Welcome Guest ( Log In | Join )

Discover the best free computer help!
Learn more about Geeks to Go by taking the tour. Spyware, virus, trojan, fake security or privacy alerts? Read the malware cleaning guide. Want to reply to a topic, start a new one, or remove the advertising? Join today (always free).
      
 
Closed TopicStart new topic
Mal_Otorun1 [RESOLVED]
michaeldwshaw
post Oct 4 2008, 06:19 AM
Post #1


New Member
*
Posts: 4
OS: XP



I'm a volunteer from the UK currently working in Africa as a VSO for food security. I think the virus may have come off a flash USB drive a local guy put in the laptop to shae some info... any help much appreciated!!


I'm running Trend Micro and it's up to date. Every 5 seconds or so it comes up with a warning:
infected file: D:\autorun.inf
Name: Mal_Otorun1
Action taken: remove this file

I changed it from quarantine because it was filling up so fast with these files so now it auto-deletes them.

When I look in the D: drive - there is nothing there. I have everything in the C drive. I cannot see a link for 'show hidden files' although I can see there is 1gig or so of stuf in the D drive.

I have followed steps 1-4 before posting this log....


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:22:01, on 04/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Huawei technologies\Mobile Connect\HuaWeiEVDO.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Google\Google Updater\2.4.1368.5602\GoogleUpdaterInstallMgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/
O15 - Trusted Zone: *.remote.boosey.com
O15 - Trusted Zone: remote.boosey.com
O15 - Trusted Zone: *.boosey.com
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - https://remote.boosey.com/CitrixSessionInit...AWEB/icaweb.cab
O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://access.boosey.com/dana-cached/setup...oterisSetup.cab
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O16 - DPF: {6416C78A-E810-445C-8712-1785809FA433} (CCAOControl Object) - https://remote.boosey.com/CitrixLogonPoint/...t/EPAClient.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6E48946B-934D-47F5-865E-546711F2D423} - https://remote.boosey.com/CitrixFEI/Cabs/LiveEdit.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B3C17C89-6126-400D-B0E0-AD0EA57C3D75}: NameServer = 41.221.96.67 41.221.96.68
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

--
End of file - 14244 bytes
Go to the top of the page
 
+Quote Post
greyknight17
post Oct 4 2008, 09:23 AM
Post #2


Malware Expert
Group Icon
Posts: 15,811
From: New York
OS: Windows 98, XP, Vista, Mac OS X



Welcome to GTG.

Download the Flash Disinfector at http://www.techsupportforum.com/sectools/s...Disinfector.exe and save it to your desktop. Double-click on it to run it and follow the on-screen instructions.

1. Download combofix at http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe or http://download.bleepingcomputer.com/sUBs/ComboFix.exe Save it to your Desktop before you run it.
2. Double-click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply.

Note:
Do not click on combofix's window while it's running. That may cause it to stall.
Go to the top of the page
 
+Quote Post
michaeldwshaw
post Oct 6 2008, 01:25 AM
Post #3


New Member
*
Posts: 4
OS: XP



Hi

I have run the flash disinfector on all external drives and flash USB pens. I have also run Malwarebytes' anti-malware across everything. Since then it seems to have worked (?!) because trend is no longer flashing up the Mal_otorun1 warning every 10seconds.

I have tried downloading the ComboFix program but Trend hates it. According to Trend software on my computer it carries a very dangerous trojan virus. So I have deleted this for now pending further instructions..

many thanks for your help so far!

M
Go to the top of the page
 
+Quote Post
greyknight17
post Oct 6 2008, 05:53 PM
Post #4


Malware Expert
Group Icon
Posts: 15,811
From: New York
OS: Windows 98, XP, Vista, Mac OS X



Can you add Combofix to be one of the files to exclude or in the exceptions list? If not, disable TrendMicro and download Combofix. Disconnect from the internet once you do this and then run Combofix. Post the log here when ready.
Go to the top of the page
 
+Quote Post
michaeldwshaw
post Oct 7 2008, 08:59 AM
Post #5


New Member
*
Posts: 4
OS: XP



OK thanks. Done it. Here you go:


ComboFix 08-10-05.05 - Michael Shaw 2008-10-07 16:47:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.508 [GMT 2:00]
Running from: C:\Documents and Settings\Michael Shaw\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\yew.bat
D:\otyh.cmd
D:\yew.bat

.
((((((((((((((((((((((((( Files Created from 2008-09-07 to 2008-10-07 )))))))))))))))))))))))))))))))
.

2008-11-01 10:12 . 2008-11-01 10:12 <DIR> d----c--- C:\Documents and Settings\Michael Shaw\Application Data\dvdcss
2008-10-30 17:28 . 2008-10-30 17:40 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-10-07 14:12 . 2008-10-07 14:12 <DIR> d--hsc--- C:\Documents and Settings\Michael Shaw\UserData
2008-10-06 14:48 . 2008-10-06 14:48 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-10-06 09:03 . 2008-07-18 22:07 270,880 --a------ C:\WINDOWS\system32\mucltui.dll
2008-10-06 09:03 . 2008-07-18 22:07 29,728 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-10-04 15:35 . 2008-10-04 15:35 0 --a------ C:\WINDOWS\system32\drivers\trrb.sys
2008-10-04 15:29 . 2008-10-04 15:29 <DIR> d-------- C:\Program Files\ERUNT
2008-10-04 15:08 . 2008-10-04 15:08 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-04 15:08 . 2008-10-04 15:08 <DIR> d----c--- C:\Documents and Settings\Michael Shaw\Application Data\Malwarebytes
2008-10-04 15:08 . 2008-10-04 15:08 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-04 15:08 . 2008-09-10 01:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-04 15:08 . 2008-09-10 01:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-04 15:06 . 2008-10-04 15:06 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-10-04 13:43 . 2008-10-04 13:43 <DIR> d-------- C:\Program Files\Google
2008-10-04 13:43 . 2008-10-07 07:48 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-04 13:17 . 2008-10-04 15:36 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-10-04 11:30 . 2008-10-04 11:30 42,273,429 --a------ C:\Temp\3420-enu-win2k_xp.zip
2008-10-02 11:56 . 2008-10-02 11:56 16,384 --a------ C:\WINDOWS\DCEBoot.exe
2008-09-29 09:16 . 2008-09-29 09:16 <DIR> d-------- C:\Program Files\Huawei technologies
2008-09-29 09:16 . 2006-06-21 22:29 65,152 --a------ C:\WINDOWS\system32\drivers\ewusbser.sys
2008-09-29 09:16 . 2006-06-21 22:29 65,152 --a------ C:\WINDOWS\system32\drivers\ewusbmdm.sys
2008-09-29 09:16 . 2006-06-21 22:29 65,152 --a------ C:\WINDOWS\system32\drivers\ewusbapp.sys
2008-09-29 09:16 . 2004-08-04 00:08 17,024 --a------ C:\WINDOWS\system32\drivers\usbohci.sys
2008-09-29 09:16 . 2004-08-04 00:08 17,024 --a--c--- C:\WINDOWS\system32\dllcache\usbohci.sys
2008-09-27 11:25 . 2008-09-29 13:36 <DIR> d----c--- C:\Documents and Settings\Michael Shaw\Application Data\ZTEEVDO

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-05 09:58 --------- d-----w C:\Program Files\Duplicate Finder
2008-10-04 12:19 --------- d-----w C:\Program Files\Trend Micro
2008-10-04 11:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-04 10:16 --------- d-----w C:\Program Files\Sony
2008-09-04 07:10 --------- dc----w C:\Documents and Settings\Michael Shaw\Application Data\Netscape
2008-09-04 07:10 --------- dc----w C:\Documents and Settings\Michael Shaw\Application Data\Citrix
2008-09-03 19:38 --------- dc----w C:\Documents and Settings\All Users\Application Data\Seagate
2008-09-03 19:37 --------- d-----w C:\Program Files\MSXML 6.0
2008-08-23 18:31 --------- d-----w C:\Program Files\iTunes
2008-08-23 18:31 --------- d-----w C:\Program Files\iPod
2008-08-23 18:23 --------- dc--a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-16 15:40 --------- d-----w C:\Program Files\Handbrake
2008-08-15 17:41 --------- dc----w C:\Documents and Settings\Michael Shaw\Application Data\DivX
2008-08-13 20:19 --------- d-----w C:\Program Files\Microsoft Works
2008-08-13 20:19 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2008-08-13 20:18 --------- d-----w C:\Program Files\hp deskjet 3420 series
2008-08-13 19:17 --------- d-----w C:\Program Files\Java
2008-08-12 22:07 --------- d-----w C:\Program Files\Apple Software Update
2008-08-10 18:34 --------- dc----w C:\Documents and Settings\Michael Shaw\Application Data\vlc
2008-08-10 18:29 --------- d-----w C:\Program Files\VideoLAN
2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2007-04-23 10:17 3,606,784 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_19509473.reg
2007-02-14 22:39 3,558,928 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_1760304.reg
2007-01-31 15:00 3,559,350 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_12159142.reg
2006-12-30 10:52 3,555,478 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_16805237.reg
2006-12-29 11:05 3,555,478 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_26392982.reg
2006-09-11 18:39 3,537,406 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_2814081.reg
2006-09-11 09:58 3,537,406 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_18734302.reg
2006-07-25 13:13 3,523,584 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_29987161.reg
2006-07-23 13:28 3,522,632 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_15582114.reg
2006-07-10 09:33 3,519,662 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_3912376.reg
2006-06-19 17:31 3,518,696 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_26194423.reg
2006-06-08 21:41 3,513,310 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_7652266.reg
2006-05-01 19:02 3,502,578 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_4729123.reg
2006-04-29 01:44 3,499,882 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_23503403.reg
2006-04-28 01:32 3,499,882 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_18926678.reg
2006-04-24 00:22 3,498,570 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_19736127.reg
2006-04-21 16:29 3,498,570 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_10690075.reg
2006-04-21 02:50 3,498,570 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_1117233.reg
2006-04-19 22:43 3,498,518 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_28420709.reg
2006-04-17 18:20 3,497,994 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_10711912.reg
2006-04-17 18:09 3,497,994 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_471035.reg
2006-03-27 21:49 3,465,370 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_30911772.reg
2006-03-25 18:43 3,437,704 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_31476927.reg
2006-03-25 17:21 3,437,782 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_5612344.reg
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"OE"="C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2008-03-07 492808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [X]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-29 7335936]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-11-17 118784]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
"VAIOCameraUtility"="C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-01 69632]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2005-11-28 217088]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"Switcher.exe"="C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-11-24 167936]
"VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-11 151552]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2005-03-03 483328]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-05-14 188416]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-22 180269]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-03-19 228088]
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 C:\WINDOWS\system32\ico.exe]
"WD Button Manager"="WDBtnMgr.exe" [2007-12-12 C:\WINDOWS\system32\WDBtnMgr.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 19:42 73728 C:\WINDOWS\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
"msacm.l3codec"= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe"=
"C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 7520337]
R3 hwcdcmdm0;HUAWEI Mobile Connect - 3G Modem;C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2006-06-21 65152]
R3 hwusbapp;HUAWEI Mobile Connect - 3G PC UI Interface;C:\WINDOWS\system32\DRIVERS\ewusbapp.sys [2006-06-21 65152]
R3 hwusbser;HUAWEI Mobile Connect - 3G Application Interface;C:\WINDOWS\system32\DRIVERS\ewusbser.sys [2006-06-21 65152]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2005-10-04 217472]
S3 RimSerPort;RIM Virtual Serial Port;C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 26496]
S3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2005-11-30 28800]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 311872]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{530ede5c-8df6-11dd-846f-0013020db7e6}]
\Shell\AutoRun\command - G:\fe.bat
\Shell\explore\Command - G:\
\Shell\open\Command - G:\fe.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57acc898-6423-11db-836d-0013a90ebe60}]
\Shell\AutoRun\command - G:\fe.bat
\Shell\explore\Command - G:\fe.bat
\Shell\open\Command - G:\fe.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0e80c08-79ef-11dd-8465-0013a90ebe60}]
\Shell\AutoRun\command - H:\Launch.exe /run

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb391169-a8c1-11dc-8411-0013a90ebe60}]
\Shell\AutoRun\command - G:\wd_windows_tools\setup.exe

*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2008-09-09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]

2008-10-04 C:\WINDOWS\Tasks\User_Feed_Synchronization-{7011CBC4-158F-4880-9485-C114101B1A8C}.job
- C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 13:58]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Michael Shaw\Application Data\Mozilla\Firefox\Profiles\ska6qstr.default\
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-07 16:51:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ASP.NET]
"ImagePath"=""
.
Completion time: 2008-10-07 16:53:05
ComboFix-quarantined-files.txt 2008-10-07 14:52:59

Pre-Run: 25,700,913,152 bytes free
Post-Run: 26,194,882,560 bytes free

205 --- E O F --- 2008-10-06 12:48:56
Go to the top of the page
 
+Quote Post
greyknight17
post Oct 7 2008, 10:51 AM
Post #6


Malware Expert
Group Icon
Posts: 15,811
From: New York
OS: Windows 98, XP, Vista, Mac OS X



Good job. Your log is clean.

To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided.

Are there any problems now? If none, go to Start->Run, copy/paste in combofix /u and hit OK to remove it. You should be set to go.
Go to the top of the page
 
+Quote Post
michaeldwshaw
post Oct 8 2008, 03:51 AM
Post #7


New Member
*
Posts: 4
OS: XP



great - thanks very much!!!!!!!!!!
Go to the top of the page
 
+Quote Post
greyknight17
post Oct 8 2008, 07:44 PM
Post #8


Malware Expert
Group Icon
Posts: 15,811
From: New York
OS: Windows 98, XP, Vista, Mac OS X



Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. smile.gif

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 2nd December 2008 - 05:38 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.