![]() ![]() |
Jul 3 2009, 12:20 PM
Post
#1
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 47 Joined: 23-March 05 Member No.: 28,454 Operating System: xp |
I have a friend's computer here that I think may be infected. I can't access the internet, and I cannot install MBAM or Hijackthis. Also cannot run Spybot. Adaware seems to run fine. I ran ad-aware and deleted everything found. Still having problems. Your help is greatly appreciated, Thank you, mike |
|
|
|
Jul 3 2009, 07:19 PM
Post
#2
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Is the computer able to access safe mode? To Enter Safemode
If so. Download the following programs onto another computer and transfer to the infected computer via USB or other removable media. STEP #1 Please download DDS and save it to your desktop.
Please include the contents of the following in your next reply: DDS.txt Attach.txt. STEP #2 ![]() Download GMER Rootkit Scanner from here or here.
**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries |
|
|
|
Jul 3 2009, 09:01 PM
Post
#3
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 47 Joined: 23-March 05 Member No.: 28,454 Operating System: xp |
Hello,
here are logs. hope i did 'attach' right. I couldn't get gmer to run. thanks, DDS (Ver_09-06-26.01) - NTFSx86 MINIMAL Run by Karl at 19:43:45.81 on Fri 07/03/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1.#QNAN.770 [GMT -7:00] AV: McAfee VirusScan *On-access scanning disabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\svchost.exe -k netsvcs C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe c:\PROGRA~1\mcafee\msc\mcuimgr.exe C:\Program Files\Internet Explorer\Iexplore.exe C:\Documents and Settings\Karl\Desktop\dds.pif ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [NeroFilterCheck] "c:\program files\common files\ahead\lib\NeroCheck.exe" mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe" mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [McAfee Backup] c:\program files\mcafee\mbk\McAfeeDataBackup.exe mRun: [MBkLogOnHook] c:\program files\mcafee\mbk\LogOnHook.exe mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll Trusted Zone: internet Trusted Zone: mcafee.com DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Notify: igfxcui - igfxdev.dll Notify: WRNotifier - WRLogonNTF.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\karl\applic~1\mozilla\firefox\profiles\1xf9wd7e.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/ ============= SERVICES / DRIVERS =============== R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664] S1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-5-10 201320] S2 ipfw;ipfw_helper;c:\windows\system32\13482.exe --> c:\windows\system32\13482.exe [?] S2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-5-10 359248] S2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2008-5-10 144704] S3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;c:\windows\system32\drivers\l251x86.sys [2008-4-23 30720] S3 ip_fw;ipfw kernel-mode driver;c:\windows\system32\drivers\ip_fw.sys [2009-5-30 28800] S3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2008-5-10 695624] S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-5-10 79304] S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-5-10 35240] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-5-10 33832] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-5-10 40488] =============== Created Last 30 ================ 2009-07-03 11:24 <DIR> --d----- c:\program files\CCleaner 2009-07-03 11:13 15,504 a------- c:\windows\system32\drivers\mbam.sys 2009-07-03 11:13 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-03 11:13 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware 2009-07-03 11:13 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-02 14:47 <DIR> --d----- c:\program files\Lavasoft 2009-07-02 14:47 <DIR> --d----- c:\program files\common files\Wise Installation Wizard ==================== Find3M ==================== 2009-05-30 21:19 28,800 a------- c:\windows\system32\drivers\ip_fw.sys 2009-02-23 16:21 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009022320090224\index.dat ============= FINISH: 19:45:16.20 ===============
Attached File(s)
|
|
|
|
Jul 3 2009, 09:04 PM
Post
#4
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 47 Joined: 23-March 05 Member No.: 28,454 Operating System: xp |
Safe Mode was accessible.
|
|
|
|
Jul 4 2009, 03:58 AM
Post
#5
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Did you try GMER in safe mode? Leave that for now then - please do the following: Note: It is very important that McAfee be totally disabled before running Combo-fix.
Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
Link 1 Link 2 Link 3 During the download, rename Combofix to Combo-Fix as follows: ![]() ![]() --------------------------------------------------------------------
-----------------------------------------------------------
|
|
|
|
Jul 4 2009, 11:01 AM
Post
#6
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 47 Joined: 23-March 05 Member No.: 28,454 Operating System: xp |
Yes, i was in safe mode when i tried gmer. Here's combo log. had to rename it Comba. My apologies, but when i ran it, i forgot to boot up in safe mode. Will this make a difference?
thanks, ComboFix 09-07-03.03 - Karl 07/04/2009 9:30.4 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.626 [GMT -7:00] Running from: c:\documents and settings\Karl\Desktop\CombaFix.exe AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Start Menu\PAV c:\program files\PAV c:\windows\Installer\336c2359.msi c:\windows\system32\drivers\ip_fw.sys c:\windows\system32\drivers\UACekmqmjjtphuncib.sys c:\windows\system32\UACadipqqfxylibtdw.dat c:\windows\system32\UACfhosdcuteccjysd.dll c:\windows\system32\UACgbgltjjiaipawgq.dll c:\windows\system32\uacinit.dll c:\windows\system32\UACjskurnmvmvvnrxi.dll c:\windows\system32\UACqhmauolhwoqssiw.dll c:\windows\system32\UACqxmfapohsxnyvbc.log c:\windows\system32\UACubewcdpondakhts.log c:\windows\system32\UACuvgialgsncdmqkv.log c:\windows\system32\UACwyqdirhbwmiooef.dll c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job c:\windows\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_UACd.sys -------\Legacy_IPFW -------\Legacy_IP_FW -------\Service_ip_fw -------\Service_ipfw ((((((((((((((((((((((((( Files Created from 2009-06-04 to 2009-07-04 ))))))))))))))))))))))))))))))) . 2009-07-03 18:24 . 2009-07-03 18:24 -------- d-----w- c:\program files\CCleaner 2009-07-03 18:13 . 2008-10-27 04:53 15504 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-07-03 18:13 . 2008-10-27 04:53 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-03 18:13 . 2009-07-03 18:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-07-03 18:13 . 2009-07-03 18:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-07-02 21:47 . 2009-07-02 21:47 -------- d-----w- c:\program files\Lavasoft 2009-07-02 21:47 . 2009-07-02 21:47 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-03 18:26 . 2008-10-31 08:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-07-02 05:59 . 2009-03-08 18:58 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-05-27 21:38 . 2008-05-10 19:51 -------- d-----w- c:\program files\McAfee 2009-05-12 17:23 . 2009-02-19 00:18 266400 ----a-w- c:\documents and settings\Karl\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll 2009-05-12 01:43 . 2009-05-08 15:43 261240 ----a-w- c:\documents and settings\Karl\Application Data\McAfee\Supportability\MVTLogs\mpsdbchk.exe 2009-05-07 23:13 . 2009-05-07 23:13 -------- d-----w- c:\program files\Common Files\Uninstall . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-24 143360] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-09 39408] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-11-08 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-11-08 166424] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928] "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992] "McAfee Backup"="c:\program files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 4838952] "MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= . Contents of the 'Scheduled Tasks' folder 2009-02-21 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2008-05-10 20:32] 2009-05-01 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2008-05-10 20:32] . . ------- Supplementary Scan ------- . Trusted Zone: internet Trusted Zone: mcafee.com FF - ProfilePath - c:\documents and settings\Karl\Application Data\Mozilla\Firefox\Profiles\1xf9wd7e.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/ . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-04 09:35 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run McAfee Backup = c:\program files\McAfee\MBK\McAfeeDataBackup.exe????????????????????????????????????????????????????????????????????????????????? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(3296) c:\program files\Common Files\Ahead\Lib\NeroSearchBar.dll c:\program files\Common Files\Ahead\Lib\MFC71U.DLL c:\program files\Common Files\Ahead\Lib\BCGCBPRO800u.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Lavasoft\Ad-Aware\aawservice.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\McAfee\MBK\MBackMonitor.exe c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe c:\program files\CyberLink\Shared Files\RichVideo.exe c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe . ************************************************************************** . Completion time: 2009-07-04 9:38 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-04 16:37 ComboFix2.txt 2009-03-11 00:51 Pre-Run: 152,892,411,904 bytes free Post-Run: 152,807,313,408 bytes free Current=4 Default=4 Failed=3 LastKnownGood=2 Sets=1,2,3,4 150 --- E O F --- 2009-06-06 18:29 |
|
|
|
Jul 4 2009, 01:06 PM
Post
#7
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Normal mode is fine for ComboFix, I was just inquiring if you tried GMER in safe mode. Please do the following: Download TFC to your desktop
It's normal after running TFC cleaner that the PC will be slower to boot the first time. NEXT
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. NEXT **Vista users - right click on the IE icon and run as administrator Run an on-line scan with Kaspersky Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
In your next reply please include
|
|
|
|
Jul 4 2009, 05:12 PM
Post
#8
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 47 Joined: 23-March 05 Member No.: 28,454 Operating System: xp |
Here ye be...
-------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0 REPORT Saturday, July 4, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Saturday, July 04, 2009 23:46:36 Records in database: 2427850 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ Scan statistics: Files scanned: 37315 Threat name: 4 Infected objects: 5 Suspicious objects: 0 Duration of the scan: 00:31:15 File name / Threat name / Threats count C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACekmqmjjtphuncib.sys.vir Infected: Trojan.Win32.Agent.chwd 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\UACfhosdcuteccjysd.dll.vir Infected: Trojan.Win32.TDSS.adzx 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\UACgbgltjjiaipawgq.dll.vir Infected: Trojan.Win32.TDSS.aegg 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\UACjskurnmvmvvnrxi.dll.vir Infected: Trojan.Win32.TDSS.adzz 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\UACwyqdirhbwmiooef.dll.vir Infected: Trojan.Win32.TDSS.adzx 1 The selected area was scanned. Malwarebytes' Anti-Malware 1.38 Database version: 2374 Windows 5.1.2600 Service Pack 3 7/4/2009 1:59:25 PM mbam-log-2009-07-04 (13-59-25).txt Scan type: Quick Scan Objects scanned: 86849 Time elapsed: 5 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 4 Registry Data Items Infected: 2 Folders Infected: 2 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3ba4271e-5c1e-48e2-b432-d8bf420dd31d} (Rogue.DeusCleaner) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\aspch (Rogue.AntiSpyCheck) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\rhcg28j0epb3 (Rogue.AntiVirusXP2008) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\WINDOWS\system32\734914 (Trojan.BHO) -> Quarantined and deleted successfully. C:\WINDOWS\system32\931928 (Trojan.BHO) -> Quarantined and deleted successfully. Files Infected: (No malicious items detected) |
|
|
|
Jul 4 2009, 05:19 PM
Post
#9
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please post a fresh DDS log and advise how the computer is running now and if there are any outstanding issues. Are you now able to access the internet without any difficulties with that computer? |
|
|
|
Jul 4 2009, 08:15 PM
Post
#10
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 47 Joined: 23-March 05 Member No.: 28,454 Operating System: xp |
Everything seems to be working nicely. No problems.
Thank you very much, DDS (Ver_09-06-26.01) - NTFSx86 Run by Karl at 19:03:48.40 on Sat 07/04/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.601 [GMT -7:00] AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe svchost.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\McAfee\MBK\MBackMonitor.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe -k netsvcs C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter c:\PROGRA~1\mcafee\msc\mcuimgr.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Documents and Settings\Karl\Desktop\dds.pif ============== Pseudo HJT Report =============== uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [NeroFilterCheck] "c:\program files\common files\ahead\lib\NeroCheck.exe" mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe" mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [McAfee Backup] c:\program files\mcafee\mbk\McAfeeDataBackup.exe mRun: [MBkLogOnHook] c:\program files\mcafee\mbk\LogOnHook.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll Trusted Zone: internet Trusted Zone: mcafee.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Notify: igfxcui - igfxdev.dll Notify: WRNotifier - WRLogonNTF.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\karl\applic~1\mozilla\firefox\profiles\1xf9wd7e.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-5-10 201320] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664] R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-5-10 359248] R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2008-5-10 144704] R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;c:\windows\system32\drivers\l251x86.sys [2008-4-23 30720] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-5-10 79304] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-5-10 35240] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-5-10 33832] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-5-10 40488] S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2008-5-10 695624] =============== Created Last 30 ================ 2009-07-04 14:21 410,984 a------- c:\windows\system32\deploytk.dll 2009-07-04 14:21 73,728 a------- c:\windows\system32\javacpl.cpl 2009-07-04 13:51 <DIR> --d----- c:\docume~1\karl\applic~1\Malwarebytes 2009-07-04 12:23 <DIR> --d----- c:\windows\system32\LogFiles 2009-07-04 09:37 <DIR> -cd----- c:\windows\system32\dllcache\cache 2009-07-04 09:26 161,792 a------- c:\windows\SWREG.exe 2009-07-04 09:26 155,136 a------- c:\windows\PEV.exe 2009-07-04 09:26 98,816 a------- c:\windows\sed.exe 2009-07-04 09:26 <DIR> --ds---- C:\CombaFix 2009-07-03 11:24 <DIR> --d----- c:\program files\CCleaner 2009-07-03 11:13 19,096 a------- c:\windows\system32\drivers\mbam.sys 2009-07-03 11:13 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-03 11:13 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware 2009-07-03 11:13 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-02 14:47 <DIR> --d----- c:\program files\Lavasoft 2009-07-02 14:47 <DIR> --d----- c:\program files\common files\Wise Installation Wizard ==================== Find3M ==================== 2009-02-23 16:21 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009022320090224\index.dat ============= FINISH: 19:04:06.98 ===============
Attached File(s)
|
|
|
|
Jul 4 2009, 08:36 PM
Post
#11
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
OK,
Everything looks good, time for some housekeeping Please do the following: Follow these steps to uninstall Combofix
![]() NEXT Now to remove the rest of the tools that we have used in fixing your machine:
NEXT Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. Thank you for your patience, and performing all of the procedures requested. Please respond one last time so we can consider the thread resolved and close it, thank-you. |
|
|
|
Jul 5 2009, 10:30 AM
Post
#12
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 47 Joined: 23-March 05 Member No.: 28,454 Operating System: xp |
Everything's working great. Thanks again.
|
|
|
|
Jul 5 2009, 10:31 AM
Post
#13
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
You are more than welcome
stay safe ~CB |
|
|
|
Jul 5 2009, 10:32 AM
Post
#14
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
20 | Wakenaam | 366 | Yesterday, 09:54 AM Last post by: Tomk |
|||
![]() |
16 | mesa215 | 282 | Yesterday, 12:05 AM Last post by: Raktor |
|||
![]() |
17 | stjohn | 360 | 19th November 2009 - 06:17 PM Last post by: CatByte |
|||
![]() |
57 | VanDavies | 662 | 19th November 2009 - 05:20 PM Last post by: CatByte |
|||
|
Time is now: 21st November 2009 - 10:04 AM |