spenno
Topic Starter
Hi
I have read some of the threads and tried some of the approaches to get rid of my trojan virus. I downloaded a screensaver and it came through that. I have:
It seems to get rid of it but then it comes back when I start my computer from cold.
It shows as a flashing item in my taskbar bottom right and it says :security warning: your computer may be infected with harmful or unwanted software.
Here are my reports

Hijack this
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:55, on 2008-01-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
D:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe
D:\Program Files\Spyware Doctor\pctsAuxs.exe
D:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
D:\Programmes\IObit SmartDefrag\IObit SmartDefrag.exe
D:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Program Files\Act.Outlook.Service.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
D:\Program Files\RssReader.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Mozilla Firefox\plugins\MyWebEx\419\mwmpad.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
D:\Program Files\Office12\ONENOTEM.EXE
D:\Program Files\Desktop Clock\DekctopClock.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Downloads\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.uk.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.uk.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {157B8898-115A-4E87-9323-54CC0D9493AA} - C:\WINDOWS\system32\pmnlj.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [SmartDefrag] "D:\Programmes\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [MSDisp32] rundll32.exe C:\WINDOWS\system32\drvzah.dll,startup
O4 - HKLM\..\Run: [MSDrive] rundll32.exe C:\WINDOWS\system32\drvtiz.dll,startup
O4 - HKLM\..\Run: [SDTray] "D:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [ISTray] "D:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Act.Outlook.Service] "D:\Program Files\Act.Outlook.Service.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [RssReader] D:\Program Files\RssReader.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Sky Alerts.lnk = C:\Program Files\Sky Alerts\skinker.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = D:\Program Files\Office12\ONENOTEM.EXE
O4 - Startup: Desktop Clock.lnk = D:\Program Files\Desktop Clock\DekctopClock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Start WebEx MeetMeNow.LNK = C:\Program Files\Mozilla Firefox\plugins\MyWebEx\419\mwmpad.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact… - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Start WebEx MeetMeNow - {F5AD6CC5-776C-4DBB-B38F-F5404A3582F3} - C:\PROGRA~1\MOZILL~1\plugins\MyWebEx\419\mwmie.dll
O9 - Extra 'Tools' menuitem: Start WebEx MeetMeNow - {F5AD6CC5-776C-4DBB-B38F-F5404A3582F3} - C:\PROGRA~1\MOZILL~1\plugins\MyWebEx\419\mwmie.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Grapevine-Group.local
O17 - HKLM\Software\..\Telephony: DomainName = Grapevine-Group.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Grapevine-Group.local
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\Program Files\Spyware Doctor\pctsSvc.exe
–
End of file - 9917 bytes
COMBOFIX
ComboFix 08-01-29.1 - dean 2008-01-29 22:43:11.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.605 [GMT 0:00]
Running from: D:\Downloads\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))
.
2008-01-30 03:01 . 2008-01-30 03:01 d——– C:\WINDOWS\LastGood
2008-01-29 22:09 . 2008-01-29 22:09 d——– C:\Program Files\Trend Micro
2008-01-29 21:47 . 2008-01-29 21:47 d——– C:\Documents and Settings\dean.GRAPEVINE-GROUP\.SunDownloadManager
2008-01-28 20:47 . 2008-01-28 20:47 d——– C:\VundoFix Backups
2008-01-28 16:12 . 2008-01-28 16:12 65 –a—— C:\WINDOWS\wininit.ini
2008-01-28 16:02 . 2008-01-28 16:02 103,936 –a—— C:\WINDOWS\system32\drvtiz.dll
2008-01-28 16:00 . 2008-01-28 16:00 18,944 –a—— C:\WINDOWS\system32\drvzah.dll
2008-01-14 11:47 . 2008-01-14 11:47 d——– C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\Alibre Design
2008-01-14 11:15 . 2008-01-14 11:15 d——– C:\Program Files\Alibre Design Help
2008-01-14 11:14 . 2008-01-14 11:14 d——– C:\Program Files\PDFCreator Toolbar
2008-01-14 11:14 . 2008-01-14 11:14 264,097 –a—— C:\WINDOWS\PDFCreator_Toolbar_Uninstaller_8484.exe
2008-01-14 11:14 . 1998-06-24 01:00 137,000 –a—— C:\WINDOWS\system32\MSMAPI32.OCX
2008-01-14 11:14 . 2001-10-28 17:42 116,224 –a—— C:\WINDOWS\system32\pdfcmnnt.dll
2008-01-14 11:14 . 1998-07-06 01:00 23,552 –a—— C:\WINDOWS\system32\MSMPIDE.DLL
2008-01-14 11:13 . 2008-01-14 11:13 852 –a—— C:\WINDOWS\system32\wjview.exe.manifest
2008-01-14 11:12 . 2008-01-14 11:12 d——– C:\Documents and Settings\All Users\Application Data\Alibre Design
2008-01-14 11:12 . 2008-01-14 11:12 36 –a—— C:\WINDOWS\system32\InstallAlibre.config
2008-01-11 17:28 . 2008-01-11 17:28 268 –ah—– C:\sqmdata11.sqm
2008-01-11 17:28 . 2008-01-11 17:28 244 –ah—– C:\sqmnoopt11.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 12:39 77,383 —-a-w C:\WINDOWS\system32\atasnt40.dll
2008-01-14 11:01 155,995 —-a-w C:\WINDOWS\java\Packages\FDRN5ZV9.ZIP
2007-12-27 18:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\NtiDvdCopy
2007-12-14 10:09 ——— d—–w C:\Program Files\Windows Live Toolbar
2007-12-14 10:09 ——— d—–w C:\Program Files\Windows Live Favorites
2007-12-14 09:58 ——— d-sh–w C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-14 09:58 ——— d—–w C:\Program Files\Windows Live
2007-12-14 09:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-11 13:38 ——— d—–w C:\Program Files\Macromedia
2007-12-10 14:53 81,288 —-a-w C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-10 14:53 66,952 —-a-w C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-10 14:53 41,864 —-a-w C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-10 14:53 29,576 —-a-w C:\WINDOWS\system32\drivers\kcom.sys
2007-12-09 11:46 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\Locktime
2007-12-09 11:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Locktime
2007-12-09 10:26 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\PC Tools
2007-11-30 11:33 32 —-a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-30 11:33 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\skypePM
2007-11-30 11:31 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\Skype
2007-11-30 11:30 ——— d—–w C:\Program Files\Skype
2007-11-30 11:30 ——— d—–w C:\Program Files\Common Files\Skype
2007-11-30 11:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-11-30 09:21 ——— d—–w C:\Program Files\MSXML 6.0
2007-11-28 17:03 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\IsolatedStorage
2007-11-28 16:52 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-11-28 16:51 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\ACT
2007-11-28 16:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\ACT
2007-11-14 07:26 450,560 —-a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 10:16 3,058,688 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39 1289000]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"Act.Outlook.Service"="D:\Program Files\Act.Outlook.Service.exe" [2006-10-25 15:57 9728]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-11-16 12:36 21760296]
"RssReader"="D:\Program Files\RssReader.exe" [2004-04-04 17:21 1077248]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ePower_DMC"="C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-08-10 19:29 352256]
"SmartDefrag"="D:\Programmes\IObit SmartDefrag\IObit SmartDefrag.exe" [2008-01-07 23:29 2743552]
"MSDisp32"="C:\WINDOWS\system32\drvzah.dll" [2008-01-28 16:00 18944]
"MSDrive"="C:\WINDOWS\system32\drvtiz.dll" [2008-01-28 16:02 103936]
"SDTray"="D:\Program Files\Spyware Doctor\SDTrayApp.exe" [ ]
"ISTray"="D:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 14:53 1103752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 09:06 219136]
C:\Documents and Settings\dean.GRAPEVINE-GROUP\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 110592]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Start WebEx MeetMeNow.LNK - C:\Program Files\Mozilla Firefox\plugins\MyWebEx\419\mwmpad.exe [2007-05-01 19:16:49 496968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\pmnlj
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 17:14]
R1 OsaFsLoc;OsaFsLoc;C:\WINDOWS\system32\drivers\OsaFsLoc.sys [2005-10-15 18:20]
R2 MSSQL$ACT7;SQL Server (ACT7);"D:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe" [2007-02-10 05:29]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 16:58]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57]
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
S3 NdisFilt;OSA NdisFilter Protocol;C:\WINDOWS\system32\Drivers\NdisFilt.sys [2005-09-13 15:34]
.
Contents of the 'Scheduled Tasks' folder
"2007-09-16 11:03:36 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- D:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2008-01-25 16:58:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-29 08:07:46 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-14 08:09:10 C:\WINDOWS\Tasks\SmartDefrag.job"
- D:\Programmes\IObit SmartDefrag\schedule.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 08:08:57
Windows 5.1.2600 Service Pack 2 FAT NTAPI
detected NTDLL code modification:
ZwClose
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
D:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe
D:\Program Files\Spyware Doctor\pctsAuxs.exe
D:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
D:\Programmes\IObit SmartDefrag\IObit SmartDefrag.exe
D:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\Program Files\Act.Outlook.Service.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
D:\Program Files\RssReader.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Mozilla Firefox\plugins\MyWebEx\419\mwmpad.exe
D:\Program Files\Office12\ONENOTEM.EXE
D:\Program Files\Desktop Clock\DekctopClock.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2008-01-29 8:11:48 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-29 08:11:44
ComboFix2.txt 2008-01-29 21:24:10
.
2008-01-30 03:01:22 — E O F —
Vundofix
ComboFix 08-01-29.1 - dean 2008-01-29 22:43:11.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.605 [GMT 0:00]
Running from: D:\Downloads\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))
.
2008-01-30 03:01 . 2008-01-30 03:01 d——– C:\WINDOWS\LastGood
2008-01-29 22:09 . 2008-01-29 22:09 d——– C:\Program Files\Trend Micro
2008-01-29 21:47 . 2008-01-29 21:47 d——– C:\Documents and Settings\dean.GRAPEVINE-GROUP\.SunDownloadManager
2008-01-28 20:47 . 2008-01-28 20:47 d——– C:\VundoFix Backups
2008-01-28 16:12 . 2008-01-28 16:12 65 –a—— C:\WINDOWS\wininit.ini
2008-01-28 16:02 . 2008-01-28 16:02 103,936 –a—— C:\WINDOWS\system32\drvtiz.dll
2008-01-28 16:00 . 2008-01-28 16:00 18,944 –a—— C:\WINDOWS\system32\drvzah.dll
2008-01-14 11:47 . 2008-01-14 11:47 d——– C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\Alibre Design
2008-01-14 11:15 . 2008-01-14 11:15 d——– C:\Program Files\Alibre Design Help
2008-01-14 11:14 . 2008-01-14 11:14 d——– C:\Program Files\PDFCreator Toolbar
2008-01-14 11:14 . 2008-01-14 11:14 264,097 –a—— C:\WINDOWS\PDFCreator_Toolbar_Uninstaller_8484.exe
2008-01-14 11:14 . 1998-06-24 01:00 137,000 –a—— C:\WINDOWS\system32\MSMAPI32.OCX
2008-01-14 11:14 . 2001-10-28 17:42 116,224 –a—— C:\WINDOWS\system32\pdfcmnnt.dll
2008-01-14 11:14 . 1998-07-06 01:00 23,552 –a—— C:\WINDOWS\system32\MSMPIDE.DLL
2008-01-14 11:13 . 2008-01-14 11:13 852 –a—— C:\WINDOWS\system32\wjview.exe.manifest
2008-01-14 11:12 . 2008-01-14 11:12 d——– C:\Documents and Settings\All Users\Application Data\Alibre Design
2008-01-14 11:12 . 2008-01-14 11:12 36 –a—— C:\WINDOWS\system32\InstallAlibre.config
2008-01-11 17:28 . 2008-01-11 17:28 268 –ah—– C:\sqmdata11.sqm
2008-01-11 17:28 . 2008-01-11 17:28 244 –ah—– C:\sqmnoopt11.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 12:39 77,383 —-a-w C:\WINDOWS\system32\atasnt40.dll
2008-01-14 11:01 155,995 —-a-w C:\WINDOWS\java\Packages\FDRN5ZV9.ZIP
2007-12-27 18:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\NtiDvdCopy
2007-12-14 10:09 ——— d—–w C:\Program Files\Windows Live Toolbar
2007-12-14 10:09 ——— d—–w C:\Program Files\Windows Live Favorites
2007-12-14 09:58 ——— d-sh–w C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-14 09:58 ——— d—–w C:\Program Files\Windows Live
2007-12-14 09:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-11 13:38 ——— d—–w C:\Program Files\Macromedia
2007-12-10 14:53 81,288 —-a-w C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-10 14:53 66,952 —-a-w C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-10 14:53 41,864 —-a-w C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-10 14:53 29,576 —-a-w C:\WINDOWS\system32\drivers\kcom.sys
2007-12-09 11:46 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\Locktime
2007-12-09 11:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Locktime
2007-12-09 10:26 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\PC Tools
2007-11-30 11:33 32 —-a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-30 11:33 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\skypePM
2007-11-30 11:31 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\Skype
2007-11-30 11:30 ——— d—–w C:\Program Files\Skype
2007-11-30 11:30 ——— d—–w C:\Program Files\Common Files\Skype
2007-11-30 11:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-11-30 09:21 ——— d—–w C:\Program Files\MSXML 6.0
2007-11-28 17:03 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\IsolatedStorage
2007-11-28 16:52 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-11-28 16:51 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\ACT
2007-11-28 16:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\ACT
2007-11-14 07:26 450,560 —-a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 10:16 3,058,688 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39 1289000]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"Act.Outlook.Service"="D:\Program Files\Act.Outlook.Service.exe" [2006-10-25 15:57 9728]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-11-16 12:36 21760296]
"RssReader"="D:\Program Files\RssReader.exe" [2004-04-04 17:21 1077248]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ePower_DMC"="C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-08-10 19:29 352256]
"SmartDefrag"="D:\Programmes\IObit SmartDefrag\IObit SmartDefrag.exe" [2008-01-07 23:29 2743552]
"MSDisp32"="C:\WINDOWS\system32\drvzah.dll" [2008-01-28 16:00 18944]
"MSDrive"="C:\WINDOWS\system32\drvtiz.dll" [2008-01-28 16:02 103936]
"SDTray"="D:\Program Files\Spyware Doctor\SDTrayApp.exe" [ ]
"ISTray"="D:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 14:53 1103752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 09:06 219136]
C:\Documents and Settings\dean.GRAPEVINE-GROUP\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 110592]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Start WebEx MeetMeNow.LNK - C:\Program Files\Mozilla Firefox\plugins\MyWebEx\419\mwmpad.exe [2007-05-01 19:16:49 496968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\pmnlj
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 17:14]
R1 OsaFsLoc;OsaFsLoc;C:\WINDOWS\system32\drivers\OsaFsLoc.sys [2005-10-15 18:20]
R2 MSSQL$ACT7;SQL Server (ACT7);"D:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe" [2007-02-10 05:29]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 16:58]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57]
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
S3 NdisFilt;OSA NdisFilter Protocol;C:\WINDOWS\system32\Drivers\NdisFilt.sys [2005-09-13 15:34]
.
Contents of the 'Scheduled Tasks' folder
"2007-09-16 11:03:36 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- D:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2008-01-25 16:58:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-29 08:07:46 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-14 08:09:10 C:\WINDOWS\Tasks\SmartDefrag.job"
- D:\Programmes\IObit SmartDefrag\schedule.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 08:08:57
Windows 5.1.2600 Service Pack 2 FAT NTAPI
detected NTDLL code modification:
ZwClose
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
D:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe
D:\Program Files\Spyware Doctor\pctsAuxs.exe
D:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
D:\Programmes\IObit SmartDefrag\IObit SmartDefrag.exe
D:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\Program Files\Act.Outlook.Service.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
D:\Program Files\RssReader.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Mozilla Firefox\plugins\MyWebEx\419\mwmpad.exe
D:\Program Files\Office12\ONENOTEM.EXE
D:\Program Files\Desktop Clock\DekctopClock.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2008-01-29 8:11:48 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-29 08:11:44
ComboFix2.txt 2008-01-29 21:24:10
.
2008-01-30 03:01:22 — E O F —
Smitfraud
SmitFraudFix v2.281
Scan done at 9:20:55.82, 2008-02-08
Run from D:\Downloads\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is FAT32
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix.exe by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Broadcom 440x 10/100 Integrated Controller - Packet Scheduler Miniport
DNS Server Search Order: 10.0.0.2
Description: Atheros AR5005G Wireless Network Adapter - Packet Scheduler Miniport
DNS Server Search Order: 10.0.0.2
HKLM\SYSTEM\CCS\Services\Tcpip\..\{14F1818C-01EB-4B85-AA4C-68B47BD20271}: DhcpNameServer=192.168.10.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{1C1095A1-E632-45E1-A053-9C83AC10A47C}: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CCS\Services\Tcpip\..\{8A5E8E91-7010-48ED-BDA2-1AE42443FE58}: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CCS\Services\Tcpip\..\{8D947B40-02D4-42BD-BB23-A68C0049F71D}: DhcpNameServer=192.168.10.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{14F1818C-01EB-4B85-AA4C-68B47BD20271}: DhcpNameServer=192.168.10.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{1C1095A1-E632-45E1-A053-9C83AC10A47C}: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CS1\Services\Tcpip\..\{8A5E8E91-7010-48ED-BDA2-1AE42443FE58}: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CS1\Services\Tcpip\..\{8D947B40-02D4-42BD-BB23-A68C0049F71D}: DhcpNameServer=192.168.10.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{14F1818C-01EB-4B85-AA4C-68B47BD20271}: DhcpNameServer=192.168.10.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{1C1095A1-E632-45E1-A053-9C83AC10A47C}: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CS3\Services\Tcpip\..\{8A5E8E91-7010-48ED-BDA2-1AE42443FE58}: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CS3\Services\Tcpip\..\{8D947B40-02D4-42BD-BB23-A68C0049F71D}: DhcpNameServer=192.168.10.10
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.2
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
Here is hoping that someone can help me
Thanks in advance
I have read some of the threads and tried some of the approaches to get rid of my trojan virus. I downloaded a screensaver and it came through that. I have:
- Ran a full AVG check
- Ran a Spy Doctor check
- Ran Vundofix
- Ran Combofix
- Ran smit fraud fix
It seems to get rid of it but then it comes back when I start my computer from cold.
It shows as a flashing item in my taskbar bottom right and it says :security warning: your computer may be infected with harmful or unwanted software.
Here are my reports
Hijack this
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:55, on 2008-01-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
D:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe
D:\Program Files\Spyware Doctor\pctsAuxs.exe
D:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
D:\Programmes\IObit SmartDefrag\IObit SmartDefrag.exe
D:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
D:\Program Files\Act.Outlook.Service.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
D:\Program Files\RssReader.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Mozilla Firefox\plugins\MyWebEx\419\mwmpad.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
D:\Program Files\Office12\ONENOTEM.EXE
D:\Program Files\Desktop Clock\DekctopClock.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Downloads\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.uk.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.uk.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {157B8898-115A-4E87-9323-54CC0D9493AA} - C:\WINDOWS\system32\pmnlj.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [SmartDefrag] "D:\Programmes\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [MSDisp32] rundll32.exe C:\WINDOWS\system32\drvzah.dll,startup
O4 - HKLM\..\Run: [MSDrive] rundll32.exe C:\WINDOWS\system32\drvtiz.dll,startup
O4 - HKLM\..\Run: [SDTray] "D:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [ISTray] "D:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Act.Outlook.Service] "D:\Program Files\Act.Outlook.Service.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [RssReader] D:\Program Files\RssReader.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Sky Alerts.lnk = C:\Program Files\Sky Alerts\skinker.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = D:\Program Files\Office12\ONENOTEM.EXE
O4 - Startup: Desktop Clock.lnk = D:\Program Files\Desktop Clock\DekctopClock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Start WebEx MeetMeNow.LNK = C:\Program Files\Mozilla Firefox\plugins\MyWebEx\419\mwmpad.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact… - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Start WebEx MeetMeNow - {F5AD6CC5-776C-4DBB-B38F-F5404A3582F3} - C:\PROGRA~1\MOZILL~1\plugins\MyWebEx\419\mwmie.dll
O9 - Extra 'Tools' menuitem: Start WebEx MeetMeNow - {F5AD6CC5-776C-4DBB-B38F-F5404A3582F3} - C:\PROGRA~1\MOZILL~1\plugins\MyWebEx\419\mwmie.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Grapevine-Group.local
O17 - HKLM\Software\..\Telephony: DomainName = Grapevine-Group.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Grapevine-Group.local
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\Program Files\Spyware Doctor\pctsSvc.exe
–
End of file - 9917 bytes
ComboFix 08-01-29.1 - dean 2008-01-29 22:43:11.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.605 [GMT 0:00]
Running from: D:\Downloads\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))
.
2008-01-30 03:01 . 2008-01-30 03:01 d——– C:\WINDOWS\LastGood
2008-01-29 22:09 . 2008-01-29 22:09 d——– C:\Program Files\Trend Micro
2008-01-29 21:47 . 2008-01-29 21:47 d——– C:\Documents and Settings\dean.GRAPEVINE-GROUP\.SunDownloadManager
2008-01-28 20:47 . 2008-01-28 20:47 d——– C:\VundoFix Backups
2008-01-28 16:12 . 2008-01-28 16:12 65 –a—— C:\WINDOWS\wininit.ini
2008-01-28 16:02 . 2008-01-28 16:02 103,936 –a—— C:\WINDOWS\system32\drvtiz.dll
2008-01-28 16:00 . 2008-01-28 16:00 18,944 –a—— C:\WINDOWS\system32\drvzah.dll
2008-01-14 11:47 . 2008-01-14 11:47 d——– C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\Alibre Design
2008-01-14 11:15 . 2008-01-14 11:15 d——– C:\Program Files\Alibre Design Help
2008-01-14 11:14 . 2008-01-14 11:14 d——– C:\Program Files\PDFCreator Toolbar
2008-01-14 11:14 . 2008-01-14 11:14 264,097 –a—— C:\WINDOWS\PDFCreator_Toolbar_Uninstaller_8484.exe
2008-01-14 11:14 . 1998-06-24 01:00 137,000 –a—— C:\WINDOWS\system32\MSMAPI32.OCX
2008-01-14 11:14 . 2001-10-28 17:42 116,224 –a—— C:\WINDOWS\system32\pdfcmnnt.dll
2008-01-14 11:14 . 1998-07-06 01:00 23,552 –a—— C:\WINDOWS\system32\MSMPIDE.DLL
2008-01-14 11:13 . 2008-01-14 11:13 852 –a—— C:\WINDOWS\system32\wjview.exe.manifest
2008-01-14 11:12 . 2008-01-14 11:12 d——– C:\Documents and Settings\All Users\Application Data\Alibre Design
2008-01-14 11:12 . 2008-01-14 11:12 36 –a—— C:\WINDOWS\system32\InstallAlibre.config
2008-01-11 17:28 . 2008-01-11 17:28 268 –ah—– C:\sqmdata11.sqm
2008-01-11 17:28 . 2008-01-11 17:28 244 –ah—– C:\sqmnoopt11.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 12:39 77,383 —-a-w C:\WINDOWS\system32\atasnt40.dll
2008-01-14 11:01 155,995 —-a-w C:\WINDOWS\java\Packages\FDRN5ZV9.ZIP
2007-12-27 18:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\NtiDvdCopy
2007-12-14 10:09 ——— d—–w C:\Program Files\Windows Live Toolbar
2007-12-14 10:09 ——— d—–w C:\Program Files\Windows Live Favorites
2007-12-14 09:58 ——— d-sh–w C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-14 09:58 ——— d—–w C:\Program Files\Windows Live
2007-12-14 09:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-11 13:38 ——— d—–w C:\Program Files\Macromedia
2007-12-10 14:53 81,288 —-a-w C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-10 14:53 66,952 —-a-w C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-10 14:53 41,864 —-a-w C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-10 14:53 29,576 —-a-w C:\WINDOWS\system32\drivers\kcom.sys
2007-12-09 11:46 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\Locktime
2007-12-09 11:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Locktime
2007-12-09 10:26 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\PC Tools
2007-11-30 11:33 32 —-a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-30 11:33 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\skypePM
2007-11-30 11:31 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\Skype
2007-11-30 11:30 ——— d—–w C:\Program Files\Skype
2007-11-30 11:30 ——— d—–w C:\Program Files\Common Files\Skype
2007-11-30 11:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-11-30 09:21 ——— d—–w C:\Program Files\MSXML 6.0
2007-11-28 17:03 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\IsolatedStorage
2007-11-28 16:52 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-11-28 16:51 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\ACT
2007-11-28 16:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\ACT
2007-11-14 07:26 450,560 —-a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 10:16 3,058,688 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39 1289000]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"Act.Outlook.Service"="D:\Program Files\Act.Outlook.Service.exe" [2006-10-25 15:57 9728]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-11-16 12:36 21760296]
"RssReader"="D:\Program Files\RssReader.exe" [2004-04-04 17:21 1077248]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ePower_DMC"="C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-08-10 19:29 352256]
"SmartDefrag"="D:\Programmes\IObit SmartDefrag\IObit SmartDefrag.exe" [2008-01-07 23:29 2743552]
"MSDisp32"="C:\WINDOWS\system32\drvzah.dll" [2008-01-28 16:00 18944]
"MSDrive"="C:\WINDOWS\system32\drvtiz.dll" [2008-01-28 16:02 103936]
"SDTray"="D:\Program Files\Spyware Doctor\SDTrayApp.exe" [ ]
"ISTray"="D:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 14:53 1103752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 09:06 219136]
C:\Documents and Settings\dean.GRAPEVINE-GROUP\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 110592]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Start WebEx MeetMeNow.LNK - C:\Program Files\Mozilla Firefox\plugins\MyWebEx\419\mwmpad.exe [2007-05-01 19:16:49 496968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\pmnlj
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 17:14]
R1 OsaFsLoc;OsaFsLoc;C:\WINDOWS\system32\drivers\OsaFsLoc.sys [2005-10-15 18:20]
R2 MSSQL$ACT7;SQL Server (ACT7);"D:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe" [2007-02-10 05:29]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 16:58]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57]
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
S3 NdisFilt;OSA NdisFilter Protocol;C:\WINDOWS\system32\Drivers\NdisFilt.sys [2005-09-13 15:34]
.
Contents of the 'Scheduled Tasks' folder
"2007-09-16 11:03:36 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- D:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2008-01-25 16:58:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-29 08:07:46 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-14 08:09:10 C:\WINDOWS\Tasks\SmartDefrag.job"
- D:\Programmes\IObit SmartDefrag\schedule.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 08:08:57
Windows 5.1.2600 Service Pack 2 FAT NTAPI
detected NTDLL code modification:
ZwClose
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
D:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe
D:\Program Files\Spyware Doctor\pctsAuxs.exe
D:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
D:\Programmes\IObit SmartDefrag\IObit SmartDefrag.exe
D:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\Program Files\Act.Outlook.Service.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
D:\Program Files\RssReader.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Mozilla Firefox\plugins\MyWebEx\419\mwmpad.exe
D:\Program Files\Office12\ONENOTEM.EXE
D:\Program Files\Desktop Clock\DekctopClock.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2008-01-29 8:11:48 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-29 08:11:44
ComboFix2.txt 2008-01-29 21:24:10
.
2008-01-30 03:01:22 — E O F —
ComboFix 08-01-29.1 - dean 2008-01-29 22:43:11.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.605 [GMT 0:00]
Running from: D:\Downloads\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))
.
2008-01-30 03:01 . 2008-01-30 03:01 d——– C:\WINDOWS\LastGood
2008-01-29 22:09 . 2008-01-29 22:09 d——– C:\Program Files\Trend Micro
2008-01-29 21:47 . 2008-01-29 21:47 d——– C:\Documents and Settings\dean.GRAPEVINE-GROUP\.SunDownloadManager
2008-01-28 20:47 . 2008-01-28 20:47 d——– C:\VundoFix Backups
2008-01-28 16:12 . 2008-01-28 16:12 65 –a—— C:\WINDOWS\wininit.ini
2008-01-28 16:02 . 2008-01-28 16:02 103,936 –a—— C:\WINDOWS\system32\drvtiz.dll
2008-01-28 16:00 . 2008-01-28 16:00 18,944 –a—— C:\WINDOWS\system32\drvzah.dll
2008-01-14 11:47 . 2008-01-14 11:47 d——– C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\Alibre Design
2008-01-14 11:15 . 2008-01-14 11:15 d——– C:\Program Files\Alibre Design Help
2008-01-14 11:14 . 2008-01-14 11:14 d——– C:\Program Files\PDFCreator Toolbar
2008-01-14 11:14 . 2008-01-14 11:14 264,097 –a—— C:\WINDOWS\PDFCreator_Toolbar_Uninstaller_8484.exe
2008-01-14 11:14 . 1998-06-24 01:00 137,000 –a—— C:\WINDOWS\system32\MSMAPI32.OCX
2008-01-14 11:14 . 2001-10-28 17:42 116,224 –a—— C:\WINDOWS\system32\pdfcmnnt.dll
2008-01-14 11:14 . 1998-07-06 01:00 23,552 –a—— C:\WINDOWS\system32\MSMPIDE.DLL
2008-01-14 11:13 . 2008-01-14 11:13 852 –a—— C:\WINDOWS\system32\wjview.exe.manifest
2008-01-14 11:12 . 2008-01-14 11:12 d——– C:\Documents and Settings\All Users\Application Data\Alibre Design
2008-01-14 11:12 . 2008-01-14 11:12 36 –a—— C:\WINDOWS\system32\InstallAlibre.config
2008-01-11 17:28 . 2008-01-11 17:28 268 –ah—– C:\sqmdata11.sqm
2008-01-11 17:28 . 2008-01-11 17:28 244 –ah—– C:\sqmnoopt11.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 12:39 77,383 —-a-w C:\WINDOWS\system32\atasnt40.dll
2008-01-14 11:01 155,995 —-a-w C:\WINDOWS\java\Packages\FDRN5ZV9.ZIP
2007-12-27 18:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\NtiDvdCopy
2007-12-14 10:09 ——— d—–w C:\Program Files\Windows Live Toolbar
2007-12-14 10:09 ——— d—–w C:\Program Files\Windows Live Favorites
2007-12-14 09:58 ——— d-sh–w C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-14 09:58 ——— d—–w C:\Program Files\Windows Live
2007-12-14 09:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-11 13:38 ——— d—–w C:\Program Files\Macromedia
2007-12-10 14:53 81,288 —-a-w C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-10 14:53 66,952 —-a-w C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-10 14:53 41,864 —-a-w C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-10 14:53 29,576 —-a-w C:\WINDOWS\system32\drivers\kcom.sys
2007-12-09 11:46 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\Locktime
2007-12-09 11:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Locktime
2007-12-09 10:26 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\PC Tools
2007-11-30 11:33 32 —-a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-30 11:33 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\skypePM
2007-11-30 11:31 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\Skype
2007-11-30 11:30 ——— d—–w C:\Program Files\Skype
2007-11-30 11:30 ——— d—–w C:\Program Files\Common Files\Skype
2007-11-30 11:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-11-30 09:21 ——— d—–w C:\Program Files\MSXML 6.0
2007-11-28 17:03 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\IsolatedStorage
2007-11-28 16:52 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-11-28 16:51 ——— d—–w C:\Documents and Settings\dean.GRAPEVINE-GROUP\Application Data\ACT
2007-11-28 16:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\ACT
2007-11-14 07:26 450,560 —-a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 10:16 3,058,688 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39 1289000]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"Act.Outlook.Service"="D:\Program Files\Act.Outlook.Service.exe" [2006-10-25 15:57 9728]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-11-16 12:36 21760296]
"RssReader"="D:\Program Files\RssReader.exe" [2004-04-04 17:21 1077248]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ePower_DMC"="C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-08-10 19:29 352256]
"SmartDefrag"="D:\Programmes\IObit SmartDefrag\IObit SmartDefrag.exe" [2008-01-07 23:29 2743552]
"MSDisp32"="C:\WINDOWS\system32\drvzah.dll" [2008-01-28 16:00 18944]
"MSDrive"="C:\WINDOWS\system32\drvtiz.dll" [2008-01-28 16:02 103936]
"SDTray"="D:\Program Files\Spyware Doctor\SDTrayApp.exe" [ ]
"ISTray"="D:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 14:53 1103752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 09:06 219136]
C:\Documents and Settings\dean.GRAPEVINE-GROUP\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 110592]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Start WebEx MeetMeNow.LNK - C:\Program Files\Mozilla Firefox\plugins\MyWebEx\419\mwmpad.exe [2007-05-01 19:16:49 496968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\pmnlj
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 17:14]
R1 OsaFsLoc;OsaFsLoc;C:\WINDOWS\system32\drivers\OsaFsLoc.sys [2005-10-15 18:20]
R2 MSSQL$ACT7;SQL Server (ACT7);"D:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe" [2007-02-10 05:29]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 16:58]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57]
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
S3 NdisFilt;OSA NdisFilter Protocol;C:\WINDOWS\system32\Drivers\NdisFilt.sys [2005-09-13 15:34]
.
Contents of the 'Scheduled Tasks' folder
"2007-09-16 11:03:36 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- D:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2008-01-25 16:58:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-29 08:07:46 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-14 08:09:10 C:\WINDOWS\Tasks\SmartDefrag.job"
- D:\Programmes\IObit SmartDefrag\schedule.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 08:08:57
Windows 5.1.2600 Service Pack 2 FAT NTAPI
detected NTDLL code modification:
ZwClose
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
D:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe
D:\Program Files\Spyware Doctor\pctsAuxs.exe
D:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
D:\Programmes\IObit SmartDefrag\IObit SmartDefrag.exe
D:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\Program Files\Act.Outlook.Service.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
D:\Program Files\RssReader.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Mozilla Firefox\plugins\MyWebEx\419\mwmpad.exe
D:\Program Files\Office12\ONENOTEM.EXE
D:\Program Files\Desktop Clock\DekctopClock.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2008-01-29 8:11:48 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-29 08:11:44
ComboFix2.txt 2008-01-29 21:24:10
.
2008-01-30 03:01:22 — E O F —
Smitfraud
SmitFraudFix v2.281
Scan done at 9:20:55.82, 2008-02-08
Run from D:\Downloads\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is FAT32
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix.exe by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Broadcom 440x 10/100 Integrated Controller - Packet Scheduler Miniport
DNS Server Search Order: 10.0.0.2
Description: Atheros AR5005G Wireless Network Adapter - Packet Scheduler Miniport
DNS Server Search Order: 10.0.0.2
HKLM\SYSTEM\CCS\Services\Tcpip\..\{14F1818C-01EB-4B85-AA4C-68B47BD20271}: DhcpNameServer=192.168.10.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{1C1095A1-E632-45E1-A053-9C83AC10A47C}: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CCS\Services\Tcpip\..\{8A5E8E91-7010-48ED-BDA2-1AE42443FE58}: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CCS\Services\Tcpip\..\{8D947B40-02D4-42BD-BB23-A68C0049F71D}: DhcpNameServer=192.168.10.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{14F1818C-01EB-4B85-AA4C-68B47BD20271}: DhcpNameServer=192.168.10.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{1C1095A1-E632-45E1-A053-9C83AC10A47C}: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CS1\Services\Tcpip\..\{8A5E8E91-7010-48ED-BDA2-1AE42443FE58}: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CS1\Services\Tcpip\..\{8D947B40-02D4-42BD-BB23-A68C0049F71D}: DhcpNameServer=192.168.10.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{14F1818C-01EB-4B85-AA4C-68B47BD20271}: DhcpNameServer=192.168.10.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{1C1095A1-E632-45E1-A053-9C83AC10A47C}: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CS3\Services\Tcpip\..\{8A5E8E91-7010-48ED-BDA2-1AE42443FE58}: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CS3\Services\Tcpip\..\{8D947B40-02D4-42BD-BB23-A68C0049F71D}: DhcpNameServer=192.168.10.10
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.2
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.2
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
Here is hoping that someone can help me
Thanks in advance