Unsolved

This post is more than 5 years old

23 Posts

5219

October 2nd, 2009 15:00

Antivirus Pro 2010 and Windows Police Pro

I have a Lenovo S10 Netbook running Windows XP SP3. 

It has been taken over by Antivirus Pro 2010 and Windows Police Pro pop-ups.

I had to boot in Safe Mode in order to run the Hijackthis program.  The malware blocked the running of the program in regular mode.

Here is my Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:28:20 PM, on 10/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Cnd\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://aimzones.aol.com/homepage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://lenovo.live.com/
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{03402f96-3dc7-4285-bc50-9e81fefafe43} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: ICQSys (IE PlugIn) - {77DC0B63-1535-4ba9-8BE8-D59EB676FA02} - C:\WINDOWS\system32\plugie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IdeaNotesUser] C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Antivirus Pro 2010] "C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe" /hide
O4 - HKLM\..\Run: [7606509191] C:\Documents and Settings\Cnd\Application Data\7606509191\7606509191.exe
O4 - HKLM\..\Run: [yakajeyij] Rundll32.exe "c:\windows\system32\vonibusa.dll",a
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [mserv] C:\Documents and Settings\Cnd\Application Data\svcst.exe
O4 - HKCU\..\Run: [svchost] C:\Documents and Settings\Cnd\Application Data\svcst.exe
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: LENOVO - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.lenovo.com (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk/6u13-b03/jinstall-6u13-windows-i586-jc.cab?e=1241247500030&h=2833b30abb1974eb4cdadb10158b4033/&filename=jinstall-6u13-windows-i586-jc.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: c:\windows\system32\vonibusa.dll,wafiguvu.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: PicNotify - C:\WINDOWS\SYSTEM32\PicNotify.dll
O21 - SSODL: tahinoteb - {f40e7dde-ffd3-425c-b021-391951381521} - c:\windows\system32\vonibusa.dll
O22 - SharedTaskScheduler: tokatiluy - {f40e7dde-ffd3-425c-b021-391951381521} - c:\windows\system32\vonibusa.dll
O23 - Service: AntiPol - Unknown owner - C:\WINDOWS\svchast.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DDNIMSGService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe
O23 - Service: DDNIService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\DIBS\DDNIService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 7706 bytes

Any help you can provide will be greatly appreciated.

10.4K Posts

October 8th, 2009 08:00


jecameron

Please download Combofix and save to your desktop:
  • Note: It is important that it is saved directly to your desktop
    Close any open browsers.
    Double click on combofix.exe and follow the prompts.
    When it's finished it will produce a log.
    Post the contents of the C:\ComboFix.txt into your next reply.
    Note: Do not mouseclick combofix's window whilst it's running.
    That may cause the program to freeze/hang.



23 Posts

October 8th, 2009 11:00

Here are the Combofix results:

 

ComboFix 09-10-07.05 - Cnd 10/08/2009  9:29.1.2 - FAT32x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1014.683 [GMT -7:00]
Running from: c:\documents and settings\Cnd\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

Overlay aborted ... Please run ComboFix once more
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\izycug.sys
c:\documents and settings\All Users\Application Data\lori._sy
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Documents\gehipuxeqa.reg
c:\documents and settings\All Users\Documents\niqylinido.scr
c:\documents and settings\All Users\Documents\xiwas.dll
c:\documents and settings\Cnd\Application Data\awiqedis.sys
c:\documents and settings\Cnd\Application Data\cepysu.inf
c:\documents and settings\Cnd\Application Data\cetaruton.inf
c:\documents and settings\Cnd\Application Data\evum.dl
c:\documents and settings\Cnd\Application Data\iniasd.txt
c:\documents and settings\Cnd\Application Data\lizkavd.exe
c:\documents and settings\Cnd\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Cnd\Application Data\nykuqyle.inf
c:\documents and settings\Cnd\Application Data\ogolevuxut.bat
c:\documents and settings\Cnd\Application Data\seres.exe
c:\documents and settings\Cnd\Application Data\svcst.exe
c:\documents and settings\Cnd\Cookies\gavoc.bin
c:\documents and settings\Cnd\Cookies\geregowez.scr
c:\documents and settings\Cnd\Cookies\ivaviw.dll
c:\documents and settings\Cnd\Cookies\mykiq.ban
c:\documents and settings\Cnd\Cookies\ocohibuv.dll
c:\documents and settings\Cnd\Desktop\Advanced Virus Remover.lnk
c:\documents and settings\Cnd\Local Settings\Application Data\ohyqi._dl
c:\documents and settings\Cnd\Local Settings\Temporary Internet Files\edorumom.inf
c:\documents and settings\Cnd\Local Settings\Temporary Internet Files\omyko.reg
c:\documents and settings\Cnd\Local Settings\Temporary Internet Files\qidypaxot.dll
c:\documents and settings\Cnd\Start Menu\Advanced Virus Remover.lnk
c:\documents and settings\Cnd\Start Menu\Programs\AntivirusPro_2010
c:\documents and settings\Cnd\Start Menu\Programs\AntivirusPro_2010\AntivirusPro_2010.lnk
c:\documents and settings\Cnd\Start Menu\Programs\AntivirusPro_2010\Uninstall.lnk
c:\program files\AdvancedVirusRemover
c:\program files\AdvancedVirusRemover\PAVRM.exe
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg
c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe
c:\program files\Common Files\azanuwycyj.com
c:\program files\Windows Police Pro
c:\windows\abukuno.bin
c:\windows\duwax.bin
c:\windows\idugoqu.reg
c:\windows\koqologybe.sys
c:\windows\svchast.exe
c:\windows\system32\_scui.cpl
c:\windows\system32\~.exe
c:\windows\system32\18467.exe
c:\windows\system32\26500.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\bincd32.dat
c:\windows\system32\biravoja.dll
c:\windows\system32\bozoyipo.exe
c:\windows\system32\doqypa.inf
c:\windows\system32\febobafi.dll
c:\windows\system32\gawarege.dll.tmp
c:\windows\system32\gawojuso.dll
c:\windows\system32\gidobedi.dll
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\ipil.vbs
c:\windows\system32\kiduruka.dll
c:\windows\system32\losorede.dll
c:\windows\system32\mifolole.exe
c:\windows\system32\nadusajo.dll
c:\windows\system32\nivumosi.dll.tmp
c:\windows\system32\plUGie.dll
c:\windows\system32\royoneyu.dll.tmp
c:\windows\system32\wafiguvu.dll
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\winhelper.dll
c:\windows\system32\wispex.html
c:\windows\system32\yefapuza.dll
c:\windows\system32\zitakihu.exe
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat . . . . failed to delete
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat . . . . failed to delete

----- BITS: Possible infected sites -----

hxxp://dibs.ddni.net
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll

c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe

.
(((((((((((((((((((((((((   Files Created from 2009-09-08 to 2009-10-08  )))))))))))))))))))))))))))))))
.

2009-10-08 16:53 . 2008-04-14 12:42 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-08 16:31 . 2009-10-08 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\AIM Toolbar
2009-10-08 15:31 . 2009-10-08 15:31 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-10-03 07:34 . 2009-10-03 07:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\0739412875
2009-10-02 21:26 . 2009-10-08 15:53 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-02 19:11 . 2009-10-03 00:19 131731 ----a-w- c:\windows\system32\dbsinit.exe
2009-10-02 19:07 . 2009-10-03 00:44 58 ----a-w- c:\windows\wf4.dat
2009-10-02 19:07 . 2009-10-03 00:44 2 ----a-w- c:\windows\wf3.dat
2009-10-02 19:07 . 2009-10-02 19:07 36 ----a-w- c:\windows\system32\skynet.dat
2009-10-02 19:07 . 2009-10-03 00:44 545792 ----a-w- c:\windows\system32\pump.exe
2009-10-02 02:14 . 2009-10-02 02:14 -------- d-----w- c:\documents and settings\Cnd\Application Data\7606509191
2009-10-02 01:40 . 2009-10-02 01:40 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-02 01:16 . 2009-10-02 01:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-02 01:14 . 2009-10-02 01:14 -------- d-----w- C:\Lenovo
2009-10-02 01:13 . 2009-10-02 01:13 16007 ----a-w- c:\documents and settings\Cnd\Local Settings\Application Data\egiweb.dat
2009-10-02 01:13 . 2009-10-02 01:13 13892 ----a-w- c:\windows\awiv.com
2009-10-02 01:08 . 2009-10-02 01:08 45568 ----a-w- C:\hrngen.exe
2009-10-02 01:08 . 2009-10-02 01:08 196887 ----a-w- C:\prdfjhha.exe
2009-10-02 01:08 . 2009-10-02 01:08 52736 ----a-w- C:\afuqr.exe
2009-10-02 01:08 . 2009-10-02 01:08 6144 ----a-w- C:\avjelge.exe
2009-10-02 01:08 . 2009-10-02 01:08 17920 ----a-w- C:\qgferewy.exe
2009-09-09 04:32 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 22:53 . 2009-08-26 22:53 0 ----a-w- c:\windows\nsreg.dat
2009-08-26 06:28 . 2009-05-02 06:29 15912 ----a-w- c:\documents and settings\Cnd\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 06:21 . 2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-26 06:21 . 2009-08-26 06:21 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-26 06:21 . 2009-08-26 06:21 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-26 06:21 . 2009-08-26 06:21 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\program files\AVG
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-26 05:34 . 2009-08-26 05:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\AVG8
2009-08-06 00:01 . 2004-08-04 19:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-18 10:01 . 2004-08-04 19:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 17:08 . 2004-08-04 19:00 286720 ----a-w- c:\windows\system32\wmpdxm.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 18:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2009-04-15 12:39 241752 ----a-w- c:\windows\system32\IcnOvrly.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-23 1146880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"IdeaNotesUser"="c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe" [2009-08-24 221872]
"VeriFaceManager"="c:\program files\Lenovo\VeriFaceIII\PManage.exe" [2009-04-15 323584]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2008-07-09 4456448]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2008-08-28 1283984]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-02 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-08 2023704]
"7606509191"="c:\documents and settings\Cnd\Application Data\7606509191\7606509191.exe" [2009-10-02 1048100]
"0739412875"="c:\documents and settings\Cnd\Application Data\0739412875\0739412875.exe" [2009-10-03 1048611]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-02-17 17508864]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PicNotify]
2009-04-15 12:39 1167360 ----a-w- c:\windows\system32\PicNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\DDNI\\Lenovo Idea Notes\\DDNIMSGService.exe"=
"c:\\WINDOWS\\System32\\SPOOLSV.EXE"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/25/2009 11:21 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/25/2009 11:21 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/25/2009 11:20 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/25/2009 11:20 PM 297752]
R2 DDNIMSGService;DDNIMSGService;c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe [10/6/2008 11:23 AM 172720]
R2 DDNIService;DDNIService;c:\program files\DDNI\DIBS\DDNIService.exe [4/15/2009 5:30 AM 160432]
R2 System_Repair_UpdateMonitor;System Repair Windows Update Monitor;c:\program files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe [4/15/2009 5:54 AM 430080]
R2 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [4/15/2009 5:54 AM 48192]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/23/2009 9:41 PM 24652]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [4/15/2009 6:22 AM 9472]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [4/15/2009 5:20 AM 157696]
S2 AntiPol;AntiPol;c:\windows\svchast.exe --> c:\windows\svchast.exe [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [4/15/2009 5:18 AM 1684736]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [4/15/2009 5:54 AM 81192]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-10-08 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 22:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://aimzones.aol.com/homepage
uInternet Connection Wizard,ShellNext = hxxp://lenovo.live.com/
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
FF - ProfilePath - c:\documents and settings\Cnd\Application Data\Mozilla\Firefox\Profiles\jiwyidvz.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

BHO-{90c9a067-0a9a-4253-ae70-29f851f14e5e} - yefapuza.dll
HKLM-Run-yakajeyij - c:\windows\system32\gidobedi.dll
HKLM-Run-sufepomaro - gawojuso.dll
SharedTaskScheduler-{e00c5003-5afd-4041-8516-9227adc60baf} - c:\windows\system32\gidobedi.dll
SSODL-sudimimez-{e00c5003-5afd-4041-8516-9227adc60baf} - c:\windows\system32\gidobedi.dll

 

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-08 09:56
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\PicNotify.dll
c:\windows\system32\FaceVerify.dll
c:\windows\system32\MainOp.dll
c:\windows\system32\VideoOp.dll
c:\windows\system32\Image.dll
c:\windows\system32\Momo.dll
c:\windows\system32\Apblend.dll
c:\windows\system32\SetDev.dll
c:\windows\system32\FunFrm.dll
c:\windows\system32\facev.dll

- - - - - - - > 'lsass.exe'(892)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3976)
c:\windows\system32\WININET.dll
gasfkyqmowykxd.dll 10000000    32768 \\?\globalroot\systemroot\system32\gasfkyqmowykxd.dll
c:\windows\system32\IcnOvrly.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\AVGWDSVC.EXE
c:\program files\JAVA\JRE6\BIN\JQS.EXE
c:\program files\AVG\AVG8\AVGRSX.EXE
c:\program files\AVG\AVG8\AVGNSX.EXE
c:\windows\SYSTEM32\WDFMGR.EXE
c:\program files\AVG\AVG8\AVGEMC.EXE
c:\program files\AVG\AVG8\AVGCSRVX.EXE
c:\windows\SYSTEM32\IGFXSRVC.EXE
c:\program files\AVG\AVG8\AVGTRAY.EXE
c:\program files\AIM6\aolsoftware.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-10-08 10:05 - machine was rebooted
ComboFix-quarantined-files.txt  2009-10-08 17:05

Pre-Run: 92,747,137,024 bytes free
Post-Run: 94,119,329,792 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

319 --- E O F --- 2009-09-17 07:57

10.4K Posts

October 8th, 2009 12:00


jecameron

1. Open NotePad (not wordpad). Copy and paste the following into Notepad

Driver::
AntiPol

File::
c:\documents and settings\Cnd\Local Settings\Application Data\egiweb.dat
c:\windows\awiv.com
C:\hrngen.exe
C:\prdfjhha.exe
C:\afuqr.exe
C:\avjelge.exe
C:\qgferewy.exe
c:\windows\wf4.dat
c:\windows\wf3.dat
c:\windows\system32\skynet.dat
c:\windows\system32\pump.exe
c:\windows\system32\dbsinit.exe
C:\Windows\system32\gasfkyqmowykxd.dll

Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop

Using the Image as a reference, drag CFScript into ComboFix.exe

user posted image
  • You will be prompted to run Combofix again, Do so
    Following the same rules as indicated in my first post
    Then post the contents of the C:\ComboFix.txt log in your reply


23 Posts

October 8th, 2009 18:00

Here are the latest Combofix results.  BTW...thanks very much for your efforts.

 

ComboFix 09-10-07.05 - Cnd 10/08/2009 16:17.2.2 - FAT32x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1014.682 [GMT -7:00]
Running from: c:\documents and settings\Cnd\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Cnd\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"C:\afuqr.exe"
"C:\avjelge.exe"
"c:\documents and settings\Cnd\Local Settings\Application Data\egiweb.dat"
"C:\hrngen.exe"
"C:\prdfjhha.exe"
"C:\qgferewy.exe"
"c:\windows\awiv.com"
"c:\windows\system32\dbsinit.exe"
"c:\windows\system32\gasfkyqmowykxd.dll"
"c:\windows\system32\pump.exe"
"c:\windows\system32\skynet.dat"
"c:\windows\wf3.dat"
"c:\windows\wf4.dat"

file zipped: C:\hrngen.exe
file zipped: C:\prdfjhha.exe
file zipped: C:\qgferewy.exe
file zipped: c:\windows\system32\pump.exe
.

Overlay aborted ... Please run ComboFix once more
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\afuqr.exe
C:\avjelge.exe
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Cnd\Local Settings\Application Data\egiweb.dat
C:\hrngen.exe
C:\prdfjhha.exe
C:\qgferewy.exe
c:\windows\awiv.com
c:\windows\system32\dbsinit.exe
c:\windows\system32\pump.exe
c:\windows\system32\skynet.dat
c:\windows\wf3.dat
c:\windows\wf4.dat

----- BITS: Possible infected sites -----

hxxp://dibs.ddni.net
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ANTIPOL
-------\Service_AntiPol


(((((((((((((((((((((((((   Files Created from 2009-09-08 to 2009-10-08  )))))))))))))))))))))))))))))))
.

2009-10-08 16:53 . 2008-04-14 12:42 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-08 16:31 . 2009-10-08 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\AIM Toolbar
2009-10-08 15:31 . 2009-10-08 15:31 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-10-03 07:34 . 2009-10-03 07:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\0739412875
2009-10-02 21:26 . 2009-10-08 15:53 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-02 02:14 . 2009-10-02 02:14 -------- d-----w- c:\documents and settings\Cnd\Application Data\7606509191
2009-10-02 01:40 . 2009-10-02 01:40 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-02 01:16 . 2009-10-02 01:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-02 01:14 . 2009-10-02 01:14 -------- d-----w- C:\Lenovo
2009-09-09 04:32 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 22:53 . 2009-08-26 22:53 0 ----a-w- c:\windows\nsreg.dat
2009-08-26 06:28 . 2009-05-02 06:29 15912 ----a-w- c:\documents and settings\Cnd\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 06:21 . 2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-26 06:21 . 2009-08-26 06:21 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-26 06:21 . 2009-08-26 06:21 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-26 06:21 . 2009-08-26 06:21 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\program files\AVG
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-26 05:34 . 2009-08-26 05:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\AVG8
2009-08-06 00:01 . 2004-08-04 19:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-18 10:01 . 2004-08-04 19:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 17:08 . 2004-08-04 19:00 286720 ----a-w- c:\windows\system32\wmpdxm.dll
.

(((((((((((((((((((((((((((((   SnapShot@2009-10-08_16.57.08   )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-08 23:41 . 2009-10-08 23:41 16384              c:\windows\TEMP\Perflib_Perfdata_29c.dat
+ 2006-07-28 17:17 . 2009-10-08 23:13 32768              c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 32768              c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2006-07-28 17:17 . 2009-10-08 23:13 32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-10-02 01:16 . 2009-10-08 23:13 16384              c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-10-02 01:16 . 2009-10-08 16:26 16384              c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2006-07-28 17:17 . 2009-10-08 23:13 16384              c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 16384              c:\windows\system32\config\systemprofile\Cookies\index.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 18:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2009-04-15 12:39 241752 ----a-w- c:\windows\system32\IcnOvrly.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-23 1146880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"IdeaNotesUser"="c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe" [2009-08-24 221872]
"VeriFaceManager"="c:\program files\Lenovo\VeriFaceIII\PManage.exe" [2009-04-15 323584]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2008-07-09 4456448]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2008-08-28 1283984]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-02 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-08 2023704]
"7606509191"="c:\documents and settings\Cnd\Application Data\7606509191\7606509191.exe" [2009-10-02 1048100]
"0739412875"="c:\documents and settings\Cnd\Application Data\0739412875\0739412875.exe" [2009-10-03 1048611]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-02-17 17508864]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PicNotify]
2009-04-15 12:39 1167360 ----a-w- c:\windows\system32\PicNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\DDNI\\Lenovo Idea Notes\\DDNIMSGService.exe"=
"c:\\WINDOWS\\System32\\SPOOLSV.EXE"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/25/2009 11:21 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/25/2009 11:21 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/25/2009 11:20 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/25/2009 11:20 PM 297752]
R2 DDNIMSGService;DDNIMSGService;c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe [10/6/2008 11:23 AM 172720]
R2 DDNIService;DDNIService;c:\program files\DDNI\DIBS\DDNIService.exe [4/15/2009 5:30 AM 160432]
R2 System_Repair_UpdateMonitor;System Repair Windows Update Monitor;c:\program files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe [4/15/2009 5:54 AM 430080]
R2 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [4/15/2009 5:54 AM 48192]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/23/2009 9:41 PM 24652]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [4/15/2009 6:22 AM 9472]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [4/15/2009 5:20 AM 157696]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [4/15/2009 5:18 AM 1684736]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [4/15/2009 5:54 AM 81192]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-10-08 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 22:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://aimzones.aol.com/homepage
uInternet Connection Wizard,ShellNext = hxxp://lenovo.live.com/
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
FF - ProfilePath - c:\documents and settings\Cnd\Application Data\Mozilla\Firefox\Profiles\jiwyidvz.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-08 16:42
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\PicNotify.dll
c:\windows\system32\FaceVerify.dll
c:\windows\system32\MainOp.dll
c:\windows\system32\VideoOp.dll
c:\windows\system32\Image.dll
c:\windows\system32\Momo.dll
c:\windows\system32\Apblend.dll
c:\windows\system32\SetDev.dll
c:\windows\system32\FunFrm.dll
c:\windows\system32\facev.dll

- - - - - - - > 'lsass.exe'(892)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(2748)
c:\windows\system32\WININET.dll
gasfkyqmowykxd.dll 10000000    32768 \\?\globalroot\systemroot\system32\gasfkyqmowykxd.dll
c:\windows\system32\IcnOvrly.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\AVGWDSVC.EXE
c:\program files\JAVA\JRE6\BIN\JQS.EXE
c:\program files\AVG\AVG8\AVGRSX.EXE
c:\program files\AVG\AVG8\AVGNSX.EXE
c:\windows\SYSTEM32\WDFMGR.EXE
c:\program files\AVG\AVG8\AVGEMC.EXE
c:\program files\AVG\AVG8\AVGCSRVX.EXE
c:\windows\SYSTEM32\IGFXSRVC.EXE
c:\program files\AVG\AVG8\AVGTRAY.EXE
c:\program files\AIM6\AOLSOFTWARE.EXE
.
**************************************************************************
.
Completion time: 2009-10-08 16:52 - machine was rebooted
ComboFix-quarantined-files.txt  2009-10-08 23:52
ComboFix2.txt  2009-10-08 17:06

Pre-Run: 94,119,100,416 bytes free
Post-Run: 94,120,574,976 bytes free

238 --- E O F --- 2009-09-17 07:57
Upload was successful

10.4K Posts

October 9th, 2009 09:00

jecameron

Good work. Combofix had requested that it be run again to complete the job.

So, following the previous instructions with the script file rerun Combofix and post the results.

23 Posts

October 10th, 2009 10:00

Here are the latest ComboFix results:

 

ComboFix 09-10-08.04 - Cnd 10/10/2009  8:58.3.2 - FAT32x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1014.674 [GMT -7:00]
Running from: c:\documents and settings\Cnd\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Cnd\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

----- BITS: Possible infected sites -----

hxxp://dibs.ddni.net
.
(((((((((((((((((((((((((   Files Created from 2009-09-10 to 2009-10-10  )))))))))))))))))))))))))))))))
.

2009-10-09 00:19 . 2005-08-26 02:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-10-09 00:19 . 2009-10-09 00:19 -------- d-----w- c:\program files\SpywareBlaster
2009-10-08 16:53 . 2008-04-14 12:42 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-08 16:31 . 2009-10-08 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\AIM Toolbar
2009-10-08 15:31 . 2009-10-08 15:31 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-10-03 07:34 . 2009-10-03 07:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\0739412875
2009-10-02 21:26 . 2009-10-08 15:53 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-02 02:14 . 2009-10-02 02:14 -------- d-----w- c:\documents and settings\Cnd\Application Data\7606509191
2009-10-02 01:40 . 2009-10-02 01:40 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-02 01:16 . 2009-10-02 01:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-02 01:14 . 2009-10-02 01:14 -------- d-----w- C:\Lenovo

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 22:53 . 2009-08-26 22:53 0 ----a-w- c:\windows\nsreg.dat
2009-08-26 06:28 . 2009-05-02 06:29 15912 ----a-w- c:\documents and settings\Cnd\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 06:21 . 2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-26 06:21 . 2009-08-26 06:21 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-26 06:21 . 2009-08-26 06:21 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-26 06:21 . 2009-08-26 06:21 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\program files\AVG
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-26 05:34 . 2009-08-26 05:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\AVG8
2009-08-06 00:01 . 2004-08-04 19:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-18 10:01 . 2004-08-04 19:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 17:08 . 2004-08-04 19:00 286720 ----a-w- c:\windows\system32\wmpdxm.dll
.

(((((((((((((((((((((((((((((   SnapShot@2009-10-08_16.57.08   )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-07-28 17:17 . 2009-10-10 15:55 32768              c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 32768              c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-07-28 17:17 . 2009-10-10 15:55 32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-10-02 01:16 . 2009-10-10 15:55 16384              c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-10-02 01:16 . 2009-10-08 16:26 16384              c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2006-07-28 17:17 . 2009-10-10 15:55 32768              c:\windows\system32\config\systemprofile\Cookies\index.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 18:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2009-04-15 12:39 241752 ----a-w- c:\windows\system32\IcnOvrly.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-23 1146880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"IdeaNotesUser"="c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe" [2009-08-24 221872]
"VeriFaceManager"="c:\program files\Lenovo\VeriFaceIII\PManage.exe" [2009-04-15 323584]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2008-07-09 4456448]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2008-08-28 1283984]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-02 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-08 2023704]
"7606509191"="c:\documents and settings\Cnd\Application Data\7606509191\7606509191.exe" [2009-10-02 1048100]
"0739412875"="c:\documents and settings\Cnd\Application Data\0739412875\0739412875.exe" [2009-10-03 1048611]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-02-17 17508864]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PicNotify]
2009-04-15 12:39 1167360 ----a-w- c:\windows\system32\PicNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\DDNI\\Lenovo Idea Notes\\DDNIMSGService.exe"=
"c:\\WINDOWS\\System32\\SPOOLSV.EXE"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/25/2009 11:21 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/25/2009 11:21 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/25/2009 11:20 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/25/2009 11:20 PM 297752]
R2 DDNIMSGService;DDNIMSGService;c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe [10/6/2008 11:23 AM 172720]
R2 DDNIService;DDNIService;c:\program files\DDNI\DIBS\DDNIService.exe [4/15/2009 5:30 AM 160432]
R2 System_Repair_UpdateMonitor;System Repair Windows Update Monitor;c:\program files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe [4/15/2009 5:54 AM 430080]
R2 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [4/15/2009 5:54 AM 48192]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/23/2009 9:41 PM 24652]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [4/15/2009 6:22 AM 9472]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [4/15/2009 5:20 AM 157696]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [4/15/2009 5:18 AM 1684736]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [4/15/2009 5:54 AM 81192]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-10-09 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 22:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://aimzones.aol.com/homepage
uInternet Connection Wizard,ShellNext = hxxp://lenovo.live.com/
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
FF - ProfilePath - c:\documents and settings\Cnd\Application Data\Mozilla\Firefox\Profiles\jiwyidvz.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

AddRemove-HijackThis - c:\documents and settings\Cnd\Desktop\HijackThis.exe

 

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-10 09:17
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(840)
c:\windows\system32\PicNotify.dll
c:\windows\system32\FaceVerify.dll
c:\windows\system32\MainOp.dll
c:\windows\system32\VideoOp.dll
c:\windows\system32\Image.dll
c:\windows\system32\Momo.dll
c:\windows\system32\Apblend.dll
c:\windows\system32\SetDev.dll
c:\windows\system32\FunFrm.dll
c:\windows\system32\facev.dll

- - - - - - - > 'lsass.exe'(896)
c:\windows\system32\WININET.dll
.
Completion time: 2009-10-10  9:23
ComboFix-quarantined-files.txt  2009-10-10 16:23
ComboFix2.txt  2009-10-08 23:55
ComboFix3.txt  2009-10-08 17:06

Pre-Run: 94,108,712,960 bytes free
Post-Run: 94,105,305,088 bytes free

184 --- E O F --- 2009-09-17 07:57

10.4K Posts

October 12th, 2009 14:00

jecameron

That looks better. Rerun Hijackthis and post a fresh Hiajcktis log.

And in your reply give me an update on how your PC is running now.

23 Posts

October 13th, 2009 21:00

There are a number of remaining issues:

 

1) Strange Tray icon

-- when I boot, there is a strange icon in the tray; it looks like a little red shield with a cross in it; when I point at the icon, it disappears

 

2) Strange Desktop icon

-- there is a strange Desktop icon called “Security Tool”; it is a shortcut to:

C:\Documents and Settings\Cnd\Application Data\0739412875\0739412875.exe

-- I cannot find a Cnd sub-folder in the Documents and Settings folder, and therefore cannot find the .exe file; I’m using Windows Explorer

-- I deleted the shortcut icon from the Desktop, but it re-appears after booting

 

3) Desktop icons disappear

-- when I boot, the Desktop icons appear for about ten seconds, then disappear; so my Desktop is basically a blue screen with the Start button and the Taskbar

-- apparently something has taken over the explorer.exe file in the C:\Windows folder; I can rename or delete the explorer.exe file using Windows Explorer and it reappears in the file list after a few seconds; I was going to rename explorer.exe and copy a version from another computer running XP, but almost immediately after I renamed the file, it re-appeared as explorer.exe in the file list

 

4) Search engine problem

-- when I use a search engine, there is a strange problem that occurs sometimes; I enter a search keyword and get a hit list; when I click one of the links in the hit list, I’m taken to an advertising site; it happens in both Internet Explorer and Firefox; it happens in both Google and Bing

-- I do not have any problems if I type a URL in the Address Box.

 

These are the weird things that I have identified so far.  My netbook remains pretty much unusable.

 

Again, thanks very much for your assistance.

 

Here is the latest HijackThis log:

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 7:20:09 PM, on 10/13/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe

C:\Program Files\DDNI\DIBS\DDNIService.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe

C:\Program Files\Lenovo\VeriFaceIII\PManage.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Program Files\Lenovo\Energy Management\utility.exe

C:\Program Files\Lenovo\Energy Management\Energy Management.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\AIM6\aim6.exe

C:\WINDOWS\system32\ctfmon.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\PROGRA~1\AVG\AVG8\avgnsx.exe

C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe

C:\Program Files\Viewpoint\Common\ViewpointService.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\Program Files\AVG\AVG8\avgcsrvx.exe

C:\Program Files\AIM6\aolsoftware.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://aimzones.aol.com/homepage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://lenovo.live.com/

R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll

R3 - URLSearchHook: (no name) - *{03402f96-3dc7-4285-bc50-9e81fefafe43} - (no file)

R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll

O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll

O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll

O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [IdeaNotesUser] C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe

O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFaceIII\PManage.exe

O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe

O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [7606509191] C:\Documents and Settings\Cnd\Application Data\7606509191\7606509191.exe

O4 - HKLM\..\Run: [0739412875] C:\Documents and Settings\Cnd\Application Data\0739412875\0739412875.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm

O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com

O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab

O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk/6u13-b03/jinstall-6u13-windows-i586-jc.cab?e=1241247500030&h=2833b30abb1974eb4cdadb10158b4033/&filename=jinstall-6u13-windows-i586-jc.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O20 - Winlogon Notify: PicNotify - C:\WINDOWS\SYSTEM32\PicNotify.dll

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: DDNIMSGService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe

O23 - Service: DDNIService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\DIBS\DDNIService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

 

--

End of file - 7984 bytes

 

10.4K Posts

October 14th, 2009 08:00


jecameron

We still have a few things to do, and thanks for the update. This infection leaves a lot of trash behind.

We are going to create another script for Combofix

1. Open NotePad (not wordpad). Copy and paste the following into Notepad

Folder::
c:\documents and settings\Cnd\Application Data\0739412875
c:\documents and settings\Cnd\Application Data\7606509191

Registry::
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"=-
"NoActiveDesktopChanges"=-

[-HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop

Using the Image as a reference, drag CFScript into ComboFix.exe

user posted image
  • You will be prompted to run Combofix again, Do so
    Following the same rules as indicated in my first post
    Then post the contents of the C:\ComboFix.txt log in your reply

23 Posts

October 14th, 2009 12:00

Latest ComboFix results:

 

ComboFix 09-10-13.04 - Cnd 10/14/2009 10:59.4.2 - FAT32x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1014.657 [GMT -7:00]
Running from: E:\ComboFix.exe
Command switches used :: E:\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Cnd\Application Data\0739412875
c:\documents and settings\Cnd\Application Data\0739412875\0739412875.bat
c:\documents and settings\Cnd\Application Data\0739412875\0739412875.cfg
c:\documents and settings\Cnd\Application Data\0739412875\0739412875.exe
c:\documents and settings\Cnd\Application Data\7606509191
c:\documents and settings\Cnd\Application Data\7606509191\7606509191.bat
c:\documents and settings\Cnd\Application Data\7606509191\7606509191.cfg
c:\documents and settings\Cnd\Application Data\7606509191\7606509191.exe
c:\documents and settings\Cnd\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk
c:\documents and settings\Cnd\Desktop\Security Tool.lnk
c:\documents and settings\Cnd\Start Menu\Programs\Security Tool.lnk
c:\windows\system32\nuar.old

----- BITS: Possible infected sites -----

hxxp://dibs.ddni.net
.
(((((((((((((((((((((((((   Files Created from 2009-09-14 to 2009-10-14  )))))))))))))))))))))))))))))))
.

2009-10-14 02:19 . 2009-10-14 02:19 -------- d-----w- c:\program files\Trend Micro
2009-10-12 14:11 . 2007-06-13 10:23 1033216 ----a-w- c:\windows\explorer.exe
2009-10-09 00:19 . 2005-08-26 02:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-10-09 00:19 . 2009-10-09 00:19 -------- d-----w- c:\program files\SpywareBlaster
2009-10-08 16:53 . 2008-04-14 12:42 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-08 16:31 . 2009-10-08 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\AIM Toolbar
2009-10-08 15:31 . 2009-10-08 15:31 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-10-02 21:26 . 2009-10-12 14:06 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-02 01:40 . 2009-10-02 01:40 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-02 01:16 . 2009-10-02 01:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-02 01:14 . 2009-10-02 01:14 -------- d-----w- C:\Lenovo

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 22:53 . 2009-08-26 22:53 0 ----a-w- c:\windows\nsreg.dat
2009-08-26 06:28 . 2009-05-02 06:29 15912 ----a-w- c:\documents and settings\Cnd\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 06:21 . 2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-26 06:21 . 2009-08-26 06:21 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-26 06:21 . 2009-08-26 06:21 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-26 06:21 . 2009-08-26 06:21 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\program files\AVG
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-26 05:34 . 2009-08-26 05:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\AVG8
2009-08-06 00:01 . 2004-08-04 19:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-18 10:01 . 2004-08-04 19:00 58880 ----a-w- c:\windows\system32\atl.dll
.

------- Sigcheck -------

[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ERDNT\cache\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\explorer.exe
[7] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\explorer.exe
.
(((((((((((((((((((((((((((((   SnapShot@2009-10-08_16.57.08   )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-07-28 17:17 . 2009-10-14 17:55 32768              c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 32768              c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-07-28 17:17 . 2009-10-14 17:55 32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-10-02 01:16 . 2009-10-14 17:16 16384              c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-10-02 01:16 . 2009-10-08 16:26 16384              c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2006-07-28 17:17 . 2009-10-14 17:55 32768              c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2004-08-04 19:00 . 2008-04-14 12:42 1033728              c:\windows\explorer-old.exe
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 18:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2009-04-15 12:39 241752 ----a-w- c:\windows\system32\IcnOvrly.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-23 1146880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"IdeaNotesUser"="c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe" [2009-08-24 221872]
"VeriFaceManager"="c:\program files\Lenovo\VeriFaceIII\PManage.exe" [2009-04-15 323584]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2008-07-09 4456448]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2008-08-28 1283984]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-02 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-08 2023704]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-02-17 17508864]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PicNotify]
2009-04-15 12:39 1167360 ----a-w- c:\windows\system32\PicNotify.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ    autocheck autochk /p \??\C:\0autocheck autochk *

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\DDNI\\Lenovo Idea Notes\\DDNIMSGService.exe"=
"c:\\WINDOWS\\System32\\SPOOLSV.EXE"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/25/2009 11:21 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/25/2009 11:21 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/25/2009 11:20 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/25/2009 11:20 PM 297752]
R2 DDNIMSGService;DDNIMSGService;c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe [10/6/2008 11:23 AM 172720]
R2 DDNIService;DDNIService;c:\program files\DDNI\DIBS\DDNIService.exe [4/15/2009 5:30 AM 160432]
R2 System_Repair_UpdateMonitor;System Repair Windows Update Monitor;c:\program files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe [4/15/2009 5:54 AM 430080]
R2 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [4/15/2009 5:54 AM 48192]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/23/2009 9:41 PM 24652]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [4/15/2009 6:22 AM 9472]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [4/15/2009 5:20 AM 157696]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [4/15/2009 5:18 AM 1684736]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [4/15/2009 5:54 AM 81192]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-10-14 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 22:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://aimzones.aol.com/homepage
uInternet Connection Wizard,ShellNext = hxxp://lenovo.live.com/
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
FF - ProfilePath - c:\documents and settings\Cnd\Application Data\Mozilla\Firefox\Profiles\jiwyidvz.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-7606509191 - c:\documents and settings\Cnd\Application Data\7606509191\7606509191.exe
HKLM-Run-0739412875 - c:\documents and settings\Cnd\Application Data\0739412875\0739412875.exe

 

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-14 11:18
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\PicNotify.dll
c:\windows\system32\FaceVerify.dll
c:\windows\system32\MainOp.dll
c:\windows\system32\VideoOp.dll
c:\windows\system32\Image.dll
c:\windows\system32\Momo.dll
c:\windows\system32\Apblend.dll
c:\windows\system32\SetDev.dll
c:\windows\system32\FunFrm.dll
c:\windows\system32\facev.dll

- - - - - - - > 'lsass.exe'(900)
c:\windows\system32\WININET.dll
.
Completion time: 2009-10-14 11:28
ComboFix-quarantined-files.txt  2009-10-14 18:28
ComboFix2.txt  2009-10-10 16:23
ComboFix3.txt  2009-10-08 23:55
ComboFix4.txt  2009-10-08 17:06

Pre-Run: 94,057,922,560 bytes free
Post-Run: 94,099,570,688 bytes free

201 --- E O F --- 2009-09-17 07:57

10.4K Posts

October 15th, 2009 07:00


jecameron

Good work

Please perform a BitDefender Online Virus and Malware Scan here:
* Click on I Agree.
* An ActiveX warning box will appear, click on Install.
* Under Select What You Want To Check For Viruses.
* Please Check My Computer and Click Ok
* Now Click On Click Here To Scan
* Next, Click on Click here to export the scan report
* Save it to your Desktop.
* In your next reply, please include the BitDefender log.

23 Posts

October 15th, 2009 09:00

Here is the Bit Defender log:

 

BitDefender Online Scanner

Scan report generated at: Thu, Oct 15, 2009 - 08:05:48

Scan path: C:\Documents and Settings\Cnd\My Documents;C:\Documents and Settings\All Users\Documents;C:\;D:\;C:\Documents and Settings\Cnd\My Documents;C:\Documents and Settings\Cnd\Desktop\New York;C:\Documents and Settings\Cnd\Desktop\Favorites;
 

 

Statistics

Time
 

00:52:06

Files
 

177311

Folders
 

3318

Boot Sectors
 

0

Archives
 

7276

Packed Files
 

8209
 

 
 

 

Results

Identified Viruses
 

21

Infected Files
 

35

Suspect Files
 

0

Warnings
 

0

Disinfected
 

0

Deleted Files
 

34
 

 
 

 

Engines Info

Virus Definitions
 

4349177

Engine build
 

AVCORE v2.1 Windows/i386 11.0.0.26 (Aug 27 2009)

Scan plugins
 

17

Archive plugins
 

44

Unpack plugins
 

8

E-mail plugins
 

6

System plugins
 

4
 

 
 

 

Scan Settings

First Action
 

Disinfect

Second Action
 

Delete

Heuristics
 

Yes

Enable Warnings
 

Yes

Scanned Extensions
 

*;

Exclude Extensions
 

 

Scan Emails
 

Yes

Scan Archives
 

Yes

Scan Packed
 

Yes

Scan Files
 

Yes

Scan Boot
 

Yes
 

 
 

 
 

Scanned File
 

 Status

C:\System Volume Information\_restore{F8136B96-1D4C-4145-839F-7B8F940A9052}\RP23\A0005315.dll
 

Infected with: Trojan.Generic.2474880

C:\System Volume Information\_restore{F8136B96-1D4C-4145-839F-7B8F940A9052}\RP23\A0005315.dll
 

Deleted

C:\Lenovo\OneKey App\System Repair\UF\WINDOWS\system32\eventlog.dll
 

Infected with: Trojan.Generic.2492473

C:\Lenovo\OneKey App\System Repair\UF\WINDOWS\system32\eventlog.dll
 

Deleted

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\lizkavd.exe.vir
 

Infected with: Gen:Packed.FakeAV.3

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\lizkavd.exe.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\lizkavd.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\seres.exe.vir
 

Infected with: Win32.KME.Based.1.Gen

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\seres.exe.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\seres.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\svcst.exe.vir
 

Infected with: Win32.KME.Based.1.Gen

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\svcst.exe.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\svcst.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\0739412875\0739412875.exe.vir
 

Infected with: Trojan.CryptRedol.Gen.5

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\0739412875\0739412875.exe.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\0739412875\0739412875.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\7606509191\7606509191.exe.vir
 

Infected with: Trojan.CryptRedol.Gen.5

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\7606509191\7606509191.exe.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\7606509191\7606509191.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\Program Files\AdvancedVirusRemover\PAVRM.exe.vir
 

Infected with: Trojan.Generic.2506199

C:\Qoobox\Quarantine\C\Program Files\AdvancedVirusRemover\PAVRM.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe.vir
 

Infected with: Gen:Packed.FakeAV.3

C:\Qoobox\Quarantine\C\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\_scui.cpl.vir
 

Infected with: Trojan.Generic.2501728

C:\Qoobox\Quarantine\C\WINDOWS\system32\_scui.cpl.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\~.exe.vir
 

Infected with: Trojan.Agent.ANPU

C:\Qoobox\Quarantine\C\WINDOWS\system32\~.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\biravoja.dll.vir
 

Infected with: Trojan.Generic.2506343

C:\Qoobox\Quarantine\C\WINDOWS\system32\biravoja.dll.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\bozoyipo.exe.vir
 

Infected with: Trojan.CryptRedol.Gen.5

C:\Qoobox\Quarantine\C\WINDOWS\system32\bozoyipo.exe.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\bozoyipo.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\febobafi.dll.vir
 

Infected with: Gen:Trojan.Heur.TDSS.bu4@iyVm4nii

C:\Qoobox\Quarantine\C\WINDOWS\system32\febobafi.dll.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\febobafi.dll.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\gawarege.dll.tmp.vir
 

Infected with: Trojan.Vundo.GMM

C:\Qoobox\Quarantine\C\WINDOWS\system32\gawarege.dll.tmp.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\gawarege.dll.tmp.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\gawojuso.dll.vir
 

Infected with: Trojan.Vundo.GMM

C:\Qoobox\Quarantine\C\WINDOWS\system32\gawojuso.dll.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\gawojuso.dll.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\kiduruka.dll.vir
 

Infected with: Trojan.Generic.2507159

C:\Qoobox\Quarantine\C\WINDOWS\system32\kiduruka.dll.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\losorede.dll.vir
 

Infected with: Trojan.Generic.2506345

C:\Qoobox\Quarantine\C\WINDOWS\system32\losorede.dll.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\mifolole.exe.vir
 

Infected with: Trojan.CryptRedol.Gen.5

C:\Qoobox\Quarantine\C\WINDOWS\system32\mifolole.exe.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\mifolole.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\nadusajo.dll.vir
 

Infected with: Trojan.Vundo.GMM

C:\Qoobox\Quarantine\C\WINDOWS\system32\nadusajo.dll.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\nadusajo.dll.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\nivumosi.dll.tmp.vir
 

Infected with: Trojan.Vundo.GMM

C:\Qoobox\Quarantine\C\WINDOWS\system32\nivumosi.dll.tmp.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\nivumosi.dll.tmp.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\royoneyu.dll.tmp.vir
 

Infected with: Trojan.Vundo.GMM

C:\Qoobox\Quarantine\C\WINDOWS\system32\royoneyu.dll.tmp.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\royoneyu.dll.tmp.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\wafiguvu.dll.vir
 

Infected with: Trojan.Vundo.GMM

C:\Qoobox\Quarantine\C\WINDOWS\system32\wafiguvu.dll.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\wafiguvu.dll.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\wbem\proquota.exe.vir
 

Infected with: Trojan.Agent.ANPT

C:\Qoobox\Quarantine\C\WINDOWS\system32\wbem\proquota.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\winhelper.dll.vir
 

Infected with: Trojan.FakeAlert.TK

C:\Qoobox\Quarantine\C\WINDOWS\system32\winhelper.dll.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\winhelper.dll.vir
 

Delete failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\wispex.html.vir
 

Infected with: Trojan.Script.212078

C:\Qoobox\Quarantine\C\WINDOWS\system32\wispex.html.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\yefapuza.dll.vir
 

Infected with: Trojan.Vundo.GMM

C:\Qoobox\Quarantine\C\WINDOWS\system32\yefapuza.dll.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\yefapuza.dll.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\zitakihu.exe.vir
 

Infected with: Trojan.CryptRedol.Gen.5

C:\Qoobox\Quarantine\C\WINDOWS\system32\zitakihu.exe.vir
 

Disinfection failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\zitakihu.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\eventlog.dll.vir
 

Infected with: Trojan.Generic.2492473

C:\Qoobox\Quarantine\C\WINDOWS\system32\eventlog.dll.vir
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\dbsinit.exe.vir=>(RAR Sfx o)=>wispex.html
 

Infected with: Trojan.Script.212078

C:\Qoobox\Quarantine\C\WINDOWS\system32\dbsinit.exe.vir=>(RAR Sfx o)=>wispex.html
 

Deleted

C:\Qoobox\Quarantine\C\WINDOWS\system32\dbsinit.exe.vir=>(RAR Sfx o)
 

Update failed

C:\Qoobox\Quarantine\C\WINDOWS\system32\pump.exe.vir
 

Infected with: Trojan.Generic.IS.611245

C:\Qoobox\Quarantine\C\WINDOWS\system32\pump.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\afuqr.exe.vir
 

Infected with: Trojan.Generic.2502308

C:\Qoobox\Quarantine\C\afuqr.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\avjelge.exe.vir
 

Infected with: Trojan.Generic.2507281

C:\Qoobox\Quarantine\C\avjelge.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\hrngen.exe.vir
 

Infected with: Trojan.FakeAlert.BNR

C:\Qoobox\Quarantine\C\hrngen.exe.vir
 

Deleted

C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)=>install.exe
 

Infected with: Gen:Trojan.Heur.Rustock.1

C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)=>install.exe
 

Disinfection failed

C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)=>install.exe
 

Deleted

C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)
 

Update failed
 

10.4K Posts

October 15th, 2009 10:00

jecameron

How is your PC running now?

23 Posts

October 16th, 2009 09:00

My computer is running much better, thank you.  I have re-run the BitDefender scan multiple times and each time
it finds something new.  Is this normal?

The screens at BitDefender have changed.  Here is a suggested procedure for running the BitDefender scan:

Please perform a BitDefender Online Virus and Malware Scan here:
* Click Start Scanner.
* Click I Agree… and Start Here.
* An ActiveX warning box will appear; click Install.
* Options displayed are Folders to Scan and Cleaning Options; click Folders to Scan.
* Select folders to be scanned by clicking check boxes; click OK.
* Click Start Scan.
* After the scan has completed, click Click here to export the scan report.
* Save the report to your Desktop.
* In your next reply, please include the BitDefender log.

 

The following issue remains:
Search engine problem
-- when I use a search engine, there is a strange problem that occurs sometimes; I enter a search keyword and
get a hit list; when I click one of the links in the hit list, I’m taken to an advertising site; it happens in
both Internet Explorer and Firefox; it happens in both Google and Bing


I also downloaded and tried to run Ad-Aware.  Ad-Aware identifies a major problem that BitDefender does
not find.  Ad-Aware tells me to reboot to remove the problem, but when I reboot, the Ad-Watch feature
of Ad-Aware causes Ad-Aware to automatically start a scan and re-identifies the same problem.  So, I'm in
a tight loop.  Here is the Ad-Aware log for what it's worth:

Logfile created: 10/15/2009 19:17:39
Lavasoft Ad-Aware version: 8.1.0
Extended engine: 191738264
Extended engine version:
User performing scan: Cnd

*********************** Definitions database information ***********************
Lavasoft definition file: 149.72
Genotype definition file version: 2009/10/05 15:03:45

******************************** Scan results: *********************************
Scan profile name: Smart Scan  (ID: smart)
Objects scanned: 8668
Objects detected: 1


Type              Detected
==========================
Processes.......:        1
Registry entries:        0
Hostfile entries:        0
Files...........:        0
Folders.........:        0
LSPs............:        0
Cookies.........:        0
Browser hijacks.:        0
MRU objects.....:        0

 

Quarantined items:
Description: \\?\globalroot\systemroot\system32\gasfkyqmowykxd.dll Family Name: Win32.Trojan.Tdss Engine: 1 Clean status: Reboot required Item ID: 1622997 Family ID: 5401

Scan and cleaning complete: Finished correctly after 52 seconds


Again, thanks so much for all your help.

====================================================================

Here is the latest BitDefender log:


BitDefender Online Scanner
 
Scan report generated at: Fri, Oct 16, 2009 - 08:30:10
 
Scan path: C:\Documents and Settings\Cnd\My Documents;C:\Documents and Settings\All Users\Documents;C:\;D:\;C:\Documents and Settings\Cnd\My Documents;C:\Documents and Settings\Cnd\Desktop\New York;C:\Documents and Settings\Cnd\Desktop\Favorites;
 
Statistics
 
Time
 00:47:23
 
Files
 177682
 
Folders
 3536
 
Boot Sectors
 0
 
Archives
 7323
 
Packed Files
 8177
 
 
Results
 
Identified Viruses
 3
 
Infected Files
 3
 
Suspect Files
 0
 
Warnings
 0
 
Disinfected
 0
 
Deleted Files
 3
 
 
 
 
Engines Info
 
Virus Definitions
 4355376
 
Engine build
 AVCORE v2.1 Windows/i386 11.0.0.26 (Aug 27 2009)
 
Scan plugins
 17
 
Archive plugins
 44
 
Unpack plugins
 8
 
E-mail plugins
 6
 
System plugins
 4
 
 
 
 
Scan Settings
 
First Action
 Disinfect
 
Second Action
 Delete
 
Heuristics
 Yes
 
Enable Warnings
 Yes
 
Scanned Extensions
 *;
 
Exclude Extensions
 
 
Scan Emails
 Yes
 
Scan Archives
 Yes
 
Scan Packed
 Yes
 
Scan Files
 Yes
 
Scan Boot
 Yes
 
 
 
 
  Scanned File
  Status
 
C:\Qoobox\Quarantine\C\WINDOWS\system32\plugie.dll.vir
 Infected with: Trojan.Generic.2528887
 
C:\Qoobox\Quarantine\C\WINDOWS\system32\plugie.dll.vir
 Deleted
 
C:\Qoobox\Quarantine\C\WINDOWS\system32\dbsinit.exe.vir=>(RAR Sfx o)=>wispex.html
 Infected with: Trojan.Script.212078
 
C:\Qoobox\Quarantine\C\WINDOWS\system32\dbsinit.exe.vir=>(RAR Sfx o)=>wispex.html
 Deleted
 
C:\Qoobox\Quarantine\C\WINDOWS\system32\dbsinit.exe.vir=>(RAR Sfx o)
 Update failed
 
C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)=>install.exe
 Infected with: Gen:Trojan.Heur.Rustock.1
 
C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)=>install.exe
 Disinfection failed
 
C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)=>install.exe
 Deleted
 
C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)
 Update failed

10.4K Posts

October 16th, 2009 10:00


jecameron

Is this what AdAware keeps finding?


CODE
Description: \\?\globalroot\systemroot\system32\gasfkyqmowykxd.dll Family Name: Win32.Trojan.Tdss Engine: 1 Clean status: Reboot required Item ID: 1622997 Family ID:


I'm not concerned with what BitDefender found in C:\Qoobox\Quarantine\ they can do no harm there
And do you use a router?


No Events found!

Top