Options

Browser redirect virus

I have contracted the browser redirect virus. I have downloaded highjackthis and malwarebytes to my desktop. I have tried to run the programs, but that does not seem to be working.

Any help would be greatly appreciated. I could use the step by step help.

Comments

  • VekaVeka Finland
    edited December 2008
    Hi and welcome to Icrontic. Please check your Private Messages for instructions.
  • edited December 2008
    I ran the program you suggested.

    HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tdssserv.sys
    NextInstance REG_DWORD 1 (0x1)

    HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tdssserv.sys\0000
    Service REG_SZ TDSSserv.sys
    Legacy REG_DWORD 1 (0x1)
    ConfigFlags REG_DWORD 0 (0x0)
    Class REG_SZ LegacyDriver
    ClassGUID REG_SZ {8ECC055D-047F-11D1-A537-0000F8753ED1}
    DeviceDesc REG_SZ TDSSserv.sys
    Capabilities REG_DWORD 0 (0x0)

    HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tdssserv.sys\0000\LogConf

    HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_tdssserv.sys\0000\Control
    ActiveService REG_SZ TDSSserv.sys

    TDSS infection active!
  • VekaVeka Finland
    edited December 2008
    Thank you. It is TDSS, just as I suspected.

    I must give instructions via PM once again. Follow them and come back here.


    We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

    http://www.bleepingcomputer.com/comb...o-use-combofix

    Please ensure you read this guide carefully and install the Recovery Console first.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    Once installed, you should see a blue screen prompt that says:

    The Recovery Console was successfully installed.

    Please continue as follows:
    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    2. Click Yes to allow ComboFix to continue scanning for malware.

    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New HijackThis log.
  • edited December 2008
    Combofix log ( I will post the HiJack this log in next post):

    ComboFix 08-12-11.04 - Owner 2008-12-11 22:16:34.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.163 [GMT -5:00]
    Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Owner\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    * Created a new restore point
    * Resident AV is active

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\svhost.exe
    c:\documents and settings\All Users\Application Data\winlogon.exe
    c:\documents and settings\Owner\Application Data\gadcom
    c:\documents and settings\Owner\Application Data\gadcom\gadcom.exe
    c:\documents and settings\Owner\Application Data\GetModule
    c:\documents and settings\Owner\Local Settings\Temporary Internet Files\fbk.sts
    c:\program files\Common\helper.dll
    c:\program files\Common\helper.sig
    c:\program files\GetModule
    c:\program files\GetModule\GetModule31.exe
    c:\program files\iCheck
    c:\program files\iCheck\Uninstall.exe
    c:\windows\system32\bcgfxrdx.dll
    c:\windows\system32\bfmnsjee.dll
    c:\windows\system32\cfLTCJlm.ini
    c:\windows\system32\cfLTCJlm.ini2
    c:\windows\system32\digeste.dll
    c:\windows\system32\Drivers\TDSSmaxt.sys
    c:\windows\system32\fbrsboxx.dll
    c:\windows\system32\itvykjuq.dll
    c:\windows\system32\khvqwmpa.dll
    c:\windows\system32\macpye.dll
    c:\windows\system32\mlJCSlIY.dll
    c:\windows\system32\mlJCTLfc.dll
    c:\windows\system32\mst120.dll
    c:\windows\system32\mxryuz.dll
    c:\windows\system32\nggorz.dll
    c:\windows\system32\obvhvebk.dll
    c:\windows\system32\sxgefk.dll
    c:\windows\system32\TDSScfum.dll
    c:\windows\system32\TDSSnrsr.dll
    c:\windows\system32\TDSSofxh.dll
    c:\windows\system32\TDSSosvd.dat
    c:\windows\system32\TDSSriqp.dll
    c:\windows\system32\TDSStkdv.log
    c:\windows\system32\urqRHaWN.dll
    c:\windows\system32\vckmug.dll
    c:\windows\system32\vxduhlnp.dll
    c:\windows\system32\wpv331228549885.cpx
    c:\windows\system32\xvyltecr.dll
    c:\windows\wiaserviv.log

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    \Legacy_TDSSSERV.SYS
    \Service_TDSSserv.sys


    ((((((((((((((((((((((((( Files Created from 2008-11-12 to 2008-12-12 )))))))))))))))))))))))))))))))
    .

    2008-12-11 20:44 . 2008-12-11 20:45 1,623,552 --ahs---- c:\windows\system32\rcetlyvx.ini
    2008-12-10 17:31 . 2008-12-10 17:32 1,584,290 --ahs---- c:\windows\system32\xxobsrbf.ini
    2008-12-09 20:41 . 2008-12-09 20:41 232,960 --a
    c:\windows\system32\opdyqtkg.exe
    2008-12-09 20:35 . 2008-12-10 00:13 1,545,207 --ahs---- c:\windows\system32\cfgpdeij.ini
    2008-12-08 20:39 . 2008-12-11 20:36 2,707 --a
    c:\windows\system32\TDSSfxwp.dll
    2008-12-08 20:38 . 2008-12-08 20:38 158,208 --a
    c:\windows\system32\qcamdsxi.exe
    2008-12-08 20:33 . 2008-12-08 20:33 1,598,743 --ahs---- c:\windows\system32\qujkyvti.ini
    2008-12-07 13:00 . 2008-12-08 20:32 1,598,743 --ahs---- c:\windows\system32\krhoacch.ini
    2008-12-07 12:50 . 2008-12-07 12:50 31,744 --a
    c:\documents and settings\Owner\~.exe
    2008-12-04 08:50 . 2008-12-11 22:17 <DIR> d
    c:\program files\Common

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-12-22 02:21
    d
    w c:\program files\McAfee
    2008-12-12 03:40
    d
    w c:\program files\Microsoft AntiSpyware
    2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2007-03-05 15:49 2,189,824 ----a-w c:\program files\iPodCopy.msi
    2007-01-30 16:00 275,832,704 ----a-w c:\program files\AcroPro80_efg.exe
    2005-09-28 03:09 8,338,325 ----a-w c:\program files\tcsetup.exe
    2005-09-28 02:30 110,592 ----a-w c:\program files\setup.exe
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TCOYFReminder"="c:\progra~1\TCOYF\tcoyftray.exe" [2005-06-28 139264]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-10 155648]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-11 155648]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-11 118784]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-02 32768]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-03-27 98304]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-03-27 499712]
    "gcasServ"="c:\program files\Microsoft AntiSpyware\gcasServ.exe" [2005-07-12 473928]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
    "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
    "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
    "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
    "ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2005-07-13 933888]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-05 267064]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
    BigFix.lnk - c:\program files\BigFix\BigFix.exe [2004-09-04 1742384]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "MSACM.CTRXAUD"= ctrxaud.acm
    "VIDC.CTRX"= ctrxvid.drv

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\StubInstaller.exe"=
    "c:\\Program Files\\Quicken WillMaker Plus 2004\\qlp.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-09 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]

    2008-11-15 c:\windows\Tasks\McDefragTask.job
    - c:\program files\mcafee\mqc\QcConsol.exe [2007-01-17 18:02]

    2008-12-01 c:\windows\Tasks\McQcTask.job
    - c:\program files\mcafee\mqc\QcConsol.exe [2007-01-17 18:02]
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{C4040481-8005-4A9F-B35A-E81BC5E66FF1} - c:\windows\system32\mlJCTLfc.dll
    WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
    HKCU-Run-GetModule31 - c:\program files\GetModule\GetModule31.exe


    .
    Supplementary Scan
    .
    uStart Page = hxxp://www.espn.com/
    uInternet Connection Wizard,ShellNext = hxxp://www.usatoday.com/
    IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\jmpwqb73.default\
    FF - plugin: c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
    FF - plugin: c:\program files\iTunes\Mozilla Plugins\npitunes.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava11.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava12.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava13.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava14.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava32.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJPI150_11.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPOJI610.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-11 22:38:15
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    DLLs Loaded Under Running Processes

    - - - - - - - > 'winlogon.exe'(688)
    c:\windows\System32\BCMLogon.dll
    .
    Other Running Processes
    .
    c:\windows\system32\BRSVC01A.EXE
    c:\windows\system32\BRSS01A.EXE
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    c:\program files\Common Files\McAfee\HackerWatch\HWAPI.exe
    c:\progra~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\Common Files\McAfee\MNA\McNASvc.exe
    c:\progra~1\McAfee\VIRUSS~1\mcods.exe
    c:\progra~1\McAfee\MSC\mcpromgr.exe
    c:\progra~1\COMMON~1\McAfee\RedirSvc\RedirSvc.exe
    c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
    c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
    c:\program files\McAfee\MPF\MpfSrv.exe
    c:\windows\system32\wdfmgr.exe
    c:\windows\system32\WLTRYSVC.EXE
    c:\windows\system32\BCMWLTRY.EXE
    c:\progra~1\McAfee.com\Agent\mcagent.exe
    c:\program files\Microsoft AntiSpyware\gcasDtServ.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\program files\Java\jre1.5.0_11\bin\jucheck.exe
    .
    **************************************************************************
    .
    Completion time: 2008-12-11 22:49:09 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-12-12 03:48:49

    Pre-Run: 61,578,117,120 bytes free
    Post-Run: 61,863,100,416 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINNT="Microsoft Windows XP Home Edition" /fastdetect

    205 --- E O F --- 2008-11-13 00:25:27
  • edited December 2008
    Hijackthis log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:02:03 PM, on 12/11/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\brsvc01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\common files\mcafee\mna\mcnasvc.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
    c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\System32\bcmwltry.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
    C:\Program Files\Brother\ControlCenter2\brctrcen.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\BigFix\BigFix.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\SoftwareDistribution\Download\9f4032b7c01ffa276d9d4715007a565f\update\update.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.espn.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.usatoday.com/
    O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
    O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
    O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [TCOYFReminder] C:\PROGRA~1\TCOYF\tcoyftray.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.gateway.com
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
    O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (ZPA_TexasHoldem Object) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab55579.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab55579.cab
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
    O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
    O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

    --
    End of file - 9107 bytes
  • VekaVeka Finland
    edited December 2008
    Open notepad and copy/paste the text in the codebox below into it:
    File::
    c:\windows\system32\rcetlyvx.ini
    c:\windows\system32\xxobsrbf.ini
    c:\windows\system32\opdyqtkg.exe
    c:\windows\system32\cfgpdeij.ini
    c:\windows\system32\TDSSfxwp.dll
    c:\windows\system32\qcamdsxi.exe
    c:\windows\system32\qujkyvti.ini
    c:\windows\system32\krhoacch.ini
    c:\documents and settings\Owner\~.exe
    
    Save this as CFScript.txt


    CFScriptB-4.gif

    Refering to the picture above, drag CFScript.txt into ComboFix.exe

    When finished, it shall produce a log for you. Post that log in your next reply.
  • edited December 2008
    ComboFix 08-12-11.04 - Owner 2008-12-12 19:55:06.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.92 [GMT -5:00]
    Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Owner\Desktop\cfscript.txt
    * Created a new restore point
    * Resident AV is active


    FILE ::
    c:\documents and settings\Owner\~.exe
    c:\windows\system32\cfgpdeij.ini
    c:\windows\system32\krhoacch.ini
    c:\windows\system32\opdyqtkg.exe
    c:\windows\system32\qcamdsxi.exe
    c:\windows\system32\qujkyvti.ini
    c:\windows\system32\rcetlyvx.ini
    c:\windows\system32\TDSSfxwp.dll
    c:\windows\system32\xxobsrbf.ini
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Owner\~.exe
    c:\windows\system32\cfgpdeij.ini
    c:\windows\system32\krhoacch.ini
    c:\windows\system32\opdyqtkg.exe
    c:\windows\system32\qcamdsxi.exe
    c:\windows\system32\qujkyvti.ini
    c:\windows\system32\rcetlyvx.ini
    c:\windows\system32\TDSSfxwp.dll
    c:\windows\system32\xxobsrbf.ini

    .
    ((((((((((((((((((((((((( Files Created from 2008-11-13 to 2008-12-13 )))))))))))))))))))))))))))))))
    .

    2008-12-12 19:50 . 2008-12-12 19:50 <DIR> d
    C:\32788R22FWJFW
    2008-12-11 22:58 . 2008-12-11 22:58 <DIR> d
    c:\program files\Trend Micro
    2008-12-04 08:50 . 2008-12-11 22:17 <DIR> d
    c:\program files\Common

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-12-22 02:21
    d
    w c:\program files\McAfee
    2008-12-13 00:13
    d
    w c:\program files\Microsoft AntiSpyware
    2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-23 13:01 283,648 ----a-w c:\windows\system32\gdi32.dll
    2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
    2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
    2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
    2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
    2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
    2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
    2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
    2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
    2008-10-16 19:06 268,648 ----a-w c:\windows\system32\mucltui.dll
    2008-10-16 19:06 208,744 ----a-w c:\windows\system32\muweb.dll
    2008-10-16 10:37 659,456 ----a-w c:\windows\system32\wininet.dll
    2008-10-03 10:15 247,326 ----a-w c:\windows\system32\strmdll.dll
    2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
    2007-03-05 15:49 2,189,824 ----a-w c:\program files\iPodCopy.msi
    2007-01-30 16:00 275,832,704 ----a-w c:\program files\AcroPro80_efg.exe
    2005-09-28 03:09 8,338,325 ----a-w c:\program files\tcsetup.exe
    2005-09-28 02:30 110,592 ----a-w c:\program files\setup.exe
    .

    ((((((((((((((((((((((((((((( snapshot@2008-12-11_22.47.04.76 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-10-22 09:47:25 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP2QFE\tzchange.exe
    + 2008-10-23 10:06:59 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP3GDR\tzchange.exe
    + 2008-10-23 10:17:49 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP3QFE\tzchange.exe
    + 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB955839\spmsg.dll
    + 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB955839\spuninst.exe
    + 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB955839\update\spcustom.dll
    + 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB955839\update\update.exe
    + 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB955839\update\updspapi.dll
    + 2008-10-23 12:51:04 284,160 ----a-w c:\windows\$hf_mig$\KB956802\SP2QFE\gdi32.dll
    + 2008-10-23 12:36:14 286,720 ----a-w c:\windows\$hf_mig$\KB956802\SP3GDR\gdi32.dll
    + 2008-10-23 12:43:42 286,720 ----a-w c:\windows\$hf_mig$\KB956802\SP3QFE\gdi32.dll
    + 2008-07-08 13:02:01 17,272 ----a-w c:\windows\$hf_mig$\KB956802\spmsg.dll
    + 2008-07-08 13:02:02 231,288 ----a-w c:\windows\$hf_mig$\KB956802\spuninst.exe
    + 2008-07-08 13:02:01 26,488 ----a-w c:\windows\$hf_mig$\KB956802\update\spcustom.dll
    + 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB956802\update\update.exe
    + 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB956802\update\updspapi.dll
    - 2008-11-13 00:24:29 593,920 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
    + 2008-12-13 00:09:47 593,920 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
    - 2008-11-13 00:24:29 12,288 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    + 2008-12-13 00:09:47 12,288 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    - 2008-11-13 00:24:30 86,016 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
    + 2008-12-13 00:09:47 86,016 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
    - 2008-11-13 00:24:28 135,168 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
    + 2008-12-13 00:09:46 135,168 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
    - 2008-11-13 00:24:30 11,264 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    + 2008-12-13 00:09:47 11,264 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    - 2008-11-13 00:24:30 27,136 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    + 2008-12-13 00:09:47 27,136 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    - 2008-11-13 00:24:30 4,096 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    + 2008-12-13 00:09:47 4,096 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    - 2008-11-13 00:24:30 794,624 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
    + 2008-12-13 00:09:47 794,624 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
    - 2008-11-13 00:24:29 249,856 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
    + 2008-12-13 00:09:47 249,856 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
    - 2008-11-13 00:24:29 61,440 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
    + 2008-12-13 00:09:46 61,440 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
    - 2008-11-13 00:24:30 23,040 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    + 2008-12-13 00:09:47 23,040 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    - 2008-11-13 00:24:28 286,720 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    + 2008-12-13 00:09:46 286,720 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    - 2008-11-13 00:24:27 409,600 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    + 2008-12-13 00:09:46 409,600 ----a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    - 2008-08-20 05:38:45 1,023,488 ----a-w c:\windows\system32\browseui.dll
    + 2008-10-16 10:37:04 1,023,488 ----a-w c:\windows\system32\browseui.dll
    - 2008-08-20 05:38:39 151,040 ----a-w c:\windows\system32\cdfview.dll
    + 2008-10-16 10:37:02 151,040 ----a-w c:\windows\system32\cdfview.dll
    - 2008-08-20 05:38:40 1,054,208 ----a-w c:\windows\system32\danim.dll
    + 2008-10-16 10:37:02 1,054,208 ----a-w c:\windows\system32\danim.dll
    - 2008-08-20 05:38:45 1,023,488 -c--a-w c:\windows\system32\dllcache\browseui.dll
    + 2008-10-16 10:37:04 1,023,488 -c--a-w c:\windows\system32\dllcache\browseui.dll
    - 2008-08-20 05:38:39 151,040 -c--a-w c:\windows\system32\dllcache\cdfview.dll
    + 2008-10-16 10:37:02 151,040 -c--a-w c:\windows\system32\dllcache\cdfview.dll
    - 2008-08-20 05:38:40 1,054,208 -c--a-w c:\windows\system32\dllcache\danim.dll
    + 2008-10-16 10:37:02 1,054,208 -c--a-w c:\windows\system32\dllcache\danim.dll
    - 2008-08-20 05:38:40 357,888 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
    + 2008-10-16 10:37:02 357,888 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
    - 2008-08-20 05:38:40 205,312 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
    + 2008-10-16 10:37:02 205,312 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
    - 2008-08-20 05:38:40 55,808 -c--a-w c:\windows\system32\dllcache\extmgr.dll
    + 2008-10-16 10:37:02 55,808 -c--a-w c:\windows\system32\dllcache\extmgr.dll
    - 2008-02-20 06:51:05 282,624 -c--a-w c:\windows\system32\dllcache\gdi32.dll
    + 2008-10-23 13:01:36 283,648 -c--a-w c:\windows\system32\dllcache\gdi32.dll
    - 2008-08-19 09:30:39 18,432 -c--a-w c:\windows\system32\dllcache\iedw.exe
    + 2008-10-15 09:45:01 18,432 -c--a-w c:\windows\system32\dllcache\iedw.exe
    - 2008-08-20 05:38:41 251,392 -c--a-w c:\windows\system32\dllcache\iepeers.dll
    + 2008-10-16 10:37:02 251,392 -c--a-w c:\windows\system32\dllcache\iepeers.dll
    - 2008-08-20 05:38:41 96,256 -c--a-w c:\windows\system32\dllcache\inseng.dll
    + 2008-10-16 10:37:02 96,256 -c--a-w c:\windows\system32\dllcache\inseng.dll
    - 2008-08-20 05:38:44 16,384 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
    + 2008-10-16 10:37:03 16,384 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
    - 2004-09-22 22:45:44 96,768 -c--a-w c:\windows\system32\dllcache\logagent.exe
    + 2008-06-10 14:17:42 96,768 -c--a-w c:\windows\system32\dllcache\logagent.exe
    - 2008-08-20 05:38:47 3,060,224 -c--a-w c:\windows\system32\dllcache\mshtml.dll
    + 2008-10-16 10:37:05 3,059,712 -c--a-w c:\windows\system32\dllcache\mshtml.dll
    - 2008-08-20 05:38:43 449,024 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
    + 2008-10-16 10:37:03 449,024 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
    - 2008-08-20 05:38:41 146,432 -c--a-w c:\windows\system32\dllcache\msrating.dll
    + 2008-10-16 10:37:02 146,432 -c--a-w c:\windows\system32\dllcache\msrating.dll
    - 2008-08-20 05:38:41 532,480 -c--a-w c:\windows\system32\dllcache\mstime.dll
    + 2008-10-16 10:37:02 532,480 -c--a-w c:\windows\system32\dllcache\mstime.dll
    - 2008-08-20 05:38:41 39,424 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
    + 2008-10-16 10:37:02 39,424 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
    - 2008-08-20 05:38:42 1,494,528 -c--a-w c:\windows\system32\dllcache\shdocvw.dll
    + 2008-10-16 10:37:03 1,494,528 -c--a-w c:\windows\system32\dllcache\shdocvw.dll
    - 2008-08-20 05:38:44 474,112 -c--a-w c:\windows\system32\dllcache\shlwapi.dll
    + 2008-10-16 10:37:03 474,112 -c--a-w c:\windows\system32\dllcache\shlwapi.dll
    - 2006-08-21 14:52:08 246,814 -c--a-w c:\windows\system32\dllcache\strmdll.dll
    + 2008-10-03 10:15:47 247,326 -c--a-w c:\windows\system32\dllcache\strmdll.dll
    - 2008-08-20 05:38:45 615,936 -c--a-w c:\windows\system32\dllcache\urlmon.dll
    + 2008-10-16 10:37:04 615,936 -c--a-w c:\windows\system32\dllcache\urlmon.dll
    - 2008-08-20 05:38:43 659,456 -c--a-w c:\windows\system32\dllcache\wininet.dll
    + 2008-10-16 10:37:03 659,456 -c--a-w c:\windows\system32\dllcache\wininet.dll
    - 2004-09-22 22:46:16 1,027,072 -c--a-w c:\windows\system32\dllcache\wmnetmgr.dll
    + 2008-06-10 16:37:02 1,026,048 -c--a-w c:\windows\system32\dllcache\WMNetmgr.dll
    - 2006-12-07 06:40:49 2,362,184 -c--a-w c:\windows\system32\dllcache\wmvcore.dll
    + 2008-06-10 16:57:40 2,364,472 -c--a-w c:\windows\system32\dllcache\WMVCore.dll
    - 2008-08-20 05:38:40 357,888 ----a-w c:\windows\system32\dxtmsft.dll
    + 2008-10-16 10:37:02 357,888 ----a-w c:\windows\system32\dxtmsft.dll
    - 2008-08-20 05:38:40 205,312 ----a-w c:\windows\system32\dxtrans.dll
    + 2008-10-16 10:37:02 205,312 ----a-w c:\windows\system32\dxtrans.dll
    - 2008-08-20 05:38:40 55,808 ----a-w c:\windows\system32\extmgr.dll
    + 2008-10-16 10:37:02 55,808 ----a-w c:\windows\system32\extmgr.dll
    - 2008-08-20 05:38:41 251,392 ----a-w c:\windows\system32\iepeers.dll
    + 2008-10-16 10:37:02 251,392 ----a-w c:\windows\system32\iepeers.dll
    - 2008-08-20 05:38:41 96,256 ----a-w c:\windows\system32\inseng.dll
    + 2008-10-16 10:37:02 96,256 ----a-w c:\windows\system32\inseng.dll
    - 2008-08-20 05:38:44 16,384 ----a-w c:\windows\system32\jsproxy.dll
    + 2008-10-16 10:37:03 16,384 ----a-w c:\windows\system32\jsproxy.dll
    - 2004-09-22 22:45:44 96,768 ----a-w c:\windows\system32\logagent.exe
    + 2008-06-10 14:17:42 96,768 ----a-w c:\windows\system32\logagent.exe
    - 2008-08-20 05:38:47 3,060,224 ----a-w c:\windows\system32\mshtml.dll
    + 2008-10-16 10:37:05 3,059,712 ----a-w c:\windows\system32\mshtml.dll
    - 2008-08-20 05:38:43 449,024 ----a-w c:\windows\system32\mshtmled.dll
    + 2008-10-16 10:37:03 449,024 ----a-w c:\windows\system32\mshtmled.dll
    - 2008-08-20 05:38:41 146,432 ----a-w c:\windows\system32\msrating.dll
    + 2008-10-16 10:37:02 146,432 ----a-w c:\windows\system32\msrating.dll
    - 2008-08-20 05:38:41 532,480 ----a-w c:\windows\system32\mstime.dll
    + 2008-10-16 10:37:02 532,480 ----a-w c:\windows\system32\mstime.dll
    - 2008-08-20 05:38:41 39,424 ----a-w c:\windows\system32\pngfilt.dll
    + 2008-10-16 10:37:02 39,424 ----a-w c:\windows\system32\pngfilt.dll
    - 2008-08-20 05:38:42 1,494,528 ----a-w c:\windows\system32\shdocvw.dll
    + 2008-10-16 10:37:03 1,494,528 ----a-w c:\windows\system32\shdocvw.dll
    - 2008-08-20 05:38:44 474,112 ----a-w c:\windows\system32\shlwapi.dll
    + 2008-10-16 10:37:03 474,112 ----a-w c:\windows\system32\shlwapi.dll
    - 2008-07-08 13:02:01 17,272 ----a-w c:\windows\system32\spmsg.dll
    + 2007-07-27 14:41:40 16,760
    w c:\windows\system32\spmsg.dll
    - 2008-07-14 11:09:18 62,976 ----a-w c:\windows\system32\tzchange.exe
    + 2008-10-22 09:47:07 62,976 ----a-w c:\windows\system32\tzchange.exe
    - 2008-08-20 05:38:45 615,936 ----a-w c:\windows\system32\urlmon.dll
    + 2008-10-16 10:37:04 615,936 ----a-w c:\windows\system32\urlmon.dll
    - 2004-09-22 22:46:16 1,027,072 ----a-w c:\windows\system32\wmnetmgr.dll
    + 2008-06-10 16:37:02 1,026,048 ----a-w c:\windows\system32\WMNetmgr.dll
    - 2006-12-07 06:40:49 2,362,184 ----a-w c:\windows\system32\wmvcore.dll
    + 2008-06-10 16:57:40 2,364,472 ----a-w c:\windows\system32\WMVCore.dll
    - 2008-08-19 09:20:32 351,744 ----a-w c:\windows\system32\xpsp3res.dll
    + 2008-10-15 14:00:41 351,744 ----a-w c:\windows\system32\xpsp3res.dll
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TCOYFReminder"="c:\progra~1\TCOYF\tcoyftray.exe" [2005-06-28 139264]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-10 155648]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-11 155648]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-11 118784]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-02 32768]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-03-27 98304]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-03-27 499712]
    "gcasServ"="c:\program files\Microsoft AntiSpyware\gcasServ.exe" [2005-07-12 473928]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
    "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
    "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
    "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
    "ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2005-07-13 933888]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-05 267064]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
    BigFix.lnk - c:\program files\BigFix\BigFix.exe [2004-09-04 1742384]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "MSACM.CTRXAUD"= ctrxaud.acm
    "VIDC.CTRX"= ctrxvid.drv

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\StubInstaller.exe"=
    "c:\\Program Files\\Quicken WillMaker Plus 2004\\qlp.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-09 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]

    2008-11-15 c:\windows\Tasks\McDefragTask.job
    - c:\program files\mcafee\mqc\QcConsol.exe [2007-01-17 18:02]

    2008-12-01 c:\windows\Tasks\McQcTask.job
    - c:\program files\mcafee\mqc\QcConsol.exe [2007-01-17 18:02]
    .
    - - - - ORPHANS REMOVED - - - -

    WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)


    .
    Supplementary Scan
    .
    uStart Page = hxxp://www.espn.com/
    uInternet Connection Wizard,ShellNext = hxxp://www.usatoday.com/
    IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\jmpwqb73.default\
    FF - plugin: c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
    FF - plugin: c:\program files\iTunes\Mozilla Plugins\npitunes.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava11.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava12.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava13.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava14.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava32.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJPI150_11.dll
    FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPOJI610.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-12 19:58:25
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    DLLs Loaded Under Running Processes

    - - - - - - - > 'winlogon.exe'(684)
    c:\windows\System32\BCMLogon.dll
    .
    Completion time: 2008-12-12 20:00:04
    ComboFix-quarantined-files.txt 2008-12-13 00:59:32
    ComboFix2.txt 2008-12-12 03:49:12

    Pre-Run: 61,629,390,848 bytes free
    Post-Run: 61,611,237,376 bytes free

    295 --- E O F --- 2008-12-13 00:10:38
  • VekaVeka Finland
    edited December 2008
    Please download Malwarebytes' Anti-Malware to your desktop.
    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform full scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. please copy and paste the log into your next reply.
    • If you accidently close it, the log file is saved here and will be named like this: C:\Documents and Settings\<your username>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • edited December 2008
    Malwarebytes' Anti-Malware 1.31
    Database version: 1496
    Windows 5.1.2600 Service Pack 2

    12/13/2008 9:42:54 AM
    mbam-log-2008-12-13 (09-42-54).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 88269
    Time elapsed: 41 minute(s), 34 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 3
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 44

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\main.bho.1 (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Spyware Guard 2008 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Qoobox\Quarantine\C\Documents and Settings\Owner\Application Data\gadcom\gadcom.exe.vir (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\bcgfxrdx.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\bfmnsjee.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\fbrsboxx.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\itvykjuq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\khvqwmpa.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\macpye.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\mlJCTLfc.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\mxryuz.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\nggorz.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\obvhvebk.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\sxgefk.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\TDSScfum.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\TDSSnrsr.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\TDSSofxh.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\TDSSriqp.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\urqRHaWN.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\vckmug.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\vxduhlnp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\xvyltecr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\TDSSmaxt.sys.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000022.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000024.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000025.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000026.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000027.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000028.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000030.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000031.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000032.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000033.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000034.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000035.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000036.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000037.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000038.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000039.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000042.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000043.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000044.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000023.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{60E9B3CE-ECA7-4B34-AF90-4202F8D2CBFA}\RP1\A0000041.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Protect\track.sys (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Program Files\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
  • VekaVeka Finland
    edited December 2008
    Looks good. How is the computer working now?
  • edited December 2008
    A lot better. Thank you very much. Is there anything I should look out for in the future? I am not a big downloader of things. I am reasonably safe on the internet. How could I have gotten so affected?

    I run McAfee...but apparently it does not catch a alot. What do you recommend I do in the future to protect myself? ANy other programs?
    Again, thank you for your help.
  • VekaVeka Finland
    edited December 2008
    You're welcome!

    Please uninstall ComboFix.
    • Click Start then Run
    • Now type Combofix /u in the runbox and click OK

    Please download JavaRa and unzip it to your desktop.

    ***Please close any instances of Internet Explorer before continuing!***
    • Double-click on JavaRa.exe to start the program.
    • From the drop-down menu, choose English and click on Select.
    • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
    • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
    • A logfile will pop up. Please save it to a convenient location.
    Then download and install Java Runtime Environment (JRE) 6 Update 10.


    Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

    • Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

      You can find instructions on how to enable and re-enable system restore here:

      Windows XP System Restore Guide
    Re-enable system restore with instructions from tutorial above

    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
    • Update your AntiVirus Software and keep your other programs up-to-date Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
      You can use one of these sites to check if any updates are needed for your pc.
      Secunia Software Inspector
      F-secure Health Check

    • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
    • Install Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
      totally free but for real-time protection you will have to pay a small one-time fee. Tutorial on installing & using this product can be found below:

      Malwarebytes' Anti-Malware Setup Guide

      Malwarebytes' Anti-Malware Scanning Guide


    • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
    Follow this list and your potential for being infected again will reduce dramatically.

    Here are some additional utilities that will enhance your safety

    Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!

    The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

    Also, please read this great article by Tony Klein So How Did I Get Infected In First Place

    Happy surfing and stay clean! bigthumb.gif
  • VekaVeka Finland
    edited December 2008
    Glad we could be of assistance! The help you received here was free.

    This topic is now closed. If you wish it reopened, please send a Private Message to Trogan with a link to your thread.

    If you are not the user who started this thread, you must start your own Thread instead :)
    _______________________________
    Have we helped you with any issues you have had with your PCs or other items? If so, you can now help us by Joining Team 93 and fold for a cure.
Sign In or Register to comment.