Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Laptop had lots of malware and trojans


  • This topic is locked This topic is locked
2 replies to this topic

#1 omegatek

omegatek

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:04:46 PM

Posted 09 January 2009 - 11:33 AM

I ran some scans using Adaware and Avast Antivirus and found a lot of viruses and trojans.
I cleaned those but I'm still worried.

I'm using:
Adaware
Avast
Spyware Blaster
Panda Antirootkit
Windows Defender


I'm not noticing anything anymore like all the crazy popups but I don't know if there are hidden malware still.
Could someone take a look and tell me what they think?

Thanks




DDS (Ver_09-01-07.01) - NTFSx86
Run by Heidi Olvera at 11:19:43.93 on Fri 01/09/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1983.1409 [GMT -5:00]

AV: avast! antivirus 4.8.1296 [VPS 090105-0] *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Heidi Olvera\Temporary Internet Files\Content.IE5\9XJE7AT8\dds[1].scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant =
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {44d36d56-8e19-45a8-0434-08ae40f7b986}: {689b7f04-ea80-4340-8a54-91e865d63d44} - c:\windows\system32\utjwky.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {77ab59b4-55a3-4737-9fd5-b93c6430bf78} - c:\windows\system32\dyayioqf.dll
BHO: {d3efe3da-e8df-4a89-bbb4-ba9ec7cb27cb} - c:\windows\system32\opnlLBRL.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [msiexec.exe] ~.exe
uRun: [SVCHOST.EXE] c:\windows\system32\drivers\svchost.exe
mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
IE: &Search - ?p=ZN
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Filter: text/html - {edfddd9f-ffab-4dc3-8eda-6094e9ef3a49} - c:\windows\system32\mst122.dll
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: ddcyyyVm - ddcyyyVm.dll
AppInit_DLLs: yatgwi.dll zaodhr.dll dgibac.dll lrvimp.dll utjwky.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, msansspc.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\opnlLBRL

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-30 111184]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-12-30 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-12-30 352920]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-30 20560]
R4 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-12-30 155160]
R4 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R4 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 Flash1;Flash1;c:\swsetup\sp38062\winphlash\FLASH1.sys [2006-3-1 3456]
S3 SWNC8U80;Sierra Wireless MUX NDIS Driver (UMTS80);c:\windows\system32\drivers\swnc8u80.sys [2008-1-10 165248]
S3 SWUMX80;Sierra Wireless USB MUX Driver (UMTS80);c:\windows\system32\drivers\swumx80.sys [2008-1-10 142976]
S4 lxdc_device;lxdc_device;c:\windows\system32\lxdccoms.exe -service --> c:\windows\system32\lxdccoms.exe -service [?]
S4 lxdcCATSCustConnectService;lxdcCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdcserv.exe [2007-5-25 99248]
S4 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-10-16 1174664]

=============== Created Last 30 ================

2009-01-02 04:18 <DIR> --d----- c:\program files\Trend Micro
2009-01-01 15:25 873,374 a------- c:\windows\system32\oem169.inf
2009-01-01 15:24 <DIR> --d----- c:\docume~1\heidio~1\applic~1\Windows Desktop Search
2009-01-01 15:23 <DIR> --d----- c:\windows\system32\GroupPolicy
2009-01-01 15:23 <DIR> --d----- c:\program files\Windows Desktop Search
2009-01-01 15:23 192,000 -------- c:\windows\system32\dllcache\offfilt.dll
2009-01-01 15:23 98,304 -------- c:\windows\system32\dllcache\nlhtml.dll
2009-01-01 15:23 29,696 -------- c:\windows\system32\dllcache\mimefilt.dll
2009-01-01 15:20 <DIR> --d----- c:\windows\system32\LogFiles
2008-12-31 19:51 <DIR> --d----- c:\windows\system32\scripting
2008-12-31 19:51 <DIR> --d----- c:\windows\system32\en
2008-12-31 19:51 <DIR> --d----- c:\windows\l2schemas
2008-12-31 19:51 <DIR> --d----- c:\windows\system32\bits
2008-12-31 19:48 <DIR> --d----- c:\windows\ServicePackFiles
2008-12-31 19:24 23,576 a------- c:\windows\system32\wuapi.dll.mui
2008-12-31 18:55 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-30 18:50 2,704 a------- c:\windows\system32\TDSSlxwp.dll
2008-12-30 18:50 441 a------- c:\windows\system32\TDSSosvd.dat
2008-12-30 18:48 <DIR> --d----- c:\program files\SpywareBlaster
2008-12-30 18:44 102,176 a------- c:\windows\system32\cont_globaladsolution-remove.exe
2008-12-30 18:44 <DIR> --d----- c:\program files\GrandPack
2008-12-30 18:44 <DIR> --d----- c:\program files\Spybot - Search & Destroy

==================== Find3M ====================

2008-12-31 19:57 92,819 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-12-13 01:40 3,593,216 -------- c:\windows\system32\dllcache\mshtml.dll
2008-12-12 07:32 4,212 ----h--- c:\windows\system32\zllictbl.dat
2008-11-11 05:49 17,619 a------- c:\windows\camohid.dll
2008-11-10 18:13 26,504 a------- c:\windows\system32\drivers\swmsflt.sys
2008-11-10 18:04 18,467 a------- c:\docume~1\heidio~1\applic~1\aqudizuje.com
2008-11-10 18:04 16,449 a------- c:\windows\etihuc.vbs
2008-11-10 18:04 10,506 a------- c:\program files\common files\axan.bin
2008-11-10 18:04 12,719 a------- c:\docume~1\alluse~1\applic~1\evefazy.dat
2008-11-10 18:04 19,582 a------- c:\windows\system32\ikypid.reg
2008-11-10 18:04 13,416 a------- c:\program files\common files\odego.bin
2008-11-07 13:48 18,864 a------- c:\windows\system32\bujogugiz.com
2008-11-07 13:48 17,284 a------- c:\docume~1\heidio~1\applic~1\ocyneqego.bin
2008-11-07 13:48 16,233 a------- c:\windows\orag.exe
2008-11-07 13:48 14,700 a------- c:\docume~1\alluse~1\applic~1\uporobuxun.dat
2008-11-07 13:48 11,929 a------- c:\windows\ritij.dat
2008-11-07 13:48 11,414 a------- c:\program files\common files\ufeziv.bat
2008-11-07 13:48 10,593 a------- c:\program files\common files\areqetunoh.vbs
2008-11-07 13:48 19,497 a------- c:\windows\velozy.vbs
2008-11-07 13:48 15,820 a------- c:\windows\system32\capuvaz.dll
2008-10-24 06:21 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 07:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-23 07:36 286,720 -------- c:\windows\system32\dllcache\gdi32.dll
2008-10-23 01:58 87,280 a------- c:\windows\system32\bcmwlcoi.dll
2008-10-16 14:13 1,809,944 a------- c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 14:12 202,776 a------- c:\windows\system32\dllcache\wuweb.dll
2008-10-16 14:12 323,608 a------- c:\windows\system32\dllcache\wucltui.dll
2008-10-16 14:12 561,688 a------- c:\windows\system32\dllcache\wuapi.dll
2008-10-16 14:09 92,696 a------- c:\windows\system32\dllcache\cdm.dll
2008-10-16 14:09 51,224 a------- c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 14:08 34,328 a------- c:\windows\system32\dllcache\wups.dll
2008-10-16 08:11 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 08:11 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 11:34 337,408 -------- c:\windows\system32\dllcache\netapi32.dll
2008-10-15 02:06 633,632 -------- c:\windows\system32\dllcache\iexplore.exe
2008-10-15 02:04 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
2008-03-25 21:00 67,656 a------- c:\docume~1\heidio~1\applic~1\GDIPFONTCACHEV1.DAT
2007-12-19 17:46 0 a------- c:\docume~1\heidio~1\applic~1\wklnhst.dat
2007-09-30 18:55 6,440 -c-sh--- c:\windows\system32\aycdd.bak1
2007-09-24 16:23 6,480 -c-sh--- c:\windows\system32\hhkmp.bak1
2007-09-25 06:40 7,985 -c-sh--- c:\windows\system32\hhkmp.ini2
2007-09-26 18:42 6,480 -c-sh--- c:\windows\system32\ilkkj.bak1
2007-09-22 00:11 6,480 -c-sh--- c:\windows\system32\oqtss.bak1
2007-09-23 17:20 7,264 -c-sh--- c:\windows\system32\oqtss.bak2
2007-09-26 21:47 6,480 -c-sh--- c:\windows\system32\qqstv.bak1
2008-02-26 11:28 239,743 ---sh--- c:\windows\system32\rrqss.bak1
2008-02-26 09:44 243,126 ---sh--- c:\windows\system32\rrqss.bak2
2008-02-26 11:33 239,338 ---sh--- c:\windows\system32\rrqss.ini2
2007-09-27 19:02 6,440 -c-sh--- c:\windows\system32\ttstv.bak1
2007-09-26 20:50 6,480 -c-sh--- c:\windows\system32\ttvwa.bak1
2007-10-01 16:57 7,211 -c-sh--- c:\windows\system32\ttvwa.bak2
2007-09-27 05:23 6,480 -c-sh--- c:\windows\system32\uttss.bak1
2007-09-24 05:59 6,440 -c-sh--- c:\windows\system32\wvvwa.bak1
2008-05-27 06:09 16,384 a--sh--- c:\windows\temp\cookies\index.dat
2008-05-27 06:09 16,384 a--sh--- c:\windows\temp\history\history.ie5\index.dat
2008-05-27 06:09 32,768 a--sh--- c:\windows\temp\temporary internet files\content.ie5\index.dat

============= FINISH: 11:20:45.50 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,538 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:06:46 PM

Posted 09 January 2009 - 03:36 PM

Hi, omegatek :thumbsup:

Welcome.

Posted Image Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combofix.exe & follow the prompts.
  • If you receive a message that Combofix has detected the presence of rootkit activity and needs to reboot, kindly write down on paper the list of files present in the message before continuing, and post it in your next reply.
  • Install the Recovery Console upon request.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#3 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,538 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:06:46 PM

Posted 13 January 2009 - 08:49 PM

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member with address of this thread. This applies only to the original topic starter. Everyone else please begin a New Topic.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users