whyme?
Topic Starter
my hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:10:51 AM, on 06/09/2009
Platform: Unknown Windows (WinNT 6.01.3164)
MSIE: Internet Explorer v8.00 (8.00.7260.0000)
Boot mode: Normal
Running processes:
A:\Windows\System32\smss.exe
A:\Windows\system32\csrss.exe
A:\Windows\system32\wininit.exe
A:\Windows\system32\csrss.exe
A:\Windows\system32\services.exe
A:\Windows\system32\lsass.exe
A:\Windows\system32\lsm.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\nvvsvc.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\winlogon.exe
A:\Windows\System32\svchost.exe
A:\Windows\System32\svchost.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\WUDFHost.exe
A:\Windows\system32\Dwm.exe
A:\Windows\Explorer.EXE
A:\Windows\system32\svchost.exe
A:\Windows\system32\taskhost.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\svchost.exe
A:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
A:\Windows\system32\svchost.exe
A:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
A:\Windows\system32\svchost.exe
A:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
A:\Windows\System32\StikyNot.exe
A:\Windows\system32\SearchIndexer.exe
A:\Program Files\Windows Media Player\wmpnetwk.exe
A:\Windows\System32\svchost.exe
A:\Windows\system32\svchost.exe
A:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
A:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
A:\Windows\system32\sppsvc.exe
A:\Windows\system32\WUDFHost.exe
A:\Program Files\Internet Download Manager\IDMan.exe
A:\Windows\system32\SearchProtocolHost.exe
A:\Program Files\Mozilla Firefox\firefox.exe
A:\Windows\system32\taskhost.exe
A:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
A:\Windows\system32\SearchFilterHost.exe
A:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - A:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - A:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - A:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [VirtualCloneDrive] "A:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "A:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] A:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-21-899037044-396731412-349137126-1001\..\Run: [RESTART_STICKY_NOTES] A:\Windows\System32\StikyNot.exe (User '?')
O8 - Extra context menu item: Download all links with IDM - A:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - A:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - A:\Program Files\Internet Download Manager\IEExt.htm
O13 - Gopher Prefix:
O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} (F5 Networks CacheCleaner) - https://employees.cpr.ca/vdesk/cachecleaner…,2008,0212,2003
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://employees.cpr.ca/vdesk/terminal/InstallerControl.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - Winlogon Notify: !SASWinLogon - A:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - A:\Windows\System32\DreamScene.dll
O23 - Service: Google Update Service (gupdate1ca16133877e5) (gupdate1ca16133877e5) - Google Inc. - A:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: MBAMService - Malwarebytes Corporation - A:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - A:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - A:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: sofatnet Service (sofatnet) - Unknown owner - A:\Windows\system32\sofatnet.exe (file missing)
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - A:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - A:\Windows\System32\TUProgSt.exe
I've removed those files I mentioned in the description multiple times with Malwarebytes,Superantispyware and TrojanRemover,but they keep coming back.Makes my Firefox hang-up constantly,and my machine painfully slow at times.
Rootrepeal and dds aren't compatible with 7 unfortunately.Any help would be greatly appreciated.Thanks in advance.
I know nobody has asked for this,but this is an example of my Malwarebytes scan that I keep deleting,but they just keep comin' back:
Malwarebytes' Anti-Malware 1.40
Database version: 2720
Windows 6.1.7260
30/08/2009 22:47:48
mbam-log-2009-08-30 (22-47-48).txt
Scan type: Quick Scan
Objects scanned: 86477
Time elapsed: 3 minute(s), 44 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 7
Registry Values Infected: 11
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 6
Memory Processes Infected:
A:\Windows\System32\sofatnet.exe (Backdoor.Bot) -> Unloaded process successfully.
Memory Modules Infected:
a:\Windows\System32\evdoserver.dll (Trojan.Agent) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Protection System (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\BuildW (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\FirstInstallFlag (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mEv (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Ulrn (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Update (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateNew (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
A:\Program Files\Protection System (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
Files Infected:
a:\Windows\System32\evdoserver.dll (Trojan.Agent) -> Delete on reboot.
A:\Windows\System32\dvdpaly.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
A:\Windows\System32\wiwow64.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
A:\Windows\System32\FInstall.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
A:\Windows\System32\sofatnet.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
A:\Windows\sc.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:10:51 AM, on 06/09/2009
Platform: Unknown Windows (WinNT 6.01.3164)
MSIE: Internet Explorer v8.00 (8.00.7260.0000)
Boot mode: Normal
Running processes:
A:\Windows\System32\smss.exe
A:\Windows\system32\csrss.exe
A:\Windows\system32\wininit.exe
A:\Windows\system32\csrss.exe
A:\Windows\system32\services.exe
A:\Windows\system32\lsass.exe
A:\Windows\system32\lsm.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\nvvsvc.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\winlogon.exe
A:\Windows\System32\svchost.exe
A:\Windows\System32\svchost.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\WUDFHost.exe
A:\Windows\system32\Dwm.exe
A:\Windows\Explorer.EXE
A:\Windows\system32\svchost.exe
A:\Windows\system32\taskhost.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\svchost.exe
A:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
A:\Windows\system32\svchost.exe
A:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
A:\Windows\system32\svchost.exe
A:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
A:\Windows\System32\StikyNot.exe
A:\Windows\system32\SearchIndexer.exe
A:\Program Files\Windows Media Player\wmpnetwk.exe
A:\Windows\System32\svchost.exe
A:\Windows\system32\svchost.exe
A:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
A:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
A:\Windows\system32\sppsvc.exe
A:\Windows\system32\WUDFHost.exe
A:\Program Files\Internet Download Manager\IDMan.exe
A:\Windows\system32\SearchProtocolHost.exe
A:\Program Files\Mozilla Firefox\firefox.exe
A:\Windows\system32\taskhost.exe
A:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
A:\Windows\system32\SearchFilterHost.exe
A:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - A:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - A:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - A:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [VirtualCloneDrive] "A:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "A:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] A:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-21-899037044-396731412-349137126-1001\..\Run: [RESTART_STICKY_NOTES] A:\Windows\System32\StikyNot.exe (User '?')
O8 - Extra context menu item: Download all links with IDM - A:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - A:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - A:\Program Files\Internet Download Manager\IEExt.htm
O13 - Gopher Prefix:
O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} (F5 Networks CacheCleaner) - https://employees.cpr.ca/vdesk/cachecleaner…,2008,0212,2003
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://employees.cpr.ca/vdesk/terminal/InstallerControl.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - Winlogon Notify: !SASWinLogon - A:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - A:\Windows\System32\DreamScene.dll
O23 - Service: Google Update Service (gupdate1ca16133877e5) (gupdate1ca16133877e5) - Google Inc. - A:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: MBAMService - Malwarebytes Corporation - A:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - A:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - A:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: sofatnet Service (sofatnet) - Unknown owner - A:\Windows\system32\sofatnet.exe (file missing)
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - A:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - A:\Windows\System32\TUProgSt.exe
I've removed those files I mentioned in the description multiple times with Malwarebytes,Superantispyware and TrojanRemover,but they keep coming back.Makes my Firefox hang-up constantly,and my machine painfully slow at times.
Rootrepeal and dds aren't compatible with 7 unfortunately.Any help would be greatly appreciated.Thanks in advance.
I know nobody has asked for this,but this is an example of my Malwarebytes scan that I keep deleting,but they just keep comin' back:
Malwarebytes' Anti-Malware 1.40
Database version: 2720
Windows 6.1.7260
30/08/2009 22:47:48
mbam-log-2009-08-30 (22-47-48).txt
Scan type: Quick Scan
Objects scanned: 86477
Time elapsed: 3 minute(s), 44 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 7
Registry Values Infected: 11
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 6
Memory Processes Infected:
A:\Windows\System32\sofatnet.exe (Backdoor.Bot) -> Unloaded process successfully.
Memory Modules Infected:
a:\Windows\System32\evdoserver.dll (Trojan.Agent) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Protection System (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\BuildW (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\FirstInstallFlag (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mEv (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Ulrn (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Update (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateNew (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
A:\Program Files\Protection System (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.
Files Infected:
a:\Windows\System32\evdoserver.dll (Trojan.Agent) -> Delete on reboot.
A:\Windows\System32\dvdpaly.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
A:\Windows\System32\wiwow64.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
A:\Windows\System32\FInstall.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
A:\Windows\System32\sofatnet.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
A:\Windows\sc.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.