amvo.exe; Win32/nsanti; help[1].exe malware...Please help!, malware - amvo.exe, win32/nsanti... |
![]() ![]() |
amvo.exe; Win32/nsanti; help[1].exe malware...Please help!, malware - amvo.exe, win32/nsanti... |
Jan 12 2008, 07:48 AM
Post
#1
|
|
|
New Member ![]() Posts: 8 OS: Windows XP Home Edition |
I am sorry to bother but approximately 2 weeks ago I copied through USB some files from my friend. From that time I have a serious problems with the malware (virus, trojan) called amvo.exe, Win32/nsanti and help[1].exe. I don't know but probably all this things have something to do with each other. I tried almost everything I could find online about how to get rid of this malware but I didn't succeed. When I erase amvo.exe, amvo.dll it doesn't help. When I restart my PC and try to open my USB disk on drive F: NoAdware programm shows that amvo.exe was added to my startup programs again. Is there anybody that can help me with this. I am getting really desperate. Thank you very much in advance for your early reply. Here I'm posting my log from HJT: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:29:07 PM, on 1/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Avast4\aswUpdSv.exe C:\Program Files\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Vongo\VongoService.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\PROGRA~1\Avast4\ashDisp.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\Internet TV\FlashGet\jccatch.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\Internet TV\FlashGet\getflash.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM') O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user') O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user') O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_all.htm O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_link.htm O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?c9b12eaa7cb44a169b54f3e4d6eec6e5 O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?c9b12eaa7cb44a169b54f3e4d6eec6e5 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing) O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing) O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123fd.bay123.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a...asyInstallX.CAB O17 - HKLM\System\CCS\Services\Tcpip\..\{299F4FC9-2A6C-4D40-AEA5-382035FD868F}: NameServer = 217.118.96.203 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- End of file - 9528 bytes |
|
|
Jan 12 2008, 08:02 AM
Post
#2
|
|
![]() GeekU Teacher Posts: 10,078 From: Somewhere OS: Windows xp home |
I see that you are running 2 antivirus which is less help rather than more.
Please uninstall Trend Micro Internet Security suite. ================================= Please download the OTMoveIt2 by OldTimer.
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. ======================= After OTMoveit 2 Please download FixWareout from here: http://downloads.subratam.org/Fixwareout.exe Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. If your firewall gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead. Then you will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal. Once the desktop loads please post the text that will open (report.txt) and a new Hijackthis log |
|
|
Jan 12 2008, 11:09 AM
Post
#3
|
|
|
New Member ![]() Posts: 8 OS: Windows XP Home Edition |
Hi!
Thank you for your fast reply. I did everything what you said. OTMoveit.exe did not find one of those files. Here is the report: C:\WINDOWS\system32\amvo.exe moved successfully. File/Folder HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\amva not found. Created on 01/12/2008 17:47:37 Here is the report from Fixwareout.exe: TEM\CurrentControlSet\Services\Tcpip\Parameters "nameserver"="85.255.116.146 85.255.112.196" <Value cleared. Successfully flushed the DNS Resolver Cache. System was rebooted successfully. ~~~~~ Postrun check HKLM\SOFTWARE\~\Winlogon\ "System"="lsass.exe" .... .... ~~~~~ Misc files. .... ~~~~~ Checking for older varients. .... ~~~~~ Current runs (hklm hkcu "run" Keys Only) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" "AT-Watch"="" "avast!"="C:\\PROGRA~1\\Avast4\\ashDisp.exe" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "amva"="C:\\WINDOWS\\system32\\amvo.exe" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" .... Hosts file was reset, If you use a custom hosts file please replace it... ~~~~~ End report ~~~~~ And new HJT report: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:58:51 PM, on 1/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Avast4\aswUpdSv.exe C:\Program Files\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Vongo\VongoService.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\Avast4\ashMaiSv.exe C:\Program Files\Avast4\ashWebSv.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\notepad.exe C:\PROGRA~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\Notepad.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\Internet TV\FlashGet\jccatch.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\Internet TV\FlashGet\getflash.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM') O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user') O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user') O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_all.htm O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_link.htm O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?c9b12eaa7cb44a169b54f3e4d6eec6e5 O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?c9b12eaa7cb44a169b54f3e4d6eec6e5 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing) O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing) O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123fd.bay123.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a...asyInstallX.CAB O17 - HKLM\System\CCS\Services\Tcpip\..\{299F4FC9-2A6C-4D40-AEA5-382035FD868F}: NameServer = 217.118.96.203 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- End of file - 9015 bytes Thank you again. Please let me know what should I do next. After fixing this, when I will connect my USB disk, camera and other USB media again I used before and also during that time I had problem with this malware, will the virus come back or it will be safe? Thank you. Can't wait for your reply. |
|
|
Jan 13 2008, 07:51 AM
Post
#4
|
|
![]() GeekU Teacher Posts: 10,078 From: Somewhere OS: Windows xp home |
Are you saying that your Flash Drive is infected?
Please re-open Hijackthis and click on "Do a system scan only" Then place a check mark next to these entries below: R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) Now click on Fix Checked and then close Hijackthis. ==================================== After that Please download ComboFix from Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
|
|
|
Jan 13 2008, 10:14 AM
Post
#5
|
|
|
New Member ![]() Posts: 8 OS: Windows XP Home Edition |
Hi again!
Thank you again for helping me. About the USB drive...I was just asking if that virus is able to copy to USB storage medias? Because I'm using my 120 GB USB Hard Disk, small USB flash drive, copying some pictures from camera through usb etc. I was just wondering if that virus could copy into these drives or if I don't have to worry about it? I don't know much about this virus so I'm rather asking. Anyway, here is the ComboFix.txt report: ComboFix 08-01-13.1 - Branislav Mesaros 2008-01-13 16:50:12.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.206 [GMT 1:00] Running from: C:\Documents and Settings\Branislav Mesaros\Desktop\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Autorun.inf C:\Documents and Settings\All Users\Start Menu\UUSEE~1.LNK C:\Documents and Settings\Branislav Mesaros\Application Data\DriveCleaner 2006 Free C:\Documents and Settings\Branislav Mesaros\Application Data\DriveCleaner 2006 Free\Logs\update.log C:\Documents and Settings\Branislav Mesaros\Local Settings\Application Data\baidu C:\WINDOWS\system32\amvo1.dll D:\80avp08.com D:\Autorun.inf D:\semo2x.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\LEGACY_WERFGH ((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 ))))))))))))))))))))))))))))))) . 2008-01-13 16:48 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe 2008-01-12 13:02 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr 2008-01-12 13:02 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2008-01-12 13:02 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2008-01-12 13:02 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2008-01-12 13:02 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2008-01-12 13:02 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2008-01-12 13:01 . 2008-01-12 13:02 <DIR> d-------- C:\Program Files\Avast4 2008-01-12 13:01 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe 2008-01-12 01:28 . 2008-01-12 01:28 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab 2008-01-12 01:28 . 2008-01-12 01:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2008-01-11 23:24 . 2008-01-11 23:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro 2008-01-11 21:47 . 2006-05-11 06:48 <DIR> d-------- C:\Documents and Settings\Administrator.BRANO\Application Data\Intuit 2008-01-10 00:53 . 2008-01-10 00:53 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7 2008-01-10 00:52 . 2008-01-11 19:12 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\AVG7 2008-01-10 00:51 . 2008-01-11 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7 2008-01-10 00:47 . 2008-01-11 23:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft 2008-01-10 00:16 . 2008-01-10 00:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Genie-Soft 2008-01-10 00:15 . 2008-01-10 00:15 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Genie-Soft 2008-01-10 00:11 . 2007-02-06 16:03 129,784 --------- C:\WINDOWS\system32\pxafs.dll 2008-01-10 00:11 . 2007-02-02 03:00 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys 2008-01-10 00:11 . 2007-02-02 03:00 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys 2008-01-10 00:10 . 2008-01-10 00:11 <DIR> d-------- C:\Program Files\Genie Backup Manager Pro 8.0 2008-01-10 00:10 . 2006-11-02 01:50 128,104 --a------ C:\WINDOWS\system32\drivers\WimFltr.sys 2008-01-09 20:27 . 2008-01-11 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-01-09 20:13 . 2008-01-09 20:13 <DIR> d-------- C:\Program Files\K-Lite Codec Pack 2008-01-09 17:36 . 2008-01-09 17:36 819,200 --a------ C:\WINDOWS\is-RT58A.exe 2008-01-09 17:36 . 2008-01-09 17:36 10,620 --a------ C:\WINDOWS\is-RT58A.msg 2008-01-09 17:36 . 2008-01-09 17:36 1,917 --a------ C:\WINDOWS\is-RT58A.lst 2008-01-09 14:42 . 2008-01-09 14:42 104,392 --a------ C:\tio8x6.cmd 2008-01-09 11:23 . 2008-01-09 11:23 1,355 --a------ C:\WINDOWS\imsins.BAK 2008-01-09 02:15 . 2008-01-10 17:06 <DIR> d-------- C:\Program Files\Uniblue 2008-01-09 02:15 . 2008-01-10 17:06 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Uniblue 2008-01-09 02:15 . 2008-01-09 02:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue 2008-01-08 13:28 . 2008-01-08 13:29 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Regrun 2008-01-08 13:28 . 2008-01-08 13:29 <DIR> d-------- C:\backreg 2008-01-08 13:27 . 2008-01-08 13:27 25,773 --a------ C:\WINDOWS\system32\drivers\regguard.sys 2008-01-08 13:27 . C:\WINDOWS\(2) C:\ComboFix\winstart.bat 2008-01-08 13:25 . 2008-01-08 13:54 <DIR> d-------- C:\Program Files\RegRunSuite 2008-01-07 15:04 . 2008-01-07 15:04 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\TrojanHunter 2008-01-07 10:59 . 2008-01-07 13:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee.com 2008-01-07 10:41 . 2008-01-07 13:03 <DIR> d-------- C:\Program Files\Security Task Manager 2008-01-07 10:41 . 2008-01-11 17:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan 2008-01-07 10:16 . 2008-01-11 17:54 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\PrevxCSI 2008-01-07 10:16 . 2008-01-07 10:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx 2008-01-07 10:10 . 2008-01-11 18:12 165 --a------ C:\WINDOWS\startUp manager.INI 2008-01-06 00:47 . 2008-01-06 00:47 <DIR> d-------- C:\Program Files\Ligos 2008-01-06 00:47 . 2000-06-23 10:36 745,984 --a------ C:\WINDOWS\system32\ir50_32.dll 2008-01-06 00:47 . 2000-06-23 14:05 136,704 --a------ C:\WINDOWS\system32\iacenc.dll 2008-01-06 00:47 . 2000-06-22 13:09 56,320 --------- C:\WINDOWS\system32\iyvu9_32.dll 2008-01-05 23:52 . 2008-01-05 23:52 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Media Player Classic 2008-01-05 18:05 . 2005-03-30 05:05 3,031,040 --a------ C:\WINDOWS\system32\NCTVideoTransform.dll 2008-01-05 18:05 . 2003-10-30 16:14 679,936 --a------ C:\WINDOWS\system32\NCTMPEGFile.dll 2008-01-05 18:05 . 2005-02-23 02:32 589,824 --a------ C:\WINDOWS\system32\NCTVideoView.dll 2008-01-05 18:05 . 2003-08-07 04:01 237,568 --a------ C:\WINDOWS\system32\lame_enc.dll 2008-01-05 18:05 . 2004-01-09 03:54 188,416 --a------ C:\WINDOWS\system32\actsplash.ocx 2008-01-05 16:13 . 2008-01-05 16:13 14 --a------ C:\WINDOWS\system32\SystemInfo32.sys 2008-01-05 16:12 . 2008-01-05 16:13 <DIR> d-------- C:\Program Files\DVD X Player 4.1 Professional 2008-01-05 16:12 . 2008-01-05 16:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD X Studios 2008-01-05 00:19 . 2008-01-05 00:19 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Systweak 2008-01-05 00:16 . 2008-01-11 01:48 <DIR> d-------- C:\Program Files\Advanced System Optimizer 2008-01-04 21:09 . 2008-01-06 11:17 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-01-04 21:09 . 2008-01-04 21:09 1,409 --a------ C:\WINDOWS\QTFont.for 2008-01-04 15:44 . 2008-01-04 15:44 <DIR> d-------- C:\Program Files\MP3 programs 2008-01-03 20:10 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx 2008-01-03 18:20 . 2008-01-13 16:44 <DIR> d-------- C:\Program Files\PeerGuardian2 2008-01-03 17:17 . 2008-01-06 20:07 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\Azureus 2008-01-03 17:17 . 2008-01-03 17:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus 2008-01-03 17:10 . 2008-01-03 17:10 <DIR> d-------- C:\Program Files\Azureus 2008-01-03 16:27 . 2008-01-03 16:27 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\FreeCap 2008-01-03 15:36 . 2008-01-12 11:58 <DIR> d-------- C:\Program Files\Hide IP Platinum 3.5 2008-01-03 13:09 . 2008-01-12 17:44 <DIR> d-------- C:\Program Files\Trend Micro 2008-01-03 13:09 . 2008-01-03 13:10 2,150 --a------ C:\WINDOWS\system32\tmmute.ini 2007-12-31 22:21 . 2007-12-31 22:21 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\InstallShield 2007-12-29 01:39 . 2007-12-29 01:41 <DIR> d-------- C:\Program Files\HyperCam 2007-12-28 14:12 . 2007-12-28 14:42 <DIR> d-------- C:\Documents and Settings\Branislav Mesaros\Application Data\U3 2007-12-26 11:16 . 2007-12-26 11:17 67 --a------ C:\WINDOWS\#1 DVD Ripper.INI 2007-12-25 14:01 . 2007-12-26 11:09 5 --a------ C:\WINDOWS\system32\SySDVD.dat . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-13 15:43 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\uTorrent 2008-01-13 10:58 --------- d-----w C:\Program Files\Mp3 converter 2008-01-12 19:01 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\Skype 2008-01-11 19:08 --------- d-----w C:\Program Files\DVD CD burner 2008-01-11 18:04 --------- d-----w C:\Program Files\NoAdware5.0 2008-01-10 17:18 --------- d-----w C:\Program Files\DVD convert & burn 2008-01-09 21:29 --------- d-----w C:\Program Files\uTorrent 2008-01-07 17:57 --------- d-----w C:\Program Files\DC++ 2008-01-07 14:51 --------- d-----w C:\Program Files\Common Files\Real 2008-01-03 17:51 --------- d-----w C:\Program Files\Google 2008-01-03 13:36 --------- d-----w C:\Program Files\Microangelo 2008-01-02 19:12 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\dvdcss 2007-12-15 19:33 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\SopCast 2007-12-12 10:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help 2007-12-11 00:51 --------- d-----w C:\Program Files\Vodei 2007-12-04 16:13 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\ICQ 2007-12-04 10:28 --------- d-----w C:\Program Files\Windows Live Toolbar 2007-11-20 15:33 --------- d-----w C:\Program Files\Skype 2007-11-20 15:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype 2007-11-20 15:32 --------- d-----w C:\Program Files\Common Files\Skype 2007-11-14 17:42 --------- d-----w C:\Program Files\Nero 2007-11-14 17:42 --------- d-----w C:\Documents and Settings\Branislav Mesaros\Application Data\Ahead 2007-11-14 17:40 --------- d-----w C:\Program Files\Nero 6 2007-11-14 17:40 --------- d-----w C:\Program Files\Common Files\Ahead 2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-05-03 01:17 174 ----a-w C:\Documents and Settings\Branislav Mesaros\Application Data\wklnhst.dat 2007-01-21 18:37 87,608 ----a-w C:\Documents and Settings\Branislav Mesaros\Application Data\ezpinst.exe 2007-01-21 18:37 47,360 ----a-w C:\Documents and Settings\Branislav Mesaros\Application Data\pcouffin.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 22:00 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 22:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe] "AT-Watch"="" [] "avast!"="C:\PROGRA~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224] C:\Documents and Settings\Default User\Start Menu\Programs\Startup\ Vongo Tray.lnk - C:\Program Files\Vongo\Tray.exe [2006-03-14 17:51:44] C:\Documents and Settings\Administrator.BRANO\Start Menu\Programs\Startup\ Vongo Tray.lnk - C:\Program Files\Vongo\Tray.exe [2006-03-14 17:51:44] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "System"="lsass.exe" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk] backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Branislav Mesaros^Start Menu^Programs^StartUp^Vongo Tray.lnk] backup=C:\WINDOWS\pss\Vongo Tray.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection] C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDial] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLSP Scheduler] C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset] --a------ 2006-02-22 16:03 40960 C:\Program Files\HPQ\Default Settings\cpqset.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut] --a------ 2006-06-02 22:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager] C:\Program Files\Common Files\AOL\1154847324\EE\AOLHostManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] --a------ 2006-02-19 09:41 49152 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant] --a------ 2006-02-15 03:49 454656 C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd] --a------ 2006-03-23 13:13 77824 C:\WINDOWS\system32\hkcmd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers] --a------ 2006-03-23 13:17 118784 C:\WINDOWS\system32\igfxpers.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray] --a------ 2006-03-23 13:17 94208 C:\WINDOWS\system32\igfxtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] --a------ 2005-08-12 00:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] --a------ 2005-08-12 00:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl] --a------ 2006-03-07 21:38 131072 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2006-08-06 07:57 98304 C:\Program Files\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecGuard] --------- 2005-10-11 18:23 1187840 C:\Windows\SMINST\RecGuard.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder] --------- 2006-02-09 17:52 643072 C:\Windows\CREATOR\Remind_XP.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2005-11-11 06:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] --a------ 2006-03-04 06:46 761948 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] --a------ 2004-12-20 19:41 33792 C:\Program Files\Winamp\winampa.exe S0 Partizan;Partizan;C:\WINDOWS\system32\drivers\Partizan.sys [] S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 15:05] S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys [] S3 RegGuard;RegGuard;C:\WINDOWS\system32\Drivers\regguard.sys [2008-01-08 13:27] S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [] S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F] \Shell\AutoRun\command - F:\d.com \Shell\explore\Command - F:\d.com \Shell\open\Command - F:\d.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10ddb2e8-2551-11db-91b3-00038a000015}] \Shell\AutoRun\command - F:\80avp08.com \Shell\explore\Command - F:\80avp08.com \Shell\open\Command - F:\80avp08.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10ddb2ea-2551-11db-91b3-00038a000015}] \Shell\AutoRun\command - F:\d.com \Shell\explore\Command - F:\d.com \Shell\open\Command - F:\d.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4572ca8c-7bfc-11db-927c-0014a5b64560}] \Shell\AutoRun\command - F:\usdeiect.com \Shell\explore\Command - F:\usdeiect.com \Shell\open\Command - F:\usdeiect.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{50cbc1d2-8ac6-11db-92b2-0014a5b64560}] \Shell\AutoRun\command - F:\80avp08.com \Shell\explore\Command - F:\80avp08.com \Shell\open\Command - F:\80avp08.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{515b49f2-5f84-11dc-9542-0016d43313d2}] \Shell\AutoRun\command - F:\usdeiect.com \Shell\explore\Command - F:\usdeiect.com \Shell\open\Command - F:\usdeiect.com [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a0754fed-5004-11dc-9516-0016d43313d2}] \Shell\AutoRun\command - F:\u.bat \Shell\explore\Command - F:\u.bat \Shell\open\Command - F:\u.bat . Contents of the 'Scheduled Tasks' folder "2008-01-13 15:49:42 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job" - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE "2008-01-10 16:06:44 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job" - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe "2008-01-10 16:06:43 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job" - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe "2008-01-11 22:48:48 C:\WINDOWS\Tasks\Uniblue SpyEraser.job" - C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-13 16:57:51 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-01-13 17:00:10 - machine was rebooted ComboFix-quarantined-files.txt 2008-01-13 16:00:06 . 2008-01-09 10:25:10 --- E O F --- and new HJT report: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:05:05 PM, on 1/13/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Avast4\aswUpdSv.exe C:\Program Files\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Vongo\VongoService.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\PROGRA~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\Internet TV\FlashGet\jccatch.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\Internet TV\FlashGet\getflash.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM') O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user') O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user') O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_all.htm O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\Internet TV\FlashGet\jc_link.htm O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?c9b12eaa7cb44a169b54f3e4d6eec6e5 O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?c9b12eaa7cb44a169b54f3e4d6eec6e5 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing) O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing) O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\Internet TV\FlashGet\FlashGet.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by123fd.bay123.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a...asyInstallX.CAB O17 - HKLM\System\CCS\Services\Tcpip\..\{299F4FC9-2A6C-4D40-AEA5-382035FD868F}: NameServer = 217.118.96.203 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- End of file - 8387 bytes Thank you very much again for doing this. Please let me know if I have to do something else to fix this virus problem or if it's clear. |
|
|
Jan 13 2008, 12:16 PM
Post
#6
|
|
![]() GeekU Teacher Posts: 10,078 From: Somewhere OS: Windows xp home |
Yes your drive F: is infected keep it plugged in for the duration of the fix please.
It is not likely that the other drives are infected but to be sure plug in all devices you are concerned about. ======================================================================= 1. Please open Notepad
2. Now copy/paste the entire content of the codebox below into the Notepad window: CODE File:: C:\tio8x6.cmd C:\WINDOWS\imsins.BAK F:\d.com F:\80avp08.com F:\d.com F:\usdeiect.com F:\u.bat Registry:: [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "System"="" 3. Save the above as CFScript.txt 4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again. ![]() 5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
===================== Also Download Dr.Web CureIt to the desktop: ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
This post has been edited by kahdah: Jan 13 2008, 12:18 PM |
|
|