Logfile of Trend Micro HijackThis v2.0.2Scan saved at 12:45:51 AM, on 12/15/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Google\Gmail Notifier\gnotify.exeC:\Program Files\ULI5289\ALi5289.exeC:\Program Files\Java\jre1.6.0_03\bin\jusched.exeC:\Program Files\Spybot - Search & Destroy\SpybotSD.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\Program Files\AIM6\aim6.exeC:\Program Files\AIM6\aolsoftware.exeC:\WINDOWS\system32\nqcqwmga.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\wuauclt.exeC:\Documents and Settings\Gili\Desktop\HiJackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blankO4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exeO4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exeO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autocloseO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imAppO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: DomainService - - C:\WINDOWS\system32\nqcqwmga.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe–End of file - 3340 bytesPop-Ups, that is. This is the situation at the moment. Help? Thanks.
Hi, and Welcome to
WhatTheTech
My name is
jpshortstuff . I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
[*]I will working be on your Malware issues, this may or may not, solve other issues you have with your machine. [*]The fixes are specific to your problem and should only be used for the issues on this machine. [*]Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear. [*]It's often worth reading through these instructions and printing them for ease of reference. [*]If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry. [*]Please reply to this thread. Do not start a new topic.
As I am still training here, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer.
Show all hidden files:
[*]Click Start . [*]Open My Computer . [*]Select the Tools menu and click Folder Options . [*]Select the View Tab. [*]Under the Hidden files and folders heading select Show hidden files and folders . [*]Uncheck the Hide protected operating system files (recommended) option. [*]Click Yes to confirm. [*]Click OK .Please do not delete anything unless instructed to.
Next, rename HijackThis.exe to scanner.exe .
Scan again with HijackThis, and "copy/paste " a new log file into this thread.
I need to see another log from HijackThis.
[*]Run Hijackthis . [*]Click on Open the Misc Tools section . [*]Next click on Open uninstall manager . [*]Press the Save list button. [*]Save the file to your desktop, with the default name of uninstall_list [*]Copy & Paste the entire contents of that file in your in your next post.
Thanks,
jpshortstuff
Thanks!So…I hope I got this right. I renamed HiJackThis and ran it again. This is the log:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:22:18 PM, on 12/15/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Google\Gmail Notifier\gnotify.exeC:\Program Files\ULI5289\ALi5289.exeC:\Program Files\Java\jre1.6.0_03\bin\jusched.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\Program Files\AIM6\aim6.exeC:\Program Files\AIM6\aolsoftware.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Documents and Settings\Gili\Desktop\scanner.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blankO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {20907D5B-6893-4A22-BDD7-83B54A802D04} - C:\WINDOWS\system32\jkklm.dllO2 - BHO: {58116da7-724a-b039-f4e4-302a38393713} - {31739383-a203-4e4f-930b-a4277ad61185} - C:\WINDOWS\system32\qqeeljce.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)O2 - BHO: (no name) - {A70E9493-2ACF-4AAD-B243-4B217C8648DC} - (no file)O2 - BHO: (no name) - {B1AE8E6B-34FA-3F0E-DA29-3BE6778F5BB1} - C:\WINDOWS\system32\tygn.dll (file missing)O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\yayyaxu.dll (file missing)O2 - BHO: (no name) - {C27F3316-913F-429C-B563-BE9AEF2C1371} - (no file)O2 - BHO: (no name) - {E1AA8E3A-63FA-365D-D829-3BE6778F03B7} - C:\WINDOWS\system32\ybeupl.dll (file missing)O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exeO4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exeO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autocloseO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imAppO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO20 - Winlogon Notify: hsijxizk - hsijxizk.dll (file missing)O20 - Winlogon Notify: yayyaxu - yayyaxu.dll (file missing)O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe–End of file - 4425 bytesAnd…this is the unistall_list log:7-Zip 4.57AC3Filter (remove only)Ad-Aware SE PersonalAdobe Bridge 1.0Adobe Common File InstallerAdobe Flash Player PluginAdobe Help Center 1.0Adobe Illustrator CS2Adobe InDesign CS2Adobe Photoshop CS2Adobe Reader 7.0.9Adobe Stock Photos 1.0Adobe SVG Viewer 3.0Ahead Nero Burning ROMAhead NeroVision ExpressAIM 6AOL Instant MessengerApple Software UpdateAthlon 64 Processor DriverAvanquest updateCanon EOS 5D WIA DriverCanon EOS Kiss_N REBEL_XT 350D WIA DriverCanon EOS-1Ds Mark II WIA DriverCanon Utilities Digital Photo Professional 3.2Canon Utilities EOS UtilityCanon Utilities Original Data Security ToolsCanon Utilities PhotoStitchCanon Utilities WFT-E1/E2 UtilityDeluxeFTP 6.0.1DivX CodecDivX Content UploaderDivX ConverterDivX PlayerDivX Web PlayereMuleEV Nova (remove only)Final Fantasy VIIFlickr Uploadr 2.3Google Gmail NotifierHijackThis 2.0.2HP Photo & Imaging 3.1HP PSC & OfficeJet 3.0HP Software UpdateIndigo Prophecy DemoIntel A/V Codecs V2.0J2SE Runtime Environment 5.0 Update 10J2SE Runtime Environment 5.0 Update 11J2SE Runtime Environment 5.0 Update 6J2SE Runtime Environment 5.0 Update 9Jade EmpireJava™ 6 Update 2Java™ 6 Update 3Java™ SE Runtime Environment 6 Update 1Macromedia Extension ManagerMacromedia Flash 8Macromedia Flash 8 Video EncoderMacromedia Flash Player 8Macromedia Flash Player 8MediaMonkey 2.5Microsoft .NET Framework 1.1Microsoft .NET Framework 1.1Microsoft .NET Framework 1.1 Hotfix (KB928366)Microsoft .NET Framework 2.0Microsoft Kernel-Mode Driver Framework Feature Pack 1.5Microsoft Office XP Professional with FrontPageMicrosoft Visual C++ 2005 RedistributableMotorola Driver InstallationMotorola Phone ToolsMozilla Firefox (2.0.0.11)MSXML 4.0 SP2 (KB927978)MSXML 4.0 SP2 (KB936181)NVIDIA DriversPhotomatix Pro version 2.4Power MP3 WMA Converter 2006, (ver 3.42)QuickTimeRealPlayerRosetta Stone Ltd ServicesSecurity Update for Microsoft .NET Framework 2.0 (KB928365)Security Update for Windows Media Player 10 (KB936782)Security Update for Windows XP (KB890046)Security Update for Windows XP (KB893756)Security Update for Windows XP (KB896358)Security Update for Windows XP (KB896423)Security Update for Windows XP (KB896428)Security Update for Windows XP (KB899587)Security Update for Windows XP (KB899591)Security Update for Windows XP (KB900725)Security Update for Windows XP (KB901017)Security Update for Windows XP (KB901214)Security Update for Windows XP (KB902400)Security Update for Windows XP (KB904706)Security Update for Windows XP (KB905414)Security Update for Windows XP (KB905749)Security Update for Windows XP (KB908519)Security Update for Windows XP (KB911562)Security Update for Windows XP (KB911927)Security Update for Windows XP (KB913433)Security Update for Windows XP (KB913580)Security Update for Windows XP (KB914388)Security Update for Windows XP (KB914389)Security Update for Windows XP (KB917344)Security Update for Windows XP (KB917953)Security Update for Windows XP (KB918118)Security Update for Windows XP (KB918439)Security Update for Windows XP (KB919007)Security Update for Windows XP (KB920213)Security Update for Windows XP (KB920670)Security Update for Windows XP (KB920683)Security Update for Windows XP (KB920685)Security Update for Windows XP (KB921503)Security Update for Windows XP (KB922819)Security Update for Windows XP (KB923191)Security Update for Windows XP (KB923414)Security Update for Windows XP (KB923689)Security Update for Windows XP (KB923980)Security Update for Windows XP (KB924191)Security Update for Windows XP (KB924270)Security Update for Windows XP (KB924496)Security Update for Windows XP (KB924667)Security Update for Windows XP (KB925902)Security Update for Windows XP (KB926255)Security Update for Windows XP (KB926436)Security Update for Windows XP (KB927779)Security Update for Windows XP (KB927802)Security Update for Windows XP (KB928255)Security Update for Windows XP (KB928843)Security Update for Windows XP (KB929123)Security Update for Windows XP (KB929969)Security Update for Windows XP (KB930178)Security Update for Windows XP (KB931261)Security Update for Windows XP (KB931784)Security Update for Windows XP (KB932168)Security Update for Windows XP (KB933566)Security Update for Windows XP (KB933729)Security Update for Windows XP (KB935839)Security Update for Windows XP (KB935840)Security Update for Windows XP (KB936021)Security Update for Windows XP (KB937143)Security Update for Windows XP (KB937894)Security Update for Windows XP (KB938127)Security Update for Windows XP (KB938829)Security Update for Windows XP (KB939653)Security Update for Windows XP (KB941202)Security Update for Windows XP (KB941568)Security Update for Windows XP (KB941569)Security Update for Windows XP (KB942615)Security Update for Windows XP (KB943460)Security Update for Windows XP (KB944653)SimCity 4 DeluxeSoundMAXSpybot - Search & DestroyThe Rosetta StoneULi M5289 SATA Controller DriverULi PCI 10-100 Fast Ethernet Controller DriverULi PCI to AGP Controller DriverUpdate for Windows XP (KB894391)Update for Windows XP (KB900485)Update for Windows XP (KB908531)Update for Windows XP (KB910437)Update for Windows XP (KB911280)Update for Windows XP (KB916595)Update for Windows XP (KB920872)Update for Windows XP (KB922582)Update for Windows XP (KB927891)Update for Windows XP (KB930916)Update for Windows XP (KB931836)Update for Windows XP (KB933360)Update for Windows XP (KB938828)Update for Windows XP (KB942763)Update for Windows XP (KB942840)Winamp (remove only)Windows Installer 3.1 (KB893803)Windows Media Format RuntimeWindows Media Player 10Windows XP Hotfix - KB873339Windows XP Hotfix - KB885835Windows XP Hotfix - KB885836Windows XP Hotfix - KB885884Windows XP Hotfix - KB886185Windows XP Hotfix - KB888302Windows XP Hotfix - KB890859Windows XP Hotfix - KB891781WinRAR archiverWinZipYAMAHA SoftSynthesizer S-YXG70YOU DON'T KNOW JACK Volume 3
Hi
Gilco
You don't appear to be running any Anti-Virus software.
Install Anti-Virus software! Without any anti-virus software, your computer is wide open to infection. If you don't have any Anti-Virus software I strongly recommend you download
Avast! or AVG Free
You need to disable TeaTimer , so that it doesn't interfere with our fix.
This is a two step process .
First step:
[*]Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol) [*]If you have the new version 1.5, click once on Resident Protection , then right-click the Spybot icon again and make sure Resident Protection is now Unchecked . The Spybot icon in the System tray should now be now colorless. [*]If you have Version 1.4, Click on Exit Spybot S&D Resident Second step, For both versions :
[*]Open Spybot S&D [*]Click Mode , choose Advanced Mode [*]Go to the bottom of the vertical panel on the left, click Tools [*]Then, also in left panel, click Resident shows a red/white shield. [*]If your firewall raises a question, say OK [*]In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active [*]OK any prompts. [*]Use File, Exit to terminate Spybot [*]Reboot your machine for the changes to take effect.
Please download ATF Cleaner by Atribune .
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.
Download ComboFix by sUBs from here or here
**Save it to your desktop**
Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Thanks,
jpshortstuff
Here's the ComboFix log:
ComboFix 07-12-15.5 - Gili 2007-12-15 18:08:22.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1650 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Gili\Favorites\Online Security Guide.lnk
C:\WINDOWS\pppatc~1
C:\WINDOWS\system32\fskrrbal.dll
C:\WINDOWS\system32\gmsywodu.dll
C:\WINDOWS\system32\install.exe
C:\WINDOWS\system32\jkklm.dll
C:\WINDOWS\system32\labrrksf.ini
C:\WINDOWS\system32\lmuongcs.ini
C:\WINDOWS\system32\mlkkj.ini
C:\WINDOWS\system32\mlkkj.ini2
C:\WINDOWS\system32\qqeeljce.dll
C:\WINDOWS\system32\scgnouml.dll
C:\WINDOWS\system32\sks~1
C:\WINDOWS\system32\uegmhmcp.dll
C:\WINDOWS\system32\xgtiiftx.ini
C:\WINDOWS\system32\xtfiitgx.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-11-15 to 2007-12-15 )))))))))))))))))))))))))))))))
.
2007-12-15 18:12 . 2007-12-15 18:12 0 –a—— C:\WINDOWS\system32\mcrh.tmp
2007-12-15 00:36 . 2007-12-15 00:36 d–h—– C:\WINDOWS\PIF
2007-12-14 18:06 . 2007-12-14 18:06 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-14 18:06 . 2007-12-14 18:06 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-14 18:04 . 2007-12-14 18:04 d——– C:\Program Files\Apple Software Update
2007-12-14 18:04 . 2007-12-14 18:04 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-12-14 18:03 . 2007-12-14 18:03 d——– C:\Program Files\7-Zip
2007-12-12 01:31 . 2007-12-12 01:31 d——– C:\Documents and Settings\Gili\Application Data\Talkback
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-10 03:32 . 2007-12-10 12:44 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-10 03:26 . 2007-12-10 03:26 d——– C:\Program Files\Enigma Software Group
2007-12-10 01:57 . 2007-12-10 01:57 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft
2007-12-03 22:59 . 2007-12-03 23:14 d——– C:\Program Files\Photomatix
2007-12-03 22:38 . 2007-12-03 22:55 d——– C:\Program Files\eMule
2007-12-03 17:23 . 2007-12-03 17:24 d——– C:\Program Files\MioNetApplet
2007-11-29 17:31 . 2007-11-29 17:31 d——– C:\Program Files\Avanquest update
2007-11-29 17:31 . 2007-11-29 17:31 d——– C:\Documents and Settings\Gili\Application Data\InstallShield
2007-11-27 17:45 . 2007-11-27 17:45 d——– C:\Documents and Settings\Gili\Application Data\Canon
2007-11-27 17:39 . 2007-12-06 17:51 d——– C:\Program Files\Canon
2007-11-27 17:37 . 2007-12-06 17:50 d——– C:\Program Files\Common Files\Canon
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-14 23:07 ——— d—–w C:\Program Files\QuickTime
2007-12-14 23:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-10 06:23 ——— d—–w C:\Documents and Settings\Gili\Application Data\BitTorrent DNA
2007-12-01 22:09 ——— d—–w C:\Program Files\Java
2007-11-30 21:48 ——— d—–w C:\Documents and Settings\Gili\Application Data\Viewpoint
2007-11-30 21:46 ——— d—–w C:\Program Files\Kodak
2007-11-30 21:44 ——— d—–w C:\Program Files\LightSurf
2007-11-29 22:32 ——— d—–w C:\Program Files\Motorola Phone Tools
2007-11-29 22:31 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-29 22:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\BVRP Software
2007-11-24 18:34 ——— d—–w C:\Documents and Settings\Gili\Application Data\BitTorrent
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-10 02:22 ——— d—–w C:\Documents and Settings\Gili\Application Data\Bioshock
2007-11-02 23:23 ——— d—–w C:\Program Files\The Rosetta Stone
2007-11-02 21:10 ——— d—–w C:\Program Files\BitTorrent_DNA
2007-11-02 21:10 ——— d—–w C:\Program Files\BitTorrent
2007-10-30 04:13 ——— d—–w C:\Documents and Settings\Gili\Application Data\SecondLife
2007-10-29 20:00 ——— d—–w C:\Program Files\RosettaStoneLtdServices
2007-10-29 20:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\RosettaStoneLtdServices
2007-10-28 16:20 218,064 —-a-w C:\Documents and Settings\Gili\Application Data\GDIPFONTCACHEV1.DAT
2007-10-28 15:52 ——— d—–w C:\Program Files\AIM6
2007-10-28 15:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-21 17:46 ——— d—–w C:\Program Files\Easy CD-DA Extractor 9
2007-10-21 07:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2006-12-10 05:19 24,192 —-a-w C:\Documents and Settings\Gili\usbsermptxp.sys
2006-12-10 05:19 22,768 —-a-w C:\Documents and Settings\Gili\usbsermpt.sys
2006-12-10 05:12 92,064 —-a-w C:\Documents and Settings\Gili\mqdmmdm.sys
2006-12-10 05:12 9,232 —-a-w C:\Documents and Settings\Gili\mqdmmdfl.sys
2006-12-10 05:12 79,328 —-a-w C:\Documents and Settings\Gili\mqdmserd.sys
2006-12-10 05:12 66,656 —-a-w C:\Documents and Settings\Gili\mqdmbus.sys
2006-12-10 05:12 6,208 —-a-w C:\Documents and Settings\Gili\mqdmcmnt.sys
2006-12-10 05:12 5,936 —-a-w C:\Documents and Settings\Gili\mqdmwhnt.sys
2006-12-10 05:12 4,048 —-a-w C:\Documents and Settings\Gili\mqdmcr.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{875A1348-7674-42aa-ADAC-B4F36A004A2D}]
C:\Program Files\QdrDrive\QdrDrive8.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B1AE8E6B-34FA-3F0E-DA29-3BE6778F5BB1}]
C:\WINDOWS\system32\tygn.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1AA8E3A-63FA-365D-D829-3BE6778F03B7}]
C:\WINDOWS\system32\ybeupl.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 10:20]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 16:48]
"ALi5289"="C:\Program Files\ULI5289\ALi5289.exe" [2005-03-10 16:56]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" [2007-08-31 16:46]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 00:56 C:\WINDOWS\system32\rundll32.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hsijxizk]
hsijxizk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayyaxu]
yayyaxu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Gili^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Gili\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2007-11-02 16:10 286016 –a—— C:\Program Files\BitTorrent_DNA\dna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2003-06-26 17:50 212992 –a—— C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2003-06-25 10:24 49152 –a—— C:\Program Files\HP\HP Software Update\HPWuSchd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2001-07-09 04:50 155648 -ra—— C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pho]
C:\Documents and Settings\Gili\Application Data\A?pPatch\?hkntfs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrModule10]
C:\Program Files\QdrModule\QdrModule10.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrPack10]
C:\Program Files\QdrPack\QdrPack10.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RosettaStoneLtdController"=2 (0x2)
"IDriverT"=3 (0x3)
R0 m5289;m5289;C:\WINDOWS\system32\drivers\m5289.sys
R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys
R3 ULI5261;ULi Based Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN.SYS
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys
S3 PciCon;PciCon;\??\D:\PciCon.sys
S4 RosettaStoneLtdController;RosettaStoneLtdController;"C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c219698-e164-11db-b8e2-0015f27269c9}]
\Shell\AutoRun\command - F:\wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-14 23:04:29 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-13 04:41:07 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 2500 series#1147495092.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-15 18:15:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
**************************************************************************
.
Completion time: 2007-12-15 18:17:11 - machine was rebooted
.
2007-12-13 00:02:03 — E O F —
And here's the HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:18:56 PM, on 12/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\ULI5289\ALi5289.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Gili\Desktop\scanner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)
O2 - BHO: (no name) - {B1AE8E6B-34FA-3F0E-DA29-3BE6778F5BB1} - C:\WINDOWS\system32\tygn.dll (file missing)
O2 - BHO: (no name) - {E1AA8E3A-63FA-365D-D829-3BE6778F03B7} - C:\WINDOWS\system32\ybeupl.dll (file missing)
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: hsijxizk - hsijxizk.dll (file missing)
O20 - Winlogon Notify: yayyaxu - yayyaxu.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
–
End of file - 3913 bytes
Hi
1. Please
open Notepad
[*]Click Start , then Run [*]Type notepad .exe in the Run Box. 2. Now copy/paste the entire content of the codebox below into the Notepad window:
File::C:\WINDOWS\system32\mcrh.tmpC:\WINDOWS\system32\tygn.dllC:\WINDOWS\system32\ybeupl.dllC:\WINDOWS\system32\hsijxizk.dllC:\WINDOWS\system32\yayyaxu.dllFolder::C:\Documents and Settings\All Users\Application Data\ViewpointC:\Program Files\QdrDriveRegistry::[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{875A1348-7674-42aa-ADAC-B4F36A004A2D}][-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B1AE8E6B-34FA-3F0E-DA29-3BE6778F5BB1}][-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1AA8E3A-63FA-365D-D829-3BE6778F03B7}][-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hsijxizk][-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayyaxu]
3.
Save the above as
CFScript.txt
4. Then
drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
[external image: Posted Image]
5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
[*]Combofix.txt [*]A new HijackThis log .
Please do an online scan with Kaspersky WebScanner
Follow this link in Internet Explorer (Note: You must use Internet explorer to use Kaspersky ): Kaspersky WebScanner
You will be prompted to install an ActiveX component from Kaspersky,
Click Yes .
[*]The program will launch and then begin downloading the latest definition files:
[*]Once the files have been downloaded click on NEXT
[*]Now click on Scan Settings
[*]In the scan settings make sure that the following are selected: o Scan using the following Anti-Virus database:
Extended (if available otherwise Standard)
o Scan Options:
Scan Archives Scan Mail Bases
[*]Click OK
[*]Now under select a target to scan: Select My Computer
[*]The program will start and scan your system.
[*]The scan will take a while so be patient and let it run.
[*]Once the scan is complete it will display if your system has been infected. o Now click on the Save as Text button:
[*]Save the file to your desktop.
Please post the results of the Kaspersky scan in your next reply, along with a fresh HijackThis log.
Also, please describe how your computer is behaving at the moment.
Thanks,
jpshortstuff
ComboFix log:
ComboFix 07-12-15.5 - Gili 2007-12-15 19:10:46.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1634 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Gili\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\hsijxizk.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\tygn.dll
C:\WINDOWS\system32\yayyaxu.dll
C:\WINDOWS\system32\ybeupl.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((( Files Created from 2007-11-16 to 2007-12-16 )))))))))))))))))))))))))))))))
.
2007-12-15 19:08 . 2007-12-15 19:08 0 –a—— C:\Documents and Settings\Gili\.exe
2007-12-15 00:36 . 2007-12-15 00:36 d–h—– C:\WINDOWS\PIF
2007-12-14 18:06 . 2007-12-14 18:06 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-14 18:06 . 2007-12-14 18:06 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-14 18:04 . 2007-12-14 18:04 d——– C:\Program Files\Apple Software Update
2007-12-14 18:04 . 2007-12-14 18:04 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-12-14 18:03 . 2007-12-14 18:03 d——– C:\Program Files\7-Zip
2007-12-12 01:31 . 2007-12-12 01:31 d——– C:\Documents and Settings\Gili\Application Data\Talkback
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-10 03:32 . 2007-12-10 12:44 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-10 03:26 . 2007-12-10 03:26 d——– C:\Program Files\Enigma Software Group
2007-12-10 01:57 . 2007-12-10 01:57 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft
2007-12-03 22:59 . 2007-12-03 23:14 d——– C:\Program Files\Photomatix
2007-12-03 22:38 . 2007-12-03 22:55 d——– C:\Program Files\eMule
2007-12-03 17:23 . 2007-12-03 17:24 d——– C:\Program Files\MioNetApplet
2007-11-29 17:31 . 2007-11-29 17:31 d——– C:\Program Files\Avanquest update
2007-11-29 17:31 . 2007-11-29 17:31 d——– C:\Documents and Settings\Gili\Application Data\InstallShield
2007-11-27 17:45 . 2007-11-27 17:45 d——– C:\Documents and Settings\Gili\Application Data\Canon
2007-11-27 17:39 . 2007-12-06 17:51 d——– C:\Program Files\Canon
2007-11-27 17:37 . 2007-12-06 17:50 d——– C:\Program Files\Common Files\Canon
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-16 00:08 0 —-a-w C:\Documents and Settings\Gili\.exe
2007-12-14 23:07 ——— d—–w C:\Program Files\QuickTime
2007-12-14 23:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-10 06:23 ——— d—–w C:\Documents and Settings\Gili\Application Data\BitTorrent DNA
2007-12-01 22:09 ——— d—–w C:\Program Files\Java
2007-11-30 21:48 ——— d—–w C:\Documents and Settings\Gili\Application Data\Viewpoint
2007-11-30 21:46 ——— d—–w C:\Program Files\Kodak
2007-11-30 21:44 ——— d—–w C:\Program Files\LightSurf
2007-11-29 22:32 ——— d—–w C:\Program Files\Motorola Phone Tools
2007-11-29 22:31 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-29 22:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\BVRP Software
2007-11-24 18:34 ——— d—–w C:\Documents and Settings\Gili\Application Data\BitTorrent
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-10 02:22 ——— d—–w C:\Documents and Settings\Gili\Application Data\Bioshock
2007-11-02 23:23 ——— d—–w C:\Program Files\The Rosetta Stone
2007-11-02 21:10 ——— d—–w C:\Program Files\BitTorrent_DNA
2007-11-02 21:10 ——— d—–w C:\Program Files\BitTorrent
2007-10-30 04:13 ——— d—–w C:\Documents and Settings\Gili\Application Data\SecondLife
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 20:00 ——— d—–w C:\Program Files\RosettaStoneLtdServices
2007-10-29 20:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\RosettaStoneLtdServices
2007-10-28 16:20 218,064 —-a-w C:\Documents and Settings\Gili\Application Data\GDIPFONTCACHEV1.DAT
2007-10-28 15:52 ——— d—–w C:\Program Files\AIM6
2007-10-28 15:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-27 22:40 227,328 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-21 17:46 ——— d—–w C:\Program Files\Easy CD-DA Extractor 9
2007-09-17 18:23 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 18:23 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 18:22 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 18:22 739,840 —-a-w C:\WINDOWS\system32\DivX.dll
2006-12-10 05:19 24,192 —-a-w C:\Documents and Settings\Gili\usbsermptxp.sys
2006-12-10 05:19 22,768 —-a-w C:\Documents and Settings\Gili\usbsermpt.sys
2006-12-10 05:12 92,064 —-a-w C:\Documents and Settings\Gili\mqdmmdm.sys
2006-12-10 05:12 9,232 —-a-w C:\Documents and Settings\Gili\mqdmmdfl.sys
2006-12-10 05:12 79,328 —-a-w C:\Documents and Settings\Gili\mqdmserd.sys
2006-12-10 05:12 66,656 —-a-w C:\Documents and Settings\Gili\mqdmbus.sys
2006-12-10 05:12 6,208 —-a-w C:\Documents and Settings\Gili\mqdmcmnt.sys
2006-12-10 05:12 5,936 —-a-w C:\Documents and Settings\Gili\mqdmwhnt.sys
2006-12-10 05:12 4,048 —-a-w C:\Documents and Settings\Gili\mqdmcr.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 10:20]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 16:48]
"ALi5289"="C:\Program Files\ULI5289\ALi5289.exe" [2005-03-10 16:56]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" [2007-08-31 16:46]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 00:56 C:\WINDOWS\system32\rundll32.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Gili^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Gili\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2007-11-02 16:10 286016 –a—— C:\Program Files\BitTorrent_DNA\dna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2003-06-26 17:50 212992 –a—— C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2003-06-25 10:24 49152 –a—— C:\Program Files\HP\HP Software Update\HPWuSchd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2001-07-09 04:50 155648 -ra—— C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pho]
C:\Documents and Settings\Gili\Application Data\A?pPatch\?hkntfs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrModule10]
C:\Program Files\QdrModule\QdrModule10.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrPack10]
C:\Program Files\QdrPack\QdrPack10.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RosettaStoneLtdController"=2 (0x2)
"IDriverT"=3 (0x3)
R0 m5289;m5289;C:\WINDOWS\system32\drivers\m5289.sys
R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys
R3 ULI5261;ULi Based Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN.SYS
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys
S3 PciCon;PciCon;\??\D:\PciCon.sys
S4 RosettaStoneLtdController;RosettaStoneLtdController;"C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c219698-e164-11db-b8e2-0015f27269c9}]
\Shell\AutoRun\command - F:\wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-14 23:04:29 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-13 04:41:07 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 2500 series#1147495092.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe0/#Hewlett-Packard#hp psc 2500 series#1147495092
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-15 19:14:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-15 19:15:16
C:\ComboFix2.txt … 2007-12-15 18:17
.
2007-12-13 00:02:03 — E O F —
Kaspersky Log:
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, December 15, 2007 9:45:37 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 16/12/2007
Kaspersky Anti-Virus database records: 483501
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 130301
Number of viruses found: 9
Number of infected objects: 23
Number of suspicious objects: 0
Duration of the scan process: 01:15:05
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Gili\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\cert8.db Object is locked skipped
C:\Documents and Settings\Gili\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\history.dat Object is locked skipped
C:\Documents and Settings\Gili\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\key3.db Object is locked skipped
C:\Documents and Settings\Gili\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\parent.lock Object is locked skipped
C:\Documents and Settings\Gili\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Gili\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Gili\Application Data\Sun\Java\Deployment\cache\6.0\31\f410cdf-17c771a1/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Gili\Application Data\Sun\Java\Deployment\cache\6.0\31\f410cdf-17c771a1/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Gili\Application Data\Sun\Java\Deployment\cache\6.0\31\f410cdf-17c771a1/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\Documents and Settings\Gili\Application Data\Sun\Java\Deployment\cache\6.0\31\f410cdf-17c771a1 ZIP: infected - 3 skipped
C:\Documents and Settings\Gili\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Gili\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Gili\Local Settings\Application Data\AOL OCP\AIM\Storage\data\giliofleaves\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Gili\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Gili\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Gili\Local Settings\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Gili\Local Settings\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Gili\Local Settings\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Gili\Local Settings\Application Data\Mozilla\Firefox\Profiles\ub1zkrar.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Gili\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gili\Local Settings\History\History.IE5\MSHist012007121520071216\index.dat Object is locked skipped
C:\Documents and Settings\Gili\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gili\ntuser.dat Object is locked skipped
C:\Documents and Settings\Gili\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\fskrrbal.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\gmsywodu.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\qqeeljce.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\scgnouml.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\uegmhmcp.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\xtfiitgx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP115\A0016756.exe Infected: Trojan-Downloader.Win32.Tibs.rl skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP116\A0016959.dll Infected: not-a-virus:AdWare.Win32.AdBand.e skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP116\A0016960.exe Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP116\A0017004.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP117\A0017037.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP117\A0017164.exe Infected: Trojan-Downloader.Win32.Agent.fuc skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP117\A0017248.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP121\A0018831.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP121\A0018832.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP121\A0018833.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP121\A0018834.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP121\A0018835.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP121\A0018836.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP122\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
New HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:47:54 PM, on 12/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\ULI5289\ALi5289.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Gili\Desktop\scanner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
–
End of file - 3550 bytes
The PC seems fine (no pop-ups, although I usually get them at start-up) but Kaspersky picked up a buncha infections.
Hi
Run
ATFCleaner . Place a check mark next to
Java Cache , and then hit
Empty Selected .
I'm going to bug you about installing an Anti-Virus program now. Without one, you are very likely to get yourself more infections, and we don't like seeing return visitors.
As well as the Anti-Virus, you don't appear to have a Firewall running. It is equally critical to have both of these security softwares intalled and running, if you want to stand a chance of preventing infection.
Install a
firewall ! Without a firewall you are very susceptible to being hacked, and people could gain access to your computer. If you don't have a firewall I strongly recommend you download
ONE of the following:
1) ZoneAlarm
2) Agnitum
3) Sunbelt/Kerio
4) Comodo
After this, reboot your computer and post a fresh HijackThis log, and describe all (if any) remaining problems with your computer.
Thanks,
jpshortstuff
Installed Avast! and ran it. The PC rebooted and ran the scan upon reboot. Here's the log:
12/16/2007 10:58
Scan of all local drives
File C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP116\A0017000.exe\[UPX] is infected by Win32:PurityScan-Q [Trj], Deleted
File C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP117\A0017164.exe\[UPX] is infected by Win32:Agent-NMX [Trj], Deleted
File C:\System Volume Information\_restore{AEA19F05-4693-4698-BC28-D1A5D38AFB63}\RP117\A0017247.exe is infected by Win32:Adware-gen [Adw], Deleted
Number of searched folders: 8580
Number of tested files: 122955
Number of infected files: 3
HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:56:02 AM, on 12/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\ULI5289\ALi5289.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Documents and Settings\Gili\Desktop\scanner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
–
End of file - 4405 bytes
The PC seems fine, although Avast! didn't pick up as many infections as Kaspersky did yesterday.
The items found by both Avast! and Kaspersky are nothing to worry about, they are leftovers that we will deal with in the final post.How about the firewall, are you going to get one of those?
Hi
Gilco
Log looks good
Click
Start >>
Run , and then type
ComboFix /u and hit enter.
Re-enable TeaTimer:
Open Spybot Click on Tools in bottom left hand corner. Click on Resident . Check Resident "TeaTimer" box. Click on Allow change ONLY to popup box with: Entry: SpybotSD Teatimer Click on Mode , select Default mode Close Spybot
Now that you appear to be clean, theres just a few steps I'd like you to take to prevent any future infections.
Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.
Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.
Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED] :
SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
Freely available: Download SpywareBlaster
Download and install the free version of WinPatrol . This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein:
So How Did I Get Infected In First Place
Glad we could be of assistance.
Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Stay Clean!
jpshortstuff
All done. This part is unclear:
# Click on Allow change ONLY to popup box with:
# Entry: SpybotSD Teatimer
Where would I find that in SpyBot?
When you "Check Resident "TeaTimer" box." it usually comes up with various popup boxes. One of them is "Entry: SpybotSD Teatimer", this one you can allow, the rest deny.
If you didn't get them, don't worry I think thats fine.
Alright! Everything looks fine. Thanks a lot for the help!!!