This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hijackthis, Combofix Logs and Infections Removal Help

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, apologies If I have not done this correctly…. First post.

I was unable to run Spybot and Malwarebytes Combofix in Safe Mode or Unsafe, I can click the .exe shortcuts but nothing happens. I realised I had a problem when my google started redirecting to other sites then just crashing or going to blank screens. I got rounfd this by renaming combofix and Hijackthis and rans the checks… See my logs below,

After my combofix finished I receieved a couple of error messages " windows or eexplorer couldn't run catchme.tmp do you want to send a report to microsoft etc" there was another error with catchme.dmp or similar… then I was able to run a spybot which didn't find anything, I then tried to run malwarebytes but not running again same as before.

Also tried to re-install msn but not running same as other programs, I would like to know how to completely remove these files as I think I have not completed the procedure but need some guidance…


Thanks in advance for any support
Kevin

ComboFix 09-02-21.01 - kev 2009-02-23 22:15:15.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.701 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix1.exe
AV: AVG 7.5.552 *On-access scanning enabled* (Updated)

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\_006126_.tmp.dll
c:\windows\system32\_006127_.tmp.dll
c:\windows\system32\_006128_.tmp.dll
c:\windows\system32\_006129_.tmp.dll
c:\windows\system32\_006135_.tmp.dll
c:\windows\system32\_006136_.tmp.dll
c:\windows\system32\_006137_.tmp.dll
c:\windows\system32\_006138_.tmp.dll
c:\windows\system32\_006139_.tmp.dll
c:\windows\system32\_006141_.tmp.dll
c:\windows\system32\_006142_.tmp.dll
c:\windows\system32\_006145_.tmp.dll
c:\windows\system32\_006146_.tmp.dll
c:\windows\system32\_006148_.tmp.dll
c:\windows\system32\_006149_.tmp.dll
c:\windows\system32\_006150_.tmp.dll
c:\windows\system32\_006152_.tmp.dll
c:\windows\system32\_006155_.tmp.dll
c:\windows\system32\_006156_.tmp.dll
c:\windows\system32\_006160_.tmp.dll
c:\windows\system32\_006161_.tmp.dll
c:\windows\system32\_006163_.tmp.dll
c:\windows\system32\_006166_.tmp.dll
c:\windows\system32\_006168_.tmp.dll
c:\windows\system32\_006169_.tmp.dll
c:\windows\system32\_006170_.tmp.dll
c:\windows\system32\_006171_.tmp.dll
c:\windows\system32\_006172_.tmp.dll
c:\windows\system32\_006175_.tmp.dll
c:\windows\system32\_006176_.tmp.dll
c:\windows\system32\_006177_.tmp.dll
c:\windows\system32\_006178_.tmp.dll
c:\windows\system32\_006179_.tmp.dll
c:\windows\system32\_006184_.tmp.dll
c:\windows\system32\_006186_.tmp.dll
c:\windows\system32\drivers\UACnqqoedbw.sys
c:\windows\system32\UACcmalexvk.log
c:\windows\system32\UACebafmxfb.db
c:\windows\system32\UACixrohntt.log
c:\windows\system32\UAClwxidmir.dll
c:\windows\system32\UACpatneaon.dll
c:\windows\system32\UACqeexdore.dll
c:\windows\system32\UACulqpppmn.dll
c:\windows\system32\UACvpevxews.dat
c:\windows\system32\UACwwkvdjyq.dll
c:\windows\system32\UACxvbuyfbo.log

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys
——-\Legacy_{FBE1D620-5418-4AAE-A0F0-316D590663A1}
——-\Service_{FBE1D620-5418-4aae-A0F0-316D590663A1}


((((((((((((((((((((((((( Files Created from 2009-01-23 to 2009-02-23 )))))))))))))))))))))))))))))))
.

2009-02-23 21:58 . 2009-02-23 21:59 d——– C:\ComboFixx
2009-02-23 21:33 . 2009-02-23 21:33 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-23 21:33 . 2009-02-23 21:33 d——– c:\documents and settings\kev\Application Data\Malwarebytes
2009-02-23 21:33 . 2009-02-23 21:33 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-23 21:33 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-23 21:33 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-23 21:25 . 2009-02-23 21:25 d——– c:\program files\Trend Micro
2009-02-22 19:16 . 2009-02-22 20:05 d——– c:\windows\system32\NtmsData
2009-02-21 19:02 . 2009-02-23 17:23 5,187 –a—— c:\windows\system32\uacinit.dll
2009-02-09 00:05 . 2009-02-09 00:05 d——– c:\program files\Panasonic
2009-02-09 00:05 . 2006-02-27 11:45 36,864 –a—— c:\windows\system32\SDDEVMGR.dll
2009-02-06 22:41 . 2006-10-04 14:06 1,197,294 ——— c:\windows\system32\dllcache\sysmain.sdb
2009-02-06 22:41 . 2006-10-04 14:06 764,868 ——— c:\windows\system32\dllcache\apph_sp.sdb
2009-02-06 22:41 . 2006-10-04 14:06 217,118 ——— c:\windows\system32\dllcache\apphelp.sdb
2009-02-06 22:40 . 2009-02-06 22:40 d——– c:\program files\Windows Media Connect 2
2009-02-06 22:37 . 2009-02-06 22:38 d——– c:\windows\system32\drivers\UMDF
2009-02-06 22:36 . 2009-02-06 22:38 d——– c:\documents and settings\kev\Application Data\vlc
2009-02-06 22:34 . 2009-02-06 22:34 d——– c:\program files\VideoLAN

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-23 17:20 ——— d—–w c:\documents and settings\kev\Application Data\AVG7
2009-02-22 20:28 ——— d–h–r c:\documents and settings\kev\Application Data\yahoo!
2009-02-22 20:28 ——— d—–w c:\program files\Yahoo!
2009-02-22 20:28 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo!
2009-02-22 15:20 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-22 15:18 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-02-09 00:05 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-05 22:01 7,304 —-a-w c:\windows\TMP0001.TMP
2008-10-15 08:57 83,544 ——w c:\documents and settings\kev\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 158208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2007-12-27 219136]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
–a—— 2003-04-30 05:00 315392 c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
–a—— 2008-10-16 16:13 590848 c:\progra~1\Grisoft\AVG7\avgcc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMMGAG]
–a—— 2003-01-17 09:32 64000 c:\progra~1\ThinkPad\UTILIT~1\PWRMONIT.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMMLREF]
–a—— 2003-01-17 09:32 20480 c:\program files\ThinkPad\Utilities\BMMLREF.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
–a—— 2003-01-10 11:50 106551 c:\windows\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZEJMNAP]
–a—— 2002-12-24 10:01 204800 c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ibmmessages]
–a—— 2003-01-07 22:52 495616 c:\program files\IBM\Messages By IBM\ibmmessages.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
——— 2007-12-27 22:30 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QCWLICON]
–a—— 2003-03-27 10:06 53248 c:\program files\ThinkPad\ConnectUtilities\QCWLICON.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
——— 2009-01-26 15:31 2144088 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
–a—— 2002-06-18 08:01 155648 c:\program files\VERITAS Software\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-05-02 04:15 75520 c:\program files\Java\jre1.5.0_12\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
–a—— 2003-06-24 13:33 561152 c:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
–a—— 2003-06-24 13:34 126976 c:\program files\Synaptics\SynTP\SynTPLpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPHOTKEY]
–a—— 2003-01-25 01:37 94208 c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPMN]
–a—— 2003-02-17 08:30 32835 c:\program files\ThinkPad\Utilities\TpKmapMn.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
–a—— 2002-10-18 19:07 87751 c:\windows\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
–a—— 2005-03-22 18:56 25088 c:\windows\system32\Ati2mdxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
–a—— 2004-08-04 07:56 380416 c:\windows\system32\irprops.cpl

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EXSHOW95.EXE]
–a—— 2001-09-07 16:18 45056 c:\windows\system32\exshow95.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\S3TRAY2]
–a—— 2001-10-12 06:32 69632 c:\windows\system32\S3Tray2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TP4EX]
–a—— 2002-09-04 09:05 53248 c:\windows\system32\TP4EX.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"aawservice"=2 (0x2)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\William Hill Poker\\UA.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=

R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2007-12-27 2295]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2007-12-27 15360]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-03-16 13352]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{0fb395e0-b4ff-11dd-9b17-00054e41e1f6}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{0fb395e2-b4ff-11dd-9b17-00054e41e1f6}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{837f8450-b7e1-11dd-9b1e-00054e41e1f6}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{837f8451-b7e1-11dd-9b1e-00054e41e1f6}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{837f8452-b7e1-11dd-9b1e-00054e41e1f6}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{83ff6fc0-b751-11dd-9b1c-00054e41e1f6}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{83ff6fc1-b751-11dd-9b1c-00054e41e1f6}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{83ff6fc2-b751-11dd-9b1c-00054e41e1f6}]
\Shell\AutoRun\command - E:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{8b8e3dc0-b419-11dd-9b0f-00054e41e1f6}]
\Shell\AutoRun\command - E:\AutoRun.exe
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
MSConfigStartUp-PostSetupCheck - c:\windows\System32\atgban.dll
MSConfigStartUp-SpywareBot - c:\program files\SpywareBot\SpywareBot.exe
MSConfigStartUp-tgcmd - c:\program files\Support.com\bin\tgcmd.exe
MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\YahooMessenger.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = hxxp:///
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\kev\Application Data\Mozilla\Firefox\Profiles\h2r5ca2b.default\
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJPI150_12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-23 22:35:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-627446036-2653871946-2631661031-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*`%T%,%]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-627446036-2653871946-2631661031-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*`%T%,%\O penWithList]
@Class="Shell"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-02-23 22:39:04 - machine was rebooted [kev]
ComboFix-quarantined-files.txt 2009-02-23 22:38:20

Pre-Run: 28,845,436,928 bytes free
Post-Run: 29,725,700,096 bytes free

234 — E O F — 2009-02-22 14:45:03

My Hijackthis log…….

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:22:24, on 23/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http:///
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE

–
End of file - 4029 bytes

[Managed to get Malwarebytes to run, see Log below found a few things that correspond with combofix UAC things. What next ?

Malwarebytes' Anti-Malware 1.34
Database version: 1798
Windows 5.1.2600 Service Pack 2

24/02/2009 18:20:07
mbam-log-2009-02-24 (18-20-07).txt

Scan type: Full Scan (C:\|)
Objects scanned: 146167
Time elapsed: 42 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 11

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{16b435f6-b6ce-4f24-a568-944b27ed919c} (Adware.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Qoobox\Quarantine\C\WINDOWS\system32\UAClwxidmir.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACpatneaon.dll.vir (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACulqpppmn.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACwwkvdjyq.dll.vir (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP107\A0084925.dll (Rogue.SpyCleaner) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP107\A0085117.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP125\A0100140.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP125\A0100141.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP125\A0100142.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP125\A0100144.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
Hello.

A lot of things were removed by Combofix. Unfortunately one was a rootkit/backdoor.

[external image: Posted Image]Rootkit Threat

Unfortunatly One or more of the identified infections is a Rootkit/backdoor trojan.

IMPORTANT NOTE: Rootkits and backdoor Trojans are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information which they send back to the hacker. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to gain unauthorized access to a computer and take control of it without your knowledge.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connect again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Although the rootkit has been identified and may be removed, your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because this malware has been removed the computer is now secure. In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read: Should you decide not to follow that advice, we will do our best to help clean the computer of any infections but we cannot guarantee it to be trustworthy or that the removal will be successful. Tell me what you want to do.

With Regards,
Extremeboy
Hi again, All fingers and thumbs there :) I am willing to reformat if needed. Just a small inconvenience looking for my office discs again and other software…

Ok so is it safe to save and dump to new image…. my personal pics, word, excel sheets charts etc? As not sure if a checker will find any hidden remainders…



Also looking for a way to save my outlook express contents as a few emails needed if possible.

Here is the auctiva statement where this may have came from…. funny how they say "very low risk"

Will a standard re-image to factory contents from partition be good enough? I have an IBM T40 series with the preloaded recovery system.


http://community.auctiva.com/eve/forums/a/…0411/m/61310502

Thanks in advance

Kevin
Hello again.

Format/Reinstall is a good decision. :)

Ok so is it safe to save and dump to new image…. my personal pics, word, excel sheets charts etc? As not sure if a checker will find any hidden remainders…

Yes.

When backing up files and datas there are mainly 2 general guidelines:

1) Backup all your important data files, pictures, music, work etc… and save it onto an external hard-drive. These files usually include .doc, .txt, .mp3, .jpg etc…
2) Do not backup any executables files or any window files. These include .exe's, .scr, .com, .pif etc… as they may contain traces of malware. Also, .html or .htm files that are webpages should also be avoided.

Then you can do a reinstall. This will not remove any of your files or pictures etc… it just reinstall windows onto your Drive. If you partitioned your drive it would be easier because you just have to reinstall windows on that one drive, and all your other data will be safe.

However a format will remove everything. If you need help reinstall or formating please start another topic in the Microsoft Windows™ forum as this forum is only removing malware infections. Thanks.

Hope that helps.

With Regards,
Extremeboy
Thanks again for speedy response, I have seen a few topics on how to remove but not sure what files to dump/delete etc… I don't have a partition so just the standard IBM image that is partitioned etc so will lose everything. Not really wanting to reformat, do you mind guiding me to clean the mess up? Then I can re-format if have any further suspicions. I probably have out of date java etc…. Do you need any fresh logs?
Hello again.

Sure we will remove this mess. :)

I want to see a more detailed log so run this tool instead please.

Download and Run OTScanIT2

Now download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.

Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanIt2 folder and double-click on OTScanIt2.exe to start the program (if you are running on Vista then right-click the program and choose Run as Administrator).
  • Do not change any settings.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
  • Close Notepad (saving the change if necessry).
Use the Add Reply button and Attach the scan back here (do not copy/paste it as it will be too big to fit into the post). It will be located in the OTScanIt2 folder and named OTScanIt.txt.

Note: I will need to leave now and won't be back for the next 3-4 hours. Just wanted to let you know in case you wait here wondering where I am.. Sorry for any inconveniences.

With Regards,
Extremeboy
Hi some fresh logs, I have noticed some microsoft processes stopped in msconfig running services these are
Application management, Computer browser, indexing service, com+ system application, logical disc manager administrative service, logical disc manager, wired autoconfig, extensible authentication protocal service, health key and certificate management service, windows installer, network access protection agent, net logon, and a few more is this ok and normal….



Hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:27:53, on 26/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http:///
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE

–
End of file - 4716 bytes



Malware Log
Malwarebytes' Anti-Malware 1.34
Database version: 1807
Windows 5.1.2600 Service Pack 3

26/02/2009 22:36:44
mbam-log-2009-02-26 (22-36-44).txt

Scan type: Quick Scan
Objects scanned: 46447
Time elapsed: 4 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hello.

Did you follow my instructions in my previous post? Did I ask for a Hijackthis log or MBAM Scan log? Please read my previous post and post the OTScanIT log…

Hi some fresh logs, I have noticed some microsoft processes stopped in msconfig running services these are
Application management, Computer browser, indexing service, com+ system application, logical disc manager administrative service, logical disc manager, wired autoconfig, extensible authentication protocal service, health key and certificate management service, windows installer, network access protection agent, net logon, and a few more is this ok and normal….

That is definitely NOT normal… We will see what we can do later. Do you have your Windows XP CD available? We may need it later.

With Regards,
Extremeboy
hi, apologies didn't see your log. I will do this later about 5pm GMT and post the logs. I do not have a recovery/op disc, my recovery to factory settings is partitioned on the drive (not 100% but thinks this is same for all IBM). Thanks Kevin
Hello.

That looks better. Please run GMER and an online scan. Tell me, how is your computer running currently?

Install Antivirus

An anti-virus is essential in keeping your computer safe while surfing the Internet. Please install a (ONE) free anti-virus program from one of the links below:

Update It after the installation is complete please.

Uninstall AVG 7 afterwards because it's not longer being updated.

Download and Run Scan with GMER

We will use GMER to scan for rootkits.
  • Double-click on Gmer.exe to start the program.
  • Allow the gmer.sys driver to load if asked.
  • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan…click NO.
  • Click the >>>
  • Click on Settings, then check the first five settings:
    • System Protection and Tracing
    • Processes
    • Save created processes to the log
    • Drivers
    • Save loaded drivers to the log
  • You will be prompted to restart your computer. Please do so.

  • After the reboot, run Gmer again and click on the Rootkit tab.
    • Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
    • Make sure all other boxes on the right of the screen are checked, EXCEPT for Show All.
    • Click on the Scan and wait for the scan to finish.
      Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan. You will know that the scan is done when the Stop buttons turns back to Scan.
    • When completed, click on the Copy button and right-click on your Desktop, choose New>Text document. Once the file is created, open it and right-click again and choose Paste. Save the file as gmer.txt and copy the information in your next reply.
    If GMER doesn't work in Normal Mode try running it in Safe Mode

    Important!:Please do not select the Show all checkbox during the scan..

    Run Scan with Kaspersky

    Please do a scan with Kaspersky Online Scanner.

    If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


    • Please disable your realtime protection software before proceeding. Refer to this page if you are unsure how.
    • Open the Kaspersky Scanner page.
    • Click on Accept and install any components it needs.
    • The program will install and then begin downloading the latest definition files.
    • After the files have been downloaded on the left side of the page in the Scan section select My Computer
    • This will start the program and scan your system.
    • The scan will take a while, so be patient and let it run.
    • Once the scan is complete, click on View scan report
    • Now, click on the Save Report as button.
    • Save the file to your desktop.
    • Copy and paste that information in your next post.
    You can refer to this animation by sundavis.

    Post back with:
    -GMER scan log
    -Kaspersky scan log
    -How's your computer running right now?

    Attach back with:
    - New OTScanIT 2 log

    With Regards,
    Extremeboy
Hello.

That looks better. Please run GMER and an online scan. Tell me, how is your computer running currently?

Install Antivirus

An anti-virus is essential in keeping your computer safe while surfing the Internet. Please install a (ONE) free anti-virus program from one of the links below:

Update It after the installation is complete please.

Uninstall AVG 7 afterwards because it's not longer being updated.

Download and Run Scan with GMER

We will use GMER to scan for rootkits.
  • Double-click on Gmer.exe to start the program.
  • Allow the gmer.sys driver to load if asked.
  • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan…click NO.
  • Click the >>>
  • Click on Settings, then check the first five settings:
    • System Protection and Tracing
    • Processes
    • Save created processes to the log
    • Drivers
    • Save loaded drivers to the log
  • You will be prompted to restart your computer. Please do so.

  • After the reboot, run Gmer again and click on the Rootkit tab.
    • Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
    • Make sure all other boxes on the right of the screen are checked, EXCEPT for Show All.
    • Click on the Scan and wait for the scan to finish.
      Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan. You will know that the scan is done when the Stop buttons turns back to Scan.
    • When completed, click on the Copy button and right-click on your Desktop, choose New>Text document. Once the file is created, open it and right-click again and choose Paste. Save the file as gmer.txt and copy the information in your next reply.
    If GMER doesn't work in Normal Mode try running it in Safe Mode

    Important!:Please do not select the Show all checkbox during the scan..

    Run Scan with Kaspersky

    Please do a scan with Kaspersky Online Scanner.

    If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


    • Please disable your realtime protection software before proceeding. Refer to this page if you are unsure how.
    • Open the Kaspersky Scanner page.
    • Click on Accept and install any components it needs.
    • The program will install and then begin downloading the latest definition files.
    • After the files have been downloaded on the left side of the page in the Scan section select My Computer
    • This will start the program and scan your system.
    • The scan will take a while, so be patient and let it run.
    • Once the scan is complete, click on View scan report
    • Now, click on the Save Report as button.
    • Save the file to your desktop.
    • Copy and paste that information in your next post.
    You can refer to this animation by sundavis.

    Post back with:
    -GMER scan log
    -Kaspersky scan log
    -How's your computer running right now?

    Attach back with:
    - New OTScanIT 2 log

    With Regards,
    Extremeboy
Hi, Kapersky updating data now, here is my system logs from gmer. Got a warning when first reboot by gmer from windows see below. also forgot to mention a few times in recent weeks system has been crashing with blue screen and think was dumprep 0 -k %systemroot% -0 -k some sort of memory error i think hangs have to hold power button in. This is an intermittant fault…. When typing this text sursorc keeps movign back like that …. will post other logs asap…

System recovered from serious problem….


BCCode : 100000d1 BCP1 : 00000004 BCP2 : 00000002 BCP3 : 00000001
BCP4 : 8687171C OSVer : 5_1_2600 SP : 3_0 Product : 256_1

details…

C:\DOCUME~1\kev\LOCALS~1\Temp\WERb538.dir00\Mini022609-02.dmp
C:\DOCUME~1\kev\LOCALS~1\Temp\WERb538.dir00\sysdata.xml

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-02-27 22:24:23
Windows 5.1.2600 Service Pack 3


—- Kernel code sections - GMER 1.0.14 —-

PAGE CLASSPNP.SYS!ClassInitialize + F4 F762742C 4 Bytes [ F2, 67, 76, 86 ]
PAGE CLASSPNP.SYS!ClassInitialize + FF F7627437 4 Bytes [ 2A, 14, 76, 86 ]
PAGE CLASSPNP.SYS!ClassInitialize + 10A F7627442 4 Bytes [ 04, 68, 76, 86 ]
PAGE CLASSPNP.SYS!ClassInitialize + 111 F7627449 4 Bytes [ F8, 67, 76, 86 ]
PAGE CLASSPNP.SYS!ClassInitialize + 118 F7627450 4 Bytes [ FE, 67, 76, 86 ]
PAGE …

—- User code sections - GMER 1.0.14 —-

.text C:\WINDOWS\Explorer.EXE[268] ADVAPI32.dll!CryptDestroyKey 77DE9E9C 7 Bytes JMP 02442B93
.text C:\WINDOWS\Explorer.EXE[268] ADVAPI32.dll!CryptDecrypt 77DEA109 7 Bytes JMP 02442B50
.text C:\WINDOWS\Explorer.EXE[268] ADVAPI32.dll!CryptEncrypt 77DEE340 7 Bytes JMP 02442B14
.text C:\WINDOWS\Explorer.EXE[268] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 02442AF9
.text C:\WINDOWS\Explorer.EXE[268] WS2_32.dll!send 71AB4C27 5 Bytes JMP 02442985
.text C:\WINDOWS\Explorer.EXE[268] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 02442A77
.text C:\WINDOWS\Explorer.EXE[268] WS2_32.dll!recv 71AB676F 5 Bytes JMP 024429BD
.text C:\WINDOWS\Explorer.EXE[268] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 024429F5
.text C:\Program Files\Mozilla Firefox\firefox.exe[3852] ADVAPI32.dll!CryptDestroyKey 77DE9E9C 7 Bytes JMP 00F82B93
.text C:\Program Files\Mozilla Firefox\firefox.exe[3852] ADVAPI32.dll!CryptDecrypt 77DEA109 7 Bytes JMP 00F82B50
.text C:\Program Files\Mozilla Firefox\firefox.exe[3852] ADVAPI32.dll!CryptEncrypt 77DEE340 7 Bytes JMP 00F82B14
.text C:\Program Files\Mozilla Firefox\firefox.exe[3852] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00F82AF9
.text C:\Program Files\Mozilla Firefox\firefox.exe[3852] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00F82985
.text C:\Program Files\Mozilla Firefox\firefox.exe[3852] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00F82A77
.text C:\Program Files\Mozilla Firefox\firefox.exe[3852] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00F829BD
.text C:\Program Files\Mozilla Firefox\firefox.exe[3852] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00F829F5

—- Devices - GMER 1.0.14 —-

AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device \Driver\Tcpip \Device\Ip avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\Tcpip \Device\Tcp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Cdrom \Device\CdRom0 867667F2
Device \Driver\Tcpip \Device\Udp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Disk \Device\Harddisk0\DR0 867667F2
Device \Driver\Tcpip \Device\RawIp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\IPMULTICAST avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Direct Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Direct Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Direct Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Direct Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Direct Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Direct Access Component/Sonic Solutions)

—- Threads - GMER 1.0.14 —-

Thread 4:788 86766B6A
Thread 4:844 867688FA
Thread 4:848 86760E5E
Thread 4:852 86766E8C
Thread 4:1080 86760886
Thread 4:1092 86760886
Thread 4:1916 86799040
Thread 4:1920 86786140
Thread 4:1924 867CED70
Thread 4:1928 867721C0
Thread 4:1932 86766C96
Thread 4:2044 86799040
Thread 4:132 86786140
Thread 4:136 867CED70
Thread 4:156 867721C0

—- Registry - GMER 1.0.14 —-

Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACnqqoedbw.sys
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACnqqoedbw.sys
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACulqpppmn.dll
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uacsr \\?\globalroot\systemroot\system32\UACvpevxews.dat
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uaclog \\?\globalroot\systemroot\system32\UACwwkvdjyq.dll
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uacmask \\?\globalroot\systemroot\system32\UACpatneaon.dll
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uacmal \\?\globalroot\systemroot\system32\UACebafmxfb.db
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uacrem \\?\globalroot\systemroot\system32\UACqeexdore.dll
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UAClwxidmir.dll
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@UACproc \\?\globalroot\systemroot\system32\UACcmalexvk.log
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uacurls \\?\globalroot\systemroot\system32\UACixrohntt.log
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uacerrors \\?\globalroot\systemroot\system32\UACxvbuyfbo.log

—- Disk sectors - GMER 1.0.14 —-

Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior; MBR rootkit code detected <– ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 01: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 02: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 60: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 61: rootkit-like behavior; malicious code @ sector 0x8f28480 size 0x1e8
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior; copy of MBR

—- EOF - GMER 1.0.14 —-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI