This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]  Antivirus XP 2008 Leftovers

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK. I wasn't sure which thread you wanted this posted in, but I assume you want it here.

I deleted a folder called uTorrent, and now here's my Combofix log:


ComboFix 08-10-08.02 - Christopher 2008-10-08 18:27:06.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.264 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\3913605.exe
C:\WINDOWS\system32\c.ico
C:\WINDOWS\system32\config\systemprofile\Desktop\Search Online.url
C:\WINDOWS\system32\config\systemprofile\Desktop\VIP Casino.url
C:\WINDOWS\system32\config\systemprofile\Favorites\Search Online.url
C:\WINDOWS\system32\config\systemprofile\Favorites\VIP Casino.url
C:\WINDOWS\system32\config\systemprofile\Start Menu\Search Online.url
C:\WINDOWS\system32\config\systemprofile\Start Menu\VIP Casino.url
C:\WINDOWS\system32\lsystipl64.dll
C:\WINDOWS\system32\m.ico
C:\WINDOWS\system32\msupdate.exe
C:\WINDOWS\system32\s.ico

.
((((((((((((((((((((((((( Files Created from 2008-09-08 to 2008-10-08 )))))))))))))))))))))))))))))))
.

2008-10-07 00:31 . 2008-10-07 00:32 d——– C:\Program Files\iTunes
2008-10-07 00:31 . 2008-10-07 00:31 d——– C:\Program Files\iPod
2008-10-07 00:31 . 2008-10-07 00:32 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-04 10:13 . 2008-10-04 10:13 58 –a—— C:\WINDOWS\system32\winwp.bmp
2008-10-04 10:07 . 2008-10-04 10:07 139,264 –a—— C:\WINDOWS\system32\mkrnl.exe
2008-10-04 10:07 . 2008-10-04 10:07 139,264 ——— C:\WINDOWS\sx2_77000531.exe
2008-10-04 10:07 . 2008-10-04 10:07 44 –a—— C:\WINDOWS\$$$$$$$$.bat
2008-10-02 17:23 . 2008-10-02 17:32 d——– C:\Program Files\SpywareBlaster
2008-10-02 17:23 . 2008-10-08 17:06 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-01 10:04 . 2008-10-01 15:16 98,332 –a—— C:\WINDOWS\yambafile.exe
2008-09-30 14:51 . 2008-10-08 10:20 d——– C:\Documents and Settings\All Users\Application Data\Soulseek
2008-09-30 14:35 . 2008-09-30 14:35 d——– C:\Program Files\BillP Studios
2008-09-30 14:35 . 2008-09-30 14:35 d——– C:\Documents and Settings\Christopher\Application Data\WinPatrol
2008-09-28 16:42 . 2008-09-28 16:52 d——– C:\Lop SD
2008-09-26 10:30 . 2008-09-26 10:30 d——– C:\WINDOWS\ERUNT
2008-09-25 12:34 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-25 12:32 . 2008-09-25 12:32 d——– C:\Program Files\Common Files\Java
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Program Files\Avira
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-09-24 12:16 . 2008-09-24 12:16 d——– C:\Documents and Settings\Christopher\Application Data\Malwarebytes
2008-09-24 12:16 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-24 12:16 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-24 12:15 . 2008-09-24 12:19 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-24 12:15 . 2008-09-24 12:15 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-23 17:15 . 2008-09-23 17:15 d——– C:\Program Files\ERUNT
2008-09-21 00:02 . 2008-09-21 00:02 d——– C:\Program Files\Apple Software Update
2008-09-18 19:36 . 2008-09-18 19:36 d——– C:\Program Files\Trend Micro
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Program Files\Security Task Manager2
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-09-18 19:21 . 2008-09-18 19:21 d——– C:\Program Files\Security Task Manager
2008-09-18 15:05 . 2008-10-02 13:31 d——– C:\WINDOWS\system32\wTR19
2008-09-18 15:05 . 2008-09-18 15:05 d——– C:\Temp\dax41
2008-09-16 08:19 . 2008-09-18 17:35 d——– C:\WINDOWS\system32\CatRoot_bak
2008-09-12 08:51 . 2008-05-01 10:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-08 22:22 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-10-01 17:01 32,000 —-a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-09-25 16:34 ——— d—–w C:\Program Files\Java
2008-09-23 19:10 ——— d—–w C:\Program Files\Soulseek
2008-09-21 04:06 ——— d—–w C:\Program Files\Bonjour
2008-09-21 04:04 ——— d—–w C:\Program Files\QuickTime
2008-09-21 04:04 ——— d—–w C:\Program Files\Common Files\Apple
2008-09-18 20:46 ——— d—–w C:\Program Files\Norton Security Scan
2008-09-12 12:42 ——— d—–w C:\Program Files\Safari
2008-09-12 12:39 ——— d—–w C:\Program Files\Common Files\Macromedia
2008-09-12 12:35 ——— d—–w C:\Program Files\iTunes(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\iPod(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\Apple Software Update(2)
2008-08-29 14:18 87,336 —-a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 13:53 61,440 —-a-w C:\WINDOWS\system32\dnssd.dll
2008-07-19 02:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-08 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-07 159744]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-11 335872]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2003-09-26 237568]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-21 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2008-09-18 333120]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"AGRSMMSG"="AGRSMMSG.exe" [2003-09-30 C:\WINDOWS\AGRSMMSG.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-15 108544]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
–a—— 2003-10-07 23:41 28672 C:\WINDOWS\system32\Ati2mdxx.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 IFP300;iRiver Internet Audio Player IFP-300;C:\WINDOWS\system32\DRIVERS\ifp300.sys [2003-03-06 13543]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2008-10-02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-10-08 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-08 17:22]

2008-10-08 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]

2008-10-08 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-04-19 22:42]
.
- - - - ORPHANS REMOVED - - - -

Notify-c00EC64 - (no file)
Notify-m0_glkp_011008 - (no file)


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Christopher\Application Data\Mozilla\Firefox\Profiles\579bhqqr.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://news.google.com/nwshp?hl=en&tab=wn
FF -: plugin - C:\Documents and Settings\Christopher\Application Data\Mozilla\Firefox\Profiles\579bhqqr.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF -: plugin - C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\1.2.131.11\npGoogleOneClick5.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 18:42:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe??????????~????|?????? ?deB???????????????B? ??????

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka]
"imagepath"="\systemroot\system32\drivers\seneka.sys"
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-10-08 18:48:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-08 22:48:06
ComboFix2.txt 2008-09-29 14:31:45

Pre-Run: 65,385,902,080 bytes free
Post-Run: 65,479,950,336 bytes free

187 — E O F — 2008-09-18 21:35:03
filmcynic,

Erm.. You've picked up a couple more nasties since I saw your last logs. :wacko:

First off. Lets get a look in a couple of folders that you have:

Please download DirLook by jpshortstuff from one of the following mirrors:
Link 1
Link 2
Link 3
  • Double-click DirLook.exe to run it (Vista Users should right-click and select Run As Administrator…).
  • Ensure that Show Hidden Files/Folders and BBCode Ouput are both checked.
  • Copy the content of the following codebox into the main textfield:

    C:\WINDOWS\system32\wTR19
    C:\Temp\dax41
  • Click the DirLook button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. (Note: The log can also be found at C:\DirLook.txt)
Note: Scanning may take longer for large folders.
OK, that seemed to go too fast and reveal nothing, but here's the log:


DirLook.exe v2.0 by jpshortstuff
Log created at 09:16 on 09/10/2008
==================================
Contents of "C:\WINDOWS\system32\wTR19"

—FOLDERS—

(none found)

—FILES—

(none found)

==================================
Contents of "C:\Temp\dax41"

—FOLDERS—

(none found)

—FILES—

A3G.log (1858 bytes - created on 18/09/2008 at 19:06, modified on 18/09/2008 at 19:06) –a—

==================================
=EOF=
filmcynic,

Those folders can be related to a trojan. The executable files related to this trojan are not there. Your antivirus may have taken care of them but we will remove them anyway as they serve no good purpose.

Speaking of Trojans:
Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\WINDOWS\sx2_77000531.exe
    C:\WINDOWS\system32\winwp.bmp
    C:\WINDOWS\system32\mkrnl.exe
    C:\WINDOWS\yambafile.exe
    C:\WINDOWS\$$$$$$$$.bat
    
    Folder::
    C:\WINDOWS\system32\wTR19
    C:\Temp\dax41
    C:\Program Files\Soulseek
    C:\Documents and Settings\All Users\Application Data\TEMP
    C:\Documents and Settings\All Users\Application Data\Soulseek
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • ComboFix.txt
  • Kaspersky report
  • New HijackThis log taken after everything else completed
Tomk,

As always, I am unable to get to any tech type websites, and so can not do the Kaspersky scan.

Also, I was wondering if it's a problem that when Combofix goes to restart my computer, the shutdown never finishes (or else is taking a long, long, long time to do so) and so I force shut off the computer and manually restart it. Also, does it matter that upon starting back up that Avira starts back up (I immediately disable when possible)?

Ok, here are the Combo and Hijack logs:

ComboFix 08-10-08.02 - Christopher 2008-10-09 11:45:58.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.280 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Christopher\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\$$$$$$$$.bat
C:\WINDOWS\sx2_77000531.exe
C:\WINDOWS\system32\mkrnl.exe
C:\WINDOWS\system32\winwp.bmp
C:\WINDOWS\yambafile.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\$$$$$$$$.bat
C:\WINDOWS\sx2_77000531.exe
C:\WINDOWS\system32\mkrnl.exe
C:\WINDOWS\system32\winwp.bmp
C:\WINDOWS\yambafile.exe

.
((((((((((((((((((((((((( Files Created from 2008-09-09 to 2008-10-09 )))))))))))))))))))))))))))))))
.

2008-10-07 00:31 . 2008-10-07 00:32 d——– C:\Program Files\iTunes
2008-10-07 00:31 . 2008-10-07 00:31 d——– C:\Program Files\iPod
2008-10-07 00:31 . 2008-10-07 00:32 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-02 17:23 . 2008-10-02 17:32 d——– C:\Program Files\SpywareBlaster
2008-10-02 17:23 . 2008-10-08 17:06 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-30 14:51 . 2008-10-08 10:20 d——– C:\Documents and Settings\All Users\Application Data\Soulseek
2008-09-30 14:35 . 2008-09-30 14:35 d——– C:\Program Files\BillP Studios
2008-09-30 14:35 . 2008-09-30 14:35 d——– C:\Documents and Settings\Christopher\Application Data\WinPatrol
2008-09-28 16:42 . 2008-09-28 16:52 d——– C:\Lop SD
2008-09-26 10:30 . 2008-09-26 10:30 d——– C:\WINDOWS\ERUNT
2008-09-25 12:34 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-25 12:32 . 2008-09-25 12:32 d——– C:\Program Files\Common Files\Java
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Program Files\Avira
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-09-24 12:16 . 2008-09-24 12:16 d——– C:\Documents and Settings\Christopher\Application Data\Malwarebytes
2008-09-24 12:16 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-24 12:16 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-24 12:15 . 2008-09-24 12:19 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-24 12:15 . 2008-09-24 12:15 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-23 17:15 . 2008-09-23 17:15 d——– C:\Program Files\ERUNT
2008-09-21 00:02 . 2008-09-21 00:02 d——– C:\Program Files\Apple Software Update
2008-09-18 19:36 . 2008-09-18 19:36 d——– C:\Program Files\Trend Micro
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Program Files\Security Task Manager2
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-09-18 19:21 . 2008-09-18 19:21 d——– C:\Program Files\Security Task Manager
2008-09-18 15:05 . 2008-10-02 13:31 d——– C:\WINDOWS\system32\wTR19
2008-09-18 15:05 . 2008-09-18 15:05 d——– C:\Temp\dax41
2008-09-16 08:19 . 2008-09-18 17:35 d——– C:\WINDOWS\system32\CatRoot_bak
2008-09-12 08:51 . 2008-05-01 10:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-09 15:29 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-10-01 17:01 32,000 —-a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-09-25 16:34 ——— d—–w C:\Program Files\Java
2008-09-23 19:10 ——— d—–w C:\Program Files\Soulseek
2008-09-21 04:06 ——— d—–w C:\Program Files\Bonjour
2008-09-21 04:04 ——— d—–w C:\Program Files\QuickTime
2008-09-21 04:04 ——— d—–w C:\Program Files\Common Files\Apple
2008-09-18 20:46 ——— d—–w C:\Program Files\Norton Security Scan
2008-09-12 12:42 ——— d—–w C:\Program Files\Safari
2008-09-12 12:39 ——— d—–w C:\Program Files\Common Files\Macromedia
2008-09-12 12:35 ——— d—–w C:\Program Files\iTunes(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\iPod(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\Apple Software Update(2)
2008-08-29 14:18 87,336 —-a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 13:53 61,440 —-a-w C:\WINDOWS\system32\dnssd.dll
2008-07-19 02:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
.

((((((((((((((((((((((((((((( snapshot@2008-10-08_18.45.59.68 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-10-08 11:30:49 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-10-09 11:37:57 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-10-08 11:30:49 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-10-09 11:37:57 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-10-08 11:30:49 49,152 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-09 11:37:57 49,152 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-08 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-07 159744]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-11 335872]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2003-09-26 237568]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-21 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2008-09-18 333120]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"AGRSMMSG"="AGRSMMSG.exe" [2003-09-30 C:\WINDOWS\AGRSMMSG.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-15 108544]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
–a—— 2003-10-07 23:41 28672 C:\WINDOWS\system32\Ati2mdxx.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 IFP300;iRiver Internet Audio Player IFP-300;C:\WINDOWS\system32\DRIVERS\ifp300.sys [2003-03-06 13543]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2008-10-02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-10-09 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-08 17:22]

2008-10-09 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]

2008-10-08 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-04-19 22:42]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-09 11:59:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????1?5?8?7??????? ?deB???????????????B? ??????

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka]
"imagepath"="\systemroot\system32\drivers\seneka.sys"
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-10-09 12:05:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-09 16:04:53
ComboFix2.txt 2008-10-08 22:48:23
ComboFix3.txt 2008-09-29 14:31:45

Pre-Run: 65,546,080,256 bytes free
Post-Run: 65,542,885,376 bytes free

177 — E O F — 2008-09-18 21:35:03


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:07, on 2008-10-09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://music.yahoo.com/launchcast/station.asp?u=136758632
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 6162 bytes
Also, I don't mind reformatting/reinstalling or whatever. Though when this happened, the first thing I did was try to insert my system recovery disks, but my computer claimed it didn't recognize the first one. I don't know if that was because of the spyware or becaue my CD-rom isn't in great shape these days (it skips when I try to play CDs and often has trouble when I enter program disks).
filmcynic,

Also, I was wondering if it's a problem that when Combofix goes to restart my computer, the shutdown never finishes (or else is taking a long, long, long time to do so) and so I force shut off the computer and manually restart it. Also, does it matter that upon starting back up that Avira starts back up (I immediately disable when possible)?

I'm not concerned about the Avira but I am about the shutdown problem. I'm not sure what to do about it, but I'm concerned. This time, please wait 15 to 20 minutes before manually finishing up.

I'm kind of stubborn. I'm willing to keep trying to beat this thing if you are.

For some reason, only 1/2 our script ran last time. We'll try again.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\WINDOWS\Tasks\Norton Security Scan.job
    C:\WINDOWS\system32\drivers\seneka.sys
    
    Folder::
    C:\Documents and Settings\All Users\Application Data\TEMP
    C:\Documents and Settings\All Users\Application Data\Soulseek
    C:\WINDOWS\system32\wTR19
    C:\Temp\dax41
    C:\Program Files\Soulseek
    C:\Program Files\Norton Security Scan
    
    Registry::
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Now, I need you to be logged in as an administrator(or have administrator rights) before running the next tool.

Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.
  • Close Gmer.
  • Open Command Prompt by going to Start > Run and type in cmd. Press Enter.
  • In Command Prompt, type in net stop gmer. Press Enter.
  • Type in exit to close Command Prompt.

Note: Do not run any programs while Gmer is running.
OK, the computer shut down much easier this time around. Hopefully everything went as it's supposed to. One thing, though: in the cmd screen, when I type "net stop gmer" it says: "System error 1060 has occurred. The specified device does not exist as an installed service."

Here are my logs:

ComboFix 08-10-08.02 - Christopher 2008-10-10 12:29:30.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.326 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Christopher\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\drivers\seneka.sys
C:\WINDOWS\Tasks\Norton Security Scan.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Soulseek
C:\Documents and Settings\All Users\Application Data\Soulseek\attributes.cfg
C:\Documents and Settings\All Users\Application Data\TEMP
C:\Program Files\Norton Security Scan
C:\Program Files\Norton Security Scan\ccL60U.dll
C:\Program Files\Norton Security Scan\ccScanw.dll
C:\Program Files\Norton Security Scan\ccVrTrst.dll
C:\Program Files\Norton Security Scan\dec_abi.dll
C:\Program Files\Norton Security Scan\DefUtDCD.dll
C:\Program Files\Norton Security Scan\ecmldr32.dll
C:\Program Files\Norton Security Scan\help.htm
C:\Program Files\Norton Security Scan\msl.dll
C:\Program Files\Norton Security Scan\msvcp71.dll
C:\Program Files\Norton Security Scan\msvcr71.dll
C:\Program Files\Norton Security Scan\NSS.exe
C:\Program Files\Norton Security Scan\NSS.exe.replace
C:\Program Files\Norton Security Scan\patch25d.dll
C:\Program Files\Norton Security Scan\SAUpdt.dll
C:\Program Files\Norton Security Scan\ScanCore.dll
C:\Program Files\Norton Security Scan\ScanRes.dll
C:\Program Files\Norton Security Scan\SKURes.dll
C:\Program Files\Soulseek
C:\Program Files\Soulseek\attributes.cfg
C:\Program Files\Soulseek\attrstrings.cfg
C:\Program Files\Soulseek\autoaway.cfg
C:\Program Files\Soulseek\chatrooms.cfg
C:\Program Files\Soulseek\chatui.cfg
C:\Program Files\Soulseek\dlbans.cfg
C:\Program Files\Soulseek\extensions.cfg
C:\Program Files\Soulseek\hotlist.cfg
C:\Program Files\Soulseek\ignores.cfg
C:\Program Files\Soulseek\login.cfg
C:\Program Files\Soulseek\pchat.cfg
C:\Program Files\Soulseek\port.cfg
C:\Program Files\Soulseek\queue.cfg
C:\Program Files\Soulseek\queue2.cfg
C:\Program Files\Soulseek\rcmnd.cfg
C:\Program Files\Soulseek\save.cfg
C:\Program Files\Soulseek\search.cfg
C:\Program Files\Soulseek\shared.cfg
C:\Program Files\Soulseek\ticker.cfg
C:\Program Files\Soulseek\transfersview.cfg
C:\Program Files\Soulseek\ui.cfg
C:\Program Files\Soulseek\userinfo.cfg
C:\Program Files\Soulseek\usernotes.cfg
C:\Program Files\Soulseek\wishlist.cfg
C:\Temp\dax41
C:\Temp\dax41\A3G.log
C:\WINDOWS\system32\wTR19
C:\WINDOWS\Tasks\Norton Security Scan.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_seneka
——-\Service_seneka


((((((((((((((((((((((((( Files Created from 2008-09-10 to 2008-10-10 )))))))))))))))))))))))))))))))
.

2008-10-07 00:31 . 2008-10-07 00:32 d——– C:\Program Files\iTunes
2008-10-07 00:31 . 2008-10-07 00:31 d——– C:\Program Files\iPod
2008-10-07 00:31 . 2008-10-07 00:32 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-02 17:23 . 2008-10-02 17:32 d——– C:\Program Files\SpywareBlaster
2008-09-30 14:35 . 2008-09-30 14:35 d——– C:\Program Files\BillP Studios
2008-09-30 14:35 . 2008-09-30 14:35 d——– C:\Documents and Settings\Christopher\Application Data\WinPatrol
2008-09-28 16:42 . 2008-09-28 16:52 d——– C:\Lop SD
2008-09-26 10:30 . 2008-09-26 10:30 d——– C:\WINDOWS\ERUNT
2008-09-25 12:34 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-25 12:32 . 2008-09-25 12:32 d——– C:\Program Files\Common Files\Java
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Program Files\Avira
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-09-24 12:16 . 2008-09-24 12:16 d——– C:\Documents and Settings\Christopher\Application Data\Malwarebytes
2008-09-24 12:16 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-24 12:16 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-24 12:15 . 2008-09-24 12:19 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-24 12:15 . 2008-09-24 12:15 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-23 17:15 . 2008-09-23 17:15 d——– C:\Program Files\ERUNT
2008-09-21 00:02 . 2008-09-21 00:02 d——– C:\Program Files\Apple Software Update
2008-09-18 19:36 . 2008-09-18 19:36 d——– C:\Program Files\Trend Micro
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Program Files\Security Task Manager2
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-09-18 19:21 . 2008-09-18 19:21 d——– C:\Program Files\Security Task Manager
2008-09-18 16:48 . 2008-10-01 10:04 10,240 –a—— C:\WINDOWS\system32\senekadf.dll
2008-09-18 16:48 . 2008-10-10 12:25 2,396 –a—— C:\WINDOWS\system32\senekadf.dat
2008-09-18 16:48 . 2008-10-10 12:25 92 –a—— C:\WINDOWS\system32\seneka.dat
2008-09-18 16:43 . 2008-10-10 12:25 290,380 –a—— C:\WINDOWS\system32\senekaul.dat
2008-09-18 16:43 . 2008-09-18 16:43 20,535 –a—— C:\WINDOWS\system32\seneka.dll
2008-09-18 16:43 . 2008-10-10 08:20 87 –a—— C:\WINDOWS\system32\senekakl.dat
2008-09-16 08:19 . 2008-09-18 17:35 d——– C:\WINDOWS\system32\CatRoot_bak
2008-09-12 08:51 . 2008-05-01 10:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-10 12:33 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-10-01 17:01 32,000 —-a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-09-25 16:34 ——— d—–w C:\Program Files\Java
2008-09-21 04:06 ——— d—–w C:\Program Files\Bonjour
2008-09-21 04:04 ——— d—–w C:\Program Files\QuickTime
2008-09-21 04:04 ——— d—–w C:\Program Files\Common Files\Apple
2008-09-12 12:42 ——— d—–w C:\Program Files\Safari
2008-09-12 12:39 ——— d—–w C:\Program Files\Common Files\Macromedia
2008-09-12 12:35 ——— d—–w C:\Program Files\iTunes(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\iPod(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\Apple Software Update(2)
2008-08-29 14:18 87,336 —-a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 13:53 61,440 —-a-w C:\WINDOWS\system32\dnssd.dll
2008-07-19 02:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
.

((((((((((((((((((((((((((((( snapshot@2008-10-08_18.45.59.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 00:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
- 2008-10-08 11:30:49 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-10-10 12:20:47 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-10-08 11:30:49 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-10-10 12:20:47 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-10-08 11:30:49 49,152 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-10 12:20:47 49,152 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-08 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-07 159744]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-11 335872]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2003-09-26 237568]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-21 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2008-09-18 333120]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"AGRSMMSG"="AGRSMMSG.exe" [2003-09-30 C:\WINDOWS\AGRSMMSG.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-15 108544]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\seneka.sys]
@="driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
–a—— 2003-10-07 23:41 28672 C:\WINDOWS\system32\Ati2mdxx.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 IFP300;iRiver Internet Audio Player IFP-300;C:\WINDOWS\system32\DRIVERS\ifp300.sys [2003-03-06 13543]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2008-10-02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-10-10 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-08 17:22]

2008-10-10 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-10 12:40:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????1?5?8?7??p???? ?deB???????????????B? ??????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka]
"imagepath"="\systemroot\system32\drivers\seneka.sys"
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-10-10 12:53:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-10 16:53:28
ComboFix2.txt 2008-10-09 16:05:10
ComboFix3.txt 2008-10-08 22:48:23
ComboFix4.txt 2008-09-29 14:31:45

Pre-Run: 65,473,359,872 bytes free
Post-Run: 65,029,201,920 bytes free

223 — E O F — 2008-09-18 21:35:03



GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-10-10 13:18:33
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.14 —-

SSDT F8BDA89C ZwCreateThread
SSDT F8BDA888 ZwOpenProcess
SSDT F8BDA88D ZwOpenThread
SSDT F8BDA897 ZwTerminateProcess
SSDT F8BDA892 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.14 —-

? Combo-Fix.sys The system cannot find the file specified. !
? C:\ComboFix\catchme.sys The system cannot find the path specified. !
? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !

—- Devices - GMER 1.0.14 —-

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 EABFiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Company)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 EABFiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Company)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Services - GMER 1.0.14 —-

Service system32\drivers\seneka.sys (*** hidden *** ) [SYSTEM] seneka <– ROOTKIT !!!

—- Registry - GMER 1.0.14 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\seneka@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\seneka@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\seneka@imagepath \systemroot\system32\drivers\seneka.sys
Reg HKLM\SYSTEM\ControlSet003\Services\seneka@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\seneka@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\seneka@imagepath \systemroot\system32\drivers\seneka.sys

—- EOF - GMER 1.0.14 —-
filmcynic,

Ah-ha! Now we're getting somewhere. We made that nasty rootkit show itself. Now to rip it out.

"System error 1060 has occurred. The specified device does not exist as an installed service."

Probably related to this issue. Not a problem for what we needed.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    Rootkit::
    C:\WINDOWS\system32\senekadf.dll
    C:\WINDOWS\system32\senekadf.dat
    C:\WINDOWS\system32\seneka.dat
    C:\WINDOWS\system32\senekaul.dat
    C:\WINDOWS\system32\seneka.dll
    C:\WINDOWS\system32\senekakl.dat
    \systemroot\system32\drivers\seneka.sys
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\seneka.sys]
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka]
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka@start 1]
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka@type 1]
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka@imagepath]
    
    Driver::
    Seneka
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Lets run an F-Secure online scan it will scan for Viruses, Spyware and RootKits:
  • Click HERE
  • Scroll to the bottom of the page and click the Start Scanning button. A window will pop up.
  • Allow the Active X control to be installed on your computer, then click the Accept button
  • Click Full System Scan and allow the components to download and the scan to complete.
  • If malware is found, check Submit samples to F-Secure then select Automatic cleaning
  • When cleaning has finished, click Show report (this will open an Internet Explorer window containing the report)
    Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
If Automatic cleaning with Submit samples hangs, click Cancel, then New Scan
  • When the cleaning option is presented, Uncheck Submit samples to F-Secure
  • Click Automatic cleaning
  • When cleaning has finished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post with a new Hijackthis log.

Note: This scan will only work with Internet Explorer.
You must be logged on a administrator rights to run this scan.
The scan may take a few hours.
Sorry for the lapse in replying, Tomk. I honestly forgot about getting the update alert last Friday and thought I was still waiting for another reply.

OK, so first of all, thank you so much for finding and erasing the thing that was causing my internet block. For the first time, I was able to access WhatTheTech.com on my own computer. Also, I was finally able to do an online scan.

Here are the logs/reports:



ComboFix 08-10-14.03 - Christopher 2008-10-14 17:31:58.7 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Christopher\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\seneka.dat
C:\WINDOWS\system32\senekadf.dat
C:\WINDOWS\system32\senekakl.dat
C:\WINDOWS\system32\senekaul.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_seneka


((((((((((((((((((((((((( Files Created from 2008-09-14 to 2008-10-14 )))))))))))))))))))))))))))))))
.

2008-10-10 13:06 . 2008-10-10 13:06 250 –a—— C:\WINDOWS\gmer.ini
2008-10-07 00:31 . 2008-10-07 00:32 d——– C:\Program Files\iTunes
2008-10-07 00:31 . 2008-10-07 00:31 d——– C:\Program Files\iPod
2008-10-07 00:31 . 2008-10-07 00:32 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-02 17:23 . 2008-10-02 17:32 d——– C:\Program Files\SpywareBlaster
2008-09-30 14:35 . 2008-09-30 14:35 d——– C:\Program Files\BillP Studios
2008-09-30 14:35 . 2008-09-30 14:35 d——– C:\Documents and Settings\Christopher\Application Data\WinPatrol
2008-09-28 16:42 . 2008-09-28 16:52 d——– C:\Lop SD
2008-09-26 10:30 . 2008-09-26 10:30 d——– C:\WINDOWS\ERUNT
2008-09-25 12:34 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-25 12:32 . 2008-09-25 12:32 d——– C:\Program Files\Common Files\Java
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Program Files\Avira
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-09-24 12:16 . 2008-09-24 12:16 d——– C:\Documents and Settings\Christopher\Application Data\Malwarebytes
2008-09-24 12:16 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-24 12:16 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-24 12:15 . 2008-09-24 12:19 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-24 12:15 . 2008-09-24 12:15 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-23 17:15 . 2008-09-23 17:15 d——– C:\Program Files\ERUNT
2008-09-21 00:02 . 2008-09-21 00:02 d——– C:\Program Files\Apple Software Update
2008-09-18 19:36 . 2008-09-18 19:36 d——– C:\Program Files\Trend Micro
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Program Files\Security Task Manager2
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-09-18 19:21 . 2008-09-18 19:21 d——– C:\Program Files\Security Task Manager
2008-09-16 08:19 . 2008-10-11 09:22 d——– C:\WINDOWS\system32\CatRoot_bak

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-14 12:18 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-10-01 17:01 32,000 —-a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-09-25 16:34 ——— d—–w C:\Program Files\Java
2008-09-21 04:06 ——— d—–w C:\Program Files\Bonjour
2008-09-21 04:04 ——— d—–w C:\Program Files\QuickTime
2008-09-21 04:04 ——— d—–w C:\Program Files\Common Files\Apple
2008-09-12 12:42 ——— d—–w C:\Program Files\Safari
2008-09-12 12:39 ——— d—–w C:\Program Files\Common Files\Macromedia
2008-09-12 12:35 ——— d—–w C:\Program Files\iTunes(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\iPod(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\Apple Software Update(2)
.

((((((((((((((((((((((((((((( snapshot@2008-10-08_18.45.59.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 00:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
+ 2008-10-10 17:06:47 884,736 —-a-w C:\WINDOWS\gmer.dll
+ 2008-04-18 01:13:02 811,008 —-a-w C:\WINDOWS\gmer.exe
- 2008-10-08 11:30:49 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-10-10 12:20:47 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-10-08 11:30:49 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-10-10 12:20:47 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-10-08 11:30:49 49,152 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-10 12:20:47 49,152 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-10 17:06:47 85,969 —-a-w C:\WINDOWS\system32\drivers\gmer.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-08 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-07 159744]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-11 335872]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2003-09-26 237568]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-21 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2008-09-18 333120]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"AGRSMMSG"="AGRSMMSG.exe" [2003-09-30 C:\WINDOWS\AGRSMMSG.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-15 108544]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
–a—— 2003-10-07 23:41 28672 C:\WINDOWS\system32\Ati2mdxx.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 IFP300;iRiver Internet Audio Player IFP-300;C:\WINDOWS\system32\DRIVERS\ifp300.sys [2003-03-06 13543]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2008-10-02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-10-14 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-08 17:22]

2008-10-14 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-14 17:38:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????1?5?8?7??????? ?deB???????????????B? ??????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2008-10-14 17:45:43 - machine was rebooted [Christopher]
ComboFix-quarantined-files.txt 2008-10-14 21:45:38
ComboFix2.txt 2008-10-10 16:53:50
ComboFix3.txt 2008-10-09 16:05:10
ComboFix4.txt 2008-10-08 22:48:23
ComboFix5.txt 2008-10-14 21:29:22

Pre-Run: 64,868,421,632 bytes free
Post-Run: 65,219,350,528 bytes free

158 — E O F — 2008-10-11 13:24:18




Scanning Report
Tuesday, October 14, 2008 18:08:22 - 19:54:12

Computer name: PORKCHOP
Scanning type: Scan system for malware, rootkits
Target: C:\
Result: 2 malware found
TrackingCookie.Atwola (spyware)

* System

TrackingCookie.Revsci (spyware)

* System

Statistics
Scanned:

* Files: 47832
* System: 3349
* Not scanned: 6

Actions:

* Disinfected: 0
* Renamed: 0
* Deleted: 0
* None: 2
* Submitted: 0

Files not scanned:

* C:\PAGEFILE.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\WINDOWS\SYSTEM32\CONFIG\SAM
* C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
* C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
* C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM

Options
Scanning engines:

* F-Secure USS: 2.30.0
* F-Secure Hydra: 2.8.8110, 2008-10-14
* F-Secure AVP: 7.0.171, 2008-10-14
* F-Secure Pegasus: 1.20.0, 2008-09-01
* F-Secure Blacklight: 1.0.68

Scanning options:

* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
* Use Advanced heuristics

Copyright © 1998-2007 Product support |Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
filmcynic, No problem. This has been a tough battle. Thanks for hanging in there with me. :thumbup: How are things on your end now? If it is looking good, we'll clean up and let you go.
Actually I might not be getting the update emails from the forum, since I just came on on a whim and saw your latest reply. Everything seems good on my end now, though the computer seems a bit slow. That could be due to all the monitoring going on, I don't know.
filmcynic,

Actually I might not be getting the update emails from the forum, since I just came on on a whim and saw your latest reply.

It happens sometime. Sometimes I don't get a notice until hours after I've already responded.

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Please re-enable any security that was disabled.
Please delete any tools that we used.

You mentioned before that you were having trouble with restore points. Here is how to manually do it:
You need to create a new Clean restore point.
Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Let me know if you need anything else. I'm going to leave this thread open a couple of days just in case.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI