View Full Version : virus/popups please help
deion21
19 Aug 2009, 6:21am
Hi,
Having major issues on my desktop,
here is my hijack log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:57:40 PM, on 8/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PrivacyCenter\protector.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {93E601D3-978D-4D52-AC7F-D541E5F7CA51} - C:\DOCUME~1\Mike\LOCALS~1\Temp\~1B.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [PSDrvCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\RunOnce: [PrivacyCenter] C:\Program Files\PrivacyCenter\protector.exe -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: PrivacyCenter - {5199201E-60B4-11DE-85CF-260556D89593} - C:\Program Files\PrivacyCenter\protector.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} (Interealty MultiSelect) - http://mlslink.mlxchange.com/Control/MultiSelectComboBox.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} (MLXchange Client Utils) - http://mlslink.mlxchange.com/Control/MLXClientUtils.cab
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} (GeacRevw Control) - http://mlslink.mlxchange.com/4.2.04.18/Control/IRCSharc.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://costco.pnimedia.com/upload/activex/v2_0_0_9/PCAXSetupv2.0.0.9.cab?
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 6145 bytes
thanks for your help
Hey there, welcome. :)
Please download Malwarebytes' Anti-Malware by clicking the link below:
http://www.besttechie.net/tools/mbam-setup.exe
Double Click mbam-setup.exe to install the application.
* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform Quick Scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* You'll be required to post the contents of this log later.
Please Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
Next let's have you download ComboFix.exe. Please visit this webpage for downloading and instructions for running the tool:
Go here ======> A guide and tutorial on using ComboFix (http://www.bleepingcomputer.com/combofix/how-to-use-combofix) <====== Go here
Please ensure you read this guide carefully and install the Recovery Console first.This applies to XP Pro and XP Home users only.If you have SP3 installed you will need to use the download meant for SP2.
The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
Once installed, you should get a prompt that says:
The Recovery Console was successfully installed.
Please continue as follows:
(1) Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
(2) Click Yes to allow ComboFix to continue scanning for malware.
When the tool is finished, it will produce a report for you.
Please include the MBAM log, C:\ComboFix.txt as well as a new HijackThis log for further review, so that we may continue cleansing the system.
Caution: Never run and remove files with Combofix unless supervised by a qualified security analyst who is experienced in the use of Combofix. Misuse can cause serious computer problems.
deion21
20 Aug 2009, 3:43am
first issue.....the website comes up for a second, and then it says access denied when I click on your link. It seems to do that for any spyware site. What now?
chiaz
20 Aug 2009, 11:05am
Does this work?
http://74.125.153.132/search?q=cache:co6Gsc_3zHEJ:www.bleepingcomputer.com/combofix/how-to-use-combofix+http://www.bleepingcomputer.com/combofix/how-to-use-combofix&cd=1&hl=en&ct=clnk&gl=sg
deion21
20 Aug 2009, 7:17pm
yes, but you told me to get Malwarebytes' Anti-Malware, and that is what I can not download. I click on your link, and it says access denied. Should I skip that step, and go toi combofix?
Thanks,
chiaz
20 Aug 2009, 10:46pm
Oh I thought you weren't able to access the ComboFix instructions....
For alternative MBAM links, try these:
http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html
http://www.filehippo.com/download_malwarebytes_anti_malware/
http://majorgeeks.com/download.php?det=5756
deion21
21 Aug 2009, 12:38am
Thanks Chiaz.
ok, I downloaded MBAM. I ran the install, but when it gets finished, the program does not start. Also, if I try clicking on the desktop icon, it brings up the hourglass for a second, and then nothing. So the program will not run.
So I have the program on my computer, I tried uninstall, and reinstalling it, and nothing.
Rename the MBAM icon on your desktop, and try running it again.
If that doesn't work, go on with ComboFix.
deion21
22 Aug 2009, 12:05am
got combofix to run. here is the log:
ComboFix 09-08-20.07 - Mike 08/21/2009 15:43.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.512.241 [GMT -7:00]
Running from: c:\documents and settings\Mike\Desktop\test.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Mike\Application Data\Google\Shell32.dll
c:\windows\Fonts\WPHV07NB.TTF
c:\windows\Install.txt
c:\windows\system32\42KJE738.ocx
c:\windows\system32\Data
c:\windows\system32\drivers\UAClvdwmxuhnkvoafd.sys
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\twain.dll
c:\windows\system32\UACauppnvqufjenjug.dll
c:\windows\system32\UACfawtfdnslcbmyay.log
c:\windows\system32\UACiehphsfodexjekn.dat
c:\windows\system32\UACildcbsjjacuqopu.log
c:\windows\system32\uacinit.dll
c:\windows\system32\UACkbldcknrvkbncrp.dll
c:\windows\system32\UACoafbwkrrdqcbwtm.dll
c:\windows\system32\UACrnaomsyrcevvhuy.log
c:\windows\system32\UACupchrhybbtculqd.dll
c:\windows\system32\UACwovptnntdgsiibb.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-07-21 to 2009-08-21 )))))))))))))))))))))))))))))))
.
2009-08-20 23:35 . 2009-08-03 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-20 23:35 . 2009-08-20 23:35 -------- d-----w- c:\program files\the program
2009-08-20 23:35 . 2009-08-20 23:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-20 23:35 . 2009-08-03 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-19 04:57 . 2009-08-19 04:57 -------- d-----w- c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-21 22:28 . 2008-12-30 21:21 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-19 04:42 . 2009-05-26 19:01 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-01 17:03 . 2008-12-30 21:22 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-28 16:53 . 2008-12-30 21:22 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-28 16:53 . 2008-12-30 21:22 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-01 06:31 . 2009-06-01 06:31 422 ----a-w- c:\documents and settings\Mike\Application Data\Ahead\socks1.exe
2009-06-01 06:31 . 2009-06-01 06:31 16141 ----a-w- c:\documents and settings\Mike\Application Data\ArcSoft\lego.exe
2009-06-01 06:31 . 2009-06-01 06:31 145131 ----a-w- c:\documents and settings\Mike\Application Data\Apple Computer\nomad.exe
2009-06-01 06:31 . 2009-06-01 06:31 13221 ----a-w- c:\documents and settings\Mike\Application Data\AdobeUM\rengo.dll
2009-06-01 06:31 . 2009-06-01 06:31 11410 ----a-w- c:\documents and settings\Mike\Application Data\Corel\msgdi.dll
2009-06-01 06:31 . 2009-06-01 06:31 10121 ----a-w- c:\documents and settings\Mike\Application Data\CyberLink\kern.dll
2009-06-01 06:31 . 2009-06-01 06:31 11232 ----a-w- c:\documents and settings\Mike\Application Data\Adobe\shalom.exe
2009-06-01 06:30 . 2009-06-01 06:30 118272 ----a-w- c:\documents and settings\Mike\Application Data\Google\vsjyn859746.exe
2009-05-29 22:28 . 2009-05-29 22:28 280832 ----a-w- C:\052909.reg
2009-05-29 21:53 . 2009-05-29 22:03 3371360 ----a-w- C:\mbam-setup.exe
2009-05-26 18:24 . 2009-05-26 18:24 177 ----a-w- c:\documents and settings\Mike\Application Data\asd.bat
2009-05-26 18:24 . 2009-05-26 18:24 177 ----a-w- c:\documents and settings\Mike\Application Data\asd.bat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Lexmark X1100 Series"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 57344]
"PSDrvCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-02-23 377856]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-12-06 282624]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-28 1948440]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"realteks"="c:\documents and settings\Mike\Application Data\Google\vsjyn859746.exe" [2009-06-01 118272]
c:\documents and settings\Mike\Start Menu\Programs\Startup\
CorelCENTRAL Alarms.LNK - c:\program files\Corel\WordPerfect Office 2000\programs\alarm.exe [2006-1-10 249856]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-12 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-28 16:53 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"="1"
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WS_FTP Pro\\wsftppro.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/30/2008 2:22 PM 335752]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/30/2008 2:21 PM 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 1:44 PM 24652]
S3 ab3af53c-334c-4d2f-bfc0-ed6cf9421d00;ab3af53c-334c-4d2f-bfc0-ed6cf9421d00;\??\d:\cds300\cds300.dll --> d:\cds300\cds300.dll [?]
.
- - - - ORPHANS REMOVED - - - -
BHO-{93E601D3-978D-4D52-AC7F-D541E5F7CA51} - c:\docume~1\Mike\LOCALS~1\Temp\~1B.dll
SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: aol.com\free
DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} - hxxp://mlslink.mlxchange.com/Control/MultiSelectComboBox.cab
DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} - hxxp://mlslink.mlxchange.com/Control/MLXClientUtils.cab
DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} - hxxp://mlslink.mlxchange.com/4.2.04.18/Control/IRCSharc.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-21 15:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(640)
c:\windows\system32\NavLogon.dll
.
Completion time: 2009-08-21 15:55
ComboFix-quarantined-files.txt 2009-08-21 22:55
Pre-Run: 40,216,678,400 bytes free
Post-Run: 40,836,546,560 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
143
deion21
22 Aug 2009, 12:06am
chiaz, before I forget, thanks for the help.....now what next!!!
There are definitely still signs of infection; but before I come up with the fix I will need to know some things first.
Do you have any idea what this folder is/contains?
c:\program files\the program
And this registry file?
C:\052909.reg
=================================================
Please go to http://virusscan.jotti.org (http://virusscan.jotti.org) , click on Browse, and upload the following files for analysis: You will only be able to have one file scanned at a time.
c:\documents and settings\Mike\Application Data\Ahead\socks1.exe
c:\documents and settings\Mike\Application Data\ArcSoft\lego.exe
c:\documents and settings\Mike\Application Data\Apple Computer\nomad.exe
c:\documents and settings\Mike\Application Data\AdobeUM\rengo.dll
c:\documents and settings\Mike\Application Data\Corel\msgdi.dll
c:\documents and settings\Mike\Application Data\CyberLink\kern.dll
c:\documents and settings\Mike\Application Data\Adobe\shalom.exe
Then click Submit. Allow the files to be scanned individually. Now please Copy/Paste the results here for me to see, as well as provide me answers to the 2 questions above.
If Jotti is busy, please go to http://www.virustotal.com (http://www.virustotal.com/).
deion21
23 Aug 2009, 12:14am
c:\program files\the program is just the name i renamed MBAM. I have no idea what C:\052909.reg is. Shoudl I delete it?
chiaz
23 Aug 2009, 12:17am
Yes, delete it please and carry on with the Jotti scans.
deion21
23 Aug 2009, 11:20pm
c:\documents and settings\Mike\Application Data\Ahead\socks1.exe
Is this what you need?
File socks1.exe received on 2009.07.24 05:06:10 (UTC)
Current status: finished
Result: 3/40 (7.50%)
http://www.virustotal.com/img/compress-icon.png Compact (http://www.virustotal.com/analisis/04c179d3859b2a6c98d83a568944c719a92140f83c7a9ab0d17804ed8dbe8f9e-1248411970#)
Print results (javascript:window.print()) http://www.virustotal.com/img/print-icon.png
AntivirusVersionLast UpdateResulta-squared4.5.0.242009.07.23-AhnLab-V35.0.0.22009.07.24-AntiVir7.9.0.2282009.07.23-Antiy-AVL2.0.3.72009.07.24-Authentium5.1.2.42009.07.24W32/Heuristic-CO2!EldoradoAvast4.8.1335.02009.07.23-AVG8.5.0.3872009.07.23-BitDefender7.22009.07.24-CAT-QuickHeal10.002009.07.23-ClamAV0.94.12009.07.24-Comodo17492009.07.24-DrWeb5.0.0.121822009.07.24-eSafe7.0.17.02009.07.23-eTrust-Vet31.6.66372009.07.24-F-Prot4.4.4.562009.07.23W32/Heuristic-CO2!EldoradoF-Secure8.0.14470.02009.07.23-Fortinet3.120.0.02009.07.24-GData192009.07.24-IkarusT3.1.1.64.02009.07.23-Jiangmin11.0.8002009.07.23-K7AntiVirus7.10.8002009.07.23-Kaspersky7.0.0.1252009.07.24-McAfee56862009.07.23-McAfee+Artemis56862009.07.23-McAfee-GW-Edition6.8.52009.07.24Heuristic.LooksLike.Win32.SuspiciousPE.P!80Microsoft1.49032009.07.23-NOD3242722009.07.24-Norman6.01.092009.07.22-nProtect2009.1.8.02009.07.24-PCTools4.4.2.02009.07.23-Prevx3.02009.07.24-Rising21.39.40.002009.07.24-Sophos4.44.02009.07.24-Sunbelt3.2.1858.22009.07.23-Symantec1.4.4.122009.07.24-TheHacker6.3.4.3.3732009.07.24-TrendMicro8.950.0.10942009.07.23-VBA323.12.10.92009.07.24-ViRobot2009.7.23.18492009.07.23-VirusBuster4.6.5.02009.07.23-Additional informationFile size: 422 bytesMD5 : 8c2a7a62a031961dcccc90637a7c40cbSHA1 : 8fa5d2cb1184bd20e41a1609f268de35c8604682SHA256: 04c179d3859b2a6c98d83a568944c719a92140f83c7a9ab0d17804ed8dbe8f9eTrID : File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)ssdeep: 3:MpPqt/wlEh/jFkjXFeyxi4slltlml2mzlXlbp/stMlHvlt/9vl7//llrllTll/ly:MxlEh/jKjXFeyclltA96ibtwPEiD : -packers (Kaspersky): PE_PatchCWSandbox: http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=8c2a7a62a031961dcccc90637a7c40cb (http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=8c2a7a62a031961dcccc90637a7c40cb)RDS : NSRL Reference Data Set
-
chiaz
24 Aug 2009, 10:20am
Yes, how about the other 6 files?
Actually just the URLs linking to the various result pages will do.
deion21
24 Aug 2009, 3:32pm
just wanted to make sure I was doing it correctly. I will get the others shortly
deion21
26 Aug 2009, 2:16am
c:\documents and settings\Mike\Application Data\ArcSoft\lego.exe
analisis/da06b133bf5ca3cd2053b366fc4ad9c341238dba06fb8b0c99a2cebe044a83f2-1243899196 (http://www.virustotal.com/analisis/da06b133bf5ca3cd2053b366fc4ad9c341238dba06fb8b0c99a2cebe044a83f2-1243899196)
deion21
26 Aug 2009, 2:20am
c:\documents and settings\Mike\Application Data\Apple Computer\nomad.exe
http://www.virustotal.com/analisis/e6379bc5819b7bb9b0cec9b392a3478e1a41143d71ea7b4af183b996b687062d-1251249438
deion21
26 Aug 2009, 2:20am
c:\documents and settings\Mike\Application Data\AdobeUM\rengo.dll
analisis/33bd273604e8deb38eac4c8d0afd17fc7b5a39e4d29194733b7959ee90affd04-1243899492 (http://www.virustotal.com/analisis/33bd273604e8deb38eac4c8d0afd17fc7b5a39e4d29194733b7959ee90affd04-1243899492)
deion21
26 Aug 2009, 2:21am
c:\documents and settings\Mike\Application Data\Corel\msgdi.dll
analisis/527edb3d96f78699ce50c9c2c2251c92025a7f8217a29a6f9fe9e4a92329c3ce-1243869988 (http://www.virustotal.com/analisis/527edb3d96f78699ce50c9c2c2251c92025a7f8217a29a6f9fe9e4a92329c3ce-1243869988)
deion21
26 Aug 2009, 2:22am
c:\documents and settings\Mike\Application Data\CyberLink\kern.dll
analisis/b65ecd60c457a529c49e491aeeeb7e96eb91f8b0084585cc7b005889d4bf586c-1243870003 (http://www.virustotal.com/analisis/b65ecd60c457a529c49e491aeeeb7e96eb91f8b0084585cc7b005889d4bf586c-1243870003)
deion21
26 Aug 2009, 2:23am
c:\documents and settings\Mike\Application Data\Adobe\shalom.exe
analisis/45b7150b8bf5052267b83a1241f7f554ffd6339e501e341cffe9a63265d4b31e-1243869944 (http://www.virustotal.com/analisis/45b7150b8bf5052267b83a1241f7f554ffd6339e501e341cffe9a63265d4b31e-1243869944)
deion21
26 Aug 2009, 2:23am
I am able to run MBAM now.....would you lik eme to do that as well, since I could not do it at the beginning?
chiaz
26 Aug 2009, 11:23am
Yes, please do.
deion21
27 Aug 2009, 4:03pm
MBAM is now done....
What next
Please navigate to and delete the following files:
c:\documents and settings\Mike\Application Data\Ahead\socks1.exe
c:\documents and settings\Mike\Application Data\Corel\msgdi.dll
Leave them in your Recycle Bin first.
How's your PC running now? Let's have you go HERE (http://www.pandasecurity.com/activescan/index/) to run Panda ActiveScan 2.0
Click the big green Scan now button
If it wants to install an ActiveX component allow it
It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
Once the scan is completed, please hit the notepad icon next to the text Export to:
Save it to a convenient location such as your Desktop
Post the contents of the ActiveScan.txt in your next reply.
deion21
29 Aug 2009, 8:47am
;***********************************************************************************************************************************************************************************
ANALYSIS: 2009-08-29 00:45:42
PROTECTIONS: 1
MALWARE: 66
SUSPECTS: 1
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
AVG Anti-Virus Free 8.5 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00032745 adware/sahagent Adware No 0 Yes No c:\windows\downloaded program files\sporder_.dll
00047879 Adware/IST.ISTBar Adware No 1 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ODUB0LYZ\image[1].0tm
00048250 Adware/IST.ISTBar Adware No 1 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ZVLJ79OW\codec_v2[1].htm
00048251 Adware/WUpd Adware No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WLKJ83GV\pageid=84816394[1].htm
00048251 Adware/WUpd Adware No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Local Settings\Temporary Internet Files\Content.IE5\W1YRC1UR\search[1].htm
00048251 Adware/WUpd Adware No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Local Settings\Temporary Internet Files\Content.IE5\STU7W9AB\welcometoatlanta[1].htm
00048251 Adware/WUpd Adware No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WLKJ83GV\search[2].htm
00136827 Adware/SAHAgent Adware No 0 Yes No C:\WINDOWS\system32\xmltok.dll
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@trafficmp[2].txt
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@casalemedia[2].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@doubleclick[2].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@atdmt[1].txt
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@247realmedia[2].txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@fastclick[2].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@tribalfusion[2].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@mediaplex[2].txt
00148840 Cookie/Pollstar TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@pollstar[2].txt
00148914 Cookie/Tucows TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@tucows[1].txt
00149116 Cookie/Ccbill TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@ccbill[1].txt
00152401 Cookie/Belnk TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@belnk[1].txt
00159564 Cookie/WUpd TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@revenue[2].txt
00162730 Cookie/Belnk TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@dist.belnk[1].txt
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@com[1].txt
00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@yadro[2].txt
00167650 Cookie/GangbangSquad TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@gangbangsquad[1].txt
00167677 Cookie/WebPower TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@webpower[2].txt
00167690 Cookie/Rightmedia TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@rightmedia[2].txt
00167714 Cookie/64.62.232 TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@64.62.232[2].txt
00167738 Cookie/fe.lea.lycos TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@fe.lea.lycos[1].txt
00167744 Cookie/GoStats TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@gostats[1].txt
00167749 Cookie/Toplist TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@toplist[1].txt
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@statcounter[1].txt
00167761 Cookie/Sextracker TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@counter8.sextracker[1].txt
00167776 Cookie/Kount TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@kount[1].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@ad.yieldmanager[1].txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@apmebf[2].txt
00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@burstnet[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@bs.serving-sys[2].txt
00168097 Cookie/BurstBeacon TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@www.burstbeacon[2].txt
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@adtech[1].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@advertising[2].txt
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@sextracker[2].txt
00170087 Cookie/Hbmediapro TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@adopt.hbmediapro[1].txt
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@statse.webtrendslive[2].txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@ads.pointroll[2].txt
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@overture[1].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@questionmarket[1].txt
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@zedo[2].txt
00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@bluestreak[2].txt
00173545 Cookie/Rn11 TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@rn11[2].txt
00173992 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@c5.zedo[1].txt
00184086 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@image.checkmystats.com[2].txt
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@adrevolver[2].txt
00186561 Cookie/Banner TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@banner[2].txt
00187951 Cookie/seeqA TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@www.seeq[2].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@go[1].txt
00196960 Cookie/Belnk TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@ath.belnk[2].txt
00199984 Cookie/Searchportal TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@searchportal.information[1].txt
00207712 Cookie/360i TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@ct.360i[1].txt
00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@atwola[1].txt
00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@atwola[1].txt
00286736 Cookie/Cgi-bin TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@cgi-bin[1].txt
00590315 Rootkit/Agent.LNB HackTools No 0 Yes No C:\WINDOWS\system32\drivers\hhtioto.sys
01196325 Cookie/Enhance TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@enhance[2].txt
01281813 Adware/AntivirusXPPro Adware No 0 Yes No C:\System Volume Information\_restore{02B53434-2A06-4576-BABD-60A14277FCE5}\RP1\A0000045.dll
01281813 Adware/AntivirusXPPro Adware No 0 Yes No C:\Qoobox\Quarantine\C\Documents and Settings\Mike\Application Data\Google\Shell32.dll.vir
01606636 Cookie/Adserver TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@adserver.easyad[1].txt
01690516 Spyware/Virtumonde Spyware No 1 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_UAClvdwmxuhnkvoafd_.sys.zip[UAClvdwmxuhnkvoafd.sys]
02515974 Adware/PrivacyCenter Adware No 0 Yes No C:\RECYCLER\S-1-5-21-484763869-2147189391-682003330-1005\Dc2.exe
02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{02B53434-2A06-4576-BABD-60A14277FCE5}\RP0\A0000007.sys
;===================================================================================================================================================================================
SUSPECTS
Sent Location
;===================================================================================================================================================================================
No C:\WINDOWS\system32\xmlparse.dll
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description
;===================================================================================================================================================================================
211784 HIGH MS09-032
211781 HIGH MS09-029
210625 HIGH MS09-026
210624 HIGH MS09-025
210621 HIGH MS09-022
210618 HIGH MS09-019
208380 HIGH MS09-015
208379 HIGH MS09-014
208378 HIGH MS09-013
208377 HIGH MS09-012
206981 HIGH MS09-007
206980 HIGH MS09-006
204670 HIGH MS09-001
203806 HIGH MS08-078
203508 HIGH MS08-073
203505 HIGH MS08-071
202465 HIGH MS08-068
201683 HIGH MS08-067
201258 HIGH MS08-066
201256 HIGH MS08-064
201255 HIGH MS08-063
201253 HIGH MS08-061
201250 HIGH MS08-058
209275 HIGH MS08-049
209273 HIGH MS08-045
196455 MEDIUM MS08-037
194862 HIGH MS08-032
194861 HIGH MS08-031
194860 HIGH MS08-030
191618 HIGH MS08-025
191617 HIGH MS08-024
191616 HIGH MS08-023
191614 HIGH MS08-021
191613 HIGH MS08-020
187735 HIGH MS08-010
187733 HIGH MS08-008
184380 MEDIUM MS08-002
184379 MEDIUM MS08-001
;===================================================================================================================================================================================
Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions. It's IMPORTANT to carry out the instructions in the sequence listed below.
First return to Jotti/VirusTotal and upload the following file for analysis:
C:\WINDOWS\system32\xmlparse.dll
Post the links to the results later.
=============
Now,
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Open *notepad* and copy/paste the text in the quotebox below into it:
File::
c:\windows\downloaded program files\sporder_.dll
C:\WINDOWS\system32\xmltok.dll
C:\WINDOWS\system32\drivers\hhtioto.sys
Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.
http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif
Refering to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt in your next reply please, along with the VirusTotal/Jotti results.
*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Altering this script in any way could damage your computer*
deion21
30 Aug 2009, 1:50am
C:\WINDOWS\system32\xmlparse.dll
http://virusscan.jotti.org/en/scanresult/68675ac976f8a087f2f38078e9bdddf56cc57828
Thank you, have you started on the CFScript yet?
If no, then don't proceed with that first and post back here.
If you already have, then post the ComboFix.txt in your reply.
deion21
31 Aug 2009, 12:37am
i was doing it as you posted. Here is it
ComboFix 09-08-29.01 - Mike 08/29/2009 18:01.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.512.304 [GMT -7:00]
Running from: c:\documents and settings\Mike\Desktop\test.exe
Command switches used :: c:\documents and settings\Mike\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Mike\My Documents\ZbThumbnail.info
.
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-30 )))))))))))))))))))))))))))))))
.
2009-08-29 01:40 . 2008-06-20 00:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-08-29 01:40 . 2009-08-29 01:40 -------- d-----w- c:\program files\Panda Security
2009-08-21 23:10 . 2009-08-21 23:10 -------- d-----w- c:\documents and settings\Mike\Application Data\Malwarebytes
2009-08-20 23:35 . 2009-08-03 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-20 23:35 . 2009-08-20 23:35 -------- d-----w- c:\program files\the program
2009-08-20 23:35 . 2009-08-20 23:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-20 23:35 . 2009-08-03 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-19 04:57 . 2009-08-19 04:57 -------- d-----w- c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-29 01:39 . 2006-01-10 21:19 -------- d-----w- c:\documents and settings\Mike\Application Data\Corel
2009-08-29 01:38 . 2004-08-14 15:43 -------- d-----w- c:\documents and settings\Mike\Application Data\Ahead
2009-08-25 21:53 . 2005-01-13 03:40 -------- d-----w- c:\program files\Lexmark X1100 Series
2009-08-19 04:42 . 2009-05-26 19:01 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-01 06:31 . 2009-06-01 06:31 16141 ----a-w- c:\documents and settings\Mike\Application Data\ArcSoft\lego.exe
2009-06-01 06:31 . 2009-06-01 06:31 145131 ----a-w- c:\documents and settings\Mike\Application Data\Apple Computer\nomad.exe
2009-06-01 06:31 . 2009-06-01 06:31 13221 ----a-w- c:\documents and settings\Mike\Application Data\AdobeUM\rengo.dll
2009-06-01 06:31 . 2009-06-01 06:31 10121 ----a-w- c:\documents and settings\Mike\Application Data\CyberLink\kern.dll
2009-06-01 06:31 . 2009-06-01 06:31 11232 ----a-w- c:\documents and settings\Mike\Application Data\Adobe\shalom.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-08-21_22.53.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-17 15:59 . 2009-04-17 15:59 128256 c:\windows\Downloaded Program Files\as2stubie.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Lexmark X1100 Series"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 57344]
"PSDrvCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-02-23 377856]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-12-06 282624]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
c:\documents and settings\Mike\Start Menu\Programs\Startup\
CorelCENTRAL Alarms.LNK - c:\program files\Corel\WordPerfect Office 2000\programs\alarm.exe [2006-1-10 249856]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-12 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WS_FTP Pro\\wsftppro.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [8/28/2009 6:40 PM 28544]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 1:44 PM 24652]
S3 ab3af53c-334c-4d2f-bfc0-ed6cf9421d00;ab3af53c-334c-4d2f-bfc0-ed6cf9421d00;\??\d:\cds300\cds300.dll --> d:\cds300\cds300.dll [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - PAVBOOT
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: aol.com\free
DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} - hxxp://mlslink.mlxchange.com/Control/MultiSelectComboBox.cab
DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} - hxxp://mlslink.mlxchange.com/Control/MLXClientUtils.cab
DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} - hxxp://mlslink.mlxchange.com/4.2.04.18/Control/IRCSharc.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-29 18:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(632)
c:\windows\system32\NavLogon.dll
.
Completion time: 2009-08-30 18:09
ComboFix-quarantined-files.txt 2009-08-30 01:09
ComboFix2.txt 2009-08-21 22:56
Pre-Run: 40,859,291,648 bytes free
Post-Run: 40,806,207,488 bytes free
105
I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player's components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager -- the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision. To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.
Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware (http://www.clickz.com/showPage.html?page=3561546).
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
Click Start, point to Settings, and then click Control Panel.
In Control Panel, double-click Add or Remove Programs.
In Add or Remove Programs, highlight >>Viewpoint component<< , click Remove.
Do the same for each Viewpoint component.
Restart your PC when you're done.
==========================
Now,
1. Delete CFScript.txt from your desktop.
2. Close any open browsers.
3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Open *notepad* and copy/paste the text in the quotebox below into it:
File::
C:\WINDOWS\system32\xmlparse.dll
Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.
http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif
Refering to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt in your next reply please. Also let me know whether you removed ViewPoint.
*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Altering this script in any way could damage your computer*
deion21
2 Sep 2009, 3:10am
ComboFix 09-09-01.04 - Mike 09/01/2009 18:34.4.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.512.281 [GMT -7:00]
Running from: c:\documents and settings\Mike\Desktop\test.exe
Command switches used :: c:\documents and settings\Mike\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.
2009-08-29 01:40 . 2008-06-20 00:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-08-29 01:40 . 2009-08-29 01:40 -------- d-----w- c:\program files\Panda Security
2009-08-21 23:10 . 2009-08-21 23:10 -------- d-----w- c:\documents and settings\Mike\Application Data\Malwarebytes
2009-08-20 23:35 . 2009-08-03 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-20 23:35 . 2009-08-20 23:35 -------- d-----w- c:\program files\the program
2009-08-20 23:35 . 2009-08-20 23:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-20 23:35 . 2009-08-03 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-19 04:57 . 2009-08-19 04:57 -------- d-----w- c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-29 01:39 . 2006-01-10 21:19 -------- d-----w- c:\documents and settings\Mike\Application Data\Corel
2009-08-29 01:38 . 2004-08-14 15:43 -------- d-----w- c:\documents and settings\Mike\Application Data\Ahead
2009-08-25 21:53 . 2005-01-13 03:40 -------- d-----w- c:\program files\Lexmark X1100 Series
2009-08-19 04:42 . 2009-05-26 19:01 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
.
((((((((((((((((((((((((((((( SnapShot@2009-08-21_22.53.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-17 15:59 . 2009-04-17 15:59 128256 c:\windows\Downloaded Program Files\as2stubie.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Lexmark X1100 Series"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 57344]
"PSDrvCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-02-23 377856]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-12-06 282624]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
c:\documents and settings\Mike\Start Menu\Programs\Startup\
CorelCENTRAL Alarms.LNK - c:\program files\Corel\WordPerfect Office 2000\programs\alarm.exe [2006-1-10 249856]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-12 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WS_FTP Pro\\wsftppro.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [8/28/2009 6:40 PM 28544]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 1:44 PM 24652]
S3 ab3af53c-334c-4d2f-bfc0-ed6cf9421d00;ab3af53c-334c-4d2f-bfc0-ed6cf9421d00;\??\d:\cds300\cds300.dll --> d:\cds300\cds300.dll [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - PAVBOOT
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: aol.com\free
DPF: {4989312D-58CF-11D5-A7D7-00E02911103E} - hxxp://mlslink.mlxchange.com/Control/MultiSelectComboBox.cab
DPF: {6FD482A3-7B57-438B-B040-52CAA30147EE} - hxxp://mlslink.mlxchange.com/Control/MLXClientUtils.cab
DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} - hxxp://mlslink.mlxchange.com/4.2.04.18/Control/IRCSharc.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-01 18:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(632)
c:\windows\system32\NavLogon.dll
.
Completion time: 2009-09-02 18:42
ComboFix-quarantined-files.txt 2009-09-02 01:42
ComboFix2.txt 2009-09-01 03:52
ComboFix3.txt 2009-08-30 01:09
ComboFix4.txt 2009-08-21 22:56
Pre-Run: 40,794,968,064 bytes free
Post-Run: 40,740,372,480 bytes free
99
Did you remove ViewPoint? Also can you post one final Panda ActiveScan log, I want to check if those files are truly removed.
deion21
3 Sep 2009, 2:51am
Viewpoint is now removed...Sorry I forgot to do that
Can you post one final Panda ActiveScan log? I want to check if those files are truly removed. And then you can be on your way. :)
deion21
4 Sep 2009, 12:15am
Still says I am infected
;***********************************************************************************************************************************************************************************
ANALYSIS: 2009-09-03 15:30:04
PROTECTIONS: 0
MALWARE: 67
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00032745 adware/sahagent Adware No 0 Yes No c:\windows\downloaded program files\sporder_.dll
00047879 Adware/IST.ISTBar Adware No 1 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ODUB0LYZ\image[1].0tm
00048250 Adware/IST.ISTBar Adware No 1 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ZVLJ79OW\codec_v2[1].htm
00048251 Adware/WUpd Adware No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Local Settings\Temporary Internet Files\Content.IE5\STU7W9AB\welcometoatlanta[1].htm
00048251 Adware/WUpd Adware No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Local Settings\Temporary Internet Files\Content.IE5\W1YRC1UR\search[1].htm
00048251 Adware/WUpd Adware No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WLKJ83GV\pageid=84816394[1].htm
00048251 Adware/WUpd Adware No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WLKJ83GV\search[2].htm
00136827 Adware/SAHAgent Adware No 0 Yes No C:\WINDOWS\system32\xmltok.dll
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@trafficmp[2].txt
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@casalemedia[2].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@doubleclick[2].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@atdmt[1].txt
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@247realmedia[2].txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@fastclick[2].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@tribalfusion[1].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@mediaplex[2].txt
00148840 Cookie/Pollstar TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@pollstar[2].txt
00148914 Cookie/Tucows TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@tucows[1].txt
00149116 Cookie/Ccbill TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@ccbill[1].txt
00152401 Cookie/Belnk TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@belnk[1].txt
00159564 Cookie/WUpd TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@revenue[2].txt
00162730 Cookie/Belnk TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@dist.belnk[1].txt
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@com[1].txt
00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@yadro[2].txt
00167650 Cookie/GangbangSquad TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@gangbangsquad[1].txt
00167677 Cookie/WebPower TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@webpower[2].txt
00167690 Cookie/Rightmedia TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@rightmedia[2].txt
00167714 Cookie/64.62.232 TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@64.62.232[2].txt
00167738 Cookie/fe.lea.lycos TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@fe.lea.lycos[1].txt
00167744 Cookie/GoStats TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@gostats[1].txt
00167749 Cookie/Toplist TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@toplist[1].txt
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@statcounter[1].txt
00167761 Cookie/Sextracker TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@counter8.sextracker[1].txt
00167776 Cookie/Kount TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@kount[1].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@ad.yieldmanager[1].txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@apmebf[2].txt
00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@burstnet[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@bs.serving-sys[2].txt
00168097 Cookie/BurstBeacon TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@www.burstbeacon[2].txt
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@adtech[1].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@advertising[1].txt
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@sextracker[2].txt
00170087 Cookie/Hbmediapro TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@adopt.hbmediapro[1].txt
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@statse.webtrendslive[2].txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@ads.pointroll[2].txt
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@overture[1].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@questionmarket[1].txt
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@zedo[2].txt
00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@bluestreak[2].txt
00173545 Cookie/Rn11 TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@rn11[2].txt
00173992 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@c5.zedo[1].txt
00184086 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@image.checkmystats.com[2].txt
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@adrevolver[2].txt
00186561 Cookie/Banner TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@banner[2].txt
00187951 Cookie/seeqA TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@www.seeq[2].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@go[1].txt
00196960 Cookie/Belnk TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@ath.belnk[2].txt
00199984 Cookie/Searchportal TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@searchportal.information[1].txt
00207712 Cookie/360i TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@ct.360i[1].txt
00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\Carly\Desktop\Administrator\Cookies\administrator@atwola[1].txt
00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@atwola[1].txt
00286736 Cookie/Cgi-bin TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@cgi-bin[1].txt
00590315 Rootkit/Agent.LNB HackTools No 0 Yes No C:\System Volume Information\_restore{02B53434-2A06-4576-BABD-60A14277FCE5}\RP5\A0000293.sys
01196325 Cookie/Enhance TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@enhance[2].txt
01281813 Adware/AntivirusXPPro Adware No 0 Yes No C:\System Volume Information\_restore{02B53434-2A06-4576-BABD-60A14277FCE5}\RP1\A0000045.dll
01281813 Adware/AntivirusXPPro Adware No 0 Yes No C:\Qoobox\Quarantine\C\Documents and Settings\Mike\Application Data\Google\Shell32.dll.vir
01606636 Cookie/Adserver TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Cookies\mike@adserver.easyad[1].txt
01690516 Spyware/Virtumonde Spyware No 1 Yes No C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_UAClvdwmxuhnkvoafd_.sys.zip[UAClvdwmxuhnkvoafd.sys]
02515974 Adware/PrivacyCenter Adware No 0 Yes No C:\System Volume Information\_restore{02B53434-2A06-4576-BABD-60A14277FCE5}\RP5\A0000378.exe
02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{02B53434-2A06-4576-BABD-60A14277FCE5}\RP0\A0000007.sys
03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\WINDOWS\system32\xmlparse.dll
;===================================================================================================================================================================================
SUSPECTS
Sent Location p
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description p
;===================================================================================================================================================================================
212494 HIGH MS09-042 p
212493 HIGH MS09-041 p
212490 HIGH MS09-038 p
212530 HIGH MS09-034 p
211784 HIGH MS09-032 p
211781 HIGH MS09-029 p
210625 HIGH MS09-026 p
210624 HIGH MS09-025 p
210621 HIGH MS09-022 p
210618 HIGH MS09-019 p
208380 HIGH MS09-015 p
208379 HIGH MS09-014 p
208378 HIGH MS09-013 p
208377 HIGH MS09-012 p
206981 HIGH MS09-007 p
206980 HIGH MS09-006 p
204670 HIGH MS09-001 p
203806 HIGH MS08-078 p
203508 HIGH MS08-073 p
203505 HIGH MS08-071 p
202465 HIGH MS08-068 p
201683 HIGH MS08-067 p
201258 HIGH MS08-066 p
201256 HIGH MS08-064 p
201255 HIGH MS08-063 p
201253 HIGH MS08-061 p
201250 HIGH MS08-058 p
209275 HIGH MS08-049 p
209273 HIGH MS08-045 p
196455 MEDIUM MS08-037 p
194862 HIGH MS08-032 p
194861 HIGH MS08-031 p
194860 HIGH MS08-030 p
191618 HIGH MS08-025 p
191617 HIGH MS08-024 p
191616 HIGH MS08-023 p
191614 HIGH MS08-021 p
191613 HIGH MS08-020 p
187735 HIGH MS08-010 p
187733 HIGH MS08-008 p
184380 MEDIUM MS08-002 p
184379 MEDIUM MS08-001 p
;===================================================================================================================================================================================
OK, those files were NOT removed. Let's use another tool.
Download KillBox from the following link :
http://www.bleepingcomputer.com/files/killbox.php (http://www.bleepingcomputer.com/files/killbox.php)
Unzip the folder to your Desktop.
Please double-click Killbox.exe to run it.
Select:
Delete on Reboot
then click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
c:\windows\downloaded program files\sporder_.dll
C:\WINDOWS\system32\xmltok.dll
C:\WINDOWS\system32\drivers\hhtioto.sys
C:\WINDOWS\system32\xmlparse.dll
Return to Killbox, go to the File menu, and choose Paste from Clipboard.
Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
Please reboot the computer, and post a new Panda ActiveScan log upon reboot.
vBulletin® v3.8.1, Copyright ©2000-2009, Jelsoft Enterprises Ltd.