This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] WinAntivirusPro 2007

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Pleas help me with this. I cannot get rid of this infection. I have tried ad-aware, spybot, and f-secure online until it gets locked up by a popup. I have gone through manual removal and non of the DLLS, registry settings, or files are present yet I am still infected by it. Here is the hijackthis log. Please help.

Logfile of HijackThis v1.99.1
Scan saved at 1:57:52 PM, on 10/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{04B54FEB-A495-4DB5-9AB7-9DD107E4A25F}: NameServer = 192.168.3.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{04B54FEB-A495-4DB5-9AB7-9DD107E4A25F}: NameServer = 192.168.3.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{04B54FEB-A495-4DB5-9AB7-9DD107E4A25F}: NameServer = 192.168.3.5
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I am still training here, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer.


If you still need help:

Show all hidden files:
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Please do not delete anything unless instructed to.

Next, rename HijackThis.exe to scanner.exe.
Scan again with HijackThis, and "copy/paste" a new log file into this thread.

Then I will analyze your log and sort out a fix for you :)

Also please describe how your computer behaves at the moment.


jpshortstuff
Hello jpshortstuff!

Thanks for taking a look at my file. I believe I have made some progress since I posted. I don't seem to have WinAntivirusPro any longer. Now when I open a browser a popup will soon appear indicating a malware infection and a button to push to fix it. It comes from IP 89.188.16.10. I know this can be related to Vundo. I have run fixvundo and it was not found. Another page may open when I open the browser also, typically to an adult site. I renamed hijackthis to scanner and made another scan. It appears quite different. Do certain things hide from hijackthis? Thanks again for your help. I will get back to this computer tomorrow as it is at my work.

Just a note: this computer has a dongle for a licensed program so that is what "C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe" is.


Logfile of HijackThis v1.99.1
Scan saved at 4:23:32 PM, on 10/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\HJT\scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1286D4BD-3422-4EC5-B046-76921C85EE89} - C:\Program Files\ComPlus Applications\merotexoh83122.dll
O2 - BHO: (no name) - {447E2361-74A3-49CB-99FA-4981028A0093} - C:\WINNT\system32\xxwxx.dll
O2 - BHO: (no name) - {540F30B9-5F1F-4073-A51B-9547A617C8AB} - C:\Program Files\ComPlus Applications\merotexoh4444.dll
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINNT\system32\hjslnmey.dll
O2 - BHO: (no name) - {AD0F18EE-AE25-CCA0-0C5A-8C9A85894D97} - C:\WINNT\system32\eedolhg.dll
O2 - BHO: (no name) - {BACEB7AF-8D88-456E-82D0-7BEB9A4410FE} - C:\WINNT\system32\khfedaw.dll
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{04B54FEB-A495-4DB5-9AB7-9DD107E4A25F}: NameServer = 192.168.3.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{04B54FEB-A495-4DB5-9AB7-9DD107E4A25F}: NameServer = 192.168.3.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{04B54FEB-A495-4DB5-9AB7-9DD107E4A25F}: NameServer = 192.168.3.5
O20 - Winlogon Notify: khfedaw - C:\WINNT\SYSTEM32\khfedaw.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)

Do certain things hide from hijackthis?

They certainly do, especially Vundo, which is what I suspected, and thus why I asked you to rename.
You were right about the Vundo infection definitely there.

Just waiting for my fix to you to be approved, shouldn't be too long.

jpshortstuff
Hi Rstoner


Please delete/uninstall HijackThis and downaload the newer version from here.


Are you running an AntiVirus or a Firewall program? I can't see any in your log…

If Not:
Install Anti-Virus software! Without any anti-virus software, your computer is wide open to infection. If you don't have any Anti-Virus software I strongly recommend you download Avast! or AVG Free

DO NOT install a firewall until the computer is clean as this can cause problems.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.



Download ComboFix by sUBs from here or here

**Save it to your desktop**

Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall



In your next post:
  • Include the ComboFix log
  • Include a fresh HijackThis log
  • Please describe how your computer is behaving at the moment
Thanks,

jpshortstuff
Thank you jpshortstuff.

The first time I ran combofix I coudn't find the log file so I ran it again. This computer never got anti-virus software installed since it is used to work with a measuring robot and has little exposure to much else. I realize it should have something intsalled as well.

Here is the combofix log file after the second running…

ComboFix 07-10-23.2 - rstone 2007-10-23 11:45:51.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.446 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-09-23 to 2007-10-23 )))))))))))))))))))))))))))))))
.

2007-10-23 11:44 d——– C:\Program Files\Trend Micro
2007-10-23 11:33 812,344 –a—— C:\HJTInstall.exe
2007-10-23 11:31 51,200 –a—— C:\WINNT\NirCmd.exe
2007-10-23 11:20 d——– C:\Documents and Settings\rstone\Application Data\PTC
2007-10-22 14:16 d——– C:\Documents and Settings\rstone\Application Data\Apple Computer
2007-10-22 09:08 d——– C:\Documents and Settings\rstone\Application Data\Lavasoft
2007-10-19 09:20 d——– C:\Documents and Settings\lsheriff\Application Data\Lavasoft
2007-10-19 09:16 d——– C:\Program Files\Lavasoft
2007-10-17 10:14 499,712 –a—— C:\WINNT\SYSTEM32\msvcp71.dll
2007-10-17 10:14 89,088 –a—— C:\WINNT\SYSTEM32\atl71.dll
2007-10-17 10:12 d——– C:\WINNT\SYSTEM32\pod2
2007-10-17 10:12 d——– C:\WINNT\SYSTEM32\cap1
2007-10-17 10:12 d——– C:\WINNT\SYSTEM32\bib1
2007-10-17 10:12 d——– C:\WINNT\SYSTEM32\bco2
2007-10-17 10:12 d–hs—- C:\WINNT\QWR2YW5jZWQgQ29tcG9uZW50
2007-10-17 10:12 45,056 –a—— C:\WINNT\SYSTEM32\katzppd.exe
2007-10-17 10:11 d——– C:\Temp
2007-10-17 10:10 d——– C:\Program Files\Common Files\Nullsoft
2007-10-17 10:05 d——– C:\Documents and Settings\lsheriff\Application Data\Apple Computer
2007-10-17 10:03 d——– C:\WINNT\SYSTEM32\DRVSTORE
2007-10-17 10:03 d——– C:\Program Files\QuickTime
2007-10-01 16:00 d——– C:\Documents and Settings\lsheriff\Application Data\PTC

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-04-12 16:05 64,624 —-a-w C:\Documents and Settings\jkruger\Application Data\GDIPFONTCACHEV1.DAT
2002-08-08 13:36 271 –sh–w C:\Program Files\DESKTOP.INI
2002-08-08 13:36 21,952 —h–w C:\Program Files\FOLDER.HTT
2005-07-29 21:24:26 472 –sha-r C:\WINNT\QWR2YW5jZWQgQ29tcG9uZW50\kqlZsqc3tqk0kZ6Qw36RtqcX.vbs
.

((((((((((((((((((((((((((((( snapshot@2007-10-23_11.40.38.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 15:57:12 163,328 —-a-w C:\WINNT\erdnt\subs\F3M\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="C:\WINNT\system32\mobsync.exe" [2004-08-04 12:00]
"PCTVOICE"="pctspk.exe" [2002-10-11 00:37 C:\WINNT\SYSTEM32\pctspk.exe]
"ATIModeChange"="Ati2mdxx.exe" [2002-05-08 21:14 C:\WINNT\SYSTEM32\Ati2mdxx.exe]
"AtiPTA"="atiptaxx.exe" [2002-05-08 21:14 C:\WINNT\SYSTEM32\atiptaxx.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2002-08-01 14:43]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2002-08-01 14:43]
"WinVNC"="C:\Program Files\ORL\VNC\WinVNC.exe" [2000-05-23 18:09]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 12:00]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
"tscuninstall"=%systemroot%\system32\tscupgrd.exe

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"internat.exe"=internat.exe

C:\Documents and Settings\jkruger\Start Menu\Programs\Startup\
Punch In Punch Out.url [2007-03-27 10:49:08]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"=0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"

R0 fasttrak;fasttrak;C:\WINNT\system32\DRIVERS\fasttrak.sys
R0 Fd16_700;Fd16_700;C:\WINNT\system32\DRIVERS\fd16_700.sys
R0 mraid2k;mraid2k;C:\WINNT\system32\DRIVERS\mraid2k.sys
S3 EL90BC;3Com EtherLink XL B/C Adapter Driver;C:\WINNT\system32\DRIVERS\el90xbc5.sys

.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-23 11:47:49
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-23 11:48:21
C:\ComboFix2.txt … 2007-10-23 11:41
.
— E O F —


Here is a fresh hijackthis file….

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:49, on 2007-10-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [internat.exe] internat.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [internat.exe] internat.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [internat.exe] internat.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{04B54FEB-A495-4DB5-9AB7-9DD107E4A25F}: NameServer = 192.168.3.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{04B54FEB-A495-4DB5-9AB7-9DD107E4A25F}: NameServer = 192.168.3.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{04B54FEB-A495-4DB5-9AB7-9DD107E4A25F}: NameServer = 192.168.3.5
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: VNC Server (winvnc) - AT&T Research Labs Cambridge - C:\Program Files\ORL\VNC\WinVNC.exe

–
End of file - 4095 bytes


The computer seems to be behaving now. The log looks clean to me. Thanks very much for your help. I have picked up some valuable information from this session. Is the newer version of hijackthis less able to be fooled by things?

Thanks again!
Stay with us just a bit longer, still a little bit left to do on your computer.

As for a version of HijackThis that isn't fooled by that Vundo, I don't think there is one as of yet. Perhaps there will be one later on, but as of now, just a quick rename to anything you like (.exe) will suffice.

Fix coming soon…

Thanks,

jpshortstuff
Hi Rstoner


Go to http://virusscan.jotti.org
Copy the following line into the white textbox:
C:\WINNT\SYSTEM32\katzppd.exe
Click Submit.
Please post the results of this scan to this thread.


1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINNT\QWR2YW5jZWQgQ29tcG9uZW50\kqlZsqc3tqk0kZ6Qw36RtqcX.vbs
C:\WINNT\SYSTEM32\katzppd.exe

Folder::
C:\WINNT\SYSTEM32\pod2
C:\WINNT\SYSTEM32\cap1
C:\WINNT\SYSTEM32\bib1
C:\WINNT\SYSTEM32\bco2
C:\WINNT\QWR2YW5jZWQgQ29tcG9uZW50

DirLook::
C:\Temp


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please do an online scan with Kaspersky WebScanner

Follow this link in Internet Explorer (Note: You must use Internet explorer to use Kaspersky): Kaspersky WebScanner

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    o Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)

    o Scan Options:
    Scan Archives Scan Mail Bases

  • Click OK
  • Now under select a target to scan:
    Select My Computer
  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    o Now click on the Save as Text button:
  • Save the file to your desktop.
In your next reply, please include:
  • A fresh HijackThis log
  • The results from the Jotti scan
  • The Results from the Kaspersky scan
  • ComboFix log
Thanks,

jpshortstuff
OK jpshortstuff,

Jotti found nothing in the file Katzppd.exe

Here is the latest hijackthis file…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:01, on 2007-10-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\explorer.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINNT\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [internat.exe] internat.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [internat.exe] internat.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [internat.exe] internat.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{04B54FEB-A495-4DB5-9AB7-9DD107E4A25F}: NameServer = 192.168.3.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{04B54FEB-A495-4DB5-9AB7-9DD107E4A25F}: NameServer = 192.168.3.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{04B54FEB-A495-4DB5-9AB7-9DD107E4A25F}: NameServer = 192.168.3.5
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: VNC Server (winvnc) - AT&T Research Labs Cambridge - C:\Program Files\ORL\VNC\WinVNC.exe

–
End of file - 4226 bytes


Here is the Kaspersky file…Many things found in the system restore folders…

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
2007-10-23 16:54
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 23/10/2007
Kaspersky Anti-Virus database records: 443492
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\

Scan Statistics:
Total number of scanned objects: 109492
Number of viruses found: 15
Number of infected objects: 48
Number of suspicious objects: 0
Duration of the scan process: 01:53:32

Infected Object Name / Virus Name / Last Action
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP393\A0029392.exe Infected: Trojan-Downloader.Win32.Agent.dve skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP393\A0029393.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP393\A0029393.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP393\A0029401.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP393\A0029411.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP393\A0029411.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP393\A0029450.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP393\A0029459.dll Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP393\A0029506.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP397\A0029570.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP398\A0029606.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.ady skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP398\A0029641.EXE Infected: Trojan.Win32.VB.bik skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032000.exe Infected: Trojan-Downloader.Win32.Agent.ehg skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032001.exe Infected: Trojan-Downloader.Win32.Agent.dve skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032002.exe Infected: Trojan-Downloader.Win32.Agent.ecz skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032003.exe Infected: Trojan.Win32.Agent.bck skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032005.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032006.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032007.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aea skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032010.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032010.exe/data0003 Infected: not-a-virus:AdWare.Win32.PurityScan.bu skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032010.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032017.exe Infected: Trojan-Downloader.Win32.VB.bnq skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032019.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP403\A0032019.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP404\change.log Object is locked skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP404\A0032092.exe Infected: Trojan-Downloader.Win32.Delf.cpy skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP404\A0032093.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP404\A0032093.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{97058861-7B22-4EF6-9026-3868AF3CE54C}\RP404\A0032094.exe Infected: not-a-virus:AdWare.Win32.Agent.co skipped
C:\WINNT\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINNT\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINNT\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINNT\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINNT\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINNT\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINNT\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINNT\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINNT\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINNT\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINNT\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINNT\SYSTEM32\h323log.txt Object is locked skipped
C:\WINNT\CSC\000001 Object is locked skipped
C:\WINNT\Temp\spnserv.dat Object is locked skipped
C:\WINNT\Temp\spserv.dat Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Debug\Netlogon.log Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\Sti_Trace.log Object is locked skipped
C:\WINNT\wiaservc.log Object is locked skipped
C:\WINNT\wiadebug.log Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\qoobox\Quarantine\C\WINNT\SYSTEM32\rsgtbhue.exe.vir Infected: Trojan.Win32.Agent.bck skipped
C:\qoobox\Quarantine\C\WINNT\SYSTEM32\hjslnmey.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aea skipped
C:\qoobox\Quarantine\C\WINNT\SYSTEM32\oTt08e\oTt08e1099.exe.vir Infected: Trojan-Downloader.Win32.VB.bnq skipped
C:\qoobox\Quarantine\C\WINNT\SYSTEM32\bib1\rwv12drvr.exe.vir Infected: Trojan-Downloader.Win32.Delf.cpy skipped
C:\qoobox\Quarantine\C\WINNT\SYSTEM32\cap1\dode83122.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\qoobox\Quarantine\C\WINNT\SYSTEM32\cap1\dode83122.exe.vir NSIS: infected - 1 skipped
C:\qoobox\Quarantine\C\WINNT\SYSTEM32\pod2\c94byvr.exe.vir Infected: not-a-virus:AdWare.Win32.Agent.co skipped
C:\qoobox\Quarantine\C\WINNT\b122.exe.vir Infected: Trojan-Downloader.Win32.Agent.ehg skipped
C:\qoobox\Quarantine\C\WINNT\tsitra77.exe.vir Infected: Trojan-Downloader.Win32.Agent.dve skipped
C:\qoobox\Quarantine\C\WINNT\tsitra1000106.exe.vir Infected: Trojan-Downloader.Win32.Agent.ecz skipped
C:\qoobox\Quarantine\C\WINNT\TTC-4444.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\qoobox\Quarantine\C\WINNT\TTC-4444.exe.vir NSIS: infected - 1 skipped
C:\qoobox\Quarantine\C\Program Files\ComPlus Applications\merotexoh83122.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\qoobox\Quarantine\C\Program Files\ComPlus Applications\merotexoh4444.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\qoobox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped
C:\qoobox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir/data0003 Infected: not-a-virus:AdWare.Win32.PurityScan.bu skipped
C:\qoobox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir NSIS: infected - 2 skipped
C:\Documents and Settings\rstone\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\rstone\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\rstone\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\rstone\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\rstone\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\rstone\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\rstone\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Program Files\ORL\VNC\WinVNC.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
C:\Program Files\ORL\VNC\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped

Scan process completed.

Here is the combofix file…

ComboFix 07-10-23.2 - rstone 2007-10-23 14:08:24.3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.451 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\rstone\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\WINNT\QWR2YW5jZWQgQ29tcG9uZW50\kqlZsqc3tqk0kZ6Qw36RtqcX.vbs
C:\WINNT\SYSTEM32\katzppd.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINNT\QWR2YW5jZWQgQ29tcG9uZW50
C:\WINNT\QWR2YW5jZWQgQ29tcG9uZW50\kqlZsqc3tqk0kZ6Qw36RtqcX.vbs
C:\WINNT\SYSTEM32\bco2
C:\WINNT\SYSTEM32\bib1
C:\WINNT\SYSTEM32\bib1\rwv12drvr.exe
C:\WINNT\SYSTEM32\cap1
C:\WINNT\SYSTEM32\cap1\dode83122.exe
C:\WINNT\SYSTEM32\katzppd.exe
C:\WINNT\SYSTEM32\pod2
C:\WINNT\SYSTEM32\pod2\c94byvr.exe

.
((((((((((((((((((((((((( Files Created from 2007-09-23 to 2007-10-23 )))))))))))))))))))))))))))))))
.

2007-10-23 11:44 d——– C:\Program Files\Trend Micro
2007-10-23 11:33 812,344 –a—— C:\HJTInstall.exe
2007-10-23 11:31 51,200 –a—— C:\WINNT\NirCmd.exe
2007-10-23 11:20 d——– C:\Documents and Settings\rstone\Application Data\PTC
2007-10-22 14:16 d——– C:\Documents and Settings\rstone\Application Data\Apple Computer
2007-10-22 09:08 d——– C:\Documents and Settings\rstone\Application Data\Lavasoft
2007-10-19 09:20 d——– C:\Documents and Settings\lsheriff\Application Data\Lavasoft
2007-10-19 09:16 d——– C:\Program Files\Lavasoft
2007-10-17 10:14 499,712 –a—— C:\WINNT\SYSTEM32\msvcp71.dll
2007-10-17 10:14 89,088 –a—— C:\WINNT\SYSTEM32\atl71.dll
2007-10-17 10:11 d——– C:\Temp
2007-10-17 10:10 d——– C:\Program Files\Common Files\Nullsoft
2007-10-17 10:05 d——– C:\Documents and Settings\lsheriff\Application Data\Apple Computer
2007-10-17 10:03 d——– C:\WINNT\SYSTEM32\DRVSTORE
2007-10-17 10:03 d——– C:\Program Files\QuickTime
2007-10-01 16:00 d——– C:\Documents and Settings\lsheriff\Application Data\PTC

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-04-12 16:05 64,624 —-a-w C:\Documents and Settings\jkruger\Application Data\GDIPFONTCACHEV1.DAT
2002-08-08 13:36 271 –sh–w C:\Program Files\DESKTOP.INI
2002-08-08 13:36 21,952 —h–w C:\Program Files\FOLDER.HTT
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Temp —-



((((((((((((((((((((((((((((( snapshot@2007-10-23_11.40.38.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 15:57:12 163,328 —-a-w C:\WINNT\erdnt\subs\F3M\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="C:\WINNT\system32\mobsync.exe" [2004-08-04 12:00]
"PCTVOICE"="pctspk.exe" [2002-10-11 00:37 C:\WINNT\SYSTEM32\pctspk.exe]
"ATIModeChange"="Ati2mdxx.exe" [2002-05-08 21:14 C:\WINNT\SYSTEM32\Ati2mdxx.exe]
"AtiPTA"="atiptaxx.exe" [2002-05-08 21:14 C:\WINNT\SYSTEM32\atiptaxx.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2002-08-01 14:43]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2002-08-01 14:43]
"WinVNC"="C:\Program Files\ORL\VNC\WinVNC.exe" [2000-05-23 18:09]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 12:00]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
"tscuninstall"=%systemroot%\system32\tscupgrd.exe

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"internat.exe"=internat.exe

C:\Documents and Settings\jkruger\Start Menu\Programs\Startup\
Punch In Punch Out.url [2007-03-27 10:49:08]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"=0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"

R0 fasttrak;fasttrak;C:\WINNT\system32\DRIVERS\fasttrak.sys
R0 Fd16_700;Fd16_700;C:\WINNT\system32\DRIVERS\fd16_700.sys
R0 mraid2k;mraid2k;C:\WINNT\system32\DRIVERS\mraid2k.sys
S3 EL90BC;3Com EtherLink XL B/C Adapter Driver;C:\WINNT\system32\DRIVERS\el90xbc5.sys

.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-23 14:10:20
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-23 14:10:50
C:\ComboFix3.txt … 2007-10-23 11:41
C:\ComboFix2.txt … 2007-10-23 11:48
.
— E O F —

Thanks, I'll get back to this one again tomorrow. The computer acts normal now.
Hi Rstoner

Log looks good :thumbup:


Click Start >> Run, and then type ComboFix /u and hit enter.


If you are using Intrnet Explorer v. 6

Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialise and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
There are good reasons to upgrade to Internet Explorer v. 7. Do look into this. You can find a lot of information about it on Microsoft's website.


Now that you appear to be clean, theres just a few steps I'd like you to take to prevent any future infections.
  • Install a firewall! Without a firewall you are very susceptible to being hacked, and people could gain access to your computer. If you don't have a firewall I strongly recommend you download ONE of the following:
    1) ZoneAlarm
    2) Agnitum
    3) Sunbelt/Kerio
    4) Comodo

  • System restore:
    This is a good time to clear your existing system restore points and establish a new clean restore point:
    • Go to Start > All Programs > Accessories > System Tools > System Restore
    • Select Create a restore point, and Ok it.
    • Next, go to Start > Run and type in cleanmgr
    • Select the More options tab
    • Choose the option to clean up system restore and OK it.
    This will remove all restore points except the new one you just created.
    Make sure you do this now, as your System Restore currently has infected files in it.

  • Use Mozilla Firefox or Opera as your internet browser.
    These are more secure than Internet Explorer and can be downloaded for free from here:
    Download Mozilla FireFox
    Download Opera

  • Make sure your update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have:
    Download Spybot Search and Destroy 1.5 from here
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

  • Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Please reply once more so I can mark this problem solved.

Glad we could be of assistance

Stay Clean!

jpshortstuff
Thanks very much jpshortstuff. I use a lot of these tools when I go after these things. This one was a bit over my head. Ou network has a firewall on the public side of the Internet which isn't much good when I spread the infection internally. :blush: Thanks again, I appreciate your help.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI