katsrock
Hello oldman960,
While trying to run haxfix, a window kept popping up called "ping.exe - Bad Image". This notice contained the following text: "The application or DLL C:\WINNT\system32\CSLSP.DLL is not a valid windows image. Please check this against your installation diskette." An "OK" button was displayed.
Haxfix would continually pause it's next task until I closed this "Bad Image" window. I probably closed it 25 times. Is this a problem? Anyway, the log did finish.
I searched for C:\combofix.txt file, but could not find it. How do you search for it or find it?
I unchecked the "Use a proxy server…" and still no internet. In fact, the "IE cannot display…" comes up even faster since I ran Combofix or Haxfix. Up till the running of Haxfix or Combofix, the page seemed to load but was seemed to be blocked after it loaded.??
My email is no longer receiving or sending, so I had to download the haxfix and hjt logs to disk so I could post them.
Here are my logs you asked for except for the combofix I couldn't find:
Rooter Log:
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3
C:\ [Fixed] - NTFS - (Total:76316 Mo/Free:2002 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
Tue 03/10/2009|13:14
———————-\\ Processes..
–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINNT\system32\csrss.exe
———- \??\C:\WINNT\system32\winlogon.exe
———- C:\WINNT\system32\services.exe
———- C:\WINNT\system32\lsass.exe
———- C:\WINNT\system32\svchost.exe
———- C:\WINNT\system32\svchost.exe
———- C:\WINNT\System32\svchost.exe
———- C:\WINNT\System32\svchost.exe
———- C:\WINNT\System32\svchost.exe
———- C:\WINNT\Explorer.EXE
———- C:\WINNT\system32\spoolsv.exe
———- C:\WINNT\system32\svchost.exe
———- C:\WINNT\System32\hkcmd.exe
———- C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
———- C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
———- C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
———- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
———- C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
———- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
———- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
———- C:\Program Files\Messenger\msmsgs.exe
———- C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
———- C:\WINNT\system32\ctfmon.exe
———- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
———- C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
———- C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
———- C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
———- C:\Program Files\ewido\security suite\ewidoctrl.exe
———- C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
———- C:\WINNT\System32\svchost.exe
———- C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
———- C:\WINNT\System32\alg.exe
———- C:\WINNT\system32\cmd.exe
———- C:\Rooter$\RK.exe
———————-\\ Search..
———————-\\ ROOTKIT !!
1 - "C:\Rooter$\Rooter_1.txt" - Tue 03/10/2009|13:16
———————-\\ Scan completed at 13:16
HAXFIX logfile - by Marckie
version 5.066
2009-03-10 20:04:11.84
running from C:\HaxFix
— Checking for Haxdoor —
checking for a3d files
a3d files found
fltr.a3d
checking for matching notify keys
no matching notify keys found
checking for matching services
no matching services found
checking for matching safeboot services
no matching safeboot services found
— Checking for Goldun - Spybanker —
checking for SSODL keys
no ssodl keys found
checking for notify keys
no notify keys found
checking for services
no services found
checking for random used files and services
– these files are not necessarily malicious
– scanning all folders
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Movie Maker\MEDIATAB0.DAT
C:\Documents and Settings\Owner\My Documents\My Music\Led Zeppelin\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\The Beatles\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\Various Artists\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\Thin Lizzy\Dedication- The Very Best of Thin Lizzy\AlbumArt_{01110B79-A40D-458E-8643-3234EF5AB3B8}_Large.jpg
C:\Documents and Settings\Owner\My Documents\My Music\Thin Lizzy\Dedication- The Very Best of Thin Lizzy\Folder.jpg
C:\Program Files\Windows Media Connect 2\wmccds.exe
C:\Program Files\Windows Media Connect 2\WMCCFG.exe
C:\Program Files\HP\Digital Imaging\Data\projectstemplates\flowers1_2F_A4.{B439E359-B2DF-4336-AD0E-E567C24D365C}.creativetempl
C:\Program Files\HP\Digital Imaging\Data\projectstemplates\pt-summerC4x6H1template.png
C:\Program Files\Intel\ANS\ianswxp.cat
C:\Program Files\McAfee\McAfee Firewall\fwnetcfg.dll
C:\Program Files\Microsoft Works\1033\Wizards\inspuus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\notrnus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\nottsus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\schbrus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\schesus.wwp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Html\Help\MusicMatch_Radio.htm
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonadd.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttondelete.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonexplorer.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonjewelcase.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonsmartsplit.bmp
C:\Program Files\PC-Doctor for Windows\Java\Native Help\en\ftsform.htm
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP2\change.log.1
C:\WINNT\$NtServicePackUninstall$\fxsperf.dll
C:\WINNT\$NtServicePackUninstall$\snmptrap.exe
C:\WINNT\$NtServicePackUninstall$\tty.dll
C:\WINNT\$NtUninstallKB840374$\hscupd.exe
C:\WINNT\Fonts\ega40857.fon
C:\WINNT\Fonts\modern.fon
C:\WINNT\inf\netel90a.inf
C:\WINNT\inf\netel980.inf
C:\WINNT\inf\netdf650.PNF
C:\WINNT\inf\mtxvideo.PNF
C:\WINNT\inf\netbcm4u.PNF
C:\WINNT\system32\c_10tman.dll
C:\WINNT\system32\eventvwr.exe
C:\WINNT\system32\npwmsdrm.dll
C:\WINNT\system32\uwdf.exe
C:\WINNT\system32\wdfmgr.exe
C:\WINNT\$hf_mig$\KB902400\SP2QFE\migregdb.exe
C:\WINNT\ServicePackFiles\i386\fxsperf.dll
C:\WINNT\ServicePackFiles\i386\snmptrap.exe
C:\WINNT\ServicePackFiles\i386\tty.dll
C:\WINNT\system32\dllcache\eventvwr.exe
C:\WINNT\system32\dllcache\modern.fon
C:\WINNT\system32\en-US\icardie.dll.mui
C:\WINNT\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem21.CAT
C:\WINNT\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem22.CAT
no matching random used services found
checking for browser helper objects
no known browser helper objects found
checking for appinit files
no files found
checking for possible infected files
please submit these file here: http://www.bleepingcomputer.com/submit-mal….php?channel=11
no files found
checking for Active Setup Installed Components
no known Active Setup Installed Components found
checking iexplore.exe
iexplore.exe is not infected
— Checking for other Goldun, Spybanker and Haxdoor files —
C:\WINNT\system32\P2.INI
— Catchme logfile - thank you Gmer —
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-10 20:15:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"AppInit_DLLs"="\\?\C:\WINNT\System32\lpt3.bsp"
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
— Analysing Catchme logfile —
no matching regkeys found
Finished!
HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:42, on 2009-03-10
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: KTBho Class - {25EDC164-41A6-47C3-80BD-5E4FBE1BA7AB} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O2 - BHO: XBTB05988 - {5C43B8A2-24E8-4336-B86E-A94558E10C60} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Kaboodle Toolbar - {92857633-2441-4A14-8236-DFCB97AD3E87} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O3 - Toolbar: Blue Dot Toolbar - {2751F3AD-5600-44cc-A653-8A24CAE5AF6D} - C:\Program Files\Blue Dot Toolbar\bdtool.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft Office Quick Launcher] iau1.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [HP Component Manager] "c:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [4156015816] "C:\WINNT\system32\manporeg.exe"
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: searchle it! - {0376FDB9-A132-4929-8336-8CB3B2CAFCC0} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles2.js (HKCU)
O9 - Extra button: my!searchles - {3B72BA76-67BE-11DB-8373-B622A1EF5492} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles.js (HKCU)
O16 - DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} (RegUserCfgUI Class) - http://us.dl1.yimg.com/download.yahoo.com/…_1/yregucfg.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1165704139859
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SentinelProtectionServer - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
–
End of file - 8013 bytes
Thanks.
While trying to run haxfix, a window kept popping up called "ping.exe - Bad Image". This notice contained the following text: "The application or DLL C:\WINNT\system32\CSLSP.DLL is not a valid windows image. Please check this against your installation diskette." An "OK" button was displayed.
Haxfix would continually pause it's next task until I closed this "Bad Image" window. I probably closed it 25 times. Is this a problem? Anyway, the log did finish.
I searched for C:\combofix.txt file, but could not find it. How do you search for it or find it?
I unchecked the "Use a proxy server…" and still no internet. In fact, the "IE cannot display…" comes up even faster since I ran Combofix or Haxfix. Up till the running of Haxfix or Combofix, the page seemed to load but was seemed to be blocked after it loaded.??
My email is no longer receiving or sending, so I had to download the haxfix and hjt logs to disk so I could post them.
Here are my logs you asked for except for the combofix I couldn't find:
Rooter Log:
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3
C:\ [Fixed] - NTFS - (Total:76316 Mo/Free:2002 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
Tue 03/10/2009|13:14
———————-\\ Processes..
–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINNT\system32\csrss.exe
———- \??\C:\WINNT\system32\winlogon.exe
———- C:\WINNT\system32\services.exe
———- C:\WINNT\system32\lsass.exe
———- C:\WINNT\system32\svchost.exe
———- C:\WINNT\system32\svchost.exe
———- C:\WINNT\System32\svchost.exe
———- C:\WINNT\System32\svchost.exe
———- C:\WINNT\System32\svchost.exe
———- C:\WINNT\Explorer.EXE
———- C:\WINNT\system32\spoolsv.exe
———- C:\WINNT\system32\svchost.exe
———- C:\WINNT\System32\hkcmd.exe
———- C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
———- C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
———- C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
———- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
———- C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
———- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
———- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
———- C:\Program Files\Messenger\msmsgs.exe
———- C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
———- C:\WINNT\system32\ctfmon.exe
———- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
———- C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
———- C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
———- C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
———- C:\Program Files\ewido\security suite\ewidoctrl.exe
———- C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
———- C:\WINNT\System32\svchost.exe
———- C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
———- C:\WINNT\System32\alg.exe
———- C:\WINNT\system32\cmd.exe
———- C:\Rooter$\RK.exe
———————-\\ Search..
———————-\\ ROOTKIT !!
1 - "C:\Rooter$\Rooter_1.txt" - Tue 03/10/2009|13:16
———————-\\ Scan completed at 13:16
HAXFIX logfile - by Marckie
version 5.066
2009-03-10 20:04:11.84
running from C:\HaxFix
— Checking for Haxdoor —
checking for a3d files
a3d files found
fltr.a3d
checking for matching notify keys
no matching notify keys found
checking for matching services
no matching services found
checking for matching safeboot services
no matching safeboot services found
— Checking for Goldun - Spybanker —
checking for SSODL keys
no ssodl keys found
checking for notify keys
no notify keys found
checking for services
no services found
checking for random used files and services
– these files are not necessarily malicious
– scanning all folders
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Movie Maker\MEDIATAB0.DAT
C:\Documents and Settings\Owner\My Documents\My Music\Led Zeppelin\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\The Beatles\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\Various Artists\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\Thin Lizzy\Dedication- The Very Best of Thin Lizzy\AlbumArt_{01110B79-A40D-458E-8643-3234EF5AB3B8}_Large.jpg
C:\Documents and Settings\Owner\My Documents\My Music\Thin Lizzy\Dedication- The Very Best of Thin Lizzy\Folder.jpg
C:\Program Files\Windows Media Connect 2\wmccds.exe
C:\Program Files\Windows Media Connect 2\WMCCFG.exe
C:\Program Files\HP\Digital Imaging\Data\projectstemplates\flowers1_2F_A4.{B439E359-B2DF-4336-AD0E-E567C24D365C}.creativetempl
C:\Program Files\HP\Digital Imaging\Data\projectstemplates\pt-summerC4x6H1template.png
C:\Program Files\Intel\ANS\ianswxp.cat
C:\Program Files\McAfee\McAfee Firewall\fwnetcfg.dll
C:\Program Files\Microsoft Works\1033\Wizards\inspuus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\notrnus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\nottsus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\schbrus.wwp
C:\Program Files\Microsoft Works\1033\Wizards\schesus.wwp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Html\Help\MusicMatch_Radio.htm
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonadd.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttondelete.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonexplorer.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonjewelcase.bmp
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Skins\Zephyr\fw_buttonsmartsplit.bmp
C:\Program Files\PC-Doctor for Windows\Java\Native Help\en\ftsform.htm
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP2\change.log.1
C:\WINNT\$NtServicePackUninstall$\fxsperf.dll
C:\WINNT\$NtServicePackUninstall$\snmptrap.exe
C:\WINNT\$NtServicePackUninstall$\tty.dll
C:\WINNT\$NtUninstallKB840374$\hscupd.exe
C:\WINNT\Fonts\ega40857.fon
C:\WINNT\Fonts\modern.fon
C:\WINNT\inf\netel90a.inf
C:\WINNT\inf\netel980.inf
C:\WINNT\inf\netdf650.PNF
C:\WINNT\inf\mtxvideo.PNF
C:\WINNT\inf\netbcm4u.PNF
C:\WINNT\system32\c_10tman.dll
C:\WINNT\system32\eventvwr.exe
C:\WINNT\system32\npwmsdrm.dll
C:\WINNT\system32\uwdf.exe
C:\WINNT\system32\wdfmgr.exe
C:\WINNT\$hf_mig$\KB902400\SP2QFE\migregdb.exe
C:\WINNT\ServicePackFiles\i386\fxsperf.dll
C:\WINNT\ServicePackFiles\i386\snmptrap.exe
C:\WINNT\ServicePackFiles\i386\tty.dll
C:\WINNT\system32\dllcache\eventvwr.exe
C:\WINNT\system32\dllcache\modern.fon
C:\WINNT\system32\en-US\icardie.dll.mui
C:\WINNT\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem21.CAT
C:\WINNT\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem22.CAT
no matching random used services found
checking for browser helper objects
no known browser helper objects found
checking for appinit files
no files found
checking for possible infected files
please submit these file here: http://www.bleepingcomputer.com/submit-mal….php?channel=11
no files found
checking for Active Setup Installed Components
no known Active Setup Installed Components found
checking iexplore.exe
iexplore.exe is not infected
— Checking for other Goldun, Spybanker and Haxdoor files —
C:\WINNT\system32\P2.INI
— Catchme logfile - thank you Gmer —
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-10 20:15:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"AppInit_DLLs"="\\?\C:\WINNT\System32\lpt3.bsp"
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
— Analysing Catchme logfile —
no matching regkeys found
Finished!
HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:42, on 2009-03-10
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://new.kentuckysportsradio.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: KTBho Class - {25EDC164-41A6-47C3-80BD-5E4FBE1BA7AB} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O2 - BHO: XBTB05988 - {5C43B8A2-24E8-4336-B86E-A94558E10C60} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Kaboodle Toolbar - {92857633-2441-4A14-8236-DFCB97AD3E87} - C:\PROGRA~1\kaboodle\KABOOD~1\KTBar.dll
O3 - Toolbar: Blue Dot Toolbar - {2751F3AD-5600-44cc-A653-8A24CAE5AF6D} - C:\Program Files\Blue Dot Toolbar\bdtool.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft Office Quick Launcher] iau1.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [HP Component Manager] "c:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [4156015816] "C:\WINNT\system32\manporeg.exe"
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: searchle it! - {0376FDB9-A132-4929-8336-8CB3B2CAFCC0} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles2.js (HKCU)
O9 - Extra button: my!searchles - {3B72BA76-67BE-11DB-8373-B622A1EF5492} - C:\Program Files\Searchles.com\Searchles Browser Buttons\searchles.js (HKCU)
O16 - DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} (RegUserCfgUI Class) - http://us.dl1.yimg.com/download.yahoo.com/…_1/yregucfg.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1165704139859
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SentinelProtectionServer - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
–
End of file - 8013 bytes
Thanks.