Unsolved
This post is more than 5 years old
23 Posts
0
5219
October 2nd, 2009 15:00
Antivirus Pro 2010 and Windows Police Pro
I have a Lenovo S10 Netbook running Windows XP SP3.
It has been taken over by Antivirus Pro 2010 and Windows Police Pro pop-ups.
I had to boot in Safe Mode in order to run the Hijackthis program. The malware blocked the running of the program in regular mode.
Here is my Hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:28:20 PM, on 10/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Cnd\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://aimzones.aol.com/homepage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://lenovo.live.com/
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{03402f96-3dc7-4285-bc50-9e81fefafe43} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: ICQSys (IE PlugIn) - {77DC0B63-1535-4ba9-8BE8-D59EB676FA02} - C:\WINDOWS\system32\plugie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IdeaNotesUser] C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Antivirus Pro 2010] "C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe" /hide
O4 - HKLM\..\Run: [7606509191] C:\Documents and Settings\Cnd\Application Data\7606509191\7606509191.exe
O4 - HKLM\..\Run: [yakajeyij] Rundll32.exe "c:\windows\system32\vonibusa.dll",a
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [mserv] C:\Documents and Settings\Cnd\Application Data\svcst.exe
O4 - HKCU\..\Run: [svchost] C:\Documents and Settings\Cnd\Application Data\svcst.exe
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: LENOVO - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.lenovo.com (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk/6u13-b03/jinstall-6u13-windows-i586-jc.cab?e=1241247500030&h=2833b30abb1974eb4cdadb10158b4033/&filename=jinstall-6u13-windows-i586-jc.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: c:\windows\system32\vonibusa.dll,wafiguvu.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: PicNotify - C:\WINDOWS\SYSTEM32\PicNotify.dll
O21 - SSODL: tahinoteb - {f40e7dde-ffd3-425c-b021-391951381521} - c:\windows\system32\vonibusa.dll
O22 - SharedTaskScheduler: tokatiluy - {f40e7dde-ffd3-425c-b021-391951381521} - c:\windows\system32\vonibusa.dll
O23 - Service: AntiPol - Unknown owner - C:\WINDOWS\svchast.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DDNIMSGService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe
O23 - Service: DDNIService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\DIBS\DDNIService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 7706 bytes
Any help you can provide will be greatly appreciated.


bamajim
10.4K Posts
0
October 8th, 2009 08:00
Please download Combofix and save to your desktop:
Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the contents of the C:\ComboFix.txt into your next reply.
Note: Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.
jecameron
23 Posts
0
October 8th, 2009 11:00
Here are the Combofix results:
ComboFix 09-10-07.05 - Cnd 10/08/2009 9:29.1.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.683 [GMT -7:00]
Running from: c:\documents and settings\Cnd\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
Overlay aborted ... Please run ComboFix once more
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\izycug.sys
c:\documents and settings\All Users\Application Data\lori._sy
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Documents\gehipuxeqa.reg
c:\documents and settings\All Users\Documents\niqylinido.scr
c:\documents and settings\All Users\Documents\xiwas.dll
c:\documents and settings\Cnd\Application Data\awiqedis.sys
c:\documents and settings\Cnd\Application Data\cepysu.inf
c:\documents and settings\Cnd\Application Data\cetaruton.inf
c:\documents and settings\Cnd\Application Data\evum.dl
c:\documents and settings\Cnd\Application Data\iniasd.txt
c:\documents and settings\Cnd\Application Data\lizkavd.exe
c:\documents and settings\Cnd\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Cnd\Application Data\nykuqyle.inf
c:\documents and settings\Cnd\Application Data\ogolevuxut.bat
c:\documents and settings\Cnd\Application Data\seres.exe
c:\documents and settings\Cnd\Application Data\svcst.exe
c:\documents and settings\Cnd\Cookies\gavoc.bin
c:\documents and settings\Cnd\Cookies\geregowez.scr
c:\documents and settings\Cnd\Cookies\ivaviw.dll
c:\documents and settings\Cnd\Cookies\mykiq.ban
c:\documents and settings\Cnd\Cookies\ocohibuv.dll
c:\documents and settings\Cnd\Desktop\Advanced Virus Remover.lnk
c:\documents and settings\Cnd\Local Settings\Application Data\ohyqi._dl
c:\documents and settings\Cnd\Local Settings\Temporary Internet Files\edorumom.inf
c:\documents and settings\Cnd\Local Settings\Temporary Internet Files\omyko.reg
c:\documents and settings\Cnd\Local Settings\Temporary Internet Files\qidypaxot.dll
c:\documents and settings\Cnd\Start Menu\Advanced Virus Remover.lnk
c:\documents and settings\Cnd\Start Menu\Programs\AntivirusPro_2010
c:\documents and settings\Cnd\Start Menu\Programs\AntivirusPro_2010\AntivirusPro_2010.lnk
c:\documents and settings\Cnd\Start Menu\Programs\AntivirusPro_2010\Uninstall.lnk
c:\program files\AdvancedVirusRemover
c:\program files\AdvancedVirusRemover\PAVRM.exe
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg
c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe
c:\program files\Common Files\azanuwycyj.com
c:\program files\Windows Police Pro
c:\windows\abukuno.bin
c:\windows\duwax.bin
c:\windows\idugoqu.reg
c:\windows\koqologybe.sys
c:\windows\svchast.exe
c:\windows\system32\_scui.cpl
c:\windows\system32\~.exe
c:\windows\system32\18467.exe
c:\windows\system32\26500.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\bincd32.dat
c:\windows\system32\biravoja.dll
c:\windows\system32\bozoyipo.exe
c:\windows\system32\doqypa.inf
c:\windows\system32\febobafi.dll
c:\windows\system32\gawarege.dll.tmp
c:\windows\system32\gawojuso.dll
c:\windows\system32\gidobedi.dll
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\ipil.vbs
c:\windows\system32\kiduruka.dll
c:\windows\system32\losorede.dll
c:\windows\system32\mifolole.exe
c:\windows\system32\nadusajo.dll
c:\windows\system32\nivumosi.dll.tmp
c:\windows\system32\plUGie.dll
c:\windows\system32\royoneyu.dll.tmp
c:\windows\system32\wafiguvu.dll
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\winhelper.dll
c:\windows\system32\wispex.html
c:\windows\system32\yefapuza.dll
c:\windows\system32\zitakihu.exe
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat . . . . failed to delete
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat . . . . failed to delete
----- BITS: Possible infected sites -----
hxxp://dibs.ddni.net
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((( Files Created from 2009-09-08 to 2009-10-08 )))))))))))))))))))))))))))))))
.
2009-10-08 16:53 . 2008-04-14 12:42 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-08 16:31 . 2009-10-08 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\AIM Toolbar
2009-10-08 15:31 . 2009-10-08 15:31 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-10-03 07:34 . 2009-10-03 07:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\0739412875
2009-10-02 21:26 . 2009-10-08 15:53 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-02 19:11 . 2009-10-03 00:19 131731 ----a-w- c:\windows\system32\dbsinit.exe
2009-10-02 19:07 . 2009-10-03 00:44 58 ----a-w- c:\windows\wf4.dat
2009-10-02 19:07 . 2009-10-03 00:44 2 ----a-w- c:\windows\wf3.dat
2009-10-02 19:07 . 2009-10-02 19:07 36 ----a-w- c:\windows\system32\skynet.dat
2009-10-02 19:07 . 2009-10-03 00:44 545792 ----a-w- c:\windows\system32\pump.exe
2009-10-02 02:14 . 2009-10-02 02:14 -------- d-----w- c:\documents and settings\Cnd\Application Data\7606509191
2009-10-02 01:40 . 2009-10-02 01:40 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-02 01:16 . 2009-10-02 01:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-02 01:14 . 2009-10-02 01:14 -------- d-----w- C:\Lenovo
2009-10-02 01:13 . 2009-10-02 01:13 16007 ----a-w- c:\documents and settings\Cnd\Local Settings\Application Data\egiweb.dat
2009-10-02 01:13 . 2009-10-02 01:13 13892 ----a-w- c:\windows\awiv.com
2009-10-02 01:08 . 2009-10-02 01:08 45568 ----a-w- C:\hrngen.exe
2009-10-02 01:08 . 2009-10-02 01:08 196887 ----a-w- C:\prdfjhha.exe
2009-10-02 01:08 . 2009-10-02 01:08 52736 ----a-w- C:\afuqr.exe
2009-10-02 01:08 . 2009-10-02 01:08 6144 ----a-w- C:\avjelge.exe
2009-10-02 01:08 . 2009-10-02 01:08 17920 ----a-w- C:\qgferewy.exe
2009-09-09 04:32 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 22:53 . 2009-08-26 22:53 0 ----a-w- c:\windows\nsreg.dat
2009-08-26 06:28 . 2009-05-02 06:29 15912 ----a-w- c:\documents and settings\Cnd\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 06:21 . 2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-26 06:21 . 2009-08-26 06:21 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-26 06:21 . 2009-08-26 06:21 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-26 06:21 . 2009-08-26 06:21 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\program files\AVG
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-26 05:34 . 2009-08-26 05:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\AVG8
2009-08-06 00:01 . 2004-08-04 19:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-18 10:01 . 2004-08-04 19:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 17:08 . 2004-08-04 19:00 286720 ----a-w- c:\windows\system32\wmpdxm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 18:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2009-04-15 12:39 241752 ----a-w- c:\windows\system32\IcnOvrly.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-23 1146880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"IdeaNotesUser"="c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe" [2009-08-24 221872]
"VeriFaceManager"="c:\program files\Lenovo\VeriFaceIII\PManage.exe" [2009-04-15 323584]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2008-07-09 4456448]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2008-08-28 1283984]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-02 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-08 2023704]
"7606509191"="c:\documents and settings\Cnd\Application Data\7606509191\7606509191.exe" [2009-10-02 1048100]
"0739412875"="c:\documents and settings\Cnd\Application Data\0739412875\0739412875.exe" [2009-10-03 1048611]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-02-17 17508864]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PicNotify]
2009-04-15 12:39 1167360 ----a-w- c:\windows\system32\PicNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\DDNI\\Lenovo Idea Notes\\DDNIMSGService.exe"=
"c:\\WINDOWS\\System32\\SPOOLSV.EXE"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/25/2009 11:21 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/25/2009 11:21 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/25/2009 11:20 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/25/2009 11:20 PM 297752]
R2 DDNIMSGService;DDNIMSGService;c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe [10/6/2008 11:23 AM 172720]
R2 DDNIService;DDNIService;c:\program files\DDNI\DIBS\DDNIService.exe [4/15/2009 5:30 AM 160432]
R2 System_Repair_UpdateMonitor;System Repair Windows Update Monitor;c:\program files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe [4/15/2009 5:54 AM 430080]
R2 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [4/15/2009 5:54 AM 48192]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/23/2009 9:41 PM 24652]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [4/15/2009 6:22 AM 9472]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [4/15/2009 5:20 AM 157696]
S2 AntiPol;AntiPol;c:\windows\svchast.exe --> c:\windows\svchast.exe [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [4/15/2009 5:18 AM 1684736]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [4/15/2009 5:54 AM 81192]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-08 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 22:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://aimzones.aol.com/homepage
uInternet Connection Wizard,ShellNext = hxxp://lenovo.live.com/
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
FF - ProfilePath - c:\documents and settings\Cnd\Application Data\Mozilla\Firefox\Profiles\jiwyidvz.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
BHO-{90c9a067-0a9a-4253-ae70-29f851f14e5e} - yefapuza.dll
HKLM-Run-yakajeyij - c:\windows\system32\gidobedi.dll
HKLM-Run-sufepomaro - gawojuso.dll
SharedTaskScheduler-{e00c5003-5afd-4041-8516-9227adc60baf} - c:\windows\system32\gidobedi.dll
SSODL-sudimimez-{e00c5003-5afd-4041-8516-9227adc60baf} - c:\windows\system32\gidobedi.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-08 09:56
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\PicNotify.dll
c:\windows\system32\FaceVerify.dll
c:\windows\system32\MainOp.dll
c:\windows\system32\VideoOp.dll
c:\windows\system32\Image.dll
c:\windows\system32\Momo.dll
c:\windows\system32\Apblend.dll
c:\windows\system32\SetDev.dll
c:\windows\system32\FunFrm.dll
c:\windows\system32\facev.dll
- - - - - - - > 'lsass.exe'(892)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3976)
c:\windows\system32\WININET.dll
gasfkyqmowykxd.dll 10000000 32768 \\?\globalroot\systemroot\system32\gasfkyqmowykxd.dll
c:\windows\system32\IcnOvrly.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\AVGWDSVC.EXE
c:\program files\JAVA\JRE6\BIN\JQS.EXE
c:\program files\AVG\AVG8\AVGRSX.EXE
c:\program files\AVG\AVG8\AVGNSX.EXE
c:\windows\SYSTEM32\WDFMGR.EXE
c:\program files\AVG\AVG8\AVGEMC.EXE
c:\program files\AVG\AVG8\AVGCSRVX.EXE
c:\windows\SYSTEM32\IGFXSRVC.EXE
c:\program files\AVG\AVG8\AVGTRAY.EXE
c:\program files\AIM6\aolsoftware.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-10-08 10:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-08 17:05
Pre-Run: 92,747,137,024 bytes free
Post-Run: 94,119,329,792 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
319 --- E O F --- 2009-09-17 07:57
bamajim
10.4K Posts
0
October 8th, 2009 12:00
1. Open NotePad (not wordpad). Copy and paste the following into Notepad
Driver::
AntiPol
File::
c:\documents and settings\Cnd\Local Settings\Application Data\egiweb.dat
c:\windows\awiv.com
C:\hrngen.exe
C:\prdfjhha.exe
C:\afuqr.exe
C:\avjelge.exe
C:\qgferewy.exe
c:\windows\wf4.dat
c:\windows\wf3.dat
c:\windows\system32\skynet.dat
c:\windows\system32\pump.exe
c:\windows\system32\dbsinit.exe
C:\Windows\system32\gasfkyqmowykxd.dll
Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop
Using the Image as a reference, drag CFScript into ComboFix.exe
Following the same rules as indicated in my first post
Then post the contents of the C:\ComboFix.txt log in your reply
jecameron
23 Posts
0
October 8th, 2009 18:00
Here are the latest Combofix results. BTW...thanks very much for your efforts.
ComboFix 09-10-07.05 - Cnd 10/08/2009 16:17.2.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.682 [GMT -7:00]
Running from: c:\documents and settings\Cnd\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Cnd\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FILE ::
"C:\afuqr.exe"
"C:\avjelge.exe"
"c:\documents and settings\Cnd\Local Settings\Application Data\egiweb.dat"
"C:\hrngen.exe"
"C:\prdfjhha.exe"
"C:\qgferewy.exe"
"c:\windows\awiv.com"
"c:\windows\system32\dbsinit.exe"
"c:\windows\system32\gasfkyqmowykxd.dll"
"c:\windows\system32\pump.exe"
"c:\windows\system32\skynet.dat"
"c:\windows\wf3.dat"
"c:\windows\wf4.dat"
file zipped: C:\hrngen.exe
file zipped: C:\prdfjhha.exe
file zipped: C:\qgferewy.exe
file zipped: c:\windows\system32\pump.exe
.
Overlay aborted ... Please run ComboFix once more
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\afuqr.exe
C:\avjelge.exe
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Cnd\Local Settings\Application Data\egiweb.dat
C:\hrngen.exe
C:\prdfjhha.exe
C:\qgferewy.exe
c:\windows\awiv.com
c:\windows\system32\dbsinit.exe
c:\windows\system32\pump.exe
c:\windows\system32\skynet.dat
c:\windows\wf3.dat
c:\windows\wf4.dat
----- BITS: Possible infected sites -----
hxxp://dibs.ddni.net
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ANTIPOL
-------\Service_AntiPol
((((((((((((((((((((((((( Files Created from 2009-09-08 to 2009-10-08 )))))))))))))))))))))))))))))))
.
2009-10-08 16:53 . 2008-04-14 12:42 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-08 16:31 . 2009-10-08 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\AIM Toolbar
2009-10-08 15:31 . 2009-10-08 15:31 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-10-03 07:34 . 2009-10-03 07:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\0739412875
2009-10-02 21:26 . 2009-10-08 15:53 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-02 02:14 . 2009-10-02 02:14 -------- d-----w- c:\documents and settings\Cnd\Application Data\7606509191
2009-10-02 01:40 . 2009-10-02 01:40 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-02 01:16 . 2009-10-02 01:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-02 01:14 . 2009-10-02 01:14 -------- d-----w- C:\Lenovo
2009-09-09 04:32 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 22:53 . 2009-08-26 22:53 0 ----a-w- c:\windows\nsreg.dat
2009-08-26 06:28 . 2009-05-02 06:29 15912 ----a-w- c:\documents and settings\Cnd\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 06:21 . 2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-26 06:21 . 2009-08-26 06:21 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-26 06:21 . 2009-08-26 06:21 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-26 06:21 . 2009-08-26 06:21 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\program files\AVG
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-26 05:34 . 2009-08-26 05:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\AVG8
2009-08-06 00:01 . 2004-08-04 19:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-18 10:01 . 2004-08-04 19:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 17:08 . 2004-08-04 19:00 286720 ----a-w- c:\windows\system32\wmpdxm.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-10-08_16.57.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-08 23:41 . 2009-10-08 23:41 16384 c:\windows\TEMP\Perflib_Perfdata_29c.dat
+ 2006-07-28 17:17 . 2009-10-08 23:13 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2006-07-28 17:17 . 2009-10-08 23:13 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-10-02 01:16 . 2009-10-08 23:13 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-10-02 01:16 . 2009-10-08 16:26 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2006-07-28 17:17 . 2009-10-08 23:13 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 18:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2009-04-15 12:39 241752 ----a-w- c:\windows\system32\IcnOvrly.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-23 1146880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"IdeaNotesUser"="c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe" [2009-08-24 221872]
"VeriFaceManager"="c:\program files\Lenovo\VeriFaceIII\PManage.exe" [2009-04-15 323584]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2008-07-09 4456448]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2008-08-28 1283984]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-02 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-08 2023704]
"7606509191"="c:\documents and settings\Cnd\Application Data\7606509191\7606509191.exe" [2009-10-02 1048100]
"0739412875"="c:\documents and settings\Cnd\Application Data\0739412875\0739412875.exe" [2009-10-03 1048611]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-02-17 17508864]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PicNotify]
2009-04-15 12:39 1167360 ----a-w- c:\windows\system32\PicNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\DDNI\\Lenovo Idea Notes\\DDNIMSGService.exe"=
"c:\\WINDOWS\\System32\\SPOOLSV.EXE"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/25/2009 11:21 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/25/2009 11:21 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/25/2009 11:20 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/25/2009 11:20 PM 297752]
R2 DDNIMSGService;DDNIMSGService;c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe [10/6/2008 11:23 AM 172720]
R2 DDNIService;DDNIService;c:\program files\DDNI\DIBS\DDNIService.exe [4/15/2009 5:30 AM 160432]
R2 System_Repair_UpdateMonitor;System Repair Windows Update Monitor;c:\program files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe [4/15/2009 5:54 AM 430080]
R2 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [4/15/2009 5:54 AM 48192]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/23/2009 9:41 PM 24652]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [4/15/2009 6:22 AM 9472]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [4/15/2009 5:20 AM 157696]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [4/15/2009 5:18 AM 1684736]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [4/15/2009 5:54 AM 81192]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-08 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 22:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://aimzones.aol.com/homepage
uInternet Connection Wizard,ShellNext = hxxp://lenovo.live.com/
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
FF - ProfilePath - c:\documents and settings\Cnd\Application Data\Mozilla\Firefox\Profiles\jiwyidvz.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-08 16:42
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\PicNotify.dll
c:\windows\system32\FaceVerify.dll
c:\windows\system32\MainOp.dll
c:\windows\system32\VideoOp.dll
c:\windows\system32\Image.dll
c:\windows\system32\Momo.dll
c:\windows\system32\Apblend.dll
c:\windows\system32\SetDev.dll
c:\windows\system32\FunFrm.dll
c:\windows\system32\facev.dll
- - - - - - - > 'lsass.exe'(892)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2748)
c:\windows\system32\WININET.dll
gasfkyqmowykxd.dll 10000000 32768 \\?\globalroot\systemroot\system32\gasfkyqmowykxd.dll
c:\windows\system32\IcnOvrly.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\AVGWDSVC.EXE
c:\program files\JAVA\JRE6\BIN\JQS.EXE
c:\program files\AVG\AVG8\AVGRSX.EXE
c:\program files\AVG\AVG8\AVGNSX.EXE
c:\windows\SYSTEM32\WDFMGR.EXE
c:\program files\AVG\AVG8\AVGEMC.EXE
c:\program files\AVG\AVG8\AVGCSRVX.EXE
c:\windows\SYSTEM32\IGFXSRVC.EXE
c:\program files\AVG\AVG8\AVGTRAY.EXE
c:\program files\AIM6\AOLSOFTWARE.EXE
.
**************************************************************************
.
Completion time: 2009-10-08 16:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-08 23:52
ComboFix2.txt 2009-10-08 17:06
Pre-Run: 94,119,100,416 bytes free
Post-Run: 94,120,574,976 bytes free
238 --- E O F --- 2009-09-17 07:57
Upload was successful
bamajim
10.4K Posts
0
October 9th, 2009 09:00
jecameron
Good work. Combofix had requested that it be run again to complete the job.
So, following the previous instructions with the script file rerun Combofix and post the results.
jecameron
23 Posts
0
October 10th, 2009 10:00
Here are the latest ComboFix results:
ComboFix 09-10-08.04 - Cnd 10/10/2009 8:58.3.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.674 [GMT -7:00]
Running from: c:\documents and settings\Cnd\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Cnd\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible infected sites -----
hxxp://dibs.ddni.net
.
((((((((((((((((((((((((( Files Created from 2009-09-10 to 2009-10-10 )))))))))))))))))))))))))))))))
.
2009-10-09 00:19 . 2005-08-26 02:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-10-09 00:19 . 2009-10-09 00:19 -------- d-----w- c:\program files\SpywareBlaster
2009-10-08 16:53 . 2008-04-14 12:42 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-08 16:31 . 2009-10-08 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\AIM Toolbar
2009-10-08 15:31 . 2009-10-08 15:31 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-10-03 07:34 . 2009-10-03 07:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\0739412875
2009-10-02 21:26 . 2009-10-08 15:53 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-02 02:14 . 2009-10-02 02:14 -------- d-----w- c:\documents and settings\Cnd\Application Data\7606509191
2009-10-02 01:40 . 2009-10-02 01:40 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-02 01:16 . 2009-10-02 01:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-02 01:14 . 2009-10-02 01:14 -------- d-----w- C:\Lenovo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 22:53 . 2009-08-26 22:53 0 ----a-w- c:\windows\nsreg.dat
2009-08-26 06:28 . 2009-05-02 06:29 15912 ----a-w- c:\documents and settings\Cnd\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 06:21 . 2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-26 06:21 . 2009-08-26 06:21 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-26 06:21 . 2009-08-26 06:21 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-26 06:21 . 2009-08-26 06:21 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\program files\AVG
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-26 05:34 . 2009-08-26 05:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\AVG8
2009-08-06 00:01 . 2004-08-04 19:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-18 10:01 . 2004-08-04 19:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 17:08 . 2004-08-04 19:00 286720 ----a-w- c:\windows\system32\wmpdxm.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-10-08_16.57.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-07-28 17:17 . 2009-10-10 15:55 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-07-28 17:17 . 2009-10-10 15:55 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-10-02 01:16 . 2009-10-10 15:55 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-10-02 01:16 . 2009-10-08 16:26 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2006-07-28 17:17 . 2009-10-10 15:55 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 18:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2009-04-15 12:39 241752 ----a-w- c:\windows\system32\IcnOvrly.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-23 1146880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"IdeaNotesUser"="c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe" [2009-08-24 221872]
"VeriFaceManager"="c:\program files\Lenovo\VeriFaceIII\PManage.exe" [2009-04-15 323584]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2008-07-09 4456448]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2008-08-28 1283984]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-02 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-08 2023704]
"7606509191"="c:\documents and settings\Cnd\Application Data\7606509191\7606509191.exe" [2009-10-02 1048100]
"0739412875"="c:\documents and settings\Cnd\Application Data\0739412875\0739412875.exe" [2009-10-03 1048611]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-02-17 17508864]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PicNotify]
2009-04-15 12:39 1167360 ----a-w- c:\windows\system32\PicNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\DDNI\\Lenovo Idea Notes\\DDNIMSGService.exe"=
"c:\\WINDOWS\\System32\\SPOOLSV.EXE"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/25/2009 11:21 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/25/2009 11:21 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/25/2009 11:20 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/25/2009 11:20 PM 297752]
R2 DDNIMSGService;DDNIMSGService;c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe [10/6/2008 11:23 AM 172720]
R2 DDNIService;DDNIService;c:\program files\DDNI\DIBS\DDNIService.exe [4/15/2009 5:30 AM 160432]
R2 System_Repair_UpdateMonitor;System Repair Windows Update Monitor;c:\program files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe [4/15/2009 5:54 AM 430080]
R2 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [4/15/2009 5:54 AM 48192]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/23/2009 9:41 PM 24652]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [4/15/2009 6:22 AM 9472]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [4/15/2009 5:20 AM 157696]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [4/15/2009 5:18 AM 1684736]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [4/15/2009 5:54 AM 81192]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-09 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 22:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://aimzones.aol.com/homepage
uInternet Connection Wizard,ShellNext = hxxp://lenovo.live.com/
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
FF - ProfilePath - c:\documents and settings\Cnd\Application Data\Mozilla\Firefox\Profiles\jiwyidvz.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
AddRemove-HijackThis - c:\documents and settings\Cnd\Desktop\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-10 09:17
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(840)
c:\windows\system32\PicNotify.dll
c:\windows\system32\FaceVerify.dll
c:\windows\system32\MainOp.dll
c:\windows\system32\VideoOp.dll
c:\windows\system32\Image.dll
c:\windows\system32\Momo.dll
c:\windows\system32\Apblend.dll
c:\windows\system32\SetDev.dll
c:\windows\system32\FunFrm.dll
c:\windows\system32\facev.dll
- - - - - - - > 'lsass.exe'(896)
c:\windows\system32\WININET.dll
.
Completion time: 2009-10-10 9:23
ComboFix-quarantined-files.txt 2009-10-10 16:23
ComboFix2.txt 2009-10-08 23:55
ComboFix3.txt 2009-10-08 17:06
Pre-Run: 94,108,712,960 bytes free
Post-Run: 94,105,305,088 bytes free
184 --- E O F --- 2009-09-17 07:57
bamajim
10.4K Posts
0
October 12th, 2009 14:00
jecameron
That looks better. Rerun Hijackthis and post a fresh Hiajcktis log.
And in your reply give me an update on how your PC is running now.
jecameron
23 Posts
0
October 13th, 2009 21:00
There are a number of remaining issues:
1) Strange Tray icon
-- when I boot, there is a strange icon in the tray; it looks like a little red shield with a cross in it; when I point at the icon, it disappears
2) Strange Desktop icon
-- there is a strange Desktop icon called “Security Tool”; it is a shortcut to:
C:\Documents and Settings\Cnd\Application Data\0739412875\0739412875.exe
-- I cannot find a Cnd sub-folder in the Documents and Settings folder, and therefore cannot find the .exe file; I’m using Windows Explorer
-- I deleted the shortcut icon from the Desktop, but it re-appears after booting
3) Desktop icons disappear
-- when I boot, the Desktop icons appear for about ten seconds, then disappear; so my Desktop is basically a blue screen with the Start button and the Taskbar
-- apparently something has taken over the explorer.exe file in the C:\Windows folder; I can rename or delete the explorer.exe file using Windows Explorer and it reappears in the file list after a few seconds; I was going to rename explorer.exe and copy a version from another computer running XP, but almost immediately after I renamed the file, it re-appeared as explorer.exe in the file list
4) Search engine problem
-- when I use a search engine, there is a strange problem that occurs sometimes; I enter a search keyword and get a hit list; when I click one of the links in the hit list, I’m taken to an advertising site; it happens in both Internet Explorer and Firefox; it happens in both Google and Bing
-- I do not have any problems if I type a URL in the Address Box.
These are the weird things that I have identified so far. My netbook remains pretty much unusable.
Again, thanks very much for your assistance.
Here is the latest HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:20:09 PM, on 10/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe
C:\Program Files\DDNI\DIBS\DDNIService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe
C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://aimzones.aol.com/homepage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://lenovo.live.com/
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{03402f96-3dc7-4285-bc50-9e81fefafe43} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IdeaNotesUser] C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files\Lenovo\VeriFaceIII\PManage.exe
O4 - HKLM\..\Run: [EnergyUtility] C:\Program Files\Lenovo\Energy Management\utility.exe
O4 - HKLM\..\Run: [Energy Management] C:\Program Files\Lenovo\Energy Management\Energy Management.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [7606509191] C:\Documents and Settings\Cnd\Application Data\7606509191\7606509191.exe
O4 - HKLM\..\Run: [0739412875] C:\Documents and Settings\Cnd\Application Data\0739412875\0739412875.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/jdk/6u13-b03/jinstall-6u13-windows-i586-jc.cab?e=1241247500030&h=2833b30abb1974eb4cdadb10158b4033/&filename=jinstall-6u13-windows-i586-jc.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: PicNotify - C:\WINDOWS\SYSTEM32\PicNotify.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DDNIMSGService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe
O23 - Service: DDNIService - Digital Delivery Networks, Inc. - C:\Program Files\DDNI\DIBS\DDNIService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: System Repair Windows Update Monitor (System_Repair_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 7984 bytes
bamajim
10.4K Posts
0
October 14th, 2009 08:00
We still have a few things to do, and thanks for the update. This infection leaves a lot of trash behind.
We are going to create another script for Combofix
1. Open NotePad (not wordpad). Copy and paste the following into Notepad
Folder::
c:\documents and settings\Cnd\Application Data\0739412875
c:\documents and settings\Cnd\Application Data\7606509191
Registry::
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"=-
"NoActiveDesktopChanges"=-
[-HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop
Using the Image as a reference, drag CFScript into ComboFix.exe
Following the same rules as indicated in my first post
Then post the contents of the C:\ComboFix.txt log in your reply
jecameron
23 Posts
0
October 14th, 2009 12:00
Latest ComboFix results:
ComboFix 09-10-13.04 - Cnd 10/14/2009 10:59.4.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.657 [GMT -7:00]
Running from: E:\ComboFix.exe
Command switches used :: E:\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Cnd\Application Data\0739412875
c:\documents and settings\Cnd\Application Data\0739412875\0739412875.bat
c:\documents and settings\Cnd\Application Data\0739412875\0739412875.cfg
c:\documents and settings\Cnd\Application Data\0739412875\0739412875.exe
c:\documents and settings\Cnd\Application Data\7606509191
c:\documents and settings\Cnd\Application Data\7606509191\7606509191.bat
c:\documents and settings\Cnd\Application Data\7606509191\7606509191.cfg
c:\documents and settings\Cnd\Application Data\7606509191\7606509191.exe
c:\documents and settings\Cnd\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk
c:\documents and settings\Cnd\Desktop\Security Tool.lnk
c:\documents and settings\Cnd\Start Menu\Programs\Security Tool.lnk
c:\windows\system32\nuar.old
----- BITS: Possible infected sites -----
hxxp://dibs.ddni.net
.
((((((((((((((((((((((((( Files Created from 2009-09-14 to 2009-10-14 )))))))))))))))))))))))))))))))
.
2009-10-14 02:19 . 2009-10-14 02:19 -------- d-----w- c:\program files\Trend Micro
2009-10-12 14:11 . 2007-06-13 10:23 1033216 ----a-w- c:\windows\explorer.exe
2009-10-09 00:19 . 2005-08-26 02:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-10-09 00:19 . 2009-10-09 00:19 -------- d-----w- c:\program files\SpywareBlaster
2009-10-08 16:53 . 2008-04-14 12:42 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-08 16:31 . 2009-10-08 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\AIM Toolbar
2009-10-08 15:31 . 2009-10-08 15:31 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-10-02 21:26 . 2009-10-12 14:06 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-02 01:40 . 2009-10-02 01:40 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-02 01:16 . 2009-10-02 01:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-02 01:14 . 2009-10-02 01:14 -------- d-----w- C:\Lenovo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 22:53 . 2009-08-26 22:53 0 ----a-w- c:\windows\nsreg.dat
2009-08-26 06:28 . 2009-05-02 06:29 15912 ----a-w- c:\documents and settings\Cnd\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 06:21 . 2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-26 06:21 . 2009-08-26 06:21 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-26 06:21 . 2009-08-26 06:21 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-26 06:21 . 2009-08-26 06:21 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\program files\AVG
2009-08-26 06:20 . 2009-08-26 06:20 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-26 05:34 . 2009-08-26 05:34 -------- d-----w- c:\documents and settings\Cnd\Application Data\AVG8
2009-08-06 00:01 . 2004-08-04 19:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-18 10:01 . 2004-08-04 19:00 58880 ----a-w- c:\windows\system32\atl.dll
.
------- Sigcheck -------
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\ERDNT\cache\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\explorer.exe
[7] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\explorer.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-10-08_16.57.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-07-28 17:17 . 2009-10-14 17:55 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-07-28 17:17 . 2009-10-14 17:55 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-07-28 17:17 . 2009-10-08 16:31 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-10-02 01:16 . 2009-10-14 17:16 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-10-02 01:16 . 2009-10-08 16:26 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2006-07-28 17:17 . 2009-10-14 17:55 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2004-08-04 19:00 . 2008-04-14 12:42 1033728 c:\windows\explorer-old.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 18:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2009-04-15 12:39 241752 ----a-w- c:\windows\system32\IcnOvrly.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-05-23 1146880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"IdeaNotesUser"="c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe" [2009-08-24 221872]
"VeriFaceManager"="c:\program files\Lenovo\VeriFaceIII\PManage.exe" [2009-04-15 323584]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2008-07-09 4456448]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2008-08-28 1283984]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-02 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-08 2023704]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-02-17 17508864]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-26 06:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PicNotify]
2009-04-15 12:39 1167360 ----a-w- c:\windows\system32\PicNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C:\0autocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\DDNI\\Lenovo Idea Notes\\DDNIMSGService.exe"=
"c:\\WINDOWS\\System32\\SPOOLSV.EXE"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/25/2009 11:21 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/25/2009 11:21 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/25/2009 11:20 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/25/2009 11:20 PM 297752]
R2 DDNIMSGService;DDNIMSGService;c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe [10/6/2008 11:23 AM 172720]
R2 DDNIService;DDNIService;c:\program files\DDNI\DIBS\DDNIService.exe [4/15/2009 5:30 AM 160432]
R2 System_Repair_UpdateMonitor;System Repair Windows Update Monitor;c:\program files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe [4/15/2009 5:54 AM 430080]
R2 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [4/15/2009 5:54 AM 48192]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/23/2009 9:41 PM 24652]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [4/15/2009 6:22 AM 9472]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [4/15/2009 5:20 AM 157696]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [4/15/2009 5:18 AM 1684736]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [4/15/2009 5:54 AM 81192]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-14 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 22:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://aimzones.aol.com/homepage
uInternet Connection Wizard,ShellNext = hxxp://lenovo.live.com/
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
FF - ProfilePath - c:\documents and settings\Cnd\Application Data\Mozilla\Firefox\Profiles\jiwyidvz.default\
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-7606509191 - c:\documents and settings\Cnd\Application Data\7606509191\7606509191.exe
HKLM-Run-0739412875 - c:\documents and settings\Cnd\Application Data\0739412875\0739412875.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-14 11:18
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\PicNotify.dll
c:\windows\system32\FaceVerify.dll
c:\windows\system32\MainOp.dll
c:\windows\system32\VideoOp.dll
c:\windows\system32\Image.dll
c:\windows\system32\Momo.dll
c:\windows\system32\Apblend.dll
c:\windows\system32\SetDev.dll
c:\windows\system32\FunFrm.dll
c:\windows\system32\facev.dll
- - - - - - - > 'lsass.exe'(900)
c:\windows\system32\WININET.dll
.
Completion time: 2009-10-14 11:28
ComboFix-quarantined-files.txt 2009-10-14 18:28
ComboFix2.txt 2009-10-10 16:23
ComboFix3.txt 2009-10-08 23:55
ComboFix4.txt 2009-10-08 17:06
Pre-Run: 94,057,922,560 bytes free
Post-Run: 94,099,570,688 bytes free
201 --- E O F --- 2009-09-17 07:57
bamajim
10.4K Posts
0
October 15th, 2009 07:00
Good work
Please perform a BitDefender Online Virus and Malware Scan here:
* Click on I Agree.
* An ActiveX warning box will appear, click on Install.
* Under Select What You Want To Check For Viruses.
* Please Check My Computer and Click Ok
* Now Click On Click Here To Scan
* Next, Click on Click here to export the scan report
* Save it to your Desktop.
* In your next reply, please include the BitDefender log.
jecameron
23 Posts
0
October 15th, 2009 09:00
Here is the Bit Defender log:
BitDefender Online Scanner
Scan report generated at: Thu, Oct 15, 2009 - 08:05:48
Scan path: C:\Documents and Settings\Cnd\My Documents;C:\Documents and Settings\All Users\Documents;C:\;D:\;C:\Documents and Settings\Cnd\My Documents;C:\Documents and Settings\Cnd\Desktop\New York;C:\Documents and Settings\Cnd\Desktop\Favorites;
Statistics
Time
00:52:06
Files
177311
Folders
3318
Boot Sectors
0
Archives
7276
Packed Files
8209
Results
Identified Viruses
21
Infected Files
35
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
34
Engines Info
Virus Definitions
4349177
Engine build
AVCORE v2.1 Windows/i386 11.0.0.26 (Aug 27 2009)
Scan plugins
17
Archive plugins
44
Unpack plugins
8
E-mail plugins
6
System plugins
4
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\System Volume Information\_restore{F8136B96-1D4C-4145-839F-7B8F940A9052}\RP23\A0005315.dll
Infected with: Trojan.Generic.2474880
C:\System Volume Information\_restore{F8136B96-1D4C-4145-839F-7B8F940A9052}\RP23\A0005315.dll
Deleted
C:\Lenovo\OneKey App\System Repair\UF\WINDOWS\system32\eventlog.dll
Infected with: Trojan.Generic.2492473
C:\Lenovo\OneKey App\System Repair\UF\WINDOWS\system32\eventlog.dll
Deleted
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\lizkavd.exe.vir
Infected with: Gen:Packed.FakeAV.3
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\lizkavd.exe.vir
Disinfection failed
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\lizkavd.exe.vir
Deleted
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\seres.exe.vir
Infected with: Win32.KME.Based.1.Gen
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\seres.exe.vir
Disinfection failed
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\seres.exe.vir
Deleted
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\svcst.exe.vir
Infected with: Win32.KME.Based.1.Gen
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\svcst.exe.vir
Disinfection failed
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\svcst.exe.vir
Deleted
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\0739412875\0739412875.exe.vir
Infected with: Trojan.CryptRedol.Gen.5
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\0739412875\0739412875.exe.vir
Disinfection failed
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\0739412875\0739412875.exe.vir
Deleted
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\7606509191\7606509191.exe.vir
Infected with: Trojan.CryptRedol.Gen.5
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\7606509191\7606509191.exe.vir
Disinfection failed
C:\Qoobox\Quarantine\C\Documents and Settings\Cnd\Application Data\7606509191\7606509191.exe.vir
Deleted
C:\Qoobox\Quarantine\C\Program Files\AdvancedVirusRemover\PAVRM.exe.vir
Infected with: Trojan.Generic.2506199
C:\Qoobox\Quarantine\C\Program Files\AdvancedVirusRemover\PAVRM.exe.vir
Deleted
C:\Qoobox\Quarantine\C\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe.vir
Infected with: Gen:Packed.FakeAV.3
C:\Qoobox\Quarantine\C\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe.vir
Disinfection failed
C:\Qoobox\Quarantine\C\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\_scui.cpl.vir
Infected with: Trojan.Generic.2501728
C:\Qoobox\Quarantine\C\WINDOWS\system32\_scui.cpl.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\~.exe.vir
Infected with: Trojan.Agent.ANPU
C:\Qoobox\Quarantine\C\WINDOWS\system32\~.exe.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\biravoja.dll.vir
Infected with: Trojan.Generic.2506343
C:\Qoobox\Quarantine\C\WINDOWS\system32\biravoja.dll.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\bozoyipo.exe.vir
Infected with: Trojan.CryptRedol.Gen.5
C:\Qoobox\Quarantine\C\WINDOWS\system32\bozoyipo.exe.vir
Disinfection failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\bozoyipo.exe.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\febobafi.dll.vir
Infected with: Gen:Trojan.Heur.TDSS.bu4@iyVm4nii
C:\Qoobox\Quarantine\C\WINDOWS\system32\febobafi.dll.vir
Disinfection failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\febobafi.dll.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\gawarege.dll.tmp.vir
Infected with: Trojan.Vundo.GMM
C:\Qoobox\Quarantine\C\WINDOWS\system32\gawarege.dll.tmp.vir
Disinfection failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\gawarege.dll.tmp.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\gawojuso.dll.vir
Infected with: Trojan.Vundo.GMM
C:\Qoobox\Quarantine\C\WINDOWS\system32\gawojuso.dll.vir
Disinfection failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\gawojuso.dll.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\kiduruka.dll.vir
Infected with: Trojan.Generic.2507159
C:\Qoobox\Quarantine\C\WINDOWS\system32\kiduruka.dll.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\losorede.dll.vir
Infected with: Trojan.Generic.2506345
C:\Qoobox\Quarantine\C\WINDOWS\system32\losorede.dll.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\mifolole.exe.vir
Infected with: Trojan.CryptRedol.Gen.5
C:\Qoobox\Quarantine\C\WINDOWS\system32\mifolole.exe.vir
Disinfection failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\mifolole.exe.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\nadusajo.dll.vir
Infected with: Trojan.Vundo.GMM
C:\Qoobox\Quarantine\C\WINDOWS\system32\nadusajo.dll.vir
Disinfection failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\nadusajo.dll.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\nivumosi.dll.tmp.vir
Infected with: Trojan.Vundo.GMM
C:\Qoobox\Quarantine\C\WINDOWS\system32\nivumosi.dll.tmp.vir
Disinfection failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\nivumosi.dll.tmp.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\royoneyu.dll.tmp.vir
Infected with: Trojan.Vundo.GMM
C:\Qoobox\Quarantine\C\WINDOWS\system32\royoneyu.dll.tmp.vir
Disinfection failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\royoneyu.dll.tmp.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\wafiguvu.dll.vir
Infected with: Trojan.Vundo.GMM
C:\Qoobox\Quarantine\C\WINDOWS\system32\wafiguvu.dll.vir
Disinfection failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\wafiguvu.dll.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\wbem\proquota.exe.vir
Infected with: Trojan.Agent.ANPT
C:\Qoobox\Quarantine\C\WINDOWS\system32\wbem\proquota.exe.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\winhelper.dll.vir
Infected with: Trojan.FakeAlert.TK
C:\Qoobox\Quarantine\C\WINDOWS\system32\winhelper.dll.vir
Disinfection failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\winhelper.dll.vir
Delete failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\wispex.html.vir
Infected with: Trojan.Script.212078
C:\Qoobox\Quarantine\C\WINDOWS\system32\wispex.html.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\yefapuza.dll.vir
Infected with: Trojan.Vundo.GMM
C:\Qoobox\Quarantine\C\WINDOWS\system32\yefapuza.dll.vir
Disinfection failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\yefapuza.dll.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\zitakihu.exe.vir
Infected with: Trojan.CryptRedol.Gen.5
C:\Qoobox\Quarantine\C\WINDOWS\system32\zitakihu.exe.vir
Disinfection failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\zitakihu.exe.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\eventlog.dll.vir
Infected with: Trojan.Generic.2492473
C:\Qoobox\Quarantine\C\WINDOWS\system32\eventlog.dll.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\dbsinit.exe.vir=>(RAR Sfx o)=>wispex.html
Infected with: Trojan.Script.212078
C:\Qoobox\Quarantine\C\WINDOWS\system32\dbsinit.exe.vir=>(RAR Sfx o)=>wispex.html
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\dbsinit.exe.vir=>(RAR Sfx o)
Update failed
C:\Qoobox\Quarantine\C\WINDOWS\system32\pump.exe.vir
Infected with: Trojan.Generic.IS.611245
C:\Qoobox\Quarantine\C\WINDOWS\system32\pump.exe.vir
Deleted
C:\Qoobox\Quarantine\C\afuqr.exe.vir
Infected with: Trojan.Generic.2502308
C:\Qoobox\Quarantine\C\afuqr.exe.vir
Deleted
C:\Qoobox\Quarantine\C\avjelge.exe.vir
Infected with: Trojan.Generic.2507281
C:\Qoobox\Quarantine\C\avjelge.exe.vir
Deleted
C:\Qoobox\Quarantine\C\hrngen.exe.vir
Infected with: Trojan.FakeAlert.BNR
C:\Qoobox\Quarantine\C\hrngen.exe.vir
Deleted
C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)=>install.exe
Infected with: Gen:Trojan.Heur.Rustock.1
C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)=>install.exe
Disinfection failed
C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)=>install.exe
Deleted
C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)
Update failed
bamajim
10.4K Posts
0
October 15th, 2009 10:00
jecameron
How is your PC running now?
jecameron
23 Posts
0
October 16th, 2009 09:00
My computer is running much better, thank you. I have re-run the BitDefender scan multiple times and each time
it finds something new. Is this normal?
The screens at BitDefender have changed. Here is a suggested procedure for running the BitDefender scan:
Please perform a BitDefender Online Virus and Malware Scan here:
* Click Start Scanner.
* Click I Agree… and Start Here.
* An ActiveX warning box will appear; click Install.
* Options displayed are Folders to Scan and Cleaning Options; click Folders to Scan.
* Select folders to be scanned by clicking check boxes; click OK.
* Click Start Scan.
* After the scan has completed, click Click here to export the scan report.
* Save the report to your Desktop.
* In your next reply, please include the BitDefender log.
The following issue remains:
Search engine problem
-- when I use a search engine, there is a strange problem that occurs sometimes; I enter a search keyword and
get a hit list; when I click one of the links in the hit list, I’m taken to an advertising site; it happens in
both Internet Explorer and Firefox; it happens in both Google and Bing
I also downloaded and tried to run Ad-Aware. Ad-Aware identifies a major problem that BitDefender does
not find. Ad-Aware tells me to reboot to remove the problem, but when I reboot, the Ad-Watch feature
of Ad-Aware causes Ad-Aware to automatically start a scan and re-identifies the same problem. So, I'm in
a tight loop. Here is the Ad-Aware log for what it's worth:
Logfile created: 10/15/2009 19:17:39
Lavasoft Ad-Aware version: 8.1.0
Extended engine: 191738264
Extended engine version:
User performing scan: Cnd
*********************** Definitions database information ***********************
Lavasoft definition file: 149.72
Genotype definition file version: 2009/10/05 15:03:45
******************************** Scan results: *********************************
Scan profile name: Smart Scan (ID: smart)
Objects scanned: 8668
Objects detected: 1
Type Detected
==========================
Processes.......: 1
Registry entries: 0
Hostfile entries: 0
Files...........: 0
Folders.........: 0
LSPs............: 0
Cookies.........: 0
Browser hijacks.: 0
MRU objects.....: 0
Quarantined items:
Description: \\?\globalroot\systemroot\system32\gasfkyqmowykxd.dll Family Name: Win32.Trojan.Tdss Engine: 1 Clean status: Reboot required Item ID: 1622997 Family ID: 5401
Scan and cleaning complete: Finished correctly after 52 seconds
Again, thanks so much for all your help.
====================================================================
Here is the latest BitDefender log:
BitDefender Online Scanner
Scan report generated at: Fri, Oct 16, 2009 - 08:30:10
Scan path: C:\Documents and Settings\Cnd\My Documents;C:\Documents and Settings\All Users\Documents;C:\;D:\;C:\Documents and Settings\Cnd\My Documents;C:\Documents and Settings\Cnd\Desktop\New York;C:\Documents and Settings\Cnd\Desktop\Favorites;
Statistics
Time
00:47:23
Files
177682
Folders
3536
Boot Sectors
0
Archives
7323
Packed Files
8177
Results
Identified Viruses
3
Infected Files
3
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
3
Engines Info
Virus Definitions
4355376
Engine build
AVCORE v2.1 Windows/i386 11.0.0.26 (Aug 27 2009)
Scan plugins
17
Archive plugins
44
Unpack plugins
8
E-mail plugins
6
System plugins
4
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Qoobox\Quarantine\C\WINDOWS\system32\plugie.dll.vir
Infected with: Trojan.Generic.2528887
C:\Qoobox\Quarantine\C\WINDOWS\system32\plugie.dll.vir
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\dbsinit.exe.vir=>(RAR Sfx o)=>wispex.html
Infected with: Trojan.Script.212078
C:\Qoobox\Quarantine\C\WINDOWS\system32\dbsinit.exe.vir=>(RAR Sfx o)=>wispex.html
Deleted
C:\Qoobox\Quarantine\C\WINDOWS\system32\dbsinit.exe.vir=>(RAR Sfx o)
Update failed
C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)=>install.exe
Infected with: Gen:Trojan.Heur.Rustock.1
C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)=>install.exe
Disinfection failed
C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)=>install.exe
Deleted
C:\Qoobox\Quarantine\C\prdfjhha.exe.vir=>(RAR Sfx o)
Update failed
bamajim
10.4K Posts
0
October 16th, 2009 10:00
Is this what AdAware keeps finding?
I'm not concerned with what BitDefender found in C:\Qoobox\Quarantine\ they can do no harm there
And do you use a router?