Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Cooking Luck, Blackbird


  • Please log in to reply
28 replies to this topic

#1 Riyonuk

Riyonuk

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:11:57 PM

Posted 23 April 2008 - 04:23 PM

Desktop goes away, Task Manager is disabled, pop ups telling me I'm infected, here is the DSS

Deckard's System Scanner v20071014.68
Run by Administrator on 2008-04-23 16:21:38
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Administrator.exe) ---------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:21:58 PM, on 4/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
E:\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\mrofinu1535.exe
C:\WINDOWS\system32\drivers\spools.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\flciijjq.exe
E:\Firefox\firefox.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\W32BRG55.EXE
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\System32\svchost.exe
E:\mIRC\mirc.exe
E:\Winamp\winamp.exe
E:\Microsoft Office\Office12\WINWORD.EXE
C:\Documents and Settings\Administrator\Desktop\dss.exe
C:\DOCUME~1\ADMINI~1\Desktop\Administrator.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = Download Directory
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=104...amp;clcid=0x409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=104...amp;clcid=0x409
O2 - BHO: (no name) - {b5818f71-2218-4e29-9a21-77fe52fb6b5c} - C:\WINDOWS\system32\yayyWmMf.dll
O2 - BHO: C:\WINDOWS\system32\jfiehayd.dll - {c5af49a2-94f3-42bd-f434-2604812c897d} - C:\WINDOWS\system32\jfiehayd.dll
O2 - BHO: (no name) - {f50b3f5e-856e-4757-9bb1-b35d46ca7719} - C:\WINDOWS\system32\pmnmnOFy.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - E:\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: dpevflbg - {B4CE8035-501B-4750-9535-CE7F8B708A36} - C:\WINDOWS\dpevflbg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\system32\msconfig.exe /auto
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\Administrator\cftmon.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\Administrator\cftmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Append to existing PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nwprovau.dll' missing
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1194495320687
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{125D395A-533C-4AEE-8330-F045A481AFAD}: NameServer = 85.255.116.134,85.255.112.139
O17 - HKLM\System\CCS\Services\Tcpip\..\{A643A6B6-8682-4B64-83CD-2D74A424987F}: NameServer = 85.255.116.134,85.255.112.139
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB0ECA17-D45F-48DC-BC3E-976B76A5AADB}: NameServer = 85.255.116.134,85.255.112.139
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5209746-9966-43FB-B80C-133B6F8E6CF0}: NameServer = 85.255.116.134,85.255.112.139
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.134 85.255.112.139
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.134 85.255.112.139
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.116.134 85.255.112.139
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.134 85.255.112.139
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: ibudu - C:\WINDOWS\SYSTEM32\ibudu.dll
O20 - Winlogon Notify: pmnmnOFy - C:\WINDOWS\SYSTEM32\pmnmnOFy.dll
O21 - SSODL: wdpoefan - {21BB8D84-BC59-475F-AE3B-E6A7379E3040} - C:\WINDOWS\wdpoefan.dll
O21 - SSODL: vadokmxt - {27D3D1F5-FFAC-42C5-A249-1C4C3528B3DD} - C:\WINDOWS\vadokmxt.dll
O21 - SSODL: BootAvp - {ae4a823e-ac33-417b-9ce2-cd4300f7f36a} - C:\WINDOWS\Resources\BootAvp.dll
O22 - SharedTaskScheduler: jhsf8d984jief8dsfus98jkefn - {C5AF49A2-94F3-42BD-F434-2604812C897D} - C:\WINDOWS\system32\jfiehayd.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: wampapache - Apache Software Foundation - c:\WAMP\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\WAMP\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe

--
End of file - 8504 bytes

-- Files created between 2008-03-23 and 2008-04-23 -----------------------------

2008-04-23 16:12:35 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-23 16:07:17 0 d-------- C:\WINDOWS\privacy_danger
2008-04-23 15:51:36 0 d-------- C:\Program Files\AVG
2008-04-23 13:02:20 16464 -r-hs---- C:\Program Files\tmp3.exe
2008-04-23 13:02:15 16464 -r-hs---- C:\Program Files\tmp2.exe
2008-04-23 13:02:10 16464 -r-hs---- C:\Program Files\tmp1.exe
2008-04-23 13:02:05 0 d-------- C:\WINDOWS\system32\382077
2008-04-23 13:02:05 16464 -r-hs---- C:\Program Files\tmp0.exe
2008-04-23 13:02:05 21588 --a------ C:\Program Files\antiviirus.exe
2008-04-23 08:42:00 0 d-------- C:\Documents and Settings\Administrator\Application Data\TmpRecentIcons
2008-04-23 08:39:50 2560 --a------ C:\WINDOWS\system32\itcoe.sys
2008-04-23 08:39:50 6672 --a------ C:\WINDOWS\system32\ibudu.dll
2008-04-23 07:35:07 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-23 07:07:38 365148 --ahs---- C:\WINDOWS\system32\fMmWyyay.ini2
2008-04-23 07:07:33 272384 --a------ C:\WINDOWS\system32\yayyWmMf.dll
2008-04-23 07:04:05 346112 --a------ C:\WINDOWS\system32\hgghgda.dll
2008-04-23 07:03:57 61952 --a------ C:\WINDOWS\system32\flciijjq.exe
2008-04-23 07:03:35 37888 --a------ C:\WINDOWS\system32\byXRhEUM.dll
2008-04-23 07:02:49 346112 --a------ C:\WINDOWS\system32\efccawu.dll
2008-04-23 07:02:37 0 d-------- C:\Program Files\Helper
2008-04-23 07:02:36 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-04-23 07:02:30 37888 --a------ C:\WINDOWS\system32\nnnnKCvs.dll
2008-04-23 07:02:26 4096 --a------ C:\WINDOWS\userconfig9x.dll
2008-04-23 07:02:26 4096 --a------ C:\WINDOWS\system32\winlogonpc.exe
2008-04-23 07:02:26 4096 --a------ C:\WINDOWS\FVProtect.exe
2008-04-23 07:02:25 81920 --a------ C:\WINDOWS\wxvgsdbq.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\winsystem.exe
2008-04-23 07:02:25 212992 --a------ C:\WINDOWS\wdpoefan.dll
2008-04-23 07:02:25 167936 --a------ C:\WINDOWS\vadokmxt.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\WINWGPX.EXE
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\winsystem.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\vcatchpi.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\vbsys2.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\thun32.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\thun.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\temp#01.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\taack.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\taack.dat
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\sysreq.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\ssvchost.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\ssvchost.com
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\ssurf022.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\sncntr.exe
2008-04-23 07:02:25 0 d-------- C:\WINDOWS\system32\smp
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\Rundl1.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\regm64.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\regc64.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\psoft1.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\psof1.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\ps1.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\newsd32.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\netode.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\mwin32.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\mtr2.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\msvchost.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\mssecu.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\msnbho.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\msgp.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\medup020.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\medup012.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\hxiwlgpm.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\hxiwlgpm.dat
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\hoproxy.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\h@tkeysh@@k.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\emesx.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\dpcproxy.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\bsva-egihsg52.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\bdn.com
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\awtoolb.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\anticipator.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\system32\akttzn.exe
2008-04-23 07:02:25 212992 --a------ C:\WINDOWS\qnmargolanp.dll
2008-04-23 07:02:25 94208 --a------ C:\WINDOWS\olgdqarf.exe
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\mssecu.exe
2008-04-23 07:02:25 0 d-------- C:\WINDOWS\mslagent
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\iTunesMusic.exe
2008-04-23 07:02:25 151552 --a------ C:\WINDOWS\dpevflbg.dll
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\bdn.com
2008-04-23 07:02:25 4096 --a------ C:\WINDOWS\a.bat
2008-04-23 07:02:25 0 d-------- C:\Program Files\Inet Delivery
2008-04-23 07:02:25 0 d-------- C:\Program Files\akl
2008-04-23 07:02:11 98304 --a------ C:\WINDOWS\system32\vkfcbgzk.exe
2008-04-23 07:02:11 0 d-------- C:\Documents and Settings\All Users\Application Data\jsfqrivs
2008-04-23 07:02:04 37376 --a------ C:\WINDOWS\system32\yayaWOeb.dll
2008-04-23 07:01:59 10000 --a------ C:\WINDOWS\system32\jfiehayd.dll
2008-04-23 07:01:58 61874 --a------ C:\WINDOWS\ydhqzop.sys
2008-04-23 07:01:55 61952 --a------ C:\flciijjq.exe
2008-04-23 07:01:53 7168 --a------ C:\WINDOWS\system32\drivers\spools.exe
2008-04-23 07:01:53 13824 --a------ C:\Documents and Settings\Administrator\cftmon.exe
2008-04-23 07:01:42 37376 --a------ C:\WINDOWS\mrofinu1535.exe
2008-04-23 07:01:18 39936 --a------ C:\WINDOWS\system32\pmnmnOFy.dll
2008-04-22 22:28:25 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-04-21 20:30:57 0 d-------- C:\Documents and Settings\Administrator\Application Data\FileZilla
2008-04-21 17:25:56 0 d-------- C:\Documents and Settings\Administrator\Application Data\GlobalSCAPE
2008-04-20 16:42:18 0 d-------- C:\Documents and Settings\Administrator\Application Data\Inkscape
2008-04-15 15:51:54 0 d-------- C:\Documents and Settings\Administrator\Application Data\Opera
2008-03-29 11:53:26 0 d-------- C:\WAMP
2008-03-24 17:53:05 17240 --a------ C:\WINDOWS\sess_377edh790c7dt52h4jsvqglb46


-- Find3M Report ---------------------------------------------------------------

2008-04-23 16:12:35 0 d-------- C:\Program Files\Common Files
2008-04-23 16:05:16 0 d-------- C:\Documents and Settings\Administrator\Application Data\mIRC
2008-04-23 07:38:26 0 d-------- C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-04-22 22:36:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-04-22 06:57:31 0 d-------- C:\Program Files\Image-Line
2008-04-22 06:56:30 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-21 13:23:48 28068 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-04-20 19:08:47 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-04-13 22:48:59 0 d-------- C:\Documents and Settings\Administrator\Application Data\Winamp
2008-03-22 23:28:40 0 d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-03-17 20:26:50 0 d-------- C:\Program Files\vanBasco's Karaoke Player
2008-03-09 22:41:17 0 d-------- C:\Documents and Settings\Administrator\Application Data\Digsby
2008-03-09 22:38:16 0 d-------- C:\Program Files\WinDirStat
2008-03-09 11:12:41 0 d-------- C:\Program Files\ZyDAS Technology Corporation
2008-03-09 11:12:32 0 d-------- C:\Program Files\Datel
2008-03-03 18:15:54 0 d-------- C:\Documents and Settings\Administrator\Application Data\Skype
2008-03-02 17:02:35 0 d-------- C:\Documents and Settings\Administrator\Application Data\skypePM
2008-03-01 22:16:56 0 d-------- C:\Program Files\Yahoo!
2008-02-28 23:14:32 0 --a------ C:\Documents and Settings\Administrator\Application Data\.googlewebacchosts
2008-02-28 23:12:26 0 d-------- C:\Program Files\Google
2008-02-28 23:07:11 0 d-------- C:\Program Files\MagicISO
2008-02-27 22:54:20 0 d-------- C:\Documents and Settings\Administrator\Application Data\MySpace
2008-02-27 22:54:18 0 d-------- C:\Program Files\MySpace
2008-02-26 19:43:26 0 d-------- C:\Program Files\Movie Maker
2008-02-26 18:35:11 0 d-------- C:\Program Files\Common Files\Adobe
2008-02-26 18:33:11 0 d-------- C:\Program Files\Common Files\Control Panels
2008-02-26 18:14:55 0 d-------- C:\Program Files\QuickTime
2008-02-26 18:01:23 0 d-------- C:\Program Files\Bonjour
2008-02-25 21:10:09 1688 --a------ C:\WINDOWS\mozver.dat
2008-02-16 13:42:18 103437 --a------ C:\WINDOWS\hpqins13.dat
2008-02-14 20:06:23 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-02-13 08:57:52 149 --a------ C:\WINDOWS\system32\'
2008-02-10 21:05:25 233472 --a------ C:\WINDOWS\system32\REX Shared Library.dll <Not Verified; Propellerhead Software AB; REX SDK>
2008-02-10 21:05:25 368640 --a------ C:\WINDOWS\system32\ReWire.dll <Not Verified; Propellerhead Software AB; ReWire>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b5818f71-2218-4e29-9a21-77fe52fb6b5c}]
04/23/2008 07:07 AM 272384 --a------ C:\WINDOWS\system32\yayyWmMf.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af49a2-94f3-42bd-f434-2604812c897d}]
04/23/2008 07:01 AM 10000 --a------ C:\WINDOWS\system32\jfiehayd.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f50b3f5e-856e-4757-9bb1-b35d46ca7719}]
04/23/2008 07:01 AM 39936 --a------ C:\WINDOWS\system32\pmnmnOFy.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [08/23/2006 03:12 PM]
"nwiz"="nwiz.exe" [08/23/2006 03:12 PM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [08/23/2006 03:12 PM]
"SigmatelSysTrayApp"="stsystra.exe" [07/27/2006 03:19 PM C:\WINDOWS\stsystra.exe]
"MSConfig"="C:\WINDOWS\system32\msconfig.exe" [08/06/2006 07:00 AM]
"ntuser"="C:\WINDOWS\system32\drivers\spools.exe" [04/23/2008 07:02 AM]
"autoload"="C:\Documents and Settings\Administrator\cftmon.exe" [04/23/2008 07:01 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ntuser"="C:\WINDOWS\system32\drivers\spools.exe" [04/23/2008 07:02 AM]
"autoload"="C:\Documents and Settings\Administrator\cftmon.exe" [04/23/2008 07:01 AM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=1 (0x1)
"DisableTaskMgr"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"=1 (0x1)
"ForceClassicControlPanel"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"=1 (0x1)
"NoResolveTrack"=1 (0x1)
"LinkResolveIgnoreLinkInfo"=1 (0x1)
"NoResolveSearch"=1 (0x1)
"ClearRecentDocsOnExit"=1 (0x1)
"NoRecentDocsMenu"=1 (0x1)
"NoRecentDocsHistory"=1 (0x1)
"NoStartBanner"=1 (0x1)
"NoSMConfigurePrograms"=1 (0x1)
"NoInstrumentation"=1 (0x1)
"NoSMBalloonTip"=1 (0x1)
"NoFolderOptions"=1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"=1 (0x1)
"NoResolveTrack"=1 (0x1)
"LinkResolveIgnoreLinkInfo"=1 (0x1)
"NoResolveSearch"=1 (0x1)
"ClearRecentDocsOnExit"=1 (0x1)
"NoRecentDocsMenu"=1 (0x1)
"NoRecentDocsHistory"=1 (0x1)
"NoStartBanner"=1 (0x1)
"NoSMConfigurePrograms"=1 (0x1)
"NoInstrumentation"=1 (0x1)
"NoSMBalloonTip"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{C5AF49A2-94F3-42BD-F434-2604812C897D}"= C:\WINDOWS\system32\jfiehayd.dll [04/23/2008 07:01 AM 10000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{F50B3F5E-856E-4757-9BB1-B35D46CA7719}"= C:\WINDOWS\system32\pmnmnOFy.dll [04/23/2008 07:01 AM 39936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"wdpoefan"= {21BB8D84-BC59-475F-AE3B-E6A7379E3040} - C:\WINDOWS\wdpoefan.dll [04/23/2008 05:09 AM 212992]
"vadokmxt"= {27D3D1F5-FFAC-42C5-A249-1C4C3528B3DD} - C:\WINDOWS\vadokmxt.dll [04/23/2008 05:09 AM 167936]
"BootAvp"= {ae4a823e-ac33-417b-9ce2-cd4300f7f36a} - C:\WINDOWS\Resources\BootAvp.dll [04/23/2008 01:02 PM 14374]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="kdepr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ibudu]
ibudu.dll 04/23/2008 08:39 AM 6672 C:\WINDOWS\system32\ibudu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmnOFy]
pmnmnOFy.dll 04/23/2008 07:01 AM 39936 C:\WINDOWS\system32\pmnmnOFy.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\yayyWmMf

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^administrator^start menu^programs^startup^rklauncher.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\RKLauncher.lnk
backup=C:\WINDOWS\pss\RKLauncher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^administrator^start menu^programs^startup^yahoo! widgets.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Yahoo! Widgets.lnk
backup=C:\WINDOWS\pss\Yahoo! Widgets.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^zdwlan utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZDWLan Utility.lnk
backup=C:\WINDOWS\pss\ZDWLan Utility.lnkCommon Startup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acrobat assistant 8.0]
"E:\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adobe_id0eythm]
C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\autoload]
C:\Documents and Settings\Administrator\cftmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msvtt]
C:\WINDOWS\system32\flciijjq.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntuser]
C:\WINDOWS\system32\drivers\spools.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\registrymechanic]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1535.exe 61A847B5BBF7281337983D466188719AB689201522886B092CBD44BD8689220221DD3257

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinVNC]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yahoo! pager]
"E:\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService LmHosts upnphost SSDPSRV
NetworkService
DcomLaunch DcomLaunch


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3200db41-8161-11dc-a4a5-806d6172696f}]
AutoRun\command- G:\autoRcd.exe




-- End of Deckard's System Scanner: finished at 2008-04-23 16:22:41 ------------

BC AdBot (Login to Remove)

 


m

#2 Rahina

Rahina

    Security Helper


  • Members
  • 681 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:08:57 AM

Posted 23 April 2008 - 04:31 PM

One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

==============================================

Looking over your log, it seems you don't have any evidence of an anti-virus software.

Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network. Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these excellent vendors NOW:

1) Antivir PersonalEdition Classic- Free anti-virus software for Windows. Detects and removes more than 50,000 viruses. Free support.
2) avast! 4 Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
3) AVG Anti-Virus Free Edition - Free edition of the AVG anti-virus program for Windows.

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.

==============================================

Download Combofix from any of the links below, and save it to your desktop. For information regarding this download, please visit this webpage: http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Link 1
Link 2
Link 3

**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall



If there is something you did not understand, ask me!

Let me now the results.

Edited by Rahina Rescue, 23 April 2008 - 04:31 PM.

[ Antivirus ] [ Firewall ] [ Spywareblaster ] [ Malwarebytes Anti-Malware ] [ Windows update ] [ Firefox ] [ WinPatrol ] [ ATF Cleaner ]

If i have helped you, donate to help me continue helping others. Posted Image
Posted Image Posted Image

#3 Riyonuk

Riyonuk
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:11:57 PM

Posted 23 April 2008 - 10:34 PM

Ok, I installed AVG Free, and ran a scan after updating. 39 entries found! All were removed except 1, which I moved to the vault. I then ran Combox fix, but left Winamp open, as I needed to listen to music :thumbsup:

ComboFix 08-04-22.5 - Administrator 2008-04-23 22:28:31.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1442 [GMT -5:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Desktop\Error Cleaner.url
C:\Documents and Settings\Administrator\Desktop\Privacy Protector.url
C:\Documents and Settings\Administrator\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Administrator\Favorites\Error Cleaner.url
C:\Documents and Settings\Administrator\Favorites\Privacy Protector.url
C:\Documents and Settings\Administrator\Favorites\Spyware&Malware Protection.url
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\rs.txt

.
((((((((((((((((((((((((( Files Created from 2008-03-24 to 2008-04-24 )))))))))))))))))))))))))))))))
.

2008-04-23 22:30 . 2008-04-23 22:30 <DIR> d-------- C:\TEMP
2008-04-23 22:30 . 2008-04-23 22:30 53,248 --a------ C:\TEMP\catchme.dll
2008-04-23 22:24 . 2008-04-23 22:25 <DIR> dr-h----- C:\$VAULT$.AVG
2008-04-23 21:09 . 2008-04-23 21:09 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-04-23 21:08 . 2008-04-23 21:08 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-23 16:52 . 2008-04-23 16:52 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-04-23 16:21 . 2008-04-23 16:21 <DIR> d-------- C:\Deckard
2008-04-23 16:12 . 2008-04-23 16:12 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-23 15:51 . 2008-04-23 15:51 <DIR> d-------- C:\Program Files\AVG
2008-04-23 13:02 . 2008-04-23 16:51 <DIR> d-------- C:\WINDOWS\system32\382077
2008-04-23 08:42 . 2008-04-23 08:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\TmpRecentIcons
2008-04-23 07:35 . 2008-04-23 15:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-23 07:33 . 2008-04-23 21:08 8,192 --a------ C:\Documents and Settings\Hybride
2008-04-23 07:03 . 2008-04-23 07:01 61,952 --a------ C:\WINDOWS\system32\flciijjq.exe
2008-04-23 07:02 . 2008-04-23 22:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\jsfqrivs
2008-04-23 07:01 . 2008-04-23 07:01 61,952 --a------ C:\flciijjq.exe
2008-04-23 07:01 . 2008-04-23 07:01 61,874 --a------ C:\WINDOWS\ydhqzop.sys
2008-04-21 20:30 . 2008-04-21 20:30 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\FileZilla
2008-04-21 17:25 . 2008-04-21 17:25 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\GlobalSCAPE
2008-04-20 16:42 . 2008-04-20 16:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Inkscape
2008-03-29 11:53 . 2008-04-21 21:07 <DIR> d-------- C:\WAMP
2008-03-24 17:53 . 2008-03-24 17:53 17,240 --a------ C:\WINDOWS\sess_377edh790c7dt52h4jsvqglb46

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-24 02:51 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-04-24 02:22 --------- d-----w C:\Documents and Settings\Administrator\Application Data\mIRC
2008-04-24 02:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2008-04-24 02:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-23 02:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-22 11:57 --------- d-----w C:\Program Files\Image-Line
2008-04-22 11:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-14 03:48 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Winamp
2008-03-23 04:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-23 04:28 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-03-18 01:26 --------- d-----w C:\Program Files\vanBasco's Karaoke Player
2008-03-13 04:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-03-10 03:41 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Digsby
2008-03-10 03:38 --------- d-----w C:\Program Files\WinDirStat
2008-03-10 03:26 196,608 ----a-w C:\WINDOWS\system32\libssl32.dll
2008-03-09 16:12 --------- d-----w C:\Program Files\ZyDAS Technology Corporation
2008-03-09 16:12 --------- d-----w C:\Program Files\Datel
2008-03-03 23:15 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2008-03-02 22:02 --------- d-----w C:\Documents and Settings\Administrator\Application Data\skypePM
2008-03-02 03:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-03-02 03:16 --------- d-----w C:\Program Files\Yahoo!
2008-02-29 04:12 --------- d-----w C:\Program Files\Google
2008-02-29 04:07 --------- d-----w C:\Program Files\MagicISO
2008-02-28 03:54 --------- d-----w C:\Program Files\MySpace
2008-02-28 03:54 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MySpace
2008-02-26 23:35 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-26 23:33 --------- d-----w C:\Program Files\Common Files\Control Panels
2008-02-26 23:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\ALM
2008-02-26 23:14 --------- d-----w C:\Program Files\QuickTime
2008-02-26 23:01 --------- d-----w C:\Program Files\Bonjour
2008-02-13 21:44 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-11 02:05 368,640 ----a-w C:\WINDOWS\system32\ReWire.dll
2008-02-11 02:05 233,472 ----a-w C:\WINDOWS\system32\REX Shared Library.dll
.

------- Sigcheck -------

2006-08-06 07:00 360576 c7be59b07c6eb74bea6fd67c1b164015 C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( snapshot@2008-04-23_17.02.22.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-08-06 12:00:00 126,976 ----a-w C:\WINDOWS\system32\dllcache\apphelp.dll
+ 2008-04-24 02:08:27 821,856 ----a-w C:\WINDOWS\system32\drivers\avg7core.sys
+ 2008-04-24 02:08:30 4,224 ----a-w C:\WINDOWS\system32\drivers\avg7rsw.sys
+ 2008-04-24 02:08:30 27,776 ----a-w C:\WINDOWS\system32\drivers\avg7rsxp.sys
+ 2008-04-24 02:08:30 10,760 ----a-w C:\WINDOWS\system32\drivers\avgclean.sys
+ 2008-04-24 02:08:30 26,952 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-04-24 02:08:30 4,960 ----a-w C:\WINDOWS\system32\drivers\avgtdi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af49a2-94f3-42bd-f434-2604812c897d}]
C:\WINDOWS\system32\jfiehayd.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B4CE8035-501B-4750-9535-CE7F8B708A36}"= "C:\WINDOWS\dpevflbg.dll" [ ]

[HKEY_CLASSES_ROOT\clsid\{b4ce8035-501b-4750-9535-ce7f8b708a36}]
[HKEY_CLASSES_ROOT\dpevflbg.1]
[HKEY_CLASSES_ROOT\TypeLib\{ACCC6E53-BF0F-48A5-9B9F-7A60450A2AE5}]
[HKEY_CLASSES_ROOT\dpevflbg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-23 15:12 7630848]
"nwiz"="nwiz.exe" [2006-08-23 15:12 1617920 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-23 15:12 86016]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 15:19 282624 C:\WINDOWS\stsystra.exe]
"MSConfig"="C:\WINDOWS\system32\msconfig.exe" [2006-08-06 07:00 158208]
"AVG7_CC"="E:\AVG\avgcc.exe" [2008-04-23 21:08 579584]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [ ]
"AVG7_Run"="E:\AVG\avgw.exe" [2008-04-23 21:08 219136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{C5AF49A2-94F3-42BD-F434-2604812C897D}"= C:\WINDOWS\system32\jfiehayd.dll [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"wdpoefan"= {21BB8D84-BC59-475F-AE3B-E6A7379E3040} - C:\WINDOWS\wdpoefan.dll [ ]
"vadokmxt"= {27D3D1F5-FFAC-42C5-A249-1C4C3528B3DD} - C:\WINDOWS\vadokmxt.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ibudu]
ibudu.dll

[HKLM\~\startupfolder\c:^documents and settings^administrator^start menu^programs^startup^rklauncher.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\RKLauncher.lnk
backup=C:\WINDOWS\pss\RKLauncher.lnkStartup

[HKLM\~\startupfolder\c:^documents and settings^administrator^start menu^programs^startup^yahoo! widgets.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Yahoo! Widgets.lnk
backup=C:\WINDOWS\pss\Yahoo! Widgets.lnkStartup

[HKLM\~\startupfolder\c:^documents and settings^all users^start menu^programs^startup^zdwlan utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZDWLan Utility.lnk
backup=C:\WINDOWS\pss\ZDWLan Utility.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acrobat assistant 8.0]
--a------ 2008-01-11 20:54 623992 E:\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adobe_id0eythm]
--a------ 2007-03-20 17:40 1884160 C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\autoload]
C:\Documents and Settings\Administrator\cftmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2008-02-10 19:47 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msvtt]
--a------ 2008-04-23 07:01 61952 C:\WINDOWS\system32\flciijjq.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntuser]
C:\WINDOWS\system32\drivers\spools.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\registrymechanic]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1535.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinVNC]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yahoo! pager]
--a------ 2007-08-30 18:43 4670704 E:\Yahoo!\Messenger\YahooMessenger.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"E:\\mIRC\\mirc.exe"=
"E:\\uTorrent\\uTorrent.exe"=
"E:\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"E:\\PuTTY\\PuTTY.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"E:\\Skype\\Phone\\Skype.exe"=
"E:\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"E:\\Yahoo!\\Messenger\\YServer.exe"=
"E:\\AVG\\avginet.exe"=
"E:\\AVG\\avgamsvr.exe"=
"E:\\AVG\\avgcc.exe"=
"E:\\AVG\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R1 itcoe;itcoe adapter;C:\WINDOWS\system32\itcoe.sys []
R3 wampapache;wampapache;"c:\WAMP\bin\apache\apache2.2.8\bin\httpd.exe" -k runservice []
R3 wampmysqld;wampmysqld;c:\WAMP\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe wampmysqld []
R3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-08-17 15:43]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\BRGSp50.sys [2005-06-08 19:44]
S3 PsSdk30;PsSdk30;C:\WINDOWS\system32\Drivers\PsSdk30.drv []
S3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2006-10-01 07:37]
S3 usbvm328;HP Camera;C:\WINDOWS\system32\Drivers\usbvm326.sys [2007-04-13 07:56]
S3 VBoxTAP;VirtualBox TAP Adapter;C:\WINDOWS\system32\DRIVERS\VBoxTAP.sys [2007-10-18 10:55]
S3 vmfilter323;VC0326 filter service for Serome;C:\WINDOWS\system32\drivers\vmfilter323.sys [2007-04-13 07:56]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
DcomLaunch REG_MULTI_SZ DcomLaunch

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3200db41-8161-11dc-a4a5-806d6172696f}]
\Shell\AutoRun\command - G:\autoRcd.exe

*Newly Created Service* - avg7alrt
*Newly Created Service* - AVG7CORE
*Newly Created Service* - AVG7RSXP
*Newly Created Service* - avg7updsvc
*Newly Created Service* - AVGCLEAN
*Newly Created Service* - avgems
*Newly Created Service* - AVGTDI
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-23 22:30:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\PsSdk30]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\PsSdk30.drv"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\ibudu.dll
.
Completion time: 2008-04-23 22:32:39
ComboFix-quarantined-files.txt 2008-04-24 03:31:37
ComboFix2.txt 2008-04-23 22:03:16

Pre-Run: 2,534,289,408 bytes free
Post-Run: 2,528,571,392 bytes free

236




















And the next HJT Log...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:37:17 PM, on 4/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
E:\AVG\avgamsvr.exe
E:\Firefox\firefox.exe
E:\AVG\avgcc.exe
E:\AVG\avgupsvc.exe
E:\AVG\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\Winamp\winamp.exe
C:\WINDOWS\system32\wuauclt.exe
E:\HijackThis\Riyonuk[HJT].exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = Download Directory
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=104...amp;clcid=0x409
O2 - BHO: C:\WINDOWS\system32\jfiehayd.dll - {c5af49a2-94f3-42bd-f434-2604812c897d} - C:\WINDOWS\system32\jfiehayd.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - E:\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: dpevflbg - {B4CE8035-501B-4750-9535-CE7F8B708A36} - C:\WINDOWS\dpevflbg.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\system32\msconfig.exe /auto
O4 - HKLM\..\Run: [AVG7_CC] E:\AVG\avgcc.exe /STARTUP
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] E:\AVG\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1194495320687
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{125D395A-533C-4AEE-8330-F045A481AFAD}: NameServer = 85.255.116.134,85.255.112.139
O17 - HKLM\System\CCS\Services\Tcpip\..\{A643A6B6-8682-4B64-83CD-2D74A424987F}: NameServer = 85.255.116.134,85.255.112.139
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB0ECA17-D45F-48DC-BC3E-976B76A5AADB}: NameServer = 85.255.116.134,85.255.112.139
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5209746-9966-43FB-B80C-133B6F8E6CF0}: NameServer = 85.255.116.134,85.255.112.139
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.134 85.255.112.139
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.134 85.255.112.139
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.116.134 85.255.112.139
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.134 85.255.112.139
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: ibudu - ibudu.dll (file missing)
O21 - SSODL: wdpoefan - {21BB8D84-BC59-475F-AE3B-E6A7379E3040} - C:\WINDOWS\wdpoefan.dll (file missing)
O21 - SSODL: vadokmxt - {27D3D1F5-FFAC-42C5-A249-1C4C3528B3DD} - C:\WINDOWS\vadokmxt.dll (file missing)
O21 - SSODL: BootAvp - {ae4a823e-ac33-417b-9ce2-cd4300f7f36a} - (no file)
O22 - SharedTaskScheduler: jhsf8d984jief8dsfus98jkefn - {C5AF49A2-94F3-42BD-F434-2604812C897D} - C:\WINDOWS\system32\jfiehayd.dll (file missing)
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: AVG7 Alert Manager Server (avg7alrt) - GRISOFT, s.r.o. - E:\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (avg7updsvc) - GRISOFT, s.r.o. - E:\AVG\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (avgems) - GRISOFT, s.r.o. - E:\AVG\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Indexing Service (cisvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: wampapache - Apache Software Foundation - c:\WAMP\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\WAMP\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe

--
End of file - 7585 bytes

#4 Rahina

Rahina

    Security Helper


  • Members
  • 681 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:08:57 AM

Posted 24 April 2008 - 04:27 AM

You don't have Window's Recovery Console installed. Whilst it may not be needed at this time, current infections tend to patch a lot of critical system files now, these often result to multiple problems and sometimes, they can cause unbootable machines. Having Window's Recovery Console installed on your machine will help you and I in case something goes wrong while we are in the process of cleaning your machine.

Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System


Posted Image


Download the file & save it as it's originally named, next to ComboFix.exe.



Posted Image


Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log.
[ Antivirus ] [ Firewall ] [ Spywareblaster ] [ Malwarebytes Anti-Malware ] [ Windows update ] [ Firefox ] [ WinPatrol ] [ ATF Cleaner ]

If i have helped you, donate to help me continue helping others. Posted Image
Posted Image Posted Image

#5 Rahina

Rahina

    Security Helper


  • Members
  • 681 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:08:57 AM

Posted 24 April 2008 - 04:30 AM

When you have Recovery console Installed:

Please download FixWareout . Save it to your desktop and run it.

Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
Then you will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
Once the desktop loads please post the text that will open (report.txt) and a new Hijackthis log.

=============================================

This is how you should get your taskbar working again:

Open notepad and copy/paste the text in the quotebox below into it: ( Please make sure you copy everything in the code box )

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"=-
"ForceClassicControlPanel"=-
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"=-
"NoResolveTrack"=-
"NoResolveSearch"=-
"NoSMConfigurePrograms"=-
"NoInstrumentation"=-
"NoSMBalloonTip"=-
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"=-
"NoResolveTrack"=-
"NoResolveSearch"=-
"NoSMConfigurePrograms"=-
"NoInstrumentation"=-
"NoSMBalloonTip"=-

Save this as CFScript.txt

Posted Image

Refering to the picture above, drag CFScript.txt into ComboFix.exe

=============================================

Please download Malwarebytes' Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Double-click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • If you have trouble with the update process, please download the latest updates here.
  • Double-click the mbam-rules.exe file on your desktop and let it update the application.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to restart. (see extra note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Please copy and paste the entire report in your next reply. :thumbsup:
Extra note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Edited by Rahina Rescue, 24 April 2008 - 04:31 AM.

[ Antivirus ] [ Firewall ] [ Spywareblaster ] [ Malwarebytes Anti-Malware ] [ Windows update ] [ Firefox ] [ WinPatrol ] [ ATF Cleaner ]

If i have helped you, donate to help me continue helping others. Posted Image
Posted Image Posted Image

#6 Riyonuk

Riyonuk
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:11:57 PM

Posted 24 April 2008 - 04:02 PM

You said: When complete, a log named CF_RC.txt will open

Well a file named C:\TEMP\log.txt opened up, and my taskbar disappeared and reappeared several times.

ComboFix 08-04-22.5 - Administrator 2008-04-24 16:00:59.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1421 [GMT -5:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
.

((((((((((((((((((((((((( Files Created from 2008-03-24 to 2008-04-24 )))))))))))))))))))))))))))))))
.

2008-04-24 16:02 . 2008-04-24 16:03 <DIR> d-------- C:\TEMP
2008-04-24 16:02 . 2008-04-24 16:02 53,248 --a------ C:\TEMP\catchme.dll
2008-04-23 22:24 . 2008-04-23 22:25 <DIR> dr-h----- C:\$VAULT$.AVG
2008-04-23 21:09 . 2008-04-24 08:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-04-23 21:08 . 2008-04-23 21:08 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-23 16:52 . 2008-04-23 16:52 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-04-23 16:21 . 2008-04-23 16:21 <DIR> d-------- C:\Deckard
2008-04-23 16:12 . 2008-04-23 16:12 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-23 15:51 . 2008-04-23 15:51 <DIR> d-------- C:\Program Files\AVG
2008-04-23 13:02 . 2008-04-23 16:51 <DIR> d-------- C:\WINDOWS\system32\382077
2008-04-23 08:42 . 2008-04-23 08:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\TmpRecentIcons
2008-04-23 07:35 . 2008-04-23 15:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-23 07:33 . 2008-04-23 21:08 8,192 --a------ C:\Documents and Settings\Hybride
2008-04-23 07:03 . 2008-04-23 07:01 61,952 --a------ C:\WINDOWS\system32\flciijjq.exe
2008-04-23 07:02 . 2008-04-23 22:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\jsfqrivs
2008-04-23 07:01 . 2008-04-23 07:01 61,952 --a------ C:\flciijjq.exe
2008-04-23 07:01 . 2008-04-23 07:01 61,874 --a------ C:\WINDOWS\ydhqzop.sys
2008-04-21 20:30 . 2008-04-21 20:30 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\FileZilla
2008-04-21 17:25 . 2008-04-21 17:25 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\GlobalSCAPE
2008-04-20 16:42 . 2008-04-20 16:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Inkscape
2008-03-29 11:53 . 2008-04-21 21:07 <DIR> d-------- C:\WAMP
2008-03-24 17:53 . 2008-03-24 17:53 17,240 --a------ C:\WINDOWS\sess_377edh790c7dt52h4jsvqglb46

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-24 21:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\mIRC
2008-04-24 02:51 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-04-24 02:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2008-04-24 02:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-23 02:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-22 11:57 --------- d-----w C:\Program Files\Image-Line
2008-04-22 11:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-14 03:48 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Winamp
2008-03-23 04:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-23 04:28 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-03-18 01:26 --------- d-----w C:\Program Files\vanBasco's Karaoke Player
2008-03-13 04:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-03-10 03:41 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Digsby
2008-03-10 03:38 --------- d-----w C:\Program Files\WinDirStat
2008-03-10 03:26 196,608 ----a-w C:\WINDOWS\system32\libssl32.dll
2008-03-09 16:12 --------- d-----w C:\Program Files\ZyDAS Technology Corporation
2008-03-09 16:12 --------- d-----w C:\Program Files\Datel
2008-03-03 23:15 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2008-03-02 22:02 --------- d-----w C:\Documents and Settings\Administrator\Application Data\skypePM
2008-03-02 03:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-03-02 03:16 --------- d-----w C:\Program Files\Yahoo!
2008-02-29 04:12 --------- d-----w C:\Program Files\Google
2008-02-29 04:07 --------- d-----w C:\Program Files\MagicISO
2008-02-28 03:54 --------- d-----w C:\Program Files\MySpace
2008-02-28 03:54 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MySpace
2008-02-26 23:35 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-26 23:33 --------- d-----w C:\Program Files\Common Files\Control Panels
2008-02-26 23:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\ALM
2008-02-26 23:14 --------- d-----w C:\Program Files\QuickTime
2008-02-26 23:01 --------- d-----w C:\Program Files\Bonjour
2008-02-13 21:44 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-11 02:05 368,640 ----a-w C:\WINDOWS\system32\ReWire.dll
2008-02-11 02:05 233,472 ----a-w C:\WINDOWS\system32\REX Shared Library.dll
.

------- Sigcheck -------

2006-08-06 07:00 360576 c7be59b07c6eb74bea6fd67c1b164015 C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( snapshot@2008-04-23_17.02.22.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-23 21:52:56 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-24 03:34:20 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2006-08-06 12:00:00 126,976 ----a-w C:\WINDOWS\system32\dllcache\apphelp.dll
+ 2008-04-24 02:08:27 821,856 ----a-w C:\WINDOWS\system32\drivers\avg7core.sys
+ 2008-04-24 02:08:30 4,224 ----a-w C:\WINDOWS\system32\drivers\avg7rsw.sys
+ 2008-04-24 02:08:30 27,776 ----a-w C:\WINDOWS\system32\drivers\avg7rsxp.sys
+ 2008-04-24 02:08:30 10,760 ----a-w C:\WINDOWS\system32\drivers\avgclean.sys
+ 2008-04-24 02:08:30 26,952 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-04-24 02:08:30 4,960 ----a-w C:\WINDOWS\system32\drivers\avgtdi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af49a2-94f3-42bd-f434-2604812c897d}]
C:\WINDOWS\system32\jfiehayd.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B4CE8035-501B-4750-9535-CE7F8B708A36}"= "C:\WINDOWS\dpevflbg.dll" [ ]

[HKEY_CLASSES_ROOT\clsid\{b4ce8035-501b-4750-9535-ce7f8b708a36}]
[HKEY_CLASSES_ROOT\dpevflbg.1]
[HKEY_CLASSES_ROOT\TypeLib\{ACCC6E53-BF0F-48A5-9B9F-7A60450A2AE5}]
[HKEY_CLASSES_ROOT\dpevflbg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-23 15:12 7630848]
"nwiz"="nwiz.exe" [2006-08-23 15:12 1617920 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-23 15:12 86016]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 15:19 282624 C:\WINDOWS\stsystra.exe]
"MSConfig"="C:\WINDOWS\system32\msconfig.exe" [2006-08-06 07:00 158208]
"AVG7_CC"="E:\AVG\avgcc.exe" [2008-04-23 21:08 579584]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [ ]
"AVG7_Run"="E:\AVG\avgw.exe" [2008-04-23 21:08 219136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{C5AF49A2-94F3-42BD-F434-2604812C897D}"= C:\WINDOWS\system32\jfiehayd.dll [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"wdpoefan"= {21BB8D84-BC59-475F-AE3B-E6A7379E3040} - C:\WINDOWS\wdpoefan.dll [ ]
"vadokmxt"= {27D3D1F5-FFAC-42C5-A249-1C4C3528B3DD} - C:\WINDOWS\vadokmxt.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ibudu]
ibudu.dll

[HKLM\~\startupfolder\c:^documents and settings^administrator^start menu^programs^startup^rklauncher.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\RKLauncher.lnk
backup=C:\WINDOWS\pss\RKLauncher.lnkStartup

[HKLM\~\startupfolder\c:^documents and settings^administrator^start menu^programs^startup^yahoo! widgets.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Yahoo! Widgets.lnk
backup=C:\WINDOWS\pss\Yahoo! Widgets.lnkStartup

[HKLM\~\startupfolder\c:^documents and settings^all users^start menu^programs^startup^zdwlan utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZDWLan Utility.lnk
backup=C:\WINDOWS\pss\ZDWLan Utility.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acrobat assistant 8.0]
--a------ 2008-01-11 20:54 623992 E:\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adobe_id0eythm]
--a------ 2007-03-20 17:40 1884160 C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\autoload]
C:\Documents and Settings\Administrator\cftmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2008-02-10 19:47 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msvtt]
--a------ 2008-04-23 07:01 61952 C:\WINDOWS\system32\flciijjq.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntuser]
C:\WINDOWS\system32\drivers\spools.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\registrymechanic]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1535.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinVNC]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yahoo! pager]
--a------ 2007-08-30 18:43 4670704 E:\Yahoo!\Messenger\YahooMessenger.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"E:\\mIRC\\mirc.exe"=
"E:\\uTorrent\\uTorrent.exe"=
"E:\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"E:\\PuTTY\\PuTTY.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"E:\\Skype\\Phone\\Skype.exe"=
"E:\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"E:\\Yahoo!\\Messenger\\YServer.exe"=
"E:\\AVG\\avginet.exe"=
"E:\\AVG\\avgamsvr.exe"=
"E:\\AVG\\avgcc.exe"=
"E:\\AVG\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-08-17 15:43]
S1 itcoe;itcoe adapter;C:\WINDOWS\system32\itcoe.sys []
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\BRGSp50.sys [2005-06-08 19:44]
S3 PsSdk30;PsSdk30;C:\WINDOWS\system32\Drivers\PsSdk30.drv []
S3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2006-10-01 07:37]
S3 usbvm328;HP Camera;C:\WINDOWS\system32\Drivers\usbvm326.sys [2007-04-13 07:56]
S3 VBoxTAP;VirtualBox TAP Adapter;C:\WINDOWS\system32\DRIVERS\VBoxTAP.sys [2007-10-18 10:55]
S3 vmfilter323;VC0326 filter service for Serome;C:\WINDOWS\system32\drivers\vmfilter323.sys [2007-04-13 07:56]
S3 wampapache;wampapache;"c:\WAMP\bin\apache\apache2.2.8\bin\httpd.exe" -k runservice []
S3 wampmysqld;wampmysqld;c:\WAMP\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe wampmysqld []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
DcomLaunch REG_MULTI_SZ DcomLaunch

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3200db41-8161-11dc-a4a5-806d6172696f}]
\Shell\AutoRun\command - G:\autoRcd.exe

*Newly Created Service* - catchme
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-24 16:02:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\PsSdk30]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\PsSdk30.drv"
.
Completion time: 2008-04-24 16:04:27
ComboFix-quarantined-files.txt 2008-04-24 21:03:25
ComboFix2.txt 2008-04-24 03:32:40
ComboFix3.txt 2008-04-23 22:03:16

Pre-Run: 2,762,936,320 bytes free
Post-Run: 2,734,567,424 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

220

#7 Riyonuk

Riyonuk
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:11:57 PM

Posted 24 April 2008 - 04:03 PM

Next, you said to download this FixWareOut, well when I click the link it says..

404 ERROR: Page Not Found!

The requested page http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe could not be found on this server.

#8 Rahina

Rahina

    Security Helper


  • Members
  • 681 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:08:57 AM

Posted 25 April 2008 - 03:37 AM

TRY this link for Fixwareout:

http://downloads.subratam.org/Fixwareout.exe

my taskbar disappeared and reappeared several times.

This is normal when you run combofix.

You said: When complete, a log named CF_RC.txt will open

It's ok, CF_RC.txt is included in combofix report.

==========================================

Please download Malwarebytes' Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Double-click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • If you have trouble with the update process, please download the latest updates here.
  • Double-click the mbam-rules.exe file on your desktop and let it update the application.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to restart. (see extra note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Please copy and paste the entire report in your next reply. :thumbsup:
Extra note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
[ Antivirus ] [ Firewall ] [ Spywareblaster ] [ Malwarebytes Anti-Malware ] [ Windows update ] [ Firefox ] [ WinPatrol ] [ ATF Cleaner ]

If i have helped you, donate to help me continue helping others. Posted Image
Posted Image Posted Image

#9 Riyonuk

Riyonuk
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:11:57 PM

Posted 25 April 2008 - 03:41 PM

Username "Administrator" - 04/25/2008 15:40:40 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.116.134 85.255.112.139" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{125D395A-533C-4AEE-8330-F045A481AFAD}
"nameserver"="85.255.116.134,85.255.112.139" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{A643A6B6-8682-4B64-83CD-2D74A424987F}
"nameserver"="85.255.116.134,85.255.112.139" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{DB0ECA17-D45F-48DC-BC3E-976B76A5AADB}
"nameserver"="85.255.116.134,85.255.112.139" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{F5209746-9966-43FB-B80C-133B6F8E6CF0}
"nameserver"="85.255.116.134,85.255.112.139" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{00A060A5-CB7B-4E30-855A-B8614F7EE0FE}
"DhcpNameServer"="85.255.116.134,85.255.112.139" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{A643A6B6-8682-4B64-83CD-2D74A424987F}
"DhcpNameServer"="85.255.116.134,85.255.112.139" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{F5209746-9966-43FB-B80C-133B6F8E6CF0}
"DhcpNameServer"="85.255.116.134,85.255.112.139" <Value cleared.

Could not flush the DNS Resolver Cache: Function failed during execution.


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"SigmatelSysTrayApp"="stsystra.exe"
"AVG7_CC"="E:\\AVG\\avgcc.exe /STARTUP"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"msnmsgr"="\"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe\" /background"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run\adobeupdater]
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~

#10 Rahina

Rahina

    Security Helper


  • Members
  • 681 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:08:57 AM

Posted 25 April 2008 - 03:44 PM

Very nice.

Also please run Malwarebytes & Deckard's system scanner

Post the results :thumbsup:

Edited by Rahina Rescue, 25 April 2008 - 03:45 PM.

[ Antivirus ] [ Firewall ] [ Spywareblaster ] [ Malwarebytes Anti-Malware ] [ Windows update ] [ Firefox ] [ WinPatrol ] [ ATF Cleaner ]

If i have helped you, donate to help me continue helping others. Posted Image
Posted Image Posted Image

#11 Riyonuk

Riyonuk
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:11:57 PM

Posted 25 April 2008 - 03:47 PM

ComboFix 08-04-22.5 - Administrator 2008-04-25 15:45:39.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1510 [GMT -5:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Files Created from 2008-03-25 to 2008-04-25 )))))))))))))))))))))))))))))))
.

2008-04-25 15:47 . 2008-04-25 15:47 <DIR> d-------- C:\TEMP
2008-04-25 15:47 . 2008-04-25 15:47 53,248 --a------ C:\TEMP\catchme.dll
2008-04-25 15:40 . 2008-04-25 15:42 <DIR> d-------- C:\fixwareout
2008-04-23 22:24 . 2008-04-23 22:25 <DIR> dr-h----- C:\$VAULT$.AVG
2008-04-23 21:09 . 2008-04-25 08:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-04-23 21:08 . 2008-04-23 21:08 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-23 16:52 . 2008-04-23 16:52 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-04-23 16:21 . 2008-04-23 16:21 <DIR> d-------- C:\Deckard
2008-04-23 16:12 . 2008-04-23 16:12 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-23 15:51 . 2008-04-23 15:51 <DIR> d-------- C:\Program Files\AVG
2008-04-23 13:02 . 2008-04-23 16:51 <DIR> d-------- C:\WINDOWS\system32\382077
2008-04-23 08:42 . 2008-04-23 08:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\TmpRecentIcons
2008-04-23 07:35 . 2008-04-23 15:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-23 07:33 . 2008-04-23 21:08 8,192 --a------ C:\Documents and Settings\Hybride
2008-04-23 07:03 . 2008-04-23 07:01 61,952 --a------ C:\WINDOWS\system32\flciijjq.exe
2008-04-23 07:02 . 2008-04-23 22:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\jsfqrivs
2008-04-23 07:01 . 2008-04-23 07:01 61,952 --a------ C:\flciijjq.exe
2008-04-23 07:01 . 2008-04-23 07:01 61,874 --a------ C:\WINDOWS\ydhqzop.sys
2008-04-21 20:30 . 2008-04-24 20:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\FileZilla
2008-04-21 17:25 . 2008-04-21 17:25 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\GlobalSCAPE
2008-04-20 16:42 . 2008-04-20 16:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Inkscape
2008-03-29 11:53 . 2008-04-21 21:07 <DIR> d-------- C:\WAMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-24 22:06 --------- d-----w C:\Documents and Settings\Administrator\Application Data\mIRC
2008-04-24 02:51 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-04-24 02:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2008-04-24 02:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-23 02:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-22 11:57 --------- d-----w C:\Program Files\Image-Line
2008-04-22 11:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-14 03:48 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Winamp
2008-03-23 04:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-23 04:28 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-03-18 01:26 --------- d-----w C:\Program Files\vanBasco's Karaoke Player
2008-03-13 04:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-03-10 03:41 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Digsby
2008-03-10 03:38 --------- d-----w C:\Program Files\WinDirStat
2008-03-10 03:26 196,608 ----a-w C:\WINDOWS\system32\libssl32.dll
2008-03-09 16:12 --------- d-----w C:\Program Files\ZyDAS Technology Corporation
2008-03-09 16:12 --------- d-----w C:\Program Files\Datel
2008-03-03 23:15 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2008-03-02 22:02 --------- d-----w C:\Documents and Settings\Administrator\Application Data\skypePM
2008-03-02 03:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-03-02 03:16 --------- d-----w C:\Program Files\Yahoo!
2008-02-29 04:12 --------- d-----w C:\Program Files\Google
2008-02-29 04:07 --------- d-----w C:\Program Files\MagicISO
2008-02-28 03:54 --------- d-----w C:\Program Files\MySpace
2008-02-28 03:54 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MySpace
2008-02-26 23:35 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-26 23:33 --------- d-----w C:\Program Files\Common Files\Control Panels
2008-02-26 23:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\ALM
2008-02-26 23:14 --------- d-----w C:\Program Files\QuickTime
2008-02-26 23:01 --------- d-----w C:\Program Files\Bonjour
2008-02-13 21:44 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-11 02:05 368,640 ----a-w C:\WINDOWS\system32\ReWire.dll
2008-02-11 02:05 233,472 ----a-w C:\WINDOWS\system32\REX Shared Library.dll
.

------- Sigcheck -------

2006-08-06 07:00 360576 c7be59b07c6eb74bea6fd67c1b164015 C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( snapshot@2008-04-23_17.02.22.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-23 21:52:56 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-25 20:41:35 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2006-08-06 12:00:00 126,976 ----a-w C:\WINDOWS\system32\dllcache\apphelp.dll
+ 2008-04-24 02:08:27 821,856 ----a-w C:\WINDOWS\system32\drivers\avg7core.sys
+ 2008-04-24 02:08:30 4,224 ----a-w C:\WINDOWS\system32\drivers\avg7rsw.sys
+ 2008-04-24 02:08:30 27,776 ----a-w C:\WINDOWS\system32\drivers\avg7rsxp.sys
+ 2008-04-24 02:08:30 10,760 ----a-w C:\WINDOWS\system32\drivers\avgclean.sys
+ 2008-04-24 02:08:30 26,952 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-04-24 02:08:30 4,960 ----a-w C:\WINDOWS\system32\drivers\avgtdi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af49a2-94f3-42bd-f434-2604812c897d}]
C:\WINDOWS\system32\jfiehayd.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B4CE8035-501B-4750-9535-CE7F8B708A36}"= "C:\WINDOWS\dpevflbg.dll" [ ]

[HKEY_CLASSES_ROOT\clsid\{b4ce8035-501b-4750-9535-ce7f8b708a36}]
[HKEY_CLASSES_ROOT\dpevflbg.1]
[HKEY_CLASSES_ROOT\TypeLib\{ACCC6E53-BF0F-48A5-9B9F-7A60450A2AE5}]
[HKEY_CLASSES_ROOT\dpevflbg]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2008-02-10 19:47 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-23 15:12 7630848]
"nwiz"="nwiz.exe" [2006-08-23 15:12 1617920 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-23 15:12 86016]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 15:19 282624 C:\WINDOWS\stsystra.exe]
"AVG7_CC"="E:\AVG\avgcc.exe" [2008-04-23 21:08 579584]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [ ]
"AVG7_Run"="E:\AVG\avgw.exe" [2008-04-23 21:08 219136]

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-11 17:34:48 3746856]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ZDWLan Utility.lnk - C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2008-03-09 11:12:42 475136]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{C5AF49A2-94F3-42BD-F434-2604812C897D}"= C:\WINDOWS\system32\jfiehayd.dll [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"wdpoefan"= {21BB8D84-BC59-475F-AE3B-E6A7379E3040} - C:\WINDOWS\wdpoefan.dll [ ]
"vadokmxt"= {27D3D1F5-FFAC-42C5-A249-1C4C3528B3DD} - C:\WINDOWS\vadokmxt.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ibudu]
ibudu.dll

[HKLM\~\startupfolder\c:^documents and settings^administrator^start menu^programs^startup^rklauncher.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\RKLauncher.lnk
backup=C:\WINDOWS\pss\RKLauncher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acrobat assistant 8.0]
--a------ 2008-01-11 20:54 623992 E:\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adobeupdater]
--a------ 2007-03-01 00:06 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adobe_id0eythm]
--a------ 2007-03-20 17:40 1884160 C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\autoload]
C:\Documents and Settings\Administrator\cftmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2008-02-10 19:47 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msvtt]
--a------ 2008-04-23 07:01 61952 C:\WINDOWS\system32\flciijjq.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntuser]
C:\WINDOWS\system32\drivers\spools.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\registrymechanic]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1535.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinVNC]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yahoo! pager]
--a------ 2007-08-30 18:43 4670704 E:\Yahoo!\Messenger\YahooMessenger.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"E:\\uTorrent\\uTorrent.exe"=
"E:\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"E:\\PuTTY\\PuTTY.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"E:\\Skype\\Phone\\Skype.exe"=
"E:\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"E:\\Yahoo!\\Messenger\\YServer.exe"=
"E:\\AVG\\avginet.exe"=
"E:\\AVG\\avgamsvr.exe"=
"E:\\AVG\\avgcc.exe"=
"E:\\AVG\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R3 BRGSp50;BRGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\BRGSp50.sys [2005-06-08 19:44]
R3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-08-17 15:43]
S1 itcoe;itcoe adapter;C:\WINDOWS\system32\itcoe.sys []
S3 PsSdk30;PsSdk30;C:\WINDOWS\system32\Drivers\PsSdk30.drv []
S3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2006-10-01 07:37]
S3 usbvm328;HP Camera;C:\WINDOWS\system32\Drivers\usbvm326.sys [2007-04-13 07:56]
S3 VBoxTAP;VirtualBox TAP Adapter;C:\WINDOWS\system32\DRIVERS\VBoxTAP.sys [2007-10-18 10:55]
S3 vmfilter323;VC0326 filter service for Serome;C:\WINDOWS\system32\drivers\vmfilter323.sys [2007-04-13 07:56]
S3 wampapache;wampapache;"c:\WAMP\bin\apache\apache2.2.8\bin\httpd.exe" -k runservice []
S3 wampmysqld;wampmysqld;c:\WAMP\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe wampmysqld []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
DcomLaunch REG_MULTI_SZ DcomLaunch

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3200db41-8161-11dc-a4a5-806d6172696f}]
\Shell\AutoRun\command - G:\autoRcd.exe

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-25 15:47:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\PsSdk30]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\PsSdk30.drv"
.
Completion time: 2008-04-25 15:50:14
ComboFix-quarantined-files.txt 2008-04-25 20:49:13
ComboFix2.txt 2008-04-24 21:04:28
ComboFix3.txt 2008-04-24 03:32:40
ComboFix4.txt 2008-04-23 22:03:16

Pre-Run: 2,751,852,544 bytes free
Post-Run: 2,740,543,488 bytes free

196

#12 Riyonuk

Riyonuk
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:11:57 PM

Posted 25 April 2008 - 03:54 PM

Malwarebytes' Anti-Malware 1.11
Database version: 682

Scan type: Quick Scan
Objects scanned: 26043
Time elapsed: 2 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 17
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 45

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{f0a035ec-c865-4e47-bf73-b17741dd5232} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c5af49a2-94f3-42bd-f434-2604812c897d} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c5af49a2-94f3-42bd-f434-2604812c897d} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{0fb05157-ca37-410b-87e3-3fa4da645794} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2c1f22cd-1c58-4c24-bbd4-62d865b00bfc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{47dd2d81-8184-4361-aac2-e05d4d017ae5} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8b12cfb7-bfcf-44d9-9ca8-2f252687556d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{accc6e53-bf0f-48a5-9b9f-7a60450a2ae5} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\mslagent (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Golden Palace Casino NEW (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\dpevflbg.bfeb (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\dpevflbg.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{c5af49a2-94f3-42bd-f434-2604812c897d} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0e1230f8-ea50-42a9-983c-d22abc2eeb4c} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\vadokmxt (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\wdpoefan (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\382077 (Trojan.BHO) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\flciijjq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\flciijjq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\akttzn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\anticipator.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\awtoolb.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dpcproxy.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\h@tkeysh@@k.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hoproxy.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxiwlgpm.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxiwlgpm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\medup012.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\medup020.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msgp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msnbho.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mtr2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mwin32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\netode.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\newsd32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ps1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\psof1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\psoft1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\regc64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\regm64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Rundl1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sncntr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssurf022.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssvchost.com (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sysreq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\taack.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\taack.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\temp#01.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\thun.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\thun32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\VBIEWER.OCX (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vbsys2.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vcatchpi.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winlogonpc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winsystem.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\WINWGPX.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\ydhqzop.sys (Rootkit.Agent) -> Quarantined and deleted successfully.

#13 Rahina

Rahina

    Security Helper


  • Members
  • 681 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:08:57 AM

Posted 25 April 2008 - 04:10 PM

looks much better already

Please download Deckard's System Scanner (DSS) and save to your Desktop.
alternate download site

DSS will do the following:
  • Create a new System Restore point in Windows XP and Vista.
  • Clean your Temporary Files, Downloaded Program Files, Internet Cache Files, and empty the Recycle Bin on all drives.
  • Check some important areas of your system and produce a report for me to analyze.
  • Automatically run HijackThis. It will also install and place a shortcut to HijackThis on your desktop if you do not already have it installed. So if HijackThis is not installed and DSS prompts you to download it, please answer yes.
You must be logged onto an account with administrator privileges when using.
  • Close all applications and windows.
  • Double-click on dss.exe to run it and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not
    malicious.
  • When the scan is complete, two text files will open in Notepad:
    • main.txt <- this one will be maximized
    • extra.txt <- this one will be minimized
  • If not, they both can be found in the C:\Deckard\System Scanner folder.
  • Please copy (Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your next reply.
-- When running DSS, some firewalls may warn that it is trying to access the Internet especially if your asked to download the most current version of HijackThis. Please ensure that you allow it permission to do so.
-- If you get a warning from your anti-virus while DSS is scanning, please allow DSS to continue as the scan is not harmful.

[ Antivirus ] [ Firewall ] [ Spywareblaster ] [ Malwarebytes Anti-Malware ] [ Windows update ] [ Firefox ] [ WinPatrol ] [ ATF Cleaner ]

If i have helped you, donate to help me continue helping others. Posted Image
Posted Image Posted Image

#14 Riyonuk

Riyonuk
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:11:57 PM

Posted 25 April 2008 - 04:16 PM

There is no extra.txt, no matter how many times I run it :/

Deckard's System Scanner v20071014.68
Run by Administrator on 2008-04-25 16:18:13
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Administrator.exe) ---------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:18:14 PM, on 4/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\AVG\avgamsvr.exe
E:\AVG\avgupsvc.exe
E:\AVG\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\stsystra.exe
E:\AVG\avgcc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\W32BRG55.EXE
E:\Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\WAMP\wampmanager.exe
c:\WAMP\bin\apache\apache2.2.8\bin\httpd.exe
c:\WAMP\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe
C:\WAMP\bin\apache\apache2.2.8\bin\httpd.exe
E:\Winamp\winamp.exe
C:\Documents and Settings\Administrator\Desktop\dss.exe
E:\HIJACK~1\ADMINI~1.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = Download Directory
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=104...amp;clcid=0x409
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - E:\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: dpevflbg - {B4CE8035-501B-4750-9535-CE7F8B708A36} - C:\WINDOWS\dpevflbg.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [AVG7_CC] E:\AVG\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] E:\AVG\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
O8 - Extra context menu item: Append to existing PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1194495320687
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.134 85.255.112.139
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: ibudu - ibudu.dll (file missing)
O21 - SSODL: BootAvp - {ae4a823e-ac33-417b-9ce2-cd4300f7f36a} - (no file)
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: AVG7 Alert Manager Server (avg7alrt) - GRISOFT, s.r.o. - E:\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (avg7updsvc) - GRISOFT, s.r.o. - E:\AVG\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (avgems) - GRISOFT, s.r.o. - E:\AVG\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Indexing Service (cisvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: wampapache - Apache Software Foundation - c:\WAMP\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\WAMP\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe

--
End of file - 7051 bytes

-- Files created between 2008-03-25 and 2008-04-25 -----------------------------

2008-04-25 15:51:41 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-25 15:47:31 53248 --a------ C:\WINDOWS\PSEXESVC.EXE <Not Verified; Sysinternals; Sysinternals PsExec>
2008-04-25 15:47:27 0 d-------- C:\TEMP
2008-04-25 15:40:48 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-04-24 16:00:35 0 d-------- C:\cmdcons
2008-04-23 22:24:21 0 dr-h----- C:\$VAULT$.AVG
2008-04-23 21:09:08 0 d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-04-23 21:08:31 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-23 16:52:57 0 d-------- C:\WINDOWS\system32\xircom
2008-04-23 16:52:57 0 d-------- C:\WINDOWS\system32\restore
2008-04-23 16:52:57 0 d-------- C:\WINDOWS\system32\oobe
2008-04-23 16:52:57 0 d-------- C:\WINDOWS\system32\npp
2008-04-23 16:52:57 0 d-------- C:\WINDOWS\system32\ime
2008-04-23 16:52:57 0 d-------- C:\WINDOWS\system32\com
2008-04-23 16:52:57 0 d-------- C:\WINDOWS\srchasst
2008-04-23 16:52:57 0 d-------- C:\WINDOWS\pchealth
2008-04-23 16:52:57 0 d-------- C:\WINDOWS\msagent
2008-04-23 16:52:57 0 d-------- C:\Program Files\windows nt
2008-04-23 16:52:57 0 d-------- C:\Program Files\msn gaming zone
2008-04-23 16:52:57 0 d-------- C:\Program Files\Common Files\speechengines
2008-04-23 16:52:56 0 d-------- C:\WINDOWS\system32\inetsrv
2008-04-23 16:52:56 0 d--hs---- C:\WINDOWS\system32\dllcache
2008-04-23 16:52:56 0 d-------- C:\Program Files\microsoft frontpage
2008-04-23 16:47:00 68096 --a------ C:\WINDOWS\zip.exe
2008-04-23 16:47:00 49152 --a------ C:\WINDOWS\VFind.exe
2008-04-23 16:47:00 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-04-23 16:47:00 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-04-23 16:47:00 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-04-23 16:47:00 98816 --a------ C:\WINDOWS\sed.exe
2008-04-23 16:47:00 80412 --a------ C:\WINDOWS\grep.exe
2008-04-23 16:47:00 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-04-23 16:12:35 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-23 15:51:36 0 d-------- C:\Program Files\AVG
2008-04-23 08:42:00 0 d-------- C:\Documents and Settings\Administrator\Application Data\TmpRecentIcons
2008-04-23 07:35:07 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-23 07:02:36 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-04-23 07:02:11 0 d-------- C:\Documents and Settings\All Users\Application Data\jsfqrivs
2008-04-21 20:30:57 0 d-------- C:\Documents and Settings\Administrator\Application Data\FileZilla
2008-04-21 17:25:56 0 d-------- C:\Documents and Settings\Administrator\Application Data\GlobalSCAPE
2008-04-20 16:42:18 0 d-------- C:\Documents and Settings\Administrator\Application Data\Inkscape
2008-04-15 15:51:54 0 d-------- C:\Documents and Settings\Administrator\Application Data\Opera
2008-03-29 11:53:26 0 d-------- C:\WAMP


-- Find3M Report ---------------------------------------------------------------

2008-04-24 18:03:37 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-04-24 17:06:54 0 d-------- C:\Documents and Settings\Administrator\Application Data\mIRC
2008-04-23 21:51:47 0 d-------- C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-04-23 16:52:57 0 d-------- C:\Program Files\Common Files
2008-04-22 22:36:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-04-22 06:57:31 0 d-------- C:\Program Files\Image-Line
2008-04-22 06:56:30 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-21 13:23:48 28068 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-04-13 22:48:59 0 d-------- C:\Documents and Settings\Administrator\Application Data\Winamp
2008-03-24 17:53:05 17240 --a------ C:\WINDOWS\sess_377edh790c7dt52h4jsvqglb46
2008-03-22 23:28:40 0 d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-03-17 20:26:50 0 d-------- C:\Program Files\vanBasco's Karaoke Player
2008-03-09 22:41:17 0 d-------- C:\Documents and Settings\Administrator\Application Data\Digsby
2008-03-09 22:38:16 0 d-------- C:\Program Files\WinDirStat
2008-03-09 11:12:41 0 d-------- C:\Program Files\ZyDAS Technology Corporation
2008-03-09 11:12:32 0 d-------- C:\Program Files\Datel
2008-03-03 18:15:54 0 d-------- C:\Documents and Settings\Administrator\Application Data\Skype
2008-03-02 17:02:35 0 d-------- C:\Documents and Settings\Administrator\Application Data\skypePM
2008-03-01 22:16:56 0 d-------- C:\Program Files\Yahoo!
2008-02-28 23:14:32 0 --a------ C:\Documents and Settings\Administrator\Application Data\.googlewebacchosts
2008-02-28 23:12:26 0 d-------- C:\Program Files\Google
2008-02-28 23:07:11 0 d-------- C:\Program Files\MagicISO
2008-02-27 22:54:20 0 d-------- C:\Documents and Settings\Administrator\Application Data\MySpace
2008-02-27 22:54:18 0 d-------- C:\Program Files\MySpace
2008-02-26 19:43:26 0 d-------- C:\Program Files\Movie Maker
2008-02-26 18:35:11 0 d-------- C:\Program Files\Common Files\Adobe
2008-02-26 18:33:11 0 d-------- C:\Program Files\Common Files\Control Panels
2008-02-26 18:14:55 0 d-------- C:\Program Files\QuickTime
2008-02-26 18:01:23 0 d-------- C:\Program Files\Bonjour
2008-02-25 21:10:09 1688 --a------ C:\WINDOWS\mozver.dat
2008-02-16 13:42:18 103437 --a------ C:\WINDOWS\hpqins13.dat
2008-02-14 20:06:23 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-02-13 08:57:52 149 --a------ C:\WINDOWS\system32\'
2008-02-10 21:05:25 233472 --a------ C:\WINDOWS\system32\REX Shared Library.dll <Not Verified; Propellerhead Software AB; REX SDK>
2008-02-10 21:05:25 368640 --a------ C:\WINDOWS\system32\ReWire.dll <Not Verified; Propellerhead Software AB; ReWire>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [08/23/2006 03:12 PM]
"nwiz"="nwiz.exe" [08/23/2006 03:12 PM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [08/23/2006 03:12 PM]
"SigmatelSysTrayApp"="stsystra.exe" [07/27/2006 03:19 PM C:\WINDOWS\stsystra.exe]
"AVG7_CC"="E:\AVG\avgcc.exe" [04/23/2008 09:08 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [02/10/2008 07:47 PM]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"=E:\AVG\avgw.exe /RUNONCE

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe [12/11/2007 5:34:48 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ZDWLan Utility.lnk - C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [3/9/2008 11:12:42 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=1 (0x1)
"ClearRecentDocsOnExit"=1 (0x1)
"NoRecentDocsMenu"=1 (0x1)
"NoRecentDocsHistory"=1 (0x1)
"NoStartBanner"=1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=1 (0x1)
"ClearRecentDocsOnExit"=1 (0x1)
"NoRecentDocsMenu"=1 (0x1)
"NoRecentDocsHistory"=1 (0x1)
"NoStartBanner"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ibudu]
ibudu.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^administrator^start menu^programs^startup^rklauncher.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\RKLauncher.lnk
backup=C:\WINDOWS\pss\RKLauncher.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acrobat assistant 8.0]
"E:\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adobeupdater]
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adobe_id0eythm]
C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\autoload]
C:\Documents and Settings\Administrator\cftmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msvtt]
C:\WINDOWS\system32\flciijjq.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntuser]
C:\WINDOWS\system32\drivers\spools.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\registrymechanic]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1535.exe 61A847B5BBF7281337983D466188719AB689201522886B092CBD44BD8689220221DD3257

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinVNC]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yahoo! pager]
"E:\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService LmHosts upnphost SSDPSRV
NetworkService
DcomLaunch DcomLaunch


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3200db41-8161-11dc-a4a5-806d6172696f}]
AutoRun\command- G:\autoRcd.exe




-- End of Deckard's System Scanner: finished at 2008-04-25 16:18:30 ------------

#15 Rahina

Rahina

    Security Helper


  • Members
  • 681 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:08:57 AM

Posted 26 April 2008 - 09:08 AM

Please open HiJackThis and scan. Check the boxes next to all the entries listed below

O3 - Toolbar: dpevflbg - {B4CE8035-501B-4750-9535-CE7F8B708A36} - C:\WINDOWS\dpevflbg.dll (file missing)
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.134 85.255.112.139
O20 - Winlogon Notify: ibudu - ibudu.dll (file missing)
O21 - SSODL: BootAvp - {ae4a823e-ac33-417b-9ce2-cd4300f7f36a} - (no file)
O23 - Service: Indexing Service (cisvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)


Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis

=======================================

Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix!!

Open notepad and copy/paste the text in the quotebox below into it: ( Please make sure you copy everything in the code box )

Dirlook:
C:\WINDOWS\sess_377edh790c7dt52h4jsvqglb46

Folder::
C:\Documents and Settings\All Users\Application Data\jsfqrivs

Driver::
cisvc

File::
C:\WINDOWS\system32\flciijjq.exe
C:\WINDOWS\system32\drivers\spools.exe
C:\WINDOWS\mrofinu1535.exe

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=
"HideLegacyLogonScripts"=-
"HideLogoffScripts"=-
"RunLogonScriptSync"=-
"RunStartupScriptSync"=-
"HideStartupScripts"=-
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=-
"HideLogoffScripts"=-
"RunLogonScriptSync"=-
"RunStartupScriptSync"=-
"HideStartupScripts"=-
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=-
"ClearRecentDocsOnExit"=-
"NoRecentDocsMenu"=-
"NoRecentDocsHistory"=-
"NoStartBanner"=-
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=-
"ClearRecentDocsOnExit"=-
"NoRecentDocsMenu"=-
"NoRecentDocsHistory"=-
"NoStartBanner"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ibudu]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msvtt]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntuser]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
Save this as CFScript.txt

Posted Image

Refering to the picture above, drag CFScript.txt into ComboFix.exe

=======================================

Download CCleaner If you don't want the Yahoo toolbar, be sure to UNcheck that option when installing the software or update.

Instructions for using CCleaner:
  • Launch CCleaner and under Options > Advanced > UNcheck "Only delete files in Windows Temp folder older than 48 hours".
  • A pop up box will appear advising this process will permanently delete files from your system.
  • To protect logon cookies that you wish to retain, under Options > Cookies. Select and using the arrow move those cookies to the "Cookies to keep" column.
  • Then select the items you wish to clean up.
    • In the Windows Tab:
    • Clean all entries in the "Internet Explorer" section.
    • Clean all the entries in the "Windows Explorer" section.
    • Clean all entries in the "System" section.
    • Clean all entries in the "Advanced" section.
    • Clean any others that you choose.
  • In the Applications Tab:
  • Clean all in the Firefox/Mozilla section if you use it.
  • Clean all in the Opera section if you use it.
  • Clean Sun Java in the Internet Section.
  • Please UNcheck "Utilities" (i.e., Ad-Aware, ewido and other security program logs.)
  • Click the "Run Cleaner" button and it will scan and clean your system.
  • Click exit.
  • Shutdown/restart the computer.
=======================================

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Turn off the real time scanner of any existing antivirus program while performing the online scan
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Let me know the results!

Also, are things running better now?
[ Antivirus ] [ Firewall ] [ Spywareblaster ] [ Malwarebytes Anti-Malware ] [ Windows update ] [ Firefox ] [ WinPatrol ] [ ATF Cleaner ]

If i have helped you, donate to help me continue helping others. Posted Image
Posted Image Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users