Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Vundo.H, Trojan.Agent, BHO


  • This topic is locked This topic is locked
13 replies to this topic

#1 cflannagan

cflannagan

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:12:24 PM

Posted 13 March 2009 - 01:23 PM

Wife's PC is running XP Pro SP3. Appears to be infected with Vundo.H, BHO, Trojan.Agent (according to Malwarebyte's Anti-Malware tool).

Followed Preparation Guide exactly (http://www.bleepingcomputer.com/forums/topic34773.html) - however when I run DDS.scr, a black DOS window shows up briefly then goes away.

When I tried to run DDS.scr from a CMD window instead, (CMD.exe), it appeared to restart the Explorer (desktop briefly blanks out, then comes back).

Restarted computer to enter Safe Mode with Networking, same results.

Downloading RSIT.exe and running it was successful though.. (log results are from normal mode, not safe mode)

Logfile of random's system information tool 1.05 (written by random/random)
Run by Anita Flannagan at 2009-03-13 11:05:25
Microsoft Windows XP Professional Service Pack 3
System drive C: has 288 GB (94%) free of 305 GB
Total RAM: 1918 MB (71% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:38 AM, on 3/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\acs.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Backblaze\bzserv.exe
C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Backblaze\bzbui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Documents and Settings\Anita Flannagan\Desktop\RSIT.exe
C:\Program Files\trend micro\Anita Flannagan.exe

O2 - BHO: {c9adc8a8-7ced-c6f9-32c4-2f4ce298b2e2} - {2e2b892e-c4f2-4c23-9f6c-dec78a8cda9c} - C:\WINDOWS\system32\hoxzvh.dll
O2 - BHO: (no name) - {45ad9371-e245-4d83-be1a-604ac56da2e0} - C:\WINDOWS\system32\wopowupa.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Browser Helper Object - {AFD4AD01-58C1-47DB-A404-FBE00A6C5486} - C:\Program Files\Common\helper.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [DACSMiniApp] C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Monitor] "C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe"
O4 - HKLM\..\Run: [ladoritopi] Rundll32.exe "C:\WINDOWS\system32\nolomipu.dll",s
O4 - HKLM\..\Run: [58be52d9] rundll32.exe "C:\WINDOWS\system32\tihaduza.dll",b
O4 - HKLM\..\Run: [CPM5b8d6145] Rundll32.exe "c:\windows\system32\mivojova.dll",a
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Backblaze] "C:\Program Files\Backblaze\bzbui.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ladoritopi] Rundll32.exe "C:\WINDOWS\system32\nolomipu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ladoritopi] Rundll32.exe "C:\WINDOWS\system32\nolomipu.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Backblaze] "C:\Program Files\Backblaze\bzbui.exe" -quiet (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Backblaze] "C:\Program Files\Backblaze\bzbui.exe" -quiet (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Wireless Connection Manager.lnk = C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter hijack: text/html - {d18016da-6d14-47d9-962b-b68cba778fd5} - C:\WINDOWS\system32\mst122.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\fosifopu.dll c:\windows\system32\mivojova.dll hoxzvh.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mivojova.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mivojova.dll
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Backblaze Service (bzserv) - Unknown owner - C:\Program Files\Backblaze\bzserv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LeapFrog Connect Device Service - Unknown owner - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 7756 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2e2b892e-c4f2-4c23-9f6c-dec78a8cda9c}]
C:\WINDOWS\system32\hoxzvh.dll [2009-03-13 142336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45ad9371-e245-4d83-be1a-604ac56da2e0}]
C:\WINDOWS\system32\wopowupa.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-02-16 251504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [2009-02-16 657904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}]
Browser Helper Object - C:\Program Files\Common\helper.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [2009-02-16 522224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-02-02 1968920]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-02-16 251504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-03-20 16126464]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"DACSMiniApp"=C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe [2008-03-13 128256]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe [2006-12-15 75520]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-02-02 1601304]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]
"Monitor"=C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe [2008-11-25 356352]
"ladoritopi"=C:\WINDOWS\system32\nolomipu.dll []
"58be52d9"=C:\WINDOWS\system32\tihaduza.dll [2009-03-12 103424]
"CPM5b8d6145"=c:\windows\system32\mivojova.dll [2009-03-12 105984]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"Aim6"=C:\Program Files\AIM6\aim6.exe [2008-10-31 50480]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-04-21 68856]
"Backblaze"=C:\Program Files\Backblaze\bzbui.exe [2009-02-13 303104]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Wireless Connection Manager.lnk - C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe

C:\Documents and Settings\Anita Flannagan\Start Menu\Programs\Startup
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\system32\fosifopu.dll c:\windows\system32\mivojova.dll hoxzvh.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-02-02 110592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-02-02 10520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mivojova.dll [2009-03-12 105984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mivojova.dll [2009-03-12 105984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\WINDOWS\system32\fosifopu.dll

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceClassicControlPanel"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\WINDOWS\system32\drivers\svchost.exe"="C:\WINDOWS\system32\drivers\svchost.exe:*:Disabled:svchost"
"C:\Program Files\AIM6\aim6.exe"="C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:explorer"
"C:\WINDOWS\system32\logonui.exe"="C:\WINDOWS\system32\logonui.exe:*:Enabled:logonui"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

65535-65535-31889 379:31889:443 ----ASH---- C:\WINDOWS\system32\tihaduza.dll
65535-65535-31889 379:31889:443 ----ASH---- C:\WINDOWS\system32\mivojova.dll
65535-65535-31889 379:31889:443 ----ASH---- C:\WINDOWS\system32\merumebe.dll
65535-65535-31889 379:31889:443 ----ASH---- C:\WINDOWS\system32\hesudipi.dll
2009-03-13 11:03:03 ----D---- C:\Program Files\trend micro
2009-03-13 11:03:02 ----D---- C:\rsit
2009-03-13 10:55:46 ----D---- C:\WINDOWS\CSC
2009-03-13 10:55:39 ----A---- C:\WINDOWS\ntbtlog.txt
2009-03-13 00:02:47 ----ASH---- C:\WINDOWS\system32\hoxzvh.dll
2009-03-12 12:02:28 ----SH---- C:\WINDOWS\system32\azudahit.ini
2009-03-12 12:02:18 ----ASH---- C:\WINDOWS\system32\ikiydl.dll
2009-03-12 09:08:19 ----D---- C:\WINDOWS\Prefetch
2009-03-12 08:15:34 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-03-12 08:15:27 ----HDC---- C:\WINDOWS\$NtUninstallKB960714$
2009-03-12 08:15:23 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-03-12 08:15:19 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-03-12 08:15:13 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-03-12 08:15:09 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-03-12 08:15:04 ----HDC---- C:\WINDOWS\$NtUninstallKB958215$
2009-03-12 08:14:58 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-03-12 08:14:54 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2009-03-12 08:14:49 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-03-12 08:14:44 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-03-12 08:14:39 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-03-12 08:14:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956390$
2009-03-12 08:14:25 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-03-12 08:14:21 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-03-12 08:14:16 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-03-12 08:14:10 ----HDC---- C:\WINDOWS\$NtUninstallKB953838$
2009-03-12 08:14:05 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-03-12 08:14:01 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-03-12 08:13:56 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-03-12 08:13:52 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-03-12 08:13:48 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-03-12 08:13:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2009-03-12 08:13:38 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-03-12 08:13:33 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-03-12 08:13:29 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-03-12 08:13:23 ----HDC---- C:\WINDOWS\$NtUninstallKB950759$
2009-03-12 08:13:19 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-03-12 08:13:15 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2009-03-12 08:10:31 ----D---- C:\WINDOWS\system32\en-us
2009-03-12 08:10:30 ----D---- C:\WINDOWS\system32\scripting
2009-03-12 08:10:30 ----D---- C:\WINDOWS\system32\en
2009-03-12 08:10:30 ----D---- C:\WINDOWS\l2schemas
2009-03-12 08:10:29 ----D---- C:\WINDOWS\system32\bits
2009-03-12 08:08:03 ----D---- C:\WINDOWS\ServicePackFiles
2009-03-12 08:06:01 ----D---- C:\WINDOWS\network diagnostic
2009-03-12 08:03:27 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-03-12 03:01:15 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2009-03-12 03:01:08 ----HDC---- C:\WINDOWS\$NtUninstallKB958690_0$
2009-03-04 10:17:11 ----D---- C:\Documents and Settings\Anita Flannagan\Application Data\Help
2009-02-25 04:00:25 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$

======List of files/folders modified in the last 1 months======

2009-03-13 11:03:03 ----RD---- C:\Program Files
2009-03-13 10:55:46 ----D---- C:\WINDOWS
2009-03-13 10:55:38 ----D---- C:\WINDOWS\system32
2009-03-13 10:53:26 ----D---- C:\WINDOWS\Temp
2009-03-13 07:57:22 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2009-03-13 07:11:19 ----HD---- C:\$AVG8.VAULT$
2009-03-12 19:04:34 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-03-12 13:25:47 ----HD---- C:\Program Files\InstallShield Installation Information
2009-03-12 13:25:47 ----D---- C:\Program Files\Fisher-Price
2009-03-12 09:10:31 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-03-12 09:09:19 ----SHD---- C:\WINDOWS\Installer
2009-03-12 09:09:14 ----A---- C:\WINDOWS\OEWABLog.txt
2009-03-12 09:08:59 ----D---- C:\WINDOWS\system32\CatRoot2
2009-03-12 09:08:24 ----A---- C:\WINDOWS\setuplog.txt
2009-03-12 09:07:41 ----D---- C:\WINDOWS\system32\Setup
2009-03-12 09:07:41 ----D---- C:\WINDOWS\AppPatch
2009-03-12 09:07:41 ----D---- C:\Program Files\Messenger
2009-03-12 09:07:40 ----D---- C:\WINDOWS\system32\wbem
2009-03-12 09:07:39 ----RSD---- C:\WINDOWS\Fonts
2009-03-12 09:07:31 ----D---- C:\WINDOWS\system32\drivers
2009-03-12 08:15:36 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-03-12 08:15:36 ----D---- C:\WINDOWS\system32\CatRoot
2009-03-12 08:15:33 ----HD---- C:\WINDOWS\inf
2009-03-12 08:13:03 ----D---- C:\WINDOWS\security
2009-03-12 08:11:04 ----D---- C:\WINDOWS\WinSxS
2009-03-12 08:10:58 ----D---- C:\Program Files\Windows Media Player
2009-03-12 08:10:40 ----D---- C:\WINDOWS\system32\inetsrv
2009-03-12 08:10:40 ----D---- C:\WINDOWS\ime
2009-03-12 08:10:40 ----D---- C:\WINDOWS\Help
2009-03-12 08:10:31 ----D---- C:\WINDOWS\system32\usmt
2009-03-12 08:10:30 ----D---- C:\Program Files\Internet Explorer
2009-03-12 08:10:29 ----D---- C:\WINDOWS\PeerNet
2009-03-12 08:10:29 ----D---- C:\Program Files\Movie Maker
2009-03-12 08:07:52 ----D---- C:\WINDOWS\system32\Restore
2009-03-12 08:07:52 ----D---- C:\WINDOWS\system32\npp
2009-03-12 08:07:52 ----D---- C:\WINDOWS\mui
2009-03-12 08:07:51 ----D---- C:\WINDOWS\msagent
2009-03-12 08:07:50 ----D---- C:\WINDOWS\srchasst
2009-03-12 08:07:49 ----D---- C:\Program Files\NetMeeting
2009-03-12 08:07:47 ----D---- C:\WINDOWS\system32\Com
2009-03-12 08:07:45 ----D---- C:\Program Files\Windows NT
2009-03-12 08:07:45 ----D---- C:\Program Files\Outlook Express
2009-03-12 08:07:42 ----D---- C:\Program Files\Common Files\System
2009-03-12 08:07:25 ----D---- C:\WINDOWS\system32\oobe
2009-03-12 08:07:24 ----D---- C:\WINDOWS\system
2009-03-12 08:05:03 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-03-12 08:03:26 ----D---- C:\WINDOWS\ehome
2009-03-12 03:00:51 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-03-11 05:21:06 ----HD---- C:\WINDOWS\$hf_mig$
2009-02-16 19:17:49 ----D---- C:\Program Files\Google
2009-02-16 19:17:27 ----D---- C:\Documents and Settings\All Users\Application Data\Google

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 36864]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-02-02 325128]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-02-02 27656]
R3 AR5416;D-Link DWA-552 XtremeN Desktop Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5416.sys [2007-01-31 1050784]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-02-02 1975296]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-03-26 4395008]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-08-14 83200]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 WSIMD;wsimd Service; C:\WINDOWS\system32\DRIVERS\wsimd.sys [2006-07-20 54432]
S3 FlyUsb;FLY Fusion; C:\WINDOWS\system32\DRIVERS\FlyUsb.sys [2008-11-25 18560]
S3 PRISM_A02;D-Link Wireless 802.11b/g Driver (USB); C:\WINDOWS\system32\DRIVERS\PRISMA02.sys [2004-08-05 381312]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACS;Atheros Configuration Service; C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\acs.exe [2006-08-25 360532]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-02-02 446464]
R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-02-02 298264]
R2 bzserv;Backblaze Service; C:\Program Files\Backblaze\bzserv.exe [2009-02-13 122880]
R2 LeapFrog Connect Device Service;LeapFrog Connect Device Service; C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe [2008-11-25 991232]
R2 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-16 137200]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Edited by cflannagan, 13 March 2009 - 02:40 PM.


BC AdBot (Login to Remove)

 


#2 Jat90

Jat90

  • Members
  • 1,515 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:United Kingdom
  • Local time:09:24 PM

Posted 13 March 2009 - 02:45 PM

Hello, cflannagan

Welcome to the Bleeping Computer Forums. My name is Jat, and I will be helping you with your situation.

If you do not make a reply in 5 days, we will have to close your topic.


You may want to keep the link to this topic in your favourites. Alternatively, you can click the Posted Image button at the top bar of this topic and Track this Topic. The topics you are tracking can be found here.

Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Please reply using the Posted Image button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just post back here so that we know you're still here.


I need some time to look over your log, I will post back soon.
- Jat90 -

If I have not responded to you within 24 hours, then please feel free to send me a message.

Posted Image

#3 cflannagan

cflannagan
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:12:24 PM

Posted 13 March 2009 - 03:06 PM

Thanks Jat90 and looking forward to working w/you to squash out malware/viruses! :thumbup2:

#4 Jat90

Jat90

  • Members
  • 1,515 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:United Kingdom
  • Local time:09:24 PM

Posted 13 March 2009 - 06:21 PM

Hello,

ViewPoint

Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This changed from what we know in 2006 read this article:

http://www.clickz.com/news/article.php/3561546

I suggest you remove the program now. Click on start > run > and then paste the following into the "open" field: appwiz.cpl and press OK. From within Add or Remove Programs uninstall the following if they exist: Viewpoint, Viewpoint Manager, Viewpoint Media Player.

Registry Backup

Backup Your Registry with ERUNT
  • Download from here
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe

OTMoveIt

We need to execute an OTMoveIt3 script
  • Please download OTMoveIt3 by OldTimer and save it to your desktop.
  • Double click the Posted Image icon on your desktop.
  • Paste the following code under the Posted Image area. Do not include the word "Code".
    :files
    C:\WINDOWS\system32\drivers\svchost.exe
    C:\WINDOWS\system32\hoxzvh.dll
    C:\WINDOWS\system32\wopowupa.dll
    C:\WINDOWS\system32\nolomipu.dll
    C:\WINDOWS\system32\tihaduza.dll
    C:\windows\system32\mivojova.dll
    C:\WINDOWS\system32\fosifopu.dll
    C:\WINDOWS\system32\merumebe.dll
    C:\WINDOWS\system32\hesudipi.dll
    C:\WINDOWS\system32\azudahit.ini
    C:\WINDOWS\system32\ikiydl.dll
    
    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2e2b892e-c4f2-4c23-9f6c-dec78a8cda9c}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45ad9371-e245-4d83-be1a-604ac56da2e0}]
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "ladoritopi"=-
    "58be52d9"=-
    "CPM5b8d6145"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLS"=""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "SSODL"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
    "STS"=-
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
    "notification packages"=hex(7):"scecli"
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "C:\WINDOWS\system32\drivers\svchost.exe"=-
    
    :commands
    [EmptyTemp]
    [Reboot]
  • Push the large Posted Image button.
  • OTMI3 may ask to reboot the machine. Please do so if asked.
  • Copy/Paste the contents under the Posted Image line here in your next reply.
  • If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
ESET Online Scan

Please go to Eset website to perform an online scan. Please use Internet Explorer as it uses ActiveX.
  • Check (tick) this box: YES, I accept the Terms of Use.
  • Click on the Start button next to it.
  • When prompted to run ActiveX. click Yes.
  • You will be asked to install an ActiveX. Click Install.
  • Once installed, the scanner will be initialized.
  • After the scanner is initialized, click Start.
  • Uncheck (untick) Remove found threats box.
  • Check (tick) Scan unwanted applications.
  • Click on Scan.
  • It will start scanning. Please be patient.
  • Once the scan is done, you will find a log in C:\Program Files\esetonlinescanner\log.txt. Please post this log in your next reply.
ReScan

Please rescan with RSIT and post the logs


In your next reply, please post:
  • OTMI log
  • ESET log
  • RSIT logs

Edited by Jat90, 13 March 2009 - 06:25 PM.

- Jat90 -

If I have not responded to you within 24 hours, then please feel free to send me a message.

Posted Image

#5 cflannagan

cflannagan
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:12:24 PM

Posted 13 March 2009 - 08:31 PM

Viewpoint applicaitons removal: Complete

Registry backup: Complete

(3 log files are also attached)

OTMI Log:

DllUnregisterServer procedure not found in C:\WINDOWS\system32\hesudipi.dll
C:\WINDOWS\system32\hesudipi.dll NOT unregistered.
C:\WINDOWS\system32\hesudipi.dll moved successfully.
C:\WINDOWS\system32\azudahit.ini moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ikiydl.dll
C:\WINDOWS\system32\ikiydl.dll NOT unregistered.
C:\WINDOWS\system32\ikiydl.dll moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2e2b892e-c4f2-4c23-9f6c-dec78a8cda9c}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45ad9371-e245-4d83-be1a-604ac56da2e0}\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ladoritopi deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\58be52d9 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CPM5b8d6145 deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLS"|"" /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\SSODL deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler\\STS not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\"notification packages"|hex(7):"scecli" /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\WINDOWS\system32\drivers\svchost.exe deleted successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03132009_174653


ESET Log:

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3936 (20090313)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=b0db8e4ff2967d4085726064a1a9724a
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2009-03-14 01:22:02
# local_time=2009-03-13 06:22:02 (-0800, Pacific Daylight Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=151777
# found=0
# scan_time=1440


RSIT Log:

Logfile of random's system information tool 1.05 (written by random/random)
Run by Anita Flannagan at 2009-03-13 18:24:00
Microsoft Windows XP Professional Service Pack 3
System drive C: has 290 GB (95%) free of 305 GB
Total RAM: 1918 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:24:02 PM, on 3/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\acs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Backblaze\bzbui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Backblaze\bzserv.exe
C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
C:\Program Files\Backblaze\bztransmit.exe
C:\Documents and Settings\Anita Flannagan\Desktop\Cleanup stuff by Craig\RSIT\RSIT.exe
C:\Program Files\trend micro\Anita Flannagan.exe

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Browser Helper Object - {AFD4AD01-58C1-47DB-A404-FBE00A6C5486} - C:\Program Files\Common\helper.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [DACSMiniApp] C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Monitor] "C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe"
O4 - HKLM\..\Run: [CPM5b8d6145] Rundll32.exe "c:\windows\system32\mivojova.dll",a
O4 - HKLM\..\Run: [58be52d9] rundll32.exe "C:\WINDOWS\system32\tihaduza.dll",b
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Backblaze] "C:\Program Files\Backblaze\bzbui.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ladoritopi] Rundll32.exe "C:\WINDOWS\system32\nolomipu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ladoritopi] Rundll32.exe "C:\WINDOWS\system32\nolomipu.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Backblaze] "C:\Program Files\Backblaze\bzbui.exe" -quiet (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Backblaze] "C:\Program Files\Backblaze\bzbui.exe" -quiet (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Wireless Connection Manager.lnk = C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter hijack: text/html - {d18016da-6d14-47d9-962b-b68cba778fd5} - C:\WINDOWS\system32\mst122.dll
O20 - AppInit_DLLs: c:\windows\system32\mivojova.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mivojova.dll (file missing)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mivojova.dll (file missing)
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Backblaze Service (bzserv) - Unknown owner - C:\Program Files\Backblaze\bzserv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LeapFrog Connect Device Service - Unknown owner - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe

--
End of file - 7367 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-02-16 251504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [2009-02-16 657904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}]
Browser Helper Object - C:\Program Files\Common\helper.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [2009-02-16 522224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-02-02 1968920]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-02-16 251504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-03-20 16126464]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"DACSMiniApp"=C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe [2008-03-13 128256]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe [2006-12-15 75520]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-02-02 1601304]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]
"Monitor"=C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe [2008-11-25 356352]
"CPM5b8d6145"=c:\windows\system32\mivojova.dll []
"58be52d9"=C:\WINDOWS\system32\tihaduza.dll []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"Aim6"=C:\Program Files\AIM6\aim6.exe [2008-10-31 50480]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-04-21 68856]
"Backblaze"=C:\Program Files\Backblaze\bzbui.exe [2009-02-13 303104]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Wireless Connection Manager.lnk - C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe

C:\Documents and Settings\Anita Flannagan\Start Menu\Programs\Startup
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="c:\windows\system32\mivojova.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-02-02 110592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-02-02 10520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mivojova.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mivojova.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceClassicControlPanel"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\AIM6\aim6.exe"="C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:explorer"
"C:\WINDOWS\system32\logonui.exe"="C:\WINDOWS\system32\logonui.exe:*:Enabled:logonui"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2009-03-13 17:56:35 ----D---- C:\WINDOWS\LastGood
2009-03-13 17:54:56 ----D---- C:\Program Files\EsetOnlineScanner
2009-03-13 17:46:53 ----D---- C:\_OTMoveIt
2009-03-13 11:03:03 ----D---- C:\Program Files\trend micro
2009-03-13 11:03:02 ----D---- C:\rsit
2009-03-13 10:55:46 ----D---- C:\WINDOWS\CSC
2009-03-13 10:55:39 ----A---- C:\WINDOWS\ntbtlog.txt
2009-03-12 09:08:19 ----D---- C:\WINDOWS\Prefetch
2009-03-12 08:15:34 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-03-12 08:15:27 ----HDC---- C:\WINDOWS\$NtUninstallKB960714$
2009-03-12 08:15:23 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-03-12 08:15:19 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-03-12 08:15:13 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-03-12 08:15:09 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-03-12 08:15:04 ----HDC---- C:\WINDOWS\$NtUninstallKB958215$
2009-03-12 08:14:58 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-03-12 08:14:54 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2009-03-12 08:14:49 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-03-12 08:14:44 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-03-12 08:14:39 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-03-12 08:14:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956390$
2009-03-12 08:14:25 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-03-12 08:14:21 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-03-12 08:14:16 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-03-12 08:14:10 ----HDC---- C:\WINDOWS\$NtUninstallKB953838$
2009-03-12 08:14:05 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-03-12 08:14:01 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-03-12 08:13:56 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-03-12 08:13:52 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-03-12 08:13:48 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-03-12 08:13:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2009-03-12 08:13:38 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-03-12 08:13:33 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-03-12 08:13:29 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-03-12 08:13:23 ----HDC---- C:\WINDOWS\$NtUninstallKB950759$
2009-03-12 08:13:19 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-03-12 08:13:15 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2009-03-12 08:10:31 ----D---- C:\WINDOWS\system32\en-us
2009-03-12 08:10:30 ----D---- C:\WINDOWS\system32\scripting
2009-03-12 08:10:30 ----D---- C:\WINDOWS\system32\en
2009-03-12 08:10:30 ----D---- C:\WINDOWS\l2schemas
2009-03-12 08:10:29 ----D---- C:\WINDOWS\system32\bits
2009-03-12 08:08:03 ----D---- C:\WINDOWS\ServicePackFiles
2009-03-12 08:06:01 ----D---- C:\WINDOWS\network diagnostic
2009-03-12 08:03:27 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-03-12 03:01:15 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2009-03-12 03:01:08 ----HDC---- C:\WINDOWS\$NtUninstallKB958690_0$
2009-03-04 10:17:11 ----D---- C:\Documents and Settings\Anita Flannagan\Application Data\Help
2009-02-25 04:00:25 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$

======List of files/folders modified in the last 1 months======

2009-03-13 17:56:38 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-03-13 17:56:38 ----D---- C:\WINDOWS\Temp
2009-03-13 17:56:37 ----D---- C:\WINDOWS\system32
2009-03-13 17:56:35 ----D---- C:\WINDOWS
2009-03-13 17:54:56 ----RD---- C:\Program Files
2009-03-13 17:54:38 ----D---- C:\WINDOWS\system32\CatRoot2
2009-03-13 17:50:41 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-03-13 17:38:37 ----D---- C:\Documents and Settings\All Users\Application Data\Viewpoint
2009-03-13 07:57:22 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2009-03-13 07:11:19 ----HD---- C:\$AVG8.VAULT$
2009-03-12 13:25:47 ----HD---- C:\Program Files\InstallShield Installation Information
2009-03-12 13:25:47 ----D---- C:\Program Files\Fisher-Price
2009-03-12 09:10:31 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-03-12 09:09:19 ----SHD---- C:\WINDOWS\Installer
2009-03-12 09:09:14 ----A---- C:\WINDOWS\OEWABLog.txt
2009-03-12 09:08:24 ----A---- C:\WINDOWS\setuplog.txt
2009-03-12 09:07:41 ----D---- C:\WINDOWS\system32\Setup
2009-03-12 09:07:41 ----D---- C:\WINDOWS\AppPatch
2009-03-12 09:07:41 ----D---- C:\Program Files\Messenger
2009-03-12 09:07:40 ----D---- C:\WINDOWS\system32\wbem
2009-03-12 09:07:39 ----RSD---- C:\WINDOWS\Fonts
2009-03-12 09:07:31 ----D---- C:\WINDOWS\system32\drivers
2009-03-12 08:15:36 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-03-12 08:15:36 ----D---- C:\WINDOWS\system32\CatRoot
2009-03-12 08:15:33 ----HD---- C:\WINDOWS\inf
2009-03-12 08:13:03 ----D---- C:\WINDOWS\security
2009-03-12 08:11:04 ----D---- C:\WINDOWS\WinSxS
2009-03-12 08:10:58 ----D---- C:\Program Files\Windows Media Player
2009-03-12 08:10:40 ----D---- C:\WINDOWS\system32\inetsrv
2009-03-12 08:10:40 ----D---- C:\WINDOWS\ime
2009-03-12 08:10:40 ----D---- C:\WINDOWS\Help
2009-03-12 08:10:31 ----D---- C:\WINDOWS\system32\usmt
2009-03-12 08:10:30 ----D---- C:\Program Files\Internet Explorer
2009-03-12 08:10:29 ----D---- C:\WINDOWS\PeerNet
2009-03-12 08:10:29 ----D---- C:\Program Files\Movie Maker
2009-03-12 08:07:52 ----D---- C:\WINDOWS\system32\Restore
2009-03-12 08:07:52 ----D---- C:\WINDOWS\system32\npp
2009-03-12 08:07:52 ----D---- C:\WINDOWS\mui
2009-03-12 08:07:51 ----D---- C:\WINDOWS\msagent
2009-03-12 08:07:50 ----D---- C:\WINDOWS\srchasst
2009-03-12 08:07:49 ----D---- C:\Program Files\NetMeeting
2009-03-12 08:07:47 ----D---- C:\WINDOWS\system32\Com
2009-03-12 08:07:45 ----D---- C:\Program Files\Windows NT
2009-03-12 08:07:45 ----D---- C:\Program Files\Outlook Express
2009-03-12 08:07:42 ----D---- C:\Program Files\Common Files\System
2009-03-12 08:07:25 ----D---- C:\WINDOWS\system32\oobe
2009-03-12 08:07:24 ----D---- C:\WINDOWS\system
2009-03-12 08:05:03 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-03-12 08:03:26 ----D---- C:\WINDOWS\ehome
2009-03-12 03:00:51 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-03-11 05:21:06 ----HD---- C:\WINDOWS\$hf_mig$
2009-02-16 19:17:49 ----D---- C:\Program Files\Google
2009-02-16 19:17:27 ----D---- C:\Documents and Settings\All Users\Application Data\Google

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 36864]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-02-02 325128]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-02-02 27656]
R3 AR5416;D-Link DWA-552 XtremeN Desktop Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5416.sys [2007-01-31 1050784]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-02-02 1975296]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-03-26 4395008]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-08-14 83200]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 WSIMD;wsimd Service; C:\WINDOWS\system32\DRIVERS\wsimd.sys [2006-07-20 54432]
S3 FlyUsb;FLY Fusion; C:\WINDOWS\system32\DRIVERS\FlyUsb.sys [2008-11-25 18560]
S3 PRISM_A02;D-Link Wireless 802.11b/g Driver (USB); C:\WINDOWS\system32\DRIVERS\PRISMA02.sys [2004-08-05 381312]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACS;Atheros Configuration Service; C:\Program Files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\acs.exe [2006-08-25 360532]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-02-02 446464]
R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-02-02 298264]
R2 bzserv;Backblaze Service; C:\Program Files\Backblaze\bzserv.exe [2009-02-13 122880]
R2 LeapFrog Connect Device Service;LeapFrog Connect Device Service; C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe [2008-11-25 991232]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-16 137200]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Attached Files



#6 Jat90

Jat90

  • Members
  • 1,515 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:United Kingdom
  • Local time:09:24 PM

Posted 14 March 2009 - 07:26 AM

Hello,

ComboFix

Please download ComboFix from one of these locations (if you already have ComboFix, then delete it and download again) :

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. See this topic to find out how to disable your antivirus and firewall (post #1 and #2).
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

NOTE**ComboFix was intended to be used under the supervision of a helper, not for general use. This is a powerful tool which can permanently damage your computer.

Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.
- Jat90 -

If I have not responded to you within 24 hours, then please feel free to send me a message.

Posted Image

#7 cflannagan

cflannagan
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:12:24 PM

Posted 14 March 2009 - 11:01 AM

ComboFix completed, posting ComboFix log

ComboFix 09-03-13.02 - Anita Flannagan 2009-03-14 8:51:32.1 - NTFSx86
Running from: c:\documents and settings\Anita Flannagan\Desktop\Cleanup stuff by Craig\ComboFix\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Anita Flannagan\Cookies\aqakid.dll
c:\documents and settings\Anita Flannagan\Cookies\eqabofo.lib
c:\documents and settings\Anita Flannagan\Cookies\luxagoleke._dl
c:\documents and settings\Anita Flannagan\Cookies\qeren.bin
c:\documents and settings\Anita Flannagan\Local Settings\Temporary Internet Files\ajan.sys
c:\documents and settings\Anita Flannagan\Local Settings\Temporary Internet Files\hysaforol.scr
c:\documents and settings\Anita Flannagan\Local Settings\Temporary Internet Files\nine.dat
c:\documents and settings\Anita Flannagan\Local Settings\Temporary Internet Files\varubil.lib
c:\program files\Common\helper.sig
c:\windows\sptxryw.nsq

.
((((((((((((((((((((((((( Files Created from 2009-02-14 to 2009-03-14 )))))))))))))))))))))))))))))))
.

2009-03-13 17:54 . 2009-03-13 18:22 <DIR> d-------- c:\program files\EsetOnlineScanner
2009-03-13 17:46 . 2009-03-13 17:46 <DIR> d-------- C:\_OTMoveIt
2009-03-13 11:03 . 2009-03-13 11:03 <DIR> d-------- C:\rsit
2009-03-13 11:03 . 2009-03-13 18:24 <DIR> d-------- c:\program files\trend micro
2009-03-12 08:10 . 2009-03-12 08:10 <DIR> d-------- c:\windows\system32\scripting
2009-03-12 08:10 . 2009-03-12 08:10 <DIR> d-------- c:\windows\system32\en
2009-03-12 08:10 . 2009-03-12 08:10 <DIR> d-------- c:\windows\system32\bits
2009-03-12 08:10 . 2009-03-12 08:10 <DIR> d-------- c:\windows\l2schemas
2009-03-12 08:08 . 2009-03-12 08:08 <DIR> d-------- c:\windows\ServicePackFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-14 15:51 --------- d-----w c:\program files\Common
2009-03-14 00:38 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-03-13 14:57 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-03-12 20:25 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-12 20:25 --------- d-----w c:\program files\Fisher-Price
2009-03-12 10:00 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-17 02:17 --------- d-----w c:\program files\Google
2009-02-14 01:45 --------- d-----w c:\program files\Backblaze
2009-02-02 17:15 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-11-04 00:08 18,330 ----a-w c:\documents and settings\Anita Flannagan\Application Data\tewud.bin
2008-11-04 00:08 14,074 ----a-w c:\documents and settings\All Users\Application Data\lohegacyz.exe
2008-11-04 00:08 11,336 ----a-w c:\documents and settings\Anita Flannagan\Application Data\onafejate.vbs
2008-11-04 00:08 10,555 ----a-w c:\program files\Common Files\ahif.bin
2008-11-04 00:06 19,414 ----a-w c:\program files\Common Files\defunizi.pif
2008-11-04 00:06 12,706 ----a-w c:\program files\Common Files\ehihe.lib
2008-11-04 00:06 10,223 ----a-w c:\documents and settings\All Users\Application Data\meqet.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-31 50480]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-21 68856]
"Backblaze"="c:\program files\Backblaze\bzbui.exe" [2009-02-13 303104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DACSMiniApp"="c:\program files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe" [2008-03-13 128256]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-02 1601304]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2008-11-25 356352]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-20 c:\windows\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Backblaze"="c:\program files\Backblaze\bzbui.exe" [2009-02-13 303104]

c:\documents and settings\Anita Flannagan\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Wireless Connection Manager.lnk - c:\program files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe [2009-01-13 13357056]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-02 10:15 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\mivojova.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-05-08 325128]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-05-08 298264]
R2 bzserv;Backblaze Service;c:\program files\Backblaze\bzserv.exe [2008-07-23 122880]
R2 LeapFrog Connect Device Service;LeapFrog Connect Device Service;c:\program files\LeapFrog\LeapFrog Connect\CommandService.exe [2008-11-25 991232]
R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [2009-01-13 54432]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2009-01-07 18560]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {A75BF1D0-C7C3-CB55-EE17-3225387FD154} /qb
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-CPM5b8d6145 - c:\windows\system32\mivojova.dll
HKLM-Run-58be52d9 - c:\windows\system32\tihaduza.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-14 08:53:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(908)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\acs.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\SoftwareDistribution\Download\d492dac6f594bf63184cb839b64eb87d\update\update.exe
c:\program files\Backblaze\bzfilelist.exe
.
**************************************************************************
.
Completion time: 2009-03-14 8:57:06 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-14 15:56:29

Pre-Run: 303,875,895,296 bytes free
Post-Run: 303,895,085,056 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

157 --- E O F --- 2009-03-12 15:15:39

Attached Files



#8 Jat90

Jat90

  • Members
  • 1,515 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:United Kingdom
  • Local time:09:24 PM

Posted 14 March 2009 - 11:29 AM

Hello,

Submit Files

Download this program:

submit files packer

Highlight the files listed below in bold and right-click and selecting copy.

c:\documents and settings\All Users\Application Data\lohegacyz.exe
c:\documents and settings\Anita Flannagan\Application Data\onafejate.vbs
c:\program files\Common Files\defunizi.pif
c:\documents and settings\All Users\Application Data\meqet.exe



Then start the file packer program and right click in the white box and select paste to paste the copied file names in the field.

Then press the Continue button.

It will create an archive with these files and a small log on your Desktop that starts with a name like requested-file[date].cab.

Rename this file to samples.

Click Here to upload the files please.

CFScript

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\documents and settings\Anita Flannagan\Application Data\tewud.bin
c:\documents and settings\All Users\Application Data\lohegacyz.exe
c:\documents and settings\Anita Flannagan\Application Data\onafejate.vbs
c:\program files\Common Files\ahif.bin
c:\program files\Common Files\defunizi.pif
c:\program files\Common Files\ehihe.lib
c:\documents and settings\All Users\Application Data\meqet.exe
c:\windows\system32\mivojova.dll

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Edited by Jat90, 14 March 2009 - 11:31 AM.

- Jat90 -

If I have not responded to you within 24 hours, then please feel free to send me a message.

Posted Image

#9 cflannagan

cflannagan
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:12:24 PM

Posted 14 March 2009 - 11:45 AM

Submit Files part completed.

ComboFix w/CFSCript completed. Log as follows:

ComboFix 09-03-13.02 - Anita Flannagan 2009-03-14 9:42:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1379 [GMT -7:00]
Running from: c:\documents and settings\Anita Flannagan\Desktop\Cleanup stuff by Craig\ComboFix\ComboFix.exe
Command switches used :: c:\documents and settings\Anita Flannagan\Desktop\Cleanup stuff by Craig\ComboFix\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\documents and settings\All Users\Application Data\lohegacyz.exe
c:\documents and settings\All Users\Application Data\meqet.exe
c:\documents and settings\Anita Flannagan\Application Data\onafejate.vbs
c:\documents and settings\Anita Flannagan\Application Data\tewud.bin
c:\program files\Common Files\ahif.bin
c:\program files\Common Files\defunizi.pif
c:\program files\Common Files\ehihe.lib
c:\windows\system32\mivojova.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\lohegacyz.exe
c:\documents and settings\All Users\Application Data\meqet.exe
c:\documents and settings\Anita Flannagan\Application Data\onafejate.vbs
c:\documents and settings\Anita Flannagan\Application Data\tewud.bin
c:\program files\Common Files\ahif.bin
c:\program files\Common Files\defunizi.pif
c:\program files\Common Files\ehihe.lib

.
((((((((((((((((((((((((( Files Created from 2009-02-14 to 2009-03-14 )))))))))))))))))))))))))))))))
.

2009-03-13 17:54 . 2009-03-13 18:22 <DIR> d-------- c:\program files\EsetOnlineScanner
2009-03-13 17:46 . 2009-03-13 17:46 <DIR> d-------- C:\_OTMoveIt
2009-03-13 11:03 . 2009-03-13 11:03 <DIR> d-------- C:\rsit
2009-03-13 11:03 . 2009-03-13 18:24 <DIR> d-------- c:\program files\trend micro
2009-03-12 08:10 . 2009-03-12 08:10 <DIR> d-------- c:\windows\system32\scripting
2009-03-12 08:10 . 2009-03-12 08:10 <DIR> d-------- c:\windows\system32\en
2009-03-12 08:10 . 2009-03-12 08:10 <DIR> d-------- c:\windows\system32\bits
2009-03-12 08:10 . 2009-03-12 08:10 <DIR> d-------- c:\windows\l2schemas
2009-03-12 08:08 . 2009-03-12 08:08 <DIR> d-------- c:\windows\ServicePackFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-14 15:51 --------- d-----w c:\program files\Common
2009-03-14 00:38 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-03-13 14:57 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-03-12 20:25 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-12 20:25 --------- d-----w c:\program files\Fisher-Price
2009-03-12 10:00 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-17 02:17 --------- d-----w c:\program files\Google
2009-02-14 01:45 --------- d-----w c:\program files\Backblaze
2009-02-09 11:13 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-02 17:15 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-02 17:15 10,520 ----a-w c:\windows\system32\avgrsstx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-03-14_ 8.55.40.64 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-09 07:38:24 17,272 ------w c:\windows\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ------w c:\windows\system32\spmsg.dll
+ 2008-04-15 17:47:33 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\GdiPlus.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-31 50480]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-21 68856]
"Backblaze"="c:\program files\Backblaze\bzbui.exe" [2009-02-13 303104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DACSMiniApp"="c:\program files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe" [2008-03-13 128256]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-02 1601304]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2008-11-25 356352]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-20 c:\windows\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Backblaze"="c:\program files\Backblaze\bzbui.exe" [2009-02-13 303104]

c:\documents and settings\Anita Flannagan\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Wireless Connection Manager.lnk - c:\program files\D-Link\D-Link DWA-552 Xtreme N Desktop Adapter\wirelesscm.exe [2009-01-13 13357056]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-02 10:15 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-05-08 325128]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-05-08 298264]
R2 bzserv;Backblaze Service;c:\program files\Backblaze\bzserv.exe [2008-07-23 122880]
R2 LeapFrog Connect Device Service;LeapFrog Connect Device Service;c:\program files\LeapFrog\LeapFrog Connect\CommandService.exe [2008-11-25 991232]
R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [2009-01-13 54432]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2009-01-07 18560]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {A75BF1D0-C7C3-CB55-EE17-3225387FD154} /qb
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.google.com
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-14 09:42:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(904)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-03-14 9:43:37
ComboFix-quarantined-files.txt 2009-03-14 16:43:26

Pre-Run: 303,856,365,568 bytes free
Post-Run: 303,844,659,200 bytes free

138 --- E O F --- 2009-03-14 15:57:14

Attached Files



#10 Jat90

Jat90

  • Members
  • 1,515 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:United Kingdom
  • Local time:09:24 PM

Posted 14 March 2009 - 12:51 PM

Hello,

Things are looking better now. We just need to update Java. Also, can you tell me how your pc is now? do you have anymore issues?

Update Java

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "Java Runtime Environment (JRE)" JRE 6 Update 12.
  • Click the Download button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u12-windows-i586-p.exe to install the newest version.
-- If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
-- If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
-- The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.


Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click Ok and reboot your computer.
- Jat90 -

If I have not responded to you within 24 hours, then please feel free to send me a message.

Posted Image

#11 cflannagan

cflannagan
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:12:24 PM

Posted 14 March 2009 - 01:15 PM

Java has been updated with new JRE.

Wife's PC appears to be okay now.. no more popups, and no more "missing DLL module" error messages upon Windows startup after rebootings.

Thank you, thank you!

I'm fairly certain the PC got infected by some sites she visited.. but is there a way to find out which site it was? I do keep telling her not to visit questionable sites and not to click on links that does not seem trustworthy.

#12 cflannagan

cflannagan
  • Topic Starter

  • Members
  • 28 posts
  • OFFLINE
  •  
  • Local time:12:24 PM

Posted 14 March 2009 - 01:20 PM

Well, Malwarebyte's Anti-Malware says there's 1 infected object: Trojan.BHO, at HKEY_CLASSES_ROOT\main.bho.1. Is this a concern? Should I let MBAM remove this, or would you want to handle this in a different way? I will stand by for your advice.

I also forgot to check to see if opening up DOS windows (cmd.exe) works now (at beginning of thread, it wasn't). Will get back to this post in a minute.

Update: The CMD.exe does appear to be working now, so that means I can do DDS log if desired.

Edited by cflannagan, 14 March 2009 - 01:26 PM.


#13 Jat90

Jat90

  • Members
  • 1,515 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:United Kingdom
  • Local time:09:24 PM

Posted 15 March 2009 - 05:02 AM

Hello,

Yes, have MBAM remove that. That is just a leftover registry entry, nothing to worry about. Other than that your system appears clean.

Congratulations you are now clean! :thumbup2:

We should tidy up our mess though.

Uninstall ComboFix
  • Go to Start, then click Run
  • In the box, type: Combofix /u
  • Press Enter or click ok, and ComboFix will uninstall. Refer to the picture below if unsure.
    Posted Image
OTCleanIt
  • Please download OTCleanIt from one of the following mirrors and save it to your desktop:
  • Double click the Posted Image icon.
  • Push the large "Cleanup!" button.
  • Allow your system to reboot.
Other Deletions

Locate where you saved RSIT.exe, right click the file and select Delete.



Take a read of this excellent tutorial:

Simple and easy ways to keep your computer safe and secure on the Internet


Disable and Enable System Restore.

You should disable and re-enable system restore to make sure there are no infected files found in a restore point. You should now create a new restore point, since your system is clean.

You can find instructions on how to disable and re-enable system restore here:

Windows XP System Restore Guide

Visit Microsoft's Windows Update Site Frequently
  • It is important that you visit http://www.windowsupdate.com regularly.
  • This will ensure your computer has always the latest security updates available installed on your computer.
  • If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
System still slow?

You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.

Next, I would recommend the download and installation of some (I would say two is enough) of the following programs:

Spybot© - Search and Destroy
  • This will provide real-time spyware & hijacker protection on your computer alongside your virus protection.
  • You should also scan your computer with program on a regular basis just as you would an anti virus software.
SUPERAntiSpyware
  • You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot.
  • Each antispyware product has different detection rates for different infections, using different products therefore increases your chances of finding and killing most malware.
Javacools© SpywareBlaster
  • SpywareBlaster will added a large list of programs and sites into your Internet Explorer and Firefox settings and that will protect you from running and downloading known malicious programs.
Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.

Glad I could Help :)
- Jat90 -

If I have not responded to you within 24 hours, then please feel free to send me a message.

Posted Image

#14 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:04:24 PM

Posted 16 March 2009 - 05:40 PM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :thumbup2:

If your the topic starter, and need this topic reopened, please contact me via pm with the address of the thread.

Everyone else please begin a New Topic.
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users