Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4324
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
7/18/2010 11:34:13 AM
mbam-log-2010-07-18 (11-34-13).txt
Scan type: Full scan (C:\|)
Objects scanned: 176358
Time elapsed: 20 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: 93.188.166.105 93.188.161.105 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{c63cd119-5144-4b6f-ac29-f14726d492ad}\DhcpNameServer (Trojan.DNSChanger) -> Data: 93.188.166.105 93.188.161.105 -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Here are the other logs asked to run in the preparation guide;
DDS
DDS (Ver_10-03-17.01) - NTFSx86
Run by Rick at 13:33:09.29 on Sun 07/18/2010
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.660 [GMT -7:00]
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\TDispVol.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\DLACTRLW.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Rick\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://my.yahoo.com/
uSearch Bar = hxxp://www.toshiba.com/search
mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
uInternet Connection Wizard,ShellNext = "c:\program files\outlook express\msimn.exe"
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [TDispVol] TDispVol.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [THotkey] c:\program files\toshiba\toshiba applet\thotkey.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [LtMoh] c:\program files\ltmoh\Ltmoh.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [Tvs] c:\program files\toshiba\tvs\TvsTray.exe
mRun: [TPSMain] TPSMain.exe
mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
mRun: [dla] c:\windows\system32\dla\DLACTRLW.exe
mRun: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_04\bin\npjpi150_04.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
Notify: igfxcui - igfxdev.dll
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-7-11 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-7-11 17744]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-11 40384]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-11 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-11 40384]
=============== Created Last 30 ================
2010-07-18 20:30:52 0 ----a-w- c:\documents and settings\rick\defogger_reenable
2010-07-11 19:06:27 3833 ----a-w- c:\windows\machine.ver
2010-07-11 18:18:34 0 d-----w- c:\windows\system32\appmgmt
2010-07-11 18:15:15 2 ----a-w- c:\windows\msoffice.ini
2010-07-11 18:11:42 38848 ----a-w- c:\windows\avastSS.scr
2010-07-11 18:11:30 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-07-11 17:46:19 0 d-----w- c:\program files\SmartPCTools
2010-07-11 17:29:20 0 d-----w- c:\program files\Trend Micro
2010-07-11 16:40:36 0 d-----w- c:\docume~1\rick\applic~1\Malwarebytes
2010-07-11 16:40:29 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-11 16:40:28 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-07-11 16:40:27 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-11 16:40:27 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-11 04:44:01 0 d-----w- c:\docume~1\rick\applic~1\You've Got Pictures Screensaver
2010-07-11 04:44:01 0 d-----w- c:\docume~1\rick\applic~1\Intel
2010-07-11 04:44:01 0 d-----w- c:\docume~1\rick\applic~1\AOL
2010-07-11 04:43:05 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-07-11 04:36:47 8192 ----a-w- c:\windows\REGLOCS.OLD
2010-07-11 04:34:32 61 ----a-w- c:\windows\smscfg.ini
2010-07-11 04:32:53 0 d-----w- c:\program files\AVerMedia
2010-07-11 04:32:35 69632 ----a-r- c:\windows\system32\MCSysUtil.dll
2010-07-11 04:32:35 50176 ----a-w- c:\windows\system32\CSH.DLL
2010-07-11 04:32:35 4528 ----a-r- c:\windows\system32\SETBROWS.EXE
2010-07-11 04:32:35 163840 ----a-w- c:\windows\system32\MCCoreUtil.dll
2010-07-11 04:32:35 135168 ----a-w- c:\windows\system32\XML30Lib.dll
2010-07-11 04:32:32 0 d-----w- c:\program files\Metamail Inc
2010-07-11 04:32:00 0 d-----w- c:\program files\common files\InterVideo
2010-07-11 04:31:22 135168 ----a-w- c:\windows\system32\igfxres.dll
2010-07-11 04:29:29 126 ----a-w- c:\docume~1\rick\applic~1\wklnhst.dat
2010-07-11 04:28:22 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2010-07-11 04:28:22 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-07-11 04:28:08 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2010-07-11 04:28:08 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-07-11 04:20:31 0 d-----w- c:\windows\system32\LogFiles
2010-07-11 04:18:19 0 d-s---w- c:\documents and settings\rick\UserData
==================== Find3M ====================
============= FINISH: 13:33:33.67 ===============