This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Devious New Malware

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi menk

Sorry for the delay. We'll need to do another ComboScript.

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\Program Files\DLD.DAT
C:\WINDOWS\system32\cajcte.dll
C:\WINDOWS\system32\wbzpvt.dll
C:\WINDOWS\system32\htqkse.dll
C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll
C:\WINDOWS\system32\qhbpri.dll
C:\WINDOWS\system32\3222.dll
C:\WINDOWS\system32\dhapri.dll
 
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{91B1E846-2BEF-4345-8848-7699C7C9935F}"=-
"{26368135-64FA-BC34-DA32-DCF4FD431C92}"=-
"{3495D328-661A-4FB0-BA67-8ACDD1704D1E}"=-
"{12311A42-AC1B-158F-FD32-5674345F23A1}"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=""
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57de17e0-7a09-11db-94f3-00e05e394056}]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log, if HJT is working now.
Hello Scot

Don't be concerned about delay, I believe we have different sleeping time! In as much as I want to get rid of this problem asap I must allow for some delay. Here is the new log:

"yangyq" - 2007-07-18 12:08:42 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\yangyq\Desktop\CFScript.txt


((((((((((((((((((((((((( Files Created from 2007-06-18 to 2007-07-18 )))))))))))))))))))))))))))))))


2007-07-17 23:34 34 —hs—- C:\Program Files\DLD.DAT
2007-07-16 09:01 23,552 –a—— C:\WINDOWS\system32\cajcte.dll
2007-07-16 09:01 11,264 –a—— C:\WINDOWS\system32\wbzpvt.dll
2007-07-16 09:00 22,016 –a—— C:\WINDOWS\system32\htqkse.dll
2007-07-15 21:35 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-07-15 18:53 drahs—- C:\autorun.inf
2007-07-14 20:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-14 20:19 d——– C:\Deckard
2007-07-13 22:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
2007-07-10 20:30 99 –a—— C:\WINDOWS\system32\pfdnnt_actions.sys
2007-07-10 18:54 d——– C:\WINDOWS\system32\ActiveScan
2007-07-10 17:27 d——– C:\DOCUME~1\yangyq\APPLIC~1\Skype
2007-07-10 17:23 d——– C:\Program Files\Skype


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-03 11:59:39 ——– d—–w C:\DOCUME~1\yangyq\APPLIC~1\VoipStunt
2007-06-13 12:29:53 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-13 12:27:58 ——– d—–w C:\Program Files\Veoh Networks
2007-06-13 12:24:51 ——– d—–w C:\Program Files\DivX
2007-05-28 14:34:23 ——– d—–w C:\Program Files\Opera 9
2007-05-24 04:09:11 ——– d—–w C:\Program Files\Windows Live Toolbar
2007-05-23 07:50:03 ——– d—–w C:\Program Files\Windows Desktop Search
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 13:09:19 1,744 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-13 14:26:38 1,901 —-a-w C:\WINDOWS\panose.bin
2007-05-12 10:39:34 4,096 —-a-w C:\WINDOWS\d3dx.dat
2007-05-02 01:08:19 2,560 —-a-w C:\WINDOWS\system32\BitCometRes.dll
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2005-04-29 09:27:28 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
2007-03-29 22:31 394816 –a—— C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-12-15 03:23 440056 –a—— C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 13:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"@"="C:\Program Files\Common Files\Microsoft Shared\" [2007-07-17 23:40]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"@"="" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{12311A42-AC1B-158F-FD32-5674345F23A1}"="C:\WINDOWS\system32\dhapri.dll" [2004-08-04 11:13]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=dhapri.dll


**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-18 12:11:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-18 12:13:12
C:\ComboFix-quarantined-files.txt … 2007-07-18 12:12
C:\ComboFix2.txt … 2007-07-17 23:45
C:\ComboFix3.txt … 2007-07-16 20:58

— E O F —

I notice you are searching back in time for each log, I suppose you are trying to see when the virus made its entry. A wild guess as I'm totally new in this.

Have a good day/night.

Menk
Scot, when you said 'post the resultant log with a new HijackThis log, if HJT is working now', did you mean I should get the log by running HijackThis? If so, I cannot run this programme because of the block. Menk
Hi menk

Ok we are making progress. As for HijackThis, you might be best to uninstall the current one and download a new one, but we do have Deckards to use.

Download the Killbox.
Unzip it to the desktop

Double-click Killbox.exe to run it.

Select "Delete on Reboot".
Place the following line (complete path) in bold in the "Full Path of File to Delete" box in Killbox:
C:\WINDOWS\system32\dhapri.dll
Put a mark next to "Delete on Reboot"
Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.
If your computer does not restart automatically, please restart it manually.
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again.

Open Notepad and Copy/Paste the text in the codebox below into it:

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{12311A42-AC1B-158F-FD32-5674345F23A1}"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=""

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.
Hello Scot

Good to hear we are progressing. Here's the log:

"yangyq" - 2007-07-18 20:20:00 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\yangyq\Desktop\CFScript.txt


((((((((((((((((((((((((( Files Created from 2007-06-18 to 2007-07-18 )))))))))))))))))))))))))))))))


2007-07-18 20:11 d——– C:\!KillBox
2007-07-17 23:34 34 —hs—- C:\Program Files\DLD.DAT
2007-07-16 09:01 23,552 –a—— C:\WINDOWS\system32\cajcte.dll
2007-07-16 09:01 11,264 –a—— C:\WINDOWS\system32\wbzpvt.dll
2007-07-16 09:00 22,016 –a—— C:\WINDOWS\system32\htqkse.dll
2007-07-15 21:35 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-07-15 18:53 drahs—- C:\autorun.inf
2007-07-14 20:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-14 20:19 d——– C:\Deckard
2007-07-13 22:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
2007-07-10 20:30 99 –a—— C:\WINDOWS\system32\pfdnnt_actions.sys
2007-07-10 18:54 d——– C:\WINDOWS\system32\ActiveScan
2007-07-10 17:27 d——– C:\DOCUME~1\yangyq\APPLIC~1\Skype
2007-07-10 17:23 d——– C:\Program Files\Skype


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-03 11:59:39 ——– d—–w C:\DOCUME~1\yangyq\APPLIC~1\VoipStunt
2007-06-13 12:29:53 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-13 12:27:58 ——– d—–w C:\Program Files\Veoh Networks
2007-06-13 12:24:51 ——– d—–w C:\Program Files\DivX
2007-05-28 14:34:23 ——– d—–w C:\Program Files\Opera 9
2007-05-24 04:09:11 ——– d—–w C:\Program Files\Windows Live Toolbar
2007-05-23 07:50:03 ——– d—–w C:\Program Files\Windows Desktop Search
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 13:09:19 1,744 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-13 14:26:38 1,901 —-a-w C:\WINDOWS\panose.bin
2007-05-12 10:39:34 4,096 —-a-w C:\WINDOWS\d3dx.dat
2007-05-02 01:08:19 2,560 —-a-w C:\WINDOWS\system32\BitCometRes.dll
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2005-04-29 09:27:28 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
2007-03-29 22:31 394816 –a—— C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-12-15 03:23 440056 –a—— C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 13:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"@"="C:\Program Files\Common Files\Microsoft Shared\" [2007-07-17 23:40]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"@"="" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=


**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-18 20:22:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-18 20:24:14
C:\ComboFix-quarantined-files.txt … 2007-07-18 20:23
C:\ComboFix2.txt … 2007-07-18 12:13
C:\ComboFix3.txt … 2007-07-17 23:45

— E O F —

Am I out of the woods yet? I do not see the 2 rogue files in the Task Manager. Does this also mean that meex.exe has also been removed?

Menk
Hello Scot

I'm delighted to be able to run dss.exe and furthermore my young son now knows there is more to it than just knowing how to play online games! The main log is:

Deckard's System Scanner v20070711.54
Run by [removed] on 2007-07-18 at 21:44:37
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
15: 2007-07-18 13:45:05 UTC - RP52 - Deckard's System Scanner Restore Point
14: 2007-07-18 05:35:03 UTC - RP51 - System Checkpoint
13: 2007-07-16 08:32:49 UTC - RP50 - System Checkpoint
12: 2007-07-15 03:25:47 UTC - RP49 - System Checkpoint
11: 2007-07-13 14:37:13 UTC - RP48 - Removed AVG 7.5


– First Restore Point –
1: 2007-06-19 11:20:33 UTC - RP38 - System Checkpoint


Backed up registry hives.

Performed disk cleanup.


– HijackThis (run as yangyq.exe) ———————————————-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:49:07 PM, on 7/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\yangyq\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\yangyq.exe

R3 - URLSearchHook: (no name) - {2C5AA40E-8814-4EB6-876E-7EFB8B3F9662} - (no file)
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [] C:\Program Files\Common Files\Microsoft Shared\
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: http://aolmusicnow.122.2o7.net
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1106318163126
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130988789699
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/mjolauncher.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37940.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {90F7E144-984F-4FA6-83A7-C9C8DCB9974C} (RSActiveXObj Control) - http://cnet.radarsync.com/RSActiveX.ocx
O16 - DPF: {97AFC0D9-660E-4ACE-B025-46FD64AE335A} (EmailImport.EmailImportControl) - http://www.friendster.com/emailimport/ms/emailimport.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/dd/instal…edsolutions.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktank…ownloadCtrl.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDECF656-6DF2-42B4-8714-48703568669F}: NameServer = 202.106.0.20 202.106.46.151
O18 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ODBC Administration Service (odbcasvc) - Unknown owner - C:\WINDOWS\SYSTEM32\odbcasvc.EXE (file missing)
O24 - Desktop Component 0: (no name) - http://us.i1.yimg.com/us.yimg.com/i/us/ga/…lt/lt-40-b1.gif
O24 - Desktop Component 2: FreeWorld Radio Setup - http://www.freeworldradio.com/FreeWorldRadio.php?pls1=

–
End of file - 6600 bytes

– File Associations ———————————————————–

.js - JSFile - DefaultIcon - C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe,2
.js - JSFile - shell\open\command - "C:\Program Files\Macromedia\Dreamweaver MX 2004\Dreamweaver.exe" "%1"


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys
Hi menk

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
c:\windows\system32\drivers\mxdispdr.sys

Driver::
mxdispdr
odbcasvc

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{BC207F7D-3E63-4ACA-99B5-FB5F8428200C}"=-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{2C5AA40E-8814-4EB6-876E-7EFB8B3F9662}"=-
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
@=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7E980B9B-8AE5-466A-B6D6-DA8CF814E78A}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\KuGoo3]

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.
Morning Scot

Here's the latest log:

"yangyq" - 2007-07-19 9:22:20 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\yangyq\Desktop\CFScript.txt


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_MXDISPDR
——-\LEGACY_ODBCASVC
——-\mxdispdr
——-\odbcasvc


((((((((((((((((((((((((( Files Created from 2007-06-19 to 2007-07-19 )))))))))))))))))))))))))))))))


2007-07-18 22:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-07-18 22:55 75,932 –a—— C:\WINDOWS\system32\drivers\klick.dat
2007-07-18 22:55 75,248 –a—— C:\WINDOWS\zllsputility.exe
2007-07-18 22:55 74,396 –a—— C:\WINDOWS\system32\drivers\klin.dat
2007-07-18 22:55 69,664 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-07-18 22:55 110,360 –a—— C:\WINDOWS\system32\drivers\kl1.sys
2007-07-18 22:54 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-07-18 22:54 d——– C:\WINDOWS\system32\ZoneLabs
2007-07-18 21:48 d——– C:\Program Files\Trend Micro
2007-07-18 20:11 d——– C:\!KillBox
2007-07-17 23:34 34 —hs—- C:\Program Files\DLD.DAT
2007-07-16 09:01 23,552 –a—— C:\WINDOWS\system32\cajcte.dll
2007-07-16 09:01 11,264 –a—— C:\WINDOWS\system32\wbzpvt.dll
2007-07-16 09:00 22,016 –a—— C:\WINDOWS\system32\htqkse.dll
2007-07-15 21:35 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-07-15 18:53 drahs—- C:\autorun.inf
2007-07-14 20:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-14 20:19 d——– C:\Deckard
2007-07-13 22:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
2007-07-10 20:30 99 –a—— C:\WINDOWS\system32\pfdnnt_actions.sys
2007-07-10 18:54 d——– C:\WINDOWS\system32\ActiveScan
2007-07-10 17:27 d——– C:\DOCUME~1\yangyq\APPLIC~1\Skype
2007-07-10 17:23 d——– C:\Program Files\Skype


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-19 01:28:00 1,868 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-07-18 14:58:01 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-07-03 11:59:39 ——– d—–w C:\DOCUME~1\yangyq\APPLIC~1\VoipStunt
2007-06-13 12:29:53 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-13 12:27:58 ——– d—–w C:\Program Files\Veoh Networks
2007-06-13 12:24:51 ——– d—–w C:\Program Files\DivX
2007-05-28 14:34:23 ——– d—–w C:\Program Files\Opera 9
2007-05-24 04:09:11 ——– d—–w C:\Program Files\Windows Live Toolbar
2007-05-23 07:50:03 ——– d—–w C:\Program Files\Windows Desktop Search
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 13:09:19 1,744 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-13 14:26:38 1,901 —-a-w C:\WINDOWS\panose.bin
2007-05-12 10:39:34 4,096 —-a-w C:\WINDOWS\d3dx.dat
2007-05-02 01:08:19 2,560 —-a-w C:\WINDOWS\system32\BitCometRes.dll
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2005-04-29 09:27:28 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
2007-03-29 22:31 394816 –a—— C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-12-15 03:23 440056 –a—— C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 13:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"@"="" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=


**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-19 09:29:31
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-19 9:33:34 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-19 09:33
C:\ComboFix2.txt … 2007-07-18 20:24
C:\ComboFix3.txt … 2007-07-18 12:13

— E O F —

Is it ok if I install avg or should I wait till my pc is clear?

Menk
Hello menk

Still got a few files needing to go.

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\WINDOWS\system32\cajcte.dll
C:\WINDOWS\system32\wbzpvt.dll
C:\WINDOWS\system32\htqkse.dll
C:\WINDOWS\system32\pfdnnt_actions.sys

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.
Hiya Scot

"yangyq" - 2007-07-20 8:50:26 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\yangyq\Desktop\CFScript.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\cajcte.dll
C:\WINDOWS\system32\htqkse.dll
C:\WINDOWS\system32\pfdnnt_actions.sys
C:\WINDOWS\system32\wbzpvt.dll


((((((((((((((((((((((((( Files Created from 2007-06-20 to 2007-07-20 )))))))))))))))))))))))))))))))


2007-07-18 22:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-07-18 22:55 75,932 –a—— C:\WINDOWS\system32\drivers\klick.dat
2007-07-18 22:55 75,248 –a—— C:\WINDOWS\zllsputility.exe
2007-07-18 22:55 74,396 –a—— C:\WINDOWS\system32\drivers\klin.dat
2007-07-18 22:55 221,216 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-07-18 22:55 110,360 –a—— C:\WINDOWS\system32\drivers\kl1.sys
2007-07-18 22:54 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-07-18 22:54 d——– C:\WINDOWS\system32\ZoneLabs
2007-07-18 21:48 d——– C:\Program Files\Trend Micro
2007-07-18 20:11 d——– C:\!KillBox
2007-07-17 23:34 34 —hs—- C:\Program Files\DLD.DAT
2007-07-15 21:35 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-07-15 18:53 drahs—- C:\autorun.inf
2007-07-14 20:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-14 20:19 d——– C:\Deckard
2007-07-13 22:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
2007-07-10 18:54 d——– C:\WINDOWS\system32\ActiveScan
2007-07-10 17:27 d——– C:\DOCUME~1\yangyq\APPLIC~1\Skype
2007-07-10 17:23 d——– C:\Program Files\Skype


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-19 15:12:17 3,548 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-07-18 14:58:01 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-07-03 11:59:39 ——– d—–w C:\DOCUME~1\yangyq\APPLIC~1\VoipStunt
2007-06-13 12:29:53 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-13 12:27:58 ——– d—–w C:\Program Files\Veoh Networks
2007-06-13 12:24:51 ——– d—–w C:\Program Files\DivX
2007-05-28 14:34:23 ——– d—–w C:\Program Files\Opera 9
2007-05-24 04:09:11 ——– d—–w C:\Program Files\Windows Live Toolbar
2007-05-23 07:50:03 ——– d—–w C:\Program Files\Windows Desktop Search
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 13:09:19 1,744 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-13 14:26:38 1,901 —-a-w C:\WINDOWS\panose.bin
2007-05-12 10:39:34 4,096 —-a-w C:\WINDOWS\d3dx.dat
2007-05-02 01:08:19 2,560 —-a-w C:\WINDOWS\system32\BitCometRes.dll
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2005-04-29 09:27:28 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
2007-03-29 22:31 394816 –a—— C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-12-15 03:23 440056 –a—— C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 13:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"@"="" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=


**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-20 08:55:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-20 8:57:38
C:\ComboFix-quarantined-files.txt … 2007-07-20 08:57
C:\ComboFix2.txt … 2007-07-19 09:33
C:\ComboFix3.txt … 2007-07-18 20:24

— E O F —
Good morning menk

I hope all is well with you today.
  • Please go HERE to run PandaActiveScan…

  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)

  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to your desktop.
Run HijackThis and post a log here with the Panda scan report, please.
Good day Scot

Looks like I've still got some rubbish!


Incident Status Location
Virus:Trj/Downloader.MDW Disinfected C:\!KillBox\dhapri.dll
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\yangyq\Cookies\yangyq@com[1].txt
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\yangyq\Desktop\ComboFix.exe[nircmd.exe]
Virus:Trj/QQPass.AHS Disinfected C:\Program Files\Common Files\Microsoft Shared\MSInfo\SysWFGQQ2.dll
Virus:Generic Malware Disinfected C:\QooBox\Quarantine\C\Program Files\Common Files\CPUSH\cpush.1dll.vir
Adware:Adware/Sohu Not disinfected C:\QooBox\Quarantine\C\Program Files\Common Files\CPUSH\Uninst.1exe.vir
Virus:Bck/Hupigon.AZG Disinfected C:\QooBox\Quarantine\C\Program Files\Common Files\Microsoft Shared\vnwpbns.exe.vir
Virus:Bck/Hupigon.AZG Disinfected C:\QooBox\Quarantine\C\Program Files\Common Files\System\cfhskjn.exe.vir
Virus:Bck/Hupigon.AZG Disinfected C:\QooBox\Quarantine\C\Program Files\meex.exe.vir
Virus:Trj/Lineage.EPB Disinfected C:\QooBox\Quarantine\C\WINDOWS\cmdbcs.exe.vir
Virus:Trj/Lineage.EPB Disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\cmdbcs.dll.vir
Virus:Trj/Lineage.EOU Disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\htqkse.dll.vir
Adware:Adware/BaiduBar Not disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\promote.dll.vir
Virus:Trj/Downloader.MDW Disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\RemoteDbg.dll.vir
Virus:Trj/Lineage.EKG Disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\TIMHost.dll.vir
Virus:Trj/Lineage.EKG Disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\wbzpvt.dll.vir
Virus:Trj/Lineage.EKG Disinfected C:\QooBox\Quarantine\C\WINDOWS\TIMHost.exe.vir
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\system32\nircmd.exe
Virus:Bck/Hupigon.AZG Disinfected D:\KWJKPWW.EXE
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:49:25 PM, on 7/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: http://aolmusicnow.122.2o7.net
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1106318163126
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130988789699
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37940.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {90F7E144-984F-4FA6-83A7-C9C8DCB9974C} (RSActiveXObj Control) - http://cnet.radarsync.com/RSActiveX.ocx
O16 - DPF: {97AFC0D9-660E-4ACE-B025-46FD64AE335A} (EmailImport.EmailImportControl) - http://www.friendster.com/emailimport/ms/emailimport.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/dd/instal…edsolutions.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktank…ownloadCtrl.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDECF656-6DF2-42B4-8714-48703568669F}: NameServer = 202.106.0.20 202.106.46.151
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O24 - Desktop Component 0: (no name) - http://us.i1.yimg.com/us.yimg.com/i/us/ga/…lt/lt-40-b1.gif
O24 - Desktop Component 2: FreeWorld Radio Setup - http://www.freeworldradio.com/FreeWorldRadio.php?pls1=

–
End of file - 6218 bytes

Have a good weekend ahead!

Menk
Hello menk

I am deeply sorry for the delay in getting back to you. I hope you are still with us.

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\Program Files\Common Files\Microsoft Shared\MSInfo\SysWFGQQ2.dll
C:\Documents and Settings\yangyq\Cookies\yangyq@com[1].txt
D:\KWJKPWW.EXE

Folder::
C:\!KillBox
C:\QooBox\Quarantine
C:\QooBox

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.

Delete the older versions of Java and download the newest.
Please follow these steps to remove older version Java components.
  • Close any programmes you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer once all Java components are removed.
Then download the latest version of Java Runtime Environment (JRE) (4th one down the list), which is JRE6u2, and click Yes at the page warning, then accept the Licence Agreement before downloading the Offline file.

Let me know how the computer is running now.
Hello Scot

Always good to hear from you. Apology not necessary for I believe you have other urgent and important matters to attend to than just getting rid of a few miserable bugs from my pc!! :D

I managed to uninstall all older versions of java except one as its uninst.isu is missing. If I can still install the newer version without adverse effect, I can live with it remaining in the control panel unless you can suggest something.

"yangyq" - 2007-07-26 14:06:09 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\yangyq\Desktop\CFScript.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\!KillBox
C:\!KillBox\Logs\kb.log
C:\Documents and Settings\yangyq\Cookies\yangyq@com[1].txt
C:\QooBox . . . . failed to delete
C:\QooBox\Quarantine . . . . failed to delete


((((((((((((((((((((((((( Files Created from 2007-06-26 to 2007-07-26 )))))))))))))))))))))))))))))))


2007-07-26 13:51 55,808 ——— C:\WINDOWS\system32\ActPanel.dll
2007-07-23 16:15 91,856 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-07-23 16:15 123,488 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-07-23 16:14 d——– C:\Program Files\Symantec
2007-07-23 16:13 d——– C:\Program Files\Symantec AntiVirus
2007-07-23 16:13 d——– C:\Program Files\Common Files\Symantec Shared
2007-07-23 16:13 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-07-22 18:29 2,829 –a—— C:\WINDOWS\War3Unin.pif
2007-07-22 18:29 16,120 –a—— C:\WINDOWS\War3Unin.dat
2007-07-22 18:29 126,976 –a—— C:\WINDOWS\War3Unin.exe
2007-07-21 14:38 d——– C:\game
2007-07-20 23:05 8,576 –a—— C:\WINDOWS\system32\drivers\pgubnabnfdjx.sys
2007-07-18 22:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-07-18 22:55 75,932 –a—— C:\WINDOWS\system32\drivers\klick.dat
2007-07-18 22:55 75,248 –a—— C:\WINDOWS\zllsputility.exe
2007-07-18 22:55 74,396 –a—— C:\WINDOWS\system32\drivers\klin.dat
2007-07-18 22:55 110,360 –a—— C:\WINDOWS\system32\drivers\kl1.sys
2007-07-18 22:55 1,966,112 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-07-18 22:54 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-07-18 22:54 d——– C:\WINDOWS\system32\ZoneLabs
2007-07-18 21:48 d——– C:\Program Files\Trend Micro
2007-07-17 23:34 34 —hs—- C:\Program Files\DLD.DAT
2007-07-15 21:35 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-07-15 18:53 drahs—- C:\autorun.inf
2007-07-14 20:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-14 20:19 d——– C:\Deckard
2007-07-13 22:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
2007-07-10 18:54 d——– C:\WINDOWS\system32\ActiveScan
2007-07-10 17:27 d——– C:\DOCUME~1\yangyq\APPLIC~1\Skype
2007-07-10 17:23 d——– C:\Program Files\Skype


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-26 06:17:14 24,092 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-07-26 03:51:58 1,632 —-a-w C:\WINDOWS\system32\d3d8caps.dat
2007-07-24 01:59:29 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-07-24 01:57:10 ——– d—–w C:\Program Files\Opera 9
2007-07-24 01:56:18 ——– d—–w C:\Program Files\Windows NT
2007-07-18 14:58:01 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-07-03 11:59:39 ——– d—–w C:\DOCUME~1\yangyq\APPLIC~1\VoipStunt
2007-06-13 12:27:58 ——– d—–w C:\Program Files\Veoh Networks
2007-06-13 12:24:51 ——– d—–w C:\Program Files\DivX
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 13:09:19 1,744 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-13 14:26:38 1,901 —-a-w C:\WINDOWS\panose.bin
2007-05-12 10:39:34 4,096 —-a-w C:\WINDOWS\d3dx.dat
2007-05-02 01:08:19 2,560 —-a-w C:\WINDOWS\system32\BitCometRes.dll
2005-04-29 09:27:28 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
2007-03-29 22:31 394816 –a—— C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 13:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-07-21 11:10]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-07-26 10:29]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=


**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-26 14:19:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-26 14:23:32 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-26 14:23
C:\ComboFix2.txt … 2007-07-20 08:57
C:\ComboFix3.txt … 2007-07-19 09:33

— E O F —

My antivirus popped up to say I've got 5 files of infostealer.gampass and 2 of trojan.retvorp.

Menk

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI