Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Please help, Virtool:Win32/Obfuscator.ID virus


  • This topic is locked This topic is locked
14 replies to this topic

#1 entime

entime

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 29 March 2010 - 09:28 AM

Referred from here: http://www.bleepingcomputer.com/forums/t/305248/please-help-cant-get-rid-of-trojanvundo/ ~ OB

Please help, I keep getting access denied error massages "RUNDLL error loading C:\WINDOWS\System32\pmlljk.dll Access is denied" Each time the error message pops up it's a different .dll file name. My ativirus software keeps finding Virtool:Win32/Obfuscator.ID virus and each time I ran Malewarebytes it finds Vundo. I'm told to run gmer and post DDS.txt and attach attach.txt and ark.


DDS (Ver_10-03-17.01) - NTFSx86
Run by Tyrone at 8:09:35.62 on Mon 03/29/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.397 [GMT -4:00]

AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
C:\Program Files\Sprint\Sprint SmartView\bmctl.exe
C:\Program Files\Sprint\Sprint SmartView\SwiApiMuxCdma.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Sprint\Sprint SmartView\bmop.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Tyrone\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ISBMgr.exe] c:\program files\sony\isb utility\ISBMgr.exe
mRun: [Switcher.exe] c:\program files\sony\wireless switch setting utility\Switcher.exe
mRun: [SonyPowerCfg] c:\program files\sony\vaio power management\SPMgr.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Sprint SmartView] "c:\program files\sprint\sprint smartview\SprintSV.exe" -a
mRun: [RDVCHG] "c:\program files\sprint\sprint smartview\RDVCHG.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [jkhhgdsys] rundll32.exe "tutuvu.dll",DllRegisterServer
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
dRun: [Install] c:\windows\system32\config\systemprofile\application data\3122632986\3122632986.bat
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [nnkihesys] rundll32.exe "tutuvu.dll",DllRegisterServer
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: bmnet.dll
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.8.1/GarminAxControl.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} - hxxp://archives.gametap.com/static/cab_headless/GameTapWebUpdater.cab
DPF: {CAFECAFE-0013-0001-0021-ABCDEFABCDEF}
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
TCP: {24629F3C-1D29-4913-9004-225CEEC14ED9} = 68.28.154.91 68.28.146.91
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: VESWinlogon - VESWinlogon.dll
AppInit_DLLs: zuvararo.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: kuvahuyel - {194a24f8-8dac-4cf5-bbd4-177a8b942f53} - No File
STS: {194a24f8-8dac-4cf5-bbd4-177a8b942f53} - No File
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Authentication Packages = msv1_0 tutuvu.dll
LSA: Notification Packages = scecli c:\documents and settings\tyrone\desktop\ hikebaga.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\tyrone\applic~1\mozilla\firefox\profiles\ay8ttjyu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\tyrone\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\tyrone\application data\move networks\plugins\npqmp071701000002.dll
FF - HiddenExtension: XULRunner: {A8D53D27-FAD6-4489-8EB3-FAD078422586} - c:\documents and settings\tyrone\local settings\application data\{A8D53D27-FAD6-4489-8EB3-FAD078422586}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 149040]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-2-17 66632]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-2-17 12872]
S3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [2008-10-8 91830]

=============== Created Last 30 ================

2010-03-29 04:07:40 0 ----a-w- c:\documents and settings\tyrone\defogger_reenable
2010-03-29 01:53:06 0 d-----w- c:\program files\Microsoft Security Essentials
2010-03-27 13:57:09 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-03-27 03:59:04 0 d-----w- C:\VundoFix Backups
2010-03-23 15:27:10 0 d-----w- c:\program files\Trend Micro
2010-03-23 13:40:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-23 13:40:05 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-21 16:39:29 0 d-----w- c:\program files\Symantec AntiVirus
2010-03-18 03:31:18 0 d-----w- c:\documents and settings\tyrone\DoctorWeb
2010-03-17 15:28:34 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-03-17 15:28:22 0 d-----w- c:\program files\SUPERAntiSpyware
2010-03-17 15:28:22 0 d-----w- c:\docume~1\tyrone\applic~1\SUPERAntiSpyware.com
2010-03-17 14:51:09 0 d-----w- c:\program files\common files\xing shared
2010-03-16 13:37:13 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-03-16 13:37:13 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-03-15 14:08:42 36488 ----a-w- c:\windows\system32\drivers\klmd.sys
2010-03-14 23:03:55 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-14 22:29:31 0 d-----w- C:\BackUpMSNCleaner
2010-03-14 18:27:45 87552 ---ha-w- c:\windows\system32\tutuvu.dll
2010-03-10 22:27:38 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 03:16:57 0 d-sh--w- c:\documents and settings\tyrone\IECompatCache
2010-03-06 16:28:01 0 d-sh--w- c:\documents and settings\tyrone\PrivacIE
2010-03-06 16:26:02 0 d-sh--w- c:\documents and settings\tyrone\IETldCache
2010-03-06 16:21:44 0 d-----w- c:\windows\ie8updates
2010-03-06 16:18:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-06 16:18:00 78336 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2010-03-06 16:12:37 69120 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-03-06 16:12:17 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-03-06 16:12:17 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-03-06 14:24:52 0 d-----w- c:\docume~1\tyrone\applic~1\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-03-06 05:38:37 14848 ----a-w- c:\windows\system32\drivers\sscdmdfl.sys
2010-03-06 05:38:37 12416 ----a-w- c:\windows\system32\drivers\sscdcmnt.sys
2010-03-06 05:38:37 12416 ----a-w- c:\windows\system32\drivers\sscdcm.sys
2010-03-06 05:38:37 123648 ----a-w- c:\windows\system32\drivers\sscdmdm.sys
2010-03-06 05:38:34 98560 ----a-w- c:\windows\system32\drivers\sscdbus.sys
2010-03-06 05:38:34 12288 ----a-w- c:\windows\system32\drivers\sscdwhnt.sys
2010-03-06 05:38:34 12288 ----a-w- c:\windows\system32\drivers\sscdwh.sys
2010-03-06 05:38:33 0 d-----w- c:\program files\SAMSUNG
2010-03-06 05:38:00 0 d-----w- c:\docume~1\alluse~1\applic~1\Samsung
2010-03-06 05:37:22 0 d-----w- c:\program files\Samsung Electronics

==================== Find3M ====================

2010-03-17 14:50:16 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-06 14:35:41 51672 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-02-24 14:16:06 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-01-05 10:00:29 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00:20 17408 ----a-w- c:\windows\system32\corpol.dll
2009-09-21 21:27:54 19286 ----a-w- c:\program files\common files\jysycugi.dat
2009-09-21 21:27:54 17709 ----a-w- c:\program files\common files\qudyvin.inf
2009-09-21 21:27:54 10742 ----a-w- c:\program files\common files\minomyra.db
2009-09-21 21:27:53 13277 ----a-w- c:\program files\common files\qela._dl
2009-08-27 23:52:43 14466 ----a-w- c:\program files\common files\fobamyf.lib
2009-08-27 23:52:43 13957 ----a-w- c:\program files\common files\yboliduhu.exe
2009-08-27 23:52:43 13493 ----a-w- c:\program files\common files\ralufef.com
2009-10-04 18:21:30 32768 --sha-w- c:\windows\system32\config\systemprofile\cookies\index.dat
2009-10-04 18:21:30 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat
2008-09-24 02:17:28 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092320080924\index.dat
2009-10-04 18:21:30 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat

============= FINISH: 8:10:31.20 ===============

Attached Files


Edited by Orange Blossom, 29 March 2010 - 11:24 PM.


BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:26 PM

Posted 02 April 2010 - 01:33 PM

Hi,

My name is Extremeboy (or EB for short), and I will be helping you with your log.

I apologize for the delay.

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs.

Refer to this page if needed.

Thanks.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 entime

entime
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 02 April 2010 - 07:11 PM

Hi EB

Below is the DDS log.


DDS (Ver_10-03-17.01) - NTFSx86
Run by Tyrone at 20:04:46.54 on Fri 04/02/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_19
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.449 [GMT -4:00]

AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe
C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
C:\Program Files\Sprint\Sprint SmartView\bmctl.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Sprint\Sprint SmartView\SwiApiMuxCdma.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Sprint\Sprint SmartView\bmop.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\Tyrone\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ISBMgr.exe] c:\program files\sony\isb utility\ISBMgr.exe
mRun: [Switcher.exe] c:\program files\sony\wireless switch setting utility\Switcher.exe
mRun: [SonyPowerCfg] c:\program files\sony\vaio power management\SPMgr.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Sprint SmartView] "c:\program files\sprint\sprint smartview\SprintSV.exe" -a
mRun: [RDVCHG] "c:\program files\sprint\sprint smartview\RDVCHG.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [jkhhgdsys] rundll32.exe "tutuvu.dll",DllRegisterServer
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
dRun: [Install] c:\windows\system32\config\systemprofile\application data\3122632986\3122632986.bat
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [nnkihesys] rundll32.exe "tutuvu.dll",DllRegisterServer
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: bmnet.dll
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.8.1/GarminAxControl.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} - hxxp://archives.gametap.com/static/cab_headless/GameTapWebUpdater.cab
DPF: {CAFECAFE-0013-0001-0021-ABCDEFABCDEF}
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
TCP: {24629F3C-1D29-4913-9004-225CEEC14ED9} = 68.28.154.91 68.28.146.91
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: VESWinlogon - VESWinlogon.dll
AppInit_DLLs: zuvararo.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: kuvahuyel - {194a24f8-8dac-4cf5-bbd4-177a8b942f53} - No File
STS: {194a24f8-8dac-4cf5-bbd4-177a8b942f53} - No File
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Authentication Packages = msv1_0 tutuvu.dll
LSA: Notification Packages = scecli c:\documents and settings\tyrone\desktop\ hikebaga.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\tyrone\applic~1\mozilla\firefox\profiles\ay8ttjyu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\tyrone\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\tyrone\application data\move networks\plugins\npqmp071701000002.dll
FF - HiddenExtension: XULRunner: {A8D53D27-FAD6-4489-8EB3-FAD078422586} - c:\documents and settings\tyrone\local settings\application data\{A8D53D27-FAD6-4489-8EB3-FAD078422586}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 149040]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-2-17 66632]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-2-17 12872]
S3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [2008-10-8 91830]

=============== Created Last 30 ================

2010-03-29 04:07:40 0 ----a-w- c:\documents and settings\tyrone\defogger_reenable
2010-03-29 01:53:06 0 d-----w- c:\program files\Microsoft Security Essentials
2010-03-27 13:57:09 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-03-27 03:59:04 0 d-----w- C:\VundoFix Backups
2010-03-23 15:27:10 0 d-----w- c:\program files\Trend Micro
2010-03-23 13:40:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-23 13:40:05 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-21 16:39:29 0 d-----w- c:\program files\Symantec AntiVirus
2010-03-18 03:31:18 0 d-----w- c:\documents and settings\tyrone\DoctorWeb
2010-03-17 15:28:34 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-03-17 15:28:22 0 d-----w- c:\program files\SUPERAntiSpyware
2010-03-17 15:28:22 0 d-----w- c:\docume~1\tyrone\applic~1\SUPERAntiSpyware.com
2010-03-17 14:51:09 0 d-----w- c:\program files\common files\xing shared
2010-03-16 13:37:13 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-03-16 13:37:13 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-03-15 14:08:42 36488 ----a-w- c:\windows\system32\drivers\klmd.sys
2010-03-14 23:03:55 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-14 22:29:31 0 d-----w- C:\BackUpMSNCleaner
2010-03-14 18:27:45 87552 ---ha-w- c:\windows\system32\tutuvu.dll
2010-03-10 22:27:38 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 03:16:57 0 d-sh--w- c:\documents and settings\tyrone\IECompatCache
2010-03-06 16:28:01 0 d-sh--w- c:\documents and settings\tyrone\PrivacIE
2010-03-06 16:26:02 0 d-sh--w- c:\documents and settings\tyrone\IETldCache
2010-03-06 16:21:44 0 d-----w- c:\windows\ie8updates
2010-03-06 16:18:00 78336 -c--a-w- c:\windows\system32\dllcache\ieencode.dll
2010-03-06 16:18:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-06 16:12:37 69120 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-03-06 16:12:17 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-03-06 16:12:17 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-03-06 14:24:52 0 d-----w- c:\docume~1\tyrone\applic~1\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-03-06 05:38:37 14848 ----a-w- c:\windows\system32\drivers\sscdmdfl.sys
2010-03-06 05:38:37 12416 ----a-w- c:\windows\system32\drivers\sscdcmnt.sys
2010-03-06 05:38:37 12416 ----a-w- c:\windows\system32\drivers\sscdcm.sys
2010-03-06 05:38:37 123648 ----a-w- c:\windows\system32\drivers\sscdmdm.sys
2010-03-06 05:38:34 98560 ----a-w- c:\windows\system32\drivers\sscdbus.sys
2010-03-06 05:38:34 12288 ----a-w- c:\windows\system32\drivers\sscdwhnt.sys
2010-03-06 05:38:34 12288 ----a-w- c:\windows\system32\drivers\sscdwh.sys
2010-03-06 05:38:33 0 d-----w- c:\program files\SAMSUNG
2010-03-06 05:38:00 0 d-----w- c:\docume~1\alluse~1\applic~1\Samsung
2010-03-06 05:37:22 0 d-----w- c:\program files\Samsung Electronics

==================== Find3M ====================

2010-03-17 14:50:16 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-11 12:38:54 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38:51 17408 ----a-w- c:\windows\system32\corpol.dll
2010-03-09 08:28:20 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-06 14:35:41 51672 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-02-24 14:16:06 181632 ------w- c:\windows\system32\MpSigStub.exe
2009-09-21 21:27:54 19286 ----a-w- c:\program files\common files\jysycugi.dat
2009-09-21 21:27:54 17709 ----a-w- c:\program files\common files\qudyvin.inf
2009-09-21 21:27:54 10742 ----a-w- c:\program files\common files\minomyra.db
2009-09-21 21:27:53 13277 ----a-w- c:\program files\common files\qela._dl
2009-08-27 23:52:43 14466 ----a-w- c:\program files\common files\fobamyf.lib
2009-08-27 23:52:43 13957 ----a-w- c:\program files\common files\yboliduhu.exe
2009-08-27 23:52:43 13493 ----a-w- c:\program files\common files\ralufef.com
2009-10-04 18:21:30 32768 --sha-w- c:\windows\system32\config\systemprofile\cookies\index.dat
2009-10-04 18:21:30 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat
2008-09-24 02:17:28 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092320080924\index.dat
2009-10-04 18:21:30 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat

============= FINISH: 20:05:34.53 ===============

Attached Files



#4 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:26 PM

Posted 03 April 2010 - 10:41 AM

Hello.

Quite a few things on your machine. I see a lot of vundo related infections.

We'll start with Combofix and continue from there.

Download and Run Combofix

Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page on instructions on doing so.

Please include the C:\ComboFix.txt in your next reply for further review.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#5 entime

entime
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 04 April 2010 - 10:10 AM

Okay, below is the combofix.txt

ComboFix 10-04-03.02 - Tyrone 04/04/2010 10:48:28.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.592 [GMT -4:00]
Running from: c:\documents and settings\Tyrone\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Documents\zexidogada.bat
c:\documents and settings\Tyrone\Application Data\umekuvany.inf
c:\documents and settings\Tyrone\Local Settings\Application Data\eruxeki.bat
c:\documents and settings\Tyrone\Local Settings\Application Data\vicehuz.vbs
c:\program files\Common Files\qudyvin.inf
c:\windows\abawi.scr
c:\windows\AppPatch\AcAdProc.dll
c:\windows\axolywijez._sy
c:\windows\bypo.bat
c:\windows\erolewipy.scr
c:\windows\lubuwinyq.reg
c:\windows\nohaxanuk._sy
c:\windows\sapuhy._sy
c:\windows\system32\26500.exe
c:\windows\system32\bytu.bat
c:\windows\system32\dddaax.dll
c:\windows\system32\tutuvu.dll
c:\windows\ukokezoh.vbs
c:\windows\wile._sy
c:\windows\yrepybed.reg

c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe

.
((((((((((((((((((((((((( Files Created from 2010-03-04 to 2010-04-04 )))))))))))))))))))))))))))))))
.

2010-04-04 14:53 . 2008-04-14 00:12 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2010-04-04 14:53 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2010-03-31 14:10 . 2010-03-31 14:10 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{03E3B82A-747F-D976-7D9B-B54DECA2C65C}-gededa.dll
2010-03-31 13:02 . 2010-03-31 13:02 503808 ----a-w- c:\documents and settings\Tyrone\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2da74354-n\msvcp71.dll
2010-03-31 13:02 . 2010-03-31 13:02 499712 ----a-w- c:\documents and settings\Tyrone\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2da74354-n\jmc.dll
2010-03-31 13:02 . 2010-03-31 13:02 348160 ----a-w- c:\documents and settings\Tyrone\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2da74354-n\msvcr71.dll
2010-03-31 13:02 . 2010-03-31 13:02 61440 ----a-w- c:\documents and settings\Tyrone\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-34a4e2ae-n\decora-sse.dll
2010-03-31 13:02 . 2010-03-31 13:02 12800 ----a-w- c:\documents and settings\Tyrone\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-34a4e2ae-n\decora-d3d.dll
2010-03-31 12:33 . 2010-03-31 12:33 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{A7032BE5-D633-2BE6-3986-8D8060BA92B7}-yabbbb.dll
2010-03-31 11:33 . 2010-03-31 11:33 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{11A4D78E-406E-AEE2-14E0-417CFFF7B63C}-qomjkj.dll
2010-03-31 10:33 . 2010-03-31 10:33 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{E51DB021-D833-79C9-CC22-706B6E008A06}-xxvtqn.dll
2010-03-31 09:33 . 2010-03-31 09:33 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{8CE61756-AB0A-4C2A-6541-746FD8D4C942}-gebbca.dll
2010-03-31 08:33 . 2010-03-31 08:33 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{4A7FF134-9946-8694-3029-F260964571AF}-khihfe.dll
2010-03-30 05:58 . 2010-03-30 05:58 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{ADFB0C2E-9336-9985-AB48-420F7ABA08A3}-fcbxuv.dll
2010-03-29 02:32 . 2010-03-29 02:32 97792 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{4F8874E5-D760-5223-9CDF-1237AE037076}-rqpnop.dll
2010-03-29 01:53 . 2010-03-29 01:53 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-03-28 17:42 . 2010-03-28 17:42 52224 ----a-w- c:\documents and settings\Tyrone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-03-28 17:42 . 2010-03-28 17:42 117760 ----a-w- c:\documents and settings\Tyrone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-03-27 13:57 . 2010-03-29 02:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-03-27 13:57 . 2010-03-27 13:57 -------- d-----w- c:\program files\Alwil Software
2010-03-27 03:59 . 2010-03-27 03:59 -------- d-----w- C:\VundoFix Backups
2010-03-23 15:27 . 2010-03-23 15:27 -------- d-----w- c:\program files\Trend Micro
2010-03-23 13:40 . 2010-01-07 20:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-23 13:40 . 2010-01-07 20:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-21 16:39 . 2010-03-27 13:56 -------- d-----w- c:\program files\Symantec AntiVirus
2010-03-19 02:49 . 2010-03-19 02:49 -------- d-----w- c:\documents and settings\Tyrone\Local Settings\Application Data\PCHealth
2010-03-18 03:31 . 2010-03-18 03:53 -------- d-----w- c:\documents and settings\Tyrone\DoctorWeb
2010-03-17 15:28 . 2010-03-17 15:28 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-03-17 15:28 . 2010-03-28 17:40 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-03-17 15:28 . 2010-03-28 17:40 -------- d-----w- c:\documents and settings\Tyrone\Application Data\SUPERAntiSpyware.com
2010-03-16 13:37 . 2010-03-21 02:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-03-16 13:37 . 2010-03-21 02:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-03-15 14:08 . 2010-03-15 14:08 36488 ----a-w- c:\windows\system32\drivers\klmd.sys
2010-03-15 03:10 . 2010-03-15 03:20 -------- d-----w- c:\program files\Windows Live Safety Center
2010-03-14 23:03 . 2010-03-23 14:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-14 22:29 . 2010-03-14 22:29 -------- d-----w- C:\BackUpMSNCleaner
2010-03-10 22:27 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 03:16 . 2010-03-09 03:16 -------- d-sh--w- c:\documents and settings\Tyrone\IECompatCache
2010-03-06 16:28 . 2010-03-06 16:28 -------- d-sh--w- c:\documents and settings\Tyrone\PrivacIE
2010-03-06 16:26 . 2010-03-06 16:26 -------- d-sh--w- c:\documents and settings\Tyrone\IETldCache
2010-03-06 16:21 . 2010-03-21 02:09 -------- d-----w- c:\windows\ie8updates
2010-03-06 16:18 . 2010-03-11 12:38 78336 -c--a-w- c:\windows\system32\dllcache\ieencode.dll
2010-03-06 16:18 . 2010-03-11 12:38 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-06 16:12 . 2009-12-11 08:38 69120 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-03-06 16:12 . 2009-12-21 19:14 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-03-06 16:12 . 2009-12-21 19:14 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-03-06 14:24 . 2010-03-06 14:24 -------- d-----w- c:\documents and settings\Tyrone\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-03-06 05:38 . 2010-01-14 07:02 14848 ----a-w- c:\windows\system32\drivers\sscdmdfl.sys
2010-03-06 05:38 . 2010-01-14 07:02 12416 ----a-w- c:\windows\system32\drivers\sscdcmnt.sys
2010-03-06 05:38 . 2010-01-14 07:02 12416 ----a-w- c:\windows\system32\drivers\sscdcm.sys
2010-03-06 05:38 . 2010-01-14 07:02 123648 ----a-w- c:\windows\system32\drivers\sscdmdm.sys
2010-03-06 05:38 . 2010-01-14 07:02 12288 ----a-w- c:\windows\system32\drivers\sscdwhnt.sys
2010-03-06 05:38 . 2010-01-14 07:02 12288 ----a-w- c:\windows\system32\drivers\sscdwh.sys
2010-03-06 05:38 . 2010-01-14 07:02 98560 ----a-w- c:\windows\system32\drivers\sscdbus.sys
2010-03-06 05:38 . 2010-03-06 05:38 -------- d-----w- c:\program files\SAMSUNG
2010-03-06 05:38 . 2010-03-06 05:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Samsung
2010-03-06 05:37 . 2010-03-06 05:37 53248 ----a-r- c:\documents and settings\Tyrone\Application Data\Microsoft\Installer\{64C85B95-E971-4705-B3ED-D4A0153C0D5B}\ARPPRODUCTICON.exe
2010-03-06 05:37 . 2010-03-06 05:37 -------- d-----w- c:\program files\Samsung Electronics

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-31 13:02 . 2008-01-05 03:13 -------- d-----w- c:\program files\Common Files\Java
2010-03-31 13:01 . 2008-01-05 03:15 -------- d-----w- c:\program files\Java
2010-03-29 03:57 . 2009-05-08 02:04 -------- d-----w- c:\documents and settings\Tyrone\Application Data\Move Networks
2010-03-28 17:40 . 2007-07-26 23:50 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-03-27 13:56 . 2007-04-20 17:57 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-03-27 13:56 . 2007-04-20 17:58 -------- d-----w- c:\program files\Symantec
2010-03-27 13:56 . 2007-04-20 17:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-03-17 14:51 . 2010-03-17 14:51 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-03-17 14:51 . 2010-03-17 14:51 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-03-17 14:51 . 2010-03-17 14:51 49152 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-03-17 14:51 . 2010-03-17 14:51 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-03-17 14:51 . 2010-03-17 14:51 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-03-17 14:51 . 2010-03-17 14:51 40960 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-17 14:51 . 2010-03-17 14:51 308808 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-03-17 14:51 . 2010-03-17 14:51 14848 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-03-17 14:51 . 2010-03-17 14:51 341600 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-03-17 14:51 . 2007-05-23 20:25 -------- d-----w- c:\program files\Common Files\Real
2010-03-17 14:51 . 2007-05-23 20:23 -------- d-----w- c:\program files\Real
2010-03-17 14:51 . 2010-03-17 14:51 -------- d-----w- c:\program files\Common Files\xing shared
2010-03-17 14:50 . 2003-03-19 01:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-11 12:38 . 2004-08-04 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-03-09 08:28 . 2009-02-10 00:22 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-06 14:35 . 2007-08-13 23:49 51672 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-03-06 14:35 . 2007-04-20 18:08 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-25 13:58 . 2008-02-22 03:42 -------- d-----w- c:\program files\Yahoo!
2010-02-24 14:16 . 2010-01-11 05:21 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-24 04:23 . 2010-02-24 04:22 -------- d-----w- c:\documents and settings\Tyrone\Application Data\Yahoo!
2010-02-24 04:22 . 2008-02-22 03:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-02-21 02:09 . 2010-01-31 20:57 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-02-09 04:03 . 2010-02-09 04:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-02-09 04:03 . 2010-02-09 04:03 -------- d-----w- c:\documents and settings\Tyrone\Application Data\Office Genuine Advantage
2010-02-07 20:13 . 2010-02-07 20:13 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-07 02:24 . 2009-10-15 00:50 5642688 ----a-w- c:\documents and settings\Tyrone\Application Data\Move Networks\plugins\npqmp071701000002.dll
2010-01-07 02:24 . 2009-09-17 22:45 143976 ----a-w- c:\documents and settings\Tyrone\Application Data\Move Networks\uninstall.exe
2010-01-07 02:24 . 2010-01-07 02:23 1794456 ----a-w- c:\documents and settings\Tyrone\Application Data\Move Networks\MoveMediaPlayerWin_071701000002.exe
2009-09-21 21:27 . 2009-09-21 21:27 19286 ----a-w- c:\program files\Common Files\jysycugi.dat
2009-09-21 21:27 . 2009-09-21 21:27 10742 ----a-w- c:\program files\Common Files\minomyra.db
2009-09-21 21:27 . 2009-09-21 21:27 13277 ----a-w- c:\program files\Common Files\qela._dl
2009-08-27 23:52 . 2009-08-27 23:52 14466 ----a-w- c:\program files\Common Files\fobamyf.lib
2009-08-27 23:52 . 2009-08-27 23:52 13957 ----a-w- c:\program files\Common Files\yboliduhu.exe
2009-08-27 23:52 . 2009-08-27 23:52 13493 ----a-w- c:\program files\Common Files\ralufef.com
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-02-22 13783040]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-11-07 114688]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-02-17 5406720]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-10 385024]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-01-21 167936]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2005-01-14 184320]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Sprint SmartView"="c:\program files\Sprint\Sprint SmartView\SprintSV.exe" [2009-12-02 75072]
"RDVCHG"="c:\program files\Sprint\Sprint SmartView\RDVCHG.exe" [2009-12-02 316736]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-17 202256]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-8-12 122880]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 18:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-01-18 16:48 73728 ----a-w- c:\windows\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Sprint\\Sprint SmartView\\SwiApiMux.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/17/2010 10:15 AM 66632]
S3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [10/8/2008 11:27 PM 91830]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2010 10:15 AM 12872]

--- Other Services/Drivers In Memory ---

*Deregistered* - BMLoad
.
Contents of the 'Scheduled Tasks' folder

2010-04-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]

2010-04-04 c:\windows\Tasks\Malwarebytes' Scheduled Update for Tyrone.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2010-03-23 20:07]

2010-04-04 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-09 22:02]

2010-04-04 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]

2010-04-04 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1123561945-1383384898-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-03-31 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1123561945-1383384898-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
LSP: bmnet.dll
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.8.1/GarminAxControl.CAB
DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} - hxxp://archives.gametap.com/static/cab_headless/GameTapWebUpdater.cab
FF - ProfilePath - c:\documents and settings\Tyrone\Application Data\Mozilla\Firefox\Profiles\ay8ttjyu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\Tyrone\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Tyrone\Application Data\Move Networks\plugins\npqmp071701000002.dll
FF - HiddenExtension: XULRunner: {A8D53D27-FAD6-4489-8EB3-FAD078422586} - c:\documents and settings\Tyrone\Local Settings\Application Data\{A8D53D27-FAD6-4489-8EB3-FAD078422586}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)
HKCU-Run-rqomkkdrv - dddaax.dll
HKLM-Run-jkhhgdsys - tutuvu.dll
HKLM-Run-ljkigedrv - dddaax.dll
HKU-Default-Run-nnkihesys - tutuvu.dll
HKU-Default-Run-yaxwutdrv - dddaax.dll
SharedTaskScheduler-{194a24f8-8dac-4cf5-bbd4-177a8b942f53} - (no file)
SSODL-kuvahuyel-{194a24f8-8dac-4cf5-bbd4-177a8b942f53} - (no file)
Notify-NavLogon - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-04 10:57
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(880)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\VESWinlogon.dll

- - - - - - - > 'lsass.exe'(936)
c:\windows\system32\bmnet.dll

- - - - - - - > 'explorer.exe'(2300)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\program files\Apoint\Apntex.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2010-04-04 11:03:04 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-04 15:03
ComboFix2.txt 2009-04-04 19:16

Pre-Run: 48,880,300,032 bytes free
Post-Run: 48,784,388,096 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 41A7CDC2ECBACA29F6FEEB41CCB7F40B


#6 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:26 PM

Posted 04 April 2010 - 10:29 AM

Hello.

Run ComboFix with CFScript

We will run ComboFix again. This time it will be slightly different from the initial run.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are unsure how.
  • Open notepad (Start>Run>"notepad") and copy/paste the text in the quotebox below into it:
    CODE
    http://www.bleepingcomputer.com/forums/t/305672/please-help-virtoolwin32obfuscatorid-virus/
    Collect::[68]
    c:\program files\Common Files\jysycugi.dat
    c:\program files\Common Files\minomyra.db
    c:\program files\Common Files\qela._dl
    c:\program files\Common Files\fobamyf.lib
    c:\program files\Common Files\yboliduhu.exe
    c:\program files\Common Files\ralufef.com
    Save this as CFScript.txt, in the same location as ComboFix.exe. (This should be your desktop.)
  • Refering to the picture above, drag CFScript into ComboFix.exe.
  • When finished, it shall produce a log for you at "C:\ComboFix.txt"
  • Please post the contents of the Combofix log in your next reply.

Upload Samples by ComboFix

When Combofix finishes running, the ComboFix log will open along with a message box. With the above script, ComboFix captured some files to submit for analysis.
  • Important: Ensure you are connected to the internet before clicking OK on the message box.
  • A blue-screen would appear auto-uploading the zipped file I requested.
  • After the uploading is done you should see a message near the bottom saying "Upload was Succesfull".

**NOTE**
=================
  • IF for some reason Combofix fails to upload anything please do the following:
  • Go to Start >> My Computer > C:\
  • Then Navigate to the C:\Qoobox\Quarantine folder.
  • Find the archive zip file called "[68]-Submit_Date_Time.zip"
  • Simply go to This Channel and upload the submit.zip archive file to me.
  • Follow the instructions on that page to copy/paste/send the requested file.

Let me know how it goes and if the upload went successfully or not in your next reply.
---

Update and Scan with MalwareBytes Anti-Malware
  • Launch Malwarebytes' Anti-Malware
  • Go to the Update tab
  • Select Check for Update and let MBAM download and install any available updates.
  • After the update is complete go to the Scanner tab.
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#7 entime

entime
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 04 April 2010 - 01:41 PM

Hi EB,

Below is the combofix.txt and the mbam-log.txt.


ComboFix 10-04-03.02 - Tyrone 04/04/2010 11:57:19.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.592 [GMT -4:00]
Running from: c:\documents and settings\Tyrone\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Tyrone\Desktop\CFScript.txt
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

file zipped: c:\program files\Common Files\fobamyf.lib
file zipped: c:\program files\Common Files\jysycugi.dat
file zipped: c:\program files\Common Files\minomyra.db
file zipped: c:\program files\Common Files\qela._dl
file zipped: c:\program files\Common Files\ralufef.com
file zipped: c:\program files\Common Files\yboliduhu.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Common Files\fobamyf.lib
c:\program files\Common Files\jysycugi.dat
c:\program files\Common Files\minomyra.db
c:\program files\Common Files\qela._dl
c:\program files\Common Files\ralufef.com
c:\program files\Common Files\yboliduhu.exe

.
((((((((((((((((((((((((( Files Created from 2010-03-04 to 2010-04-04 )))))))))))))))))))))))))))))))
.

2010-04-04 14:53 . 2008-04-14 00:12 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2010-04-04 14:53 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2010-03-31 14:10 . 2010-03-31 14:10 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{03E3B82A-747F-D976-7D9B-B54DECA2C65C}-gededa.dll
2010-03-31 13:02 . 2010-03-31 13:02 503808 ----a-w- c:\documents and settings\Tyrone\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2da74354-n\msvcp71.dll
2010-03-31 13:02 . 2010-03-31 13:02 499712 ----a-w- c:\documents and settings\Tyrone\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2da74354-n\jmc.dll
2010-03-31 13:02 . 2010-03-31 13:02 348160 ----a-w- c:\documents and settings\Tyrone\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2da74354-n\msvcr71.dll
2010-03-31 13:02 . 2010-03-31 13:02 61440 ----a-w- c:\documents and settings\Tyrone\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-34a4e2ae-n\decora-sse.dll
2010-03-31 13:02 . 2010-03-31 13:02 12800 ----a-w- c:\documents and settings\Tyrone\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-34a4e2ae-n\decora-d3d.dll
2010-03-31 12:33 . 2010-03-31 12:33 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{A7032BE5-D633-2BE6-3986-8D8060BA92B7}-yabbbb.dll
2010-03-31 11:33 . 2010-03-31 11:33 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{11A4D78E-406E-AEE2-14E0-417CFFF7B63C}-qomjkj.dll
2010-03-31 10:33 . 2010-03-31 10:33 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{E51DB021-D833-79C9-CC22-706B6E008A06}-xxvtqn.dll
2010-03-31 09:33 . 2010-03-31 09:33 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{8CE61756-AB0A-4C2A-6541-746FD8D4C942}-gebbca.dll
2010-03-31 08:33 . 2010-03-31 08:33 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{4A7FF134-9946-8694-3029-F260964571AF}-khihfe.dll
2010-03-30 05:58 . 2010-03-30 05:58 94208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{ADFB0C2E-9336-9985-AB48-420F7ABA08A3}-fcbxuv.dll
2010-03-29 02:32 . 2010-03-29 02:32 97792 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{4F8874E5-D760-5223-9CDF-1237AE037076}-rqpnop.dll
2010-03-29 01:53 . 2010-03-29 01:53 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-03-28 17:42 . 2010-03-28 17:42 52224 ----a-w- c:\documents and settings\Tyrone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-03-28 17:42 . 2010-03-28 17:42 117760 ----a-w- c:\documents and settings\Tyrone\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-03-27 13:57 . 2010-03-29 02:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-03-27 13:57 . 2010-03-27 13:57 -------- d-----w- c:\program files\Alwil Software
2010-03-27 03:59 . 2010-03-27 03:59 -------- d-----w- C:\VundoFix Backups
2010-03-23 15:27 . 2010-03-23 15:27 -------- d-----w- c:\program files\Trend Micro
2010-03-23 13:40 . 2010-01-07 20:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-23 13:40 . 2010-01-07 20:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-21 16:39 . 2010-03-27 13:56 -------- d-----w- c:\program files\Symantec AntiVirus
2010-03-19 02:49 . 2010-03-19 02:49 -------- d-----w- c:\documents and settings\Tyrone\Local Settings\Application Data\PCHealth
2010-03-18 03:31 . 2010-03-18 03:53 -------- d-----w- c:\documents and settings\Tyrone\DoctorWeb
2010-03-17 15:28 . 2010-03-17 15:28 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-03-17 15:28 . 2010-03-28 17:40 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-03-17 15:28 . 2010-03-28 17:40 -------- d-----w- c:\documents and settings\Tyrone\Application Data\SUPERAntiSpyware.com
2010-03-16 13:37 . 2010-03-21 02:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-03-16 13:37 . 2010-03-21 02:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-03-15 14:08 . 2010-03-15 14:08 36488 ----a-w- c:\windows\system32\drivers\klmd.sys
2010-03-15 03:10 . 2010-03-15 03:20 -------- d-----w- c:\program files\Windows Live Safety Center
2010-03-14 23:03 . 2010-03-23 14:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-14 22:29 . 2010-03-14 22:29 -------- d-----w- C:\BackUpMSNCleaner
2010-03-10 22:27 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 03:16 . 2010-03-09 03:16 -------- d-sh--w- c:\documents and settings\Tyrone\IECompatCache
2010-03-06 16:28 . 2010-03-06 16:28 -------- d-sh--w- c:\documents and settings\Tyrone\PrivacIE
2010-03-06 16:26 . 2010-03-06 16:26 -------- d-sh--w- c:\documents and settings\Tyrone\IETldCache
2010-03-06 16:21 . 2010-03-21 02:09 -------- d-----w- c:\windows\ie8updates
2010-03-06 16:18 . 2010-03-11 12:38 78336 -c--a-w- c:\windows\system32\dllcache\ieencode.dll
2010-03-06 16:18 . 2010-03-11 12:38 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-06 16:12 . 2009-12-11 08:38 69120 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-03-06 16:12 . 2009-12-21 19:14 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-03-06 16:12 . 2009-12-21 19:14 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-03-06 14:24 . 2010-03-06 14:24 -------- d-----w- c:\documents and settings\Tyrone\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-03-06 05:38 . 2010-01-14 07:02 14848 ----a-w- c:\windows\system32\drivers\sscdmdfl.sys
2010-03-06 05:38 . 2010-01-14 07:02 12416 ----a-w- c:\windows\system32\drivers\sscdcmnt.sys
2010-03-06 05:38 . 2010-01-14 07:02 12416 ----a-w- c:\windows\system32\drivers\sscdcm.sys
2010-03-06 05:38 . 2010-01-14 07:02 123648 ----a-w- c:\windows\system32\drivers\sscdmdm.sys
2010-03-06 05:38 . 2010-01-14 07:02 12288 ----a-w- c:\windows\system32\drivers\sscdwhnt.sys
2010-03-06 05:38 . 2010-01-14 07:02 12288 ----a-w- c:\windows\system32\drivers\sscdwh.sys
2010-03-06 05:38 . 2010-01-14 07:02 98560 ----a-w- c:\windows\system32\drivers\sscdbus.sys
2010-03-06 05:38 . 2010-03-06 05:38 -------- d-----w- c:\program files\SAMSUNG
2010-03-06 05:38 . 2010-03-06 05:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Samsung
2010-03-06 05:37 . 2010-03-06 05:37 53248 ----a-r- c:\documents and settings\Tyrone\Application Data\Microsoft\Installer\{64C85B95-E971-4705-B3ED-D4A0153C0D5B}\ARPPRODUCTICON.exe
2010-03-06 05:37 . 2010-03-06 05:37 -------- d-----w- c:\program files\Samsung Electronics

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-31 13:02 . 2008-01-05 03:13 -------- d-----w- c:\program files\Common Files\Java
2010-03-31 13:01 . 2008-01-05 03:15 -------- d-----w- c:\program files\Java
2010-03-29 03:57 . 2009-05-08 02:04 -------- d-----w- c:\documents and settings\Tyrone\Application Data\Move Networks
2010-03-28 17:40 . 2007-07-26 23:50 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-03-27 13:56 . 2007-04-20 17:57 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-03-27 13:56 . 2007-04-20 17:58 -------- d-----w- c:\program files\Symantec
2010-03-27 13:56 . 2007-04-20 17:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-03-17 14:51 . 2010-03-17 14:51 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-03-17 14:51 . 2010-03-17 14:51 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-03-17 14:51 . 2010-03-17 14:51 49152 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-03-17 14:51 . 2010-03-17 14:51 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-03-17 14:51 . 2010-03-17 14:51 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-03-17 14:51 . 2010-03-17 14:51 40960 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-17 14:51 . 2010-03-17 14:51 308808 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-03-17 14:51 . 2010-03-17 14:51 14848 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-03-17 14:51 . 2010-03-17 14:51 341600 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-03-17 14:51 . 2007-05-23 20:25 -------- d-----w- c:\program files\Common Files\Real
2010-03-17 14:51 . 2007-05-23 20:23 -------- d-----w- c:\program files\Real
2010-03-17 14:51 . 2010-03-17 14:51 -------- d-----w- c:\program files\Common Files\xing shared
2010-03-17 14:50 . 2003-03-19 01:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-11 12:38 . 2004-08-04 12:00 832512 ------w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-03-09 08:28 . 2009-02-10 00:22 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-06 14:35 . 2007-08-13 23:49 51672 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-03-06 14:35 . 2007-04-20 18:08 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-25 13:58 . 2008-02-22 03:42 -------- d-----w- c:\program files\Yahoo!
2010-02-24 14:16 . 2010-01-11 05:21 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-24 04:23 . 2010-02-24 04:22 -------- d-----w- c:\documents and settings\Tyrone\Application Data\Yahoo!
2010-02-24 04:22 . 2008-02-22 03:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-02-21 02:09 . 2010-01-31 20:57 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-02-09 04:03 . 2010-02-09 04:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-02-09 04:03 . 2010-02-09 04:03 -------- d-----w- c:\documents and settings\Tyrone\Application Data\Office Genuine Advantage
2010-02-07 20:13 . 2010-02-07 20:13 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-07 02:24 . 2009-10-15 00:50 5642688 ----a-w- c:\documents and settings\Tyrone\Application Data\Move Networks\plugins\npqmp071701000002.dll
2010-01-07 02:24 . 2009-09-17 22:45 143976 ----a-w- c:\documents and settings\Tyrone\Application Data\Move Networks\uninstall.exe
2010-01-07 02:24 . 2010-01-07 02:23 1794456 ----a-w- c:\documents and settings\Tyrone\Application Data\Move Networks\MoveMediaPlayerWin_071701000002.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-02-22 13783040]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-11-07 114688]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-02-17 5406720]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-10 385024]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-01-21 167936]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2005-01-14 184320]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Sprint SmartView"="c:\program files\Sprint\Sprint SmartView\SprintSV.exe" [2009-12-02 75072]
"RDVCHG"="c:\program files\Sprint\Sprint SmartView\RDVCHG.exe" [2009-12-02 316736]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-17 202256]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-8-12 122880]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 18:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-01-18 16:48 73728 ----a-w- c:\windows\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Sprint\\Sprint SmartView\\SwiApiMux.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\network diagnostic\\xpnetdiag.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/17/2010 10:15 AM 66632]
S3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [10/8/2008 11:27 PM 91830]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2010 10:15 AM 12872]

--- Other Services/Drivers In Memory ---

*Deregistered* - BMLoad
.
Contents of the 'Scheduled Tasks' folder

2010-04-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]

2010-04-04 c:\windows\Tasks\Malwarebytes' Scheduled Update for Tyrone.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2010-03-23 20:07]

2010-04-04 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-09 22:02]

2010-04-04 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]

2010-04-04 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1123561945-1383384898-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]

2010-03-31 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1123561945-1383384898-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
LSP: bmnet.dll
TCP: {24629F3C-1D29-4913-9004-225CEEC14ED9} = 68.28.154.91 68.28.146.91
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.8.1/GarminAxControl.CAB
DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} - hxxp://archives.gametap.com/static/cab_headless/GameTapWebUpdater.cab
FF - ProfilePath - c:\documents and settings\Tyrone\Application Data\Mozilla\Firefox\Profiles\ay8ttjyu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\Tyrone\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Tyrone\Application Data\Move Networks\plugins\npqmp071701000002.dll
FF - HiddenExtension: XULRunner: {A8D53D27-FAD6-4489-8EB3-FAD078422586} - c:\documents and settings\Tyrone\Local Settings\Application Data\{A8D53D27-FAD6-4489-8EB3-FAD078422586}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-04 12:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(880)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\VESWinlogon.dll

- - - - - - - > 'lsass.exe'(936)
c:\windows\system32\bmnet.dll
.
Completion time: 2010-04-04 12:03:36
ComboFix-quarantined-files.txt 2010-04-04 16:03
ComboFix2.txt 2010-04-04 15:03
ComboFix3.txt 2009-04-04 19:16

Pre-Run: 48,790,085,632 bytes free
Post-Run: 48,776,192,000 bytes free

- - End Of File - - C64FB4103106E875AC22028141E1902E
Upload was successful





Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3953

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

4/4/2010 2:09:20 PM
mbam-log-2010-04-04 (14-09-20).txt

Scan type: Full scan (C:\|D:\|E:\|F:\|)
Objects scanned: 152872
Time elapsed: 43 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 4
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\config\systemprofile\Application Data\3122632986 (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\4929826037 (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\5036633230 (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\5105559219 (Rogue.SecurityTool) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\config\systemprofile\Application Data\3122632986\3122632986.bat (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\3122632986\3122632986.cfg (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\4929826037\4929826037.bat (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\4929826037\4929826037.cfg (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\5036633230\5036633230.bat (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\5036633230\5036633230.cfg (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\5105559219\5105559219.bat (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\5105559219\5105559219.cfg (Rogue.SecurityTool) -> Quarantined and deleted successfully.


#8 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:26 PM

Posted 04 April 2010 - 02:11 PM

Thanks for those logs. Let's continue with an online scan now and take another look of your system.

Run ESET Online Scan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the icon on your desktop.
  4. Check
  5. Click the button.
  6. Accept any security warnings from your browser.
  7. Check
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
  11. Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the button.
  13. Push
You can refer to this animation by neomage if needed.

Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Also, let me know how your computer is running and if you have any more problems, issues or symptoms left.

Thanks.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#9 entime

entime
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 05 April 2010 - 10:17 AM

Hi EB

I ran ESET online scan and it didn't find any threats. I was not given the option to perform steps 10 through 12. Below is the DDS log. I'm not getting anymore "RUNDLL" error messages and virus warnings on my computer.


DDS (Ver_10-03-17.01) - NTFSx86
Run by Tyrone at 10:23:04.73 on Mon 04/05/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_19
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.566 [GMT -4:00]

AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Tyrone\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ISBMgr.exe] c:\program files\sony\isb utility\ISBMgr.exe
mRun: [Switcher.exe] c:\program files\sony\wireless switch setting utility\Switcher.exe
mRun: [SonyPowerCfg] c:\program files\sony\vaio power management\SPMgr.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Sprint SmartView] "c:\program files\sprint\sprint smartview\SprintSV.exe" -a
mRun: [RDVCHG] "c:\program files\sprint\sprint smartview\RDVCHG.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: bmnet.dll
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.8.1/GarminAxControl.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} - hxxp://archives.gametap.com/static/cab_headless/GameTapWebUpdater.cab
DPF: {CAFECAFE-0013-0001-0021-ABCDEFABCDEF}
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: VESWinlogon - VESWinlogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\tyrone\applic~1\mozilla\firefox\profiles\ay8ttjyu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\tyrone\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\tyrone\application data\move networks\plugins\npqmp071701000002.dll
FF - HiddenExtension: XULRunner: {A8D53D27-FAD6-4489-8EB3-FAD078422586} - c:\documents and settings\tyrone\local settings\application data\{A8D53D27-FAD6-4489-8EB3-FAD078422586}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 149040]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-2-17 66632]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-3-23 303952]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-3-23 20824]
S3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [2008-10-8 91830]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-2-17 12872]

=============== Created Last 30 ================

2010-04-04 14:53:50 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2010-04-04 14:53:50 50176 ----a-w- c:\windows\system32\proquota.exe
2010-04-04 14:46:43 0 d-sha-r- C:\cmdcons
2010-04-04 14:43:02 77312 ----a-w- c:\windows\MBR.exe
2010-04-04 14:43:01 261632 ----a-w- c:\windows\PEV.exe
2010-03-29 04:07:40 0 ----a-w- c:\documents and settings\tyrone\defogger_reenable
2010-03-29 01:53:06 0 d-----w- c:\program files\Microsoft Security Essentials
2010-03-27 13:57:09 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-03-27 03:59:04 0 d-----w- C:\VundoFix Backups
2010-03-23 15:27:10 0 d-----w- c:\program files\Trend Micro
2010-03-23 13:40:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-23 13:40:05 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-21 16:39:29 0 d-----w- c:\program files\Symantec AntiVirus
2010-03-18 03:31:18 0 d-----w- c:\documents and settings\tyrone\DoctorWeb
2010-03-17 15:28:34 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-03-17 15:28:22 0 d-----w- c:\program files\SUPERAntiSpyware
2010-03-17 15:28:22 0 d-----w- c:\docume~1\tyrone\applic~1\SUPERAntiSpyware.com
2010-03-17 14:51:09 0 d-----w- c:\program files\common files\xing shared
2010-03-16 13:37:13 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-03-16 13:37:13 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-03-15 14:08:42 36488 ----a-w- c:\windows\system32\drivers\klmd.sys
2010-03-14 23:03:55 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-14 22:29:31 0 d-----w- C:\BackUpMSNCleaner
2010-03-10 22:27:38 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 03:16:57 0 d-sh--w- c:\documents and settings\tyrone\IECompatCache
2010-03-06 16:28:01 0 d-sh--w- c:\documents and settings\tyrone\PrivacIE
2010-03-06 16:26:02 0 d-sh--w- c:\documents and settings\tyrone\IETldCache
2010-03-06 16:21:44 0 d-----w- c:\windows\ie8updates
2010-03-06 16:18:00 78336 -c--a-w- c:\windows\system32\dllcache\ieencode.dll
2010-03-06 16:18:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-06 16:12:37 69120 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-03-06 16:12:17 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-03-06 16:12:17 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-03-06 14:24:52 0 d-----w- c:\docume~1\tyrone\applic~1\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

==================== Find3M ====================

2010-03-17 14:50:16 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-11 12:38:54 832512 ------w- c:\windows\system32\wininet.dll
2010-03-11 12:38:51 17408 ----a-w- c:\windows\system32\corpol.dll
2010-03-09 08:28:20 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-06 14:35:41 51672 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-02-24 14:16:06 181632 ------w- c:\windows\system32\MpSigStub.exe
2009-10-04 18:21:30 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat
2008-09-24 02:17:28 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092320080924\index.dat
2009-10-04 18:21:30 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat

============= FINISH: 10:23:57.73 ===============

Attached Files



#10 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:26 PM

Posted 05 April 2010 - 10:29 AM

Looking good.

Just a few things left.

QUOTE
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7

Uninstall those older versions of Java.

Now run GooredFix.

Download and Run GooredFix

Please download GooredFix and save it to your Desktop if you lost your copy.
Alternative Download Mirror #1

Please make sure all instances of Firefox are closed at this point before proceeding.
  • Ensure all Firefox windows are closed at this time.
  • Please double-click GooredFix.exe on your Desktop to run it. If you are using Vista, please right-click and select run as administartor
  • When prompted to run the scan, click Yes.
  • The removal process will begin, please be paitent until it finishes.
  • A log will open with the file after completion, please post the contents of that log in your next reply
*Note: The log can also be found on your desktop called GooredFix.txt
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#11 entime

entime
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 05 April 2010 - 09:59 PM

Okay, I uninstall the older versions of Java and I ran GooredFix below is the log.

GooredFix by jpshortstuff (08.01.10.1)
Log created at 22:51 on 05/04/2010 (Tyrone)
Firefox version 3.5.8 (en-US)

========== GooredScan ==========

Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{A8D53D27-FAD6-4489-8EB3-FAD078422586} -> Success!
Deleting C:\Documents and Settings\Tyrone\Local Settings\Application Data\{A8D53D27-FAD6-4489-8EB3-FAD078422586} -> Success!

========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [17:11 11/05/2008]
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [00:22 10/02/2009]
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [10:42 12/06/2009]
{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [02:58 10/08/2009]
{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [00:18 04/11/2009]
{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} [13:01 31/03/2010]

C:\Documents and Settings\Tyrone\Application Data\Mozilla\Firefox\Profiles\ay8ttjyu.default\extensions\
{635abd67-4fe9-1b23-4f01-e679fa7484c1} [04:23 24/02/2010]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [00:22 10/02/2009]

-=E.O.F=-

#12 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:26 PM

Posted 06 April 2010 - 03:54 PM

That looks good.

Let's clean up now. smile.gif

Please follow/read the steps below to remove the tools we used and for some more information. smile.gif


Uninstall ComboFix

Remove Combofix now that we're done with it.
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
This will uninstall Combofix and anything assoicated with it.

Download and Run OTC

We will now remove the tools we used during this fix using OTC.
  • Download OTC by OldTimer and save it to your desktop.
  • Double click icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.

System A bit Slow? Try StartupLight

You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.

If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.


Congratulations! You now appear clean! specool.gif

Now that you are clean, please follow and read some of the prevention tips below.

Preventing Infections in the Future


Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

Some of the main things you should consider to perform/read are:
  • Disabling Autorun/Play on Flash-Drive/Removable Drives
  • Avoid gaming sites, underground web pages, pirated software sites, and Peer to Peer Programs
  • Keep Windows Updated through going to Windows Updates
  • Updating Non-Microsoft Programs
  • Keeping Security softwares updated

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Update all programs regularly - Make sure you update all the programs you have installed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help and thank you for choosing Bleeping Computer as you malware removal source.
Don't forget to tell your friends about us and Good luck thumbup2.gif


If you have no more questions, comments or problems please tell us, so we can close off the topic.

Thanks smile.gif

With Regards,
Extremeboy

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#13 entime

entime
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:12:26 PM

Posted 06 April 2010 - 11:11 PM

My problem is fix. Thanks you!

#14 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:26 PM

Posted 07 April 2010 - 08:48 PM

You're welcome. smile.gif

Glad I could help out. Stay clean and Happy surfing again.

~Extremeboy

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#15 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:26 PM

Posted 07 April 2010 - 08:56 PM

Hello.

Since the problem appears to be resolved, this topic is now Closed. Glad we could help smile.gif
If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.

This applies only to the original topic starter

Everyone else please start a new topic.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users