![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Feb 2005
Posts: 18
OS: win 2000
|
ucleaner
internet explorer goes to the ucleaner website, and system running very slow
your assistance will be most appreciated attached is a dss log file Deckard's System Scanner v20071014.68 Run by mstratman on 2008-03-25 11:34:13 Computer is in Normal Mode. -------------------------------------------------------------------------------- Backed up registry hives. Performed disk cleanup. -- HijackThis (run as mstratman.exe) ------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:35:03 AM, on 25/03/2008 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\svchost.exe C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe C:\WINNT\TEMP\BW1B03.EXE C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe C:\WINNT\system32\igfxtray.exe C:\WINNT\system32\hkcmd.exe C:\Program Files\antiviirus.exe C:\WINNT\system32\ctfmon.exe C:\Program Files\tmp0.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\tmp1.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\WINNT\system32\yvgnufaf.exe C:\WINNT\system32\wuauclt.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\Program Files\tmp2.exe C:\Program Files\tmp3.exe C:\Program Files\Microsoft ActiveSync\WCESMgr.exe C:\Program Files\dss.exe C:\WINNT\explorer.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\mstratman.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.microsoft.com O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: GNX Bingo - {B2DCA34E-9D1C-4EDA-A1BE-C24D1B4AAE55} - C:\WINNT\kdftlboepta.dll O3 - Toolbar: qvdntlmw - {8BD58549-BB16-480E-8530-3F957AE09B51} - C:\DOCUME~1\MSTRAT~1.RMG\LOCALS~1\Temp\ac8zt2\qvdntlmw.dll (file missing) O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe O4 - HKLM\..\Run: [antiviirus] C:\Program Files\antiviirus.exe O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [pqpohocu] C:\WINNT\system32\yvgnufaf.exe O4 - HKLM\..\Policies\Explorer\Run: [uJLNy1DPOi] C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user') O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://www.boral.com.au/OutdoorDesignGuide/ScriptX.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - http://www.cit.org.au/crystalreportv...iveXViewer.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = rmgpl.local O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = rmgpl.local O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = rmgpl.local O21 - SSODL: DrvDrive - {e56e9ea8-ae04-4f5d-b581-d8b783fc0a16} - C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16}\DrvDrive.dll O21 - SSODL: zip - {dd76a9ab-b5d8-4f1d-94d6-20829530a33a} - C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a}\zip.dll O21 - SSODL: vbgtorfd - {3153A3B8-DF57-45DC-9A23-E0D23DC05913} - C:\WINNT\vbgtorfd.dll O21 - SSODL: dwnrpofk - {3F795C44-FCF6-4E4C-82F9-3D6D3257C006} - C:\WINNT\dwnrpofk.dll O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe O24 - Desktop Component 0: Privacy Protection - file:///C:\WINNT\privacy_danger\index.htm -- End of file - 6729 bytes -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R2 TM_CFW (Common Firewall Driver) - c:\program files\trend micro\officescan client\tm_cfw.sys <Not Verified; Trend Micro Inc.; Trend Micro Common Firewall Module 1.2> -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 OfcPfwSvc (Trend Micro Client/Server Security Agent Personal Firewall) - c:\program files\trend micro\officescan client\ofcpfwsvc.exe <Not Verified; Trend Micro Inc.; Trend Micro Client/Server/Messaging Security for SMB> S4 %AF夶À¨ (Network Security Service (NSS)) - c:\winnt\system32\apiug.exe /s (file missing) -- Device Manager: Disabled ---------------------------------------------------- No disabled devices found. -- Files created between 2008-02-25 and 2008-03-25 ----------------------------- 2008-03-25 11:32:50 686630 --a------ C:\Program Files\dss.exe 2008-03-24 18:25:51 16384 --a------ C:\WINNT\system32\Perflib_Perfdata_b08.dat 2008-03-24 18:25:46 0 d-------- C:\DrWatson 2008-03-24 17:04:05 0 d-------- C:\WINNT\privacy_danger 2008-03-24 11:40:52 0 d-------- C:\Documents and Settings\All Users\Application Data\yfmrqhsn 2008-03-24 11:40:49 114688 --a------ C:\WINNT\system32\yvgnufaf.exe 2008-03-24 11:39:56 270336 --a------ C:\WINNT\vbgtorfd.dll 2008-03-24 11:39:56 184320 --a------ C:\WINNT\qvdntlmw.dll 2008-03-24 11:39:56 94208 --a------ C:\WINNT\norlatmx.exe 2008-03-24 11:39:56 249856 --a------ C:\WINNT\kdftlboepta.dll 2008-03-24 11:39:56 249856 --a------ C:\WINNT\dwnrpofk.dll 2008-03-24 11:39:45 16444 -r-hs---- C:\Program Files\tmp3.exe 2008-03-24 11:39:40 16444 -r-hs---- C:\Program Files\tmp2.exe 2008-03-24 11:39:35 16444 -r-hs---- C:\Program Files\tmp1.exe 2008-03-24 11:39:30 16444 -r-hs---- C:\Program Files\tmp0.exe 2008-03-24 11:39:29 21568 --a------ C:\Program Files\antiviirus.exe <ANTIVI~1.EXE> -- Find3M Report --------------------------------------------------------------- 2008-02-29 12:12:48 106 --a------ C:\WINNT\!MemIni 2008-01-10 08:32:54 1285922 ---h----- C:\WINNT\ShellIconCache -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B2DCA34E-9D1C-4EDA-A1BE-C24D1B4AAE55}] 24/03/08 10:41a 249856 --a------ C:\WINNT\kdftlboepta.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Synchronization Manager"="mobsync.exe" [19/06/03 12:05p C:\WINNT\system32\mobsync.exe] "NeroCheck"="C:\WINNT\System32\\NeroCheck.exe" [09/07/01 08:20p] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [02/05/05 09:16a] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05/07/05 12:58p] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [24/06/05 03:16p] "OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [29/03/07 09:10a] "IgfxTray"="C:\WINNT\system32\igfxtray.exe" [21/06/05 04:48p] "HotKeysCmds"="C:\WINNT\system32\hkcmd.exe" [21/06/05 04:44p] "antiviirus"="C:\Program Files\antiviirus.exe" [24/03/08 11:39a] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="ctfmon.exe" [20/02/01 01:09p C:\WINNT\system32\CTFMON.EXE] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [30/03/06 04:45p] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [15/11/05 07:44p] "pqpohocu"="C:\WINNT\system32\yvgnufaf.exe" [24/03/08 11:40a] [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce] "^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "internat.exe"=internat.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [16/07/2002 5:25:05 PM] Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [23/09/2005 10:05:26 PM] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"=0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoWelcomeScreen"=1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run] "uJLNy1DPOi"=C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "DisablePersonalDirChange"=1 (0x1) [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] Source= file:///C:\WINNT\privacy_danger\index.htm FriendlyName= Privacy Protection [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "DrvDrive"= {e56e9ea8-ae04-4f5d-b581-d8b783fc0a16} - C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16}\DrvDrive.dll [24/03/08 11:39a 14378] "zip"= {dd76a9ab-b5d8-4f1d-94d6-20829530a33a} - C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a}\zip.dll [24/03/08 11:39a 23202] "vbgtorfd"= {3153A3B8-DF57-45DC-9A23-E0D23DC05913} - C:\WINNT\vbgtorfd.dll [24/03/08 10:41a 270336] "dwnrpofk"= {3F795C44-FCF6-4E4C-82F9-3D6D3257C006} - C:\WINNT\dwnrpofk.dll [24/03/08 10:41a 249856] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ActiveSync] WcesWlgn.dll 15/11/05 07:44p 7168 C:\WINNT\system32\WcesWlgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys] @="Driver" -- End of Deckard's System Scanner: finished at 2008-03-25 11:35:39 ------------ Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows 2000 Professional (build 2195) SP 4.0 Architecture: X86; Language: English CPU 0: Intel(R) Pentium(R) 4 CPU 1.70GHz Percentage of Memory in Use: 69% Physical Memory (total/avail): 509.8 MiB / 155.43 MiB Pagefile Memory (total/avail): 1244.45 MiB / 895.82 MiB Virtual Memory (total/avail): 2047.88 MiB / 1956.36 MiB A: is Removable (No Media) C: is Fixed (FAT32) - 37.26 GiB total, 8.63 GiB free. D: is CDROM (No Media) E: is Removable (FAT) G: is Network (NTFS) H: is Network (NTFS) I: is Network (NTFS) J: is Network (NTFS) S: is Network (NTFS) V: is Network (NTFS) \\.\PHYSICALDRIVE0 - ST340014A - 37.27 GiB - 1 partition \PARTITION0 (bootable) - Unknown - 37.27 GiB - C: \\.\PHYSICALDRIVE1 - SanDisk USB Flash Drive USB Device - 1898.31 MiB - 1 partition \PARTITION0 (bootable) - Win95 w/Extended Int 13 - 1905.99 MiB - E: -- Security Center ------------------------------------------------------------- AUOptions is set to notify before install. -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\mstratman.RMGPL\Application Data CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=WORKSTATION1 ComSpec=C:\WINNT\system32\cmd.exe HOMEDRIVE=C: HOMEPATH=\Documents and Settings\mstratman.RMGPL LOGONSERVER=\\SERVER NUMBER_OF_PROCESSORS=1 OS=Windows_NT Os2LibPath=C:\WINNT\system32\os2\dll; Path=C:\WINNT\system32;C:\WINNT;C:\WINNT\System32\Wbem;C:\PROGRA~1\MICROS~2\Office PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 1 Stepping 2, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=0102 ProgramFiles=C:\Program Files PROMPT=$P$G SystemDrive=C: SystemRoot=C:\WINNT TEMP=C:\DOCUME~1\MSTRAT~1.RMG\LOCALS~1\Temp TMP=C:\DOCUME~1\MSTRAT~1.RMG\LOCALS~1\Temp USERDNSDOMAIN=rmgpl.local USERDOMAIN=RMGPL USERNAME=mstratman USERPROFILE=C:\Documents and Settings\mstratman.RMGPL windir=C:\WINNT -- User Profiles --------------------------------------------------------------- Administrator.APG (admin) PJRYAN mstratman (admin) lmcmanus (new local, net ready) mstratman.RMGPL (admin) pjryan.RMGPL sgoyne (admin) fax.RMGPL CorporateDiary (admin) kmarcato admin realagribusiness rzessig (new local, net ready) awatson (new local, net ready) administrator.RMGPL (admin) mstratman.WORKSTATION1 (admin) Administrator (admin) mstratman.APG (admin) EOvermaat pjryan.APG Jarrod Ryan Rosemary Saunders corporate diary Mal Parker (admin) TBrown Michael Bryant (new local, net ready) Travel Diary (admin) Michael Dillon (new local, net ready) clive wilson (new local, admin, net ready) Shanene Romano Megan Dempsey (new local, net ready) Ken Daly (new local, net ready) fax administrator.APG.000 (admin) -- Add/Remove Programs --------------------------------------------------------- --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> C:\Program Files\Installshield Installation Information\{1002F324-18D1-4A79-95C8-84EA3E940287}\QBReplace.exe {1002F324-18D1-4A79-95C8-84EA3E940287}#{BB9C4072-0110-4192-A351-6DCEF8B67AFD} ACD FotoSlate --> C:\PROGRA~1\ACDSYS~1\FOTOSL~1\UNWISE.EXE C:\PROGRA~1\ACDSYS~1\FOTOSL~1\INSTALL.LOG Ad-Aware SE Personal --> C:\PROGRA~1\LAVASOFT\AD-AWA~2\UNWISE.EXE C:\PROGRA~1\LAVASOFT\AD-AWA~2\INSTALL.LOG Ad-Aware SE Personal --> MsiExec.exe /X{78CC3BAB-DE2A-4FB4-8FBB-E4DADDC26747} Adobe Acrobat 5.0 --> C:\WINNT\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll" Adobe Download Manager 1.2 (Remove Only) --> "C:\Program Files\Common Files\Adobe\ESD\uninst.exe" Adobe Flash Player 9 ActiveX --> C:\WINNT\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002} Avanquest update --> C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe -runfromtemp -l0x0009 -removeonly BurnInTest --> C:\WINNT\IsUninst.exe -f"C:\Program Files\PassMark\BurnInTest\Uninst.isu" CleanUp! --> C:\Program Files\CleanUp!\uninstall.exe DirectX 8.1 Hotfix - KB839643 --> C:\WINNT\$NtUninstallKB839643-DirectX81$\spuninst\spuninst.exe Express Burn --> C:\Program Files\NCH Swift Sound\ExpressBurn\uninst.exe getPlus(R)_ocx --> rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\inf\GETPLUSo.INF, DefaultUninstall Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll" HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall Icon Converter Plus --> C:\WINNT\Icon Converter Plus Uninstaller.exe Intel(R) Extreme Graphics Driver --> RUNDLL32.EXE C:\WINNT\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562 Intel(R) PRO Ethernet Adapter and Software --> Prounstl.exe Internet Explorer Q903235 --> C:\WINNT\ieuninst.exe C:\WINNT\INF\Q903235.inf iriver plus 3 (remove only) --> "C:\Program Files\iriver\iriver plus 3\uninstall.exe" iTunes --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{47808F78-F178-49DC-B708-15FE538B16FF} Macromedia Shockwave Player --> C:\WINNT\system32\MACROMED\SHOCKW~1\UNWISE.EXE C:\WINNT\system32\MACROMED\SHOCKW~1\Install.log Microsoft ActiveSync 4.0 --> MsiExec.exe /I{B208806F-A231-4FA0-AB3F-5C1B8979223E} Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{91110409-6000-11D3-8CFE-0150048383C9} Microsoft Office Project Professional 2003 --> MsiExec.exe /I{913B0409-6000-11D3-8CFE-0150048383C9} Microsoft XML Parser and SDK --> MsiExec.exe /I{3E908702-AF35-4611-9518-955DA24B7E07} Motorola Phone Tools --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}\setup.exe" -l0x9 -removeonly MSXML 4.0 SP2 (KB927978) --> MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F} MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} MYOB Accounting Plus v12 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{21057832-D865-4049-BCA4-CEF3C55A394F} MYOB Accounting Plus v13 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{BCC46C36-9460-409C-BF33-589445B0A0F1} MYOB Accounting Plus v13.5 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{5F73DF33-F605-4EE7-8035-A5A69E8EAAE7} MYOB Accounting Plus v14 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{C0C2A5D4-34E9-45EA-B529-D640E384B612} MYOB ODBC Direct v7 --> C:\Program Files\InstallShield Installation Information\{C71F2873-3229-4A9E-A2A2-F14DCBF63F56}\setup.exe -runfromtemp -l0x0409 MYOB Premier v10 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{DEC02295-F5D5-4371-ABB0-9818C45DDDBF} MYOB Premier v11 --> C:\Program Files\InstallShield Installation Information\{56A27C76-F24A-49BD-BA67-A969ABF954B4}\setup.exe -runfromtemp -l0x0409 MYOB Premier v8 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{3F5CFC8C-2F9C-4D50-9F81-EB96D2790448} MYOB Premier v9 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{61D794E5-8899-461D-A4CA-8F91CD0FBADC} Nero - Burning Rom --> MsiExec.exe /X{A4D7B764-4140-11D4-88EB-0050DA3579C0} QuickBooks Premier: Multi User Accounting 2005/06 --> C:\Program Files\Installshield Installation Information\{442E5924-1BB6-4EAA-893D-62291D87219A}\QBReplace.exe {442E5924-1BB6-4EAA-893D-62291D87219A}#{BA0FD89C-32B4-4D4E-A024-D2B071C84749} QuickLine Version 5.0 SR-2 --> C:\QUICKL~1\UNWISE.EXE C:\QUICKL~1\INSTALL.LOG QuickTime --> C:\WINNT\unvise32qt.exe C:\WINNT\system32\QuickTime\Uninstall.log RALPH-Chambers Screen Saver --> C:\WINNT\system32\RALPH-Chambers.scr /u RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 Security Update for DirectX 8 (KB941568) --> "C:\WINNT\$NtUninstallKB941568_DX8$\spuninst\spuninst.exe" Security Update for Windows 2000 (KB904706) --> "C:\WINNT\$NtUninstallKB904706$\spuninst\spuninst.exe" Security Update for Windows 2000 (KB923689) --> "C:\WINNT\$NtUninstallKB923689$\spuninst\spuninst.exe" Security Update for Windows 2000 (KB941569) --> "C:\WINNT\$NtUninstallKB941569$\spuninst\spuninst.exe" SigmaTel AC97 Audio Drivers --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7959721D-8268-4565-9E0E-C41A9F4848A9}\setup.exe" -nodialog -uninstall Spybot - Search & Destroy 1.3 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe" SpywareBlaster v3.5.1 --> "C:\Program Files\SpywareBlaster\unins000.exe" SpywareGuard v2.2 --> "C:\Program Files\SpywareGuard\unins000.exe" TNA 5 Service Release --> C:\Program Files\TNA5\Uninst_TNA 5 Service Release.exe /U "C:\Program Files\TNA5\Uninst_TNA 5 Service Release.log" Trend Micro Client/Server Security Agent --> "C:\Program Files\Trend Micro\OfficeScan Client\ntrmv.exe" Viewpoint Media Player (Remove Only) --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe -u VX2 Cleaner plug-in for Ad-Aware SE --> C:\PROGRA~1\LAVASOFT\AD-AWA~2\PLUGINS\VX2CLE~1\UNWISE.EXE C:\PROGRA~1\LAVASOFT\AD-AWA~2\PLUGINS\VX2CLE~1\INSTALL.LOG WebVideo Support --> C:\WINNT\norlatmx.exe Window Active --> C:\Program Files\Window Active\winactive.exe -uninstall Windows 2000 Service Pack 4 --> C:\WINNT\$NtServicePackUninstall$\spuninst\spuninst.exe Windows Media Player system update (9 Series) --> C:\PROGRA~1\WINDOW~2\setup_wm.exe /Uninstall WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall Yahoo! Toolbar --> C:\PROGRA~1\YAHOO!\COMMON\unyt.exe -- Application Event Log ------------------------------------------------------- Event Record #/Type6759 / Error Event Submitted/Written: 03/24/2008 00:25:04 PM Event ID/Source: 1000 / Userenv Event Description: Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator. DETAIL - Access is denied. , Build number ((2195)). Event Record #/Type6748 / Error Event Submitted/Written: 03/17/2008 07:12:55 PM Event ID/Source: 1000 / Userenv Event Description: Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator. DETAIL - Access is denied. , Build number ((2195)). Event Record #/Type6746 / Error Event Submitted/Written: 03/17/2008 11:35:54 AM Event ID/Source: 1000 / Userenv Event Description: Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator. DETAIL - Access is denied. , Build number ((2195)). Event Record #/Type6742 / Error Event Submitted/Written: 03/14/2008 05:11:04 PM Event ID/Source: 1000 / Userenv Event Description: Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator. DETAIL - Access is denied. , Build number ((2195)). Event Record #/Type6737 / Error Event Submitted/Written: 03/11/2008 07:17:17 PM Event ID/Source: 1000 / Userenv Event Description: Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator. DETAIL - Access is denied. , Build number ((2195)). -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type13582 / Error Event Submitted/Written: 03/25/2008 11:30:20 AM Event ID/Source: 2504 / Server Event Description: The server could not bind to the transport \Device\NetBT_Tcpip_{A6EBB69A-36F7-4E5B-9CB6-17D5344D1944}. Event Record #/Type13581 / Error Event Submitted/Written: 03/25/2008 11:30:20 AM Event ID/Source: 2000 / Srv Event Description: The server's call to a system service failed unexpectedly. Event Record #/Type13580 / Error Event Submitted/Written: 03/25/2008 11:30:20 AM Event ID/Source: 2000 / Srv Event Description: The server's call to a system service failed unexpectedly. Event Record #/Type13577 / Error Event Submitted/Written: 03/25/2008 11:29:47 AM Event ID/Source: 7024 / Service Control Manager Event Description: The Computer Browser service terminated with service-specific error 2250. Event Record #/Type13533 / Error Event Submitted/Written: 03/25/2008 07:49:22 AM Event ID/Source: 2504 / Server Event Description: The server could not bind to the transport \Device\NetBT_Tcpip_{A6EBB69A-36F7-4E5B-9CB6-17D5344D1944}. -- End of Deckard's System Scanner: finished at 2008-03-25 11:35:39 ------------ |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home
|
Re: ucleaner
Please visit this webpage for instructions for downloading and running ComboFix:
http://www.bleepingcomputer.com/comb...o-use-combofix Please ensure you read this guide carefully and install the Recovery Console first. The Windows Recovery Console will allow you to boot up into a special recovery mode. This allows us to help you in the case that your computer has a problem after an attempted removal of malware. Post the log from ComboFix when you've accomplished that, along with a new HijackThis log. If you have any questions along the way, STOP and ask them before proceeding.
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#4 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home
|
Re: ucleaner
Windows 2000 users typically have an installation CD.
Install the Windows Recovery Console After Windows is Already Installed on the Computer 1. Click Start, click Run, and then type <CD-ROM drive letter>:\i386\winnt32.exe /cmdcons in the Open box, where <CD-ROM drive letter> is the drive letter assigned to your CD-ROM drive. 2. Click OK, follow the instructions on the screen to finish Setup, and then restart your computer. If you do not have an installation CD, there is no similar download package for Windows 2000 as there is for XP. http://support.microsoft.com/kb/216417
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: Feb 2005
Posts: 18
OS: win 2000
|
Re: ucleaner
New HJT log file below. attached the combofix file
ComboFix 08-03-24.1 - mstratman 2008-04-01 11:44:58.2 - FAT32x86 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.345 [GMT 9.5:30] Running from: C:\Documents and Settings\mstratman.RMGPL\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\mstratman.RMGPL\Desktop\Privacy Protector.url C:\WINNT\dwnrpofk.dll . ((((((((((((((((((((((((( Files Created from 2008-03-01 to 2008-04-01 ))))))))))))))))))))))))))))))) . 2008-04-01 11:45 . 08-04-01 11:45 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_30c.dat 2008-04-01 07:39 . 08-04-01 07:39 16,384 --a------ C:\WINNT\system32\Perflib_Perfdata_320.dat 2008-03-31 12:00 . 08-03-31 12:00 94,208 --a------ C:\WINNT\system32\betkdotc.exe 2008-03-30 09:55 . 08-03-30 09:55 <DIR> d-------- C:\WINNT\Favorites 2008-03-25 11:35 . 08-03-25 11:35 16,384 --a------ C:\WINNT\system32\Perflib_Perfdata_32c.dat 2008-03-25 11:33 . 08-03-25 11:33 <DIR> d-------- C:\Deckard 2008-03-25 11:32 . 08-03-25 10:02 686,630 --a------ C:\Program Files\dss.exe 2008-03-25 07:45 . 08-03-25 07:45 0 --a------ C:\si0.1k 2008-03-24 18:25 . 08-03-24 18:25 <DIR> d-------- C:\DrWatson 2008-03-24 18:25 . 08-03-24 18:25 16,384 --a------ C:\WINNT\system32\Perflib_Perfdata_b08.dat 2008-03-24 11:40 . 08-03-24 11:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\yfmrqhsn 2008-03-24 11:39 . 08-03-24 10:41 270,336 --a------ C:\WINNT\vbgtorfd.dll 2008-03-24 11:39 . 08-03-24 10:41 249,856 --a------ C:\WINNT\kdftlboepta.dll 2008-03-24 11:39 . 08-03-24 10:41 94,208 --a------ C:\WINNT\norlatmx.exe 2008-03-17 18:13 . 08-03-24 11:42 54,156 --ah----- C:\WINNT\QTFont.qfn 2008-03-17 18:13 . 08-03-17 18:13 1,409 --a------ C:\WINNT\QTFont.for . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-06 00:18 25,755,448 ----a-w C:\wmp11-windowsxp-x86-enu.exe 2007-01-12 06:52 92,064 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmmdm.sys 2007-01-12 06:52 9,232 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmmdfl.sys 2007-01-12 06:52 79,328 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmserd.sys 2007-01-12 06:52 66,656 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmbus.sys 2007-01-12 06:52 6,208 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmcmnt.sys 2007-01-12 06:52 5,936 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmwhnt.sys 2007-01-12 06:52 4,048 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmcr.sys 2007-01-12 06:52 25,600 ----a-w C:\Documents and Settings\mstratman.RMGPL\usbsermptxp.sys 2007-01-12 06:52 22,768 ----a-w C:\Documents and Settings\mstratman.RMGPL\usbsermpt.sys 2006-06-13 08:29 1,023,486 ----a-w C:\Documents and Settings\mstratman.RMGPL\speakers.zip 2005-05-01 23:44 21,848,504 ----a-w C:\Program Files\iTunesSetup.exe 2002-06-19 05:00 271 ---h--w C:\Program Files\desktop.ini 2002-06-19 05:00 21,952 ---h--w C:\Program Files\folder.htt 2001-05-08 13:30 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys 2004-10-25 03:30 56 --sh--r C:\WINNT\system32\C2095087DE.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B2DCA34E-9D1C-4EDA-A1BE-C24D1B4AAE55}] 08-03-24 10:41 249856 --a------ C:\WINNT\kdftlboepta.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="ctfmon.exe" [01-02-20 13:09 8192 C:\WINNT\system32\CTFMON.EXE] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [06-03-30 16:45 313472] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [05-11-15 19:44 1200128] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [08-01-28 11:43 2097488] "pqpohocu"="C:\WINNT\system32\yvgnufaf.exe" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Synchronization Manager"="mobsync.exe" [03-06-19 12:05 111376 C:\WINNT\system32\mobsync.exe] "NeroCheck"="C:\WINNT\System32\\NeroCheck.exe" [01-07-09 20:20 155648] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [05-05-02 09:16 98304] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05-07-05 12:58 180269] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [05-06-24 15:16 278528] "OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [07-03-29 09:10 394952] "IgfxTray"="C:\WINNT\system32\igfxtray.exe" [05-06-21 16:48 155648] "HotKeysCmds"="C:\WINNT\system32\hkcmd.exe" [05-06-21 16:44 126976] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "internat.exe"="internat.exe" [01-05-08 23:00 20752 C:\WINNT\system32\internat.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 12:05 186640] C:\Documents and Settings\mstratman.APG\Start Menu\Programs\Startup\ SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35 360448] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2002-07-16 17:25:05 106560] Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoWelcomeScreen"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run] "uJLNy1DPOi"= C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "DisablePersonalDirChange"= 1 (0x1) [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] Source= file:///C:\WINNT\privacy_danger\index.htm FriendlyName= Privacy Protection [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "DrvDrive"= {e56e9ea8-ae04-4f5d-b581-d8b783fc0a16} - C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16}\DrvDrive.dll [08-03-24 11:39 14378] "zip"= {dd76a9ab-b5d8-4f1d-94d6-20829530a33a} - C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a}\zip.dll [08-03-24 11:39 23202] "vbgtorfd"= {3153A3B8-DF57-45DC-9A23-E0D23DC05913} - C:\WINNT\vbgtorfd.dll [08-03-24 10:41 270336] "dwnrpofk"= {3F795C44-FCF6-4E4C-82F9-3D6D3257C006} - C:\WINNT\dwnrpofk.dll [ ] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ActiveSync] WcesWlgn.dll 05-11-15 19:44 7168 C:\WINNT\system32\WcesWlgn.dll R3 usb_rndisy;USB RNDIS Adapter;C:\WINNT\system32\DRIVERS\usb8023y.sys [05-10-25 09:02 ] R3 usbhub20;USB Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys [03-06-19 12:05 ] . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-01 11:47:33 Windows 5.0.2195 Service Pack 4 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-04-01 11:48:13 ComboFix-quarantined-files.txt 2008-04-01 02:18:12 . 2008-02-04 23:53:48 --- E O F --- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:56, on 2008-04-01 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\svchost.exe C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINNT\system32\igfxtray.exe C:\WINNT\system32\hkcmd.exe C:\WINNT\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\WINNT\system32\wuauclt.exe C:\Program Files\Microsoft ActiveSync\WCESMgr.exe C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\WINNT\explorer.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: GNX Bingo - {B2DCA34E-9D1C-4EDA-A1BE-C24D1B4AAE55} - C:\WINNT\kdftlboepta.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [pqpohocu] C:\WINNT\system32\yvgnufaf.exe O4 - HKLM\..\Policies\Explorer\Run: [uJLNy1DPOi] C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user') O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://www.boral.com.au/OutdoorDesignGuide/ScriptX.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - http://www.cit.org.au/crystalreportv...iveXViewer.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = rmgpl.local O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = rmgpl.local O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = rmgpl.local O21 - SSODL: DrvDrive - {e56e9ea8-ae04-4f5d-b581-d8b783fc0a16} - C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16}\DrvDrive.dll O21 - SSODL: zip - {dd76a9ab-b5d8-4f1d-94d6-20829530a33a} - C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a}\zip.dll O21 - SSODL: vbgtorfd - {3153A3B8-DF57-45DC-9A23-E0D23DC05913} - C:\WINNT\vbgtorfd.dll O21 - SSODL: dwnrpofk - {3F795C44-FCF6-4E4C-82F9-3D6D3257C006} - C:\WINNT\dwnrpofk.dll (file missing) O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe O24 - Desktop Component 0: Privacy Protection - file:///C:\WINNT\privacy_danger\index.htm -- End of file - 6758 bytes Last edited by tetonbob; 03-31-2008 at 07:35 PM. |
|
|
|
|
#6 (permalink) | |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home
|
Re: ucleaner
S& D Spybot's Tea Timer
While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent our tools from fixing certain things. Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
Download ResetTeaTimer.bat by right-clicking on the link, and choosing Save As. Save it to your desktop, or somewhere you can find it easily. Double click ResetTeaTimer.bat to remove all entries set by TeaTimer. Spywareguard Please disable Spywareguard, as it may hinder the removal of some entries. You can re-enable it after you're clean.
Open notepad and copy/paste the text in the quotebox below into it: Quote:
![]() Refering to the picture above, drag CFScript.txt into ComboFix.exe When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply. Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture a file to submit for analysis. Ensure you are connected to the internet and click OK. A browser will open. Simply follow the instructions to copy/paste/send the requested file. --------------------------------------------------------------------------------------------- Go to Control Panel click Display>Desktop>Customize Desktop>Web> Now, Uncheck Everything and delete if present:
--------------------------------------------------------------------------------------------- Open HijackThis and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here. ---------------------------------------------------------------------------------------------
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: Feb 2005
Posts: 18
OS: win 2000
|
Re: ucleaner
All seems to have gone through OK
no spybot in the system tray to stop In the combofix, had an error message of missing file, but clicked OK and it worked OK Also at the end, it rebooted the computer before it prepared the log looked in control panel > display>web tab - only item (other than home page) was privacy protection that I deleted new HJT log below and combofix log attached ComboFix 08-03-24.1 - mstratman 2008-04-01 13:58:53.3 - FAT32x86 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.215 [GMT 9.5:30] Running from: C:\Documents and Settings\mstratman.RMGPL\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\mstratman.RMGPL\Desktop\CFScript.txt FILE :: C:\si0.1k . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe C:\si0.1k C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a} C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a}\zip.dll C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16} C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16}\DrvDrive.dll C:\WINNT\kdftlboepta.dll C:\WINNT\norlatmx.exe C:\WINNT\system32\betkdotc.exe C:\WINNT\vbgtorfd.dll . ((((((((((((((((((((((((( Files Created from 2008-03-01 to 2008-04-01 ))))))))))))))))))))))))))))))) . 2008-04-01 14:09 . 08-04-01 14:09 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_434.dat 2008-04-01 14:04 . 03-06-19 12:05 17,680 --a------ C:\WINNT\system32\CF_init.exe 2008-04-01 13:58 . 08-04-01 13:58 270,336 --a------ C:\WINNT\vbgtorfd.dll.vir 2008-04-01 13:58 . 08-04-01 13:58 249,856 --a------ C:\WINNT\kdftlboepta.dll.vir 2008-04-01 13:58 . 08-04-01 13:58 94,208 --a------ C:\WINNT\system32\betkdotc.exe.vir 2008-04-01 13:58 . 08-04-01 13:58 94,208 --a------ C:\WINNT\norlatmx.exe.vir 2008-03-30 09:55 . 08-03-30 09:55 <DIR> d-------- C:\WINNT\Favorites 2008-03-25 11:33 . 08-03-25 11:33 <DIR> d-------- C:\Deckard 2008-03-25 11:32 . 08-03-25 10:02 686,630 --a------ C:\Program Files\dss.exe 2008-03-24 18:25 . 08-03-24 18:25 <DIR> d-------- C:\DrWatson 2008-03-24 11:40 . 08-03-24 11:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\yfmrqhsn 2008-03-17 18:13 . 08-03-24 11:42 54,156 --ah----- C:\WINNT\QTFont.qfn 2008-03-17 18:13 . 08-03-17 18:13 1,409 --a------ C:\WINNT\QTFont.for . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-06 00:18 25,755,448 ----a-w C:\wmp11-windowsxp-x86-enu.exe 2007-01-12 06:52 92,064 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmmdm.sys 2007-01-12 06:52 9,232 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmmdfl.sys 2007-01-12 06:52 79,328 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmserd.sys 2007-01-12 06:52 66,656 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmbus.sys 2007-01-12 06:52 6,208 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmcmnt.sys 2007-01-12 06:52 5,936 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmwhnt.sys 2007-01-12 06:52 4,048 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmcr.sys 2007-01-12 06:52 25,600 ----a-w C:\Documents and Settings\mstratman.RMGPL\usbsermptxp.sys 2007-01-12 06:52 22,768 ----a-w C:\Documents and Settings\mstratman.RMGPL\usbsermpt.sys 2006-06-13 08:29 1,023,486 ----a-w C:\Documents and Settings\mstratman.RMGPL\speakers.zip 2005-05-01 23:44 21,848,504 ----a-w C:\Program Files\iTunesSetup.exe 2002-06-19 05:00 271 ---h--w C:\Program Files\desktop.ini 2002-06-19 05:00 21,952 ---h--w C:\Program Files\folder.htt 2001-05-08 13:30 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys 2004-10-25 03:30 56 --sh--r C:\WINNT\system32\C2095087DE.sys . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ---- Directory of C:\Documents and Settings\All Users\Application Data\yfmrqhsn ---- 08-04-01 13:58 43008 --a------ C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe.vir 08-03-24 11:40 43008 --a------ C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe ((((((((((((((((((((((((((((( snapshot@Tue 2008-04-01_11.47.55.68 ))))))))))))))))))))))))))))))))))))))))) . + 2007-03-28 23:40:02 214,712 ----a-w C:\WINNT\TEMP\YY219.EXE . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="ctfmon.exe" [01-02-20 13:09 8192 C:\WINNT\system32\CTFMON.EXE] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [06-03-30 16:45 313472] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [05-11-15 19:44 1200128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Synchronization Manager"="mobsync.exe" [03-06-19 12:05 111376 C:\WINNT\system32\mobsync.exe] "NeroCheck"="C:\WINNT\System32\\NeroCheck.exe" [01-07-09 20:20 155648] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [05-05-02 09:16 98304] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05-07-05 12:58 180269] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [05-06-24 15:16 278528] "OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [07-03-29 09:10 394952] "IgfxTray"="C:\WINNT\system32\igfxtray.exe" [05-06-21 16:48 155648] "HotKeysCmds"="C:\WINNT\system32\hkcmd.exe" [05-06-21 16:44 126976] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "internat.exe"="internat.exe" [01-05-08 23:00 20752 C:\WINNT\system32\internat.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 12:05 186640] C:\Documents and Settings\mstratman.APG\Start Menu\Programs\Startup\ SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35 360448] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2002-07-16 17:25:05 106560] Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoWelcomeScreen"= 1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "DisablePersonalDirChange"= 1 (0x1) [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] Source= file:///C:\WINNT\privacy_danger\index.htm FriendlyName= Privacy Protection [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ActiveSync] WcesWlgn.dll 05-11-15 19:44 7168 C:\WINNT\system32\WcesWlgn.dll R3 usbhub20;USB Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys [03-06-19 12:05 ] S3 usb_rndisy;USB RNDIS Adapter;C:\WINNT\system32\DRIVERS\usb8023y.sys [05-10-25 09:02 ] . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-01 14:09:15 Windows 5.0.2195 Service Pack 4 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe C:\WINNT\system32\regsvc.exe C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe C:\WINNT\TEMP\YY219.EXE C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Microsoft ActiveSync\WCESMgr.exe . ************************************************************************** . Completion time: 2008-04-01 13:23:07 - machine was rebooted [mstratman] ComboFix-quarantined-files.txt 2008-04-01 03:51:12 ComboFix2.txt 2008-04-01 02:18:16 . 2008-02-04 23:53:48 --- E O F --- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:13, on 2008-04-01 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\svchost.exe C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe C:\WINNT\system32\regsvc.exe C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe C:\WINNT\TEMP\YY219.EXE C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe C:\WINNT\system32\igfxtray.exe C:\WINNT\system32\hkcmd.exe C:\WINNT\system32\ctfmon.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\PROGRA~1\MI3AA1~1\rapimgr.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Microsoft ActiveSync\WCESMgr.exe C:\WINNT\system32\wuauclt.exe C:\WINNT\explorer.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user') O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://www.boral.com.au/OutdoorDesignGuide/ScriptX.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - http://www.cit.org.au/crystalreportv...iveXViewer.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = rmgpl.local O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = rmgpl.local O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = rmgpl.local O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe -- End of file - 5454 bytes Last edited by tetonbob; 03-31-2008 at 11:23 PM. |
|
|
|
|
#8 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home
|
Re: ucleaner
Please now delete the zip file on your desktop.
Open NOTEPAD.exe and copy/paste the text in the codebox below into it: Code:
@echo off if exist "%temp%\log.txt" del "%temp%\log.txt" for %%g in ( "C:\WINNT\system32\CF_init.exe" "C:\WINNT\vbgtorfd.dll.vir" "C:\WINNT\kdftlboepta.dll.vir" "C:\WINNT\system32\betkdotc.exe.vir" "C:\WINNT\norlatmx.exe.vir" ) do ( del /a/f %%g >nul 2>&1 if exist %%g echo.%%g>>"%temp%\log.txt" ) for %%g in ( %systemdrive%\Deckard "C:\Documents and Settings\All Users\Application Data\yfmrqhsn" ) do ( rd /s/q %%g >nul 2>&1 if exist %%g echo.%%g>>"%temp%\log.txt" ) if exist "%temp%\log.txt" ( start notepad "%temp%\log.txt" ) else echo.Deleted Successfully !! pause del %0 It should look like this: Double click on fix.bat & allow it to run Post back to tell me what it says
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#10 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home
|
Re: ucleaner
Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they exist (make sure you do not miss any) and click Fix Checked
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2 Close HijackThis now. --------------------------------------------------------------------------------------------- For a final check..... Please run this online scan to help look for remnants. First, Go to Start>Control Panel>Add/Remove Programs and remove Kaspersky online scanner if present prior to downloading the most up-to-date one. Next, establish an internet connection & perform an online scan using Internet Explorer at Kaspersky Online Scanner Answer Yes, when prompted to install an ActiveX component.
Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%. --------------------------------------------------------------------------------------------- How is the machine behaving?
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#13 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home
|
Re: ucleaner
There are some suspicious mails found in your archives....though they've been there a while, new definitions have identified them as exploits.
C:\contacts.pst /Personal Folders/Inbox/06 Oct 2001 17:26 from Vanessa Lintner:WWW.APGL.COM.AU.rtf /Personal Folders/Inbox/07 Dec 2001 03:28 from Antony Bolton:Re: PROPOSED FUNCTIONS 2001 C:\outlook backup\mstratman desktop.pst /Personal Folders/Inbox/13 Oct 2002 23:01 from kym willett:Fwd: SICK WORLD RECORDS /Personal Folders/Inbox/13 Oct 2002 06:32 from Kevin:Fw: School Photo Site /Personal Folders/Inbox/02 Oct 2002 00:07 from Tiffany Gordon:Read story before opening /Personal Folders/Sent Items/23 May 2001 08:46 to Ros Doherty:FW: 'Wirreebilla' vineyard proj.rtf /Personal Folders/Sent Items/30 Apr 2001 05:59 to 'CHUCK (E-mail)'; 'VANESSA HOME (E-mail)':F C:\outlook backup\backuplaptopall.pst /Personal Folders/Inbox/13 Oct 2002 23:01 from kym willett:Fwd: SICK WORLD RECORDS /Personal Folders/Inbox/13 Oct 2002 06:32 from Kevin:Fw: School Photo Site /Personal Folders/Inbox/02 Oct 2002 00:07 from Tiffany Gordon:Read story before opening Locate and delete these: C:\Documents and Settings\mstratman.RMGPL\Desktop\[4]-Submit_Tue 2008-04-01@13.58.zip C:\Program Files\Trend Micro\HijackThis\backups Other than that, the other items found by Kaspersky will be addressed by uninstalling ComboFix as instructed below. Go to -> Run -> copy/paste in the following single line command & click OKcombofix /u This will uninstall ComboFix. It will also implement some cleanup procedures and reset System Restore points. Now that your system is clean, to help protect your computer in the future I recommend that you follow these steps and use the following free programs:
Scan here http://secunia.com/software_inspector/ for out of date & vulnerable common applications on your computer Here are some additional utilities that will further enhance your safety.
In light of your recent troubles, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles If you want to fight back the Malware Writers that have made your life a misery, please take a look here and read what you can do against it. Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#14 (permalink) |
|
Registered User
Join Date: Feb 2005
Posts: 18
OS: win 2000
|
Re: ucleaner
where I've got to:
deleted the files the emails arent currently used so will copy of and clean up later combofix uninstalled windows update installed spyblaster installed rebooted the computer this morning to continue, and it is running extremely slow again no popups though rebooted again just in case and still running very slow attached a current HJT log in case I missed something |
|
|
|
|
#15 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home
|
Re: ucleaner
Is this a work machine?
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#17 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home
|
Re: ucleaner
There are nearly three dozen user profiles listed on this machine. Are they all necessary?
We are typically here to support the home user. Is there not an IT dept at the workplace? It's possible that recent updates to the Trend Micro AntiVirus package are now using more resources than before. There is less than 512MB memory on this machine; though that is typically enough for Windows 2000, more is better. There is no more infection showing in the logs. Some machines never recover from infection, and must be formatted and installed clean. See if the information on this page helps, as far as a slow machine goes. http://users.telenet.be/bluepatchy/m...wcomputer.html
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#18 (permalink) |
|
Registered User
Join Date: Feb 2005
Posts: 18
OS: win 2000
|
Re: ucleaner
thanks tetonbob
small operation in an even smaller town have rerun kaspersky and spybot and both clean the user profiles are different people who have come and gone over time using the machine will do a cleanup of the system, check the ram and see how it goes thanks again for your help |
|
|
| Thread Tools | |
|
|