This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help! Trojan Horse Clicker.SXT & Clicker.TQR

81 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello all and thank you so much for your help. This site is a great resource and I hope you can help me get rid of this annoying issue. AVG detected Trojan horse Clicker.TQR and Clicker.SXT on my computer a couple of days ago. I get alerts and send them to the vault, but it keeps coming back. I randomly get pop-ups and sounds and soundclips and can't seem to stop them. I also get low Windows virtual memory alerts. Any help is very much appreciated.

Here is my HiJack This log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:27:49 PM, on 11/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\Program Files\Corel\Graphics10\Programs\photopnt.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\Program Files\Adobe\Acrobat 4.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Microsoft Office\OFFICE11\FRONTPG.EXE
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
C:\Program Files\eAcceleration\Station\station_bk.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
C:\Program Files\Adobe\Acrobat 4.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
O4 - HKLM\..\Run: [StopSignSsSsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\ssssmon.dll",VerifyStatus
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
O4 - HKLM\..\RunOnce: [StopSignSsSsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\ssssmon.dll",VerifyStatus /ro
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: eAcceleration Notification Service (eac_notifysvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
O23 - Service: eAcceleration Product Manager Service (eac_productsvc) - eAcceleration Corp - C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\WINDOWS\system32\Wacom_Tablet.exe

–
End of file - 8054 bytes

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.


Unless informed of in advance, failure to post replies within 5 days will result in this thread being closed.


Hi FrancescoF

I'm Gary R, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
If you can do these things, everything should go smoothly.
  • If you're using XP, you'll need Administrator privileges to perform the fixes. (XP accounts are Administrator by default)
  • If you're using Vista, it will be necessary to right click all tools we use and select —-> Run as Admistrator

It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.


You appear to have both AVG and e-Acceleration Stop Sign installed as anti-virus protection on your computer. Having two Anti-Virus programmes will cause conflicts, uninstall one of those programmes immediately using Control Panel > Add/Remove Programmes. I recommend you keep AVG.

OK, now for getting rid of your infection.

Please download Malwarebytes' Anti-Malware to your Desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.

  • Click on the Malwarebytes' Anti-Malware icon to launch the programme.
    • Click the Updates tab.
    • Click Check for Updates and allow the programme to download the latest definitions.
  • Click the Scanner tab.
    • Check Perform Full Scan.
    • Click Scan and wait for the scan to complete.
    • When the scan is complete, click OK, then Show Results.
    • Ensure all items are checked then click Remove Selected.
    • A box will pop-up telling you that files have been quarantined.
    • A log will pop-up.
  • Post the log in your next reply please.

You can also access the log by doing the following
  • Click on the Logs tab.
  • Click on the log at the bottom of those listed to highlight it.
  • Click Open

Next

  • Click Start > Run and type cleanmgr then click OK.
  • This will bring up the Disk Cleanup window.
  • Check the following entries.
    • Temporary Internet Files.
    • Recycle Bin.
    • Temporary Files.
  • Click OK.
  • When a prompt pops up click Yes.

Then

I need you to run an online scan for me (this scan needs you to have Java installed).

If you don't already have Java
  • Click here to visit Java's website.
  • Scroll down to Java Runtime Environment (JRE) 6 Update 7.
  • Click on Download.
  • Select Windows from the drop-down list for Platform.
  • Select Multi-language from the drop-down list for Language.
  • Check (tick) I agree to the Java SE Runtime Environment 6 License Agreement box and click on Continue.
  • Click on the jre-6u7-windows-i586-p.exe link to download, and save it to a convenient location.
  • Double click on jre-6u7-windows-i586-p.exe to install Java.

After installing Java, or if you already have Java installed.
  • Please go to Kaspersky Online Scanner.
  • Read through the requirements and privacy statement and click on the Accept button.
  • It will start downloading and installing the scanner and virus definitions.
    • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they're not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers and other potentially dangerous programs.
    • Archives.
    • Mail databases.
  • Under Scan, click on My Computer.
  • Once the scan is complete, it will display the results.
    • Click on View Scan Report.
  • You will see a list of infected items.
    • Click the Save Report As… button (see red arrow below)

      [external image: Posted Image]
    • In the Save as… prompt, select Desktop
    • In the File name box, name the file KAVScan
    • In the Save as type prompt, select Text file (see below)

      [external image: Posted Image]
    • Copy and paste that information in your next post please.

Finally

Run a new scan with HJT and post me the log please.

Summary of the logs I need from you in your next post:
  • MBAM log
  • Kaspersky log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.
Hi Gary, thank you so much for replying and taking care of this, I really appreciate it :) Stop SIgn is a trial version I downloaded last night in my clumsy attempt to get tird of these trojans. I am definitely sticking with AVG and will unintsall Stop SIgn and then follow your instructions. Right now I am backing up all my work files just in case somethign goes wrong in the process (I have been burned already once for not backing up files and the data recovery wasn't cheap at all ;)). Thanks again and will be back with those logs you asked . Cheers, Francesco
Hi Gary, here's the mbam log. Thanks , Francesco Malwarebytes' Anti-Malware 1.30 Database version: 1370 Windows 5.1.2600 Service Pack 2 11/6/2008 3:03:20 PM mbam-log-2008-11-06 (15-03-20).txt Scan type: Full Scan (C:\|) Objects scanned: 153587 Time elapsed: 1 hour(s), 12 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\Kxl7BJoS.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lAcOUYa8.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
Hi Gary, here's the Kaspersky scan result: it didn't find anything but I have a couple of notes: 1) halfway the scan I noticed the footnote about turning off other antivirus before scanning, but I didn't turn off my AVG (I did, however, uninstall stop-sign). Do I need to run the K-scan again with avg turned off? 2) during the K-scan I got one of those audio ads popping up and telling me I won a laptop! While I should be happy for the prize (being sarcastic here ;)) that shows the adware or whatever it is is still on the machine. New HJT log coming soon. Thanks, Francesco ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Thursday, November 6, 2008 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Thursday, November 06, 2008 17:36:36 Records in database: 1372674 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 105250 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 01:33:14 No malware has been detected. The scan area is clean. The selected area was scanned.
Here's the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:13:55 PM, on 11/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
c:\program files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jdk/6u1…ows-i586-jc.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\WINDOWS\system32\Wacom_Tablet.exe

–
End of file - 7316 bytes
Hi Gary, can I work on the machine (I do graphics) while we fix this or do I need to stay away from softwares (Corel, Flash) until we are clean? Cheers, Francesco
OK, I can see that the file that MBAM removed is back, so either you've been re-infected, or we missed something and it's replaced the file.

We need to look a little deeper into your machine and see if we can find what we've missed.

Download GMER and unzip it to your Desktop. (It will create a folder GMER)

Alternate Download Site

  • Disconnect from the Internet, and close all running programmes.
  • There is a small chance this programme may crash your computer, so save any work you have open.
  • Open the GMER folder, and double click gmer.exe
  • Let the gmer.sys driver load if asked.
  • If it gives you a warning at programme start about rootkit activity and asks if you want to run a scan ….. click OK.
  • If no warning:
    • Click Rootkit tab.
    • Ensure that All the boxes to the right of the program are checked except Show All.
    • Click Scan.
  • Do not use your computer while the scan is running.
  • Once scan is finished click Copy.
    • Click Start > Run then type Notepad.exe then click OK.
    • This will open a Notepad file.
    • Hit Ctrl+V to paste log into it.
    • Save the log to your Desktop.
  • Reconnect to internet and post the log please.

Next

Download ComboFix from one of these locations and save it to your Desktop:

Link 1
Link 2
Link 3

IMPORTANT !!! ComboFix.exe must be run from your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with Combofix. There are details for disabling many programmes here.
  • Double click on ComboFix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install Microsoft Windows Recovery Console.

**Please note: If Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

Once Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you.

Please include this log in your next reply. ……… (it can also be found at C:\ComboFix.txt)

IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • If you've lost your Internet connection when Combofix has completely finished, re-start your computer to restore it.
If you have any problems with these instructions, a detailed Tutorial for how to use Combofix is available here.

Finally

Run a new scan with HJT and post me the log please.

Summary of the logs I need from you in your next post:
  • GMER log
  • Combofix log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.

Probably best not to go online too much until we get this thing cleared fully from your computer. There's no sign so far that we're dealing with a file infector, so should be OK for you to work on your computer though.
Hi Gary,

here's the GMER log (sorry for the delay but I am in US so there is a time gap between us ;))

Running combo fix now.

Thanks,
Francesco

——————————

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-11-07 08:38:59
Windows 5.1.2600 Service Pack 2


—- User code sections - GMER 1.0.14 —-

.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2056] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 42F0F301 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2056] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 430A179F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2056] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 430A1720 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2056] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 430A1764 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2056] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 430A16AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2056] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 430A16E6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2056] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 430A17DA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2056] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 42F316B6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3832] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 42F0F301 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3832] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 430A179F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3832] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 430A1720 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3832] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 430A1764 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3832] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 430A16AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3832] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 430A16E6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3832] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 430A17DA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3832] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 42F316B6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- EOF - GMER 1.0.14 —-
Hi Gary,

here's the combofix log.

Thanks,
Francesco

—————

ComboFix 08-11-06.01 - Owner 2008-11-07 9:00:49.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2516 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\bold.log
c:\windows\system32\Kxl7BJoS.exe.a_a

.
((((((((((((((((((((((((( Files Created from 2008-10-07 to 2008-11-07 )))))))))))))))))))))))))))))))
.

2008-11-07 08:15 . 2008-11-07 08:15 250 –a—— c:\windows\gmer.ini
2008-11-06 15:18 . 2008-11-06 15:18 d——– c:\windows\Sun
2008-11-06 15:17 . 2008-11-06 15:17 d——– c:\program files\Java
2008-11-06 15:17 . 2008-11-06 15:17 410,976 –a—— c:\windows\system32\deploytk.dll
2008-11-06 15:17 . 2008-11-06 15:17 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-11-06 13:48 . 2008-11-06 13:48 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-06 13:48 . 2008-11-06 13:48 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-11-06 13:48 . 2008-11-06 13:48 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-06 13:48 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-06 13:48 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-05 22:27 . 2008-11-05 22:27 d——– c:\program files\Trend Micro
2008-11-05 20:13 . 2008-11-05 20:13 d——– c:\program files\Lavasoft
2008-11-05 20:13 . 2008-11-05 20:13 d——– c:\program files\Common Files\Wise Installation Wizard
2008-11-05 20:13 . 2008-11-05 20:15 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-04 06:14 . 2008-11-07 08:43 41,986 –a—— c:\windows\system32\Kxl7BJoS.exe
2008-11-04 06:14 . 2008-11-06 23:02 41,474 –a—— c:\windows\system32\Kxl7BJoS.exe_
2008-11-02 23:55 . 2008-11-02 23:54 31,744 –a—— c:\windows\system32\lAcOUYa8.exe
2008-10-16 21:15 . 2008-10-16 21:15 d——– c:\program files\iTunes
2008-10-16 21:15 . 2008-10-16 21:15 d——– c:\program files\iPod
2008-10-16 21:15 . 2008-10-16 21:15 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-07 12:02 ——— d—–w c:\documents and settings\Owner\Application Data\WTablet
2008-10-01 17:01 32,000 —-a-w c:\windows\system32\drivers\usbaapl.sys
2008-09-25 00:26 ——— d—–w c:\documents and settings\Owner\Application Data\Apple Computer
2008-09-24 22:51 ——— d—–w c:\program files\Apple Software Update
2008-09-24 22:37 ——— d—–w c:\program files\QuickTime
2008-09-24 22:33 ——— d—–w c:\program files\Bonjour
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-08-29 14:18 87,336 —-a-w c:\windows\system32\dns-sd.exe
2008-08-29 13:53 61,440 —-a-w c:\windows\system32\dnssd.dll
2008-08-26 07:24 826,368 —-a-w c:\windows\system32\wininet.dll
2008-08-14 09:58 2,136,064 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:22 2,015,744 —-a-w c:\windows\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2006-04-07 135168]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-19 925696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-08-28 185632]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-09-30 1234712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-06 136600]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 c:\windows\system32\HdAShCut.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2007-08-24 135680]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R2 JavaQuickStarterService;Java Quick Starter;c:\program files\Java\jre6\bin\jqs.exe [2008-11-06 152984]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2007-09-07 1373480]
R3 wacommousefilter;Wacom Mouse Filter Driver;c:\windows\system32\DRIVERS\wacommousefilter.sys [2007-02-16 11312]
R3 wacomvhid;Wacom Virtual Hid Driver;c:\windows\system32\DRIVERS\wacomvhid.sys [2007-02-16 12848]
R3 WacomVKHid;Virtual Keyboard Driver;c:\windows\system32\DRIVERS\WacomVKHid.sys [2007-02-15 11440]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - e:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80498636-c9b1-11dc-9b56-00173171b4a3}]
\Shell\AutoRun\command - e:\wd_windows_tools\setup.exe

*Newly Created Service* - GMER
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2008-11-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-11-03 c:\windows\Tasks\At1.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-06 c:\windows\Tasks\At10.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-06 c:\windows\Tasks\At11.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-06 c:\windows\Tasks\At12.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-06 c:\windows\Tasks\At13.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-06 c:\windows\Tasks\At14.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-06 c:\windows\Tasks\At15.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-06 c:\windows\Tasks\At16.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-06 c:\windows\Tasks\At17.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-06 c:\windows\Tasks\At18.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-06 c:\windows\Tasks\At19.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-03 c:\windows\Tasks\At2.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-07 c:\windows\Tasks\At20.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-07 c:\windows\Tasks\At21.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-07 c:\windows\Tasks\At22.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-07 c:\windows\Tasks\At23.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-07 c:\windows\Tasks\At24.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-04 c:\windows\Tasks\At25.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-04 c:\windows\Tasks\At26.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-04 c:\windows\Tasks\At27.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-04 c:\windows\Tasks\At28.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-04 c:\windows\Tasks\At29.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-03 c:\windows\Tasks\At3.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-04 c:\windows\Tasks\At30.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-04 c:\windows\Tasks\At31.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-06 c:\windows\Tasks\At32.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-07 c:\windows\Tasks\At33.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-06 c:\windows\Tasks\At34.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-06 c:\windows\Tasks\At35.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-06 c:\windows\Tasks\At36.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-06 c:\windows\Tasks\At37.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-06 c:\windows\Tasks\At38.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-06 c:\windows\Tasks\At39.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-03 c:\windows\Tasks\At4.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-06 c:\windows\Tasks\At40.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-06 c:\windows\Tasks\At41.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-06 c:\windows\Tasks\At42.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-06 c:\windows\Tasks\At43.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-07 c:\windows\Tasks\At44.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-07 c:\windows\Tasks\At45.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-07 c:\windows\Tasks\At46.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-07 c:\windows\Tasks\At47.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-07 c:\windows\Tasks\At48.job
- c:\windows\system32\Kxl7BJoS.exe [2008-11-07 08:43]

2008-11-03 c:\windows\Tasks\At5.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-03 c:\windows\Tasks\At6.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-04 c:\windows\Tasks\At7.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-06 c:\windows\Tasks\At8.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-07 c:\windows\Tasks\At9.job
- c:\windows\system32\lAcOUYa8.exe [2008-11-02 23:54]

2008-11-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Corel Reminder - (no file)


.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\7bc52buw.default\
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Real\RhapsodyPlayerEngine\nprhapengine.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-07 09:02:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-11-07 9:02:51
ComboFix-quarantined-files.txt 2008-11-07 14:02:34

Pre-Run: 166,016,880,640 bytes free
Post-Run: 166,534,856,704 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

228 — E O F — 2008-11-07 12:06:40
And this is the HJT log: the bastard appears to be still there :(

F

—–
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:08:15 AM, on 11/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\Kxl7BJoS.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jdk/6u1…ows-i586-jc.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\WINDOWS\system32\Wacom_Tablet.exe

–
End of file - 6611 bytes
OK, think I can see why the thing keeps re-loading.

Download OTMoveIt3 by Old Timer and save it to your Desktop.
  • Double-click OTMoveIt3.exe to run it.
  • Copy the lines in the codebox below.
:Files
c:\windows\system32\Kxl7BJoS.exe
c:\windows\system32\Kxl7BJoS.exe_
c:\windows\system32\lAcOUYa8.exe
c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
c:\windows\Tasks\At*.job

:Reg
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=-
  • Return to OTMoveIt3, right click in the Paste Instructions for Items to be Moved window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.
  • Close OTMoveIt3

Run a scan with Combofix
  • First
    • Important! Temporarily disable your anti-virus, and anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its files which may cause unpredictable results.
    • Click here to see a list of programs that should be disabled (ignore the firewalls). The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Double click combofix.exe & follow the prompts.
  • Note: Combofix will automatically disconnect your Internet connection when it runs, do not reconnect it.
  • When finished, it will
    • Produce a log for you. (it can also be found at C:\Combofix.txt)
    • Restore your Internet connection.
  • Post the log in your next reply please.
  • Now run a new HJT scan and send me the log from that as well please.
IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • If you've lost your Internet connection when Combofix has completely finished, re-start your computer to restore it.
If you have any problems with these instructions, a detailed Tutorial for how to use Combofix is available here.

Summary of the logs I need from you in your next post:
  • OTMoveIt log
  • New Combofix log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.
Hi Gary, here's the moveit log. Gonna run the combofix scan now. Thanks again fo all your help, truly appreciated. Cheers, Francesco ========== FILES ========== c:\windows\system32\Kxl7BJoS.exe moved successfully. c:\windows\system32\Kxl7BJoS.exe_ moved successfully. c:\windows\system32\lAcOUYa8.exe moved successfully. c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86 moved successfully. c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86 moved successfully. c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} moved successfully. c:\windows\Tasks\At1.job moved successfully. c:\windows\Tasks\At10.job moved successfully. c:\windows\Tasks\At11.job moved successfully. c:\windows\Tasks\At12.job moved successfully. c:\windows\Tasks\At13.job moved successfully. c:\windows\Tasks\At14.job moved successfully. c:\windows\Tasks\At15.job moved successfully. c:\windows\Tasks\At16.job moved successfully. c:\windows\Tasks\At17.job moved successfully. c:\windows\Tasks\At18.job moved successfully. c:\windows\Tasks\At19.job moved successfully. c:\windows\Tasks\At2.job moved successfully. c:\windows\Tasks\At20.job moved successfully. c:\windows\Tasks\At21.job moved successfully. c:\windows\Tasks\At22.job moved successfully. c:\windows\Tasks\At23.job moved successfully. c:\windows\Tasks\At24.job moved successfully. c:\windows\Tasks\At25.job moved successfully. c:\windows\Tasks\At26.job moved successfully. c:\windows\Tasks\At27.job moved successfully. c:\windows\Tasks\At28.job moved successfully. c:\windows\Tasks\At29.job moved successfully. c:\windows\Tasks\At3.job moved successfully. c:\windows\Tasks\At30.job moved successfully. c:\windows\Tasks\At31.job moved successfully. c:\windows\Tasks\At32.job moved successfully. c:\windows\Tasks\At33.job moved successfully. c:\windows\Tasks\At34.job moved successfully. c:\windows\Tasks\At35.job moved successfully. c:\windows\Tasks\At36.job moved successfully. c:\windows\Tasks\At37.job moved successfully. c:\windows\Tasks\At38.job moved successfully. c:\windows\Tasks\At39.job moved successfully. c:\windows\Tasks\At4.job moved successfully. c:\windows\Tasks\At40.job moved successfully. c:\windows\Tasks\At41.job moved successfully. c:\windows\Tasks\At42.job moved successfully. c:\windows\Tasks\At43.job moved successfully. c:\windows\Tasks\At44.job moved successfully. c:\windows\Tasks\At45.job moved successfully. c:\windows\Tasks\At46.job moved successfully. c:\windows\Tasks\At47.job moved successfully. c:\windows\Tasks\At48.job moved successfully. c:\windows\Tasks\At5.job moved successfully. c:\windows\Tasks\At6.job moved successfully. c:\windows\Tasks\At7.job moved successfully. c:\windows\Tasks\At8.job moved successfully. c:\windows\Tasks\At9.job moved successfully. ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\software\microsoft\security center\\AntiVirusOverride deleted successfully. OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 11072008_131938
New combofix log:

—————————

ComboFix 08-11-06.01 - Owner 2008-11-07 13:36:34.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2403 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\bold.log
c:\windows\system32\Kxl7BJoS.exe.a_a

.
((((((((((((((((((((((((( Files Created from 2008-10-07 to 2008-11-07 )))))))))))))))))))))))))))))))
.

2008-11-07 13:19 . 2008-11-07 13:19 d——– C:\_OTMoveIt
2008-11-07 08:15 . 2008-11-07 08:15 250 –a—— c:\windows\gmer.ini
2008-11-06 15:18 . 2008-11-06 15:18 d——– c:\windows\Sun
2008-11-06 15:17 . 2008-11-06 15:17 d——– c:\program files\Java
2008-11-06 15:17 . 2008-11-06 15:17 410,976 –a—— c:\windows\system32\deploytk.dll
2008-11-06 15:17 . 2008-11-06 15:17 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-11-06 13:48 . 2008-11-06 13:48 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-06 13:48 . 2008-11-06 13:48 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-11-06 13:48 . 2008-11-06 13:48 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-06 13:48 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-06 13:48 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-05 22:27 . 2008-11-05 22:27 d——– c:\program files\Trend Micro
2008-11-05 20:13 . 2008-11-05 20:13 d——– c:\program files\Lavasoft
2008-11-05 20:13 . 2008-11-05 20:13 d——– c:\program files\Common Files\Wise Installation Wizard
2008-11-05 20:13 . 2008-11-05 20:15 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-10-16 21:15 . 2008-10-16 21:15 d——– c:\program files\iTunes
2008-10-16 21:15 . 2008-10-16 21:15 d——– c:\program files\iPod

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-07 12:02 ——— d—–w c:\documents and settings\Owner\Application Data\WTablet
2008-10-01 17:01 32,000 —-a-w c:\windows\system32\drivers\usbaapl.sys
2008-09-25 00:26 ——— d—–w c:\documents and settings\Owner\Application Data\Apple Computer
2008-09-24 22:51 ——— d—–w c:\program files\Apple Software Update
2008-09-24 22:37 ——— d—–w c:\program files\QuickTime
2008-09-24 22:33 ——— d—–w c:\program files\Bonjour
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-08-29 14:18 87,336 —-a-w c:\windows\system32\dns-sd.exe
2008-08-29 13:53 61,440 —-a-w c:\windows\system32\dnssd.dll
2008-08-26 07:24 826,368 —-a-w c:\windows\system32\wininet.dll
2008-08-14 09:58 2,136,064 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:22 2,015,744 —-a-w c:\windows\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2006-04-07 135168]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-19 925696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-08-28 185632]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-09-30 1234712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-06 136600]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 c:\windows\system32\HdAShCut.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2007-08-24 135680]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R2 JavaQuickStarterService;Java Quick Starter;c:\program files\Java\jre6\bin\jqs.exe [2008-11-06 152984]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2007-09-07 1373480]
R3 wacommousefilter;Wacom Mouse Filter Driver;c:\windows\system32\DRIVERS\wacommousefilter.sys [2007-02-16 11312]
R3 wacomvhid;Wacom Virtual Hid Driver;c:\windows\system32\DRIVERS\wacomvhid.sys [2007-02-16 12848]
R3 WacomVKHid;Virtual Keyboard Driver;c:\windows\system32\DRIVERS\WacomVKHid.sys [2007-02-15 11440]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - e:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80498636-c9b1-11dc-9b56-00173171b4a3}]
\Shell\AutoRun\command - e:\wd_windows_tools\setup.exe

*Newly Created Service* - CATCHME
*Newly Created Service* - GMER
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2008-11-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-11-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\7bc52buw.default\
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Real\RhapsodyPlayerEngine\nprhapengine.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-07 13:37:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-11-07 13:38:02
ComboFix-quarantined-files.txt 2008-11-07 18:37:47
ComboFix2.txt 2008-11-07 14:02:52

Pre-Run: 166,536,142,848 bytes free
Post-Run: 166,535,335,936 bytes free

119 — E O F — 2008-11-07 12:06:40

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI