![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: May 2009
Location: NJ
Posts: 6
OS: win XP sp 3
|
annoying peice of malware
ok here is whats going on.
in fire fox and internet explorer, when i use google and click a link, it redirects me to a totally different site than the link specifies every time. Zonealarm wont update says it can connect, despite the internet is working. Im noticing the computer is crashing and a little slower than usual here is the logs on what not you asked for: DDS (Ver_09-05-14.01) - NTFSx86 Run by dude at 16:07:18.92 on Wed 05/13/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.553 [GMT -4:00] AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Outdated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF} FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\WZCBDL Service\WZCBDLS.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Digital Media Reader\shwicon2k.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\D-Link\Air USB Utility\AirCFG.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DNA\btdna.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Documents and Settings\dude\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: {09c72999-5c10-41a3-a524-24661d942003} - c:\windows\system32\vtUmnOiJ.dll BHO: {15bc4a4e-b8b5-47f1-a9b5-fc407d4b7067} - c:\windows\system32\mlJBSkhI.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {08c94d8e-c44d-8a8a-72d4-462b4ea1d365}: {563d1ae4-b264-4d27-a8a8-d44ce8d49c80} - c:\windows\system32\izszba.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [<NO NAME>] mRun: [SunKist] c:\program files\digital media reader\shwicon2k.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY mRun: [D-Link Air USB Utility] c:\program files\d-link\air usb utility\AirCFG.exe mRun: [ChangeFilterMerit] c:\program files\newsoft\presto! wms2.5\ChangeFilterMerit.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe" mRun: [ace040f7] rundll32.exe "c:\windows\system32\wchjilid.dll",b StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1232684135744 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk/6u12-b04/jinstall-6u12-windows-i586-jc.cab?e=1235255957956&h=fb6885e5a69b40c2c15f2f812ee0b4cf/&filename=jinstall-6u12-windows-i586-jc.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab TCP: NameServer = 85.255.112.107,85.255.112.226 TCP: {B8472F9A-FF66-4CA2-AEA8-9687EA94BFA1} = 85.255.112.107,85.255.112.226 TCP: {FAF81239-79F5-44CC-8E20-60B30D9E5771} = 85.255.112.107,85.255.112.226 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL Notify: AtiExtEvent - Ati2evxx.dll Notify: vtUmnOiJ - vtUmnOiJ.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: {09c72999-5c10-41a3-a524-24661d942003} - c:\windows\system32\vtUmnOiJ.dll SEH: {1b26e755-278e-0db9-a564-57ee27e40c36}: {63c04e72-ee75-465a-9bd0-e872557e62b1} - c:\windows\system32\izszba.dll LSA: Authentication Packages = msv1_0 c:\windows\system32\mlJBSkhI ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\dude\applic~1\mozilla\firefox\profiles\himwypa6.default\ FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dll ============= SERVICES / DRIVERS =============== R?2 WZCBDLService;WZCBDL Service;c:\program files\wzcbdl service\WZCBDLS.exe [2002-3-19 36864] R1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2009-4-10 148496] R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-4-10 353672] R2 NIOC;NIOC Service;c:\windows\system32\NIOC.sys [2002-9-27 22912] R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2009-1-22 200192] R3 NsSmrCap;NsSmrCap;c:\windows\system32\drivers\NsSmrCap.sys [2009-1-23 26624] S2 gupdate1c98e12f88c2d89;Google Update Service (gupdate1c98e12f88c2d89);c:\program files\google\update\GoogleUpdate.exe [2009-2-13 133104] S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?] S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-1-23 33752] S3 Maya5PLEHelpServer;Alias Maya 5.0 PLE Help Server;c:\program files\aliaswavefront\maya 5.0 personal learning edition\docs\Wrapper.exe [2009-2-18 98304] S3 NsTopaz;NewSoft Protocol Driver;c:\windows\system32\drivers\NSTopaz.sys [2009-1-23 13238] =============== Created Last 30 ================ 2009-05-13 15:53 98,816 a------- c:\windows\system32\izszba.dll 2009-05-13 15:53 98,816 a------- c:\windows\system32\wfbdwbwv.dll 2009-05-12 11:33 99,328 a------- c:\windows\system32\tmklrk.dll 2009-05-12 11:33 99,328 a------- c:\windows\system32\kvxuespa.dll 2009-05-11 15:47 1,457,411 ---sh--- c:\windows\system32\dilijhcw.ini 2009-05-11 15:47 74,752 a------- c:\windows\system32\wchjilid.dll 2009-05-10 12:14 1,457,411 ---sh--- c:\windows\system32\uixghqsl.ini 2009-05-10 12:11 99,328 a------- c:\windows\system32\gzmnwb.dll 2009-05-10 12:11 99,328 a------- c:\windows\system32\vbdkptjf.dll 2009-05-09 12:08 1,457,411 ---sh--- c:\windows\system32\pawfrgab.ini 2009-05-09 12:06 99,840 a------- c:\windows\system32\ooiyat.dll 2009-05-09 12:06 99,840 a------- c:\windows\system32\hjcqtnsb.dll 2009-05-08 11:22 99,840 a------- c:\windows\system32\kvacsl.dll 2009-05-08 11:22 99,840 a------- c:\windows\system32\ipxiatra.dll 2009-05-08 11:19 1,457,411 ---sh--- c:\windows\system32\qihgsagq.ini 2009-05-07 15:49 99,328 a------- c:\windows\system32\wbmssz.dll 2009-05-07 15:49 99,328 a------- c:\windows\system32\bfvdjdba.dll 2009-05-07 15:47 121 ---sh--- c:\windows\system32\opfcmscj.ini 2009-05-07 15:47 74,752 a------- c:\windows\system32\jcsmcfpo.dll 2009-05-06 17:30 99,328 a------- c:\windows\system32\vajubbhk.dll 2009-05-06 17:30 99,328 a------- c:\windows\system32\tlqwvp.dll 2009-05-06 17:27 1,457,411 ---sh--- c:\windows\system32\rmffbhvi.ini 2009-05-05 11:43 99,328 a------- c:\windows\system32\optfiq.dll 2009-05-05 11:43 99,328 a------- c:\windows\system32\arnkwaue.dll 2009-05-05 11:40 1,457,411 ---sh--- c:\windows\system32\ptihsisr.ini 2009-05-04 16:07 1,457,411 ---sh--- c:\windows\system32\hebevwmw.ini 2009-05-04 16:04 99,328 a------- c:\windows\system32\tighoz.dll 2009-05-04 16:04 99,328 a------- c:\windows\system32\ridsmqiy.dll 2009-05-03 16:51 1,457,411 ---sh--- c:\windows\system32\fpadqdyu.ini 2009-05-03 16:48 99,328 a------- c:\windows\system32\ykdgiwcp.dll 2009-05-03 16:48 99,328 a------- c:\windows\system32\hahotp.dll 2009-05-02 22:26 664 a------- c:\windows\system32\d3d9caps.dat 2009-05-02 12:34 1,457,411 ---sh--- c:\windows\system32\klakcrei.ini 2009-05-02 12:32 99,328 a------- c:\windows\system32\qloibi.dll 2009-05-02 12:32 99,328 a------- c:\windows\system32\coybivll.dll 2009-05-01 22:09 27,136 a------- c:\windows\system32\WAVMIX16.DLL 2009-05-01 22:09 92,208 a------- c:\windows\system32\WING.DLL 2009-05-01 22:09 12,800 a------- c:\windows\system32\WING32.DLL 2009-05-01 12:51 1,457,411 ---sh--- c:\windows\system32\xxxqkiwk.ini 2009-05-01 12:49 99,328 a------- c:\windows\system32\cvjmzx.dll 2009-05-01 12:49 99,328 a------- c:\windows\system32\lmlgouul.dll 2009-04-30 16:12 1,457,411 ---sh--- c:\windows\system32\akgkucrl.ini 2009-04-30 16:09 99,328 a------- c:\windows\system32\zuhqdc.dll 2009-04-30 16:09 99,328 a------- c:\windows\system32\fipyyefh.dll 2009-04-29 16:05 1,457,411 ---sh--- c:\windows\system32\eprmqnjv.ini 2009-04-29 16:02 98,816 a------- c:\windows\system32\wkjcfq.dll 2009-04-29 16:02 98,816 a------- c:\windows\system32\wyvkfmcq.dll 2009-04-28 12:44 99,328 a------- c:\windows\system32\uikwoada.dll 2009-04-28 12:44 99,328 a------- c:\windows\system32\rgqspo.dll 2009-04-27 19:39 1,457,411 ---sh--- c:\windows\system32\jsdritsw.ini 2009-04-27 19:36 99,328 a------- c:\windows\system32\oslfgr.dll 2009-04-27 19:36 99,328 a------- c:\windows\system32\mbinaore.dll 2009-04-27 15:56 99,328 a------- c:\windows\system32\xhutyxci.dll 2009-04-27 15:56 99,328 a------- c:\windows\system32\wzeyqe.dll 2009-04-27 15:53 1,450,868 ---sh--- c:\windows\system32\bpbqrkpl.ini 2009-04-26 15:53 99,840 a------- c:\windows\system32\tttltg.dll 2009-04-26 15:53 99,840 a------- c:\windows\system32\mhoogjkn.dll 2009-04-26 15:51 1,450,868 ---sh--- c:\windows\system32\inaydwmv.ini 2009-04-25 20:50 99,328 a------- c:\windows\system32\mpjdby.dll 2009-04-25 20:50 99,328 a------- c:\windows\system32\ahabwase.dll 2009-04-25 20:47 1,430,089 ---sh--- c:\windows\system32\anxulgpo.ini 2009-04-24 16:50 59,264 ac------ c:\windows\system32\dllcache\usbaudio.sys 2009-04-24 16:50 59,264 a------- c:\windows\system32\drivers\USBAUDIO.sys 2009-04-24 12:22 1,429,809 ---sh--- c:\windows\system32\mjkhlxkb.ini 2009-04-24 12:19 99,328 a------- c:\windows\system32\zxkqhr.dll 2009-04-24 12:19 99,328 a------- c:\windows\system32\kcujhxks.dll 2009-04-23 16:39 99,840 a------- c:\windows\system32\spbpwj.dll 2009-04-23 16:39 99,840 a------- c:\windows\system32\cbhvndmw.dll 2009-04-23 16:36 1,429,771 ---sh--- c:\windows\system32\jyajkvbg.ini 2009-04-22 18:29 99,328 a------- c:\windows\system32\wjvgxv.dll 2009-04-22 18:29 99,328 a------- c:\windows\system32\ygmmdhdv.dll 2009-04-22 18:26 1,429,035 ---sh--- c:\windows\system32\vhphaqsw.ini 2009-04-21 12:11 99,840 a------- c:\windows\system32\xbfajlvk.dll 2009-04-21 12:11 99,840 a------- c:\windows\system32\hdkxtc.dll 2009-04-21 12:08 1,419,785 ---sh--- c:\windows\system32\srxpaoie.ini 2009-04-20 16:13 1,419,524 ---sh--- c:\windows\system32\ibfdlobw.ini 2009-04-19 13:31 1,419,524 ---sh--- c:\windows\system32\jvxwicik.ini 2009-04-19 13:28 99,840 a------- c:\windows\system32\wvuxjl.dll 2009-04-19 13:28 99,840 a------- c:\windows\system32\inuwhkjy.dll 2009-04-18 12:15 99,840 a------- c:\windows\system32\vvrxsm.dll 2009-04-18 12:15 99,840 a------- c:\windows\system32\unrchxyx.dll 2009-04-18 12:13 1,419,524 ---sh--- c:\windows\system32\oufdrkeu.ini 2009-04-17 11:06 121 ---sh--- c:\windows\system32\eteqgtys.ini 2009-04-17 11:05 74,752 a------- c:\windows\system32\sytgqete.dll 2009-04-16 16:43 99,840 a------- c:\windows\system32\rokkgz.dll 2009-04-16 16:43 99,840 a------- c:\windows\system32\ievvmaxm.dll 2009-04-16 16:40 1,419,524 ---sh--- c:\windows\system32\hcfnpyqw.ini 2009-04-15 19:35 99,840 a------- c:\windows\system32\bjkuiu.dll 2009-04-15 19:35 99,840 a------- c:\windows\system32\dpqovymc.dll 2009-04-15 19:33 1,417,381 ---sh--- c:\windows\system32\whplvidg.ini 2009-04-15 16:23 1,417,381 ---sh--- c:\windows\system32\homstmyb.ini 2009-04-15 16:20 99,840 a------- c:\windows\system32\zqypfq.dll 2009-04-15 16:20 99,840 a------- c:\windows\system32\qxkyngwf.dll 2009-04-14 16:23 1,408,666 ---sh--- c:\windows\system32\uiplgchd.ini 2009-04-14 16:20 99,840 a------- c:\windows\system32\mytbpo.dll 2009-04-14 16:20 99,840 a------- c:\windows\system32\sufkrfij.dll 2009-04-13 18:21 1,405,695 ---sh--- c:\windows\system32\ibtkwuxp.ini 2009-04-13 18:20 99,840 a------- c:\windows\system32\xquasdgr.dll 2009-04-13 18:20 99,840 a------- c:\windows\system32\fzduom.dll 2009-04-13 18:17 61,440 a------- c:\windows\system32\eyuxootj.exe ==================== Find3M ==================== 2009-05-13 16:05 1,879 a--sh--- c:\windows\system32\IhkSBJlm.ini2 2009-04-27 09:08 4,212 a---h--- c:\windows\system32\zllictbl.dat 2009-04-12 11:55 61,440 a------- c:\windows\system32\fiyhqsxu.exe 2009-04-12 11:49 99,840 a------- c:\windows\system32\thrognvt.dll 2009-04-12 11:49 99,840 a------- c:\windows\system32\ekrmyc.dll 2009-04-11 13:34 61,440 a------- c:\windows\system32\cnnxmwpv.exe 2009-04-11 13:28 99,840 a------- c:\windows\system32\rccvet.dll 2009-04-11 13:28 99,840 a------- c:\windows\system32\ocmxfwpx.dll 2009-04-10 10:59 99,840 a------- c:\windows\system32\uewixj.dll 2009-04-10 10:59 99,840 a------- c:\windows\system32\hlwhhltl.dll 2009-04-10 10:54 61,440 a------- c:\windows\system32\qcsclkyh.exe 2009-04-09 18:37 74,240 a------- c:\windows\system32\jnpnqmar.dll 2009-04-09 18:37 99,840 a------- c:\windows\system32\jtvzxn.dll 2009-04-09 18:37 99,840 a------- c:\windows\system32\fqdvkwfd.dll 2009-04-09 18:34 61,440 a------- c:\windows\system32\ttfdxmgp.exe 2009-04-09 18:32 99,840 a------- c:\windows\system32\lhnjeebk.dll 2009-04-09 18:32 99,840 a------- c:\windows\system32\drhdvd.dll 2009-04-08 17:46 74,752 a------- c:\windows\system32\jlyqpdft.dll 2009-04-08 17:46 61,440 a------- c:\windows\system32\cypoqssn.exe 2009-04-08 17:46 99,328 a------- c:\windows\system32\rjdtsqcg.dll 2009-04-08 17:46 99,328 a------- c:\windows\system32\hxitex.dll 2009-04-08 17:45 236,544 a------- c:\windows\system32\mlJBSkhI.dll 2009-04-08 17:40 44,544 a------- c:\windows\system32\vtUmnOiJ.dll 2009-04-08 17:40 44,544 a------- c:\windows\system32\ljJARlIc.dll 2009-02-21 18:38 410,984 a------- c:\windows\system32\deploytk.dll 2009-02-18 20:40 249,856 -------- c:\windows\Setup1.exe 2009-02-18 20:40 73,216 a------- c:\windows\ST6UNST.EXE 2009-02-16 00:10 72,584 a------- c:\windows\zllsputility.exe 2009-02-16 00:10 1,221,512 a------- c:\windows\system32\zpeng25.dll ============= FINISH: 16:09:07.20 =============== any assistance would be appreciated. |
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3
|
Re: annoying peice of malware
Hello, and welcome to TSF.
I am currently reviewing your log. I will be back with a fix for your problem as soon as possible. Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe. Please be patient with me during this time. |
|
|
|
|
|
#3 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3
|
Re: annoying peice of malware
Hi,
Please do the following: Download ComboFix from one of these locations: Link 1 Link 2 Link 3 VERY IMPORTANT !!! Save ComboFix.exe to your Desktop * IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
Notes: 1. Do not mouse-click Combofix's window while it is running. That may cause it to stall. 2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions. Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now |
|
|
|
|
|
#4 (permalink) |
|
Registered User
Join Date: May 2009
Location: NJ
Posts: 6
OS: win XP sp 3
|
Re: annoying peice of malware
good news, the links on google works like it should and zone alarm updates itself now. As far as the crashing i concerned, I'll need to use the laptop for several days to see if it still happens. I'll post with in 2 days to let you know if its fully working.
ps the log file is attached as asked ComboFix 09-05-14.07 - dude 05/15/2009 13:34.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.697 [GMT -4:00] Running from: c:\documents and settings\dude\Desktop\ComboFix.exe AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Outdated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF} FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} * Resident AV is active . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\ahabwase.dll c:\windows\system32\ahgjmpxc.dll c:\windows\system32\akgkucrl.ini c:\windows\system32\anxulgpo.ini c:\windows\system32\arnkwaue.dll c:\windows\system32\bfvdjdba.dll c:\windows\system32\bjkuiu.dll c:\windows\system32\bpbqrkpl.ini c:\windows\system32\cbhvndmw.dll c:\windows\system32\coybivll.dll c:\windows\system32\cvjmzx.dll c:\windows\system32\dilijhcw.ini c:\windows\system32\dpqovymc.dll c:\windows\system32\dpqrem.dll c:\windows\system32\drhdvd.dll c:\windows\system32\drivers\gxvxcbwqgikhbmqhtimoyxtetfmynkmavxegy.sys c:\windows\system32\ekrmyc.dll c:\windows\system32\eprmqnjv.ini c:\windows\system32\eteqgtys.ini c:\windows\system32\ffxmmqlr.ini c:\windows\system32\fipyyefh.dll c:\windows\system32\fpadqdyu.ini c:\windows\system32\fqdvkwfd.dll c:\windows\system32\fzduom.dll c:\windows\system32\gxvxccounter c:\windows\system32\gxvxciuhpihrlprybqpxwirqptxjcaorwporj.dll c:\windows\system32\gzmnwb.dll c:\windows\system32\hahotp.dll c:\windows\system32\hcfnpyqw.ini c:\windows\system32\hdkxtc.dll c:\windows\system32\hebevwmw.ini c:\windows\system32\hjcqtnsb.dll c:\windows\system32\hlwhhltl.dll c:\windows\system32\homstmyb.ini c:\windows\system32\hxitex.dll c:\windows\system32\ibfdlobw.ini c:\windows\system32\ibtkwuxp.ini c:\windows\system32\ievvmaxm.dll c:\windows\system32\IhkSBJlm.ini c:\windows\system32\IhkSBJlm.ini2 c:\windows\system32\inaydwmv.ini c:\windows\system32\inuwhkjy.dll c:\windows\system32\ipxiatra.dll c:\windows\system32\iyccscvx.ini c:\windows\system32\izszba.dll c:\windows\system32\jcsmcfpo.dll c:\windows\system32\jlyqpdft.dll c:\windows\system32\jnpnqmar.dll c:\windows\system32\jsdritsw.ini c:\windows\system32\jtvzxn.dll c:\windows\system32\jvxwicik.ini c:\windows\system32\jyajkvbg.ini c:\windows\system32\kcujhxks.dll c:\windows\system32\klakcrei.ini c:\windows\system32\kvacsl.dll c:\windows\system32\kvxuespa.dll c:\windows\system32\lhnjeebk.dll c:\windows\system32\ljJARlIc.dll c:\windows\system32\lmlgouul.dll c:\windows\system32\mbinaore.dll c:\windows\system32\mhoogjkn.dll c:\windows\system32\mjkhlxkb.ini c:\windows\system32\mlJBSkhI.dll c:\windows\system32\mpjdby.dll c:\windows\system32\mytbpo.dll c:\windows\system32\ocmxfwpx.dll c:\windows\system32\ooiyat.dll c:\windows\system32\opfcmscj.ini c:\windows\system32\optfiq.dll c:\windows\system32\oslfgr.dll c:\windows\system32\otxjww.dll c:\windows\system32\oufdrkeu.ini c:\windows\system32\pawfrgab.ini c:\windows\system32\ptihsisr.ini c:\windows\system32\qihgsagq.ini c:\windows\system32\qloibi.dll c:\windows\system32\qxkyngwf.dll c:\windows\system32\ramqnpnj.ini c:\windows\system32\rccvet.dll c:\windows\system32\rgqspo.dll c:\windows\system32\ridsmqiy.dll c:\windows\system32\rjdtsqcg.dll c:\windows\system32\rmffbhvi.ini c:\windows\system32\rokkgz.dll c:\windows\system32\rpvjeday.ini c:\windows\system32\rsgphdtv.dll c:\windows\system32\rtdxtcjw.ini c:\windows\system32\spbpwj.dll c:\windows\system32\srxpaoie.ini c:\windows\system32\sufkrfij.dll c:\windows\system32\sytgqete.dll c:\windows\system32\tfdpqylj.ini c:\windows\system32\thrognvt.dll c:\windows\system32\tighoz.dll c:\windows\system32\tlqwvp.dll c:\windows\system32\tmklrk.dll c:\windows\system32\tttltg.dll c:\windows\system32\uewixj.dll c:\windows\system32\uikwoada.dll c:\windows\system32\uiplgchd.ini c:\windows\system32\uixghqsl.ini c:\windows\system32\unrchxyx.dll c:\windows\system32\vajubbhk.dll c:\windows\system32\vbdkptjf.dll c:\windows\system32\vhphaqsw.ini c:\windows\system32\vtUmnOiJ.dll c:\windows\system32\vvrxsm.dll c:\windows\system32\wbmssz.dll c:\windows\system32\wchjilid.dll c:\windows\system32\wfbdwbwv.dll c:\windows\system32\whplvidg.ini c:\windows\system32\wjvgxv.dll c:\windows\system32\wkjcfq.dll c:\windows\system32\wvuxjl.dll c:\windows\system32\wyvkfmcq.dll c:\windows\system32\wzeyqe.dll c:\windows\system32\xbfajlvk.dll c:\windows\system32\xhutyxci.dll c:\windows\system32\xquasdgr.dll c:\windows\system32\xxxqkiwk.ini c:\windows\system32\ygmmdhdv.dll c:\windows\system32\ykdgiwcp.dll c:\windows\system32\zqypfq.dll c:\windows\system32\zuhqdc.dll c:\windows\system32\zxkqhr.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_GXVXCSERV.SYS ((((((((((((((((((((((((( Files Created from 2009-04-15 to 2009-05-15 ))))))))))))))))))))))))))))))) . 2009-05-15 17:27 . 2009-05-15 18:40 3322400 --sha-w c:\windows\system32\drivers\fidbox.dat 2009-05-03 02:26 . 2009-05-03 02:26 664 ----a-w c:\windows\system32\d3d9caps.dat 2009-05-02 02:09 . 1995-04-19 04:00 27136 ----a-w c:\windows\system32\WAVMIX16.DLL 2009-05-02 02:09 . 1995-04-19 04:00 12800 ----a-w c:\windows\system32\WING32.DLL 2009-05-02 02:09 . 1995-04-19 04:00 92208 ----a-w c:\windows\system32\WING.DLL 2009-04-24 20:50 . 2004-08-04 03:07 59264 -c--a-w c:\windows\system32\dllcache\usbaudio.sys 2009-04-24 20:50 . 2004-08-04 03:07 59264 ----a-w c:\windows\system32\drivers\USBAUDIO.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-15 19:00 . 2009-03-31 18:40 -------- d-----w c:\program files\DNA 2009-05-15 17:27 . 2009-05-15 17:27 32 --sha-w c:\windows\system32\drivers\fidbox.idx 2009-04-27 13:08 . 2009-04-10 15:53 4212 ---ha-w c:\windows\system32\zllictbl.dat 2009-04-15 23:41 . 2009-02-18 19:34 -------- d-----w c:\program files\GameSpy Arcade 2009-04-15 21:50 . 2009-03-26 00:41 715 ----a-w c:\windows\eReg.dat 2009-04-15 21:41 . 2009-01-23 02:47 -------- d--h--w c:\program files\InstallShield Installation Information 2009-04-15 21:41 . 2009-02-15 00:10 -------- d-----w c:\program files\EA GAMES 2009-04-13 22:17 . 2009-04-13 22:17 61440 ----a-w c:\windows\system32\eyuxootj.exe 2009-04-12 15:55 . 2009-04-12 15:55 61440 ----a-w c:\windows\system32\fiyhqsxu.exe 2009-04-11 21:01 . 2009-04-08 20:29 -------- d-----w c:\program files\Visual Zip Password Recovery Processor 2009-04-11 17:34 . 2009-04-11 17:34 61440 ----a-w c:\windows\system32\cnnxmwpv.exe 2009-04-10 15:52 . 2009-04-10 15:52 -------- d-----w c:\program files\Zone Labs 2009-04-10 14:54 . 2009-04-10 14:54 61440 ----a-w c:\windows\system32\qcsclkyh.exe 2009-04-09 22:34 . 2009-04-09 22:34 61440 ----a-w c:\windows\system32\ttfdxmgp.exe 2009-04-09 01:40 . 2009-04-09 01:40 0 ----a-w c:\windows\nsreg.dat 2009-04-08 21:46 . 2009-04-08 21:46 61440 ----a-w c:\windows\system32\cypoqssn.exe 2009-04-07 22:56 . 2009-04-07 22:56 -------- d-----w c:\program files\Pcsx2 2009-04-04 23:11 . 2009-04-04 23:11 -------- d-----w c:\program files\Sizer 2009-04-03 16:04 . 2009-03-06 23:56 -------- d-----w c:\program files\Microsoft SQL Server 2009-04-03 16:00 . 2009-03-06 23:50 -------- d-----w c:\program files\Microsoft Visual Studio 9.0 2009-04-03 15:58 . 2009-04-03 15:58 -------- d-----w c:\program files\Microsoft Web Designer Tools 2009-03-31 21:05 . 2009-02-08 22:59 -------- d-----w c:\program files\EVEMon 2009-03-26 00:40 . 2009-03-26 00:40 -------- d-----w c:\program files\Maxis 2009-03-07 23:14 . 2009-02-08 23:00 68456 ----a-w c:\documents and settings\dude\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-02-21 22:38 . 2009-02-21 22:38 410984 ----a-w c:\windows\system32\deploytk.dll 2009-02-19 00:40 . 2009-02-19 00:40 249856 ------w c:\windows\Setup1.exe 2009-02-19 00:40 . 2009-02-19 00:40 73216 ----a-w c:\windows\ST6UNST.EXE 2009-02-16 04:10 . 2009-04-10 15:53 72584 ----a-w c:\windows\zllsputility.exe 2009-02-16 04:10 . 2009-04-10 15:52 1221512 ----a-w c:\windows\system32\zpeng25.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{32099AAC-C132-4136-9E9A-4E364A424E17}"= "c:\program files\DAEMON Tools Toolbar\DTToolbar.dll" [2008-12-10 929224] [HKEY_CLASSES_ROOT\clsid\{32099aac-c132-4136-9e9a-4e364a424e17}] [HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj.1] [HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}] [HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{32099AAC-C132-4136-9E9A-4E364A424E17}"= "c:\program files\DAEMON Tools Toolbar\DTToolbar.dll" [2008-12-10 929224] [HKEY_CLASSES_ROOT\clsid\{32099aac-c132-4136-9e9a-4e364a424e17}] [HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj.1] [HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}] [HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-07-27 15360] "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-03-31 321344] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-29 344064] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 98394] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 688218] "SunKist"="c:\program files\Digital Media Reader\shwicon2k.exe" [2004-05-26 139264] "D-Link Air USB Utility"="c:\program files\D-Link\Air USB Utility\AirCFG.exe" [2003-07-23 2695168] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-21 148888] "ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-16 981384] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128] [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\CCP\\EVE\\bin\\ExeFile.exe"= "c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"= "c:\\Program Files\\MohaaProxy\\mohaaProxy.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Program Files\\CCP\\EVE test\\bin\\ExeFile.exe"= "c:\\Program Files\\DNA\\btdna.exe"= R2 NIOC;NIOC Service;c:\windows\system32\NIOC.sys [9/27/2002 7:21 PM 22912] R2 WZCBDLService;WZCBDL Service;c:\program files\WZCBDL Service\WZCBDLS.exe [3/19/2002 1:15 PM 36864] R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [1/22/2009 11:01 PM 200192] R3 NsSmrCap;NsSmrCap;c:\windows\system32\drivers\NsSmrCap.sys [1/23/2009 10:23 AM 26624] S2 gupdate1c98e12f88c2d89;Google Update Service (gupdate1c98e12f88c2d89);c:\program files\Google\Update\GoogleUpdate.exe [2/13/2009 3:40 PM 133104] S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [1/23/2009 8:15 PM 33752] S3 Maya5PLEHelpServer;Alias Maya 5.0 PLE Help Server;c:\program files\AliasWavefront\Maya 5.0 Personal Learning Edition\docs\Wrapper.exe [2/18/2009 12:54 PM 98304] S3 NsTopaz;NewSoft Protocol Driver;c:\windows\system32\drivers\NSTopaz.sys [1/23/2009 10:28 AM 13238] . Contents of the 'Scheduled Tasks' folder 2009-03-31 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34] 2009-05-15 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-13 21:34] 2009-05-15 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-13 19:40] . - - - - ORPHANS REMOVED - - - - BHO-{09C72999-5C10-41A3-A524-24661D942003} - c:\windows\system32\vtUmnOiJ.dll BHO-{251d00d1-1995-4c97-b900-33436898a095} - c:\windows\system32\otxjww.dll BHO-{3DFDB2C8-AE0E-4413-878F-7FFC4E2C71E8} - c:\windows\system32\mlJBSkhI.dll HKLM-Run-ChangeFilterMerit - c:\program files\NewSoft\Presto! WMS2.5\ChangeFilterMerit.exe ShellExecuteHooks-{09C72999-5C10-41A3-A524-24661D942003} - c:\windows\system32\vtUmnOiJ.dll ShellExecuteHooks-{c270d96e-0335-4fd6-aae2-c1490c5f6780} - c:\windows\system32\otxjww.dll . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\dude\Application Data\Mozilla\Firefox\Profiles\himwypa6.default\ FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-15 15:01 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(912) c:\windows\system32\Ati2evxx.dll c:\windows\System32\BCMLogon.dll - - - - - - - > 'explorer.exe'(2988) c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\windows\system32\WLTRYSVC.EXE c:\windows\system32\BCMWLTRY.EXE c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\searchindexer.exe c:\windows\system32\wscntfy.exe c:\windows\system32\ati2evxx.exe c:\windows\system32\WLTRAY.EXE . ************************************************************************** . Completion time: 2009-05-15 15:04 - machine was rebooted ComboFix-quarantined-files.txt 2009-05-15 19:04 Pre-Run: 31,310,495,744 bytes free Post-Run: 39,897,292,800 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 310 |
|
|
|
|
|
#5 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3
|
Re: annoying peice of malware
Hi, we still have more work to do, please stay with me till I give you the all clean, I will analyze your log as quickly as I can and get back to you with further instructions
|
|
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: May 2009
Location: NJ
Posts: 6
OS: win XP sp 3
|
Re: annoying peice of malware
ok, zone alarm did and automatic scan while i was playing a game, and quarantined a few Trojans. here is the info zone alarm gave me on them:
Trojan-Downloader.Win32.FraudLoad.vohb was found in C:\WINDOWS\system32\cnnxmwpv.exe on 5/15/2009 16:44:48 Trojan-Downloader.Win32.FraudLoad.vohb was found in C:\WINDOWS\system32\cypoqssn.exe on 5/15/2009 16:44:50 Trojan-Downloader.Win32.FraudLoad.vohb was found in C:\WINDOWS\system32\eyuxootj.exe on 5/15/2009 16:46:44 Trojan-Downloader.Win32.FraudLoad.vohb was found in C:\WINDOWS\system32\fiyhqsxu.exe on 5/15/2009 16:46:44 Trojan-Downloader.Win32.FraudLoad.vohb was found in C:\WINDOWS\system32\qcsclkyh.exe on 5/15/2009 16:48:28 Trojan-Downloader.Win32.FraudLoad.vohb was found in C:\WINDOWS\system32\ttfdxmgp.exe on 5/15/2009 16:48:44 two questions, 1, should i go into zone alarm and delete the Trojans, and 2, should i shut the automatic scan off. |
|
|
|
|
|
#7 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3
|
Re: annoying peice of malware
Hi, don't delete anything just yet, disable the autoscan until we have finished cleaning this machine.
Thanks, I will be back soon with more instructions |
|
|
|
|
|
#8 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3
|
Re: annoying peice of malware
Hi,
Please do the following
Here's how to do that: Click Start > Run type Notepad click OK. This will open an empty notepad file: Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy') Code:
http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/376105-annoying-peice-malware.html#post2138098 Collect:: c:\windows\system32\eyuxootj.exe c:\windows\system32\fiyhqsxu.exe c:\windows\system32\cnnxmwpv.exe c:\windows\system32\qcsclkyh.exe c:\windows\system32\ttfdxmgp.exe c:\windows\system32\cypoqssn.exe Save this file to your desktop, Save this as "CFScript" Here's how to do that: 1.Click File; 2.Click Save As... Change the directory to your desktop; 3.Change the Save as type to "All Files"; 4.Type in the file name: CFScript 5.Click Save ... ![]()
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall. |
|
|
|
|
|
#9 (permalink) |
|
Registered User
Join Date: May 2009
Location: NJ
Posts: 6
OS: win XP sp 3
|
Re: annoying peice of malware
ok, zone alarm automatic scan is disabled, and i left the quarintined files alone. Here is the log you asked for.
ComboFix 09-05-14.07 - dude 05/15/2009 23:09.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.608 [GMT -4:00] Running from: c:\documents and settings\dude\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\dude\Desktop\CFScript.txt AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF} FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2009-04-16 to 2009-05-16 ))))))))))))))))))))))))))))))) . 2009-05-15 17:27 . 2009-05-16 03:11 5123360 --sha-w c:\windows\system32\drivers\fidbox.dat 2009-05-03 02:26 . 2009-05-03 02:26 664 ----a-w c:\windows\system32\d3d9caps.dat 2009-05-02 02:09 . 1995-04-19 04:00 27136 ----a-w c:\windows\system32\WAVMIX16.DLL 2009-05-02 02:09 . 1995-04-19 04:00 12800 ----a-w c:\windows\system32\WING32.DLL 2009-05-02 02:09 . 1995-04-19 04:00 92208 ----a-w c:\windows\system32\WING.DLL 2009-04-24 20:50 . 2004-08-04 03:07 59264 -c--a-w c:\windows\system32\dllcache\usbaudio.sys 2009-04-24 20:50 . 2004-08-04 03:07 59264 ----a-w c:\windows\system32\drivers\USBAUDIO.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-16 03:02 . 2009-03-31 18:40 -------- d-----w c:\program files\DNA 2009-05-15 21:47 . 2009-05-15 17:27 57284 --sha-w c:\windows\system32\drivers\fidbox.idx 2009-04-27 13:08 . 2009-04-10 15:53 4212 ---ha-w c:\windows\system32\zllictbl.dat 2009-04-15 23:41 . 2009-02-18 19:34 -------- d-----w c:\program files\GameSpy Arcade 2009-04-15 21:50 . 2009-03-26 00:41 715 ----a-w c:\windows\eReg.dat 2009-04-15 21:41 . 2009-01-23 02:47 -------- d--h--w c:\program files\InstallShield Installation Information 2009-04-15 21:41 . 2009-02-15 00:10 -------- d-----w c:\program files\EA GAMES 2009-04-11 21:01 . 2009-04-08 20:29 -------- d-----w c:\program files\Visual Zip Password Recovery Processor 2009-04-10 15:52 . 2009-04-10 15:52 -------- d-----w c:\program files\Zone Labs 2009-04-09 01:40 . 2009-04-09 01:40 0 ----a-w c:\windows\nsreg.dat 2009-04-07 22:56 . 2009-04-07 22:56 -------- d-----w c:\program files\Pcsx2 2009-04-04 23:11 . 2009-04-04 23:11 -------- d-----w c:\program files\Sizer 2009-04-03 16:04 . 2009-03-06 23:56 -------- d-----w c:\program files\Microsoft SQL Server 2009-04-03 16:00 . 2009-03-06 23:50 -------- d-----w c:\program files\Microsoft Visual Studio 9.0 2009-04-03 15:58 . 2009-04-03 15:58 -------- d-----w c:\program files\Microsoft Web Designer Tools 2009-03-31 21:05 . 2009-02-08 22:59 -------- d-----w c:\program files\EVEMon 2009-03-26 00:40 . 2009-03-26 00:40 -------- d-----w c:\program files\Maxis 2009-03-07 23:14 . 2009-02-08 23:00 68456 ----a-w c:\documents and settings\dude\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-02-21 22:38 . 2009-02-21 22:38 410984 ----a-w c:\windows\system32\deploytk.dll 2009-02-19 00:40 . 2009-02-19 00:40 249856 ------w c:\windows\Setup1.exe 2009-02-19 00:40 . 2009-02-19 00:40 73216 ----a-w c:\windows\ST6UNST.EXE 2009-02-16 04:10 . 2009-04-10 15:53 72584 ----a-w c:\windows\zllsputility.exe 2009-02-16 04:10 . 2009-04-10 15:52 1221512 ----a-w c:\windows\system32\zpeng25.dll . ((((((((((((((((((((((((((((( SnapShot@2009-05-15_19.01.38 ))))))))))))))))))))))))))))))))))))))))) . + 2009-05-16 03:01 . 2009-05-16 03:01 16384 c:\windows\Temp\Perflib_Perfdata_264.dat + 2009-04-10 16:00 . 2009-05-16 03:05 34332 c:\windows\system32\ZoneLabs\avsys\bases\sfdb.dat + 2009-04-10 16:15 . 2009-05-15 20:48 385024 c:\windows\system32\ZoneLabs\zlqrtdb.dat + 2009-05-15 19:18 . 2009-05-15 19:18 11576520 c:\windows\system32\ZoneLabs\spyware0.dat + 2009-04-10 15:53 . 2009-05-15 19:18 12221531 c:\windows\system32\ZoneLabs\spyware.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-07-27 15360] "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-03-31 321344] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-29 344064] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 98394] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 688218] "SunKist"="c:\program files\Digital Media Reader\shwicon2k.exe" [2004-05-26 139264] "D-Link Air USB Utility"="c:\program files\D-Link\Air USB Utility\AirCFG.exe" [2003-07-23 2695168] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-21 148888] "ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-16 981384] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128] [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\CCP\\EVE\\bin\\ExeFile.exe"= "c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"= "c:\\Program Files\\MohaaProxy\\mohaaProxy.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Program Files\\CCP\\EVE test\\bin\\ExeFile.exe"= "c:\\Program Files\\DNA\\btdna.exe"= R?2 WZCBDLService;WZCBDL Service;c:\program files\WZCBDL Service\WZCBDLS.exe [3/19/2002 1:15 PM 36864] R2 NIOC;NIOC Service;c:\windows\system32\NIOC.sys [9/27/2002 7:21 PM 22912] R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [1/22/2009 11:01 PM 200192] R3 NsSmrCap;NsSmrCap;c:\windows\system32\drivers\NsSmrCap.sys [1/23/2009 10:23 AM 26624] S2 gupdate1c98e12f88c2d89;Google Update Service (gupdate1c98e12f88c2d89);c:\program files\Google\Update\GoogleUpdate.exe [2/13/2009 3:40 PM 133104] S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [1/23/2009 8:15 PM 33752] S3 Maya5PLEHelpServer;Alias Maya 5.0 PLE Help Server;c:\program files\AliasWavefront\Maya 5.0 Personal Learning Edition\docs\Wrapper.exe [2/18/2009 12:54 PM 98304] S3 NsTopaz;NewSoft Protocol Driver;c:\windows\system32\drivers\NSTopaz.sys [1/23/2009 10:28 AM 13238] . Contents of the 'Scheduled Tasks' folder 2009-03-31 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34] 2009-05-16 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-13 21:34] 2009-05-16 c:\windows\Tasks\GoogleUpdateTaskMachine.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-13 19:40] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\dude\Application Data\Mozilla\Firefox\Profiles\himwypa6.default\ FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-15 23:11 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(908) c:\windows\system32\Ati2evxx.dll c:\windows\System32\BCMLogon.dll - - - - - - - > 'explorer.exe'(2308) c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2009-05-16 23:13 ComboFix-quarantined-files.txt 2009-05-16 03:13 ComboFix2.txt 2009-05-15 19:04 Pre-Run: 39,786,774,528 bytes free Post-Run: 39,767,728,128 bytes free 143 So far computer is still running fine, google still works, zone alarm updates, and no crashes yet. |
|
|
|
|
|
#10 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3
|
Re: annoying peice of malware
Hi please do the following:
Your Java is out of date. Java(TM) 6 Update 12 can be updated from the Java control panel. Go to Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now. An update should begin; follow the prompts. NEXT Please do a scan with Kaspersky Online Scanner.
|
|
|
|
|
|
#11 (permalink) |
|
Registered User
Join Date: May 2009
Location: NJ
Posts: 6
OS: win XP sp 3
|
Re: annoying peice of malware
sorry its been a couple of days, got real busy over the weekend. When i tried to update java, it said it was up to date, should i continue and do the Kaspersky scan anyway?
|
|
|
|
|
|
#13 (permalink) |
|
Registered User
Join Date: May 2009
Location: NJ
Posts: 6
OS: win XP sp 3
|
Re: annoying peice of malware
ok here is the report from kaspersky:
Wednesday, May 20, 2009 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Wednesday, May 20, 2009 00:55:16 Records in database: 2200588 Scan settings Scan using the following database extended Scan archives yes Scan mail databases yes Scan area My Computer C:\ D:\ E:\ F:\ Scan statistics Files scanned 97813 Threat name 21 Infected objects 103 Suspicious objects 0 Duration of the scan 06:15:22 File name Threat name Threats count C:\Qoobox\Quarantine\C\WINDOWS\system32\cbhvndmw.dll.vir Infected: Backdoor.Win32.Agent.afzy 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drhdvd.dll.vir Infected: Trojan-Downloader.Win32.Small.joo 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\fqdvkwfd.dll.vir Infected: Trojan-Downloader.Win32.Small.joo 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\fzduom.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.tls 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\gxvxciuhpihrlprybqpxwirqptxjcaorwporj.dll.vir Infected: Trojan.Win32.Agent2.hoq 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\gzmnwb.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\hahotp.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\hlwhhltl.dll.vir Infected: Trojan-Downloader.Win32.Small.joo 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\hxitex.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.txb 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\ievvmaxm.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\inuwhkjy.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\ipxiatra.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uwq 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\jcsmcfpo.dll.vir Infected: Trojan-Downloader.Win32.Boltolog.bxo 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\jlyqpdft.dll.vir Infected: Trojan.Win32.Monder.byuj 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\jnpnqmar.dll.vir Infected: Trojan.Win32.Monder.byzu 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\jtvzxn.dll.vir Infected: Trojan-Downloader.Win32.Small.joo 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\kvacsl.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uwq 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\kvxuespa.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\lhnjeebk.dll.vir Infected: Trojan-Downloader.Win32.Small.joo 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\ljJARlIc.dll.vir Infected: Trojan.Win32.Monderb.rrf 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\mbinaore.dll.vir Infected: Trojan.Win32.Monderd.w 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\mytbpo.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.txc 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\oslfgr.dll.vir Infected: Trojan.Win32.Monderd.w 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\otxjww.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.vji 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\rgqspo.dll.vir Infected: Trojan.Win32.Monderd.w 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\ridsmqiy.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\rjdtsqcg.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.txb 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\rokkgz.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\rsgphdtv.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.vji 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\spbpwj.dll.vir Infected: Backdoor.Win32.Agent.afzy 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\sufkrfij.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.txc 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\sytgqete.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvk 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\tighoz.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\tmklrk.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\uewixj.dll.vir Infected: Trojan-Downloader.Win32.Small.joo 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\uikwoada.dll.vir Infected: Trojan.Win32.Monderd.w 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\unrchxyx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\vbdkptjf.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\vtUmnOiJ.dll.vir Infected: Trojan.Win32.Monderb.rrf 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\vvrxsm.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\wchjilid.dll.vir Infected: Trojan.Win32.Monder.cfuv 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\wkjcfq.dll.vir Infected: Trojan-Spy.Win32.Agent.anra 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\wvuxjl.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\wyvkfmcq.dll.vir Infected: Trojan-Spy.Win32.Agent.anra 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\wzeyqe.dll.vir Infected: Trojan.Win32.Monderd.w 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\xhutyxci.dll.vir Infected: Trojan.Win32.Monderd.w 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\xquasdgr.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.tls 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\ykdgiwcp.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP59\A0010117.exe Infected: Trojan-Spy.Win32.Agent.bnx 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010120.dll Infected: Trojan.Win32.Agent2.hoq 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010163.dll Infected: Backdoor.Win32.Agent.afzy 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010169.dll Infected: Trojan-Downloader.Win32.Small.joo 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010176.dll Infected: Trojan-Downloader.Win32.Small.joo 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010177.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.tls 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010178.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010179.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010184.dll Infected: Trojan-Downloader.Win32.Small.joo 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010186.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.txb 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010190.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010192.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010193.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uwq 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010196.dll Infected: Trojan-Downloader.Win32.Boltolog.bxo 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010197.dll Infected: Trojan.Win32.Monder.byuj 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010198.dll Infected: Trojan.Win32.Monder.byzu 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010200.dll Infected: Trojan-Downloader.Win32.Small.joo 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010205.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uwq 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010206.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010207.dll Infected: Trojan-Downloader.Win32.Small.joo 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010208.dll Infected: Trojan.Win32.Monderb.rrf 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010210.dll Infected: Trojan.Win32.Monderd.w 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010215.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.txc 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010220.dll Infected: Trojan.Win32.Monderd.w 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010221.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.vji 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010230.dll Infected: Trojan.Win32.Monderd.w 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010231.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010232.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.txb 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010234.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010236.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.vji 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010238.dll Infected: Backdoor.Win32.Agent.afzy 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010240.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.txc 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010241.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvk 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010244.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010246.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010248.dll Infected: Trojan-Downloader.Win32.Small.joo 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010249.dll Infected: Trojan.Win32.Monderd.w 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010252.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010254.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uxi 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010256.dll Infected: Trojan.Win32.Monderb.rrf 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010257.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010259.dll Infected: Trojan.Win32.Monder.cfuv 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010263.dll Infected: Trojan-Spy.Win32.Agent.anra 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010264.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.avvj 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010265.dll Infected: Trojan-Spy.Win32.Agent.anra 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010266.dll Infected: Trojan.Win32.Monderd.w 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010268.dll Infected: Trojan.Win32.Monderd.w 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010269.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.tls 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0010272.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.uip 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0011203.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0011204.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0011206.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0011207.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0011209.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1 C:\System Volume Information\_restore{74E80B42-1452-4B96-9137-98F7785885EC}\RP60\A0011210.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1 The selected area was scanned. |
|
|
|
|
|
#14 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,177
OS: XP sp3
|
Re: annoying peice of malware
Hi,
Your machine is clean. Everything that Kaspersky found was either already in quarantine or in an old system restore point, which we are now going to clean up. One way of assuring your machine doesn't get reinfected is never to use peer2peer file sharing applications As mentioned in our pre-posting topic: NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help P2P - There are remnants of the BitTorrent DNA application remaining on your machine. (Did you recently uninstall BitTorrent?) We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It probably contributed to your current situation. This page will give you further information. Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.Please see this topic for more information: Perils of P2P File Sharing.I would strongly recommend that you uninstall this now. You can do so via Control Panel >> Add or Remove Programs. Now for some housekeeping: Java should be version 6 update 13, sometimes the auto update doesn't kick in, but you can get the latest update directly from the Java site HERE NEXT You can delete the DDS and GMER folders from your desktop, then Follow these steps to uninstall Combofix
![]() NEXT Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. Thank you for your patience, and performing all of the procedures requested |
|
|
|
![]() |
| Thread Tools | |
|
|