Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan(s?) Keep Coming Back


  • This topic is locked This topic is locked
2 replies to this topic

#1 gazaway

gazaway

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:08:37 PM

Posted 20 November 2010 - 01:51 PM

I've been working on a user's laptop (Win XP SP3) that wouldn't boot, even into safe mode. I ran a windows repair from a Win SP SP3 installation CD, which allowed me to at least get into safe mode. There I found several trojans and viruses, including (these are Symantec names) Trojan.FakeAV!gen29, W32.Harakit, Trojan.Gen, Trojan.FakeAV. After cleaning, Malwarebytes found registry entries for Hijack.FolderOptions and Trojan.Agent. Finally satisfied that the system was clean, I restored the drivers and downloaded and installed all the Windows updates. Both processes required several reboots. I then returned the laptop to the user. Unfortunately, I made the mistake of not running final scans of the system first. But there had been no symptoms during the system restoration, so I was lulled into what was obviously a false sense of security.

Immediately after booting the system the next day, he got an alert from Symantec AV about two infected files: DWH9F.tmp and DWH1E.tmp, both in his profile's Local Settings\Temp folder. They were identified only as "Trojans" - no specifics. He was not yet connected to the internet and had no external devices attached. Laptop back to me. Malwarebytes found two infected registry items: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost (Trojan.Agent) and HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Trojan.Agent).

I'm concerned that there is something else lurking on the system that I failed to clean, something that is continuing to download trojans. The DDS.txt file is included below and I am attaching the attach.txt and ark.txt files (the latter was too big to upload, so I zipped it).

Thanks in advance for any advice you can offer me!

------------ DDS.txt file -------------------

DDS (Ver_10-11-10.01) - NTFSx86
Run by jhm at 13:18:45.32 on Fri 11/19/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1242 [GMT -7:00]

AV: Security Master AV *On-access scanning enabled* (Updated) {2A0973AE-99E0-49B3-B59F-79AE42A06081}
AV: Symantec Endpoint Protection *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Security Master AV *enabled* {5C46EFFB-BB9B-41D9-854C-F44AA1601655}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Symantec AntiVirus\Smc.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k eapsvcs
svchost.exe
C:\WINDOWS\System32\svchost.exe -k dot3svc
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Altiris\AClient\AClient.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Wave Systems Corp\Common\DataServer.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec AntiVirus\SmcGui.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\dpmw32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\iprntctl.exe
C:\WINDOWS\system32\iprntlgn.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Altiris\AClient\AClntUsr.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\I8kfanGUI\I8kfanGUI.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\jhm\Desktop\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.byu.edu/webapp/home/index.jsp
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = http=127.0.0.1:50370
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: WhiteSmoke Toolbar: {52794457-af6c-4c50-9def-f2e24f4c8889} - c:\program files\whitesmoketoolbar\whitesmoketoolbarX.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: WhiteSmoke Toolbar: {52794457-af6c-4c50-9def-f2e24f4c8889} - c:\program files\whitesmoketoolbar\whitesmoketoolbarX.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [i8kfangui] c:\program files\i8kfangui\I8kfanGUI.exe /startup
uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup
mRun: [NWTRAY] NWTRAY.EXE
mRun: [SansaDispatch] c:\program files\sandisk\sansa updater\SansaDispatch.exe
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NDPS] c:\windows\system32\dpmw32.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -startup
mRun: [iPrint Tray] c:\windows\system32\iprntctl.exe TRAY_ICON
mRun: [iPrint Event Monitor] c:\windows\system32\iprntlgn.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [Document Manager] c:\program files\wave systems corp\services manager\docmgr\bin\docmgr.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [AClntUsr] c:\program files\altiris\aclient\AClntUsr.EXE
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\toshiba\bluetooth toshiba stack\TosBtMng.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\embass~1.lnk - c:\program files\wave systems corp\services manager\secure update\AutoUpdate.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{21e247d4-5e27-4bea-aa4d-19a81203fe2a}\Icon3E5562ED7.ico
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
mPolicies-system: CompatibleRUPSecurity = 1 (0x1)
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: %SYSTEMROOT%\system32\biolsp.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://tky09.celartem.com/en/download/data/djvu_autoinstall/DjVuControl_en_US.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: {4D2D3A17-9B46-483C-A5F4-1DC471080009} - hxxps://nac1.app.byu.edu/auth/taweb.cab
DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://www.nick.com/common/groove/gx/GrooveAX27.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe
AppInit_DLLs: wxvault.dll woyohipo.dll c:\windows\system32\zahasila.dll c:\windows\system32\
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: vavugipum - {69e414b3-0991-46f2-84d7-4a5006ec9807} - No File
STS: {8a422564-d751-497c-a0a8-93d58e679eac} - No File
STS: {69e414b3-0991-46f2-84d7-4a5006ec9807} - No File
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Authentication Packages = msv1_0 nwv1_0
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 128.187.67.3 geont3.byu.edu

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jhm\applic~1\mozilla\firefox\profiles\0wunj4ns.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\jhm\application data\move networks\plugins\npqmp071500000347.dll
FF - plugin: c:\documents and settings\jhm\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\jhm\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\virtools\3d life player\npvirtools.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified

============= SERVICES / DRIVERS ===============

R1 fanio;FanIO driver;c:\windows\system32\drivers\fanio.sys [2008-7-12 14464]
R1 nipplpt2;Novell iCapture Lpt Redirector 2;c:\windows\system32\drivers\nipplpt.sys [2007-3-27 34671]
R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2005-10-18 61440]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2010-4-26 108392]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2010-4-26 108392]
R2 SentinelKeysServer;Sentinel Keys Server;c:\program files\common files\safenet sentinel\sentinel keys server\sntlkeyssrvr.exe [2008-7-11 328992]
R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec antivirus\Rtvscan.exe [2010-4-26 1822296]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-28 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20101117.019\NAVENG.SYS [2010-11-18 86064]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20101117.019\NAVEX15.SYS [2010-11-18 1371184]
S0 xqkf;xqkf;c:\windows\system32\drivers\efwcnhxl.sys --> c:\windows\system32\drivers\efwcnhxl.sys [?]
S0 zsritjzmu;zsritjzmu; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-5 135664]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2009-4-20 23888]
S3 ne2000;Novell/Eagle NE2000 Adapter Driver;c:\windows\system32\drivers\ne2000.sys [2001-8-17 15872]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-11-14 394952]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

=============== Created Last 30 ================

2010-11-19 16:32:44 -------- d-----w- c:\docume~1\jhm\applic~1\Windows Search
2010-11-17 21:51:40 -------- d-----w- c:\docume~1\jhm\applic~1\WhiteSmokeTranslator
2010-11-17 21:13:15 -------- d-----w- c:\windows\system32\winrm
2010-11-17 21:13:11 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2010-11-17 21:12:31 -------- d-----w- c:\docume~1\jhm\applic~1\Windows Desktop Search
2010-11-17 21:11:53 -------- d-----w- c:\windows\system32\GroupPolicy
2010-11-17 21:11:53 -------- d-----w- c:\program files\Windows Desktop Search
2010-11-17 21:07:02 13312 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-11-17 20:38:27 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-11-17 20:38:27 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-11-17 20:38:26 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-11-17 20:38:26 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-11-17 20:38:25 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-11-17 20:38:24 1986560 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-11-17 20:38:21 11080192 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-11-17 20:01:19 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-17 20:01:19 472808 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2010-11-17 18:58:34 -------- d-----w- c:\docume~1\jhm\locals~1\applic~1\Mozilla
2010-11-17 17:42:04 457 ----a-w- c:\windows\system32\vcredist_x86.bat
2010-11-17 17:42:04 2682880 ----a-w- c:\windows\system32\vcredist_x86.exe
2010-11-17 17:42:01 155648 ----a-w- c:\windows\system32\bcmwlapi.dll
2010-11-17 17:38:30 217185 ----a-w- c:\windows\system32\GTDownDE_130.ocx
2010-11-17 17:37:51 -------- d-----w- c:\program files\Dell Support
2010-11-17 17:35:39 147456 ----a-w- c:\windows\system32\nvcolor.exe
2010-11-17 17:35:37 327680 ----a-w- c:\windows\system32\nvwrsesm.dll
2010-11-17 17:35:37 294912 ----a-w- c:\windows\system32\nvwrspl.dll
2010-11-17 17:35:37 2670592 ----a-w- c:\windows\system32\nvwssr.dll
2010-11-17 17:35:37 2629632 ----a-w- c:\windows\system32\nvwss.dll
2010-11-17 17:35:35 274432 ----a-w- c:\windows\system32\nvrsesm.dll
2010-11-17 17:35:35 258048 ----a-w- c:\windows\system32\nvrspl.dll
2010-11-17 17:35:34 1241088 ----a-w- c:\windows\system32\nvcuda.dll
2010-11-17 17:32:48 666 ----a-w- c:\windows\speed.reg
2010-11-17 17:31:13 146944 ----a-w- c:\windows\system32\st325602.dll
2010-11-17 17:21:18 -------- d-----w- c:\program files\Digital Line Detect
2010-11-17 15:58:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-11-17 15:56:12 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-11-17 15:51:15 2146304 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-11-17 15:51:14 2189952 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-11-17 15:51:14 2066816 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-11-17 15:51:14 2024448 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-11-17 15:47:55 -------- d-----w- c:\docume~1\jhm\applic~1\Dell
2010-11-17 15:47:51 61440 ----a-w- c:\windows\system32\KPower.dll
2010-11-17 15:47:51 307200 ----a-w- c:\windows\system32\BMAPI.dll
2010-11-17 15:47:51 233472 ----a-w- c:\windows\system32\NicConfigSvc.cpl
2010-11-17 15:47:25 16128 ----a-w- c:\windows\system32\drivers\APPDRV.SYS
2010-11-16 17:11:33 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2010-11-16 01:38:45 -------- d-----w- c:\docume~1\jhm\applic~1\whitesmoketoolbar
2010-11-16 01:29:30 -------- d-----w- c:\program files\whitesmoketoolbar
2010-11-16 01:29:17 -------- d-----w- c:\program files\WhiteSmoke Translator
2010-11-16 01:29:12 -------- d-----w- c:\windows\system32\%APPDATA%
2010-11-15 22:41:56 229439 -c--a-w- c:\windows\system32\dllcache\multibox.dll
2010-11-15 22:40:55 10096640 -c--a-w- c:\windows\system32\dllcache\hwxcht.dll
2010-11-15 22:39:58 7168 -c--a-w- c:\windows\system32\dllcache\wamregps.dll
2010-11-15 22:36:39 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2010-11-15 22:36:39 16384 ----a-w- c:\program files\internet explorer\connection wizard\isignup.exe
2010-11-15 22:29:52 45086 ----a-r- c:\windows\system32\SET291.tmp
2010-11-15 22:29:40 135200 ----a-r- c:\windows\system32\SET289.tmp
2010-11-15 22:29:38 172064 ----a-r- c:\windows\system32\SET288.tmp
2010-11-15 22:29:37 188448 ----a-r- c:\windows\system32\SET287.tmp
2010-11-15 22:29:36 90144 ----a-r- c:\windows\system32\SET286.tmp
2010-11-15 22:00:41 8192 ----a-w- c:\windows\system32\wshirda.dll
2010-11-15 22:00:41 28160 ----a-w- c:\windows\system32\irmon.dll
2010-11-15 22:00:41 151552 ----a-w- c:\windows\system32\irftp.exe
2010-11-15 21:50:30 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2010-11-15 21:50:30 13312 ----a-w- c:\windows\system32\irclass.dll
2010-11-15 21:50:29 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2010-11-15 21:50:29 24661 ----a-w- c:\windows\system32\spxcoins.dll
2010-11-15 21:50:13 14573 ----a-r- c:\windows\SET143.tmp
2010-11-15 21:50:02 16535 ----a-r- c:\windows\SET108.tmp
2010-11-15 21:49:55 1088840 ----a-r- c:\windows\SETFC.tmp
2010-11-15 21:49:52 1296669 ----a-r- c:\windows\SETF9.tmp
2010-11-12 19:24:09 -------- d-----w- C:\Kim
2010-11-11 21:49:43 -------- d-----w- c:\docume~1\jhm\locals~1\applic~1\{FF231E6B-3860-4ECB-BA91-1C8F46280F5D}
2010-11-11 21:49:14 -------- d-----w- c:\windows\system32\2015
2010-11-11 21:49:08 202 ----a-w- c:\documents and settings\jhm\delme.bat
2010-11-11 21:48:01 -------- d-----w- c:\docume~1\alluse~1\applic~1\WSTB
2010-10-25 00:35:42 -------- d-----w- c:\program files\WinSCP
2010-10-25 00:35:35 -------- d-----w- c:\program files\Free Offers from Freeze.com

==================== Find3M ====================

2010-11-11 21:49:44 0 ----a-w- c:\windows\Aluzeroqax.bin
2010-11-01 05:57:51 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-10-29 17:14:46 65536 ----a-w- c:\windows\system32\wltrynt.dll
2010-10-29 17:14:46 25088 ----a-w- c:\windows\system32\WLTRYSVC.EXE
2010-10-29 17:14:44 69632 ----a-w- c:\windows\system32\bcmwlpkt.dll
2010-10-29 17:14:44 303104 ----a-w- c:\windows\system32\bcmwlu00.exe
2010-10-29 17:14:44 2670592 ----a-w- c:\windows\system32\WLBCGCBPRO731.DLL
2010-10-29 17:14:44 2498560 ----a-w- c:\windows\system32\WLTRAY.EXE
2010-10-29 17:14:44 2232320 ----a-w- c:\windows\system32\BCMWLTRY.EXE
2010-10-29 17:14:44 143360 ----a-w- c:\windows\system32\preflib.dll
2010-10-29 17:14:12 831488 ----a-w- c:\windows\system32\BCMLogon.dll
2010-10-29 17:14:12 761856 ----a-w- c:\windows\system32\bcm1xsup.dll
2010-10-29 17:14:12 5431296 ----a-w- c:\windows\system32\BCMWLCPL.CPL
2010-09-18 19:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-15 09:29:49 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 12:52:45 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll

============= FINISH: 13:20:30.17 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 rigacci

rigacci

    Fiorentino


  • Members
  • 2,604 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:37 PM

Posted 29 November 2010 - 05:33 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review your topic an do their best to resolve your issues.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.

Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

We also need a new log from the GMER anti-rootkit scanner. Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice


Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log


Thanks.

DR

#3 thcbytes

thcbytes

  • Malware Response Team
  • 14,790 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:37 PM

Posted 16 April 2011 - 04:40 PM

Due to the lack of feedback, this topic is now closed.In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.
Proud member - Unified Network of Instructors and Trained Eliminators
Posted Image

I do not accept personal donations for assistance provided. I would ask that you instead consider donating the greatest gift - Organ Donation. Your organs are of no use to you when your gone. You will save a life that would otherwise be lost!

http://donatelife.net/register-now/




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users