Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Infected with Troj/Virtum-Gen. Pls.. Help


  • Please log in to reply

#16
IndiGenus

IndiGenus

    Anti-Malware Buddha

  • Member
  • PipPipPipPip
  • 1,617 posts
OK, we can go with combofix from here again.

Also, are the infections really dangerous or are they pretty comman virus that dont pose much risk...??

That's hard to say exactly, but I don't see any signs of backdoors or rootkits. But that's the problem, you don't always see them. This Vundo is usually more focused on giving you false warnings around infections that aren't there, and taking your money. But at the same time, when we first started you were very heavily infected. Let's give cf another try and see if it's something I missed or if something is hiding.
  • 0

Advertisements


#17
villabhi

villabhi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
ok... Lets hope for the best...

Here is the combofix log

ComboFix 09-01-19.05 - 501407560 2009-01-20 22:37:02.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1501 [GMT -5:00]
Running from: d:\documents and settings\501407560\Desktop\Combo-Fix.exe
AV: Sophos Anti-Virus *On-access scanning disabled* (Outdated)
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
FW: Sophos Client Firewall *enabled*
.
The following files were disabled during the run:
c:\windows\system32\nodedeje.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
d:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

----- BITS: Possible infected sites -----

hxxp://wsus.ad.ge.com
.
((((((((((((((((((((((((( Files Created from 2008-12-21 to 2009-01-21 )))))))))))))))))))))))))))))))
.

2009-01-20 16:52 . 2009-01-20 16:52 26,155 --a------ c:\windows\system32\drivers\LKD3E.tmp
2009-01-20 08:31 . 2008-11-06 02:03 <DIR> d-------- C:\SDFix
2009-01-19 18:58 . 2009-01-19 18:58 <DIR> d-------- c:\windows\Sun
2009-01-19 18:57 . 2009-01-19 18:56 410,984 --a------ c:\windows\system32\deploytk.dll
2009-01-19 18:57 . 2009-01-19 18:56 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-01-19 18:11 . 2009-01-19 18:11 <DIR> d-------- d:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-19 18:11 . 2009-01-19 18:11 <DIR> d-------- d:\documents and settings\501407560\Application Data\Malwarebytes
2009-01-19 18:11 . 2009-01-19 18:11 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-19 18:11 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-19 18:11 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-19 13:40 . 2009-01-19 13:40 <DIR> d--h----- c:\windows\PIF
2009-01-19 09:45 . 2009-01-19 13:41 <DIR> d-------- C:\ComboFix
2009-01-18 11:13 . 2009-01-18 11:13 <DIR> d-------- c:\program files\Trend Micro
2009-01-15 10:07 . 2009-01-15 10:07 <DIR> d-------- c:\windows\PacTrack
2009-01-15 10:06 . 2009-01-15 10:06 <DIR> d-------- c:\program files\Common Files\Sophos
2009-01-15 10:06 . 2009-01-15 10:02 100,096 --a------ c:\windows\system32\drivers\scfdriver.sys
2009-01-15 10:04 . 2009-01-15 10:04 <DIR> d-------- c:\program files\Common Files\Cisco Systems
2009-01-15 10:04 . 2009-01-15 10:02 17,920 --a------ c:\windows\system32\sophosboottasks.exe
2009-01-15 10:03 . 2009-01-15 10:06 <DIR> d-------- d:\documents and settings\All Users\Application Data\Sophos
2009-01-15 10:02 . 2009-01-15 10:02 101,120 --a------ c:\windows\system32\drivers\savonaccesscontrol.sys
2009-01-15 10:02 . 2009-01-15 10:02 33,408 --a------ c:\windows\system32\drivers\savonaccessfilter.sys
2009-01-15 10:00 . 2009-01-15 10:07 <DIR> d-------- c:\program files\Sophos
2009-01-15 09:46 . 2009-01-15 09:46 <DIR> d-------- c:\temp\Sophos
2009-01-15 09:46 . 2009-01-15 10:07 <DIR> d-------- C:\Logs
2008-12-22 10:53 . 2009-01-15 17:01 <DIR> d-------- C:\GE Work
2008-12-22 07:37 . 2008-12-22 07:37 262,144 --a------ C:\ntuser.dat
2008-12-22 06:33 . 2008-12-22 06:33 <DIR> d---s---- d:\documents and settings\LocalService\UserData

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-21 03:04 --------- d-----w d:\documents and settings\501407560\Application Data\Sametime
2009-01-20 15:50 30,267 ----a-w c:\windows\system32\drivers\safeboot.sys
2009-01-20 15:49 --------- d-----w c:\program files\SafeBoot
2009-01-19 23:56 --------- d-----w c:\program files\Java
2009-01-17 20:33 --------- d-----w d:\documents and settings\501407560\Application Data\Move Networks
2009-01-15 15:50 --------- d-----w c:\program files\Common Files\Real
2009-01-15 15:48 --------- d-----w c:\program files\Google
2009-01-15 15:34 --------- d-----w d:\documents and settings\All Users\Application Data\Symantec
2009-01-15 15:34 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-10 14:21 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-02 16:41 4,524,004 ----a-w c:\windows\java\Packages\ON9R757V.ZIP
2009-01-02 15:59 --------- d-----w c:\program files\Nortel Networks
2008-12-24 03:30 726,008 ----a-w c:\windows\java\gotomypc_438.exe
2008-12-22 09:15 --------- d---a-w d:\documents and settings\All Users\Application Data\TEMP
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
.

((((((((((((((((((((((((((((( snapshot@2009-01-19_14.13.30.87 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-19 19:28:43 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
- 2008-10-30 18:22:23 38,240 ----a-r c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2009-01-19 19:29:10 38,240 ----a-r c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2009-01-13 18:17:16 658,288 ----a-w c:\windows\Options\Packages\CoreApps\PCHealthService\Updates\kb958687.exe
+ 2008-12-17 19:59:18 1,861,488 ----a-w c:\windows\Options\Packages\CoreApps\PCHealthService\Updates\kb960714ie60.exe
- 2008-12-03 16:16:58 8,750,592 ----a-w c:\windows\Options\Packages\CoreApps\PCHealthService\Utils\office\cifs\puids.dat
+ 2008-12-12 22:48:08 8,763,904 ----a-w c:\windows\Options\Packages\CoreApps\PCHealthService\Utils\office\cifs\puids.dat
- 2008-12-10 01:11:38 679,936 ----a-w c:\windows\Options\Packages\CoreApps\PCHealthService\Utils\PCHealthService.exe
+ 2009-01-13 19:19:52 679,936 ----a-w c:\windows\Options\Packages\CoreApps\PCHealthService\Utils\PCHealthService.exe
- 2008-11-11 21:04:04 28,718 ----a-w c:\windows\Options\Packages\CoreApps\PCHealthService\Utils\servers.dat
+ 2009-01-13 18:30:02 28,756 ----a-w c:\windows\Options\Packages\CoreApps\PCHealthService\Utils\servers.dat
- 2008-12-10 02:54:32 317,741 ----a-w c:\windows\Options\Packages\CoreApps\PCHealthService\Utils\UpdateMD5.dat
+ 2009-01-13 18:33:52 323,342 ----a-w c:\windows\Options\Packages\CoreApps\PCHealthService\Utils\UpdateMD5.dat
- 2008-10-16 10:37:05 3,059,712 -c--a-w c:\windows\system32\dllcache\mshtml.dll
+ 2008-12-12 17:33:23 3,060,224 -c--a-w c:\windows\system32\dllcache\mshtml.dll
- 2008-08-28 10:04:17 333,056 -c--a-w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 11:57:21 333,184 -c--a-w c:\windows\system32\dllcache\srv.sys
- 2008-10-30 23:23:25 208,584 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-01-20 13:34:21 208,584 ----a-w c:\windows\system32\FNTCACHE.DAT
- 2008-02-09 05:22:58 49,248 ----a-w c:\windows\system32\java.exe
+ 2009-01-19 23:56:36 144,792 ----a-w c:\windows\system32\java.exe
- 2008-02-09 05:23:08 53,346 ----a-w c:\windows\system32\javaw.exe
+ 2009-01-19 23:56:37 144,792 ----a-w c:\windows\system32\javaw.exe
- 2008-02-09 07:05:02 131,174 ----a-w c:\windows\system32\javaws.exe
+ 2009-01-19 23:56:37 148,888 ----a-w c:\windows\system32\javaws.exe
- 2008-10-16 10:37:05 3,059,712 ----a-w c:\windows\system32\mshtml.dll
+ 2008-12-12 17:33:23 3,060,224 ----a-w c:\windows\system32\mshtml.dll
- 2007-05-08 19:03:04 1,275,392 ----a-w c:\windows\system32\msxml4.dll
+ 2008-09-30 21:43:34 1,286,152 ----a-w c:\windows\system32\msxml4.dll
- 2007-05-15 19:43:10 1,320,800 ----a-w c:\windows\system32\msxml6.dll
+ 2008-08-30 01:06:44 1,350,664 ----a-w c:\windows\system32\msxml6.dll
- 2007-07-27 14:41:40 16,760 ------w c:\windows\system32\spmsg.dll
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\system32\spmsg.dll
+ 2009-01-21 03:46:46 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_2c0.dat
+ 2009-01-21 03:45:23 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_74c.dat
+ 2008-09-30 21:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2008-09-30 21:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-03 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-16 138008]
"OdTray.exe"="c:\program files\Juniper Networks\Odyssey Access Client\OdTray.exe" [2007-06-20 1028160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-19 136600]
"Sxplog"="c:\sxpinst\sxpstub.exe" [2005-10-24 20480]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-09 2183168]
"SBMGRNT.EXE"="c:\progra~1\SafeBoot\SBMGRNT.EXE" [2008-04-28 49212]
"CA-AMAgent"="c:\program files\CA\Unicenter Asset Management\Agents\amagent.exe" [2003-03-07 45056]
"ENDFORCEAgent"="c:\program files\ENDFORCE\AgntTray.exe" [2007-12-21 1646592]
"SCFTrayStartUp"="c:\program files\Sophos\Sophos Client Firewall\SCFTray.exe" [2009-01-15 224312]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2006-02-28 c:\windows\system32\bthprops.cpl]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 c:\windows\stsystra.exe]
"SDJobCheck"="triggusr.exe" [2006-02-22 Delivery\BIN\triggusr.exe]

d:\documents and settings\Default User\Start Menu\Programs\Startup\
Sametime 7.5.lnk - c:\program files\IBM\Sametime Connect\sametime.exe [2006-10-18 360448]

d:\documents and settings\501056442\Start Menu\Programs\Startup\
Sametime 7.5.lnk - c:\program files\IBM\Sametime Connect\sametime.exe [2006-10-18 360448]

d:\documents and settings\501407560\Start Menu\Programs\Startup\
Sametime 7.5.lnk - c:\program files\IBM\Sametime Connect\sametime.exe [2006-10-18 360448]

d:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2007-10-26 245760]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OdysseyClient]
2008-04-28 08:21 122949 c:\windows\system32\odyEvent.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\0\0]
"Script"=firefox_shutdown.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=Disable_Hibernation_for_Safeboot.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=firefox_startup.vbs

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dllhost.exe"=
"c:\\Program Files\\IBM\\Sametime Connect\\sametime.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5556:TCP"= 5556:TCP:SafeBoot

R0 SafeBoot;SafeBoot;c:\windows\system32\drivers\safeboot.sys [2008-04-28 30267]
R0 SBAlg;SBAlg;c:\windows\system32\drivers\sbalg.sys [2008-04-28 44848]
R1 RsvLock;RsvLock;c:\windows\system32\drivers\rsvlock.sys [2008-04-28 4752]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [2009-01-15 101120]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [2009-01-15 33408]
R1 SBFlop;SBFlop;c:\windows\system32\drivers\sbflop.sys [2008-04-28 6096]
R1 SbPrcCtl;SbPrcCtl;c:\windows\system32\drivers\sbprcctl.sys [2008-04-28 14864]
R1 scfdriver;SCF Kernel Driver;c:\windows\system32\drivers\scfdriver.sys [2009-01-15 100096]
R3 Eacfilt;Eacfilt Miniport;c:\windows\system32\drivers\eacfilt.sys [2007-10-15 9433]
R3 jnprna;Juniper Network Agent Miniport;c:\windows\system32\drivers\jnprna.sys [2007-06-14 398720]
R4 ENDFORCE Agent API;ENDFORCE Agent API;c:\program files\ENDFORCE\AgentAPI.exe [2007-12-19 2945024]
R4 JuniperAccessService;Juniper Unified Network Service;c:\program files\Common Files\Juniper Networks\JUNS\dsAccessService.exe [2007-06-14 87664]
R4 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2006-10-17 69632]
R4 SafeBootConfigurationManager;SafeBoot Configuration Manager;c:\program files\SafeBoot\sbmgrnt.exe [2008-04-28 49212]
R4 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2009-01-15 69632]
R4 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [2009-01-15 98304]
R4 SDService;Unicenter Software Delivery;c:\program files\CA\Unicenter Software Delivery\BIN\SDServ.exe [2006-02-22 32768]
R4 Sophos Client Firewall Manager;Sophos Client Firewall Manager;c:\program files\Sophos\Sophos Client Firewall\SCFManager.exe [2009-01-15 109624]
R4 Sophos Client Firewall;Sophos Client Firewall;c:\program files\Sophos\Sophos Client Firewall\SCFService.exe [2009-01-15 93240]
S0 iastor3400;Intel AHCI Controller;c:\windows\system32\drivers\iaStor3400.sys [2008-02-20 308248]
S0 iaStor390;Intel AHCI Controller;c:\windows\system32\drivers\iaStor390.sys [2007-12-13 304920]
S0 iastor755;Intel AHCI Controller;c:\windows\system32\drivers\IaStor755.sys [2007-10-18 305176]
S0 symmpi7400;symmpi7400;c:\windows\system32\drivers\symmpi7400.sys [2008-02-20 100096]
S3 EacService;Juniper TNC Endpoint Assessment;c:\program files\Common Files\Juniper Networks\TNC Client\jTnccService.exe [2007-06-20 81992]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [?]
S3 ExtranetAccess;Contivity VPN Service;c:\program files\Nortel Networks\Extranet_serv.exe [2007-10-15 630784]
S4 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [2007-10-15 115680]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - AMOAGENT

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9570a551-4bdf-11dc-86d1-806d6172696f}]
\Shell\AutoRun\command - F:\setup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EEBF9CA6-567B-41cd-B5F6-EF2C7FEF37B5}]
rundll32.exe advpack.dll,LaunchINFSectionEx c:\windows\INF\wmactedp.inf,PerUserStub,,4
.
Contents of the 'Scheduled Tasks' folder

2009-01-19 c:\windows\Tasks\workstations.job
- c:\program files\Sophos\Sophos Anti-Virus\BackgroundScanClient.exe [2009-01-15 10:02]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-CPM6fb81b72 - c:\windows\system32\nodedeje.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://corp.home.ge.com/
uInternet Connection Wizard,ShellNext = https://discoverer.f...feelname=oracle
uInternet Settings,ProxyOverride = <local>
Trusted Zone: *.webex.com
Trusted Zone: *.webex.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: Sametime MRC 651FP1 - hxxp://americascomm01.ge.com/sametime/stmeetingroomclient/STMeetingRoomClient.cab
DPF: {8F0DF9DB-AA5A-4ED0-9176-1C4A9C762C59} - hxxp://americascomm01.ge.com/sametime/STMeetingRoomClient/STJNILoader.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-20 22:47:39
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sophos Message Router]
"ImagePath"="\"c:\program files\Sophos\Remote Management System\RouterNT.exe\" -service -name Router -ORBListenEndpoints iiop://:8193/ssl_port=8194"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1744)
c:\program files\SafeBoot\SBGINA.DLL
c:\program files\SafeBoot\SBIPC.DLL
c:\windows\system32\odyEvent.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Juniper Networks\Odyssey Access Client\odClientService.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\scardsvr.exe
c:\program files\CA\SharedComponents\CAM\bin\cam.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Sophos\Remote Management System\ManagementAgentNT.exe
c:\program files\Sophos\AutoUpdate\ALsvc.exe
c:\program files\Sophos\Remote Management System\RouterNT.exe
c:\program files\CA\Unicenter Software Delivery\BIN\TRIGGAG.exe
c:\program files\SigmaTel\C-Major Audio\WDM\stacsv.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\igfxsrvc.exe
c:\sxpinst\sxplog32.exe
c:\windows\UMCSTUB.EXE
c:\program files\IBM\Sametime Connect\jre\bin\sametime75.exe
c:\program files\CA\Unicenter Asset Management\Agents\UMCLISVC.EXE
.
**************************************************************************
.
Completion time: 2009-01-20 22:53:43 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-21 03:53:40
ComboFix2.txt 2009-01-19 21:06:19
ComboFix3.txt 2009-01-19 19:15:09

Pre-Run: 21,220,626,432 bytes free
Post-Run: 21,234,352,128 bytes free

270 --- E O F --- 2009-01-19 19:29:31


********************************************************************************
*********************************************************************************
*********************************************************************************
*********************************************************************************
*******************************************************


And here is the latest Hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:54, on 2009-01-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\SafeBoot\SBMGRNT.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
C:\Program Files\CA\SharedComponents\CAM\bin\cam.exe
C:\Program Files\ENDFORCE\AgentAPI.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\CA\Unicenter Software Delivery\BIN\SDSERV.EXE
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\Program Files\CA\Unicenter Software Delivery\BIN\TRIGGAG.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\SxpInst\sxplog32.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\ENDFORCE\AgntTray.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\IBM\Sametime Connect\sametime.exe
C:\WINDOWS\UMCSTUB.EXE
C:\Program Files\IBM\Sametime Connect\jre\bin\sametime75.exe
C:\Program Files\CA\Unicenter Asset Management\Agents\umclisvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\CA\SharedComponents\CAM\bin\caftf.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://corp.home.ge.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://discoverer.f...feelname=oracle
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://corp.setpac.ge.com/pac.pac
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: SupportCentral - {E5CA3FCB-32F0-4602-A3FD-0785E3F0F5BF} - C:\WINDOWS\system32\SCTOOL~1.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Sxplog] C:\SxpInst\sxpstub.exe
O4 - HKLM\..\Run: [SDJobCheck] triggusr.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SBMGRNT.EXE] C:\PROGRA~1\SafeBoot\SBMGRNT.EXE -WinLogon
O4 - HKLM\..\Run: [CA-AMAgent] "C:\Program Files\CA\Unicenter Asset Management\Agents\amagent.exe"
O4 - HKLM\..\Run: [ENDFORCEAgent] "C:\Program Files\ENDFORCE\AgntTray.exe"
O4 - HKLM\..\Run: [SCFTrayStartUp] C:\Program Files\Sophos\Sophos Client Firewall\SCFTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Sametime 7.5.lnk = C:\Program Files\IBM\Sametime Connect\sametime.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Sametime 7.5.lnk = C:\Program Files\IBM\Sametime Connect\sametime.exe (User 'Default user')
O4 - Startup: Sametime 7.5.lnk = C:\Program Files\IBM\Sametime Connect\sametime.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Sametime MRC 651FP1 - http://americascomm0...gRoomClient.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.co...?BundleId=26688
O16 - DPF: {8F0DF9DB-AA5A-4ED0-9176-1C4A9C762C59} (JNILoader Control) - http://americascomm0...STJNILoader.cab
O16 - DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} (KooPlayer Control) - http://www.ooxtv.com/livetv.ocx
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = treasury.corp.ge.com
O17 - HKLM\Software\..\Telephony: DomainName = treasury.corp.ge.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = treasury.corp.ge.com
O23 - Service: Asset Management Agent (AmoAgent) - Computer Associates International, Inc. - C:\WINDOWS\UMCSTUB.EXE
O23 - Service: Unicenter Message Queuing Server (CA-MessageQueuing) - Computer Associates International, Inc. - C:\Program Files\CA\SharedComponents\CAM\bin\cam.exe
O23 - Service: Juniper TNC Endpoint Assessment (EacService) - Juniper Networks - C:\Program Files\Common Files\Juniper Networks\TNC Client\jTnccService.exe
O23 - Service: ENDFORCE Agent API - ENDFORCE, Inc. - C:\Program Files\ENDFORCE\AgentAPI.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Juniper Unified Network Service (JuniperAccessService) - Juniper Networks - C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Juniper OAC Service (odClientService) - Juniper Networks, Inc. - C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe
O23 - Service: SafeBoot Configuration Manager (SafeBootConfigurationManager) - Control Break International - C:\Program Files\SafeBoot\SBMGRNT.EXE
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Unicenter Software Delivery (SDService) - Computer Associates International, Inc. - C:\Program Files\CA\Unicenter Software Delivery\BIN\SDSERV.EXE
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Client Firewall - Sophos Plc - C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
O23 - Service: Sophos Client Firewall Manager - Sophos Plc - C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 10005 bytes
  • 0

#18
IndiGenus

IndiGenus

    Anti-Malware Buddha

  • Member
  • PipPipPipPip
  • 1,617 posts
Looks like that got it. How's it running?

I would suggest you go back through and run MalwareBytes and Kaspersky again. Post both logs.
  • 0

#19
villabhi

villabhi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Hi Indigenus,
The PC is now running a lot better, the malware popups are not coming up now... Seems Combofix worked well this time.
I have Run MalwareBytes and Kaspersky scan again, please find the logs below...

MBAM Scan Log:

Malwarebytes' Anti-Malware 1.33
Database version: 1668
Windows 5.1.2600 Service Pack 2

2009-01-21 18:18:35
mbam-log-2009-01-21 (18-18-35).txt

Scan type: Quick Scan
Objects scanned: 66132
Time elapsed: 32 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


********************************************************************************
*********************************************************************************
*********************************************************************************
**********

Kaspersky Scan log:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Wednesday, January 21, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, January 21, 2009 22:08:53
Records in database: 1660831
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 88063
Threat name: 4
Infected objects: 14
Suspicious objects: 0
Duration of the scan: 03:48:06


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\birizofu.dll.vir Infected: Trojan.Win32.Monderd.l 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\nibaheya.dll.vir Infected: Trojan.Win32.Monder.amxj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\nupotuku.dll.vir Infected: Trojan.Win32.Monderd.l 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\pnswty.dll.vir Infected: Trojan.Win32.Monderd.l 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\puseveni.dll.vir Infected: Trojan.Win32.Monderd.l 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\rocvwt.dll.vir Infected: Trojan.Win32.Monderd.l 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ruhegozi.dll.vir Infected: Trojan.Win32.Agent.bilk 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\vinomisu.dll.vir Infected: Trojan-Spy.Win32.Agent.pni 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\waguroho.dll.vir Infected: Trojan.Win32.Monder.amxj 1
C:\WINDOWS\system32\nodedeje.dll Infected: Trojan-Spy.Win32.Agent.pni 1
D:\_OTMoveIt\MovedFiles\01202009_075641\WINDOWS\system32\mulumobu.dll.tmp Infected: Trojan.Win32.Agent.bilk 1
D:\_OTMoveIt\MovedFiles\01202009_075641\WINDOWS\system32\nodedeje.dll Infected: Trojan-Spy.Win32.Agent.pni 1
D:\_OTMoveIt\MovedFiles\01202009_075641\WINDOWS\system32\yizofuyu.dll.tmp Infected: Trojan.Win32.Agent.bilk 1
D:\_OTMoveIt\MovedFiles\01202009_075641\WINDOWS\system32\yuhisona.dll.tmp Infected: Trojan.Win32.Agent.bilk 1

The selected area was scanned.

********************************************************************************
*********************************************************************************
*********************************************************************************
**********************************

I hope everything is clean now... Also, during one of the scan something prompted that it would change the date format of my pc. Can you please telle me how i would change it back to original format....
  • 0

#20
IndiGenus

IndiGenus

    Anti-Malware Buddha

  • Member
  • PipPipPipPip
  • 1,617 posts
Hi,

I hope everything is clean now... Also, during one of the scan something prompted that it would change the date format of my pc. Can you please telle me how i would change it back to original format..

That's combofix. When we uninstall it at the end then it will change it back automatically.


One file in question....and I'm not sure what is going on with it. We already moved it as you can see from the logs with OTMoveIt, but it was either put back or replaced. Let's move it again.



  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :processes
    explorer.exe
    
    :files
    C:\WINDOWS\system32\nodedeje.dll
    
    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Also post a new HijackThis log and let me know how it's running.
  • 0

#21
villabhi

villabhi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Hi Indigenus,
I ran OTMoveit3 and until i ran this app, everything was running fine but not now i see the malware pop-ups are back. I wonder if the virus are back in full force after we run this...

Anyways plese find the OTMoveit log below..

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
DllUnregisterServer procedure not found in C:\WINDOWS\system32\nodedeje.dll
C:\WINDOWS\system32\nodedeje.dll NOT unregistered.
C:\WINDOWS\system32\nodedeje.dll moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. D:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\JET7824.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_170.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_7bc.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01222009_220537

Files moved on Reboot...
File move failed. D:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. D:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. D:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully.
File C:\WINDOWS\temp\JET7824.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_170.dat not found!
File C:\WINDOWS\temp\Perflib_Perfdata_7bc.dat not found!

********************************************************************************
*********************************************************************************
*********************************************************************************
*********************************************************************************
*********************************************************************************
****************

Please find the HijackThis log below

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:51, on 2009-01-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\SafeBoot\SBMGRNT.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
C:\Program Files\CA\SharedComponents\CAM\bin\cam.exe
C:\Program Files\ENDFORCE\AgentAPI.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\CA\Unicenter Software Delivery\BIN\SDSERV.EXE
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\CA\Unicenter Software Delivery\BIN\TRIGGAG.EXE
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\SxpInst\sxplog32.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\ENDFORCE\AgntTray.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\UMCSTUB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\IBM\Sametime Connect\sametime.exe
C:\Program Files\IBM\Sametime Connect\jre\bin\sametime75.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://corp.home.ge.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://discoverer.f...feelname=oracle
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://corp.setpac.ge.com/pac.pac
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: SupportCentral - {E5CA3FCB-32F0-4602-A3FD-0785E3F0F5BF} - C:\WINDOWS\system32\SCTOOL~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Sxplog] C:\SxpInst\sxpstub.exe
O4 - HKLM\..\Run: [SDJobCheck] triggusr.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SBMGRNT.EXE] C:\PROGRA~1\SafeBoot\SBMGRNT.EXE -WinLogon
O4 - HKLM\..\Run: [CA-AMAgent] "C:\Program Files\CA\Unicenter Asset Management\Agents\amagent.exe"
O4 - HKLM\..\Run: [ENDFORCEAgent] "C:\Program Files\ENDFORCE\AgntTray.exe"
O4 - HKLM\..\Run: [SCFTrayStartUp] C:\Program Files\Sophos\Sophos Client Firewall\SCFTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CPM6fb81b72] Rundll32.exe "c:\windows\system32\nodedeje.dll",a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Sametime 7.5.lnk = C:\Program Files\IBM\Sametime Connect\sametime.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Sametime 7.5.lnk = C:\Program Files\IBM\Sametime Connect\sametime.exe (User 'Default user')
O4 - Startup: Sametime 7.5.lnk = C:\Program Files\IBM\Sametime Connect\sametime.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Sametime MRC 651FP1 - http://americascomm0...gRoomClient.cab
O16 - DPF: {3A45C7F1-E772-46C9-A84D-7F60D401D2BD} (prjBrowseFolder.ctrlBrowseFolder) - http://libraries.ge....rowseFolder.CAB
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {4B58531F-5100-4FCD-9801-51D2728F85A6} (MassUploadDnD.UserInterface) - http://libraries.ge....ssUploadDnd.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.co...?BundleId=26688
O16 - DPF: {8F0DF9DB-AA5A-4ED0-9176-1C4A9C762C59} (JNILoader Control) - http://americascomm0...STJNILoader.cab
O16 - DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} (KooPlayer Control) - http://www.ooxtv.com/livetv.ocx
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = treasury.corp.ge.com
O17 - HKLM\Software\..\Telephony: DomainName = treasury.corp.ge.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = treasury.corp.ge.com
O20 - AppInit_DLLs: c:\windows\system32\nodedeje.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\nodedeje.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\nodedeje.dll
O23 - Service: Asset Management Agent (AmoAgent) - Computer Associates International, Inc. - C:\WINDOWS\UMCSTUB.EXE
O23 - Service: Unicenter Message Queuing Server (CA-MessageQueuing) - Computer Associates International, Inc. - C:\Program Files\CA\SharedComponents\CAM\bin\cam.exe
O23 - Service: Juniper TNC Endpoint Assessment (EacService) - Juniper Networks - C:\Program Files\Common Files\Juniper Networks\TNC Client\jTnccService.exe
O23 - Service: ENDFORCE Agent API - ENDFORCE, Inc. - C:\Program Files\ENDFORCE\AgentAPI.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Juniper Unified Network Service (JuniperAccessService) - Juniper Networks - C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Juniper OAC Service (odClientService) - Juniper Networks, Inc. - C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe
O23 - Service: SafeBoot Configuration Manager (SafeBootConfigurationManager) - Control Break International - C:\Program Files\SafeBoot\SBMGRNT.EXE
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Unicenter Software Delivery (SDService) - Computer Associates International, Inc. - C:\Program Files\CA\Unicenter Software Delivery\BIN\SDSERV.EXE
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Client Firewall - Sophos Plc - C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
O23 - Service: Sophos Client Firewall Manager - Sophos Plc - C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 11101 bytes
  • 0

#22
IndiGenus

IndiGenus

    Anti-Malware Buddha

  • Member
  • PipPipPipPip
  • 1,617 posts
When we move/delete this file:

C:\WINDOWS\system32\nodedeje.dll

It comes right back and the entire infection returns. Give me a little bit more time to look at this and I'll get back to you asap. In the meantime, please run combofix again, and post the log. It should at least get you back to where you are running without apparent issues.
  • 0

#23
IndiGenus

IndiGenus

    Anti-Malware Buddha

  • Member
  • PipPipPipPip
  • 1,617 posts
Also, I had a question. Did you just recently install the Sophos AV and Firewall yourself? You have Symantec running on there also, I assume set up by your IT people. You don't want to run more than one AV or Firewall.

I would also like to do a rootkit scan.

Please create a new subfolder in the Program Files folder called GMER. If you have an older version of GMER installed, you must delete it.

Please run a GMER Rootkit scan:

Download GMER from here:
http://www.gmer.net/gmer.zip

Unzip it to the GMER Folder and start GMER.exe
Click the Rootkit tab and click the Scan button.

Warning! Please do not select the "Show all" checkbox during the scan.

Once done, click the Copy button.
This will copy the results to your clipboard.
Paste the results here in your next reply.
  • 0

#24
villabhi

villabhi

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Hi Indigenus,
Here is the latest Combofix log

ComboFix 09-01-21.04 - 501407560 2009-01-28 7:35:28.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1380 [GMT -5:00]
Running from: d:\documents and settings\501407560\Desktop\Combo-Fix.exe
AV: Sophos Anti-Virus *On-access scanning disabled* (Outdated)
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
FW: Sophos Client Firewall *enabled*
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\dehaziku.dll.tmp
c:\windows\system32\doyanavo.dll.tmp
c:\windows\system32\fonaneki.dll.tmp
c:\windows\system32\foponiga.dll.tmp
c:\windows\system32\gurohodo.dll.tmp
c:\windows\system32\wupadupo.dll.tmp

.
((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-28 )))))))))))))))))))))))))))))))
.

2009-01-27 19:51 . 2009-01-27 20:21 <DIR> d-------- c:\program files\Veoh Networks
2009-01-27 14:35 . 2009-01-27 14:35 26,155 --a------ c:\windows\system32\drivers\LKDC.tmp
2009-01-26 15:24 . 2009-01-26 15:24 <DIR> d-------- c:\program files\Common Files\Mercury Interactive
2009-01-26 15:24 . 2009-01-27 10:43 223 --a------ c:\windows\mercury.ini
2009-01-26 11:14 . 2009-01-26 11:14 26,155 --a------ c:\windows\system32\drivers\LKDD.tmp
2009-01-23 10:32 . 2009-01-23 10:32 26,155 --a------ c:\windows\system32\drivers\LKD3C.tmp
2009-01-23 07:12 . 2009-01-27 01:00 46,592 --a------ C:\win32.exe
2009-01-22 11:27 . 2009-01-22 11:27 26,155 --a------ c:\windows\system32\drivers\LKD24F.tmp
2009-01-21 18:19 . 2009-01-21 18:19 <DIR> d-------- c:\program files\Common Files\xing shared
2009-01-21 18:18 . 2009-01-21 18:18 <DIR> d-------- c:\program files\Real
2009-01-21 16:02 . 2008-04-28 08:25 <DIR> d-------- d:\documents and settings\200013630\FavoritesLink
2009-01-21 16:02 . 2007-08-21 21:48 <DIR> d-------- d:\documents and settings\200013630\Application Data\Sametime
2009-01-21 16:02 . 2007-08-21 21:13 <DIR> d-------- d:\documents and settings\200013630\Application Data\Microsoft Web Folders
2009-01-21 16:02 . 2008-04-28 10:39 <DIR> d-------- d:\documents and settings\200013630\Application Data\InstallShield
2009-01-21 16:01 . 2009-01-21 16:02 <DIR> d-------- d:\documents and settings\200013630
2009-01-20 16:52 . 2009-01-20 16:52 26,155 --a------ c:\windows\system32\drivers\LKD3E.tmp
2009-01-20 08:31 . 2008-11-06 02:03 <DIR> d-------- C:\SDFix
2009-01-19 18:58 . 2009-01-19 18:58 <DIR> d-------- c:\windows\Sun
2009-01-19 18:57 . 2009-01-19 18:56 410,984 --a------ c:\windows\system32\deploytk.dll
2009-01-19 18:57 . 2009-01-19 18:56 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-01-19 18:11 . 2009-01-19 18:11 <DIR> d-------- d:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-19 18:11 . 2009-01-19 18:11 <DIR> d-------- d:\documents and settings\501407560\Application Data\Malwarebytes
2009-01-19 18:11 . 2009-01-19 18:11 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-19 18:11 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-19 18:11 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-19 13:40 . 2009-01-19 13:40 <DIR> d--h----- c:\windows\PIF
2009-01-19 09:45 . 2009-01-19 13:41 <DIR> d-------- C:\ComboFix
2009-01-18 11:13 . 2009-01-18 11:13 <DIR> d-------- c:\program files\Trend Micro
2009-01-15 10:07 . 2009-01-15 10:07 <DIR> d-------- c:\windows\PacTrack
2009-01-15 10:06 . 2009-01-15 10:06 <DIR> d-------- c:\program files\Common Files\Sophos
2009-01-15 10:06 . 2009-01-15 10:02 100,096 --a------ c:\windows\system32\drivers\scfdriver.sys
2009-01-15 10:04 . 2009-01-15 10:04 <DIR> d-------- c:\program files\Common Files\Cisco Systems
2009-01-15 10:04 . 2009-01-15 10:02 17,920 --a------ c:\windows\system32\sophosboottasks.exe
2009-01-15 10:03 . 2009-01-15 10:06 <DIR> d-------- d:\documents and settings\All Users\Application Data\Sophos
2009-01-15 10:02 . 2009-01-15 10:02 101,120 --a------ c:\windows\system32\drivers\savonaccesscontrol.sys
2009-01-15 10:02 . 2009-01-15 10:02 33,408 --a------ c:\windows\system32\drivers\savonaccessfilter.sys
2009-01-15 10:00 . 2009-01-15 10:07 <DIR> d-------- c:\program files\Sophos
2009-01-15 09:46 . 2009-01-15 09:46 <DIR> d-------- c:\temp\Sophos
2009-01-15 09:46 . 2009-01-15 10:07 <DIR> d-------- C:\Logs

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-28 00:53 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-27 23:14 30,267 ----a-w c:\windows\system32\drivers\safeboot.sys
2009-01-27 23:00 --------- d-----w d:\documents and settings\501407560\Application Data\Sametime
2009-01-23 23:16 --------- d-----w d:\documents and settings\501407560\Application Data\Move Networks
2009-01-23 14:22 --------- d-----w c:\program files\Nortel Networks
2009-01-23 01:16 --------- d-----w c:\program files\SafeBoot
2009-01-22 18:20 --------- d-----w d:\documents and settings\501407560\Application Data\U3
2009-01-21 23:19 --------- d-----w c:\program files\Common Files\Real
2009-01-21 23:18 499,712 ----a-w c:\windows\system32\msvcp71.dll
2009-01-21 23:16 --------- d-----w c:\program files\Google
2009-01-19 23:56 --------- d-----w c:\program files\Java
2009-01-16 01:57 127,765 ----a-w c:\windows\system32\nodedeje.dll.vir
2009-01-15 15:34 --------- d-----w d:\documents and settings\All Users\Application Data\Symantec
2009-01-15 15:34 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-02 16:41 4,524,004 ----a-w c:\windows\java\Packages\ON9R757V.ZIP
2008-12-24 03:30 726,008 ----a-w c:\windows\java\gotomypc_438.exe
2008-12-22 12:37 262,144 ----a-w C:\ntuser.dat
2008-12-22 09:15 --------- d---a-w d:\documents and settings\All Users\Application Data\TEMP
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
.

((((((((((((((((((((((((((((( snapshot_2009-01-20_22.52.07.93 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-02-23 18:41:02 466,944 ----a-w c:\windows\system32\capicom.dll
+ 2007-12-14 16:28:12 516,832 ----a-w c:\windows\system32\capicom.dll
- 2009-01-20 13:34:21 208,584 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-01-25 02:09:50 208,584 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-01-21 23:18:41 278,528 ----a-w c:\windows\system32\pncrt.dll
+ 2009-01-21 23:18:43 6,656 ----a-w c:\windows\system32\pndx5016.dll
+ 2009-01-21 23:18:43 5,632 ----a-w c:\windows\system32\pndx5032.dll
+ 2009-01-21 23:18:56 185,920 ----a-w c:\windows\system32\rmoc3260.dll
+ 2009-01-27 22:55:10 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_59c.dat
+ 2009-01-27 22:56:35 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_d4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
"Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-28 3660848]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2008-12-16 3528440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-03 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-16 138008]
"OdTray.exe"="c:\program files\Juniper Networks\Odyssey Access Client\OdTray.exe" [2007-06-20 1028160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-19 136600]
"Sxplog"="c:\sxpinst\sxpstub.exe" [2005-10-24 20480]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-09 2183168]
"SBMGRNT.EXE"="c:\progra~1\SafeBoot\SBMGRNT.EXE" [2008-04-28 49212]
"CA-AMAgent"="c:\program files\CA\Unicenter Asset Management\Agents\amagent.exe" [2003-03-07 45056]
"ENDFORCEAgent"="c:\program files\ENDFORCE\AgntTray.exe" [2007-12-21 1646592]
"SCFTrayStartUp"="c:\program files\Sophos\Sophos Client Firewall\SCFTray.exe" [2009-01-15 224312]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-21 185872]
"CPM6fb81b72"="c:\windows\system32\nodedeje.dll" [BU]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2006-02-28 c:\windows\system32\bthprops.cpl]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 c:\windows\stsystra.exe]
"SDJobCheck"="triggusr.exe" [2006-02-22 Delivery\BIN\triggusr.exe]

d:\documents and settings\Default User\Start Menu\Programs\Startup\
Sametime 7.5.lnk - c:\program files\IBM\Sametime Connect\sametime.exe [2006-10-18 360448]

d:\documents and settings\501407560\Start Menu\Programs\Startup\
Sametime 7.5.lnk - c:\program files\IBM\Sametime Connect\sametime.exe [2006-10-18 360448]

d:\documents and settings\501056442\Start Menu\Programs\Startup\
Sametime 7.5.lnk - c:\program files\IBM\Sametime Connect\sametime.exe [2006-10-18 360448]

d:\documents and settings\200013630\Start Menu\Programs\Startup\
Sametime 7.5.lnk - c:\program files\IBM\Sametime Connect\sametime.exe [2006-10-18 360448]

d:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2007-10-26 245760]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OdysseyClient]
2008-04-28 08:21 122949 c:\windows\system32\odyEvent.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\nodedeje.dll
"LoadAppInit_DLLs"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\0\0]
"Script"=firefox_shutdown.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=Disable_Hibernation_for_Safeboot.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=firefox_startup.vbs

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dllhost.exe"=
"c:\\Program Files\\IBM\\Sametime Connect\\sametime.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5556:TCP"= 5556:TCP:SafeBoot

R0 SafeBoot;SafeBoot;c:\windows\system32\drivers\safeboot.sys [2008-04-28 30267]
R0 SBAlg;SBAlg;c:\windows\system32\drivers\sbalg.sys [2008-04-28 44848]
R1 RsvLock;RsvLock;c:\windows\system32\drivers\rsvlock.sys [2008-04-28 4752]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [2009-01-15 101120]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [2009-01-15 33408]
R1 SBFlop;SBFlop;c:\windows\system32\drivers\sbflop.sys [2008-04-28 6096]
R1 SbPrcCtl;SbPrcCtl;c:\windows\system32\drivers\sbprcctl.sys [2008-04-28 14864]
R1 scfdriver;SCF Kernel Driver;c:\windows\system32\drivers\scfdriver.sys [2009-01-15 100096]
R3 Eacfilt;Eacfilt Miniport;c:\windows\system32\drivers\eacfilt.sys [2007-10-15 9433]
R3 jnprna;Juniper Network Agent Miniport;c:\windows\system32\drivers\jnprna.sys [2007-06-14 398720]
R4 ENDFORCE Agent API;ENDFORCE Agent API;c:\program files\ENDFORCE\AgentAPI.exe [2007-12-19 2945024]
R4 JuniperAccessService;Juniper Unified Network Service;c:\program files\Common Files\Juniper Networks\JUNS\dsAccessService.exe [2007-06-14 87664]
R4 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2006-10-17 69632]
R4 SafeBootConfigurationManager;SafeBoot Configuration Manager;c:\program files\SafeBoot\sbmgrnt.exe [2008-04-28 49212]
R4 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2009-01-15 69632]
R4 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [2009-01-15 98304]
R4 SDService;Unicenter Software Delivery;c:\program files\CA\Unicenter Software Delivery\BIN\SDServ.exe [2006-02-22 32768]
R4 Sophos Client Firewall Manager;Sophos Client Firewall Manager;c:\program files\Sophos\Sophos Client Firewall\SCFManager.exe [2009-01-15 109624]
R4 Sophos Client Firewall;Sophos Client Firewall;c:\program files\Sophos\Sophos Client Firewall\SCFService.exe [2009-01-15 93240]
S0 iastor3400;Intel AHCI Controller;c:\windows\system32\drivers\iaStor3400.sys [2008-02-20 308248]
S0 iaStor390;Intel AHCI Controller;c:\windows\system32\drivers\iaStor390.sys [2007-12-13 304920]
S0 iastor755;Intel AHCI Controller;c:\windows\system32\drivers\IaStor755.sys [2007-10-18 305176]
S0 symmpi7400;symmpi7400;c:\windows\system32\drivers\symmpi7400.sys [2008-02-20 100096]
S3 EacService;Juniper TNC Endpoint Assessment;c:\program files\Common Files\Juniper Networks\TNC Client\jTnccService.exe [2007-06-20 81992]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [?]
S3 ExtranetAccess;Contivity VPN Service;c:\program files\Nortel Networks\Extranet_serv.exe [2007-10-15 630784]
S4 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [2007-10-15 115680]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - AMOAGENT

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9570a551-4bdf-11dc-86d1-806d6172696f}]
\Shell\AutoRun\command - F:\setup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EEBF9CA6-567B-41cd-B5F6-EF2C7FEF37B5}]
rundll32.exe advpack.dll,LaunchINFSectionEx c:\windows\INF\wmactedp.inf,PerUserStub,,4
.
Contents of the 'Scheduled Tasks' folder

2009-01-26 c:\windows\Tasks\workstations.job
- c:\program files\Sophos\Sophos Anti-Virus\BackgroundScanClient.exe [2009-01-15 10:02]
.
- - - - ORPHANS REMOVED - - - -

SharedTaskScheduler-{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\nodedeje.dll
SSODL-SSODL-{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\nodedeje.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://corp.home.ge.com/
uInternet Connection Wizard,ShellNext = https://discoverer.f...feelname=oracle
uInternet Settings,ProxyOverride = <local>
Trusted Zone: webex.com
Trusted Zone: webex.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: Sametime MRC 651FP1 - hxxp://americascomm01.ge.com/sametime/stmeetingroomclient/STMeetingRoomClient.cab
DPF: {3A45C7F1-E772-46C9-A84D-7F60D401D2BD} - hxxp://libraries.ge.com/Massuploadclient/prjBrowseFolder.CAB
DPF: {4B58531F-5100-4FCD-9801-51D2728F85A6} - hxxp://libraries.ge.com/Massuploadclient/massupload/MassUploadDnd.cab
DPF: {8F0DF9DB-AA5A-4ED0-9176-1C4A9C762C59} - hxxp://americascomm01.ge.com/sametime/STMeetingRoomClient/STJNILoader.cab
DPF: {B2FC031D-8C74-46AE-8042-BCF4FC03C1EF} - hxxp://qc92.corporate.ge.com/qcbin/Spider91.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-28 07:39:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sophos Message Router]
"ImagePath"="\"c:\program files\Sophos\Remote Management System\RouterNT.exe\" -service -name Router -ORBListenEndpoints iiop://:8193/ssl_port=8194"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(412)
c:\windows\system32\nodedeje.dll
c:\program files\SafeBoot\SBGINA.DLL
c:\program files\SafeBoot\SBIPC.DLL
c:\windows\system32\odyEvent.dll
c:\windows\system32\igfxdev.dll

- - - - - - - > 'lsass.exe'(1460)
c:\windows\system32\nodedeje.dll
.
Completion time: 2009-01-28 7:41:55
ComboFix-quarantined-files.txt 2009-01-28 12:41:44
ComboFix2.txt 2009-01-21 03:53:44
ComboFix3.txt 2009-01-19 21:06:19
ComboFix4.txt 2009-01-19 19:15:09

Pre-Run: 20,598,288,384 bytes free
Post-Run: 20,607,524,864 bytes free

251 --- E O F --- 2009-01-19 19:29:31


********************************************************************************
*********************************************************************************
*********************************************************************************
*********************************************************************************
*****************************************************


Here is the latest HijackThis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:42, on 2009-01-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\SafeBoot\SBMGRNT.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
C:\Program Files\CA\SharedComponents\CAM\bin\cam.exe
C:\Program Files\ENDFORCE\AgentAPI.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\CA\Unicenter Software Delivery\BIN\SDSERV.EXE
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\CA\Unicenter Software Delivery\BIN\TRIGGAG.EXE
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\SxpInst\sxplog32.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\ENDFORCE\AgntTray.exe
C:\Program Files\Sophos\Sophos Client Firewall\SCFTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\WINDOWS\UMCSTUB.EXE
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://corp.home.ge.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://discoverer.f...feelname=oracle
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://corp.setpac.ge.com/pac.pac
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: SupportCentral - {E5CA3FCB-32F0-4602-A3FD-0785E3F0F5BF} - C:\WINDOWS\system32\SCTOOL~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Juniper Networks\Odyssey Access Client\OdTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Sxplog] C:\SxpInst\sxpstub.exe
O4 - HKLM\..\Run: [SDJobCheck] triggusr.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SBMGRNT.EXE] C:\PROGRA~1\SafeBoot\SBMGRNT.EXE -WinLogon
O4 - HKLM\..\Run: [CA-AMAgent] "C:\Program Files\CA\Unicenter Asset Management\Agents\amagent.exe"
O4 - HKLM\..\Run: [ENDFORCEAgent] "C:\Program Files\ENDFORCE\AgntTray.exe"
O4 - HKLM\..\Run: [SCFTrayStartUp] C:\Program Files\Sophos\Sophos Client Firewall\SCFTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CPM6fb81b72] Rundll32.exe "c:\windows\system32\nodedeje.dll",a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
O4 - HKUS\S-1-5-21-1174098837-827816596-1734353810-3639\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1174098837-827816596-1734353810-8482\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - S-1-5-21-1174098837-827816596-1734353810-3639 Startup: Sametime 7.5.lnk = C:\Program Files\IBM\Sametime Connect\sametime.exe (User '?')
O4 - S-1-5-21-1174098837-827816596-1734353810-8482 Startup: Sametime 7.5.lnk = C:\Program Files\IBM\Sametime Connect\sametime.exe (User '?')
O4 - S-1-5-18 Startup: Sametime 7.5.lnk = C:\Program Files\IBM\Sametime Connect\sametime.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Sametime 7.5.lnk = C:\Program Files\IBM\Sametime Connect\sametime.exe (User 'Default user')
O4 - Startup: Sametime 7.5.lnk = C:\Program Files\IBM\Sametime Connect\sametime.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Sametime MRC 651FP1 - http://americascomm0...gRoomClient.cab
O16 - DPF: {3A45C7F1-E772-46C9-A84D-7F60D401D2BD} (prjBrowseFolder.ctrlBrowseFolder) - http://libraries.ge....rowseFolder.CAB
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {4B58531F-5100-4FCD-9801-51D2728F85A6} (MassUploadDnD.UserInterface) - http://libraries.ge....ssUploadDnd.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.co...?BundleId=26688
O16 - DPF: {8F0DF9DB-AA5A-4ED0-9176-1C4A9C762C59} (JNILoader Control) - http://americascomm0...STJNILoader.cab
O16 - DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} (KooPlayer Control) - http://www.ooxtv.com/livetv.ocx
O16 - DPF: {B2FC031D-8C74-46AE-8042-BCF4FC03C1EF} (Loader Class v4) - http://qc92.corporat...in/Spider91.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = treasury.corp.ge.com
O17 - HKLM\Software\..\Telephony: DomainName = treasury.corp.ge.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = treasury.corp.ge.com
O20 - AppInit_DLLs: c:\windows\system32\nodedeje.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\nodedeje.dll (file missing)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\nodedeje.dll (file missing)
O23 - Service: Asset Management Agent (AmoAgent) - Computer Associates International, Inc. - C:\WINDOWS\UMCSTUB.EXE
O23 - Service: Unicenter Message Queuing Server (CA-MessageQueuing) - Computer Associates International, Inc. - C:\Program Files\CA\SharedComponents\CAM\bin\cam.exe
O23 - Service: Juniper TNC Endpoint Assessment (EacService) - Juniper Networks - C:\Program Files\Common Files\Juniper Networks\TNC Client\jTnccService.exe
O23 - Service: ENDFORCE Agent API - ENDFORCE, Inc. - C:\Program Files\ENDFORCE\AgentAPI.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Juniper Unified Network Service (JuniperAccessService) - Juniper Networks - C:\Program Files\Common Files\Juniper Networks\JUNS\dsAccessService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Juniper OAC Service (odClientService) - Juniper Networks, Inc. - C:\Program Files\Juniper Networks\Odyssey Access Client\odClientService.exe
O23 - Service: SafeBoot Configuration Manager (SafeBootConfigurationManager) - Control Break International - C:\Program Files\SafeBoot\SBMGRNT.EXE
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Unicenter Software Delivery (SDService) - Computer Associates International, Inc. - C:\Program Files\CA\Unicenter Software Delivery\BIN\SDSERV.EXE
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Client Firewall - Sophos Plc - C:\Program Files\Sophos\Sophos Client Firewall\SCFService.exe
O23 - Service: Sophos Client Firewall Manager - Sophos Plc - C:\Program Files\Sophos\Sophos Client Firewall\SCFManager.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\StacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 12115 bytes
  • 0

#25
IndiGenus

IndiGenus

    Anti-Malware Buddha

  • Member
  • PipPipPipPip
  • 1,617 posts
Would like to run ATFCleaner and MBAM again too. I know you already have the tools so you can skip the download part of instructions.


First, use Use ATF Cleaner to remove temp files,
cookies, cache, ect...

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a Hijackthis log.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP