This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] ROOTKIT? MY HIJACK THIS LOG

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Since I posted this I was looking at your site a little more in depth and found a post on the topic spyware protect 2009 and this is exactly what my PC did (The popup Spyware protect 2009) although I didn't click on anything to make it come up and I already knew by the Avast popup that it wasn't good. I downloaded the MBAM and ran it like the tech told the other member to do and it found 7 infections. I removed them via MBAM and now I will post my MBAM log.

Please let me know if I need to do anything further.

Thank you very much,

April


MBAM log:


Malwarebytes' Anti-Malware 1.36
Database version: 2173
Windows 5.1.2600 Service Pack 3

5/24/2009 12:15:21 AM
mbam-log-2009-05-24 (00-15-21).txt

Scan type: Quick Scan
Objects scanned: 95317
Time elapsed: 11 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AvScan (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\sysguard.exe (Trojan.Crypt) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cpnprt2.cid (Adware.Agent) -> Quarantined and deleted successfully



Then I ran MBAM again :


Malwarebytes' Anti-Malware 1.36
Database version: 2173
Windows 5.1.2600 Service Pack 3

5/24/2009 12:15:21 AM
mbam-log-2009-05-24 (00-15-21).txt

Scan type: Quick Scan
Objects scanned: 95317
Time elapsed: 11 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AvScan (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\sysguard.exe (Trojan.Crypt) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cpnprt2.cid (Adware.Agent) -> Quarantined and deleted successfully.



MBAM Again for third time:


Malwarebytes' Anti-Malware 1.36
Database version: 2173
Windows 5.1.2600 Service Pack 3

5/24/2009 2:52:15 PM
mbam-log-2009-05-24 (14-52-15).txt

Scan type: Full Scan (C:\|)
Objects scanned: 156550
Time elapsed: 43 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{F77AA171-2C8C-427B-8621-CCAF1DB6497B}\RP513\A0061977.exe (Trojan.Crypt) -> Quarantined and deleted successfully.


Finally a fourth time:

Malwarebytes' Anti-Malware 1.36
Database version: 2173
Windows 5.1.2600 Service Pack 3

5/24/2009 3:17:44 PM
mbam-log-2009-05-24 (15-17-44).txt

Scan type: Quick Scan
Objects scanned: 94785
Time elapsed: 11 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




I will download the combofix as you have instructed to see what it comes up with and report back on my next reply.



If I'm doing this wrong by editing please let me know. I've never been very good with forums.



Thank you very much,

April












Hi,

I was playing internet poker on a site called NLOP and my Avast popped up saying Malware detected…The suggested action was to move to chest but it wouldn't let me. It said the file was being used already. I think there were more files mentioned in different popups from Avast but the last one was C:\windows\sysguard.exe and the Avast popup also said something about Win32: Rootkit-gen (RTK)

Also sometimes when I try to get on the internet it comes up browser security and won't let me access any web pages. I downloaded IE 8 to see if that would help and I can at least get on the internet for the moment.



Can you help me get rid of this? I am on a router with cable internet. Below is my Hijack this logfile it's the first time I've used Hijack this so I hope I did it right

Thank you,


April






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:56:13 PM, on 5/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Turtle\Local Settings\Temporary Internet Files\Content.IE5\MC13N9N5\RootkitRevealer[1]\RootkitRevealer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O1 - Hosts: ::1 localhost
O1 - Hosts: 94.232.248.66 browser-security.microsoft.com
O1 - Hosts: 94.232.248.66 antivirprotection.com
O1 - Hosts: 94.232.248.66 www.antivirprotection.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Intertops Poker - {A2AB1320-B1B6-40fd-A694-8197D8596FFD} - C:\Microgaming\Poker\IntertopsMPP\MPPoker.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Spin32 - 3497d1fd-bd47-4046-b167-4e4382228237 - C:\Documents and Settings\Turtle\Start Menu\Programs\Spin32\Spin32.lnk (HKCU)
O9 - Extra button: ReeferPoker - 60a501e4-a078-4cb2-8728-3fab4264f3c1 - C:\Documents and Settings\Turtle\Start Menu\Programs\ReeferPoker\ReeferPoker.lnk (HKCU)
O9 - Extra button: 32Red Poker Room - {00000000-0000-0000-0000-000000000000} - C:\MicroGaming\Poker\32RedMPP\MPPoker.exe (file missing) (HKCU)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1184715141359
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1226115272078
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://icebluez.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - http://www.worldwinner.com/games/v45/royal/royal.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47/famil…/familyfeud.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Br…OCX/flashax.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/bejewel…aploader_v6.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: YSPONUVJBGL - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Turtle\LOCALS~1\Temp\YSPONUVJBGL.exe

–
End of file - 8366 bytes
Hi,

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, (AVAST) usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Since I posted this I was looking at your site a little more in depth and found a post on the topic spyware protect 2009 and this is exactly what my PC did (The popup Spyware protect 2009) although I didn't click on anything to make it come up and I already knew by the Avast popup that it wasn't good. I downloaded the MBAM and ran it like the tech told the other member to do and it found 7 infections. I removed them via MBAM and now I will post my MBAM log. Please let me know if I need to do anything further. Thank you very much, April MBAM log: Malwarebytes' Anti-Malware 1.36 Database version: 2173 Windows 5.1.2600 Service Pack 3 5/24/2009 12:15:21 AM mbam-log-2009-05-24 (00-15-21).txt Scan type: Quick Scan Objects scanned: 95317 Time elapsed: 11 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\AvScan (Malware.Trace) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\sysguard.exe (Trojan.Crypt) -> Quarantined and deleted successfully. C:\WINDOWS\system32\cpnprt2.cid (Adware.Agent) -> Quarantined and deleted successfully Then I ran MBAM again : Malwarebytes' Anti-Malware 1.36 Database version: 2173 Windows 5.1.2600 Service Pack 3 5/24/2009 12:15:21 AM mbam-log-2009-05-24 (00-15-21).txt Scan type: Quick Scan Objects scanned: 95317 Time elapsed: 11 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\SOFTWARE\Microsoft\Windows\CurrentVersion\Run (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\AvScan (Malware.Trace) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\sysguard.exe (Trojan.Crypt) -> Quarantined and deleted successfully. C:\WINDOWS\system32\cpnprt2.cid (Adware.Agent) -> Quarantined and deleted successfully. MBAM Again for third time: Malwarebytes' Anti-Malware 1.36 Database version: 2173 Windows 5.1.2600 Service Pack 3 5/24/2009 2:52:15 PM mbam-log-2009-05-24 (14-52-15).txt Scan type: Full Scan (C:\|) Objects scanned: 156550 Time elapsed: 43 minute(s), 6 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\System Volume Information\_restore{F77AA171-2C8C-427B-8621-CCAF1DB6497B}\RP513\A0061977.exe (Trojan.Crypt) -> Quarantined and deleted successfully. Finally a fourth time: Malwarebytes' Anti-Malware 1.36 Database version: 2173 Windows 5.1.2600 Service Pack 3 5/24/2009 3:17:44 PM mbam-log-2009-05-24 (15-17-44).txt Scan type: Quick Scan Objects scanned: 94785 Time elapsed: 11 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I will download the combofix as you have instructed to see what it comes up with and report back on my next reply. If I'm doing this wrong by editing please let me know. I've never been very good with forums. Thank you very much, April
Hi, Please do not run any further scans or fix anything on your own. Stick with me, till I give you the all clean. Absence of symptoms does not mean your computer is completely clean. Thank-you CB
Hi again :)

Ok I will stick with you. I ran the combofix and copied the log.


Combofix log:


ComboFix 09-05-23.04 - Turtle 05/24/2009 15:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.895.534 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\absolutely1900cff.exe
AV: avast! antivirus 4.8.1335 [VPS 090524-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\AutoRun.inf

.
((((((((((((((((((((((((( Files Created from 2009-04-24 to 2009-05-24 )))))))))))))))))))))))))))))))
.

2009-05-24 05:03 . 2009-05-24 05:03 0 —-a-w c:\windows\nsreg.dat
2009-05-24 05:03 . 2009-05-24 05:03 ——– d—–w c:\documents and settings\Turtle\Local Settings\Application Data\Mozilla
2009-05-24 03:59 . 2009-05-24 03:59 ——– d-sh–w c:\documents and settings\LocalService\IETldCache
2009-05-24 03:51 . 2009-05-24 03:51 ——– d—–w c:\documents and settings\Turtle\Application Data\Malwarebytes
2009-05-24 03:50 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-24 03:50 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-24 03:50 . 2009-05-24 03:50 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-24 03:50 . 2009-05-24 03:51 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-24 02:35 . 2009-05-24 02:35 ——– d—–w c:\program files\Trend Micro
2009-05-24 02:02 . 2009-05-24 02:02 ——– d-sh–w c:\documents and settings\Turtle\IECompatCache
2009-05-24 01:59 . 2009-05-24 01:59 ——– d-sh–w c:\documents and settings\Turtle\PrivacIE
2009-05-24 01:58 . 2009-05-24 01:58 ——– d-sh–w c:\documents and settings\Turtle\IETldCache
2009-05-24 01:55 . 2009-05-24 01:55 ——– d—–w c:\windows\ie8updates
2009-05-24 01:52 . 2009-05-24 01:54 ——– dc-h–w c:\windows\ie8
2009-05-24 01:51 . 2009-05-24 01:51 ——– d—–w c:\program files\Microsoft Silverlight
2009-05-24 01:48 . 2009-04-25 05:30 102400 -c—-w c:\windows\system32\dllcache\iecompat.dll
2009-05-23 00:08 . 2009-05-23 00:32 ——– d—–w c:\documents and settings\Turtle\Application Data\Ventrilo
2009-05-23 00:07 . 2009-05-23 00:07 ——– d—–w c:\program files\Ventrilo
2009-05-23 00:06 . 2009-05-23 00:06 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-05-04 08:31 . 2009-05-24 08:37 ——– d—–w c:\program files\PokerPages Software
2009-04-28 07:02 . 2009-04-28 07:01 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-04-28 07:02 . 2009-04-28 07:02 299352 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-04-28 07:02 . 2009-04-28 07:02 25440 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-04-28 07:02 . 2009-04-28 07:02 165728 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-04-28 07:02 . 2009-04-28 07:02 15688 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-04-28 07:02 . 2009-04-28 07:02 343888 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-04-28 07:02 . 2009-04-28 07:02 289632 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-04-28 07:01 . 2009-04-28 07:01 82784 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-04-28 07:01 . 2009-04-28 07:01 1629024 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-04-28 07:01 . 2009-04-28 07:01 212848 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-04-28 07:01 . 2009-04-28 07:01 64160 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-04-28 07:01 . 2009-04-28 07:01 40288 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-04-28 07:01 . 2009-04-28 07:01 632680 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-04-28 07:00 . 2009-04-28 07:00 539512 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-04-28 07:00 . 2009-04-28 07:00 552808 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-04-28 07:00 . 2009-04-28 07:00 2324808 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-04-28 07:00 . 2009-04-28 07:00 626000 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-04-28 07:00 . 2009-04-28 07:00 516440 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-04-28 07:00 . 2009-04-28 07:00 953168 —-a-w c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-04-28 06:55 . 2009-04-28 06:55 ——– dc-h–w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-04-28 06:55 . 2009-03-12 08:17 2902048 -c–a-w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-24 04:22 . 2007-07-17 23:55 ——– d—–w c:\program files\Google
2009-05-24 02:15 . 2009-02-16 00:31 ——– d—–w c:\program files\NLOP
2009-05-24 02:14 . 2008-12-08 23:44 ——– d—–w c:\program files\Yahoo!
2009-05-24 02:14 . 2008-12-08 23:44 ——– d—–w c:\documents and settings\All Users\Application Data\Yahoo!
2009-05-24 02:13 . 2008-10-25 06:55 ——– d—–w c:\program files\Tiger Gaming
2009-05-24 02:13 . 2009-04-22 01:50 ——– d—–w c:\documents and settings\Turtle\Application Data\OzyPoker
2009-05-24 02:12 . 2007-07-17 23:02 ——– d–h–w c:\program files\InstallShield Installation Information
2009-05-15 22:22 . 2009-05-15 22:22 ——– d—–w c:\program files\ANI
2009-05-15 22:22 . 2009-05-15 22:22 ——– d—–w c:\program files\Airlink101
2009-05-15 22:21 . 2007-07-17 23:02 ——– d—–w c:\program files\Common Files\InstallShield
2009-04-28 07:02 . 2008-05-16 15:58 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-04-26 10:13 . 2009-02-12 10:55 ——– d—–w c:\documents and settings\Turtle\Application Data\NLOP
2009-04-22 06:05 . 2008-02-22 05:09 ——– d—–w c:\program files\BugsysClub Software
2009-04-21 23:46 . 2007-07-17 23:56 ——– d—–w c:\program files\Java
2009-04-21 23:46 . 2009-04-21 23:46 152576 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-10 00:27 . 2009-04-10 00:27 ——– d—–w c:\program files\MSXML 4.0
2009-04-08 18:03 . 2008-02-26 07:05 ——– d—–w c:\program files\Motorola Phone Tools
2009-04-08 18:02 . 2009-04-08 18:02 ——– d—–w c:\program files\Motorola
2009-04-08 17:59 . 2008-01-05 00:57 ——– d—–w c:\program files\LiveUpdate
2009-04-01 05:36 . 2009-04-01 05:36 57344 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-464674f0-n\Decora-SSE.dll
2009-04-01 05:36 . 2009-04-01 05:36 24064 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-39534128-n\Decora-D3D.dll
2009-04-01 05:36 . 2009-04-01 05:36 499712 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-33db9f33-n\msvcp71.dll
2009-04-01 05:36 . 2009-04-01 05:36 499712 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-33db9f33-n\jmc.dll
2009-04-01 05:36 . 2009-04-01 05:36 348160 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-33db9f33-n\msvcr71.dll
2009-03-10 08:54 . 2009-03-10 08:54 57344 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\37\3976f065-6e62e27c-n\Decora-SSE.dll
2009-03-10 08:54 . 2009-03-10 08:54 24064 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\37\2c4a0065-37c70e75-n\Decora-D3D.dll
2009-03-10 08:54 . 2009-03-10 08:54 315392 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-7294eed5-n\jogl.dll
2009-03-10 08:54 . 2009-03-10 08:54 20480 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-7294eed5-n\jogl_awt.dll
2009-03-10 08:54 . 2009-03-10 08:54 114688 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-7294eed5-n\jogl_cg.dll
2009-03-10 08:54 . 2009-03-10 08:54 503808 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-4d039cda-n\msvcp71.dll
2009-03-10 08:54 . 2009-03-10 08:54 499712 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-4d039cda-n\jmc.dll
2009-03-10 08:54 . 2009-03-10 08:54 348160 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-4d039cda-n\msvcr71.dll
2009-03-10 08:54 . 2009-03-10 08:54 20480 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-3d32dde5-n\gluegen-rt.dll
2009-03-10 08:52 . 2009-03-10 08:52 152576 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-03-09 09:19 . 2008-09-21 14:06 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-08 08:34 . 2001-08-23 12:00 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 08:34 . 2001-08-23 12:00 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 08:33 . 2001-08-23 12:00 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 08:33 . 2001-08-23 12:00 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 08:32 . 2001-08-23 12:00 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 08:32 . 2001-08-23 12:00 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 08:31 . 2001-08-23 12:00 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 08:31 . 2001-08-23 12:00 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 08:31 . 2001-08-23 12:00 45568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 08:22 . 2001-08-23 12:00 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2001-08-23 12:00 284160 —-a-w c:\windows\system32\pdh.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sprestrt\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111v3 Smart Wizard.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk
backup=c:\windows\pss\NETGEAR WG111v3 Smart Wizard.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Turtle^Start Menu^Programs^Startup^MSN Pictures Displayer.lnk]
path=c:\documents and settings\Turtle\Start Menu\Programs\Startup\MSN Pictures Displayer.lnk
backup=c:\windows\pss\MSN Pictures Displayer.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaw.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ReeferPoker\\client.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Spin32\\client.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4/28/2009 3:02 AM 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/4/2008 8:51 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/4/2008 8:51 PM 20560]
R3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCCFLTR.SYS [12/6/2007 1:29 AM 14092]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [11/16/2007 11:56 AM 550272]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [12/16/2007 1:30 AM 713728]
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\DRIVERS\wg111v3.sys –> c:\windows\system32\DRIVERS\wg111v3.sys [?]
S3 YSPONUVJBGL;YSPONUVJBGL;c:\docume~1\Turtle\LOCALS~1\Temp\YSPONUVJBGL.exe –> c:\docume~1\Turtle\LOCALS~1\Temp\YSPONUVJBGL.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-05-19 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 07:00]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys
SafeBoot-Lavasoft Ad-Aware Service


.
——- Supplementary Scan ——-
.
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: {{A2AB1320-B1B6-40fd-A694-8197D8596FFD} - c:\microgaming\Poker\IntertopsMPP\MPPoker.exe
FF - ProfilePath - c:\documents and settings\Turtle\Application Data\Mozilla\Firefox\Profiles\s4wemmbt.default\
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-24 15:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
Completion time: 2009-05-24 15:44
ComboFix-quarantined-files.txt 2009-05-24 19:43

Pre-Run: 50,088,988,672 bytes free
Post-Run: 51,593,424,896 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /usepmtimer /NoExecute=OptIn /maxmem=896

191 — E O F — 2009-05-13 06:49



Thank you very much,


April
I have not recieved a reply from bleeping computers as of yet but I was looking at the site a little more and found a thread about the Spyware Protect 2009 and the MBAM so I downloaded it and tried it but I wasn't working with anyone through the other site. I was basically starved for answers so I went searching. Thank you, April
Hi Cat, I apoligize I was waiting to see replies in my email and hadn't visited the other site to see the reply so I didn't know it was there. I would like to continue working with you so how do I close the other thread? Thank you very much, April
That's fine, I'm happy to help you just reply in the other thread that you are receiving help at another forum so the thread can be closed. And apologize for any inconvenience to the helper…it's not a problem, it happens all the time.
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

KillAll::

File::
c:\docume~1\Turtle\LOCALS~1\Temp\YSPONUVJBGL.exe

Driver::
YSPONUVJBGL

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Hi,

Again Thank you very much…I truly appreciate your help.


I followed your instructions. I disabled the antivirus but when combofix restarted the PC it came back on…Should I have unchecked it in the startup menu through msconfig?


Here is the log that I recieved:


ComboFix 09-05-24.06 - Turtle 05/25/2009 0:55.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.895.613 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\absolutely1900cff.exe
Command switches used :: c:\documents and settings\Turtle\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090524-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

FILE ::
c:\docume~1\Turtle\LOCALS~1\Temp\YSPONUVJBGL.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_YSPONUVJBGL
——-\Service_YSPONUVJBGL


((((((((((((((((((((((((( Files Created from 2009-04-25 to 2009-05-25 )))))))))))))))))))))))))))))))
.

2009-05-24 05:03 . 2009-05-24 05:03 0 —-a-w c:\windows\nsreg.dat
2009-05-24 05:03 . 2009-05-24 05:03 ——– d—–w c:\documents and settings\Turtle\Local Settings\Application Data\Mozilla
2009-05-24 03:59 . 2009-05-24 03:59 ——– d-sh–w c:\documents and settings\LocalService\IETldCache
2009-05-24 03:51 . 2009-05-24 03:51 ——– d—–w c:\documents and settings\Turtle\Application Data\Malwarebytes
2009-05-24 03:50 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-24 03:50 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-24 03:50 . 2009-05-24 03:50 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-24 03:50 . 2009-05-24 03:51 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-24 02:35 . 2009-05-24 02:35 ——– d—–w c:\program files\Trend Micro
2009-05-24 02:02 . 2009-05-24 02:02 ——– d-sh–w c:\documents and settings\Turtle\IECompatCache
2009-05-24 01:59 . 2009-05-24 01:59 ——– d-sh–w c:\documents and settings\Turtle\PrivacIE
2009-05-24 01:58 . 2009-05-24 01:58 ——– d-sh–w c:\documents and settings\Turtle\IETldCache
2009-05-24 01:55 . 2009-05-24 01:55 ——– d—–w c:\windows\ie8updates
2009-05-24 01:52 . 2009-05-24 01:54 ——– dc-h–w c:\windows\ie8
2009-05-24 01:51 . 2009-05-24 01:51 ——– d—–w c:\program files\Microsoft Silverlight
2009-05-24 01:48 . 2009-04-25 05:30 102400 -c—-w c:\windows\system32\dllcache\iecompat.dll
2009-05-23 00:08 . 2009-05-23 00:32 ——– d—–w c:\documents and settings\Turtle\Application Data\Ventrilo
2009-05-23 00:07 . 2009-05-23 00:07 ——– d—–w c:\program files\Ventrilo
2009-05-23 00:06 . 2009-05-23 00:06 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-05-04 08:31 . 2009-05-24 08:37 ——– d—–w c:\program files\PokerPages Software

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-24 04:22 . 2007-07-17 23:55 ——– d—–w c:\program files\Google
2009-05-24 02:15 . 2009-02-16 00:31 ——– d—–w c:\program files\NLOP
2009-05-24 02:14 . 2008-12-08 23:44 ——– d—–w c:\program files\Yahoo!
2009-05-24 02:14 . 2008-12-08 23:44 ——– d—–w c:\documents and settings\All Users\Application Data\Yahoo!
2009-05-24 02:13 . 2008-10-25 06:55 ——– d—–w c:\program files\Tiger Gaming
2009-05-24 02:13 . 2009-04-22 01:50 ——– d—–w c:\documents and settings\Turtle\Application Data\OzyPoker
2009-05-24 02:12 . 2007-07-17 23:02 ——– d–h–w c:\program files\InstallShield Installation Information
2009-05-15 22:22 . 2009-05-15 22:22 ——– d—–w c:\program files\ANI
2009-05-15 22:22 . 2009-05-15 22:22 ——– d—–w c:\program files\Airlink101
2009-05-15 22:21 . 2007-07-17 23:02 ——– d—–w c:\program files\Common Files\InstallShield
2009-04-26 10:13 . 2009-02-12 10:55 ——– d—–w c:\documents and settings\Turtle\Application Data\NLOP
2009-04-22 06:05 . 2008-02-22 05:09 ——– d—–w c:\program files\BugsysClub Software
2009-04-21 23:46 . 2007-07-17 23:56 ——– d—–w c:\program files\Java
2009-04-21 23:46 . 2009-04-21 23:46 152576 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-10 00:27 . 2009-04-10 00:27 ——– d—–w c:\program files\MSXML 4.0
2009-04-08 18:03 . 2008-02-26 07:05 ——– d—–w c:\program files\Motorola Phone Tools
2009-04-08 18:02 . 2009-04-08 18:02 ——– d—–w c:\program files\Motorola
2009-04-08 17:59 . 2008-01-05 00:57 ——– d—–w c:\program files\LiveUpdate
2009-04-01 05:36 . 2009-04-01 05:36 57344 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-464674f0-n\Decora-SSE.dll
2009-04-01 05:36 . 2009-04-01 05:36 24064 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-39534128-n\Decora-D3D.dll
2009-04-01 05:36 . 2009-04-01 05:36 499712 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-33db9f33-n\msvcp71.dll
2009-04-01 05:36 . 2009-04-01 05:36 499712 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-33db9f33-n\jmc.dll
2009-04-01 05:36 . 2009-04-01 05:36 348160 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-33db9f33-n\msvcr71.dll
2009-03-10 08:54 . 2009-03-10 08:54 57344 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\37\3976f065-6e62e27c-n\Decora-SSE.dll
2009-03-10 08:54 . 2009-03-10 08:54 24064 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\37\2c4a0065-37c70e75-n\Decora-D3D.dll
2009-03-10 08:54 . 2009-03-10 08:54 315392 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-7294eed5-n\jogl.dll
2009-03-10 08:54 . 2009-03-10 08:54 20480 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-7294eed5-n\jogl_awt.dll
2009-03-10 08:54 . 2009-03-10 08:54 114688 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-7294eed5-n\jogl_cg.dll
2009-03-10 08:54 . 2009-03-10 08:54 503808 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-4d039cda-n\msvcp71.dll
2009-03-10 08:54 . 2009-03-10 08:54 499712 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-4d039cda-n\jmc.dll
2009-03-10 08:54 . 2009-03-10 08:54 348160 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-4d039cda-n\msvcr71.dll
2009-03-10 08:54 . 2009-03-10 08:54 20480 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-3d32dde5-n\gluegen-rt.dll
2009-03-10 08:52 . 2009-03-10 08:52 152576 —-a-w c:\documents and settings\Turtle\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-03-09 09:19 . 2008-09-21 14:06 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-08 08:34 . 2001-08-23 12:00 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 08:34 . 2001-08-23 12:00 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 08:33 . 2001-08-23 12:00 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 08:33 . 2001-08-23 12:00 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 08:32 . 2001-08-23 12:00 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 08:32 . 2001-08-23 12:00 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 08:31 . 2001-08-23 12:00 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 08:31 . 2001-08-23 12:00 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 08:31 . 2001-08-23 12:00 45568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 08:22 . 2001-08-23 12:00 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2001-08-23 12:00 284160 —-a-w c:\windows\system32\pdh.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-24_19.41.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-25 04:58 . 2009-05-25 04:58 16384 c:\windows\Temp\Perflib_Perfdata_69c.dat
+ 2009-05-25 04:58 . 2009-05-25 04:58 16384 c:\windows\Temp\Perflib_Perfdata_4d4.dat
+ 2009-05-25 04:46 . 2009-05-25 04:46 16384 c:\windows\Temp\Perflib_Perfdata_4c8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sprestrt

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111v3 Smart Wizard.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk
backup=c:\windows\pss\NETGEAR WG111v3 Smart Wizard.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Turtle^Start Menu^Programs^Startup^MSN Pictures Displayer.lnk]
path=c:\documents and settings\Turtle\Start Menu\Programs\Startup\MSN Pictures Displayer.lnk
backup=c:\windows\pss\MSN Pictures Displayer.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaw.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ReeferPoker\\client.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Spin32\\client.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/4/2008 8:51 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/4/2008 8:51 PM 20560]
R3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCCFLTR.SYS [12/6/2007 1:29 AM 14092]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [11/16/2007 11:56 AM 550272]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [12/16/2007 1:30 AM 713728]
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\DRIVERS\wg111v3.sys –> c:\windows\system32\DRIVERS\wg111v3.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: {{A2AB1320-B1B6-40fd-A694-8197D8596FFD} - c:\microgaming\Poker\IntertopsMPP\MPPoker.exe
FF - ProfilePath - c:\documents and settings\Turtle\Application Data\Mozilla\Firefox\Profiles\s4wemmbt.default\
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-25 00:58
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1288)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2009-05-25 1:04 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-25 05:03
ComboFix2.txt 2009-05-24 19:44

Pre-Run: 51,761,115,136 bytes free
Post-Run: 51,677,667,328 bytes free

191 — E O F — 2009-05-13 06:49
Hi,

Everything ran fine, you did well,

now please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

NOTE: Make sure you disable your Security Programs first, so there are no conflicts with the scanner


  • Open the Kaspersky WebScanner
    page.
  • Click on the 🖼Click to load external image (Posted Image) button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the 🖼Click to load external image (Posted Image) button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the 🖼Click to load external image (Posted Image) …button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the 🖼Click to load external image (Posted Image) button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.
Hi, Here is the MBAM scan log and I'm getting ready to complete the next step. Thank you, April MBAM scan: Malwarebytes' Anti-Malware 1.36 Database version: 2178 Windows 5.1.2600 Service Pack 3 5/25/2009 3:45:51 PM mbam-log-2009-05-25 (15-45-51).txt Scan type: Quick Scan Objects scanned: 81323 Time elapsed: 4 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi, I am unable to do the kaspersky scan. I keep getting an error message, I'm including a screen shot of the message. I went to the java site and clicked download and it came up very quickly saying that I have the recommended java. Just let me know what you would like me to do next. Thank you, April

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI