Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan? Spyware? Help Please!


  • This topic is locked This topic is locked
20 replies to this topic

#1 bighead_norris

bighead_norris

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 12 May 2008 - 06:00 PM

Desktop background has turned blue and reads: "Warning: Spyware threat has been detected on your PC. Your computer has several fatal errors due to spyware activity. It is strongly recommended to install an antispyware software to close all security vulnerabilities. Antispyware software helps to protect your PC against spyware and other security threats. Click here to scan your PC for spyware..."
When you click on the link, it takes you to a website for some spyware removal products.

Please help!!!



Deckard's System Scanner v20071014.68
Run by Owner on 2008-05-12 18:06:56
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
57: 2008-05-12 22:07:04 UTC - RP623 - Deckard's System Scanner Restore Point
56: 2008-05-12 21:08:47 UTC - RP622 - Removed Windows Defender
55: 2008-05-12 20:58:11 UTC - RP621 - Restore Operation
54: 2008-05-12 17:19:08 UTC - RP620 - Windows Defender Checkpoint
53: 2008-05-12 17:04:18 UTC - RP619 - Restore Operation


-- First Restore Point --
1: 2008-05-11 19:34:06 UTC - RP567 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 448 MiB (512 MiB recommended).


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-05-12 18:10:07
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:WINDOWSsystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesCommon FilesSymantec SharedccSvcHst.exe
C:WINDOWSexplorer.exe
C:Program FilesCommon FilesSymantec SharedAppCoreAppSvc32.exe
C:WINDOWSsystem32LEXBCES.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32LEXPPS.EXE
C:Program FilesSymantecLiveUpdateAluSchedulerSvc.exe
C:Program FilesCommon FilesSymantec SharedccSvcHst.exe
C:WINDOWSsystem32gearsec.exe
C:WINDOWSsystem32driversKodakCCS.exe
C:WINDOWSb2new.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32VTTimer.exe
C:WINDOWSAGRSMMSG.exe
C:WINDOWSALCXMNTR.EXE
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesiTunesiTunesHelper.exe
C:Program FilesiPodbiniPodService.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesCompaq Connections1940576ProgramBackWeb-1940576.exe
C:Program FilesKodakKodak EasyShare SoftwarebinEasyShare.exe
C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
C:Program FilesInterMutePopSubtractPopSub.exe
C:Program FilesInterMuteSpySubtractspysub.exe
C:Program FilesInterMuteSpamSubtractSpamSub.exe
C:WINDOWSsystem32rundll32.exe
C:WINDOWSsystem32rundll32.exe
C:WINDOWSsystem32rundll32.exe
C:Program FilesInternet Exploreriexplore.exe
C:Documents and SettingsOwnerDesktopdss.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.google.com/ie
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yahoo.com/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
F2 - REG:system.ini: UserInit=C:WINDOWSsystem32userinit.exe,C:WINDOWSsystem32wmsdkns.exe,
O2 - BHO: (no name) - {0D6F3915-706C-4B98-A03D-E1A6BC0F3E74} - C:WINDOWSsystem32rqRKbbAp.dll
O2 - BHO: (no name) - {2C8811BD-C44A-44EA-B097-27FDBFC2CB0C} - C:WINDOWSsystem32ddcDwVLc.dll
O2 - BHO: (no name) - {5038F88D-4316-0BCE-3C27-6DE4BDB0BDBD} - C:WINDOWSSystem32jcymqrmr.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {69EDD3BC-C4B1-4476-B5F2-9236B0ED9CD4} - C:WINDOWSsystem32mlJBqpml.dll
O2 - BHO: (no name) - {75825E4D-AF7A-47E3-82AB-4E4FC6C24134} - C:WINDOWSsystem32pmnKAqNe.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_10binssv.dll
O2 - BHO: (no name) - {77BDC792-8B57-42B5-BB80-8B23079DDA05} - C:WINDOWSsystem32sSmLfdBr.dll (file missing)
O2 - BHO: (no name) - {8EF9D9AB-666B-7FEC-1B30-4CC62F4966B8} - C:WINDOWSSystem32envn.dll (file missing)
O2 - BHO: (no name) - {C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8} - C:WINDOWSsystem32iiFWQGVO.dll
O2 - BHO: {8a53136c-8f88-895a-73a4-7f2d19c329ad} - {da923c91-d2f7-4a37-a598-88f8c63135a8} - C:WINDOWSsystem32ninjksct.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM..Run: [VTTimer] VTTimer.exe
O4 - HKLM..Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM..Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [osCheck] "C:Program FilesNorton AntiVirusosCheck.exe"
O4 - HKLM..Run: [iTunesHelper] C:Program FilesiTunesiTunesHelper.exe
O4 - HKLM..Run: [Symantec PIF AlertEng] "C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe" /a /m "C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}AlertEng.dll"
O4 - HKLM..Run: [BM0fc81340] Rundll32.exe "C:WINDOWSsystem32afaqugdg.dll",s
O4 - HKLM..Run: [0cfb20dc] rundll32.exe "C:WINDOWSsystem32opuigkau.dll",b
O4 - HKCU..Run: [updateMgr] "C:Program FilesAdobeAcrobat 7.0ReaderAdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Startup: SpamSubtract.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:Program FilesCompaq Connections1940576ProgramBackWeb-1940576.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:Program FilesKodakKodak EasyShare SoftwarebinEasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe
O4 - Global Startup: PopSubtract.lnk = C:Program FilesInterMutePopSubtractPopSub.exe
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:Program FilesCommon FilesIntuitQuickBooksQBUpdateqbupdate.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:Program FilesQuickenbagent.exe
O4 - Global Startup: SpySubtract.lnk = C:Program FilesInterMuteSpySubtractspysub.exe
O7 - HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem, DisableTaskMgr=1
O7 - HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem, DisableTaskMgr=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MI1933~1OFFICE11EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_10binssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:Program FilesAIMaim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O10 - Unknown file in Winsock LSP: C:WINDOWSsystem32nwprovau.dll
O15 - Trusted Zone: *.doginhispen.com (HKCU)
O15 - Trusted Zone: *.whataboutadog.com (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:Program FilesMSN Messengermsgrapp.8.0.0812.00.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:Program FilesMSN Messengermsgrapp.8.0.0812.00.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:Program FilesCommon FilesMicrosoft SharedWeb Components11OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:Program FilesCommon FilesMicrosoft SharedOFFICE11MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:Program FilesSUPERAntiSpywareSASWINLO.dll
O20 - Winlogon Notify: iiFWQGVO - C:WINDOWSsystem32iiFWQGVO.dll
O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:Program FilesSymantecLiveUpdateAluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:WINDOWSsystem32gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:Program FilesiPodbiniPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:Program FilesNorton AntiVirusisPwdSvc.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:WINDOWSsystem32driversKodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:Program FilesSymantecLiveUpdateLuComServer_3_2.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe
O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:WINDOWSb2new.exe
O23 - Service: Symantec Core LC - Unknown owner - C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedAppCoreAppSvc32.exe


--
End of file - 10339 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

S3 ialm - c:windowssystem32driversialmnt5.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT®>
S3 SASENUM - c:program filessuperantispywaresasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S3 usbcm (USB Cable Modem 351000 NDIS Driver) - c:windowssystem32driversusbcm.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 GEARSecurity (Gear Security Service) - c:windowssystem32gearsec.exe <Not Verified; GEAR Software; gearsec>
R2 MsSecurity1.209.4 (MsSecurity Updated) - c:windowsb2new.exe service

S3 gusvc (Google Updater Service) - "c:program filesgooglecommongoogle updatergoogleupdaterservice.exe" (file missing)


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: SW{4245FF73-1DB4-11D2-86E4-98AE20524153}{9B365890-165F-11D0-A195-0020AFD156E4}
Manufacturer:
Name:
PNP Device ID: SW{4245FF73-1DB4-11D2-86E4-98AE20524153}{9B365890-165F-11D0-A195-0020AFD156E4}
Service:


-- Scheduled Tasks -------------------------------------------------------------

2008-03-24 20:00:21 556 --a------ C:WINDOWSTasksNorton AntiVirus - Run Full System Scan - Owner.job


-- Files created between 2008-04-12 and 2008-05-12 -----------------------------

2008-05-12 17:15:28 98960 --a------ C:WINDOWSsystem32ninjksct.dll
2008-05-12 17:12:29 83072 --a------ C:WINDOWSsystem32opuigkau.dll
2008-05-12 17:10:03 2112 --a------ C:WINDOWSsystem32brjncslk.exe
2008-05-12 17:09:33 90240 --a------ C:WINDOWSsystem32afaqugdg.dll
2008-05-12 17:06:26 1050725 --ahs---- C:WINDOWSsystem32lmpqBJlm.ini2
2008-05-12 17:06:17 314480 --a------ C:WINDOWSsystem32mlJBqpml.dll
2008-05-12 14:39:57 1652 --ahs---- C:WINDOWSsystem32pAbbKRqr.ini2
2008-05-12 14:39:53 314480 --a------ C:WINDOWSsystem32rqRKbbAp.dll
2008-05-12 12:56:49 708 --ahs---- C:WINDOWSsystem32ybeeLRqr.ini2
2008-05-12 09:50:56 98896 --a------ C:WINDOWSsystem32tcshotjw.dll
2008-05-12 09:48:17 83008 --a------ C:WINDOWSsystem32lktyoimc.dll
2008-05-12 09:44:53 2048 --a------ C:WINDOWSsystem32bvjlyqfe.exe
2008-05-12 09:42:38 90176 --a------ C:WINDOWSsystem32qwvbmhfu.dll
2008-05-12 09:41:53 1048609 --ahs---- C:WINDOWSsystem32cLVwDcdd.ini2
2008-05-12 09:41:50 316496 --a------ C:WINDOWSsystem32ddcDwVLc.dll
2008-05-12 07:02:21 98896 --a------ C:WINDOWSsystem32ttfohbox.dll
2008-05-12 07:01:53 0 d-------- C:Documents and SettingsOwnerApplication DataInterMute
2008-05-12 07:01:46 131072 --a------ C:WINDOWSsystem32SpSubLSP.dll <Not Verified; InterMute, Inc.; SpamSubtract>
2008-05-12 06:59:20 2048 --a------ C:WINDOWSsystem32wwbmmjnn.exe
2008-05-12 06:57:03 90176 --a------ C:WINDOWSsystem32ocrtrxlj.dll
2008-05-12 06:56:20 1036224 --ahs---- C:WINDOWSsystem32eNqAKnmp.ini2
2008-05-12 06:56:16 316496 --a------ C:WINDOWSsystem32pmnKAqNe.dll
2008-05-11 20:07:36 0 d-------- C:Documents and SettingsAll UsersApplication DataSUPERAntiSpyware.com
2008-05-11 20:06:50 0 d-------- C:Program FilesSUPERAntiSpyware
2008-05-11 20:06:48 0 d-------- C:Documents and SettingsOwnerApplication DataSUPERAntiSpyware.com
2008-05-11 20:05:17 0 d-------- C:Program FilesCommon FilesWise Installation Wizard
2008-05-11 18:30:16 316464 -----n--- C:WINDOWSsystem32hgGwWQKA.dll
2008-05-11 15:33:55 6773 --ahs---- C:WINDOWSsystem32rBdfLmSs.ini2
2008-05-11 15:28:46 25728 --a------ C:WINDOWSsystem32iiFWQGVO.dll
2008-05-11 15:28:32 0 d-------- C:WINDOWSsystem32dFrnx06
2008-05-11 15:28:25 0 d-------- C:Documents and SettingsLocalServiceApplication DataMacromedia
2008-05-11 15:28:18 0 dr------- C:Documents and SettingsLocalServiceFavorites
2008-05-11 15:28:14 4 --a------ C:WINDOWSsystem32winfrun32.bin
2008-05-11 15:27:51 25600 --a------ C:WINDOWSb2new.exe
2008-05-09 13:10:10 229514 --a------ C:WINDOWSsystem32000080.exe


-- Find3M Report ---------------------------------------------------------------

2008-05-12 17:09:03 0 d-------- C:Program FilesWindows Defender
2008-05-12 14:18:54 0 d-------- C:Program FilesCommon FilesSymantec Shared
2008-05-12 09:34:39 0 d-------- C:Program FilesInterMute
2008-05-11 21:12:03 0 d-------- C:Program FilesCommon Files
2008-05-11 18:55:59 0 d-------- C:Program FilesYahoo!
2008-05-11 18:47:47 0 d-------- C:Program FilesMsnMusic
2008-05-09 06:38:37 0 d-------- C:Documents and SettingsOwnerApplication DataAdobeUM
2008-04-16 21:22:07 413 --a------ C:WINDOWSPowerReg.dat


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE~Browser Helper Objects{0D6F3915-706C-4B98-A03D-E1A6BC0F3E74}]
05/12/2008 02:39 PM 314480 --a------ C:WINDOWSsystem32rqRKbbAp.dll

[HKEY_LOCAL_MACHINE~Browser Helper Objects{2C8811BD-C44A-44EA-B097-27FDBFC2CB0C}]
05/12/2008 09:41 AM 316496 --a------ C:WINDOWSsystem32ddcDwVLc.dll

[HKEY_LOCAL_MACHINE~Browser Helper Objects{5038F88D-4316-0BCE-3C27-6DE4BDB0BDBD}]
C:WINDOWSSystem32jcymqrmr.dll

[HKEY_LOCAL_MACHINE~Browser Helper Objects{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_LOCAL_MACHINE~Browser Helper Objects{69EDD3BC-C4B1-4476-B5F2-9236B0ED9CD4}]
05/12/2008 05:06 PM 314480 --a------ C:WINDOWSsystem32mlJBqpml.dll

[HKEY_LOCAL_MACHINE~Browser Helper Objects{75825E4D-AF7A-47E3-82AB-4E4FC6C24134}]
05/12/2008 06:56 AM 316496 --a------ C:WINDOWSsystem32pmnKAqNe.dll

[HKEY_LOCAL_MACHINE~Browser Helper Objects{77BDC792-8B57-42B5-BB80-8B23079DDA05}]
C:WINDOWSsystem32sSmLfdBr.dll

[HKEY_LOCAL_MACHINE~Browser Helper Objects{8EF9D9AB-666B-7FEC-1B30-4CC62F4966B8}]
C:WINDOWSSystem32envn.dll

[HKEY_LOCAL_MACHINE~Browser Helper Objects{C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8}]
05/11/2008 03:28 PM 25728 --a------ C:WINDOWSsystem32iiFWQGVO.dll

[HKEY_LOCAL_MACHINE~Browser Helper Objects{da923c91-d2f7-4a37-a598-88f8c63135a8}]
05/12/2008 05:15 PM 98960 --a------ C:WINDOWSsystem32ninjksct.dll

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"VTTimer"="VTTimer.exe" [01/16/2004 07:33 AM C:WINDOWSsystem32VTTimer.exe]
"AGRSMMSG"="AGRSMMSG.exe" [06/29/2004 10:06 AM C:WINDOWSAGRSMMSG.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [09/07/2004 02:47 PM C:WINDOWSALCXMNTR.EXE]
"ccApp"="C:Program FilesCommon FilesSymantec SharedccApp.exe" [01/10/2007 01:59 AM]
"osCheck"="C:Program FilesNorton AntiVirusosCheck.exe" [01/14/2007 03:11 AM]
"iTunesHelper"="C:Program FilesiTunesiTunesHelper.exe" [01/16/2004 12:16 PM]
"Symantec PIF AlertEng"="C:Program FilesCommon FilesSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe" [11/28/2007 08:51 PM]
"BM0fc81340"="C:WINDOWSsystem32afaqugdg.dll" [05/12/2008 05:09 PM]
"0cfb20dc"="C:WINDOWSsystem32opuigkau.dll" [05/12/2008 05:12 PM]

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"updateMgr"="C:Program FilesAdobeAcrobat 7.0ReaderAdobeUpdateManager.exe" [03/30/2006 04:45 PM]

C:Documents and SettingsOwnerStart MenuProgramsStartup
SpamSubtract.lnk - C:Program FilesInterMuteSpamSubtractSpamSub.exe [5/12/2008 7:01:47 AM]

C:Documents and SettingsAll UsersStart MenuProgramsStartup
Adobe Reader Speed Launch.lnk - C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe [9/23/2005 10:05:26 PM]
Compaq Connections.lnk - C:Program FilesCompaq Connections1940576ProgramBackWeb-1940576.exe [4/2/2004 6:51:16 PM]
Kodak EasyShare software.lnk - C:Program FilesKodakKodak EasyShare SoftwarebinEasyShare.exe [3/10/2005 10:40:30 AM]
Kodak software updater.lnk - C:Program FilesKodakKODAK Software Updater7288971ProgramKodak Software Updater.exe [2/13/2004 3:12:08 PM]
PopSubtract.lnk - C:Program FilesInterMutePopSubtractPopSub.exe [5/12/2008 7:01:02 AM]
QuickBooks 2002 Delivery Agent.lnk - C:Program FilesIntuitQuickBooks ProComponentsQBAgentqbdagent2002.exe [8/12/2004 8:35:27 AM]
QuickBooks Update Agent.lnk - C:Program FilesCommon FilesIntuitQuickBooksQBUpdateqbupdate.exe [10/2/2007 10:03:35 PM]
Quicken Scheduled Updates.lnk - C:Program FilesQuickenbagent.exe [7/30/2003 8:49:48 AM]
SpySubtract.lnk - C:Program FilesInterMuteSpySubtractspysub.exe [5/12/2008 7:01:28 AM]

[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"DisableTaskMgr"=1 (0x1)

[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"DisableTaskMgr"=1 (0x1)

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks]
"{C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8}"= C:WINDOWSsystem32iiFWQGVO.dll [05/11/2008 03:28 PM 25728]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:Program FilesSUPERAntiSpywareSASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad]
"WebProxy"= {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll [ ]

[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogon]
"Userinit"="C:WINDOWSsystem32userinit.exe,C:WINDOWSsystem32wmsdkns.exe,"

[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogonnotify!SASWinLogon]
C:Program FilesSUPERAntiSpywareSASWINLO.dll 04/19/2007 12:41 PM 294912 C:Program FilesSUPERAntiSpywareSASWINLO.dll

[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogonnotifyiiFWQGVO]
iiFWQGVO.dll 05/11/2008 03:28 PM 25728 C:WINDOWSsystem32iiFWQGVO.dll

[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetcontrollsa]
"Authentication Packages"= msv1_0 C:WINDOWSsystem32mlJBqpml

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalvds]
@="Service"

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimal{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionsvchost]
Usnsvc usnsvc

*Newly Created Service* - SASDIFSV

[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{66186F05-BBBB-4a39-864F-72D84615C679}]
rundll32 sockins32.dll,InitModule



-- End of Deckard's System Scanner: finished at 2008-05-12 18:12:53 ------------
------------
Also here is the Kaspersky scan report.........

Merged posts. ~ OB

Edited by Orange Blossom, 12 May 2008 - 09:02 PM.


BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:11:30 AM

Posted 13 May 2008 - 02:21 PM

Hello bighead_norris,

We will run ComboFix.

You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert. It is intended by its creator to be used under the guidance and supervision of an expert, not for private use. Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.


You need to disable your Symantec/Norton Antivirus and Spy subtract
before running ComboFix, as they will prevent it from running.

To disable Norton Antivirus:
Please navigate to the system tray on the bottom right hand corner and look for a Posted Image sign.
  • right-click it -> chose "Disable Auto-Protect."
  • select a duration of 5 hours (this assures no interference with the cleanup of your pc)
  • click "Ok."
  • a popup will warn that protection will now be disabled and the sign will now look like this: Posted Image
You succesfully disabled the Norton Antivirus Guard.

Disable Spy subtract

I don't have instructions how to disable Spysubtract. I'm sure you'll figure that one out yourself. Usually, with many programs there is an icon in the taskbar that you can right click on and turn off.




Please visit this webpage for instructions for downloading and running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

To work properly, you must install ComboFix on the Desktop.

When following the instructions please install the Windows XP Recovery Console if you are using XP. <== IMPORTANT It is a simple procedure that will only take a few moments of your time.


You DO NOT need to have the Windows CD to install Recovery Console!

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.


We need Recovery Console because malware damages a lot and causes an instable system - and because of that, it may happen that your computer won't be able to boot anymore. With the Recovery Console installed, there are extra options present to repair whatever malware damaged.
Also, even though you're not infected, the presence of the Recovery Console is a useful feature in case a computer won't boot anymore because of several other reasons. Read here what you can do with the Recovery Console.

Extra note: After you have installed the Recovery Console - if you reboot your computer, right after reboot, you'll see the option for the Recovery Console now as well.
Don't select to run the Recovery Console as we don't need it.
By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows.

A caution -
Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.
Disconnect from the Internet.
Do not run Combofix more than once.
Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

Post the ComboFix log. Do not post a Hijackthis log.

Edited by SifuMike, 13 May 2008 - 05:06 PM.
add disable norton, spy subtract

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 bighead_norris

bighead_norris
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 13 May 2008 - 09:21 PM

My ComboFix Log:

ComboFix 08-05-12.1 - Owner 2008-05-13 21:34:39.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.135 [GMT -4:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Owner\Application Data\ASEMBL~1
C:\Documents and Settings\Owner\Application Data\PPATCH~1
C:\Documents and Settings\Owner\Application Data\SCURIT~1
C:\Documents and Settings\Owner\My Documents\ASKS~1
C:\Documents and Settings\Owner\My Documents\CROSOF~1.NET
C:\Documents and Settings\Owner\My Documents\SMANTE~1
C:\Program Files\Common Files\icroso~1.net
C:\Program Files\Common Files\smbols~1
C:\Program Files\Common Files\ssembl~1
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\matrix.dat
C:\WINDOWS\123messenger.per
C:\WINDOWS\cookies.ini
C:\WINDOWS\crosof~1.net
C:\WINDOWS\default.htm
C:\WINDOWS\didduid.ini
C:\WINDOWS\licencia.txt
C:\WINDOWS\mainms.vpi
C:\WINDOWS\megavid.cdt
C:\WINDOWS\muotr.so
C:\WINDOWS\pppatc~1
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\000080.exe
C:\WINDOWS\system32\bnvyvyai.ini
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\cLVwDcdd.ini
C:\WINDOWS\system32\cLVwDcdd.ini2
C:\WINDOWS\system32\cmioytkl.ini
C:\WINDOWS\system32\crosof~1
C:\WINDOWS\system32\dtsagpef.ini
C:\WINDOWS\system32\icroso~1.net
C:\WINDOWS\system32\jpayssjn.dll
C:\WINDOWS\system32\njssyapj.ini
C:\WINDOWS\system32\OWHjmUvw.ini
C:\WINDOWS\system32\OWHjmUvw.ini2
C:\WINDOWS\system32\pAbbKRqr.ini
C:\WINDOWS\system32\pAbbKRqr.ini2
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rBdfLmSs.ini
C:\WINDOWS\system32\rBdfLmSs.ini2
C:\WINDOWS\system32\ssnlrafu.dll
C:\WINDOWS\system32\tbhhpxuc.ini
C:\WINDOWS\system32\tDMWxyxx.ini
C:\WINDOWS\system32\tDMWxyxx.ini2
C:\WINDOWS\system32\uakgiupo.ini
C:\WINDOWS\system32\ufarlnss.ini
C:\WINDOWS\system32\winfrun32.bin
C:\WINDOWS\system32\ybeeLRqr.ini
C:\WINDOWS\system32\ybeeLRqr.ini2
C:\WINDOWS\system32\ystem~1
C:\WINDOWS\telefonos.txt
C:\WINDOWS\textos.txt
D:\Autorun.inf

----- BITS: Possible infected sites -----

hxxp://80.93.48.89
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MSSECURITY1.209.4
-------\Legacy_NWSAPAGENT
-------\Service_MsSecurity1.209.4
-------\Service_NwSapAgent


((((((((((((((((((((((((( Files Created from 2008-04-14 to 2008-05-14 )))))))))))))))))))))))))))))))
.

2008-05-13 21:13 . 2008-05-13 21:13 99,008 --a------ C:\WINDOWS\system32\igsfblji.dll
2008-05-13 21:08 . 2008-05-13 21:08 2,112 --a------ C:\WINDOWS\system32\jmulhfle.exe
2008-05-13 21:06 . 2008-05-13 21:06 90,304 --a------ C:\WINDOWS\system32\bwuptkec.dll
2008-05-13 20:40 . 2008-05-13 20:40 2,112 --a------ C:\WINDOWS\system32\vcdrccqu.exe
2008-05-13 20:37 . 2008-05-13 20:37 99,008 --a------ C:\WINDOWS\system32\aolwbpub.dll
2008-05-13 20:30 . 2008-05-13 20:30 90,304 --a------ C:\WINDOWS\system32\hbpkssvh.dll
2008-05-13 20:29 . 2008-05-13 20:29 314,480 --a------ C:\WINDOWS\system32\xxyxWMDt.dll
2008-05-13 07:48 . 2008-05-13 07:48 98,928 --a------ C:\WINDOWS\system32\ywegyajl.dll
2008-05-13 07:31 . 2008-05-13 07:32 2,112 --a------ C:\WINDOWS\system32\gsuqkytu.exe
2008-05-13 07:29 . 2008-05-13 07:29 90,240 --a------ C:\WINDOWS\system32\rttrduwv.dll
2008-05-13 07:28 . 2008-05-13 07:28 314,432 --a------ C:\WINDOWS\system32\wvUmjHWO.dll
2008-05-12 21:35 . 2008-05-12 21:35 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-05-12 21:34 . 2008-05-12 21:36 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-12 21:34 . 2008-05-12 21:36 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-05-12 21:34 . 2008-05-12 21:36 10,563 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-05-12 21:34 . 2008-05-12 21:36 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-05-12 18:56 . 2008-05-12 18:56 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-12 18:56 . 2008-05-12 18:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-12 18:55 . 2008-05-12 21:33 9,506 --a------ C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate
2008-05-12 18:06 . 2008-05-12 18:06 <DIR> d-------- C:\Deckard
2008-05-12 17:15 . 2008-05-12 17:15 98,960 --a------ C:\WINDOWS\system32\ninjksct.dll
2008-05-12 17:10 . 2008-05-12 17:10 2,112 --a------ C:\WINDOWS\system32\brjncslk.exe
2008-05-12 17:09 . 2008-05-12 17:09 90,240 --a------ C:\WINDOWS\system32\afaqugdg.dll
2008-05-12 14:39 . 2008-05-12 14:39 314,480 --a------ C:\WINDOWS\system32\rqRKbbAp.dll
2008-05-12 09:50 . 2008-05-12 09:50 98,896 --a------ C:\WINDOWS\system32\tcshotjw.dll
2008-05-12 09:48 . 2008-05-12 09:48 1,504,983 ---hs---- C:\WINDOWS\system32\dtsagpef.tmp
2008-05-12 09:48 . 2008-05-12 09:48 83,008 --a------ C:\WINDOWS\system32\lktyoimc.dll
2008-05-12 09:44 . 2008-05-12 09:44 2,048 --a------ C:\WINDOWS\system32\bvjlyqfe.exe
2008-05-12 09:42 . 2008-05-12 09:42 90,176 --a------ C:\WINDOWS\system32\qwvbmhfu.dll
2008-05-12 09:41 . 2008-05-12 09:41 316,496 --a------ C:\WINDOWS\system32\ddcDwVLc.dll
2008-05-12 07:02 . 2008-05-12 07:02 98,896 --a------ C:\WINDOWS\system32\ttfohbox.dll
2008-05-12 07:01 . 2008-05-12 07:01 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\InterMute
2008-05-12 07:01 . 2008-05-12 07:01 131,072 --a------ C:\WINDOWS\system32\SpSubLSP.dll
2008-05-12 07:01 . 2008-05-12 07:02 2,154 --a------ C:\WINDOWS\system32\ssmute.ini
2008-05-12 07:01 . 2008-05-12 07:02 2,150 --a------ C:\WINDOWS\system32\mshrml.ini
2008-05-12 07:01 . 2008-05-12 07:01 1,195 --a------ C:\WINDOWS\system32\imbrmute.ini
2008-05-12 06:59 . 2008-05-12 06:59 2,048 --a------ C:\WINDOWS\system32\wwbmmjnn.exe
2008-05-12 06:57 . 2008-05-13 21:44 109,803 --a------ C:\WINDOWS\BM0fc81340.xml
2008-05-12 06:57 . 2008-05-12 06:57 90,176 --a------ C:\WINDOWS\system32\ocrtrxlj.dll
2008-05-11 20:07 . 2008-05-11 20:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-11 20:06 . 2008-05-12 13:41 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-11 20:06 . 2008-05-11 20:06 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2008-05-11 20:05 . 2008-05-11 20:05 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-11 18:30 . 2008-05-11 18:30 316,464 --------- C:\WINDOWS\system32\hgGwWQKA.dll
2008-05-11 15:28 . 2008-05-11 15:28 <DIR> d-------- C:\WINDOWS\system32\dFrnx06
2008-05-11 15:28 . 2008-05-11 15:28 <DIR> d-------- C:\temp\tmpvc14
2008-05-11 15:28 . 2008-05-11 15:28 25,728 --a------ C:\WINDOWS\system32\iiFWQGVO.dll
2008-05-11 15:28 . 2008-05-11 15:28 578 --a------ C:\WINDOWS\index.html
2008-05-11 15:27 . 2008-05-11 15:27 25,600 --a------ C:\WINDOWS\b2new.exe
2008-04-27 17:18 . 2008-05-12 19:14 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-27 17:18 . 2008-04-27 17:18 1,409 --a------ C:\WINDOWS\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-13 21:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-13 21:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-13 11:34 --------- d-----w C:\Program Files\Norton AntiVirus
2008-05-13 01:36 --------- d-----w C:\Program Files\Symantec
2008-05-12 21:09 --------- d-----w C:\Program Files\Windows Defender
2008-05-12 13:34 --------- d-----w C:\Program Files\InterMute
2008-05-11 22:55 --------- d-----w C:\Program Files\Yahoo!
2008-05-11 22:47 --------- d-----w C:\Program Files\MsnMusic
2008-05-09 10:38 --------- d-----w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 08:59 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2003-08-27 19:19 36,963 ----a-r C:\Program Files\Common Files\SM1updtr.dll
2005-01-24 00:17 0 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 61,440 2003-02-12 03:02:48 C:\hp\KBD\bak\KBD.EXE

----a-w 180,269 2006-07-12 15:45:01 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe

----a-w 229,376 2004-01-17 03:16:18 C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w 229,376 2004-01-16 16:16:18 C:\Program Files\iTunes\iTunesHelper.exe

----a-w 102 2007-10-07 01:56:15 C:\Program Files\iTunes\bak\iTunesHelperAppLog.txt

----a-w 49,263 2006-11-09 20:07:30 C:\Program Files\Java\jre1.5.0_10\bin\bak\jusched.exe

----a-w 106,496 2003-09-04 02:33:54 C:\Program Files\Lexmark 3100 Series\bak\lxbrbmgr.exe

----a-w 294,912 2003-06-13 14:57:18 C:\Program Files\Lexmark 3100 Series\bak\LXBRKsk.exe

----a-w 98,304 2004-04-02 22:35:19 C:\Program Files\QuickTime\bak\qttask.exe

----a-w 233,472 2004-04-14 20:43:46 C:\WINDOWS\SMINST\bak\RECGUARD.EXE

----a-w 52,736 1998-05-08 00:04:38 C:\WINDOWS\system\bak\hpsysdrv.exe

----a-w 98,304 2003-09-13 03:13:20 C:\WINDOWS\system32\bak\ps2.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5038F88D-4316-0BCE-3C27-6DE4BDB0BDBD}]
C:\WINDOWS\System32\jcymqrmr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-05-12 21:41 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{77BDC792-8B57-42B5-BB80-8B23079DDA05}]
C:\WINDOWS\system32\sSmLfdBr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8EF9D9AB-666B-7FEC-1B30-4CC62F4966B8}]
C:\WINDOWS\System32\envn.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BCCFE114-4C6E-4657-81C1-5EAADC0FE466}]
2008-05-13 20:29 314480 --a------ C:\WINDOWS\system32\xxyxWMDt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8}]
2008-05-11 15:28 25728 --a------ C:\WINDOWS\system32\iiFWQGVO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cc97ce76-af40-4e5b-8ff0-4633939acd8a}]
2008-05-13 21:13 99008 --a------ C:\WINDOWS\system32\igsfblji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CCEB9A1F-F9C2-47D6-B694-37A940EFFEFE}]
2008-05-12 14:39 314480 --a------ C:\WINDOWS\system32\rqRKbbAp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F33E93A7-6402-4948-9F1C-9B5650DE7F7D}]
2008-05-13 07:28 314432 --a------ C:\WINDOWS\system32\wvUmjHWO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2004-01-16 07:33 49152 C:\WINDOWS\system32\VTTimer.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 10:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 14:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-16 12:16 229376]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-25 21:47 51048]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-02-07 02:49 718704]
"BM0fc81340"="C:\WINDOWS\system32\bwuptkec.dll" [2008-05-13 21:06 90304]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
SpamSubtract.lnk - C:\Program Files\InterMute\SpamSubtract\SpamSub.exe [2008-05-12 07:01:47 589824]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-02 18:51:16 16384]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe [2005-03-10 10:40:30 757760]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 15:12:08 16423]
PopSubtract.lnk - C:\Program Files\InterMute\PopSubtract\PopSub.exe [2008-05-12 07:01:02 233472]
QuickBooks 2002 Delivery Agent.lnk - C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\qbdagent2002.exe [2004-08-12 08:35:27 315392]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-10-02 22:03:35 815104]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-07-30 08:49:48 57344]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\spysub.exe [2008-05-12 07:01:28 983040]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
"{C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8}"= C:\WINDOWS\system32\iiFWQGVO.dll [2008-05-11 15:28 25728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebProxy"= {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iiFWQGVO]
iiFWQGVO.dll 2008-05-11 15:28 25728 C:\WINDOWS\system32\iiFWQGVO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\msncall.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{66186F05-BBBB-4a39-864F-72D84615C679}]
rundll32 sockins32.dll,InitModule
.
Contents of the 'Scheduled Tasks' folder
"2008-05-13 11:30:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Owner.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-13 21:45:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\iiFWQGVO.dll

PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\bwuptkec.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\gearsec.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-05-13 21:56:42 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-05-14 01:56:19

Pre-Run: 86,723,072,000 bytes free
Post-Run: 87,163,445,248 bytes free

267 --- E O F --- 2008-04-10 16:03:47

#4 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:11:30 AM

Posted 13 May 2008 - 11:15 PM

Hi bighead_norris,


You have some suspicious files we need to check.

Go to My Computer and double-click C.
Go to the Tools menu and select 'Folder Options'.
On the 'View' tab select 'show hidden files and folders',
deselect (uncheck) 'hide protected operating system files (recommended)', and
deselect (uncheck) "Hide extensions for known file types.'


Go to next site: http://www.virustotal.com/en/indexf.html
On top you'll find 'Browse'
Click the browse button and browse to next file:

C:\WINDOWS\BM0fc81340.xml

Click open.
Then click the 'Send' button next to it.
This will scan the file. Please be patient.
Save the results in notepad.

Perform the same for next files:

C:\WINDOWS\system32\ssmute.ini
C:\WINDOWS\system32\mshrml.ini
C:\WINDOWS\system32\imbrmute.ini



Once scanned, copy and paste the results also in your next reply.

NOTE: I usually enter my email address at virus total so they can send me the scan results. They usually only take a couple minutes to reply.
You can copy/paste the results of scan results here.

********************************

Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


Click Start, then Run and type Notepad and click OK.
Open notepad - don't use any other text editor than notepad or the script will fail.
Copy/paste the text in the code box below into notepad:

KILLALL:: 

File::
C:\WINDOWS\system32\dtsagpef.tmp
C:\WINDOWS\system32\hgGwWQKA.dll
C:\WINDOWS\system32\iiFWQGVO.dll
C:\WINDOWS\b2new.exe 
C:\WINDOWS\index.html
C:\WINDOWS\system32\igsfblji.dll
C:\WINDOWS\system32\jmulhfle.exe
C:\WINDOWS\system32\bwuptkec.dll
C:\WINDOWS\system32\vcdrccqu.exe
C:\WINDOWS\system32\aolwbpub.dll
C:\WINDOWS\system32\hbpkssvh.dll
C:\WINDOWS\system32\xxyxWMDt.dll
C:\WINDOWS\system32\ywegyajl.dll
C:\WINDOWS\system32\gsuqkytu.exe
C:\WINDOWS\system32\rttrduwv.dll
C:\WINDOWS\system32\wvUmjHWO.dll
C:\WINDOWS\system32\ninjksct.dll
C:\WINDOWS\system32\brjncslk.exe
C:\WINDOWS\system32\afaqugdg.dll
C:\WINDOWS\system32\rqRKbbAp.dll
C:\WINDOWS\system32\tcshotjw.dll
C:\WINDOWS\system32\dtsagpef.tmp
C:\WINDOWS\system32\lktyoimc.dll
C:\WINDOWS\system32\bvjlyqfe.exe
C:\WINDOWS\system32\qwvbmhfu.dll
C:\WINDOWS\system32\ddcDwVLc.dll
C:\WINDOWS\system32\ttfohbox.dll
C:\WINDOWS\system32\wwbmmjnn.exe
C:\WINDOWS\system32\ocrtrxlj.dll
C:\WINDOWS\system32\bwuptkec.dll
C:\WINDOWS\system32\iiFWQGVO.dll

Registry:: 
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5038F88D-4316-0BCE-3C27-6DE4BDB0BDBD}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{77BDC792-8B57-42B5-BB80-8B23079DDA05}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8EF9D9AB-666B-7FEC-1B30-4CC62F4966B8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BCCFE114-4C6E-4657-81C1-5EAADC0FE466}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cc97ce76-af40-4e5b-8ff0-4633939acd8a}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CCEB9A1F-F9C2-47D6-B694-37A940EFFEFE}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F33E93A7-6402-4948-9F1C-9B5650DE7F7D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BM0fc81340"=-	
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iiFWQGVO]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8}"=- 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebProxy"=-


Name the Notepad file CFScript.txt and Save it to your desktop.

IMPORTANT: The above script was written specifically for this infection on this person's computer. It is NOT to be used on another computer, as it may cause damage that could result in a format!

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Edited by SifuMike, 13 May 2008 - 11:33 PM.
hilite fields

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:11:30 AM

Posted 20 May 2008 - 09:07 PM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact me or a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#6 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:11:30 AM

Posted 20 May 2008 - 11:13 PM

topic reopened :thumbsup:
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 bighead_norris

bighead_norris
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 21 May 2008 - 04:44 PM

Files scanned by VirusTotal........



File BM0fc81340.xml received on 05.21.2008 05:21:23 (CET)Antivirus Version Last Update Result
AhnLab-V3 2008.5.20.0 2008.05.20 -
AntiVir 7.8.0.19 2008.05.20 -
Authentium 5.1.0.4 2008.05.21 -
Avast 4.8.1195.0 2008.05.21 -
AVG 7.5.0.516 2008.05.20 -
BitDefender 7.2 2008.05.21 -
CAT-QuickHeal 9.50 2008.05.19 -
ClamAV 0.92.1 2008.05.21 -
DrWeb 4.44.0.09170 2008.05.20 -
eSafe 7.0.15.0 2008.05.20 -
eTrust-Vet 31.4.5808 2008.05.21 -
Ewido 4.0 2008.05.20 -
F-Prot 4.4.2.54 2008.05.14 -
F-Secure 6.70.13260.0 2008.05.21 -
Fortinet 3.14.0.0 2008.05.21 -
GData 2.0.7306.1023 2008.05.21 -
Ikarus T3.1.1.26.0 2008.05.21 -
Kaspersky 7.0.0.125 2008.05.21 -
McAfee 5299 2008.05.20 -
Microsoft 1.3520 2008.05.21 -
NOD32v2 3115 2008.05.20 -
Norman 5.80.02 2008.05.20 -
Panda 9.0.0.4 2008.05.21 -
Prevx1 V2 2008.05.21 -
Rising 20.45.12.00 2008.05.20 -
Sophos 4.29.0 2008.05.21 -
Sunbelt 3.0.1123.1 2008.05.17 -
Symantec 10 2008.05.21 -
TheHacker 6.2.92.314 2008.05.20 -
VBA32 3.12.6.6 2008.05.20 -
VirusBuster 4.3.26:9 2008.05.20 -
Webwasher-Gateway 6.6.2 2008.05.21 BlockReason.0

Additional information
File size: 109803 bytes
MD5...: 5676901470271a7eff508b60b82c49d7
SHA1..: 6b8e5cde1c7e3169c2540a102b3876e0a405c3be
SHA256: 04e377d94e888bf9ebd6fb8e903a9cd371a397ebfeeb04bc55fe89e58cda6543
SHA512: 00e1d397b7f9eb777d90d80e9435015d806b96d38c605b6b50db0387f3a178a6<BR>eb6eb91374407896698de5154911f0f880ab35a284de883b08955f814a557516
PEiD..: -
PEInfo: -



File ssmute.ini received on 05.21.2008 05:28:53 (CET)Antivirus Version Last Update Result
AhnLab-V3 2008.5.20.0 2008.05.20 -
AntiVir 7.8.0.19 2008.05.20 -
Authentium 5.1.0.4 2008.05.21 -
Avast 4.8.1195.0 2008.05.21 -
AVG 7.5.0.516 2008.05.20 -
BitDefender 7.2 2008.05.21 -
CAT-QuickHeal 9.50 2008.05.19 -
ClamAV 0.92.1 2008.05.21 -
DrWeb 4.44.0.09170 2008.05.20 -
eSafe 7.0.15.0 2008.05.20 -
eTrust-Vet 31.4.5808 2008.05.21 -
Ewido 4.0 2008.05.20 -
F-Prot 4.4.2.54 2008.05.16 -
F-Secure 6.70.13260.0 2008.05.21 -
Fortinet 3.14.0.0 2008.05.21 -
GData 2.0.7306.1023 2008.05.21 -
Ikarus T3.1.1.26.0 2008.05.21 -
Kaspersky 7.0.0.125 2008.05.21 -
McAfee 5299 2008.05.20 -
Microsoft 1.3520 2008.05.21 -
NOD32v2 3115 2008.05.20 -
Norman 5.80.02 2008.05.20 -
Panda 9.0.0.4 2008.05.21 -
Prevx1 V2 2008.05.21 -
Rising 20.45.12.00 2008.05.20 -
Sophos 4.29.0 2008.05.21 -
Sunbelt 3.0.1123.1 2008.05.17 -
Symantec 10 2008.05.21 -
TheHacker 6.2.92.314 2008.05.20 -
VBA32 3.12.6.6 2008.05.20 -
VirusBuster 4.3.26:9 2008.05.20 -
Webwasher-Gateway 6.6.2 2008.05.21 BlockReason.0

Additional information
File size: 2154 bytes
MD5...: b2e739f966efd22f6bf29b6e1acc791c
SHA1..: df158ac7bf52a5bf249883a80f73eac8099cb8ca
SHA256: adf963ab2d0c08f19935ff301d54406259ea1890e1f4c244d728201892683f06
SHA512: 990b95f5197b844e35114f6e97e18c32f31170a8c1db3df9173d0da1d8fd2bd1<BR>754571f62a3165103e230ba20240ff2c612337215954eacc0c06f2ac8261fcf8
PEiD..: -
PEInfo: -



File mshrml.ini received on 05.21.2008 05:32:04 (CET)Antivirus Version Last Update Result
AhnLab-V3 2008.5.20.0 2008.05.20 -
AntiVir 7.8.0.19 2008.05.20 -
Authentium 5.1.0.4 2008.05.21 -
Avast 4.8.1195.0 2008.05.21 -
AVG 7.5.0.516 2008.05.20 -
BitDefender 7.2 2008.05.21 -
CAT-QuickHeal 9.50 2008.05.19 -
ClamAV 0.92.1 2008.05.21 -
DrWeb 4.44.0.09170 2008.05.20 -
eSafe 7.0.15.0 2008.05.20 -
eTrust-Vet 31.4.5808 2008.05.21 -
Ewido 4.0 2008.05.20 -
F-Prot 4.4.2.54 2008.05.16 -
F-Secure 6.70.13260.0 2008.05.21 -
Fortinet 3.14.0.0 2008.05.21 -
GData 2.0.7306.1023 2008.05.21 -
Ikarus T3.1.1.26.0 2008.05.21 -
Kaspersky 7.0.0.125 2008.05.21 -
McAfee 5299 2008.05.20 -
Microsoft 1.3520 2008.05.21 -
NOD32v2 3115 2008.05.20 -
Norman 5.80.02 2008.05.20 -
Panda 9.0.0.4 2008.05.21 -
Prevx1 V2 2008.05.21 -
Rising 20.45.12.00 2008.05.20 -
Sophos 4.29.0 2008.05.21 -
Sunbelt 3.0.1123.1 2008.05.17 -
Symantec 10 2008.05.21 -
TheHacker 6.2.92.314 2008.05.20 -
VBA32 3.12.6.6 2008.05.20 -
VirusBuster 4.3.26:9 2008.05.20 -
Webwasher-Gateway 6.6.2 2008.05.21 BlockReason.0

Additional information
File size: 2150 bytes
MD5...: 6ef421a4ef950da29cff948710f8d428
SHA1..: d7c31cd1af17af87dfb64eccfa77a645a1f53932
SHA256: 3b6646c218e6f8980696e5ea35eb2aa6102432f6d0ea99d8471da557698ac158
SHA512: 13e973f417da65f2b0f1281793ea653a300d3c182c051bcd70cf2bfb27efa026<BR>eb77fe26cd54de30b6f8a86737e0ea8cc7a9e1fb68322e98e65afafda94ecdab
PEiD..: -
PEInfo: -


File imbrmute.ini received on 05.21.2008 05:33:37 (CET)Antivirus Version Last Update Result
AhnLab-V3 2008.5.20.0 2008.05.20 -
AntiVir 7.8.0.19 2008.05.20 -
Authentium 5.1.0.4 2008.05.21 -
Avast 4.8.1195.0 2008.05.21 -
AVG 7.5.0.516 2008.05.20 -
BitDefender 7.2 2008.05.21 -
CAT-QuickHeal 9.50 2008.05.19 -
ClamAV 0.92.1 2008.05.21 -
DrWeb 4.44.0.09170 2008.05.20 -
eSafe 7.0.15.0 2008.05.20 -
eTrust-Vet 31.4.5808 2008.05.21 -
Ewido 4.0 2008.05.20 -
F-Prot 4.4.2.54 2008.05.16 -
F-Secure 6.70.13260.0 2008.05.21 -
Fortinet 3.14.0.0 2008.05.21 -
GData 2.0.7306.1023 2008.05.21 -
Ikarus T3.1.1.26.0 2008.05.21 -
Kaspersky 7.0.0.125 2008.05.21 -
McAfee 5299 2008.05.20 -
Microsoft 1.3520 2008.05.21 -
NOD32v2 3115 2008.05.20 -
Norman 5.80.02 2008.05.20 -
Panda 9.0.0.4 2008.05.21 -
Prevx1 V2 2008.05.21 -
Rising 20.45.12.00 2008.05.20 -
Sophos 4.29.0 2008.05.21 -
Sunbelt 3.0.1123.1 2008.05.17 -
Symantec 10 2008.05.21 -
TheHacker 6.2.92.314 2008.05.20 -
VBA32 3.12.6.6 2008.05.20 -
VirusBuster 4.3.26:9 2008.05.20 -
Webwasher-Gateway 6.6.2 2008.05.21 BlockReason.0

Additional information
File size: 1195 bytes
MD5...: 8401bdd151fc994d44e6d9c55ff81bf5
SHA1..: 9a0baf2ef5719ce4dd6ae64cf5315f3b60f83179
SHA256: 35634f5c5cefbaa449b3156b788512d2bac225fe6c54389a2ce3c56def074194
SHA512: 517c9fb805ee16ce06590f4e3504512b5386d0ba196ee38fc5f2d3df815686ba<BR>88873edc7a5068320bde07a308e1fb223aa882fad242aaf308ee93d788327463
PEiD..: -
PEInfo: -

#8 bighead_norris

bighead_norris
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 21 May 2008 - 04:53 PM

Deckard's System Scanner v20071014.68
Run by Owner on 2008-05-21 17:48:06
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 448 MiB (512 MiB recommended).


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-05-21 17:48:51
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\gearsec.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\InterMute\PopSubtract\PopSub.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\InterMute\SpySubtract\spysub.exe
C:\Program Files\InterMute\SpamSubtract\SpamSub.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\FRAH0VQN\dss[1].exe
C:\WINDOWS\system32\rundll32.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
O2 - BHO: {7b6f376b-8288-d0aa-3d64-e85a8029aa04} - {40aa9208-a58e-46d3-aa0d-8828b673f6b7} - C:\WINDOWS\system32\sdoemwjn.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Startup: SpamSubtract.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: PopSubtract.lnk = C:\Program Files\InterMute\PopSubtract\PopSub.exe
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\spysub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\nwprovau.dll
O15 - Trusted Zone: *.doginhispen.com (HKCU)
O15 - Trusted Zone: *.whataboutadog.com (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.0.0812.00.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.0.0812.00.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\system32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


--
End of file - 8275 bytes

-- Files created between 2008-04-21 and 2008-05-21 -----------------------------

2008-05-20 22:16:46 100048 --a------ C:\WINDOWS\system32\sdoemwjn.dll
2008-05-20 22:16:40 2624 --a------ C:\WINDOWS\system32\xejuehpc.exe
2008-05-20 22:15:14 90272 --a------ C:\WINDOWS\system32\jtvnwdbf.dll
2008-05-19 12:28:43 99920 --a------ C:\WINDOWS\system32\awkcwrpf.dll
2008-05-19 08:26:10 90224 --a------ C:\WINDOWS\system32\amflingd.dll
2008-05-13 21:30:29 68096 --a------ C:\WINDOWS\zip.exe
2008-05-13 21:30:29 49152 --a------ C:\WINDOWS\VFind.exe
2008-05-13 21:30:29 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-05-13 21:30:29 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-05-13 21:30:29 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-05-13 21:30:29 98816 --a------ C:\WINDOWS\sed.exe
2008-05-13 21:30:29 80412 --a------ C:\WINDOWS\grep.exe
2008-05-13 21:30:29 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-05-12 21:35:20 0 d-------- C:\Program Files\Windows Sidebar
2008-05-12 18:56:13 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-12 18:56:09 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-12 07:01:53 0 d-------- C:\Documents and Settings\Owner\Application Data\InterMute
2008-05-12 07:01:46 131072 --a------ C:\WINDOWS\system32\SpSubLSP.dll <Not Verified; InterMute, Inc.; SpamSubtract>
2008-05-11 20:07:36 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-11 20:06:50 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-05-11 20:06:48 0 d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2008-05-11 20:05:17 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-11 15:28:32 0 d-------- C:\WINDOWS\system32\dFrnx06
2008-05-11 15:28:25 0 d-------- C:\Documents and Settings\LocalService\Application Data\Macromedia
2008-05-11 15:28:18 0 dr------- C:\Documents and Settings\LocalService\Favorites


-- Find3M Report ---------------------------------------------------------------

2008-05-21 12:09:55 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-05-13 21:35:45 0 d-------- C:\Program Files\Common Files
2008-05-13 07:34:08 0 d-------- C:\Program Files\Norton AntiVirus
2008-05-12 21:36:59 0 d-------- C:\Program Files\Symantec
2008-05-12 17:09:03 0 d-------- C:\Program Files\Windows Defender
2008-05-12 09:34:39 0 d-------- C:\Program Files\InterMute
2008-05-11 18:55:59 0 d-------- C:\Program Files\Yahoo!
2008-05-11 18:47:47 0 d-------- C:\Program Files\MsnMusic
2008-05-09 06:38:37 0 d-------- C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-04-16 21:22:07 413 --a------ C:\WINDOWS\PowerReg.dat


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40aa9208-a58e-46d3-aa0d-8828b673f6b7}]
05/20/2008 10:16 PM 100048 --a------ C:\WINDOWS\system32\sdoemwjn.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
05/12/2008 09:41 PM 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [01/16/2004 07:33 AM C:\WINDOWS\system32\VTTimer.exe]
"AGRSMMSG"="AGRSMMSG.exe" [06/29/2004 10:06 AM C:\WINDOWS\AGRSMMSG.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [09/07/2004 02:47 PM C:\WINDOWS\ALCXMNTR.EXE]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [01/16/2004 12:16 PM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/25/2008 09:47 PM]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [02/07/2008 02:49 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [03/30/2006 04:45 PM]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
SpamSubtract.lnk - C:\Program Files\InterMute\SpamSubtract\SpamSub.exe [5/12/2008 7:01:47 AM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM]
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [4/2/2004 6:51:16 PM]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe [3/10/2005 10:40:30 AM]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2/13/2004 3:12:08 PM]
PopSubtract.lnk - C:\Program Files\InterMute\PopSubtract\PopSub.exe [5/12/2008 7:01:02 AM]
QuickBooks 2002 Delivery Agent.lnk - C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\qbdagent2002.exe [8/12/2004 8:35:27 AM]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [10/2/2007 10:03:35 PM]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [7/30/2003 8:49:48 AM]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\spysub.exe [5/12/2008 7:01:28 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{66186F05-BBBB-4a39-864F-72D84615C679}]
rundll32 sockins32.dll,InitModule



-- End of Deckard's System Scanner: finished at 2008-05-21 17:50:00 ------------

#9 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:11:30 AM

Posted 21 May 2008 - 05:43 PM

Hi bighead_norris,

You have a AWF infection on this computer, so some of your programs are not working.

Download FindAWF:
http://noahdfear.geekstogo.com/FindAWF.exe
Save the file to the Desktop
Double-click the FindAWF icon.

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 1 then Enter to scan for bak folders
The scan may take a while, please be patient.

When done, a text file, Find AWF report is produced that we need to look at.
Please post it in your reply.

****************************


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


Click Start, then Run and type Notepad and click OK.
Open notepad - don't use any other text editor than notepad or the script will fail.
Copy/paste the text in the code box below into notepad:

KILLALL:: 

File::
C:\WINDOWS\system32\sdoemwjn.dll
C:\WINDOWS\system32\xejuehpc.exe
C:\WINDOWS\system32\jtvnwdbf.dll
C:\WINDOWS\system32\awkcwrpf.dll
C:\WINDOWS\system32\amflingd.dll
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\BM0fc81340.xml

Registry:: 
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40aa9208-a58e-46d3-aa0d-8828b673f6b7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"=-


Name the Notepad file CFScript.txt and Save it to your desktop.

IMPORTANT: The above script was written specifically for this infection on this person's computer. It is NOT to be used on another computer, as it may cause damage that could result in a format!

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt, a new HijackThis log and the FindAWF log.

Edited by SifuMike, 21 May 2008 - 05:45 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#10 bighead_norris

bighead_norris
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 21 May 2008 - 06:40 PM

Logs.......

#11 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:11:30 AM

Posted 21 May 2008 - 10:36 PM

Hi bighead_norris,

Please double-click the FindAWF icon once again

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 2 then Enter to restore files from bak folders

A text file opens called: files.txt
Click below the line and paste the following list of files to be restored:


"C:\hp\KBD\bak\KBD.EXE"
"C:\Program Files\iTunes\bak\iTunesHelper.exe"
"C:\Program Files\iTunes\bak\iTunesHelperAppLog.txt"
"C:\Program Files\Lexmark 3100 Series\bak\lxbrbmgr.exe"
"C:\Program Files\Lexmark 3100 Series\bak\LXBRKsk.exe"
"C:\Program Files\QuickTime\bak\qttask.exe"
"C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
"C:\WINDOWS\system\bak\hpsysdrv.exe"
"C:\WINDOWS\system32\bak\ps2.exe"
"C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
"C:\Program Files\Java\jre1.5.0_10\bin\bak\jusched.exe"


Next, close and click Yes to save the changes.

Once files.txt is saved, FindAWF does the following:
-It attempts to terminate the process represented by each filename on the list, if running
-Deletes the rogue file from the parent folder, if present
-Copies the original file to the parent folder

When done with the above, it automatically runs a new scan and opens a new log.
Please provide the new FindAWF log in your reply.
Please DO NOT attach your logs. They are too hard to read that way.
****************************


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


Click Start, then Run and type Notepad and click OK.
Open notepad - don't use any other text editor than notepad or the script will fail.
Copy/paste the text in the code box below into notepad:

KILLALL:: 

Registry:: 
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{66186F05-BBBB-4a39-864F-72D84615C679}]


Name the Notepad file CFScript.txt and Save it to your desktop.

IMPORTANT: The above script was written specifically for this infection on this person's computer. It is NOT to be used on another computer, as it may cause damage that could result in a format!

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
Please DO NOT attach your logs. They are too hard to read that way.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#12 bighead_norris

bighead_norris
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 22 May 2008 - 05:02 PM

Find AWF report by noahdfear ©2006
Version 1.40
Option 2 run successfully

The current date is: Thu 05/22/2008
The current time is: 17:24:18.42


bak folders found
~~~~~~~~~~~


Directory of C:\HP\KBD\BAK

02/11/2003 11:02 PM 61,440 KBD.EXE
1 File(s) 61,440 bytes

Directory of C:\PROGRA~1\ITUNES\BAK

01/16/2004 11:16 PM 229,376 iTunesHelper.exe
10/06/2007 09:56 PM 102 iTunesHelperAppLog.txt
2 File(s) 229,478 bytes

Directory of C:\PROGRA~1\LEXMAR~1\BAK

09/03/2003 10:33 PM 106,496 lxbrbmgr.exe
06/13/2003 10:57 AM 294,912 LXBRKsk.exe
2 File(s) 401,408 bytes

Directory of C:\PROGRA~1\MSNMES~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

04/02/2004 06:35 PM 98,304 qttask.exe
1 File(s) 98,304 bytes

Directory of C:\WINDOWS\SMINST\BAK

04/14/2004 04:43 PM 233,472 RECGUARD.EXE
1 File(s) 233,472 bytes

Directory of C:\WINDOWS\SYSTEM\BAK

05/07/1998 08:04 PM 52,736 hpsysdrv.exe
1 File(s) 52,736 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

09/12/2003 11:13 PM 98,304 ps2.exe
1 File(s) 98,304 bytes

Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

07/12/2006 11:45 AM 180,269 realsched.exe
1 File(s) 180,269 bytes

Directory of C:\PROGRA~1\JAVA\JRE15~1.0_1\BIN\BAK

11/09/2006 04:07 PM 49,263 jusched.exe
1 File(s) 49,263 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

61440 Feb 11 2003 "C:\hp\KBD\KBD.EXE"
61440 Feb 11 2003 "C:\hp\KBD\bak\KBD.EXE"
229376 Jan 16 2004 "C:\Program Files\iTunes\iTunesHelper.exe"
229376 Jan 16 2004 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
102 Oct 6 2007 "C:\Program Files\iTunes\iTunesHelperAppLog.txt"
102 Oct 6 2007 "C:\Program Files\iTunes\bak\iTunesHelperAppLog.txt"
106496 Sep 3 2003 "C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe"
106496 Sep 3 2003 "C:\Program Files\Lexmark 3100 Series\bak\lxbrbmgr.exe"
294912 Jun 13 2003 "C:\Program Files\Lexmark 3100 Series\LXBRKsk.exe"
294912 Jun 13 2003 "C:\Program Files\Lexmark 3100 Series\bak\LXBRKsk.exe"
98304 Apr 2 2004 "C:\Program Files\QuickTime\qttask.exe"
98304 Apr 2 2004 "C:\Program Files\QuickTime\bak\qttask.exe"
233472 Apr 14 2004 "C:\WINDOWS\SMINST\RECGUARD.EXE"
233472 Apr 14 2004 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
233472 Apr 14 2004 "C:\hp\patches\43WW3OWN\files\UP\Recguard.exe"
233472 Apr 14 2004 "D:\hp\patches\43WW3OWN\files\UP\Recguard.exe"
52736 May 7 1998 "C:\WINDOWS\system\hpsysdrv.exe"
52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe"
98304 Sep 12 2003 "C:\WINDOWS\system32\ps2.exe"
98304 Sep 12 2003 "C:\hp\drivers\keyboard\PS2.EXE"
98304 Sep 12 2003 "C:\WINDOWS\system32\bak\ps2.exe"
180269 Jul 12 2006 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
180269 Jul 12 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
32881 Apr 2 2004 "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
32881 Jun 3 2004 "C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe"
36975 Jun 3 2005 "C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe"
49263 Nov 9 2006 "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
36975 Nov 10 2005 "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
49263 Nov 9 2006 "C:\Program Files\Java\jre1.5.0_10\bin\bak\jusched.exe"


end of report

#13 bighead_norris

bighead_norris
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 22 May 2008 - 05:04 PM

ComboFix 08-05-12.1 - Owner 2008-05-22 17:32:14.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.168 [GMT -4:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-04-22 to 2008-05-22 )))))))))))))))))))))))))))))))
.

2008-05-22 17:24 . 2003-09-12 23:13 98,304 --a------ C:\WINDOWS\system32\ps2.exe
2008-05-22 17:24 . 1998-05-07 20:04 52,736 --a------ C:\WINDOWS\system\hpsysdrv.exe
2008-05-21 19:36 . 2008-05-21 19:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-12 21:35 . 2008-05-12 21:35 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-05-12 21:34 . 2008-05-12 21:36 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-12 21:34 . 2008-05-12 21:36 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-05-12 21:34 . 2008-05-12 21:36 10,563 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-05-12 21:34 . 2008-05-12 21:36 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-05-12 18:56 . 2008-05-12 18:56 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-12 18:56 . 2008-05-12 18:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-12 18:55 . 2008-05-12 21:33 9,506 --a------ C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate
2008-05-12 18:06 . 2008-05-12 18:06 <DIR> d-------- C:\Deckard
2008-05-12 07:01 . 2008-05-12 07:01 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\InterMute
2008-05-12 07:01 . 2008-05-12 07:01 131,072 --a------ C:\WINDOWS\system32\SpSubLSP.dll
2008-05-12 07:01 . 2008-05-12 07:02 2,154 --a------ C:\WINDOWS\system32\ssmute.ini
2008-05-12 07:01 . 2008-05-12 07:02 2,150 --a------ C:\WINDOWS\system32\mshrml.ini
2008-05-12 07:01 . 2008-05-12 07:01 1,195 --a------ C:\WINDOWS\system32\imbrmute.ini
2008-05-11 20:07 . 2008-05-11 20:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-11 20:06 . 2008-05-12 13:41 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-11 20:06 . 2008-05-11 20:06 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2008-05-11 20:05 . 2008-05-11 20:05 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-11 15:28 . 2008-05-11 15:28 <DIR> d-------- C:\WINDOWS\system32\dFrnx06
2008-05-11 15:28 . 2008-05-11 15:28 <DIR> d-------- C:\temp\tmpvc14
2008-04-27 17:18 . 2008-05-12 19:14 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-27 17:18 . 2008-04-27 17:18 1,409 --a------ C:\WINDOWS\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-22 21:24 --------- d-----w C:\Program Files\QuickTime
2008-05-22 21:24 --------- d-----w C:\Program Files\Lexmark 3100 Series
2008-05-22 21:24 --------- d-----w C:\Program Files\iTunes
2008-05-21 23:15 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-14 02:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-13 11:34 --------- d-----w C:\Program Files\Norton AntiVirus
2008-05-13 01:36 --------- d-----w C:\Program Files\Symantec
2008-05-12 21:09 --------- d-----w C:\Program Files\Windows Defender
2008-05-12 13:34 --------- d-----w C:\Program Files\InterMute
2008-05-11 22:55 --------- d-----w C:\Program Files\Yahoo!
2008-05-11 22:47 --------- d-----w C:\Program Files\MsnMusic
2008-05-09 10:38 --------- d-----w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2003-08-27 19:19 36,963 ----a-r C:\Program Files\Common Files\SM1updtr.dll
2005-01-24 00:17 0 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((( snapshot_2008-05-21_19.26.40.96 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-21 23:16:51 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-22 21:35:51 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2004-04-14 20:43:46 233,472 ----a-w C:\WINDOWS\SMINST\RECGUARD.EXE
+ 2008-05-22 21:36:40 40,960 ----a-w C:\WINDOWS\Temp\rtdrvmon.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 61,440 2003-02-12 03:02:48 C:\hp\KBD\bak\KBD.EXE
----a-w 61,440 2003-02-12 03:02:48 C:\hp\KBD\KBD.EXE

----a-w 180,269 2006-07-12 15:45:01 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
----a-w 180,269 2006-07-12 15:45:01 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

----a-w 229,376 2004-01-17 03:16:18 C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w 229,376 2004-01-17 03:16:18 C:\Program Files\iTunes\iTunesHelper.exe

----a-w 102 2007-10-07 01:56:15 C:\Program Files\iTunes\bak\iTunesHelperAppLog.txt
----a-w 102 2007-10-07 01:56:15 C:\Program Files\iTunes\iTunesHelperAppLog.txt

----a-w 49,263 2006-11-09 20:07:30 C:\Program Files\Java\jre1.5.0_10\bin\bak\jusched.exe
----a-w 49,263 2006-11-09 20:07:30 C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe

----a-w 106,496 2003-09-04 02:33:54 C:\Program Files\Lexmark 3100 Series\bak\lxbrbmgr.exe
----a-w 106,496 2003-09-04 02:33:54 C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe

----a-w 294,912 2003-06-13 14:57:18 C:\Program Files\Lexmark 3100 Series\bak\LXBRKsk.exe
----a-w 294,912 2003-06-13 14:57:18 C:\Program Files\Lexmark 3100 Series\LXBRKsk.exe

----a-w 98,304 2004-04-02 22:35:19 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 98,304 2004-04-02 22:35:19 C:\Program Files\QuickTime\qttask.exe

----a-w 233,472 2004-04-14 20:43:46 C:\WINDOWS\SMINST\bak\RECGUARD.EXE
----a-w 233,472 2004-04-14 20:43:46 C:\WINDOWS\SMINST\RECGUARD.EXE

----a-w 52,736 1998-05-08 00:04:38 C:\WINDOWS\system\bak\hpsysdrv.exe
----a-w 52,736 1998-05-08 00:04:38 C:\WINDOWS\system\hpsysdrv.exe

----a-w 98,304 2003-09-13 03:13:20 C:\WINDOWS\system32\bak\ps2.exe
----a-w 98,304 2003-09-13 03:13:20 C:\WINDOWS\system32\ps2.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-05-12 21:41 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2004-01-16 07:33 49152 C:\WINDOWS\system32\VTTimer.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 10:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-16 23:16 229376]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-25 21:47 51048]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-02-07 02:49 718704]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
SpamSubtract.lnk - C:\Program Files\InterMute\SpamSubtract\SpamSub.exe [2008-05-12 07:01:47 589824]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-02 18:51:16 16384]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe [2005-03-10 10:40:30 757760]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 15:12:08 16423]
PopSubtract.lnk - C:\Program Files\InterMute\PopSubtract\PopSub.exe [2008-05-12 07:01:02 233472]
QuickBooks 2002 Delivery Agent.lnk - C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\qbdagent2002.exe [2004-08-12 08:35:27 315392]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-10-02 22:03:35 815104]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-07-30 08:49:48 57344]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\spysub.exe [2008-05-12 07:01:28 983040]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\msncall.exe"=
"C:\\Program Files\\InterMute\\SpamSubtract\\SpamSub.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Compaq Connections\\1940576\\Program\\BackWeb-1940576.exe"=
"C:\\Documents and Settings\\Owner\\Desktop\\dss.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]

.
Contents of the 'Scheduled Tasks' folder
"2008-05-20 23:09:51 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Owner.job"
- C:\Program Files\Norton AntiVirus\Navw32.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-22 17:36:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\gearsec.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-05-22 17:57:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-22 21:57:24
ComboFix2.txt 2008-05-21 23:30:23
ComboFix3.txt 2008-05-21 04:22:44
ComboFix4.txt 2008-05-14 01:56:46

Pre-Run: 87,455,584,256 bytes free
Post-Run: 87,565,918,208 bytes free

169 --- E O F --- 2008-05-21 04:26:27


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:58:26 PM, on 5/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\System32\gearsec.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\InterMute\PopSubtract\PopSub.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\InterMute\SpySubtract\spysub.exe
C:\Program Files\InterMute\SpamSubtract\SpamSub.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Startup: SpamSubtract.lnk = C:\Program Files\InterMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: PopSubtract.lnk = C:\Program Files\InterMute\PopSubtract\PopSub.exe
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\qbdagent2002.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\spysub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: *.doginhispen.com
O15 - Trusted Zone: *.whataboutadog.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 7511 bytes

#14 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:11:30 AM

Posted 22 May 2008 - 06:10 PM

Hi bighead_norris,

Please download ATF Cleaner by Atribune.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Reboot your computer  <==== Important

Please double-click the FindAWF icon once again
This time we are going to remove some folders.

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 3 then Enter to remove bak folders

A text file opens called: folders.txt
Click below the line and paste the following list of folders to be removed:

C:\hp\KBD\bak\KBD.EXE
C:\Program Files\iTunes\bak\iTunesHelper.exe
C:\Program Files\iTunes\bak\iTunesHelperAppLog.txt
C:\Program Files\Lexmark 3100 Series\bak\lxbrbmgr.exe
C:\Program Files\Lexmark 3100 Series\bak\LXBRKsk.exe
C:\Program Files\QuickTime\bak\qttask.exe
C:\WINDOWS\SMINST\bak\RECGUARD.EXE
C:\WINDOWS\system\bak\hpsysdrv.exe
C:\WINDOWS\system32\bak\ps2.exe
C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
C:\Program Files\Java\jre1.5.0_10\bin\bak\jusched.exe


Next, close and click Yes to save the changes.

When done with the above, FindAWF automatically runs a new scan and opens a new log that you need to post.
Please provide the new FindAWF log in your reply
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#15 bighead_norris

bighead_norris
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 22 May 2008 - 09:41 PM

Find AWF report by noahdfear ©2006
Version 1.40
Option 3 run successfully

The current date is: Thu 05/22/2008
The current time is: 22:37:04.20


bak folders found
~~~~~~~~~~~


Directory of C:\HP\KBD\BAK

02/11/2003 11:02 PM 61,440 KBD.EXE
1 File(s) 61,440 bytes

Directory of C:\PROGRA~1\ITUNES\BAK

01/16/2004 11:16 PM 229,376 iTunesHelper.exe
10/06/2007 09:56 PM 102 iTunesHelperAppLog.txt
2 File(s) 229,478 bytes

Directory of C:\PROGRA~1\LEXMAR~1\BAK

09/03/2003 10:33 PM 106,496 lxbrbmgr.exe
06/13/2003 10:57 AM 294,912 LXBRKsk.exe
2 File(s) 401,408 bytes

Directory of C:\PROGRA~1\MSNMES~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

04/02/2004 06:35 PM 98,304 qttask.exe
1 File(s) 98,304 bytes

Directory of C:\WINDOWS\SMINST\BAK

04/14/2004 04:43 PM 233,472 RECGUARD.EXE
1 File(s) 233,472 bytes

Directory of C:\WINDOWS\SYSTEM\BAK

05/07/1998 08:04 PM 52,736 hpsysdrv.exe
1 File(s) 52,736 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

09/12/2003 11:13 PM 98,304 ps2.exe
1 File(s) 98,304 bytes

Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

07/12/2006 11:45 AM 180,269 realsched.exe
1 File(s) 180,269 bytes

Directory of C:\PROGRA~1\JAVA\JRE15~1.0_1\BIN\BAK

11/09/2006 04:07 PM 49,263 jusched.exe
1 File(s) 49,263 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

61440 Feb 11 2003 "C:\hp\KBD\KBD.EXE"
61440 Feb 11 2003 "C:\hp\KBD\bak\KBD.EXE"
229376 Jan 16 2004 "C:\Program Files\iTunes\iTunesHelper.exe"
229376 Jan 16 2004 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
102 Oct 6 2007 "C:\Program Files\iTunes\iTunesHelperAppLog.txt"
102 Oct 6 2007 "C:\Program Files\iTunes\bak\iTunesHelperAppLog.txt"
106496 Sep 3 2003 "C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe"
106496 Sep 3 2003 "C:\Program Files\Lexmark 3100 Series\bak\lxbrbmgr.exe"
294912 Jun 13 2003 "C:\Program Files\Lexmark 3100 Series\LXBRKsk.exe"
294912 Jun 13 2003 "C:\Program Files\Lexmark 3100 Series\bak\LXBRKsk.exe"
98304 Apr 2 2004 "C:\Program Files\QuickTime\qttask.exe"
98304 Apr 2 2004 "C:\Program Files\QuickTime\bak\qttask.exe"
233472 Apr 14 2004 "C:\WINDOWS\SMINST\RECGUARD.EXE"
233472 Apr 14 2004 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
233472 Apr 14 2004 "C:\hp\patches\43WW3OWN\files\UP\Recguard.exe"
233472 Apr 14 2004 "D:\hp\patches\43WW3OWN\files\UP\Recguard.exe"
52736 May 7 1998 "C:\WINDOWS\system\hpsysdrv.exe"
52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe"
98304 Sep 12 2003 "C:\WINDOWS\system32\ps2.exe"
98304 Sep 12 2003 "C:\hp\drivers\keyboard\PS2.EXE"
98304 Sep 12 2003 "C:\WINDOWS\system32\bak\ps2.exe"
180269 Jul 12 2006 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
180269 Jul 12 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
32881 Apr 2 2004 "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
32881 Jun 3 2004 "C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe"
36975 Jun 3 2005 "C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe"
49263 Nov 9 2006 "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
36975 Nov 10 2005 "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
49263 Nov 9 2006 "C:\Program Files\Java\jre1.5.0_10\bin\bak\jusched.exe"


end of report




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users