Jeff H
Topic Starter
I have once again had a friend ask me for help with a malware issue. This time the issue is with a netbook and one possibility she hasn't ruled out is deliberate sabotage by her husband (they're separated and there's a lot of drama).
Anyway, I ran MBAM and found like 38 things wrong before Norton popped up, having found #39, insisting on rebooting the machine to facilitate its removal. I decided to reboot in safe mode which I'm posting this from, and ran HJT. I'll do another MBAM scan right away as well. Meanwhile, here's what HJT has to say for itself. (Note that she's been removing stuff via HJT on advice from another site, I warned her that was unlikely to permanently resolve most issues.)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:32:14 PM, on 27/07/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Administrator.BRENNABOOK\Local Settings\Application Data\Opera\Opera\temporary_downloads\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eeepc.asus.com/global
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.7.0.12\IPSBHO.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\WINDOWS\AsScrPro.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [STrHH] C:\Documents and Settings\Brenna.BRENNABOOK\dfdfdf.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
–
End of file - 6230 bytes
*****************************************************
EDIT: Here is the log from running MBAM post-reboot. It found tons of stuff. I think the log is from just before I told it to fix everything it could.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4360
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 7.0.5730.13
27/07/2010 11:07:16 PM
mbam-log-2010-07-27 (23-07-16).txt
Scan type: Quick scan
Objects scanned: 143976
Time elapsed: 12 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 7
Files Infected: 73
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\idid (Trojan.Sasfix) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Defense Center (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center (Rogue.DefenseCenter) -> No action taken.
C:\EQUITY\Q-5-6-99-222222CCCC-333333333333-7777777777-111 (Backdoor.IRCBot) -> No action taken.
C:\Recycle\P-1-3-64-8794238531-8742492-9897532 (Trojan.Agent) -> No action taken.
C:\Soft\G-414141ERER-1233211231-12313242131-555 (Worm.AutoRun) -> No action taken.
C:\TeekA\ANAS (Backdoor.Agent) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt (Trojan.DNSChanger) -> No action taken.
Files Infected:
C:\RECYCLER\S-1-5-21-0847472823-8338374939-518292446-5370\yv8g67.exe (Trojan.Proxy) -> No action taken.
C:\WINDOWS\system32\ernel32.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\vryw.kco (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\A3kUO3oC9.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\A55eI.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\A7kU17.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\a93eI93.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\AA3kUO3.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\C1s9eI7q.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\C5sKU.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\eI31q93.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\g31a931s9.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\kU55i.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\KU9317.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\kUOC317y.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\mYWS9317y.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\OC1sKUOC9.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\Q3wS9eIQG.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\s5eIQ.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\sKUOC7.dll (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\UO9o17.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\UOCE3a7k.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\uOCE3aA9.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\WSK93gMY.dll (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\y3c7s317u.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\y555m.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\y793m7.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\1PV3GWDA\401-direct[1].ex (Trojan.Agent.Gen) -> No action taken.
C:\WINDOWS\itrelsr.dll (Trojan.Hiloti) -> No action taken.
C:\WINDOWS\Ktirua.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktirub.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktiruc.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktirud.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktirue.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktiruf.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktirug.exe (Trojan.FraudPack) -> No action taken.
C:\Program Files\Defense Center\about.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\activate.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\buy.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\def.db (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\defext.dll (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\defhook.dll (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\help.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\scan.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\settings.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\splash.mp3 (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\Uninstall.exe (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\update.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\virus.mp3 (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\About.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Activate.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Buy.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Defense Center Support.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Defense Center.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Scan.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Settings.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Update.lnk (Rogue.DefenseCenter) -> No action taken.
C:\EQUITY\Q-5-6-99-222222CCCC-333333333333-7777777777-111\Desktop.ini (Backdoor.IRCBot) -> No action taken.
C:\Recycle\P-1-3-64-8794238531-8742492-9897532\Desktop.ini (Trojan.Agent) -> No action taken.
C:\Soft\G-414141ERER-1233211231-12313242131-555\DeSkToP.ini (Worm.AutoRun) -> No action taken.
C:\TeekA\ANAS\Desktop.ini (Backdoor.Agent) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\pragmabbr.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\PRAGMAc.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\PRAGMAcfg.ini (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\pragmaserf.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\PRAGMAsrcr.dat (Trojan.DNSChanger) -> No action taken.
C:\Documents and Settings\NetworkService\Application Data\dhxiuw.dat (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\config\systemprofile\Application Data\dhxiuw.dat (Malware.Trace) -> No action taken.
C:\Documents and Settings\All Users\Application Data\pragmamfeklnmal.dll (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Application Data\Microsoft\Internet Explorer\Quick Launch\Defense Center.LNK (Rogue.DefenseCenter) -> No action taken.
C:\WINDOWS\system32\sdra64.exe (Spyware.Zbot) -> No action taken.
C:\WINDOWS\system32\secupdat.dat (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\secupdat.dat (Worm.Autorun) -> No action taken.
Anyway, I ran MBAM and found like 38 things wrong before Norton popped up, having found #39, insisting on rebooting the machine to facilitate its removal. I decided to reboot in safe mode which I'm posting this from, and ran HJT. I'll do another MBAM scan right away as well. Meanwhile, here's what HJT has to say for itself. (Note that she's been removing stuff via HJT on advice from another site, I warned her that was unlikely to permanently resolve most issues.)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:32:14 PM, on 27/07/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Administrator.BRENNABOOK\Local Settings\Application Data\Opera\Opera\temporary_downloads\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eeepc.asus.com/global
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.7.0.12\IPSBHO.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\WINDOWS\AsScrPro.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [STrHH] C:\Documents and Settings\Brenna.BRENNABOOK\dfdfdf.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
–
End of file - 6230 bytes
*****************************************************
EDIT: Here is the log from running MBAM post-reboot. It found tons of stuff. I think the log is from just before I told it to fix everything it could.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4360
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 7.0.5730.13
27/07/2010 11:07:16 PM
mbam-log-2010-07-27 (23-07-16).txt
Scan type: Quick scan
Objects scanned: 143976
Time elapsed: 12 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 7
Files Infected: 73
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\idid (Trojan.Sasfix) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Defense Center (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center (Rogue.DefenseCenter) -> No action taken.
C:\EQUITY\Q-5-6-99-222222CCCC-333333333333-7777777777-111 (Backdoor.IRCBot) -> No action taken.
C:\Recycle\P-1-3-64-8794238531-8742492-9897532 (Trojan.Agent) -> No action taken.
C:\Soft\G-414141ERER-1233211231-12313242131-555 (Worm.AutoRun) -> No action taken.
C:\TeekA\ANAS (Backdoor.Agent) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt (Trojan.DNSChanger) -> No action taken.
Files Infected:
C:\RECYCLER\S-1-5-21-0847472823-8338374939-518292446-5370\yv8g67.exe (Trojan.Proxy) -> No action taken.
C:\WINDOWS\system32\ernel32.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\vryw.kco (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\A3kUO3oC9.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\A55eI.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\A7kU17.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\a93eI93.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\AA3kUO3.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\C1s9eI7q.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\C5sKU.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\eI31q93.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\g31a931s9.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\kU55i.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\KU9317.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\kUOC317y.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\mYWS9317y.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\OC1sKUOC9.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\Q3wS9eIQG.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\s5eIQ.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\sKUOC7.dll (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\UO9o17.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\UOCE3a7k.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\uOCE3aA9.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\WSK93gMY.dll (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\y3c7s317u.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\y555m.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\y793m7.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\1PV3GWDA\401-direct[1].ex (Trojan.Agent.Gen) -> No action taken.
C:\WINDOWS\itrelsr.dll (Trojan.Hiloti) -> No action taken.
C:\WINDOWS\Ktirua.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktirub.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktiruc.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktirud.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktirue.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktiruf.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktirug.exe (Trojan.FraudPack) -> No action taken.
C:\Program Files\Defense Center\about.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\activate.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\buy.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\def.db (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\defext.dll (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\defhook.dll (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\help.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\scan.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\settings.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\splash.mp3 (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\Uninstall.exe (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\update.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\virus.mp3 (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\About.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Activate.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Buy.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Defense Center Support.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Defense Center.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Scan.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Settings.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Update.lnk (Rogue.DefenseCenter) -> No action taken.
C:\EQUITY\Q-5-6-99-222222CCCC-333333333333-7777777777-111\Desktop.ini (Backdoor.IRCBot) -> No action taken.
C:\Recycle\P-1-3-64-8794238531-8742492-9897532\Desktop.ini (Trojan.Agent) -> No action taken.
C:\Soft\G-414141ERER-1233211231-12313242131-555\DeSkToP.ini (Worm.AutoRun) -> No action taken.
C:\TeekA\ANAS\Desktop.ini (Backdoor.Agent) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\pragmabbr.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\PRAGMAc.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\PRAGMAcfg.ini (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\pragmaserf.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\PRAGMAsrcr.dat (Trojan.DNSChanger) -> No action taken.
C:\Documents and Settings\NetworkService\Application Data\dhxiuw.dat (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\config\systemprofile\Application Data\dhxiuw.dat (Malware.Trace) -> No action taken.
C:\Documents and Settings\All Users\Application Data\pragmamfeklnmal.dll (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Application Data\Microsoft\Internet Explorer\Quick Launch\Defense Center.LNK (Rogue.DefenseCenter) -> No action taken.
C:\WINDOWS\system32\sdra64.exe (Spyware.Zbot) -> No action taken.
C:\WINDOWS\system32\secupdat.dat (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\secupdat.dat (Worm.Autorun) -> No action taken.