pineapple Posted July 6, 2009 ID:96099 Share Posted July 6, 2009 Malwarebytes' Anti-Malware 1.38Database version: 2378Windows 5.1.2600 Service Pack 27/6/2009 11:36:17 AMmbam-log-2009-07-06 (11-36-17).txtScan type: Quick ScanObjects scanned: 93249Time elapsed: 11 minute(s), 41 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 0Registry Values Infected: 0Registry Data Items Infected: 0Folders Infected: 0Files Infected: 1Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:(No malicious items detected)Registry Values Infected:(No malicious items detected)Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:C:\WINDOWS\system32\drivers\str.sys (Rootkit.Agent) -> Delete on reboot.-----------------------------------------------Logfile of Trend Micro HijackThis v2.0.2Scan saved at 11:40:44 AM, on 7/6/2009Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\RunDll32.exeC:\Program Files\CyberLink\PowerDVD\PDVDServ.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\iPod\bin\iPodService.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\rundll32.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Avira\AntiVir Desktop\avguard.exeC:\Program Files\Avira\AntiVir Desktop\sched.exeC:\Program Files\Avira\AntiVir Desktop\avgnt.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeO1 - Hosts: ::1 localhostO1 - Hosts: 209.44.111.62 antispy.microsoft.comO1 - Hosts: 209.44.111.62 antiaware-pro.comO1 - Hosts: 209.44.111.62 www.antiaware-pro.comO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWndO4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttrayO4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /minO4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscriptO4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimizedO4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -hO4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quietO4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silentO4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Alison\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /cO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exeO9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1120864279749O17 - HKLM\System\CCS\Services\Tcpip\..\{8EDFC43E-BE23-4C9C-9166-CBCD477E76A3}: NameServer = 192.168.2.1O20 - AppInit_DLLs: smvteh.dllO23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exeO23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exeO23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exeO23 - Service: NVIDIA Display Driver Service (Omega 1.6693) (Q) (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe--End of file - 6433 bytes Link to post Share on other sites More sharing options...
Fatdcuk Posted July 6, 2009 ID:96140 Share Posted July 6, 2009 Please download the following tool>>>http://rootrepeal.googlepages.com/Extract from zip/rar and run Rootrepeal.exeAt the bottom of the software is a list of buttons, goto Report button and click on it.Next select scan and make sure all box's are checked(Tick) except SSDT.Press OK and next select drive to be scanned(Should be C),Copy and paste the output log generated into your next reply.Thanks in advance Link to post Share on other sites More sharing options...
pineapple Posted July 6, 2009 Author ID:96142 Share Posted July 6, 2009 ROOTREPEAL © AD, 2007-2009==================================================Scan Time: 2009/07/06 15:54Program Version: Version 1.3.0.0Windows Version: Windows XP SP2==================================================Drivers-------------------Name: 00000982Image Path: 00000982Address: 0x81C08000 Size: 41221 File Visible: No Signed: -Status: -Name: 00000982Image Path: 00000982Address: 0xEBEA3000 Size: 70656 File Visible: No Signed: -Status: Hidden from Windows API!Name: dump_nvatabus.sysImage Path: C:\WINDOWS\System32\Drivers\dump_nvatabus.sysAddress: 0xEBE2B000 Size: 81920 File Visible: No Signed: -Status: -Name: dump_WMILIB.SYSImage Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYSAddress: 0xF8A4A000 Size: 8192 File Visible: No Signed: -Status: -Name: rootrepeal.sysImage Path: C:\WINDOWS\system32\drivers\rootrepeal.sysAddress: 0xEC1D4000 Size: 49152 File Visible: No Signed: -Status: -Name: schmvhnv.sysImage Path: schmvhnv.sysAddress: 0xF8536000 Size: 61440 File Visible: No Signed: -Status: -Name: ubutuf.sysImage Path: ubutuf.sysAddress: 0xF8546000 Size: 61440 File Visible: No Signed: -Status: -Hidden/Locked Files-------------------Path: C:\WINDOWS\system32\drivers\str.sysStatus: Invisible to the Windows API!Path: c:\documents and settings\alison\local settings\temp\etilqs_poxqqwfc0qpypdkydcxgStatus: Allocation size mismatch (API: 32768, Raw: 0)Stealth Objects-------------------Object: Hidden Thread [ETHREAD: 0x81f09250, TID: 424]Process: svchost.exe (PID: 888) Address: 0x00771f3c Size: -Hidden Services-------------------Service Name: ijyjccjImage Path: C:\WINDOWS\system32\drivers\yazghhuj.sys==EOF== Link to post Share on other sites More sharing options...
Fatdcuk Posted July 7, 2009 ID:96350 Share Posted July 7, 2009 Hi ya,Please update and run MBAM quickscan.Allow it to remove what it finds then reboot!Run MBAM QS again to find out if the previous detected objects are still surviving ? Link to post Share on other sites More sharing options...
pineapple Posted July 7, 2009 Author ID:96371 Share Posted July 7, 2009 Rescan looks clean this time, thank you very much for your help Link to post Share on other sites More sharing options...
Fatdcuk Posted July 7, 2009 ID:96372 Share Posted July 7, 2009 Hi ya,If possible i would like to see a couple more reports before we sound the all clear STEP 01Please visit this webpage for instructions for downloading ComboFix to your DESKTOP : how-to-use-combofixPlease ensure you read this guide carefully and install the Recovery Console first.NOTE!!: You must save and run ComboFix.exe on your DESKTOP and not from any other folder.Also, DO NOT click the mouse or launch any other applications while this is running or it may stall the programAdditional links to download the tool:ComboFix.exeComboFix.exeComboFix.exehttp://www.forospyware.com/sUBs/ComboFix.exe' rel="external nofollow">Note: The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.Once installed, you should see a blue screen prompt that says:The Recovery Console was successfully installed.Please continue as follows:Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.Click Yes to allow ComboFix to continue scanning for malware.When the tool is finished, it will produce a report for you.Please post the C:\ComboFix.txt along with a new HijackThis log so we may continue cleaning the system. Link to post Share on other sites More sharing options...
pineapple Posted July 7, 2009 Author ID:96398 Share Posted July 7, 2009 sure thing ComboFix 09-07-06.A0 - Alison 07/07/2009 13:36.1 - NTFSx86Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.289 [GMT -4:00]Running from: c:\documents and settings\Alison\Desktop\ComboFix.exeAV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).c:\windows\system32\bdqbexul.inic:\windows\Tasks\tongdead.jobc:\windows\system32\proquota.exe was missing Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe.((((((((((((((((((((((((( Files Created from 2009-06-07 to 2009-07-07 ))))))))))))))))))))))))))))))).2009-07-07 17:39 . 2004-08-04 07:56 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe2009-07-07 17:39 . 2004-08-04 07:56 50176 ----a-w- c:\windows\system32\proquota.exe2009-07-06 15:38 . 2009-07-06 15:38 -------- d-----w- c:\program files\Trend Micro2009-07-06 14:35 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys2009-07-06 14:35 . 2009-03-24 20:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys2009-07-06 14:35 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys2009-07-06 14:35 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys2009-07-06 14:35 . 2009-07-06 14:35 -------- d-----w- c:\program files\Avira2009-07-06 14:35 . 2009-07-06 14:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira2009-07-03 14:30 . 2009-07-03 14:30 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe2009-06-12 02:36 . 2009-06-12 02:36 152576 ----a-w- c:\documents and settings\Alison\Application Data\Sun\Java\jre1.6.0_14\lzma.dll.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-07-07 01:45 . 2008-05-29 18:59 -------- d-----w- c:\program files\Steam2009-07-06 15:39 . 2005-09-22 23:12 -------- d-----w- c:\documents and settings\Alison\Application Data\uTorrent2009-07-03 14:30 . 2009-02-13 04:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware2009-06-17 15:27 . 2009-02-13 04:24 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys2009-06-17 15:27 . 2009-02-13 04:24 19096 ----a-w- c:\windows\system32\drivers\mbam.sys2009-06-12 02:37 . 2005-07-18 02:43 -------- d-----w- c:\program files\Java2009-05-21 15:33 . 2008-12-02 04:55 410984 ----a-w- c:\windows\system32\deploytk.dll2009-05-08 15:46 . 2009-05-08 15:46 55 ----a-w- c:\documents and settings\Alison\Application Data\RenPy\persistent\act1.katawa-shoujo.com2009-04-16 13:02 . 2009-04-16 13:02 152576 ----a-w- c:\documents and settings\Alison\Application Data\Sun\Java\jre1.6.0_13\lzma.dll.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"AIM"="c:\program files\AIM\aim.exe" [2006-08-01 67112]"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2006-07-31 4617720]"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]"Steam"="c:\program files\Steam\Steam.exe" [2009-07-03 1217784]"Google Update"="c:\documents and settings\Alison\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-12 133104][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-29 4620288]"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-10-29 86016]"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-06-17 414992]"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-10-29 921600]c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-7-11 113664]Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360][HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]"EnableFirewall"= 0 (0x0)[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="c:\\Program Files\\Messenger\\msmsgs.exe"="c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="c:\\Program Files\\BitTorrent\\btdownloadgui.exe"="c:\\Program Files\\Mozilla Firefox\\firefox.exe"="c:\\Documents and Settings\\Alison\\My Documents\\utorrent.exe"="c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="c:\\Program Files\\AIM\\aim.exe"="c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="c:\\Program Files\\Bonjour\\mDNSResponder.exe"="c:\\Program Files\\iTunes\\iTunes.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"8085:TCP"= 8085:TCP:drvR2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [7/6/2009 10:35 AM 108289]R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2/13/2009 12:24 AM 195856]R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2/13/2009 12:24 AM 19096]S2 ijyjccj;ijyjccj;\??\c:\windows\system32\drivers\yazghhuj.sys --> c:\windows\system32\drivers\yazghhuj.sys [?]S3 XDva277;XDva277;\??\c:\windows\system32\XDva277.sys --> c:\windows\system32\XDva277.sys [?].Contents of the 'Scheduled Tasks' folder2009-07-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1078145449-839522115-1003Core.job- c:\documents and settings\Alison\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-12 03:55]2009-07-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1078145449-839522115-1003UA.job- c:\documents and settings\Alison\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-12 03:55].- - - - ORPHANS REMOVED - - - -HKCU-Run-Skype - c:\program files\Skype\Phone\Skype.exeHKCU-Run-ares - c:\program files\Ares\Ares.exeHKLM-Run-Cmaudio - cmicnfg.cpl.------- Supplementary Scan -------.uStart Page = hxxp://www.google.com/IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000TCP: {8EDFC43E-BE23-4C9C-9166-CBCD477E76A3} = 192.168.2.1FF - ProfilePath - c:\documents and settings\Alison\Application Data\Mozilla\Firefox\Profiles\mwhwomav.default\FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/FF - plugin: c:\documents and settings\Alison\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dllFF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}---- FIREFOX POLICIES ----c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");.**************************************************************************catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2009-07-07 13:40Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... **************************************************************************.Completion time: 2009-07-07 13:43ComboFix-quarantined-files.txt 2009-07-07 17:42Pre-Run: 6,949,666,816 bytes freePost-Run: 7,772,901,376 bytes freeWindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe[boot loader]timeout=2default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS[operating systems]c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdconsmulti(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn134 --- E O F --- 2009-01-14 08:00---------------------------------------------------------------------------------------------------------------------------------------Logfile of Trend Micro HijackThis v2.0.2Scan saved at 1:47:08 PM, on 7/7/2009Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Avira\AntiVir Desktop\sched.exeC:\Program Files\Avira\AntiVir Desktop\avguard.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\CyberLink\PowerDVD\PDVDServ.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Program Files\Avira\AntiVir Desktop\avgnt.exeC:\Program Files\iPod\bin\iPodService.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\notepad.exeC:\WINDOWS\explorer.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896O1 - Hosts: ::1 localhostO1 - Hosts: 209.44.111.62 antispy.microsoft.comO1 - Hosts: 209.44.111.62 antiaware-pro.comO1 - Hosts: 209.44.111.62 www.antiaware-pro.comO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttrayO4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /minO4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quietO4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silentO4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Alison\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /cO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exeO9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1120864279749O17 - HKLM\System\CCS\Services\Tcpip\..\{8EDFC43E-BE23-4C9C-9166-CBCD477E76A3}: NameServer = 192.168.2.1O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exeO23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exeO23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exeO23 - Service: NVIDIA Display Driver Service (Omega 1.6693) (Q) (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe--End of file - 6311 bytes Link to post Share on other sites More sharing options...
Fatdcuk Posted July 7, 2009 ID:96400 Share Posted July 7, 2009 Hi ya,Please open HijackThis and Fixcheck the following entries onlyO1 - Hosts: 209.44.111.62 antispy.microsoft.comO1 - Hosts: 209.44.111.62 antiaware-pro.comO1 - Hosts: 209.44.111.62 www.antiaware-pro.comO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)Combofix report and HJT looking good to go so how is the pc now ? Link to post Share on other sites More sharing options...
pineapple Posted July 7, 2009 Author ID:96402 Share Posted July 7, 2009 Everything seems okay to me. Link to post Share on other sites More sharing options...
Fatdcuk Posted July 7, 2009 ID:96403 Share Posted July 7, 2009 Ok well i can see no more malware issue's in the logs so will give ya the all clear Here's some handy reading tho Prevention page with lots of info and tips how to prevent this in the future.And if you want to improve speed/system performance after malware removal, take a look here.Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan.We hope our application has helped you eradicate this malicious Malware. If your current anti-virus solution let this infection through please consider purchasing the PRO version of Malwarebytes' Anti-Malware for additional protection against these types of malware.Safe surfing Link to post Share on other sites More sharing options...
Recommended Posts