Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Multiple Trojan Horse SHeur3.NSG Crypt.QSH


  • This topic is locked This topic is locked
28 replies to this topic

#1 michelle0818

michelle0818

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 02 April 2010 - 06:39 PM

Hello All,

Hubby spent a little 'alone time' with the computer and brought home some nasty bugs! Please help.

Started with the "Anti-Virus Soft" bogus software. I used another machine and followed the removal guide for that and it seemed to work. I am now getting google re-directs, slow downs, and ie crashing.

AVG calls it Trojan HOrse SHeur3.NSG and it has infected MULTIPLE files.
Ran mbam and followed it's advice. Still infected....(attached log)
Ran DDS.

System blue screens (Different error every time) when I try to run GAMR.

Thanks so much in advance...



DDS (Ver_10-03-17.01) - NTFSx86
Run by Michelle at 17:49:26.76 on Fri 04/02/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2038.963 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton PC Checkup\Norton PC Checkup\Engine\2.0.2.506\SymcPCCULaunchSvc.exe
C:\Program Files\Norton PC Checkup\Norton PC Checkup\Engine\2.0.2.506\ccSvcHst.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\U2VSvr.exe
C:\WINDOWS\system32\Tdxvgautil.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Norton PC Checkup\Norton PC Checkup\Engine\2.0.2.506\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\OEM02Mon.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Logitech\SetPoint\LU\LULnchr.exe
C:\Program Files\Logitech\SetPoint\LU\LogitechUpdate.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Safari\Safari.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Michelle\My Documents\remove\dds.scr

============== Pseudo HJT Report ===============

uLocal Page = \blank.htm
uStart Page = hxxp://dallas.craigslist.org/
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6080408
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uURLSearchHooks: Feboz Toolbar: {f2257711-226b-4529-8e1d-e82e1c55ebd8} - c:\program files\feboz\tbFebo.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Feboz Toolbar: {f2257711-226b-4529-8e1d-e82e1c55ebd8} - c:\program files\feboz\tbFebo.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Feboz Toolbar: {f2257711-226b-4529-8e1d-e82e1c55ebd8} - c:\program files\feboz\tbFebo.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [DELL Webcam Manager] "c:\program files\dell\dell webcam manager\DellWMgr.exe" /s
mRun: [<NO NAME>]
mRun: [KADxMain] c:\windows\system32\KADxMain.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [dlcxmon.exe] "c:\program files\dell photo aio printer 926\dlcxmon.exe"
mRun: [MemoryCardManager] "c:\program files\dell photo aio printer 926\memcard.exe"
mRun: [FaxCenterServer] "c:\program files\dell pc fax\fm3032.exe" /s
mRun: [Corel Photo Downloader] c:\program files\corel\corel photo album 6\MediaDetect.exe
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: intuit.com\ttlc
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {94B82441-A413-4E43-8422-D49930E69764} - hxxps://chat1.j2.com/Media/VisitorchatEnu/TLIEFlash.CAB
DPF: {A4110378-789B-455F-AE86-3A1BFC402853} - hxxp://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} - hxxp://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - hxxps://signin3.valueactive.eu/Register/Branding/olr3313/OCX/v1018/flashax.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://fortunelounge.gameassists.co.uk/generic/FlashAX2.cab
TCP: NameServer = 93.188.162.172,93.188.166.21
TCP: {1C8D8D10-F01B-4FC0-9B41-E5F24FA87A55} = 93.188.162.172,93.188.166.21
TCP: {59ADFD3A-CEF6-4F41-9CCF-B27CE19A12AC} = 93.188.162.172,93.188.166.21
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
AppInit_DLLs: aLynGRJTV.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-3-21 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-3-21 29512]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-3-21 242696]
R1 oreans32;oreans32;c:\windows\system32\drivers\oreans32.sys [2008-10-31 33824]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-3-21 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-21 308064]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\norton pc checkup\norton pc checkup\engine\2.0.2.506\SymcPCCULaunchSvc.exe [2009-12-9 103280]
R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\norton pc checkup\norton pc checkup\engine\2.0.2.506\ccSvcHst.exe [2009-12-9 126392]
R2 U2VSvr;U2VSvr;c:\windows\system32\U2VSvr.exe [2009-10-17 172032]
R3 NWDellModem;Dell Wireless Mobile Broadband Modem Driver;c:\windows\system32\drivers\nwdelmdm.sys [2008-4-8 92288]
R3 NWDellPort;Dell Wireless Mobile Broadband Status Port Driver;c:\windows\system32\drivers\nwdelser.sys [2008-4-8 92288]
R3 TdxMrMINI;TdxMrMINI;c:\windows\system32\drivers\TdxMrMini.sys [2009-10-17 247808]
R3 TdxVGAMINI;TdxVGAMINI;c:\windows\system32\drivers\TdxVgaMini.sys [2009-10-17 253184]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-4 135664]
S3 ADM851X;ADM851X USB To Fast Ethernet Adapter;c:\windows\system32\drivers\ADM851X.sys [2009-10-17 22144]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-4-8 30192]
S3 NW001NDIS;Dell Wireless Network Adapter Service;c:\windows\system32\drivers\nw01ndis.sys [2007-6-1 210432]
S3 TdxVGAUSB;TARGUS USB 2.0 VGA DOCK DEVICE(USB);c:\windows\system32\drivers\TdxVGAUSB.SYS [2009-10-17 34944]

=============== Created Last 30 ================

2010-04-02 17:51:23 0 d-----w- C:\.jagex_cache_32
2010-04-02 14:43:21 69 ----a-w- c:\documents and settings\michelle\jagex_runescape_preferences2.dat
2010-04-02 14:43:21 0 ----a-w- c:\documents and settings\michelle\jagex__preferences3.dat
2010-04-02 14:42:25 41 ----a-w- c:\documents and settings\michelle\jagex_runescape_preferences.dat
2010-04-02 14:42:11 0 d-----w- c:\windows\.jagex_cache_32
2010-03-21 19:54:29 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-21 19:32:11 0 d--h--w- C:\$AVG
2010-03-21 19:31:58 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-21 19:31:52 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-21 19:31:44 0 d-----w- c:\windows\system32\drivers\Avg
2010-03-21 19:31:29 0 d-----w- c:\program files\AVG
2010-03-21 19:31:26 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-03-21 16:10:28 0 d-----w- c:\windows\pss
2010-03-21 15:42:34 0 d-----w- c:\docume~1\michelle\applic~1\Malwarebytes
2010-03-21 15:42:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-21 15:42:28 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-21 15:42:28 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-21 15:42:28 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-21 07:15:31 0 d-----w- C:\7a11e2ac5ce6594d941b69
2010-03-12 19:28:44 1089601 ------w- c:\windows\system32\dllcache\ntprint.cat
2010-03-12 18:22:18 0 d-----w- c:\docume~1\michelle\applic~1\Intuit
2010-03-12 18:22:13 0 d-----w- c:\program files\common files\AnswerWorks 5.0
2010-03-12 18:18:04 0 d-----w- c:\program files\common files\Intuit
2010-03-12 18:17:31 0 d-----w- c:\program files\TurboTax
2010-03-12 18:07:34 0 d-----w- c:\windows\system32\XPSViewer
2010-03-12 18:06:08 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-12 18:06:08 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-12 18:06:08 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-03-12 18:06:08 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-12 18:06:08 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-03-12 18:06:08 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-03-12 18:06:08 117760 ------w- c:\windows\system32\prntvpt.dll
2010-03-12 18:06:07 0 d-----w- C:\f985ebd5697339c131d7
2010-03-12 17:59:07 0 d-----w- c:\docume~1\alluse~1\applic~1\Intuit
2010-03-09 19:25:55 3555328 ------w- c:\windows\system32\dllcache\moviemk.exe

==================== Find3M ====================

2010-03-26 03:11:38 7308 --sha-w- c:\windows\system32\KGyGaAvL.sys
2010-03-21 17:09:47 29508 ---ha-w- c:\windows\system32\mlfcache.dat
2008-04-08 19:55:54 76 --sh--r- c:\windows\CT4CET.bin
2008-05-11 20:23:18 56 --sh--r- c:\windows\system32\7AB53E9577.sys
2008-08-12 20:31:32 56 --sh--r- c:\windows\system32\AA6DB7B3FE.sys
2009-11-19 15:54:12 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009111920091120\index.dat

============= FINISH: 17:50:28.96 ===============


BC AdBot (Login to Remove)

 


#2 michelle0818

michelle0818
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 05 April 2010 - 07:20 AM


Do not mean to pester, but I am in serious trouble with this virus. Thanks again in advance.
Posted new DDS and attach

Running XP HOme Version 2002
SP2

Safari

Windows firewall

AVG Free







DDS (Ver_10-03-17.01) - NTFSx86

Run by Michelle at 6:53:50.37 on Mon 04/05/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2038.1319 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton PC Checkup\Norton PC Checkup\Engine\2.0.2.506\SymcPCCULaunchSvc.exe
C:\Program Files\Norton PC Checkup\Norton PC Checkup\Engine\2.0.2.506\ccSvcHst.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\U2VSvr.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton PC Checkup\Norton PC Checkup\Engine\2.0.2.506\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\OEM02Mon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Michelle\My Documents\remove\dds.scr

============== Pseudo HJT Report ===============

uLocal Page = \blank.htm
uStart Page = hxxp://dallas.craigslist.org/
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6080408
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uURLSearchHooks: Feboz Toolbar: {f2257711-226b-4529-8e1d-e82e1c55ebd8} - c:\program files\feboz\tbFebo.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Feboz Toolbar: {f2257711-226b-4529-8e1d-e82e1c55ebd8} - c:\program files\feboz\tbFebo.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Feboz Toolbar: {f2257711-226b-4529-8e1d-e82e1c55ebd8} - c:\program files\feboz\tbFebo.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [DELL Webcam Manager] "c:\program files\dell\dell webcam manager\DellWMgr.exe" /s
mRun: [<NO NAME>]
mRun: [KADxMain] c:\windows\system32\KADxMain.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [dlcxmon.exe] "c:\program files\dell photo aio printer 926\dlcxmon.exe"
mRun: [MemoryCardManager] "c:\program files\dell photo aio printer 926\memcard.exe"
mRun: [FaxCenterServer] "c:\program files\dell pc fax\fm3032.exe" /s
mRun: [Corel Photo Downloader] c:\program files\corel\corel photo album 6\MediaDetect.exe
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: intuit.com\ttlc
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {94B82441-A413-4E43-8422-D49930E69764} - hxxps://chat1.j2.com/Media/VisitorchatEnu/TLIEFlash.CAB
DPF: {A4110378-789B-455F-AE86-3A1BFC402853} - hxxp://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} - hxxp://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - hxxps://signin3.valueactive.eu/Register/Branding/olr3313/OCX/v1018/flashax.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://fortunelounge.gameassists.co.uk/generic/FlashAX2.cab
TCP: NameServer = 93.188.162.172,93.188.166.21
TCP: {1C8D8D10-F01B-4FC0-9B41-E5F24FA87A55} = 93.188.162.172,93.188.166.21
TCP: {59ADFD3A-CEF6-4F41-9CCF-B27CE19A12AC} = 93.188.162.172,93.188.166.21
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
AppInit_DLLs: aLynGRJTV.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-3-21 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-3-21 29512]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-3-21 242696]
R1 oreans32;oreans32;c:\windows\system32\drivers\oreans32.sys [2008-10-31 33824]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-3-21 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-21 308064]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\norton pc checkup\norton pc checkup\engine\2.0.2.506\SymcPCCULaunchSvc.exe [2009-12-9 103280]
R2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\norton pc checkup\norton pc checkup\engine\2.0.2.506\ccSvcHst.exe [2009-12-9 126392]
R2 U2VSvr;U2VSvr;c:\windows\system32\U2VSvr.exe [2009-10-17 172032]
R3 NWDellModem;Dell Wireless Mobile Broadband Modem Driver;c:\windows\system32\drivers\nwdelmdm.sys [2008-4-8 92288]
R3 NWDellPort;Dell Wireless Mobile Broadband Status Port Driver;c:\windows\system32\drivers\nwdelser.sys [2008-4-8 92288]
R3 TdxMrMINI;TdxMrMINI;c:\windows\system32\drivers\TdxMrMini.sys [2009-10-17 247808]
R3 TdxVGAMINI;TdxVGAMINI;c:\windows\system32\drivers\TdxVgaMini.sys [2009-10-17 253184]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-4 135664]
S3 ADM851X;ADM851X USB To Fast Ethernet Adapter;c:\windows\system32\drivers\ADM851X.sys [2009-10-17 22144]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-4-8 30192]
S3 NW001NDIS;Dell Wireless Network Adapter Service;c:\windows\system32\drivers\nw01ndis.sys [2007-6-1 210432]
S3 TdxVGAUSB;TARGUS USB 2.0 VGA DOCK DEVICE(USB);c:\windows\system32\drivers\TdxVGAUSB.SYS [2009-10-17 34944]

=============== Created Last 30 ================

2010-04-02 23:19:46 0 ----a-w- c:\documents and settings\michelle\defogger_reenable
2010-04-02 17:51:23 0 d-----w- C:\.jagex_cache_32
2010-04-02 14:43:21 69 ----a-w- c:\documents and settings\michelle\jagex_runescape_preferences2.dat
2010-04-02 14:43:21 0 ----a-w- c:\documents and settings\michelle\jagex__preferences3.dat
2010-04-02 14:42:25 41 ----a-w- c:\documents and settings\michelle\jagex_runescape_preferences.dat
2010-04-02 14:42:11 0 d-----w- c:\windows\.jagex_cache_32
2010-03-21 19:54:29 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-21 19:32:11 0 d--h--w- C:\$AVG
2010-03-21 19:31:58 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-21 19:31:52 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-21 19:31:44 0 d-----w- c:\windows\system32\drivers\Avg
2010-03-21 19:31:29 0 d-----w- c:\program files\AVG
2010-03-21 19:31:26 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-03-21 16:10:28 0 d-----w- c:\windows\pss
2010-03-21 15:42:34 0 d-----w- c:\docume~1\michelle\applic~1\Malwarebytes
2010-03-21 15:42:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-21 15:42:28 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-21 15:42:28 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-21 15:42:28 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-21 07:15:31 0 d-----w- C:\7a11e2ac5ce6594d941b69
2010-03-12 19:28:44 1089601 ------w- c:\windows\system32\dllcache\ntprint.cat
2010-03-12 18:22:18 0 d-----w- c:\docume~1\michelle\applic~1\Intuit
2010-03-12 18:22:13 0 d-----w- c:\program files\common files\AnswerWorks 5.0
2010-03-12 18:18:04 0 d-----w- c:\program files\common files\Intuit
2010-03-12 18:17:31 0 d-----w- c:\program files\TurboTax
2010-03-12 18:07:34 0 d-----w- c:\windows\system32\XPSViewer
2010-03-12 18:06:08 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-12 18:06:08 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-12 18:06:08 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-03-12 18:06:08 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-12 18:06:08 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-03-12 18:06:08 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-03-12 18:06:08 117760 ------w- c:\windows\system32\prntvpt.dll
2010-03-12 18:06:07 0 d-----w- C:\f985ebd5697339c131d7
2010-03-12 17:59:07 0 d-----w- c:\docume~1\alluse~1\applic~1\Intuit
2010-03-09 19:25:55 3555328 ------w- c:\windows\system32\dllcache\moviemk.exe

==================== Find3M ====================

2010-03-26 03:11:38 7308 --sha-w- c:\windows\system32\KGyGaAvL.sys
2010-03-21 17:09:47 29508 ---ha-w- c:\windows\system32\mlfcache.dat
2008-04-08 19:55:54 76 --sh--r- c:\windows\CT4CET.bin
2008-05-11 20:23:18 56 --sh--r- c:\windows\system32\7AB53E9577.sys
2008-08-12 20:31:32 56 --sh--r- c:\windows\system32\AA6DB7B3FE.sys
2009-11-19 15:54:12 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009111920091120\index.dat

============= FINISH: 6:57:08.71 ===============

Attached Files



#3 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,688 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:50 PM

Posted 05 April 2010 - 11:29 AM

Hi michelle0818,

Welcome to Virus/Trojan/Spyware/Malware Removal (VTSMR) forum. I am going to assist you with your problem.

Please refrain from making any changes to your system (scanning or running other tools, updating Windows, installing applications, removing files, etc.) from now on as it might interfere with our fixes. Please let me know in your next reply if you agree with this.
  1. Open a notepad (Start > Run and type in Notepad )

    Copy and paste the text in code box into it.

    CODE
    REGEDIT4


    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
    "NameServer"=-

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{59ADFD3A-CEF6-4F41-9CCF-B27CE19A12AC}]
    "NameServer"=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1C8D8D10-F01B-4FC0-9B41-E5F24FA87A55}]
    "NameServer"=""

    [HKEY_CURRENT_USSER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable"=-

    [HKEY_CURRENT_USSER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyServer "=-

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "appinit_dlls"=""
    • Save the file to the desktop as regfix.reg
    • Make sure the Save as type field says All files.
    • Locate regfix.reg on the desktop and double-click on it and confirm. It should look like
    • A window pops up asking if you are sure to add the file to the registry. Click Yes.
    • You get another window popup saying that regfix.reg successfully added to the registry.
    Note: You have to turn off any registry protector software you have in order the changes to be taken place.

  2. Make sure the following setting is set as it is supposed to be set:
    • Go to Start -> Control Panel -> Double click on Network Connections.
    • Right click on your default connection (usually Local Area Connection) and select Properties.
    • Select the General tab.
    • Double click on Internet Protocol (TCP/IP).
      Under General tab:
      • Select "Obtain an IP address automatically".
      • Select "Obtain DNS server address automatically".
    • Click OK twice to save the settings.
    • Reboot if you had to change any setting.

  3. Disable AVG Resident Shield:
    • Double click AVG system tray icon to open AVG.
    • In Overview section double click Resident Shield.
    • Uncheck Resident Shield Active.
    • Press Save Changes.

  4. Download the GMER Rootkit Scanner exe file from here and save it to your desktop.
    • Temporarily disable any real-time active protection so your security program drivers will not conflict with gmer's driver.
    • Click on this link to see a list of programs that should be disabled.
    • Disconnect from the Internet and close all running programs.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
    • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
    • In the right panel, you will see several boxes that have been checked. Make sure the following are unchecked:
      • Devices.
      • Drives/Partition other than C:\ drive (C:\ drive should remain checked)
      • Show All (this one also should be unchecked)
    • Then click the Scan button & wait for it to begin. (Please be patient as it can take some time to complete).
    • When the scan is finished, you will see the scan button appears again. Click Save to save the scan results to your Desktop.
    • Save the file as gmer.log and copy/paste the contents in your next reply.

Edited by farbar, 05 April 2010 - 12:13 PM.


#4 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,688 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:50 PM

Posted 05 April 2010 - 12:14 PM

It is important to activate the resident shield immediately GMER produced its log before connecting to internet again.

#5 michelle0818

michelle0818
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 05 April 2010 - 12:33 PM

Thank you so very much! Following instructions and will post back shortly!

#6 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,688 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:50 PM

Posted 05 April 2010 - 12:43 PM

thumbup2.gif

#7 michelle0818

michelle0818
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 05 April 2010 - 05:11 PM

Hey FB,

Running GMER and after 6 hrs it seems to have frozen in place. The machine will still respond very very slowly, but no movement on the gmer program. Should I leave it alone?

OK...edited to say.... system froze....tried running gmer 3 more times and blue screened each time.

Also, not sure if it's relevant, but I tried to boot in safe mode, and just got a blue screen...litteraly a blue screen with no writing or anything. (all three safe modes)

This is such a mess......

Thanks again

Edited by michelle0818, 05 April 2010 - 07:54 PM.


#8 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,688 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:50 PM

Posted 06 April 2010 - 03:07 AM

Did you disabled AVG resident shield?
Did you uncheck the Devices section of GMER?
  1. Open your Malwarebytes' Anti-Malware.
    • First update it, to do that under the Update tab press "Check for Updates".
    • Under Scanner tab select "Perform Quick Scan", then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the MBAM log.

    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.



  2. Download ComboFix from one of these locations:

    Link 1
    Link 2
    Link 3

    * IMPORTANT !!! Save ComboFix.exe to your Desktop

    • Disable your AntiVirus and AntiSpyware applications. They may otherwise interfere with our tools. (Information on A/V control HERE)
    • Double click on ComboFix.exe & follow the prompts.
    • You will get a warning about the not trusted download sites for ComboFix, click Yes.
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please copy and paste the C:\ComboFix.txt in your next reply.



#9 michelle0818

michelle0818
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 06 April 2010 - 07:16 AM

Good Morning,

Yes AVG was disabled.
Yes Devices were unchecked.

Before bed last night I unchecked the Services in gmer just to see what would happen and I woke up this AM to a good scan! It took all night and did not produce much. Not sure if this will help with out services checked. Do you still want me to continue with the combo fix now?




GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-06 07:03:46
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Michelle\LOCALS~1\Temp\kxtdqpog.sys


---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Aces High II@DisplayName Aces High II
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Aces High II@UninstallString C:\PROGRA~1\HTC\ACESHI~1\UNWISE.EXE C:\PROGRA~1\HTC\ACESHI~1\INSTALL.LOG
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSNINST@DisplayName MSN
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSNINST@UninstallString C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MSNINST@DisplayIcon C:\Program Files\MSN\MsnInstaller\msnms.ico

---- EOF - GMER 1.0.15 ----


#10 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,688 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:50 PM

Posted 06 April 2010 - 07:29 AM

Well done. thumbup2.gif

Please proceed with everything including ComboFix.

#11 michelle0818

michelle0818
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 06 April 2010 - 09:59 AM

Ok...

I was able to run mbam the log is attached.

I had not re-enabled AVG but I verified the Resident Sheild was still not active. ComboFix will not run. I click on the icon, combofix square comes up, the green dots proceed and it freezes up the system.

I still can not boot in any safe mode (plain blue screen).


M

Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3930

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

4/6/2010 9:18:57 AM
mbam-log-2010-04-06 (09-18-57).txt

Scan type: Quick scan
Objects scanned: 172661
Time elapsed: 38 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\WEK9EMDHI9 (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Michelle\Local Settings\Temp\3tr3xo6z.tmp\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.

Edited by michelle0818, 06 April 2010 - 11:34 AM.


#12 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,688 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:50 PM

Posted 06 April 2010 - 10:29 AM

MBAM is not updated fully. Did you have any trouble updating it?

#13 michelle0818

michelle0818
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 06 April 2010 - 10:41 AM

It said it updated fine...downloaded and installed..I had to re-start mbam before i was able to run the scan...

Re-connected to internet, updated again went from 3930 to 3960. I am re-scanning. I also just uninstalled an old version of norton PC check up and AVG and will try combofix again when mbam finishes.

Thanks for keeping up!

michelle

Edited by michelle0818, 06 April 2010 - 10:51 AM.


#14 michelle0818

michelle0818
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:08:50 AM

Posted 06 April 2010 - 11:33 AM

OK here we go...

New MBAM included (nothing found this scan)

uninstalled AVG and old Norton PC checkup that was on system and Combofix will still not run...

Found thes running in services with msconfig (U2VSvr stllssvr dlcx_device) not sure what any of them are. I will do nothing with them until I hear back.

Not sure if it will help, but I was able to get a hijack this log. I have attached it.


M


Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3960

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

4/6/2010 11:26:44 AM
mbam-log-2010-04-06 (11-26-44).txt

Scan type: Quick scan
Objects scanned: 163914
Time elapsed: 23 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Attached Files


Edited by michelle0818, 06 April 2010 - 12:43 PM.


#15 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,688 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:50 PM

Posted 06 April 2010 - 01:27 PM

You should be connected to internet while running the test.bat file.
  1. Go to start > Run copy and paste the following line in the run box and click OK:

    Reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyServer /f

    A window flashes it is normal.

  2. Please run Notepad (start > All Programs > Accessories > Notepad) and copy and paste the text in the code box into a new file:


    CODE
    @echo off
    (ipconfig /all
    nslookup google.com
    ping -n 2 google.com
    nslookup yahoo.com
    ping -n 2 yahoo.com
    route print) >Log1.txt
    dir  /a/od/s  c:\mini*.dmp >>log.txt 2>&1
    start Log1.txt

    • Go to the File menu at the top of the Notepad and select Save as.
    • Select save in: desktop
    • Fill in File name: test.bat
    • Save as type: All file types (*.*)
    • Click save.
    • Close the Notepad.
    • Locate and double-click test.bat on the desktop.
    • A notepad opens, copy and paste the content it (log.txt) to your reply.

  3. You need to install at least one antivirus. If you wanted you can keep AVG otherwise I recommend this good free antivirus:

    Avira
    • Download the installer from softpedia.com link as it has a secure download mirror. Install and update it.
    • In the left pane click Status. In the right pane click Scan system now.
    • After the scan finished let it remove what it finds and then Click Report.
    • You can get the last report also by clicking on Reports on the left pane.
    • In the right window under Action double-click on the last Scan listed (you see also the corresponding Dat/Time).
    • A window opens, click on Report file.
    • Copy and paste the content of the report to your reply.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users