Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

bestsearchforever.biz/ HOW TO REMOVE [Closed]


  • This topic is locked This topic is locked

#1
marknc392

marknc392

    New Member

  • Member
  • Pip
  • 8 posts
Hi, I am hit with this problem, currently when I click on IE this is in the address bar bestsearchforever.biz/,
It also now tells me Internet Explorer cannot display the webpage and has the standard click here thing.
Well I have also went into internet options and changed to say google, but when I reopen page its back to this screen.
I am attaching my file of the OTL

OTL logfile created on: 1/5/2013 11:36:25 PM - Run 6
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Auser\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.96 Gb Total Physical Memory | 0.78 Gb Available Physical Memory | 39.56% Memory free
3.81 Gb Paging File | 2.87 Gb Available in Paging File | 75.30% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 214.10 Gb Free Space | 91.93% Space Free | Partition Type: NTFS

Computer Name: CHOICENODE | User Name: Auser | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Auser\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\dkabcoms.exe ( )
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SavUI.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\DWHWizrd.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\RTDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\WlanCU.exe ()
PRC - C:\Program Files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\SiSWLSvc.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Adobe\Reader 8.0\Reader\ccme_base.dll ()
MOD - C:\Program Files\Adobe\Reader 8.0\Reader\cryptocme2.dll ()
MOD - C:\Program Files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\WlanDll.dll ()
MOD - C:\Program Files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\WlanCU.exe ()
MOD - C:\Program Files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\SiSWLSvc.exe ()


========== Services (SafeList) ==========

SRV - (HidServ) -- %SystemRoot%\System32\hidserv.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (Norton PC Checkup Application Launcher) -- C:\Program Files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (SmcService) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (dkab_device) -- C:\WINDOWS\system32\dkabcoms.exe ( )
SRV - (Symantec AntiVirus) -- C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SNAC) -- C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (SiSWLSvc) -- C:\Program Files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\SiSWLSvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (cerc6) -- File not found
DRV - (5016) -- C:\DOCUME~1\Auser\LOCALS~1\Temp\5016.sys File not found
DRV - (NAVEX15) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20130105.017\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20130105.017\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SRTSPL) -- C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSPX) -- C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SPBBCDrv) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (CmtlPort) -- C:\WINDOWS\system32\drivers\rp2cport.sys (Comtrol Corporation)
DRV - (IntcAzAudAddService) -- C:\WINDOWS\system32\drivers\RtDHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RcktPort) -- C:\WINDOWS\system32\drivers\rp2.sys (Comtrol Corporation)
DRV - (SYMTDI) -- C:\WINDOWS\system32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMREDRV) -- C:\WINDOWS\system32\drivers\symredrv.sys (Symantec Corporation)
DRV - (k57w2k) -- C:\WINDOWS\system32\drivers\k57xp32.sys (Broadcom Corporation)
DRV - (Blfp) -- C:\WINDOWS\system32\drivers\baspxp32.sys (Broadcom Corporation)
DRV - (SIS163u) -- C:\WINDOWS\system32\drivers\sis163u.sys (SiS Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?...=OIE8HP&PC=UP50
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Value error.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Value error.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?...=OIE8HP&PC=UP50
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?...=OIE8HP&PC=UP50
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://bestsearchforever.biz/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://bestsearchforever.biz/"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..network.proxy.type: 0

FF - user.js..browser.startup.homepage: "http://bestsearchforever.biz/"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/DownloadManager,version=1.1: C:\WINDOWS\ [2013/01/04 23:43:43 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)


[2012/11/29 23:18:55 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Auser\Application Data\Mozilla\Extensions
[2012/12/23 02:26:58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Auser\Application Data\Mozilla\Firefox\Profiles\kqo41fxs.default\extensions

O1 HOSTS File: ([2012/07/24 20:34:22 | 000,000,761 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [Nuadipetop] C:\Documents and Settings\Auser\Application Data\Maerpa\yfun.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless Configuration Utility HW.32.lnk = C:\WINDOWS\Installer\{BDC88E5A-F47B-4314-AB38-994592E32C95}\NewShortcut1.exe (InstallShield Software Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: choiceadvantage.com ([] in My Computer)
O15 - HKCU\..Trusted Domains: choiceadvantage.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: choiceadvantage.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: choicecentral.com ([support] http in Trusted sites)
O15 - HKCU\..Trusted Domains: chotel.com ([] in My Computer)
O15 - HKCU\..Trusted Domains: remove.me ([] in My Computer)
O16 - DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} http://download.micr...loadManager.cab (Microsoft Download Manager ActiveX control)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} http://www.cvsphoto....veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logme...trl.cab?lmi=972 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{352F1033-F0A0-485B-9963-5617FCFCF3C8}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/23 13:04:02 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/01/04 23:48:31 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Auser\Recent
[2013/01/04 23:48:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Auser\Local Settings\Application Data\Deployment
[2013/01/03 16:18:40 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2013/01/03 16:18:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Auser\Local Settings\Application Data\Google
[2013/01/02 19:05:28 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Auser\Desktop\OTL.exe
[2012/12/26 22:00:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2012/12/23 02:44:05 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/12/23 02:31:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2012/12/23 02:21:30 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2012/12/20 21:33:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Auser\Application Data\Ukiros
[2012/12/20 21:33:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Auser\Application Data\Maerpa
[2012/12/20 21:33:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Auser\Application Data\Imfas
[2012/12/19 14:46:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Auser\My Documents\Housekeeping Schedules
[2012/12/19 14:45:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Auser\My Documents\STEVES PAPERWORK
[2012/12/09 01:07:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Auser\Local Settings\Application Data\GetBooks
[2012/12/09 01:06:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Auser\Local Settings\Application Data\WideSearch
[2012/12/09 01:02:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Auser\Local Settings\Application Data\Temp
[2012/12/08 12:14:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Auser\Local Settings\Application Data\PhotoChannel
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/01/05 23:26:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/01/04 23:51:01 | 000,002,657 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless Configuration Utility HW.32.lnk
[2013/01/04 23:50:22 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/01/04 23:49:36 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/01/02 19:05:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Auser\Desktop\OTL.exe
[2013/01/02 18:59:06 | 000,000,392 | ---- | M] () -- C:\WINDOWS\tasks\PC Checkup 3 Weekly Scan.job
[2012/12/29 17:45:59 | 000,002,953 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\dsgsdgdsgdsgw.js
[2012/12/28 15:25:59 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Auser\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2012/12/26 22:33:24 | 000,001,919 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012/12/26 21:54:58 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/12/25 16:28:07 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\Auser\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/12/14 00:10:15 | 000,475,466 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/12/14 00:10:15 | 000,076,374 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/12/13 03:20:00 | 000,337,848 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/12/29 17:45:59 | 000,002,953 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\dsgsdgdsgdsgw.js
[2012/12/26 22:33:24 | 000,001,919 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012/11/16 03:28:48 | 001,488,022 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1417001333-1935655697-2147097355-1003-0.dat
[2012/11/10 04:48:50 | 000,299,638 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/09/15 03:46:51 | 000,002,656 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate
[2012/09/05 09:48:38 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012/09/03 04:38:15 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Auser\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/27 08:49:56 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\swunilog.ini
[2012/07/24 00:40:26 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/05/15 20:05:44 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/05/15 19:02:38 | 000,495,616 | R--- | C] () -- C:\WINDOWS\System32\softcoin.dll
[2012/05/15 19:02:37 | 000,356,352 | R--- | C] () -- C:\WINDOWS\System32\gencoin.dll
[2012/05/15 17:57:04 | 000,372,736 | ---- | C] ( ) -- C:\WINDOWS\System32\lexlog.dll
[2012/05/15 17:54:11 | 000,643,072 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabpmui.dll
[2012/05/15 17:54:10 | 001,044,480 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabserv.dll
[2012/05/15 17:54:10 | 000,847,872 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabusb1.dll
[2012/05/15 17:54:10 | 000,479,232 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabpar1.dll
[2012/05/15 17:54:10 | 000,344,064 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabiesc.dll
[2012/05/15 17:54:09 | 000,909,312 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabip1.dll
[2012/05/15 17:54:09 | 000,569,344 | ---- | C] ( ) -- C:\WINDOWS\System32\dkablmpm.dll
[2012/05/15 17:54:09 | 000,450,560 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabiobj.dll
[2012/05/15 17:54:09 | 000,368,640 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabinpa.dll
[2012/05/15 17:54:08 | 000,802,816 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabcomc.dll
[2012/05/15 17:54:08 | 000,603,456 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabcoms.exe
[2012/05/15 17:54:08 | 000,372,736 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabcomm.dll
[2012/05/15 17:54:08 | 000,356,352 | ---- | C] ( ) -- C:\WINDOWS\System32\dkabhcp.dll
[2012/04/11 15:59:30 | 000,008,592 | ---- | C] () -- C:\WINDOWS\System32\ractrlkeyhook.dll

========== ZeroAccess Check ==========

[2012/12/29 03:00:14 | 000,002,048 | -HS- | M] () -- C:\RECYCLER\S-1-5-18\$49ba4cc03380111052d4fee1910fe109\@
[2012/10/13 01:08:30 | 000,000,000 | -HSD | M] -- C:\RECYCLER\S-1-5-18\$49ba4cc03380111052d4fee1910fe109\L
[2012/12/29 18:47:14 | 000,000,000 | -HSD | M] -- C:\RECYCLER\S-1-5-18\$49ba4cc03380111052d4fee1910fe109\U
[2010/02/23 14:25:30 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
"ThreadingModel" = Apartment
"" = %SystemRoot%\system32\SHELL32.dll -- [2012/06/08 09:26:20 | 008,462,848 | ---- | M] (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 02:00:00 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %SystemRoot%\system32\wbem\fastprox.dll -- [2009/02/09 07:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/14 02:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

========== LOP Check ==========

[2012/12/13 22:42:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CA-SupportBridge
[2012/07/26 20:07:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HitmanPro
[2012/07/26 21:57:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2012/11/16 00:57:56 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{BE42545F-033F-4590-A2DB-7AE2913B86B8}
[2012/12/05 07:45:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Auser\Application Data\Catalina Marketing Corp
[2013/01/05 23:38:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Auser\Application Data\Imfas
[2012/12/20 21:33:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Auser\Application Data\Maerpa
[2012/11/30 01:09:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Auser\Application Data\OpenOffice.org
[2012/05/31 23:04:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Auser\Application Data\Oracle
[2012/11/04 17:54:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Auser\Application Data\PCCUStubInstaller
[2012/12/20 21:33:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Auser\Application Data\Ukiros

========== Purity Check ==========



========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB5174$] -> Error: Cannot create file handle -> Unknown point type

< End of report >

Edited by marknc392, 05 January 2013 - 11:27 PM.

  • 0

Advertisements


#2
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Greetings and Welcome to The Forums!!

My name is Gringo and I'll be glad to help you with your malware problems.

I have put together somethings for you to keep in mind while I am helping you to make things go easier and faster for both of us

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the Watch Topic Button, select Immediate Notification, and click on Proceed. This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.




These are the programs I would like you to run next, if you have any problems with these just skip it and run the next one.

-Security Check-

  • Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

-AdwCleaner-

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

--RogueKiller--

  • Download & SAVE to your Desktop RogueKiller or from here
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select "Run as Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • click on "delete"
  • Wait until the Status box shows "Deleting Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Exit/Close RogueKiller+

Gringo
  • 0

#3
marknc392

marknc392

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Results of screen317's Security Check version 0.99.56
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Please wait while WMIC compiles updated MOF files.
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
JavaFX 2.1.0
Java 7 Update 9
Adobe Flash Player 11.5.502.135
Adobe Reader 8 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 24% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````


# AdwCleaner v2.104 - Logfile created 01/06/2013 at 02:37:16
# Updated 29/12/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Auser - CHOICENODE
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Auser\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v [Unable to get version]

File : C:\Documents and Settings\Auser\Application Data\Mozilla\Firefox\Profiles\kqo41fxs.default\prefs.js

C:\Documents and Settings\Auser\Application Data\Mozilla\Firefox\Profiles\kqo41fxs.default\user.js ... Deleted !

[OK] File is clean.

File : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\tffs1zfu.default\prefs.js

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [5568 octets] - [02/01/2013 00:56:19]
AdwCleaner[S1].txt - [5860 octets] - [02/01/2013 00:57:02]
AdwCleaner[S2].txt - [1091 octets] - [06/01/2013 02:37:16]

########## EOF - C:\AdwCleaner[S2].txt - [1151 octets] ##########


RogueKiller V8.4.2 [Dec 31 2012] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo...13-roguekiller/
Website : http://tigzy.geeksto...roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Auser [Admin rights]
Mode : Scan -- Date : 01/06/2013 02:40:28

¤¤¤ Bad processes : 1 ¤¤¤
[SUSP PATH] RTDCPL.EXE -- C:\WINDOWS\RTDCPL.EXE -> KILLED [TermProc]

¤¤¤ Registry Entries : 7 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : Nuadipetop ("C:\Documents and Settings\Auser\Application Data\Maerpa\yfun.exe") -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-1417001333-1935655697-2147097355-1003[...]\Run : Nuadipetop ("C:\Documents and Settings\Auser\Application Data\Maerpa\yfun.exe") -> FOUND
[Services][ROGUE ST] HKLM\[...]\ControlSet001\Services\5016 (C:\DOCUME~1\Auser\LOCALS~1\Temp\5016.sys) -> FOUND
[Services][ROGUE ST] HKLM\[...]\ControlSet002\Services\5016 (C:\DOCUME~1\Auser\LOCALS~1\Temp\5016.sys) -> FOUND
[PROXY IE] HKCU\[...]\Internet Settings : ProxyEnable (1) -> FOUND
[HJPOL] HKCU\[...]\System : disableregistrytools (0) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤
[ZeroAccess][FILE] @ : C:\RECYCLER\S-1-5-18\$49ba4cc03380111052d4fee1910fe109\@ --> FOUND
[ZeroAccess][FILE] @ : C:\RECYCLER\S-1-5-21-1417001333-1935655697-2147097355-1003\$49ba4cc03380111052d4fee1910fe109\@ --> FOUND
[ZeroAccess][FOLDER] U : C:\RECYCLER\S-1-5-18\$49ba4cc03380111052d4fee1910fe109\U --> FOUND
[ZeroAccess][FOLDER] U : C:\RECYCLER\S-1-5-21-1417001333-1935655697-2147097355-1003\$49ba4cc03380111052d4fee1910fe109\U --> FOUND
[ZeroAccess][FOLDER] L : C:\RECYCLER\S-1-5-18\$49ba4cc03380111052d4fee1910fe109\L --> FOUND
[ZeroAccess][FOLDER] L : C:\RECYCLER\S-1-5-21-1417001333-1935655697-2147097355-1003\$49ba4cc03380111052d4fee1910fe109\L --> FOUND

¤¤¤ Driver : [LOADED] ¤¤¤
SSDT[12] : NtAlertResumeThread @ 0x805D4BDC -> HOOKED (Unknown @ 0x89434F00)
SSDT[13] : NtAlertThread @ 0x805D4B8C -> HOOKED (Unknown @ 0x894442B0)
SSDT[17] : NtAllocateVirtualMemory @ 0x805A8AC2 -> HOOKED (Unknown @ 0x894747D0)
SSDT[31] : NtConnectPort @ 0x805A45D8 -> HOOKED (Unknown @ 0x8951FF18)
SSDT[43] : NtCreateMutant @ 0x806176AE -> HOOKED (Unknown @ 0x89468BB0)
SSDT[53] : unknown @ 0x805D1038 -> HOOKED (Unknown @ 0x894452A8)
SSDT[83] : NtFreeVirtualMemory @ 0x805B2FBA -> HOOKED (Unknown @ 0x89436418)
SSDT[89] : NtImpersonateAnonymousToken @ 0x805F9258 -> HOOKED (Unknown @ 0x89435B18)
SSDT[91] : NtImpersonateThread @ 0x805D7860 -> HOOKED (Unknown @ 0x894744D8)
SSDT[108] : NtMapViewOfSection @ 0x805B2042 -> HOOKED (Unknown @ 0x894333D0)
SSDT[114] : NtOpenEvent @ 0x8060F06C -> HOOKED (Unknown @ 0x89468AF0)
SSDT[123] : NtOpenProcessToken @ 0x805EDF26 -> HOOKED (Unknown @ 0x89436288)
SSDT[129] : NtOpenThreadToken @ 0x805EDF44 -> HOOKED (Unknown @ 0x89464F38)
SSDT[206] : NtResumeThread @ 0x805D4A18 -> HOOKED (Unknown @ 0x894688C8)
SSDT[213] : NtSetContextThread @ 0x805D2C1A -> HOOKED (Unknown @ 0x89468960)
SSDT[228] : NtSetInformationProcess @ 0x805CDEA0 -> HOOKED (Unknown @ 0x89434F38)
SSDT[229] : NtSetInformationThread @ 0x805CC124 -> HOOKED (Unknown @ 0x8948F008)
SSDT[253] : NtSuspendProcess @ 0x805D4AE0 -> HOOKED (Unknown @ 0x89468A30)
SSDT[254] : NtSuspendThread @ 0x805D4952 -> HOOKED (Unknown @ 0x89433890)
SSDT[257] : NtTerminateProcess @ 0x805D22D8 -> HOOKED (Unknown @ 0x89433480)
SSDT[258] : NtTerminateThread @ 0x805D24D2 -> HOOKED (Unknown @ 0x894FD718)
SSDT[267] : NtUnmapViewOfSection @ 0x805B2E50 -> HOOKED (Unknown @ 0x89433250)
SSDT[277] : NtWriteVirtualMemory @ 0x805B43D4 -> HOOKED (Unknown @ 0x894353F8)

¤¤¤ Infection : ZeroAccess ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost
::1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 23a62181bed6b986c17e57fe9ddd4f86
[BSP] 6214f78725f0569ea78e8b570fe2aa5d : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 238472 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[1]_S_01062013_02d0240.txt >>
RKreport[1]_S_01062013_02d0240.txt



RogueKiller V8.4.2 [Dec 31 2012] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo...13-roguekiller/
Website : http://tigzy.geeksto...roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Auser [Admin rights]
Mode : Remove -- Date : 01/06/2013 02:41:26

¤¤¤ Bad processes : 1 ¤¤¤
[SUSP PATH] RTDCPL.EXE -- C:\WINDOWS\RTDCPL.EXE -> KILLED [TermProc]

¤¤¤ Registry Entries : 6 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : Nuadipetop ("C:\Documents and Settings\Auser\Application Data\Maerpa\yfun.exe") -> DELETED
[Services][ROGUE ST] HKLM\[...]\ControlSet001\Services\5016 (C:\DOCUME~1\Auser\LOCALS~1\Temp\5016.sys) -> DELETED
[Services][ROGUE ST] HKLM\[...]\ControlSet002\Services\5016 (C:\DOCUME~1\Auser\LOCALS~1\Temp\5016.sys) -> DELETED
[PROXY IE] HKCU\[...]\Internet Settings : ProxyEnable (1) -> NOT REMOVED, USE PROXYFIX
[HJPOL] HKCU\[...]\System : disableregistrytools (0) -> DELETED
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤
[ZeroAccess][FILE] @ : C:\RECYCLER\S-1-5-18\$49ba4cc03380111052d4fee1910fe109\@ --> REMOVED
[ZeroAccess][FILE] @ : C:\RECYCLER\S-1-5-21-1417001333-1935655697-2147097355-1003\$49ba4cc03380111052d4fee1910fe109\@ --> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\RECYCLER\S-1-5-18\$49ba4cc03380111052d4fee1910fe109\U --> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\RECYCLER\S-1-5-21-1417001333-1935655697-2147097355-1003\$49ba4cc03380111052d4fee1910fe109\U --> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\RECYCLER\S-1-5-18\$49ba4cc03380111052d4fee1910fe109\L --> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\RECYCLER\S-1-5-21-1417001333-1935655697-2147097355-1003\$49ba4cc03380111052d4fee1910fe109\L --> REMOVED

¤¤¤ Driver : [LOADED] ¤¤¤
SSDT[12] : NtAlertResumeThread @ 0x805D4BDC -> HOOKED (Unknown @ 0x89434F00)
SSDT[13] : NtAlertThread @ 0x805D4B8C -> HOOKED (Unknown @ 0x894442B0)
SSDT[17] : NtAllocateVirtualMemory @ 0x805A8AC2 -> HOOKED (Unknown @ 0x894747D0)
SSDT[31] : NtConnectPort @ 0x805A45D8 -> HOOKED (Unknown @ 0x8951FF18)
SSDT[43] : NtCreateMutant @ 0x806176AE -> HOOKED (Unknown @ 0x89468BB0)
SSDT[53] : unknown @ 0x805D1038 -> HOOKED (Unknown @ 0x894452A8)
SSDT[83] : NtFreeVirtualMemory @ 0x805B2FBA -> HOOKED (Unknown @ 0x89436418)
SSDT[89] : NtImpersonateAnonymousToken @ 0x805F9258 -> HOOKED (Unknown @ 0x89435B18)
SSDT[91] : NtImpersonateThread @ 0x805D7860 -> HOOKED (Unknown @ 0x894744D8)
SSDT[108] : NtMapViewOfSection @ 0x805B2042 -> HOOKED (Unknown @ 0x894333D0)
SSDT[114] : NtOpenEvent @ 0x8060F06C -> HOOKED (Unknown @ 0x89468AF0)
SSDT[123] : NtOpenProcessToken @ 0x805EDF26 -> HOOKED (Unknown @ 0x89436288)
SSDT[129] : NtOpenThreadToken @ 0x805EDF44 -> HOOKED (Unknown @ 0x89464F38)
SSDT[206] : NtResumeThread @ 0x805D4A18 -> HOOKED (Unknown @ 0x894688C8)
SSDT[213] : NtSetContextThread @ 0x805D2C1A -> HOOKED (Unknown @ 0x89468960)
SSDT[228] : NtSetInformationProcess @ 0x805CDEA0 -> HOOKED (Unknown @ 0x89434F38)
SSDT[229] : NtSetInformationThread @ 0x805CC124 -> HOOKED (Unknown @ 0x8948F008)
SSDT[253] : NtSuspendProcess @ 0x805D4AE0 -> HOOKED (Unknown @ 0x89468A30)
SSDT[254] : NtSuspendThread @ 0x805D4952 -> HOOKED (Unknown @ 0x89433890)
SSDT[257] : NtTerminateProcess @ 0x805D22D8 -> HOOKED (Unknown @ 0x89433480)
SSDT[258] : NtTerminateThread @ 0x805D24D2 -> HOOKED (Unknown @ 0x894FD718)
SSDT[267] : NtUnmapViewOfSection @ 0x805B2E50 -> HOOKED (Unknown @ 0x89433250)
SSDT[277] : NtWriteVirtualMemory @ 0x805B43D4 -> HOOKED (Unknown @ 0x894353F8)

¤¤¤ Infection : ZeroAccess ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost
::1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 23a62181bed6b986c17e57fe9ddd4f86
[BSP] 6214f78725f0569ea78e8b570fe2aa5d : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 238472 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[2]_D_01062013_02d0241.txt >>
RKreport[1]_S_01062013_02d0240.txt ; RKreport[2]_D_01062013_02d0241.txt
  • 0

#4
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello

I Would like you to do the following.

Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
  • 0

#5
marknc392

marknc392

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
seemed like it didn't wanna work tried it a couple times then boom started working, after all was said and done the system seems better.

ComboFix 13-01-05.01 - Auser 01/06/2013 4:48.1.2 - x86
Running from: c:\documents and settings\Auser\Desktop\ComboFi.exe
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Auser\Application Data\Maerpa
c:\documents and settings\Auser\Application Data\Maerpa\yfun.exe
c:\documents and settings\Auser\Local Settings\Application Data\WideSearch
c:\program files\Vid-Saver
c:\program files\Vid-Saver\ButtonUtil.dll
c:\program files\Vid-Saver\Vid-Saver-bg.exe
c:\program files\Vid-Saver\Vid-Saver.exe
c:\windows\$NtUninstallKB5174$
c:\windows\$NtUninstallKB5174$\2162737900
c:\windows\$NtUninstallKB5174$\2964694147\@
c:\windows\$NtUninstallKB5174$\2964694147\Desktop.ini
c:\windows\$NtUninstallKB5174$\2964694147\L\00000004.@
c:\windows\$NtUninstallKB5174$\2964694147\L\201d3dde
c:\windows\$NtUninstallKB5174$\2964694147\L\76603ac3
c:\windows\$NtUninstallKB5174$\2964694147\L\nekiyaty
c:\windows\$NtUninstallKB5174$\2964694147\U\00000004.@
c:\windows\$NtUninstallKB5174$\2964694147\U\00000008.@
c:\windows\$NtUninstallKB5174$\2964694147\U\000000cb.@
c:\windows\$NtUninstallKB5174$\2964694147\U\80000000.@
c:\windows\$NtUninstallKB5174$\2964694147\U\80000032.@
.
.
((((((((((((((((((((((((( Files Created from 2012-12-06 to 2013-01-06 )))))))))))))))))))))))))))))))
.
.
2013-01-06 06:57 . 2013-01-06 06:57 -------- d--h--w- c:\windows\system32\GroupPolicy
2013-01-05 04:48 . 2013-01-05 04:48 -------- d-----w- c:\documents and settings\Auser\Local Settings\Application Data\Deployment
2013-01-03 21:18 . 2013-01-05 09:49 -------- d-----w- c:\program files\Google
2013-01-03 21:18 . 2013-01-05 09:49 -------- d-----w- c:\documents and settings\Auser\Local Settings\Application Data\Google
2012-12-29 22:45 . 2012-12-29 22:45 2953 ----a-w- c:\documents and settings\All Users\Application Data\dsgsdgdsgdsgw.js
2012-12-27 13:11 . 2012-12-27 13:11 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-12-27 03:00 . 2013-01-05 04:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2012-12-23 07:44 . 2012-12-23 07:44 -------- d-----w- C:\TDSSKiller_Quarantine
2012-12-23 07:33 . 2012-12-27 03:33 -------- d-----w- c:\documents and settings\Administrator
2012-12-23 07:31 . 2012-12-23 07:31 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-12-21 02:33 . 2013-01-06 09:31 -------- d-----w- c:\documents and settings\Auser\Application Data\Imfas
2012-12-21 02:33 . 2012-12-21 02:33 -------- d-----w- c:\documents and settings\Auser\Application Data\Ukiros
2012-12-09 06:07 . 2012-12-14 05:04 -------- d-----w- c:\documents and settings\Auser\Local Settings\Application Data\GetBooks
2012-12-09 06:02 . 2012-12-09 06:02 -------- d-----w- c:\documents and settings\Auser\Local Settings\Application Data\Temp
2012-12-08 17:14 . 2012-12-09 18:37 -------- d-----w- c:\documents and settings\Auser\Local Settings\Application Data\PhotoChannel
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-23 07:45 . 2008-04-14 07:00 75264 ----a-w- c:\windows\system32\drivers\ipsec.sys
2012-12-12 03:26 . 2012-05-17 02:56 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-12 03:26 . 2012-05-17 02:56 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-11-13 01:25 . 2008-04-14 07:00 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-11-06 00:41 . 2008-04-14 07:00 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-11-02 02:02 . 2008-04-14 07:00 375296 ----a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:17 . 2008-04-14 07:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-11-01 12:17 . 2008-04-14 07:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-11-01 12:17 . 2008-04-14 07:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-11-01 00:35 . 2008-04-14 07:00 385024 ------w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-07-28 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-07-28 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-07-28 142872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2010-05-07 115560]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"RTHDCPL"="RTDCPL.EXE" [2009-08-26 2691072]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Wireless Configuration Utility HW.32.lnk - c:\windows\Installer\{BDC88E5A-F47B-4314-AB38-994592E32C95}\NewShortcut1.exe [2012-8-27 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 12:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 cerc6;cerc6; [x]
R3 CmtlPort;Comtrol Serial Port;c:\windows\system32\DRIVERS\rp2cport.sys [x]
R3 RcktPort;Comtrol RocketPort Infinity;c:\windows\system32\DRIVERS\rp2.sys [x]
R3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [x]
S2 dkab_device;dkab_device;c:\windows\system32\DKabcoms.exe [x]
S2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
S3 k57w2k;Broadcom NetLink ™ Gigabit Ethernet;c:\windows\system32\DRIVERS\k57xp32.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-17 03:26]
.
2013-01-02 c:\windows\Tasks\PC Checkup 3 Weekly Scan.job
- c:\program files\Norton PC Checkup 3.0\NLAppLauncher.exe [2012-11-04 20:14]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://bestsearchforever.biz/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
Trusted Zone: choiceadvantage.com\www
Trusted Zone: choicecentral.com\support
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKCU-Run-Nuadipetop - c:\documents and settings\Auser\Application Data\Maerpa\yfun.exe
SafeBoot-98016750.sys
SafeBoot-Wdf01000.sys
SafeBoot-Symantec Antvirus
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-06 05:02
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(3716)
c:\windows\system32\WININET.dll
c:\windows\system32\igfxdo.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
c:\program files\Symantec\Symantec Endpoint Protection\SescLU.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\windows\system32\WgaTray.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\SiSWLSvc.exe
c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTDCPL.EXE
c:\program files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\WlanCU.exe
c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
c:\program files\Symantec\Symantec Endpoint Protection\DoScan.exe
.
**************************************************************************
.
Completion time: 2013-01-06 05:03:30 - machine was rebooted
ComboFix-quarantined-files.txt 2013-01-06 10:03
.
Pre-Run: 229,756,076,032 bytes free
Post-Run: 232,295,534,592 bytes free
.
- - End Of File - - C1FBE7D748ADCD9EA3F478C7838B4229
  • 0

#6
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Greetings

At this time I would like you to run this script for me and it is a good time to check out the computer to see if there is anything else that needs to be addressed.

:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

ClearJavaCache::

Folder::
c:\documents and settings\Auser\Application Data\Imfas
c:\documents and settings\Auser\Application Data\Ukiros

Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
Posted Image
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following

  • report from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now after running the script?

Gringo

  • 0

#7
marknc392

marknc392

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
seems a ok, and thanks for that

ComboFix 13-01-05.01 - Auser 01/06/2013 5:29.2.2 - x86
Running from: c:\documents and settings\Auser\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Auser\Desktop\CFScript.txt
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Auser\Application Data\Imfas
c:\documents and settings\Auser\Application Data\Imfas\sawa.dat
c:\documents and settings\Auser\Application Data\Ukiros
c:\documents and settings\Auser\Application Data\Ukiros\ehfu.asi
.
.
((((((((((((((((((((((((( Files Created from 2012-12-06 to 2013-01-06 )))))))))))))))))))))))))))))))
.
.
2013-01-06 06:57 . 2013-01-06 06:57 -------- d--h--w- c:\windows\system32\GroupPolicy
2013-01-05 04:48 . 2013-01-05 04:48 -------- d-----w- c:\documents and settings\Auser\Local Settings\Application Data\Deployment
2013-01-03 21:18 . 2013-01-05 09:49 -------- d-----w- c:\program files\Google
2013-01-03 21:18 . 2013-01-05 09:49 -------- d-----w- c:\documents and settings\Auser\Local Settings\Application Data\Google
2012-12-29 22:45 . 2012-12-29 22:45 2953 ----a-w- c:\documents and settings\All Users\Application Data\dsgsdgdsgdsgw.js
2012-12-27 13:11 . 2012-12-27 13:11 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-12-27 03:00 . 2013-01-05 04:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2012-12-23 07:33 . 2012-12-27 03:33 -------- d-----w- c:\documents and settings\Administrator
2012-12-23 07:31 . 2012-12-23 07:31 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-12-09 06:07 . 2012-12-14 05:04 -------- d-----w- c:\documents and settings\Auser\Local Settings\Application Data\GetBooks
2012-12-09 06:02 . 2012-12-09 06:02 -------- d-----w- c:\documents and settings\Auser\Local Settings\Application Data\Temp
2012-12-08 17:14 . 2012-12-09 18:37 -------- d-----w- c:\documents and settings\Auser\Local Settings\Application Data\PhotoChannel
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-23 07:45 . 2008-04-14 07:00 75264 ----a-w- c:\windows\system32\drivers\ipsec.sys
2012-12-12 03:26 . 2012-05-17 02:56 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-12 03:26 . 2012-05-17 02:56 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-11-13 01:25 . 2008-04-14 07:00 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-11-06 00:41 . 2008-04-14 07:00 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-11-02 02:02 . 2008-04-14 07:00 375296 ----a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:17 . 2008-04-14 07:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-11-01 12:17 . 2008-04-14 07:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-11-01 12:17 . 2008-04-14 07:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-11-01 00:35 . 2008-04-14 07:00 385024 ------w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-07-28 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-07-28 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-07-28 142872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2010-05-07 115560]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"RTHDCPL"="RTDCPL.EXE" [2009-08-26 2691072]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Wireless Configuration Utility HW.32.lnk - c:\windows\Installer\{BDC88E5A-F47B-4314-AB38-994592E32C95}\NewShortcut1.exe [2012-8-27 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 12:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 cerc6;cerc6; [x]
R3 CmtlPort;Comtrol Serial Port;c:\windows\system32\DRIVERS\rp2cport.sys [x]
R3 RcktPort;Comtrol RocketPort Infinity;c:\windows\system32\DRIVERS\rp2.sys [x]
R3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [x]
S2 dkab_device;dkab_device;c:\windows\system32\DKabcoms.exe [x]
S2 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
S3 k57w2k;Broadcom NetLink ™ Gigabit Ethernet;c:\windows\system32\DRIVERS\k57xp32.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-17 03:26]
.
2013-01-02 c:\windows\Tasks\PC Checkup 3 Weekly Scan.job
- c:\program files\Norton PC Checkup 3.0\NLAppLauncher.exe [2012-11-04 20:14]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
Trusted Zone: choiceadvantage.com\www
Trusted Zone: choicecentral.com\support
TCP: DhcpNameServer = 192.168.1.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-06 05:32
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-01-06 05:33:06
ComboFix-quarantined-files.txt 2013-01-06 10:33
ComboFix2.txt 2013-01-06 10:03
.
Pre-Run: 232,210,640,896 bytes free
Post-Run: 232,328,175,616 bytes free
.
- - End Of File - - FBE933B1B41FE0A88FED49F3B14FFF0F
  • 0

#8
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello marknc392

I would like to see a report that combofix makes.

extra combofix report

  • push the "windows key" + "R" (between the "Ctrl" button and "Alt" Button)
  • please copy and past the following into the box
C:\Qoobox\Add-Remove Programs.txt
  • click ok

copy and paste the report into this topic for me to review

Gringo
  • 0

#9
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello

48 Hour bump

It has been more than 48 hours since my last post.

  • do you still need help with this?
  • do you need more time?
  • are you having problems following my instructions?
  • if after 48hrs you have not replied to this thread then it will have to be closed!

Gringo
  • 0

#10
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP