![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jun 2009
Posts: 6
OS: XP
|
Please Help Remove Google Redirect Malware:Skynet
Hi,
First, thanks for your assistance. I greatly appreciate your time and effort in helping me. For several days, I've been having a problem with google search links being redirected to weird sites. The DSS and GMER logs are attached. Here's the DSS output. DDS (Ver_09-05-14.01) - NTFSx86 Run by Eric at 17:53:22.85 on Wed 06/24/2009 Internet Explorer: 6.0.2900.5512 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.249 [GMT -5:00] AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160} ============== Running Processes =============== C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\CA\CA Internet Security Suite\casc.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-7.0.0.510\QOELoader.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Config2500\Utility\Config2500.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\WinZip\WZQKPICK.EXE C:\Documents and Settings\Eric\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://news.google.com/nwshp?hl=en&tab=wn uSearch Bar = hxxp://www.google.com mDefault_Page_URL = hxxp://www.averatec.com uInternet Connection Wizard,ShellNext = hxxp://www.averatec.com/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: CA Toolbar Helper: {fbf2401b-7447-4727-be5d-c19b2075ca84} - c:\program files\ca\ca internet security suite\ca website inspector\toolbar\CallingIDIE.dll TB: CA Toolbar: {10134636-e7af-4ac5-a1dc-c7c44bb97d81} - c:\program files\ca\ca internet security suite\ca website inspector\toolbar\CallingIDIE.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Power2GoExpress] uRun: [PowerBar] "c:\program files\cyberlink\powerstarter\PowerBar.exe" /AtBootTime uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [ATIModeChange] Ati2mdxx.exe mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [masqform.exe] c:\program files\pureedge\viewer 6.0\masqform.exe -UpdateCurrentUser mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [cctray] "c:\program files\ca\ca internet security suite\casc.exe" mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe" mRun: [cafw] c:\program files\ca\ca internet security suite\ca personal firewall\cafw.exe -cl mRun: [capfasem] c:\program files\ca\ca internet security suite\ca personal firewall\capfasem.exe mRun: [capfupgrade] c:\program files\ca\ca internet security suite\ca personal firewall\capfupgrade.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [CAPPActiveProtection] "c:\program files\ca\ca internet security suite\ca anti-spyware\CAPPActiveProtection.exe" mRun: [QOELOADER] "c:\program files\ca\ca internet security suite\ca anti-spam\qsp-7.0.0.510\QOELoader.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\config~1.lnk - c:\program files\config2500\utility\Config2500.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: c:\windows\system32\VetRedir.dll DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38099.484212963 DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://www.adobe.com/products/acrobat/nos/gp.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {F3D4C08D-3616-43F0-9E29-44C749B0664B} - hxxp://12.107.134.185/JpegInst.cab TCP: {1841E1FF-BAC0-4999-B722-6BBB27478B84} = 10.10.1.22,10.10.1.19 Notify: PFW - UmxWnp.Dll SEH: ShellHook Class: {1869181a-9f50-4fcf-8bff-1b8588ecb85c} - c:\program files\ca\ca internet security suite\ca website inspector\linkadvisor\CIDLinkAdvisor.dll ============= SERVICES / DRIVERS =============== R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [2009-1-5 107512] R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [2008-11-18 72696] R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [2008-8-25 52728] R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [2008-12-12 115704] R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2009-4-24 26352] R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2009-4-24 21104] R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\vetefile.sys [2009-4-24 880560] R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\vetfddnt.sys [2009-4-24 21488] R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2009-4-24 161008] R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe [2008-10-12 144696] R2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\ca\ca internet security suite\ccschedulersvc.exe [2009-4-24 128240] R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [2008-12-12 144376] R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [2008-7-30 58872] R2 UmxAgent;HIPS Event Manager;c:\program files\ca\sharedcomponents\hipsengine\UmxAgent.exe [2008-12-12 1153528] R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\ca\sharedcomponents\hipsengine\UmxCfg.exe [2008-12-10 797176] R2 UmxPol;HIPS Policy Manager;c:\program files\ca\sharedcomponents\hipsengine\UmxPol.exe [2008-12-19 297464] R2 VETMSGNT;VET Message Service;c:\program files\ca\ca internet security suite\ca anti-virus\vetmsg.exe [2008-10-12 292080] R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [2004-4-22 187668] R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [2008-12-12 205304] R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [2004-4-22 5817] R3 PPCtlPriv;PPCtlPriv;c:\program files\ca\ca internet security suite\ca anti-spyware\PPCtlPriv.exe [2008-10-12 222448] R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2009-4-24 108368] S2 QQORQRTV;QQORQRTV;c:\windows\system32\drivers\QQORQRTV.sys [2008-11-7 178176] S3 CB102;D-Link DFE-680TXD DirectPort CardBus Driver;c:\windows\system32\drivers\cb102.sys [2004-4-23 37916] S3 fa410;NETGEAR FA410TX Fast Ethernet PC Card Driver;c:\windows\system32\drivers\fa410nd5.sys [2004-5-3 24618] =============== Created Last 30 ================ 2009-06-23 10:12 <DIR> --d----- c:\docume~1\eric\applic~1\Malwarebytes 2009-06-23 10:12 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-23 10:12 19,096 a------- c:\windows\system32\drivers\mbam.sys 2009-06-23 10:12 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware 2009-06-23 10:12 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-06-23 09:44 <DIR> --d----- c:\program files\Trend Micro ==================== Find3M ==================== 2009-05-07 10:32 345,600 a------- c:\windows\system32\localspl.dll 2009-04-28 23:46 666,624 a------- c:\windows\system32\wininet.dll 2009-04-28 23:46 81,920 -------- c:\windows\system32\ieencode.dll 2009-04-17 07:26 1,847,168 a------- c:\windows\system32\win32k.sys 2009-04-15 09:51 585,216 a------- c:\windows\system32\rpcrt4.dll ============= FINISH: 17:57:22.00 =============== Again, thank you very much. Cheers, Thurston |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,017
OS: XP sp3
|
Re: Please Help Remove Google Redirect Malware:Skynet
hi,
Please do the following: NOTE: It is very important that you disable your CA Antivirus and TeaTimer: For Teatimer: 1) Right click the TEA TIMER system tray icon and shut down. 2) Run Spybot-S&D 3) Go to the Mode menu, and make sure "Advanced Mode" is selected 4) On the left hand side, choose Tools -> Resident 5) Uncheck "Resident TeaTimer" and OK any prompts NOW Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop. Link 1 Link 2 Link 3 ![]() ![]() -------------------------------------------------------------------- Double click on Combo-Fix.exe & follow the prompts.
|
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Jun 2009
Posts: 6
OS: XP
|
Re: Please Help Remove Google Redirect Malware:Skynet
Hi Catbyte,
Infinite thanks for helping me. I greatly appreciate your time. Below I've cut and pasted the log results, but I think I pretty much botched the run. Sorry. Although the menu descriptions were a little off, I was able to disable teatimer. I don't think I did an adequate job with the CA suite, however. I simply exited the running programs, not thinking about the possibility of a reboot (duh!). Combofix was doing its thing just fine when it showed I had root kit issues, indicated it had to reboot and asked me to write down the following files for reference: C:\windows\system32\drivers\SKYNETwilannbm.sys C:\windows\system32\SKYNETnreeicbv.dll C:\windows\system32\SKYNETdeiufjwc.dat C:\windows\system32\SKYNETspmevwbw.dll C:\windows\system32\SKYNETqdhoetb.dat Upon reboot, things went badly. Received an error that said the contents of folder c:\windows\erdnt\HIV-backup could not be completely deleted. It continued saying it needed to run a deeper scan. A few seconds later the computer crashed. The blue screen was up for too short a time to read the lengthy message. Upon reboot there was a windows recovered from critical error message. Combofix continued, but began having additional errors, "NRCMDC is not recognized as an internal or external command, operablr program or batch file" Access was denied to a couple of files and there was a message about 0 files being copied. Combofix then froze. I rebooted again. It resumed and created the following log file. I've since figured out how to fully disable CA and assume I'll need to rerun Combofix, perhaps after reboot from the restore point. However, since I obviously don't have a clue as to what I'm doing I will await further instruction. Thanks again and sorry I screwed that one up. I appreciate your help and your patience. All the best, Thurston ComboFix 09-06-24.05 - Eric 06/25/2009 8:34.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.213 [GMT -5:00] Running from: c:\documents and settings\Eric\Desktop\Combo-Fix.exe AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160} . /wow section not completed ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\drivers\SKYNETwilannbm.sys c:\windows\system32\icqmlib.exe c:\windows\system32\iepref32.dll c:\windows\system32\ierplc.dll c:\windows\system32\ips.dll c:\windows\system32\koos.exe c:\windows\system32\kprof c:\windows\system32\lanmandrv.sys c:\windows\system32\lanmanwrk.exe c:\windows\system32\laprxy.dllexe c:\windows\system32\ocxapi.dll c:\windows\system32\ocxloader.exe c:\windows\system32\poof c:\windows\system32\qmopt.dll c:\windows\system32\SKYNETdeiufjwc.dat c:\windows\system32\SKYNETnreeicbv.dll c:\windows\system32\SKYNETqdhoextb.dat c:\windows\system32\SKYNETspmevwbw.dll . ((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-06-25 ))))))))))))))))))))))))))))))) . 2009-06-24 18:57 . 2009-06-24 18:57 -------- d-----w- c:\documents and settings\Eric\Local Settings\Application Data\WinZip 2009-06-24 18:56 . 2009-06-24 18:57 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip 2009-06-23 15:12 . 2009-06-23 15:12 -------- d-----w- c:\documents and settings\Eric\Application Data\Malwarebytes 2009-06-23 15:12 . 2009-06-17 16:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-23 15:12 . 2009-06-23 21:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-23 15:12 . 2009-06-23 15:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-23 15:12 . 2009-06-17 16:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-23 14:44 . 2009-06-23 14:44 -------- d-----w- c:\program files\Trend Micro . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-25 03:21 . 2008-10-12 15:22 -------- d-----w- c:\documents and settings\Eric\Application Data\CallingID 2009-06-23 13:21 . 2008-10-12 18:21 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-06-23 13:21 . 2008-10-12 18:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-05-07 15:32 . 2004-04-22 16:38 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-29 04:46 . 2006-06-23 17:33 666624 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:46 . 2004-08-04 07:56 81920 ------w- c:\windows\system32\ieencode.dll 2009-04-24 18:56 . 2009-04-24 18:00 880560 ----a-w- c:\windows\system32\drivers\vetefile.sys 2009-04-24 18:56 . 2009-04-24 18:00 108368 ----a-w- c:\windows\system32\drivers\veteboot.sys 2009-04-24 18:56 . 2008-10-12 16:51 1385760 ----a-w- c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll 2009-04-24 17:55 . 2009-04-24 17:28 112716144 ----a-w- c:\documents and settings\All Users\Application Data\CA\Consumer\CCube\tmp\DAE28645C536241BEA137E87E6C9DF86.exe 2009-04-17 12:26 . 2004-04-22 16:38 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2004-04-23 16:19 585216 ----a-w- c:\windows\system32\rpcrt4.dll . c:\windows\system32\svchost.exe ... Infected -- Win32.Qhost !! "c:\windows\system32\ws2_32.dll" is infected ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] "PowerBar"="c:\program files\CyberLink\PowerStarter\PowerBar.exe" [2004-04-08 110592] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-10-29 335872] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-04-24 110592] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-04-24 610304] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768] "masqform.exe"="c:\program files\PureEdge\Viewer 6.0\masqform.exe" [2003-12-03 1052672] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-10-17 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576] "ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2001-09-04 28672] "SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-11-14 62464] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Config2500.lnk - c:\program files\Config2500\Utility\Config2500.exe [2005-2-24 565248] WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-6-10 525640] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= "c:\program files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll" [2008-12-14 1376256] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "cctray"="c:\program files\CA\CA Internet Security Suite\casc.exe" "CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" "CAPPActiveProtection"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe" "capfupgrade"=c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe "capfasem"=c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe "cafw"=c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl "QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-7.0.0.510\QOELoader.exe" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [1/5/2009 11:36 AM 107512] R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [11/18/2008 12:14 PM 72696] R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [8/25/2008 2:18 PM 52728] R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [12/12/2008 12:37 PM 115704] R2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\CA\CA Internet Security Suite\ccschedulersvc.exe [4/24/2009 1:00 PM 128240] R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [12/12/2008 12:37 PM 144376] R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [7/30/2008 12:38 PM 58872] R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [12/12/2008 12:37 PM 1153528] R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [12/10/2008 12:58 PM 797176] R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [12/19/2008 1:59 PM 297464] R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [4/22/2004 12:21 PM 187668] R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [12/12/2008 12:37 PM 205304] R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [4/22/2004 12:21 PM 5817] S2 QQORQRTV;QQORQRTV;c:\windows\system32\drivers\QQORQRTV.sys [11/7/2008 10:39 PM 178176] S3 CB102;D-Link DFE-680TXD DirectPort CardBus Driver;c:\windows\system32\drivers\cb102.sys [4/23/2004 3:01 PM 37916] S3 fa410;NETGEAR FA410TX Fast Ethernet PC Card Driver;c:\windows\system32\drivers\fa410nd5.sys [5/3/2004 11:25 AM 24618] S3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [10/12/2008 10:22 AM 222448] . - - - - ORPHANS REMOVED - - - - HKCU-Run-Power2GoExpress - (no file) . ------- Supplementary Scan ------- . uStart Page = hxxp://news.google.com/nwshp?hl=en&tab=wn uInternet Connection Wizard,ShellNext = hxxp://www.averatec.com/ uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 LSP: c:\windows\system32\VetRedir.dll TCP: {1841E1FF-BAC0-4999-B722-6BBB27478B84} = 10.10.1.22,10.10.1.19 DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {F3D4C08D-3616-43F0-9E29-44C749B0664B} - hxxp://12.107.134.185/JpegInst.cab . ************************************************************************** scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(664) c:\windows\system32\UmxWnp.Dll c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll - - - - - - - > 'explorer.exe'(2508) c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe c:\windows\system32\MsPMSPSv.exe c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe c:\program files\CA\CA Internet Security Suite\ccprovsp.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2009-06-25 8:40 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-25 13:40 Pre-Run: 31,416,881,152 bytes free Post-Run: 31,383,609,344 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn 183 --- E O F --- 2009-06-10 16:25 |
|
|
|
|
#4 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,017
OS: XP sp3
|
Re: Please Help Remove Google Redirect Malware:Skynet
Yes, having CA running will have caused that blue screen.
delete the copy of ComboFix you have on your desktop. Lets download it again and give it a chance to run uninterrupted with the security programs totally disabled Download a fresh copy of ComboFix from the links previously given - no need to re-name it this time. Post the log provided. |
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: Jun 2009
Posts: 6
OS: XP
|
Re: Please Help Remove Google Redirect Malware:Skynet
Hi,
Thanks for being patient with me. Sorry for the need. Here's the latest combofix log. I'm very thankful for the assistance. Cheers, Toz Combofix log "capfasem"=c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe "cafw"=c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl "QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-7.0.0.510\QOELoader.exe" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [1/5/2009 11:36 AM 107512] R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [11/18/2008 12:14 PM 72696] R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [8/25/2008 2:18 PM 52728] R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [12/12/2008 12:37 PM 115704] R2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\CA\CA Internet Security Suite\ccschedulersvc.exe [4/24/2009 1:00 PM 128240] R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [12/12/2008 12:37 PM 144376] R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [7/30/2008 12:38 PM 58872] R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [12/12/2008 12:37 PM 1153528] R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [12/10/2008 12:58 PM 797176] R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [12/19/2008 1:59 PM 297464] R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [4/22/2004 12:21 PM 187668] R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [12/12/2008 12:37 PM 205304] R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [4/22/2004 12:21 PM 5817] S2 QQORQRTV;QQORQRTV;c:\windows\system32\drivers\QQORQRTV.sys [11/7/2008 10:39 PM 178176] S3 CB102;D-Link DFE-680TXD DirectPort CardBus Driver;c:\windows\system32\drivers\cb102.sys [4/23/2004 3:01 PM 37916] S3 fa410;NETGEAR FA410TX Fast Ethernet PC Card Driver;c:\windows\system32\drivers\fa410nd5.sys [5/3/2004 11:25 AM 24618] S3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [10/12/2008 10:22 AM 222448] . . ------- Supplementary Scan ------- . uStart Page = hxxp://news.google.com/nwshp?hl=en&tab=wn uInternet Connection Wizard,ShellNext = hxxp://www.averatec.com/ uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 LSP: c:\windows\system32\VetRedir.dll TCP: {1841E1FF-BAC0-4999-B722-6BBB27478B84} = 10.10.1.22,10.10.1.19 DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {F3D4C08D-3616-43F0-9E29-44C749B0664B} - hxxp://12.107.134.185/JpegInst.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-25 21:36 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(664) c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll - - - - - - - > 'explorer.exe'(3732) c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe c:\windows\system32\MsPMSPSv.exe c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe c:\program files\CA\CA Internet Security Suite\ccprovsp.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2009-06-26 21:41 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-26 02:41 Pre-Run: 31,363,903,488 bytes free Post-Run: 31,362,437,120 bytes free 188 --- E O F --- 2009-06-10 16:25 Thanks!!!!!
|
|
|
|
|
#6 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,017
OS: XP sp3
|
Re: Please Help Remove Google Redirect Malware:Skynet
There seems to be a lot of information missing from that log.
I will need to have all of the log to examine. The first line should start with a date: Like this: ComboFix 09-06-24.05 - Eric 06/25/2009 8:34.2 - NTFSx86 Please look for the most recent log and post it again. Thank-you. If you are ahving any difficulties, please let me know. Don't worry, you are doing fine, I'll help you through.... |
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: Jun 2009
Posts: 6
OS: XP
|
Re: Please Help Remove Google Redirect Malware:Skynet
Ok, I think I've got it all now.. Sorry about that. Thanks again.
Cheers. ComboFix 09-06-25.01 - Eric 06/25/2009 21:15.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.210 [GMT -5:00] Running from: c:\documents and settings\Eric\Desktop\ComboFix.exe AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} FW: CA Personal Firewall *disabled* {14CB4B80-8E52-45EA-905E-67C1267B4160} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\nfr.assembly . ((((((((((((((((((((((((( Files Created from 2009-05-26 to 2009-06-26 ))))))))))))))))))))))))))))))) . 2009-06-26 02:17 . 2009-06-26 02:17 51328 ----a-w- c:\windows\system32\drivers\_rasl2tp.sys_.vir 2009-06-26 02:17 . 2009-06-26 02:17 52480 ----a-w- c:\windows\system32\drivers\_i8042prt.sys_.vir 2009-06-26 02:17 . 2009-06-26 02:17 56623 ----a-w- c:\windows\system32\drivers\_ati1btxx.sys_.vir 2009-06-26 02:17 . 2009-06-26 02:17 53376 ----a-w- c:\windows\system32\drivers\_1394bus.sys_.vir 2009-06-25 13:38 . 2009-06-25 13:38 -------- dc----w- c:\windows\system32\dllcache\cache 2009-06-25 12:48 . 2009-06-25 12:48 389120 ----a-w- c:\windows\system32\CF25002.exe 2009-06-24 18:57 . 2009-06-24 18:57 -------- d-----w- c:\documents and settings\Eric\Local Settings\Application Data\WinZip 2009-06-24 18:56 . 2009-06-24 18:57 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip 2009-06-23 15:12 . 2009-06-23 15:12 -------- d-----w- c:\documents and settings\Eric\Application Data\Malwarebytes 2009-06-23 15:12 . 2009-06-17 16:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-23 15:12 . 2009-06-23 21:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-23 15:12 . 2009-06-23 15:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-23 15:12 . 2009-06-17 16:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-23 14:44 . 2009-06-23 14:44 -------- d-----w- c:\program files\Trend Micro . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-26 02:12 . 2008-10-12 15:22 -------- d-----w- c:\documents and settings\Eric\Application Data\CallingID 2009-06-23 13:21 . 2008-10-12 18:21 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-06-23 13:21 . 2008-10-12 18:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-05-07 15:32 . 2004-04-22 16:38 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-29 04:46 . 2006-06-23 17:33 666624 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:46 . 2004-08-04 07:56 81920 ------w- c:\windows\system32\ieencode.dll 2009-04-24 18:56 . 2009-04-24 18:00 880560 ----a-w- c:\windows\system32\drivers\vetefile.sys 2009-04-24 18:56 . 2009-04-24 18:00 108368 ----a-w- c:\windows\system32\drivers\veteboot.sys 2009-04-24 18:56 . 2008-10-12 16:51 1385760 ----a-w- c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll 2009-04-24 17:55 . 2009-04-24 17:28 112716144 ----a-w- c:\documents and settings\All Users\Application Data\CA\Consumer\CCube\tmp\DAE28645C536241BEA137E87E6C9DF86.exe 2009-04-17 12:26 . 2004-04-22 16:38 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2004-04-23 16:19 585216 ----a-w- c:\windows\system32\rpcrt4.dll . ((((((((((((((((((((((((((((( SnapShot@2009-06-25_13.37.05 ))))))))))))))))))))))))))))))))))))))))) . + 2009-06-25 13:38 . 2008-10-16 20:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe + 2009-06-25 13:38 . 2008-04-14 00:12 82432 c:\windows\system32\dllcache\cache\ws2_32.dll + 2009-06-25 13:38 . 2008-04-14 00:12 26112 c:\windows\system32\dllcache\cache\userinit.exe + 2009-06-25 13:38 . 2008-04-14 00:12 14336 c:\windows\system32\dllcache\cache\svchost.exe + 2009-06-25 13:38 . 2008-04-14 00:12 57856 c:\windows\system32\dllcache\cache\spoolsv.exe + 2009-06-25 13:38 . 2008-04-14 00:12 17408 c:\windows\system32\dllcache\cache\powrprof.dll + 2009-06-25 13:38 . 2008-04-14 00:12 13312 c:\windows\system32\dllcache\cache\lsass.exe + 2009-06-25 13:38 . 2008-04-13 18:39 24576 c:\windows\system32\dllcache\cache\kbdclass.sys + 2009-06-25 13:38 . 2008-04-13 18:53 36608 c:\windows\system32\dllcache\cache\ip6fw.sys + 2009-06-25 13:38 . 2008-04-14 00:12 15360 c:\windows\system32\dllcache\cache\ctfmon.exe + 2009-06-25 13:38 . 2008-04-14 00:12 507904 c:\windows\system32\dllcache\cache\winlogon.exe + 2009-06-25 13:38 . 2009-04-29 04:46 666624 c:\windows\system32\dllcache\cache\wininet.dll + 2009-06-25 13:38 . 2008-11-15 01:50 578560 c:\windows\system32\dllcache\cache\user32.DLL + 2009-06-25 13:38 . 2008-04-14 00:12 295424 c:\windows\system32\dllcache\cache\termsrv.dll + 2009-06-25 13:38 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\cache\tcpip.sys + 2009-06-25 13:38 . 2009-02-06 11:11 110592 c:\windows\system32\dllcache\cache\services.exe + 2009-06-25 13:38 . 2008-04-13 19:20 182656 c:\windows\system32\dllcache\cache\ndis.sys + 2009-06-25 13:38 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\cache\kernel32.dll + 2009-06-25 13:38 . 2008-04-14 00:11 110080 c:\windows\system32\dllcache\cache\imm32.dll + 2009-06-25 13:38 . 2008-04-14 00:12 1614848 c:\windows\system32\dllcache\cache\sfcfiles.dll + 2009-06-25 13:38 . 2009-02-06 11:06 2145280 c:\windows\system32\dllcache\cache\ntoskrnl.exe + 2009-06-25 13:38 . 2009-02-06 10:32 2023936 c:\windows\system32\dllcache\cache\ntkrnlpa.exe + 2009-06-25 13:38 . 2008-04-14 00:12 1033728 c:\windows\system32\dllcache\cache\explorer.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] "PowerBar"="c:\program files\CyberLink\PowerStarter\PowerBar.exe" [2004-04-08 110592] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-10-29 335872] "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-04-24 110592] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-04-24 610304] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768] "masqform.exe"="c:\program files\PureEdge\Viewer 6.0\masqform.exe" [2003-12-03 1052672] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-10-17 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576] "ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2001-09-04 28672] "SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-11-14 62464] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Config2500.lnk - c:\program files\Config2500\Utility\Config2500.exe [2005-2-24 565248] WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-6-10 525640] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= "c:\program files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll" [2008-12-14 1376256] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "cctray"="c:\program files\CA\CA Internet Security Suite\casc.exe" "CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" "CAPPActiveProtection"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe" "capfupgrade"=c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe "capfasem"=c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe "cafw"=c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl "QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-7.0.0.510\QOELoader.exe" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [1/5/2009 11:36 AM 107512] R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [11/18/2008 12:14 PM 72696] R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [8/25/2008 2:18 PM 52728] R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [12/12/2008 12:37 PM 115704] R2 ccSchedulerSVC;CA Common Scheduler Service;c:\program files\CA\CA Internet Security Suite\ccschedulersvc.exe [4/24/2009 1:00 PM 128240] R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [12/12/2008 12:37 PM 144376] R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [7/30/2008 12:38 PM 58872] R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [12/12/2008 12:37 PM 1153528] R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [12/10/2008 12:58 PM 797176] R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [12/19/2008 1:59 PM 297464] R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [4/22/2004 12:21 PM 187668] R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [12/12/2008 12:37 PM 205304] R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [4/22/2004 12:21 PM 5817] S2 QQORQRTV;QQORQRTV;c:\windows\system32\drivers\QQORQRTV.sys [11/7/2008 10:39 PM 178176] S3 CB102;D-Link DFE-680TXD DirectPort CardBus Driver;c:\windows\system32\drivers\cb102.sys [4/23/2004 3:01 PM 37916] S3 fa410;NETGEAR FA410TX Fast Ethernet PC Card Driver;c:\windows\system32\drivers\fa410nd5.sys [5/3/2004 11:25 AM 24618] S3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [10/12/2008 10:22 AM 222448] . . ------- Supplementary Scan ------- . uStart Page = hxxp://news.google.com/nwshp?hl=en&tab=wn uInternet Connection Wizard,ShellNext = hxxp://www.averatec.com/ uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 LSP: c:\windows\system32\VetRedir.dll TCP: {1841E1FF-BAC0-4999-B722-6BBB27478B84} = 10.10.1.22,10.10.1.19 DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {F3D4C08D-3616-43F0-9E29-44C749B0664B} - hxxp://12.107.134.185/JpegInst.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-25 21:36 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(664) c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll - - - - - - - > 'explorer.exe'(3732) c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe c:\windows\system32\MsPMSPSv.exe c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe c:\program files\CA\CA Internet Security Suite\ccprovsp.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2009-06-26 21:41 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-26 02:41 Pre-Run: 31,363,903,488 bytes free Post-Run: 31,362,437,120 bytes free 188 --- E O F --- 2009-06-10 16:25 |
|
|
|
|
#8 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,017
OS: XP sp3
|
Re: Please Help Remove Google Redirect Malware:Skynet
Hi,
Please do the following: Download TFC to your desktop
NEXT Open your Malwarebytes Antimalware program
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so. NEXT It's important to run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course: Using Internet Explorer or Firefox, visit Kaspersky Online Scanner: 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
|
|
|
|
|
#9 (permalink) |
|
Registered User
Join Date: Jun 2009
Posts: 6
OS: XP
|
Re: Please Help Remove Google Redirect Malware:Skynet
Hi Catbyte,
Well I ran the scans per your after the TFC scan, the MB and Kaspersky scans came up empty. Too good to be true? Please let me know. Here is the requested log. I did not cut and paste kaspersky because there was nothing in it. Once again thank you so much. Cheers, Thurston Malwarebytes' Anti-Malware 1.38 Database version: 2338 Windows 5.1.2600 Service Pack 3 6/26/2009 12:55:36 PM mbam-log-2009-06-26 (12-55-36).txt Scan type: Quick Scan Objects scanned: 97716 Time elapsed: 5 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
|
|
#10 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,017
OS: XP sp3
|
Re: Please Help Remove Google Redirect Malware:Skynet
Hi,
You are clean, just some housekeeping to do now: Please do the following: Visit ADOBEand download the latest version of Acrobat Reader (version 9.1) Having the latest updates ensures there are no security vulnerabilities in your system. NEXT You can delete the DDS and GMER folders from your desktop. NEXT Follow these steps to uninstall Combofix
![]() Should you wish to contribute to the ongoing development of ComboFix, donations are being accepted via PayPal. NEXT Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. Thank you for your patience, and performing all of the procedures requested. Please respond one last time so we can consider the thread resolved and close it, thank-you. |
|
|
|
|
#12 (permalink) | ||
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,017
OS: XP sp3
|
Re: Please Help Remove Google Redirect Malware:Skynet
Quote:
The rest of my advise - though sage, is optional. Quote:
stay safe CB |
||
|
|
|
|
#13 (permalink) |
|
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
Join Date: Jun 2006
Location: USA
Posts: 7,303
OS: XP SP3
|
Re: Please Help Remove Google Redirect Malware:Skynet
Since this issue appears resolved, this topic will now be closed. If you need continued support, please begin a new thread, and provide a link to this topic. This applies only to the original topic starter. Everyone else please begin a New Topic, after following the steps outlined here:
http://www.techsupportforum.com/secu...oval-help.html Surf Safely, and Think Prevention!
__________________
My services are free. However, you can donate to TSF to help keep it running. ![]() ![]() Member of ASAP since 2005 Member of UNITE since 2006 |
|
|
| Thread Tools | |
|
|