ok here is what happened:
ATF ran w/o a problem.
Hijack this fixed BHO and run entries w/o a problem.
Located C:\WINDOWS\system32\yxemcw.dll but was unable to delete, rebooted to release file, deleted w/o a problem.
I was unable to locate the following files:
C:\PROGRA~1\MYWEBS~1\
C:\Windows\SysD.exe
But I did find:
C:\Windows\Sys1C2.exe
C:\Windows\SysB.exe
Your directions said to delete "if they exists", so I continued with the directions.
Malwarebyte's software downloaded and installed but was unable to locate update server? I had this problem earlier before posting log. Any ideas?
anyways... I ran MBAM here is the log:
Malwarebytes' Anti-Malware 1.21
Database version: 966
Windows 5.1.2600 Service Pack 2
6:30:27 PM 7/19/2008
mbam-log-7-19-2008 (18-30-27).txt
Scan type: Quick Scan
Objects scanned: 38335
Time elapsed: 6 minute(s), 33 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 6
Files Infected: 16
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\rhc52oj0e99a (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\SecuriSoft SARL (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\BASE (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\DELETED (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\SAVED (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\Sys1C2.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wdocmixy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-2000478354-507921405-839522115-1003\Dc1.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080718161841137.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080718162404997.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080718164650807.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080718165717742.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080718170507486.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080718175144682.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080718190501070.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080718195321465.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080718212751328.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080719094811006.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080719102746700.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecuriSoft SARL\WinSpywareProtect\LOG\20080719105018142.log (Rogue.WinSpywareProtect) -> Quarantined and deleted successfully.
C:\WINDOWS\SysB.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Here is the combofix log:
ComboFix 08-07-19.1 - User 2008-07-19 19:29:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.212 [GMT -5:00]
Running from: C:\Documents and Settings\User\Desktop\Virus cleanup\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\1.tmp
C:\WINDOWS\system32\2.tmp
C:\WINDOWS\system32\3.tmp
C:\WINDOWS\system32\9.tmp
C:\WINDOWS\system32\A.tmp
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((( Files Created from 2008-06-20 to 2008-07-20 )))))))))))))))))))))))))))))))
.
2008-07-19 18:20 . 2008-07-19 18:20 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-19 18:20 . 2008-07-18 19:15 36,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-19 18:20 . 2008-07-18 19:15 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-19 11:09 . 2008-07-19 11:09 <DIR> d-------- C:\VundoFix Backups
2008-07-19 10:15 . 2008-07-19 10:15 <DIR> d-------- C:\Documents and Settings\User\Application Data\Malwarebytes
2008-07-19 10:15 . 2008-07-19 10:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-18 22:15 . 2008-07-19 13:40 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-18 22:15 . 2008-07-18 22:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-18 21:47 . 2008-07-18 21:47 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-18 21:28 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-07-18 21:28 . 2004-08-04 00:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-07-18 19:25 . 2008-07-18 19:25 <DIR> d-------- C:\Program Files\Alwil Software
2008-07-18 19:18 . 2008-07-18 19:18 <DIR> d-------- C:\Documents and Settings\User\Application Data\Sammsoft
2008-07-18 19:17 . 2008-07-18 19:17 <DIR> d-------- C:\Program Files\Advanced Registry Optimizer
2008-07-18 13:33 . 2008-07-18 13:33 <DIR> d-------- C:\Documents and Settings\User\Application Data\Apple Computer
2008-07-18 13:32 . 2008-07-18 13:32 <DIR> d-------- C:\Program Files\Bonjour
2008-07-18 13:30 . 2008-07-18 13:30 <DIR> d-------- C:\Program Files\Apple Software Update
2008-07-18 13:29 . 2008-07-18 13:29 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-07-18 13:29 . 2008-07-18 13:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-07-06 19:47 . 2008-07-06 19:47 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-07-06 19:47 . 2008-07-06 19:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-06-22 17:23 . 2008-06-13 08:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-22 17:23 . 2008-06-13 08:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-18 22:11 12,464 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2008-07-18 20:59 --------- d-----w C:\Documents and Settings\User\Application Data\LimeWire
2008-07-14 01:46 --------- d-----w C:\Program Files\Lx_cats
2008-07-07 00:50 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-27 01:13 --------- d-----w C:\Program Files\e-Sword
2008-06-25 01:42 --------- d-----w C:\Program Files\Libronix DLS
2008-06-23 00:43 --------- d-----w C:\Program Files\LimeWire
2008-06-04 03:25 --------- d-----w C:\Documents and Settings\User\Application Data\U3
2008-05-25 00:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-25 00:08 --------- d-----w C:\Program Files\EA GAMES
2008-05-23 23:50 --------- d-----w C:\Program Files\Yahoo!
2008-05-23 23:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\YAHOO
2008-05-23 22:37 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2008-05-23 22:36 --------- d-----w C:\Program Files\illiminable
2008-05-23 22:35 --------- d-----w C:\Program Files\RCA
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 08:18 15360]
"AROReminder"="C:\Program Files\Advanced Registry Optimizer\aro.exe" [2008-04-09 14:22 2135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-06 00:05 339968]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-12-19 12:08 1347584]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 14:50 155648]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-05-21 04:21 90112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"LXCFCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 12:47 73728]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
C:\Documents and Settings\User\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dbd32733-2f83-11d8-b2af-000f1fa0bb67}]
\Shell\AutoRun\command - D:\Menu.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-07-18 18:31:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)
HKCU-Run-PhotoShow Deluxe Media Manager - C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-19 19:32:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
.
**************************************************************************
.
Completion time: 2008-07-19 19:34:46 - machine was rebooted [User]
ComboFix-quarantined-files.txt 2008-07-20 00:34:42
Pre-Run: 28,674,301,952 bytes free
Post-Run: 28,611,014,656 bytes free
129 --- E O F --- 2008-07-18 15:08:36
Edited by SpaCeTraNce, 19 July 2008 - 06:44 PM.