Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Browser Hijacker, possibly Vundo


  • This topic is locked This topic is locked
12 replies to this topic

#1 stevepremo

stevepremo

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:56 AM

Posted 20 March 2009 - 12:20 PM

My computer is infected with some kind of browser hijacker which does the following: (1) clicking on a Google search result takes me to an ad site, not to the appropriate link; (2) new instances of Internet Explorer keep popping up, usually with an audio ad, sometimes with a web page; (3) attempts to install anti-spyware programs either fail completely, or the programs will not open.

Windows Defender and the Windows Malicious Software Removal Tool do not detect it.

Here is the DDS log:


DDS (Ver_09-03-16.01) - NTFSx86
Run by sup026 at 10:09:36.74 on Fri 03/20/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_12
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1526.544 [GMT -7:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PMService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\ePOAgent\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\ePOAgent\UpdaterUI.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\SHOREL~1\SHOREW~1\STCHost.exe
C:\PROGRA~1\SHOREL~1\SHOREW~1\CSISCMGR.exe
C:\Program Files\Propalms Client\iqclntmgr.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Microsoft Shared\Speech\sapisvr.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\sup026\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.premofine.com/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.dell.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\progra~1\yahoo!\common\yhexbmesus.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [ShoreTel Personal Call Manager] c:\program files\shoreline communications\shoreware client\StartCli.exe
uRun: [HijackThis startup scan] c:\program files\hijackthis\HijackThis.exe /startupscan
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [McAfeeUpdaterUI] "c:\epoagent\UpdaterUI.exe" /StartedFromRunKey
mRun: [ShStatEXE] "c:\program files\network associates\virusscan\SHSTAT.EXE" /STANDALONE
mRun: [EPA_EZ_GPO_Tool] c:\windows\system32\EZ_GPO_Tool.exe
mRun: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
dRunOnce: [WMC_WMPDBExport] c:\program files\windows media player\wmdbexport.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\refres~1.lnk - c:\windows\installer\{8a27a7e0-618c-4f75-82c8-92ac88bf6140}\Icon8A27A7E02.exe
uPolicies-explorer: NoStartMenuMyMusic = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229703002922
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\sup026\applic~1\mozilla\firefox\profiles\4mt4b0dd.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.premofine.com/
FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll

============= SERVICES / DRIVERS ===============

R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [2005-9-8 58464]
R2 EPA_GPO_PMService;Energy Star™ EZ GPO Power Management Configuration Tool;c:\windows\system32\PMService.exe [2005-1-21 81920]
R2 McAfeeFramework;McAfee Framework Service;c:\epoagent\FrameworkService.exe [2005-9-7 106583]
R2 McShield;Network Associates McShield;c:\program files\network associates\virusscan\Mcshield.exe [2006-2-14 221191]
R2 McTaskManager;Network Associates Task Manager;c:\program files\network associates\virusscan\VsTskMgr.exe [2006-6-8 29184]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 NaiAvFilter1;NaiAvFilter1;c:\windows\system32\drivers\naiavf5x.sys [2005-9-8 116864]
S4 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-11-20 33752]

=============== Created Last 30 ================

2009-03-19 15:03 <DIR> --dsh--- c:\documents and settings\sup026\PrivacIE
2009-03-19 15:02 <DIR> --dsh--- c:\documents and settings\sup026\IECompatCache
2009-03-19 15:00 <DIR> --dsh--- c:\documents and settings\sup026\IETldCache
2009-03-19 14:57 <DIR> -cd-h--- c:\windows\ie8
2009-03-17 09:42 333,288 a------- c:\windows\system\sqlite3.dll
2009-03-08 14:22 49,152 -------- c:\windows\system32\msrating.dll.mui
2009-03-08 14:22 2,560 -------- c:\windows\system32\mshta.exe.mui
2009-03-08 14:21 4,096 -------- c:\windows\system32\ie4uinit.exe.mui
2009-03-08 14:20 81,920 -------- c:\windows\system32\iedkcs32.dll.mui
2009-03-08 04:33 18,944 -------- c:\windows\system32\dllcache\corpol.dll
2009-03-06 17:46 <DIR> --d----- c:\program files\Rootkit Revealer
2009-03-06 17:39 19,929 a------- c:\windows\system32\AAWService_2009_03_06_16_39_36.dmp
2009-03-06 15:45 19,717 a------- c:\windows\system32\AAWService_2009_03_06_14_45_08.dmp
2009-03-06 15:22 19,717 a------- c:\windows\system32\AAWService_2009_03_06_14_22_57.dmp
2009-03-06 15:15 19,717 a------- c:\windows\system32\AAWService_2009_03_06_14_15_17.dmp
2009-03-06 15:08 19,929 a------- c:\windows\system32\AAWService_2009_03_06_14_08_56.dmp
2009-03-06 14:47 21,622 a------- c:\windows\system32\AAWService_2009_03_06_13_47_48.dmp
2009-03-06 13:43 <DIR> --d----- c:\program files\Lavasoft
2009-03-06 11:35 47,870 a------- C:\MGlogs.zip
2009-03-06 11:34 <DIR> --d----- C:\MGtools
2009-03-06 11:11 1,337,489 a------- C:\MGtools.exe
2009-03-06 10:38 <DIR> --d----- c:\program files\CCleaner
2009-03-06 10:32 <DIR> --d----- c:\windows\pss
2009-03-03 16:20 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-03-03 16:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-03-03 13:29 1,985,024 a------- c:\windows\system32\dllcache\iertutil.dll
2009-03-03 13:29 594,432 a------- c:\windows\system32\dllcache\msfeeds.dll
2009-03-03 13:29 59,904 a------- c:\windows\system32\dllcache\icardie.dll
2009-03-03 13:29 55,296 a------- c:\windows\system32\dllcache\msfeedsbs.dll
2009-03-03 13:29 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2009-03-03 13:29 3,698,584 a------- c:\windows\system32\dllcache\ieapfltr.dat
2009-03-03 13:29 1,241,088 a------- c:\windows\system32\dllcache\ieframe.dll.mui
2009-03-03 13:29 445,952 a------- c:\windows\system32\dllcache\ieapfltr.dll
2009-03-03 13:29 11,063,808 a------- c:\windows\system32\dllcache\ieframe.dll
2009-03-03 13:28 333,952 -------- c:\windows\system32\dllcache\srv.sys
2009-03-03 13:26 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
2009-03-03 13:25 1,106,944 -------- c:\windows\system32\dllcache\msxml3.dll
2009-03-03 13:25 2,189,184 -------- c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-03 13:25 2,145,280 -------- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-03 13:25 2,023,936 -------- c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-03 13:25 2,066,048 -------- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-03 13:24 1,846,400 -------- c:\windows\system32\dllcache\win32k.sys
2009-03-03 13:23 331,776 -------- c:\windows\system32\dllcache\msadce.dll
2009-03-03 13:22 691,712 -------- c:\windows\system32\dllcache\inetcomm.dll
2009-03-03 13:21 272,128 -------- c:\windows\system32\dllcache\bthport.sys
2009-03-03 13:20 203,136 -------- c:\windows\system32\dllcache\rmcast.sys

==================== Find3M ====================

2009-03-10 08:50 410,984 a------- c:\windows\system32\deploytk.dll
2009-03-08 14:09 638,816 a------- c:\windows\system32\dllcache\iexplore.exe
2009-03-08 14:09 391,536 a------- c:\windows\system32\dllcache\iedkcs32.dll
2009-03-08 04:41 5,937,152 a------- c:\windows\system32\dllcache\mshtml.dll
2009-03-08 04:34 914,944 a------- c:\windows\system32\wininet.dll
2009-03-08 04:34 914,944 a------- c:\windows\system32\dllcache\wininet.dll
2009-03-08 04:34 1,206,784 a------- c:\windows\system32\dllcache\urlmon.dll
2009-03-08 04:34 236,544 a------- c:\windows\system32\dllcache\webcheck.dll
2009-03-08 04:34 43,008 a------- c:\windows\system32\licmgr10.dll
2009-03-08 04:34 43,008 a------- c:\windows\system32\dllcache\licmgr10.dll
2009-03-08 04:34 105,984 a------- c:\windows\system32\dllcache\url.dll
2009-03-08 04:34 193,536 a------- c:\windows\system32\dllcache\msrating.dll
2009-03-08 04:34 109,568 a------- c:\windows\system32\dllcache\occache.dll
2009-03-08 04:33 759,296 a------- c:\windows\system32\dllcache\VGX.dll
2009-03-08 04:33 18,944 a------- c:\windows\system32\corpol.dll
2009-03-08 04:33 25,600 a------- c:\windows\system32\dllcache\jsproxy.dll
2009-03-08 04:33 726,528 a------- c:\windows\system32\dllcache\jscript.dll
2009-03-08 04:33 229,376 a------- c:\windows\system32\dllcache\ieaksie.dll
2009-03-08 04:33 420,352 a------- c:\windows\system32\vbscript.dll
2009-03-08 04:33 420,352 a------- c:\windows\system32\dllcache\vbscript.dll
2009-03-08 04:33 125,952 a------- c:\windows\system32\dllcache\ieakeng.dll
2009-03-08 04:32 72,704 a------- c:\windows\system32\dllcache\admparse.dll
2009-03-08 04:32 72,704 a------- c:\windows\system32\admparse.dll
2009-03-08 04:32 173,056 a------- c:\windows\system32\dllcache\ie4uinit.exe
2009-03-08 04:32 163,840 a------- c:\windows\system32\dllcache\ieakui.dll
2009-03-08 04:32 71,680 a------- c:\windows\system32\iesetup.dll
2009-03-08 04:32 71,680 a------- c:\windows\system32\dllcache\iesetup.dll
2009-03-08 04:32 55,808 a------- c:\windows\system32\dllcache\iernonce.dll
2009-03-08 04:32 128,512 a------- c:\windows\system32\dllcache\advpack.dll
2009-03-08 04:32 94,720 a------- c:\windows\system32\dllcache\inseng.dll
2009-03-08 04:32 611,840 a------- c:\windows\system32\dllcache\mstime.dll
2009-03-08 04:31 183,808 a------- c:\windows\system32\dllcache\iepeers.dll
2009-03-08 04:31 348,160 a------- c:\windows\system32\dllcache\dxtmsft.dll
2009-03-08 04:31 216,064 a------- c:\windows\system32\dllcache\dxtrans.dll
2009-03-08 04:31 34,816 a------- c:\windows\system32\imgutil.dll
2009-03-08 04:31 34,816 a------- c:\windows\system32\dllcache\imgutil.dll
2009-03-08 04:31 46,592 a------- c:\windows\system32\dllcache\pngfilt.dll
2009-03-08 04:31 66,560 a------- c:\windows\system32\dllcache\mshtmled.dll
2009-03-08 04:31 48,128 a------- c:\windows\system32\mshtmler.dll
2009-03-08 04:31 48,128 a------- c:\windows\system32\dllcache\mshtmler.dll
2009-03-08 04:31 45,568 a------- c:\windows\system32\mshta.exe
2009-03-08 04:31 45,568 a------- c:\windows\system32\dllcache\mshta.exe
2009-03-08 04:24 68,608 a------- c:\windows\system32\dllcache\hmmapi.dll
2009-03-08 04:22 156,160 a------- c:\windows\system32\msls31.dll
2009-03-08 04:22 156,160 a------- c:\windows\system32\dllcache\msls31.dll
2009-02-25 11:43 24,776 a------- c:\docume~1\sup026\applic~1\GDIPFONTCACHEV1.DAT
2009-01-07 18:21 26,144 a------- c:\windows\system32\spupdsvc.exe
2009-01-07 18:20 134,144 -------- c:\windows\system32\dllcache\sqmapi.dll
2009-01-07 18:20 1,497,088 -------- c:\windows\system32\dllcache\shdocvw.dll
2009-01-07 18:20 1,022,976 -------- c:\windows\system32\dllcache\browseui.dll
2009-01-07 18:20 24,576 a------- c:\windows\system32\nlsdl.dll
2009-01-07 18:20 26,112 a------- c:\windows\system32\idndl.dll
2009-01-07 18:20 23,552 a------- c:\windows\system32\normaliz.dll
2009-01-07 18:20 265,720 a------- c:\windows\system32\msdbg2.dll
2008-12-20 16:15 133,120 a------- c:\windows\system32\dllcache\extmgr.dll
2006-07-07 14:55 1,414,801 a------- c:\docume~1\sup026\applic~1\Install.dat

============= FINISH: 10:11:22.18 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:08:56 AM

Posted 29 March 2009 - 07:09 PM

Hello stevepremo,

Posted Image

Sorry about the delay.:thumbup2: If you still need help, please post a new HijackThis log to make sure nothing has changed, and I'll be happy to look at it for you.

Please do this:
1. Download HijackThis™ here:
http://www.trendsecure.com/portal/en-US/th.../hijackthis.php

2. Click 'Do a System Scan and Save log'.
The HJT log will open in notepad.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 stevepremo

stevepremo
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:56 AM

Posted 01 April 2009 - 12:33 PM

Here is my current HJT log. It does not show iexplorer.exe running, but that process does start running two instances very frequently. When I notice them open, I close them. One typically takes about 18 megabytes of memory, and the other takes about 160 megabytes. I close the smaller one and that closes the larger one. If I close the larger one, it pops back up right away.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:28:38 AM, on 4/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PMService.exe
C:\ePOAgent\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\ePOAgent\UpdaterUI.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\SHOREL~1\SHOREW~1\STCHost.exe
C:\Program Files\Propalms Client\iqclntmgr.exe
C:\PROGRA~1\SHOREL~1\SHOREW~1\CSISCMGR.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\PMAIL\Programs\winpm-32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\Documents and Settings\sup026\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\ePOAgent\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [EPA_EZ_GPO_Tool] C:\WINDOWS\system32\EZ_GPO_Tool.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ShoreTel Personal Call Manager] C:\Program Files\Shoreline Communications\ShoreWare Client\StartCli.exe
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\HijackThis\HijackThis.exe /startupscan
O4 - HKUS\S-1-5-18\..\RunOnce: [WMC_WMPDBExport] C:\Program Files\Windows Media Player\wmdbexport.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [WMC_WMPDBExport] C:\Program Files\Windows Media Player\wmdbexport.exe (User 'Default user')
O4 - Global Startup: Refresh All Propalms TSE Shortcuts .lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase6662.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1229703002922
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = santacruzcourt.local
O17 - HKLM\Software\..\Telephony: DomainName = santacruzcourt.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = santacruzcourt.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = santacruzcourt.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = santacruzcourt.local
O23 - Service: Energy Star™ EZ GPO Power Management Configuration Tool (EPA_GPO_PMService) - TerraNovum - C:\WINDOWS\system32\PMService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\ePOAgent\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe

--
End of file - 5925 bytes

#4 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:08:56 AM

Posted 01 April 2009 - 12:50 PM

Hello,

Please download GooredFix and save it to your Desktop. Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt). Note: Do not run Option #2 yet.

Please download Malwarebytes' Anti-Malware from one of these places:
http://www.majorgeeks.com/Malwarebytes_Ant...ware_d5756.html
http://www.besttechie.net/mbam/mbam-setup.exe

Double Click mbam-setup.exe to install the application.

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform Quick Scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy&Paste the entire report in your next reply along with a fresh HijackThis log.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#5 stevepremo

stevepremo
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:56 AM

Posted 01 April 2009 - 01:43 PM

I downloaded Malwarebytes' Anti-Malware but it will not install. The process mbam-setup.exe will start running, and I can see it in the task manager, but nothing else happens.

Here is the Gooredfix log:

GooredFix v1.92 by jpshortstuff
Log created at 11:10 on 01/04/2009 running Option #1 (sup026)
Firefox version 3.0.7 (en-US)

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.7\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.7\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"

#6 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:08:56 AM

Posted 01 April 2009 - 01:51 PM

Hello,

Okay then, we'll do something else. GooredFix came up clean and you can delete it. This is telling me you may have a rootkit, so we may have to trick the thing to allow this next tool to run.

I need for you to go offline completely and disable ALL your protective programs after you download ComboFix, but before you run it. Sometimes those programs interfere with it, and we don't want that! :thumbup2:

This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please, along with a new HijackThis log.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.

If it can't run, then rename ComboFix.exe to stevepremo.exe and try it again. Also, if McAfee gives you too much trouble, uninstall it temporarily.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#7 stevepremo

stevepremo
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:56 AM

Posted 01 April 2009 - 03:35 PM

I succeeded in downloading and running combofix. Here is the log:

ComboFix 09-04-01.01 - SUP026 2009-04-01 13:18:11.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1526.1079 [GMT -7:00]
Running from: c:\documents and settings\sup026\Desktop\stevepremo.exe
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\sup026\Application Data\Install.dat
c:\windows\system32\drivers\UACetypehwh.sys
c:\windows\system32\UACbfjdnkfx.log
c:\windows\system32\UACdctvbfam.dll
c:\windows\system32\UACgobqjroa.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACkdmbpxhm.dll
c:\windows\system32\UACmbqvyyiq.log
c:\windows\system32\UACmkjgercr.dll
c:\windows\system32\UACmmnrfdqv.dll
c:\windows\system32\UAComliqowk.dll
c:\windows\system32\UACpllipnur.log
c:\windows\system32\UACsiboewwx.dat
c:\windows\system32\UACtxlempqm.db

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-03-01 to 2009-04-01 )))))))))))))))))))))))))))))))
.

2009-03-19 15:03 . 2009-03-19 15:03 <DIR> d--hs---- c:\documents and settings\sup026\PrivacIE
2009-03-19 15:02 . 2009-03-19 15:02 <DIR> d--hs---- c:\documents and settings\sup026\IECompatCache
2009-03-19 15:00 . 2009-03-19 15:00 <DIR> d--hs---- c:\windows\system32\config\systemprofile\IETldCache
2009-03-19 15:00 . 2009-03-19 15:00 <DIR> d--hs---- c:\documents and settings\sup026\IETldCache
2009-03-19 14:58 . 2009-03-23 09:35 1,374 --a------ c:\windows\imsins.BAK
2009-03-19 14:57 . 2009-03-19 14:58 <DIR> d--h-c--- c:\windows\ie8
2009-03-17 09:42 . 2008-09-03 13:57 333,288 --a------ c:\windows\system\sqlite3.dll
2009-03-08 14:22 . 2009-03-08 14:22 49,152 --------- c:\windows\system32\msrating.dll.mui
2009-03-08 14:22 . 2009-03-08 14:22 2,560 --------- c:\windows\system32\mshta.exe.mui
2009-03-08 14:21 . 2009-03-08 14:21 4,096 --------- c:\windows\system32\ie4uinit.exe.mui
2009-03-08 14:20 . 2009-03-08 14:20 81,920 --------- c:\windows\system32\iedkcs32.dll.mui
2009-03-08 04:33 . 2009-03-08 04:33 18,944 --------- c:\windows\system32\dllcache\corpol.dll
2009-03-06 17:46 . 2009-03-06 17:46 <DIR> d-------- c:\program files\Rootkit Revealer
2009-03-06 17:39 . 2009-03-06 17:39 19,929 --a------ c:\windows\system32\AAWService_2009_03_06_16_39_36.dmp
2009-03-06 15:45 . 2009-03-06 15:45 19,717 --a------ c:\windows\system32\AAWService_2009_03_06_14_45_08.dmp
2009-03-06 15:22 . 2009-03-06 15:22 19,717 --a------ c:\windows\system32\AAWService_2009_03_06_14_22_57.dmp
2009-03-06 15:15 . 2009-03-06 15:15 19,717 --a------ c:\windows\system32\AAWService_2009_03_06_14_15_17.dmp
2009-03-06 15:08 . 2009-03-06 15:08 19,929 --a------ c:\windows\system32\AAWService_2009_03_06_14_08_56.dmp
2009-03-06 14:47 . 2009-03-06 14:47 21,622 --a------ c:\windows\system32\AAWService_2009_03_06_13_47_48.dmp
2009-03-06 13:49 . 2009-03-20 08:49 <DIR> d----c--- c:\windows\system32\DRVSTORE
2009-03-06 13:43 . 2009-03-20 08:49 <DIR> d-------- c:\program files\Lavasoft
2009-03-06 13:23 . 2009-03-06 13:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-06 11:35 . 2009-03-06 12:53 47,870 --a------ C:\MGlogs.zip
2009-03-06 11:34 . 2009-03-06 12:53 <DIR> d-------- C:\MGtools
2009-03-06 11:11 . 2009-03-06 11:11 1,337,489 --a------ C:\MGtools.exe
2009-03-06 10:38 . 2009-03-06 10:38 <DIR> d-------- c:\program files\CCleaner
2009-03-03 16:20 . 2009-03-20 08:49 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-03-03 16:20 . 2009-03-20 08:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-03 13:44 . 2009-03-17 12:21 <DIR> d-------- c:\program files\Windows Live Safety Center
2009-03-03 13:29 . 2009-03-08 04:39 11,063,808 --a------ c:\windows\system32\dllcache\ieframe.dll
2009-03-03 13:29 . 2009-02-06 21:07 3,698,584 --a------ c:\windows\system32\dllcache\ieapfltr.dat
2009-03-03 13:29 . 2009-03-08 04:32 1,985,024 --a------ c:\windows\system32\dllcache\iertutil.dll
2009-03-03 13:29 . 2009-03-08 14:22 1,241,088 --a------ c:\windows\system32\dllcache\ieframe.dll.mui
2009-03-03 13:29 . 2009-03-08 04:32 594,432 --a------ c:\windows\system32\dllcache\msfeeds.dll
2009-03-03 13:29 . 2009-03-08 04:11 445,952 --a------ c:\windows\system32\dllcache\ieapfltr.dll
2009-03-03 13:29 . 2009-03-08 04:31 59,904 --a------ c:\windows\system32\dllcache\icardie.dll
2009-03-03 13:29 . 2009-03-08 04:31 55,296 --a------ c:\windows\system32\dllcache\msfeedsbs.dll
2009-03-03 13:29 . 2008-12-19 02:10 13,824 --------- c:\windows\system32\dllcache\ieudinit.exe
2009-03-03 13:28 . 2008-12-11 03:57 333,952 --------- c:\windows\system32\dllcache\srv.sys
2009-03-03 13:26 . 2008-10-24 04:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2009-03-03 13:25 . 2008-08-14 03:11 2,189,184 --------- c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-03 13:25 . 2008-08-14 03:09 2,145,280 --------- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-03 13:25 . 2008-08-14 02:33 2,066,048 --------- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-03 13:25 . 2008-08-14 02:33 2,023,936 --------- c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-03 13:25 . 2008-09-04 10:15 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
2009-03-03 13:24 . 2009-02-09 04:13 1,846,784 --------- c:\windows\system32\dllcache\win32k.sys
2009-03-03 13:23 . 2008-05-01 07:33 331,776 --------- c:\windows\system32\dllcache\msadce.dll
2009-03-03 13:22 . 2008-04-11 12:04 691,712 --------- c:\windows\system32\dllcache\inetcomm.dll
2009-03-03 13:21 . 2008-06-13 04:05 272,128 --------- c:\windows\system32\dllcache\bthport.sys
2009-03-03 13:20 . 2008-05-08 07:02 203,136 --------- c:\windows\system32\dllcache\rmcast.sys
2009-03-03 12:44 . 2009-03-03 12:44 0 --a------ c:\windows\nsreg.dat
2009-03-03 09:28 . 2009-03-19 14:41 1,896,749 --a------ c:\windows\system32\uactmp.db

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-01 15:51 --------- d-----w c:\program files\Java
2009-03-09 12:19 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 21:09 638,816 ----a-w c:\windows\system32\dllcache\iexplore.exe
2009-03-08 21:09 391,536 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
2009-03-08 11:41 5,937,152 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-03-08 11:34 914,944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 914,944 ----a-w c:\windows\system32\dllcache\wininet.dll
2009-03-08 11:34 43,008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:34 43,008 ----a-w c:\windows\system32\dllcache\licmgr10.dll
2009-03-08 11:34 236,544 ----a-w c:\windows\system32\dllcache\webcheck.dll
2009-03-08 11:34 193,536 ----a-w c:\windows\system32\dllcache\msrating.dll
2009-03-08 11:34 109,568 ----a-w c:\windows\system32\dllcache\occache.dll
2009-03-08 11:34 105,984 ----a-w c:\windows\system32\dllcache\url.dll
2009-03-08 11:34 1,206,784 ----a-w c:\windows\system32\dllcache\urlmon.dll
2009-03-08 11:33 759,296 ----a-w c:\windows\system32\dllcache\VGX.dll
2009-03-08 11:33 726,528 ----a-w c:\windows\system32\dllcache\jscript.dll
2009-03-08 11:33 420,352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 11:33 420,352 ----a-w c:\windows\system32\dllcache\vbscript.dll
2009-03-08 11:33 25,600 ----a-w c:\windows\system32\dllcache\jsproxy.dll
2009-03-08 11:33 229,376 ----a-w c:\windows\system32\dllcache\ieaksie.dll
2009-03-08 11:33 18,944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 125,952 ----a-w c:\windows\system32\dllcache\ieakeng.dll
2009-03-08 11:32 94,720 ----a-w c:\windows\system32\dllcache\inseng.dll
2009-03-08 11:32 72,704 ----a-w c:\windows\system32\dllcache\admparse.dll
2009-03-08 11:32 72,704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 71,680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 71,680 ----a-w c:\windows\system32\dllcache\iesetup.dll
2009-03-08 11:32 611,840 ----a-w c:\windows\system32\dllcache\mstime.dll
2009-03-08 11:32 55,808 ----a-w c:\windows\system32\dllcache\iernonce.dll
2009-03-08 11:32 173,056 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2009-03-08 11:32 163,840 ----a-w c:\windows\system32\dllcache\ieakui.dll
2009-03-08 11:32 128,512 ----a-w c:\windows\system32\dllcache\advpack.dll
2009-03-08 11:31 66,560 ----a-w c:\windows\system32\dllcache\mshtmled.dll
2009-03-08 11:31 48,128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 48,128 ----a-w c:\windows\system32\dllcache\mshtmler.dll
2009-03-08 11:31 46,592 ----a-w c:\windows\system32\dllcache\pngfilt.dll
2009-03-08 11:31 45,568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 11:31 45,568 ----a-w c:\windows\system32\dllcache\mshta.exe
2009-03-08 11:31 348,160 ----a-w c:\windows\system32\dllcache\dxtmsft.dll
2009-03-08 11:31 34,816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 34,816 ----a-w c:\windows\system32\dllcache\imgutil.dll
2009-03-08 11:31 216,064 ----a-w c:\windows\system32\dllcache\dxtrans.dll
2009-03-08 11:31 183,808 ----a-w c:\windows\system32\dllcache\iepeers.dll
2009-03-08 11:24 68,608 ----a-w c:\windows\system32\dllcache\hmmapi.dll
2009-03-08 11:22 156,160 ----a-w c:\windows\system32\msls31.dll
2009-03-08 11:22 156,160 ----a-w c:\windows\system32\dllcache\msls31.dll
2009-02-25 18:43 24,776 ----a-w c:\documents and settings\sup026\Application Data\GDIPFONTCACHEV1.DAT
2009-02-09 11:13 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-01-08 01:21 26,144 ----a-w c:\windows\system32\spupdsvc.exe
2009-01-08 01:20 265,720 ----a-w c:\windows\system32\msdbg2.dll
2009-01-08 01:20 26,112 ----a-w c:\windows\system32\idndl.dll
2009-01-08 01:20 24,576 ----a-w c:\windows\system32\nlsdl.dll
2009-01-08 01:20 23,552 ----a-w c:\windows\system32\normaliz.dll
2009-01-08 01:20 134,144 ------w c:\windows\system32\dllcache\sqmapi.dll
2009-01-08 01:20 1,497,088 ------w c:\windows\system32\dllcache\shdocvw.dll
2009-01-08 01:20 1,022,976 ------w c:\windows\system32\dllcache\browseui.dll
2006-06-22 18:41 5,032 ----a-r c:\windows\inf\SET22.tmp
2006-06-22 18:41 5,032 ----a-r c:\windows\inf\SET12.tmp
2005-08-27 21:30 5,065 ----a-w c:\windows\inf\SET34.tmp
2005-08-27 21:30 5,065 ----a-w c:\windows\inf\SET17.tmp
2005-08-27 21:30 5,065 ----a-w c:\windows\inf\SET14.tmp
2005-08-27 21:30 5,065 ----a-w c:\windows\inf\SET10.tmp
2008-12-19 17:15 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008121920081220\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"ShoreTel Personal Call Manager"="c:\program files\Shoreline Communications\ShoreWare Client\StartCli.exe" [2008-09-30 41000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"McAfeeUpdaterUI"="c:\epoagent\UpdaterUI.exe" [2004-01-28 135248]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-22 94208]
"EPA_EZ_GPO_Tool"="c:\windows\system32\EZ_GPO_Tool.exe" [2005-01-21 69632]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-13 143360]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WMC_WMPDBExport"="c:\program files\Windows Media Player\wmdbexport.exe" [2006-10-18 493568]

c:\documents and settings\jerry.SANTACRUZCOURT\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\palmOne\HOTSYNC.EXE [2004-04-13 299008]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Refresh All Propalms TSE Shortcuts .lnk - c:\windows\Installer\{8A27A7E0-618C-4F75-82C8-92AC88BF6140}\Icon8A27A7E02.exe [2006-09-27 55296]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuMyMusic"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3679447974-1749364436-3802554648-1263\Scripts\Logon\0\0]
"Script"=Map_Drives.vbs

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [2005-09-08 58464]
R2 EPA_GPO_PMService;Energy Star™ EZ GPO Power Management Configuration Tool;c:\windows\system32\PMService.exe [2005-01-21 81920]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S4 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-11-20 33752]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-03-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []

2009-04-01 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 20:20]

2009-04-01 c:\windows\Tasks\User_Feed_Synchronization-{3EFA6DAE-30C1-432C-8C4A-0B64AB9C02F5}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 04:31]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\sup026\Application Data\Mozilla\Firefox\Profiles\4mt4b0dd.default\
FF - prefs.js: browser.search.selectedEngine - Umibozu search
FF - prefs.js: browser.startup.homepage - hxxp://www.premofine.com/
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-01 13:21:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(700)
c:\windows\system32\EntApi.dll
.
Completion time: 2009-04-01 13:23:04
ComboFix-quarantined-files.txt 2009-04-01 20:23:01

Pre-Run: 26,618,638,336 bytes free
Post-Run: 26,916,589,568 bytes free

225 --- E O F --- 2009-04-01 15:27:14

#8 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:08:56 AM

Posted 01 April 2009 - 03:37 PM

Excellent! :thumbup2: And just like I thought.....nasty old rootkit. :step4: How is it running now? :step1:

Try MBAM now and see if it will update and run. You may have to download it again. Post the report if it does go. :)

tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#9 stevepremo

stevepremo
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:56 AM

Posted 01 April 2009 - 04:11 PM

MBAM did update and run this time! I think that fixed it. Thank you so much!

Here's the MBAM log, followed by a fresh HJT log:

Malwarebytes' Anti-Malware 1.35
Database version: 1929
Windows 5.1.2600 Service Pack 3

2009-04-01 14:05:43
mbam-log-2009-04-01 (14-05-43).txt

Scan type: Quick Scan
Objects scanned: 94848
Time elapsed: 2 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

[end mbam log]

[begin HJT log]

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:06, on 2009-04-01
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PMService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\ePOAgent\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\explorer.exe
C:\ePOAgent\UpdaterUI.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\ePOAgent\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [EPA_EZ_GPO_Tool] C:\WINDOWS\system32\EZ_GPO_Tool.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ShoreTel Personal Call Manager] C:\Program Files\Shoreline Communications\ShoreWare Client\StartCli.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [WMC_WMPDBExport] C:\Program Files\Windows Media Player\wmdbexport.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [WMC_WMPDBExport] C:\Program Files\Windows Media Player\wmdbexport.exe (User 'Default user')
O4 - Global Startup: Refresh All Propalms TSE Shortcuts .lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase6662.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1229703002922
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = santacruzcourt.local
O17 - HKLM\Software\..\Telephony: DomainName = santacruzcourt.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = santacruzcourt.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = santacruzcourt.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = santacruzcourt.local
O23 - Service: Energy Star™ EZ GPO Power Management Configuration Tool (EPA_GPO_PMService) - TerraNovum - C:\WINDOWS\system32\PMService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\ePOAgent\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe

--
End of file - 5662 bytes

#10 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:08:56 AM

Posted 01 April 2009 - 04:19 PM

Great! :thumbup2: How is it running now please? :)
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#11 stevepremo

stevepremo
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:06:56 AM

Posted 01 April 2009 - 05:10 PM

It's running normally! Finally! Thank you so much! :thumbup2:

#12 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:08:56 AM

Posted 01 April 2009 - 05:18 PM

Hello,

You're welcome, and I'm glad. :thumbup2:

Please delete ComboFix and its accompanying folder C:\Qoobox. Empty your Recycle bin and reboot your computer.

If there are no further problems:

Below I have included a number of recommendations on how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously! These few simple steps can stave off the vast majority of spyware problems.

You should definitely maintain a firewall. Some good free firewalls are Kerio, or Outpost. I use Comodo on my own system and really like it. http://comodo.com
A tutorial on understanding and using firewalls may be found here.

Regularly go to http://windowsupdate.microsoft.com and download all the "critical updates" for Windows, including the latest version of Internet Explorer. This can patch many of the security holes through which attackers can gain access to your computer. You should also turn on the Windows automatic update feature.

In order to protect yourself against spyware, you should consider installing and running the following free programs:

SpywareBlaster
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.

SpywareGuard
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.

Spybot-Search & Destroy
A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

* Avoid illegal sites, because that's where most malware is present.
* Don't click on links inside popups.
* Don't click on links in spam messages claiming to offer anti-spyware software; because most of these so called removers ARE spyware.
* Download free software only from sites you know and trust. A lot of free software can bundle other software, including spyware.

Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
http://www.mozilla.org/products/firefox/

Please make sure to run your antivirus software regularly, and to keep it up-to-date.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

Take care!
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#13 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:08:56 AM

Posted 04 April 2009 - 06:32 AM

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users