Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

TrojanDownloader.XS suspicion? [RESOLVED]


  • This topic is locked This topic is locked

#1
WildaNdCrazy

WildaNdCrazy

    Member

  • Member
  • PipPip
  • 29 posts

Hello,

I was downloading what I thought was a clean file, but it turned out the be the dirtiest virus that has happend to get on my computer! I was downloading it over night, installed it the next morning. It seemed to upload a lot of things on my computer, lets run through the list..Command Service, CoolWWWSearch, Double Click, MediaPlex, Network Monitor, Smitfraud-C, SWAgent, Virtumonde, and webHance, the list goes on! I just want to get down to removing these things! I hope I can help with the info I'm giving. Also my desktop turned black, with all my icons highlighted, In the middle it says, computer is infected, It shows my IP, and says my computer is being connected to by another computer. And a little triangle (the fake ones) where popping up redirecting me to download spyware programs, at this point I didn't want to download anything else. So i restored my computer to an earlier day (Just a day before) and the background and everything back to normal, but I know thats not the end of it. I just did a quick scan with spybot- Search & Destroy and its telling me I have all this crap on my computer (the things I listed above). My Windows Security Manager is still telling me, "Your computer is running slowly due to malware activity" and is redirecting me to AntispySpider, which I am ignoring at the moment. Help on this would be great

Thanks in advance.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:14:55 PM, on 6/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\RGV2YXVnaG4gSm9uZXM\command.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\444.470
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WUSB54GSC.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RTDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Razer\Copperhead\razerhid.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\vVX6000.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Razer\Tarantula\razerhid.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\DEVAUG~1\MYDOCU~1\Programs\WALLPA~1.90\WALLPA~1.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Razer\Copperhead\razerofa.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
c:\windows\system32\jlwnw64l.exe
C:\WINDOWS\system32\mcntmkdm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = file://c:/windows/homepage.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: 87.118.118.162 nprotect.roseonlinegame.com
O1 - Hosts: 87.118.118.162 update.nprotect.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: (no name) - {20D11127-7295-4CA6-A3A3-CAE22F846F12} - C:\WINDOWS\system32\efcCvTKC.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A98D0065-7326-41B5-B8D9-C5B692CDB82F} - C:\WINDOWS\system32\pmnmjHyV.dll
O2 - BHO: gooochi browser optimizer - {de91d9ea-b2d3-58c1-a001-764c59e0511c} - C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [RTDCPL] RTDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Tarantula] C:\Program Files\Razer\Tarantula\razerhid.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\mcntmkdm.exe DWramFF
O4 - HKLM\..\Run: [{9e128f1b-f405-62bb-bd72-99fabb5fccda}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll" DllStart
O4 - HKLM\..\RunOnce: [SpybotDeletingA317] command /c del "C:\Program Files\webHancer\Programs\sporder.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5791] cmd /c del "C:\Program Files\webHancer\Programs\sporder.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5835] command /c del "C:\Program Files\webHancer\Programs\readme.txt"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9509] cmd /c del "C:\Program Files\webHancer\Programs\readme.txt"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5360] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5916] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WallPaper] C:\DOCUME~1\DEVAUG~1\MYDOCU~1\Programs\WALLPA~1.90\WALLPA~1.EXE /h
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\RunOnce: [SpybotDeletingB5478] command /c del "C:\Program Files\webHancer\Programs\sporder.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2106] cmd /c del "C:\Program Files\webHancer\Programs\sporder.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3766] command /c del "C:\Program Files\webHancer\Programs\readme.txt"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5924] cmd /c del "C:\Program Files\webHancer\Programs\readme.txt"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4440] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2204] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\mcntmkdm.exe
O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\jlwnw64l.exe
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} -
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplane...DC_2.2.1.87.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games....GamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail....es/MSNPUpld.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://ca.com/securi...an/pestscan.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zon...wn.cab56986.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload....Plugin11USA.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemreq.../sysreqlab2.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.c.../acclaim_v5.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zon...nt.cab55762.cab
O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_USAv1001 Class) - http://ares.netgame....ch_USAv1002.cab
O16 - DPF: {9FC84F7D-D177-4A75-A7BB-429DA5BD0A3E} (SG_CAppAtx Control) -
O16 - DPF: {A1D886C6-4039-4451-97A9-515F5BE5D4C2} (mkdplusCtrl Class) - http://ahnlabdownloa...cab/mkdplus.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zon...ro.cab55579.cab
O16 - DPF: {BBB0FC2D-1D95-45CA-BDCF-03B53F247FCC} (EwsLoader Class) -
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload....GPlugin9USA.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.del...ll/gtdownde.cab
O20 - Winlogon Notify: pmnmjHyV - C:\WINDOWS\SYSTEM32\pmnmjHyV.dll
O20 - Winlogon Notify: RelevantKnowledge - C:\WINDOWS\system32\rlls.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGV2YXVnaG4gSm9uZXM\command.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Help and Support Center (helpsvcc) - Unknown owner - C:\WINDOWS\system32\cache\dllhost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\444.470.exe (file missing)
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: WUSB54GSCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe

--
End of file - 15962 bytes
  • 0

Advertisements


#2
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi WildaNdCrazy, welcome to GeeksToGo!

I am currently reviewing your log and will post back soon.

Please take note of the following points.
  • Please keep in mind that there may be a time difference between us, If you are not in the GMT +1 time zone, than you can expect a slight delay.
  • Please do not run any tools other than what I request of you to run. Some of the tools we will use are very powerful, and using them without the required knowledge could cause more damage and prove to be more troublesome than the problem you are currently facing.
  • If at any time you have a doubt about what you are to do, please stop there and ask. No question is considered dumb here at GeeksToGo!.

Thanks,

Mike :)
  • 0

#3
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi again WildaNdCrazy,

Please follow my instructions in the order they were given, if you come across something you don't understand or don't feel comfortable doing, don't hesitate to ask and I will get you sorted out :)
If you cannot complete a step in my instructions, please skip it and continue with the rest of my instructions and tell me in your next reply which one you were having trouble with.

Preperation

I notice you have no Anti-Virus program installed on your computer. These programs are necessary in keeping your computer free of malware, without it you are very likely to get re-infected within a very short period of time.
I would like you to download one of these free programs I have listed here for you.
Note: Make sure to only install ONE program, as having more can cause confliction between these programs, which in turn lowers your protection and slows down your computer.

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent HijackThis from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose "Yes" at the Warning prompt.
  • Expand the "Tools" menu.
  • Click "Resident".
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • In the File menu click "Exit" to exit Spybot Search & Destroy.


Step 1. Running HostsXpert

Download the HostsXpert 3.7 - Hosts File Manager.
  • Unzip HostsXpert 3.7 - Hosts File Manager to a convenient folder such as C:\HostsXpert
  • Click HostsXpert.exe to Run HostsXpert 3.7 - Hosts File Manager from its new home
  • Click "Make Hosts Writable?" in the upper right corner (If available).
  • Click Restore Microsoft's Hosts file and then click OK.
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.

Step 2. Fixes

Please download LSPFix from here.

Do not do anything with it yet please.

Please go to add or remove programs (start > control panel > add or remove programs) and uninstall the following:

WebHancer
gooochi browser optimizer


And delete the following items:

c:\program files\webhancer\
c:\windows\webhdll.dll
c:\windows\whagent.inf
c:\windows\whInstaller.exe
c:\windows\whInstaller.ini

If you can not connect to the Internet after removing Webhancer, please run the LSP-Fix program I had you download earlier, and click on the finish button. Reboot and you should be able to get back on.

Please open HijackThis again and choose "Do a system scan only". Please put a check next to each of the following entries (if still present):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = file://c:/windows/homepage.html
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -
O16 - DPF: {9FC84F7D-D177-4A75-A7BB-429DA5BD0A3E} (SG_CAppAtx Control) -
O16 - DPF: {A1D886C6-4039-4451-97A9-515F5BE5D4C2} (mkdplusCtrl Class) - http://ahnlabdownloa...cab/mkdplus.cab
O16 - DPF: {BBB0FC2D-1D95-45CA-BDCF-03B53F247FCC} (EwsLoader Class) -


Now please close all open windows except HJT and press "Fix checked".

Step 3. Combofix

Please go here to install the recovery console and for a guide on using combofix.
Please note: Installing the Recovery Console plays a vital part in making this process of cleaning your computer safe, please don't overlook this!

Download ComboFix from one of the locations below, and save it to your Desktop.

Link 1
Link 2
Link 3

Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall

In your next reply

Please post the log from ComboFix.
Please post a new log from Hijack This (after doing the above fixes.)

If the logs are to big to fit in one reply please spread them out over multiple replies.
  • 0

#4
WildaNdCrazy

WildaNdCrazy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
The anti-virus I had was norton 360, but that thing didnt even help at all when i was forced to put it on my computer. It wouldn't even start up anymore afted the 1st time i used it. But I suppose even norton is better then no anti-virus program. :)

Ok so here is both report logs.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin.zip
C:\Documents and Settings\Devaughn Jones\Application Data\ShoppingReport
C:\Documents and Settings\Devaughn Jones\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Devaughn Jones\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Devaughn Jones\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Devaughn Jones\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Devaughn Jones\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Devaughn Jones\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Devaughn Jones\Application Data\ShoppingReport\cs\res2\WhiteList.dbs
C:\Documents and Settings\LocalService\Application Data\ShoppingReport
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Program Files\akl
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\unsetup.dat
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\winam.dat
C:\Program Files\AntispyStorm
C:\Program Files\AntispyStorm\config.dat
C:\Program Files\AntispyStorm\filesbase.bin
C:\Program Files\AntispyStorm\global_virus_table.bin
C:\Program Files\AntispyStorm\regbase.bin
C:\Program Files\AntispyStorm\stat.bin
C:\Program Files\AntispyStorm\uninstall.log
C:\Program Files\AntispyStorm\urlbase.bin
C:\Program Files\outlook
C:\Program Files\outlook\p.zip
C:\Program Files\ShoppingReport
C:\Program Files\ShoppingReport\Uninst.exe
C:\Program Files\webhancer
C:\Program Files\webhancer\Programs\webhdll.dll
C:\setup.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\Temp\vtmp2
C:\Temp\vtmp2\ktnv33.log
C:\WINDOWS\acontidialer.txt
C:\WINDOWS\BM57be5f13.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\default.htm
C:\WINDOWS\Downloaded Program Files\Quarantine
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\homepage.html
C:\WINDOWS\index.html
C:\WINDOWS\mainms.vpi
C:\WINDOWS\megavid.cdt
C:\WINDOWS\muotr.so
C:\WINDOWS\promo1.html
C:\WINDOWS\promo2.html
C:\WINDOWS\promo3.html
C:\WINDOWS\promo4.html
C:\WINDOWS\promo5.html
C:\WINDOWS\promo6.html
C:\WINDOWS\promogif1.gif
C:\WINDOWS\promogif2.gif
C:\WINDOWS\promogif3.gif
C:\WINDOWS\pskt.ini
C:\WINDOWS\RGV2YXVnaG4gSm9uZXM\
C:\WINDOWS\RGV2YXVnaG4gSm9uZXM\\command.exe
C:\WINDOWS\RGV2YXVnaG4gSm9uZXM\\l3pZsrpBu3b0mA6Rtrg.vbs
C:\WINDOWS\RGV2YXVnaG4gSm9uZXM\command.exe
C:\WINDOWS\rundll32.vbe
C:\WINDOWS\system32\adult.txt
C:\WINDOWS\system32\apeuwdvr.ini
C:\WINDOWS\system32\atyixhvg.ini
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\Cache\active.txt
C:\WINDOWS\system32\Cache\aliases.ini
C:\WINDOWS\system32\Cache\channels.txt
C:\WINDOWS\system32\Cache\dllhost.exe
C:\WINDOWS\system32\Cache\do.txt
C:\WINDOWS\system32\Cache\hi.txt
C:\WINDOWS\system32\Cache\logs\status.euIRCnet.log
C:\WINDOWS\system32\Cache\logs\status.GameSurge.log
C:\WINDOWS\system32\Cache\mirc.ini
C:\WINDOWS\system32\Cache\names.txt
C:\WINDOWS\system32\Cache\nick.txt
C:\WINDOWS\system32\Cache\perform.ini
C:\WINDOWS\system32\Cache\prefix.txt
C:\WINDOWS\system32\Cache\remote.ini
C:\WINDOWS\system32\Cache\restart.bat
C:\WINDOWS\system32\Cache\s.bat
C:\WINDOWS\system32\Cache\sc.exe
C:\WINDOWS\system32\Cache\script.ini
C:\WINDOWS\system32\Cache\servers.ini
C:\WINDOWS\system32\Cache\suffixes.txt
C:\WINDOWS\system32\CKTvCcfe.ini
C:\WINDOWS\system32\CKTvCcfe.ini2
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\crypts.dll
C:\WINDOWS\system32\din.ip
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\efcCvTKC.dll
C:\WINDOWS\system32\egmulhxk.dll
C:\WINDOWS\system32\finance.txt
C:\WINDOWS\system32\g27.exe
C:\WINDOWS\system32\gside.exe
C:\WINDOWS\system32\hljwugsf.bin
C:\WINDOWS\system32\ldpackage.dll
C:\WINDOWS\system32\lpcywinp.exe
C:\WINDOWS\system32\lt.res
C:\WINDOWS\system32\mcntmkdm.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\model.dat
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mysidesearch_sidebar.dll
C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\nrmkmgdb.ini
C:\WINDOWS\system32\other.txt
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pharma.txt
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\priixupa.ini
C:\WINDOWS\system32\pskill.exe
C:\WINDOWS\system32\rwwnw64d.exe
C:\WINDOWS\system32\sft.res
C:\WINDOWS\system32\sockins32.dll
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\sznf.ascii
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tracert.com
C:\WINDOWS\system32\winpfz33.sys
C:\WINDOWS\system32\zxdnt3d.cfg

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_CMDSERVICE
-------\Legacy_MSSECURITY1.209.4
-------\Legacy_NETWORK_MONITOR
-------\Service_cmdService
-------\Service_MsSecurity1.209.4
-------\Legacy_helpsvcc
-------\Service_helpsvcc


((((((((((((((((((((((((( Files Created from 2008-05-10 to 2008-06-10 )))))))))))))))))))))))))))))))
.

2008-06-10 19:14 . 2008-06-10 19:17 <DIR> d-------- C:\WINDOWS\system32\3161
2008-06-10 00:36 . 2008-06-10 00:36 <DIR> d-------- C:\Documents and Settings\Devaughn Jones\.SunDownloadManager
2008-06-09 22:35 . 2008-06-09 22:35 <DIR> d-------- C:\Program Files\PremiumSoft
2008-06-09 22:24 . 2008-06-09 22:42 <DIR> d-------- C:\wamp
2008-06-09 21:42 . 2008-06-09 21:42 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-06-09 21:41 . 2008-06-09 21:44 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-06-09 21:41 . 2008-06-09 21:42 <DIR> d-------- C:\Program Files\Common Files\Merge Modules
2008-06-09 21:41 . 2008-06-09 21:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-09 21:40 . 2008-06-09 21:40 <DIR> d-------- C:\Program Files\Microsoft SDKs
2008-06-09 21:24 . 2008-06-09 21:24 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-06-09 18:24 . 2008-06-10 19:18 <DIR> d--h----- C:\$AVG8.VAULT$
2008-06-09 18:13 . 2008-06-10 18:35 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-09 18:13 . 2008-06-09 18:13 <DIR> d-------- C:\Program Files\AVG
2008-06-09 18:13 . 2008-06-09 18:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-09 18:13 . 2008-06-09 18:13 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-09 18:13 . 2008-06-09 18:13 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-09 18:13 . 2008-06-09 18:13 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-06-09 17:58 . 2008-06-10 18:49 <DIR> d-------- C:\HostsXpert
2008-06-09 17:36 . 2008-06-09 17:38 <DIR> d-------- C:\Program Files\MySQL
2008-06-09 17:36 . 2008-06-09 17:46 <DIR> d-------- C:\Documents and Settings\Devaughn Jones\Application Data\MySQL
2008-06-08 15:12 . 2008-06-09 18:29 <DIR> d-------- C:\WINDOWS\system32\5960
2008-06-08 15:12 . 2008-06-08 15:12 55,808 --a------ C:\WINDOWS\portsv.exe
2008-06-08 10:41 . 2008-06-08 10:41 87,511 --a------ C:\WINDOWS\system32\iftuyszv.exe
2008-06-08 10:41 . 2008-06-08 10:41 49,158 --a------ C:\WINDOWS\444.0
2008-06-07 14:51 . 2008-06-08 21:36 <DIR> d-------- C:\Program Files\Fraps
2008-06-07 11:14 . 2008-06-10 13:13 63,918 --a------ C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll-uninst.exe
2008-06-06 23:22 . 2008-06-06 23:22 <DIR> d-------- C:\Documents and Settings\Devaughn Jones\Application Data\Screaming Bee
2008-06-06 23:17 . 2008-06-06 23:17 <DIR> d-------- C:\Program Files\Common Files\Screaming Bee
2008-06-06 23:15 . 2008-06-06 23:15 <DIR> d-------- C:\Program Files\Screaming Bee
2008-06-05 09:58 . 2008-06-10 19:17 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-05 09:58 . 2008-06-05 09:58 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-04 21:58 . 2008-06-04 21:58 <DIR> d-------- C:\WINDOWS\NamelessRO Eclipse
2008-06-03 23:18 . 2008-06-03 23:19 <DIR> d-------- C:\Program Files\vghd
2008-06-03 22:31 . 2008-06-08 03:32 <DIR> d-------- C:\Downloads
2008-06-03 20:42 . 2008-06-08 21:20 <DIR> d-------- C:\Program Files\Rohan
2008-06-03 16:03 . 2008-06-03 16:03 <DIR> d-------- C:\Documents and Settings\Devaughn Jones\Application Data\Talkback
2008-05-31 20:11 . 2008-05-31 21:42 <DIR> d-------- C:\Program Files\Triggersoft
2008-05-27 09:30 . 2008-05-27 09:30 370,176 --a------ C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll
2008-05-26 12:14 . 2008-05-26 12:14 365,568 --a------ C:\WINDOWS\system32\{aa6d4daf-dc0e-3b9c-e5e2-fc03f2a75c7e}.dll
2008-05-20 17:05 . 2008-05-20 17:05 32,768 --a------ C:\WINDOWS\system32\vntiho06\vntiho061083.exe
2008-05-16 06:15 . 2008-05-16 06:15 80 --ah----- C:\WINDOWS\system32\HsInfo.dat
2008-05-15 22:50 . 2008-06-01 00:41 <DIR> d-------- C:\Program Files\Gravity
2008-05-13 21:29 . 2008-05-13 21:29 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-10 04:24 --------- d-----w C:\Program Files\Java
2008-06-09 21:27 54,913 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-06-08 14:42 167,976 ----a-w C:\WINDOWS\system32\drivers\core.cache.dsk
2008-06-08 07:30 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-07 15:12 --------- d-----w C:\Documents and Settings\Devaughn Jones\Application Data\uTorrent
2008-06-05 14:00 --------- d-----w C:\Program Files\Apple Software Update
2008-06-05 13:57 --------- d-----w C:\Program Files\iTunes
2008-06-05 13:57 --------- d-----w C:\Program Files\iPod
2008-06-05 13:55 --------- d-----w C:\Program Files\QuickTime
2008-06-05 12:47 --------- d-----w C:\Program Files\uTorrent
2008-06-05 00:33 --------- d-s---w C:\Program Files\Xfire
2008-06-03 21:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-01 04:37 65,536 -c--a-w C:\WINDOWS\IFinst27.exe
2008-05-25 04:31 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-19 22:12 --------- d-----w C:\Documents and Settings\Devaughn Jones\Application Data\Xfire
2008-05-15 20:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-05-12 10:31 --------- d-----w C:\Program Files\cdcgames
2008-04-28 23:05 --------- d-----w C:\Program Files\Nexon
2008-04-21 04:16 --------- d-----w C:\Program Files\Acclaim
2008-04-20 16:11 --------- d-----w C:\Documents and Settings\Devaughn Jones\Application Data\Nexon
2007-12-09 15:48 88 --sh--r C:\WINDOWS\system32\22F73B16BC.sys
2008-01-02 18:01 56 -csh--r C:\WINDOWS\system32\C4C2FCF8F3.sys
2008-01-02 18:01 6,580 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{de91d9ea-b2d3-58c1-a001-764c59e0511c}]
2008-05-27 09:30 370176 --a------ C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2007-06-28 18:29 190024]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"WallPaper"="C:\DOCUME~1\DEVAUG~1\MYDOCU~1\Programs\WALLPA~1.90\WALLPA~1.exe" [2001-06-10 19:28 246272]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 22:56 218032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTDCPL"="RTDCPL.EXE" [2005-05-26 16:38 12275200 C:\WINDOWS\system32\RTDCPL.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07 8491008]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 22:56 218032]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 22:56 86960]
"razer"="C:\Program Files\Razer\Copperhead\razerhid.exe" [2005-10-08 17:27 155648]
"nwiz"="nwiz.exe" [2007-09-17 01:07 1626112 C:\WINDOWS\system32\nwiz.exe]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 06:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 08:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 06:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00 455168]
"VX6000"="C:\WINDOWS\vVX6000.exe" [2006-10-13 17:04 994096]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 01:07 81920]
"Tarantula"="C:\Program Files\Razer\Tarantula\razerhid.exe" [2006-08-14 13:30 176128]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 10:24 16384]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 21:54 116072]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.7.0\bin\jusched.exe" [2008-06-10 00:24 140672]
"{9e128f1b-f405-62bb-bd72-99fabb5fccda}"="C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll" [2008-05-27 09:30 370176]
"548d6c8f"="C:\WINDOWS\system32\gvhxiyta.dll" [ ]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-09 18:13 1177368]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmjHyV]
pmnmjHyV.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~2\wbsrv.dll 2008-01-14 18:02 210168 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~2\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll,avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Trillian\\trillian.exe"=
"C:\\Program Files\\Xfire\\Xfire.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\snyter\\counter-strike\\hl.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\snyter\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\snyter\\condition zero\\hl.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Triggersoft\\Rose Online Evolution\\TRose.exe"=
"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\javaw.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\Valve\\Steam\\steam.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\OGPlanet\\CABAL Online\\cabal.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:Blizzard DOwnloader
"31161:TCP"= 31161:TCP:uTorrent

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-09 18:13]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 11:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 11:21]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-09 18:13]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-09 18:13]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-09 18:13]
R2 PlugPlayRPC;Plug and Play (RPC);C:\WINDOWS\portsv.exe service []
R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 11:21]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 10:23]
R2 WUSB54GSCSVC;WUSB54GSCSVC;"C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe" "WUSB54GSC.exe" []
S1 vnetusbrr;vnetusbrr;C:\WINDOWS\system32\drivers\vnetusbrr.sys []
S3 Mkd2kfNt;Mkd2kfNt;C:\WINDOWS\system32\drivers\Mkd2kfNt.sys [2007-08-20 16:42]
S3 Mkd2Usbf;Mkd2Usbf;C:\WINDOWS\system32\drivers\Mkd2Usbf.sys [2007-07-12 11:32]
S3 PRISM_USB;Linksys Wireless-B USB Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\LSPMUSB.sys [2003-10-02 02:47]
S3 Razerlow;Razer Copperhead Driver;C:\WINDOWS\system32\Drivers\Razerlow.sys [2005-08-12 11:11]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys []
S3 scskusbf;USB SCSK Filter Driver Service;C:\WINDOWS\system32\drivers\scskusbf.sys [2008-04-08 19:45]
S3 scskusbs;USB SCSK Driver Service;C:\WINDOWS\system32\drivers\scskusbs.sys [2008-04-08 19:45]
S3 TarFltr;Razer Tarantula USB Keyboard;C:\WINDOWS\system32\Drivers\UsbFltr.sys [2006-07-11 19:46]
S3 USBNET;Instant Wireless USB Network Adapter ver.2.6 Driver;C:\WINDOWS\system32\DRIVERS\vnetusbr.sys [2003-04-04 02:33]
S3 VX6000;Microsoft LifeCam VX-6000;C:\WINDOWS\system32\DRIVERS\VX6000Xp.sys [2006-10-13 17:04]
S3 wampapache;wampapache;"c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe" -k runservice []
S3 wampmysqld;wampmysqld;c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe wampmysqld []
S3 XDva076;XDva076;C:\WINDOWS\system32\XDva076.sys []
S3 XDva134;XDva134;C:\WINDOWS\system32\XDva134.sys []
S3 XDva167;XDva167;C:\WINDOWS\system32\XDva167.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6432b566-4521-11db-95f4-000c41380024}]
\Shell\AutoRun\command - G:\LaunchU3.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-06-05 13:48:28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-10 19:16:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Stardock\Object Desktop\WindowBlinds\tray.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\portsv.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Razer\Copperhead\razerofa.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WUSB54GSC.exe
C:\Program Files\vghd\vghd.exe
.
**************************************************************************
.
Completion time: 2008-06-10 19:24:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-10 23:24:04

Pre-Run: 84,997,013,504 bytes free
Post-Run: 84,948,881,408 bytes free

433 --- E O F --- 2008-05-28 14:00:41


and Hijacks

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:44:59 PM, on 6/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\portsv.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\RTDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Razer\Copperhead\razerhid.exe
C:\WINDOWS\vVX6000.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Razer\Tarantula\razerhid.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Razer\Copperhead\razerofa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.7.0\bin\jusched.exe
C:\WINDOWS\System32\Rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\DOCUME~1\DEVAUG~1\MYDOCU~1\Programs\WALLPA~1.90\WALLPA~1.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WUSB54GSC.exe
C:\Program Files\vghd\vghd.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.7.0\bin\ssv.dll
O2 - BHO: gooochi browser optimizer - {de91d9ea-b2d3-58c1-a001-764c59e0511c} - C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll
O4 - HKLM\..\Run: [RTDCPL] RTDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Tarantula] C:\Program Files\Razer\Tarantula\razerhid.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.7.0\bin\jusched.exe"
O4 - HKLM\..\Run: [{9e128f1b-f405-62bb-bd72-99fabb5fccda}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll" DllStart
O4 - HKLM\..\Run: [548d6c8f] rundll32.exe "C:\WINDOWS\system32\gvhxiyta.dll",b
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WallPaper] C:\DOCUME~1\DEVAUG~1\MYDOCU~1\Programs\WALLPA~1.90\WALLPA~1.EXE /h
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - Startup: Deewoo.lnk = C:\QooBox\Quarantine\C\WINDOWS\system32\mcntmkdm.exe.vir
O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\jlwnw64l.exe
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.7.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.7.0\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplane...DC_2.2.1.87.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games....GamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail....es/MSNPUpld.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://ca.com/securi...an/pestscan.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zon...wn.cab56986.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload....Plugin11USA.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemreq.../sysreqlab2.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.c.../acclaim_v5.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zon...nt.cab55762.cab
O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_USAv1001 Class) - http://ares.netgame....ch_USAv1002.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zon...ro.cab55579.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload....GPlugin9USA.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.del...ll/gtdownde.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: wbsys.dll,avgrsstx.dll
O20 - Winlogon Notify: pmnmjHyV - pmnmjHyV.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Plug and Play (RPC) (PlugPlayRPC) - Unknown owner - C:\WINDOWS\portsv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe
O23 - Service: WUSB54GSCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe

--
End of file - 12714 bytes
  • 0

#5
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi again,

Please go to add or remove programs and uninstall if present:

Virtual Girl

Please click Start then Run, in the window appears type in Notepad.exe.
Highlight the entire content of the codebox below. Copy (Control + C) and Paste (Control + V) the content into the notepad window:
DirLook::
C:\WINDOWS\system32\3161
C:\WINDOWS\system32\5960

File::
C:\WINDOWS\portsv.exe
C:\WINDOWS\system32\iftuyszv.exe
C:\WINDOWS\444.0
C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll-uninst.exe
C:\Windows\system32\pmnmjHyV.dll
C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll
C:\WINDOWS\system32\{aa6d4daf-dc0e-3b9c-e5e2-fc03f2a75c7e}.dll
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\IFinst27.exe
C:\WINDOWS\system32\C4C2FCF8F3.sys
C:\WINDOWS\system32\KGyGaAvL.sys
C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll

Folder::
C:\Program Files\vghd
C:\WINDOWS\system32\vntiho06

Driver::
PlugPlayRPC
vnetusbrr

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{de91d9ea-b2d3-58c1-a001-764c59e0511c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{9e128f1b-f405-62bb-bd72-99fabb5fccda}"=-
"548d6c8f"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmjHyV]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6432b566-4521-11db-95f4-000c41380024}]
Now in Notepad, go to File and in the menu that drops down click on Save As...
Save the file as CFScript.txt

Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
Posted Image

After that please reboot your computer if it asks you to and post ComboFix.txt (the report the ComboFix will generate) in your next reply.
  • 0

#6
WildaNdCrazy

WildaNdCrazy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
The 1st time I did it I got a blue screen, for some reason. But the 2ed time I did it, it worked.

FILE ::
C:\WINDOWS\444.0
C:\WINDOWS\IFinst27.exe
C:\WINDOWS\portsv.exe
C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll
C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll-uninst.exe
C:\WINDOWS\system32\{aa6d4daf-dc0e-3b9c-e5e2-fc03f2a75c7e}.dll
C:\WINDOWS\system32\C4C2FCF8F3.sys
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\iftuyszv.exe
C:\WINDOWS\system32\KGyGaAvL.sys
C:\Windows\system32\pmnmjHyV.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
---- Previous Run -------
.
C:\Documents and Settings\Devaughn Jones\Favorites\Online Security Test.url
C:\Documents and Settings\Devaughn Jones\Start Menu\Programs\Startup\Deewoo.lnk
C:\Documents and Settings\Devaughn Jones\Start Menu\Programs\Startup\DW_Start.lnk
C:\Program Files\vghd
C:\Program Files\vghd\uninstall1212549516.exe
C:\WINDOWS\b.exe
C:\WINDOWS\IFinst27.exe
C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll-uninst.exe
C:\WINDOWS\system32\{63ac493c-4160-19a7-6c80-683057e50cbb}.dll
C:\WINDOWS\system32\{aa6d4daf-dc0e-3b9c-e5e2-fc03f2a75c7e}.dll
C:\WINDOWS\system32\C4C2FCF8F3.sys
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\KGyGaAvL.sys
C:\WINDOWS\system32\vntiho06

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_PLUGPLAYRPC
-------\Legacy_VNETUSBRR
-------\Service_PlugPlayRPC
-------\Service_vnetusbrr


((((((((((((((((((((((((( Files Created from 2008-05-10 to 2008-06-10 )))))))))))))))))))))))))))))))
.

2008-06-11 02:10 . 2008-06-11 02:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Stardock
2008-06-10 19:14 . 2008-06-10 19:17 <DIR> d-------- C:\WINDOWS\system32\3161
2008-06-10 00:36 . 2008-06-10 00:36 <DIR> d-------- C:\Documents and Settings\Devaughn Jones\.SunDownloadManager
2008-06-09 22:35 . 2008-06-09 22:35 <DIR> d-------- C:\Program Files\PremiumSoft
2008-06-09 22:24 . 2008-06-09 22:42 <DIR> d-------- C:\wamp
2008-06-09 21:42 . 2008-06-09 21:42 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-06-09 21:41 . 2008-06-09 21:44 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-06-09 21:41 . 2008-06-09 21:42 <DIR> d-------- C:\Program Files\Common Files\Merge Modules
2008-06-09 21:41 . 2008-06-09 21:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-09 21:40 . 2008-06-09 21:40 <DIR> d-------- C:\Program Files\Microsoft SDKs
2008-06-09 21:24 . 2008-06-09 21:24 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-06-09 18:24 . 2008-06-10 13:18 <DIR> d--h----- C:\$AVG8.VAULT$
2008-06-09 18:13 . 2008-06-10 08:02 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-09 18:13 . 2008-06-09 18:13 <DIR> d-------- C:\Program Files\AVG
2008-06-09 18:13 . 2008-06-09 18:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-09 18:13 . 2008-06-09 18:13 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-09 18:13 . 2008-06-09 18:13 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-09 18:13 . 2008-06-09 18:13 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-06-09 17:58 . 2008-06-10 18:49 <DIR> d-------- C:\HostsXpert
2008-06-09 17:36 . 2008-06-09 17:38 <DIR> d-------- C:\Program Files\MySQL
2008-06-09 17:36 . 2008-06-09 17:46 <DIR> d-------- C:\Documents and Settings\Devaughn Jones\Application Data\MySQL
2008-06-08 15:12 . 2008-06-09 18:29 <DIR> d-------- C:\WINDOWS\system32\5960
2008-06-08 10:42 . 2008-06-10 23:44 <DIR> d-------- C:\WINDOWS\system32\xrem
2008-06-08 10:42 . 2008-06-10 23:43 <DIR> d-------- C:\WINDOWS\system32\NMP
2008-06-08 10:42 . 2008-06-10 23:42 <DIR> d-------- C:\WINDOWS\system32\inet2
2008-06-08 10:42 . 2008-06-08 10:43 <DIR> d-------- C:\WINDOWS\system32\expo
2008-06-08 10:42 . 2008-06-10 23:40 <DIR> d-------- C:\WINDOWS\system32\btz
2008-06-08 10:42 . 2008-06-10 23:40 <DIR> d-------- C:\WINDOWS\system32\105772
2008-06-08 10:42 . 2008-06-08 10:42 63,909 --a------ C:\WINDOWS\system32\{aa6d4daf-dc0e-3b9c-e5e2-fc03f2a75c7e}.dll-uninst.exe
2008-06-08 10:42 . 2008-06-08 10:42 4 --a------ C:\WINDOWS\system32\jpewocmz.ini
2008-06-07 14:51 . 2008-06-08 21:36 <DIR> d-------- C:\Program Files\Fraps
2008-06-06 23:22 . 2008-06-06 23:22 <DIR> d-------- C:\Documents and Settings\Devaughn Jones\Application Data\Screaming Bee
2008-06-06 23:17 . 2008-06-06 23:17 <DIR> d-------- C:\Program Files\Common Files\Screaming Bee
2008-06-06 23:15 . 2008-06-06 23:15 <DIR> d-------- C:\Program Files\Screaming Bee
2008-06-05 09:58 . 2008-06-10 13:42 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-05 09:58 . 2008-06-05 09:58 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-04 21:58 . 2008-06-04 21:58 <DIR> d-------- C:\WINDOWS\NamelessRO Eclipse
2008-06-03 22:31 . 2008-06-10 23:20 <DIR> d-------- C:\Downloads
2008-06-03 20:42 . 2008-06-08 21:20 <DIR> d-------- C:\Program Files\Rohan
2008-06-03 16:03 . 2008-06-03 16:03 <DIR> d-------- C:\Documents and Settings\Devaughn Jones\Application Data\Talkback
2008-05-31 20:11 . 2008-05-31 21:42 <DIR> d-------- C:\Program Files\Triggersoft
2008-05-16 06:15 . 2008-05-16 06:15 80 --ah----- C:\WINDOWS\system32\HsInfo.dat
2008-05-15 22:50 . 2008-06-01 00:41 <DIR> d-------- C:\Program Files\Gravity
2008-05-13 21:29 . 2008-05-13 21:29 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-11 03:37 --------- d-----w C:\Documents and Settings\Devaughn Jones\Application Data\uTorrent
2008-06-10 17:32 55,958 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-06-10 04:24 --------- d-----w C:\Program Files\Java
2008-06-08 07:30 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-05 14:00 --------- d-----w C:\Program Files\Apple Software Update
2008-06-05 13:57 --------- d-----w C:\Program Files\iTunes
2008-06-05 13:57 --------- d-----w C:\Program Files\iPod
2008-06-05 13:55 --------- d-----w C:\Program Files\QuickTime
2008-06-05 12:47 --------- d-----w C:\Program Files\uTorrent
2008-06-05 00:33 --------- d-s---w C:\Program Files\Xfire
2008-06-03 21:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-25 04:31 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-19 22:12 --------- d-----w C:\Documents and Settings\Devaughn Jones\Application Data\Xfire
2008-05-15 20:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-05-12 10:31 --------- d-----w C:\Program Files\cdcgames
2008-05-06 19:25 58,616 ----a-w C:\WINDOWS\system32\wbload.dll
2008-04-28 23:05 --------- d-----w C:\Program Files\Nexon
2008-04-28 15:35 42,672 ----a-w C:\WINDOWS\system32\wbsys.dll
2008-04-21 04:16 --------- d-----w C:\Program Files\Acclaim
2008-04-20 16:11 --------- d-----w C:\Documents and Settings\Devaughn Jones\Application Data\Nexon
2008-04-09 22:52 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-04-05 21:59 3,148 ----a-w C:\WINDOWS\system32\tmp.reg
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2007-12-09 15:48 88 --sh--r C:\WINDOWS\system32\22F73B16BC.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\WINDOWS\system32\3161 ----


---- Directory of C:\WINDOWS\system32\5960 ----

2008-06-09 18:29 476 -r-hs---- C:\WINDOWS\system32\5960\~!22064p.spt


((((((((((((((((((((((((((((( snapshot@2008-06-10_19.22.53.64 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-10 23:14:49 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-10 17:41:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2004-08-04 10:00:00 237,056 ----a-w C:\WINDOWS\system32\dllcache\provthrd.dll
+ 2004-08-04 10:00:00 75,264 ----a-w C:\WINDOWS\system32\dllcache\wmipicmp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2007-06-28 18:29 190024]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"WallPaper"="C:\DOCUME~1\DEVAUG~1\MYDOCU~1\Programs\WALLPA~1.90\WALLPA~1.exe" [2001-06-10 19:28 246272]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 22:56 218032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTDCPL"="RTDCPL.EXE" [2005-05-26 16:38 12275200 C:\WINDOWS\system32\RTDCPL.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07 8491008]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 22:56 218032]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 22:56 86960]
"razer"="C:\Program Files\Razer\Copperhead\razerhid.exe" [2005-10-08 17:27 155648]
"nwiz"="nwiz.exe" [2007-09-17 01:07 1626112 C:\WINDOWS\system32\nwiz.exe]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 06:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 08:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 06:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00 455168]
"VX6000"="C:\WINDOWS\vVX6000.exe" [2006-10-13 17:04 994096]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 01:07 81920]
"Tarantula"="C:\Program Files\Razer\Tarantula\razerhid.exe" [2006-08-14 13:30 176128]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 10:24 16384]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 21:54 116072]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.7.0\bin\jusched.exe" [2008-06-10 00:24 140672]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-09 18:13 1177368]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~2\wbsrv.dll 2008-04-28 11:35 210168 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~2\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll,avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Trillian\\trillian.exe"=
"C:\\Program Files\\Xfire\\Xfire.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\snyter\\counter-strike\\hl.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\snyter\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\snyter\\condition zero\\hl.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Triggersoft\\Rose Online Evolution\\TRose.exe"=
"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\javaw.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\Valve\\Steam\\steam.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\OGPlanet\\CABAL Online\\cabal.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
"C:\\Program Files\\Nexon\\MapleStory\\MapleVIOLAUNCHER_v55.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:Blizzard DOwnloader
"31161:TCP"= 31161:TCP:uTorrent


*Newly Created Service* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder
"2008-06-05 13:48:28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-10 13:57:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-10 14:01:15
ComboFix-quarantined-files.txt 2008-06-10 18:01:09
ComboFix2.txt 2008-06-10 23:24:45

Pre-Run: 86,178,529,280 bytes free
Post-Run: 86,158,409,728 bytes free

235 --- E O F --- 2008-05-28 14:00:41
  • 0

#7
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi again,

Quick Question, when you installed MessengerPlus! 3 did you check the "sponsor program", or leave it out? http://www.softwaret...MsgPlusexe.html

Step 1. Making a CFScript

Please post the header as well!! You've been leaving out the top part of the Combofix log.

Please click Start then Run, in the window appears type in Notepad.exe.
Highlight the entire content of the codebox below. Copy (Control + C) and Paste (Control + V) the content into the notepad window:
File::
C:\WINDOWS\system32\{aa6d4daf-dc0e-3b9c-e5e2-fc03f2a75c7e}.dll-uninst.exe
C:\WINDOWS\system32\jpewocmz.ini
C:\WINDOWS\system32\tmp.reg

Folder::
C:\WINDOWS\system32\3161
C:\WINDOWS\system32\5960
C:\WINDOWS\system32\xrem
C:\WINDOWS\system32\NMP
C:\WINDOWS\system32\inet2
C:\WINDOWS\system32\expo
C:\WINDOWS\system32\btz
C:\WINDOWS\system32\105772
Now in Notepad, go to File and in the menu that drops down click on Save As...
Save the file as CFScript.txt

Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
Posted Image

After that please reboot your computer if it asks you to and post ComboFix.txt (the report the ComboFix will generate) in your next reply.

Step 2. Running MalwareByte's Anti-Malware

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

In your next reply

Please post the log from ComboFix.
Please post the log from MalwareBytes' Anti-Malware.

If the logs are to big to fit in one reply please spread them out over multiple replies.

Edited by Mike, 10 June 2008 - 07:23 AM.

  • 0

#8
WildaNdCrazy

WildaNdCrazy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
I don't believe I did click the, "sponcer program" button when downloading MessengerPlus! 3.

Both logs now, with everything..

ComboFix 08-06-08.2 - Devaughn Jones 2008-06-11 12:58:24.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.49.1033.18.520 [GMT -4:00]
Running from: C:\Documents and Settings\Devaughn Jones\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Devaughn Jones\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\{aa6d4daf-dc0e-3b9c-e5e2-fc03f2a75c7e}.dll-uninst.exe
C:\WINDOWS\system32\jpewocmz.ini
C:\WINDOWS\system32\tmp.reg
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\{aa6d4daf-dc0e-3b9c-e5e2-fc03f2a75c7e}.dll-uninst.exe
C:\WINDOWS\system32\105772
C:\WINDOWS\system32\3161
C:\WINDOWS\system32\5960
C:\WINDOWS\system32\5960\~!22064p.spt
C:\WINDOWS\system32\btz
C:\WINDOWS\system32\expo
C:\WINDOWS\system32\inet2
C:\WINDOWS\system32\jpewocmz.ini
C:\WINDOWS\system32\NMP
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\system32\xrem

.
((((((((((((((((((((((((( Files Created from 2008-05-11 to 2008-06-11 )))))))))))))))))))))))))))))))
.

2008-06-11 02:10 . 2008-06-11 02:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Stardock
2008-06-10 00:36 . 2008-06-10 00:36 <DIR> d-------- C:\Documents and Settings\Devaughn Jones\.SunDownloadManager
2008-06-09 22:35 . 2008-06-09 22:35 <DIR> d-------- C:\Program Files\PremiumSoft
2008-06-09 22:24 . 2008-06-09 22:42 <DIR> d-------- C:\wamp
2008-06-09 21:42 . 2008-06-09 21:42 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-06-09 21:41 . 2008-06-09 21:44 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-06-09 21:41 . 2008-06-09 21:42 <DIR> d-------- C:\Program Files\Common Files\Merge Modules
2008-06-09 21:41 . 2008-06-09 21:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-09 21:40 . 2008-06-09 21:40 <DIR> d-------- C:\Program Files\Microsoft SDKs
2008-06-09 21:24 . 2008-06-09 21:24 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-06-09 18:24 . 2008-06-10 15:09 <DIR> d--h----- C:\$AVG8.VAULT$
2008-06-09 18:13 . 2008-06-10 15:07 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-09 18:13 . 2008-06-09 18:13 <DIR> d-------- C:\Program Files\AVG
2008-06-09 18:13 . 2008-06-09 18:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-09 18:13 . 2008-06-09 18:13 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-09 18:13 . 2008-06-09 18:13 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-09 18:13 . 2008-06-09 18:13 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-06-09 17:58 . 2008-06-10 18:49 <DIR> d-------- C:\HostsXpert
2008-06-09 17:36 . 2008-06-09 17:38 <DIR> d-------- C:\Program Files\MySQL
2008-06-09 17:36 . 2008-06-09 17:46 <DIR> d-------- C:\Documents and Settings\Devaughn Jones\Application Data\MySQL
2008-06-07 14:51 . 2008-06-08 21:36 <DIR> d-------- C:\Program Files\Fraps
2008-06-06 23:22 . 2008-06-06 23:22 <DIR> d-------- C:\Documents and Settings\Devaughn Jones\Application Data\Screaming Bee
2008-06-06 23:17 . 2008-06-06 23:17 <DIR> d-------- C:\Program Files\Common Files\Screaming Bee
2008-06-06 23:15 . 2008-06-06 23:15 <DIR> d-------- C:\Program Files\Screaming Bee
2008-06-05 09:58 . 2008-06-10 13:42 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-05 09:58 . 2008-06-05 09:58 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-04 21:58 . 2008-06-04 21:58 <DIR> d-------- C:\WINDOWS\NamelessRO Eclipse
2008-06-03 22:31 . 2008-06-10 23:20 <DIR> d-------- C:\Downloads
2008-06-03 20:42 . 2008-06-08 21:20 <DIR> d-------- C:\Program Files\Rohan
2008-06-03 16:03 . 2008-06-03 16:03 <DIR> d-------- C:\Documents and Settings\Devaughn Jones\Application Data\Talkback
2008-06-02 20:56 . 2008-06-02 20:56 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-05-31 20:11 . 2008-05-31 21:42 <DIR> d-------- C:\Program Files\Triggersoft
2008-05-16 06:15 . 2008-05-16 06:15 80 --ah----- C:\WINDOWS\system32\HsInfo.dat
2008-05-15 22:50 . 2008-06-01 00:41 <DIR> d-------- C:\Program Files\Gravity

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-11 05:43 56,738 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-06-11 03:37 --------- d-----w C:\Documents and Settings\Devaughn Jones\Application Data\uTorrent
2008-06-11 00:13 --------- d-s---w C:\Program Files\Xfire
2008-06-10 22:07 --------- d-----w C:\Documents and Settings\Devaughn Jones\Application Data\Xfire
2008-06-10 04:24 --------- d-----w C:\Program Files\Java
2008-06-08 07:30 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-05 14:00 --------- d-----w C:\Program Files\Apple Software Update
2008-06-05 13:57 --------- d-----w C:\Program Files\iTunes
2008-06-05 13:57 --------- d-----w C:\Program Files\iPod
2008-06-05 13:55 --------- d-----w C:\Program Files\QuickTime
2008-06-05 12:47 --------- d-----w C:\Program Files\uTorrent
2008-06-03 21:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-25 04:31 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-15 20:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-05-12 10:31 --------- d-----w C:\Program Files\cdcgames
2008-05-06 19:25 58,616 ----a-w C:\WINDOWS\system32\wbload.dll
2008-04-28 23:05 --------- d-----w C:\Program Files\Nexon
2008-04-28 15:35 42,672 ----a-w C:\WINDOWS\system32\wbsys.dll
2008-04-21 04:16 --------- d-----w C:\Program Files\Acclaim
2008-04-20 16:11 --------- d-----w C:\Documents and Settings\Devaughn Jones\Application Data\Nexon
2008-04-09 22:52 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2007-12-09 15:48 88 --sh--r C:\WINDOWS\system32\22F73B16BC.sys
.

((((((((((((((((((((((((((((( snapshot@2008-06-10_19.22.53.64 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-10 23:14:49 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-10 17:41:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2004-08-04 10:00:00 237,056 ----a-w C:\WINDOWS\system32\dllcache\provthrd.dll
+ 2004-08-04 10:00:00 75,264 ----a-w C:\WINDOWS\system32\dllcache\wmipicmp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2007-06-28 18:29 190024]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"WallPaper"="C:\DOCUME~1\DEVAUG~1\MYDOCU~1\Programs\WALLPA~1.90\WALLPA~1.exe" [2001-06-10 19:28 246272]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 22:56 218032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTDCPL"="RTDCPL.EXE" [2005-05-26 16:38 12275200 C:\WINDOWS\system32\RTDCPL.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07 8491008]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 22:56 218032]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 22:56 86960]
"razer"="C:\Program Files\Razer\Copperhead\razerhid.exe" [2005-10-08 17:27 155648]
"nwiz"="nwiz.exe" [2007-09-17 01:07 1626112 C:\WINDOWS\system32\nwiz.exe]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 06:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 08:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 06:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00 455168]
"VX6000"="C:\WINDOWS\vVX6000.exe" [2006-10-13 17:04 994096]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 01:07 81920]
"Tarantula"="C:\Program Files\Razer\Tarantula\razerhid.exe" [2006-08-14 13:30 176128]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 10:24 16384]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 21:54 116072]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.7.0\bin\jusched.exe" [2008-06-10 00:24 140672]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-09 18:13 1177368]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~2\wbsrv.dll 2008-04-28 11:35 210168 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~2\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll,avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Trillian\\trillian.exe"=
"C:\\Program Files\\Xfire\\Xfire.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\snyter\\counter-strike\\hl.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\snyter\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\snyter\\condition zero\\hl.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Triggersoft\\Rose Online Evolution\\TRose.exe"=
"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\javaw.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\Valve\\Steam\\steam.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\OGPlanet\\CABAL Online\\cabal.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
"C:\\Program Files\\Nexon\\MapleStory\\MapleVIOLAUNCHER_v55.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:Blizzard DOwnloader
"31161:TCP"= 31161:TCP:uTorrent

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-09 18:13]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 11:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 11:21]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-09 18:13]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 10:23]
R2 WUSB54GSCSVC;WUSB54GSCSVC;"C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe" "WUSB54GSC.exe" []
S2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-09 18:13]
S2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-09 18:13]
S2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 11:21]
S3 Mkd2kfNt;Mkd2kfNt;C:\WINDOWS\system32\drivers\Mkd2kfNt.sys [2007-08-20 16:42]
S3 Mkd2Usbf;Mkd2Usbf;C:\WINDOWS\system32\drivers\Mkd2Usbf.sys [2007-07-12 11:32]
S3 PRISM_USB;Linksys Wireless-B USB Network Adapter Driver;C:\WINDOWS\system32\DRIVERS\LSPMUSB.sys [2003-10-02 02:47]
S3 Razerlow;Razer Copperhead Driver;C:\WINDOWS\system32\Drivers\Razerlow.sys [2005-08-12 11:11]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys []
S3 scskusbf;USB SCSK Filter Driver Service;C:\WINDOWS\system32\drivers\scskusbf.sys [2008-04-08 19:45]
S3 scskusbs;USB SCSK Driver Service;C:\WINDOWS\system32\drivers\scskusbs.sys [2008-04-08 19:45]
S3 TarFltr;Razer Tarantula USB Keyboard;C:\WINDOWS\system32\Drivers\UsbFltr.sys [2006-07-11 19:46]
S3 USBNET;Instant Wireless USB Network Adapter ver.2.6 Driver;C:\WINDOWS\system32\DRIVERS\vnetusbr.sys [2003-04-04 02:33]
S3 VX6000;Microsoft LifeCam VX-6000;C:\WINDOWS\system32\DRIVERS\VX6000Xp.sys [2006-10-13 17:04]
S3 wampapache;wampapache;"c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe" -k runservice []
S3 wampmysqld;wampmysqld;c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe wampmysqld []
S3 XDva076;XDva076;C:\WINDOWS\system32\XDva076.sys []
S3 XDva134;XDva134;C:\WINDOWS\system32\XDva134.sys []
S3 XDva167;XDva167;C:\WINDOWS\system32\XDva167.sys []

*Newly Created Service* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder
"2008-06-05 13:48:28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-11 13:03:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\Documents and Settings\Devaughn Jones\Local Settings\Application Data\Microsoft\Messenger\REMOVED EMAIL\SharingMetadata\Working\database_6C54_8D9E_548D_6C20\fsr007B1.log 131072 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2008-06-11 13:05:44
ComboFix-quarantined-files.txt 2008-06-11 17:05:39
ComboFix2.txt 2008-06-10 18:01:18
ComboFix3.txt 2008-06-10 23:24:45

Pre-Run: 86,115,995,648 bytes free
Post-Run: 86,099,005,440 bytes free

228 --- E O F --- 2008-05-28 14:00:41



Malwarebytes' Anti-Malware 1.16
Database version: 845

1:15:28 PM 6/11/2008
mbam-log-6-11-2008 (13-15-28).txt

Scan type: Quick Scan
Objects scanned: 42302
Time elapsed: 5 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{85e06077-c824-43d0-a8dc-5efb17bc348a} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\targetedbanner (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\AdwareAlert (Rogue.AdwareAlert) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\AdwareAlert\AdwareAlert.url (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Program Files\AdwareAlert\license.rtf (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\Program Files\AdwareAlert\unins000.dat (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\image09.zip (Backdoor.Bot) -> Quarantined and deleted successfully.

Edited by Mike, 10 June 2008 - 11:59 AM.
Removed email.

  • 0

#9
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi there,

Your e-mail address was in your post, so I took the liberty and removed it. Don't want to have you spammed by all those bots lurking the forums.

Your logs look good, any problems?

  • Download the latest version of Java Runtime Environment (JRE) 6 Update 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u6-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.
Step 1. Running ATF Cleaner

Please download ATF Cleaner by Atribune.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Step 2. Running Kaspersky Online Virusscaner

Please run a free online scan with Kaspersky AntiVirus (works only with MS Internet Explorer 5.0 or higher).
Go to http://www.kaspersky.com/virusscanner and click the "Kaspersky Online Scanner" button (NOT "Kaspersky File Scanner").
  • In the new window that opens, click the "Accept" button to accept the user agreement, install the ActiveX control, and download the program.
  • When you get the Windows dialog asking if you want to install this software, click the "Install" button.
  • When the "Update progress" line changes to "Ready" and the "NEXT ->" button lights up with a green arrow, click it.
  • Click on the "Scan Settings" button, and in the next window select the "extended" database, and click Ok.
  • Under "Please select a target to scan:", click My Computer to start the scan.
When the scan is finished, click the "Save as Text" button, and save the file as kavscan.txt to your Desktop, close the Kaspersky On-line Scanner window, and post the text in kavscan.txt in your next reply.

Edited by Mike, 10 June 2008 - 12:16 PM.

  • 0

#10
WildaNdCrazy

WildaNdCrazy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Okay, Ignore that message, it didn't work on IE but I tried it on Firefox and it worked and is currently scanning right now.

Edited by WildaNdCrazy, 10 June 2008 - 04:19 PM.

  • 0

Advertisements


#11
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
From what I know, the Kaspersky scan only works in IE. You can use the IE Tab add-on in firefox to run it though.

The scan takes a while to complete.

I'll wait for your response :)

Cheers,

Mike
  • 0

#12
WildaNdCrazy

WildaNdCrazy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Okay sorry for the long reply, had a few problems with scanning..but its over now. Now...the list is pretty long and would take a lot of post to show all of it..so could it be possible to just upload it?

Edited by WildaNdCrazy, 12 June 2008 - 07:00 AM.

  • 0

#13
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
You can attach it to your post, Click on Add Reply and in the middle there should be a place where you can attach the file.
  • 0

#14
WildaNdCrazy

WildaNdCrazy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Okay the files are pretty big I have to actually send them in two different files. I suppose its from the years of supposedly thinking I removed threats correctly. Sorry if its a bit overwhelming.

Attached Files


  • 0

#15
WildaNdCrazy

WildaNdCrazy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
And here is the second part of the scan.

Attached Files


Edited by WildaNdCrazy, 12 June 2008 - 07:59 AM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP