This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] XP Security Tool

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'm infected with the XP Security tool (that I know of ). I tried to search the forums but recieved an error message each time. I followed the instructions for first time postings but could not run GMER. I did include the initial start-up file.

DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 21:58:20.20 on Mon 04/19/2010
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2039.1309
[GMT -7:00]

AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled*
(Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device
Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe
C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdServer.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\Mixer.exe
C:\Documents and Settings\Strongbad\Local Settings\Application Data\vma.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wpabaln.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Strongbad\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.bluegrassguitar.com/
uWindow Title = Microsoft Internet Explorer provided by Comcast
mWindow Title = Microsoft Internet Explorer provided by Comcast
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
BHO: Adobe PDF Reader Link Helper:
{06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program
files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: SpywareGuardDLBLOCK.CBrowserHelper:
{4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program
files\spywareguard\dlprotect.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} -
c:\program files\java\jre1.5.0_09\bin\ssv.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program
files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [updateMgr] "c:\program files\adobe\acrobat
7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [C-Media Mixer] Mixer.exe /startup
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album
starter edition\3.2\apps\apdproxy.exe"
mRun: [Ssefonul] rundll32.exe "c:\windows\urunoses.dll",Startup
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program
files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\docume~1\strong~1\startm~1\programs\startup\erunta~1.lnk
- c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\strong~1\startm~1\programs\startup\spywar~1.lnk
- c:\program files\spywareguard\sgmain.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk
- c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/
IE: {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/
IE: {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network
Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program
files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC} - c:\program
files\java\jre1.5.0_09\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
{FF059E31-CC5A-4E2E-BF3B-96E929D65503} -
c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
DPF: {00000161-0000-0010-8000-00AA00389B71} -
hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab
DPF: {3334504D-9980-0010-8000-00AA00389B71} -
hxxp://download.microsoft.com/download/0/C/8/0C8EDFAB-30BC-4792-898E-2DABE27B2C4D/mp43dmo.CAB
DPF: {33564D57-0000-0010-8000-00AA00389B71} -
hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
hxxp://software-dl.real.com/044645566f5d94c80e23/netzip/RdxIE601.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -
hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1126756539921
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} -
hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab
DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} -
hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} -
hxxp://by1fd.bay1.hotmail.msn.com/activex/HMAtchmt.ocx
Notify: igfxcui - igfxsrvc.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
c:\windows\system32\WPDShServiceObj.dll
SEH: CShellExecuteHookImpl Object:
{54d9498b-cf93-414f-8984-8ce7fde0d391} - c:\program
files\ewido\security suite\shellhook.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} -
c:\program files\spywareguard\spywareguard.dll
LSA: Notification Packages = scecli scecli

================= FIREFOX ===================

FF - ProfilePath -
c:\docume~1\strong~1\applic~1\mozilla\firefox\profiles\9kum25y4.default\
FF - prefs.js: browser.startup.homepage -
hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=https%3A%2F%2Fmail.google.com%2Fmail%2F%3Fshva%3D1%26nsr%3D0%26ui%3Dhtml%26zy%3Dl FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\strongbad\application
data\mozilla\firefox\profiles\9kum25y4.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPJPI150_09.dll
FF - plugin: c:\program files\java\jre1.5.0_09\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - HiddenExtension: XULRunner:
{69C9FF6A-7C74-41BA-AE64-1ADCCFC3A460} - c:\documents and
settings\strongbad\local settings\application
data\{69C9FF6A-7C74-41BA-AE64-1ADCCFC3A460}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R0 IFP300;iriver Internet Audio Player
IFP-300;c:\windows\system32\drivers\ifp300.sys [2006-6-7 14531]
R0 Pnp680;SiI 680 ATA
Controller;c:\windows\system32\drivers\pnp680.sys [2002-3-15 37031]
R1 ewido security suite driver;ewido security suite driver;c:\program
files\ewido\security suite\guard.sys [2004-11-22 3072]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2004-2-9 301200]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common
files\symantec shared\ccEvtMgr.exe [2004-6-9 255096]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common
files\symantec shared\ccSetMgr.exe [2004-6-9 242808]
R2 ewido security suite control;ewido security suite
control;c:\program files\ewido\security suite\ewidoctrl.exe
[2004-11-11 16448]
R2 RosettaStoneLtdController;RosettaStoneLtdController;c:\program
files\rosettastoneltdservices\RosettaStoneLtdController.exe
[2007-10-31 354648]
R2 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe
[2004-8-2 173392]
R2 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys
[2004-2-9 37008]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec
antivirus\Rtvscan.exe [2004-8-2 1267024]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100416.003\naveng.sys
[2010-4-19 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100416.003\navex15.sys
[2010-4-19 1324720]
S2 OxSer;PCI Serial Driver;c:\windows\system32\drivers\oxser.sys
[2004-12-30 54584]
S2 PARXPORT;PCI Parallel
Driver;c:\windows\system32\drivers\parxport.sys [2004-12-30 13608]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common
files\symantec shared\ccPwdSvc.exe [2004-6-9 87160]
S3 cmudax;C-Media Azalia Audio
Interface;c:\windows\system32\drivers\cmudax.sys –>
c:\windows\system32\drivers\cmudax.sys [?]
S3 HwIOctl;HwIOctl;\??\c:\program files\setup files\ms-7058
v1.40\hwioctl.sys –> c:\program files\setup files\ms-7058
v1.40\HwIOctl.sys [?]
S3 Ipd30ci;Ipd30ci; [x]
S4 ewido security suite guard;ewido security suite guard;c:\program
files\ewido\security suite\ewidoguard.exe [2006-2-6 151616]

============== File Associations ===============

.exe=secfile

=============== Created Last 30 ================

2010-04-20 02:16:15 160 —-a-w- c:\documents and
settings\strongbad\defogger_reenable
2010-04-19 23:42:36 0 d—–w- c:\docume~1\alluse~1\applic~1\avG
2010-04-19 15:35:42 0 d—–w- c:\docume~1\strong~1\applic~1\DAEMON Tools Lite
2010-04-19 15:35:16 0 d—–w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite

==================== Find3M ====================

2010-03-30 07:46:30 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-30 07:45:52 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2006-08-15 17:46:45 604 -c-ha-w- c:\program files\STLL Notifier
2010-01-19 06:05:14 32768 –sha-w- c:\windows\system32\config\systemprofile\local
settings\history\history.ie5\mshist012010011820100119\index.dat
2010-01-16 05:04:01 16384 –sha-w- c:\windows\temp\cookies\index.dat
2010-01-16 05:04:01 16384 –sha-w- c:\windows\temp\history\history.ie5\index.dat
2010-01-16 05:04:01 49152 –sha-w- c:\windows\temp\temporary internet
files\content.ie5\index.dat

============= FINISH: 22:03:58.73 ===============

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-04-19 22:07:01
Windows 5.1.2600 Service Pack 2
Running: s9lbh5ej.exe; Driver: C:\DOCUME~1\STRONG~1\LOCALS~1\Temp\pwtyypoc.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 8A7EA856

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Hello JJPhat and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.
Hello JJPhat

Thank you for the logs.

Please work your way through the following steps. If you encounter any difficulties come back and let me know.


  • Security Programs


    • I can see from your log that you have a number of real-time security programs running, namely Ewido Security Suite , Norton Internet Security Suite and SpywareGuard Internet Security Utility.
    • Whilst these programs provide good security, they may clash with each other which can leave your system vulnerable to infection.
    • Please make sure that you only have ONE Firewall and ONE real-time Antivirus running on your system.

  • Download Combofix and RE-NAME it BEFORE saving


    • Download Combofix from either of the links below. You must rename it to JJPhat.exe before saving it.
    • Save it to your desktop. Change the "save as file type" to "all files".
    • Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop.


    • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".


    Link 1
    Link 2



    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.


    • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.


    • Double click on the renamed ComboFix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the C:\ComboFix.txt so we can continue cleaning the system.
Thanks JonTom. Here are the results of the combofix scan:

ComboFix 10-04-18.04 - Strongbad 04/22/2010 7:27.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2039.1313 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\JJPhat.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Strongbad\Local Settings\Application Data\vma.exe
c:\documents and settings\Strongbad\Local Settings\Temporary Internet Files\173CVJC.jpg
c:\documents and settings\Strongbad\Local Settings\Temporary Internet Files\EcQObYYr.jpg
c:\documents and settings\Strongbad\Local Settings\Temporary Internet Files\Ihi57i1.jpg
c:\documents and settings\Strongbad\Local Settings\Temporary Internet Files\N8624BC3.jpg
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\system32\bszip.dll
c:\windows\system32\fjhdyfhsn.bat
c:\windows\system32\smss32.exe
c:\windows\system32\winlogon32.exe

Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2010-03-22 to 2010-04-22 )))))))))))))))))))))))))))))))
.

2010-04-20 06:17 . 2010-01-22 16:55 767952 —-a-w- c:\windows\BDTSupport.dll
2010-04-20 06:17 . 2010-01-22 16:56 149456 —-a-w- c:\windows\SGDetectionTool.dll
2010-04-20 06:17 . 2010-01-22 16:56 165840 —-a-w- c:\windows\PCTBDRes.dll
2010-04-20 06:17 . 2010-01-22 16:56 1652688 —-a-w- c:\windows\PCTBDCore.dll
2010-04-20 06:17 . 2009-10-28 08:36 1152444 —-a-w- c:\windows\UDB.zip
2010-04-20 06:17 . 2008-11-26 19:08 131 —-a-w- c:\windows\IDB.zip
2010-04-20 06:16 . 2010-02-05 16:17 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-04-20 06:16 . 2010-03-10 18:36 217032 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2010-04-20 06:16 . 2009-11-23 20:54 88040 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-04-20 06:16 . 2010-02-05 16:25 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2010-04-20 06:16 . 2010-04-22 14:32 ——– d—–w- c:\program files\Spyware Doctor
2010-04-20 06:16 . 2010-04-20 06:18 ——– d—–w- c:\program files\Common Files\PC Tools
2010-04-20 06:16 . 2010-04-20 06:16 ——– d—–w- c:\documents and settings\Strongbad\Application Data\PC Tools
2010-04-20 06:16 . 2010-04-20 06:16 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-04-20 06:15 . 2010-04-22 14:25 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-20 02:58 . 2010-04-20 02:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\avG
2010-04-20 02:58 . 2010-04-20 02:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-20 02:14 . 2010-04-20 02:14 ——– d—–w- c:\program files\ERUNT
2010-04-19 23:42 . 2010-04-19 23:42 ——– d—–w- c:\documents and settings\Strongbad\Local Settings\Application Data\avG
2010-04-19 23:42 . 2010-04-19 23:42 ——– d—–w- c:\documents and settings\All Users\Application Data\avG
2010-04-19 15:35 . 2010-04-19 15:35 ——– d—–w- c:\documents and settings\Strongbad\Application Data\DAEMON Tools Lite
2010-04-19 15:35 . 2010-04-19 15:36 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-22 14:26 . 2006-01-12 16:14 ——– d—–w- c:\program files\Symantec AntiVirus
2010-04-21 04:10 . 2004-12-17 06:37 95360 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-04-20 02:58 . 2006-02-07 02:52 82560 -c–a-w- c:\documents and settings\LocalService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-20 02:49 . 2010-01-20 03:52 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-19 16:13 . 2010-01-16 18:58 0 —-a-w- c:\windows\Emafejog.bin
2010-04-19 16:13 . 2010-01-16 18:58 120 —-a-w- c:\windows\Wfilewotehokofat.dat
2010-03-30 07:46 . 2010-01-20 03:52 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-30 07:45 . 2010-01-20 03:52 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2006-08-15 17:46 . 2006-08-15 17:46 604 -c-ha-w- c:\program files\STLL Notifier
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-11-02 155648]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 61952]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-06-10 66680]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2004-08-03 124232]
"C-Media Mixer"="Mixer.exe" [2002-10-16 1818624]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-11-02 126976]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-26 267064]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-03-30 1086856]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2010-03-09 1286608]

c:\documents and settings\Strongbad\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 07:56 15360 —-a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2004-11-02 16:59 126976 —-a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveMonitor]
2006-09-06 00:45 497152 -c–a-w- c:\program files\MSI\Live Update 3\LMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2007-06-29 13:24 286720 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2006-10-12 10:10 49263 -c–a-w- c:\program files\Java\jre1.5.0_09\bin\jusched.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls]
cacltutl REG_SZ c:\windows\system32\odbcrsvp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program1\\EA GAMES\\Command and Conquer Generals\\game.dat"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Soulseek156c\\slsk.exe"=
"c:\\Program Files\\Soulseek156b\\slsk.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdController.exe"=
"c:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdServer.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"55567:TCP"= 55567:TCP:RosettaStoneLtdServices Port 55567
"55570:TCP"= 55570:TCP:RosettaStoneLtdServices Port 55570
"55568:TCP"= 55568:TCP:RosettaStoneLtdServer Port 55568
"55569:TCP"= 55569:TCP:RosettaStoneLtdController Port 55569
"55566:TCP"= 55566:TCP:RosettaStoneLtdServices Port 55566

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 IFP300;iriver Internet Audio Player IFP-300;c:\windows\system32\drivers\ifp300.sys [6/7/2006 3:46 PM 14531]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [4/19/2010 11:16 PM 217032]
R0 Pnp680;SiI 680 ATA Controller;c:\windows\system32\drivers\pnp680.sys [3/15/2002 6:09 PM 37031]
R1 ewido security suite driver;ewido security suite driver;c:\program files\ewido\security suite\guard.sys [11/22/2004 7:15 AM 3072]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [4/19/2010 11:17 PM 112592]
R2 RosettaStoneLtdController;RosettaStoneLtdController;c:\program files\RosettaStoneLtdServices\RosettaStoneLtdController.exe [10/31/2007 3:11 PM 354648]
R2 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [8/2/2004 7:36 PM 173392]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [4/19/2010 11:16 PM 366840]
S2 OxSer;PCI Serial Driver;c:\windows\system32\drivers\oxser.sys [12/30/2004 8:24 PM 54584]
S2 PARXPORT;PCI Parallel Driver;c:\windows\system32\drivers\parxport.sys [12/30/2004 8:25 PM 13608]
S3 cmudax;C-Media Azalia Audio Interface;c:\windows\system32\drivers\cmudax.sys –> c:\windows\system32\drivers\cmudax.sys [?]
S3 HwIOctl;HwIOctl;\??\c:\program files\Setup Files\MS-7058 v1.40\HwIOctl.sys –> c:\program files\Setup Files\MS-7058 v1.40\HwIOctl.sys [?]
S3 Ipd30ci;Ipd30ci; [x]
S4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys –> c:\windows\system32\Drivers\sptd.sys [?]

— Other Services/Drivers In Memory —

*Deregistered* - PCTSDInjDriver32
.
Contents of the 'Scheduled Tasks' folder

2010-01-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bluegrassguitar.com/
mWindow Title = Microsoft Internet Explorer provided by Comcast
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
Trusted Zone: buy-security-essentials.com
Trusted Zone: get-key-se10.com
FF - ProfilePath - c:\documents and settings\Strongbad\Application Data\Mozilla\Firefox\Profiles\9kum25y4.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive;=true&rm;=false&continue;=https%3A%2F%2Fmail.google.com%2Fmail%2F%3Fshva%3D1%26nsr%3D0%26ui%3Dhtml%26zy%3Dl FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\Strongbad\Application Data\Mozilla\Firefox\Profiles\9kum25y4.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJPI150_09.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - HiddenExtension: XULRunner: {69C9FF6A-7C74-41BA-AE64-1ADCCFC3A460} - c:\documents and settings\Strongbad\Local Settings\Application Data\{69C9FF6A-7C74-41BA-AE64-1ADCCFC3A460}

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKLM-Run-Ssefonul - c:\windows\urunoses.dll
MSConfigStartUp-iRiver Updater - \Updater.exe
MSConfigStartUp-PC Pitstop Optimize Scheduler - c:\program files\PCPitstop\Optimize\PCPOptimize.exe
MSConfigStartUp-PCPitstop Optimize Registration Reminder - c:\program files\PCPitstop\Optimize\Reminder.exe
MSConfigStartUp-PWRISOVM - c:\program files\PowerISO\PWRISOVM.EXE
AddRemove-VLC media player - c:\documents and settings\Strongbad\Desktop\Temporary Video\VLC\uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-22 07:39
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1078081533-725345543-307154453-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:0d,f3,12,5c,c4,f1,3a,ec,e5,62,e8,a6,c4,11,a7,45,b7,3e,e2,cd,44,22,4a,
c5,51,cc,b5,65,ca,a3,6f,ca,00,52,51,4c,9c,23,58,f4,a4,72,0e,29,ab,40,55,ae,\
"??"=hex:e6,f8,74,d7,5b,31,3a,72,04,0a,74,b0,c2,ad,38,a5
.
Completion time: 2010-04-22 07:48:27
ComboFix-quarantined-files.txt 2010-04-22 14:48

Pre-Run: 27,325,960,192 bytes free
Post-Run: 27,434,467,328 bytes free

- - End Of File - - AE131AB1BBB707D72FDD820D5A54A9AE
Hello JJPhat

Thank you for the log. Were you prompted to install the recovery console when you ran ComboFix?

Please work your way through the following steps. If you encounter any difficulties come back and let me know.


  • Please download and Install the Windows Recovery Console

    • With malware infections being as they are today, it's strongly recommended to have the Windows Recovery Console pre-installed on your machine before removing any malware.
    • The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
    • Download the tools needed to a flash drive or other removable media, and transfer them to the infected computer.
    • Go to Microsoft's website => http://support.microsoft.com/kb/310994
    • Select the download that's appropriate for your Operating System.

      [external image: Posted Image]
    • Download the file and save it as it's originally named.
    • Transfer all of the downloaded files to the desktop of the infected computer.
    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
    • Refering to the image below, drag the setup package onto the ComboFix.exe icon and drop it.


      [external image: Posted Image]
    • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.


      [external image: Posted Image]
    • At the next prompt, click 'Yes' to run the full ComboFix scan.
    • When the tool is finished, it will produce a report for you.
    • Please post the C:\ComboFix.txt in your next reply.

  • Please work through the following steps


    • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
    • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
    • Copy and Paste the text in the quotebox below into the open Notepad window:

      File::
      c:\windows\system32\odbcrsvp.dll
      c:\windows\Emafejog.bin
      c:\windows\Wfilewotehokofat.dat

      Folder::
      c:\documents and settings\Strongbad\Local Settings\Application Data\{69C9FF6A-7C74-41BA-AE64-1ADCCFC3A460}

      Registry::
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls]
      "cacltutl"=-

      DDS::
      Trusted Zone: buy-security-essentials.com
      Trusted Zone: get-key-se10.com

      Firefox::
      FF - ProfilePath - c:\documents and settings\Strongbad\Application Data\Mozilla\Firefox\Profiles\9kum25y4.default\
      FF - HiddenExtension: XULRunner: {69C9FF6A-7C74-41BA-AE64-1ADCCFC3A460} - c:\documents and settings\Strongbad\Local Settings\Application Data\{69C9FF6A-7C74-41BA-AE64-1ADCCFC3A460}

    • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
    • Close any open browsers.
    • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Refering to the picture below, drag CFScript.txt into ComboFix.exe

      [external image: Posted Image]
    • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
    • Once the log is produced, re-engage your resident anti virus.

  • Please make all files and folders VISIBLE:


    • Click "Start" Go to My Computer-> Tools-> Folder Options-> View tab:
    • Choose to "Show hidden files and folders."
    • Uncheck the "Hide protected operating system files" and the "Hide extensions for know file types" boxes.
    • Close the window with "OK".

  • Please scan the following files


    • Please visit Virus Total by clicking here.
    • Click the Browse button and search for the following file: c:\windows\UDB.zip
    • Click Open.
    • Then click Send File.
    • Please be patient while the file is scanned.
    • If Virus Total tells you that the file has already been scanned, click "reanalyse now".

    • Once the scan results appear, copy and paste them into Notepad and repeat the procedure for the following file(s):


    c:\windows\IDB.zip


    • Please provide the results from the scans in your next reply.

    In your next reply please provide the ComboFix log and the VT scan logs.

    NOTE: You may need to make more than one post to fit all of the required information in.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI