Unsolved

This post is more than 5 years old

7 Posts

1012

February 8th, 2008 13:00

HiJack This and ComboFix Logs.

I am still seeing packets being sent out of the computer. ComboFix did a lot to solve some of the MalWare stuff, but I have a feeling there si still somethign here. Can someone look at these and let me knwo what else I need to do? Thanks,

     -Rick

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:54:24 AM, on 2/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\NALNTSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wm.exe
C:\NOVELL\ZENRC\WUOLService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\System32\dpmw32.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trillian\trillian.exe
C:\Documents and Settings\rcopes\Desktop\HiJackThis_v2.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182179388984
O16 - DPF: {7BE30DB7-4BB6-41A7-BE9C-EB9EB45725DE} (WebCamX Control) - http://208.42.209.86/WebCamX.cab
O16 - DPF: {F92211F4-3913-4DC2-A275-756374D848B0} (ERViewerOCX Control) - http://66.112.17.174/MP4DVR.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D879E850-F59A-4357-8526-139D1D099036}: NameServer = 209.142.136.85,208.42.196.36
O21 - SSODL: BurnWin - {C145CF11-124F-3562-44AC-E685D962C63C} - C:\WINDOWS\system32\apiuser32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\System32\cusrvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINDOWS\System32\NALNTSRV.EXE
O23 - Service: Remote management (Novell WUser Agent) - Novell, Inc. - C:\NOVELL\ZENRC\wuser32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINDOWS\System32\wm.exe
O23 - Service: WUOLservice (WUOLService) - Novell, Inc. - C:\NOVELL\ZENRC\WUOLService.exe

--
End of file - 8119 bytes

---------------------------------------------------------------------------------------------------------

7 Posts

February 8th, 2008 13:00

This was too big to add to the other post. Here it is:

.
(((((((((((((((((((((((((   Files Created from 2008-01-07 to 2008-02-07  )))))))))))))))))))))))))))))))
.

2008-02-07 14:27 . 2008-02-07 14:33        d--------    C:\WINDOWS\system32\acespy
2008-02-07 14:27 . 2008-02-07 14:33        d--------    C:\Program Files\p2pnetworks
2008-02-07 14:27 . 2008-02-07 14:33        d--------    C:\Program Files\e-zshopper
2008-02-07 14:27 . 2008-02-07 14:33        d--------    C:\Program Files\amsys
2008-02-07 14:27 . 2008-02-07 14:33        d--------    C:\Program Files\akl
2008-02-07 14:27 . 2008-02-07 14:33        d--------    C:\Program Files\Accoona
2008-02-07 14:27 . 2008-02-07 14:33        d--------    C:\Program Files\3721
2008-02-07 12:23 . 2008-02-07 12:23        d--------    C:\Program Files\ZoneAlarmSB
2008-02-07 11:37 . 2008-02-07 11:37        d--------    C:\Program Files\Windows Defender
2008-02-06 22:17 . 2008-02-06 22:17        d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-06 22:16 . 2008-02-07 10:37        d--------    C:\Program Files\SUPERAntiSpyware
2008-02-06 22:16 . 2008-02-06 22:16        d--------    C:\Program Files\Common Files\Wise Installation Wizard
2008-02-06 22:16 . 2008-02-06 22:16        d--------    C:\Documents and Settings\rcopes\Application Data\SUPERAntiSpyware.com
2008-02-06 11:05 . 2008-02-06 11:05    0    --a------    C:\SDFix.exe
2008-02-06 10:17 . 2008-02-06 10:17        d--------    C:\Documents and Settings\rcopes\.DownloadManager
2008-02-06 10:04 . 2008-02-06 10:04    3,791,542    --a------    C:\WINDOWS\pf1rwdL5zk.exe
2008-02-06 10:03 . 2008-02-06 10:03        d--------    C:\WINDOWS\efmhfrct
2008-02-06 10:03 . 2008-02-06 10:03    256,000    --a------    C:\WINDOWS\system32\apiuser32.dll
2008-02-06 10:03 . 2008-02-06 10:03    182,272    --a------    C:\WINDOWS\kjafwdkb.dll
2008-02-06 10:03 . 2008-02-06 10:03    89,617    ---------    C:\WINDOWS\system32\rxjddnvj.exe
2008-02-06 10:03 . 2008-02-06 10:03    89,617    --a------    C:\WINDOWS\jmjyjids.exe
2008-02-06 10:03 . 2008-02-06 10:03    58,368    --a------    C:\wpohl.exe
2008-02-06 10:03 .     54,764        C:\WINDOWS\system32\jnhjkfrn
2008-02-06 10:03 . 2008-02-06 10:03    32,768    --a------    C:\arbfikac.exe
2008-02-06 10:03 . 2008-02-07 14:32    0    --a------    C:\reg.reg
2008-01-25 15:46 . 2008-01-25 15:46        d--------    C:\Pass
2008-01-15 09:03 . 2008-01-15 09:04        d--------    C:\Program Files\CCleaner
2008-01-14 15:21 . 2008-01-14 15:21        d-a------    C:\Lattis.pro

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-07 20:31    ---------    d-----w    C:\Program Files\Symantec AntiVirus
2008-02-07 20:28    3,116    --sha-w    C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-07 20:28    180,256    --sha-w    C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-07 20:27    9,472    ----a-w    C:\WINDOWS\system32\ESHOPEE.exe
2008-02-07 20:27    9,472    ----a-w    C:\WINDOWS\cbinst$.exe
2008-02-07 20:27    8,704    ----a-w    C:\WINDOWS\liqad.exe
2008-02-07 20:27    8,448    ----a-w    C:\WINDOWS\liqui-Uninstaller.exe
2008-02-07 20:27    8,448    ----a-w    C:\WINDOWS\kvnab.dll
2008-02-07 20:27    31,744    ----a-w    C:\WINDOWS\daxtime.dll
2008-02-07 20:27    31,232    ----a-w    C:\WINDOWS\hotporn.exe
2008-02-07 20:27    30,208    ----a-w    C:\WINDOWS\iexplorr23.dll
2008-02-07 20:27    29,440    ----a-w    C:\WINDOWS\wbeCheck.exe
2008-02-07 20:27    29,184    ----a-w    C:\WINDOWS\fhfmm-Uninstaller.exe
2008-02-07 20:27    28,672    ----a-w    C:\WINDOWS\ngd.dll
2008-02-07 20:27    27,136    ----a-w    C:\WINDOWS\aconti.exe
2008-02-07 20:27    26,368    ----a-w    C:\WINDOWS\eventlowg.dll
2008-02-07 20:27    26,112    ----a-w    C:\WINDOWS\hcwprn.exe
2008-02-07 20:27    22,784    ----a-w    C:\WINDOWS\dp0.dll
2008-02-07 20:27    22,528    ----a-w    C:\WINDOWS\system32\msole32.exe
2008-02-07 20:27    22,528    ----a-w    C:\WINDOWS\liqui.exe
2008-02-07 20:27    22,272    ----a-w    C:\WINDOWS\xxxvideo.exe
2008-02-07 20:27    20,992    ----a-w    C:\WINDOWS\kvnab$.exe
2008-02-07 20:27    20,736    ----a-w    C:\WINDOWS\pbsysie.dll
2008-02-07 20:27    20,224    ----a-w    C:\WINDOWS\fhfmm.exe
2008-02-07 20:27    19,968    ----a-w    C:\WINDOWS\spredirect.dll
2008-02-07 20:27    19,712    ----a-w    C:\WINDOWS\liqad.dll
2008-02-07 20:27    16,896    ----a-w    C:\WINDOWS\vxddsk.exe
2008-02-07 20:27    16,896    ----a-w    C:\WINDOWS\kvnab.exe
2008-02-07 20:27    16,128    ----a-w    C:\WINDOWS\xadbrk.dll
2008-02-07 20:27    16,128    ----a-w    C:\WINDOWS\adbar.dll
2008-02-07 20:27    15,872    ----a-w    C:\WINDOWS\pbar.dll
2008-02-07 20:27    14,848    ----a-w    C:\WINDOWS\jd2002.dll
2008-02-07 20:27    14,848    ----a-w    C:\WINDOWS\764.exe
2008-02-07 20:27    14,336    ----a-w    C:\WINDOWS\7search.dll
2008-02-07 20:27    14,080    ----a-w    C:\WINDOWS\liqui.dll
2008-02-07 20:27    13,824    ----a-w    C:\WINDOWS\ie_32.exe
2008-02-07 20:27    13,312    ----a-w    C:\WINDOWS\wml.exe
2008-02-07 20:27    13,056    ----a-w    C:\WINDOWS\xadbrk_.exe
2008-02-07 20:27    13,056    ----a-w    C:\WINDOWS\kkcomp.dll
2008-02-07 20:27    12,800    ----a-w    C:\WINDOWS\wbeInst$.exe
2008-02-07 20:27    12,032    ----a-w    C:\WINDOWS\kkcomp$.exe
2008-02-07 20:27    11,008    ----a-w    C:\WINDOWS\xadbrk.exe
2008-02-07 20:27    10,752    ----a-w    C:\WINDOWS\settn.dll
2008-02-07 20:27    10,752    ----a-w    C:\WINDOWS\flt.dll
2008-02-07 20:27    10,496    ----a-w    C:\WINDOWS\system32\ace16win.dll
2008-02-07 20:27    10,496    ----a-w    C:\WINDOWS\kkcomp.exe
2008-02-07 20:27    10,240    ----a-w    C:\WINDOWS\liqad$.exe
2008-02-07 18:25    20,149,491    ----a-w    C:\WINDOWS\Internet Logs\tvDebug.zip
2008-02-07 16:30    ---------    d-----w    C:\Program Files\Spybot - Search & Destroy
2008-02-07 16:27    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-06 06:03    85,504    ----a-w    C:\WINDOWS\system32\VACFix.exe
2008-02-01 22:26    ---------    d-----w    C:\Program Files\Trillian
2008-01-27 20:37    81,920    ----a-w    C:\WINDOWS\system32\IEDFix.exe
2008-01-15 15:15    ---------    d-----w    C:\Program Files\Yahoo!
2007-11-21 00:35    28,032    ----a-w    C:\Documents and Settings\rcopes\Application Data\GDIPFONTCACHEV1.DAT
2007-11-14 22:05    75,248    ----a-w    C:\WINDOWS\zllsputility.exe
2007-11-14 22:05    1,086,952    ----a-w    C:\WINDOWS\system32\zpeng24.dll
2007-11-07 09:26    721,920    ----a-w    C:\WINDOWS\system32\lsasrv.dll
2007-11-01 14:57    2,904,576    ----a-w    C:\WINDOWS\Internet Logs\xDBA.tmp
2007-11-01 14:57    1,302,528    ----a-w    C:\WINDOWS\Internet Logs\xDBB.tmp
2007-07-12 13:00    1,498,624    ----a-w    C:\WINDOWS\Internet Logs\xDB8.tmp
2007-07-12 12:59    1,498,624    ----a-w    C:\WINDOWS\Internet Logs\xDB9.tmp
2007-06-18 19:03    68,489    ----a-w    C:\WINDOWS\Internet Logs\vsmon_2nd_2007_06_18_13_59_26_small.dmp.zip
2007-06-14 04:45    1,568    ----a-w    C:\Documents and Settings\rcopes\Application Data\mpauth.dat
2007-06-08 21:34    2,634,752    ----a-w    C:\WINDOWS\Internet Logs\xDB7.tmp
2007-04-03 21:13    1,399,296    ----a-w    C:\WINDOWS\Internet Logs\xDB6.tmp
2006-10-09 15:48    2,640,896    ----a-w    C:\WINDOWS\Internet Logs\xDB4.tmp
2006-10-09 15:48    1,336,832    ----a-w    C:\WINDOWS\Internet Logs\xDB5.tmp
2006-10-03 06:43    2,402,550    ----a-w    C:\WINDOWS\inf\SET59.tmp
2006-08-22 18:24    1,307,136    ----a-w    C:\WINDOWS\Internet Logs\xDB3.tmp
2006-08-04 12:37    1,296,896    ----a-w    C:\WINDOWS\Internet Logs\xDB2.tmp
2006-07-05 21:13    1,264,640    ----a-w    C:\WINDOWS\Internet Logs\xDB1.tmp
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0000DE80-AEC3-70C3-4176-CE509063E000}]
            C:\WINDOWS\System32\mscorews.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2008-02-07 12:23    262144    --a------    C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-02-07 12:23 262144]

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2005-02-15 08:02 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2005-02-15 08:02 126976]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-12-30 14:19 120640]
"NDPS"="C:\WINDOWS\System32\dpmw32.exe" [2004-05-17 14:27 32859]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 10:37 28672 C:\WINDOWS\system32\nwtray.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"BurnWin"= {C145CF11-124F-3562-44AC-E685D962C63C} - C:\WINDOWS\system32\apiuser32.dll [2008-02-06 10:03 256000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="ziswin.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages    REG_MULTI_SZ       msv1_0 nwv1_0

R2 BlankScreen;HBDevice;C:\WINDOWS\system32\drivers\BlankScreen.sys [2001-07-10 11:02]
R2 Kblock;Kblock;C:\WINDOWS\system32\drivers\Kblock.sys [2001-06-15 13:01]
R2 Mouslock;Mouslock;C:\WINDOWS\system32\drivers\Mouslock.sys [2001-06-15 13:01]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 16:26]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-06-28 18:01]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 20:32:56 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-07 14:34:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\NALNTSRV.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wm.exe
C:\NOVELL\ZENRC\WUOLService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
.
**************************************************************************
.
Completion time: 2008-02-07 14:37:00 - machine was rebooted
ComboFix-quarantined-files.txt  2008-02-07 20:36:51
.
2008-01-24 14:57:27    --- E O F --- 

10.4K Posts

February 11th, 2008 13:00

rickquick

Looks like we have some work to do.

1. Open NotePad (not wordpad). Copy and paste the following into Notepad



File::
C:\WINDOWS\pf1rwdL5zk.exe
C:\WINDOWS\system32\apiuser32.dll
C:\WINDOWS\kjafwdkb.dll
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\jmjyjids.exe
C:\wpohl.exe
C:\arbfikac.exe
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\daxtime.dll
C:\WINDOWS\hotporn.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\dp0.dll
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\liqui.exe
C:\WINDOWS\xxxvideo.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\spredirect.dll
C:\WINDOWS\liqad.dll
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\kvnab.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\adbar.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\liqui.dll
C:\WINDOWS\ie_32.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\settn.dll
C:\WINDOWS\flt.dll
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\liqad$.exe

Folder::
C:\WINDOWS\system32\acespy
C:\WINDOWS\efmhfrct
C:\WINDOWS\system32\jnhjkfrn




Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop

Using the Image as a reference, drag CFScript into ComboFix.exe

user posted image
  • You will be prompted to run Combofix again, Do so
    Following the same rules as indicated in my first post
    Then post the contents of the C:\ComboFix.txt log in your reply



Microsoft MVP Consumer-Security

 


"The world is what you make of it"

10.4K Posts

February 11th, 2008 14:00

rickquick

Good work. If the CFScript.txt file is still on your desktop, delete it we are going to make another one.

1. Open NotePad (not wordpad). Copy and paste the following into Notepad


File::
C:\WINDOWS\system32\jnhjkfrn

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"BurnWin"=-


Save the File as CFScript(exactly as shown no spaces) ->> Save it to your Desktop

Using the Image as a reference, drag CFScript into ComboFix.exe

user posted image
  • You will be prompted to run Combofix again, Do so
    Following the same rules as indicated in my first post
    Then post the contents of the C:\ComboFix.txt log in your reply

2. Reboot your PC rerun Hijackthis and post a fresh Hiajckthis log as well



Microsoft MVP Consumer-Security

 


"The world is what you make of it"

7 Posts

February 11th, 2008 14:00

Here is the  new one:

ComboFix 08-02.05.3 - rdc011307 2008-02-11  9:48:34.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.295 [GMT -6:00]
Running from: C:\Documents and Settings\rcopes\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\rcopes\Desktop\CFScript.txt
 * Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\arbfikac.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\jmjyjids.exe
C:\WINDOWS\kjafwdkb.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\pf1rwdL5zk.exe
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\apiuser32.dll
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe
C:\wpohl.exe
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\arbfikac.exe
C:\Program Files\3721
C:\Program Files\Accoona
C:\Program Files\akl
C:\Program Files\amsys
C:\Program Files\e-zshopper
C:\Program Files\p2pnetworks
C:\WINDOWS\efmhfrct
C:\WINDOWS\efmhfrct\1.png
C:\WINDOWS\efmhfrct\2.png
C:\WINDOWS\efmhfrct\3.png
C:\WINDOWS\efmhfrct\4.png
C:\WINDOWS\efmhfrct\5.png
C:\WINDOWS\efmhfrct\6.png
C:\WINDOWS\efmhfrct\7.png
C:\WINDOWS\efmhfrct\8.png
C:\WINDOWS\efmhfrct\9.png
C:\WINDOWS\efmhfrct\bottom-rc.gif
C:\WINDOWS\efmhfrct\config.png
C:\WINDOWS\efmhfrct\content.png
C:\WINDOWS\efmhfrct\download.gif
C:\WINDOWS\efmhfrct\frame-bg.gif
C:\WINDOWS\efmhfrct\frame-bottom-left.gif
C:\WINDOWS\efmhfrct\frame-h1bg.gif
C:\WINDOWS\efmhfrct\head.png
C:\WINDOWS\efmhfrct\icon.png
C:\WINDOWS\efmhfrct\indexwp.html
C:\WINDOWS\efmhfrct\main.css
C:\WINDOWS\efmhfrct\memory-prots.png
C:\WINDOWS\efmhfrct\net.png
C:\WINDOWS\efmhfrct\pc-mag.gif
C:\WINDOWS\efmhfrct\pc.gif
C:\WINDOWS\efmhfrct\poloska1.png
C:\WINDOWS\efmhfrct\poloska2.png
C:\WINDOWS\efmhfrct\poloska3.png
C:\WINDOWS\efmhfrct\promowp1.html
C:\WINDOWS\efmhfrct\promowp2.html
C:\WINDOWS\efmhfrct\promowp3.html
C:\WINDOWS\efmhfrct\promowp4.html
C:\WINDOWS\efmhfrct\promowp5.html
C:\WINDOWS\efmhfrct\reg.png
C:\WINDOWS\efmhfrct\repair.png
C:\WINDOWS\efmhfrct\scr-1.png
C:\WINDOWS\efmhfrct\scr-2.png
C:\WINDOWS\efmhfrct\start.png
C:\WINDOWS\efmhfrct\styles.css
C:\WINDOWS\efmhfrct\Thumbs.db
C:\WINDOWS\efmhfrct\top-rc.gif
C:\WINDOWS\efmhfrct\vline.gif
C:\WINDOWS\efmhfrct\wp.png
C:\WINDOWS\jmjyjids.exe
C:\WINDOWS\kjafwdkb.dll
C:\WINDOWS\pf1rwdL5zk.exe
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\apiuser32.dll
C:\WINDOWS\system32\jnhjkfrn\
C:\WINDOWS\system32\rxjddnvj.exe
C:\wpohl.exe

.
(((((((((((((((((((((((((   Files Created from 2008-01-11 to 2008-02-11  )))))))))))))))))))))))))))))))
.

2008-02-07 14:18 . 2004-08-03 23:56    388,608    --a------    C:\kmd.exe
2008-02-07 12:23 . 2008-02-07 12:23        d--------    C:\Program Files\ZoneAlarmSB
2008-02-07 11:37 . 2008-02-07 11:37        d--------    C:\Program Files\Windows Defender
2008-02-06 22:17 . 2008-02-06 22:17        d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-06 22:16 . 2008-02-07 14:43        d--------    C:\Program Files\SUPERAntiSpyware
2008-02-06 22:16 . 2008-02-06 22:16        d--------    C:\Program Files\Common Files\Wise Installation Wizard
2008-02-06 22:16 . 2008-02-06 22:16        d--------    C:\Documents and Settings\rcopes\Application Data\SUPERAntiSpyware.com
2008-02-06 11:05 . 2008-02-06 11:05    0    --a------    C:\SDFix.exe
2008-02-06 10:17 . 2008-02-06 10:17        d--------    C:\Documents and Settings\rcopes\.DownloadManager
2008-02-06 10:03 .     54,764        C:\WINDOWS\system32\jnhjkfrn
2008-02-06 10:03 . 2008-02-11 09:49    0    --a------    C:\reg.reg
2008-01-25 15:46 . 2008-01-25 15:46        d--------    C:\Pass
2008-01-15 09:03 . 2008-01-15 09:04        d--------    C:\Program Files\CCleaner
2008-01-14 15:21 . 2008-01-14 15:21        d-a------    C:\Lattis.pro

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-11 15:57    ---------    d-----w    C:\Program Files\Symantec AntiVirus
2008-02-11 15:54    6,548    --sha-w    C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-11 15:54    548,864    ----a-w    C:\WINDOWS\Internet Logs\xDBC.tmp
2008-02-11 15:54    471,072    --sha-w    C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-11 15:54    1,339,392    ----a-w    C:\WINDOWS\Internet Logs\xDBD.tmp
2008-02-07 18:25    20,149,491    ----a-w    C:\WINDOWS\Internet Logs\tvDebug.zip
2008-02-07 16:30    ---------    d-----w    C:\Program Files\Spybot - Search & Destroy
2008-02-07 16:27    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-01 22:26    ---------    d-----w    C:\Program Files\Trillian
2008-01-15 15:15    ---------    d-----w    C:\Program Files\Yahoo!
2007-11-21 00:35    28,032    ----a-w    C:\Documents and Settings\rcopes\Application Data\GDIPFONTCACHEV1.DAT
2007-11-14 22:05    75,248    ----a-w    C:\WINDOWS\zllsputility.exe
2007-11-01 14:57    2,904,576    ----a-w    C:\WINDOWS\Internet Logs\xDBA.tmp
2007-11-01 14:57    1,302,528    ----a-w    C:\WINDOWS\Internet Logs\xDBB.tmp
2007-07-12 13:00    1,498,624    ----a-w    C:\WINDOWS\Internet Logs\xDB8.tmp
2007-07-12 12:59    1,498,624    ----a-w    C:\WINDOWS\Internet Logs\xDB9.tmp
2007-06-18 19:03    68,489    ----a-w    C:\WINDOWS\Internet Logs\vsmon_2nd_2007_06_18_13_59_26_small.dmp.zip
2007-06-14 04:45    1,568    ----a-w    C:\Documents and Settings\rcopes\Application Data\mpauth.dat
2007-06-08 21:34    2,634,752    ----a-w    C:\WINDOWS\Internet Logs\xDB7.tmp
2007-04-03 21:13    1,399,296    ----a-w    C:\WINDOWS\Internet Logs\xDB6.tmp
2006-10-09 15:48    2,640,896    ----a-w    C:\WINDOWS\Internet Logs\xDB4.tmp
2006-10-09 15:48    1,336,832    ----a-w    C:\WINDOWS\Internet Logs\xDB5.tmp
2006-10-03 06:43    2,402,550    ----a-w    C:\WINDOWS\inf\SET59.tmp
2006-08-22 18:24    1,307,136    ----a-w    C:\WINDOWS\Internet Logs\xDB3.tmp
2006-08-04 12:37    1,296,896    ----a-w    C:\WINDOWS\Internet Logs\xDB2.tmp
2006-07-05 21:13    1,264,640    ----a-w    C:\WINDOWS\Internet Logs\xDB1.tmp
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2008-02-07 12:23    262144    --a------    C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-02-07 12:23 262144]

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2005-02-15 08:02 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2005-02-15 08:02 126976]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-12-30 14:19 120640]
"NDPS"="C:\WINDOWS\System32\dpmw32.exe" [2004-05-17 14:27 32859]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 10:37 28672 C:\WINDOWS\system32\nwtray.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"BurnWin"= {C145CF11-124F-3562-44AC-E685D962C63C} - C:\WINDOWS\system32\apiuser32.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="ziswin.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages    REG_MULTI_SZ       msv1_0 nwv1_0

R2 BlankScreen;HBDevice;C:\WINDOWS\system32\drivers\BlankScreen.sys [2001-07-10 11:02]
R2 Kblock;Kblock;C:\WINDOWS\system32\drivers\Kblock.sys [2001-06-15 13:01]
R2 Mouslock;Mouslock;C:\WINDOWS\system32\drivers\Mouslock.sys [2001-06-15 13:01]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 16:26]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-06-28 18:01]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-11 15:58:15 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-11 09:58:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\NALNTSRV.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wm.exe
C:\NOVELL\ZENRC\WUOLService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
.
**************************************************************************
.
Completion time: 2008-02-11 10:01:50 - machine was rebooted
ComboFix-quarantined-files.txt  2008-02-11 16:01:40
ComboFix2.txt  2008-02-07 20:37:00
.
2008-01-24 14:57:27    --- E O F --- 


7 Posts

February 11th, 2008 17:00

Hijack this log (Combo Fix log will be on another post):

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:40:26 AM, on 2/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\NALNTSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wm.exe
C:\NOVELL\ZENRC\WUOLService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\System32\dpmw32.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\rcopes\Desktop\HiJackThis_v2.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182179388984
O16 - DPF: {7BE30DB7-4BB6-41A7-BE9C-EB9EB45725DE} (WebCamX Control) - http://208.42.209.86/WebCamX.cab
O16 - DPF: {F92211F4-3913-4DC2-A275-756374D848B0} (ERViewerOCX Control) - http://66.112.17.174/MP4DVR.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D879E850-F59A-4357-8526-139D1D099036}: NameServer = 209.142.136.85,208.42.196.36
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\System32\cusrvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINDOWS\System32\NALNTSRV.EXE
O23 - Service: Remote management (Novell WUser Agent) - Novell, Inc. - C:\NOVELL\ZENRC\wuser32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINDOWS\System32\wm.exe
O23 - Service: WUOLservice (WUOLService) - Novell, Inc. - C:\NOVELL\ZENRC\WUOLService.exe

--
End of file - 7605 bytes

7 Posts

February 11th, 2008 17:00

ComboFix Log:

ComboFix 08-02.05.3 - rdc011307 2008-02-11 11:24:13.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.492 [GMT -6:00]
Running from: C:\Documents and Settings\rcopes\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\rcopes\Desktop\CFScript.txt
 * Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\jnhjkfrn
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\jnhjkfrn

.
(((((((((((((((((((((((((   Files Created from 2008-01-11 to 2008-02-11  )))))))))))))))))))))))))))))))
.

2008-02-11 09:46 . 2004-08-03 23:56    388,608    --a------    C:\kmd.exe
2008-02-07 12:23 . 2008-02-07 12:23        d--------    C:\Program Files\ZoneAlarmSB
2008-02-07 11:37 . 2008-02-07 11:37        d--------    C:\Program Files\Windows Defender
2008-02-06 22:17 . 2008-02-06 22:17        d--------    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-06 22:16 . 2008-02-07 14:43        d--------    C:\Program Files\SUPERAntiSpyware
2008-02-06 22:16 . 2008-02-06 22:16        d--------    C:\Program Files\Common Files\Wise Installation Wizard
2008-02-06 22:16 . 2008-02-06 22:16        d--------    C:\Documents and Settings\rcopes\Application Data\SUPERAntiSpyware.com
2008-02-06 11:05 . 2008-02-06 11:05    0    --a------    C:\SDFix.exe
2008-02-06 10:17 . 2008-02-06 10:17        d--------    C:\Documents and Settings\rcopes\.DownloadManager
2008-02-06 10:03 . 2008-02-11 09:49    0    --a------    C:\reg.reg
2008-01-25 15:46 . 2008-01-25 15:46        d--------    C:\Pass
2008-01-15 09:03 . 2008-01-15 09:04        d--------    C:\Program Files\CCleaner
2008-01-14 15:21 . 2008-01-14 15:21        d-a------    C:\Lattis.pro

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-11 17:32    ---------    d-----w    C:\Program Files\Symantec AntiVirus
2008-02-11 17:29    6,980    --sha-w    C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-11 17:29    534,560    --sha-w    C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-07 16:30    ---------    d-----w    C:\Program Files\Spybot - Search & Destroy
2008-02-07 16:27    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-01 22:26    ---------    d-----w    C:\Program Files\Trillian
2008-01-15 15:15    ---------    d-----w    C:\Program Files\Yahoo!
2007-11-21 00:35    28,032    ----a-w    C:\Documents and Settings\rcopes\Application Data\GDIPFONTCACHEV1.DAT
2007-11-14 22:05    75,248    ----a-w    C:\WINDOWS\zllsputility.exe
2007-06-14 04:45    1,568    ----a-w    C:\Documents and Settings\rcopes\Application Data\mpauth.dat
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2008-02-07 12:23    262144    --a------    C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-02-07 12:23 262144]

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2005-02-15 08:02 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2005-02-15 08:02 126976]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-12-30 14:19 120640]
"NDPS"="C:\WINDOWS\System32\dpmw32.exe" [2004-05-17 14:27 32859]
"NWTRAY"="NWTRAY.EXE" [2002-03-12 10:37 28672 C:\WINDOWS\system32\nwtray.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="ziswin.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages    REG_MULTI_SZ       msv1_0 nwv1_0

R2 BlankScreen;HBDevice;C:\WINDOWS\system32\drivers\BlankScreen.sys [2001-07-10 11:02]
R2 Kblock;Kblock;C:\WINDOWS\system32\drivers\Kblock.sys [2001-06-15 13:01]
R2 Mouslock;Mouslock;C:\WINDOWS\system32\drivers\Mouslock.sys [2001-06-15 13:01]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 16:26]
S1 jnhjkfrn;jnhjkfrn;C:\WINDOWS\system32\jnhjkfrn []
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-06-28 18:01]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-11 17:33:21 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-11 11:36:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\NALNTSRV.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wm.exe
C:\NOVELL\ZENRC\WUOLService.exe
.
**************************************************************************
.
Completion time: 2008-02-11 11:39:43 - machine was rebooted [rcopes]
ComboFix-quarantined-files.txt  2008-02-11 17:39:35
ComboFix2.txt  2008-02-11 16:01:51
ComboFix3.txt  2008-02-07 20:37:00
.
2008-01-24 14:57:27    --- E O F --- 

7 Posts

February 11th, 2008 17:00

Unfortuantely, IE will not access the Internet. I have Firefox and it works fine. I get an error on IE, as shown below. When I diagnose the problem, I get the response at the bottom.

Internet Explorer cannot display the webpage Most likely causes:
  • You are not connected to the Internet.
  • The website is encountering problems.
  • There might be a typing error in the address.
What you can try: Diagnose Connection Problems More information More information

---------------------------------------------------------------------------------------------------------------------------------

Last diagnostic run time: 02/11/08 13:38:33 HTTP, HTTPS, FTP Diagnostic HTTP, HTTPS, FTP connectivity info HTTP: Successfully connected to www.microsoft.com. info FTP (Passive): Successfully connected to ftp.microsoft.com. info HTTPS: Successfully connected to www.microsoft.com.

10.4K Posts

February 11th, 2008 17:00

rickquick

Good work. Since you have CCleaner, go ahead and re - run it.

1. Run an online virus scan called Kaspersky from HERE.
  • 1. Click on " Kaspersky Online Scanner"
    2. A new smaller window will pop up. Press on " Accept". After reading the contents.
    3. Now Kaspersky will update the anti-virus database. Let it run.
    4. Click on " Next"->>" Scan Settings", and make sure the database is set to " extended". And check both the scan options. Then click OK.
    5. Then click on " My Computer". And the scan will start.
    6. When the scan is complete Select "Save error report as"
    Then in the file name just type in kaspersky
    Under "save as type" select text .txt
    Save it to your Desktop.









Copy and post the results of the Kaspersky Online scan










Microsoft MVP Consumer-Security

 


"The world is what you make of it"




10.4K Posts

February 11th, 2008 18:00

rickquick

 

You should be able to run the Kapsersky online using FireFox. Unless it won't allow Active X

 

You could also reload IE from here

 

http://www.microsoft.com/windows/products/winfamily/ie/default.mspx

 




 

Microsoft MVP Consumer-Security

 


"The world is what you make of it"


Message Edited by bamajim on 02-11-2008 02:01 PM
No Events found!

Top