This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I keep getting a antivirus warning from Nod32. A variant of win32/kryptik.ge/trojan. Full system scans with nod32 and spydoctor find nothing. :( Please help. TrendSecure Trend Micro Your current Web browser may not display this site properly. TrendSecure performs best when opened with the latest version of either Microsoft Internet Explorer or Mozilla Firefox. Comparison of your HijackThis log file items to others The table below compares the items HijackThis found on your computer with those on other people's computers. The column "% of PCs with item" indicates what percent of other people's HijackThis log files contain the item in that row of the table. Additional information will be provided as more HijackThis log files are added to the AnalyzeThis database. Each entry is coded to indicate the type of item it is on your computer. An explanation of these codes may be found at the bottom of this page. Index % of PCs with item Code Data 1 0.0% O1 212.150.54.250 dv-networks.com 2 0.0% O10 c:\windows\system32\nwprovau.dll 3 0.0% O2 Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll 4 0.0% O2 bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll 5 0.0% O2 Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbShar.dll 6 0.0% O2 SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll 7 0.0% O2 BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll 8 0.0% O22 Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll 9 0.0% O22 Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll 10 0.0% O23 NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe 11 0.0% O23 Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 12 0.0% O23 Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe 13 0.0% O23 NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe 14 0.0% O23 NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe 15 0.0% O23 Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe 16 0.0% O23 NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe 17 0.0% O23 Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe 18 0.0% O23 PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe 19 0.0% O23 PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe 20 0.0% O23 TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe 21 0.0% O23 Schedule - Unknown owner - C:\WINDOWS\system32\drivers\spool.exe (file missing) 22 0.0% O23 Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 23 0.0% O23 HTTP SSL HTTPFilterseclogon (HTTPFilterseclogon) - Unknown owner - C:\WINDOWS\system32\wpv7380.cpx.exe (file missing) 24 0.0% O3 Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbShar.dll 25 0.0% O4 [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') 26 0.0% O4 [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') 27 0.0% O4 [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup 28 0.0% O4 Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe 29 0.0% O4 [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') 30 0.0% O4 [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') 31 0.0% O4 [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot 32 0.0% O4 [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k 33 0.0% O4 [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE 34 0.0% O4 [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd 35 0.0% O4 [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions 36 0.0% O4 [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe 37 0.0% O4 [QuickTime Task] "C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" -atboottime 38 0.0% O4 [Microsoft all] C:\WINDOWS\mmall.exe (User 'SYSTEM') 39 0.0% O4 [ntuser] C:\WINDOWS\system32\drivers\spool.exe (User 'SYSTEM') 40 0.0% O8 E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 41 0.0% O8 &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm 42 0.0% O8 &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm 43 0.0% O8 &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm 44 0.0% O8 Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm 45 0.0% O8 Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm 46 0.0% O9 Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL 47 0.0% O9 BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing) 48 0.0% P01 C:\WINDOWS\Explorer.EXE 49 0.0% P01 C:\WINDOWS\system32\svchost.exe 50 0.0% P01 C:\WINDOWS\system32\lsass.exe 51 0.0% P01 C:\WINDOWS\system32\winlogon.exe 52 0.0% P01 C:\WINDOWS\system32\services.exe 53 0.0% P01 C:\WINDOWS\System32\smss.exe 54 0.0% P01 C:\WINDOWS\system32\spoolsv.exe 55 0.0% P01 C:\Program Files\Internet Explorer\iexplore.exe 56 0.0% P01 C:\WINDOWS\system32\nvsvc32.exe 57 0.0% P01 C:\WINDOWS\system32\rundll32.exe 58 0.0% P01 C:\Program Files\Common Files\Real\Update_OB\realsched.exe 59 0.0% P01 C:\Program Files\Eset\nod32krn.exe 60 0.0% P01 C:\Program Files\Eset\nod32kui.exe 61 0.0% P01 C:\Program Files\Canon\CAL\CALMAIN.exe 62 0.0% P01 C:\Documents and Settings\Admin\Desktop\HiJackThis_v2.exe 63 0.0% P01 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 64 0.0% R0 HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm 65 0.0% R3 Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbShar.dll Explanation of the codes R - Registry, StartPage/SearchPage changes R0 - Changed registry value R1 - Created registry value R2 - Created registry key R3 - Created extra registry value where only one should be F - IniFiles, autoloading entries F0 - Changed inifile value F1 - Created inifile value F2 - Changed inifile value, mapped to Registry F3 - Created inifile value, mapped to Registry N - Netscape/Mozilla StartPage/SearchPage changes N1 - Change in prefs.js of Netscape 4.x N2 - Change in prefs.js of Netscape 6 N3 - Change in prefs.js of Netscape 7 N4 - Change in prefs.js of Mozilla O - Other, several sections which represent: O1 - Hijack of auto.search.msn.com with Hosts file O2 - Enumeration of existing MSIE BHO's O3 - Enumeration of existing MSIE toolbars O4 - Enumeration of suspicious autoloading Registry entries O5 - Blocking of loading Internet Options in Control Panel O6 - Disabling of 'Internet Options' Main tab with Policies O7 - Disabling of Regedit with Policies O8 - Extra MSIE context menu items O9 - Extra 'Tools' menuitems and buttons O10 - Breaking of Internet access by New.Net or WebHancer O11 - Extra options in MSIE 'Advanced' settings tab O12 - MSIE plugins for file extensions or MIME types O13 - Hijack of default URL prefixes O14 - Changing of IERESET.INF O15 - Trusted Zone Autoadd O16 - Download Program Files item O17 - Domain hijack O18 - Enumeration of existing protocols and filters O19 - User stylesheet hijack O20 - AppInit_DLLs autorun Registry value, Winlogon Notify Registry keys O21 - ShellServiceObjectDelayLoad (SSODL) autorun Registry key O22 - SharedTaskScheduler autorun Registry key O23 - Enumeration of NT Services O24 - Enumeration of ActiveX Desktop Components Privacy Policy | About Trend Micro | Contact Us Copyright © 2007 Trend Micro, Inc.
Hello and welcome to Posted Image

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your information now, I will post back shortly with instructions.
Hi harrydash

We need to do a thorough diagnosis to see what is going on with your machine.

First download HJT

Click here to download HJTsetup.exe
  • Save HJTsetup.exe to your desktop.
  • Double click on the HJTsetup.exe icon on your desktop.
  • Continue to click Next in the setup dialogue boxes until you get to the Select Additional Tasks dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the rest of the prompts from there.
  • At the final dialogue box click Finish and it will launch Hijack This.
  • Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
  • Click Save to save the log file and then the log will open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.



NEXT


Download DDS by sUBs from one of the following links. Save it to your desktop.
*DDS.com
DDS.scr
DDS.pif

Double click on the DDS icon, allow it to run.

A small box will open, with an explanation about the tool.
Click Yes at the prompt for Optional Scan.
When done, DDS will open two (2) logs

1. DDS.txt
2. Attach.txt
Save both reports to your desktop.
Copy/paste the logs to your next reply
Close the DDS program window

Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control can be found HERE


In your next post include

  • HJT log
  • DDS logs


Please advise if you are having any further issues with your machine.
CatByte, Thanks for your reply. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:14:29 AM, on 2/4/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RunDll32.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm R3 - URLSearchHook: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbShar.dll O1 - Hosts: 212.150.54.250 dv-networks.com O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll O2 - BHO: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbShar.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing) O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O3 - Toolbar: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbShar.dll O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing) O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" -atboottime O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spool.exe (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [Microsoft all] C:\WINDOWS\mmall.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &D;&ownload; &with; BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: &D;&ownload; all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: &D;&ownload; all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing) O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HTTP SSL HTTPFilterseclogon (HTTPFilterseclogon) - Unknown owner - C:\WINDOWS\system32\wpv7380.cpx.exe (file missing) O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: Schedule - Unknown owner - C:\WINDOWS\system32\drivers\spool.exe (file missing) O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe – End of file - 6816 bytes DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 2:15:15.98 on Wed 02/04/2009 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_02 Microsoft Windows XP Professional 5.1.2600.2.874.66.1033.18.511.226 [GMT 7:00] AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RunDll32.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe svchost.exe "C:\WINDOWS\system32\wpv7380.cpx" C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\SYSTEM32\NOTEPAD.EXE C:\Documents and Settings\Admin\Desktop\dds.pif ============== Pseudo HJT Report =============== uLocal Page = \blank.htm uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uStart Page = hxxp://www.google.com/ mDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: Share Accelerator MM Toolbar: {4596013b-6c31-408b-a266-deae5c086dc2} - c:\program files\share_accelerator_mm\tbShar.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: bho2gr Class: {31ff080d-12a3-439a-a2ef-4ba95a3148e8} - c:\program files\getright\xx2gr.dll BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll BHO: Share Accelerator MM Toolbar: {4596013b-6c31-408b-a266-deae5c086dc2} - c:\program files\share_accelerator_mm\tbShar.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll TB: Share Accelerator MM Toolbar: {4596013b-6c31-408b-a266-deae5c086dc2} - c:\program files\share_accelerator_mm\tbShar.dll TB: &Google;: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [Sony Ericsson PC Suite] "c:\program files\sony ericsson\mobile2\application launcher\Application Launcher.exe" /startoptions mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [QuickTime Task] "c:\program files\mpcstar\codecs\quicktime\qtsystem\qttask.exe" -atboottime mRun: [MMTray] c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe mRun: [] dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRun: [jkdfj94kgdftdf] c:\windows\temp\winlogan.exe dRun: [autoload] c:\documents and settings\localservice\local settings\application data\cftmon.exe dRun: [ntuser] c:\windows\system32\drivers\spool.exe dRun: [Microsoft all] c:\windows\mmall.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe uPolicies-explorer: NoInstrumentation = 1 (0x1) uPolicies-explorer: NoStartMenuSubFolders = 1 (0x1) uPolicies-explorer: NoFavoritesMenu = 1 (0x1) IE: &D;&ownload; &with; BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm IE: &D;&ownload; all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm IE: &D;&ownload; all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm IE: Download with GetRight Pro - c:\program files\getright\GRdownload.htm IE: E&xport; to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000 IE: Open with GetRight Pro Browser - c:\program files\getright\GRbrowse.htm IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll/206 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL LSP: c:\windows\system32\imon.dll Trusted Zone: nationet.com\olb2 DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, msansspc.dll LSA: Authentication Packages = msv1_0 nwprovau ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admin\applic~1\mozilla\firefox\profiles\sp80ebjd.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - component: c:\documents and settings\admin\application data\mozilla\firefox\profiles\sp80ebjd.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll FF - component: c:\documents and settings\admin\application data\mozilla\firefox\profiles\sp80ebjd.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll FF - component: c:\documents and settings\admin\application data\mozilla\firefox\profiles\sp80ebjd.default\extensions\{b042753d-f57e-4e8e-a01b-7379a6d4cefb}\components\IBitCometExtension.dll —- FIREFOX POLICIES —- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: content.max.tokenizing.time - 200000 FF - user.js: content.notify.interval - 100000 FF - user.js: content.switch.threshold - 650000 FF - user.js: nglayout.initialpaint.delay - 300 ============= SERVICES / DRIVERS =============== R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-1-18 15424] R2 NOD32krn;NOD32 Kernel Service;c:\program files\eset\nod32krn.exe [2008-1-18 552064] S2 HTTPFilterseclogon;HTTP SSL HTTPFilterseclogon;c:\windows\system32\wpv7380.cpx srv –> c:\windows\system32\wpv7380.cpx srv [?] S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2008-12-26 40840] S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-12-26 66952] S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2008-12-26 81288] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-6-29 42512] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-12-26 356920] S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2008-12-26 1079176] S4 aawservice;Ad-Aware 2007 Service;"c:\program files\lavasoft\ad-aware 2007\aawservice.exe" –> c:\program files\lavasoft\ad-aware 2007\aawservice.exe [?] =============== Created Last 30 ================ 2009-02-04 02:09 –d—– c:\program files\Trend Micro 2009-02-03 21:43 –d—– c:\program files\ThreatExpert Memory Scanner 2009-02-03 21:22 9,728 a——- c:\windows\system32\drivers\pxscinst.dll 2009-02-03 21:22 7,680 a——- c:\windows\system32\drivers\pxinst.dll 2009-02-03 21:22 –d—– c:\docume~1\alluse~1\applic~1\Prevx 2009-01-19 14:28 69,632 a——- c:\windows\system32\lfgif13n.dll 2009-01-19 14:27 462,848 a——- c:\windows\system32\ltkrn13n.dll 2009-01-19 14:27 450,560 a——- c:\windows\system32\ltimg13n.dll 2009-01-19 14:27 401,408 a——- c:\windows\system32\lfcmp13n.dll 2009-01-19 14:27 299,008 a——- c:\windows\system32\ltdis13n.dll 2009-01-19 14:27 206,336 a——- c:\windows\system32\ltefx13n.dll 2009-01-19 14:27 163,840 a——- c:\windows\system32\ltfil13n.dll 2009-01-19 14:27 57,344 a——- c:\windows\system32\lfbmp13n.dll ==================== Find3M ==================== 2009-01-24 20:17 48,913 ac—— c:\windows\UninstVeetleTVPlayer.exe 2008-12-15 14:58 87,608 a——- c:\docume~1\admin\applic~1\inst.exe 2008-12-15 14:58 47,360 a——- c:\docume~1\admin\applic~1\pcouffin.sys 2008-12-09 17:39 195,436 a——- c:\windows\pchealth\helpctr\config\cache\Professional_32_1033.dat 2008-11-12 02:22 124,432 a——- c:\windows\system32\PanInstaller.dll 2008-11-12 02:22 83,480 a——- c:\windows\system32\FirstLoad.dll 2008-04-19 17:54 1,685,156 ac—— c:\program files\pf-setup-en.exe ============= FINISH: 2:15:46.15 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-02-01.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 5/7/2005 10:24:05 PM System Uptime: 2/4/2009 2:11:37 AM (0 hours ago) Motherboard: | | P4VT8 Processor: Intel® Pentium® 4 CPU 2.40GHz | FC-478 | 2410/133mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 59 GiB total, 7.572 GiB free. D: is FIXED (NTFS) - 16 GiB total, 4.998 GiB free. E: is CDROM () F: is CDROM () G: is CDROM () H: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP42: 1/28/2009 8:44:20 PM - Shockwave Player RP43: 2/3/2009 10:26:57 PM - Removed Ad-Aware 2007 RP44: 2/4/2009 1:24:12 AM - Restore Operation RP45: 2/4/2009 1:29:07 AM - Restore Operation ==== Installed Programs ====================== 7-Zip 4.42 Ad-Aware 2007 Adobe Bridge 1.0 Adobe Common File Installer Adobe Flash Player 10 ActiveX Adobe Help Center 1.0 Adobe Photoshop CS2 Adobe Reader 7.1.0 Adobe Shockwave Player Adobe Stock Photos 1.0 Advanced WindowsCare Personal 2.6.0 Apple Mobile Device Support Apple Software Update AusLogics Disk Defrag BitComet 1.04 C-Media WDM Audio Driver Canon Camera Access Library Canon Camera Support Core Library Canon Digital Camera Solution Disk 34 Software Starter Guide Canon Direct Print User Guide Canon G.726 WMP-Decoder Canon MovieEdit Task for ZoomBrowser EX Canon PhotoRecord Canon PowerShot A470 Camera User Guide Canon RAW Image Task for ZoomBrowser EX Canon Utilities CameraWindow Canon Utilities CameraWindow DC Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX Canon Utilities EOS Utility Canon Utilities MyCamera Canon Utilities MyCamera DC Canon Utilities PhotoStitch Canon Utilities RemoteCapture Task for ZoomBrowser EX Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility CPL All-in-One Disc2Phone DivX Codec DivX Content Uploader DivX Converter DivX Player DivX Web Player DNA FastStone Image Viewer 3.5 GetRight Pro GOM Player Google Earth Google Toolbar for Internet Explorer Google Video Player Graboid Video 1.3 HijackThis 2.0.2 Hotfix for Windows XP (KB926239) Image Resizer Powertoy for Windows XP IrfanView (remove only) J2SE Runtime Environment 5.0 Update 11 Java™ 6 Update 2 Java™ 6 Update 3 Java™ SE Runtime Environment 6 Update 1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 2.0 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0 Mozilla ActiveX Control v1.7.12 Mozilla Firefox (2.0.0.12) MpcStar 2.0 MUSICMATCH Jukebox nCleaner second [removed] Nero 6 Demo Nero 7 Ultra Edition NOD32 antivirus system NOD32 FiX NVIDIA Drivers PhotoFiltre PowerDVD PowerISO ProxyWay Extra RAW Image Task 1.1 RealPlayer Security Update for Windows XP (KB958644) Skype 2.5 Sony Ericsson PC Suite 1.20.224 SopCast 3.0.3 Spyware Doctor 6.0 TuneUp Utilities 2008 TVAnts 1.0 TVUPlayer [removed] UltraISO Premium V8.63 Update for Windows XP (KB898461) Update Service UpdateStar Veetle TV Player 0.9.13 VIA Rhine-Family Fast Ethernet Adapter VideoLAN VLC media player 0.8.6d Wallpapers from MSN WebFldrs XP Windows Installer 3.1 (KB893803) Windows Media Format 11 runtime Windows Media Player 11 WinPcap 4.0.1 WinRAR archiver ==== Event Viewer Messages From Past Week ======== 1/28/2009 8:43:16 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired. 1/28/2009 8:39:06 PM, error: Service Control Manager [7000] - The Schedule service failed to start due to the following error: The system cannot find the file specified. 1/28/2009 8:38:18 PM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 000B6A1FD9AF has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 1/31/2009 4:03:58 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system. 1/31/2009 4:03:58 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. . 1/31/2009 4:03:58 PM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\Canon\ZoomBrowser EX\Program\MFC80U.DLL. Reference error message: The operation completed successfully. . 2/4/2009 1:27:53 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: pxscan ==== End Of File ===========================
Your computer may have been infected by a backdoor trojan. These programs have the ability to information from your system. If you use your computer for sensitive purposes I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been compromised.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps.
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting and reinstalling Windows as this is the only 100% sure answer.
  • If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

First please download SDFix and save it to your Desktop.
  • You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.
Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\).
Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key repeatedly;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual user account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons
  • A text file should automatically open, so please copy the contents and post them here.

NEXT

Please download ComboFix from one of these locations:
Link 1
Link 2
Link 3
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
*IMPORTANT - Disable your AntiVirus and AntiSpyware applications, (NOD) usually via a right click on the System Tray icon.
They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

In your next response I need you to include

  • SDFix log
  • ComboFix log

Also please advise how your computer is running at the moment
CatByte,
I have successfully run SDFix and enclose log below.
However, every time I try to run ComboFix, I get a warning telling me that a real time scanner is active - eset nod32 antivirus system 2.70.
I followed the disabling advise above (clicking on quit) also tried stopping eset at services and startup all without success.
Should I run the program despite the warning ?



SDFix: Version 1.240
Run by [removed] on Wed 02/04/2009 at 01:42 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File
Resetting SecurityProviders Value
Restoring Default Schedule Service Path
Restoring Missing Security Center Service

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\wpv1190.cpx - Deleted
C:\WINDOWS\system32\wpv6490.cpx - Deleted
C:\WINDOWS\system32\wpv7380.cpx - Deleted
C:\WINDOWS\system32\wpv7580.cpx - Deleted
C:\WINDOWS\Help\agt037b.hlp - Deleted
C:\WINDOWS\system32\ps1.dat - Deleted
C:\WINDOWS\system32\rc.dat - Deleted
C:\WINDOWS\system32\svchost.t__ - Deleted
C:\WINDOWS\system32\svchost.tmp - Deleted
C:\WINDOWS\system32\xmd.dat - Deleted



Folder C:\Documents and Settings\All Users\Documents\Settings - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-04 13:52:31
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:28,ae,9f,cd,b7,9c,83,74,8b,eb,15,29,ac,15,90,79,9d,16,72,8d,8a,..
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:1a,46,54,36,49,61,48,59,bc,88,6c,cd,e4,19,f7,ab,bd,e8,42,d4,41,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:28,ae,9f,cd,b7,9c,83,74,8b,eb,15,29,ac,15,90,79,9d,16,72,8d,8a,..
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:1a,46,54,36,49,61,48,59,bc,88,6c,cd,e4,19,f7,ab,bd,e8,42,d4,41,..

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Fri 7 Nov 2008 6,656 A..H. — "C:\Program Files\Wallpapers from MSN\customActions.dll"
Thu 21 Jun 2007 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 7 Mar 2008 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 4 Jul 2008 17,516 A..H. — "C:\Documents and Settings\All Users\Application Data\Launcher\Launcher\1.0.0.0\BITFCC.tmp"

Finished!
CatByte,
I was unable to disable Nod32 but run Combofix anyway. Here is the log.
Computer is running normal.Thanks a lot for your help.

ComboFix 09-02-02.04 - Admin 2009-02-04 20:11:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.874.1.1033.18.511.225 [GMT 7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated)
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Admin\Application Data\.#
c:\documents and settings\Admin\Application Data\inst.exe
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\IEToolbar
c:\program files\IEToolbar\Free B Bar\basis.xml
c:\program files\IEToolbar\Free B Bar\freebbar.crc
c:\program files\IEToolbar\Free B Bar\icons.bmp
c:\program files\IEToolbar\Free B Bar\info.txt
c:\program files\IEToolbar\Free B Bar\version.txt
c:\program files\IEToolbar\Free B Bar\your_logo.png
c:\windows\IE4 Error Log.txt
c:\windows\system32\appcert
c:\windows\system32\w32apiw.dll

—– BITS: Possible infected sites —–

hxxp://www.graboid.com
hxxp://au.downloadj+|Cv+@J:NGD_DQ{ztHG.X}
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_COM+_MESSAGES
——-\Legacy_ISODRIVE
——-\Service_ISODrive


((((((((((((((((((((((((( Files Created from 2009-01-04 to 2009-02-04 )))))))))))))))))))))))))))))))
.

2009-02-04 13:38 . 2009-02-04 13:38 d——– c:\windows\ERUNT
2009-02-04 13:26 . 2009-02-04 13:55 d——– C:\SDFix
2009-02-04 02:09 . 2009-02-04 02:09 d——– c:\program files\Trend Micro
2009-02-03 21:43 . 2009-02-03 22:40 d——– c:\program files\ThreatExpert Memory Scanner
2009-02-03 21:22 . 2009-02-03 21:26 d——– c:\documents and settings\All Users\Application Data\Prevx
2009-02-03 21:22 . 2006-12-08 13:36 9,728 –a—— c:\windows\system32\drivers\pxscinst.dll
2009-02-03 21:22 . 2006-12-08 13:36 7,680 –a—— c:\windows\system32\drivers\pxinst.dll
2009-01-19 14:28 . 2003-11-04 15:10 69,632 –a—— c:\windows\system32\lfgif13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 462,848 –a—— c:\windows\system32\ltkrn13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 450,560 –a—— c:\windows\system32\ltimg13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 401,408 –a—— c:\windows\system32\lfcmp13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 299,008 –a—— c:\windows\system32\ltdis13n.dll
2009-01-19 14:27 . 2004-01-12 02:09 206,336 –a—— c:\windows\system32\ltefx13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 163,840 –a—— c:\windows\system32\ltfil13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 57,344 –a—— c:\windows\system32\lfbmp13n.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 07:44 ——— d—–w c:\program files\ESET
2009-02-03 15:28 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-02-03 13:29 ——— d—–w c:\program files\DNA
2009-02-03 12:49 ——— d—–w c:\program files\Mozilla ActiveX Control v1.7.12
2009-02-03 11:35 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-03 05:36 ——— d—–w c:\program files\Google
2009-01-31 09:04 ——— d—–w c:\documents and settings\Admin\Application Data\ZoomBrowser EX
2009-01-31 09:04 ——— d—–w c:\documents and settings\Admin\Application Data\CameraWindowDC
2009-01-24 13:17 48,913 -c–a-w c:\windows\UninstVeetleTVPlayer.exe
2009-01-14 16:50 ——— d—–w c:\program files\Yahoo!
2009-01-05 08:13 ——— d—–w c:\program files\TVAnts
2009-01-03 15:06 ——— d—–w c:\program files\TVUPlayer
2009-01-03 15:06 ——— d—–w c:\documents and settings\All Users\Application Data\TVU Networks
2009-01-02 21:01 ——— d—–w c:\documents and settings\All Users\Application Data\Launcher
2009-01-02 19:59 ——— d—–w c:\documents and settings\All Users\Application Data\Graboid Inc
2009-01-02 19:59 ——— d—–w c:\documents and settings\Admin\Application Data\MozillaControl
2009-01-02 19:58 ——— d—–w c:\program files\Graboid
2008-12-26 06:58 ——— d—–w c:\program files\Spyware Doctor
2008-12-26 06:56 ——— d—–w c:\documents and settings\Admin\Application Data\PC Tools
2008-12-26 06:20 ——— d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-26 06:16 ——— d—–w c:\program files\Apple Software Update
2008-12-26 06:15 ——— d—–w c:\program files\Common Files\Apple
2008-12-26 06:15 ——— d—–w c:\documents and settings\All Users\Application Data\Apple
2008-12-19 07:02 ——— d—–w c:\program files\Common Files\Teleca Shared
2008-12-19 07:02 ——— d—–w c:\documents and settings\All Users\Application Data\Sony Ericsson
2008-12-15 07:58 47,360 —-a-w c:\documents and settings\Admin\Application Data\pcouffin.sys
2008-12-15 07:58 ——— d—–w c:\documents and settings\Admin\Application Data\Vso
2008-04-19 10:54 1,685,156 -c–a-w c:\program files\pf-setup-en.exe
2008-03-02 08:47 67,696 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-03-02 08:47 54,376 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-03-02 08:47 34,952 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-03-02 08:47 46,720 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-03-02 08:47 172,144 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

——- Sigcheck ——-

2007-10-31 00:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\SoftwareDistribution\Download\146ae5e7b51a37f45e0e5cf03d0d5e3c\sp2gdr\tcpip.sys
2007-10-30 23:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\SoftwareDistribution\Download\146ae5e7b51a37f45e0e5cf03d0d5e3c\sp2qfe\tcpip.sys
2006-04-20 18:51 359808 1dbf125862891817f374f407626967f4 c:\windows\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2gdr\tcpip.sys
2006-04-20 19:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2qfe\tcpip.sys
2008-03-26 18:39 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\dllcache\TCPIP.SYS
2008-03-26 18:39 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-05 68856]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-01-18 949376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-01-09 180269]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"QuickTime Task"="c:\program files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" [2007-09-22 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 1 (0x1)
"NoFavoritesMenu"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Admin\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Start Menu^Programs^Startup^Wallpapers from MSN.lnk]
path=c:\documents and settings\Admin\Start Menu\Programs\Startup\Wallpapers from MSN.lnk
backup=c:\windows\pss\Wallpapers from MSN.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Start Menu^Programs^Startup^Zapu.lnk]
path=c:\documents and settings\Admin\Start Menu\Programs\Startup\Zapu.lnk
backup=c:\windows\pss\Zapu.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2007-01-15 16:14 147456 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
–a–c— 2004-08-04 07:56 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
–a–c— 2006-08-08 22:42 208952 c:\windows\ime\IMJP8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2006-01-12 15:40 155648 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a–c— 2006-10-22 12:22 7700480 c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a–c— 2006-10-22 12:22 86016 c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
–a—— 2008-06-16 15:52 167936 c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-09-22 12:56 282624 c:\program files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
–a—— 2007-01-09 22:27 1003520 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2005-01-12 03:01 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
–a—— 2006-07-06 18:53 20034600 c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra—— 2005-10-26 17:17 159744 c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-09-25 01:11 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-01-09 22:21 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
–a—— 2006-05-06 09:29 6656 c:\program files\Unlocker\UnlockerAssistant.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateStar]
–a—— 2007-10-05 18:31 3596976 c:\documents and settings\Admin\Application Data\UpdateStar\UpdateStar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a–c— 2006-10-22 12:22 1622016 c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"StarWindServiceAE"=2 (0x2)
"gusvc"=3 (0x3)
"aawservice"=2 (0x2)
"Bonjour Service"=2 (0x2)
"6to4"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" -atboottime

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15876:TCP"= 15876:TCP:BitComet 15876 TCP
"15876:UDP"= 15876:UDP:BitComet 15876 UDP
"7270:TCP"= 7270:TCP:BitComet 7270 TCP
"7270:UDP"= 7270:UDP:BitComet 7270 UDP
"49201:TCP"= 49201:TCP:BitComet
"49201:UDP"= 49201:UDP:BitComet
"27153:TCP"= 27153:TCP:BitComet 27153 TCP
"27153:UDP"= 27153:UDP:BitComet 27153 UDP
"16800:TCP"= 16800:TCP:TVAnts
"16800:UDP"= 16800:UDP:TVAnts

R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-01-18 15424]
S2 HTTPFilterseclogon;HTTP SSL HTTPFilterseclogon;c:\windows\system32\wpv7380.cpx srv –> c:\windows\system32\wpv7380.cpx srv [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-06-29 42512]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-12-26 356920]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-02-04 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 14:24]
.
- - - - ORPHANS REMOVED - - - -

Toolbar-ID - (no file)
HKLM-Run-MMTray - c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
HKU-Default-Run-jkdfj94kgdftdf - c:\windows\TEMP\winlogan.exe
HKU-Default-Run-Microsoft all - c:\windows\mmall.exe
MSConfigStartUp-AlcoholAutomount - c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe
MSConfigStartUp-BearShare - c:\program files\BearShare\BearShare.exe
MSConfigStartUp-jkdfj94kgdftdf - c:\windows\TEMP\winlogan.exe
MSConfigStartUp-Microsoft all - c:\windows\mmall.exe
MSConfigStartUp-MMTray - c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
MSConfigStartUp-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
MSConfigStartUp-ntuser - c:\windows\system32\drivers\spool.exe
MSConfigStartUp-PHIME2002A - c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
MSConfigStartUp-PHIME2002ASync - c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
MSConfigStartUp-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
MSConfigStartUp-Regscan - c:\windows\system32\regscan.exe
MSConfigStartUp-Run - c:\windows\mmall.exe
MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
MSConfigStartUp-Cmaudio - cmicnfg.cpl


.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &D;&ownload; &with; BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D;&ownload; all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D;&ownload; all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Download with GetRight Pro - c:\program files\GetRight\GRdownload.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Open with GetRight Pro Browser - c:\program files\GetRight\GRbrowse.htm
LSP: c:\windows\system32\imon.dll
Trusted Zone: nationet.com\olb2
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\sp80ebjd.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\sp80ebjd.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\sp80ebjd.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\sp80ebjd.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-04 20:17:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\HTTPFilterseclogon]
"ImagePath"="c:\windows\system32\wpv7380.cpx srv"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(628)
c:\windows\system32\imon.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\ESET\nod32krn.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Teleca Shared\CapabilityManager.exe
.
**************************************************************************
.
Completion time: 2009-02-04 20:24:29 - machine was rebooted [Admin]
ComboFix-quarantined-files.txt 2009-02-04 13:24:16

Pre-Run: 7,940,239,360 bytes free
Post-Run: 7,871,172,608 bytes free

Current=2 Default=2 Failed=0 LastKnownGood=4 Sets=1,2,3,4
284 — E O F — 2008-03-20 16:31:31
Hi harrydash

Please do this:


Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".


Click Start > Run type Notepad click OK.
This will open an empty notepad file:
copy/paste the text inside of the codebox into notepad

KillAll::

File::
c:\windows\system32\wpv7380.cpx sys

Driver::
HTTPFilterseclogon

Save it to your desktop as CFScript.txt
here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]


Referring to the picture above, drag CFScript.txt into ComboFix.exe

This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

In your next reply I need

  • Combofix log

  • Also advise how your computer is running now.
CatByte,
I am still unable to disable nod32.
I have carried out the task you asked. My PC is running ok, although does seem a bit slow.

ComboFix 09-02-02.04 - Admin 2009-02-05 0:15:47.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.874.1.1033.18.511.219 [GMT 7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated)
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
c:\windows\system32\wpv7380.cpx sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_HTTPFILTERSECLOGON
——-\Service_HTTPFilterseclogon


((((((((((((((((((((((((( Files Created from 2009-01-04 to 2009-02-04 )))))))))))))))))))))))))))))))
.

2009-02-04 22:19 . 2009-02-04 22:19 d——– c:\documents and settings\All Users\Application Data\TVU Networks
2009-02-04 13:38 . 2009-02-04 13:38 d——– c:\windows\ERUNT
2009-02-04 13:26 . 2009-02-04 13:55 d——– C:\SDFix
2009-02-04 02:09 . 2009-02-04 02:09 d——– c:\program files\Trend Micro
2009-02-03 21:43 . 2009-02-03 22:40 d——– c:\program files\ThreatExpert Memory Scanner
2009-02-03 21:22 . 2009-02-03 21:26 d——– c:\documents and settings\All Users\Application Data\Prevx
2009-02-03 21:22 . 2006-12-08 13:36 9,728 –a—— c:\windows\system32\drivers\pxscinst.dll
2009-02-03 21:22 . 2006-12-08 13:36 7,680 –a—— c:\windows\system32\drivers\pxinst.dll
2009-01-19 14:28 . 2003-11-04 15:10 69,632 –a—— c:\windows\system32\lfgif13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 462,848 –a—— c:\windows\system32\ltkrn13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 450,560 –a—— c:\windows\system32\ltimg13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 401,408 –a—— c:\windows\system32\lfcmp13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 299,008 –a—— c:\windows\system32\ltdis13n.dll
2009-01-19 14:27 . 2004-01-12 02:09 206,336 –a—— c:\windows\system32\ltefx13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 163,840 –a—— c:\windows\system32\ltfil13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 57,344 –a—— c:\windows\system32\lfbmp13n.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 15:19 ——— d—–w c:\program files\TVUPlayer
2009-02-04 07:44 ——— d—–w c:\program files\ESET
2009-02-03 15:28 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-02-03 13:29 ——— d—–w c:\program files\DNA
2009-02-03 12:49 ——— d—–w c:\program files\Mozilla ActiveX Control v1.7.12
2009-02-03 11:35 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-03 05:36 ——— d—–w c:\program files\Google
2009-01-31 09:04 ——— d—–w c:\documents and settings\Admin\Application Data\ZoomBrowser EX
2009-01-31 09:04 ——— d—–w c:\documents and settings\Admin\Application Data\CameraWindowDC
2009-01-24 13:17 48,913 -c–a-w c:\windows\UninstVeetleTVPlayer.exe
2009-01-14 16:50 ——— d—–w c:\program files\Yahoo!
2009-01-05 08:13 ——— d—–w c:\program files\TVAnts
2009-01-02 21:01 ——— d—–w c:\documents and settings\All Users\Application Data\Launcher
2009-01-02 19:59 ——— d—–w c:\documents and settings\All Users\Application Data\Graboid Inc
2009-01-02 19:59 ——— d—–w c:\documents and settings\Admin\Application Data\MozillaControl
2009-01-02 19:58 ——— d—–w c:\program files\Graboid
2008-12-26 06:58 ——— d—–w c:\program files\Spyware Doctor
2008-12-26 06:56 ——— d—–w c:\documents and settings\Admin\Application Data\PC Tools
2008-12-26 06:20 ——— d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-26 06:16 ——— d—–w c:\program files\Apple Software Update
2008-12-26 06:15 ——— d—–w c:\program files\Common Files\Apple
2008-12-26 06:15 ——— d—–w c:\documents and settings\All Users\Application Data\Apple
2008-12-19 07:02 ——— d—–w c:\program files\Common Files\Teleca Shared
2008-12-19 07:02 ——— d—–w c:\documents and settings\All Users\Application Data\Sony Ericsson
2008-12-15 07:58 47,360 —-a-w c:\documents and settings\Admin\Application Data\pcouffin.sys
2008-12-15 07:58 ——— d—–w c:\documents and settings\Admin\Application Data\Vso
2008-04-19 10:54 1,685,156 -c–a-w c:\program files\pf-setup-en.exe
2008-03-02 08:47 67,696 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-03-02 08:47 54,376 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-03-02 08:47 34,952 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-03-02 08:47 46,720 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-03-02 08:47 172,144 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

——- Sigcheck ——-

2007-10-31 00:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\SoftwareDistribution\Download\146ae5e7b51a37f45e0e5cf03d0d5e3c\sp2gdr\tcpip.sys
2007-10-30 23:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\SoftwareDistribution\Download\146ae5e7b51a37f45e0e5cf03d0d5e3c\sp2qfe\tcpip.sys
2006-04-20 18:51 359808 1dbf125862891817f374f407626967f4 c:\windows\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2gdr\tcpip.sys
2006-04-20 19:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2qfe\tcpip.sys
2008-03-26 18:39 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\dllcache\TCPIP.SYS
2008-03-26 18:39 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-05 68856]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-01-18 949376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-01-09 180269]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"QuickTime Task"="c:\program files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" [2007-09-22 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 1 (0x1)
"NoFavoritesMenu"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Admin\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Start Menu^Programs^Startup^Wallpapers from MSN.lnk]
path=c:\documents and settings\Admin\Start Menu\Programs\Startup\Wallpapers from MSN.lnk
backup=c:\windows\pss\Wallpapers from MSN.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Start Menu^Programs^Startup^Zapu.lnk]
path=c:\documents and settings\Admin\Start Menu\Programs\Startup\Zapu.lnk
backup=c:\windows\pss\Zapu.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2007-01-15 16:14 147456 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
–a–c— 2004-08-04 07:56 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
–a–c— 2006-08-08 22:42 208952 c:\windows\ime\IMJP8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2006-01-12 15:40 155648 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a–c— 2006-10-22 12:22 7700480 c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a–c— 2006-10-22 12:22 86016 c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
–a—— 2008-06-16 15:52 167936 c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-09-22 12:56 282624 c:\program files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
–a—— 2007-01-09 22:27 1003520 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2005-01-12 03:01 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
–a—— 2006-07-06 18:53 20034600 c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra—— 2005-10-26 17:17 159744 c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-09-25 01:11 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-01-09 22:21 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
–a—— 2006-05-06 09:29 6656 c:\program files\Unlocker\UnlockerAssistant.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateStar]
–a—— 2007-10-05 18:31 3596976 c:\documents and settings\Admin\Application Data\UpdateStar\UpdateStar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a–c— 2006-10-22 12:22 1622016 c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"StarWindServiceAE"=2 (0x2)
"gusvc"=3 (0x3)
"aawservice"=2 (0x2)
"Bonjour Service"=2 (0x2)
"6to4"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" -atboottime

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15876:TCP"= 15876:TCP:BitComet 15876 TCP
"15876:UDP"= 15876:UDP:BitComet 15876 UDP
"7270:TCP"= 7270:TCP:BitComet 7270 TCP
"7270:UDP"= 7270:UDP:BitComet 7270 UDP
"49201:TCP"= 49201:TCP:BitComet
"49201:UDP"= 49201:UDP:BitComet
"27153:TCP"= 27153:TCP:BitComet 27153 TCP
"27153:UDP"= 27153:UDP:BitComet 27153 UDP
"16800:TCP"= 16800:TCP:TVAnts
"16800:UDP"= 16800:UDP:TVAnts

R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-01-18 15424]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-06-29 42512]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-12-26 356920]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-02-04 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 14:24]
.
.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: &D;&ownload; &with; BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D;&ownload; all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D;&ownload; all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Download with GetRight Pro - c:\program files\GetRight\GRdownload.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Open with GetRight Pro Browser - c:\program files\GetRight\GRbrowse.htm
LSP: c:\windows\system32\imon.dll
Trusted Zone: nationet.com\olb2
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\sp80ebjd.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\sp80ebjd.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\sp80ebjd.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\sp80ebjd.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-05 00:22:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(624)
c:\windows\system32\imon.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\ESET\nod32krn.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Teleca Shared\CapabilityManager.exe
c:\program files\Canon\CAL\CALMAIN.exe
.
**************************************************************************
.
Completion time: 2009-02-05 0:28:40 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-04 17:28:35
ComboFix2.txt 2009-02-04 13:24:31

Pre-Run: 7,850,463,232 bytes free
Post-Run: 7,841,873,920 bytes free

Current=2 Default=2 Failed=0 LastKnownGood=4 Sets=1,2,3,4
253 — E O F — 2008-03-20 16:31:31
Hi harrydash,

Things are looking much better, just a little more work to do so stay with me.


First, your Adobe Reader is out of date.

  • Go to http://get.adobe.com/reader/
  • Clickthe Download Button

Next:

Your Java is also out of date, the older versions can be removed as they now are a security vulnerability.

Please download JavaRa and unzip it to your desktop.

***Please close any instances of Internet Explorer before continuing!***

  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.

Then download and install Java Runtime Environment (JRE) 6 Update 12.

NEXT


Please download Malwarebytes' Anti-Malware and save to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to:

    Update Malwarebytes' Anti-Malware
    Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked Except for the objects located in C:\System Volume Information, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply

    Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.

Finally I would like you to do an online virus scan to make sure your whole system is clear.

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

Then open HJT do a system scan and save a log file.
Post the fresh HJT log in your next reply.


In your next reply I need:
  • MBAM log
  • Kaspersky log
  • fresh HJT log
CatByte,
I have completed all tasks and enclose the requested logs.
Cheers.

Malwarebytes' Anti-Malware 1.33
Database version: 1728
Windows 5.1.2600 Service Pack 2

2009-02-05 04:15:34
mbam-log-2009-02-05 (04-15-34).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 106112
Time elapsed: 1 hour(s), 0 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, February 5, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, February 05, 2009 07:34:31
Records in database: 1754075
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 62041
Threat name: 43
Infected objects: 53
Suspicious objects: 0
Duration of the scan: 02:50:13


File name / Threat name / Threats count
C:\Program Files\ESET\cache\FND0.NFI Infected: Trojan.Win32.Small.ace 1
C:\Program Files\ESET\cache\FND1.NFI Infected: Trojan-Downloader.Win32.Tiny.agf 1
C:\Program Files\ESET\cache\FND10.NFI Infected: Trojan-Dropper.Win32.Agent.aapf 1
C:\Program Files\ESET\cache\FND2.NFI Infected: Trojan-Downloader.Win32.Small.fuq 1
C:\Program Files\ESET\cache\FND3.NFI Infected: Trojan.Win32.Monder.gen 1
C:\Program Files\ESET\cache\FND4.NFI Infected: Trojan-Downloader.Win32.Agent.hqz 1
C:\Program Files\ESET\cache\FND5.NFI Infected: Trojan-Downloader.Win32.Agent.jdg 1
C:\Program Files\ESET\cache\FND6.NFI Infected: Trojan.Win32.SubSys.ef 1
C:\Program Files\ESET\cache\FND8.NFI Infected: Trojan-GameThief.Win32.OnLineGames.arza 1
C:\Program Files\ESET\cache\FNDA.NFI Infected: Trojan-PSW.Win32.OnLineGames.aqna 1
C:\Program Files\ESET\cache\FNDB.NFI Infected: Trojan.Win32.Agent.alwv 1
C:\Program Files\ESET\cache\FNDC.NFI Infected: Rootkit.Win32.Podnuha.rr 1
C:\Program Files\ESET\cache\FNDE.NFI Infected: Trojan.Win32.Agent.arue 1
C:\Program Files\ESET\cache\FNDF.NFI Infected: Packed.Win32.Krap.d 1
C:\Program Files\ESET\infected\040RUSCA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.shzr 1
C:\Program Files\ESET\infected\1GBCYGBA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.asbl 1
C:\Program Files\ESET\infected\1OMZ31AA.NQF Infected: Trojan-PSW.Win32.OnLineGames.aoem 1
C:\Program Files\ESET\infected\1UH4WRCA.NQF Infected: Trojan-PSW.Win32.OnLineGames.argz 1
C:\Program Files\ESET\infected\5GMHJ1CA.NQF Infected: Rootkit.Win32.Podnuha.du 1
C:\Program Files\ESET\infected\ADIWW3AA.NQF Infected: Trojan-PSW.Win32.OnLineGames.aqbp 1
C:\Program Files\ESET\infected\ADKPXICA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.arza 1
C:\Program Files\ESET\infected\AENYTSCA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.tdgo 1
C:\Program Files\ESET\infected\AJOYPMAA.NQF Infected: Trojan-PSW.Win32.OnLineGames.aoem 1
C:\Program Files\ESET\infected\AOLTSXDA.NQF Infected: Trojan.Win32.Monder.gen 1
C:\Program Files\ESET\infected\AW5LGCCA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.asbh 1
C:\Program Files\ESET\infected\CDVLVDBA.NQF Infected: Backdoor.Win32.Agent.tzl 1
C:\Program Files\ESET\infected\E2SO24BA.NQF Infected: Trojan-PSW.Win32.OnLineGames.arpk 1
C:\Program Files\ESET\infected\EJC2RSAA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.arza 1
C:\Program Files\ESET\infected\ENVZCFAA.NQF Infected: Trojan-PSW.Win32.OnLineGames.aqna 1
C:\Program Files\ESET\infected\G4ORNFDA.NQF Infected: Trojan-PSW.Win32.Nilage.dnt 1
C:\Program Files\ESET\infected\H4KY2DBA.NQF Infected: Trojan-PSW.Win32.OnLineGames.apms 1
C:\Program Files\ESET\infected\I20D51AA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.asdg 1
C:\Program Files\ESET\infected\III04FAA.NQF Infected: Trojan-GameThief.Win32.Nilage.cnd 1
C:\Program Files\ESET\infected\J4ZNP4BA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.sfsc 1
C:\Program Files\ESET\infected\MRKKOTAA.NQF Infected: Trojan-PSW.Win32.OnLineGames.argv 1
C:\Program Files\ESET\infected\OSYAM3DA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.asbi 1
C:\Program Files\ESET\infected\PJOSPVCA.NQF Infected: Trojan-Downloader.Win32.Small.fuq 1
C:\Program Files\ESET\infected\Q0YU4JCA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.zaaf 1
C:\Program Files\ESET\infected\QKX3EUCA.NQF Infected: Rootkit.Win32.Podnuha.rr 1
C:\Program Files\ESET\infected\QRS0XDCA.NQF Infected: Trojan-Downloader.Win32.Tibs.aam 1
C:\Program Files\ESET\infected\R0X0LZBA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.asbp 1
C:\Program Files\ESET\infected\R3NJ0ZDA.NQF Infected: Trojan-Downloader.Win32.Injecter.bhk 1
C:\Program Files\ESET\infected\S3XES3AA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.szof 1
C:\Program Files\ESET\infected\TT05DJBA.NQF Infected: Trojan-PSW.Win32.OnLineGames.aqbp 1
C:\Program Files\ESET\infected\UP0SPNAA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.arza 1
C:\Program Files\ESET\infected\VKHEVKAA.NQF Infected: Trojan-GameThief.Win32.OnLineGames.asbw 1
C:\Program Files\ESET\infected\VTCT2YCA.NQF Infected: Rootkit.Win32.Agent.uy 1
C:\Program Files\ESET\infected\WK1Q3RCA.NQF Infected: Trojan-Downloader.Win32.Injecter.dz 1
C:\Program Files\ESET\infected\Y2U43PBA.NQF Infected: Trojan-Downloader.Win32.Agent.bgfz 1
C:\Program Files\ESET\infected\Y30ZTSDA.NQF Infected: Packed.Win32.Krap.d 1
C:\Program Files\ESET\infected\Z3X4RHBA.NQF Infected: Trojan-PSW.Win32.OnLineGames.aqzw 1
C:\WINDOWS\MicroSoft.vbs Infected: Trojan.VBS.Starter.n 1
C:\WINDOWS\system32\cmdow.exe Infected: not-a-virus:RiskTool.Win32.HideWindows 1

The selected area was scanned.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:42, on 2009-02-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - URLSearchHook: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbShar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbShar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbShar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

–
End of file - 6040 bytes
Hello harrydash,

Things are looking much better.

Most of what Kaspersky found is in quarantine in your ESET antivirus….you can open your ESET Antivirus program and delete all the items in quarantine.

There is one unidentified file on your system that I would like you to submit for analysis.

Please do this:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    • C:\WINDOWS\MicroSoft.vbs
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.

  • Paste the contents of the Clipboard in your next reply.
CatByte,
Here is the Virscan.

VirSCAN.org Scanned Report :
Scanned time : 2009/02/06 12:53:29 (ICT)
Scanner results: 41% Scanner(15/37) found malware!
File Name : MicroSoft.vbs
File Size : 210 byte
File Type :
MD5 : 8755dbccea95e8f5436562268c2530f1
SHA1 : 88681552e7482c6e5bc66b1f58148ff75f63c653
Online report : http://virscan.org/report/a4f87ea9c3e7f231…9e64de4ea6.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.29 20090206011617 2009-02-06 3.15 Trojan.VBS.Starter!IK
AhnLab V3 2009.02.06.01 2009.02.06 2009-02-06 1.09 -
AntiVir 7.9.0.74 7.1.1.234 2009-02-05 1.94 TR/Starter.N.4
Antiy 2.0.18 20090205.2159123 2009-02-05 0.12 Trojan/VBS.Starter.n
Authentium 5.1.1 200902051925 2009-02-05 1.12 VBS/WSRunner.I (Exact)
AVAST! 3.0.1 090205-1 2009-02-05 0.00 Unix:Malware-gen
AVG 7.5.52.442 270.10.18/1936 2009-02-05 1.88 -
BitDefender 7.81008.2639973 7.23522 2009-02-06 2.46 -
CA (VET) 9.0.0.143 31.6.6344 2009-02-05 5.39 -
ClamAV 0.94.2 8957 2009-02-06 0.00 -
Comodo 3.0 965 2009-02-05 0.97 TrojWare.VBS.Starter.n
CP Secure 1.1.0.715 2009.02.06 2009-02-06 6.99 Troj.VBS.Starter.n
Dr.Web 4.44.0.9170 2009.02.06 2009-02-06 3.96 -
F-Prot 4.4.4.56 20090205 2009-02-05 1.06 VBS/WSRunner.I (exact)
F-Secure 5.51.6100 2009.02.05.05 2009-02-05 4.56 Trojan.VBS.Starter.n [AVP]
Fortinet 2.81-3.117 10.2 2009-02-05 0.14 -
GData 19.2838/19.214 20090206 2009-02-06 3.50 Trojan.VBS.Starter.n [Engine:A]
ViRobot 20090205 2009.02.05 2009-02-05 0.40 VBS.Starter.210
Ikarus T3.1.01.45 2009.02.06.72262 2009-02-06 3.66 Trojan.VBS.Starter
JiangMin 11.0.706 2009.02.05 2009-02-05 1.47 -
Kaspersky 5.5.10 2009.02.06 2009-02-06 0.02 Trojan.VBS.Starter.n
KingSoft 2008.9.8.18 2009.2.6.9 2009-02-06 0.60 VBS.AutoRun.a.210
McAfee 5.3.00 5517 2009-02-05 3.09 -
Microsoft 1.4306 2009.02.06 2009-02-06 4.28 -
mks_vir 2.01 2009.02.05 2009-02-05 2.62 -
Norman 6.00.02 6.00.00 2009-02-05 8.01 -
Panda 9.05.01 2009.02.05 2009-02-05 1.60 -
Trend Micro 8.700-1004 5.820.02 2009-02-05 0.02 VBS_STARTER.AI
Quick Heal 10.00 2009.02.05 2009-02-05 0.92 -
Rising 20.0 21.15.30.00 2009-02-05 0.28 -
Sophos 2.83.3 4.38 2009-02-06 2.31 -
Sunbelt 4801 4801 2009-02-05 0.53 -
Symantec 1.3.0.24 20090205.007 2009-02-05 0.23 -
nProtect 20090206.01 3110299 2009-02-06 4.17 -
The Hacker [removed] v00247 2009-02-04 0.47 -
VBA32 3.12.8.12 20090205.1235 2009-02-05 1.49 -
VirusBuster 4.5.11.10 10.101.3/894342 2009-02-06 1.10 -
Hi harrydash,

We're almost there, couple more things for you to do…..

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box, put your mouse cursor at the very beginning of the text and then hold down the left button and drag your mouse so that all of the text is highlighted. Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
C:\WINDOWS\MicroSoft.vbs

Now paste the copied text into the open notepad. To do this click in the blank page so that your cursor is flashing there and press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

* Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
* ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
* When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

In your next reply I need
  • Combofix log
  • Fresh HJT log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI