Unsolved

This post is more than 5 years old

11 Posts

1275

February 10th, 2008 01:00

Trojan.Vundo in vtutq.dll

BitDefender keeps telling me that vtutq.dll is infected with the Trojan.Vundo but can't delete it seeing as it's a dll. I've tried VirtumundoBeGone and FixVundo but neither has shown signs of the trojan or it repiaring it. Her'es My HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 10:40:54 PM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {125FCE82-73E6-49D2-8312-9660D82E07DE} - (no file)
O2 - BHO: (no name) - {41A16134-ABD1-475D-AA59-3759757C2F16} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {F81D84CB-A4D9-4F7D-B041-427291A7BB0E} - C:\WINDOWS\system32\vtutq.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - Startup: PeerGuardian.lnk = C:\Program Files\PeerGuardian2\pg2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP Monitor (ASFIPmon) - Unknown owner - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe" -service (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe" /service (file missing)



And here's the VirtumundoBeGone log:


[02/09/2008, 22:41:25] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Austin\Desktop\VirtumundoBeGone.exe" )
[02/09/2008, 22:41:27] - Detected System Information:
[02/09/2008, 22:41:27] -  Windows Version: 5.1.2600, Service Pack 2
[02/09/2008, 22:41:27] -  Current Username: Austin (Admin)
[02/09/2008, 22:41:27] -  Windows is in NORMAL mode.
[02/09/2008, 22:41:27] - Searching for Browser Helper Objects:
[02/09/2008, 22:41:27] -  BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/09/2008, 22:41:27] -  BHO 2: {125FCE82-73E6-49D2-8312-9660D82E07DE} ()
[02/09/2008, 22:41:27] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/09/2008, 22:41:27] -  No filename found. Continuing.
[02/09/2008, 22:41:27] -  BHO 3: {41A16134-ABD1-475D-AA59-3759757C2F16} ()
[02/09/2008, 22:41:27] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/09/2008, 22:41:27] -  No filename found. Continuing.
[02/09/2008, 22:41:27] -  BHO 4: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
[02/09/2008, 22:41:27] -  BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/09/2008, 22:41:27] -  BHO 6: {F81D84CB-A4D9-4F7D-B041-427291A7BB0E} ()
[02/09/2008, 22:41:27] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/09/2008, 22:41:27] -  Checking for HKLM\...\Winlogon\Notify\vtutq
[02/09/2008, 22:41:27] -  Key not found: HKLM\...\Winlogon\Notify\vtutq, continuing.
[02/09/2008, 22:41:27] - Finished Searching Browser Helper Objects
[02/09/2008, 22:41:27] - Finishing up...
[02/09/2008, 22:41:27] - Nothing found! Exiting...

11 Posts

February 10th, 2008 02:00

I haven't posted this on any other forums yet, I haven't fixed any problems with HJT in the past, and all of the other stuff is fine.  Thanks for the quick reply and here's the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:27:05 PM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\BitDefender\BitDefender 2008\uiscan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {125FCE82-73E6-49D2-8312-9660D82E07DE} - (no file)
O2 - BHO: (no name) - {41A16134-ABD1-475D-AA59-3759757C2F16} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {F81D84CB-A4D9-4F7D-B041-427291A7BB0E} - C:\WINDOWS\system32\vtutq.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
O4 - Startup: PeerGuardian.lnk = C:\Program Files\PeerGuardian2\pg2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 6355 bytes

4 Apprentice

 • 

20.5K Posts

February 10th, 2008 02:00


Welcome. Thank you for using Dell Community Forums.
I am reviewing your log.
In the meantime, you can help me by doing the following:

* Have you have posted this issue on another forum? If so, please provide a link to the topic.

* If you are using any cracked software, please remove it.
Definition of cracked software:
http://en.wikipedia.org/wiki/Software_cracking

* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state.

* If this computer belongs to someone else, do you have authority to apply the fixes we will use?

* Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.

* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures.
Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using.

** We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case.
Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.

You are using an outdated version of HijackThis. Please go to Add/Remove and uninstall it that way or by using the uninstaller within HijackThis.
Please download HJT Installer for version 2.02 from Here to your desktop.
If not available use this alternate link: Here
  • Click the Download button. When the Trend Micro HJT install box appears, double click on the HJTInstall.exe. Click on Install.
  • It will be installed by default here: C:\Program Files\Trend Micro\HijackThis.
  • A shortcut to the application will also be placed on your Desktop.
  • The program will open automatically after installation.
  • You can double-click the icon that was placed on the Desktop to run subsequent HijackThis scans or you can use the icon inside the folder. The folder HijackThis is where you will find the HJT logs that you save. When you use the application to remove anything, you will also find the backup copies made by HJT inside this folder.
  • The first time you open HijackThis, check the Main Menu button at the bottom center. When the main menu appears check the box "Show this window when I start HijackThis".
  • Click on "Do a system scan and save logfile."
    When the log pops up in Notepad, copy and paste that file back here.
  • DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
  • Before closing HJT, please click on the AnalyzeThis button. "Analyze This" DOES NOT mean "Analyze My Log". You will need to post your log on the forum.
  • Close the web page that appears and then close the program


  • * If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.

    I look forward to your reply.

4 Apprentice

 • 

20.5K Posts

February 10th, 2008 03:00

Please print these instructions and refer to them for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix


Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.

Note: The above instructions were created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert. It is intended by its creator to be used under the guidance and supervision of an expert, not for private use.






11 Posts

February 10th, 2008 17:00

When I attempted to install the Recovery Console it giving me an error saying that the file hpt3xx.sys was missing and the Console wouldn't work without it.

11 Posts

February 10th, 2008 18:00

I tried and was able to get ComboFix to still work. Here's the log:

ComboFix 08-02.05.3 - Austin 2008-02-10 15:17:06.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1577 [GMT -5:00]
Running from: C:\Documents and Settings\Austin\Desktop\ComboFix.exe
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\Common Files\racle~1
C:\WINDOWS\b103.exe
C:\WINDOWS\b116.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b147.exe
C:\WINDOWS\b149.exe
C:\WINDOWS\b151.exe
C:\WINDOWS\system32\fnts~1
C:\WINDOWS\system32\llkkj.ini
C:\WINDOWS\system32\llkkj.ini2
C:\WINDOWS\system32\qtutv.ini
C:\WINDOWS\system32\qtutv.ini2
C:\WINDOWS\system32\tsuninst.exe
C:\WINDOWS\system32\vtutq.dll
C:\WINDOWS\system32\x64

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_CMDSERVICE






(((((((((((((((((((((((((   Files Created from 2008-01-10 to 2008-02-10  )))))))))))))))))))))))))))))))
.

2008-02-10 13:56 . 2008-02-10 14:48    60,416    --a------    C:\WINDOWS\system32\drivers\ComboFix.sys
2008-02-10 13:43 . 2004-08-03 23:00    260,272    -r-hs----    C:\cmldr
2008-02-10 12:48 . 2008-02-10 13:22        d--------    C:\XPSP2
2008-02-10 12:47 . 2008-02-10 13:29        d--------    C:\XPCD
2008-02-09 23:26 . 2008-02-09 23:26        d--------    C:\Program Files\Trend Micro
2008-02-08 20:26 . 2008-02-08 20:26        d--------    C:\Documents and Settings\David\Application Data\Sonic
2008-02-08 16:22 . 2008-02-08 16:22        d--------    C:\Documents and Settings\David\Application Data\vlc
2008-02-08 16:07 . 2008-02-08 16:14        d--------    C:\Documents and Settings\David\Application Data\uTorrent
2008-02-08 15:58 . 2008-02-08 15:58        d--------    C:\Documents and Settings\David\Application Data\dvdcss
2008-02-08 15:57 . 2005-11-21 00:48    45,056    --a------    C:\WINDOWS\system32\WNASPI32.DLL
2008-02-08 15:57 . 2005-11-21 00:48    16,512    --a------    C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-02-08 15:38 . 2008-02-08 15:38        d--------    C:\Program Files\Combined Community Codec Pack
2008-02-05 14:12 . 2008-02-05 14:12        d--------    C:\Documents and Settings\Barbara\Application Data\BitDefender
2008-01-31 20:19 . 2008-01-31 20:19        d--------    C:\Documents and Settings\David\Application Data\BitDefender
2008-01-31 15:16 . 2008-02-10 15:12    121    --a------    C:\WINDOWS\bdagent.INI
2008-01-31 14:52 . 2008-01-31 14:52        d--------    C:\Documents and Settings\Austin\Application Data\BitDefender
2008-01-31 14:51 . 2008-01-31 14:51        d--------    C:\Program Files\BitDefender
2008-01-31 14:51 . 2008-01-31 14:52        d--------    C:\Documents and Settings\All Users\Application Data\BitDefender
2008-01-31 14:48 . 2008-01-31 14:51        d--------    C:\Program Files\Common Files\BitDefender
2008-01-31 09:46 . 2008-01-31 09:46        d--------    C:\WINDOWS\system32\DAE0E2DEE3E3E7
2008-01-26 00:46 . 2008-01-26 00:46        d--------    C:\Program Files\uTorrent
2008-01-26 00:46 . 2008-02-10 15:11        d--------    C:\Documents and Settings\Austin\Application Data\uTorrent
2008-01-16 07:16 . 2008-01-16 07:16        d--------    C:\Program Files\iTunes
2008-01-16 07:16 . 2008-01-16 07:16        d--------    C:\Program Files\iPod
2008-01-16 07:16 . 2008-02-09 22:21    54,156    --ah-----    C:\WINDOWS\QTFont.qfn
2008-01-16 07:16 . 2008-01-16 07:16    1,409    --a------    C:\WINDOWS\QTFont.for
2008-01-16 07:15 . 2008-01-16 07:15        d--------    C:\Program Files\QuickTime
2008-01-10 15:27 . 2008-01-10 15:27    90,112    --a------    C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27    57,344    --a------    C:\WINDOWS\system32\QuickTime.qts

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-10 19:51    ---------    d-----w    C:\Program Files\PeerGuardian2
2008-02-10 02:11    ---------    d-----w    C:\Program Files\Common Files\Adobe
2008-02-10 01:54    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\River Past G5
2008-02-05 17:18    85,520    ----a-w    C:\WINDOWS\system32\drivers\bdfndisf.sys
2008-01-31 14:10    10    ----a-w    C:\Program Files\.autoreg
2008-01-07 22:41    196,368    ----a-w    C:\WINDOWS\system32\drivers\bdfsfltr.sys
2007-12-25 05:09    ---------    d--h--w    C:\Program Files\Zero G Registry
2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\David\Application Data\Gtek
2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\Barbara\Application Data\Gtek
2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\Austin\Application Data\Gtek
2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\Administrator\Application Data\GTek
2007-12-19 01:27    ---------    d--h--w    C:\Program Files\InstallShield Installation Information
2007-12-19 01:27    ---------    d-----w    C:\Program Files\Creative
2007-12-19 01:25    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\AOL
2007-12-16 18:19    ---------    d-----w    C:\Program Files\TI Education
2007-12-16 18:19    ---------    d-----w    C:\Program Files\Common Files\TI Shared
2007-12-16 18:19    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-16 18:17    ---------    d-----w    C:\Program Files\Common Files\Wise Installation Wizard
2007-12-10 23:49    ---------    d-----w    C:\Program Files\Common Files\Cisco Systems
2007-12-10 23:11    ---------    d-----w    C:\Program Files\Google
2007-12-10 21:31    66,484    ----a-w    C:\Documents and Settings\All Users\Application Data\firstlsp.reg.dat
2007-12-10 21:19    ---------    d-----w    C:\Documents and Settings\Austin\Application Data\Sony
2007-12-10 21:19    ---------    d-----w    C:\Documents and Settings\Austin\Application Data\Publish Providers
2007-12-10 21:17    ---------    d-----w    C:\Program Files\Sony
2007-12-10 21:15    ---------    d-----w    C:\Program Files\Sony Setup
2007-11-27 21:46    77,824    ----a-w    C:\WINDOWS\system32\xcomm.dll
2007-11-14 07:26    450,560    ------w    C:\WINDOWS\system32\dllcache\jscript.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{381FFDE8-2394-4F90-B10D-FC6124A40F8C}

[HKEY_CLASSES_ROOT\clsid\{381ffde8-2394-4f90-b10d-fc6124a40f8c}]
[HKEY_CLASSES_ROOT\BitDefender Toolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 10:37 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-02-05 12:18 360448]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"OE"="C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [ ]

C:\Documents and Settings\Austin\Start Menu\Programs\Startup\
PeerGuardian.lnk - C:\Program Files\PeerGuardian2\pg2.exe [2007-05-22 15:34:38 1421824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\A0A6A8A4A9A9ADAB]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]
--a------ 2005-09-08 05:20 122940 C:\WINDOWS\System32\DLA\DLACTRLW.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2005-12-09 20:29 49152 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Insider]
C:\Program Files\Insider\Insider.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2004-07-27 16:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OE]
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1044.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tair]
C:\DOCUME~1\Austin\MYDOCU~1\ASKS~1\ati2evxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UfSeAgnt.exe]
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe

R1 bdftdif;bdftdif;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys [2008-02-05 10:48]
R2 ASFIPmon;Broadcom ASF IP Monitor;"C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe" [2006-03-17 17:25]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-02-05 12:18]
R3 bdfsfltr;bdfsfltr;C:\WINDOWS\system32\drivers\bdfsfltr.sys [2008-01-07 17:41]
R3 BDSelfPr;BDSelfPr;C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys [2008-01-31 14:54]
R3 scan;BitDefender Threat Scanner;C:\WINDOWS\System32\svchost.exe [2004-08-04 06:00]
S3 avfwim;AvFw Packet Filter Miniport;C:\WINDOWS\system32\DRIVERS\avfwim.sys []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx    REG_MULTI_SZ       scan

.
Contents of the 'Scheduled Tasks' folder
"2008-02-06 12:08:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-10 15:20:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-10 15:22:07
ComboFix-quarantined-files.txt  2008-02-10 20:22:03
.
2008-01-16 02:56:14    --- E O F --- 





Here's the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:26:22 PM, on 2/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
O4 - Startup: PeerGuardian.lnk = C:\Program Files\PeerGuardian2\pg2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 4437 bytes

4 Apprentice

 • 

20.5K Posts

February 10th, 2008 21:00


Good job. The Recovery Console is just a safety net. ComboFix will work without it.
Open Notepad and copy/paste the following text between the lines.
** Make sure you copy/paste ALL the text at once. Do not try to edit extra spaces. It will copy correctly to Notepad if you highlight and copy as is.
-----------------------------

File::
C:\WINDOWS\mrofinu1044.exe


Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]


------------------------------------

Save this as CFScript.txt
Photobucket

Referring to the picture above, drag CFScript into ComboFix.exe
You will be prompted to run Combofix again. Follow the same instructions you did before for running ComboFix.
CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

When finished, a log is produced here: C:\ComboFix.txt

In your next reply, please post that log along with a new HijackThis log.
Message Edited by Bugbatter on 02-10-2008 06:08 PM

11 Posts

February 10th, 2008 21:00

Alright, I keep getting an error after I drag CFScript onto ComboFix after ComboFix begins to open.
It says "You cannot rename ComboFix as ComboFix.    Please use another name."

I tried recreating the CFScript and even redownloading the ComboFix file but bot just reproduced the same error after trying it again.

4 Apprentice

 • 

20.5K Posts

February 10th, 2008 22:00

That usually happens if you aborted a previous run of ComboFix by closing the DOS box leaving some processes still running.
Please reboot and try again .

11 Posts

February 11th, 2008 01:00

Thanks, you were right. Here's the ComboFix log:

ComboFix 08-02.05.3 - Austin 2008-02-10 22:36:03.5 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1564 [GMT -5:00]
Running from: C:\Documents and Settings\Austin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Austin\Desktop\CFScript.txt
 * Created a new restore point

FILE
C:\WINDOWS\mrofinu1044.exe
.

(((((((((((((((((((((((((   Files Created from 2008-01-11 to 2008-02-11  )))))))))))))))))))))))))))))))
.

2008-02-10 18:23 . 2004-08-04 06:00    388,608    --a------    C:\kmd.exe
2008-02-10 17:57 . 2004-08-04 00:56    1,737,856    ---------    C:\WINDOWS\system32\mtxparhd.dll
2008-02-10 17:57 . 2004-08-04 00:56    397,056    ---------    C:\WINDOWS\system32\s3gnb.dll
2008-02-10 17:57 . 2004-08-04 00:56    286,792    ---------    C:\WINDOWS\system32\slextspk.dll
2008-02-10 17:57 . 2004-08-04 00:56    188,508    ---------    C:\WINDOWS\system32\slgen.dll
2008-02-10 17:57 . 2004-08-04 00:56    73,832    ---------    C:\WINDOWS\system32\slcoinst.dll
2008-02-10 17:57 . 2004-08-04 00:56    73,796    ---------    C:\WINDOWS\system32\slserv.exe
2008-02-10 17:57 . 2004-08-04 00:56    32,866    ---------    C:\WINDOWS\system32\slrundll.exe
2008-02-10 17:57 . 2004-08-04 00:56    32,866    ---------    C:\WINDOWS\slrundll.exe
2008-02-10 17:57 . 2004-08-04 00:56    28,672    ---------    C:\WINDOWS\system32\vidcap.ax
2008-02-10 17:53 . 2008-02-10 17:53        d--------    C:\WINDOWS\ServicePackFiles
2008-02-10 17:52 . 2004-07-17 11:40    19,528    --a------    C:\WINDOWS\ 000001_.tmp
2008-02-10 13:43 . 2004-08-03 23:00    260,272    -r-hs----    C:\cmldr
2008-02-10 12:48 . 2008-02-10 13:22        d--------    C:\XPSP2
2008-02-10 12:47 . 2008-02-10 13:29        d--------    C:\XPCD
2008-02-09 23:26 . 2008-02-09 23:26        d--------    C:\Program Files\Trend Micro
2008-02-08 20:26 . 2008-02-08 20:26        d--------    C:\Documents and Settings\David\Application Data\Sonic
2008-02-08 16:22 . 2008-02-08 16:22        d--------    C:\Documents and Settings\David\Application Data\vlc
2008-02-08 16:07 . 2008-02-08 16:14        d--------    C:\Documents and Settings\David\Application Data\uTorrent
2008-02-08 15:58 . 2008-02-08 15:58        d--------    C:\Documents and Settings\David\Application Data\dvdcss
2008-02-08 15:57 . 2005-11-21 00:48    45,056    --a------    C:\WINDOWS\system32\WNASPI32.DLL
2008-02-08 15:57 . 2005-11-21 00:48    16,512    --a------    C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-02-08 15:38 . 2008-02-08 15:38        d--------    C:\Program Files\Combined Community Codec Pack
2008-02-05 14:12 . 2008-02-05 14:12        d--------    C:\Documents and Settings\Barbara\Application Data\BitDefender
2008-01-31 20:19 . 2008-01-31 20:19        d--------    C:\Documents and Settings\David\Application Data\BitDefender
2008-01-31 15:16 . 2008-02-10 18:13    121    --a------    C:\WINDOWS\bdagent.INI
2008-01-31 14:52 . 2008-01-31 14:52        d--------    C:\Documents and Settings\Austin\Application Data\BitDefender
2008-01-31 14:51 . 2008-01-31 14:51        d--------    C:\Program Files\BitDefender
2008-01-31 14:51 . 2008-01-31 14:52        d--------    C:\Documents and Settings\All Users\Application Data\BitDefender
2008-01-31 14:48 . 2008-01-31 14:51        d--------    C:\Program Files\Common Files\BitDefender
2008-01-31 09:46 . 2008-01-31 09:46        d--------    C:\WINDOWS\system32\DAE0E2DEE3E3E7
2008-01-26 00:46 . 2008-01-26 00:46        d--------    C:\Program Files\uTorrent
2008-01-26 00:46 . 2008-02-10 15:11        d--------    C:\Documents and Settings\Austin\Application Data\uTorrent
2008-01-16 07:16 . 2008-01-16 07:16        d--------    C:\Program Files\iTunes
2008-01-16 07:16 . 2008-01-16 07:16        d--------    C:\Program Files\iPod
2008-01-16 07:16 . 2008-02-10 15:57    54,156    --ah-----    C:\WINDOWS\QTFont.qfn
2008-01-16 07:16 . 2008-01-16 07:16    1,409    --a------    C:\WINDOWS\QTFont.for
2008-01-16 07:15 . 2008-01-16 07:15        d--------    C:\Program Files\QuickTime

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-11 03:34    ---------    d-----w    C:\Program Files\PeerGuardian2
2008-02-10 02:11    ---------    d-----w    C:\Program Files\Common Files\Adobe
2008-02-10 01:54    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\River Past G5
2008-02-05 17:18    85,520    ----a-w    C:\WINDOWS\system32\drivers\bdfndisf.sys
2008-01-31 14:10    10    ----a-w    C:\Program Files\.autoreg
2008-01-07 22:41    196,368    ----a-w    C:\WINDOWS\system32\drivers\bdfsfltr.sys
2007-12-25 05:09    ---------    d--h--w    C:\Program Files\Zero G Registry
2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\David\Application Data\Gtek
2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\Barbara\Application Data\Gtek
2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\Austin\Application Data\Gtek
2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\Administrator\Application Data\GTek
2007-12-19 01:27    ---------    d--h--w    C:\Program Files\InstallShield Installation Information
2007-12-19 01:27    ---------    d-----w    C:\Program Files\Creative
2007-12-19 01:25    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\AOL
2007-12-16 18:19    ---------    d-----w    C:\Program Files\TI Education
2007-12-16 18:19    ---------    d-----w    C:\Program Files\Common Files\TI Shared
2007-12-16 18:19    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-16 18:17    ---------    d-----w    C:\Program Files\Common Files\Wise Installation Wizard
2007-12-10 21:31    66,484    ----a-w    C:\Documents and Settings\All Users\Application Data\firstlsp.reg.dat
2007-11-27 21:46    77,824    ----a-w    C:\WINDOWS\system32\xcomm.dll
2007-11-14 07:26    450,560    ------w    C:\WINDOWS\system32\dllcache\jscript.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{381FFDE8-2394-4F90-B10D-FC6124A40F8C}

[HKEY_CLASSES_ROOT\clsid\{381ffde8-2394-4f90-b10d-fc6124a40f8c}]
[HKEY_CLASSES_ROOT\BitDefender Toolbar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-02-05 12:18 360448]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"OE"="C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [ ]

C:\Documents and Settings\Austin\Start Menu\Programs\Startup\
PeerGuardian.lnk - C:\Program Files\PeerGuardian2\pg2.exe [2007-05-22 15:34:38 1421824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\A0A6A8A4A9A9ADAB]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
-ra------ 2007-03-01 10:37 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]
--a------ 2005-09-08 05:20 122940 C:\WINDOWS\System32\DLA\DLACTRLW.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2005-12-09 20:29 49152 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Insider]
C:\Program Files\Insider\Insider.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2004-07-27 16:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OE]
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tair]
C:\DOCUME~1\Austin\MYDOCU~1\ASKS~1\ati2evxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UfSeAgnt.exe]
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe

R1 bdftdif;bdftdif;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys [2008-02-05 10:48]
R2 ASFIPmon;Broadcom ASF IP Monitor;"C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe" [2006-03-17 17:25]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-02-05 12:18]
R3 bdfsfltr;bdfsfltr;C:\WINDOWS\system32\drivers\bdfsfltr.sys [2008-01-07 17:41]
R3 BDSelfPr;BDSelfPr;C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys [2008-01-31 14:54]
R3 scan;BitDefender Threat Scanner;C:\WINDOWS\System32\svchost.exe [2004-08-04 06:00]
S3 avfwim;AvFw Packet Filter Miniport;C:\WINDOWS\system32\DRIVERS\avfwim.sys []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx    REG_MULTI_SZ       scan

.
Contents of the 'Scheduled Tasks' folder
"2008-02-06 12:08:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-10 22:40:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-10 22:40:43
ComboFix2.txt  2008-02-10 23:47:11
.
2008-02-10 23:39:17    --- E O F --- 

11 Posts

February 11th, 2008 01:00

and here's the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:43:14 PM, on 2/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
O4 - Startup: PeerGuardian.lnk = C:\Program Files\PeerGuardian2\pg2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 4312 bytes

4 Apprentice

 • 

20.5K Posts

February 11th, 2008 03:00

Good job :)
Now for the rest.


Run Disk Cleanup in each user's profile:
Click "Start > Programs > Accessories > System Tools > Disk Cleanup"
Please make sure only the following are checked:
-- Downloaded Program Files
-- Temporary Internet Files
-- Recycle Bin
-- Temporary Files
Click "OK" and Disk Cleanup will delete those files for you.

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. It is possible that you may be running Java code in your applications that absolutely require a specific version of the JRE to run. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u4 allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each of the Java versions.

  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windows-i586-p.exe to install the newest version.

Official JAVA Installation Instructions if needed.


After that, let me know how things are running. If all is running smoothly, we'll remove our tools and flush System Restore.

11 Posts

February 12th, 2008 01:00

Yes, everything is finally alright. CPU usage is low and load times are fast once again.
Thank you so much for your help!

11 Posts

February 12th, 2008 02:00

Excellent, I've already installed and used the majority of thos programs.
One last question. Can I remove the Recovery Console since the option for it shows up during a restart, but it doesn't work since that one file kept giving me trouble.

Thanks

4 Apprentice

 • 

20.5K Posts

February 12th, 2008 02:00

That is good news.
It's time for some housekeeping. Sweeping
Because the tools we used to scan the computer, as well as tools to delete files and folders, are no longer needed, they should be removed, along with the folders created by these tools.


* Click Start then Run
* Now type Combofix /u in the runbox and click OK.
Notice the space between the X and the /u


This will uninstall ComboFix. It will also implement some cleanup procedures and reset System Restore points.



Here is my standard list of simple steps that you can take to reduce the chance of infection in the future.

You may have already taken some of these steps, and depending on your current security, you may not need to implement all of these:
1. Visit Windows Update:
Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp

2. Consider installing the following free programs:
a. SpywareBlaster: (Not recommended for Vista)
http://www.javacoolsoftware.com/spywareblaster.html
Tutorial here: http://www.bleepingcomputer.com/forums/tutorial49.html
b. SpywareGuard:
http://www.javacoolsoftware.com/spywareguard.html
Tutorial here: http://www.bleepingcomputer.com/tutorials/tutorial50.html
Periodically check for updates in both programs.

3. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date.
Note: Zone Alarm Firewall (by Checkpoint) has a free version http://www.zonelabs.com/store/content/company/products/trial_zaFamily/trial_zaFamily.jsp?lid=home_freedownloads

4. You might consider installing Mozilla / Firefox.
http://www.mozilla.org/

5. Do not use file sharing. Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple. File sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known
vulnerabilities.

6. Before using or purchasing any Spyware/Malware protection/removal program, always check the following Rogue/Suspect Spyware Lists.
http://www.spywarewarrior.com/rogue_anti-spyware.htm
http://www.malwarebytes.org/database.php

7. If you have not already done so, you might want to install CCleaner and run it in each user's profile: http://www.ccleaner.com/
** UNcheck the option to install the Yahoo toolbar that is checked by default for the Standard version, or download the toolbar-free versions (Slim or Basic) when given the option for those.

8. If you use Adobe Reader it may need to be updated to be sure that you have a more secure version. If you are using a version prior to v. 6.05, you should update to 6.05, preferably version 8.1.0 or higher.
It would be best to remove prior versions before updating to a new version.
If you need additional assistance, the Adobe forums are here: http://www.adobe.com/support/forums/main.html

9. Make sure you are using the most updated version of Java.
The current version is Java Runtime Environment (JRE) 6u4

You can go here to download the latest version of Java Runtime Environment (JRE) 6.
Scroll down to where it says " Java Runtime Environment (JRE) 6u4 allows end-users to run Java applications".

Click the link to download the Windows (Offline Installation) package: Save it, do not run it. When the download is complete, close the browser.

Remove all prior versions using Add/Remove Programs, and delete the Java folder in Program Files.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u4-windows-i586-p.exe to install the newest version.
Official JAVA Installation Instructions if needed.
Reboot.

10. Practice Safe Surfing with with TrendProtect by Trendmicro.
TrendProtect is a browser plugin that assigns a safety rating to domains listed in your search engine. TrendProtect also adds a new button to your browser's toolbar area. The icon and color of the button changes to indicate whether the page currently open is safe, unsafe, trusted, or unrated, or whether it contains unwanted content.

The following color codes are used by TrendProtect to indicate the safety of each site.

Red for Warning
Yellow for Use Caution
Green for Safe
Grey for Unknown

11. Here are some helpful articles:
"So how did I get infected in the first place?"
by TonyKlein
http://computercops.biz/postlite7736-.html

"I'm not pulling your leg, honest"
by Sandi Hardmeier
http://www.microsoft.com/windows/IE/community/columns/pulling.mspx

12. This is an excellent resource for users of all levels. General computer maintenance as well as internet security is covered.
Rootkits for Dummies
(Paperback)
by Larry Stevenson (Author), Nancy Altholz (Author)

Let us know if we have not resolved your problem. Otherwise, you are good to go.
Happy and Safe Surfing!






















































































4 Apprentice

 • 

20.5K Posts

February 12th, 2008 02:00

Yes.
No Events found!

Top