Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help.

Reply
 
LinkBack Thread Tools
Old 05-14-2009, 03:06 PM   #1 (permalink)
Registered User
 
Join Date: May 2009
Location: NJ
Posts: 6
OS: win XP sp 3


annoying peice of malware

ok here is whats going on.

in fire fox and internet explorer, when i use google and click a link, it redirects me to a totally different site than the link specifies every time. Zonealarm wont update says it can connect, despite the internet is working. Im noticing the computer is crashing and a little slower than usual here is the logs on what not you asked for:


DDS (Ver_09-05-14.01) - NTFSx86
Run by dude at 16:07:18.92 on Wed 05/13/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.553 [GMT -4:00]

AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Outdated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\WZCBDL Service\WZCBDLS.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Digital Media Reader\shwicon2k.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\D-Link\Air USB Utility\AirCFG.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\dude\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {09c72999-5c10-41a3-a524-24661d942003} - c:\windows\system32\vtUmnOiJ.dll
BHO: {15bc4a4e-b8b5-47f1-a9b5-fc407d4b7067} - c:\windows\system32\mlJBSkhI.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {08c94d8e-c44d-8a8a-72d4-462b4ea1d365}: {563d1ae4-b264-4d27-a8a8-d44ce8d49c80} - c:\windows\system32\izszba.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [<NO NAME>]
mRun: [SunKist] c:\program files\digital media reader\shwicon2k.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY
mRun: [D-Link Air USB Utility] c:\program files\d-link\air usb utility\AirCFG.exe
mRun: [ChangeFilterMerit] c:\program files\newsoft\presto! wms2.5\ChangeFilterMerit.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [ace040f7] rundll32.exe "c:\windows\system32\wchjilid.dll",b
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1232684135744
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk/6u12-b04/jinstall-6u12-windows-i586-jc.cab?e=1235255957956&h=fb6885e5a69b40c2c15f2f812ee0b4cf/&filename=jinstall-6u12-windows-i586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
TCP: NameServer = 85.255.112.107,85.255.112.226
TCP: {B8472F9A-FF66-4CA2-AEA8-9687EA94BFA1} = 85.255.112.107,85.255.112.226
TCP: {FAF81239-79F5-44CC-8E20-60B30D9E5771} = 85.255.112.107,85.255.112.226
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: vtUmnOiJ - vtUmnOiJ.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: {09c72999-5c10-41a3-a524-24661d942003} - c:\windows\system32\vtUmnOiJ.dll
SEH: {1b26e755-278e-0db9-a564-57ee27e40c36}: {63c04e72-ee75-465a-9bd0-e872557e62b1} - c:\windows\system32\izszba.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\mlJBSkhI

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\dude\applic~1\mozilla\firefox\profiles\himwypa6.default\
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dll

============= SERVICES / DRIVERS ===============

R?2 WZCBDLService;WZCBDL Service;c:\program files\wzcbdl service\WZCBDLS.exe [2002-3-19 36864]
R1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2009-4-10 148496]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-4-10 353672]
R2 NIOC;NIOC Service;c:\windows\system32\NIOC.sys [2002-9-27 22912]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2009-1-22 200192]
R3 NsSmrCap;NsSmrCap;c:\windows\system32\drivers\NsSmrCap.sys [2009-1-23 26624]
S2 gupdate1c98e12f88c2d89;Google Update Service (gupdate1c98e12f88c2d89);c:\program files\google\update\GoogleUpdate.exe [2009-2-13 133104]
S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-1-23 33752]
S3 Maya5PLEHelpServer;Alias Maya 5.0 PLE Help Server;c:\program files\aliaswavefront\maya 5.0 personal learning edition\docs\Wrapper.exe [2009-2-18 98304]
S3 NsTopaz;NewSoft Protocol Driver;c:\windows\system32\drivers\NSTopaz.sys [2009-1-23 13238]

=============== Created Last 30 ================

2009-05-13 15:53 98,816 a------- c:\windows\system32\izszba.dll
2009-05-13 15:53 98,816 a------- c:\windows\system32\wfbdwbwv.dll
2009-05-12 11:33 99,328 a------- c:\windows\system32\tmklrk.dll
2009-05-12 11:33 99,328 a------- c:\windows\system32\kvxuespa.dll
2009-05-11 15:47 1,457,411 ---sh--- c:\windows\system32\dilijhcw.ini
2009-05-11 15:47 74,752 a------- c:\windows\system32\wchjilid.dll
2009-05-10 12:14 1,457,411 ---sh--- c:\windows\system32\uixghqsl.ini
2009-05-10 12:11 99,328 a------- c:\windows\system32\gzmnwb.dll
2009-05-10 12:11 99,328 a------- c:\windows\system32\vbdkptjf.dll
2009-05-09 12:08 1,457,411 ---sh--- c:\windows\system32\pawfrgab.ini
2009-05-09 12:06 99,840 a------- c:\windows\system32\ooiyat.dll
2009-05-09 12:06 99,840 a------- c:\windows\system32\hjcqtnsb.dll
2009-05-08 11:22 99,840 a------- c:\windows\system32\kvacsl.dll
2009-05-08 11:22 99,840 a------- c:\windows\system32\ipxiatra.dll
2009-05-08 11:19 1,457,411 ---sh--- c:\windows\system32\qihgsagq.ini
2009-05-07 15:49 99,328 a------- c:\windows\system32\wbmssz.dll
2009-05-07 15:49 99,328 a------- c:\windows\system32\bfvdjdba.dll
2009-05-07 15:47 121 ---sh--- c:\windows\system32\opfcmscj.ini
2009-05-07 15:47 74,752 a------- c:\windows\system32\jcsmcfpo.dll
2009-05-06 17:30 99,328 a------- c:\windows\system32\vajubbhk.dll
2009-05-06 17:30 99,328 a------- c:\windows\system32\tlqwvp.dll
2009-05-06 17:27 1,457,411 ---sh--- c:\windows\system32\rmffbhvi.ini
2009-05-05 11:43 99,328 a------- c:\windows\system32\optfiq.dll
2009-05-05 11:43 99,328 a------- c:\windows\system32\arnkwaue.dll
2009-05-05 11:40 1,457,411 ---sh--- c:\windows\system32\ptihsisr.ini
2009-05-04 16:07 1,457,411 ---sh--- c:\windows\system32\hebevwmw.ini
2009-05-04 16:04 99,328 a------- c:\windows\system32\tighoz.dll
2009-05-04 16:04 99,328 a------- c:\windows\system32\ridsmqiy.dll
2009-05-03 16:51 1,457,411 ---sh--- c:\windows\system32\fpadqdyu.ini
2009-05-03 16:48 99,328 a------- c:\windows\system32\ykdgiwcp.dll
2009-05-03 16:48 99,328 a------- c:\windows\system32\hahotp.dll
2009-05-02 22:26 664 a------- c:\windows\system32\d3d9caps.dat
2009-05-02 12:34 1,457,411 ---sh--- c:\windows\system32\klakcrei.ini
2009-05-02 12:32 99,328 a------- c:\windows\system32\qloibi.dll
2009-05-02 12:32 99,328 a------- c:\windows\system32\coybivll.dll
2009-05-01 22:09 27,136 a------- c:\windows\system32\WAVMIX16.DLL
2009-05-01 22:09 92,208 a------- c:\windows\system32\WING.DLL
2009-05-01 22:09 12,800 a------- c:\windows\system32\WING32.DLL
2009-05-01 12:51 1,457,411 ---sh--- c:\windows\system32\xxxqkiwk.ini
2009-05-01 12:49 99,328 a------- c:\windows\system32\cvjmzx.dll
2009-05-01 12:49 99,328 a------- c:\windows\system32\lmlgouul.dll
2009-04-30 16:12 1,457,411 ---sh--- c:\windows\system32\akgkucrl.ini
2009-04-30 16:09 99,328 a------- c:\windows\system32\zuhqdc.dll
2009-04-30 16:09 99,328 a------- c:\windows\system32\fipyyefh.dll
2009-04-29 16:05 1,457,411 ---sh--- c:\windows\system32\eprmqnjv.ini
2009-04-29 16:02 98,816 a------- c:\windows\system32\wkjcfq.dll
2009-04-29 16:02 98,816 a------- c:\windows\system32\wyvkfmcq.dll
2009-04-28 12:44 99,328 a------- c:\windows\system32\uikwoada.dll
2009-04-28 12:44 99,328 a------- c:\windows\system32\rgqspo.dll
2009-04-27 19:39 1,457,411 ---sh--- c:\windows\system32\jsdritsw.ini
2009-04-27 19:36 99,328 a------- c:\windows\system32\oslfgr.dll
2009-04-27 19:36 99,328 a------- c:\windows\system32\mbinaore.dll
2009-04-27 15:56 99,328 a------- c:\windows\system32\xhutyxci.dll
2009-04-27 15:56 99,328 a------- c:\windows\system32\wzeyqe.dll
2009-04-27 15:53 1,450,868 ---sh--- c:\windows\system32\bpbqrkpl.ini
2009-04-26 15:53 99,840 a------- c:\windows\system32\tttltg.dll
2009-04-26 15:53 99,840 a------- c:\windows\system32\mhoogjkn.dll
2009-04-26 15:51 1,450,868 ---sh--- c:\windows\system32\inaydwmv.ini
2009-04-25 20:50 99,328 a------- c:\windows\system32\mpjdby.dll
2009-04-25 20:50 99,328 a------- c:\windows\system32\ahabwase.dll
2009-04-25 20:47 1,430,089 ---sh--- c:\windows\system32\anxulgpo.ini
2009-04-24 16:50 59,264 ac------ c:\windows\system32\dllcache\usbaudio.sys
2009-04-24 16:50 59,264 a------- c:\windows\system32\drivers\USBAUDIO.sys
2009-04-24 12:22 1,429,809 ---sh--- c:\windows\system32\mjkhlxkb.ini
2009-04-24 12:19 99,328 a------- c:\windows\system32\zxkqhr.dll
2009-04-24 12:19 99,328 a------- c:\windows\system32\kcujhxks.dll
2009-04-23 16:39 99,840 a------- c:\windows\system32\spbpwj.dll
2009-04-23 16:39 99,840 a------- c:\windows\system32\cbhvndmw.dll
2009-04-23 16:36 1,429,771 ---sh--- c:\windows\system32\jyajkvbg.ini
2009-04-22 18:29 99,328 a------- c:\windows\system32\wjvgxv.dll
2009-04-22 18:29 99,328 a------- c:\windows\system32\ygmmdhdv.dll
2009-04-22 18:26 1,429,035 ---sh--- c:\windows\system32\vhphaqsw.ini
2009-04-21 12:11 99,840 a------- c:\windows\system32\xbfajlvk.dll
2009-04-21 12:11 99,840 a------- c:\windows\system32\hdkxtc.dll
2009-04-21 12:08 1,419,785 ---sh--- c:\windows\system32\srxpaoie.ini
2009-04-20 16:13 1,419,524 ---sh--- c:\windows\system32\ibfdlobw.ini
2009-04-19 13:31 1,419,524 ---sh--- c:\windows\system32\jvxwicik.ini
2009-04-19 13:28 99,840 a------- c:\windows\system32\wvuxjl.dll
2009-04-19 13:28 99,840 a------- c:\windows\system32\inuwhkjy.dll
2009-04-18 12:15 99,840 a------- c:\windows\system32\vvrxsm.dll
2009-04-18 12:15 99,840 a------- c:\windows\system32\unrchxyx.dll
2009-04-18 12:13 1,419,524 ---sh--- c:\windows\system32\oufdrkeu.ini
2009-04-17 11:06 121 ---sh--- c:\windows\system32\eteqgtys.ini
2009-04-17 11:05 74,752 a------- c:\windows\system32\sytgqete.dll
2009-04-16 16:43 99,840 a------- c:\windows\system32\rokkgz.dll
2009-04-16 16:43 99,840 a------- c:\windows\system32\ievvmaxm.dll
2009-04-16 16:40 1,419,524 ---sh--- c:\windows\system32\hcfnpyqw.ini
2009-04-15 19:35 99,840 a------- c:\windows\system32\bjkuiu.dll
2009-04-15 19:35 99,840 a------- c:\windows\system32\dpqovymc.dll
2009-04-15 19:33 1,417,381 ---sh--- c:\windows\system32\whplvidg.ini
2009-04-15 16:23 1,417,381 ---sh--- c:\windows\system32\homstmyb.ini
2009-04-15 16:20 99,840 a------- c:\windows\system32\zqypfq.dll
2009-04-15 16:20 99,840 a------- c:\windows\system32\qxkyngwf.dll
2009-04-14 16:23 1,408,666 ---sh--- c:\windows\system32\uiplgchd.ini
2009-04-14 16:20 99,840 a------- c:\windows\system32\mytbpo.dll
2009-04-14 16:20 99,840 a------- c:\windows\system32\sufkrfij.dll
2009-04-13 18:21 1,405,695 ---sh--- c:\windows\system32\ibtkwuxp.ini
2009-04-13 18:20 99,840 a------- c:\windows\system32\xquasdgr.dll
2009-04-13 18:20 99,840 a------- c:\windows\system32\fzduom.dll
2009-04-13 18:17 61,440 a------- c:\windows\system32\eyuxootj.exe

==================== Find3M ====================

2009-05-13 16:05 1,879 a--sh--- c:\windows\system32\IhkSBJlm.ini2
2009-04-27 09:08 4,212 a---h--- c:\windows\system32\zllictbl.dat
2009-04-12 11:55 61,440 a------- c:\windows\system32\fiyhqsxu.exe
2009-04-12 11:49 99,840 a------- c:\windows\system32\thrognvt.dll
2009-04-12 11:49 99,840 a------- c:\windows\system32\ekrmyc.dll
2009-04-11 13:34 61,440 a------- c:\windows\system32\cnnxmwpv.exe
2009-04-11 13:28 99,840 a------- c:\windows\system32\rccvet.dll
2009-04-11 13:28 99,840 a------- c:\windows\system32\ocmxfwpx.dll
2009-04-10 10:59 99,840 a------- c:\windows\system32\uewixj.dll
2009-04-10 10:59 99,840 a------- c:\windows\system32\hlwhhltl.dll
2009-04-10 10:54 61,440 a------- c:\windows\system32\qcsclkyh.exe
2009-04-09 18:37 74,240 a------- c:\windows\system32\jnpnqmar.dll
2009-04-09 18:37 99,840 a------- c:\windows\system32\jtvzxn.dll
2009-04-09 18:37 99,840 a------- c:\windows\system32\fqdvkwfd.dll
2009-04-09 18:34 61,440 a------- c:\windows\system32\ttfdxmgp.exe
2009-04-09 18:32 99,840 a------- c:\windows\system32\lhnjeebk.dll
2009-04-09 18:32 99,840 a------- c:\windows\system32\drhdvd.dll
2009-04-08 17:46 74,752 a------- c:\windows\system32\jlyqpdft.dll
2009-04-08 17:46 61,440 a------- c:\windows\system32\cypoqssn.exe
2009-04-08 17:46 99,328 a------- c:\windows\system32\rjdtsqcg.dll
2009-04-08 17:46 99,328 a------- c:\windows\system32\hxitex.dll
2009-04-08 17:45 236,544 a------- c:\windows\system32\mlJBSkhI.dll
2009-04-08 17:40 44,544 a------- c:\windows\system32\vtUmnOiJ.dll
2009-04-08 17:40 44,544 a------- c:\windows\system32\ljJARlIc.dll
2009-02-21 18:38 410,984 a------- c:\windows\system32\deploytk.dll
2009-02-18 20:40 249,856 -------- c:\windows\Setup1.exe
2009-02-18 20:40 73,216 a------- c:\windows\ST6UNST.EXE
2009-02-16 00:10 72,584 a------- c:\windows\zllsputility.exe
2009-02-16 00:10 1,221,512 a------- c:\windows\system32\zpeng25.dll

============= FINISH: 16:09:07.20 ===============



any assistance would be appreciated.
Attached Files
File Type: zip attach.zip (41.3 KB, 5 views)
fortismilites is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 05-14-2009, 05:19 PM   #2 (permalink)
Analyst, Security Team
 
CatByte's Avatar
 
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3


Re: annoying peice of malware

Hello, and welcome to TSF.
I am currently reviewing your log. I will be back with a fix for your problem as soon as possible.
Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread.
Make sure it is set to Instant Notification, then click Subscribe.
Please be patient with me during this time.
__________________


ASAP & UNITE Member
CatByte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-15-2009, 02:45 AM   #3 (permalink)
Analyst, Security Team
 
CatByte's Avatar
 
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3


Re: annoying peice of malware

Hi,

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
__________________


ASAP & UNITE Member
CatByte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-15-2009, 01:14 PM   #4 (permalink)
Registered User
 
Join Date: May 2009
Location: NJ
Posts: 6
OS: win XP sp 3


Re: annoying peice of malware

good news, the links on google works like it should and zone alarm updates itself now. As far as the crashing i concerned, I'll need to use the laptop for several days to see if it still happens. I'll post with in 2 days to let you know if its fully working.


ps the log file is attached as asked


ComboFix 09-05-14.07 - dude 05/15/2009 13:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.697 [GMT -4:00]
Running from: c:\documents and settings\dude\Desktop\ComboFix.exe
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Outdated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\ahabwase.dll
c:\windows\system32\ahgjmpxc.dll
c:\windows\system32\akgkucrl.ini
c:\windows\system32\anxulgpo.ini
c:\windows\system32\arnkwaue.dll
c:\windows\system32\bfvdjdba.dll
c:\windows\system32\bjkuiu.dll
c:\windows\system32\bpbqrkpl.ini
c:\windows\system32\cbhvndmw.dll
c:\windows\system32\coybivll.dll
c:\windows\system32\cvjmzx.dll
c:\windows\system32\dilijhcw.ini
c:\windows\system32\dpqovymc.dll
c:\windows\system32\dpqrem.dll
c:\windows\system32\drhdvd.dll
c:\windows\system32\drivers\gxvxcbwqgikhbmqhtimoyxtetfmynkmavxegy.sys
c:\windows\system32\ekrmyc.dll
c:\windows\system32\eprmqnjv.ini
c:\windows\system32\eteqgtys.ini
c:\windows\system32\ffxmmqlr.ini
c:\windows\system32\fipyyefh.dll
c:\windows\system32\fpadqdyu.ini
c:\windows\system32\fqdvkwfd.dll
c:\windows\system32\fzduom.dll
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxciuhpihrlprybqpxwirqptxjcaorwporj.dll
c:\windows\system32\gzmnwb.dll
c:\windows\system32\hahotp.dll
c:\windows\system32\hcfnpyqw.ini
c:\windows\system32\hdkxtc.dll
c:\windows\system32\hebevwmw.ini
c:\windows\system32\hjcqtnsb.dll
c:\windows\system32\hlwhhltl.dll
c:\windows\system32\homstmyb.ini
c:\windows\system32\hxitex.dll
c:\windows\system32\ibfdlobw.ini
c:\windows\system32\ibtkwuxp.ini
c:\windows\system32\ievvmaxm.dll
c:\windows\system32\IhkSBJlm.ini
c:\windows\system32\IhkSBJlm.ini2
c:\windows\system32\inaydwmv.ini
c:\windows\system32\inuwhkjy.dll
c:\windows\system32\ipxiatra.dll
c:\windows\system32\iyccscvx.ini
c:\windows\system32\izszba.dll
c:\windows\system32\jcsmcfpo.dll
c:\windows\system32\jlyqpdft.dll
c:\windows\system32\jnpnqmar.dll
c:\windows\system32\jsdritsw.ini
c:\windows\system32\jtvzxn.dll
c:\windows\system32\jvxwicik.ini
c:\windows\system32\jyajkvbg.ini
c:\windows\system32\kcujhxks.dll
c:\windows\system32\klakcrei.ini
c:\windows\system32\kvacsl.dll
c:\windows\system32\kvxuespa.dll
c:\windows\system32\lhnjeebk.dll
c:\windows\system32\ljJARlIc.dll
c:\windows\system32\lmlgouul.dll
c:\windows\system32\mbinaore.dll
c:\windows\system32\mhoogjkn.dll
c:\windows\system32\mjkhlxkb.ini
c:\windows\system32\mlJBSkhI.dll
c:\windows\system32\mpjdby.dll
c:\windows\system32\mytbpo.dll
c:\windows\system32\ocmxfwpx.dll
c:\windows\system32\ooiyat.dll
c:\windows\system32\opfcmscj.ini
c:\windows\system32\optfiq.dll
c:\windows\system32\oslfgr.dll
c:\windows\system32\otxjww.dll
c:\windows\system32\oufdrkeu.ini
c:\windows\system32\pawfrgab.ini
c:\windows\system32\ptihsisr.ini
c:\windows\system32\qihgsagq.ini
c:\windows\system32\qloibi.dll
c:\windows\system32\qxkyngwf.dll
c:\windows\system32\ramqnpnj.ini
c:\windows\system32\rccvet.dll
c:\windows\system32\rgqspo.dll
c:\windows\system32\ridsmqiy.dll
c:\windows\system32\rjdtsqcg.dll
c:\windows\system32\rmffbhvi.ini
c:\windows\system32\rokkgz.dll
c:\windows\system32\rpvjeday.ini
c:\windows\system32\rsgphdtv.dll
c:\windows\system32\rtdxtcjw.ini
c:\windows\system32\spbpwj.dll
c:\windows\system32\srxpaoie.ini
c:\windows\system32\sufkrfij.dll
c:\windows\system32\sytgqete.dll
c:\windows\system32\tfdpqylj.ini
c:\windows\system32\thrognvt.dll
c:\windows\system32\tighoz.dll
c:\windows\system32\tlqwvp.dll
c:\windows\system32\tmklrk.dll
c:\windows\system32\tttltg.dll
c:\windows\system32\uewixj.dll
c:\windows\system32\uikwoada.dll
c:\windows\system32\uiplgchd.ini
c:\windows\system32\uixghqsl.ini
c:\windows\system32\unrchxyx.dll
c:\windows\system32\vajubbhk.dll
c:\windows\system32\vbdkptjf.dll
c:\windows\system32\vhphaqsw.ini
c:\windows\system32\vtUmnOiJ.dll
c:\windows\system32\vvrxsm.dll
c:\windows\system32\wbmssz.dll
c:\windows\system32\wchjilid.dll
c:\windows\system32\wfbdwbwv.dll
c:\windows\system32\whplvidg.ini
c:\windows\system32\wjvgxv.dll
c:\windows\system32\wkjcfq.dll
c:\windows\system32\wvuxjl.dll
c:\windows\system32\wyvkfmcq.dll
c:\windows\system32\wzeyqe.dll
c:\windows\system32\xbfajlvk.dll
c:\windows\system32\xhutyxci.dll
c:\windows\system32\xquasdgr.dll
c:\windows\system32\xxxqkiwk.ini
c:\windows\system32\ygmmdhdv.dll
c:\windows\system32\ykdgiwcp.dll
c:\windows\system32\zqypfq.dll
c:\windows\system32\zuhqdc.dll
c:\windows\system32\zxkqhr.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_GXVXCSERV.SYS


((((((((((((((((((((((((( Files Created from 2009-04-15 to 2009-05-15 )))))))))))))))))))))))))))))))
.

2009-05-15 17:27 . 2009-05-15 18:40 3322400 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-03 02:26 . 2009-05-03 02:26 664 ----a-w c:\windows\system32\d3d9caps.dat
2009-05-02 02:09 . 1995-04-19 04:00 27136 ----a-w c:\windows\system32\WAVMIX16.DLL
2009-05-02 02:09 . 1995-04-19 04:00 12800 ----a-w c:\windows\system32\WING32.DLL
2009-05-02 02:09 . 1995-04-19 04:00 92208 ----a-w c:\windows\system32\WING.DLL
2009-04-24 20:50 . 2004-08-04 03:07 59264 -c--a-w c:\windows\system32\dllcache\usbaudio.sys
2009-04-24 20:50 . 2004-08-04 03:07 59264 ----a-w c:\windows\system32\drivers\USBAUDIO.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-15 19:00 . 2009-03-31 18:40 -------- d-----w c:\program files\DNA
2009-05-15 17:27 . 2009-05-15 17:27 32 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-27 13:08 . 2009-04-10 15:53 4212 ---ha-w c:\windows\system32\zllictbl.dat
2009-04-15 23:41 . 2009-02-18 19:34 -------- d-----w c:\program files\GameSpy Arcade
2009-04-15 21:50 . 2009-03-26 00:41 715 ----a-w c:\windows\eReg.dat
2009-04-15 21:41 . 2009-01-23 02:47 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-15 21:41 . 2009-02-15 00:10 -------- d-----w c:\program files\EA GAMES
2009-04-13 22:17 . 2009-04-13 22:17 61440 ----a-w c:\windows\system32\eyuxootj.exe
2009-04-12 15:55 . 2009-04-12 15:55 61440 ----a-w c:\windows\system32\fiyhqsxu.exe
2009-04-11 21:01 . 2009-04-08 20:29 -------- d-----w c:\program files\Visual Zip Password Recovery Processor
2009-04-11 17:34 . 2009-04-11 17:34 61440 ----a-w c:\windows\system32\cnnxmwpv.exe
2009-04-10 15:52 . 2009-04-10 15:52 -------- d-----w c:\program files\Zone Labs
2009-04-10 14:54 . 2009-04-10 14:54 61440 ----a-w c:\windows\system32\qcsclkyh.exe
2009-04-09 22:34 . 2009-04-09 22:34 61440 ----a-w c:\windows\system32\ttfdxmgp.exe
2009-04-09 01:40 . 2009-04-09 01:40 0 ----a-w c:\windows\nsreg.dat
2009-04-08 21:46 . 2009-04-08 21:46 61440 ----a-w c:\windows\system32\cypoqssn.exe
2009-04-07 22:56 . 2009-04-07 22:56 -------- d-----w c:\program files\Pcsx2
2009-04-04 23:11 . 2009-04-04 23:11 -------- d-----w c:\program files\Sizer
2009-04-03 16:04 . 2009-03-06 23:56 -------- d-----w c:\program files\Microsoft SQL Server
2009-04-03 16:00 . 2009-03-06 23:50 -------- d-----w c:\program files\Microsoft Visual Studio 9.0
2009-04-03 15:58 . 2009-04-03 15:58 -------- d-----w c:\program files\Microsoft Web Designer Tools
2009-03-31 21:05 . 2009-02-08 22:59 -------- d-----w c:\program files\EVEMon
2009-03-26 00:40 . 2009-03-26 00:40 -------- d-----w c:\program files\Maxis
2009-03-07 23:14 . 2009-02-08 23:00 68456 ----a-w c:\documents and settings\dude\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-02-21 22:38 . 2009-02-21 22:38 410984 ----a-w c:\windows\system32\deploytk.dll
2009-02-19 00:40 . 2009-02-19 00:40 249856 ------w c:\windows\Setup1.exe
2009-02-19 00:40 . 2009-02-19 00:40 73216 ----a-w c:\windows\ST6UNST.EXE
2009-02-16 04:10 . 2009-04-10 15:53 72584 ----a-w c:\windows\zllsputility.exe
2009-02-16 04:10 . 2009-04-10 15:52 1221512 ----a-w c:\windows\system32\zpeng25.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{32099AAC-C132-4136-9E9A-4E364A424E17}"= "c:\program files\DAEMON Tools Toolbar\DTToolbar.dll" [2008-12-10 929224]

[HKEY_CLASSES_ROOT\clsid\{32099aac-c132-4136-9e9a-4e364a424e17}]
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}]
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{32099AAC-C132-4136-9E9A-4E364A424E17}"= "c:\program files\DAEMON Tools Toolbar\DTToolbar.dll" [2008-12-10 929224]

[HKEY_CLASSES_ROOT\clsid\{32099aac-c132-4136-9e9a-4e364a424e17}]
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}]
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-07-27 15360]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-03-31 321344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-29 344064]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 688218]
"SunKist"="c:\program files\Digital Media Reader\shwicon2k.exe" [2004-05-26 139264]
"D-Link Air USB Utility"="c:\program files\D-Link\Air USB Utility\AirCFG.exe" [2003-07-23 2695168]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-21 148888]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-16 981384]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\CCP\\EVE\\bin\\ExeFile.exe"=
"c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"=
"c:\\Program Files\\MohaaProxy\\mohaaProxy.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\CCP\\EVE test\\bin\\ExeFile.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=

R2 NIOC;NIOC Service;c:\windows\system32\NIOC.sys [9/27/2002 7:21 PM 22912]
R2 WZCBDLService;WZCBDL Service;c:\program files\WZCBDL Service\WZCBDLS.exe [3/19/2002 1:15 PM 36864]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [1/22/2009 11:01 PM 200192]
R3 NsSmrCap;NsSmrCap;c:\windows\system32\drivers\NsSmrCap.sys [1/23/2009 10:23 AM 26624]
S2 gupdate1c98e12f88c2d89;Google Update Service (gupdate1c98e12f88c2d89);c:\program files\Google\Update\GoogleUpdate.exe [2/13/2009 3:40 PM 133104]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [1/23/2009 8:15 PM 33752]
S3 Maya5PLEHelpServer;Alias Maya 5.0 PLE Help Server;c:\program files\AliasWavefront\Maya 5.0 Personal Learning Edition\docs\Wrapper.exe [2/18/2009 12:54 PM 98304]
S3 NsTopaz;NewSoft Protocol Driver;c:\windows\system32\drivers\NSTopaz.sys [1/23/2009 10:28 AM 13238]
.
Contents of the 'Scheduled Tasks' folder

2009-03-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-05-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-13 21:34]

2009-05-15 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-13 19:40]
.
- - - - ORPHANS REMOVED - - - -

BHO-{09C72999-5C10-41A3-A524-24661D942003} - c:\windows\system32\vtUmnOiJ.dll
BHO-{251d00d1-1995-4c97-b900-33436898a095} - c:\windows\system32\otxjww.dll
BHO-{3DFDB2C8-AE0E-4413-878F-7FFC4E2C71E8} - c:\windows\system32\mlJBSkhI.dll
HKLM-Run-ChangeFilterMerit - c:\program files\NewSoft\Presto! WMS2.5\ChangeFilterMerit.exe
ShellExecuteHooks-{09C72999-5C10-41A3-A524-24661D942003} - c:\windows\system32\vtUmnOiJ.dll
ShellExecuteHooks-{c270d96e-0335-4fd6-aae2-c1490c5f6780} - c:\windows\system32\otxjww.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\dude\Application Data\Mozilla\Firefox\Profiles\himwypa6.default\
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-15 15:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(912)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(2988)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\WLTRAY.EXE
.
**************************************************************************
.
Completion time: 2009-05-15 15:04 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-15 19:04

Pre-Run: 31,310,495,744 bytes free
Post-Run: 39,897,292,800 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

310
Attached Files
File Type: txt log.txt (15.7 KB, 3 views)
fortismilites is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-15-2009, 03:01 PM   #5 (permalink)
Analyst, Security Team
 
CatByte's Avatar
 
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3


Re: annoying peice of malware

Hi, we still have more work to do, please stay with me till I give you the all clean, I will analyze your log as quickly as I can and get back to you with further instructions
__________________


ASAP & UNITE Member
CatByte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-15-2009, 03:19 PM   #6 (permalink)
Registered User
 
Join Date: May 2009
Location: NJ
Posts: 6
OS: win XP sp 3


Re: annoying peice of malware

ok, zone alarm did and automatic scan while i was playing a game, and quarantined a few Trojans. here is the info zone alarm gave me on them:

Trojan-Downloader.Win32.FraudLoad.vohb was found in C:\WINDOWS\system32\cnnxmwpv.exe on 5/15/2009 16:44:48
Trojan-Downloader.Win32.FraudLoad.vohb was found in C:\WINDOWS\system32\cypoqssn.exe on 5/15/2009 16:44:50
Trojan-Downloader.Win32.FraudLoad.vohb was found in C:\WINDOWS\system32\eyuxootj.exe on 5/15/2009 16:46:44
Trojan-Downloader.Win32.FraudLoad.vohb was found in C:\WINDOWS\system32\fiyhqsxu.exe on 5/15/2009 16:46:44
Trojan-Downloader.Win32.FraudLoad.vohb was found in C:\WINDOWS\system32\qcsclkyh.exe on 5/15/2009 16:48:28
Trojan-Downloader.Win32.FraudLoad.vohb was found in C:\WINDOWS\system32\ttfdxmgp.exe on 5/15/2009 16:48:44

two questions, 1, should i go into zone alarm and delete the Trojans, and 2, should i shut the automatic scan off.
fortismilites is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-15-2009, 03:33 PM   #7 (permalink)
Analyst, Security Team
 
CatByte's Avatar
 
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3


Re: annoying peice of malware

Hi, don't delete anything just yet, disable the autoscan until we have finished cleaning this machine.

Thanks,

I will be back soon with more instructions
__________________


ASAP & UNITE Member
CatByte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-15-2009, 03:36 PM   #8 (permalink)
Analyst, Security Team
 
CatByte's Avatar
 
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3


Re: annoying peice of malware

Hi,

Please do the following

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Code:
http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/376105-annoying-peice-malware.html#post2138098

Collect::
c:\windows\system32\eyuxootj.exe
c:\windows\system32\fiyhqsxu.exe
c:\windows\system32\cnnxmwpv.exe
c:\windows\system32\qcsclkyh.exe
c:\windows\system32\ttfdxmgp.exe
c:\windows\system32\cypoqssn.exe
Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As... Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save ...

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
__________________


ASAP & UNITE Member
CatByte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-15-2009, 09:17 PM   #9 (permalink)
Registered User
 
Join Date: May 2009
Location: NJ
Posts: 6
OS: win XP sp 3


Re: annoying peice of malware

ok, zone alarm automatic scan is disabled, and i left the quarintined files alone. Here is the log you asked for.

ComboFix 09-05-14.07 - dude 05/15/2009 23:09.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.608 [GMT -4:00]
Running from: c:\documents and settings\dude\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\dude\Desktop\CFScript.txt
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-04-16 to 2009-05-16 )))))))))))))))))))))))))))))))
.

2009-05-15 17:27 . 2009-05-16 03:11 5123360 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-03 02:26 . 2009-05-03 02:26 664 ----a-w c:\windows\system32\d3d9caps.dat
2009-05-02 02:09 . 1995-04-19 04:00 27136 ----a-w c:\windows\system32\WAVMIX16.DLL
2009-05-02 02:09 . 1995-04-19 04:00 12800 ----a-w c:\windows\system32\WING32.DLL
2009-05-02 02:09 . 1995-04-19 04:00 92208 ----a-w c:\windows\system32\WING.DLL
2009-04-24 20:50 . 2004-08-04 03:07 59264 -c--a-w c:\windows\system32\dllcache\usbaudio.sys
2009-04-24 20:50 . 2004-08-04 03:07 59264 ----a-w c:\windows\system32\drivers\USBAUDIO.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-16 03:02 . 2009-03-31 18:40 -------- d-----w c:\program files\DNA
2009-05-15 21:47 . 2009-05-15 17:27 57284 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-27 13:08 . 2009-04-10 15:53 4212 ---ha-w c:\windows\system32\zllictbl.dat
2009-04-15 23:41 . 2009-02-18 19:34 -------- d-----w c:\program files\GameSpy Arcade
2009-04-15 21:50 . 2009-03-26 00:41 715 ----a-w c:\windows\eReg.dat
2009-04-15 21:41 . 2009-01-23 02:47 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-15 21:41 . 2009-02-15 00:10 -------- d-----w c:\program files\EA GAMES
2009-04-11 21:01 . 2009-04-08 20:29 -------- d-----w c:\program files\Visual Zip Password Recovery Processor
2009-04-10 15:52 . 2009-04-10 15:52 -------- d-----w c:\program files\Zone Labs
2009-04-09 01:40 . 2009-04-09 01:40 0 ----a-w c:\windows\nsreg.dat
2009-04-07 22:56 . 2009-04-07 22:56 -------- d-----w c:\program files\Pcsx2
2009-04-04 23:11 . 2009-04-04 23:11 -------- d-----w c:\program files\Sizer
2009-04-03 16:04 . 2009-03-06 23:56 -------- d-----w c:\program files\Microsoft SQL Server
2009-04-03 16:00 . 2009-03-06 23:50 -------- d-----w c:\program files\Microsoft Visual Studio 9.0
2009-04-03 15:58 . 2009-04-03 15:58 -------- d-----w c:\program files\Microsoft Web Designer Tools
2009-03-31 21:05 . 2009-02-08 22:59 -------- d-----w c:\program files\EVEMon
2009-03-26 00:40 . 2009-03-26 00:40 -------- d-----w c:\program files\Maxis
2009-03-07 23:14 . 2009-02-08 23:00 68456 ----a-w c:\documents and settings\dude\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-02-21 22:38 . 2009-02-21 22:38 410984 ----a-w c:\windows\system32\deploytk.dll
2009-02-19 00:40 . 2009-02-19 00:40 249856 ------w c:\windows\Setup1.exe
2009-02-19 00:40 . 2009-02-19 00:40 73216 ----a-w c:\windows\ST6UNST.EXE
2009-02-16 04:10 . 2009-04-10 15:53 72584 ----a-w c:\windows\zllsputility.exe
2009-02-16 04:10 . 2009-04-10 15:52 1221512 ----a-w c:\windows\system32\zpeng25.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-15_19.01.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-16 03:01 . 2009-05-16 03:01 16384 c:\windows\Temp\Perflib_Perfdata_264.dat
+ 2009-04-10 16:00 . 2009-05-16 03:05 34332 c:\windows\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2009-04-10 16:15 . 2009-05-15 20:48 385024 c:\windows\system32\ZoneLabs\zlqrtdb.dat
+ 2009-05-15 19:18 . 2009-05-15 19:18 11576520 c:\windows\system32\ZoneLabs\spyware0.dat
+ 2009-04-10 15:53 . 2009-05-15 19:18 12221531 c:\windows\system32\ZoneLabs\spyware.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-07-27 15360]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-03-31 321344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-29 344064]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 688218]
"SunKist"="c:\program files\Digital Media Reader\shwicon2k.exe" [2004-05-26 139264]
"D-Link Air USB Utility"="c:\program files\D-Link\Air USB Utility\AirCFG.exe" [2003-07-23 2695168]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-21 148888]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-16 981384]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\CCP\\EVE\\bin\\ExeFile.exe"=
"c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"=
"c:\\Program Files\\MohaaProxy\\mohaaProxy.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\CCP\\EVE test\\bin\\ExeFile.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=

R?2 WZCBDLService;WZCBDL Service;c:\program files\WZCBDL Service\WZCBDLS.exe [3/19/2002 1:15 PM 36864]
R2 NIOC;NIOC Service;c:\windows\system32\NIOC.sys [9/27/2002 7:21 PM 22912]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [1/22/2009 11:01 PM 200192]
R3 NsSmrCap;NsSmrCap;c:\windows\system32\drivers\NsSmrCap.sys [1/23/2009 10:23 AM 26624]
S2 gupdate1c98e12f88c2d89;Google Update Service (gupdate1c98e12f88c2d89);c:\program files\Google\Update\GoogleUpdate.exe [2/13/2009 3:40 PM 133104]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [1/23/2009 8:15 PM 33752]
S3 Maya5PLEHelpServer;Alias Maya 5.0 PLE Help Server;c:\program files\AliasWavefront\Maya 5.0 Personal Learning Edition\docs\Wrapper.exe [2/18/2009 12:54 PM 98304]
S3 NsTopaz;NewSoft Protocol Driver;c:\windows\system32\drivers\NSTopaz.sys [1/23/2009 10:28 AM 13238]
.
Contents of the 'Scheduled Tasks' folder

2009-03-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-05-16 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-13 21:34]

2009-05-16 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-13 19:40]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\dude\Application Data\Mozilla\Firefox\Profiles\himwypa6.default\
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-15 23:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(908)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(2308)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-05-16 23:13
ComboFix-quarantined-files.txt 2009-05-16 03:13
ComboFix2.txt 2009-05-15 19:04

Pre-Run: 39,786,774,528 bytes free
Post-Run: 39,767,728,128 bytes free

143



So far computer is still running fine, google still works, zone alarm updates, and no crashes yet.
fortismilites is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-16-2009, 10:36 AM   #10 (permalink)
Analyst, Security Team
 
CatByte's Avatar
 
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3


Re: annoying peice of malware

Hi please do the following:

Your Java is out of date.

Java(TM) 6 Update 12 can be updated from the Java control panel. Go to Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now. An update should begin; follow the prompts.



NEXT


Please do a scan with Kaspersky Online Scanner.
  • Open the Kaspersky WebScanner
    page.
  • Click on the button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the ...button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.
__________________


ASAP & UNITE Member
CatByte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-18-2009, 08:16 PM   #11 (permalink)
Registered User
 
Join Date: May 2009
Location: NJ
Posts: 6
OS: win XP sp 3


Re: annoying peice of malware

sorry its been a couple of days, got real busy over the weekend. When i tried to update java, it said it was up to date, should i continue and do the Kaspersky scan anyway?
fortismilites is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-18-2009, 08:20 PM   #12 (permalink)
Analyst, Security Team
 
CatByte's Avatar
 
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3


Re: annoying peice of malware

Hi,

Yes please
__________________


ASAP & UNITE Member
CatByte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-20-2009, 09:46 AM   #13 (permalink)
Registered User
 
Join Date: May 2009
Location: NJ
Posts: 6
OS: win XP sp 3


Re: annoying peice of malware

ok here is the report from kaspersky:

Wednesday, May 20, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, May 20, 2009 00:55:16
Records in database: 2200588
Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes
Scan area My Computer
C:\
D:\
E:\
F:\
Scan statistics
Files scanned 97813
Threat name 21
Infected objects 103
Suspicious objects 0
Duration of the scan 06:15:22

File name Threat name Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\cbhvndmw.dll.vir Infected: Backdoor.Win32.Agent.afzy 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drhdvd.dll.vir Infected: Trojan-Downloader.Win32.Small.joo 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\fqdvkwfd.dll.vir Infected: Trojan-Downloader.Win32.Small.joo 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\fzduom.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.tls 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\gxvxciuhpihrlprybqpxwirqptxjcaorwporj.dll.vir Infected: Trojan.Win32.Agent2.hoq 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\gzmnwb.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\hahotp.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\hlwhhltl.dll.vir Infected: Trojan-Downloader.Win32.Small.joo 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\hxitex.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.txb 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ievvmaxm.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\inuwhkjy.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ipxiatra.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uwq 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\jcsmcfpo.dll.vir Infected: Trojan-Downloader.Win32.Boltolog.bxo 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\jlyqpdft.dll.vir Infected: Trojan.Win32.Monder.byuj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\jnpnqmar.dll.vir Infected: Trojan.Win32.Monder.byzu 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\jtvzxn.dll.vir Infected: Trojan-Downloader.Win32.Small.joo 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\kvacsl.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uwq 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\kvxuespa.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\lhnjeebk.dll.vir Infected: Trojan-Downloader.Win32.Small.joo 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ljJARlIc.dll.vir Infected: Trojan.Win32.Monderb.rrf 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\mbinaore.dll.vir Infected: Trojan.Win32.Monderd.w 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\mytbpo.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.txc 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\oslfgr.dll.vir Infected: Trojan.Win32.Monderd.w 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\otxjww.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.vji 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\rgqspo.dll.vir Infected: Trojan.Win32.Monderd.w 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ridsmqiy.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\rjdtsqcg.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.txb 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\rokkgz.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\rsgphdtv.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.vji 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\spbpwj.dll.vir Infected: Backdoor.Win32.Agent.afzy 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\sufkrfij.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.txc 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\sytgqete.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvk 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tighoz.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tmklrk.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\uewixj.dll.vir Infected: Trojan-Downloader.Win32.Small.joo 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\uikwoada.dll.vir Infected: Trojan.Win32.Monderd.w 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\unrchxyx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\vbdkptjf.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\vtUmnOiJ.dll.vir Infected: Trojan.Win32.Monderb.rrf 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\vvrxsm.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\wchjilid.dll.vir Infected: Trojan.Win32.Monder.cfuv 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\wkjcfq.dll.vir Infected: Trojan-Spy.Win32.Agent.anra 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\wvuxjl.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\wyvkfmcq.dll.vir Infected: Trojan-Spy.Win32.Agent.anra 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\wzeyqe.dll.vir Infected: Trojan.Win32.Monderd.w 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\xhutyxci.dll.vir Infected: Trojan.Win32.Monderd.w 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\xquasdgr.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.tls 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ykdgiwcp.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP59\A0010117.exe Infected: Trojan-Spy.Win32.Agent.bnx 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010120.dll Infected: Trojan.Win32.Agent2.hoq 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010163.dll Infected: Backdoor.Win32.Agent.afzy 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010169.dll Infected: Trojan-Downloader.Win32.Small.joo 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010176.dll Infected: Trojan-Downloader.Win32.Small.joo 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010177.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.tls 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010178.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010179.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010184.dll Infected: Trojan-Downloader.Win32.Small.joo 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010186.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.txb 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010190.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010192.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010193.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uwq 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010196.dll Infected: Trojan-Downloader.Win32.Boltolog.bxo 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010197.dll Infected: Trojan.Win32.Monder.byuj 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010198.dll Infected: Trojan.Win32.Monder.byzu 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010200.dll Infected: Trojan-Downloader.Win32.Small.joo 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010205.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uwq 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010206.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010207.dll Infected: Trojan-Downloader.Win32.Small.joo 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010208.dll Infected: Trojan.Win32.Monderb.rrf 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010210.dll Infected: Trojan.Win32.Monderd.w 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010215.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.txc 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010220.dll Infected: Trojan.Win32.Monderd.w 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010221.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.vji 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010230.dll Infected: Trojan.Win32.Monderd.w 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010231.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010232.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.txb 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010234.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010236.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.vji 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010238.dll Infected: Backdoor.Win32.Agent.afzy 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010240.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.txc 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010241.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvk 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010244.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010246.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010248.dll Infected: Trojan-Downloader.Win32.Small.joo 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010249.dll Infected: Trojan.Win32.Monderd.w 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010252.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010254.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010256.dll Infected: Trojan.Win32.Monderb.rrf 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010257.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010259.dll Infected: Trojan.Win32.Monder.cfuv 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010263.dll Infected: Trojan-Spy.Win32.Agent.anra 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010264.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010265.dll Infected: Trojan-Spy.Win32.Agent.anra 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010266.dll Infected: Trojan.Win32.Monderd.w 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010268.dll Infected: Trojan.Win32.Monderd.w 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010269.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.tls 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010272.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0011203.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0011204.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0011206.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0011207.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0011209.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1
C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0011210.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1
The selected area was scanned.
fortismilites is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-20-2009, 12:42 PM   #14 (permalink)
Analyst, Security Team
 
CatByte's Avatar
 
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3


Re: annoying peice of malware

Hi,

Your machine is clean. Everything that Kaspersky found was either already in quarantine or in an old system restore point, which we are now going to clean up.


One way of assuring your machine doesn't get reinfected is never to use peer2peer file sharing applications

As mentioned in our pre-posting topic:
NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help

P2P - There are remnants of the BitTorrent DNA application remaining on your machine. (Did you recently uninstall BitTorrent?) We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It probably contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.Please see this topic for more information:
Perils of P2P File Sharing.I would strongly recommend that you uninstall this now. You can do so via Control Panel >> Add or Remove Programs.


Now for some housekeeping:

Java should be version 6 update 13, sometimes the auto update doesn't kick in, but you can get the latest update directly from the Java site HERE

NEXT

You can delete the DDS and GMER folders from your desktop, then


Follow these steps to uninstall Combofix
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.



NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • For Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security--What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Thank you for your patience, and performing all of the procedures requested
__________________


ASAP & UNITE Member
CatByte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 06:54 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85