Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Computer infected with a virus!


  • This topic is locked This topic is locked
12 replies to this topic

#1 designz4u63

designz4u63

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:09 PM

Posted 27 December 2011 - 09:44 PM

Hello!

My computer got infected with a virus? or Trojan !. It is infected but I am not sure with what.
The symptoms are as following:
- all the files and folders pre-existing in the computer before it got infected are not acting and looking like hidden files
- I cannot send any email or download anything on the computer, however I can surf internet. On the other hand, once in a while I hear the sound of a finished downloaded file (even of I did not initiate a download, and sometime I am not even on the computer)
- I try cleaning the computer using Malwarebytes, Microsoft Essentials, TrendMicro. Everytime the cleaning programs are finding Trojans and Spyware, however if I run the antivirus programs in safe mode, as soon as I exit from Safe Mode, and I run the antivirus programs again I find new viruses (and I will have the computer disconnected from the internet).
The computer is running a Windows XP- Media Center

I followed the instruction from preparation guide and here are the attached files and info:

DDS.txt content:


.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by HP Media Center at 11:54:36 on 2011-12-26
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2953 [GMT -5:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k Akamai
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
C:\Program Files\Office Depot PC Support Agent\esService.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Office Depot PC Support Agent\escont.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\HP Media Center\Local Settings\Application Data\Akamai\netsession_win.exe
C:\Documents and Settings\HP Media Center\Local Settings\Application Data\Akamai\netsession_win.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\ping.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uWindow Title = Windows Internet Explorer provided by Yahoo!
uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8
uInternet Settings,ProxyServer = ftp=64.233.217.2:80;http=64.233.217.5:80;https=64.233.217.5:80
uURLSearchHooks: H - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [Akamai NetSession Interface] c:\documents and settings\hp media center\local settings\application data\akamai\netsession_win.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Monitor] "c:\program files\leapfrog\leapfrog connect\Monitor.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\hpmedi~1\startm~1\programs\startup\regist~1.lnk - c:\program files\ubisoft\il-2 sturmovik 1946\RegistrationReminder.exe
LSP: mswsock.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1297287619062
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: Interfaces\{FC2ADD86-8C30-4C41-9B3D-51DECCC620AE} : NameServer = 64.233.217.5,64.233.217.2
mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648]
R1 MpKsl9047b5e5;MpKsl9047b5e5;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{13be73ef-73bd-4270-9778-f08051b9d41e}\MpKsl9047b5e5.sys [2011-12-26 29904]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2006-3-15 14336]
R2 Office Depot PC Support Agent;Office Depot PC Support Agent;c:\program files\office depot pc support agent\esService.exe [2011-11-10 924568]
S1 MpKsl73ef1dd0;MpKsl73ef1dd0;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9ba639ef-9f7c-47d3-bf0a-818cad4167bd}\mpksl73ef1dd0.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{9ba639ef-9f7c-47d3-bf0a-818cad4167bd}\MpKsl73ef1dd0.sys [?]
S1 MpKslb2c0051b;MpKslb2c0051b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{01621c67-76dd-4515-a36d-bbdf71e7156a}\mpkslb2c0051b.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{01621c67-76dd-4515-a36d-bbdf71e7156a}\MpKslb2c0051b.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-15 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-15 136176]
S3 iMSPCLOj;iMSPCLOj;\??\c:\docume~1\hpmedi~1\locals~1\temp\imspcloj.sys --> c:\docume~1\hpmedi~1\locals~1\temp\iMSPCLOj.sys [?]
S3 Leapfrog-USBLAN;Leapfrog-USBLAN;c:\windows\system32\drivers\btblan.sys [2011-7-7 33792]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2011-12-5 50704]
S3 ssmirrdr;ssmirrdr;c:\windows\system32\drivers\ssmirrdr.sys [2011-1-24 10112]
.
=============== Created Last 30 ================
.
2011-12-26 16:38:10 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{13be73ef-73bd-4270-9778-f08051b9d41e}\MpKsl9047b5e5.sys
2011-12-26 16:38:07 56200 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{13be73ef-73bd-4270-9778-f08051b9d41e}\offreg.dll
2011-12-26 02:42:55 6823496 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{13be73ef-73bd-4270-9778-f08051b9d41e}\mpengine.dll
2011-12-22 23:55:48 -------- d--h--w- c:\program files\converters and assit programs
2011-12-11 05:22:01 -------- d-----w- c:\program files\freecol
2011-12-07 19:23:47 -------- d--h--w- c:\documents and settings\all users\application data\FarmFrenzy2
2011-12-07 19:23:47 -------- d--h--w- c:\documents and settings\all users\application data\AlawarWrapper
2011-12-07 19:23:18 -------- d-----w- c:\program files\Viva Media
2011-12-07 19:23:00 -------- d-----w- c:\program files\Viva Media Game Center
2011-12-06 02:42:06 -------- d-----w- c:\windows\system32\AGEIA
2011-12-06 02:41:56 -------- d--h--w- c:\program files\common files\Wise Installation Wizard
2011-12-06 00:28:30 -------- d-----w- c:\program files\Steam
2011-12-05 17:34:38 41680 ----a-w- c:\windows\system32\drivers\xahclrtd.sys
2011-12-05 17:21:12 50704 ----a-w- c:\windows\system32\drivers\npf.sys
2011-12-05 17:21:12 281104 ----a-w- c:\windows\system32\wpcap.dll
2011-12-05 17:21:12 100880 ----a-w- c:\windows\system32\Packet.dll
2011-12-05 12:52:39 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2011-12-05 03:12:50 -------- d-----w- c:\windows\system32\LogFiles
2011-12-04 16:14:19 388096 ---ha-r- c:\documents and settings\hp media center\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-12-04 16:14:18 -------- d-----w- c:\program files\trendmicro
2011-12-01 01:34:13 138496 -c--a-w- c:\windows\system32\dllcache\afd11.sys.sys
2011-12-01 01:34:13 138496 -c--a-w- c:\windows\system32\dllcache\afd.sys
2011-12-01 01:34:13 138496 ----a-w- c:\windows\system32\drivers\afd.sys
.
==================== Find3M ====================
.
2011-12-22 23:53:44 796672 ----a-w- c:\windows\GPInstall.exe
2011-12-15 23:16:51 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2011-11-23 13:25:32 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-10 10:54:13 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-10 08:27:10 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-11-04 19:20:51 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:51 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23:59 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37:08 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:02 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-06 02:20:03 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
.
============= FINISH: 12:00:59.10 ===============


Attached File  attach.txt   21.78KB   1 downloads


Attached File  ark.txt.log   65.3KB   1 downloads

I hope someone can help me clean the computer

Thank you

BC AdBot (Login to Remove)

 


#2 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:09 PM

Posted 28 December 2011 - 11:39 AM

Hello and welcome. Please follow these guidelines while we work on your PC:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until Iíve given you the ďAll clear.Ē Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please note that the forum is very busy and if I don't hear from you within five days this thread will be closed.
Posted Image Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • ComboFix log

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#3 designz4u63

designz4u63
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:09 PM

Posted 28 December 2011 - 08:13 PM

I try to download ComboFIx directly from the infected computer but I was not able to so I download the program on a different computer, and then I transfer it into the infect it one. I save ComboFix on Desktop.
I turn off all the protection installed, and I install ComboFIx. ComboFix start it and I receive the message that I do not have Microsoft Windows Recovery Console, and I was asked if I want ComboFIx to install it for me. I said "Yes" and from here things start going wrong. First I got the message that the attempt to download " Microsoft Recovery Console" took too long and it might and the program could not download the program. Right after that, I got the next message saying that ComboFIx will start scanning my computer for malware/viruses. (Just a short note: after I said yes for downloading Microsoft recovering console" I did not touch the computer anymore). Next message was that the scan process might take more than 10 minutes.
A few minutes later I got a new message telling me that the computer was infected with a Rootkit.....and that the virus is locate it into TCP/IP (I am sorry but I cannot reproduce exactly the message as long as it change quite fast and I did not have time to write it down). Right after that the computer desktop went to a background picture with no folders, shortcuts, nor the blue scree opened by ComboFix.
A few seconds later, I got a new message from ComboFix saying that the infection is difficult to clean and it needs to reboot the computer and that the reboot should be done by the program and I should not attempt to reboot manually. It also said something like " if the problem is not fix, then ComboFix should be run again.
The message disappeared, I right now I have the background of the desktop, with no file, folders or anything else (it looks the same as when you turn explorer.exe off). The blue screen for ComboFix is gone too.
The computer did not reboot and it doesn't look like it will, but I am not sure if ComboFix is still running or not, nor what I should do next.
As you can imagine I do not know what to do next.
Let me know if you want me to reboot manually or not, or what should I do next.

I should add that the mouse arrow can be moved on the screen, so as far as I know the compute do not seems to be stuck...I do not know if it is important or not, but I thought I should let you know.

UPDATE

The computer reboot it at the end (after about 1 hour) and when it re-start it, ComboFix was running and it went all the way to the end...I mean it create a ComboFix.txt log which I attach it. I hope it worked.


ComboFix 11-12-28.03 - HP Media Center 12/28/2011 21:04:27.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.3129 [GMT -5:00]
Running from: C:\Documents and Settings\HP Media Center\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\data
C:\data\default\us_sres.data
C:\Documents and Settings\HP Media Center\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
C:\Documents and Settings\HP Media Center\Start Menu\Programs\AV Protection 2011
C:\Documents and Settings\HP Media Center\Start Menu\Programs\AV Protection 2011\AV Protection 2011.lnk
C:\Documents and Settings\HP Media Center\Start Menu\Programs\System Fix
C:\Documents and Settings\HP Media Center\Start Menu\Programs\System Fix\System Fix.lnk
C:\Documents and Settings\HP Media Center\Start Menu\Programs\System Fix\Uninstall System Fix.lnk
C:\Documents and Settings\HP Media Center\WINDOWS
C:\Program Files\LP
C:\Program Files\LP\648E\ECF.tmp
C:\Program Files\LP\648E\ED1.tmp
C:\WINDOWS\$NtUninstallKB35420$
C:\WINDOWS\$NtUninstallKB35420$\149062334\@
C:\WINDOWS\$NtUninstallKB35420$\149062334\bckfg.tmp
C:\WINDOWS\$NtUninstallKB35420$\149062334\cfg.ini
C:\WINDOWS\$NtUninstallKB35420$\149062334\Desktop.ini
C:\WINDOWS\$NtUninstallKB35420$\149062334\keywords
C:\WINDOWS\$NtUninstallKB35420$\149062334\kwrd.dll
C:\WINDOWS\$NtUninstallKB35420$\149062334\L\zfwhbmea
C:\WINDOWS\$NtUninstallKB35420$\149062334\lsflt7.ver
C:\WINDOWS\$NtUninstallKB35420$\149062334\U\00000001.@
C:\WINDOWS\$NtUninstallKB35420$\149062334\U\00000002.@
C:\WINDOWS\$NtUninstallKB35420$\149062334\U\00000004.@
C:\WINDOWS\$NtUninstallKB35420$\149062334\U\80000000.@
C:\WINDOWS\$NtUninstallKB35420$\149062334\U\80000004.@
C:\WINDOWS\$NtUninstallKB35420$\149062334\U\80000032.@
C:\WINDOWS\$NtUninstallKB35420$\2380964249

Infected copy of C:\WINDOWS\system32\drivers\ipsec.sys was found and disinfected
Restored copy from - The cat found it :)

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_.afd
-------\Service_.mrxsmb


((((((((((((((((((((((((( Files Created from 2011-11-28 to 2011-12-29 )))))))))))))))))))))))))))))))


2011-12-29 02:52:46 . 2011-12-29 02:52:46 1409 ----a-w- C:\WINDOWS\QTFont.for
2011-12-29 02:40:37 . 2011-12-29 02:40:37 56200 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8B21ACB7-6C1A-4941-AE41-54E5FABA30C4}\offreg.dll
2011-12-29 02:39:59 . 2011-11-21 07:47:40 6823496 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8B21ACB7-6C1A-4941-AE41-54E5FABA30C4}\mpengine.dll
2011-12-29 00:50:54 . 2008-04-13 19:19:42 75264 ----a-w- C:\WINDOWS\system32\drivers\ipsec.sys
2011-12-28 00:21:31 . 2011-12-28 00:21:33 -------- d-----w- C:\Program Files\WinPcap
2011-12-28 00:21:09 . 2011-12-28 00:21:09 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Trend Micro
2011-12-28 00:20:17 . 2011-12-28 00:20:17 -------- d-----w- C:\Program Files\Trend Micro
2011-12-22 23:55:48 . 2011-12-22 23:56:16 -------- d--h--w- C:\Program Files\converters and assit programs
2011-12-11 05:22:01 . 2011-12-11 05:24:24 -------- d-----w- C:\Program Files\freecol
2011-12-11 00:18:12 . 2011-12-11 00:18:14 -------- d-----w- C:\Documents and Settings\Administrator\Local Settings\Application Data\Google
2011-12-11 00:18:07 . 2011-12-11 00:18:07 -------- d-----w- C:\Documents and Settings\Administrator\Application Data\Yahoo!
2011-12-10 04:26:00 . 2011-12-10 04:26:00 -------- d-sh--w- C:\Documents and Settings\Administrator\PrivacIE
2011-12-07 19:23:47 . 2011-12-07 22:06:21 -------- d--h--w- C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
2011-12-07 19:23:47 . 2011-12-07 19:23:48 -------- d--h--w- C:\Documents and Settings\All Users\Application Data\AlawarWrapper
2011-12-07 19:23:18 . 2011-12-07 19:23:18 -------- d-----w- C:\Program Files\Viva Media
2011-12-07 19:23:00 . 2011-12-07 19:23:00 -------- d-----w- C:\Program Files\Viva Media Game Center
2011-12-06 02:42:06 . 2011-12-06 02:42:17 -------- d-----w- C:\Program Files\AGEIA Technologies
2011-12-06 02:42:06 . 2011-12-06 02:42:06 -------- d-----w- C:\WINDOWS\system32\AGEIA
2011-12-06 02:41:56 . 2011-12-06 02:41:56 -------- d--h--w- C:\Program Files\Common Files\Wise Installation Wizard
2011-12-06 00:28:30 . 2011-12-29 02:52:32 -------- d-----w- C:\Program Files\Steam
2011-12-05 17:34:38 . 2011-12-05 17:34:38 41680 ----a-w- C:\WINDOWS\system32\drivers\xahclrtd.sys
2011-12-05 12:52:39 . 2011-12-05 12:52:57 43520 ----a-w- C:\WINDOWS\system32\CmdLineExt03.dll
2011-12-05 03:12:50 . 2011-12-05 03:12:50 -------- d-----w- C:\WINDOWS\system32\LogFiles
2011-12-04 16:14:19 . 2011-12-04 16:14:20 388096 ---ha-r- C:\Documents and Settings\HP Media Center\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-04 16:14:18 . 2011-12-04 16:14:18 -------- d-----w- C:\Program Files\trendmicro
2011-12-02 22:03:54 . 2011-12-20 01:05:04 -------- d-----w- C:\WINDOWS\system32\config\systemprofile\Application Data\QuickScan
2011-12-02 00:03:16 . 2011-12-02 00:03:16 -------- d-sh--w- C:\Documents and Settings\NetworkService\PrivacIE
2011-12-02 00:02:21 . 2011-12-02 00:02:21 -------- d--h--w- C:\Documents and Settings\NetworkService\Application Data\Yahoo!
2011-12-01 01:34:13 . 2011-08-17 13:49:54 138496 -c--a-w- C:\WINDOWS\system32\dllcache\afd11.sys.sys
2011-12-01 01:34:13 . 2011-08-17 13:49:54 138496 -c--a-w- C:\WINDOWS\system32\dllcache\afd.sys
2011-12-01 01:34:13 . 2011-08-17 13:49:54 138496 ----a-w- C:\WINDOWS\system32\drivers\afd.sys
.


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2011-12-22 23:53:44 . 2011-02-16 05:51:45 796672 ----a-w- C:\WINDOWS\GPInstall.exe
2011-12-15 23:16:51 . 2011-03-24 21:52:37 107888 ----a-w- C:\WINDOWS\system32\CmdLineExt.dll
2011-11-23 13:25:32 . 2006-03-15 11:00:00 1859584 ----a-w- C:\WINDOWS\system32\win32k.sys
2011-11-21 07:47:40 . 2011-02-22 18:50:38 6823496 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-10 10:54:13 . 2011-05-16 14:08:10 472808 ----a-w- C:\WINDOWS\system32\deployJava1.dll
2011-11-10 08:27:10 . 2011-05-16 14:08:10 73728 ----a-w- C:\WINDOWS\system32\javacpl.cpl
2011-11-04 19:20:51 . 2006-03-15 11:00:00 916992 ----a-w- C:\WINDOWS\system32\wininet.dll
2011-11-04 19:20:51 . 2006-03-15 11:00:00 43520 ----a-w- C:\WINDOWS\system32\licmgr10.dll
2011-11-04 19:20:51 . 2006-03-15 11:00:00 1469440 ------w- C:\WINDOWS\system32\inetcpl.cpl
2011-11-04 11:23:59 . 2006-03-15 11:00:00 385024 ----a-w- C:\WINDOWS\system32\html.iec
2011-11-01 16:07:10 . 2006-03-15 11:00:00 1288704 ----a-w- C:\WINDOWS\system32\ole32.dll
2011-10-28 05:31:48 . 2006-03-15 11:00:00 33280 ----a-w- C:\WINDOWS\system32\csrsrv.dll
2011-10-25 13:37:08 . 2006-03-15 11:00:00 2148864 ----a-w- C:\WINDOWS\system32\ntoskrnl.exe
2011-10-25 12:52:02 . 2004-08-03 22:59:02 2027008 ----a-w- C:\WINDOWS\system32\ntkrnlpa.exe
2011-10-10 14:22:41 . 2011-02-09 19:37:57 692736 ----a-w- C:\WINDOWS\system32\inetcomm.dll
2011-10-06 02:20:03 . 2011-06-06 00:00:36 414368 ----a-w- C:\WINDOWS\system32\FlashPlayerCPLApp.cpl


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-02-15 07:48:44 39408]
"Messenger (Yahoo!)"="C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 14:17:48 5252408]
"Steam"="C:\Program Files\Steam\Steam.exe" [2011-12-06 00:29:38 1242448]
"Akamai NetSession Interface"="C:\Documents and Settings\HP Media Center\Local Settings\Application Data\Akamai\netsession_win.exe" [2011-12-07 03:43:06 3305248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 09:04:42 59392]
"nwiz"="C:\Program Files\NVIDIA Corporation\nView\nwiz.exe" [2010-07-08 04:52:40 1753192]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2010-07-09 21:24:18 110696]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2010-07-09 21:24:16 13923432]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 14:32:14 18085888]
"MSC"="c:\Program Files\Microsoft Security Client\msseces.exe" [2011-06-15 19:16:48 997920]
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 17:12:22 253672]
"Monitor"="C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe" [2011-06-06 19:06:12 251744]
"TkBellExe"="C:\Program Files\Real\RealPlayer\update\realsched.exe" [2011-07-25 22:31:17 273544]
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 16:55:28 937920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2011-12-13 14:53:48 421888]
"Trend Micro RUBotted V2.0 Beta"="C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe" [2010-12-17 14:33:06 1103184]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 06:01:00 437160]

C:\Documents and Settings\HP Media Center\Start Menu\Programs\Startup\
Registration IL-2 Sturmovik 1946.LNK - C:\Program Files\Ubisoft\IL-2 Sturmovik 1946\RegistrationReminder.exe [2005-5-24 868352]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Office Depot PC Support Agent]
@="Office Depot PC Support Agent"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LeapFrog\\LeapFrog Connect\\LeapFrogConnect.exe"=
"C:\\Program Files\\Unity\\Editor\\Unity.exe"=
"C:\\Documents and Settings\\HP Media Center\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"C:\\Program Files\\Steam\\SteamApps\\common\\startrekdac\\Bin\\StarTrekDAC.exe"=
"C:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1123:TCP"= 1123:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface

R2 Akamai;Akamai NetSession Interface;C:\WINDOWS\System32\svchost.exe -k Akamai [3/15/2006 6:00:00 AM 14336]
R2 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [10/20/2009 1:19:44 PM 50704]
R2 RUBotSrv;Trend Micro RUBotted Service;C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe [12/27/2011 7:20:17 PM 439632]
S1 MpKsl0681eaa1;MpKsl0681eaa1;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8812CE2F-3E2D-4A6F-956A-C6D1E63D2BB0}\MpKsl0681eaa1.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8812CE2F-3E2D-4A6F-956A-C6D1E63D2BB0}\MpKsl0681eaa1.sys [?]
S1 MpKsl262e9351;MpKsl262e9351;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8812CE2F-3E2D-4A6F-956A-C6D1E63D2BB0}\MpKsl262e9351.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8812CE2F-3E2D-4A6F-956A-C6D1E63D2BB0}\MpKsl262e9351.sys [?]
S1 MpKsl73ef1dd0;MpKsl73ef1dd0;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9BA639EF-9F7C-47D3-BF0A-818CAD4167BD}\MpKsl73ef1dd0.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9BA639EF-9F7C-47D3-BF0A-818CAD4167BD}\MpKsl73ef1dd0.sys [?]
S1 MpKslb2c0051b;MpKslb2c0051b;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{01621C67-76DD-4515-A36D-BBDF71E7156A}\MpKslb2c0051b.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{01621C67-76DD-4515-A36D-BBDF71E7156A}\MpKslb2c0051b.sys [?]
S1 MpKslf6023e27;MpKslf6023e27;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8812CE2F-3E2D-4A6F-956A-C6D1E63D2BB0}\MpKslf6023e27.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8812CE2F-3E2D-4A6F-956A-C6D1E63D2BB0}\MpKslf6023e27.sys [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [2/15/2011 2:48:46 AM 136176]
S2 Office Depot PC Support Agent;Office Depot PC Support Agent;C:\Program Files\Office Depot PC Support Agent\esService.exe [11/10/2011 2:15:52 AM 924568]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files\Google\Update\GoogleUpdate.exe [2/15/2011 2:48:46 AM 136176]
S3 iMSPCLOj;iMSPCLOj;\??\C:\DOCUME~1\HPMEDI~1\LOCALS~1\Temp\iMSPCLOj.sys --> C:\DOCUME~1\HPMEDI~1\LOCALS~1\Temp\iMSPCLOj.sys [?]
S3 Leapfrog-USBLAN;Leapfrog-USBLAN;C:\WINDOWS\system32\drivers\btblan.sys [7/7/2011 3:05:41 PM 33792]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys --> C:\WINDOWS\system32\drivers\mbamswissarmy.sys [?]
S3 ssmirrdr;ssmirrdr;C:\WINDOWS\system32\drivers\ssmirrdr.sys [1/24/2011 1:20:14 AM 10112]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 09:32:48 128512 ----a-w- C:\WINDOWS\system32\advpack.dll

Contents of the 'Scheduled Tasks' folder

2011-12-29 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2011-02-15 07:48:46 . 2011-02-15 07:48:45]

2011-12-29 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2011-02-15 07:48:46 . 2011-02-15 07:48:45]

2011-12-29 C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-1935655697-879983540-725345543-1003.job
- C:\Program Files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47:46 . 2011-03-29 14:47:46]

2011-12-29 C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-1935655697-879983540-725345543-1003.job
- C:\Program Files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47:46 . 2011-03-29 14:47:46]

2011-12-29 C:\WINDOWS\Tasks\User_Feed_Synchronization-{B140835E-2EFD-4B2D-8C81-B42887D2B6B5}.job
- C:\WINDOWS\system32\msfeedssync.exe [2009-03-08 09:31:54 . 2009-03-08 09:31:54]


------- Supplementary Scan -------

uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = ftp=64.233.217.2:80;http=64.233.217.5:80;https=64.233.217.5:80
TCP: Interfaces\{FC2ADD86-8C30-4C41-9B3D-51DECCC620AE}: NameServer = 64.233.217.5,64.233.217.2

- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Caillou® Party Fun & Games™ - C:\Program Files\The Learning Company\Caillou® Party Fun & Games™\Uninst.isu
AddRemove-FinalTorrent_is1 - C:\Program Files\FinalTorrent\unins000.exe
AddRemove-Jay Jay Earns His Wings - C:\Program Files\The Learning Company\Jay Jay Earns His Wings\uninstall.exe
AddRemove-Napoleon - C:\Program Files\Napoleon\Uninst.isu

Attached Files


Edited by RPMcMurphy, 28 December 2011 - 11:30 PM.
Added log


#4 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:09 PM

Posted 28 December 2011 - 11:39 PM

designz4u63:

That looks like it worked fine. Please do this next:

Posted Image Open Notepad Go to Start> All Programs> Accessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above http://

http://www.bleepingcomputer.com/forums/topic434887.html
Collect::
C:\WINDOWS\system32\drivers\xahclrtd.sys
C:\DOCUME~1\HPMEDI~1\LOCALS~1\Temp\iMSPCLOj.sys
Driver::
iMSPCLOj

Save this as CFScript to your desktop.

Then disable your security programs and drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Posted Image You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Uncheck any entries from C:\System Volume Information or C:\Qoobox
  • Make sure that everything else is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

Please include the following in your next post:
  • ComboFix log
  • MBAM log

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#5 designz4u63

designz4u63
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:09 PM

Posted 29 December 2011 - 07:21 PM

I follow the instructions and everything worked "like a charm".
Here are the two files:

ComboFix 11-12-29.04 - HP Media Center 12/29/2011 13:54:10.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2989 [GMT -5:00]
Running from: c:\documents and settings\HP Media Center\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\data\default\us_sres.data
c:\documents and settings\HP Media Center\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
c:\documents and settings\HP Media Center\Start Menu\Programs\AV Protection 2011\AV Protection 2011.lnk
c:\documents and settings\HP Media Center\Start Menu\Programs\System Fix\System Fix.lnk
c:\documents and settings\HP Media Center\Start Menu\Programs\System Fix\Uninstall System Fix.lnk
c:\program files\LP\648E\ECF.tmp
c:\program files\LP\648E\ED1.tmp
c:\windows\$NtUninstallKB35420$\149062334\@
c:\windows\$NtUninstallKB35420$\149062334\bckfg.tmp
c:\windows\$NtUninstallKB35420$\149062334\cfg.ini
c:\windows\$NtUninstallKB35420$\149062334\Desktop.ini
c:\windows\$NtUninstallKB35420$\149062334\keywords
c:\windows\$NtUninstallKB35420$\149062334\kwrd.dll
c:\windows\$NtUninstallKB35420$\149062334\L\zfwhbmea
c:\windows\$NtUninstallKB35420$\149062334\lsflt7.ver
c:\windows\$NtUninstallKB35420$\149062334\U\00000001.@
c:\windows\$NtUninstallKB35420$\149062334\U\00000002.@
c:\windows\$NtUninstallKB35420$\149062334\U\00000004.@
c:\windows\$NtUninstallKB35420$\149062334\U\80000000.@
c:\windows\$NtUninstallKB35420$\149062334\U\80000004.@
c:\windows\$NtUninstallKB35420$\149062334\U\80000032.@
c:\windows\$NtUninstallKB35420$\2380964249
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_.afd
-------\Service_.mrxsmb
.
.
((((((((((((((((((((((((( Files Created from 2011-11-28 to 2011-12-29 )))))))))))))))))))))))))))))))
.
.
2011-12-29 18:30 . 2011-12-29 18:30 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2103F89D-5BD0-4C23-AFEC-3DFF999E02AC}\MpKsle4846f86.sys
2011-12-29 15:37 . 2011-12-29 15:37 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2103F89D-5BD0-4C23-AFEC-3DFF999E02AC}\MpKsle880007b.sys
2011-12-29 10:15 . 2011-12-29 10:15 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2103F89D-5BD0-4C23-AFEC-3DFF999E02AC}\MpKsl4dbe3136.sys
2011-12-29 10:15 . 2011-12-29 18:30 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2103F89D-5BD0-4C23-AFEC-3DFF999E02AC}\offreg.dll
2011-12-29 03:17 . 2011-11-21 07:47 6823496 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2103F89D-5BD0-4C23-AFEC-3DFF999E02AC}\mpengine.dll
2011-12-29 00:50 . 2008-04-13 19:19 75264 ----a-w- c:\windows\system32\drivers\ipsec.sys
2011-12-28 00:21 . 2011-12-28 00:21 -------- d-----w- c:\program files\WinPcap
2011-12-22 23:55 . 2011-12-22 23:56 -------- d--h--w- c:\program files\converters and assit programs
2011-12-11 05:22 . 2011-12-11 05:24 -------- d-----w- c:\program files\freecol
2011-12-11 00:18 . 2011-12-11 00:18 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2011-12-11 00:18 . 2011-12-11 00:18 -------- d-----w- c:\documents and settings\Administrator\Application Data\Yahoo!
2011-12-10 04:26 . 2011-12-10 04:26 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2011-12-07 19:23 . 2011-12-07 22:06 -------- d-----w- c:\documents and settings\All Users\Application Data\FarmFrenzy2
2011-12-07 19:23 . 2011-12-07 19:23 -------- d-----w- c:\documents and settings\All Users\Application Data\AlawarWrapper
2011-12-07 19:23 . 2011-12-07 19:23 -------- d-----w- c:\program files\Viva Media
2011-12-07 19:23 . 2011-12-07 19:23 -------- d-----w- c:\program files\Viva Media Game Center
2011-12-06 02:42 . 2011-12-06 02:42 -------- d-----w- c:\program files\AGEIA Technologies
2011-12-06 02:42 . 2011-12-06 02:42 -------- d-----w- c:\windows\system32\AGEIA
2011-12-06 02:41 . 2011-12-06 02:41 -------- d--h--w- c:\program files\Common Files\Wise Installation Wizard
2011-12-06 00:28 . 2011-12-29 18:32 -------- d-----w- c:\program files\Steam
2011-12-05 17:34 . 2011-12-05 17:34 41680 ----a-w- c:\windows\system32\drivers\xahclrtd.sys
2011-12-05 12:52 . 2011-12-05 12:52 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2011-12-05 03:12 . 2011-12-05 03:12 -------- d-----w- c:\windows\system32\LogFiles
2011-12-04 16:14 . 2011-12-04 16:14 388096 ----a-r- c:\documents and settings\HP Media Center\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-04 16:14 . 2011-12-04 16:14 -------- d-----w- c:\program files\trendmicro
2011-12-02 22:03 . 2011-12-20 01:05 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\QuickScan
2011-12-02 00:03 . 2011-12-02 00:03 -------- d-sh--w- c:\documents and settings\NetworkService\PrivacIE
2011-12-02 00:02 . 2011-12-02 00:02 -------- d--h--w- c:\documents and settings\NetworkService\Application Data\Yahoo!
2011-12-01 01:34 . 2011-08-17 13:49 138496 -c--a-w- c:\windows\system32\dllcache\afd11.sys.sys
2011-12-01 01:34 . 2011-08-17 13:49 138496 -c--a-w- c:\windows\system32\dllcache\afd.sys
2011-12-01 01:34 . 2011-08-17 13:49 138496 ----a-w- c:\windows\system32\drivers\afd.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-22 23:53 . 2011-02-16 05:51 796672 ----a-w- c:\windows\GPInstall.exe
2011-12-15 23:16 . 2011-03-24 21:52 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2011-11-23 13:25 . 2006-03-15 11:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-21 07:47 . 2011-02-22 18:50 6823496 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-10 10:54 . 2011-05-16 14:08 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-10 08:27 . 2011-05-16 14:08 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-11-04 19:20 . 2006-03-15 11:00 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2006-03-15 11:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2006-03-15 11:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2006-03-15 11:00 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2006-03-15 11:00 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2006-03-15 11:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2006-03-15 11:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-10 14:22 . 2011-02-09 19:37 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-06 02:20 . 2011-06-06 00:00 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-29_02.52.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-29 18:29 . 2011-12-29 18:29 16384 c:\windows\Temp\Perflib_Perfdata_760.dat
+ 2011-12-29 18:29 . 2011-12-29 18:29 16384 c:\windows\Temp\Perflib_Perfdata_658.dat
+ 2011-11-23 12:47 . 2011-12-29 18:29 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2011-11-23 12:47 . 2011-12-29 02:27 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2011-12-29 15:36 . 2011-12-29 18:29 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012011122920111230\index.dat
- 2011-12-29 01:59 . 2011-12-29 02:27 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012011122820111229\index.dat
+ 2011-12-29 01:59 . 2011-12-29 03:39 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012011122820111229\index.dat
+ 2011-02-09 19:42 . 2011-12-29 18:29 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2011-02-09 19:42 . 2011-12-29 02:27 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2011-02-09 19:42 . 2011-12-29 18:29 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2011-02-09 19:42 . 2011-12-29 02:27 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-02-15 39408]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"Steam"="c:\program files\Steam\Steam.exe" [2011-12-06 1242448]
"Akamai NetSession Interface"="c:\documents and settings\HP Media Center\Local Settings\Application Data\Akamai\netsession_win.exe" [2011-12-13 3305760]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-07-08 1753192]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-07-09 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-07-09 13923432]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 18085888]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2011-06-06 251744]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-07-25 273544]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-12-13 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\HP Media Center\Start Menu\Programs\Startup\
Registration IL-2 Sturmovik 1946.LNK - c:\program files\Ubisoft\IL-2 Sturmovik 1946\RegistrationReminder.exe [2005-5-24 868352]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Office Depot PC Support Agent]
@="Office Depot PC Support Agent"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LeapFrog\\LeapFrog Connect\\LeapFrogConnect.exe"=
"c:\\Program Files\\Unity\\Editor\\Unity.exe"=
"c:\\Documents and Settings\\HP Media Center\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\startrekdac\\Bin\\StarTrekDAC.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1077:TCP"= 1077:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R1 MpKsl4dbe3136;MpKsl4dbe3136;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2103F89D-5BD0-4C23-AFEC-3DFF999E02AC}\MpKsl4dbe3136.sys [12/29/2011 5:15 AM 29904]
R1 MpKsle4846f86;MpKsle4846f86;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2103F89D-5BD0-4C23-AFEC-3DFF999E02AC}\MpKsle4846f86.sys [12/29/2011 1:30 PM 29904]
R1 MpKsle880007b;MpKsle880007b;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2103F89D-5BD0-4C23-AFEC-3DFF999E02AC}\MpKsle880007b.sys [12/29/2011 10:37 AM 29904]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [3/15/2006 6:00 AM 14336]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [10/20/2009 1:19 PM 50704]
S1 MpKsl0681eaa1;MpKsl0681eaa1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8812CE2F-3E2D-4A6F-956A-C6D1E63D2BB0}\MpKsl0681eaa1.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8812CE2F-3E2D-4A6F-956A-C6D1E63D2BB0}\MpKsl0681eaa1.sys [?]
S1 MpKsl262e9351;MpKsl262e9351;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8812CE2F-3E2D-4A6F-956A-C6D1E63D2BB0}\MpKsl262e9351.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8812CE2F-3E2D-4A6F-956A-C6D1E63D2BB0}\MpKsl262e9351.sys [?]
S1 MpKsl73ef1dd0;MpKsl73ef1dd0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9BA639EF-9F7C-47D3-BF0A-818CAD4167BD}\MpKsl73ef1dd0.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9BA639EF-9F7C-47D3-BF0A-818CAD4167BD}\MpKsl73ef1dd0.sys [?]
S1 MpKslb2c0051b;MpKslb2c0051b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{01621C67-76DD-4515-A36D-BBDF71E7156A}\MpKslb2c0051b.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{01621C67-76DD-4515-A36D-BBDF71E7156A}\MpKslb2c0051b.sys [?]
S1 MpKslf6023e27;MpKslf6023e27;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8812CE2F-3E2D-4A6F-956A-C6D1E63D2BB0}\MpKslf6023e27.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8812CE2F-3E2D-4A6F-956A-C6D1E63D2BB0}\MpKslf6023e27.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/15/2011 2:48 AM 136176]
S2 Office Depot PC Support Agent;Office Depot PC Support Agent;c:\program files\Office Depot PC Support Agent\esService.exe [11/10/2011 2:15 AM 924568]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2/15/2011 2:48 AM 136176]
S3 iMSPCLOj;iMSPCLOj;\??\c:\docume~1\HPMEDI~1\LOCALS~1\Temp\iMSPCLOj.sys --> c:\docume~1\HPMEDI~1\LOCALS~1\Temp\iMSPCLOj.sys [?]
S3 Leapfrog-USBLAN;Leapfrog-USBLAN;c:\windows\system32\drivers\btblan.sys [7/7/2011 3:05 PM 33792]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 ssmirrdr;ssmirrdr;c:\windows\system32\drivers\ssmirrdr.sys [1/24/2011 1:20 AM 10112]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSLE4846F86
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 09:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-15 07:48]
.
2011-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-15 07:48]
.
2011-12-29 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1935655697-879983540-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
2011-12-29 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1935655697-879983540-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
2011-12-29 c:\windows\Tasks\User_Feed_Synchronization-{B140835E-2EFD-4B2D-8C81-B42887D2B6B5}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = ftp=64.233.217.2:80;http=64.233.217.5:80;https=64.233.217.5:80
TCP: Interfaces\{FC2ADD86-8C30-4C41-9B3D-51DECCC620AE}: NameServer = 64.233.217.5,64.233.217.2
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-29 14:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_d768ebc.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d0,a8,a3,d4,90,03,41,46,85,ed,94,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d0,a8,a3,d4,90,03,41,46,85,ed,94,\
.
[HKEY_USERS\S-1-5-21-1935655697-879983540-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1935655697-879983540-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:96,ba,d8,91,61,7b,b5,89,bf,a3,d7,4e,5c,97,36,5e,f9,a6,d1,fd,ce,47,68,
5b,22,e6,05,52,aa,4d,d4,0d,37,4c,e1,82,de,36,1b,2e,b4,c2,e5,47,e2,6f,17,da,\
"??"=hex:ee,20,aa,df,36,fc,3c,f2,da,b7,54,15,79,07,1d,cf
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2060)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2011-12-29 14:10:36
ComboFix-quarantined-files.txt 2011-12-29 19:10
.
Pre-Run: 22,876,426,240 bytes free
Post-Run: 22,861,635,584 bytes free
.
- - End Of File - - AB5A8D04270C43C40E5FDE59CF785D38

Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Database version: v2011.12.29.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
HP Media Center :: HP-351E3D83272B [administrator]

12/29/2011 2:26:17 PM
mbam-log-2011-12-29 (14-26-17).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 890830
Time elapsed: 3 hour(s), 23 minute(s), 53 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

PS: I discovered that my PC has now a Gateway Internet connection. I tried to disable it but I was unsuccessful. I do have a netbook which connects wireless to the internet but I am not sure how this Internet GAteway means or how to disable it. Again, I am not swure if it is important or not but I want to make sure I give all the information or the new things I find in my computer.

Attached Files


Edited by RPMcMurphy, 29 December 2011 - 11:11 PM.
Added logs


#6 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:09 PM

Posted 29 December 2011 - 11:29 PM

Hi,

I'm looking into that Gateway connection, but it doesn't look to be anything to be concerned about. I need you to try that ComboFix script one more time - ComboFix ran fine, but the script did not run. Be sure to follow the instructions carefully:

Posted Image Open Notepad Go to Start> All Programs> Accessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above http://

http://www.bleepingcomputer.com/forums/topic434887.html
Collect::
C:\WINDOWS\system32\drivers\xahclrtd.sys
C:\DOCUME~1\HPMEDI~1\LOCALS~1\Temp\iMSPCLOj.sys
Driver::
iMSPCLOj

Save this as CFScript to your desktop.

Then disable your security programs and drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Please include the following in your next post:
  • ComboFix log

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#7 designz4u63

designz4u63
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:09 PM

Posted 30 December 2011 - 07:23 PM

ComboFix Log (Dec.30,2011)

Attached File  ComboFix.txt   17.37KB   1 downloads

I hope this time it worked!

Edited by designz4u63, 30 December 2011 - 07:24 PM.


#8 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:09 PM

Posted 30 December 2011 - 11:51 PM

designz4u63:

That did the trick! How is your computer running now? Please do this next:

Posted Image Please go to here to run an online scan with ESET.
    • Turn off the real time scanner of any existing antivirus program while performing the online scan
    • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the activex control to install
    • Click Start
    • Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
    • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file....
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Please include the following in your next post:
  • How is the computer running now?
  • ESET log

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#9 designz4u63

designz4u63
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:09 PM

Posted 01 January 2012 - 10:27 AM

Happy New Year!

How is the computer running? it runns a lot faster and it doesn't initiate downloads anymore. However I do have an icon on the Task Bar, in the Notification area, called Windows Alert Security. It keeps warning me that my computer is at risk and previously that icon was a sign that I have the "Antivirus 2011" virus. On the other hand it doesn't act like the virus is on the computer, only the icon is present.

Here is the log for ESET:

Attached File  eset.log.txt.txt   6.34KB   2 downloads

Do I have to delete something?

#10 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:09 PM

Posted 01 January 2012 - 01:35 PM

designz4u63:

That ESET scan shows that a keygen is installed on this PC. Software like that is both illegal and a major source of malware infections. Please do this:

Posted Image Open notepad and copy/paste the text in the quotebox below into it:

@echo off
del "C:\Documents and Settings\HP Media Center\My Documents\Autodesk 3ds Max Design 2009\Keygen\XF-MAX2k9-32bit-KG.exe"
del "C:\Documents and Settings\HP Media Center\My Documents\Autodesk 3ds Max Design 2009\Keygen\XF-MAX2k9-64bit-KG.exe"	
del "C:\Documents and Settings\HP Media Center\My Documents\HP Media Center\Owner\My Documents\models\models by source\poser\x12.php"
del /Q %0

Save this as fix.bat Choose to "Save type as - All Files"
It should look like this: Posted Image
Double click on fix.bat & allow it to run.

Posted Image You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Uncheck any entries from C:\System Volume Information or C:\Qoobox
  • Make sure that everything else is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

Please include the following in your next post:
  • MBAM log

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#11 designz4u63

designz4u63
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:02:09 PM

Posted 04 January 2012 - 09:19 AM

MBAM log:

Attached File  mbam-log-2012-01-02 (21-44-19).txt   1.87KB   0 downloads

I do not know if everything is clean or not but the computer work so much better and it is a lot faster. It is such a pleasure now to work on it.
Do I need to do anything else?

#12 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:09 PM

Posted 04 January 2012 - 12:09 PM

designz4u63:

Everything is looking good! Unless you are still having trouble all I have left for you is some very important cleanup:

Posted Image Uninstall ComboFix
  • Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens and press OK:
    Combofix /Uninstall
Posted Image

Posted Image Delete the following tools along with any other logs you saved from our work:
  • DDS
  • GMER
Posted Image Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
Posted Image Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application and MBAM current and updated. Scan with them at least weekly.
  • Please read this post for some helpful information.
Please post once more so I know you are all set and I can mark this thread resolved. Good luck and stay safe!

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif


#13 RPMcMurphy

RPMcMurphy

    Bleeping *^#@%~


  • Malware Response Team
  • 3,970 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:09 PM

Posted 10 January 2012 - 10:40 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

Threads are closed after 5 days of inactivity.

ASAP & UNITE Member


The help you receive here is free. If you wish to show your appreciation, then you may btn_donate_SM.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users