This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Dropper Agent & Virtumonde

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hands up - I was on the net without noticing AVG needed an update - AVG warnings appeared and clicked heal and pop ups started appearing - updated AVG but the control panel went unresponsive - uninstalled it - reinstalled it 40 + warnings about the trojan , at that stage went on the net and found various forums where this was discussed. I have used yourselves before to great effect but was unable to log in nor get response from password retrieval so re registered on back up email.I have lost start progs , all restore points and do not know how to go about getting system back to normal. thanks
sorry forgot to add this

Logfile of HijackThis v1.99.1
Scan saved at 13:41:01, on 17/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\??crosoft\l?gonui.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\paul\APPLIC~1\SKS~1\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/default….;l=en&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/default….;l=en&s=gen
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=1070309
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqpp.exe
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA519] command /c del "C:\WINDOWS\system32\ssqpp.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1603] cmd /c del "C:\WINDOWS\system32\ssqpp.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [Tair] "C:\DOCUME~1\paul\APPLIC~1\SKS~1\iexplore.exe" -vt ndrv
O4 - HKCU\..\Run: [Candqs] "C:\Program Files\??crosoft\l?gonui.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6129] command /c del "C:\WINDOWS\system32\ssqpp.dll_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD704] cmd /c del "C:\WINDOWS\system32\ssqpp.dll_tobedeleted"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.onerateld.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://www.msnusers.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Br…OCX/flashax.cab
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Please remove the version of HijackThis you currently have on your pc and follow the instructions below.

Install HijackThis

  • Download HJTInstall.exe to your Desktop.
  • Doubleclick HJTInstall.exe to install it.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed, it will launch Hijackthis.
  • Close this window for now
  • Navigate to C:\Program Files\Trend Micro\HijackThis and locate the hijackthis.exe file
  • Right-click the file and select Rename. Name it iseeu.exe
  • Close all open windows and double click the HijackThis icon on your Desktop to run the program.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Copy/Paste the log to your next reply please.
Don't use the Analyse This button, its findings are dangerous if misinterpreted.
Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
thanks scotty - uninstalled and reinstalled ,renamed Hijackthis.exe and ran application ,copy of log follows - after that is the uninstall list you requested

Hijackthis log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:55:50, on 17/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\??crosoft\l?gonui.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\paul\APPLIC~1\SKS~1\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\iseeu.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/default….;l=en&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/default….;l=en&s=gen
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=1070309
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqpp.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {160995AD-611A-4134-BB0E-1DA172192CA0} - C:\WINDOWS\system32\ssqpp.dll
O2 - BHO: (no name) - {464BF21A-60A6-477F-ADB8-61A3E78AF1EC} - C:\WINDOWS\system32\julfdorh.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {B57E8055-F562-4032-973C-D0FE32ABFE84} - C:\Program Files\NetMeeting\ryxybudaC:\WINDOWS\system32\k8\tycodllz83122.exe.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA519] command /c del "C:\WINDOWS\system32\ssqpp.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1603] cmd /c del "C:\WINDOWS\system32\ssqpp.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [Tair] "C:\DOCUME~1\paul\APPLIC~1\SKS~1\iexplore.exe" -vt ndrv
O4 - HKCU\..\Run: [Candqs] "C:\Program Files\??crosoft\l?gonui.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.onerateld.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://www.msnusers.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Br…OCX/flashax.cab
O20 - Winlogon Notify: ddcdaay - ddcdaay.dll (file missing)
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

–
End of file - 5598 bytes


uninstall list

ABBYY FineReader 4.0 Sprint
AC3Filter (remove only)
Adobe Flash Player ActiveX
Adobe Reader 7.0.8
Adobe Shockwave Player
Anim-FX
Apollo DivX to DVD Creator 4.5.7
Betfair Poker
Broadband Help
CCleaner (remove only)
Dell CinePlayer
Dell Driver Reset Tool
Dell Network Assistant
Dell Support 3.2.1
Dell Support Center
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Indeo® software
Intel® Graphics Media Accelerator Driver
Intel® Matrix Storage Manager
Java™ 6 Update 3
Kaspersky Online Scanner
Lemmings Revolution
Macromedia Dreamweaver MX 2004
Macromedia Extension Manager
Macromedia HomeSite+
MCU
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MSXML 4.0 SP2 (KB936181)
Paint Shop Pro 5.03 CD
Picturetrail Photo Editor 1.9.0
RealPlayer
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
SearchAssist
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Sonic Activation Module
Sonic Update Manager
Spybot - Search & Destroy 1.4
Turbo Lister 2
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
URL Assistant
Victor Chandler
Web Page Tune Up 1.5.1
WebCyberCoach 3.2 Dell
Winamp
Windows Live OneCare safety scanner
Windows Media Format Runtime
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
WinRAR archiver
Yahoo! Toolbar
but as I tried to explain inmy original message it was using AVG to get things deleted using the messages -and AVG Contro Centre was unresponsive - I uninstalled it downloaded latest installed it updated it and the same thing happened, are you sure its required at this stage?
Hi

Sorry. Have you tried another anti-virus such as Avast? I will have a tough time trying to clean you up when you will need to go back on the net, and may well just get reinfected.

Try installing this first
Avast free

The only pain with that one is that you have to register once you have installed. If it fails too, we will crack on and try cleaning you up enough to get an av working.
Hello

Please do the following in the order I have set out.

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.


If you already have Combofix, please delete that copy and download it again as it's being updated regularly.

Please download Combofix from Bleeping Computer.

If you can't download it from there, please try these 2 alternative sites:

Forospyware
Geeks to Go

  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Click Start>Run copy/paste or type "%userprofile%\desktop\combofix.exe" /killall into the Run box and click OK.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
Vundofix.txt
ComboFix.txt
New HijackThis log taken after the above scan has run
ok done that

Vundofix didnt find anything? - did notice last night S&D listed infections and Vundo had disappeared from the list.
Combofix log

ComboFix 08-01-18.4 - paul 2008-01-18 10:10:42.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.677 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\paul\APPLIC~1\SKS~1\iexplore.exe
C:\Documents and Settings\paul\Application Data\SKS~1
C:\Documents and Settings\paul\Application Data\SKS~1\??sks\
C:\Documents and Settings\paul\Application Data\SKS~1\iexplore .exe
C:\Documents and Settings\paul\Application Data\SKS~1\iexplore.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashDisp .exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\crosof~1
C:\Program Files\crosof~1\l?gonui.exe
C:\Program Files\outerinfo
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\k8
C:\WINDOWS\system32\k8\tycodllz83122.exe
C:\WINDOWS\system32\p2
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\ppqss.ini
C:\WINDOWS\system32\ppqss.ini2
C:\WINDOWS\system32\RCX7.tmp
C:\WINDOWS\system32\ssqpp.dll

C:\Program Files\Alwil Software\Avast4\ashDisp .exe —> QooBox
.
.
((((((((((((((((((((((((( Files Created from 2007-12-18 to 2008-01-18 )))))))))))))))))))))))))))))))
.

2008-01-18 09:58 . 2008-01-18 09:58 d——– C:\VundoFix Backups
2008-01-17 21:41 . 2008-01-17 21:41 d——– C:\Program Files\Alwil Software
2008-01-17 21:41 . 2007-12-04 13:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-01-17 21:41 . 2004-01-09 09:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-01-17 21:41 . 2007-12-04 12:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2008-01-17 21:41 . 2007-12-04 14:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-17 21:41 . 2007-12-04 14:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-17 21:41 . 2007-12-04 14:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-17 21:41 . 2007-12-04 14:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-17 21:41 . 2007-12-04 14:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-17 17:48 . 2008-01-17 17:48 d——– C:\Program Files\Trend Micro
2008-01-17 12:47 . 2008-01-18 09:54 338,432 –a—— C:\WINDOWS\system32\ssqpp.exe
2008-01-17 12:33 . 2008-01-17 12:33 d——– C:\Program Files\CCleaner
2008-01-17 12:17 . 2008-01-17 12:17 d——– C:\Program Files\WebCyberCoach
2008-01-17 11:13 . 2008-01-15 16:30 60,928 –a—— C:\WINDOWS\system32\julfdorh.dll
2008-01-17 11:11 . 2008-01-17 12:13 d——– C:\WINDOWS\system32\edcA01
2008-01-17 11:11 . 2008-01-17 11:11 d——– C:\Temp\Ryuan1
2008-01-17 11:11 . 2008-01-18 10:12 d——– C:\Temp
2008-01-12 12:23 . 2004-05-14 16:53 462,848 –a—— C:\WINDOWS\system32\ltkrn13n.dll
2008-01-12 12:23 . 2004-05-14 16:53 450,560 –a—— C:\WINDOWS\system32\ltimg13n.dll
2008-01-12 12:23 . 2004-05-14 16:53 401,408 –a—— C:\WINDOWS\system32\lfcmp13n.dll
2008-01-12 12:23 . 2004-05-14 16:53 299,008 –a—— C:\WINDOWS\system32\ltdis13n.dll
2008-01-12 12:23 . 2004-01-12 02:09 206,336 –a—— C:\WINDOWS\system32\ltefx13n.dll
2008-01-12 12:23 . 2004-05-14 16:53 163,840 –a—— C:\WINDOWS\system32\ltfil13n.dll
2008-01-12 12:23 . 2003-11-04 15:10 69,632 –a—— C:\WINDOWS\system32\lfgif13n.dll
2008-01-12 12:23 . 2004-05-14 16:53 57,344 –a—— C:\WINDOWS\system32\lfbmp13n.dll
2008-01-01 22:07 . 2008-01-08 10:02 d——– C:\Documents and Settings\All Users\Application Data\Kontiki
2008-01-01 22:07 . 2008-01-01 22:07 d——– C:\Documents and Settings\All Users\Application Data\Channel4
2007-12-19 10:50 . 2007-12-19 10:50 d——– C:\Documents and Settings\All Users\Application Data\Dell
2007-12-19 10:49 . 2007-12-19 10:49 d——– C:\Documents and Settings\All Users\Application Data\SupportSoft
2007-12-19 10:48 . 2007-12-19 10:48 d——– C:\Program Files\Dell Support Center
2007-12-19 10:48 . 2007-12-19 10:48 d——– C:\Program Files\Common Files\supportsoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-18 10:14 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-17 13:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-17 12:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-01-17 12:55 ——— d—–w C:\Program Files\Azureus
2008-01-17 12:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\GTek
2008-01-17 12:13 ——— d—–w C:\Program Files\QuickTime
2008-01-17 12:13 ——— d—–w C:\Program Files\Dell Support
2008-01-17 11:36 ——— d—–w C:\Documents and Settings\paul\Application Data\Azureus
2008-01-16 12:51 ——— d—–w C:\Program Files\Paint Shop Pro 5
2008-01-08 10:05 ——— d—–w C:\Program Files\Betfair
2007-12-18 10:56 ——— d—–w C:\Documents and Settings\paul\Application Data\LimeWire
2007-12-13 21:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\MGS
2007-12-11 18:04 ——— d—–w C:\Program Files\Cryer
2007-12-11 11:35 ——— d—–w C:\Program Files\Packard Bell Diamond 1200Plus
2007-12-11 11:32 ——— d—–w C:\Program Files\ABBYY FineReader 4.0 Sprint
2007-12-11 11:31 ——— d—–w C:\Program Files\Winamp
2007-12-11 11:31 ——— d—–w C:\Program Files\CDBurnerXP
2007-12-11 11:31 ——— d—–w C:\Documents and Settings\paul\Application Data\Sonic
2007-12-11 10:52 ——— d—–w C:\Program Files\Common Files\Adobe
2007-12-06 15:06 0 —-a-w C:\Documents and Settings\paul\Application Data\wklnhst.dat
2007-12-04 15:47 ——— d—–w C:\Documents and Settings\paul\Application Data\Leadertech
2007-11-26 20:19 ——— d—–w C:\Documents and Settings\paul\Application Data\PictureTrail
2007-11-22 12:10 ——— d—–w C:\Documents and Settings\paul\Application Data\AVG7
2007-11-22 12:06 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-22 11:59 ——— d—–w C:\Program Files\McAfee
2007-11-22 11:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2007-09-12 14:14 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2007-09-03 17:05 548 —-a-w C:\Program Files\Untitled-5.htm
2007-06-01 17:43 88 –sh–r C:\WINDOWS\system32\6CEEDA1492.sys
2007-06-02 13:28 88 –sh–r C:\WINDOWS\system32\D0A54F966D.sys
2007-06-02 13:28 5,642 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{464BF21A-60A6-477F-ADB8-61A3E78AF1EC}]
2008-01-15 16:30 60928 –a—— C:\WINDOWS\system32\julfdorh.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B57E8055-F562-4032-973C-D0FE32ABFE84}]
C:\Program Files\NetMeeting\ryxybudaC:\WINDOWS\system32\k8\tycodllz83122.exe.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tair"="C:\DOCUME~1\paul\APPLIC~1\SKS~1\iexplore.exe" [ ]
"Candqs"="C:\Program Files\??crosoft\l?gonui.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 17:20 282624 C:\WINDOWS\stsystra.exe]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 13:00 79224]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcdaay]
ddcdaay.dll

R2 hnmwrlspkt;HomeNet Manager Wireless Protocol;C:\WINDOWS\system32\DRIVERS\hnm_wrls_pkt.sys [2006-07-14 01:01]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
R2 wsppkt;Wireless Security Protocol;C:\WINDOWS\system32\DRIVERS\wsp_pkt.sys [2006-07-14 01:02]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2006-06-05 03:39]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-18 10:14:31
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-18 10:18:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-18 10:18:04
ComboFix2.txt 2007-09-01 19:21:37
.
2008-01-09 19:01:14 — E O F —

HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:21:26, on 18/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\stsystra.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\iseeu.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/default….;l=en&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/default….;l=en&s=gen
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=1070309
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {464BF21A-60A6-477F-ADB8-61A3E78AF1EC} - C:\WINDOWS\system32\julfdorh.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {B57E8055-F562-4032-973C-D0FE32ABFE84} - C:\Program Files\NetMeeting\ryxybudaC:\WINDOWS\system32\k8\tycodllz83122.exe.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Tair] "C:\DOCUME~1\paul\APPLIC~1\SKS~1\iexplore.exe" -vt ndrv
O4 - HKCU\..\Run: [Candqs] "C:\Program Files\??crosoft\l?gonui.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.onerateld.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://www.msnusers.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Br…OCX/flashax.cab
O20 - Winlogon Notify: ddcdaay - ddcdaay.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

–
End of file - 5709 bytes
Hi

Because of the nature of newer malware we need to take appropriate measures to ensure we are covered in the event of something going wrong.

Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System

[external image: Posted Image]


Download the file & save it as it's originally named, next to ComboFix.exe.

[external image: Posted Image]

Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log.

Please do not reboot your machine until we have reviewed the log.
log as requested WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
Hi

I suggest uninstalling AVG again. It may conflict with Avast and slow your computer down.

Go to http://virusscan.jotti.org
Copy the following line into the white textbox:
C:\WINDOWS\system32\6CEEDA1492.sys
Click Submit.
Please post the results of this scan to this thread.

Do the same for the following:
C:\Program Files\Untitled-5.htm
C:\WINDOWS\system32\D0A54F966D.sys


Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\ssqpp.exe 
C:\WINDOWS\system32\julfdorh.dll
C:\WINDOWS\system32\edcA01

Folder::
C:\VundoFix Backups
C:\Program Files\NetMeeting\ryxybuda
C:\Program Files\??crosoft

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{464BF21A-60A6-477F-ADB8-61A3E78AF1EC}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B57E8055-F562-4032-973C-D0FE32ABFE84}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tair"=-
"Candqs"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcdaay]

DirLook::
C:\Temp\Ryuan1
C:\Program Files\Cryer

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
Jotti results
ComboFix.txt
New HJT log taken after the above scan has run
ok AVG was uninstalled earlier - it no longer appears in the uninstall list

all the items you requested are below.

Service
Service load: 0% 100%

File: 6CEEDA1492.sys
Status: OK
MD5: 83308d2c2e6841a3b962f5c5cc21e362
Packers detected: -
Bit9 reports: File not found

Scanner results
Scan taken on 19 Jan 2008 09:53:12 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing

Service
Service load: 0% 100%

File: Untitled-5.htm
Status: OK
MD5: bced10f9a5ecdf9901e660af08354864
Packers detected: -
Bit9 reports: File not found

Scanner results
Scan taken on 19 Jan 2008 09:57:19 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing



Service load: 0% 100%

File: D0A54F966D.sys
Status: OK
MD5: 980b3c827f8e91a8a5d48b8f0624858f
Packers detected: -
Bit9 reports: File not found

Scanner results
Scan taken on 19 Jan 2008 10:05:29 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing

ComboFix 08-01-18.4 - paul 2008-01-19 10:14:01.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.654 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\paul\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\edcA01
C:\WINDOWS\system32\julfdorh.dll
C:\WINDOWS\system32\ssqpp.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\VundoFix Backups

.
((((((((((((((((((((((((( Files Created from 2007-12-19 to 2008-01-19 )))))))))))))))))))))))))))))))
.

2008-01-18 17:54 . 2004-08-03 23:00 260,272 –a—— C:\cmldr
2008-01-18 17:54 . 2007-03-23 12:31 211 –a—— C:\Boot.bak
2008-01-17 21:41 . 2008-01-17 21:41 d——– C:\Program Files\Alwil Software
2008-01-17 21:41 . 2007-12-04 13:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-01-17 21:41 . 2004-01-09 09:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-01-17 21:41 . 2007-12-04 12:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2008-01-17 21:41 . 2007-12-04 14:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-17 21:41 . 2007-12-04 14:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-17 21:41 . 2007-12-04 14:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-17 21:41 . 2007-12-04 14:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-17 21:41 . 2007-12-04 14:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-17 17:48 . 2008-01-17 17:48 d——– C:\Program Files\Trend Micro
2008-01-17 12:33 . 2008-01-17 12:33 d——– C:\Program Files\CCleaner
2008-01-17 12:17 . 2008-01-17 12:17 d——– C:\Program Files\WebCyberCoach
2008-01-17 11:11 . 2008-01-17 12:13 d——– C:\WINDOWS\system32\edcA01
2008-01-17 11:11 . 2008-01-17 11:11 d——– C:\Temp\Ryuan1
2008-01-17 11:11 . 2008-01-18 10:12 d——– C:\Temp
2008-01-12 12:23 . 2004-05-14 16:53 462,848 –a—— C:\WINDOWS\system32\ltkrn13n.dll
2008-01-12 12:23 . 2004-05-14 16:53 450,560 –a—— C:\WINDOWS\system32\ltimg13n.dll
2008-01-12 12:23 . 2004-05-14 16:53 401,408 –a—— C:\WINDOWS\system32\lfcmp13n.dll
2008-01-12 12:23 . 2004-05-14 16:53 299,008 –a—— C:\WINDOWS\system32\ltdis13n.dll
2008-01-12 12:23 . 2004-01-12 02:09 206,336 –a—— C:\WINDOWS\system32\ltefx13n.dll
2008-01-12 12:23 . 2004-05-14 16:53 163,840 –a—— C:\WINDOWS\system32\ltfil13n.dll
2008-01-12 12:23 . 2003-11-04 15:10 69,632 –a—— C:\WINDOWS\system32\lfgif13n.dll
2008-01-12 12:23 . 2004-05-14 16:53 57,344 –a—— C:\WINDOWS\system32\lfbmp13n.dll
2008-01-01 22:07 . 2008-01-08 10:02 d——– C:\Documents and Settings\All Users\Application Data\Kontiki
2008-01-01 22:07 . 2008-01-01 22:07 d——– C:\Documents and Settings\All Users\Application Data\Channel4
2007-12-19 10:50 . 2007-12-19 10:50 d——– C:\Documents and Settings\All Users\Application Data\Dell
2007-12-19 10:49 . 2007-12-19 10:49 d——– C:\Documents and Settings\All Users\Application Data\SupportSoft
2007-12-19 10:48 . 2007-12-19 10:48 d——– C:\Program Files\Dell Support Center
2007-12-19 10:48 . 2007-12-19 10:48 d——– C:\Program Files\Common Files\supportsoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-19 09:43 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-17 13:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-17 12:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-01-17 12:55 ——— d—–w C:\Program Files\Azureus
2008-01-17 12:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\GTek
2008-01-17 12:13 ——— d—–w C:\Program Files\QuickTime
2008-01-17 12:13 ——— d—–w C:\Program Files\Dell Support
2008-01-17 11:36 ——— d—–w C:\Documents and Settings\paul\Application Data\Azureus
2008-01-16 12:51 ——— d—–w C:\Program Files\Paint Shop Pro 5
2008-01-08 10:05 ——— d—–w C:\Program Files\Betfair
2007-12-18 10:56 ——— d—–w C:\Documents and Settings\paul\Application Data\LimeWire
2007-12-13 21:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\MGS
2007-12-11 18:04 ——— d—–w C:\Program Files\Cryer
2007-12-11 11:35 ——— d—–w C:\Program Files\Packard Bell Diamond 1200Plus
2007-12-11 11:32 ——— d—–w C:\Program Files\ABBYY FineReader 4.0 Sprint
2007-12-11 11:31 ——— d—–w C:\Program Files\Winamp
2007-12-11 11:31 ——— d—–w C:\Program Files\CDBurnerXP
2007-12-11 11:31 ——— d—–w C:\Documents and Settings\paul\Application Data\Sonic
2007-12-11 10:52 ——— d—–w C:\Program Files\Common Files\Adobe
2007-12-06 15:06 0 —-a-w C:\Documents and Settings\paul\Application Data\wklnhst.dat
2007-12-04 15:47 ——— d—–w C:\Documents and Settings\paul\Application Data\Leadertech
2007-11-26 20:19 ——— d—–w C:\Documents and Settings\paul\Application Data\PictureTrail
2007-11-22 12:10 ——— d—–w C:\Documents and Settings\paul\Application Data\AVG7
2007-11-22 12:06 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-22 11:59 ——— d—–w C:\Program Files\McAfee
2007-11-22 11:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2007-11-14 07:26 450,560 ——w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 09:55 3,065,856 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 17:40 227,328 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 17:40 227,328 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-09-12 14:14 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2007-09-03 17:05 548 —-a-w C:\Program Files\Untitled-5.htm
2007-06-01 17:43 88 –sh–r C:\WINDOWS\system32\6CEEDA1492.sys
2007-06-02 13:28 88 –sh–r C:\WINDOWS\system32\D0A54F966D.sys
2007-06-02 13:28 5,642 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Program Files\Cryer —-

2007-12-11 18:04 72 –a—— C:\Program Files\Cryer\Web Page Tune Up\BCWebPageTuneUp.url
2007-12-11 18:04 682266 –a—— C:\Program Files\Cryer\Web Page Tune Up\unins000.exe
2007-12-11 18:04 1933 –a—— C:\Program Files\Cryer\Web Page Tune Up\unins000.dat
2007-01-01 21:35 672768 –a—— C:\Program Files\Cryer\Web Page Tune Up\BCWebPageTuneUp.exe

—- Directory of C:\Temp\Ryuan1 —-

2008-01-17 11:11 1858 –a—— C:\Temp\Ryuan1\tepU.log


((((((((((((((((((((((((((((( snapshot@2008-01-18_10.17.56.29 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-18 10:10:26 1,200,128 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-19 10:13:51 1,200,128 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-18 10:10:26 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-19 10:13:51 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-18 10:10:26 1,200,128 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-19 10:13:51 1,200,128 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-18 10:10:26 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-19 10:13:51 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-18 10:10:26 5,107,712 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-19 10:13:51 5,107,712 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-18 10:10:27 241,664 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-19 10:13:51 241,664 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-19 09:42:49 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_630.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 17:20 282624 C:\WINDOWS\stsystra.exe]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 13:00 79224]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00 15360]

R2 hnmwrlspkt;HomeNet Manager Wireless Protocol;C:\WINDOWS\system32\DRIVERS\hnm_wrls_pkt.sys [2006-07-14 01:01]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
R2 wsppkt;Wireless Security Protocol;C:\WINDOWS\system32\DRIVERS\wsp_pkt.sys [2006-07-14 01:02]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2006-06-05 03:39]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-19 10:16:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-19 10:16:56
ComboFix-quarantined-files.txt 2008-01-19 10:16:36
ComboFix2.txt 2008-01-18 10:18:06
ComboFix3.txt 2007-09-01 19:21:37
.
2008-01-09 19:01:14 — E O F —





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:19, on 19/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\stsystra.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\iseeu.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/default….;l=en&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/default….;l=en&s=gen
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=1070309
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.onerateld.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://www.msnusers.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Br…OCX/flashax.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

–
End of file - 5174 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI