Zincdust
Topic Starter
Howdy partners!
OK, upon doing my routine PC sweeps, I came across two unusual files which had found their way on there recently, by the names of:
c:\windows\system32\brh831b1.exe.a_a
c:\windows\system32\yxkRuU0c.exe.a_a
Both of which seemed to be empty (property count showing 0KB).
I run a gaggle of different spyware/virus detectors, and when I ran Avast!, the two files seemed to duplicate themselves into all-new .exe (same location/file names, but without the ".a_a" extension on the end), and they had file sizes of 41KB each. What was even more disturbing was that ever since that point, the "brh831b1.exe" file has been trying to access the network every 30-60 seconds (to be blocked by my Sysgate Personal Firewall).
Here is my HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:39:30 PM, on 11/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ps2.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\The R Files\Hijack This\HijackThis.exe
C:\WINDOWS\system32\brh831b1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: Add To HP Organize… - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1142808952000
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.disneyphotopass.com/software/ImageUploader4.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111…all/xscan53.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://onlinedesigner.hgtv.com/images/app/view22rte.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
–
End of file - 11057 bytes
And, if it will help, my ComboFix log:
ComboFix 08-11-03.04 - Owner 2008-11-03 23:22:32.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.345 [GMT -8:00]
Running from: c:\the r files\FireFox Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\bold.log
c:\windows\IE4 Error Log.txt
c:\windows\system32\brh831b1.exe.a_a
c:\windows\system32\yxkRuU0c.exe.a_a
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-10-04 to 2008-11-04 )))))))))))))))))))))))))))))))
.
2008-11-03 22:39 . 2008-11-03 22:39 41,474 –a—— c:\windows\system32\brh831b1.exe
2008-11-03 19:29 . 2007-09-29 11:23 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2008-11-03 19:26 . 2008-11-03 19:26 410,976 –a—— c:\windows\system32\deploytk.dll
2008-11-02 20:39 . 2008-11-02 20:39 31,744 –a—— c:\windows\system32\yxkRuU0c.exe
2008-11-02 11:12 . 2008-11-02 11:12 54,156 –ah—– c:\windows\QTFont.qfn
2008-11-02 11:12 . 2008-11-02 11:12 1,409 –a—— c:\windows\QTFont.for
2008-10-25 20:52 . 2008-11-02 07:49 d——– c:\program files\Mystery Case Files - Ravenhearst
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-04 03:26 ——— d—–w c:\program files\Java
2008-11-03 21:45 ——— d—–w c:\program files\Lavasoft
2008-11-03 21:45 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-11-03 21:43 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-03 20:23 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-11-02 16:57 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-02 05:28 ——— d—–w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-10-26 04:50 ——— d—–w c:\program files\bfgclient
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-08-26 07:24 826,368 —-a-w c:\windows\system32\wininet.dll
2008-08-14 10:00 2,180,352 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:22 2,057,728 —-a-w c:\windows\system32\ntkrnlpa.exe
2008-06-26 17:01 106,496 -c–a-w c:\documents and settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-05-24 20:56 0 —-a-w c:\program files\temp01
2005-03-21 03:26 0 -csha-w c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\program files\HP\Digital Imaging\bin\backupnotify.exe" [2004-01-09 32768]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-17 68856]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-06-11 4670968]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPHUPD05"="c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 49152]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-08-21 483328]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 218032]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-06-03 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-03 136600]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-10-15 2577632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-01-27 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 c:\windows\AGRSMMSG.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-12-13 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 282624]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Finding Nemo Communicator]
–a—— 2008-03-02 10:06 2805760 c:\program files\Finding Nemo Communicator\Finding Nemo Communicator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 JavaQuickStarterService;Java Quick Starter;c:\program files\Java\jre6\bin\jqs.exe [2008-11-03 152984]
S3 marsqx5;Digital Blue QX5 V2 Microscope;c:\windows\system32\DRIVERS\marsqx5.sys [2007-04-02 72576]
S3 pnicml;pnicml;c:\docume~1\Owner\LOCALS~1\Temp\pnicml.sys [ ]
*Newly Created Service* - JAVAQUICKSTARTERSERVICE
*Newly Created Service* - PROCEXP90
*Newly Created Service* - TMCOMM
.
Contents of the 'Scheduled Tasks' folder
2008-10-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 14:42]
2008-11-03 c:\windows\Tasks\At1.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At10.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At11.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At12.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At13.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At14.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At15.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At16.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At17.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At18.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At19.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At2.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At20.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At21.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At22.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At23.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At24.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At3.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At4.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At49.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-03 c:\windows\Tasks\At5.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At50.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At51.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At52.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At53.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At54.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At55.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At56.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At57.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At58.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At59.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-03 c:\windows\Tasks\At6.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At60.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At61.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At62.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At63.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At64.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At65.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At66.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At67.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At68.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At69.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-03 c:\windows\Tasks\At7.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At70.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At71.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At72.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-03 c:\windows\Tasks\At8.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At9.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-02 c:\windows\Tasks\EasyShare Registration Task.job
- c:\windows\system32\rundll32.exe [2004-08-03 23:56]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-RecordNow! - (no file)
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\x8dr9tcd.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/
FF -: plugin - c:\documents and settings\Owner\Application Data\Mozilla\plugins\npPxPlay.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\NPcol305.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npsnapfish.dll
FF -: plugin - c:\program files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-03 23:28:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
Completion time: 2008-11-03 23:32:23
ComboFix-quarantined-files.txt 2008-11-04 07:32:13
Pre-Run: 32,682,041,344 bytes free
Post-Run: 37,929,975,808 bytes free
244 — E O F — 2008-10-25 03:02:55
The combofix seemed to get rid of the original ".a_a" files, but the ".exe" files are still there. Any help would be greatly appreciated. Thanks a million in advance!!
OK, upon doing my routine PC sweeps, I came across two unusual files which had found their way on there recently, by the names of:
c:\windows\system32\brh831b1.exe.a_a
c:\windows\system32\yxkRuU0c.exe.a_a
Both of which seemed to be empty (property count showing 0KB).
I run a gaggle of different spyware/virus detectors, and when I ran Avast!, the two files seemed to duplicate themselves into all-new .exe (same location/file names, but without the ".a_a" extension on the end), and they had file sizes of 41KB each. What was even more disturbing was that ever since that point, the "brh831b1.exe" file has been trying to access the network every 30-60 seconds (to be blocked by my Sysgate Personal Firewall).
Here is my HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:39:30 PM, on 11/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ps2.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\The R Files\Hijack This\HijackThis.exe
C:\WINDOWS\system32\brh831b1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: Add To HP Organize… - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1142808952000
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.disneyphotopass.com/software/ImageUploader4.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111…all/xscan53.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://onlinedesigner.hgtv.com/images/app/view22rte.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
–
End of file - 11057 bytes
And, if it will help, my ComboFix log:
ComboFix 08-11-03.04 - Owner 2008-11-03 23:22:32.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.345 [GMT -8:00]
Running from: c:\the r files\FireFox Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\bold.log
c:\windows\IE4 Error Log.txt
c:\windows\system32\brh831b1.exe.a_a
c:\windows\system32\yxkRuU0c.exe.a_a
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-10-04 to 2008-11-04 )))))))))))))))))))))))))))))))
.
2008-11-03 22:39 . 2008-11-03 22:39 41,474 –a—— c:\windows\system32\brh831b1.exe
2008-11-03 19:29 . 2007-09-29 11:23 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2008-11-03 19:26 . 2008-11-03 19:26 410,976 –a—— c:\windows\system32\deploytk.dll
2008-11-02 20:39 . 2008-11-02 20:39 31,744 –a—— c:\windows\system32\yxkRuU0c.exe
2008-11-02 11:12 . 2008-11-02 11:12 54,156 –ah—– c:\windows\QTFont.qfn
2008-11-02 11:12 . 2008-11-02 11:12 1,409 –a—— c:\windows\QTFont.for
2008-10-25 20:52 . 2008-11-02 07:49 d——– c:\program files\Mystery Case Files - Ravenhearst
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-04 03:26 ——— d—–w c:\program files\Java
2008-11-03 21:45 ——— d—–w c:\program files\Lavasoft
2008-11-03 21:45 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-11-03 21:43 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-03 20:23 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-11-02 16:57 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-02 05:28 ——— d—–w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-10-26 04:50 ——— d—–w c:\program files\bfgclient
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-08-26 07:24 826,368 —-a-w c:\windows\system32\wininet.dll
2008-08-14 10:00 2,180,352 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:22 2,057,728 —-a-w c:\windows\system32\ntkrnlpa.exe
2008-06-26 17:01 106,496 -c–a-w c:\documents and settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2008-05-24 20:56 0 —-a-w c:\program files\temp01
2005-03-21 03:26 0 -csha-w c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\program files\HP\Digital Imaging\bin\backupnotify.exe" [2004-01-09 32768]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-17 68856]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-06-11 4670968]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPHUPD05"="c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 49152]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-08-21 483328]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 218032]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-06-03 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-03 136600]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-10-15 2577632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-01-27 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 c:\windows\AGRSMMSG.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-12-13 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 282624]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Finding Nemo Communicator]
–a—— 2008-03-02 10:06 2805760 c:\program files\Finding Nemo Communicator\Finding Nemo Communicator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 JavaQuickStarterService;Java Quick Starter;c:\program files\Java\jre6\bin\jqs.exe [2008-11-03 152984]
S3 marsqx5;Digital Blue QX5 V2 Microscope;c:\windows\system32\DRIVERS\marsqx5.sys [2007-04-02 72576]
S3 pnicml;pnicml;c:\docume~1\Owner\LOCALS~1\Temp\pnicml.sys [ ]
*Newly Created Service* - JAVAQUICKSTARTERSERVICE
*Newly Created Service* - PROCEXP90
*Newly Created Service* - TMCOMM
.
Contents of the 'Scheduled Tasks' folder
2008-10-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 14:42]
2008-11-03 c:\windows\Tasks\At1.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At10.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At11.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At12.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At13.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At14.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At15.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At16.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At17.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At18.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At19.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At2.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At20.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At21.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At22.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At23.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At24.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At3.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At4.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At49.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-03 c:\windows\Tasks\At5.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At50.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At51.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At52.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At53.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At54.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At55.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At56.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At57.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At58.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At59.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-03 c:\windows\Tasks\At6.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At60.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At61.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At62.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At63.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At64.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At65.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At66.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At67.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At68.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At69.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-03 c:\windows\Tasks\At7.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-04 c:\windows\Tasks\At70.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At71.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-04 c:\windows\Tasks\At72.job
- c:\windows\system32\brh831b1.exe [2008-11-03 22:39]
2008-11-03 c:\windows\Tasks\At8.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-03 c:\windows\Tasks\At9.job
- c:\windows\system32\yxkRuU0c.exe [2008-11-02 20:39]
2008-11-02 c:\windows\Tasks\EasyShare Registration Task.job
- c:\windows\system32\rundll32.exe [2004-08-03 23:56]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-RecordNow! - (no file)
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\x8dr9tcd.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/
FF -: plugin - c:\documents and settings\Owner\Application Data\Mozilla\plugins\npPxPlay.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\NPcol305.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npsnapfish.dll
FF -: plugin - c:\program files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-03 23:28:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
Completion time: 2008-11-03 23:32:23
ComboFix-quarantined-files.txt 2008-11-04 07:32:13
Pre-Run: 32,682,041,344 bytes free
Post-Run: 37,929,975,808 bytes free
244 — E O F — 2008-10-25 03:02:55
The combofix seemed to get rid of the original ".a_a" files, but the ".exe" files are still there. Any help would be greatly appreciated. Thanks a million in advance!!