Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I am infected by Spyware Protect 2009


  • This topic is locked This topic is locked
2 replies to this topic

#1 kayagokoglu

kayagokoglu

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:45 AM

Posted 03 February 2009 - 02:24 PM

Hi All

I am infected by Spyware Protect 2009

I installed Combofix and run according to instruction.
I got this in note pad below
what should I do next to remove that
thank you

ComboFix 09-02-02.04 - aytekim 2009-02-03 14:00:09.1 - NTFSx86Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.2046.1523 [GMT -5:00]Running from: c:\documents and settings\aytekim\Desktop\ComboFix.exeAV: Kaspersky Anti-Virus 6.0 *On-access scanning disabled* (Updated)AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) * Resident AV is active.(((((((((((((((((((((((((((((((((((((((   Other Deletions   ))))))))))))))))))))))))))))))))))))))))))))))))).c:\windows\system32\404Fix.exec:\windows\system32\Agent.OMZ.Fix.exec:\windows\system32\dumphive.exec:\windows\system32\IEDFix.C.exec:\windows\system32\IEDFix.exec:\windows\system32\iehelper.dllc:\windows\system32\o4Patch.exec:\windows\system32\Process.exec:\windows\system32\SrchSTS.exec:\windows\system32\tmp.regc:\windows\system32\VACFix.exec:\windows\system32\VCCLSID.exec:\windows\system32\WS2Fix.exec:\windows\system32temp#01.exec:\windows\wiaserviv.log.(((((((((((((((((((((((((((((((((((((((   Drivers/Services   ))))))))))))))))))))))))))))))))))))))))))))))))).-------\Service_WinDriver(((((((((((((((((((((((((   Files Created from 2009-01-03 to 2009-02-03  ))))))))))))))))))))))))))))))).2009-02-03 13:44 . 2009-02-01 15:19	363,016	--a------	c:\windows\sysguard.exe2009-02-03 09:31 . 2009-02-03 09:31	<DIR>	d--------	c:\program files\Malwarebytes' Anti-Malware2009-02-03 09:31 . 2009-02-03 09:31	<DIR>	d--------	c:\documents and settings\aytekim\Application Data\Malwarebytes2009-02-03 09:31 . 2009-02-03 09:31	<DIR>	d--------	c:\documents and settings\All Users\Application Data\Malwarebytes2009-02-03 09:31 . 2009-01-14 16:11	38,496	--a------	c:\windows\system32\drivers\mbamswissarmy.sys2009-02-03 09:31 . 2009-01-14 16:11	15,504	--a------	c:\windows\system32\drivers\mbam.sys2009-02-02 16:47 . 2009-02-02 16:47	1,152	--a------	c:\windows\system32\windrv.sys2009-02-02 16:44 . 2009-02-02 17:11	<DIR>	d--------	c:\program files\SpyNoMore2009-02-02 16:44 . 2009-02-02 16:44	<DIR>	d--------	c:\program files\Common Files\Download Manager2009-02-02 16:42 . 2009-02-02 18:23	<DIR>	d--------	c:\program files\RegCure.((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-02-03 19:15	9,116,448	--sha-w	c:\windows\system32\drivers\fidbox2.dat2009-02-03 19:14	124,966,944	--sha-w	c:\windows\system32\drivers\fidbox.dat2009-02-03 19:08	1,676,780	--sha-w	c:\windows\system32\drivers\fidbox.idx2009-02-03 19:08	1,104,164	--sha-w	c:\windows\system32\drivers\fidbox2.idx2009-02-03 18:54	---------	d---a-w	c:\documents and settings\All Users\Application Data\TEMP2009-02-03 17:30	---------	d-----w	c:\documents and settings\All Users\Application Data\Google Updater2009-02-03 16:00	---------	d-----w	c:\documents and settings\aytekim\Application Data\EndNote2009-02-02 21:28	---------	d-----w	c:\program files\Yahoo!2009-02-02 17:29	---------	d-----w	c:\program files\Ultra Flash Video FLV Converter2009-01-26 21:24	---------	d-----w	c:\documents and settings\aytekim\Application Data\Skype2009-01-26 21:00	---------	d-----w	c:\documents and settings\aytekim\Application Data\skypePM2009-01-01 00:51	---------	d-----w	c:\program files\Mus2okur2008-12-11 11:57	333,184	----a-w	c:\windows\system32\drivers\srv.sys2008-12-03 17:09	---------	d-----w	c:\program files\Google2008-02-24 19:53	32	----a-w	c:\documents and settings\All Users\Application Data\ezsid.dat2005-11-04 22:59	135,525	----a-w	c:\program files\Common Files\ReportPreview.app2005-10-05 01:39	253,952	----a-w	c:\documents and settings\aytekim\KIX32.EXE2003-09-11 22:00	2,938	----a-w	c:\documents and settings\aytekim\runas.vbs2003-02-21 09:42	348,160	----a-w	c:\program files\msvcr71.dll2001-10-05 16:53	21,866	----a-w	c:\program files\Common Files\tppupd2k.dll2006-10-12 03:09	94,208	--sh--w	c:\windows\system32\SalaatTime.dll.(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]2007-06-05 23:16	2955264	--a------	c:\program files\Protector Suite QL\farchns.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]2007-06-05 23:16	2955264	--a------	c:\program files\Protector Suite QL\farchns.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624]"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]"Microsoft Location Finder"="c:\program files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 101080]"Google Update"="c:\documents and settings\aytekim\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-08-31 133104]"sysguard"="c:\windows\sysguard.exe" [2009-02-01 363016][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-05 8491008]"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624]c:\documents and settings\aytekim\Start Menu\Programs\Startup\Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2006-10-12 421888]browsers.exe [2009-02-01 363016]InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-05-01 200704]OUTLOOK-RUN.BAT [2005-08-26 188]Program Neighborhood Agent.lnk - c:\program files\Citrix\ICA Client\pnagent.exe [2006-11-08 233744][HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"HideFastUserSwitching"= 1 (0x1)[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]"ForceRunOnStartMenu"= 1 (0x1)[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]2007-06-05 23:03 90112 c:\windows\system32\psqlpwd.dll[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]"vidc.ffds"= ffdshow.ax"msacm.ac3filter"= ac3filter.acm[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]Notification Packages	REG_MULTI_SZ   	scecli psqlpwd[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-354309246-2075033425-549785860-1108\Scripts\Logon\[u]0[/u]\[u]0[/u]]"Script"=\\lerner.ad.cchs.net\netlogon\ITD\EID\EMPIDUpdate.cmd[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-354309246-2075033425-549785860-9135\Scripts\Logon\[u]0[/u]\[u]0[/u]]"Script"=\\lerner.ad.cchs.net\netlogon\ITD\EID\EMPIDUpdate.cmd[HKEY_LOCAL_MACHINE\software\microsoft\security center]"AntiVirusDisableNotify"="0x00000000""UpdatesDisableNotify"="0x00000000"[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]"DisableMonitoring"=dword:00000001[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="c:\\Program Files\\VoipStunt.com\\VoipStunt\\VoipStunt.exe"="c:\\Program Files\\uTorrent\\uTorrent.exe"="c:\\Program Files\\Bonjour\\mDNSResponder.exe"="c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="c:\\Documents and Settings\\aytekim\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"="c:\\Documents and Settings\\aytekim\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"="c:\\Program Files\\Skype\\Phone\\Skype.exe"="c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"443:TCP"= 443:TCP:ooVoo TCP port 443"443:UDP"= 443:UDP:ooVoo UDP port 443"37674:TCP"= 37674:TCP:ooVoo TCP port 37674"37674:UDP"= 37674:UDP:ooVoo UDP port 37674"37675:UDP"= 37675:UDP:ooVoo UDP port 37675R2 SPOTKP;SPOTKP;c:\windows\system32\drivers\SpotKP.sys [2008-05-30 23156]R3 5U870UVC;Sony Visual Communication Camera VGP-VCC7;c:\windows\system32\drivers\5U870UVCx86.sys [2008-02-07 70144]R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2008-02-07 41216]R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2008-02-07 31104]R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [2008-02-07 37040]R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2008-02-07 812544]S2 gupdate1c8df72de32ab2c;Google Update Service (gupdate1c8df72de32ab2c);c:\program files\Google\Update\GoogleUpdate.exe [2008-07-14 133104]S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-01-25 42000]S3 Spot1394;Spot IEEE-1394 Driver (spot1394.sys);c:\windows\system32\drivers\Spot1394.sys [2008-05-30 25856][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]HPZ12	REG_MULTI_SZ   	Pml Driver HPZ12 Net Driver HPZ12[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7bf17508-76e0-11dd-8082-001bfb1d53a1}]\Shell\Auto\command - activexdebugger32.exe f\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL activexdebugger32.exe e\Shell\explore\Command - activexdebugger32.exe f\Shell\open\Command - activexdebugger32.exe f.Contents of the 'Scheduled Tasks' folder2009-02-03 c:\windows\Tasks\GoogleUpdateTaskMachine.job- c:\program files\Google\Update\GoogleUpdate.exe [2008-08-31 16:32]2009-02-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-354309246-2075033425-549785860-9135.job- c:\documents and settings\aytekim\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-08-31 16:55]2009-02-02 c:\windows\Tasks\ParetoLogic Registration.job- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2007-10-24 12:54]2008-11-02 c:\windows\Tasks\ParetoLogic Update Version2.job- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2007-10-24 12:54]2009-02-03 c:\windows\Tasks\RegCure Program Check.job- c:\program files\RegCure\RegCure.exe [2008-06-03 13:19]2009-02-02 c:\windows\Tasks\RegCure.job- c:\program files\RegCure\RegCure.exe [2008-06-03 13:19]2009-02-03 c:\windows\Tasks\User_Feed_Synchronization-{C653FF06-A940-49BB-9F16-72546C72DC77}.job- c:\windows\system32\msfeedssync.exe [2007-08-13 18:36].- - - - ORPHANS REMOVED - - - -BHO-{C9C42510-9B21-41c1-9DCD-8382A2D07C61} - c:\windows\system32\iehelper.dll.------- Supplementary Scan -------.uInternet Settings,ProxyOverride = *.localIE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlIE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlIE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlIE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.htmlIE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.htmlIE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlIE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlIE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000IE: Google AdSense Preview Tool - [url="http://pagead2.googlesyndication.com/pagead/preview/en/preview.html"]http://pagead2.googlesyndication.com/pagea...en/preview.html[/url]IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htmTrusted Zone: cchs.net\lerner.adTrusted Zone: medhub.com\ccDPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cabFF - ProfilePath - c:\documents and settings\aytekim\Application Data\Mozilla\Firefox\Profiles\vwgsbwaf.default\FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=FF - prefs.js: browser.search.selectedEngine - YahooFF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dllFF - plugin: c:\documents and settings\aytekim\Application Data\Mozilla\plugins\npgoogletalk.dllFF - plugin: c:\documents and settings\aytekim\Local Settings\Application Data\Google\Update\1.2.133.33\npGoogleOneClick7.dllFF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dllFF - plugin: c:\program files\Google\Update\1.2.133.33\npGoogleOneClick7.dll.**************************************************************************catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url="http://www.gmer.net"]http://www.gmer.net[/url]Rootkit scan 2009-02-03 14:15:51Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ...  scanning hidden autostart entries ... scanning hidden files ...  scan completed successfullyhidden files: 0**************************************************************************.--------------------- DLLs Loaded Under Running Processes ---------------------- - - - - - - > 'winlogon.exe'(1404)c:\windows\system32\vrlogon.dllc:\windows\system32\klogon.dllc:\windows\system32\psqlpwd.dllc:\program files\Protector Suite QL\homefus2.dllc:\program files\Protector Suite QL\infra.dllc:\program files\Protector Suite QL\homepass.dllc:\program files\Protector Suite QL\bio.dllc:\program files\Protector Suite QL\remote.dllc:\program files\Protector Suite QL\crypto.dll- - - - - - - > 'lsass.exe'(1460)c:\windows\system32\psqlpwd.dllc:\program files\Protector Suite QL\homefus2.dllc:\program files\Protector Suite QL\infra.dllc:\program files\Bonjour\mdnsNSP.dll.------------------------ Other Running Processes ------------------------.c:\program files\Intel\Wireless\Bin\S24EvMon.exec:\program files\Lavasoft\Ad-Aware 2007\aawservice.exec:\program files\Bonjour\mDNSResponder.exec:\program files\Intel\Wireless\Bin\EvtEng.exec:\program files\Google\Common\Google Updater\GoogleUpdaterService.exec:\program files\McAfee\Common Framework\FrameworkService.exec:\program files\McAfee\VirusScan Enterprise\Mcshield.exec:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exec:\windows\system32\nvsvc32.exec:\program files\McAfee\Common Framework\naPrdMgr.exec:\program files\Intel\Wireless\Bin\RegSrvc.exec:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exec:\documents and settings\All Users\Start Menu\Programs\Startup\browsers.exec:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exec:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exec:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exec:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exec:\program files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exec:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtPSS.exec:\program files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exec:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exec:\program files\McAfee\Common Framework\UdaterUI.exec:\program files\McAfee\Common Framework\Mctray.exe.**************************************************************************.Completion time: 2009-02-03 14:19:16 - machine was rebooted [aytekim]ComboFix-quarantined-files.txt  2009-02-03 19:19:13Pre-Run: 74,397,147,136 bytes freePost-Run: 77,477,834,752 bytes free257	--- E O F ---	2009-01-22 22:36:00

Attached Files

  • Attached File  log.txt   13.75KB   29 downloads


BC AdBot (Login to Remove)

 


#2 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:09:45 AM

Posted 15 February 2009 - 01:29 PM

Welcome to the BleepingComputer Forums.

Since it has been a few days since you scanned your computer with HijackThis, we will need a new HijackThis log. If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop. If you have RSIT already on your computer, please run it again.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Please post the contents of log.txt.
Thank you for your patience.

Please see Preparation Guide for use before posting about your potential Malware problem.

If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped.

Please post your HijackThis log as a reply to this thread and not as an attachment. I am always leery of opening attachments so I always request that HijackThis logs are to be posted as a reply to the thread. I do not think that you are attaching anything scary but others may do so.

While we are working on your HijackThis log, please:
  • Reply to this thread; do not start another!
  • Do not make any changes on your computer during the cleaning process or download/add programs on your computer unless instructed to do so.
  • Do not run any other tool until instructed to do so!
  • Let me know if any of the links do not work or if any of the tools do not work.
  • Tell me about problems or symptoms that occur during the fix.
  • Do not run any other programs or open any other windows while doing a fix.
  • Ask any questions that you have regarding the fix(es), the infection(s), the performance of your computer, etc.
Thanks.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#3 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:09:45 AM

Posted 22 February 2009 - 09:18 AM

This subject is now closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users