Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Background changed


  • This topic is locked This topic is locked
2 replies to this topic

#1 ptknight-a

ptknight-a

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:08:54 PM

Posted 01 January 2010 - 06:40 PM

My sister's Nokia n81 was infected so I connected it to the PC and made a scan with ESET Smart Security. The infection was cleaned but when the mobile was connected to another PC the background changed and my computer icon changed to the unknown file type icon. I downloaded some anti-spyware programs and got rid of infection. I changed the background but my computer icon is still unknown. I noticed that after removing the infection there is a strange entry in startup " Startup item : u Command : C:\WINDOWS\system32\kxp.exe\u ". Also in network connections in ESET Smart Security I noticed that smss.exe is connected to the internet and when I block the connection all my network activity is dead I can't even access to my router page.

Thanks in advance


DDS (Ver_09-12-01.01) - FAT32x86
Run by Dr.Hamdy at 23:54:13.84 on Fri 01/01/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1256.20.1033.18.319.127 [GMT 2:00]

AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
SVCHOST.EXE
C:\WINDOWS\System32\svchost.exe -k netsvcs
SVCHOST.EXE
SVCHOST.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\CTSvcCDA.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\Symantec\WinFax\WFXMOD32.EXE
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Dr.Hamdy\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com.eg/
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {79848780-3218-4973-9c99-627926b6f4a4} - LaIe
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Foxit Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
mExplorerRun: [KM_Path2] %SystemRoot%\system32\usmt\check\files\smss.exe
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
mPolicies-system: SynchronousMachineGroupPolicy = 0 (0x0)
mPolicies-system: SynchronousUserGroupPolicy = 0 (0x0)
dPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
LSP: c:\windows\system32\idmmbc.dll
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} - hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1235674996206
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
TCP: {92E7766C-F33A-41E1-B001-84564742F107} = 208.67.222.222,208.67.220.220
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Notify: Antiwpa - antiwpa.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
SSODL: LmfZYMZvVZB - {D8BCDCF2-7216-7658-BC73-2284B5F4714B} - c:\windows\system32\xfgu.dll
SEH: WinFax PRO IShellExecuteHook: {a213b520-c6c2-11d0-af9d-008029e1027e} - c:\program files\symantec\winfax\WfxSeh32.Dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\drf49e~1.ham\applic~1\mozilla\firefox\profiles\fvus6h7d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.eg/webhp?rls=ig
FF - component: c:\documents and settings\dr.hamdy\application data\idm\idmmzcc3\components\idmmzcc.dll
FF - component: c:\program files\real\realplayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\dr.hamdy\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox 3.6 beta 5\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox 3.6 beta 5\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256]
R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2009-5-14 731840]
S3 CA561B;ICatch 561B PC CAMERA;c:\windows\system32\drivers\spca561b.sys [2009-7-23 241280]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-3 32512]
S3 ultradfg;ultradfg;c:\windows\system32\drivers\ultradfg.sys [2009-10-6 41984]

=============== Created Last 30 ================

2010-01-01 20:59:44 0 d-----w- c:\program files\Trend Micro
2010-01-01 20:25:36 0 d-----w- c:\program files\Mozilla Firefox 3.6 Beta 5
2010-01-01 17:52:22 1440054 ----a-w- c:\windows\system32\Figure.dll
2010-01-01 17:38:42 0 d-sh--w- C:\FOUND.031
2009-12-28 12:41:28 0 d-----w- c:\program files\Power Mp3 Cutter(Mp3 Sound Cutter)
2009-12-28 12:21:22 0 d-----w- c:\program files\Cooolsoft
2009-12-22 20:40:42 0 d-sh--w- C:\FOUND.030
2009-12-16 17:04:36 61388 ----a-w- C:\fraglist.luar
2009-12-15 22:28:56 0 d-----w- c:\docume~1\alluse~1\applic~1\GoBit Games
2009-12-15 00:37:14 0 d-sh--w- C:\FOUND.029
2009-12-14 21:54:39 55 ----a-w- c:\windows\wininit.ini
2009-12-14 10:16:41 35840 ---h--w- c:\documents and settings\dr.hamdy\jrcesvk.exe
2009-12-14 10:16:41 35840 ----a-w- c:\windows\system32\kxp.exe
2009-12-14 09:51:57 0 d-----w- c:\program files\PSLIDESHOW
2009-12-14 09:47:34 0 d-----w- c:\program files\Slideshow XL
2009-12-14 09:47:23 0 d-----w- c:\program files\mresreg
2009-12-14 09:00:47 0 d-----w- c:\program files\Flash Slideshow Maker Professional
2009-12-14 08:31:29 0 d-----w- c:\docume~1\drf49e~1.ham\applic~1\XnView
2009-12-13 14:11:48 0 d-sh--w- C:\FOUND.028
2009-12-05 12:24:13 50 ----a-w- c:\windows\MegaManager.INI

==================== Find3M ====================

2009-12-29 10:57:10 1632 ----a-w- c:\windows\system32\d3d8caps.dat
2009-12-25 12:52:16 1744 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-23 21:27:28 40960 ----a-w- c:\windows\system32\SSubTmr6.dll
2009-10-22 09:19:04 5939712 ----a-w- c:\windows\system32\dllcache\mshtml.dll
2009-10-20 13:55:28 90624 ----a-w- c:\windows\system32\wfxsvc.exe
2009-10-20 13:55:28 36352 ----a-w- c:\windows\system32\wfxsnt40.exe
2009-10-20 13:55:28 133120 ----a-w- c:\windows\system32\wfxmnt40.dll
2009-10-20 13:55:26 19968 ----a-w- c:\windows\wfuninst.exe
2009-10-20 13:55:16 74240 ----a-w- c:\windows\system32\dccmsp32.dll
2009-10-20 13:55:16 34816 ----a-w- c:\windows\system32\dccext32.dll
2009-10-20 13:55:16 20992 ----a-w- c:\windows\system32\dccwfp32.dll
2009-10-06 07:12:00 7680 ----a-w- c:\windows\system32\bootexctrl.exe
2009-10-06 07:12:00 28672 ----a-w- c:\windows\system32\udefrag-scheduler.exe
2009-10-06 07:12:00 10240 ----a-w- c:\windows\system32\defrag_native.exe
2009-10-06 07:11:58 47104 ----a-w- c:\windows\system32\ultradefrag.exe
2009-10-06 07:11:58 46592 ----a-w- c:\windows\system32\udefrag-gui-config.exe
2009-10-06 07:11:54 7680 ----a-w- c:\windows\system32\wgx.dll
2009-10-06 07:11:52 20992 ----a-w- c:\windows\system32\udefrag.exe
2009-10-06 07:11:52 14848 ----a-w- c:\windows\system32\lua5.1a_gui.exe
2009-10-06 07:11:52 10752 ----a-w- c:\windows\system32\lua5.1a.exe
2009-10-06 07:11:50 91648 ----a-w- c:\windows\system32\lua5.1a.dll
2009-10-06 07:11:46 9728 ----a-w- c:\windows\system32\udefrag.dll
2009-10-06 07:11:44 6144 ----a-w- c:\windows\system32\hibernate4win.exe
2009-10-06 07:11:44 21504 ----a-w- c:\windows\system32\zenwinx.dll
2009-10-05 04:44:22 299008 ----a-w- c:\windows\system32\Vital.dll
2006-09-16 14:20:10 3808 ----a-w- c:\program files\SETUP.LST
2006-09-16 14:20:10 1880140 ----a-w- c:\program files\Anti NetCut.CAB
1998-06-17 22:00:00 140800 ----a-w- c:\program files\setup.exe

============= FINISH: 23:54:53.78 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 ptknight-a

ptknight-a
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:08:54 PM

Posted 09 January 2010 - 08:55 AM

I solved the problem with hijackthis tool

#3 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,591 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:08:54 PM

Posted 09 January 2010 - 10:10 AM

Since this issue seems to be resolved, this topic will be closed.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft

 

animinionsmalltext.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users