Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

infected with RON Too1 Gooochi


  • This topic is locked This topic is locked
13 replies to this topic

#1 ridin2high

ridin2high

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:03 PM

Posted 23 January 2010 - 03:49 AM

I don't know how to remove this program or whatever it is. it appears in my add or remove programs list and there seems to be other programs that i am concerned about. but that might just be me being paranoid.


DDS (Ver_09-12-01.01) - NTFSx86
Run by Seth at 1:23:20.63 on Sat 01/23/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.341 [GMT -7:00]

AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {00000000-0000-0000-0000-000000000000}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {806ED0B3-FFA4-00C8-0D24-347CA8A3377C}
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {806ED0B3-FFA4-00EB-0D24-347CA8A3377C}

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\System32\svchost.exe -k Akamai
svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\WINDOWS\System32\regsvr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Seth\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: MessengerUpdate Class: {5948a52a-ba3a-49a8-bcaf-d578502bda9d} - c:\documents and settings\seth\application data\messenger\drivers\MsgUpdate.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: gooochi browser enhancer: {f0160775-7b11-3435-fc12-6b7667e54d27} - c:\windows\system32\lbdvpxezrd.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [IgfxSys] rundll32.exe "c:\documents and settings\seth\application data\messenger\drivers\IgfxSys.dll",StartProtector
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
mRun: [ezLife] 0 (0x0)
mRun: [ezyutewifezekzegr] c:\windows\system32\regsvr32.exe /s "c:\windows\system32\lbdvpxezrd.dll"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\seth\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe
StartupFolder: c:\docume~1\seth\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154587711345
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258148382551
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\seth\applic~1\mozilla\firefox\profiles\6koigl2b.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\seth\application data\mozilla\firefox\profiles\6koigl2b.default\extensions\flashplugin@idm\platform\winnt\plugins\npidmdcp.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2003-7-16 14336]
R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\drivers\ozscr.sys [2006-8-3 92550]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-15 135664]

=============== Created Last 30 ================

2010-01-17 03:08:03 108144 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-01-17 02:46:18 0 d-----w- c:\program files\EA GAMES
2010-01-12 23:39:00 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-11 06:39:10 0 d-----w- c:\documents and settings\seth\.idlerc
2010-01-09 20:20:37 0 ----a-w- c:\documents and settings\seth\jagex_runescape_preferences.dat
2010-01-09 20:18:15 0 d-----w- c:\windows\.jagex_cache_32
2010-01-09 20:09:08 0 d-----w- c:\program files\common files\Akamai
2010-01-09 06:10:45 0 d-----w- C:\Python26
2010-01-09 06:03:05 0 d-----w- c:\docume~1\seth\applic~1\Blender Foundation
2010-01-02 00:40:47 0 d-----w- c:\program files\Full Tilt Poker.Net
2009-12-31 05:36:58 0 d-----w- c:\docume~1\seth\applic~1\ezLife
2009-12-31 05:36:57 0 d-----w- c:\docume~1\seth\applic~1\Smart-Ads-Solutions
2009-12-31 05:36:55 48285 ----a-w- c:\windows\system32\ekkmyubvngr.exe
2009-12-31 05:36:51 0 d-----w- c:\docume~1\seth\applic~1\Messenger
2009-12-31 05:36:50 0 d-----w- c:\program files\ezLife
2009-12-31 05:36:49 0 d-----w- c:\program files\Smart-Ads-Solutions
2009-12-31 04:39:20 0 d-----w- c:\docume~1\seth\applic~1\Inkscape
2009-12-31 04:38:27 0 d-sh--w- c:\documents and settings\seth\PrivacIE
2009-12-31 04:34:43 0 d-----w- c:\program files\Inkscape
2009-12-30 19:44:31 0 d-----w- c:\docume~1\seth\applic~1\LimeWire
2009-12-30 19:43:59 0 d-----w- c:\program files\LimeWire
2009-12-30 07:01:28 0 d-----w- C:\Perfect World Entertainment
2009-12-30 06:53:55 258352 ----a-w- c:\windows\system32\unicows.dll
2009-12-29 23:58:19 0 d-----w- c:\docume~1\seth\applic~1\GetRightToGo
2009-12-29 04:35:19 52224 ----a-w- c:\windows\ipuninst.exe
2009-12-29 04:31:32 0 d-----w- c:\program files\Interplay
2009-12-28 07:45:52 0 d-----w- c:\docume~1\seth\applic~1\OpenOffice.org
2009-12-28 05:44:17 442368 ----a-r- c:\windows\system32\vp6vfw.dll
2009-12-27 06:18:52 0 d-----w- c:\program files\Delphine Software
2009-12-25 00:51:03 285 ----a-w- c:\windows\EReg072.dat
2009-12-25 00:48:20 0 d-----w- c:\program files\SimTheme Park
2009-12-25 00:46:50 305152 ----a-w- c:\windows\IsUninst.exe
2009-12-24 15:26:40 299520 ----a-w- c:\windows\uninst.exe

==================== Find3M ====================

2010-01-14 18:12:06 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-08 15:01:36 494080 ----a-w- c:\windows\system32\lbdvpxezrd.dll
2009-12-24 07:07:46 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-12-23 01:07:58 301056 ----a-w- c:\windows\system32\sgymzbeq.dll
2009-12-23 01:07:40 319488 ----a-w- c:\windows\system32\vykigdsa.dll
2009-12-21 19:14:05 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-26 15:24:30 2149888 ----a-w- c:\windows\system32\python26.dll
2008-10-14 20:24:08 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008101420081015\index.dat

============= FINISH: 1:24:14.92 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:03 PM

Posted 29 January 2010 - 02:23 PM

Hi,

My name is Extremeboy (or EB for short), and I will be helping you with your log.

We apologize for the delay of response.

Do you still require help?

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a RootRepeal log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or RootRepeal log please refer to this page and in step #6 and Step #7 for further instructions on downloading and running DDS & RootRepeal. If you have any problems when running the tools or unable to produce a report for any reason, just let me know in your next reply.


For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-RootRepeal logs
-Description of any remaining problems you may still have.


Thanks again and we apologize for the delay.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:03 PM

Posted 01 February 2010 - 12:37 PM

Hello.

Are you still there? Do you still require help?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 5-7 from the last day I replied initially, the topic will need to be closed.

Thanks for understanding.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#4 ridin2high

ridin2high
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:03 PM

Posted 01 February 2010 - 07:19 PM


DDS (Ver_09-12-01.01) - NTFSx86
Run by Seth at 17:14:18.25 on Mon 02/01/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.336 [GMT -7:00]

AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {00000000-0000-0000-0000-000000000000}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {806ED0B3-FFA4-00C8-0D24-347CA8A3377C}
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {806ED0B3-FFA4-00EB-0D24-347CA8A3377C}

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\WINDOWS\System32\regsvr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
svchost.exe
C:\WINDOWS\System32\svchost.exe -k Akamai
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Seth\My Documents\Downloads\dds(2).scr

============== Pseudo HJT Report ===============

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: PlaySushi: {21608b66-026f-4dcb-9244-0daca328dced} - c:\program files\playsushi\PSText.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: MessengerUpdate Class: {5948a52a-ba3a-49a8-bcaf-d578502bda9d} - c:\documents and settings\seth\application data\messenger\drivers\MsgUpdate.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: gooochi browser enhancer: {f0160775-7b11-3435-fc12-6b7667e54d27} - c:\windows\system32\lbdvpxezrd.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [IgfxSys] rundll32.exe "c:\documents and settings\seth\application data\messenger\drivers\IgfxSys.dll",StartProtector
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
mRun: [ezLife] 0 (0x0)
mRun: [ezyutewifezekzegr] c:\windows\system32\regsvr32.exe /s "c:\windows\system32\lbdvpxezrd.dll"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\seth\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe
StartupFolder: c:\docume~1\seth\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
IE: {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - c:\program files\playsushi\PSText.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154587711345
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258148382551
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\seth\applic~1\mozilla\firefox\profiles\6koigl2b.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\seth\application data\mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@playsushi.com\components\PlaySushiFF.dll
FF - plugin: c:\documents and settings\seth\application data\mozilla\firefox\profiles\6koigl2b.default\extensions\flashplugin@idm\platform\winnt\plugins\npidmdcp.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2003-7-16 14336]
R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\drivers\ozscr.sys [2006-8-3 92550]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-15 135664]

=============== Created Last 30 ================

2010-01-29 23:47:46 0 d-----w- C:\2bc82c12fbe012ccbceff2d7
2010-01-29 02:27:41 0 d-----w- c:\program files\PlaySushi
2010-01-28 01:35:22 69 ----a-w- c:\documents and settings\seth\jagex_runescape_preferences2.dat
2010-01-25 02:33:54 82908 ----a-w- c:\documents and settings\seth\New document 1.2010_01_24_19_33_54.0
2010-01-17 03:08:03 108144 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-01-17 02:46:18 0 d-----w- c:\program files\EA GAMES
2010-01-12 23:39:00 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-11 06:39:10 0 d-----w- c:\documents and settings\seth\.idlerc
2010-01-09 20:20:37 39 ----a-w- c:\documents and settings\seth\jagex_runescape_preferences.dat
2010-01-09 20:18:15 0 d-----w- c:\windows\.jagex_cache_32
2010-01-09 20:09:08 0 d-----w- c:\program files\common files\Akamai
2010-01-09 06:10:45 0 d-----w- C:\Python26
2010-01-09 06:03:05 0 d-----w- c:\docume~1\seth\applic~1\Blender Foundation

==================== Find3M ====================

2010-01-17 20:12:57 48285 ----a-w- c:\windows\system32\ekkmyubvngr.exe
2010-01-14 18:12:06 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-08 15:01:36 494080 ----a-w- c:\windows\system32\lbdvpxezrd.dll
2009-12-30 06:53:41 258352 ----a-w- c:\windows\system32\unicows.dll
2009-12-29 04:35:19 52224 ----a-w- c:\windows\ipuninst.exe
2009-12-24 07:07:46 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-12-23 01:07:58 301056 ----a-w- c:\windows\system32\sgymzbeq.dll
2009-12-23 01:07:40 319488 ----a-w- c:\windows\system32\vykigdsa.dll
2009-12-21 19:14:05 916480 ----a-w- c:\windows\system32\wininet.dll
2008-10-14 20:24:08 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008101420081015\index.dat

============= FINISH: 17:14:44.52 ===============


Infected with RON Too1 gooochi

Attached Files



#5 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:03 PM

Posted 01 February 2010 - 08:28 PM

Hello.

Let's start with Combofix.

Download and Run Combofix

Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page on instructions on doing so.

Please include the C:\ComboFix.txt in your next reply for further review.

Note: When Combofix warns you that you have Avira enabled, please ignore it as you don't have it. It's just the WMI that wasn't de-registered when you uninstalled it probably.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#6 ridin2high

ridin2high
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:03 PM

Posted 02 February 2010 - 12:44 AM

ComboFix 10-02-01.02 - Seth 02/01/2010 22:33:09.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.609 [GMT -7:00]
Running from: c:\documents and settings\Seth\My Documents\Downloads\ComboFix.exe
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {00000000-0000-0000-0000-000000000000}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {806ED0B3-FFA4-00C8-0D24-347CA8A3377C}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {806ED0B3-FFA4-00EB-0D24-347CA8A3377C}
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Seth\Application Data\ezLife
c:\documents and settings\Seth\Application Data\Messenger
c:\documents and settings\Seth\Application Data\Messenger\Drivers\Aud32\go282.exe
c:\documents and settings\Seth\Application Data\Messenger\Drivers\Aud32\go29.exe
c:\documents and settings\Seth\Application Data\Messenger\Drivers\Aud32\go30.exe
c:\documents and settings\Seth\Application Data\Messenger\Drivers\Aud32\msgasst841.dll
c:\documents and settings\Seth\Application Data\Messenger\Drivers\Aud32\msgutil84.dll
c:\documents and settings\Seth\Application Data\Messenger\Drivers\Aud32\smartasf27.exe
c:\documents and settings\Seth\Application Data\Messenger\Drivers\Aud32\zbc20.exe
c:\documents and settings\Seth\Application Data\Messenger\Drivers\conf.sys
c:\documents and settings\Seth\Application Data\Messenger\Drivers\IgfxSys.dll
c:\documents and settings\Seth\Application Data\Messenger\Drivers\MsgUpdate.dll
c:\documents and settings\Seth\Application Data\Messenger\Drivers\phuninst.dll
c:\documents and settings\Seth\Application Data\Messenger\Drivers\pub.dll
c:\documents and settings\Seth\Application Data\Messenger\Drivers\serial.sys
c:\documents and settings\Seth\Application Data\Messenger\Sys\mu.dll
c:\documents and settings\Seth\Application Data\Smart-Ads-Solutions
c:\program files\ezLife
c:\program files\PlaySushi\PSTExt.dll
c:\program files\Smart-Ads-Solutions
c:\program files\Smart-Ads-Solutions\SmartAds\1.2.0.0\uninstall.exe
c:\windows\system32\smkkbcmw.dll
c:\windows\system32\vykigdsa.dll

.
((((((((((((((((((((((((( Files Created from 2010-01-02 to 2010-02-02 )))))))))))))))))))))))))))))))
.

2010-02-02 05:17 . 2010-02-02 05:17 -------- d-----w- c:\documents and settings\All Users\Application Data\OptiTex
2010-02-02 05:11 . 2010-02-02 05:11 -------- d-----w- c:\documents and settings\Seth\Application Data\DAZ 3D
2010-02-02 05:11 . 2010-02-02 05:11 -------- d-----w- c:\program files\Common Files\DAZ
2010-01-29 23:47 . 2010-01-29 23:47 -------- d-----w- C:\2bc82c12fbe012ccbceff2d7
2010-01-29 09:44 . 2010-01-29 09:44 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-29 09:43 . 2010-01-29 09:43 -------- d-----w- c:\documents and settings\Seth\Local Settings\Application Data\Threat Expert
2010-01-29 09:24 . 2010-01-29 09:24 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-01-29 08:58 . 2010-01-29 11:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-29 04:21 . 2010-01-29 04:21 -------- d-----w- c:\documents and settings\Seth\Local Settings\Application Data\FullTiltPoker
2010-01-29 02:27 . 2010-02-02 05:36 -------- d-----w- c:\program files\PlaySushi
2010-01-28 01:35 . 2010-01-29 00:31 69 ----a-w- c:\documents and settings\Seth\jagex_runescape_preferences2.dat
2010-01-17 03:08 . 2010-01-17 03:08 -------- d--h--r- c:\documents and settings\Seth\Application Data\SecuROM
2010-01-17 03:08 . 2010-01-17 03:08 108144 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-01-17 02:46 . 2010-01-17 02:46 -------- d-----w- c:\program files\EA GAMES
2010-01-15 19:49 . 2010-01-15 19:49 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-01-15 19:44 . 2010-02-02 02:51 -------- d-----w- c:\documents and settings\Seth\Local Settings\Application Data\Temp
2010-01-15 19:44 . 2010-01-15 19:44 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-01-15 19:44 . 2010-01-23 19:49 -------- d-----w- c:\documents and settings\Seth\Local Settings\Application Data\Google
2010-01-15 19:44 . 2010-01-15 19:49 -------- d-----w- c:\program files\Google
2010-01-12 23:39 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-11 21:18 . 2010-01-11 21:18 188928 ----a-w- c:\documents and settings\Seth\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@playsushi.com\components\PlaySushiFF.dll
2010-01-11 06:39 . 2010-01-11 06:39 -------- d-----w- c:\documents and settings\Seth\.idlerc
2010-01-09 20:20 . 2010-01-29 01:38 39 ----a-w- c:\documents and settings\Seth\jagex_runescape_preferences.dat
2010-01-09 20:18 . 2010-01-09 20:18 -------- d-----w- c:\windows\.jagex_cache_32
2010-01-09 20:09 . 2010-02-02 05:06 -------- d-----w- c:\program files\Common Files\Akamai
2010-01-09 06:10 . 2010-01-09 06:11 -------- d-----w- C:\Python26
2010-01-09 06:03 . 2010-01-09 06:03 -------- d-----w- c:\documents and settings\Seth\Application Data\Blender Foundation
2010-01-07 01:24 . 2010-01-07 01:24 319488 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{FC3E4EA2-C62B-E57E-285B-D2A82E5D7AFF}-vykigdsa.dll
2010-01-07 01:24 . 2010-01-07 01:24 319488 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{D74ADF4C-2865-5ADA-37C9-0AA0720C1DFB}-vykigdsa.dll
2010-01-03 05:44 . 2010-01-03 05:44 319488 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{5DA0DE07-428C-66EF-4677-34E824899DD7}-vykigdsa.dll
2010-01-03 05:44 . 2010-01-03 05:44 319488 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{1177C74F-0950-D92F-D7D1-E833A49961B1}-vykigdsa.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-02 04:09 . 2009-12-30 19:44 -------- d-----w- c:\documents and settings\Seth\Application Data\LimeWire
2010-02-02 00:01 . 2010-01-02 00:40 -------- d-----w- c:\program files\Full Tilt Poker.Net
2010-01-29 07:25 . 2009-12-28 07:46 1 ----a-w- c:\documents and settings\Seth\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-01-17 20:12 . 2009-12-31 05:36 48285 ----a-w- c:\windows\system32\ekkmyubvngr.exe
2010-01-14 18:12 . 2009-11-13 21:36 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-08 15:01 . 2009-12-13 14:21 494080 ----a-w- c:\windows\system32\lbdvpxezrd.dll
2010-01-03 04:36 . 2010-01-03 04:36 319488 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{AB58BE58-A23B-E108-2E59-DF821B9908EF}-vykigdsa.dll
2009-12-31 04:39 . 2009-12-31 04:39 -------- d-----w- c:\documents and settings\Seth\Application Data\Inkscape
2009-12-31 04:38 . 2009-12-31 04:34 -------- d-----w- c:\program files\Inkscape
2009-12-30 19:44 . 2009-12-30 19:44 225280 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\components\pipnss.dll
2009-12-30 19:44 . 2009-12-30 19:44 20992 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\components\pipboot.dll
2009-12-30 19:44 . 2009-12-30 19:44 19968 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\components\pippki.dll
2009-12-30 19:44 . 2009-12-30 19:44 8192 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\AccessibleMarshal.dll
2009-12-30 19:44 . 2009-12-30 19:44 20480 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\IA2Marshal.dll
2009-12-30 19:44 . 2009-12-30 19:44 20480 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\components\autoconfig.dll
2009-12-30 19:44 . 2009-12-30 19:44 18944 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.dll
2009-12-30 19:44 . 2009-12-30 19:44 17408 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\components\auth.dll
2009-12-30 19:44 . 2009-12-30 19:43 -------- d-----w- c:\program files\LimeWire
2009-12-30 06:53 . 2009-12-29 23:58 -------- d-----w- c:\documents and settings\Seth\Application Data\GetRightToGo
2009-12-30 06:53 . 2009-12-30 06:53 258352 ----a-w- c:\windows\system32\unicows.dll
2009-12-29 04:35 . 2009-12-29 04:35 52224 ----a-w- c:\windows\ipuninst.exe
2009-12-29 04:31 . 2009-12-29 04:31 -------- d-----w- c:\program files\Interplay
2009-12-28 07:45 . 2009-12-28 07:45 -------- d-----w- c:\documents and settings\Seth\Application Data\OpenOffice.org
2009-12-28 00:01 . 2009-12-28 00:01 18864 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-27 23:47 . 2009-12-27 23:47 18864 ----a-w- c:\documents and settings\Seth\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-27 06:18 . 2009-12-27 06:18 -------- d-----w- c:\program files\Delphine Software
2009-12-25 01:05 . 2009-12-25 00:48 -------- d-----w- c:\program files\SimTheme Park
2009-12-25 00:51 . 2009-12-25 00:51 285 ----a-w- c:\windows\EReg072.dat
2009-12-24 15:28 . 2009-12-24 06:43 -------- d-----w- c:\program files\LucasArts
2009-12-24 07:07 . 2009-12-24 07:07 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-12-24 06:43 . 2006-08-03 08:01 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-23 01:07 . 2009-12-23 01:07 301056 ----a-w- c:\windows\system32\sgymzbeq.dll
2009-12-21 19:14 . 2006-04-28 17:58 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 15:51 . 2003-07-16 16:17 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0160775-7B11-3435-FC12-6B7667E54D27}]
2010-01-08 15:01 494080 ----a-w- c:\windows\system32\lbdvpxezrd.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-14 1048392]
"ezyutewifezekzegr"="c:\windows\system32\lbdvpxezrd.dll" [2010-01-08 494080]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\Seth\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-12-16 503808]
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-11-11 04:05 344064 -c--a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2005-12-19 16:08 1347584 -c--a-w- c:\windows\system32\WLTRAY.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=

R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [7/16/2003 9:41 AM 14336]
R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\drivers\ozscr.sys [8/3/2006 1:06 AM 92550]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/15/2010 12:44 PM 135664]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - ROOTREPEAL2
*Deregistered* - rootrepeal2

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder

2010-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-15 19:44]

2010-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-15 19:44]

2010-01-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-07-03 00:36]
.
.
------- Supplementary Scan -------
.
IE: {{EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - c:\program files\PlaySushi\PSText.dll
FF - ProfilePath - c:\documents and settings\Seth\Application Data\Mozilla\Firefox\Profiles\6koigl2b.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\Seth\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@playsushi.com\components\PlaySushiFF.dll
FF - plugin: c:\documents and settings\Seth\Application Data\Mozilla\Firefox\Profiles\6koigl2b.default\extensions\flashplugin@idm\platform\WINNT\plugins\npidmdcp.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

BHO-{5948A52A-BA3A-49A8-BCAF-D578502BDA9D} - c:\documents and settings\Seth\Application Data\Messenger\Drivers\MsgUpdate.dll
HKCU-Run-IgfxSys - c:\documents and settings\Seth\Application Data\Messenger\Drivers\IgfxSys.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-01 22:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(928)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-02-01 22:39:40
ComboFix-quarantined-files.txt 2010-02-02 05:39

Pre-Run: 14,665,908,224 bytes free
Post-Run: 14,987,599,872 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 97D5B8AC52545CECC43B3AB4382AB935


#7 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:03 PM

Posted 02 February 2010 - 04:09 PM

Hello.

I suggest you uninstall: Full Tilt Poker.Net <- It's bundled with malware/adware.

I also suggest you uninstall limewire.

Your log shows that you are using so called peer-to-peer or file-sharing programs (in your case UTorrent). These programs allow to share files between users as the name(s) suggest. In today's world cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. Some further readings on this subject, along the included links, are as follows: File-Sharing, otherwise known as Peer To Peer and Risks of File-Sharing Technology.

It is also important to note that sharing entertainment files and proprietary software infringes the copyright laws in many countries over the world and you are putting yourself at risk of being indicted through organizations watching over the rights of the authors of such files (i.e. the RIAA for music files, or the MPAA for movie files in the USA) or the authors of the files themselves.

Naturally there are also legal ways to use these services, such as downloading Linux distributions or office suites such as "Open Office."

---
Not all poker games are considered "bad", but most are. With that said many of them are bundled with spyware and other nasties that can steal passwords and etc... Even if it is considered "good" you are going to websites that you might not necessarily trust and hosted by someone else for you to join. I do not know how those programs work so I will not criticize what they do and if they are bad or not.

I know that you may use these (this) game(s) on a regular basis but I think it's important to note that often these kind of programmes are installed with other unwanted software, namely spyware or adware.

Some of them are fine to have, but if you didn't intensionally installed it or to play it, it is best to remove them.


Run ComboFix with CFScript

We will run ComboFix again. This time it will be slightly different from the initial run.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are unsure how.
  • Open notepad (Start>Run>"notepad") and copy/paste the text in the quotebox below into it:
    CODE
    http://www.bleepingcomputer.com/forums/t/289560/infected-with-ron-too1-gooochi/
    Collect::[68]
    c:\windows\system32\ekkmyubvngr.exe
    c:\windows\system32\lbdvpxezrd.dll
    c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{1177C74F-0950-D92F-D7D1-E833A49961B1}-vykigdsa.dll
    c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{5DA0DE07-428C-66EF-4677-34E824899DD7}-vykigdsa.dll
    c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{D74ADF4C-2865-5ADA-37C9-0AA0720C1DFB}-vykigdsa.dll
    c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{FC3E4EA2-C62B-E57E-285B-D2A82E5D7AFF}-vykigdsa.dll
    c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{AB58BE58-A23B-E108-2E59-DF821B9908EF}-vykigdsa.dll
    c:\windows\system32\sgymzbeq.dll
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ezyutewifezekzegr"=-
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0160775-7B11-3435-FC12-6B7667E54D27}]
    Save this as CFScript.txt, in the same location as ComboFix.exe. (This should be your desktop.)
  • Refering to the picture above, drag CFScript into ComboFix.exe.
  • When finished, it shall produce a log for you at "C:\ComboFix.txt"
  • Please post the contents of the Combofix log in your next reply.
Upload Samples by ComboFix

When Combofix finishes running, the ComboFix log will open along with a message box. With the above script, ComboFix captured some files to submit for analysis.
  • Important: Ensure you are connected to the internet before clicking OK on the message box.
  • A blue-screen would appear auto-uploading the zipped file I requested.
  • After the uploading is done you should see a message near the bottom saying "Upload was Succesfull".
**NOTE**
=================
  • IF for some reason Combofix fails to upload anything please do the following:
  • Go to Start >> My Computer > C:\
  • Then Navigate to the C:\Qoobox\Quarantine folder.
  • Find the archive zip file called "[68]-Submit_Date_Time.zip"
  • Simply go to This Channel and upload the submit.zip archive file to me.
  • Follow the instructions on that page to copy/paste/send the requested file.
Let me know how it goes and if the upload went successfully or not in your next reply.

Poker related programs usually are bundled with malware and other nasties as described above. The best option would to remove them via Add/Remove if it is still there.

Install Antivirus

An anti-virus is essential in keeping your computer safe while surfing the Internet. Please install a (ONE) free anti-virus program from one of the links below:Update It after the installation is complete please.

Download and run MalwareBytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link

With Regards,
Extremeboy

Edited by extremeboy, 02 February 2010 - 04:10 PM.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#8 ridin2high

ridin2high
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:03 PM

Posted 03 February 2010 - 08:11 AM

Everything went ok with the ComboFix. I decided to remove limewire but kept the full tilt poker.net because it is a trusted site. i think that's everything. oh and i put the MBAM log as an attachment if that's not acceptable just let me know. thanks for all the help.


ComboFix 10-02-02.04 - Seth 02/03/2010 5:11.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.721 [GMT -7:00]
Running from: c:\documents and settings\Seth\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Seth\Desktop\CFScript.txt
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {00000000-0000-0000-0000-000000000000}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {806ED0B3-FFA4-00C8-0D24-347CA8A3377C}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {806ED0B3-FFA4-00EB-0D24-347CA8A3377C}
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

file zipped: c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{D74ADF4C-2865-5ADA-37C9-0AA0720C1DFB}-vykigdsa.dll
file zipped: c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{FC3E4EA2-C62B-E57E-285B-D2A82E5D7AFF}-vykigdsa.dll
file zipped: c:\windows\system32\ekkmyubvngr.exe
file zipped: c:\windows\system32\lbdvpxezrd.dll
file zipped: c:\windows\system32\sgymzbeq.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{D74ADF4C-2865-5ADA-37C9-0AA0720C1DFB}-vykigdsa.dll
c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{FC3E4EA2-C62B-E57E-285B-D2A82E5D7AFF}-vykigdsa.dll
c:\windows\system32\ekkmyubvngr.exe
c:\windows\system32\lbdvpxezrd.dll
c:\windows\system32\sgymzbeq.dll

.
((((((((((((((((((((((((( Files Created from 2010-01-03 to 2010-02-03 )))))))))))))))))))))))))))))))
.

2010-02-02 08:41 . 2010-02-03 11:28 -------- d-----w- c:\program files\PokerStars.NET
2010-02-02 06:22 . 2004-03-30 00:23 90112 ----a-w- c:\windows\unvise32.exe
2010-02-02 06:19 . 2010-02-02 06:19 -------- d-----w- c:\program files\DAZ
2010-02-02 05:17 . 2010-02-02 05:17 -------- d-----w- c:\documents and settings\All Users\Application Data\OptiTex
2010-02-02 05:11 . 2010-02-02 05:11 -------- d-----w- c:\documents and settings\Seth\Application Data\DAZ 3D
2010-02-02 05:11 . 2010-02-02 06:23 -------- d-----w- c:\program files\Common Files\DAZ
2010-01-29 23:47 . 2010-01-29 23:47 -------- d-----w- C:\2bc82c12fbe012ccbceff2d7
2010-01-29 09:44 . 2010-01-29 09:44 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-29 09:43 . 2010-01-29 09:43 -------- d-----w- c:\documents and settings\Seth\Local Settings\Application Data\Threat Expert
2010-01-29 09:24 . 2010-01-29 09:24 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-01-29 08:58 . 2010-01-29 11:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-29 04:21 . 2010-01-29 04:21 -------- d-----w- c:\documents and settings\Seth\Local Settings\Application Data\FullTiltPoker
2010-01-29 02:27 . 2010-02-02 05:36 -------- d-----w- c:\program files\PlaySushi
2010-01-28 01:35 . 2010-01-29 00:31 69 ----a-w- c:\documents and settings\Seth\jagex_runescape_preferences2.dat
2010-01-17 03:08 . 2010-01-17 03:08 -------- d--h--r- c:\documents and settings\Seth\Application Data\SecuROM
2010-01-17 03:08 . 2010-01-17 03:08 108144 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-01-17 02:46 . 2010-01-17 02:46 -------- d-----w- c:\program files\EA GAMES
2010-01-15 19:49 . 2010-01-15 19:49 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-01-15 19:44 . 2010-02-02 02:51 -------- d-----w- c:\documents and settings\Seth\Local Settings\Application Data\Temp
2010-01-15 19:44 . 2010-01-15 19:44 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-01-15 19:44 . 2010-01-23 19:49 -------- d-----w- c:\documents and settings\Seth\Local Settings\Application Data\Google
2010-01-15 19:44 . 2010-01-15 19:49 -------- d-----w- c:\program files\Google
2010-01-12 23:39 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-11 21:18 . 2010-01-11 21:18 188928 ----a-w- c:\documents and settings\Seth\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@playsushi.com\components\PlaySushiFF.dll
2010-01-11 06:39 . 2010-01-11 06:39 -------- d-----w- c:\documents and settings\Seth\.idlerc
2010-01-09 20:20 . 2010-01-29 01:38 39 ----a-w- c:\documents and settings\Seth\jagex_runescape_preferences.dat
2010-01-09 20:18 . 2010-01-09 20:18 -------- d-----w- c:\windows\.jagex_cache_32
2010-01-09 20:09 . 2010-02-03 12:07 -------- d-----w- c:\program files\Common Files\Akamai
2010-01-09 06:10 . 2010-01-09 06:11 -------- d-----w- C:\Python26
2010-01-09 06:03 . 2010-01-09 06:03 -------- d-----w- c:\documents and settings\Seth\Application Data\Blender Foundation

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-03 11:35 . 2009-12-30 19:44 -------- d-----w- c:\documents and settings\Seth\Application Data\LimeWire
2010-02-03 09:55 . 2010-01-02 00:40 -------- d-----w- c:\program files\Full Tilt Poker.Net
2010-01-29 07:25 . 2009-12-28 07:46 1 ----a-w- c:\documents and settings\Seth\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-01-14 18:12 . 2009-11-13 21:36 181120 ------w- c:\windows\system32\MpSigStub.exe
2009-12-31 04:39 . 2009-12-31 04:39 -------- d-----w- c:\documents and settings\Seth\Application Data\Inkscape
2009-12-31 04:38 . 2009-12-31 04:34 -------- d-----w- c:\program files\Inkscape
2009-12-30 19:44 . 2009-12-30 19:44 225280 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\components\pipnss.dll
2009-12-30 19:44 . 2009-12-30 19:44 20992 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\components\pipboot.dll
2009-12-30 19:44 . 2009-12-30 19:44 19968 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\components\pippki.dll
2009-12-30 19:44 . 2009-12-30 19:44 8192 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\AccessibleMarshal.dll
2009-12-30 19:44 . 2009-12-30 19:44 20480 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\IA2Marshal.dll
2009-12-30 19:44 . 2009-12-30 19:44 20480 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\components\autoconfig.dll
2009-12-30 19:44 . 2009-12-30 19:44 18944 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\components\appshell_modal.dll
2009-12-30 19:44 . 2009-12-30 19:44 17408 ----a-w- c:\documents and settings\Seth\Application Data\LimeWire\browser\xulrunner\components\auth.dll
2009-12-30 06:53 . 2009-12-29 23:58 -------- d-----w- c:\documents and settings\Seth\Application Data\GetRightToGo
2009-12-30 06:53 . 2009-12-30 06:53 258352 ----a-w- c:\windows\system32\unicows.dll
2009-12-29 04:35 . 2009-12-29 04:35 52224 ----a-w- c:\windows\ipuninst.exe
2009-12-29 04:31 . 2009-12-29 04:31 -------- d-----w- c:\program files\Interplay
2009-12-28 07:45 . 2009-12-28 07:45 -------- d-----w- c:\documents and settings\Seth\Application Data\OpenOffice.org
2009-12-28 00:01 . 2009-12-28 00:01 18864 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-27 23:47 . 2009-12-27 23:47 18864 ----a-w- c:\documents and settings\Seth\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-27 06:18 . 2009-12-27 06:18 -------- d-----w- c:\program files\Delphine Software
2009-12-25 01:05 . 2009-12-25 00:48 -------- d-----w- c:\program files\SimTheme Park
2009-12-25 00:51 . 2009-12-25 00:51 285 ----a-w- c:\windows\EReg072.dat
2009-12-24 15:28 . 2009-12-24 06:43 -------- d-----w- c:\program files\LucasArts
2009-12-24 07:07 . 2009-12-24 07:07 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-12-24 06:43 . 2006-08-03 08:01 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-21 15:51 . 2003-07-16 16:17 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-02-02_05.37.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-03 12:06 . 2010-02-03 12:06 16384 c:\windows\Temp\Perflib_Perfdata_7f0.dat
+ 2010-02-03 12:06 . 2010-02-03 12:06 16384 c:\windows\Temp\Perflib_Perfdata_6f8.dat
+ 2003-07-16 16:35 . 2008-10-16 20:38 44544 c:\windows\system32\pngfilt.dll
- 2003-07-16 16:30 . 2009-03-08 10:31 48128 c:\windows\system32\mshtmler.dll
+ 2003-07-16 16:30 . 2006-10-17 18:28 48128 c:\windows\system32\mshtmler.dll
+ 2003-07-16 16:30 . 2006-10-17 18:56 45568 c:\windows\system32\mshta.exe
- 2003-07-16 16:30 . 2009-03-08 10:31 45568 c:\windows\system32\mshta.exe
+ 2006-10-17 18:58 . 2006-10-17 18:58 12288 c:\windows\system32\msfeedssync.exe
+ 2006-11-08 04:03 . 2008-10-16 20:38 52224 c:\windows\system32\msfeedsbs.dll
+ 2003-07-16 16:26 . 2006-10-17 19:05 40960 c:\windows\system32\licmgr10.dll
+ 2003-07-16 16:25 . 2008-10-16 20:38 27648 c:\windows\system32\jsproxy.dll
+ 2003-07-16 16:24 . 2006-11-07 10:26 92672 c:\windows\system32\inseng.dll
+ 2003-07-16 16:24 . 2006-10-17 18:57 36352 c:\windows\system32\imgutil.dll
+ 2003-07-16 16:24 . 2006-11-07 10:26 55296 c:\windows\system32\iesetup.dll
+ 2003-07-16 16:24 . 2008-10-16 20:38 44544 c:\windows\system32\iernonce.dll
+ 2009-04-29 04:55 . 2008-04-14 11:41 81920 c:\windows\system32\ieencode.dll
+ 2003-07-16 16:24 . 2008-10-16 13:11 70656 c:\windows\system32\ie4uinit.exe
+ 2006-10-17 18:58 . 2008-10-16 20:38 63488 c:\windows\system32\icardie.dll
+ 2006-05-10 05:23 . 2008-10-16 20:38 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2003-07-16 16:30 . 2006-10-17 18:28 48128 c:\windows\system32\dllcache\mshtmler.dll
- 2003-07-16 16:30 . 2009-03-08 10:31 48128 c:\windows\system32\dllcache\mshtmler.dll
- 2003-07-16 16:30 . 2009-03-08 10:31 45568 c:\windows\system32\dllcache\mshta.exe
+ 2003-07-16 16:30 . 2006-10-17 18:56 45568 c:\windows\system32\dllcache\mshta.exe
+ 2007-06-27 14:34 . 2008-10-16 20:38 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2003-07-16 16:26 . 2006-10-17 19:05 40960 c:\windows\system32\dllcache\licmgr10.dll
+ 2006-05-10 05:22 . 2008-10-16 20:38 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2003-07-16 16:24 . 2006-11-07 10:26 92672 c:\windows\system32\dllcache\inseng.dll
+ 2006-10-17 18:57 . 2006-10-17 18:57 36352 c:\windows\system32\dllcache\imgutil.dll
+ 2003-07-16 16:24 . 2006-11-07 10:26 55296 c:\windows\system32\dllcache\iesetup.dll
+ 2003-07-16 16:24 . 2008-10-16 20:38 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2006-11-07 10:26 . 2008-10-16 13:11 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-10-10 23:55 . 2008-10-16 20:38 63488 c:\windows\system32\dllcache\icardie.dll
+ 2006-08-03 07:25 . 2006-10-17 18:44 60416 c:\windows\system32\dllcache\hmmapi.dll
+ 2003-07-16 16:17 . 2006-11-07 10:26 71680 c:\windows\system32\dllcache\admparse.dll
+ 2003-07-16 16:20 . 2008-04-14 11:41 35328 c:\windows\system32\corpol.dll
+ 2003-07-16 16:17 . 2006-11-07 10:26 71680 c:\windows\system32\admparse.dll
+ 2006-04-28 17:58 . 2008-10-16 20:38 826368 c:\windows\system32\wininet.dll
+ 2006-10-17 19:05 . 2006-10-17 19:05 206336 c:\windows\system32\winfxdocobj.exe
+ 2003-07-16 16:44 . 2008-10-16 20:38 233472 c:\windows\system32\webcheck.dll
+ 2003-07-16 16:43 . 2008-05-09 10:53 430080 c:\windows\system32\vbscript.dll
- 2003-07-16 16:43 . 2009-03-08 10:34 105984 c:\windows\system32\url.dll
+ 2003-07-16 16:43 . 2008-10-16 20:38 105984 c:\windows\system32\url.dll
+ 2003-07-16 16:34 . 2008-10-16 20:38 102912 c:\windows\system32\occache.dll
+ 2003-07-16 16:31 . 2008-10-16 20:38 671232 c:\windows\system32\mstime.dll
+ 2003-07-16 16:31 . 2008-10-16 20:38 193024 c:\windows\system32\msrating.dll
+ 2003-07-16 16:30 . 2006-11-08 04:03 156160 c:\windows\system32\msls31.dll
- 2003-07-16 16:30 . 2009-03-08 10:22 156160 c:\windows\system32\msls31.dll
+ 2003-07-16 16:30 . 2008-10-16 20:38 477696 c:\windows\system32\mshtmled.dll
+ 2006-11-08 04:03 . 2008-10-16 20:38 459264 c:\windows\system32\msfeeds.dll
+ 2003-07-16 16:25 . 2008-05-09 10:53 512000 c:\windows\system32\jscript.dll
+ 2006-11-08 04:03 . 2006-11-08 04:03 180736 c:\windows\system32\ieui.dll
+ 2006-10-17 18:57 . 2008-10-16 20:38 267776 c:\windows\system32\iertutil.dll
+ 2003-07-16 16:24 . 2006-11-08 04:03 191488 c:\windows\system32\iepeers.dll
+ 2003-07-16 16:24 . 2008-10-16 20:38 384512 c:\windows\system32\iedkcs32.dll
+ 2006-10-17 18:27 . 2008-10-16 20:38 383488 c:\windows\system32\ieapfltr.dll
+ 2003-07-16 16:24 . 2008-10-15 07:04 161792 c:\windows\system32\ieakui.dll
+ 2003-07-16 16:24 . 2008-10-16 20:38 230400 c:\windows\system32\ieaksie.dll
+ 2003-07-16 16:24 . 2008-10-16 20:38 153088 c:\windows\system32\ieakeng.dll
+ 2003-07-16 16:21 . 2008-10-16 20:38 214528 c:\windows\system32\dxtrans.dll
+ 2003-07-16 16:21 . 2008-10-16 20:38 347136 c:\windows\system32\dxtmsft.dll
+ 2006-05-10 05:23 . 2008-10-16 20:38 826368 c:\windows\system32\dllcache\wininet.dll
+ 2006-11-08 04:03 . 2008-10-16 20:38 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2006-09-18 14:15 . 2007-07-12 23:31 765952 c:\windows\system32\dllcache\vgx.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 430080 c:\windows\system32\dllcache\vbscript.dll
- 2006-10-17 19:05 . 2009-03-08 10:34 105984 c:\windows\system32\dllcache\url.dll
+ 2006-10-17 19:05 . 2008-10-16 20:38 105984 c:\windows\system32\dllcache\url.dll
+ 2006-10-17 19:04 . 2008-10-16 20:38 102912 c:\windows\system32\dllcache\occache.dll
+ 2006-05-10 05:23 . 2008-10-16 20:38 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-05-10 05:23 . 2008-10-16 20:38 193024 c:\windows\system32\dllcache\msrating.dll
+ 2003-07-16 16:30 . 2006-11-08 04:03 156160 c:\windows\system32\dllcache\msls31.dll
- 2003-07-16 16:30 . 2009-03-08 10:22 156160 c:\windows\system32\dllcache\msls31.dll
+ 2006-05-10 05:23 . 2008-10-16 20:38 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-06-27 14:34 . 2008-10-16 20:38 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 512000 c:\windows\system32\dllcache\jscript.dll
+ 2006-10-17 19:04 . 2008-10-15 07:06 633632 c:\windows\system32\dllcache\iexplore.exe
+ 2007-06-27 14:34 . 2008-10-16 20:38 267776 c:\windows\system32\dllcache\iertutil.dll
+ 2006-05-10 05:22 . 2006-11-08 04:03 191488 c:\windows\system32\dllcache\iepeers.dll
+ 2006-11-07 10:27 . 2008-10-16 20:38 384512 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-06-27 14:34 . 2008-10-16 20:38 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2003-07-16 16:24 . 2008-10-15 07:04 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2003-07-16 16:24 . 2008-10-16 20:38 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2003-07-16 16:24 . 2008-10-16 20:38 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2006-05-10 05:22 . 2008-10-16 20:38 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-05-10 05:22 . 2008-10-16 20:38 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2006-11-07 10:26 . 2008-10-16 20:38 124928 c:\windows\system32\dllcache\advpack.dll
+ 2003-07-16 16:17 . 2008-10-16 20:38 124928 c:\windows\system32\advpack.dll
+ 2009-07-16 15:59 . 2006-09-06 23:43 213216 c:\windows\ie7\spuninst\spuninst.exe
+ 2006-05-08 17:50 . 2008-10-16 20:38 1160192 c:\windows\system32\urlmon.dll
+ 2003-07-16 16:30 . 2008-12-13 06:40 3593216 c:\windows\system32\mshtml.dll
+ 2006-11-08 04:03 . 2008-10-16 20:38 6066176 c:\windows\system32\ieframe.dll
+ 2006-09-06 06:01 . 2007-04-17 09:32 2455488 c:\windows\system32\ieapfltr.dat
+ 2006-05-10 05:23 . 2008-10-16 20:38 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2006-05-19 15:08 . 2008-12-13 06:40 3593216 c:\windows\system32\dllcache\mshtml.dll
+ 2007-06-27 14:34 . 2008-10-16 20:38 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2007-04-17 09:32 . 2007-04-17 09:32 2455488 c:\windows\system32\dllcache\ieapfltr.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-14 1048392]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\Seth\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-11-11 04:05 344064 -c--a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2005-12-19 16:08 1347584 -c--a-w- c:\windows\system32\WLTRAY.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [7/16/2003 9:41 AM 14336]
R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\drivers\ozscr.sys [8/3/2006 1:06 AM 92550]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/15/2010 12:44 PM 135664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder

2010-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-15 19:44]

2010-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-15 19:44]

2010-01-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-07-03 00:36]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://bickford.com/bc/123kah.php
IE: {{EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - c:\program files\PlaySushi\PSText.dll
FF - ProfilePath - c:\documents and settings\Seth\Application Data\Mozilla\Firefox\Profiles\6koigl2b.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\Seth\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@playsushi.com\components\PlaySushiFF.dll
FF - plugin: c:\documents and settings\Seth\Application Data\Mozilla\Firefox\Profiles\6koigl2b.default\extensions\flashplugin@idm\platform\WINNT\plugins\npidmdcp.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

AddRemove-ekkmyubvngr - c:\windows\system32\ekkmyubvngr.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-03 05:16
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(932)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-02-03 05:18:35
ComboFix-quarantined-files.txt 2010-02-03 12:18
ComboFix2.txt 2010-02-02 05:39

Pre-Run: 14,857,101,312 bytes free
Post-Run: 14,835,236,864 bytes free

- - End Of File - - CB3E0A27FAAC1249CA278F318066DBA6
Upload was successful

Attached Files



#9 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:03 PM

Posted 04 February 2010 - 08:03 PM

Let's get an anti-virus software installed for you. I see none.

Install Antivirus

An anti-virus is essential in keeping your computer safe while surfing the Internet. Please install a (ONE) free anti-virus program from one of the links below:
Update It after the installation is complete please.

Then...

Run Scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Open the Kaspersky WebScanner
    page.
  • Click on the button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the ...button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis if needed.

Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Also, let me know how your computer is running and if you have any more problems, issues or symptoms left.

Thanks.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#10 ridin2high

ridin2high
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:03 PM

Posted 05 February 2010 - 04:25 AM

It seems as though the problem i came to you with is gone and the computer is running a lot more smoothly. there are a few "infected objects" that the kaspersky scanner found though.


DDS (Ver_09-12-01.01) - NTFSx86
Run by Seth at 2:18:06.99 on Fri 02/05/2010
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.546 [GMT -7:00]

AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {00000000-0000-0000-0000-000000000000}
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {806ED0B3-FFA4-00C8-0D24-347CA8A3377C}
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {806ED0B3-FFA4-00EB-0D24-347CA8A3377C}

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe -k Akamai
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Seth\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uInternet Connection Wizard,ShellNext = hxxp://bickford.com/bc/123kah.php
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\seth\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
IE: {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - c:\program files\playsushi\PSText.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154587711345
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258148382551
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\seth\applic~1\mozilla\firefox\profiles\6koigl2b.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\seth\application data\mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@playsushi.com\components\PlaySushiFF.dll
FF - plugin: c:\documents and settings\seth\application data\mozilla\firefox\profiles\6koigl2b.default\extensions\flashplugin@idm\platform\winnt\plugins\npidmdcp.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-2-3 11608]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2003-7-16 14336]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-2-3 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-2-3 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-2-3 56816]
R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\drivers\ozscr.sys [2006-8-3 92550]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-15 135664]

=============== Created Last 30 ================

2010-02-03 12:49:35 0 d-----w- c:\docume~1\seth\applic~1\Malwarebytes
2010-02-03 12:49:23 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-03 12:49:18 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-03 12:49:16 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-03 12:49:16 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-03 12:32:35 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-02-03 12:32:32 0 d-----w- c:\program files\Avira
2010-02-02 08:41:16 0 d-----w- c:\program files\PokerStars.NET
2010-02-02 06:22:41 90112 ----a-w- c:\windows\unvise32.exe
2010-02-02 06:19:10 0 d-----w- c:\program files\DAZ
2010-02-02 05:31:46 0 d-sha-r- C:\cmdcons
2010-02-02 05:29:48 98816 ----a-w- c:\windows\sed.exe
2010-02-02 05:29:48 77312 ----a-w- c:\windows\MBR.exe
2010-02-02 05:29:48 261632 ----a-w- c:\windows\PEV.exe
2010-02-02 05:29:48 161792 ----a-w- c:\windows\SWREG.exe
2010-02-02 05:17:06 0 d-----w- c:\docume~1\alluse~1\applic~1\OptiTex
2010-02-02 05:11:53 0 d-----w- c:\docume~1\seth\applic~1\DAZ 3D
2010-02-02 05:11:18 0 d-----w- c:\program files\common files\DAZ
2010-01-29 23:47:46 0 d-----w- C:\2bc82c12fbe012ccbceff2d7
2010-01-29 02:27:41 0 d-----w- c:\program files\PlaySushi
2010-01-28 01:35:22 69 ----a-w- c:\documents and settings\seth\jagex_runescape_preferences2.dat
2010-01-25 02:33:54 82908 ----a-w- c:\documents and settings\seth\New document 1.2010_01_24_19_33_54.0
2010-01-17 03:08:03 108144 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-01-17 02:46:18 0 d-----w- c:\program files\EA GAMES
2010-01-12 23:39:00 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-11 06:39:10 0 d-----w- c:\documents and settings\seth\.idlerc
2010-01-09 20:20:37 39 ----a-w- c:\documents and settings\seth\jagex_runescape_preferences.dat
2010-01-09 20:18:15 0 d-----w- c:\windows\.jagex_cache_32
2010-01-09 20:09:08 0 d-----w- c:\program files\common files\Akamai
2010-01-09 06:10:45 0 d-----w- C:\Python26
2010-01-09 06:03:05 0 d-----w- c:\docume~1\seth\applic~1\Blender Foundation

==================== Find3M ====================

2010-01-14 18:12:06 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-05 10:00:29 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00:21 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00:20 17408 ----a-w- c:\windows\system32\corpol.dll
2009-12-30 06:53:41 258352 ----a-w- c:\windows\system32\unicows.dll
2009-12-29 04:35:19 52224 ----a-w- c:\windows\ipuninst.exe
2009-12-24 07:07:46 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2008-10-14 20:24:08 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008101420081015\index.dat

============= FINISH: 2:18:52.85 ===============



KASPERSKY ONLINE SCANNER 7.0: scan report
Friday, February 5, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Friday, February 05, 2010 07:40:38
Records in database: 3423208
Scan settings
scan using the following database extended
Scan archives yes
Scan e-mail databases yes
Scan area My Computer
C:\
D:\
Scan statistics
Objects scanned 57704
Threats found 3
Infected objects found 14
Suspicious objects found 0
Scan duration 01:34:20

File name Threat Threats count
C:\Qoobox\Quarantine\C\Documents and Settings\Seth\Application Data\Messenger\Drivers\Aud32\go282.exe.vir Infected: not-a-virus:AdWare.Win32.BHO.knv 1
C:\Qoobox\Quarantine\C\Documents and Settings\Seth\Application Data\Messenger\Drivers\Aud32\go29.exe.vir Infected: not-a-virus:AdWare.Win32.RON.bol 1
C:\Qoobox\Quarantine\C\Documents and Settings\Seth\Application Data\Messenger\Drivers\Aud32\msgutil84.dll.vir Infected: not-a-virus:AdWare.Win32.Agent.qbf 1
C:\Qoobox\Quarantine\C\Documents and Settings\Seth\Application Data\Messenger\Drivers\IgfxSys.dll.vir Infected: not-a-virus:AdWare.Win32.BHO.knv 1
C:\Qoobox\Quarantine\C\Documents and Settings\Seth\Application Data\Messenger\Drivers\MsgUpdate.dll.vir Infected: not-a-virus:AdWare.Win32.BHO.knv 1
C:\Qoobox\Quarantine\C\Documents and Settings\Seth\Application Data\Messenger\Drivers\phuninst.dll.vir Infected: not-a-virus:AdWare.Win32.BHO.knv 1
C:\Qoobox\Quarantine\C\Documents and Settings\Seth\Application Data\Messenger\Sys\mu.dll.vir Infected: not-a-virus:AdWare.Win32.BHO.knv 1
C:\System Volume Information\_restore{7C3C086F-BB6F-49E1-A93E-4D10B7873DBB}\RP219\A0025850.exe Infected: not-a-virus:AdWare.Win32.BHO.knv 1
C:\System Volume Information\_restore{7C3C086F-BB6F-49E1-A93E-4D10B7873DBB}\RP219\A0025851.exe Infected: not-a-virus:AdWare.Win32.RON.bol 1
C:\System Volume Information\_restore{7C3C086F-BB6F-49E1-A93E-4D10B7873DBB}\RP219\A0025854.dll Infected: not-a-virus:AdWare.Win32.Agent.qbf 1
C:\System Volume Information\_restore{7C3C086F-BB6F-49E1-A93E-4D10B7873DBB}\RP219\A0025858.dll Infected: not-a-virus:AdWare.Win32.BHO.knv 1
C:\System Volume Information\_restore{7C3C086F-BB6F-49E1-A93E-4D10B7873DBB}\RP219\A0025859.dll Infected: not-a-virus:AdWare.Win32.BHO.knv 1
C:\System Volume Information\_restore{7C3C086F-BB6F-49E1-A93E-4D10B7873DBB}\RP219\A0025860.dll Infected: not-a-virus:AdWare.Win32.BHO.knv 1
C:\System Volume Information\_restore{7C3C086F-BB6F-49E1-A93E-4D10B7873DBB}\RP219\A0025863.dll Infected: not-a-virus:AdWare.Win32.BHO.knv 1
Selected area has been scanned.

Attached Files



#11 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:03 PM

Posted 06 February 2010 - 02:37 PM

Hello.

What Kaspersky detected were just quarantine items from Combofix and system restore points those will be gone once we uninstall Combofix.

Other than that, just update your Java.

Update Java to Version 6 Update 18

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 Update 18 and save it to your desktop.
  • Look for JDK 6 Update 18 (JDK or JRE).
  • Click the Download JRE button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u18-windows-i586-p.exe to install the newest version.
-- If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
-- If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
-- The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.


Now, let's wrap up! smile.gif

Please follow/read the steps below to remove the tools we used and for some more information. smile.gif


Uninstall ComboFix

Remove Combofix now that we're done with it.
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
This will uninstall Combofix and anything assoicated with it.

Download and Run OTC

We will now remove the tools we used during this fix using OTC.
  • Download OTC by OldTimer and save it to your desktop.
  • Double click icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.

System A bit Slow? Try StartupLight

You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.

If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.


Congratulations! You now appear clean! specool.gif

Now that you are clean, please follow and read some of the prevention tips below.

Preventing Infections in the Future


Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

Some of the main things you should consider to perform/read are:
  • Disabling Autorun/Play on Flash-Drive/Removable Drives
  • Avoid gaming sites, underground web pages, pirated software sites, and Peer to Peer Programs
  • Keep Windows Updated through going to Windows Updates
  • Updating Non-Microsoft Programs
  • Keeping Security softwares updated

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Update all programs regularly - Make sure you update all the programs you have installed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help and thank you for choosing Bleeping Computer as you malware removal source.
Don't forget to tell your friends about us and Good luck thumbup2.gif


If you have no more questions, comments or problems please tell us, so we can close off the topic.

Thanks smile.gif

With Regards,
Extremeboy

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#12 ridin2high

ridin2high
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:07:03 PM

Posted 08 February 2010 - 01:56 AM

I have no more questions or comments so you can close off this topic. and thank you again for all the help.

#13 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:03 PM

Posted 08 February 2010 - 08:24 PM

You're very welcome. smile.gif

Happy surfing again.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#14 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:03 PM

Posted 08 February 2010 - 08:28 PM

Hello.

Since the problem appears to be resolved, this topic is now Closed. Glad we could help smile.gif
If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.

This applies only to the original topic starter

Everyone else please start a new topic.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users