UNSOLVED

auty21

updated

19 years ago

A

auty21

11 Posts

0

1293

February 10th, 2008 01:00

Trojan.Vundo in vtutq.dll

BitDefender keeps telling me that vtutq.dll is infected with the Trojan.Vundo but can't delete it seeing as it's a dll. I've tried VirtumundoBeGone and FixVundo but neither has shown signs of the trojan or it repiaring it. Her'es My HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 10:40:54 PM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {125FCE82-73E6-49D2-8312-9660D82E07DE} - (no file)
O2 - BHO: (no name) - {41A16134-ABD1-475D-AA59-3759757C2F16} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {F81D84CB-A4D9-4F7D-B041-427291A7BB0E} - C:\WINDOWS\system32\vtutq.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - Startup: PeerGuardian.lnk = C:\Program Files\PeerGuardian2\pg2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP Monitor (ASFIPmon) - Unknown owner - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe" -service (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe" /service (file missing)



And here's the VirtumundoBeGone log:


[02/09/2008, 22:41:25] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Austin\Desktop\VirtumundoBeGone.exe" )
[02/09/2008, 22:41:27] - Detected System Information:
[02/09/2008, 22:41:27] -  Windows Version: 5.1.2600, Service Pack 2
[02/09/2008, 22:41:27] -  Current Username: Austin (Admin)
[02/09/2008, 22:41:27] -  Windows is in NORMAL mode.
[02/09/2008, 22:41:27] - Searching for Browser Helper Objects:
[02/09/2008, 22:41:27] -  BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/09/2008, 22:41:27] -  BHO 2: {125FCE82-73E6-49D2-8312-9660D82E07DE} ()
[02/09/2008, 22:41:27] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/09/2008, 22:41:27] -  No filename found. Continuing.
[02/09/2008, 22:41:27] -  BHO 3: {41A16134-ABD1-475D-AA59-3759757C2F16} ()
[02/09/2008, 22:41:27] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/09/2008, 22:41:27] -  No filename found. Continuing.
[02/09/2008, 22:41:27] -  BHO 4: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
[02/09/2008, 22:41:27] -  BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/09/2008, 22:41:27] -  BHO 6: {F81D84CB-A4D9-4F7D-B041-427291A7BB0E} ()
[02/09/2008, 22:41:27] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/09/2008, 22:41:27] -  Checking for HKLM\...\Winlogon\Notify\vtutq
[02/09/2008, 22:41:27] -  Key not found: HKLM\...\Winlogon\Notify\vtutq, continuing.
[02/09/2008, 22:41:27] - Finished Searching Browser Helper Objects
[02/09/2008, 22:41:27] - Finishing up...
[02/09/2008, 22:41:27] - Nothing found! Exiting...
  • auty21

    11 Posts

    452

    0

    Posted February 10th, 2008 02:00

    I haven't posted this on any other forums yet, I haven't fixed any problems with HJT in the past, and all of the other stuff is fine.  Thanks for the quick reply and here's the new HJT log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:27:05 PM, on 2/9/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
    C:\Program Files\PeerGuardian2\pg2.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\BitDefender\BitDefender 2008\uiscan.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {125FCE82-73E6-49D2-8312-9660D82E07DE} - (no file)
    O2 - BHO: (no name) - {41A16134-ABD1-475D-AA59-3759757C2F16} - (no file)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {F81D84CB-A4D9-4F7D-B041-427291A7BB0E} - C:\WINDOWS\system32\vtutq.dll
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
    O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
    O4 - Startup: PeerGuardian.lnk = C:\Program Files\PeerGuardian2\pg2.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Broadcom ASF IP Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

    --
    End of file - 6355 bytes

  • Bugbatter

    4 Apprentice

    20487 Posts

    452

    0

    Posted February 10th, 2008 02:00


    Welcome. Thank you for using Dell Community Forums.
    I am reviewing your log.
    In the meantime, you can help me by doing the following:

    * Have you have posted this issue on another forum? If so, please provide a link to the topic.

    * If you are using any cracked software, please remove it.
    Definition of cracked software:
    http://en.wikipedia.org/wiki/Software_cracking

    * If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
    The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state.

    * If this computer belongs to someone else, do you have authority to apply the fixes we will use?

    * Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.

    * After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures.
    Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using.

    ** We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case.
    Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.

    You are using an outdated version of HijackThis. Please go to Add/Remove and uninstall it that way or by using the uninstaller within HijackThis.
    Please download HJT Installer for version 2.02 from Here to your desktop.
    If not available use this alternate link: Here
    • Click the Download button. When the Trend Micro HJT install box appears, double click on the HJTInstall.exe. Click on Install.
    • It will be installed by default here: C:\Program Files\Trend Micro\HijackThis.
    • A shortcut to the application will also be placed on your Desktop.
    • The program will open automatically after installation.
    • You can double-click the icon that was placed on the Desktop to run subsequent HijackThis scans or you can use the icon inside the folder. The folder HijackThis is where you will find the HJT logs that you save. When you use the application to remove anything, you will also find the backup copies made by HJT inside this folder.
    • The first time you open HijackThis, check the Main Menu button at the bottom center. When the main menu appears check the box "Show this window when I start HijackThis".
    • Click on "Do a system scan and save logfile."
      When the log pops up in Notepad, copy and paste that file back here.
    • DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
    • Before closing HJT, please click on the AnalyzeThis button. "Analyze This" DOES NOT mean "Analyze My Log". You will need to post your log on the forum.
    • Close the web page that appears and then close the program


    • * If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.

      I look forward to your reply.

  • Bugbatter

    4 Apprentice

    20487 Posts

    452

    0

    Posted February 10th, 2008 03:00

    Please print these instructions and refer to them for downloading and running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix


    Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.

    Note: The above instructions were created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
    You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert. It is intended by its creator to be used under the guidance and supervision of an expert, not for private use.






  • auty21

    11 Posts

    452

    0

    Posted February 10th, 2008 17:00

    When I attempted to install the Recovery Console it giving me an error saying that the file hpt3xx.sys was missing and the Console wouldn't work without it.
  • auty21

    11 Posts

    452

    0

    Posted February 10th, 2008 18:00

    I tried and was able to get ComboFix to still work. Here's the log:

    ComboFix 08-02.05.3 - Austin 2008-02-10 15:17:06.3 - NTFSx86
    Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1577 [GMT -5:00]
    Running from: C:\Documents and Settings\Austin\Desktop\ComboFix.exe
    .

    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    ---- Previous Run -------
    .
    C:\Documents and Settings\LocalService\Application Data\NetMon
    C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
    C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
    C:\Program Files\Common Files\racle~1
    C:\WINDOWS\b103.exe
    C:\WINDOWS\b116.exe
    C:\WINDOWS\b122.exe
    C:\WINDOWS\b147.exe
    C:\WINDOWS\b149.exe
    C:\WINDOWS\b151.exe
    C:\WINDOWS\system32\fnts~1
    C:\WINDOWS\system32\llkkj.ini
    C:\WINDOWS\system32\llkkj.ini2
    C:\WINDOWS\system32\qtutv.ini
    C:\WINDOWS\system32\qtutv.ini2
    C:\WINDOWS\system32\tsuninst.exe
    C:\WINDOWS\system32\vtutq.dll
    C:\WINDOWS\system32\x64

    .
    (((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))

    .
    -------\LEGACY_CMDSERVICE






    (((((((((((((((((((((((((   Files Created from 2008-01-10 to 2008-02-10  )))))))))))))))))))))))))))))))
    .

    2008-02-10 13:56 . 2008-02-10 14:48    60,416    --a------    C:\WINDOWS\system32\drivers\ComboFix.sys
    2008-02-10 13:43 . 2004-08-03 23:00    260,272    -r-hs----    C:\cmldr
    2008-02-10 12:48 . 2008-02-10 13:22        d--------    C:\XPSP2
    2008-02-10 12:47 . 2008-02-10 13:29        d--------    C:\XPCD
    2008-02-09 23:26 . 2008-02-09 23:26        d--------    C:\Program Files\Trend Micro
    2008-02-08 20:26 . 2008-02-08 20:26        d--------    C:\Documents and Settings\David\Application Data\Sonic
    2008-02-08 16:22 . 2008-02-08 16:22        d--------    C:\Documents and Settings\David\Application Data\vlc
    2008-02-08 16:07 . 2008-02-08 16:14        d--------    C:\Documents and Settings\David\Application Data\uTorrent
    2008-02-08 15:58 . 2008-02-08 15:58        d--------    C:\Documents and Settings\David\Application Data\dvdcss
    2008-02-08 15:57 . 2005-11-21 00:48    45,056    --a------    C:\WINDOWS\system32\WNASPI32.DLL
    2008-02-08 15:57 . 2005-11-21 00:48    16,512    --a------    C:\WINDOWS\system32\drivers\ASPI32.SYS
    2008-02-08 15:38 . 2008-02-08 15:38        d--------    C:\Program Files\Combined Community Codec Pack
    2008-02-05 14:12 . 2008-02-05 14:12        d--------    C:\Documents and Settings\Barbara\Application Data\BitDefender
    2008-01-31 20:19 . 2008-01-31 20:19        d--------    C:\Documents and Settings\David\Application Data\BitDefender
    2008-01-31 15:16 . 2008-02-10 15:12    121    --a------    C:\WINDOWS\bdagent.INI
    2008-01-31 14:52 . 2008-01-31 14:52        d--------    C:\Documents and Settings\Austin\Application Data\BitDefender
    2008-01-31 14:51 . 2008-01-31 14:51        d--------    C:\Program Files\BitDefender
    2008-01-31 14:51 . 2008-01-31 14:52        d--------    C:\Documents and Settings\All Users\Application Data\BitDefender
    2008-01-31 14:48 . 2008-01-31 14:51        d--------    C:\Program Files\Common Files\BitDefender
    2008-01-31 09:46 . 2008-01-31 09:46        d--------    C:\WINDOWS\system32\DAE0E2DEE3E3E7
    2008-01-26 00:46 . 2008-01-26 00:46        d--------    C:\Program Files\uTorrent
    2008-01-26 00:46 . 2008-02-10 15:11        d--------    C:\Documents and Settings\Austin\Application Data\uTorrent
    2008-01-16 07:16 . 2008-01-16 07:16        d--------    C:\Program Files\iTunes
    2008-01-16 07:16 . 2008-01-16 07:16        d--------    C:\Program Files\iPod
    2008-01-16 07:16 . 2008-02-09 22:21    54,156    --ah-----    C:\WINDOWS\QTFont.qfn
    2008-01-16 07:16 . 2008-01-16 07:16    1,409    --a------    C:\WINDOWS\QTFont.for
    2008-01-16 07:15 . 2008-01-16 07:15        d--------    C:\Program Files\QuickTime
    2008-01-10 15:27 . 2008-01-10 15:27    90,112    --a------    C:\WINDOWS\system32\QuickTimeVR.qtx
    2008-01-10 15:27 . 2008-01-10 15:27    57,344    --a------    C:\WINDOWS\system32\QuickTime.qts

    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-02-10 19:51    ---------    d-----w    C:\Program Files\PeerGuardian2
    2008-02-10 02:11    ---------    d-----w    C:\Program Files\Common Files\Adobe
    2008-02-10 01:54    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\River Past G5
    2008-02-05 17:18    85,520    ----a-w    C:\WINDOWS\system32\drivers\bdfndisf.sys
    2008-01-31 14:10    10    ----a-w    C:\Program Files\.autoreg
    2008-01-07 22:41    196,368    ----a-w    C:\WINDOWS\system32\drivers\bdfsfltr.sys
    2007-12-25 05:09    ---------    d--h--w    C:\Program Files\Zero G Registry
    2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\David\Application Data\Gtek
    2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\Barbara\Application Data\Gtek
    2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\Austin\Application Data\Gtek
    2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\Administrator\Application Data\GTek
    2007-12-19 01:27    ---------    d--h--w    C:\Program Files\InstallShield Installation Information
    2007-12-19 01:27    ---------    d-----w    C:\Program Files\Creative
    2007-12-19 01:25    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\AOL
    2007-12-16 18:19    ---------    d-----w    C:\Program Files\TI Education
    2007-12-16 18:19    ---------    d-----w    C:\Program Files\Common Files\TI Shared
    2007-12-16 18:19    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\McAfee
    2007-12-16 18:17    ---------    d-----w    C:\Program Files\Common Files\Wise Installation Wizard
    2007-12-10 23:49    ---------    d-----w    C:\Program Files\Common Files\Cisco Systems
    2007-12-10 23:11    ---------    d-----w    C:\Program Files\Google
    2007-12-10 21:31    66,484    ----a-w    C:\Documents and Settings\All Users\Application Data\firstlsp.reg.dat
    2007-12-10 21:19    ---------    d-----w    C:\Documents and Settings\Austin\Application Data\Sony
    2007-12-10 21:19    ---------    d-----w    C:\Documents and Settings\Austin\Application Data\Publish Providers
    2007-12-10 21:17    ---------    d-----w    C:\Program Files\Sony
    2007-12-10 21:15    ---------    d-----w    C:\Program Files\Sony Setup
    2007-11-27 21:46    77,824    ----a-w    C:\WINDOWS\system32\xcomm.dll
    2007-11-14 07:26    450,560    ------w    C:\WINDOWS\system32\dllcache\jscript.dll
    .

    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {381FFDE8-2394-4F90-B10D-FC6124A40F8C}

    [HKEY_CLASSES_ROOT\clsid\{381ffde8-2394-4f90-b10d-fc6124a40f8c}]
    [HKEY_CLASSES_ROOT\BitDefender Toolbar]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 10:37 2321600]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-02-05 12:18 360448]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "OE"="C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [ ]

    C:\Documents and Settings\Austin\Start Menu\Programs\Startup\
    PeerGuardian.lnk - C:\Program Files\PeerGuardian2\pg2.exe [2007-05-22 15:34:38 1421824]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\A0A6A8A4A9A9ADAB]


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]
    --a------ 2005-09-08 05:20 122940 C:\WINDOWS\System32\DLA\DLACTRLW.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
    --------- 2005-12-09 20:29 49152 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Insider]
    C:\Program Files\Insider\Insider.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
    --a------ 2004-07-27 16:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    C:\Program Files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OE]
    C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
    C:\WINDOWS\mrofinu1044.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tair]
    C:\DOCUME~1\Austin\MYDOCU~1\ASKS~1\ati2evxx.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UfSeAgnt.exe]
    C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe

    R1 bdftdif;bdftdif;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys [2008-02-05 10:48]
    R2 ASFIPmon;Broadcom ASF IP Monitor;"C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe" [2006-03-17 17:25]
    R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-02-05 12:18]
    R3 bdfsfltr;bdfsfltr;C:\WINDOWS\system32\drivers\bdfsfltr.sys [2008-01-07 17:41]
    R3 BDSelfPr;BDSelfPr;C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys [2008-01-31 14:54]
    R3 scan;BitDefender Threat Scanner;C:\WINDOWS\System32\svchost.exe [2004-08-04 06:00]
    S3 avfwim;AvFw Packet Filter Miniport;C:\WINDOWS\system32\DRIVERS\avfwim.sys []

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bdx    REG_MULTI_SZ       scan

    .
    Contents of the 'Scheduled Tasks' folder
    "2008-02-06 12:08:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-02-10 15:20:35
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2008-02-10 15:22:07
    ComboFix-quarantined-files.txt  2008-02-10 20:22:03
    .
    2008-01-16 02:56:14    --- E O F --- 





    Here's the new HJT log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:26:22 PM, on 2/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
    O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
    O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
    O4 - Startup: PeerGuardian.lnk = C:\Program Files\PeerGuardian2\pg2.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Broadcom ASF IP Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

    --
    End of file - 4437 bytes

  • Bugbatter

    4 Apprentice

    20487 Posts

    452

    0

    Posted February 10th, 2008 21:00


    Good job. The Recovery Console is just a safety net. ComboFix will work without it.
    Open Notepad and copy/paste the following text between the lines.
    ** Make sure you copy/paste ALL the text at once. Do not try to edit extra spaces. It will copy correctly to Notepad if you highlight and copy as is.
    -----------------------------

    File::
    C:\WINDOWS\mrofinu1044.exe


    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]


    ------------------------------------

    Save this as CFScript.txt
    Photobucket

    Referring to the picture above, drag CFScript into ComboFix.exe
    You will be prompted to run Combofix again. Follow the same instructions you did before for running ComboFix.
    CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

    When finished, a log is produced here: C:\ComboFix.txt

    In your next reply, please post that log along with a new HijackThis log.
    Message Edited by Bugbatter on 02-10-2008 06:08 PM
  • auty21

    11 Posts

    452

    0

    Posted February 10th, 2008 21:00

    Alright, I keep getting an error after I drag CFScript onto ComboFix after ComboFix begins to open.
    It says "You cannot rename ComboFix as ComboFix.    Please use another name."

    I tried recreating the CFScript and even redownloading the ComboFix file but bot just reproduced the same error after trying it again.
  • Bugbatter

    4 Apprentice

    20487 Posts

    452

    0

    Posted February 10th, 2008 22:00

    That usually happens if you aborted a previous run of ComboFix by closing the DOS box leaving some processes still running.
    Please reboot and try again .
  • auty21

    11 Posts

    452

    0

    Posted February 11th, 2008 01:00

    Thanks, you were right. Here's the ComboFix log:

    ComboFix 08-02.05.3 - Austin 2008-02-10 22:36:03.5 - NTFSx86
    Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1564 [GMT -5:00]
    Running from: C:\Documents and Settings\Austin\Desktop\ComboFix.exe
    Command switches used :: C:\Documents and Settings\Austin\Desktop\CFScript.txt
     * Created a new restore point

    FILE
    C:\WINDOWS\mrofinu1044.exe
    .

    (((((((((((((((((((((((((   Files Created from 2008-01-11 to 2008-02-11  )))))))))))))))))))))))))))))))
    .

    2008-02-10 18:23 . 2004-08-04 06:00    388,608    --a------    C:\kmd.exe
    2008-02-10 17:57 . 2004-08-04 00:56    1,737,856    ---------    C:\WINDOWS\system32\mtxparhd.dll
    2008-02-10 17:57 . 2004-08-04 00:56    397,056    ---------    C:\WINDOWS\system32\s3gnb.dll
    2008-02-10 17:57 . 2004-08-04 00:56    286,792    ---------    C:\WINDOWS\system32\slextspk.dll
    2008-02-10 17:57 . 2004-08-04 00:56    188,508    ---------    C:\WINDOWS\system32\slgen.dll
    2008-02-10 17:57 . 2004-08-04 00:56    73,832    ---------    C:\WINDOWS\system32\slcoinst.dll
    2008-02-10 17:57 . 2004-08-04 00:56    73,796    ---------    C:\WINDOWS\system32\slserv.exe
    2008-02-10 17:57 . 2004-08-04 00:56    32,866    ---------    C:\WINDOWS\system32\slrundll.exe
    2008-02-10 17:57 . 2004-08-04 00:56    32,866    ---------    C:\WINDOWS\slrundll.exe
    2008-02-10 17:57 . 2004-08-04 00:56    28,672    ---------    C:\WINDOWS\system32\vidcap.ax
    2008-02-10 17:53 . 2008-02-10 17:53        d--------    C:\WINDOWS\ServicePackFiles
    2008-02-10 17:52 . 2004-07-17 11:40    19,528    --a------    C:\WINDOWS\ 000001_.tmp
    2008-02-10 13:43 . 2004-08-03 23:00    260,272    -r-hs----    C:\cmldr
    2008-02-10 12:48 . 2008-02-10 13:22        d--------    C:\XPSP2
    2008-02-10 12:47 . 2008-02-10 13:29        d--------    C:\XPCD
    2008-02-09 23:26 . 2008-02-09 23:26        d--------    C:\Program Files\Trend Micro
    2008-02-08 20:26 . 2008-02-08 20:26        d--------    C:\Documents and Settings\David\Application Data\Sonic
    2008-02-08 16:22 . 2008-02-08 16:22        d--------    C:\Documents and Settings\David\Application Data\vlc
    2008-02-08 16:07 . 2008-02-08 16:14        d--------    C:\Documents and Settings\David\Application Data\uTorrent
    2008-02-08 15:58 . 2008-02-08 15:58        d--------    C:\Documents and Settings\David\Application Data\dvdcss
    2008-02-08 15:57 . 2005-11-21 00:48    45,056    --a------    C:\WINDOWS\system32\WNASPI32.DLL
    2008-02-08 15:57 . 2005-11-21 00:48    16,512    --a------    C:\WINDOWS\system32\drivers\ASPI32.SYS
    2008-02-08 15:38 . 2008-02-08 15:38        d--------    C:\Program Files\Combined Community Codec Pack
    2008-02-05 14:12 . 2008-02-05 14:12        d--------    C:\Documents and Settings\Barbara\Application Data\BitDefender
    2008-01-31 20:19 . 2008-01-31 20:19        d--------    C:\Documents and Settings\David\Application Data\BitDefender
    2008-01-31 15:16 . 2008-02-10 18:13    121    --a------    C:\WINDOWS\bdagent.INI
    2008-01-31 14:52 . 2008-01-31 14:52        d--------    C:\Documents and Settings\Austin\Application Data\BitDefender
    2008-01-31 14:51 . 2008-01-31 14:51        d--------    C:\Program Files\BitDefender
    2008-01-31 14:51 . 2008-01-31 14:52        d--------    C:\Documents and Settings\All Users\Application Data\BitDefender
    2008-01-31 14:48 . 2008-01-31 14:51        d--------    C:\Program Files\Common Files\BitDefender
    2008-01-31 09:46 . 2008-01-31 09:46        d--------    C:\WINDOWS\system32\DAE0E2DEE3E3E7
    2008-01-26 00:46 . 2008-01-26 00:46        d--------    C:\Program Files\uTorrent
    2008-01-26 00:46 . 2008-02-10 15:11        d--------    C:\Documents and Settings\Austin\Application Data\uTorrent
    2008-01-16 07:16 . 2008-01-16 07:16        d--------    C:\Program Files\iTunes
    2008-01-16 07:16 . 2008-01-16 07:16        d--------    C:\Program Files\iPod
    2008-01-16 07:16 . 2008-02-10 15:57    54,156    --ah-----    C:\WINDOWS\QTFont.qfn
    2008-01-16 07:16 . 2008-01-16 07:16    1,409    --a------    C:\WINDOWS\QTFont.for
    2008-01-16 07:15 . 2008-01-16 07:15        d--------    C:\Program Files\QuickTime

    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-02-11 03:34    ---------    d-----w    C:\Program Files\PeerGuardian2
    2008-02-10 02:11    ---------    d-----w    C:\Program Files\Common Files\Adobe
    2008-02-10 01:54    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\River Past G5
    2008-02-05 17:18    85,520    ----a-w    C:\WINDOWS\system32\drivers\bdfndisf.sys
    2008-01-31 14:10    10    ----a-w    C:\Program Files\.autoreg
    2008-01-07 22:41    196,368    ----a-w    C:\WINDOWS\system32\drivers\bdfsfltr.sys
    2007-12-25 05:09    ---------    d--h--w    C:\Program Files\Zero G Registry
    2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\David\Application Data\Gtek
    2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\Barbara\Application Data\Gtek
    2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\Austin\Application Data\Gtek
    2007-12-19 01:29    ---------    d--h--w    C:\Documents and Settings\Administrator\Application Data\GTek
    2007-12-19 01:27    ---------    d--h--w    C:\Program Files\InstallShield Installation Information
    2007-12-19 01:27    ---------    d-----w    C:\Program Files\Creative
    2007-12-19 01:25    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\AOL
    2007-12-16 18:19    ---------    d-----w    C:\Program Files\TI Education
    2007-12-16 18:19    ---------    d-----w    C:\Program Files\Common Files\TI Shared
    2007-12-16 18:19    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\McAfee
    2007-12-16 18:17    ---------    d-----w    C:\Program Files\Common Files\Wise Installation Wizard
    2007-12-10 21:31    66,484    ----a-w    C:\Documents and Settings\All Users\Application Data\firstlsp.reg.dat
    2007-11-27 21:46    77,824    ----a-w    C:\WINDOWS\system32\xcomm.dll
    2007-11-14 07:26    450,560    ------w    C:\WINDOWS\system32\dllcache\jscript.dll
    .

    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {381FFDE8-2394-4F90-B10D-FC6124A40F8C}

    [HKEY_CLASSES_ROOT\clsid\{381ffde8-2394-4f90-b10d-fc6124a40f8c}]
    [HKEY_CLASSES_ROOT\BitDefender Toolbar]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-02-05 12:18 360448]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "OE"="C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [ ]

    C:\Documents and Settings\Austin\Start Menu\Programs\Startup\
    PeerGuardian.lnk - C:\Program Files\PeerGuardian2\pg2.exe [2007-05-22 15:34:38 1421824]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\A0A6A8A4A9A9ADAB]


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
    -ra------ 2007-03-01 10:37 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]
    --a------ 2005-09-08 05:20 122940 C:\WINDOWS\System32\DLA\DLACTRLW.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
    --------- 2005-12-09 20:29 49152 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Insider]
    C:\Program Files\Insider\Insider.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
    --a------ 2004-07-27 16:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --------- 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OE]
    C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tair]
    C:\DOCUME~1\Austin\MYDOCU~1\ASKS~1\ati2evxx.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UfSeAgnt.exe]
    C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe

    R1 bdftdif;bdftdif;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys [2008-02-05 10:48]
    R2 ASFIPmon;Broadcom ASF IP Monitor;"C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe" [2006-03-17 17:25]
    R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-02-05 12:18]
    R3 bdfsfltr;bdfsfltr;C:\WINDOWS\system32\drivers\bdfsfltr.sys [2008-01-07 17:41]
    R3 BDSelfPr;BDSelfPr;C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys [2008-01-31 14:54]
    R3 scan;BitDefender Threat Scanner;C:\WINDOWS\System32\svchost.exe [2004-08-04 06:00]
    S3 avfwim;AvFw Packet Filter Miniport;C:\WINDOWS\system32\DRIVERS\avfwim.sys []

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bdx    REG_MULTI_SZ       scan

    .
    Contents of the 'Scheduled Tasks' folder
    "2008-02-06 12:08:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-02-10 22:40:03
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2008-02-10 22:40:43
    ComboFix2.txt  2008-02-10 23:47:11
    .
    2008-02-10 23:39:17    --- E O F --- 
  • auty21

    11 Posts

    320

    0

    Posted February 11th, 2008 01:00

    and here's the HJT log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:43:14 PM, on 2/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070329
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
    O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
    O4 - Startup: PeerGuardian.lnk = C:\Program Files\PeerGuardian2\pg2.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Broadcom ASF IP Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

    --
    End of file - 4312 bytes