[Resolved] HighjackThis and more will not install.
24 min read
Please try these programs
try running them in safe mode.
Please download DDS from either of these links
LINK 1
LINK 2
and save it to your desktop.
- Disable any script blocking protection
- Double click dds.pif to run the tool.
- When done, two DDS.txt's will open.
- Save both reports to your desktop.
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt.
NEXT
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
- If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
[external image: Posted Image]
Click the image to enlarge it
- In the right panel, you will see several boxes that have been checked. Uncheck the following …
- Sections
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
NEXT
We Need to check for Rootkits with RootRepeal
- Download RootRepeal from the following location and save it to your desktop.
- Zip Mirrors (Recommended)
- Primary Mirror
- Secondary Mirror
- Secondary Mirror
- Rar Mirrors - Only if you know what a RAR is and can extract it.
- Extract RootRepeal.exe from the archive.
- Open [external image: Posted Image] on your desktop.
- Click the [external image: Posted Image] tab.
- Click the [external image: Posted Image] button.
- Check all seven boxes: [external image: Posted Image]
- Push Ok
- Check the box for your main system drive (Usually C:), and press Ok.
- Allow RootRepeal to run a scan of your system. This may take some time.
- Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
NEXT
Please download Sysprot Antirootkit from >>>HERE<<<
Unzip it into a folder on your desktop.
- Double click Sysprot.exe to start the program.
- Click on the Log tab.
- In the Write to log box select ALL ITEMS
- Look near the bottom left, and Check Hidden Objects Only
- Click on the Create Log button on the bottom right.
- After a few seconds a new window should appear.
- Select Scan Root Drive. Click on the Start button.
- When it is complete a new window will appear to indicate that the scan is finished.
- The log will be saved automatically in the same folder Sysprot.exe was extracted to.
- Open the text file and copy/paste the log here.
Running DDS gave me a screen of text that talked about what the program was going to do but no reports ever popped up or appeared on my system.
GMER did nothing upon double-clicking the program.
I got this error upon running RootRepeal: "Could not read the boot sector. Try adjusting the Disk Access Level in the Opeions dialog." After clicking 'OK' on this many times, the program finally loaded. In the middle of the scan the program closed. Now when I try to load the program I get the message: "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."
Sysprot Antirootkit didn't work completely in Safe Mode, but in regular mode I was able to get this log:
SysProt AntiRootkit v1.0.1.0
by swatkat
********************************************************************************
**********
********************************************************************************
**********
No Hidden Processes found
********************************************************************************
**********
********************************************************************************
**********
Kernel Modules:
Module Name: \systemroot\system32\drivers\UACyrndgxtbir.sys
Service Name: UACd.sys
Module Base: —
Module End: —
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: —
Module Base: F65E6000
Module End: F65FE000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: —
Module Base: F8AD0000
Module End: F8AD2000
Hidden: Yes
Module Name: \systemroot\win32k.sys:1
Service Name: —
Module Base: F888E000
Module End: F8893000
Hidden: Yes
Module Name: \systemroot\win32k.sys:2
Service Name: —
Module Base: F8616000
Module End: F8625000
Hidden: Yes
********************************************************************************
**********
********************************************************************************
**********
No SSDT Hooks found
********************************************************************************
**********
********************************************************************************
**********
Kernel Hooks:
Hooked Function: ZwFlushInstructionCache
At Address: 805769AB
Jump To: 82286894
Module Name: _unknown_
Hooked Function: ZwEnumerateKey
At Address: 8056F76A
Jump To: 822DE3DC
Module Name: _unknown_
Hooked Function: IofCompleteRequest
At Address: 804E418A
Jump To: 821ECB9B
Module Name: _unknown_
Hooked Function: IofCallDriver
At Address: 804E3D45
Jump To: 821BAAF3
Module Name: _unknown_
********************************************************************************
**********
********************************************************************************
**********
IRP Hooks:
Hooked Module: C:\WINDOWS\system32\DRIVERS\aksusb.sys
Hooked IRP: IRP_MJ_CREATE
Jump To: F667A341
Hooking Module: C:\WINDOWS\system32\DRIVERS\AKSCLASS.SYS
Hooked Module: C:\WINDOWS\system32\DRIVERS\aksusb.sys
Hooked IRP: IRP_MJ_CLOSE
Jump To: F667A341
Hooking Module: C:\WINDOWS\system32\DRIVERS\AKSCLASS.SYS
Hooked Module: C:\WINDOWS\system32\DRIVERS\aksusb.sys
Hooked IRP: IRP_MJ_DEVICE_CONTROL
Jump To: F6679E65
Hooking Module: C:\WINDOWS\system32\DRIVERS\AKSCLASS.SYS
Hooked Module: C:\WINDOWS\system32\DRIVERS\aksusb.sys
Hooked IRP: IRP_MJ_INTERNAL_DEVICE_CONTROL
Jump To: F667A037
Hooking Module: C:\WINDOWS\system32\DRIVERS\AKSCLASS.SYS
Hooked Module: C:\WINDOWS\system32\DRIVERS\aksusb.sys
Hooked IRP: IRP_MJ_POWER
Jump To: F667A561
Hooking Module: C:\WINDOWS\system32\DRIVERS\AKSCLASS.SYS
Hooked Module: C:\WINDOWS\system32\DRIVERS\aksusb.sys
Hooked IRP: IRP_MJ_SYSTEM_CONTROL
Jump To: F667A143
Hooking Module: C:\WINDOWS\system32\DRIVERS\AKSCLASS.SYS
********************************************************************************
**********
********************************************************************************
**********
Ports:
Local Address: HARDYCM:1068
Remote Address: MALLARD:NETBIOS-SSN
Type: TCP
Process: System
State: ESTABLISHED
Local Address: HARDYCM:1042
Remote Address: 64.213.140.254:HTTP
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: CLOSE_WAIT
Local Address: HARDYCM:1039
Remote Address: 216.240.157.130:HTTP
Type: TCP
Process: C:\Program Files\PostgreSQL\8.1\bin\postgres.exe
State: CLOSE_WAIT
Local Address: HARDYCM:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: HARDYCM:8080
Remote Address: LOCALHOST:1088
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: HARDYCM:8080
Remote Address: LOCALHOST:1087
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: HARDYCM:8005
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
State: LISTENING
Local Address: HARDYCM:5432
Remote Address: LOCALHOST:1059
Type: TCP
Process: C:\Program Files\PostgreSQL\8.1\bin\postmaster.exe
State: ESTABLISHED
Local Address: HARDYCM:5432
Remote Address: LOCALHOST:1056
Type: TCP
Process: C:\Program Files\PostgreSQL\8.1\bin\postmaster.exe
State: ESTABLISHED
Local Address: HARDYCM:5432
Remote Address: LOCALHOST:1055
Type: TCP
Process: C:\Program Files\PostgreSQL\8.1\bin\postmaster.exe
State: ESTABLISHED
Local Address: HARDYCM:5432
Remote Address: LOCALHOST:1053
Type: TCP
Process: C:\Program Files\PostgreSQL\8.1\bin\postmaster.exe
State: ESTABLISHED
Local Address: HARDYCM:5432
Remote Address: LOCALHOST:1051
Type: TCP
Process: C:\Program Files\PostgreSQL\8.1\bin\postmaster.exe
State: ESTABLISHED
Local Address: HARDYCM:5432
Remote Address: LOCALHOST:1048
Type: TCP
Process: C:\Program Files\PostgreSQL\8.1\bin\postmaster.exe
State: ESTABLISHED
Local Address: HARDYCM:5432
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\PostgreSQL\8.1\bin\postmaster.exe
State: LISTENING
Local Address: HARDYCM:5152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Java\jre6\bin\jqs.exe
State: LISTENING
Local Address: HARDYCM:1059
Remote Address: LOCALHOST:5432
Type: TCP
Process: C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
State: ESTABLISHED
Local Address: HARDYCM:1056
Remote Address: LOCALHOST:5432
Type: TCP
Process: C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
State: ESTABLISHED
Local Address: HARDYCM:1055
Remote Address: LOCALHOST:5432
Type: TCP
Process: C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
State: ESTABLISHED
Local Address: HARDYCM:1053
Remote Address: LOCALHOST:5432
Type: TCP
Process: C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
State: ESTABLISHED
Local Address: HARDYCM:1051
Remote Address: LOCALHOST:5432
Type: TCP
Process: C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
State: ESTABLISHED
Local Address: HARDYCM:1048
Remote Address: LOCALHOST:5432
Type: TCP
Process: C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
State: ESTABLISHED
Local Address: HARDYCM:1037
Remote Address: LOCALHOST:1036
Type: TCP
Process: C:\Program Files\PostgreSQL\8.1\bin\postgres.exe
State: ESTABLISHED
Local Address: HARDYCM:1036
Remote Address: LOCALHOST:1037
Type: TCP
Process: C:\Program Files\PostgreSQL\8.1\bin\postgres.exe
State: ESTABLISHED
Local Address: HARDYCM:8080
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
State: LISTENING
Local Address: HARDYCM:8009
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
State: LISTENING
Local Address: HARDYCM:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: HARDYCM:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: HARDYCM:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: HARDYCM:138
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: HARDYCM:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: HARDYCM:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: HARDYCM:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: HARDYCM:1070
Remote Address: NA
Type: UDP
Process: C:\Program Files\Internet Explorer\iexplore.exe
State: NA
Local Address: HARDYCM:1033
Remote Address: NA
Type: UDP
Process: C:\Program Files\PostgreSQL\8.1\bin\postmaster.exe
State: NA
Local Address: HARDYCM:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: HARDYCM:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: HARDYCM:1071
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: HARDYCM:1025
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: HARDYCM:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: HARDYCM:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA
********************************************************************************
**********
********************************************************************************
**********
Hidden files/folders:
Object: C:\Documents and Settings\Administrator\Local Settings\Temp\UAC1994.tmp
Status: Hidden
Object: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\E397BF3M\UACA4URE6NCA08HDU1CA8SQY4FCAO6WAD6CAP3KAV4CART7TUICA2L3DAOCAGJXVRSCARD39I3C
AR19LR9CAQB80HECA3X0X0WCAKE1NZMCA6557JNCA7Q8W1RCAGT532HCAJXPIVFCAU328D4CATFLF59
Status: Hidden
Object: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\G5OBCJOB\UACAHE26ZRCAX65RBCCACCBG0LCA3ECZI0CA26TNM5CAXXNP4HCAABKYO7CATRP668CA3COXM6C
ACJ68U6CAUV9N8GCAU1N63RCANNG4LVCA6ZS7XLCAUM6R68CA5LJFCVCACCLAZGCAVNNNJWCAEJM2LH
Status: Hidden
Object: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IVSPKFI1\UACAGTD261CA4MIPI1CA0XQ40NCAD9G4PXCAOYZXZSCAHY0618CAGRDN2YCA3EH8T6CA7Z0AJ1C
A90RWE1CA3XYVPLCAT6MT1QCAGTE69PCA8R8N3ZCAVSYIPHCAD5YZEYCAEZJGS8CA1VTPN7CAEPBEPQ
Status: Hidden
Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: C:\System Volume Information\tracking.log
Status: Access denied
Object: C:\WINDOWS\system32\drivers\UACyrndgxtbir.sys
Status: Hidden
Object: C:\WINDOWS\system32\UACabglkyebth.dat
Status: Hidden
Object: C:\WINDOWS\system32\UAChesotxifik.db
Status: Hidden
Object: C:\WINDOWS\system32\UACiibgakcova.dll
Status: Hidden
Object: C:\WINDOWS\system32\uacinit.dll
Status: Hidden
Object: C:\WINDOWS\system32\UACmfkkwyvttt.dll
Status: Hidden
Object: C:\WINDOWS\system32\UACmpdrtfpuoi.log
Status: Hidden
Object: C:\WINDOWS\system32\UACordltmjbfo.dll
Status: Hidden
Object: C:\WINDOWS\system32\UACrpawulxjsa.dll
Status: Hidden
Object: C:\WINDOWS\system32\UACvkqovjxymj.dll
Status: Hidden
Object: C:\WINDOWS\Temp\UAC249a.tmp
Status: Hidden
Object: C:\WINDOWS\Temp\UAC586b.tmp
Status: Hidden
Object: C:\WINDOWS\Temp\UACce6b.tmp
Status: Hidden
Object: C:\WINDOWS\Temp\UACe58d.tmp
Status: Hidden
please run this batch:
- Go to Start->Run and type in notepad and hit OK.
- Then copy and paste the content of the following codebox into Notepad:
@ECHO OFF DIR /a/s C:\WINDOWS\scecli.dll >Log.txt START Log.txt DEL %0
- Save the file to your DESKTOP as "get.bat". Make sure to save it with the quotes.
- Once saved, the icon to click should look like this on your desktop:
[external image: Posted Image]
- Double click get.bat to run it. A small black box should open and close - this is normal.
A text file called log.txt should open on your desktop - copy/paste the contents of log.txt here
Volume in drive C has no label.
Volume Serial Number is B080-DFB1
Directory of C:\WINDOWS\$NtServicePackUninstall$
08/23/2001 08:00 AM 174,080 scecli.dll
1 File(s) 174,080 bytes
Directory of C:\WINDOWS\ServicePackFiles\i386
08/04/2004 03:56 AM 180,224 scecli.dll
1 File(s) 180,224 bytes
Directory of C:\WINDOWS\system32
08/04/2004 03:56 AM 60,928 scecli.dll
1 File(s) 60,928 bytes
Total Files Listed:
3 File(s) 415,232 bytes
0 Dir(s) 31,097,958,400 bytes free
Please run this tool HERE
Reboot your machine after it runs,
then do the following:
Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
- If you are using Firefox, make sure that your download settings are as follows:
- Tools->Options->Main tab
- Set to "Always ask me where to Save the files".
Link 1
Link 2
During the download, rename Combofix to Combo-Fix as follows:
[external image: Posted Image]
[external image: Posted Image]
——————————————————————–
- It is important you rename Combofix during the download, but not after.
- Please do not rename Combofix to other names, but only to the one indicated.
———————————————————–
- Double click on Combo-Fix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the "C:\Combo-Fix.txt" for further review.
———————————————————–
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
———————————————————–
NOTE: ComboFix shall request to install the Recovery Console, please ALLOW it to do so.
Please do the following:
Please export a registry key:
Go to Start > Run > copy and past in the following text:
regedit /e c:\output.txt "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa"
Then press OK
That will produce a txt file in C:\ called output(C:\output.txt)
copy/paste the content of output.txt here
Please do the following:
Please run the following reg fix:
- Copy the contents inside the Code Box below to Notepad.
- Name the file as fix.reg
- Change the Save as Type to All Files
- and Save it on the desktop
REGEDIT4 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa] "Notification Packages"=hex(7):00Make sure there are NO blank lines before REGEDIT4
You should now see a file on your desktop that looks like this:
[external image: Posted Image]
Then double-click on the fix.reg file, and when it prompts to merge say yes.
Reboot:
Once you have run the reg fix please do the following:
Navigate to the file - C:\Windows\System32\scecli.dll
Check out the size of the file. (right click > properties)
Confirm it's 60,928 bytes in size, if it is, then it's the fake. So right click & select delete
Wait 5 seconds.
Then press F5 on the keyboard to refresh
See if a new scecli.dll is created.
If the new file's size if above 100KB, please let me know.
Once you have completed those steps, delete the copies of Combofix, sVchost and !sLSc that you have on your desktop.
download a fresh copy of ComboFix from the links previously provided and run it.
scecli.dll is now over 100k.
Here is the log from ComboFix:
ComboFix 09-08-10.06 - Administrator 08/13/2009 16:50.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.194 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-
52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\-1333731407
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\jotoca._sy
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\mifu.pif
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\okodan.vbs
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\uxuze.dll
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\vovysisa.inf
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\wujomo.bin
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\zake.dl
C:\p2hhr.bat
C:\vkywt.exe
c:\windows\braviax.exe
c:\windows\cru629.dat
c:\windows\msa.exe
c:\windows\run.log
c:\windows\system32\_scui.cpl
c:\windows\system32\braviax.exe
c:\windows\system32\cru629.dat
c:\windows\system32\drivers\UACyrndgxtbir.sys
c:\windows\system32\hs7f3uhduhfukde.dll
c:\windows\system32\net.net
c:\windows\system32\UACabglkyebth.dat
c:\windows\system32\UAChesotxifik.db
c:\windows\system32\UACiibgakcova.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACmfkkwyvttt.dll
c:\windows\system32\UACmpdrtfpuoi.log
c:\windows\system32\UACordltmjbfo.dll
c:\windows\system32\UACrpawulxjsa.dll
c:\windows\system32\UACvkqovjxymj.dll
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\wisdstr.exe
c:\windows\system32\drivers\beep.sys . . . is infected!!
c:\windows\system32\proquota.exe . . . is missing!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_UACd.sys
——-\Legacy_UACd.sys
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-07-14 to 2009-08-14 )))))))))))))))))))))))))))))))
.
2009-08-13 22:47 . 2008-10-16 18:06 268648 —-a-w- c:\windows\system32\mucltui.dll
2009-08-13 22:46 . 2009-08-14 07:00 ——– d—–w- c:\windows\LastGood
2009-08-13 13:06 . 2009-08-13 13:06 ——– d–h–w- c:\windows\PIF
2009-08-12 21:02 . 2009-08-13 14:45 ——– d–h–w- C:\$AVG8.VAULT$
2009-08-12 20:59 . 2009-08-12 20:59 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-12 20:59 . 2009-08-12 20:59 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-12 20:59 . 2009-08-12 20:59 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-12 20:58 . 2009-08-13 21:32 ——– d—–w- c:\windows\system32\drivers\Avg
2009-08-12 20:24 . 2009-08-12 20:24 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2009-08-12 17:16 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-12 16:23 . 2009-08-12 16:23 ——– dc-h–w- c:\docume~1\ALLUSE~1\APPLIC~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-12 16:22 . 2009-08-12 16:22 ——– d—–w- c:\program files\Lavasoft
2009-08-12 14:54 . 2009-08-12 14:54 15237 —-a-w- c:\documents and settings\Administrator\Application Data\ynyqomafu.pif
2009-08-12 14:54 . 2009-08-12 14:54 13055 —-a-w- c:\windows\zozipaka.exe
2009-08-12 14:54 . 2009-08-12 14:54 10603 —-a-w- c:\windows\system32\zywajebaro.pif
2009-08-12 14:54 . 2009-08-12 14:54 10160 —-a-w- c:\windows\pajyzetev.vbs
2009-08-12 14:54 . 2009-08-12 14:54 19830 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\unofonom.dat
2009-08-12 14:54 . 2009-08-12 14:54 15533 —-a-w- c:\windows\kyviry.pif
2009-08-12 14:54 . 2009-08-12 14:54 11734 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\vavawivu.vbs
2009-08-11 19:57 . 2009-08-12 21:02 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\avg8
2009-08-11 19:57 . 2009-08-11 19:57 ——– d—–w- c:\program files\AVG
2009-08-11 14:53 . 2009-08-11 14:53 12641 —-a-w- c:\windows\fosurabary.com
2009-08-10 15:23 . 2009-08-10 15:23 19395 —-a-w- c:\windows\system32\vokon.vbs
2009-08-10 15:23 . 2009-08-10 15:23 19380 —-a-w- c:\windows\esylaqasu.pif
2009-08-10 15:23 . 2009-08-10 15:23 19212 —-a-w- c:\windows\mubopebab.bat
2009-08-10 15:23 . 2009-08-10 15:23 18793 —-a-w- c:\windows\system32\abydo.dll
2009-08-10 15:23 . 2009-08-10 15:23 18782 —-a-w- c:\windows\xecaduv.pif
2009-08-10 15:23 . 2009-08-10 15:23 15347 —-a-w- c:\program files\Common Files\apunoze.vbs
2009-08-10 15:23 . 2009-08-10 15:23 12497 —-a-w- c:\windows\system32\dirofopy.vbs
2009-08-10 15:23 . 2009-08-10 15:23 12408 —-a-w- c:\program files\Common Files\lexery.bat
2009-08-07 23:27 . 2009-08-10 15:08 19456 —-a-w- C:\hcel.exe
2009-08-07 23:27 . 2009-08-10 15:08 89600 —-a-w- C:\ccwygkvw.exe
2009-08-07 20:47 . 2009-08-12 17:16 ——– dc—-w- c:\windows\system32\DRVSTORE
2009-08-07 20:42 . 2009-08-12 16:22 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Lavasoft
2009-08-07 19:50 . 2009-08-12 15:30 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-07 19:50 . 2009-08-07 19:52 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-08-07 15:56 . 2009-08-07 15:56 70656 —-a-w- c:\windows\system32\drivers\prdcpcbcqhtxorjq.sys
2009-07-20 19:02 . 2009-07-20 19:02 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\3DVIA
2009-07-20 19:01 . 2007-07-19 22:14 3727720 —-a-w- c:\windows\system32\d3dx9_35.dll
2009-07-20 19:01 . 2006-09-28 20:05 2414360 —-a-w- c:\windows\system32\d3dx9_31.dll
2009-07-20 19:01 . 2009-07-20 19:01 ——– d—–w- c:\windows\Logs
2009-07-20 19:01 . 2009-07-20 19:01 ——– d—–w- c:\program files\Virtools
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-13 21:05 . 2008-02-29 20:23 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-08-12 14:54 . 2009-08-12 14:54 16382 —-a-w- c:\docume~1\ALLUSE~1\APPLIC~1\sala.bat
2009-08-12 14:54 . 2009-08-12 14:54 12476 —-a-w- c:\documents and settings\Administrator\Application Data\jaqyf.dat
2009-08-12 14:54 . 2009-08-12 14:54 15263 —-a-w- c:\docume~1\ALLUSE~1\APPLIC~1\futu.vbs
2009-08-12 14:54 . 2009-08-12 14:54 12848 —-a-w- c:\program files\Common Files\yjyqozoki.ban
2009-08-11 19:55 . 2009-02-17 16:39 ——– d—–w- c:\documents and settings\Administrator\Application Data\Move Networks
2009-08-11 19:55 . 2009-05-05 16:17 ——– d—–w- c:\program files\Coupons
2009-08-10 15:23 . 2009-08-10 15:23 14484 —-a-w- c:\docume~1\ALLUSE~1\APPLIC~1\anulob.scr
2009-08-10 15:23 . 2009-08-10 15:23 10604 —-a-w- c:\documents and settings\Administrator\Application Data\epygi.bin
2009-08-07 15:34 . 2009-08-07 15:34 1234543 —-a-w- c:\windows\system32\xa.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2007-12-05 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-20 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-04-24 413696]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-12 2000152]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-12-05 1626112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2004-08-04 53760]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-12 20:59 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Apache Software Foundation\\Tomcat 5.5\\bin\\tomcat5.exe"=
"c:\\Program Files\\Scala\\InfoChannel Content Manager 5\\TransmissionServer\\TransmissionServer_Service.exe"=
"c:\\Program Files\\Scala\\InfoChannel Content Manager 5\\ServerSupport\\ServerSupport_Service.exe"=
"c:\\Program Files\\Scala\\InfoChannel Designer 5\\ICDesigner.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [8/12/2009 1:16 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/12/2009 4:59 PM 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/12/2009 4:58 PM 297752]
R2 pgsql-8.1;PostgreSQL Database Server 8.1;c:\program files\PostgreSQL\8.1\bin\pg_ctl.exe [2/13/2006 12:43 PM 75249]
R2 ScalaSupport5;Scala Server Support;c:\program files\Scala\InfoChannel Content Manager 5\ServerSupport\ServerSupport_Service.exe [2/29/2008 4:22 PM 139776]
R2 ScalaTransmission5;Scala Transmission Server;c:\program files\Scala\InfoChannel Content Manager 5\TransmissionServer\TransmissionServer_Service.exe [2/29/2008 4:22 PM 54272]
R2 Tomcat5;Apache Tomcat;c:\program files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe [4/14/2006 2:10 PM 102400]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 10:49 AM 1029456]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\Administrator\Desktop\SysProtDrv.sys [8/13/2009 9:30 AM 44288]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-PC Antispyware 2010 - c:\program files\PC_Antispyware2010\PC_Antispyware2010.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
TCP: {7B1AC2CE-3468-431F-8EF9-FF535D61F9E7} = 206.141.192.60,206.141.193.55
FF - ProfilePath - c:\docume~1\ADMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\4kzc6og1.default\
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-14 08:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1644491937-299502267-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,59,e6,92,d7,3d,6a,a9,4f,93,fa,9f,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,59,e6,92,d7,3d,6a,a9,4f,93,fa,9f,\
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(2796)
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\PostgreSQL\8.1\bin\postmaster.exe
c:\program files\PostgreSQL\8.1\bin\postgres.exe
c:\program files\PostgreSQL\8.1\bin\postgres.exe
c:\program files\PostgreSQL\8.1\bin\postgres.exe
c:\program files\PostgreSQL\8.1\bin\postgres.exe
c:\program files\PostgreSQL\8.1\bin\postgres.exe
c:\program files\PostgreSQL\8.1\bin\postgres.exe
c:\program files\PostgreSQL\8.1\bin\postgres.exe
c:\program files\PostgreSQL\8.1\bin\postgres.exe
c:\program files\PostgreSQL\8.1\bin\postgres.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-08-14 8:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-14 12:12
Pre-Run: 30,917,615,616 bytes free
Post-Run: 31,522,205,696 bytes free
216 — E O F — 2009-08-14 07:00
Please do the following:
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
- They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')
http://forums.whatthetech.com/HighjackThis_more_will_not_install_t106057.html&view=findpost&p=587541#entry587541 Collect:: c:\documents and settings\Administrator\Application Data\ynyqomafu.pif c:\windows\zozipaka.exe c:\windows\system32\zywajebaro.pif c:\windows\pajyzetev.vbs c:\documents and settings\Administrator\Local Settings\Application Data\unofonom.dat c:\windows\kyviry.pif c:\documents and settings\Administrator\Local Settings\Application Data\vavawivu.vbs c:\windows\fosurabary.com c:\windows\system32\vokon.vbs c:\windows\esylaqasu.pif c:\windows\mubopebab.bat c:\windows\system32\abydo.dll c:\windows\xecaduv.pif c:\program files\Common Files\apunoze.vbs c:\windows\system32\dirofopy.vbs c:\program files\Common Files\lexery.bat C:\hcel.exe C:\ccwygkvw.exe c:\windows\system32\drivers\prdcpcbcqhtxorjq.sys c:\documents and settings\Administrator\Application Data\jaqyf.dat c:\docume~1\ALLUSE~1\APPLIC~1\futu.vbs c:\program files\Common Files\yjyqozoki.ban c:\docume~1\ALLUSE~1\APPLIC~1\anulob.scr c:\documents and settings\Administrator\Application Data\epygi.bin c:\windows\system32\xa.tmp RegLock:: [HKEY_USERS\S-1-5-21-1644491937-299502267-725345543-500\Software\Microsoft\Internet Explorer\User Preferences] Registry:: [HKEY_USERS\S-1-5-21-1644491937-299502267-725345543-500\Software\Microsoft\Internet Explorer\User Preferences] "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=- "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=- SRPEEK:: c:\windows\system32\proquota.exe c:\windows\system32\drivers\beep.sys
Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it shall produce a log for you.
- Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
- Ensure you are connected to the internet and click OK on the message box.
Note: If combofix asks you to update - allow it and if it asks to install the recovery console - ALLOW it
Note: Please uncheck WORDWRAP from note pad
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI