This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Winantispyware2007 Plus Others

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My wife browser has been hijacked. I think she actually installed the WinAntiSpyware2007 control, but even she doesn't know. She gets lots of browser popups. AdAware and Spybot find and eliminated alot of stuff (like a bogus browser toolbar) but the computer is still infected. McAffee virus scanner is detecting viruses after popups, too. I just upgraded her from WinXP SP1 to SP2 yesterday, but I think the infection was already there.

Here is the HijackThis log.


Logfile of HijackThis v1.99.1
Scan saved at 7:18:05 PM, on 7/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\qwerty12.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {077dbb9f-47e3-42fb-928f-ecc9cefcfacd} - C:\WINDOWS\system32\c_8ina.dll
O2 - BHO: metaspinner media GmbH - {12FC9A49-CFE0-49AA-BE9E-8F4EEAFC9443} - C:\DOCUME~1\Stef\Desktop\TVgenial\IEBUTT~2.DLL (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {62b754ac-2663-469c-bad2-049f780807b5} - C:\WINDOWS\system32\c_8ina.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {8C5D82E9-9D36-4158-B074-20A87B4928E4} - C:\WINDOWS\system32\reginix86d.dll
O2 - BHO: (no name) - {938A8A03-A938-4019-B764-03FF8D167D79} - C:\WINDOWS\system32\tmp1DD.tmp.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [startdrv] C:\WINDOWS\Temp\startdrv.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [TVgenial] I:\TVgenial\TVgenial.exe -d
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\c_8ina.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\c_8ina.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200310…llInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1184251936156
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{33A4D45F-A217-4B9D-90E4-AC4E3F929BC4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{7231104E-913A-4FDF-BADB-E93347DD32E4}: NameServer = 85.255.113.107,85.255.112.121
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: c_8ina - C:\WINDOWS\SYSTEM32\c_8ina.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\System32\qwerty12.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Hello Brian_R170 and welcome to the TomCoyote Forums

My name is Trevuren and I will be helping you with your problem.


A. Please download FixWareout from one of these sites:
http://download.bleepingcomputer.com/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.
Please post the text that will open (report.txt).


B.
Please download this file - combofix.exe by sUBs
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren
Trevuren, Thanks for the quick reply. Here are the logs you asked for.

When this is fixed… Can somebody tell me how I figure out the common names of the malware I had, and point me to a site where I can look them up to find out exactly what they were doing to the computer? I know there was the Was7, but also I saw qwerty12 and c_8ina.

Thanks again!

—————————–Here is the report from FixWareout.exe——————————————————-

Username "Stef" - 2007-07-12 22:09:36 [Fixwareout edited 2007/07/05]

»»»»»Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdhbg.exe"

HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{7231104E-913A-4FDF-BADB-E93347DD32E4}
"nameserver"="85.255.113.107,85.255.112.121" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{33A4D45F-A217-4B9D-90E4-AC4E3F929BC4}
"DhcpNameServer"="[removed],[removed]" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{86C80511-CA71-4982-93D3-0F55F697008C}
"DhcpNameServer"="[removed],[removed]"
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
….
….
»»»»» Misc files.
….
»»»»» Checking for older varients.
….
»»»»» Other
C:\WINDOWS\Temp\kdhbg.ren 65117 09/03/2002

»»»»» Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"ShStatEXE"="\"C:\\Program Files\\Network Associates\\VirusScan\\SHSTAT.EXE\" /STANDALONE"
"McAfeeUpdaterUI"="\"C:\\Program Files\\Network Associates\\Common Framework\\UpdaterUI.exe\" /StartedFromRunKey"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvMcTray.dll,NvTaskbarInit"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Salestart"="\"C:\\Program Files\\Common Files\\WinAntiSpyware 2007\\WAS7Mon.exe\""
"startdrv"="C:\\WINDOWS\\Temp\\startdrv.exe"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"TVgenial"="I:\\TVgenial\\TVgenial.exe -d"
….
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»

—————————–Here is the report from Combofix.exe——————————————————-

"Stef" - 2007-07-12 22:15:15 - ComboFix 07-07-13.9 - Service Pack 2 NTFS


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\c_8ina.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\DOCUME~1\Stef\APPLIC~1\tmp107.tmp.exe
C:\DOCUME~1\Stef\APPLIC~1\tmp108.tmp.exe
C:\DOCUME~1\Stef\APPLIC~1\tmp1B.tmp.exe
C:\DOCUME~1\Stef\APPLIC~1\tmp1C.tmp.exe
C:\DOCUME~1\Stef\APPLIC~1\tmp1DD.tmp.exe
C:\DOCUME~1\Stef\APPLIC~1\tmp24.tmp.exe
C:\DOCUME~1\Stef\APPLIC~1\tmp27.tmp.exe
C:\DOCUME~1\Stef\APPLIC~1\tmp28.tmp.exe
C:\DOCUME~1\Stef\APPLIC~1\tmp64.tmp.exe
C:\DOCUME~1\Stef\APPLIC~1\tmp65.tmp.exe
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\WINDOWS\DOWNLO~1\UWA7P_0001_N91M0809NetInstaller.exe
C:\WINDOWS\retadpu2000219.exe
C:\WINDOWS\system32\4_exception.nls
C:\WINDOWS\system32\drivers\ApiMon.sys
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\drivers\runtime2.sys
C:\WINDOWS\system32\drivers\secdrv.sys
C:\WINDOWS\system32\explorer.exe
C:\WINDOWS\system32\monterreyo_ingen.exe
C:\WINDOWS\system32\qwerty12.exe
C:\WINDOWS\system32\reginid_ingen.exe
C:\WINDOWS\system32\reginix86d.dll
C:\WINDOWS\system32\reginix86d.exe
C:\WINDOWS\system32\stera.exe
C:\WINDOWS\system32\tmp1DD.tmp.dll
C:\WINDOWS\system32\tmp28.tmp.dll
C:\WINDOWS\system32\tmp65.tmp.dll
C:\WINDOWS\system32\winnb58.dll


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_DOMAINSERVICE
——-\LEGACY_RUNTIME
——-\LEGACY_RUNTIME2
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-06-13 to 2007-07-13 )))))))))))))))))))))))))))))))


2007-07-12 22:14 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-12 22:09 6,277 –a—— C:\dnsbak.reg
2007-07-12 19:14 d——– C:\HijackThis
2007-07-12 18:57 d——– C:\Program Files\MSXML 4.0
2007-07-12 15:49 d——– C:\WINDOWS\Prefetch
2007-07-12 09:28 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-07-12 09:27 d——– C:\WINDOWS\provisioning
2007-07-12 09:27 d——– C:\WINDOWS\peernet
2007-07-12 09:23 d——– C:\WINDOWS\ServicePackFiles
2007-07-12 09:14 d——– C:\WINDOWS\EHome
2007-07-12 08:05 4,569 ——— C:\WINDOWS\system32\secupd.dat
2007-07-12 08:05 11,776 ——— C:\WINDOWS\system32\spnpinst.exe
2007-07-11 22:37 1,082,368 –a—— C:\WINDOWS\system32\esent.dll
2007-07-11 22:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-11 19:22 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-11 14:50 1,745 –a—— C:\WINDOWS\mlmhyw.exe
2007-07-11 14:45 d——– C:\WINDOWS\system32\b02FdUe
2007-06-26 11:01 d——– C:\Program Files\iTunes
2007-06-26 11:01 d——– C:\Program Files\iPod


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-12 16:27:12 ——– d—–w C:\Program Files\Movie Maker
2007-07-12 16:22:57 ——– d—–w C:\Program Files\Windows NT
2007-06-13 20:18:59 ——– d–h–w C:\DOCUME~1\Stef\APPLIC~1\Move Networks
2007-06-13 10:10:20 ——– d—–w C:\Program Files\HP
2007-06-13 10:10:07 ——– d—–w C:\Program Files\Hewlett-Packard
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-15 19:03:09 ——– d—–w C:\Program Files\QuickTime
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-17 05:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 05:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 05:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 05:43:44 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2006-04-25 23:26:23 9,854 —-a-w C:\Program Files\vd20138832b.dat
2006-04-25 23:26:23 9,691 —-a-w C:\Program Files\vd05338832b.dat
2006-04-25 23:26:23 9,659 —-a-w C:\Program Files\vd05338833b.dat
2006-04-25 23:26:23 75,047 —-a-w C:\Program Files\vd12238833c.dat
2006-04-25 23:26:23 7,405 —-a-w C:\Program Files\vd08638832b.dat
2006-04-25 23:26:23 7,234 —-a-w C:\Program Files\vd08638833b.dat
2006-04-25 23:26:23 7,205 —-a-w C:\Program Files\vd03438832b.dat
2006-04-25 23:26:23 7,159 —-a-w C:\Program Files\vd04238833c.dat
2006-04-25 23:26:23 6,631 —-a-w C:\Program Files\vd21738833c.dat
2006-04-25 23:26:23 56,661 —-a-w C:\Program Files\vd12238832d.dat
2006-04-25 23:26:23 5,608 —-a-w C:\Program Files\vd21738832e.dat
2006-04-25 23:26:23 5,511 —-a-w C:\Program Files\vd02238832b.dat
2006-04-25 23:26:23 5,399 —-a-w C:\Program Files\vd02238833b.dat
2006-04-25 23:26:23 4,389 —-a-w C:\Program Files\vd05238833b.dat
2006-04-25 23:26:23 4,389 —-a-w C:\Program Files\vd05238832b.dat
2006-04-25 23:26:23 38,599 —-a-w C:\Program Files\vd03338833c.dat
2006-04-25 23:26:23 38,448 —-a-w C:\Program Files\vd03538833c.dat
2006-04-25 23:26:23 36,367 —-a-w C:\Program Files\vd03638832b.dat
2006-04-25 23:26:23 34,915 —-a-w C:\Program Files\vd03638833b.dat
2006-04-25 23:26:23 32,607 —-a-w C:\Program Files\vd01138833d.dat
2006-04-25 23:26:23 30,672 —-a-w C:\Program Files\vd00138833b.dat
2006-04-25 23:26:23 30,602 —-a-w C:\Program Files\vd20238832b.dat
2006-04-25 23:26:23 30,094 —-a-w C:\Program Files\vd01138832c.dat
2006-04-25 23:26:23 29,377 —-a-w C:\Program Files\vd03538832b.dat
2006-04-25 23:26:23 27,703 —-a-w C:\Program Files\vd20238833c.dat
2006-04-25 23:26:23 25,815 —-a-w C:\Program Files\vd00838832b.dat
2006-04-25 23:26:23 25,313 —-a-w C:\Program Files\vd13438832c.dat
2006-04-25 23:26:23 22,169 —-a-w C:\Program Files\vd24438833b.dat
2006-04-25 23:26:23 22,030 —-a-w C:\Program Files\vd00838833b.dat
2006-04-25 23:26:23 21,530 —-a-w C:\Program Files\vd00438832c.dat
2006-04-25 23:26:23 20,796 —-a-w C:\Program Files\vd00238832b.dat
2006-04-25 23:26:23 20,787 —-a-w C:\Program Files\vd00338832b.dat
2006-04-25 23:26:23 20,527 —-a-w C:\Program Files\vd03438833c.dat
2006-04-25 23:26:23 19,742 —-a-w C:\Program Files\vd00138832b.dat
2006-04-25 23:26:23 18,816 —-a-w C:\Program Files\vd13438833b.dat
2006-04-25 23:26:23 18,319 —-a-w C:\Program Files\vd00638832b.dat
2006-04-25 23:26:23 17,931 —-a-w C:\Program Files\vd24438832b.dat
2006-04-25 23:26:23 17,164 —-a-w C:\Program Files\vd00338833b.dat
2006-04-25 23:26:23 16,701 —-a-w C:\Program Files\vd20138833c.dat
2006-04-25 23:26:23 16,428 —-a-w C:\Program Files\vd00638833b.dat
2006-04-25 23:26:23 15,588 —-a-w C:\Program Files\vd00438833d.dat
2006-04-25 23:26:23 15,330 —-a-w C:\Program Files\vd05438833b.dat
2006-04-25 23:26:23 14,641 —-a-w C:\Program Files\vd00238833c.dat
2006-04-25 23:26:23 14,547 —-a-w C:\Program Files\vd08438832d.dat
2006-04-25 23:26:23 14,310 —-a-w C:\Program Files\vd08438833b.dat
2006-04-25 23:26:23 14,168 —-a-w C:\Program Files\vd00538832e.dat
2006-04-25 23:26:23 13,503 —-a-w C:\Program Files\vd05438832b.dat
2006-04-25 23:26:23 12,374 —-a-w C:\Program Files\vd00538833c.dat
2006-04-25 23:26:23 12,190 —-a-w C:\Program Files\vd07238833b.dat
2006-04-25 23:26:23 12,078 —-a-w C:\Program Files\vd07238832b.dat
2006-04-25 23:26:23 11,631 —-a-w C:\Program Files\vd03338832b.dat
2006-04-25 23:26:23 11,533 —-a-w C:\Program Files\vd04238832c.dat
2006-04-25 23:26:23 1,962 —-a-w C:\Program Files\vd04438833b.dat
2006-04-25 23:26:23 1,882 —-a-w C:\Program Files\vd04438832b.dat
2006-04-25 23:26:05 11,038 —-a-w C:\Program Files\vd20138839b.dat
2006-04-25 23:26:04 24,271 —-a-w C:\Program Files\vd00838839b.dat
2006-04-25 23:26:04 21,227 —-a-w C:\Program Files\vd01138839b.dat
2006-04-25 23:26:03 3,571 —-a-w C:\Program Files\vd05438839b.dat
2006-04-25 23:26:03 22,193 —-a-w C:\Program Files\vd20238839b.dat
2006-04-25 23:26:03 1,559 —-a-w C:\Program Files\vd05238839b.dat
2006-04-25 23:26:02 2,499 —-a-w C:\Program Files\vd05338839b.dat
2006-04-25 23:26:02 16,556 —-a-w C:\Program Files\vd00538839d.dat
2006-04-25 23:26:02 12,653 —-a-w C:\Program Files\vd00238839b.dat
2006-04-25 23:26:01 8,128 —-a-w C:\Program Files\vd08438839c.dat
2006-04-25 23:26:01 37,553 —-a-w C:\Program Files\vd12238839c.dat
2006-04-25 23:26:01 23,457 —-a-w C:\Program Files\vd00438839b.dat
2006-04-25 23:26:00 2,791 —-a-w C:\Program Files\vd13438839b.dat
2006-04-25 23:26:00 13,766 —-a-w C:\Program Files\vd00338839b.dat
2006-04-25 23:26:00 13,043 —-a-w C:\Program Files\vd00638839b.dat
2006-04-25 23:25:59 6,624 —-a-w C:\Program Files\vd07238839f.dat
2006-04-25 23:25:59 12,971 —-a-w C:\Program Files\vd00138839b.dat
2006-04-25 23:25:59 10,392 —-a-w C:\Program Files\vd03338839b.dat
2006-04-25 23:25:59 1,244 —-a-w C:\Program Files\vd04238839c.dat
2006-04-25 23:25:58 4,488 —-a-w C:\Program Files\vd03438839b.dat
2006-04-25 23:25:58 20,420 —-a-w C:\Program Files\vd03638839b.dat
2006-04-25 23:25:57 895 —-a-w C:\Program Files\vd04438839b.dat
2006-04-25 23:25:57 8,447 —-a-w C:\Program Files\vd24438839c.dat
2006-04-25 23:25:57 7,568 —-a-w C:\Program Files\vd21738839c.dat
2006-04-25 23:25:57 11,867 —-a-w C:\Program Files\vd03538839b.dat
2006-04-25 23:25:56 5,726 —-a-w C:\Program Files\vd02238839b.dat
2006-04-25 23:25:56 29,748 —-a-w C:\Program Files\vd00538838b.dat
2006-04-25 23:25:56 22,120 —-a-w C:\Program Files\vd00638838b.dat
2006-04-25 23:25:55 19,556 —-a-w C:\Program Files\vd03538838b.dat


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-05-15 00:47 50376 –a—— C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{12FC9A49-CFE0-49AA-BE9E-8F4EEAFC9443}]
C:\DOCUME~1\Stef\Desktop\TVgenial\IEBUTT~2.DLL

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 –a—— C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8C5D82E9-9D36-4158-B074-20A87B4928E4}]
C:\WINDOWS\system32\reginix86d.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2005-06-15 17:20 C:\WINDOWS\system32\nwiz.exe]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2003-09-29 07:10]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2003-09-10 03:11]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-07-15 16:05]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-01 16:51]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"TVgenial"="I:\TVgenial\TVgenial.exe" []


Contents of the 'Scheduled Tasks' folder
2007-06-26 17:46:02 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-12 22:23:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-12 22:23:50 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-12 22:23

— E O F —

—————————————–Here is the fresh report from HijackThis.exe——————————————-

Logfile of HijackThis v1.99.1
Scan saved at 10:27:37 PM, on 7/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: metaspinner media GmbH - {12FC9A49-CFE0-49AA-BE9E-8F4EEAFC9443} - C:\DOCUME~1\Stef\Desktop\TVgenial\IEBUTT~2.DLL (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {8C5D82E9-9D36-4158-B074-20A87B4928E4} - C:\WINDOWS\system32\reginix86d.dll (file missing)
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [TVgenial] I:\TVgenial\TVgenial.exe -d
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200310…llInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1184251936156
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{33A4D45F-A217-4B9D-90E4-AC4E3F929BC4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

——————————————————————————————————————————–
A. There is a file in your log of which I am unsure. For that reason, I need you to submit it to Jotti's for analysis.

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\Program Files\vd02238833b.dat

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis in your next reply.


B. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: metaspinner media GmbH - {12FC9A49-CFE0-49AA-BE9E-8F4EEAFC9443} - C:\DOCUME~1\Stef\Desktop\TVgenial\IEBUTT~2.DLL (file missing)
    O2 - BHO: (no name) - {8C5D82E9-9D36-4158-B074-20A87B4928E4} - C:\WINDOWS\system32\reginix86d.dll (file missing)
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

C. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\mlmhyw.exe
C:\WINDOWS\system32\b02FdUe

Folder::
C:\Program Files\Messenger


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (if the tool does not ask to rebooot, please restart manually)


D. Please do an online scan with Kaspersky Online Virus Scanner (Use Internet Explorer as your Browser)

Note: If you have used this particular scanner before, you MAY HAVE YO UNINSTALL the program through Add/Remove Programs before downloading the new ActiveX component

Next Click on Free Virus Scanner, then Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Standard
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.


E. Logs/Reports to Post
  • Jotti's Report
  • Combofix.txt
  • A new HijackThis log
  • Kaspersky scan Report.

To answer your questions, you use Google and play detective. A lot of malware have random names and there will be no hits on Google. For others you will be able to find a history on Google and you follow the crumbs to an AntiVirus Company's Web site where you will generally get a description of what is done to your system. Their fixes are all manual while we work with coders who provide us with the tools that eradicate the infection and make the necessary changes to the system to reverse the damage done (all in the background).

Regards

Trevuren
Hi Trevuren,

Sorry I didn't have time to get this done before work this morning and the Kaspersky scan took a couple hours to complete once it finally downloaded, but I finally got it all done.

Here's Jotti's report. Note that there were over 200 similarly-named files in c:\program files where the file you had me scan was located.
——————————————————–
Service load: 0% 100%

File: vd02238833b.dat
Status: OK
MD5: c8ecad5e37689b95212d2b4ac32e1b76
Packers detected: -
Bit9 reports: File not found

Scanner results
Scan taken on 14 Jul 2007 01:25:01 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing

———— Here is the new Combofix log ———————-

"Stef" - 2007-07-13 18:36:25 - ComboFix 07-07-13.9 - Service Pack 2 NTFS
Command switches used :: C:\HijackThis\CFScript.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Messenger
C:\Program Files\Messenger\2kmsgr5.chm
C:\Program Files\Messenger\custsat.dll
C:\Program Files\Messenger\logo.gif
C:\Program Files\Messenger\lvback.gif
C:\Program Files\Messenger\msgsc.dll
C:\Program Files\Messenger\msgslang.dll
C:\Program Files\Messenger\msimmsgr.dll
C:\Program Files\Messenger\msimnetc.dll
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Messenger\msvcp70.dll
C:\Program Files\Messenger\newalert.wav
C:\Program Files\Messenger\newemail.wav
C:\Program Files\Messenger\online.wav
C:\Program Files\Messenger\rtcimsp.dll
C:\Program Files\Messenger\type.wav
C:\Program Files\Messenger\xpmsgr.chm
C:\WINDOWS\mlmhyw.exe


((((((((((((((((((((((((( Files Created from 2007-06-14 to 2007-07-14 )))))))))))))))))))))))))))))))


2007-07-12 22:31 d——– C:\WINDOWS\system32\LogFiles
2007-07-12 22:14 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-12 22:09 6,277 –a—— C:\dnsbak.reg
2007-07-12 19:14 d——– C:\HijackThis
2007-07-12 18:57 d——– C:\Program Files\MSXML 4.0
2007-07-12 15:49 d——– C:\WINDOWS\Prefetch
2007-07-12 09:28 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-07-12 09:27 d——– C:\WINDOWS\provisioning
2007-07-12 09:27 d——– C:\WINDOWS\peernet
2007-07-12 09:23 d——– C:\WINDOWS\ServicePackFiles
2007-07-12 09:14 d——– C:\WINDOWS\EHome
2007-07-12 08:05 4,569 ——— C:\WINDOWS\system32\secupd.dat
2007-07-12 08:05 11,776 ——— C:\WINDOWS\system32\spnpinst.exe
2007-07-11 22:37 1,082,368 –a—— C:\WINDOWS\system32\esent.dll
2007-07-11 22:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-11 19:22 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-11 14:45 d——– C:\WINDOWS\system32\b02FdUe
2007-06-26 11:01 d——– C:\Program Files\iTunes
2007-06-26 11:01 d——– C:\Program Files\iPod


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-12 16:27:12 ——– d—–w C:\Program Files\Movie Maker
2007-07-12 16:22:57 ——– d—–w C:\Program Files\Windows NT
2007-06-13 20:18:59 ——– d–h–w C:\DOCUME~1\Stef\APPLIC~1\Move Networks
2007-06-13 10:10:20 ——– d—–w C:\Program Files\HP
2007-06-13 10:10:07 ——– d—–w C:\Program Files\Hewlett-Packard
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-15 19:03:09 ——– d—–w C:\Program Files\QuickTime
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-17 05:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 05:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 05:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 05:43:44 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2006-04-25 23:26:23 9,854 —-a-w C:\Program Files\vd20138832b.dat
2006-04-25 23:26:23 9,691 —-a-w C:\Program Files\vd05338832b.dat
2006-04-25 23:26:23 9,659 —-a-w C:\Program Files\vd05338833b.dat
2006-04-25 23:26:23 75,047 —-a-w C:\Program Files\vd12238833c.dat
2006-04-25 23:26:23 7,405 —-a-w C:\Program Files\vd08638832b.dat
2006-04-25 23:26:23 7,234 —-a-w C:\Program Files\vd08638833b.dat
2006-04-25 23:26:23 7,205 —-a-w C:\Program Files\vd03438832b.dat
2006-04-25 23:26:23 7,159 —-a-w C:\Program Files\vd04238833c.dat
2006-04-25 23:26:23 6,631 —-a-w C:\Program Files\vd21738833c.dat
2006-04-25 23:26:23 56,661 —-a-w C:\Program Files\vd12238832d.dat
2006-04-25 23:26:23 5,608 —-a-w C:\Program Files\vd21738832e.dat
2006-04-25 23:26:23 5,511 —-a-w C:\Program Files\vd02238832b.dat
2006-04-25 23:26:23 5,399 —-a-w C:\Program Files\vd02238833b.dat
2006-04-25 23:26:23 4,389 —-a-w C:\Program Files\vd05238833b.dat
2006-04-25 23:26:23 4,389 —-a-w C:\Program Files\vd05238832b.dat
2006-04-25 23:26:23 38,599 —-a-w C:\Program Files\vd03338833c.dat
2006-04-25 23:26:23 38,448 —-a-w C:\Program Files\vd03538833c.dat
2006-04-25 23:26:23 36,367 —-a-w C:\Program Files\vd03638832b.dat
2006-04-25 23:26:23 34,915 —-a-w C:\Program Files\vd03638833b.dat
2006-04-25 23:26:23 32,607 —-a-w C:\Program Files\vd01138833d.dat
2006-04-25 23:26:23 30,672 —-a-w C:\Program Files\vd00138833b.dat
2006-04-25 23:26:23 30,602 —-a-w C:\Program Files\vd20238832b.dat
2006-04-25 23:26:23 30,094 —-a-w C:\Program Files\vd01138832c.dat
2006-04-25 23:26:23 29,377 —-a-w C:\Program Files\vd03538832b.dat
2006-04-25 23:26:23 27,703 —-a-w C:\Program Files\vd20238833c.dat
2006-04-25 23:26:23 25,815 —-a-w C:\Program Files\vd00838832b.dat
2006-04-25 23:26:23 25,313 —-a-w C:\Program Files\vd13438832c.dat
2006-04-25 23:26:23 22,169 —-a-w C:\Program Files\vd24438833b.dat
2006-04-25 23:26:23 22,030 —-a-w C:\Program Files\vd00838833b.dat
2006-04-25 23:26:23 21,530 —-a-w C:\Program Files\vd00438832c.dat
2006-04-25 23:26:23 20,796 —-a-w C:\Program Files\vd00238832b.dat
2006-04-25 23:26:23 20,787 —-a-w C:\Program Files\vd00338832b.dat
2006-04-25 23:26:23 20,527 —-a-w C:\Program Files\vd03438833c.dat
2006-04-25 23:26:23 19,742 —-a-w C:\Program Files\vd00138832b.dat
2006-04-25 23:26:23 18,816 —-a-w C:\Program Files\vd13438833b.dat
2006-04-25 23:26:23 18,319 —-a-w C:\Program Files\vd00638832b.dat
2006-04-25 23:26:23 17,931 —-a-w C:\Program Files\vd24438832b.dat
2006-04-25 23:26:23 17,164 —-a-w C:\Program Files\vd00338833b.dat
2006-04-25 23:26:23 16,701 —-a-w C:\Program Files\vd20138833c.dat
2006-04-25 23:26:23 16,428 —-a-w C:\Program Files\vd00638833b.dat
2006-04-25 23:26:23 15,588 —-a-w C:\Program Files\vd00438833d.dat
2006-04-25 23:26:23 15,330 —-a-w C:\Program Files\vd05438833b.dat
2006-04-25 23:26:23 14,641 —-a-w C:\Program Files\vd00238833c.dat
2006-04-25 23:26:23 14,547 —-a-w C:\Program Files\vd08438832d.dat
2006-04-25 23:26:23 14,310 —-a-w C:\Program Files\vd08438833b.dat
2006-04-25 23:26:23 14,168 —-a-w C:\Program Files\vd00538832e.dat
2006-04-25 23:26:23 13,503 —-a-w C:\Program Files\vd05438832b.dat
2006-04-25 23:26:23 12,374 —-a-w C:\Program Files\vd00538833c.dat
2006-04-25 23:26:23 12,190 —-a-w C:\Program Files\vd07238833b.dat
2006-04-25 23:26:23 12,078 —-a-w C:\Program Files\vd07238832b.dat
2006-04-25 23:26:23 11,631 —-a-w C:\Program Files\vd03338832b.dat
2006-04-25 23:26:23 11,533 —-a-w C:\Program Files\vd04238832c.dat
2006-04-25 23:26:23 1,962 —-a-w C:\Program Files\vd04438833b.dat
2006-04-25 23:26:23 1,882 —-a-w C:\Program Files\vd04438832b.dat
2006-04-25 23:26:05 11,038 —-a-w C:\Program Files\vd20138839b.dat
2006-04-25 23:26:04 24,271 —-a-w C:\Program Files\vd00838839b.dat
2006-04-25 23:26:04 21,227 —-a-w C:\Program Files\vd01138839b.dat
2006-04-25 23:26:03 3,571 —-a-w C:\Program Files\vd05438839b.dat
2006-04-25 23:26:03 22,193 —-a-w C:\Program Files\vd20238839b.dat
2006-04-25 23:26:03 1,559 —-a-w C:\Program Files\vd05238839b.dat
2006-04-25 23:26:02 2,499 —-a-w C:\Program Files\vd05338839b.dat
2006-04-25 23:26:02 16,556 —-a-w C:\Program Files\vd00538839d.dat
2006-04-25 23:26:02 12,653 —-a-w C:\Program Files\vd00238839b.dat
2006-04-25 23:26:01 8,128 —-a-w C:\Program Files\vd08438839c.dat
2006-04-25 23:26:01 37,553 —-a-w C:\Program Files\vd12238839c.dat
2006-04-25 23:26:01 23,457 —-a-w C:\Program Files\vd00438839b.dat
2006-04-25 23:26:00 2,791 —-a-w C:\Program Files\vd13438839b.dat
2006-04-25 23:26:00 13,766 —-a-w C:\Program Files\vd00338839b.dat
2006-04-25 23:26:00 13,043 —-a-w C:\Program Files\vd00638839b.dat
2006-04-25 23:25:59 6,624 —-a-w C:\Program Files\vd07238839f.dat
2006-04-25 23:25:59 12,971 —-a-w C:\Program Files\vd00138839b.dat
2006-04-25 23:25:59 10,392 —-a-w C:\Program Files\vd03338839b.dat
2006-04-25 23:25:59 1,244 —-a-w C:\Program Files\vd04238839c.dat
2006-04-25 23:25:58 4,488 —-a-w C:\Program Files\vd03438839b.dat
2006-04-25 23:25:58 20,420 —-a-w C:\Program Files\vd03638839b.dat
2006-04-25 23:25:57 895 —-a-w C:\Program Files\vd04438839b.dat
2006-04-25 23:25:57 8,447 —-a-w C:\Program Files\vd24438839c.dat
2006-04-25 23:25:57 7,568 —-a-w C:\Program Files\vd21738839c.dat
2006-04-25 23:25:57 11,867 —-a-w C:\Program Files\vd03538839b.dat
2006-04-25 23:25:56 5,726 —-a-w C:\Program Files\vd02238839b.dat
2006-04-25 23:25:56 29,748 —-a-w C:\Program Files\vd00538838b.dat
2006-04-25 23:25:56 22,120 —-a-w C:\Program Files\vd00638838b.dat
2006-04-25 23:25:55 19,556 —-a-w C:\Program Files\vd03538838b.dat


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-05-15 00:47 50376 –a—— C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 –a—— C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8C5D82E9-9D36-4158-B074-20A87B4928E4}]
C:\WINDOWS\system32\reginix86d.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2005-06-15 17:20 C:\WINDOWS\system32\nwiz.exe]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2003-09-29 07:10]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2003-09-10 03:11]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-07-15 16:05]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-01 16:51]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"TVgenial"="I:\TVgenial\TVgenial.exe" []

*Newly Created Service* - CATCHME

Contents of the 'Scheduled Tasks' folder
2007-06-26 17:46:02 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-13 18:41:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

C:\WINDOWS\system32\cmd.exe [2212] 0x85CD0728


scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-13 18:41:39
C:\ComboFix-quarantined-files.txt … 2007-07-13 18:41
C:\ComboFix2.txt … 2007-07-12 22:23

— E O F —

———————– Here is the new HijackThis Log ——————————–

Logfile of HijackThis v1.99.1
Scan saved at 11:15:08 PM, on 7/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {8C5D82E9-9D36-4158-B074-20A87B4928E4} - C:\WINDOWS\system32\reginix86d.dll (file missing)
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TVgenial] I:\TVgenial\TVgenial.exe -d
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200310…llInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1184251936156
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{33A4D45F-A217-4B9D-90E4-AC4E3F929BC4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe



————————- Here is the Kaspersky report ———————-


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, July 13, 2007 11:07:06 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 14/07/2007
Kaspersky Anti-Virus database records: 339753
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 178585
Number of viruses found: 4
Number of infected objects: 13
Number of suspicious objects: 0
Duration of the scan process: 02:53:04

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_STEF-NEW.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_STEF-NEW.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Stef\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Stef\Local Settings\Application Data\Identities\{1376CF5A-A75B-4FDA-8129-D95781827D44}\Microsoft\Outlook Express\2003Q3.dbx/[From <[removed]>][Date Thu, 17 Jul 2003 16:52:10 +0000 (GMT)]/UNNAMED/Thumbs.db.exe Infected: Email-Worm.Win32.Tanatos.b skipped
C:\Documents and Settings\Stef\Local Settings\Application Data\Identities\{1376CF5A-A75B-4FDA-8129-D95781827D44}\Microsoft\Outlook Express\2003Q3.dbx/[From <[removed]>][Date Thu, 17 Jul 2003 16:52:10 +0000 (GMT)]/UNNAMED Infected: Email-Worm.Win32.Tanatos.b skipped
C:\Documents and Settings\Stef\Local Settings\Application Data\Identities\{1376CF5A-A75B-4FDA-8129-D95781827D44}\Microsoft\Outlook Express\2003Q3.dbx Mail MS Outlook 5: infected - 2 skipped
C:\Documents and Settings\Stef\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Stef\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Stef\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Stef\Local Settings\History\History.IE5\MSHist012007071320070714\index.dat Object is locked skipped
C:\Documents and Settings\Stef\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Stef\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Stef\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Stef\ntuser.dat.LOG Object is locked skipped
C:\Outlook Express Backup\2003Q3.dbx/[From <[removed]>][Date Thu, 17 Jul 2003 16:52:10 +0000 (GMT)]/UNNAMED/Thumbs.db.exe Infected: Email-Worm.Win32.Tanatos.b skipped
C:\Outlook Express Backup\2003Q3.dbx/[From <[removed]>][Date Thu, 17 Jul 2003 16:52:10 +0000 (GMT)]/UNNAMED Infected: Email-Worm.Win32.Tanatos.b skipped
C:\Outlook Express Backup\2003Q3.dbx Mail MS Outlook 5: infected - 2 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\runtime2.sys.vir Infected: Rootkit.Win32.Agent.ey skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\secdrv.sys.vir Infected: Rootkit.Win32.Agent.dp skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{2FE2CC03-B201-47FE-A52B-BDAE4A274840}\RP1381\A0088486.dll Infected: Rootkit.Win32.Agent.dp skipped
C:\System Volume Information\_restore{2FE2CC03-B201-47FE-A52B-BDAE4A274840}\RP1435\A0091464.exe Infected: Trojan.Win32.DNSChanger.hg skipped
C:\System Volume Information\_restore{2FE2CC03-B201-47FE-A52B-BDAE4A274840}\RP1435\A0091501.sys Infected: Rootkit.Win32.Agent.dp skipped
C:\System Volume Information\_restore{2FE2CC03-B201-47FE-A52B-BDAE4A274840}\RP1435\A0091503.sys Infected: Rootkit.Win32.Agent.ey skipped
C:\WINDOWS\$NtServicePackUninstall$\secdrv.sys Infected: Rootkit.Win32.Agent.dp skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.
  • First we need to make all files and folders VISIBLE:
    • Go to start>control panel>folder options>view
    • Choose to "show hidden files and folders,"
    • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
    • Close the window with ok
  • Please RUN HijackThis.
    . Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    O2 - BHO: (no name) - {8C5D82E9-9D36-4158-B074-20A87B4928E4} - C:\WINDOWS\system32\reginix86d.dll (file missing)

  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

  • Reboot Your System in Safe Mode

    How to use the F8 method to Start Your Computer in Safe Mode

    • Restart the computer.
    • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
    • Use the arrow keys to select the Safe mode menu item
    • Press Enter.
  • Using Windows Explorer (Windows Key + E), locate the following files/folders, and DELETE them (if still present):

    C:\WINDOWS\$NtServicePackUninstall$\secdrv.sys<==File
    C:\Outlook Express Backup\2003Q3.dbx<==File

    In addition,try to locate and DELETE the following pieces of mail in the From Folder or all email correspondence from 17 July 2003:

    C:\Documents and Settings\Stef\Local Settings\Application Data\Identities\{1376CF5A-A75B-4FDA-8129-D95781827D44}\Microsoft\Outlook Express\2003Q3.dbx/[From <[removed]>][Date Thu, 17 Jul 2003 16:52:10 +0000 (GMT)]/UNNAMED/Thumbs.db.exe
    C:\Documents and Settings\Stef\Local Settings\Application Data\Identities\{1376CF5A-A75B-4FDA-8129-D95781827D44}\Microsoft\Outlook Express\2003Q3.dbx Mail MS Outlook 5:

  • Exit Explorer, and REBOOT BACK INTO NORMAL MODE

  • Finally, RUN Hijackthis again and produce a new HJT log. Post it in the forum so we can check how everything looks now.
Regards,

Trevuren
Done. Here is the HijackThis log
————————————-

Logfile of HijackThis v1.99.1
Scan saved at 10:43:12 AM, on 7/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TVgenial] I:\TVgenial\TVgenial.exe -d
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200310…llInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1184251936156
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{33A4D45F-A217-4B9D-90E4-AC4E3F929BC4}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Your log looks good. If you have no more malware-related problems that you are aware of, just give me the OK and we can start the final but essential cleanup procedures and recommendations.

Trevuren
Congratulations, your log shows that your SYSTEM IS CLEAN

There are a few things you must do once you are completely clean:

1. Re-hide your System Files and Folders to prevent any future accidents.

Reconfigure Windows XP to hide hidden files:
  • Click Start. Open My Computer.
  • Select the Tools menu and click Folder Options. Select the View Tab.
  • Under the Hidden files and folders heading deselect "Show hidden files and folders".
  • Check the "Hide protected operating system files (recommended)" option.
  • Click Yes to confirm. Click OK.
2. Time for some housekeeping

Please download the OTMoveIt by OldTimer
  • Save it to your desktop.
  • Run the tool by clicking on the icon.
  • Click the Cleanup button.
  • The tools that we used as well as this one will be removed from your system.


3. Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

4. Now Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Here are some tips to reduce the potential for spyware infection in the future:

Make sure you keep your Windows OS current by visiting Windows update
regularly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.

I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
And also see TonyKlein's good advice
So how did I get infected in the first place?

Regards,

Trevuren
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI