Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Malware/popups/ie Messed Up.


  • This topic is locked This topic is locked
5 replies to this topic

#1 spoolin2

spoolin2

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:30 AM

Posted 30 June 2008 - 07:57 PM

Here's some info that might help:

I am seeing popups, IE won't open most websites, mainly only my homepage, google.com.

Some files that keep recreating themselves in the Registry: Hkey_local_machine\software\microsoft\ms juan
hkey_local_machine\software\microsoft\ms system tracker
UPDATE: norton antivirus keeps finding some trojan.vundo viruses, they recreate as well.

Thanks in advance,
see logs below:

Deckard's System Scanner v20071014.68
Run by Spoolin on 2008-06-30 20:20:33
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

System Restore is disabled; attempting to re-enable...success.


-- Last 1 Restore Point(s) --
1: 2008-07-01 00:20:34 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Spoolin.exe) ---------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:25:09 PM, on 6/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\AOL\1202005044\ee\AOLSoftware.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\3D-Relax\Living Marine Aquarium 2.0 trial\trioService.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\NETGEAR\WG111T\wlan111t.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Spoolin\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\Spoolin.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {13513771-DE43-4BFE-94DB-BA38A7ABB3B2} - C:\WINDOWS\system32\vtuts.dll (file missing)
O2 - BHO: (no name) - {159E502A-C565-4687-992F-8ABDB9A84EC8} - C:\WINDOWS\system32\yayxyvtR.dll
O2 - BHO: (no name) - {2FD744B0-CE94-496E-9F87-4AF332679DD3} - C:\WINDOWS\system32\gebcc.dll (file missing)
O2 - BHO: (no name) - {61D495E0-1334-4E1B-835A-5CE539697B52} - C:\WINDOWS\system32\mllmk.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7B8D980B-B226-4AE5-A6ED-E0CAE7EC1667} - C:\WINDOWS\system32\sstqr.dll (file missing)
O2 - BHO: (no name) - {981D954D-18CB-47A4-88E0-198CA1EDE2D1} - C:\WINDOWS\system32\pmnnk.dll (file missing)
O2 - BHO: (no name) - {D171D7DF-CEAD-4A37-BD9F-7ED46E077B9E} - C:\WINDOWS\system32\sstqo.dll (file missing)
O2 - BHO: (no name) - {EA76FCD3-B124-4661-9F7B-69EAB4FE6A6E} - C:\WINDOWS\system32\pmnll.dll (file missing)
O2 - BHO: {e0b4b8ee-e7e8-9e1b-1094-efff6d8bb2af} - {fa2bb8d6-fffe-4901-b1e9-8e7eee8b4b0e} - C:\WINDOWS\system32\ynxtrn.dll (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\PPE.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1202005044\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [trioService] "C:\Program Files\3D-Relax\Living Marine Aquarium 2.0 trial\trioService.exe "
O4 - HKLM\..\Run: [dc2379a5] rundll32.exe "C:\WINDOWS\system32\jvwftvia.dll",b
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [BMdf104a39] Rundll32.exe "C:\WINDOWS\system32\nckrhnrm.dll",s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [Owd] C:\WINDOWS\?ecurity\l?ass.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [MalwareRemovalBot] C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe -boot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Spoolin\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 10064 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 cdrbsdrv - c:\windows\system32\drivers\cdrbsdrv.sys <Not Verified; B.H.A Corporation; B's Recorder GOLD7>
R1 PCLEPCI - c:\windows\system32\drivers\pclepci.sys <Not Verified; Pinnacle Systems GmbH; PCLEPCI>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.2.0.3) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.2.0.3>
R2 MDC8021X (AEGIS Protocol (IEEE 802.1x) v2.3.1.10) - c:\windows\system32\drivers\mdc8021x.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 2.3.1.10>
R2 Nsynas32 - c:\windows\system32\drivers\nsynas32.sys <Not Verified; Syncrosoft Hard- und Software GmbH; Internet Protection Hardware Driver>
R3 DNINDIS5 (DNINDIS5 NDIS Protocol Driver) - c:\windows\system32\dnindis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
R3 HCW848NT (Hauppauge Win/TV) - c:\windows\system32\drivers\hcw848nt.sys <Not Verified; Hauppauge Computer Works; WinTV>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell>

S3 ATHFMWDL (NETGEAR WG111T bootloader driver) - c:\windows\system32\drivers\athfmwdl.sys (file missing)
S3 EWAVE - c:\windows\system32\drivers\ew.sys (file missing)
S3 FILESPY - c:\windows\system32\drivers\filespy.sys (file missing)
S3 NSTATION - c:\windows\system32\drivers\nstation.sys (file missing)
S3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>

S2 MsaSvc (Microsoft authenticate service) - c:\windows\system32\msasvc.exe (file missing)


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: RAID Controller
Device ID: PCI\VEN_10B9&DEV_5288&SUBSYS_52881849&REV_00\3&267A616A&0&B1
Manufacturer:
Name: RAID Controller
PNP Device ID: PCI\VEN_10B9&DEV_5288&SUBSYS_52881849&REV_00\3&267A616A&0&B1
Service:


-- Scheduled Tasks -------------------------------------------------------------

2008-06-30 18:42:43 548 --a------ C:\WINDOWS\Tasks\MalwareRemovalBot Scheduled Scan.job
2008-06-30 18:42:11 452 --a------ C:\WINDOWS\Tasks\XoftSpySE 2.job
2008-06-28 03:01:06 366 --a------ C:\WINDOWS\Tasks\XoftSpySE.job
2008-02-27 17:14:00 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


-- Files created between 2008-05-30 and 2008-06-30 -----------------------------

2008-06-30 18:26:27 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-06-30 18:20:02 91136 --a------ C:\WINDOWS\system32\nckrhnrm.dll
2008-06-29 23:13:52 0 d-------- C:\Program Files\Common Files\ODBC
2008-06-29 23:13:50 0 d-------- C:\Program Files\Common Files\Nullsoft
2008-06-29 23:13:47 0 d-------- C:\Program Files\Common Files\Nero
2008-06-29 23:13:47 0 d-------- C:\Program Files\Common Files\MSSoap
2008-06-29 23:08:49 0 d-------- C:\Program Files\Common Files\Merge Modules
2008-06-29 23:08:42 0 d-------- C:\Program Files\Common Files\LightScribe
2008-06-29 23:08:39 0 d-------- C:\Program Files\Common Files\L&H
2008-06-29 23:08:38 0 d-------- C:\Program Files\Common Files\KORG
2008-06-29 23:07:32 0 d-------- C:\Program Files\Common Files\Java
2008-06-29 23:07:18 0 d-------- C:\Program Files\Common Files\InstallShield
2008-06-29 23:05:49 0 d-------- C:\Program Files\Common Files\Business Objects
2008-06-29 23:05:06 0 d-------- C:\Program Files\Common Files\Apple
2008-06-29 23:05:01 0 d-------- C:\Program Files\Common Files\aolshare
2008-06-29 23:03:47 0 d-------- C:\Program Files\Common Files\AOL
2008-06-29 23:03:14 0 d-------- C:\Program Files\Common Files\Ahead
2008-06-29 23:03:13 0 d-------- C:\Program Files\Common Files\??mantec
2008-06-29 23:03:13 0 d-------- C:\Program Files\Common Files\xing shared
2008-06-29 23:03:13 0 d-------- C:\Program Files\Common Files\Adobe
2008-06-29 23:03:13 0 d-------- C:\Program Files\Common Files\{3C23790A-08A1-1033-0612-060419060001}
2008-06-29 23:03:08 0 d-------- C:\Program Files\Common Files\Ulead Systems
2008-06-29 23:03:08 0 d-------- C:\Program Files\Common Files\T?sks
2008-06-29 23:01:11 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-06-29 23:00:48 0 d-------- C:\Program Files\Common Files\Real
2008-06-29 22:31:24 0 d-------- C:\Documents and Settings\Spoolin\Cookies2
2008-06-29 17:24:43 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-06-28 01:45:20 0 d-------- C:\Documents and Settings\Administrator\Application Data\MalwareRemovalBot
2008-06-28 01:35:55 0 d-------- C:\Documents and Settings\Spoolin\Application Data\MalwareRemovalBot
2008-06-28 01:35:40 0 d-------- C:\Program Files\MalwareRemovalBot
2008-06-28 01:16:24 0 --a------ C:\WINDOWS\system32\ualmpdwi.dll
2008-06-28 01:07:27 0 --a------ C:\WINDOWS\system32\jnditral.dll
2008-06-28 01:03:25 0 --a------ C:\WINDOWS\system32\ooyasrrx.dll
2008-06-22 23:46:42 24576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe <Not Verified; Atribune.org; Vundofix Service>
2008-06-22 15:49:53 0 d-------- C:\Program Files\XoftSpySE
2008-06-22 12:23:20 99328 --a------ C:\WINDOWS\system32\oaytkcrx.dll
2008-06-22 12:23:06 90624 --a------ C:\WINDOWS\system32\nihguvdt.dll
2008-06-22 12:21:54 656676 --ahs---- C:\WINDOWS\system32\Rtvyxyay.ini2
2008-06-22 12:21:49 323072 --a------ C:\WINDOWS\system32\yayxyvtR.dll
2008-06-22 12:13:10 0 d-------- C:\Documents and Settings\Spoolin\Application Data\WinRAR
2008-06-13 14:02:11 1 --a------ C:\WINDOWS\system32\Lma.dll
2008-06-13 14:01:44 479232 --a------ C:\WINDOWS\Living Marine Aquarium 2 trial.scr
2008-06-13 14:01:41 0 d-------- C:\Program Files\3D-Relax
2008-06-13 13:43:44 1311335 --a------ C:\WINDOWS\system32\aquarium.scr <Not Verified; Axialis Software; Axialis Screen Saver Producer>
2008-06-05 22:57:37 0 d-------- C:\Program Files\DVDFab 5


-- Find3M Report ---------------------------------------------------------------

2008-06-30 18:42:52 0 d-------- C:\Program Files\Symantec AntiVirus
2008-06-30 18:27:02 0 d-------- C:\Program Files\Symantec
2008-06-30 18:26:27 0 d-------- C:\Program Files\Common Files
2008-06-29 23:03:13 0 d-------- C:\Program Files\Common Files\??mantec
2008-06-29 23:03:08 0 d-------- C:\Program Files\Common Files\T?sks
2008-06-28 12:10:07 0 d-------- C:\Documents and Settings\Spoolin\Application Data\Vso
2008-06-28 10:54:49 0 d-------- C:\Documents and Settings\Spoolin\Application Data\Mozilla
2008-06-20 23:04:47 0 d-------- C:\Documents and Settings\Spoolin\Application Data\IMVU
2008-06-20 22:32:17 0 d-------- C:\Program Files\IMVU
2008-06-15 21:52:28 2145 --a------ C:\WINDOWS\mozver.dat
2008-06-15 21:42:25 0 d-------- C:\Program Files\Sony Corporation
2008-06-01 18:31:46 33 --a------ C:\Documents and Settings\Spoolin\Application Data\pcouffin.log
2008-06-01 18:31:45 47360 --a------ C:\Documents and Settings\Spoolin\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-06-01 18:31:45 1144 --a------ C:\Documents and Settings\Spoolin\Application Data\pcouffin.inf
2008-06-01 18:31:45 7887 --a------ C:\Documents and Settings\Spoolin\Application Data\pcouffin.cat
2008-05-18 15:53:45 0 d-------- C:\Program Files\DVD Shrink
2008-05-11 22:25:46 0 d-------- C:\Program Files\Netflix


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{13513771-DE43-4BFE-94DB-BA38A7ABB3B2}]
C:\WINDOWS\system32\vtuts.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{159E502A-C565-4687-992F-8ABDB9A84EC8}]
06/22/2008 12:21 PM 323072 --a------ C:\WINDOWS\system32\yayxyvtR.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2FD744B0-CE94-496E-9F87-4AF332679DD3}]
C:\WINDOWS\system32\gebcc.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61D495E0-1334-4E1B-835A-5CE539697B52}]
C:\WINDOWS\system32\mllmk.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7B8D980B-B226-4AE5-A6ED-E0CAE7EC1667}]
C:\WINDOWS\system32\sstqr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{981D954D-18CB-47A4-88E0-198CA1EDE2D1}]
C:\WINDOWS\system32\pmnnk.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D171D7DF-CEAD-4A37-BD9F-7ED46E077B9E}]
C:\WINDOWS\system32\sstqo.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EA76FCD3-B124-4661-9F7B-69EAB4FE6A6E}]
C:\WINDOWS\system32\pmnll.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fa2bb8d6-fffe-4901-b1e9-8e7eee8b4b0e}]
C:\WINDOWS\system32\ynxtrn.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [05/17/2006 03:05 AM]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [05/11/2000 01:00 AM]
"P17Helper"="P17.dll" [05/03/2005 07:38 AM C:\WINDOWS\system32\P17.dll]
"nwiz"="nwiz.exe" [05/17/2006 03:05 AM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [05/17/2006 03:05 AM]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 10:50 AM]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [01/16/2006 12:46 PM]
"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [02/15/2005 04:10 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/27/2007 09:41 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [06/28/2007 09:14 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 05:25 AM]
"PCLEPCI"="C:\PROGRA~1\Pinnacle\PPE\PPE.EXE" [02/03/2004 03:13 PM]
"HostManager"="C:\Program Files\Common Files\AOL\1202005044\ee\AOLSoftware.exe" [09/25/2006 08:52 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [02/25/2008 10:04 PM]
"trioService"="C:\Program Files\3D-Relax\Living Marine Aquarium 2.0 trial\trioService.exe" [12/23/2005 12:27 PM]
"dc2379a5"="C:\WINDOWS\system32\jvwftvia.dll" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [04/08/2005 03:52 PM]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [04/17/2005 12:30 PM]
"BMdf104a39"="C:\WINDOWS\system32\nckrhnrm.dll" [06/30/2008 06:20 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 12:24 PM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 03:56 AM]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [12/02/2004 06:23 PM]
"Owd"="C:\WINDOWS\?ecurity\l?ass.exe" []
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [10/18/2006 08:05 PM]
"MalwareRemovalBot"="C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe" [06/26/2008 05:22 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM]
HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\Palm\Hotsync.exe [6/9/2004 2:27:34 PM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 1:01:04 AM]
NETGEAR WG111T Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111T\wlan111t.exe [3/27/2008 6:40:35 PM]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\yayxyvtR

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"




-- End of Deckard's System Scanner: finished at 2008-06-30 20:26:20 ------------

Edited by spoolin2, 30 June 2008 - 11:09 PM.


BC AdBot (Login to Remove)

 


#2 spoolin2

spoolin2
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:30 AM

Posted 01 July 2008 - 11:51 PM

It seems to be linked to ad.yieldmanager and casalemedia as those cookies keep recreating, but no adware/malware/anti-virus software products i've tried can locate where the files are being created from

#3 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:06:30 AM

Posted 02 July 2008 - 04:44 AM

Hello Spoolin2 and welcome to BleepingComputer,

1. * Clean your Cache and Cookies in IE:
  • Close all instances of Outlook Express and Internet Explorer
  • Go to Control Panel > Internet Options > General tab
  • Under Browsing History, click Delete.
  • Click Delete Files, Delete cookies and Delete history
  • Click Close below.
* Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
  • Go to Tools > Options.
  • Click Privacy in the menu..
  • Click the Clear now button below.. A new window will popup what to clear.
  • Select all and click the Clear button again.
  • Click OK to close the Options window
* Clean other Temporary files + Recycle bin
  • Go to start > run and type: cleanmgr and click ok.
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Press OK to remove them.
2. Please download Malwarebytes' Anti-Malware from Here or Here

Doubleclick mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply along with a fresh HijackThis log.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

3. Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first (not for Windows Vista users !).
The Windows Recovery Console will allow you to boot up into a special recovery mode, in case your computer has a problem after an attempted removal of malware. This allows us to help you. (WinXP SP3 users, please download the appropriate SP2 file, Home or Pro, to install the RC)

In the event you already have Combofix, delete your current version and download the latest version as described in the tutorial.
It must be saved directly to your desktop.


Note: Make sure not to click ComboFix's window while it's running. That may cause it to stall or freeze.

Please post the log from ComboFix (can also be found as C:\ComboFix.txt) in your next reply. :thumbsup:

If you have any questions along the way, STOP and ask them before proceeding !!

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#4 spoolin2

spoolin2
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:30 AM

Posted 06 July 2008 - 12:05 AM

So far I have done everything but run combofix. It looks like the only infected item left is the MS Juan Registry entry. Most of the popups are gone or have gotten better. Should I run combofix in Safe mode or normally in windows? I couldn't understand the booting in recovery mode from the boot disk. If I can't run combofix in windows or in safe mode please let me know.

Thanks

#5 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:06:30 AM

Posted 06 July 2008 - 01:43 PM

Hello Spoolin2,

Yes, please install the Recovery Console and then run ComboFix.

To install the Recovery Console use the file download here :
http://support.microsoft.com/kb/310994
at the bottom of the page, for WinXp SP2 (Home or Pro version depending on your system),
and drag it in ComboFix.
That'll set off the installation and when installed will provide the possibility to continue with the ComboFix scan. :thumbsup:

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#6 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:06:30 AM

Posted 03 August 2008 - 06:18 AM

Since there is no feedback anymore, I assume this issue is resolved ... so, this Topic is closed.
If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users