 13:44 9,232 --a------ C:\Documents and Settings\Luke\mqdmmdfl.sys
2008-02-05 13:44 . 2008-02-05 13:44 6,208 --a------ C:\Documents and Settings\Luke\mqdmcmnt.sys
2008-02-05 13:44 . 2008-02-05 13:44 5,936 --a------ C:\Documents and Settings\Luke\mqdmwhnt.sys
2008-02-05 13:44 . 2008-02-05 13:44 4,048 --a------ C:\Documents and Settings\Luke\mqdmcr.sys
2008-02-05 12:57 . 2008-02-06 13:01 <DIR> d-------- C:\Documents and Settings\Luke\Contacts
2008-02-05 12:25 . 2008-02-05 12:25 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-02-05 12:24 . 2008-02-05 12:24 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-02-05 12:24 . 2008-02-05 12:24 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-02-05 12:24 . 2008-02-05 12:25 <DIR> d-------- C:\Program Files\Project64 1.6
2008-02-05 11:32 . 2008-02-05 11:32 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-05 11:28 . 2008-02-06 14:22 <DIR> d-------- C:\Program Files\MSN Messenger
2008-02-05 01:53 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-02-05 01:39 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-02-05 01:39 . 2004-08-04 00:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-13 06:15 12,464 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2008-02-02 00:32 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-14 00:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23:00 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 18:05 143360]
"LaunchList"="C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 15:41 145496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-11-07 10:00 8523776]
"nwiz"="nwiz.exe" [2007-11-07 10:00 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-11-07 10:00 81920]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 19:08 16380416 C:\WINDOWS\RTHDCPL.exe]
"JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 17:36 36864]
"36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [2007-03-28 18:25 1953792]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 10:04 84640]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-06 04:22 26248]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 23:00 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-19 12:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 01:06 1667584 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe

R0 xmasbus;xmasbus;C:\WINDOWS\system32\DRIVERS\xmasbus.sys [2003-12-21 17:24]
R0 xmasscsi;xmasscsi;C:\WINDOWS\system32\Drivers\xmasscsi.sys [2003-12-23 02:15]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-22 09:56:51 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Luke.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-23 18:49:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-23 18:49:36
ComboFix-quarantined-files.txt 2008-02-23 07:49:34
ComboFix2.txt 2008-02-22 04:26:23
ComboFix3.txt 2008-02-22 02:01:58










Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:01:56 PM, on 23/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 6625 bytes

Edited by Lukepd, 23 February 2008 - 03:02 AM.


#9 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:49 PM

Posted 23 February 2008 - 12:35 PM

Hi Lukepd,

Your log looks clean! :thumbsup: Good job on the cleanup!


Uninstall ComboFix, go to to Start > Run & type in ComboFix /u
Make sure there's a space between Combofix and /
Then hit enter.

This will uninstall Combofix, delete any of its related folders and files (Qoobox
VundoFix Backups, Avenger, Deckard, _OTMoveIt), reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.


Please read and follow How did I get infected?, With steps so it does not happen again!
as well as
How to prevent Malware' by miekiemoes


If you want to improve speed/system performance after malware removal, take a look here.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#10 Lukepd

Lukepd
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:49 AM

Posted 24 February 2008 - 04:00 AM

awesome thank you so much!

#11 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:49 PM

Posted 24 February 2008 - 11:10 AM

Your very welcome. I hope you computer continues to run smoothly. :thumbsup:
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#12 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:49 PM

Posted 05 March 2008 - 02:52 PM

Since your problem appears to be resolved, this thread will now be closed. If you need this topic reopened, please contact me or a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users