Firefox and Internet Explorer Adware
28 min read
My name is JonTom.
- Malware Logs can sometimes take a lot of time to research and interpret.
- Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
- Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
- Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
- PLEASE NOTE: If you do not reply after 5 days your thread will be closed.
- I am looking over your log and will reply back shortly with instructions.
Thank you for the logs.
There are many things going on here.There may be other issues such as malware or viruses
Please work your way through the following steps. If you encounter any difficulties come back and let me know.
- Security Programs
- I can see evidence of multiple real-time security programs running on your system, namely Norton AntiVirus Corporate Edition and McAfee Internet Security Suite.
- Whilst both of these programs provide good security, they may clash with each other which can leave your system vulnerable to infection.
- You are advised to remove one of these programs.
- Please make sure that you only have ONE Firewall and ONE real-time Antivirus running on your system.
- Please disable Spybot Teatimer
- Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
- On the left hand side, click "Tools", then click on the "Resident" icon in the list.
- Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active" box.
- Click the "System Startup" icon in the List.
- Uncheck the "TeaTimer" box and "OK" any prompts.
- If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
- Exit Spybot S&D when done.
- Download Combofix and RE-NAME it BEFORE saving
- Download Combofix from either of the links below. You must rename it to shaenaus.exe before saving it.
- Save it to your desktop. Change the "save as file type" to "all files".
- Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop.
- If you are using Firefox, make sure that your download settings are as follows:
- Tools->Options->Main tab
- Set to "Always ask me where to Save the files".
Link 1
Link 2
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
- NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.
- Double click on the renamed ComboFix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the C:\ComboFix.txt so we can continue cleaning the system.
Please disable your Norton AntiVirus and run ComboFixI followed your instructions carefully so I don't know what to do now
Thank you for letting me know.
The malware on your system is interfering with our tools. Your machine is heavily infected and we will most likely need several rounds of treatment to get it clean.
Before we continue, please do the following:
- Please scan your system with GMER
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
- If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
[external image: Posted Image]
Click the image to enlarge it - In the right panel, you will see several boxes that have been checked. Uncheck the following …
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Please post the GMER log in your next reply.
If you encounter any difficulties come back and let me know.
Don't worry, the thread will be open and I will be here when you get backWould you please keep this thread open until 15th July?
If GMER does not run in Normal Mode, please run it from Safe Mode (if you are unable to boot into Safe Mode come back and let me know):
- Reboot Your System in Safe Mode
- Please print out the GMER instructions and the instructions provided below before proceeding, as once you are in Safe Mode you will be unable to connect to the Internet.
- Follow the steps below to Start Your Computer in Safe Mode:
- Restart your computer.
- As soon as BIOS is loaded begin tapping the F8 key until the "Advanced Options" menu appears.
- Use the arrow keys to select the "Safe mode" menu item.
- Press Enter.
- Please run GMER in Safe Mode
- Once you are in Safe Mode, open GMER.
- Work your way through the steps listed to run the scan.
- Once GMER has finished, reboot back into normal mode and post the log created in your next reply.
- If GMER crashes again please try RootRepeal (instructions provided below).
- RootRepeal
- Please download RootRepeal to your desktop
- Physically disconnect your machine from the internet as your system will be unprotected.
- Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
- Click the Report tab at the bottom and then the Scan button.
- A box will pop up, check the boxes beside Drivers, Files, Processes SSDT and click OK.
- Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
- The scan will take a little while to run, so let it go unhindered.
- Once it is done, click the "Save Report" button, call it RepealScan and save the log to your desktop.
- Reconnect to the internet.
Please post the GMER/RootRepeal log in your next reply.
Thank you for the log.
I have it on good authority that the reason why ComboFix did not run last time was most likely due to a corrupted upload. This issue has since been resolved so there should be no more problems.
Please delete the copy of ComboFix that is on your desktop and download a fresh copy using the instructions provided previously (Post number 3).
Follow the instructions provided and post the ComboFix log that is created in your next reply
Here is the ComboFix log:
ComboFix 10-07-12.02 - David 13/07/2010 12:46:31.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.492 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\shaenaus.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\cleansweep.exe
c:\cleansweep.exe\config.bin
c:\documents and settings\David\Application Data\avdrn.dat
C:\start.bat
c:\windows\cdmxtras
c:\windows\jestertb.dll
c:\windows\kbjlprb.dll
c:\windows\system32\cache329
c:\windows\system32\cache329\B_329_0_0_105300.htm
c:\windows\system32\cache329\B_329_0_0_106800.htm
c:\windows\system32\cache329\B_329_0_0_107400.htm
c:\windows\system32\cache329\B_329_1_0_449200.htm
c:\windows\system32\cache329\B_329_1_0_449600.htm
c:\windows\system32\cache329\B_329_1_0_454300.htm
c:\windows\system32\cache329\B_329_2_0_105300.htm
c:\windows\system32\cache329\B_329_2_0_106800.htm
c:\windows\system32\cache329\B_329_2_0_107400.htm
c:\windows\system32\cache329\B_329_3_0_105300.htm
c:\windows\system32\cache329\B_329_3_0_106800.htm
c:\windows\system32\cache329\B_329_3_0_107400.htm
c:\windows\system32\cache329\B_329_4_0_111600.htm
c:\windows\system32\cache329\B_329_4_0_152400.htm
c:\windows\system32\cache329\B_329_4_0_155300.htm
c:\windows\system32\cache329\B_329_4_0_164100.htm
c:\windows\system32\cache329\t_B_329_0_0_105300.htm
c:\windows\system32\cache329\t_B_329_0_0_106800.htm
c:\windows\system32\cache329\t_B_329_0_0_107400.htm
c:\windows\system32\cache329\t_B_329_1_0_449200.htm
c:\windows\system32\cache329\t_B_329_1_0_449600.htm
c:\windows\system32\cache329\t_B_329_1_0_454300.htm
c:\windows\system32\cache329\t_B_329_2_0_105300.htm
c:\windows\system32\cache329\t_B_329_2_0_106800.htm
c:\windows\system32\cache329\t_B_329_2_0_107400.htm
c:\windows\system32\cache329\t_B_329_3_0_105300.htm
c:\windows\system32\cache329\t_B_329_3_0_106800.htm
c:\windows\system32\cache329\t_B_329_3_0_107400.htm
c:\windows\system32\cache329\t_B_329_4_0_111600.htm
c:\windows\system32\cache329\t_B_329_4_0_152400.htm
c:\windows\system32\cache329\t_B_329_4_0_155300.htm
c:\windows\system32\cache329\t_B_329_4_0_164100.htm
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\utabonat.dll
c:\windows\xpsp1hfm.log
.
((((((((((((((((((((((((( Files Created from 2010-06-13 to 2010-07-13 )))))))))))))))))))))))))))))))
.
2010-07-13 01:30 . 2010-07-13 01:30 ——– d—–w- c:\documents and settings\David\Application Data\Windows Search
2010-07-08 08:25 . 2010-07-08 08:25 ——– d-sh–w- c:\documents and settings\Donna\PrivacIE
2010-07-04 01:21 . 2010-07-04 01:21 ——– d-sh–w- c:\documents and settings\Donna\IETldCache
2010-06-22 22:06 . 2010-07-12 07:02 0 —-a-w- c:\windows\Ccumituyihitama.dat
2010-06-22 22:06 . 2010-07-10 01:38 0 —-a-w- c:\windows\Cmulu.bin
2010-06-22 22:06 . 2010-06-22 22:06 ——– d—–w- c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}
2010-06-16 12:19 . 2010-06-16 12:19 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-06-16 08:26 . 2010-06-16 08:26 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-06-16 03:55 . 2010-06-16 03:56 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-06-16 03:54 . 2010-06-16 03:54 ——– d-sh–w- c:\documents and settings\David\IECompatCache
2010-06-16 03:51 . 2010-06-16 03:51 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-06-16 03:49 . 2010-06-16 03:49 ——– d-sh–w- c:\documents and settings\David\PrivacIE
2010-06-16 03:47 . 2010-06-16 03:47 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-06-16 03:44 . 2010-06-16 03:44 ——– d-sh–w- c:\documents and settings\David\IETldCache
2010-06-16 03:35 . 2010-05-06 10:41 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2010-06-16 03:35 . 2010-05-06 10:41 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2010-06-16 03:35 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-16 03:35 . 2010-06-16 04:05 ——– d—–w- c:\windows\ie8updates
2010-06-16 03:34 . 2010-04-16 11:43 41984 ——w- c:\windows\system32\dllcache\iecompat.dll
2010-06-16 03:29 . 2010-06-16 03:33 ——– dc-h–w- c:\windows\ie8
2010-06-16 03:24 . 2010-06-16 03:24 ——– d—–w- c:\documents and settings\David\Application Data\Windows Desktop Search
2010-06-16 03:23 . 2010-06-16 04:12 ——– d—–w- c:\program files\Windows Desktop Search
2010-06-16 03:23 . 2010-06-16 03:23 ——– d—–w- c:\windows\system32\GroupPolicy
2010-06-16 03:20 . 2008-03-07 17:02 98304 ——w- c:\windows\system32\dllcache\nlhtml.dll
2010-06-16 03:20 . 2008-03-07 17:02 29696 ——w- c:\windows\system32\dllcache\mimefilt.dll
2010-06-16 03:20 . 2008-03-07 17:02 192000 ——w- c:\windows\system32\dllcache\offfilt.dll
2010-06-16 01:51 . 2009-10-23 15:28 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe
2010-06-16 00:18 . 2004-08-03 12:31 20992 —-a-w- c:\windows\system32\drivers\RTL8139.sys
2010-06-16 00:18 . 2004-08-03 12:31 20992 —-a-w- c:\windows\system32\dllcache\rtl8139.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-13 03:05 . 2009-02-01 00:06 ——– d—–w- c:\program files\DNA
2010-07-13 03:05 . 2009-02-01 00:06 ——– d—–w- c:\documents and settings\David\Application Data\DNA
2010-07-12 08:32 . 2005-08-03 14:04 45840 -c–a-w- c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-07 08:00 . 2007-09-02 09:36 ——– d—–w- c:\program files\Norton Security Scan
2010-07-02 23:05 . 2010-07-02 23:05 8 —-a-w- c:\documents and settings\NetworkService\Application Data\cakzob.dat
2010-07-02 00:06 . 2010-07-02 00:06 8 —-a-w- c:\documents and settings\David\Application Data\cakzob.dat
2010-06-16 03:51 . 2010-06-16 03:51 4 —-a-w- c:\documents and settings\LocalService\Application Data\cakzob.dat
2010-05-06 10:41 . 2004-08-10 04:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-10 04:51 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-10 04:50 285696 —-a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]
"Bait 64"="c:\windows\system32\config\SYSTEM~1\APPLIC~1\2DOWNL~1\bore list heart.exe" [2009-12-16 491520]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2008-05-19 91432]
"vptray"="c:\program files\NavNT\vptray.exe" [2001-09-23 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-24 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-05 202256]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^dlbcserv.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\dlbcserv.lnk
backup=c:\windows\pss\dlbcserv.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2005-05-30 19:33 122941 -c–a-w- c:\windows\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-04-28 04:34 53248 -c–a-w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2003-03-11 08:08 172032 -c–a-w- c:\windows\system32\spool\drivers\w32x86\3\hpztsb08.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-09-19 22:32 77824 -c–a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-19 22:36 114688 -c–a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-09-19 22:35 94208 -c–a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 08:50 221184 -c–a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-07-27 08:50 81920 -c–a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 05:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 12:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
2002-02-04 12:32 53248 ——w- c:\program files\REGSHAVE\REGSHAVE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-14 11:42 1404928 —-a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2006-12-14 17:23 75520 -c–a-w- c:\program files\Java\jre1.5.0_11\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-04-05 06:49 202256 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
2001-09-23 21:59 73728 —-a-w- c:\program files\NavNT\vptray.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Documents and Settings\\Donna\\Local Settings\\Temp\\iCBB_21_21 R14-24 PRIMUS B01 Temporary Items\\iConnectDSLsvr.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1339:UDP"= 1339:UDP:Windows Media Format SDK (iexplore.exe)
"1338:UDP"= 1338:UDP:Windows Media Format SDK (iexplore.exe)
"1340:UDP"= 1340:UDP:Windows Media Format SDK (iexplore.exe)
"20856:TCP"= 20856:TCP:BitComet 20856 TCP
"20856:UDP"= 20856:UDP:BitComet 20856 UDP
"23208:TCP"= 23208:TCP:BitComet 23208 TCP
"23208:UDP"= 23208:UDP:BitComet 23208 UDP
R2 CAN300;CAN300;c:\windows\system32\drivers\can300.sys [3/08/2005 8:23 AM 10224]
S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};\??\c:\program files\CyberLink\PowerDVD8\000.fcl –> c:\program files\CyberLink\PowerDVD8\000.fcl [?]
S2 gupdate1ca8e7346fd63f8;Google Update Service (gupdate1ca8e7346fd63f8);c:\program files\Google\Update\GoogleUpdate.exe [6/01/2010 11:55 AM 133104]
S2 suh4niiio;BsHelpCS;c:\windows\system32\lyssu.exe –> c:\windows\system32\lyssu.exe [?]
S3 Ascnuntin;Ascnuntin; [x]
.
Contents of the 'Scheduled Tasks' folder
2010-07-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]
2010-07-12 c:\windows\Tasks\B35DDA3D945A4D01.job
- c:\docume~1\david\applic~1\2downl~1\RegsRemoteBib.exe [2009-02-07 23:12]
2010-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 01:54]
2010-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 01:54]
2010-07-08 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe [2008-01-08 17:08]
2010-07-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3774946206-295064592-2716718800-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]
2010-07-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3774946206-295064592-2716718800-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]
2010-07-04 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3774946206-295064592-2716718800-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]
2010-07-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3774946206-295064592-2716718800-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.iprimus.com.au/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.IPrimus.com.au;10.*;172.16.*;172.17.*;172.18.*;172.19.*;172.20.*;172.21.*;172.
22.*;172.23.*;172.24.*;172.25.*;172.26.*;172.27.*;172.28.*;172.29.*;172.30.*;172.
31.*;192.168.*;;*.local
uInternet Settings,ProxyServer = proxy.iprimus.com.au:8080
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\David\Start Menu\Programs\IMVU\Run IMVU.lnk
FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\9gozxyl5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com.au
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101849&gct=&gc=1&q=
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\9gozxyl5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\David\Desktop\Temp\DivX\DivX Web Player\npdivx32.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: XULRunner: {F76DDB26-BB84-4954-9395-CE30EB8664F3} - c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}
FF - HiddenExtension: XULRunner: {8E596A9C-3AD3-4249-9528-A8991CE62159} - c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MSKAGENTEXE - c:\progra~1\McAfee\SPAMKI~1\MSKAgent.exe
HKCU-Run-BitComet - c:\documents and settings\David\Desktop\Temp\BitComet\BitComet.exe
HKCU-Run-Iyiye - c:\windows\kbjlprb.dll
HKLM-Run-Odajudi - c:\windows\utabonat.dll
MSConfigStartUp-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
MSConfigStartUp-DeviceDiscovery - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
MSConfigStartUp-DMXLauncher - c:\program files\Dell\Media Experience\DMXLauncher.exe
MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
MSConfigStartUp-HP Software Update - c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
MSConfigStartUp-MCAgentExe - c:\progra~1\mcafee.com\agent\mcagent.exe
MSConfigStartUp-MCUpdateExe - c:\progra~1\mcafee.com\agent\mcupdate.exe
MSConfigStartUp-Yahoo! Pager - c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-13 13:06
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(628)
c:\windows\system32\NavLogon.dll
- - - - - - - > 'explorer.exe'(2544)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\NavNT\defwatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\NavNT\rtvscan.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\WgaTray.exe
c:\windows\system32\MsgSys.EXE
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-07-13 13:25:56 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-13 03:25
Pre-Run: 67,084,460,032 bytes free
Post-Run: 67,504,996,352 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 9012F597559A8C93E66AFBB46804B8F3
Thank you for the log.
Please work your way through the following steps:
- P2P Programs:
- P2P programs are a major source of Malware infections.
- From your log I see you have Kazaa, LimeWire and BitTorrent. We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
- The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
- If you wish to keep the program(s), please do not use them until your computer is cleaned.
- Information regarding the risk of using these programs can be found from here and here.
- It is strongly recommend that you uninstall any P2P programs you have on your system.
- To do this, Click on "Start" then on "Control Panel" and then on "Add or remove programs".
- A list of currently installed programs will be displayed.
- Find the "Kazaa 3.0", "LimeWire 5.2.0" and "BitTorrent DNA" programs, click on them once and then click on the "Remove" button.
- If you are prompted to re-boot your computer to complete the uninstall please do so.
PLEASE NOTE: - Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files.
- Foistware
- I can see from your log that you have Viewpoint Media Player installed.
- Viewpoint Media Player is considered as foistware rather than malware since it is installed without user's approval but doesn't spy or do anything "bad".
- It is recommended that you remove Viewpoint products. However, this choice is up to you.
- To remove these programs, click "Start" and then on "Control Panel" and then on "Add or Remove Programs".
- Select Viewpoint Media Player and click on "Remove".
I can see evidence of a LOP infection on your machine. This infection may have been obtained inadvertantly when you installed Messenger Plus! Live, as this software often contains "sponsored programs" that are bundled together with the Messenger Plus! Live install.
It would be in your best interests to un-install Messenger Plus! Live from your machine (You can do this through Add/Remove Programs - see above). If you use Messenger Plus! Live, please let me know and we can re-install it (without the bundled adware) once your system is clean.
- Please work through the following steps
- Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
- NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
- Copy and Paste the text in the codebox below (including the link) into the open Notepad window:
File:: c:\windows\Ccumituyihitama.dat c:\windows\Cmulu.bin c:\windows\system32\lyssu.exe Collect:: c:\windows\system32\config\SYSTEM~1\APPLIC~1\2DOWNL~1\bore list heart.exe c:\documents and settings\NetworkService\Application Data\cakzob.dat c:\documents and settings\David\Application Data\cakzob.dat c:\documents and settings\LocalService\Application Data\cakzob.dat Driver:: suh4niiio Ascnuntin Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Bait 64"=- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "20856:TCP"=- "23208:TCP"=- Firefox:: FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\9gozxyl5.default\ FF - HiddenExtension: XULRunner: {F76DDB26-BB84-4954-9395-CE30EB8664F3} - c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3} FF - HiddenExtension: XULRunner: {8E596A9C-3AD3-4249-9528-A8991CE62159} - c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159} Folder:: FF - HiddenExtension: XULRunner: {F76DDB26-BB84-4954-9395-CE30EB8664F3} - c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3} FF - HiddenExtension: XULRunner: {8E596A9C-3AD3-4249-9528-A8991CE62159} - c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159} DirLook:: c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3} - Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
- Close any open browsers.
- Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
- Refering to the picture below, drag CFScript.txt into ComboFix.exe
[external image: Posted Image]
- When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
- Once the log is produced, re-engage your resident anti virus.
- Note: When ComboFix finishes running, the ComboFix log will open along with a message box - do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
- Ensure you are connected to the internet and click OK on the message box.
Please post the ComboFix log in your next reply.
This is not my computer so I did not uninstall the P2P programs nor Viewpoint MediaPlayer. I did uninstall Messenger Plus! Live which I would like to reinstall later.
Here is the ComboFix log:
ComboFix 10-07-13.02 - David 14/07/2010 12:24:07.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.607 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\shaenaus.exe
Command switches used :: c:\documents and settings\David\Desktop\CFScript.txt
* Created a new restore point
FILE ::
"c:\windows\Ccumituyihitama.dat"
"c:\windows\Cmulu.bin"
"c:\windows\system32\lyssu.exe"
file zipped: c:\documents and settings\David\Application Data\cakzob.dat
file zipped: c:\documents and settings\LocalService\Application Data\cakzob.dat
file zipped: c:\documents and settings\NetworkService\Application Data\cakzob.dat
file zipped: c:\windows\system32\config\SYSTEM~1\APPLIC~1\2DOWNL~1\bore list heart.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\David\Application Data\cakzob.dat
c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}
c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\chrome.manifest
c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\chrome\content\_cfg.js
c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\chrome\content\overlay.xul
c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\install.rdf
c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}
c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}\chrome.manifest
c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}\chrome\content\_cfg.js
c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}\chrome\content\overlay.xul
c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}\install.rdf
c:\documents and settings\LocalService\Application Data\cakzob.dat
c:\documents and settings\NetworkService\Application Data\cakzob.dat
c:\windows\Ccumituyihitama.dat
c:\windows\Cmulu.bin
c:\windows\system32\config\SYSTEM~1\APPLIC~1\2DOWNL~1\bore list heart.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_SUH4NIIIO
——-\Service_Ascnuntin
——-\Service_suh4niiio
((((((((((((((((((((((((( Files Created from 2010-06-14 to 2010-07-14 )))))))))))))))))))))))))))))))
.
2010-07-13 01:30 . 2010-07-13 01:30 ——– d—–w- c:\documents and settings\David\Application Data\Windows Search
2010-07-08 08:25 . 2010-07-08 08:25 ——– d-sh–w- c:\documents and settings\Donna\PrivacIE
2010-07-04 01:21 . 2010-07-04 01:21 ——– d-sh–w- c:\documents and settings\Donna\IETldCache
2010-06-16 12:19 . 2010-06-16 12:19 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-06-16 08:26 . 2010-06-16 08:26 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-06-16 03:55 . 2010-06-16 03:56 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-06-16 03:54 . 2010-06-16 03:54 ——– d-sh–w- c:\documents and settings\David\IECompatCache
2010-06-16 03:51 . 2010-06-16 03:51 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-06-16 03:49 . 2010-06-16 03:49 ——– d-sh–w- c:\documents and settings\David\PrivacIE
2010-06-16 03:47 . 2010-06-16 03:47 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-06-16 03:44 . 2010-06-16 03:44 ——– d-sh–w- c:\documents and settings\David\IETldCache
2010-06-16 03:35 . 2010-05-06 10:41 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2010-06-16 03:35 . 2010-05-06 10:41 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2010-06-16 03:35 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-16 03:35 . 2010-06-16 04:05 ——– d—–w- c:\windows\ie8updates
2010-06-16 03:34 . 2010-04-16 11:43 41984 ——w- c:\windows\system32\dllcache\iecompat.dll
2010-06-16 03:29 . 2010-06-16 03:33 ——– dc-h–w- c:\windows\ie8
2010-06-16 03:24 . 2010-06-16 03:24 ——– d—–w- c:\documents and settings\David\Application Data\Windows Desktop Search
2010-06-16 03:23 . 2010-06-16 04:12 ——– d—–w- c:\program files\Windows Desktop Search
2010-06-16 03:23 . 2010-06-16 03:23 ——– d—–w- c:\windows\system32\GroupPolicy
2010-06-16 03:20 . 2008-03-07 17:02 98304 ——w- c:\windows\system32\dllcache\nlhtml.dll
2010-06-16 03:20 . 2008-03-07 17:02 29696 ——w- c:\windows\system32\dllcache\mimefilt.dll
2010-06-16 03:20 . 2008-03-07 17:02 192000 ——w- c:\windows\system32\dllcache\offfilt.dll
2010-06-16 01:51 . 2009-10-23 15:28 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe
2010-06-16 00:18 . 2004-08-03 12:31 20992 —-a-w- c:\windows\system32\drivers\RTL8139.sys
2010-06-16 00:18 . 2004-08-03 12:31 20992 —-a-w- c:\windows\system32\dllcache\rtl8139.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-14 02:43 . 2009-02-01 00:06 ——– d—–w- c:\program files\DNA
2010-07-14 02:43 . 2009-02-01 00:06 ——– d—–w- c:\documents and settings\David\Application Data\DNA
2010-07-12 08:32 . 2005-08-03 14:04 45840 -c–a-w- c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-07 08:00 . 2007-09-02 09:36 ——– d—–w- c:\program files\Norton Security Scan
2010-05-06 10:41 . 2004-08-10 04:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-10 04:51 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-10 04:50 285696 —-a-w- c:\windows\system32\atmfd.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3} —-
2010-06-22 22:06 . 2010-06-22 22:06 6778 —-a-w- c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\chrome\content\overlay.xul
2010-06-22 22:06 . 2010-06-22 22:06 2060 —-a-w- c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\chrome\content\_cfg.js
2010-06-22 22:06 . 2010-06-22 22:06 764 —-a-w- c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\install.rdf
2010-06-22 22:06 . 2010-06-22 22:06 122 —-a-w- c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\chrome.manifest
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2008-05-19 91432]
"vptray"="c:\program files\NavNT\vptray.exe" [2001-09-23 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-24 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-05 202256]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^dlbcserv.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\dlbcserv.lnk
backup=c:\windows\pss\dlbcserv.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2005-05-30 19:33 122941 -c–a-w- c:\windows\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-04-28 04:34 53248 -c–a-w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2003-03-11 08:08 172032 -c–a-w- c:\windows\system32\spool\drivers\w32x86\3\hpztsb08.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-09-19 22:32 77824 -c–a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-19 22:36 114688 -c–a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-09-19 22:35 94208 -c–a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 08:50 221184 -c–a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-07-27 08:50 81920 -c–a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 05:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 12:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
2002-02-04 12:32 53248 ——w- c:\program files\REGSHAVE\REGSHAVE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-14 11:42 1404928 —-a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2006-12-14 17:23 75520 -c–a-w- c:\program files\Java\jre1.5.0_11\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-04-05 06:49 202256 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
2001-09-23 21:59 73728 —-a-w- c:\program files\NavNT\vptray.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Documents and Settings\\Donna\\Local Settings\\Temp\\iCBB_21_21 R14-24 PRIMUS B01 Temporary Items\\iConnectDSLsvr.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1339:UDP"= 1339:UDP:Windows Media Format SDK (iexplore.exe)
"1338:UDP"= 1338:UDP:Windows Media Format SDK (iexplore.exe)
"1340:UDP"= 1340:UDP:Windows Media Format SDK (iexplore.exe)
"20856:UDP"= 20856:UDP:BitComet 20856 UDP
"23208:UDP"= 23208:UDP:BitComet 23208 UDP
R2 CAN300;CAN300;c:\windows\system32\drivers\can300.sys [3/08/2005 8:23 AM 10224]
S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};\??\c:\program files\CyberLink\PowerDVD8\000.fcl –> c:\program files\CyberLink\PowerDVD8\000.fcl [?]
S2 gupdate1ca8e7346fd63f8;Google Update Service (gupdate1ca8e7346fd63f8);c:\program files\Google\Update\GoogleUpdate.exe [6/01/2010 11:55 AM 133104]
.
Contents of the 'Scheduled Tasks' folder
2010-07-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]
2010-07-14 c:\windows\Tasks\B35DDA3D945A4D01.job
- c:\docume~1\david\applic~1\2downl~1\RegsRemoteBib.exe [2009-02-07 23:12]
2010-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 01:54]
2010-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 01:54]
2010-07-08 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe [2008-01-08 17:08]
2010-07-14 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3774946206-295064592-2716718800-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]
2010-07-14 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3774946206-295064592-2716718800-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]
2010-07-04 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3774946206-295064592-2716718800-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]
2010-07-14 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3774946206-295064592-2716718800-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.iprimus.com.au/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.IPrimus.com.au;10.*;172.16.*;172.17.*;172.18.*;172.19.*;172.20.*;172.21.*;172.
22.*;172.23.*;172.24.*;172.25.*;172.26.*;172.27.*;172.28.*;172.29.*;172.30.*;172
.
31.*;192.168.*;;*.local
uInternet Settings,ProxyServer = proxy.iprimus.com.au:8080
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\David\Start Menu\Programs\IMVU\Run IMVU.lnk
FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\9gozxyl5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com.au
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101849&gct=&gc=1&q=
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\9gozxyl5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-14 12:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(628)
c:\windows\system32\NavLogon.dll
- - - - - - - > 'explorer.exe'(2860)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\NavNT\defwatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\NavNT\rtvscan.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\MsgSys.EXE
c:\windows\system32\WgaTray.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-07-14 12:57:24 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-14 02:57
ComboFix2.txt 2010-07-13 03:25
Pre-Run: 67,461,906,432 bytes free
Post-Run: 67,319,545,856 bytes free
- - End Of File - - 4FFC6A88BF5BF828D0E3DA1D9793EA63
Thank you for the log.
Okay. Please do not use these programs until we have finished cleaning the system. Once you return the machine to your Sister, please advise her that it would be in her best interests to uninstall those programs.This is not my computer so I did not uninstall the P2P programs nor Viewpoint MediaPlayer.
No problem. We will take care of that once your machine is cleanI did uninstall Messenger Plus! Live which I would like to reinstall later
Before we continue:
Do you/your Sister recognise these proxies? Did you set them?uInternet Settings,ProxyOverride = *.IPrimus.com.au;10.*;172.16.*;172.17.*;172.18.*;172.19.*;172.20.*;172.21.*;172.
22.*;172.23.*;172.24.*;172.25.*;172.26.*;172.27.*;172.28.*;172.29.*;172.30.*;172
.
31.*;192.168.*;;*.local
uInternet Settings,ProxyServer = proxy.iprimus.com.au:8080
- Please manually upload the following files for analysis
- The CFScript I asked you to run was designed to upload the malware files on your system for analysis. Unfortunately the upload failed so I would like you to upload these files manually. Please do the following:
- Please click on the following LINK. A new window will open.
- In the box marked "Link to topic where this file was requested:" please paste in the following text:
http://forums.whatthetech.com/index.php?showtopic=112907
- Click the "Browse" button and navigate to C:\Qoobox\Quarantine
- There should be a zip file there called [4]-Submit_****-**-**_**.**.**.zip (the * denotes the Date and Time stamp - it will be close to this: 14/07/2010 12:24:07).
- Select this file and click "Open".
- In the Largest box please paste in:
File Requested By JonTom Failed Collect::
- Finally click "SendFile".
- Please return here and let me know when that file has been uploaded.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI