Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Spy/adware Almost Gone But Still Need Help


  • Please log in to reply
1 reply to this topic

#1 apoc8188

apoc8188

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:05:32 PM

Posted 10 June 2008 - 04:08 PM

Ok so here's the deal, I, being the gullible moron that I am, decided to google "mass effect megaupload" so that I could get a faster download of that new game "mass effect." One of the results that I was unfortunate enough to click on led me to a download claiming to be the real thing. The file was a setup file and I ran it and it gave me this virus.

The virus restricted me from accessing my local disk © drive via conventional means, conventional meaning just going to My Computer and going to local disk C. My stuff was still there, but the Local Disk C and recovery drive just weren't to be found. It also removed a lot of stuff from my Start menu, but eventually I found a way around it so that I could access my stuff.

I used a bunch of spyware stuff to get rid of the problem, eventually Combofix actually fixed most, but not all, of my problems. Among many other annoying things the virus constantly copies the following shortcuts onto my desktop:

Error Cleaner, Privacy Protector, and Spyware and Malware Protection.

It also says "VIRUS ALERT!" in a lot of standard places, such as in the bottom right hand corner where the time should be.

Does this sound familiar to anyone? Can anyone help me get rid of whatever this malignancy is? I've used spyware doctor, registry mechanic, and norton so far to "remedy" the problem.

Below is the Combofix log:

ComboFix 08-06-09.7 - Administrator 2008-06-10 13:10:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.508 [GMT -7:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\WinXP_EN_PRO_BF.EXE
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Desktop\Error Cleaner.url
C:\Documents and Settings\Administrator\Desktop\Privacy Protector.url
C:\Documents and Settings\Administrator\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Administrator\Favorites\Error Cleaner.url
C:\Documents and Settings\Administrator\Favorites\Privacy Protector.url
C:\Documents and Settings\Administrator\Favorites\Spyware&Malware Protection.url
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\rtsplgob.dll
C:\WINDOWS\system32\cwdtuagx.ini
C:\WINDOWS\system32\TsBKlnpo.ini
C:\WINDOWS\system32\TsBKlnpo.ini2
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_IPRIP
-------\Service_Iprip


((((((((((((((((((((((((( Files Created from 2008-05-10 to 2008-06-10 )))))))))))))))))))))))))))))))
.

2008-06-10 12:45 . 2008-06-10 12:45 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-06-10 11:23 . 2008-06-10 11:24 10,671 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-06-10 11:23 . 2008-06-10 11:24 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-06-10 11:02 . 2008-06-10 11:28 <DIR> d-------- C:\Program Files\Norton AntiVirus
2008-06-10 11:02 . 2008-06-10 11:24 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-06-10 11:02 . 2008-06-10 11:24 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-06-10 11:01 . 2008-06-10 11:24 <DIR> d-------- C:\Program Files\Symantec
2008-06-10 11:01 . 2008-06-10 12:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-10 11:00 . 2008-06-10 12:36 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-06-10 10:52 . 2008-06-10 10:52 51,355 --a------ C:\WINDOWS\system32\muzika.xm
2008-06-10 10:47 . 2008-06-10 10:47 1,047,552 --a------ C:\WINDOWS\system32\mfc71u.dll
2008-06-10 10:35 . 2008-06-10 10:35 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2008-06-10 10:31 . 2008-06-10 10:31 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-06-10 10:29 . 2008-06-10 10:29 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-06-10 10:24 . 2008-06-10 10:24 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-06-10 09:37 . 2008-06-10 09:37 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2008-06-10 09:11 . 2008-06-10 09:11 613,056 --a------ C:\WINDOWS\system32\SymNeti.dll
2008-06-10 07:43 . 2008-06-10 07:43 186,048 --a------ C:\WINDOWS\system32\drivers\symtdi.sys
2008-06-10 06:58 . 2008-06-10 06:58 239,808 --a------ C:\WINDOWS\system32\SymRedir.dll
2008-06-10 06:28 . 2008-06-10 06:28 144,832 --a------ C:\WINDOWS\system32\drivers\symfw.sys
2008-06-10 06:28 . 2008-06-10 06:28 11,968 --a------ C:\WINDOWS\system32\drivers\symdns.sys
2008-06-10 06:01 . 2008-06-10 06:01 39,104 --a------ C:\WINDOWS\system32\drivers\symids.sys
2008-06-10 06:01 . 2008-06-10 06:01 36,032 --a------ C:\WINDOWS\system32\drivers\symndisv.sys
2008-06-10 06:01 . 2008-06-10 06:01 33,216 --a------ C:\WINDOWS\system32\drivers\symndis.sys
2008-06-10 06:01 . 2008-06-10 06:01 26,432 --a------ C:\WINDOWS\system32\drivers\symredrv.sys
2008-06-10 06:01 . 2008-06-10 06:01 1,396 --a------ C:\WINDOWS\system32\drivers\SymRedir.inf
2008-06-10 06:01 . 2008-06-10 06:01 20 --a------ C:\WINDOWS\system32\drivers\SymRedir.cat
2008-06-10 03:56 . 2008-06-10 03:56 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-06-10 03:56 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-06-10 03:56 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-06-10 03:56 . 2007-12-10 14:53 41,864 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-06-10 03:56 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-06-10 03:48 . 2008-06-10 13:09 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-10 03:29 . 2008-06-10 03:29 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-10 02:59 . 2008-06-10 02:59 1,905 --a------ C:\WINDOWS\diagwrn.xml
2008-06-10 02:59 . 2008-06-10 02:59 1,905 --a------ C:\WINDOWS\diagerr.xml
2008-06-10 02:22 . 2008-06-09 18:28 253,952 --a------ C:\WINDOWS\rnopbfgt.dll
2008-06-10 02:22 . 2008-06-09 18:28 225,280 --a------ C:\WINDOWS\xkefqtgs.dll
2008-06-10 02:22 . 2008-06-09 18:28 163,840 --a------ C:\WINDOWS\pebgkxwq.exe
2008-06-10 02:22 . 2008-06-09 18:28 139,264 --a------ C:\WINDOWS\esrt.exe
2008-06-02 14:34 . 2008-06-06 10:58 <DIR> d-------- C:\Program Files\PeerGuardian2
2008-05-10 01:10 . 2008-05-13 17:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\skypePM
2008-05-10 01:10 . 2008-05-10 01:10 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-05-10 01:07 . 2008-05-13 19:34 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Skype
2008-05-10 01:05 . 2008-05-10 01:05 <DIR> d-------- C:\Program Files\Skype
2008-05-10 01:05 . 2008-05-10 01:05 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-05-10 01:05 . 2008-05-10 01:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-10 20:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-06-10 18:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-08 01:48 --------- d-----w C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-06-05 19:13 --------- d-----w C:\Program Files\LimeWire
2008-06-05 06:22 --------- d-----w C:\Program Files\Starcraft
2008-05-27 19:56 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-04-10 04:26 --------- d-----w C:\Documents and Settings\Administrator\Application Data\RCP 5
2008-04-10 04:25 --------- d-----w C:\Program Files\ReaConverter 5.0 Pro
2008-04-10 03:27 --------- d-----w C:\Program Files\Picasa2
2008-04-10 03:20 --------- d-----w C:\Program Files\Morgan
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{0939FF27-A717-4F67-96B5-555F9510F17F}"= "C:\WINDOWS\rtsplgob.dll" [ ]

[HKEY_CLASSES_ROOT\clsid\{0939ff27-a717-4f67-96b5-555f9510f17f}]
[HKEY_CLASSES_ROOT\rtsplgob.1]
[HKEY_CLASSES_ROOT\TypeLib\{84AEEED9-D8B2-494D-99D3-6DE8BD940ADC}]
[HKEY_CLASSES_ROOT\rtsplgob]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-03 15:29: VIRUS ALERT! 165784]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 09:15: VIRUS ALERT! 50528]
"scheduler_monitor"="C:\Program Files\ReaConverter 5.0 Pro\init_scheduler.exe" [2007-06-15 10:17: VIRUS ALERT! 27136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 10:58: VIRUS ALERT! 159744]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-07-20 20:58: VIRUS ALERT! 7581696]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-07-20 20:58: VIRUS ALERT! 86016]
"nwiz"="nwiz.exe" [2006-07-20 20:58: VIRUS ALERT! 1519616 C:\WINDOWS\system32\nwiz.exe]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-01-10 15:13: VIRUS ALERT! 472776]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 14:36: VIRUS ALERT! 827392]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-07-27 14:44: VIRUS ALERT! 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-14 15:22: VIRUS ALERT! 35328]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11: VIRUS ALERT! 132496]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13: VIRUS ALERT! 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10: VIRUS ALERT! 267048]
"RegistryMechanic"="" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-06-10 07:10: VIRUS ALERT! 84640]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-06-10 10:42: VIRUS ALERT! 26248]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38: VIRUS ALERT! 583048]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-01-23 14:47: VIRUS ALERT! 847872]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2004-08-04 05:00: VIRUS ALERT! 99840 C:\WINDOWS\system32\advpack.dll]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-08-03 15:55:53 124912]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
"NoDispCPL"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"= 1 (0x1)
"NoStartMenuMFUprogramsList"= 1 (0x1)
"NoToolbarCustomize"= 1 (0x1)
"StartMenuLogoff"= 1 (0x1)
"NoStartMenuMorePrograms"= 1 (0x1)
"NoSetFolders"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"= 1 (0x1)
"NoStartMenuMFUprogramsList"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"xkefqtgs"= {C81FCB6A-C20A-4269-A261-7A0D9B22B4AF} - C:\WINDOWS\xkefqtgs.dll [2008-06-09 18:28: VIRUS ALERT! 225280]
"rnopbfgt"= {66C7A04B-71AD-4299-A6FE-0822F03585F1} - C:\WINDOWS\rnopbfgt.dll [2008-06-09 18:28: VIRUS ALERT! 253952]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifGWPge]
iifGWPge.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Starcraft\\StarCraft.exe"=
"C:\\Program Files\\Activision\\Marvel - Ultimate Alliance\\Game.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Documents and Settings\\Administrator\\Desktop\\utorrent-1.8-beta-10431.upx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"26118:TCP"= 26118:TCP:utorrent
"26118:UDP"= 26118:UDP:utorrent

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38: VIRUS ALERT!]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2004-08-04 05:00: VIRUS ALERT!]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2004-08-04 05:00: VIRUS ALERT!]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2004-08-04 05:00: VIRUS ALERT!]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2004-08-04 05:00: VIRUS ALERT!]
S3 rcp_service;ReaConverter scheduler service;C:\Program Files\ReaConverter 5.0 Pro\rcp_scheduler.exe [2007-11-30 11:27: VIRUS ALERT!]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11e4caf6-efe3-11dc-adba-001b24095ab4}]
\Shell\AutoRun\command - F:\Programs\nu2menu\nu2menu.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11e4caf7-efe3-11dc-adba-001b24095ab4}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-03-08 01:56:25 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-10 18:12:16 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Administrator.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-10 13:15:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
C:\Program Files\Winamp\winamp.exe
.
**************************************************************************
.
Completion time: 2008-06-10 13:20:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-10 20:20:39

Pre-Run: 16,463,847,424 bytes free
Post-Run: 16,707,723,264 bytes free

WinXP_EN_PRO_BF.EXE
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

238 --- E O F --- 2008-05-15 05:15:17

BC AdBot (Login to Remove)

 


#2 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,579 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:32 AM

Posted 10 June 2008 - 05:00 PM

I wouldn't recommend running ComboFix except under the supervision of a malware removal expert. It can really mess up your system.

Run the following fix:

How to remove the Smitfraud / Generic Zlob / Quicknavigate / Virtual Maid

After that run a full system scan with Malwarebytes' Anti-Malware.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users