This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Self-help Troubles

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

These long registry entries tend to go out of the code box here, so when copying that last batch file text be sure to copy all text, including the end ….fd80}" (notice the end quote).
i did the zbove steps twice as rem2.bat returned an message: "the service has already been started" in the commandline and the error popup: "deletekey: wrong parameter." (it rebootet nonetheless).
reading your last post i feared i had made a mistake with the script, but the second attempt resulted in the same way. here are the details:

1. created and ran trendit.bat


2. ran flash_disinfector several times with all the flash drives that had been attached to the box and once with no drive attached. took only a second or two independently if a drive was mounted or not… no idea if that means anything but i thought you should know.

3. ran rem2.bat with firewall and avg disabled. resulted in the error message above and rebooted.

4. kaspersky. (log below)

5. combofix. (log below)

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, June 30, 2007 11:07:29 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 30/06/2007
Kaspersky Anti-Virus database records: 356018
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
E:\

Scan Statistics:
Total number of scanned objects: 41884
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 00:49:54

Infected Object Name / Virus Name / Last Action
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\avg7\Log\emc.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Dokumente und Einstellungen\anto\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\MSHist012007063020070701\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\anto\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\ANTO.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\SeagateFlash.exe Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ZLT021ab.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT021ae.TMP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

==============================================================================

"anto" - 2007-06-30 23:08:51 - ComboFix 07-06-27.7 - Service Pack 2 NTFS


((((((((((((((((((((((((( Files Created from 2007-05-28 to 2007-06-30 )))))))))))))))))))))))))))))))


2007-06-30 22:10 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-06-30 21:43 drahs—- C:\autorun.inf
2007-06-30 13:44 853 –a—— C:\reboot.cmd
2007-06-30 13:44 68,096 –a—— C:\diff.exe
2007-06-30 13:44 103,424 –a—— C:\grep.exe
2007-06-30 13:39 d——– C:\DiagHelp
2007-06-29 21:41 d——– C:\Programme\EVEREST Ultimate Edition
2007-06-29 00:58 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Kaspersky Lab
2007-06-27 09:59 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-06-27 09:36 d——– C:\Programme\regbackup
2007-06-26 08:34 d——– C:\WINDOWS\BDOSCAN8
2007-06-25 23:01 d——– C:\DOKUME~1\anto\ricerche di mercato
2007-06-18 09:26 d——– C:\gmer
2007-06-18 09:10 d——– C:\getservice
2007-06-16 15:41 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-06-13 14:52 d——– C:\Programme\ht
2007-06-13 13:46 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-13 12:04 75,512 –a—— C:\WINDOWS\zllsputility.exe
2007-06-13 12:03 1,087,216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-06-13 12:03 d——– C:\WINDOWS\system32\ZoneLabs
2007-06-13 11:42 5,632 –a—— C:\WINDOWS\system32\C22EE0C9.exe
2007-06-13 11:40 5,632 –a—— C:\WINDOWS\system32\A7F4841F.exe
2007-06-13 11:12 d——– C:\RkUnhooker
2007-06-13 09:45 d——– C:\pulire
2007-06-12 10:05 d——– C:\program files
2007-06-12 09:43 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-06-12 09:42 d——– C:\DOKUME~1\anto\.housecall6.6
2007-06-11 16:27 d——– C:\DOKUME~1\anto\ANWEND~1\Comodo
2007-06-11 16:26 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Comodo
2007-06-11 16:20 d——– C:\Programme\Comodo
2007-06-11 16:06 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2007-06-11 16:06 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2007-06-11 16:06 154,112 –a—— C:\WINDOWS\system32\irftp.exe
2007-05-29 11:14 d——– C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-29 11:13 d——– C:\Programme\ClamWin
2007-05-29 11:13 d——– C:\DOKUME~1\ALLUSE~1\.clamwin
2007-05-15 10:57 276,208 –a—— C:\vspubapi.dll
2007-05-15 10:57 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-05-15 10:57 104,176 –a—— C:\vsmonapi.dll
2007-05-06 20:43 d——– C:\Programme\Windows Media Connect 2
2007-05-06 20:36 d——– C:\WINDOWS\system32\drivers\UMDF


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-25 15:31:48 ——– d—–w C:\Programme\JKDefrag
2007-06-25 11:36:29 48,486 —-a-w C:\WINDOWS\system32\perfc007.dat
2007-06-25 11:36:29 316,888 —-a-w C:\WINDOWS\system32\perfh007.dat
2007-06-13 10:07:48 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-06-12 08:37:18 ——– d—–w C:\Programme\Spybot
2007-06-11 11:48:27 ——– d—–w C:\Programme\Startup Optimizer
2007-06-11 10:40:11 ——– d—–w C:\Programme\SyncBack
2007-05-29 15:33:50 ——– d—–w C:\Programme\CCleaner
2007-05-29 09:14:44 ——– d—–w C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-16 15:11:44 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:22:27 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:13:24 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Programme\Spybot\SDHelper.dll [2005-05-31 01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-05-15 12:03]
"ZoneAlarm Client"="C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Programme\Grisoft\AVGAntiSpyware7.5\shellexecutehook.dll" [2007-05-30 14:29]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2kadiras]
2kadiras.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9xadiras]
9xadiras.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
"C:\Programme\ClamWin\bin\ClamTray.exe" –logon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
pctspk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZCfgSvc.exe]
C:\WINDOWS\System32\ZCfgSvc.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


Contents of the 'Scheduled Tasks' folder
2007-01-15 18:05:04 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-30 23:11:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]


Completion time: 2007-06-30 23:13:01
C:\ComboFix-quarantined-files.txt … 2007-06-30 23:12
C:\ComboFix2.txt … 2007-06-30 17:21

— E O F —
Probably should have stayed with what worked, since so much seems to result in no positive action so often today.


Save the following as "All files" seafix.bat. Reboot into Safe Mode and click the batch file to run. After the reboot again a Kaspersky please.


@echo off
net start gmer
gmer.exe -del C:\WINDOWS\system32\SeagateFlash.exe
gmer.exe -reboot



Also after the reboot please run a new GMER scan and post that log.
1. seafix.bat said "the service has already been started" and then rebootet
2. kaspersky-log (below)
3. gmer-log (below)

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Sunday, July 01, 2007 10:45:18 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 1/07/2007
Kaspersky Anti-Virus database records: 356161
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
E:\

Scan Statistics:
Total number of scanned objects: 41882
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 00:49:00

Infected Object Name / Virus Name / Last Action
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\avg7\Log\emc.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Dokumente und Einstellungen\anto\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\MSHist012007063020070701\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\MSHist012007070120070702\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\anto\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\ANTO.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\SeagateFlash.exe Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ZLT02767.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT0276a.TMP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

==========================================================================

GMER 1.0.12.12244 - http://www.gmer.net
Rootkit scan 2007-07-01 10:53:40
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateFile
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateKey
SSDT \SystemRoot\System32\vsdatant.sys ZwCreatePort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcessEx
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateSection
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateWaitablePort
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteFile
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDuplicateObject
SSDT \SystemRoot\System32\vsdatant.sys ZwLoadKey
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenFile
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenThread
SSDT \SystemRoot\System32\vsdatant.sys ZwReplaceKey
SSDT \SystemRoot\System32\vsdatant.sys ZwRequestWaitReplyPort
SSDT \SystemRoot\System32\vsdatant.sys ZwRestoreKey
SSDT \SystemRoot\System32\vsdatant.sys ZwSecureConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwSetInformationFile
SSDT \SystemRoot\System32\vsdatant.sys ZwSetValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwTerminateProcess

—- Kernel code sections - GMER 1.0.12 —-

.text ntoskrnl.exe!_abnormal_termination + 104 804E2760 12 Bytes [ F0, 61, 9C, F0, 80, C4, 9C, … ]
? srescan.sys Das System kann die angegebene Datei nicht finden.
? C:\WINDOWS\System32\DRIVERS\update.sys
.text ntoskrnl.exe!_abnormal_termination + 104 804E2760 12 Bytes [ F0, 61, 9C, F0, 80, C4, 9C, … ]

—- Devices - GMER 1.0.12 —-

Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F97A685A] avgtdi.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F97A685A] avgtdi.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F97A685A] avgtdi.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F97A685A] avgtdi.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F97A685A] avgtdi.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [F09D78A0] vsdatant.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06846B0] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06846B0] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06846B0] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06846B0] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06846B0] tfsnifs.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [F068484C] tfsnifs.sys

—- EOF - GMER 1.0.12 —-
Still a hold-out there, again with a mechanism protecting it. What device specifically do you use the Bluetooth connection for that show in logs here?


Let's give ComboFix a new try, as we have made improvements since earlier steps.


Delete any copies of ComboFix.exe, and again download ComboFix.exe from here to your desktop.



Then open Notepad (Start > Run > in the Open field type: notepad)
Click: OK

Copy/ paste the entire contents of the textbox below to Notepad (not including the word "Code" - this is just a text box title):

File::
C:\WINDOWS\system32\SeagateFlash.exe

Folder::
C:\WINDOWS\Temp

Save as ComboFix-Do.txt
Change the "Save as type" to "All Files"
Save it to the Desktop.

[external image: Posted Image]

Referring to the screen shot above, drag ComboFix-Do.txt into ComboFix.exe
ComboFix now runs a scan on your system, and may reboot when it finishes. This is normal.

CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

When finished, a log is produced: C:\ComboFix.txt

Please provide the contents of the C:\ComboFix.txt in your next reply.
hi Jintan!
bluetooth isn't used for anything on this system, i actually had it disactivated, one of our steps must have reactivated it…?

i downloaded a new copy of combofix and followed the instructions, here's the output:

ComboFix 07-06-18.2 - C:\Dokumente und Einstellungen\anto\Desktop\ComboFix.exe
"anto" - 2007-07-01 17:48:10 - Service Pack 2 NTFS
Command switches used :: C:\Dokumente und Einstellungen\anto\Desktop\ComboFix_Do.txt


((((((((((((((((((((((((( Files Created from 2007-06-01 to 2007-07-01 )))))))))))))))))))))))))))))))


2007-06-30 22:10 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-06-30 21:43 drahs—- C:\autorun.inf
2007-06-30 13:44 853 –a—— C:\reboot.cmd
2007-06-30 13:44 68,096 –a—— C:\diff.exe
2007-06-30 13:44 103,424 –a—— C:\grep.exe
2007-06-30 13:39 d——– C:\DiagHelp
2007-06-29 21:41 d——– C:\Programme\EVEREST Ultimate Edition
2007-06-29 00:58 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Kaspersky Lab
2007-06-27 09:59 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-06-27 09:36 d——– C:\Programme\regbackup
2007-06-26 08:34 d——– C:\WINDOWS\BDOSCAN8
2007-06-25 23:01 d——– C:\DOKUME~1\anto\ricerche di mercato
2007-06-18 09:26 d——– C:\gmer
2007-06-18 09:10 d——– C:\getservice
2007-06-16 15:41 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-06-13 14:52 d——– C:\Programme\ht
2007-06-13 13:46 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-13 12:04 75,512 –a—— C:\WINDOWS\zllsputility.exe
2007-06-13 12:03 1,087,216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-06-13 12:03 d——– C:\WINDOWS\system32\ZoneLabs
2007-06-13 11:42 5,632 –a—— C:\WINDOWS\system32\C22EE0C9.exe
2007-06-13 11:40 5,632 –a—— C:\WINDOWS\system32\A7F4841F.exe
2007-06-13 11:12 d——– C:\RkUnhooker
2007-06-13 09:45 d——– C:\pulire
2007-06-12 10:05 d——– C:\program files
2007-06-12 09:43 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-06-12 09:42 d——– C:\DOKUME~1\anto\.housecall6.6
2007-06-11 16:27 d——– C:\DOKUME~1\anto\ANWEND~1\Comodo
2007-06-11 16:26 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Comodo
2007-06-11 16:20 d——– C:\Programme\Comodo
2007-06-11 16:06 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2007-06-11 16:06 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2007-06-11 16:06 154,112 –a—— C:\WINDOWS\system32\irftp.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-25 15:31:48 ——– d—–w C:\Programme\JKDefrag
2007-06-25 11:36:29 48,486 —-a-w C:\WINDOWS\system32\perfc007.dat
2007-06-25 11:36:29 316,888 —-a-w C:\WINDOWS\system32\perfh007.dat
2007-06-13 10:07:48 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-06-12 08:37:18 ——– d—–w C:\Programme\Spybot
2007-06-11 11:48:27 ——– d—–w C:\Programme\Startup Optimizer
2007-06-11 10:40:11 ——– d—–w C:\Programme\SyncBack
2007-05-29 15:33:50 ——– d—–w C:\Programme\CCleaner
2007-05-29 14:46:36 ——– d—–w C:\Programme\ClamWin
2007-05-29 09:14:44 ——– d—–w C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-16 15:11:44 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-06 18:43:15 ——– d—–w C:\Programme\Windows Media Connect 2
2007-04-25 14:22:27 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:13:24 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Programme\Spybot\SDHelper.dll [2005-05-31 01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-05-15 12:03]
"ZoneAlarm Client"="C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Programme\Grisoft\AVGAntiSpyware7.5\shellexecutehook.dll" [2007-05-30 14:29]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2kadiras]
2kadiras.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9xadiras]
9xadiras.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
"C:\Programme\ClamWin\bin\ClamTray.exe" –logon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
pctspk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZCfgSvc.exe]
C:\WINDOWS\System32\ZCfgSvc.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3a5fda0-0df4-11dc-8c7f-00904bb1fd80}]
AutoRun\command- explorer.exe /n,/e,\


Contents of the 'Scheduled Tasks' folder
2007-01-15 18:05:04 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-01 17:51:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

cmd.exe [7820]


scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]


Completion time: 2007-07-01 17:52:24
C:\ComboFix-quarantined-files.txt … 2007-07-01 17:52
C:\ComboFix2.txt … 2007-06-30 23:13
C:\ComboFix3.txt … 2007-06-30 17:21

— E O F —
No file removal log with that. I will have to check with that tool's author about these new registry entries (the mountpoints2 items we have been removing) that I see now appear linked in some manner. wE'LL AGAIN REMOVE THAT HERE. Let's apply a few different approaches, and accept what works.


REGEDIT4

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3a5fda0-0df4-11dc-8c7f-00904bb1fd80}]
Open Notepad and copy and paste the above text (inside the box) into the text file. Now go to File > Save As and call it pointfix.reg. Where it says "Files of Type", select All Files and click on Save. Exit Notepad, double-click on the file and ok the prompt asking if you wish to merge the file with your registry.


Firs please repeat the step you did earlier with the seafix.bat file and running that in Safe Mode, but here repeat also the earlier steps to open msconfig, unload the services, then recheck to reload the services (very important), and run seafix.bat.


After the reboot delete the C:\Avenger folder and copy of Avenger.exe and Avenger.zip and again download The Avenger from here to your Desktop and unzip it. If you can, download and unzip this on a different computer, rename the Avenger.exe file to remover.exe, then transfer that and click to run when called for.

Copy all the text contained in the code box below by highlighting it and right clicking and selecting "Copy"

Files to delete:
C:\WINDOWS\system32\SeagateFlash.exe

Folders to delete:
C:\WINDOWS\Temp

Now, start The Avenger program by clicking on its icon on your desktop (click the renamed remover.exe if you did that). Look under "Script file to execute" and click on "Input Script Manually". Next click on the Magnifying Glass icon and a blank dialogue box will open called "View/Edit script". Position your mouse inside the box, rightclick and choose Paste. All the text above in the code box should now appear there. Click Done and click on the Green Light to begin execution of the script. Answer "Yes" twice when prompted.

The Avenger will restart your computer. (if the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)

When you have rebooted, a black command window briefly opens on your desktop, this is normal. A logfile will be created that records all actions that The Avenger performed. This log file is saved to C:\avenger.txt. The deleted files will be backed up and saved to C:\avenger\backup.zip.


=================================================

Once your computer has rebooted, a Kaspersky scan log again please, as well as the avenger.txt log. If more difficulties we will next restore some permissions there and do new approaches.
hi jintan!

1. ran pointfixreg
2.booted into safe mode
3. ran msconfig, unloaded and then reloaded system services
4. ran seafix.bat (responding as usual "the service has already been started" and rebooting then -does this have any special meaning?)
5. deleted the avenger folder, avenger.exe and also the renamed avenger: worker.exe
6.downloaded avenger from a different pc, unzipped, renamed to remover.exe and copied to the infected pc
7. ran remover.exe with the script provided and rebooted. (log below)
8. did a new kaspersky-scan (log below)

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\icgvagos

*******************

Script file located at: \??\C:\aoajicqp.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\system32\SeagateFlash.exe deleted successfully.
Folder C:\WINDOWS\Temp deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
=================================================

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, July 02, 2007 10:14:46 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 2/07/2007
Kaspersky Anti-Virus database records: 356403
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
E:\

Scan Statistics:
Total number of scanned objects: 41867
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 00:49:21

Infected Object Name / Virus Name / Last Action
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\avg7\Log\emc.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Dokumente und Einstellungen\anto\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\MSHist012007062520070702\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\MSHist012007070220070703\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\anto\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\ANTO.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
Very good. Now we will need to see if we can see other changes made. That service error is due to the GMER service already being "Started". Although there would be other methods to do the same delete step, with unknown changes infection brings and us employing unconventional methods like service unloading that use looked a best idea.


If you would, locate this new C:\avenger\backup.zip and again upload it here as you have done before.



Then I would like you do redo a step that didn't quite work well the first go-round. Be sure when creating the following file you do not include the word "CODE", which is only the way the forum creates the text box.

Go to Start->Run and type in notepad and hit OK. Then copy and paste the following into Notepad:

regedit /e c:\1.txt "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess"
regedit /e c:\2.txt "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced"
copy c:\1.txt+c:\2.txt c:\3.txt
del c:\1.txt
del c:\2.txt
notepad c:\3.txt
Save the file as "seesome.bat". Make sure to save it with the quotes. Double click on it. Post that notepad file that opened up automatically here. Just copy and paste the text here. If it again is a very large file do not post the contents and just update me in your next reply.



Then go here and download and RootKit Revealer. Once downloaded, unzip the files to their own folder and rename RootKitRevealer.exe to Find.exe. The reason for this is that some rootkit trojans can detect this program and hide themselves from it.

When you have done this, click on Options and make sure that "Hide Standard NTFS Metadata Files" and "Scan Registry" are both checked.

Before scanning, make sure all other running programs are closed, and no other actions (like a scheduled AV scan) will occur while this scan completes. Do not use your computer during the scan. Click on scan and let it scan your drive (it will take a while so be patient). When it has finished, go to File > Save, save the log and post it in this thread.



And go here and download reglooks.exe to your Desktop. Doubleclick on it to run it and when it has finished scanning, a log named result.txt will open in Notepad. Copy the log and post it in this thread as well, and let's see if we get new info to work from (if needed).
1. uploaded avengers backup.zip

2. here is "seesome.bat"s output:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess]
"Type"=dword:00000020
"Start"=dword:00000002
"ErrorControl"=dword:00000001
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"DisplayName"="Internet Connection Sharing"
"DependOnService"=hex(7):52,00,61,00,73,00,4d,00,61,00,6e,00,00,00,00,00
"DependOnGroup"=hex(7):00,00
"ObjectName"="LocalSystem"
"Description"="Provides network address translation, addressing, and name resolution services for all computers on your home network through a dial-up connection."

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch]
"Epoch"=dword:00002e8d

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
69,00,70,00,6e,00,61,00,74,00,68,00,6c,00,70,00,2e,00,64,00,6c,00,6c,00,00,\
00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP"="139:TCP:*:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:*:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:*:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:*:Enabled:@xpsp2res.dll,-22002"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=dword:00000000
"DoNotAllowExceptions"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
"445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
"137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
"138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"
"1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,\
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
00,00,02,00,60,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,0b,00,00,00,00,\
00,18,00,fd,01,02,00,01,02,00,00,00,00,00,05,20,00,00,00,23,02,00,00,01,01,\
00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup]
"ServiceUpgrade"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate]
"{97BE45F3-2269-42F7-8DB6-7DB97DDD87B2}"=dword:00000001
"{399206AF-C485-4C6F-870A-0BF6E476C3C7}"=dword:00000001
"All"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum]
"0"="Root\\LEGACY_SHAREDACCESS\\00"
"Count"=dword:00000001
"NextInstance"=dword:00000001

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden"=dword:00000001
"ShowCompColor"=dword:00000001
"HideFileExt"=dword:00000000
"DontPrettyPath"=dword:00000000
"ShowInfoTip"=dword:00000001
"HideIcons"=dword:00000000
"MapNetDrvBtn"=dword:00000000
"WebView"=dword:00000000
"Filter"=dword:00000000
"SuperHidden"=dword:00000001
"SeparateProcess"=dword:00000000
"ListviewAlphaSelect"=dword:00000000
"ListviewShadow"=dword:00000001
"ListviewWatermark"=dword:00000000
"TaskbarAnimations"=dword:00000000
"StartMenuInit"=dword:00000002
"StartButtonBalloonTip"=dword:00000002
"TaskbarSizeMove"=dword:00000000
"TaskbarGlomming"=dword:00000001
"Start_ShowNetPlaces_ShouldShow"=dword:00000041
"Start_LargeMFUIcons"=dword:00000001
"Start_MinMFU"=dword:00000006
"ClassicViewState"=dword:00000000
"NoNetCrawling"=dword:00000000
"FolderContentsInfoTip"=dword:00000001
"FriendlyTree"=dword:00000001
"ShowSuperHidden"=dword:00000001
"WebViewBarricade"=dword:00000000
"DisableThumbnailCache"=dword:00000000
"PersistBrowsers"=dword:00000000
"ServerAdminUI"=dword:00000000
"Start_ShowNetConn_ShouldShow"=dword:00000042

3. the renamed rootkit revealer revealed this:

HKU\.DEFAULT\Control Panel\International 01.07.2007 17:52 0 bytes Security mismatch.
HKU\.DEFAULT\Control Panel\International\Geo 01.07.2007 17:52 0 bytes Security mismatch.
HKU\S-1-5-21-1993962763-1708537768-1060284298-1003\Control Panel\International 02.07.2007 09:23 0 bytes Security mismatch.
HKU\S-1-5-21-1993962763-1708537768-1060284298-1003\Control Panel\International\Geo 01.07.2007 17:52 0 bytes Security mismatch.
HKU\S-1-5-18\Control Panel\International 01.07.2007 17:52 0 bytes Security mismatch.
HKU\S-1-5-18\Control Panel\International\Geo 01.07.2007 17:52 0 bytes Security mismatch.
HKLM\SECURITY\Policy\Secrets\SAC* 31.10.2004 13:34 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 31.10.2004 13:34 0 bytes Key name contains embedded nulls (*)

4. and here is the reglooks-log.

REGLOOKS logfile

version 0.971
03.07.2007 10:26:22,58
running from: "C:\Dokumente und Einstellungen\anto\Desktop"

— SSODL regkeys —

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
only standard or legit regkeys found


— STS regkeys —

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
only standard or legit regkeys found


— USERINIT regkey —

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"


— SHELL regkey —

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
"Shell"="Explorer.exe"


— SYSTEM regkey —

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
"System"=""


— APPINIT_DLLS regkey —

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows
"AppInit_DLLs"=""


— NOTIFY regkeys —

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
"igfxcui" "DLLName"="igfxsrvc.dll"


— BOOTEXECUTE regkey —

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
BootExecute= autocheck autochk *\


— SHELLEXECUTEHOOKS regkey —

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"


— AUTORUN regkeys —

HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor
"AutoRun"=""


— HKLM\Run regkeys —

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"ZoneAlarm Client"="\"C:\\Programme\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"
[run\OptionalComponents]
[run\OptionalComponents\IMAIL]
"Installed"="1"
[run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[run\OptionalComponents\MSFS]
"Installed"="1"


— HKLM\RunOnce regkeys —

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
no HKLM RunOnce keys found


— HKLM\RunOnceEx regkeys —

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
no HKLM RunOnceEx keys found


— HKLM\RunServices regkeys —

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
no HKLM RunServices keys found


— HKLM\RunServicesOnce regkeys —

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
no HKLM RunServicesOnce keys found


— HKCU\Run regkeys —

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
no HKCU Run keys found


— HKCU\RunOnce regkeys —

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
no HKCU RunOnce keys found


— HKCU\RunOnceEx regkeys —

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
regkey does not exist


— HKCU\RunServices regkeys —

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
no HKCU RunServices keys found


— HKCU\RunServicesOnce regkeys —

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
no HKCU RunServicesOnce keys found


— HKU\.DEFAULT\Run regkeys —

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"


— HKU\S-1-5-18\Run regkeys —

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"


— HKU\S-1-5-19\Run regkeys —

HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"


— HKU\S-1-5-20\Run regkeys —

HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"


— HKLM\Explorer\Run regkeys —

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
no HKLM Explorer\Run keys found


— HKCU\Explorer\Run regkeys —

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
no HKCU Explorer\Run keys found


— Image File Execution regkeys —

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
no debuggers found


— BROWSER HELPER OBJECTS regkeys —

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
"{53707962-6F74-2D53-2644-206D7942484F}" FILE ="C:\\Programme\\Spybot\\SDHelper.dll"


— TOOLBAR regkeys —

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
no toolbars found


— URLSEARCHHOOKS regkeys —

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks
only standard regkeys found


— CONTEXTMENUHANDLERS regkeys —

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers
"AVG Anti-Spyware" CLSID ={8934FCEF-F5B8-468f-951F-78A921CD3920} FILE ="C:\\Programme\\Grisoft\\AVGAntiSpyware7.5\\context.dll"
"AVG7 Shell Extension" CLSID ={9F97547E-4609-42C5-AE0C-81C61FFAEBC3} FILE ="C:\\PROGRA~1\\Grisoft\\AVG7\\avgse.dll"
"ClamWin" CLSID ={65713842-C410-4f44-8383-BFE01A398C90} FILE ="C:\\Programme\\ClamWin\\bin\\ExpShell.dll"
"Offline Files" CLSID ={750fdf0e-2a26-11d1-a3ea-080036587f03} FILE =%SystemRoot%\System32\cscui.dll
"Open With" CLSID ={09799AFB-AD67-11d1-ABCD-00C04FC30936} FILE =%SystemRoot%\system32\SHELL32.dll
"Open With EncryptionMenu" CLSID ={A470F8CF-A1E8-4f65-8335-227475AA5C46} FILE =%SystemRoot%\system32\SHELL32.dll
"WinZip" CLSID ={E0D79304-84BE-11CE-9641-444553540000} FILE ="C:\\PROGRA~1\\WINZIP\\WZSHLSTB.DLL"
"ZLAVShExt" CLSID ={D9872D13-7651-4471-9EEE-F0A00218BEBB} FILE ="C:\\Programme\\Zone Labs\\ZoneAlarm\\zlavscan.dll"
"{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}" Start Menu Pin FILE =%SystemRoot%\system32\SHELL32.dll

HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers
"AVG Anti-Spyware" CLSID ={8934FCEF-F5B8-468f-951F-78A921CD3920} FILE ="C:\\Programme\\Grisoft\\AVGAntiSpyware7.5\\context.dll"
"EncryptionMenu" CLSID ={A470F8CF-A1E8-4f65-8335-227475AA5C46} FILE =%SystemRoot%\system32\SHELL32.dll
"Offline Files" CLSID ={750fdf0e-2a26-11d1-a3ea-080036587f03} FILE =%SystemRoot%\System32\cscui.dll
"Sharing" CLSID ={f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} FILE ="ntshrui.dll"
"WinZip" CLSID ={E0D79304-84BE-11CE-9641-444553540000} FILE ="C:\\PROGRA~1\\WINZIP\\WZSHLSTB.DLL"

HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers
"AVG7 Shell Extension" CLSID ={9F97547E-4609-42C5-AE0C-81C61FFAEBC3} FILE ="C:\\PROGRA~1\\Grisoft\\AVG7\\avgse.dll"
"ClamWin" CLSID ={65713842-C410-4f44-8383-BFE01A398C90} FILE ="C:\\Programme\\ClamWin\\bin\\ExpShell.dll"
"NetWareUNCMenu" CLSID ={e3f2bac0-099f-11cf-8daa-00aa004a5691} FILE ="nwprovau.dll"
"UnlockerShellExtension" CLSID ={DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} FILE ="C:\\Programme\\Unlocker\\UnlockerCOM.dll"
"WinZip" CLSID ={E0D79304-84BE-11CE-9641-444553540000} FILE ="C:\\PROGRA~1\\WINZIP\\WZSHLSTB.DLL"
"ZLAVShExt" CLSID ={D9872D13-7651-4471-9EEE-F0A00218BEBB} FILE ="C:\\Programme\\Zone Labs\\ZoneAlarm\\zlavscan.dll"


— ALTERNATESHELL regkey —

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
"AlternateShell"="cmd.exe"


— SAFEBOOT MINIMAL SERVICES —

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
AVG Anti-Spyware Driver
AVG Anti-Spyware Guard


— SAFEBOOT NETWORK SERVICES —

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network
AVG Anti-Spyware Driver
AVG Anti-Spyware Guard
nm
nm.sys


— SERVICES —

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ADILOADER
"DisplayName"="General Purpose USB Driver (adildr.sys)"
System32\Drivers\adildr.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adiusbaw
"DisplayName"="StarModem ADSL USB MODEM WAN ADAPTER"
System32\DRIVERS\adiusbaw.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Adobe LM Service
"DisplayName"="Adobe LM Service"
"C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AegisP
"DisplayName"="AEGIS Protocol (IEEE 802.1x) v3.0.0.7"
System32\DRIVERS\AegisP.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Aspi32
no imagepath value found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVG Anti-Spyware Driver
"DisplayName"="AVG Anti-Spyware Driver"
\??\C:\Programme\Grisoft\AVGAntiSpyware7.5\guard.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVG Anti-Spyware Guard
"DisplayName"="AVG Anti-Spyware Guard"
C:\Programme\Grisoft\AVGAntiSpyware7.5\guard.exe

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avg7Alrt
"DisplayName"="AVG7 Alert Manager Server"
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avg7Core
"DisplayName"="AVG7 Kernel"
\SystemRoot\System32\Drivers\avg7core.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avg7RsW
"DisplayName"="AVG7 Wrap Driver"
\SystemRoot\System32\Drivers\avg7rsw.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avg7RsXP
"DisplayName"="AVG7 Resident Driver XP"
\SystemRoot\System32\Drivers\avg7rsxp.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Avg7UpdSvc
"DisplayName"="AVG7 Update Service"
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgClean
"DisplayName"="AVG7 Clean Driver"
\SystemRoot\System32\Drivers\avgclean.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVGEMS
"DisplayName"="AVG E-mail Scanner"
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AvgTdi
"DisplayName"="AVG Network Redirector"
\SystemRoot\System32\Drivers\avgtdi.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Bcfilter
"DisplayName"="Jetico Personal Firewall Network Monitor"
system32\DRIVERS\bcfilter.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BcfilterMP
system32\DRIVERS\bcfilter.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BCMLogon
no imagepath value found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BthEnum
"DisplayName"="Bluetooth-Anforderungsblocktreiber"
system32\DRIVERS\BthEnum.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BthPan
"DisplayName"="Bluetooth-Gerät (PAN)"
system32\DRIVERS\bthpan.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT
"DisplayName"="Bluetooth-Porttreiber"
System32\Drivers\BTHport.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BthServ
"DisplayName"="Bluetooth Support Service"
%SystemRoot%\system32\svchost.exe -k bthsvcs

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHUSB
"DisplayName"="USB-Treiber für Bluetooth-Funkgerät"
System32\Drivers\BTHUSB.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\drvmcdb
system32\drivers\drvmcdb.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\drvncdb
no imagepath value found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\drvnddm
system32\drivers\drvnddm.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\E100B
"DisplayName"="Intel® PRO Adapter Driver"
System32\DRIVERS\e100b325.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gmer
System32\DRIVERS\gmer.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HidUsb
"DisplayName"="Microsoft HID Class-Treiber"
System32\DRIVERS\hidusb.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i740
System32\DRIVERS\i740nt5.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ialm
System32\DRIVERS\ialmnt5.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ILADFtmi
no imagepath value found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\intelppm
"DisplayName"="Intel-Prozessortreiber"
System32\DRIVERS\intelppm.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouhid
"DisplayName"="Maus-HID-Treiber"
System32\DRIVERS\mouhid.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NAL
"DisplayName"="Nal Service "
\??\C:\WINDOWS\System32\Drivers\iqvw32.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetSvc
"DisplayName"="Intel NCS NetService"
C:\Programme\Intel\NCS\Sync\NetSvc.exe

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NWCWorkstation
"DisplayName"="Client Service für NetWare"
%SystemRoot%\System32\svchost.exe -k netsvcs

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkIpx
"DisplayName"="NWLink IPX/SPX/NetBIOS-kompatibles Transportprotokoll"
System32\DRIVERS\nwlnkipx.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkNb
"DisplayName"="NWLink-NetBIOS"
System32\DRIVERS\nwlnknb.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NwlnkSpx
"DisplayName"="NWLink SPX/SPXII-Protokoll"
System32\DRIVERS\nwlnkspx.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NWRDR
"DisplayName"="NetWare Rdr"
System32\DRIVERS\nwrdr.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ptserial
"DisplayName"="W2K Pctel Serial Device Driver"
System32\DRIVERS\ptserial.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PxHelp20
"DisplayName"="PxHelp20"
System32\Drivers\PxHelp20.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RegSrvc
"DisplayName"="RegSrvc"
C:\WINDOWS\System32\RegSrvc.exe

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RFCOMM
"DisplayName"="Bluetooth-Gerät (RFCOMM-Protokoll-TDI)"
system32\DRIVERS\rfcomm.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rkhdrv31
"DisplayName"="Rootkit Unhooker Driver"
no imagepath value found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\S24EventMonitor
"DisplayName"="Spectrum24 Event Monitor"
C:\WINDOWS\System32\S24EvMon.exe

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s24trans
"DisplayName"="WLAN Transport"
System32\DRIVERS\s24trans.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ScsiPort
%SystemRoot%\system32\drivers\scsiport.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\serenum
"DisplayName"="Serenum-Filtertreiber"
System32\DRIVERS\serenum.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sscdbhk5
system32\drivers\sscdbhk5.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ssrtln
system32\drivers\ssrtln.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\STAC97
"DisplayName"="Audio Driver (WDM) - SigmaTel CODEC"
system32\drivers\stac97.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swwd
no imagepath value found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tfsnboio
system32\dla\tfsnboio.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tfsncofs
system32\dla\tfsncofs.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tfsndrct
system32\dla\tfsndrct.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tfsndres
system32\dla\tfsndres.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tfsnifs
system32\dla\tfsnifs.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tfsnopio
system32\dla\tfsnopio.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tfsnpool
system32\dla\tfsnpool.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tfsnudf
system32\dla\tfsnudf.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tfsnudfa
system32\dla\tfsnudfa.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbprint
"DisplayName"="Microsoft USB-Druckerklasse"
System32\DRIVERS\usbprint.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Vmodem
"DisplayName"="W2k Vmodem"
System32\DRIVERS\vmodem.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Vpctcom
"DisplayName"="W2k Vpctcom"
System32\DRIVERS\vpctcom.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vsdatant
"DisplayName"="vsdatant"
System32\vsdatant.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vsmon
"DisplayName"="TrueVector Internet Monitor"
C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Vvoice
"DisplayName"="W2k Vvoice"
System32\DRIVERS\vvoice.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WLTRYSVC
"DisplayName"="WLTRYSVC"
%SystemRoot%\System32\wltrysvc.exe %SystemRoot%\System32\bcmwltry.exe

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wmi
"DisplayName"="Treibererweiterungen für Windows-Verwaltungsinstrumentation"
%SystemRoot%\System32\svchost.exe -k netsvcs

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wssuitwa
system32\drivers\arhstjwr.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{95C50C0A-6F7F-48F8-98CF-02D77B2625A9}
no imagepath value found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{97BE45F3-2269-42F7-8DB6-7DB97DDD87B2}
no imagepath value found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{DEE19088-BB5A-45EE-B1DC-132DB96F1400}
no imagepath value found


— SECURITYPROVIDERS regkey —

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


— SVCHOST regkey —

HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost
LocalService: AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService: DnsCache\
netsvcs: 6to4AppMgmtAudioSrvBrowserCryptSvcDMServerDHCPERSvcEventSystemFastUserSwitchingC
mpatibilityHidServIasIpripIrmonLanmanServerLanmanWorkstationMessengerNetmanNlaNt
ssvcNWCWorkstationNwsapagentRasautoRasmanRemoteaccessScheduleSeclogonSENSShareda
cessSRServiceTapisrvThemesTrkWksW32TimeWZCSVCWmiWmdmPmSpwinmgmtTermServicewuause
vBITSShellHWDetectionhelpsvcxmlprovwscsvcWmdmPmSN\
rpcss: RpcSs\
imgsvc: StiSvc\
termsvcs: TermService\
HTTPFilter: HTTPFilter\
DcomLaunch: DcomLaunchTermService\
bthsvcs: BthServ\
WudfServiceGroup: WUDFSvc\


— WOW-CMDLINE regkeys —

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WOW
"cmdline" = %SystemRoot%\system32\ntvdm.exe
"wowcmdline" = %SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386


— STARTUP FOLDERS —



— TASK SCHEDULER JOBS —

C:\WINDOWS\tasks\AppleSoftwareUpdate.job


— File associations —

.BAT files: ("%1" %*)
.COM files: ("%1" %*)
.EXE files: ("%1" %*)
.HLP files: (%SystemRoot%\System32\winhlp32.exe %1)
.INF files: (%SystemRoot%\System32\NOTEPAD.EXE %1)
.INI files: (%SystemRoot%\System32\NOTEPAD.EXE %1)
.JS files: (%SystemRoot%\System32\WScript.exe "%1" %*)
.PIF files: ("%1" %*)
.REG files: (regedit.exe "%1")
.SCR files: ("%1" %*)
.TXT files: (%SystemRoot%\system32\NOTEPAD.EXE %1)
.VBS files: (%SystemRoot%\System32\WScript.exe "%1" %*)


FINISHED
Very good - it looks like you have more access now to checking areas that were blocked. No new stealth issues in that rootkit scan. I did receive that zip file, thanks, but for reasons unknown to me right now the SeagateFlash.exe was not saved by Avenger to it. The registry information you posted looks good, but mostly reflects the SP2 firewall settings. As you have third party firewall(s) (I notice in looking back two versions, so would hope one is inactive) - what is the status of your firewall at this time?

The last log has some extra networking related driver info that will have to be considered as part of your setup, and a random unknown driver that is possibly from an earlier failed step we did. To be safe we will remove that now.


Go to Start > Run and type

cmd

and OK. Type the below commands and hit "Enter" after each line

sc stop wssuitwa
sc delete wssuitwa


Type Exit to close.


Then do a search for the following file and rename it by adding ".old" to the name. Please zip a copy of that and upload it for review, to not leave stones unturned there.

C:\system32\drivers\arhstjwr.sys


Then reboot. Delete the existing C:\SDFix folder and SDFix.exe file, and download SDFix.exe and save it to your desktop.

===================================================


Reboot into Safe Mode (at startup tap the F8 key and select Safe Mode).


In Safe Mode, click the SDFix.exe and allow it to extract to it's own folder. Open the extracted folder and double click RunThis.bat to start the script.


Next type Y to begin the script. Once the fix has run it will prompt you to restart your computer. Press any key to restart at this time. Your system will take longer that normal to restart as the fixtool will be running and removing files.

When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
Then open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back here along with a new HijackThis log please.
hi jintan.

only one firewall is up of course: zonealarm. had installed comodo just for testing for a day or two and dumped it… must have left some folders behind.

toady the road was a little bumpy:

1. stopping wssuitwa did not work in normal mode:
"[SC] ControlService FAILED 1062:
service has not been started"
subsequently deleting it did not work as well of course:
"[SC] OpenService FAILED 1060:
The Service is not installed"

so i retried from Safe Mode and it worked :)

2.

hen do a search for the following file and rename it by adding ".old" to the name. Please zip a copy of that and upload it for review, to not leave stones unturned there.

C:\system32\drivers\arhstjwr.sys

i assume you wanted me to rename and upload C:\WINDOWS\system32\drivers\arthstjwr.sys the file was nowhere to be found however.

3.
proceeded anyhow with SDFix in Safe Mode, you'll find the report below.

4. hijackthis
ran into an error:
"An unexpected error has occurred at procedure: modMain_CheckOther1Item() Error #5 - Invalid procedure call or argument"
when doing the scan (log below). to doublecheck it i rebooted and did another scan which went fine and was identical to the first scan but for an additional running process: "C:\WINDOWS\system32\wuauclt.exe"

=======================================================
SDFix: Version 1.89

Run by [removed] on 04.07.2007 at 09:16

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:






Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Missing Security Center Service
Restoring Missing SharedAccess Service

Rebooting…


Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\WINDOWS\SYSTEM32\ERASEM~1.EXE - Deleted
C:\WINDOWS\system32\eraseme_87086.exe - Deleted



Removing Temp Files…

ADS Check:

Checking C:\WINDOWS
C:\WINDOWS
No streams found.

Checking C:\WINDOWS\system32
C:\WINDOWS\system32
No streams found.

Checking C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.

Checking C:\WINDOWS\system32\ntoskrnl.exe
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files:
—————

Backups Folder: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

C:\Dokumente und Einstellungen\All Users\DRM\Cache\Indiv01.tmp
C:\Dokumente und Einstellungen\mat\Desktop\tesi pi\Abschnitt III\~WRL3505.tmp
C:\Dokumente und Einstellungen\mat\Desktop\tesi pi\ENDFASSUNG Kapitel\~WRL2940.tmp
C:\Dokumente und Einstellungen\mat\Desktop\tesi pi\FERTIGE Kapitel\~WRL3190.tmp
C:\Dokumente und Einstellungen\mat\Desktop\tesi pi\FERTIGE Kapitel\~WRL3835.tmp
C:\WINDOWS\system32\config\default.tmp.LOG
C:\WINDOWS\system32\config\SAM.tmp.LOG
C:\WINDOWS\system32\config\SECURITY.tmp.LOG
C:\WINDOWS\system32\config\software.tmp.LOG
C:\WINDOWS\system32\config\system.tmp.LOG

Finished
================================================================================
=

Logfile of HijackThis v1.99.1
Scan saved at 09:28:21, on 04.07.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Grisoft\AVGAntiSpyware7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programme\ht\msnoob.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sev84.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.libero.it
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.it/0SEITIT/SAOS01?FORM=TOOLBR
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot\SDHelper.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O8 - Extra context menu item: E&sporta; in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.libero.it
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1113512489581
O16 - DPF: {FBFF6F10-ABCD-9544-832F-A1F75A0501AE} - http://www.ricerchiamo.net/cart/x/gsa_0082.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programme\Grisoft\AVGAntiSpyware7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Programme\Intel\NCS\Sync\NetSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Looks like each step brings progress and repair. I should mention changes have been made to some critical system components - I am sure you can tell from the reports here. We, and these great tools created by others, are correcting change when found, but the final outcome will have to assess with regular use. SDFix not only made some of those needed corrections but appears to have removed what may have been the operational backdoor component there.



Open and update AVG AntiSpyware.

====================================

Reboot into Safe Mode, and Run AVG Anti-Spyware now. First click on Settings > Recommended Action and change it to Quarantine. Next look at Reports and uncheck "Only if threats were found". Don't change any other settings.

Click on the "Scan" tab and click on "Complete System Scan" to begin scanning. When the scan is finished, look at "Set all elements to" and click to change to "Quarantine" if this option is not displayed. Click on "Apply All Actions" and then click the "Save Report" button at the bottom of the screen. Click on "Save Report As" and save the report to your desktop. Then close AVG Anti-Spyware.


While still in Safe Mode run SDFix again as you just did.

================================

After SDFix brings about the reboot let's check recent file activity.


Go to Start - Run, type notepad (and Enter). In the open text box copy/paste all the text hilighted below:

cd C:\Windows\System32
dir /O:D > c:\show2.txt & start notepad c:\show2.txt

Then go to File - Save as…, and save the file to your desktop as "Look32.bat" (be sure to include the quotes "" in the name). Then click on look32.bat to run the file check. Once that completes a text box will open - copy/paste those contents back here please. As this could create quite a list only copy back the lower portion relating to file dates from 2007.


Then post those results back along with the AVG Report and the SDFix report.txt please.



Also best to follow AVG with an additional scan for this type infection, so again please temporarily disable AVG antivirus and and go here and run an online scan with BitDefender, and save/post those results as well.
proceeded as advised:
1. updated avg anti spyware, rebooted to safemode and ran. (log below)
2. still in safemode ran SDFix (used the copy already on the system, hope this was correct) (log below)
3. created and ran "Look32.bat" (log below)
4. ran bitdefender scan with avg disactivated (log below)

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 17:37:48 04.07.2007

+ Scan result:



C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\IESkins -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\HostOI -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\HostOI\dynamic -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\HostOI\static -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\HostOI\static\1 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\HostOI\static\DownLoad -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\HostOL -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\HostOL\dynamic -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\HostOL\static -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\Hotbar -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\Hotbar\dynamic -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\Hotbar\static -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\Hotbar\static\1 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\Hotbar\static\2 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Dokumente und Einstellungen\mat\Anwendungsdaten\Hotbar\v3.0\Hotbar\static\DownLoad -> Adware.HotBar : Cleaned with backup (quarantined).
:mozilla.13:C:\Dokumente und Einstellungen\anto\Anwendungsdaten\Mozilla\Firefox\Profiles\1snzpxix.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.17:C:\Dokumente und Einstellungen\anto\Anwendungsdaten\Mozilla\Firefox\Profiles\1snzpxix.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.


::Report end

==============================================================


SDFix: Version 1.89

Run by [removed] on 04.07.2007 at 17:41

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:






Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

No Trojan Files Found




Removing Temp Files…

ADS Check:

Checking C:\WINDOWS
C:\WINDOWS
No streams found.

Checking C:\WINDOWS\system32
C:\WINDOWS\system32
No streams found.

Checking C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.

Checking C:\WINDOWS\system32\ntoskrnl.exe
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files:
—————


Files with Hidden Attributes:

C:\Dokumente und Einstellungen\All Users\DRM\Cache\Indiv01.tmp
C:\Dokumente und Einstellungen\mat\Desktop\tesi pi\Abschnitt III\~WRL3505.tmp
C:\Dokumente und Einstellungen\mat\Desktop\tesi pi\ENDFASSUNG Kapitel\~WRL2940.tmp
C:\Dokumente und Einstellungen\mat\Desktop\tesi pi\FERTIGE Kapitel\~WRL3190.tmp
C:\Dokumente und Einstellungen\mat\Desktop\tesi pi\FERTIGE Kapitel\~WRL3835.tmp
C:\WINDOWS\system32\config\default.tmp.LOG
C:\WINDOWS\system32\config\SAM.tmp.LOG
C:\WINDOWS\system32\config\SECURITY.tmp.LOG
C:\WINDOWS\system32\config\software.tmp.LOG
C:\WINDOWS\system32\config\system.tmp.LOG

Finished

======================================================

23.01.2007 21:30 546.304 hhctrl.ocx
29.01.2007 10:58 60.416 tzchange.exe
05.02.2007 22:18 185.856 upnphost.dll
28.02.2007 18:02 2.059.904 ntkrnlpa.exe
28.02.2007 18:02 2.182.656 ntoskrnl.exe
08.03.2007 16:41 ReinstallBackups
08.03.2007 16:42 1031
08.03.2007 16:44 usmt
08.03.2007 16:45 npp
08.03.2007 16:50 oobe
08.03.2007 16:51 Setup
08.03.2007 16:59 CatRoot
08.03.2007 17:03 247 spupdwxp.log
08.03.2007 17:03 wbem
08.03.2007 17:05 inetsrv
08.03.2007 17:32 1.843.712 win32k.sys
08.03.2007 17:36 40.960 mf3216.dll
08.03.2007 17:36 281.600 gdi32.dll
08.03.2007 17:36 579.072 user32.dll
09.03.2007 00:01 796.312 libeay32_0.9.6l.dll
09.03.2007 00:01 157.424 vsinit.dll
09.03.2007 00:01 83.696 vsdata.dll
09.03.2007 00:01 104.176 vsmonapi.dll
09.03.2007 00:01 71.408 vsregexp.dll
09.03.2007 00:01 276.208 vspubapi.dll
09.03.2007 00:01 472.816 vsutil.dll
09.03.2007 00:01 46.832 vswmi.dll
09.03.2007 00:01 83.696 zlcomm.dll
09.03.2007 00:01 100.080 vsxml.dll
09.03.2007 00:01 71.408 zlcommdb.dll
09.03.2007 00:01 1.087.216 zpeng24.dll
09.03.2007 00:02 394.192 vsdatant.sys
11.03.2007 18:48 PreInstall
15.03.2007 00:45 Com
15.03.2007 00:47 122.142 TZLog.log
17.03.2007 15:44 293.376 winsrv.dll
02.04.2007 14:21 428.032 swreg.exe
16.04.2007 17:53 1.058.304 kernel32.dll
16.04.2007 22:44 34.136 wucltui.dll.mui
16.04.2007 22:45 43.352 wups2.dll
16.04.2007 22:45 20.824 wuaueng.dll.mui
16.04.2007 22:45 53.080 wuauclt.exe
16.04.2007 22:45 92.504 cdm.dll
16.04.2007 22:45 203.096 wuweb.dll
16.04.2007 22:45 216.408 wuaucpl.cpl
16.04.2007 22:45 325.976 wucltui.dll
16.04.2007 22:45 549.720 wuapi.dll
16.04.2007 22:45 1.710.936 wuaueng.dll
16.04.2007 22:47 30.040 wuaucpl.cpl.mui
16.04.2007 22:47 30.040 wuapi.dll.mui
16.04.2007 22:47 33.624 wups.dll
18.04.2007 12:27 123.392 xpsp3res.dll
18.04.2007 14:31 1.023.488 browseui.dll
18.04.2007 14:31 357.888 dxtmsft.dll
18.04.2007 14:31 205.312 dxtrans.dll
18.04.2007 14:31 55.808 extmgr.dll
18.04.2007 14:31 251.392 iepeers.dll
18.04.2007 14:31 1.056.256 danim.dll
18.04.2007 14:31 152.064 cdfview.dll
18.04.2007 14:31 96.768 inseng.dll
18.04.2007 14:31 16.384 jsproxy.dll
18.04.2007 14:31 146.432 msrating.dll
18.04.2007 14:31 449.024 mshtmled.dll
18.04.2007 14:31 532.480 mstime.dll
18.04.2007 14:31 39.424 pngfilt.dll
18.04.2007 14:31 474.624 shlwapi.dll
18.04.2007 14:31 1.494.528 shdocvw.dll
18.04.2007 14:31 617.472 urlmon.dll
18.04.2007 14:31 664.576 wininet.dll
18.04.2007 18:13 2.854.400 msi.dll
25.04.2007 16:22 144.896 schannel.dll
04.05.2007 14:27 3.079.680 mshtml.dll
06.05.2007 20:36 LogFiles
08.05.2007 22:04 23.392 nscompat.tlb
08.05.2007 22:04 16.832 amcompat.tlb
16.05.2007 17:11 683.520 inetcomm.dll
06.06.2007 08:38 15.747.032 MRT.exe
11.06.2007 12:21 432.264 FNTCACHE.DAT
11.06.2007 15:18 Restore
13.06.2007 11:40 5.632 A7F4841F.exe
13.06.2007 11:42 5.632 C22EE0C9.exe
25.06.2007 13:36 723.744 PerfStringBackup.INI
25.06.2007 13:36 316.888 perfh007.dat
25.06.2007 13:36 48.486 perfc007.dat
25.06.2007 13:36 311.938 perfh009.dat
25.06.2007 13:36 40.326 perfc009.dat
25.06.2007 22:59 ZoneLabs
27.06.2007 09:59 Kaspersky Lab
29.06.2007 15:52 1.828 kwdlknvg.txt
29.06.2007 21:43 2.206 wpa.dbl
30.06.2007 17:16 config
03.07.2007 09:54 drivers
03.07.2007 22:51 CatRoot2
04.07.2007 09:19 .
04.07.2007 09:19 ..
04.07.2007 17:46 49.617 vsconfig.xml
2116 Datei(en) 408.497.743 Bytes
51 Verzeichnis(se), 23.525.797.888 Bytes frei

=================================================

BitDefender Online Scanner







Scan report generated at: Wed, Jul 04, 2007 - 18:30:24









Scan path: C:\;E:\;















Statistics

Time


00:32:42

Files


147052

Folders


4168

Boot Sectors


2

Archives


4130

Packed Files


7705







Results

Identified Viruses


0

Infected Files


0

Suspect Files


0

Warnings


0

Disinfected


0

Deleted Files


0







Engines Info

Virus Definitions


636772

Engine build


AVCORE v1.0 (build 2410) (i386) (Jun 12 2007 21:08:27)

Scan plugins


14

Archive plugins


38

Unpack plugins


6

E-mail plugins


6

System plugins


1







Scan Settings

First Action


Disinfect

Second Action


Delete

Heuristics


Yes

Enable Warnings


Yes

Scanned Extensions


*;

Exclude Extensions




Scan Emails


Yes

Scan Archives


Yes

Scan Packed


Yes

Scan Files


Yes

Scan Boot


Yes








Scanned File


Status

No virus found.
Looks excellent from this angle. We'll need to check the background an additional time, but active file issues appear resolved. You can delete the following from your System32 folder - later scans I did have indicated they were a Trojan.Generic variant, and that random name text file is either a tool of ours or an unwanted past use.

kwdlknvg.txt
A7F4841F.exe
C22EE0C9.exe


Then let's do that check. Go to Start - Run, type gmer.exe (and Enter). When GMER opens click the Processes tab. To the right click the "Safe…" button, and agree to start GMER in Safe Mode. Your system will reboot. On reboot "OK" the prompt to run GMER Safe Mode. When GMER opens run a scan as you have done already, saving that new log to post back here. Once you have completed that click the Processes tab, and click Restart to reboot the computer. Then post the GMER log please.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI