![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 5
OS: Windows XP
|
msaro.exe trojan
Whenever I log into my account, I obtain a message stating something to the effect that msaro.exe could not be opened. My antivirus software has detected quite a few trojans within the past few days, so I suspect this is related to that.
Thanks in advance. DDS (Ver_09-10-24.03) - NTFSx86 Run by James at 22:31:10.96 on Sat 10/24/2009 Internet Explorer: 8.0.6001.18702 ============== Pseudo HJT Report =============== uInternet Settings,ProxyOverride = *.local mWinlogon: Shell=Explorer.exe msaro.exe mWinlogon: Userinit=c:\windows\system32\userinit.exe,,netste.exe BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [AVG9_TRAY] c:\progra~1\avg\avgtray.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/betapit/PCPitStop.CAB Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avgpp.dll Notify: avgrsstarter - avgrsstx.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\james\applic~1\mozilla\firefox\profiles\4qqi2hyr.default\ FF - component: c:\program files\avg\firefox\components\avgssff.dll ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2009-10-25 03:20:49 0 d-----w- c:\program files\Trend Micro 2009-10-25 02:59:14 0 d-----w- c:\windows\LastGood.Tmp 2009-10-25 02:56:15 0 d-----w- c:\windows\system32\scripting 2009-10-25 02:56:14 0 d-----w- c:\windows\system32\en 2009-10-25 02:56:14 0 d-----w- c:\windows\system32\bits 2009-10-25 02:56:14 0 d-----w- c:\windows\l2schemas 2009-10-25 02:51:50 0 d-----w- c:\windows\network diagnostic 2009-10-25 02:50:39 0 d-----w- c:\windows\system32\ReinstallBackups 2009-10-25 02:48:56 0 d-----w- c:\windows\EHome 2009-10-25 02:25:52 0 d-----w- c:\program files\Spybot - Search & Destroy 2009-10-25 02:25:52 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-10-25 02:11:50 0 d-----w- c:\windows\pss 2009-10-25 02:09:29 0 d-sh--w- c:\documents and settings\james\IETldCache 2009-10-25 00:14:25 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll 2009-10-25 00:14:25 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll 2009-10-25 00:14:25 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-10-25 00:14:25 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll 2009-10-25 00:14:25 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-10-25 00:14:25 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll 2009-10-25 00:14:21 0 d-----w- c:\windows\ie8updates 2009-10-25 00:14:18 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll 2009-10-25 00:13:02 0 dc-h--w- c:\windows\ie8 2009-10-25 00:07:12 0 d-----w- c:\windows\ServicePackFiles 2009-10-25 00:03:58 1261 ------w- c:\windows\system32\pid.inf 2009-10-24 23:53:00 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-10-24 23:53:00 107368 ----a-w- c:\windows\system32\GEARAspi.dll 2009-10-24 23:52:33 0 d-----w- c:\program files\iPod 2009-10-24 23:52:30 0 d-----w- c:\program files\iTunes 2009-10-24 23:52:30 0 d-----w- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-10-24 23:52:20 0 d-----w- c:\program files\Bonjour 2009-10-24 23:51:38 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys 2009-10-24 23:51:38 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll 2009-10-24 23:28:42 0 d--h--w- C:\$AVG 2009-10-24 23:28:34 12464 ----a-w- c:\windows\system32\avgrsstx.dll 2009-10-24 23:28:33 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2009-10-24 23:28:28 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-10-24 23:28:27 0 d-----w- c:\windows\system32\drivers\Avg 2009-10-24 23:28:24 0 d-----w- c:\program files\AVG 2009-10-24 23:28:23 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9 2009-10-24 22:57:36 272128 -c----w- c:\windows\system32\dllcache\bthport.sys 2009-10-24 22:57:36 272128 ------w- c:\windows\system32\drivers\bthport.sys 2009-10-24 22:56:46 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys 2009-10-24 22:54:32 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys 2009-10-24 22:54:28 333952 -c----w- c:\windows\system32\dllcache\srv.sys 2009-10-24 22:54:23 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll 2009-10-24 22:54:18 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll 2009-10-24 22:53:51 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll 2009-10-24 22:39:20 0 d-----w- c:\windows\system32\PreInstall 2009-10-24 22:39:19 26144 ----a-w- c:\windows\system32\spupdsvc.exe 2009-10-24 22:39:18 0 d--h--w- c:\windows\$hf_mig$ 2009-10-24 22:36:06 0 d-----w- c:\windows\system32\SoftwareDistribution 2009-10-21 19:17:34 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000004-00000000-00000002-00001102-00000004-20061102}.dat 2009-10-21 19:17:34 384 ----a-w- c:\windows\system32\DVCState-{00000004-00000000-00000002-00001102-00000004-20061102}.dat 2009-10-21 19:17:34 29544 ----a-w- c:\windows\system32\BMXStateBkp-{00000004-00000000-00000002-00001102-00000004-20061102}.rfx 2009-10-21 19:17:34 29544 ----a-w- c:\windows\system32\BMXState-{00000004-00000000-00000002-00001102-00000004-20061102}.rfx 2009-10-21 19:17:34 26424 ----a-w- c:\windows\system32\BMXCtrlState-{00000004-00000000-00000002-00001102-00000004-20061102}.rfx 2009-10-21 19:17:34 26424 ----a-w- c:\windows\system32\BMXBkpCtrlState-{00000004-00000000-00000002-00001102-00000004-20061102}.rfx 2009-10-21 19:17:34 1112 ----a-w- c:\windows\system32\settingsbkup.sfm 2009-10-21 19:17:34 1112 ----a-w- c:\windows\system32\settings.sfm 2009-10-21 19:17:08 10624 ----a-w- c:\windows\system32\drivers\gameenum.sys 2009-10-21 19:10:50 16128 -c--a-w- c:\windows\system32\dllcache\modemcsa.sys 2009-10-21 19:10:50 16128 ----a-w- c:\windows\system32\drivers\MODEMCSA.sys 2009-10-21 19:09:21 6272 ----a-w- c:\windows\system32\drivers\splitter.sys 2009-10-21 19:09:20 83072 ----a-w- c:\windows\system32\drivers\wdmaud.sys 2009-10-21 19:09:18 52864 ----a-w- c:\windows\system32\drivers\dmusic.sys 2009-10-21 19:09:15 56576 ----a-w- c:\windows\system32\drivers\swmidi.sys 2009-10-21 19:09:13 142592 ----a-w- c:\windows\system32\drivers\aec.sys 2009-10-21 19:09:12 172416 ----a-w- c:\windows\system32\drivers\kmixer.sys 2009-10-21 19:09:11 2944 ----a-w- c:\windows\system32\drivers\drmkaud.sys 2009-10-21 19:09:10 60800 ----a-w- c:\windows\system32\drivers\sysaudio.sys 2009-10-21 19:09:09 7552 ----a-w- c:\windows\system32\drivers\mskssrv.sys 2009-10-21 19:09:08 4992 ----a-w- c:\windows\system32\drivers\mspqm.sys 2009-10-21 19:09:06 5376 ----a-w- c:\windows\system32\drivers\mspclock.sys 2009-10-21 19:08:59 60160 ----a-w- c:\windows\system32\drivers\drmk.sys 2009-10-21 19:08:59 4096 ----a-w- c:\windows\system32\ksuser.dll 2009-10-21 19:08:59 146048 ----a-w- c:\windows\system32\drivers\portcls.sys 2009-10-21 19:08:59 129536 ----a-w- c:\windows\system32\ksproxy.ax 2009-10-21 19 53 127254 ----a-w- c:\windows\system32\nvapps.xml2009-10-21 19 50 356352 ----a-w- c:\windows\system32\nvudisp.exe2009-10-21 19 50 17463 ----a-w- c:\windows\system32\nvdisp.nvu2009-10-21 19 50 0 d-----w- c:\windows\nview2009-10-21 19 09 356352 ----a-w- c:\windows\system32\NVUNINST.EXE2009-10-21 18:56:45 0 d-----w- c:\program files\Broadcom 2009-10-21 18:56:22 87040 -c--a-w- c:\windows\system32\dllcache\msaro.exe 2009-10-21 18:50:11 0 d-s---w- c:\windows\system32\Microsoft 2009-10-21 17:52:15 0 d-sh--w- c:\documents and settings\all users\DRM 2009-10-21 17:51:59 0 d--h--w- c:\program files\WindowsUpdate 2009-10-21 17:51:16 0 d-----w- c:\program files\common files\MSSoap 2009-10-21 17:50:08 0 d-----w- c:\program files\Online Services 2009-10-21 17:50:04 0 d-----w- c:\program files\Messenger 2009-10-21 17:50:01 0 d-----w- c:\program files\MSN Gaming Zone 2009-10-21 17:49:32 0 d-----w- c:\program files\Windows NT 2009-10-21 12:34:09 0 d-----w- c:\program files\common files\ODBC 2009-10-21 12:34:07 0 d-----w- c:\program files\common files\SpeechEngines 2009-10-21 12:33:44 0 d-----r- c:\documents and settings\all users\Documents ==================== Find3M ==================== 2009-10-21 17:50:45 21640 ----a-w- c:\windows\system32\emptyregdb.dat 2009-09-25 05:48:59 81920 ------w- c:\windows\system32\ieencode.dll 2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll 2009-08-29 08:08:21 916480 ----a-w- c:\windows\system32\wininet.dll 2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll 2009-08-05 09:01:48 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-08-04 15:13:08 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-08-04 14:20:09 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-07-29 04:37:01 81920 ----a-w- c:\windows\system32\fontsub.dll 2009-07-29 04:37:01 119808 ----a-w- c:\windows\system32\t2embed.dll ============= FINISH: 22:31:47.43 =============== |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,182
OS: XP sp3
|
Re: msaro.exe trojan
Hi,
Please do the following: Download ComboFix from either of these locations: Link 1 Link 2 VERY IMPORTANT !!! Save ComboFix.exe to your Desktop * IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
Notes: 1. Do not mouse-click Combofix's window while it is running. That may cause it to stall. 2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions. Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now |
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 5
OS: Windows XP
|
Re: msaro.exe trojan
The specific problem that I had no longer persists (I was not confronted with a message about msaro.exe when I booted up). However, there are still a number of suspicious processes running in the background that did not exist at the time that I made my previous post.
|
|
|
|
|
#4 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,182
OS: XP sp3
|
Re: msaro.exe trojan
Hi,
Please do the following:
Here's how to do that: Click Start > Run type Notepad click OK. This will open an empty notepad file: Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy') Code:
File:: c:\documents and settings\All Users\Application Data\Zwunzi\zwunzi119.exe c:\program files\Zwunzi\zwunzi.dll Folder:: c:\program files\Zwunzi c:\documents and settings\All Users\Application Data\Zwunzi Driver:: Zwunzi Service Save this file to your desktop, Save this as "CFScript" Here's how to do that: 1.Click File; 2.Click Save As... Change the directory to your desktop; 3.Change the Save as type to "All Files"; 4.Type in the file name: CFScript 5.Click Save ... ![]()
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall. NEXT Please download Malwarebytes' Anti-Malware
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. NEXT Run an on-line scan with Kaspersky Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
|
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 5
OS: Windows XP
|
Re: msaro.exe trojan
I was unable to run the Kapersky scanner, every time I attempted to do so it failed to apply an update and said that it could not begin the scan. Other than that, my computer seems to be running fine.
ComboFix 09-10-26.01 - James 10/28/2009 14:53.2.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2658 [GMT -5:00] Running from: c:\documents and settings\James\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\James\Desktop\CFScript.txt FILE :: "c:\documents and settings\All Users\Application Data\Zwunzi\zwunzi119.exe" "c:\program files\Zwunzi\zwunzi.dll" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\Zwunzi c:\documents and settings\All Users\Application Data\Zwunzi\zwunzi119.exe c:\program files\Zwunzi c:\program files\Zwunzi\uninstall.exe c:\program files\Zwunzi\zwunzi.dll c:\program files\Zwunzi\zwunzi.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_ZWUNZI_SERVICE -------\Service_Zwunzi Service ((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-28 ))))))))))))))))))))))))))))))) . 2009-10-26 01:47 . 2009-10-26 01:47 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2009-10-26 01:45 . 2009-10-26 01:45 -------- d-----w- c:\documents and settings\James\Application Data\Free Mp3 Wma Ogg Converter 2009-10-26 00:41 . 2009-10-26 01:45 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-10-25 21:59 . 2009-10-25 21:59 -------- d-sh--w- c:\documents and settings\James\PrivacIE 2009-10-25 16:00 . 2009-10-25 16:00 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP 2009-10-25 16:00 . 2009-10-25 16:01 -------- d-----w- c:\program files\SpywareBlaster 2009-10-25 16:00 . 2005-08-26 00:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL 2009-10-25 04:10 . 2009-10-25 04:10 -------- d-----w- c:\program files\CCleaner 2009-10-25 03:20 . 2009-10-25 03:20 -------- d-----w- c:\program files\Trend Micro 2009-10-25 03:18 . 2009-10-25 03:18 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-10-25 02:56 . 2009-10-25 02:56 -------- d-----w- c:\windows\system32\scripting 2009-10-25 02:56 . 2009-10-25 02:56 -------- d-----w- c:\windows\system32\en 2009-10-25 02:56 . 2009-10-25 02:56 -------- d-----w- c:\windows\system32\bits 2009-10-25 02:56 . 2009-10-25 02:56 -------- d-----w- c:\windows\l2schemas 2009-10-25 02:48 . 2009-10-25 02:48 -------- d-----w- c:\windows\EHome 2009-10-25 02:25 . 2009-10-28 00:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-10-25 02:25 . 2009-10-25 02:27 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-10-25 02:24 . 2009-10-28 19:08 0 ----a-w- c:\documents and settings\James\Local Settings\Application Data\prvlcl.dat 2009-10-25 02:09 . 2009-10-25 02:09 -------- d-sh--w- c:\documents and settings\James\IETldCache 2009-10-25 00:14 . 2009-08-29 08:08 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2009-10-25 00:14 . 2009-08-29 08:08 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll 2009-10-25 00:14 . 2009-08-29 08:08 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll 2009-10-25 00:14 . 2009-08-29 08:08 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll 2009-10-25 00:14 . 2009-08-29 08:08 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2009-10-25 00:14 . 2009-08-29 08:08 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll 2009-10-25 00:14 . 2009-10-25 17:18 -------- d-----w- c:\windows\ie8updates 2009-10-25 00:14 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll 2009-10-25 00:13 . 2009-10-25 02:18 -------- dc-h--w- c:\windows\ie8 2009-10-25 00:07 . 2009-10-25 02:54 -------- d-----w- c:\windows\ServicePackFiles 2009-10-25 00:03 . 2008-04-14 00:11 32285 ------w- c:\windows\system32\hsfcisp2.dll 2009-10-24 23:53 . 2009-10-26 00:58 13104 ----a-w- c:\documents and settings\James\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-10-24 23:53 . 2009-10-26 00:59 -------- d-----w- c:\documents and settings\James\Application Data\Apple Computer 2009-10-24 23:53 . 2009-05-18 19:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-10-24 23:53 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll 2009-10-24 23:50 . 2009-10-28 03:14 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\Apple Computer 2009-10-24 23:46 . 2009-10-24 23:46 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\Mozilla 2009-10-24 23:28 . 2009-10-28 19:23 -------- d-----w- c:\program files\AVG 2009-10-24 22:57 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys 2009-10-24 22:57 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys 2009-10-24 22:56 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys 2009-10-24 22:54 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys 2009-10-24 22:54 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys 2009-10-24 22:54 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll 2009-10-24 22:54 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll 2009-10-24 22:53 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll 2009-10-24 22:45 . 2009-10-24 22:45 0 ----a-w- c:\windows\nsreg.dat 2009-10-24 22:39 . 2009-01-07 23:21 26144 ----a-w- c:\windows\system32\spupdsvc.exe 2009-10-24 22:39 . 2009-10-25 17:18 -------- d--h--w- c:\windows\$hf_mig$ 2009-10-21 19:17 . 2009-10-28 19:56 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000004-00000000-00000002-00001102-00000004-20061102}.dat 2009-10-21 19:17 . 2009-10-28 19:56 384 ----a-w- c:\windows\system32\DVCState-{00000004-00000000-00000002-00001102-00000004-20061102}.dat 2009-10-21 19:17 . 2008-04-13 18:45 10624 ----a-w- c:\windows\system32\drivers\gameenum.sys 2009-10-21 19:10 . 2001-08-17 18:57 16128 -c--a-w- c:\windows\system32\dllcache\modemcsa.sys 2009-10-21 19:10 . 2001-08-17 18:57 16128 ----a-w- c:\windows\system32\drivers\MODEMCSA.sys 2009-10-21 19:09 . 2008-04-13 18:45 6272 ----a-w- c:\windows\system32\drivers\splitter.sys 2009-10-21 19:09 . 2008-04-13 19:17 83072 ----a-w- c:\windows\system32\drivers\wdmaud.sys 2009-10-21 19:09 . 2008-04-13 18:45 52864 ----a-w- c:\windows\system32\drivers\dmusic.sys 2009-10-21 19:09 . 2008-04-13 18:45 56576 ----a-w- c:\windows\system32\drivers\swmidi.sys 2009-10-21 19:09 . 2008-04-13 16:39 142592 ------w- c:\windows\system32\drivers\aec.sys 2009-10-21 19:09 . 2008-04-13 18:45 172416 ----a-w- c:\windows\system32\drivers\kmixer.sys 2009-10-21 19:09 . 2008-04-13 18:45 2944 ----a-w- c:\windows\system32\drivers\drmkaud.sys 2009-10-21 19:09 . 2008-04-13 19:15 60800 ----a-w- c:\windows\system32\drivers\sysaudio.sys 2009-10-21 19:09 . 2008-04-13 18:39 7552 ----a-w- c:\windows\system32\drivers\mskssrv.sys 2009-10-21 19:09 . 2008-04-13 18:39 4992 ----a-w- c:\windows\system32\drivers\mspqm.sys 2009-10-21 19:09 . 2008-04-13 18:39 5376 ----a-w- c:\windows\system32\drivers\mspclock.sys 2009-10-21 19:08 . 2008-04-14 00:11 4096 ----a-w- c:\windows\system32\ksuser.dll 2009-10-21 19:08 . 2008-04-13 19:19 146048 ----a-w- c:\windows\system32\drivers\portcls.sys 2009-10-21 19:08 . 2008-04-13 18:45 60160 ----a-w- c:\windows\system32\drivers\drmk.sys 2009-10-21 19:06 . 2009-10-21 19:06 -------- d-----w- c:\windows\nview 2009-10-21 19:06 . 2007-06-29 05:43 356352 ----a-w- c:\windows\system32\nvudisp.exe 2009-10-21 19:06 . 2007-06-29 06:54 356352 ----a-w- c:\windows\system32\NVUNINST.EXE 2009-10-21 19:06 . 2009-10-21 19:06 -------- d-----w- c:\program files\Common Files\InstallShield 2009-10-21 18:56 . 2009-10-21 18:56 -------- d-----w- c:\program files\Broadcom 2009-10-21 18:50 . 2009-10-21 18:50 -------- d-----w- c:\documents and settings\Owner 2009-10-21 18:50 . 2009-10-21 18:50 -------- d-s---w- c:\windows\system32\Microsoft 2009-10-21 18:50 . 2009-10-26 01:47 -------- d-sh--w- c:\documents and settings\LocalService 2009-10-21 18:50 . 2009-10-25 03:18 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Microsoft . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-25 00:33 . 2009-10-24 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple 2009-10-24 23:52 . 2009-10-24 23:52 -------- d-----w- c:\program files\iTunes 2009-10-24 23:52 . 2009-10-24 23:52 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-10-24 23:52 . 2009-10-24 23:52 -------- d-----w- c:\program files\iPod 2009-10-24 23:52 . 2009-10-24 23:51 -------- d-----w- c:\program files\Common Files\Apple 2009-10-24 23:52 . 2009-10-24 23:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer 2009-10-24 23:52 . 2009-10-24 23:52 -------- d-----w- c:\program files\Bonjour 2009-10-24 23:52 . 2009-10-24 23:52 -------- d-----w- c:\program files\QuickTime 2009-10-24 23:51 . 2009-10-24 23:51 -------- d-----w- c:\program files\Apple Software Update 2009-10-21 17:53 . 2009-10-21 17:53 -------- d-----w- c:\program files\microsoft frontpage 2009-10-21 17:50 . 2009-10-21 17:50 21640 ----a-w- c:\windows\system32\emptyregdb.dat 2009-09-25 05:48 . 2009-09-25 05:48 81920 ------w- c:\windows\system32\ieencode.dll 2009-09-11 14:18 . 2004-08-12 14:01 136192 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-04 21:03 . 2004-08-12 14:00 58880 ----a-w- c:\windows\system32\msasn1.dll 2009-08-29 08:08 . 2004-08-12 14:09 916480 ------w- c:\windows\system32\wininet.dll 2009-08-29 00:42 . 2009-10-24 23:51 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys 2009-08-29 00:42 . 2009-10-24 23:51 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll 2009-08-26 08:00 . 2004-08-12 14:06 247326 ----a-w- c:\windows\system32\strmdll.dll 2009-08-07 00:24 . 2009-10-21 17:51 327896 ----a-w- c:\windows\system32\wucltui.dll 2009-08-07 00:24 . 2009-10-21 17:51 209632 ----a-w- c:\windows\system32\wuweb.dll 2009-08-07 00:24 . 2009-10-21 17:51 35552 ----a-w- c:\windows\system32\wups.dll 2009-08-07 00:24 . 2008-10-16 19:09 44768 ----a-w- c:\windows\system32\wups2.dll 2009-08-07 00:24 . 2009-10-21 17:51 53472 ------w- c:\windows\system32\wuauclt.exe 2009-08-07 00:24 . 2004-08-12 13:56 96480 ----a-w- c:\windows\system32\cdm.dll 2009-08-07 00:23 . 2009-10-21 17:51 575704 ----a-w- c:\windows\system32\wuapi.dll 2009-08-07 00:23 . 2009-10-21 17:51 1929952 ----a-w- c:\windows\system32\wuaueng.dll 2009-08-05 09:01 . 2004-08-12 14:01 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-08-04 15:13 . 2004-08-12 14:02 2145280 ------w- c:\windows\system32\ntoskrnl.exe 2009-08-04 14:20 . 2004-08-03 22:59 2023936 ------w- c:\windows\system32\ntkrnlpa.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-29 8466432] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-29 81920] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-06-29 1626112] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= --- Other Services/Drivers In Memory --- *Deregistered* - mbr . Contents of the 'Scheduled Tasks' folder 2009-10-24 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34] . . ------- Supplementary Scan ------- . uInternet Settings,ProxyOverride = *.local FF - ProfilePath - c:\documents and settings\James\Application Data\Mozilla\Firefox\Profiles\4qqi2hyr.default\ FF - prefs.js: browser.startup.homepage - google.com . - - - - ORPHANS REMOVED - - - - Notify-avgrsstarter - (no file) AddRemove-Zwunzi - c:\program files\Zwunzi\uninstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-28 14:57 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... c:\docume~1\James\LOCALS~1\Temp\RGI1.tmp 7075 bytes scan completed successfully hidden files: 1 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(1140) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\nvsvc32.exe c:\combofix\CF6625.exe c:\windows\system32\wscntfy.exe c:\windows\system32\RUNDLL32.EXE c:\program files\iPod\bin\iPodService.exe c:\combofix\PEV.cfxxe . ************************************************************************** . Completion time: 2009-10-28 14:59 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-28 19:59 ComboFix2.txt 2009-10-27 01:42 Pre-Run: 242,016,837,632 bytes free Post-Run: 241,933,922,304 bytes free - - End Of File - - 0C99DB335141F3AEE37F4852481A6604 Malwarebytes' Anti-Malware 1.41 Database version: 3048 Windows 5.1.2600 Service Pack 3 10/28/2009 4:03:46 PM mbam-log-2009-10-28 (16-03-46).txt Scan type: Quick Scan Objects scanned: 87979 Time elapsed: 2 minute(s), 21 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
|
|
#6 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,182
OS: XP sp3
|
Re: msaro.exe trojan
Hi,
Please do this scan instead: Go here to run an online scanner from ESET.
Also, please post a fresh DDS and Attach.txt and advise how your computer is running now and if there are any outstanding issues. |
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 5
OS: Windows XP
|
Re: msaro.exe trojan
Everything seems to be running fine, but the online scan seemed to find some infected files.
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=1595eaf67dac5f4ba4c3e1d28347af14 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-10-30 12:27:10 # local_time=2009-10-29 07:27:10 (-0600, Central Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1024 16777175 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=31110 # found=9 # cleaned=0 # scan_time=1181 C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Zwunzi\zwunzi119.exe.vir Win32/Adware.OneStep application 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Zwunzi\zwunzi.dll.vir a variant of Win32/Adware.OneStep.C application 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Zwunzi\zwunzi.exe.vir Win32/Adware.OneStep application 00000000000000000000000000000000 I C:\System Volume Information\_restore{D34715C9-763E-477B-8363-5F55AFB0EF48}\RP12\A0004828.exe Win32/Adware.OneStep application 00000000000000000000000000000000 I C:\System Volume Information\_restore{D34715C9-763E-477B-8363-5F55AFB0EF48}\RP12\A0004853.dll a variant of Win32/Adware.OneStep.C application 00000000000000000000000000000000 I C:\System Volume Information\_restore{D34715C9-763E-477B-8363-5F55AFB0EF48}\RP12\A0004854.exe Win32/Adware.OneStep application 00000000000000000000000000000000 I C:\System Volume Information\_restore{D34715C9-763E-477B-8363-5F55AFB0EF48}\RP15\A0005743.exe Win32/Adware.OneStep application 00000000000000000000000000000000 I C:\System Volume Information\_restore{D34715C9-763E-477B-8363-5F55AFB0EF48}\RP15\A0005745.dll a variant of Win32/Adware.OneStep.C application 00000000000000000000000000000000 I C:\System Volume Information\_restore{D34715C9-763E-477B-8363-5F55AFB0EF48}\RP15\A0005746.exe Win32/Adware.OneStep application 00000000000000000000000000000000 I |
|
|
|
|
#8 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Location: Canada
Posts: 2,182
OS: XP sp3
|
Re: msaro.exe trojan
Hi,
The files found by ESET are either in quarantine or old system restore points which we will be cleaning up now. Your logs are clean, just some final housekeeping to do now. You can delete the DDS and GMER folders from your desktop. NEXT Follow these steps to uninstall Combofix
![]() Should you wish to contribute to the ongoing development of ComboFix, donations are being accepted via PayPal. NEXT Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. Thank you for your patience, and performing all of the procedures requested. Please respond one last time so we can consider the thread resolved and close it, thank-you. |
|
|
| Thread Tools | |
|
|