UNSOLVED

mnarteach

updated

18 years ago

M

mnarteach

144 Posts

0

1514

December 16th, 2008 05:00

TDSSSERV.Sys and hijack this log

Hi, A few days ago I started having troubles.  I ran my SuperAnti Spyware free edition only to find out that I had a trojan virus.  I could not get rid of it so downloaded malware.  That seemed to take care of that problem.  Now I run my SAS and it says that I have 10 TDSSServ.Sys on my computer.  I follow their directions to rid my computer of it, shut it down and it returns.  I have my system restore turned off.  I made a hijack this log and have no idea how to read it.  I am hoping that you can help me get this stuff off my computer and keep it off.  HELP!  I have been running the trend penicillin virus scan and have kept it up to date.  It doesn't seem to catch any of these.  I installed that AntiVir to see if that would help.  I think I need a spyware that will catch the stuff if it comes in but not sure if there is a good free one.

Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:10:53 AM, on 12/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Canon\Memory Card Utility\iP6700D\PDUiP6700DMon.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\hphmon03.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Documents and Settings\Linda Reilley\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\HPHipm09.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1080410
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1080410
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [PDUiP6700DMon] C:\Program Files\Canon\Memory Card Utility\iP6700D\PDUiP6700DMon.exe
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe resetprofile
O4 - HKCU\..\Run: [DellAutomatedPCTuneUp] "C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SansaDispatch] C:\Documents and Settings\Linda Reilley\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKCU\..\Run: [windpipe] "C:\Documents and Settings\Linda Reilley\Application Data\Google\fhexj6825097.exe" 2
O4 - HKUS\S-1-5-19\..\Run: [jubimasusu] Rundll32.exe "C:\WINDOWS\system32\sahahura.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [jubimasusu] Rundll32.exe "C:\WINDOWS\system32\sahahura.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x08c5 -f video -m logitech -d 11.0.0.1217 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x08c5 -f video -m logitech -d 11.0.0.1217 (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1210388825956
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1210388810925
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://66.255.127.85/AxisCamControl.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL  c:\windows\system32\tayunazi.dll 
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

--
End of file - 10434 bytes

  • Bugbatter

    4 Apprentice

    20487 Posts

    422

    0

    Posted December 16th, 2008 06:00

    Welcome. Thank you for using Dell Community Forums.

    I am reviewing your log. In the meantime, you can help me by addressing the following:

    * Please enable System Restore NOW!  We will purge your infected restore points at the end of our fix.

    * You are doing more harm than good by running two anti-virus programs in realtime. Please remove one.

    * Have you have posted this issue on another forum? If so, please provide a link to the topic.

    * If you have disabled System Restore in an attempt to begin cleaning malware, please enable it now. We will flush System Restore when we are finished cleaning and we are sure that everything is running smoothly.

    * If you are using any cracked software, please remove it. Definition of cracked software: http://en.wikipedia.org/wiki/Software_cracking

    * If you are using any P2P (file sharing) programs, please remove them before we clean your computer.  The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. There is a list here:    http://en.community.dell.com/forums/p/19241146/19367569.aspx#19367569

    * If this computer belongs to someone else, do you have authority to apply the fixes we will use?

    * Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.

    * After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures. Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using. Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

    * During the course of our cleanup please do not do any online work or surfing until we have verified that your system is clean.

    * We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case. Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.

    * If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.

    I look forward to your reply so we can begin cleaning.

    Instructions posted for this user are customized for this user only. The tools used may cause damage if used on a computer with different infections. If you think you have similar problems, please post a HijackThis log at the top of this board to start a new forum topic.

  • mnarteach

    144 Posts

    424

    0

    Posted December 16th, 2008 07:00

    Which virus scan would be a better choice?  Trend Penicillin or the AntiVir? I desperate what can I say?:emotion-1:  And yes it is my computer and I can run the files.

    Thanks

  • mnarteach

    144 Posts

    424

    0

    Posted December 16th, 2008 09:00

    I previously downloaded and ran malwarebytes.  It says there is nothing yet SuperSpyWare says there is 10 root kits.  The hijack post is after I ran these 2 programs.  I've had SuperSpyWare remove them rebooted and ran it all again.  Then Marware says there is nothing and SSW says there is 5.  So what is going on do I have a problem or not?  thanks

  • Bugbatter

    4 Apprentice

    20487 Posts

    424

    0

    Posted December 16th, 2008 09:00

    If you have a paid UPDATED version of TM, you might as well keep that. You can always go to AntiVir Free version when TM expires.

    Please download Malwarebytes Anti-Malware and save it to your desktop.
    alternate download link 1
    alternate download link 2

    • Make sure you are connected to the Internet.
    • Double-click on mbam-setup.exe to install the application.
    • When the installation begins, follow the prompts and do not make any changes to default settings.
    • When installation has finished, make sure you leave both of these checked:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
    • Then click Finish.

    MBAM will automatically start and you will be asked to update the program before performing a scan.

    • If an update is found, the program will automatically update itself.
    • Press the OK button to close that box and continue.
    • If you encounter any problems while downloading the updates,
    • manually download them from here
      and just double-click on mbam-rules.exe to install.
      Alternatively, you can update through MBAM's interface from a clean computer,
      copy the definitions (rules.ref) located in
      C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes'
      Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.

    On the Scanner tab:

    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
    • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
    • The scan will begin and "Scan in progress" will show at the top.
    • It may take some time to complete so please be patient.
    • When the scan is finished, a message box will say "The scan completed successfully.
    • Click 'Show Results' to display all objects found".
    • Click OK to close the message box and continue with the removal process.

    Back at the main Scanner screen:

    • Click on the Show Results button to see a list of any malware that was found.
    • Make sure that everything is checked, and click Remove Selected.
    • When removal is completed, a log report will open in Notepad.
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the contents of that report along with a fresh HijackThis log into your next reply and exit MBAM.

    Note:-- If MBAM encounters a file that is difficult to remove,
    you may be asked to reboot your computer so it can proceed with the disinfection process.
    Regardless if prompted to restart the computer or not, please do so immediately.
    Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

    -- MBAM may make changes to your registry as part of its disinfection routine.
    If you're using other security programs that detect registry changes (like Spybot's Teatimer),
    they may interfere with the fix or alert you after scanning with MBAM.
    Please disable such programs until disinfection is complete or permit them to allow the changes.

     

  • mnarteach

    144 Posts

    424

    0

    Posted December 16th, 2008 16:00

    I just put my system restore back on. I ran MalwareBytes and it says everything is fine. Then I ran SuperSpyWare and it says that there is 10 TDSSERV.SYS.  Deleted them, shut down started back up again and it is the same thing.  Keeps happening over and over and over.  I have never had anything like this on SuperSpyWare.

  • Bugbatter

    4 Apprentice

    20487 Posts

    424

    0

    Posted December 16th, 2008 16:00

    Please post:

    1. Your Super Anti-Spyware log

    2. Your most recent MBAM log

  • mnarteach

    144 Posts

    424

    0

    Posted December 16th, 2008 19:00

     

    Super Anti-Spyware log:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 12/16/2008 at 05:43 PM

    Application Version : 4.15.1000

    Core Rules Database Version : 3675
    Trace Rules Database Version: 1654

    Scan type       : Complete Scan
    Total Scan Time : 00:20:38

    Memory items scanned      : 400
    Memory threats detected   : 0
    Registry items scanned    : 5392
    Registry threats detected : 10
    File items scanned        : 20290
    File threats detected     : 0

    Rootkit.TDSServ
        HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys
        HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys#start
        HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys#type
        HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys#imagepath
        HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys#group
        HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\Enum
        HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\Enum#0
        HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\Enum#Count
        HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\Enum#NextInstance
        HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\Enum#INITSTARTFAILED

    This is my MBAM log:

    Malwarebytes' Anti-Malware 1.31
    Database version: 1494
    Windows 5.1.2600 Service Pack 2

    12/16/2008 5:22:28 PM
    mbam-log-2008-12-16 (17-22-28).txt

    Scan type: Quick Scan
    Objects scanned: 52992
    Time elapsed: 2 minute(s), 41 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

  • Bugbatter

    4 Apprentice

    20487 Posts

    424

    0

    Posted December 16th, 2008 20:00

    Please visit this webpage for download links, and instructions for running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

      * Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log and your MBAM log for further review.

  • mnarteach

    144 Posts

    424

    0

    Posted December 17th, 2008 17:00

    I think it's fixed???!!!!!!

    My logs:

    ComboFix 08-12-16.03 - Linda Reilley 2008-12-17 19:20:31.1 - NTFSx86
    Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.3325.2493 [GMT -6:00]
    Running from: c:\documents and settings\Linda Reilley\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Linda Reilley\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
     * Created a new restore point
    .

    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\temp\1cb
    c:\temp\1cb\syscheck.log
    c:\temp\FT62
    c:\temp\FT62\teTU.log
    c:\temp\tn3
    c:\windows\system32\dim
    c:\windows\system32\dPI19
    c:\windows\system32\gp2
    c:\windows\system32\ID2

    .
    (((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_TDSSSERV.SYS
    -------\Service_TDSSserv.sys


    (((((((((((((((((((((((((   Files Created from 2008-11-18 to 2008-12-18  )))))))))))))))))))))))))))))))
    .

    2008-12-15 21:07 . 2008-12-15 20:51    102,664    --a------    c:\windows\system32\drivers\tmcomm.sys
    2008-12-15 20:51 . 2008-12-15 21:22   

        d--------    c:\documents and settings\Linda Reilley\.housecall6.6
    2008-12-14 07:17 . 2008-12-14 07:22    120    --a------    c:\windows\CIS_Setup_3.5.57173.439_XP_Vista_x32.INI
    2008-12-14 07:11 . 2008-12-14 07:16        d--------    c:\program files\SpywareBlaster
    2008-12-14 07:11 . 2008-12-16 06:34        d-a------    c:\documents and settings\All Users\Application Data\TEMP
    2008-12-12 16:34 . 2008-12-12 16:34        d--------    c:\program files\Malwarebytes' Anti-Malware
    2008-12-12 16:34 . 2008-12-12 16:34        d--------    c:\documents and settings\Linda Reilley\Application Data\Malwarebytes
    2008-12-12 16:34 . 2008-12-12 16:34        d--------    c:\documents and settings\All Users\Application Data\Malwarebytes
    2008-12-12 16:34 . 2008-12-03 19:53    38,496    --a------    c:\windows\system32\drivers\mbamswissarmy.sys
    2008-12-12 16:34 . 2008-12-03 19:53    15,504    --a------    c:\windows\system32\drivers\mbam.sys
    2008-12-11 21:48 . 2008-12-11 21:48        d--------    c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
    2008-12-11 21:25 . 2008-12-11 21:25        d--------    c:\program files\Enigma Software Group
    2008-12-11 21:16 . 2008-12-11 21:16        d--------    c:\program files\Common Files\Download Manager
    2008-11-22 09:15 . 2008-11-22 09:15    115,016    --a------    c:\windows\system32\MSINET.OCX

    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-18 01:23    0    ----a-w    c:\windows\system32\drivers\lvuvc.hs
    2008-12-14 13:06    ---------    d-----w    c:\program files\Coupons
    2008-11-23 18:46    ---------    d-----w    c:\program files\Trend Micro
    2008-11-22 21:53    ---------    d--h--w    c:\program files\InstallShield Installation Information
    2008-11-02 01:34    ---------    d-----w    c:\documents and settings\Linda Reilley\Application Data\SanDisk
    2008-11-02 01:30    ---------    d-----w    c:\program files\SanDisk
    2008-11-01 00:51    ---------    d-----w    c:\documents and settings\Linda Reilley\Application Data\LimeWire
    2008-10-24 11:10    453,632    ----a-w    c:\windows\system32\drivers\mrxsmb.sys
    2008-09-05 00:21    61,224    -c--a-w    c:\documents and settings\Linda Reilley\GoToAssistDownloadHelper.exe
    .

    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "OE_OEM"="c:\program files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [2006-08-04 321040]
    "NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2008-01-15 106496]
    "DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-09 68856]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-07 1506544]
    "SansaDispatch"="c:\documents and settings\Linda Reilley\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2008-11-01 79872]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-14 8523776]
    "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
    "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
    "PDUiP6700DMon"="c:\program files\Canon\Memory Card Utility\iP6700D\PDUiP6700DMon.exe" [2006-03-16 61440]
    "NVRaidService"="c:\windows\system32\nvraidservice.exe" [2007-10-26 184352]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
    "HPHmon03"="c:\windows\system32\hphmon03.exe" [2006-01-13 311296]
    "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2006-01-13 196608]
    "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-01-17 17920]
    "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-03-21 1191936]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-12-22 67752]
    "RTHDCPL"="RTHDCPL.EXE" [2008-01-14 c:\windows\RTHDCPL.EXE]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2007-05-11 441120]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-23 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
    2008-09-04 18:21 10536 c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "VIDC.ACDV"= ACDV.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    --a------ 2008-04-09 21:55 1838592 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --a------ 2004-10-13 10:24 1694208 c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pccguide.exe]
    --a------ 2006-11-21 13:02 1807960 c:\program files\Trend Micro\Internet Security 14\pccguide.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
    -ra------ 2008-06-03 14:27 21718312 c:\program files\Skype\Phone\Skype.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
    --------- 2008-06-07 19:21 1506544 c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    --a------ 2008-04-09 21:55 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "gusvc"=3 (0x3)
    "GoogleDesktopManager"=3 (0x3)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001
    "AntiVirusOverride"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
    "c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\WINDOWS\\system32\\sessmgr.exe"=

    R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-02-29 8944]
    R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-02-29 55024]
    R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\DRIVERS\datunidr.sys [2007-08-23 5376]
    R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2007-11-08 345696]
    R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2007-11-08 923216]
    R2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2007-11-08 36368]
    R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2007-11-08 566872]
    R3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [2008-04-26 18864]
    R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2006-02-16 4096]
    R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\DRIVERS\TM_CFW.sys [2007-11-08 280392]
    S1 fastfatt;fastfatt;c:\windows\system32\drivers\fastfatt.sys []
    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-11 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-windpipe - c:\documents and settings\Linda Reilley\Application Data\Google\fhexj6825097.exe


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.yahoo.com/
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    mDefault_Search_URL = hxxp://www.google.com/ie
    mStart Page = hxxp://www.dell.com
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie

    c:\windows\Downloaded Program Files\vzTCPConfig.dll - O16 -: vzTCPConfig
    hxxp://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CAB
    c:\windows\Downloaded Program Files\OSD22.OSD
    FF - ProfilePath - c:\documents and settings\Linda Reilley\Application Data\Mozilla\Firefox\Profiles\696smvlx.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
    FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
    FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
    FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
    FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
    FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
    FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
    FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-17 19:23:44
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1016)
    c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
    c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
    c:\windows\system32\nvsvc32.exe
    c:\progra~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    c:\windows\system32\wdfmgr.exe
    c:\progra~1\TRENDM~1\INTERN~1\pccguide.exe
    c:\windows\system32\hphipm09.exe
    c:\windows\system32\wbem\unsecapp.exe
    c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
    .
    **************************************************************************
    .
    Completion time: 2008-12-17 19:25:28 - machine was rebooted
    ComboFix-quarantined-files.txt  2008-12-18 01:25:26

    Pre-Run: 731,297,361,920 bytes free
    Post-Run: 731,449,180,160 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    198    --- E O F ---    2008-12-18 00:32:11

     

    SuperAntiSpyware:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 12/17/2008 at 07:48 PM

    Application Version : 4.15.1000

    Core Rules Database Version : 3675
    Trace Rules Database Version: 1654

    Scan type       : Complete Scan
    Total Scan Time : 00:21:48

    Memory items scanned      : 393
    Memory threats detected   : 0
    Registry items scanned    : 5388
    Registry threats detected : 0
    File items scanned        : 20251
    File threats detected     : 0

    Malwarebytes:

    Malwarebytes' Anti-Malware 1.31
    Database version: 1494
    Windows 5.1.2600 Service Pack 2

    12/17/2008 7:54:16 PM
    mbam-log-2008-12-17 (19-54-16).txt

    Scan type: Quick Scan
    Objects scanned: 52203
    Time elapsed: 2 minute(s), 3 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

  • Bugbatter

    4 Apprentice

    20487 Posts

    224

    0

    Posted December 17th, 2008 18:00

    That sounds like good news. Please post a fresh HijackThis log.