Jump to content


Photo

Vundo Virus


  • This topic is locked This topic is locked
19 replies to this topic

#1 redhat1283

redhat1283

    Member

  • Full Member
  • Pip
  • 9 posts

Posted 08 June 2007 - 12:47 AM

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 1:44:49 AM, on 6/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
P:\Program Files\FileZilla Server\FileZilla Server.exe
P:\Program Files\LogMeIn\x86\RaMaint.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\devldr32.exe
P:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
P:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
P:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Yapta\YaptaClient.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Documents and Settings\All Users\Application Data\uhkxefqh.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
P:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
P:\Program Files\ATI Multimedia\main\ATISched.EXE
P:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
P:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\HJT\HiJackThis_v2.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://webmail.resp...n...ge&reason=0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - P:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yapta Tagger - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {8A61098D-612B-4EF2-943D-64E920684061} - C:\WINDOWS\system32\jkkjkll.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "P:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "P:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "P:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [FileZilla Server Interface] "P:\Program Files\FileZilla Server\FileZilla Server Interface.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Yapta Tracker] C:\Program Files\Yapta\YaptaClient.exe /onstartup
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [uhkxefqh.exe] C:\Documents and Settings\All Users\Application Data\uhkxefqh.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "P:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ATI Scheduler] P:\Program Files\ATI Multimedia\main\ATISched.EXE
O4 - HKCU\..\Run: [Rbtiopyo] C:\WINDOWS\?icrosoft.NET\svchost.exe
O4 - HKCU\..\Run: [Ssdo] "C:\PROGRA~1\YMBOLS~1\wuauclt.exe" -vt ndrv
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://P:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yapta.com - {0094A600-9BDD-4019-BAFE-487284F7D476} - http://www.yapta.com/user (file missing)
O9 - Extra button: Yapta Tagger Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra 'Tools' menuitem: Yapta Tagger Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - P:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - P:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - P:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - P:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - P:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - P:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{C633BB70-A5EE-4B22-99E3-158660FF1EDC}: NameServer = 192.168.0.1
O20 - Winlogon Notify:  -  (file missing)
O20 - Winlogon Notify: instcat - C:\WINDOWS\SYSTEM32\instcat.dll
O20 - Winlogon Notify: jkkjkll - C:\WINDOWS\SYSTEM32\jkkjkll.dll
O20 - Winlogon Notify: winccf32 - winccf32.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - P:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - P:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - P:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScsiAccess - Unknown owner - P:\Program Files\Photodex\ProShowGold\ScsiAccess.exe (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 10371 bytes


NAV is popping up telling me I have a virus. Also I have multiple spyware programs telling me I have threats. I have run Adaware, spybot, spysweeper, and windows defender. This is really screwed up. Thanks.

#2 SWI Support Robot

SWI Support Robot

    Helper robot

  • SWI Bot
  • PipPipPipPipPip
  • 23,520 posts

Posted 10 June 2007 - 06:30 AM

Welcome to SWI. We apologize for the delay; our helpers have been very busy.
If you have not received help after 3 days, please CLICK HERE, and post a link to your log and the date it was originally posted.

Thank you for your patience.

[this is an automated reply]
This is an automated message. It does not count as help.

#3 Chancellor

Chancellor

    Forum Deity

  • Emeritus
  • PipPipPipPipPip
  • 3,020 posts

Posted 21 June 2007 - 03:40 PM

Hi,

Sorry youve had to wait for a few days but all of the helpers here are volunteers and weve been really busy recently.

First, please download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall

Once you have run ComboFix and before posting your log from that scan, please download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the "Scan"-tab, remove the mark at "Heuristic analysis".
  • Back at the main window, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: Posted Image
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    Posted Image
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Ill look out for your reply :)
Chancellor

Please consider a donation to help Support SWI
Malware Complaints - Report them here and fight back!
Member of ASAP Since 2006 (Alliance of Security Analysis Professionals)
Please read the FAQ and the article "So how did I get infected in the first place?".

#4 redhat1283

redhat1283

    Member

  • Full Member
  • Pip
  • 9 posts

Posted 22 June 2007 - 06:32 AM

ComboFix 07-06-18 - C:\Documents and Settings\Redhat\Desktop\ComboFix.exe
"Redhat" - 2007-06-21 23:05:38 - Service Pack 2 NTFS


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\srutv.bak1
C:\WINDOWS\system32\srutv.bak2
C:\WINDOWS\system32\srutv.ini
C:\WINDOWS\system32\srutv.bak1
C:\WINDOWS\system32\srutv.bak2
C:\WINDOWS\system32\srutv.ini
C:\WINDOWS\system32\vturs.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((( Files Created from 2007-05-22 to 2007-06-22 )))))))))))))))))))))))))))))))


2007-06-19 13:46 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
2007-06-18 21:20 2,560 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-18 20:59 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-15 02:23 24,643 --a------ C:\WINDOWS\system32\vtutrqq.dll
2007-06-10 22:24 30,592 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2007-06-10 22:24 12,800 --------- C:\WINDOWS\system32\drivers\usb8023x.sys
2007-06-09 01:38 <DIR> d-------- C:\DOCUME~1\Redhat\APPLIC~1\SUPERAntiSpyware.com
2007-06-09 01:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-06-09 01:10 <DIR> d-------- C:\Program Files\Windows Defender
2007-06-08 21:59 <DIR> d--hs---- C:\WINDOWS\system32\Sys32
2007-06-08 21:56 <DIR> d-------- C:\DOCUME~1\Redhat\APPLIC~1\Photodex
2007-06-08 17:40 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-06-08 15:31 <DIR> d-------- C:\VundoFix Backups
2007-06-07 22:56 <DIR> d-------- C:\Program Files\Lavasoft
2007-06-07 22:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-07 22:55 164 --a------ C:\install.dat
2007-06-07 16:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-06-07 00:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-04 15:18 9,344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 15:17 8,320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 15:14 6,272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-29 23:35 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-05-29 23:26 83,552 --a------ C:\WINDOWS\system32\LMIRfsClientNP.dll
2007-05-29 23:26 46,112 --a------ C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
2007-05-29 23:26 <DIR> d-------- C:\Program Files\LogMeIn
2007-05-29 23:05 <DIR> d-------- C:\Program Files\Picasa2
2007-05-26 00:08 <DIR> d-------- C:\Program Files\Yapta
2007-05-26 00:08 <DIR> d-------- C:\DOCUME~1\Redhat\APPLIC~1\Yapta


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-22 03:10:58 -------- d-----w C:\Program Files\Symantec AntiVirus
2007-06-13 03:35:38 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-06-13 02:29:57 5 ----a-w C:\WINDOWS\system32\SySVid.dat
2007-06-13 02:27:04 3,082 ----a-w C:\WINDOWS\system32\affv11300p4now.sys
2007-06-12 22:22:50 14,912 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-06-07 04:02:25 -------- d-----w C:\Program Files\X-Charge
2007-06-07 04:01:24 -------- d-----w C:\Program Files\Common Files\Intuit
2007-06-07 04:01:01 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-07 03:46:00 -------- d-----w C:\Program Files\Microsoft.NET
2007-06-07 03:44:40 -------- d-----w C:\Program Files\Microsoft SQL Server
2007-06-07 03:39:45 -------- d-----w C:\Program Files\Google
2007-05-26 04:28:46 6,852 ----a-w C:\WINDOWS\mozver.dat
2007-05-25 19:22:10 26,176 ----a-w C:\WINDOWS\system32\LMIport.dll
2007-05-25 19:22:08 10,304 ----a-w C:\WINDOWS\system32\LMImirr2.dll
2007-05-25 19:22:06 24,000 ----a-w C:\WINDOWS\system32\LMImirr.dll
2007-05-25 19:22:04 63,040 ----a-w C:\WINDOWS\system32\LMIinit.dll
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-13 19:19:52 7,680 ----a-w C:\WINDOWS\system32\lsdelete.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{2020dfef-8c87-4229-aa41-549d82210355}=C:\Program Files\Yapta\YaptaOverlay.dll [2007-05-17 15:11]
{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}=C:\WINDOWS\system32\vtutrqq.dll [2007-06-15 02:23]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-03-12 15:18]
"QuickTime Task"="P:\Program Files\QuickTime\qttask.exe" [2005-09-14 23:33]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"Acrobat Assistant 7.0"="P:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52]
"AtiPTA"="atiptaxx.exe" [2001-10-27 01:32 C:\WINDOWS\system32\atiptaxx.exe]
"EEventManager"="C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2005-04-08 15:09]
"LogMeIn GUI"="P:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03]
"Yapta Tracker"="C:\Program Files\Yapta\YaptaClient.exe" [2007-05-17 15:11]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-05-02 02:08]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"H/PC Connection Agent"="P:\PROGRA~1\MICROS~2\wcescomm.exe" [2006-11-13 13:39]
"ATI Scheduler"="P:\Program Files\ATI Multimedia\main\ATISched.EXE" [2001-10-02 16:19]
"Rbtiopyo"="C:\WINDOWS\?icrosoft.NET\svchost.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"="C:\WINDOWS\system32\vtutrqq.dll" [2007-06-15 02:23]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtutrqq]
vtutrqq.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ ]
 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{256baa93-24a0-11da-8415-806d6172696f}]
AutoRun\command- I:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{256baa94-24a0-11da-8415-806d6172696f}]
AutoRun\command- J:\setup.exe


Contents of the 'Scheduled Tasks' folder
2007-06-21 05:35:24 C:\WINDOWS\tasks\MP Scheduled Scan.job
2006-07-03 05:34:48 C:\WINDOWS\tasks\TV.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-21 23:10:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001105-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]


Completion time: 2007-06-21 23:13:04 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-21 23:12
C:\ComboFix2.txt ... 2007-06-18 21:07

--- E O F ---


********************
********************
********************

Logfile of HijackThis v1.99.1
Scan saved at 7:27:15 AM, on 6/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
P:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
P:\Program Files\LogMeIn\x86\RaMaint.exe
P:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Yapta\YaptaClient.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
P:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
P:\PROGRA~1\MICROS~2\wcescomm.exe
P:\Program Files\ATI Multimedia\main\ATISched.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
P:\PROGRA~1\MICROS~2\rapimgr.exe
P:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "P:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "P:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "P:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [Yapta Tracker] C:\Program Files\Yapta\YaptaClient.exe /onstartup
O4 - HKLM\..\Run: [Picasa Media Detector] "C:\Program Files\Picasa2\PicasaMediaDetector.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] P:\PROGRA~1\MICROS~2\wcescomm.exe
O4 - HKCU\..\Run: [ATI Scheduler] "P:\Program Files\ATI Multimedia\main\ATISched.EXE"
O4 - HKCU\..\Run: [Rbtiopyo] C:\WINDOWS\?icrosoft.NET\svchost.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://P:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yapta.com - {0094A600-9BDD-4019-BAFE-487284F7D476} - http://www.yapta.com/user (file missing)
O9 - Extra button: Yapta Tagger Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra 'Tools' menuitem: Yapta Tagger Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - P:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - P:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - P:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{C633BB70-A5EE-4B22-99E3-158660FF1EDC}: NameServer = 192.168.0.1
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - P:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - P:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScsiAccess - Unknown owner - P:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe


******************
******************
******************



vtutrqq.dll;c:\windows\system32;Trojan.Virtumod;Will be cured after reboot.;
ddaby.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod;Deleted.;
instcat.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Proxy.1802;Deleted.;
winowl32.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Mezzia;Deleted.;
A0077334.dll;C:\System Volume Information\_restore{B43C1781-54A7-4CC9-98B9-431183B7472C}\RP813;Trojan.Proxy.1802;Deleted.;
A0077335.dll;C:\System Volume Information\_restore{B43C1781-54A7-4CC9-98B9-431183B7472C}\RP813;Trojan.Virtumod;Deleted.;
A0077336.dll;C:\System Volume Information\_restore{B43C1781-54A7-4CC9-98B9-431183B7472C}\RP813;Trojan.Mezzia;Deleted.;
A0077484.exe;C:\System Volume Information\_restore{B43C1781-54A7-4CC9-98B9-431183B7472C}\RP816;Trojan.EzulaAd;Deleted.;
A0077602.exe;C:\System Volume Information\_restore{B43C1781-54A7-4CC9-98B9-431183B7472C}\RP817;Tool.Prockill;Incurable.Moved.;
A0077604.exe;C:\System Volume Information\_restore{B43C1781-54A7-4CC9-98B9-431183B7472C}\RP817;Tool.ShutDown.11;Incurable.Moved.;
vtutrqq.dll;C:\WINDOWS\system32;Trojan.Virtumod;Will be cured after reboot.;







Thanks for all of your help. I'm usually pretty good about this stuff and cleaning it up but this time i'm in over my head.

#5 redhat1283

redhat1283

    Member

  • Full Member
  • Pip
  • 9 posts

Posted 22 June 2007 - 06:34 AM

As a note I do run LogMeIn knowingly.

#6 Chancellor

Chancellor

    Forum Deity

  • Emeritus
  • PipPipPipPipPip
  • 3,020 posts

Posted 22 June 2007 - 04:56 PM

Hello again,

Thanks for getting back to me, we are making progress!

There ae a couplt of puzzling lines in your log, which I need a second opinion on from some of our experts - in order to make sure that we have really got everything, so please hang in there for a little while and I will get back to you as soon as I have an answer!

Thanks :D
Chancellor

Please consider a donation to help Support SWI
Malware Complaints - Report them here and fight back!
Member of ASAP Since 2006 (Alliance of Security Analysis Professionals)
Please read the FAQ and the article "So how did I get infected in the first place?".

#7 Chancellor

Chancellor

    Forum Deity

  • Emeritus
  • PipPipPipPipPip
  • 3,020 posts

Posted 23 June 2007 - 05:29 AM

Hi again,

I have some revised instructions for you I would like to see an export of one of your systems Registry keys:

To do that, please open Notepad and copy and paste the following bold text into it:

regedit /e notify.txt "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify"

Save this file as look.bat, choose to save as type *all files and place it on your desktop.

This is how the batch file must look after youve created it: Posted Image

Doubleclick on look.bat and then e-mail the file it produces to submit [ AT ] spywarefix [ DOT ] org, so that our experts can review it.

In your e-mail, please give a link to your log and mention that the file was requested by Chancellor.

I will get back to you as soon as possible thereafter.

Thanks for your patience!

:D

Edited by Chancellor, 23 June 2007 - 02:19 PM.

Chancellor

Please consider a donation to help Support SWI
Malware Complaints - Report them here and fight back!
Member of ASAP Since 2006 (Alliance of Security Analysis Professionals)
Please read the FAQ and the article "So how did I get infected in the first place?".

#8 redhat1283

redhat1283

    Member

  • Full Member
  • Pip
  • 9 posts

Posted 23 June 2007 - 11:14 PM

Thanks. The e-mail has been sent. I am getting virus notifications from NAV whenever I open firefox. I then get popups through IE. It's getting close to reformat time.

#9 Chancellor

Chancellor

    Forum Deity

  • Emeritus
  • PipPipPipPipPip
  • 3,020 posts

Posted 24 June 2007 - 09:49 AM

Hi,

We don't seem to have received your e-mail.

Could you please resend the file to submit[AT]spywarefix[DOT]org

I do hope that it won't be necessary for your to have to reformat, but of course, the final decision is yours. If you are going to go down that route, please could you let me know?

Thanks :)
Chancellor

Please consider a donation to help Support SWI
Malware Complaints - Report them here and fight back!
Member of ASAP Since 2006 (Alliance of Security Analysis Professionals)
Please read the FAQ and the article "So how did I get infected in the first place?".

#10 redhat1283

redhat1283

    Member

  • Full Member
  • Pip
  • 9 posts

Posted 24 June 2007 - 09:55 AM

That would be because I used com not org. I would like to avoid reformatting if it's at all possible. Thanks.

#11 Chancellor

Chancellor

    Forum Deity

  • Emeritus
  • PipPipPipPipPip
  • 3,020 posts

Posted 24 June 2007 - 07:13 PM

Hello again,

Thanks for e-mailing the file I asked for, we have now got it!

Please ensure that ComboFix is on your desktop:
  • Then, please open Notepad (Start > Run > type notepad in the Open field > OK) and copy and paste the text present inside the code box below:

    File::
    C:\WINDOWS\system32\vtutrqq.dll
    C:\WINDOWS\system32\jkhhf.dll
    REGISTRY::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Rbtiopyo"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ ]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhhf]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtutrqq]
    
  • Save this as ComboFix-Do.txt and change the "Save as type" to "All Files" and place it on your desktop.

    Posted Image


  • Referring to the screenshot above, drag ComboFix-Do.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Thanks :D
Chancellor

Please consider a donation to help Support SWI
Malware Complaints - Report them here and fight back!
Member of ASAP Since 2006 (Alliance of Security Analysis Professionals)
Please read the FAQ and the article "So how did I get infected in the first place?".

#12 redhat1283

redhat1283

    Member

  • Full Member
  • Pip
  • 9 posts

Posted 24 June 2007 - 09:04 PM

ComboFix 07-06-18 - C:\Documents and Settings\Redhat\Desktop\ComboFix.exe
"Redhat" - 2007-06-24 21:54:16 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\Redhat\Desktop\ComboFix-Do.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\vtutrqq.dll


((((((((((((((((((((((((( Files Created from 2007-05-25 to 2007-06-25 )))))))))))))))))))))))))))))))


2007-06-22 11:15 1,901,003 --ahs---- C:\WINDOWS\system32\fhhkj.bak2
2007-06-21 23:33 <DIR> d-------- C:\DOCUME~1\Redhat\DoctorWeb
2007-06-21 23:15 6,530 --ahs---- C:\WINDOWS\system32\fhhkj.bak1
2007-06-18 21:20 2,560 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-18 20:59 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-10 22:24 30,592 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2007-06-10 22:24 12,800 --------- C:\WINDOWS\system32\drivers\usb8023x.sys
2007-06-09 01:38 <DIR> d-------- C:\DOCUME~1\Redhat\APPLIC~1\SUPERAntiSpyware.com
2007-06-09 01:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-06-09 01:10 <DIR> d-------- C:\Program Files\Windows Defender
2007-06-08 21:59 <DIR> d--hs---- C:\WINDOWS\system32\Sys32
2007-06-08 21:56 <DIR> d-------- C:\DOCUME~1\Redhat\APPLIC~1\Photodex
2007-06-08 17:40 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-06-08 15:31 <DIR> d-------- C:\VundoFix Backups
2007-06-07 22:56 <DIR> d-------- C:\Program Files\Lavasoft
2007-06-07 22:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-07 22:55 164 --a------ C:\install.dat
2007-06-07 16:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-06-07 00:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-04 15:18 9,344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 15:17 8,320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 15:14 6,272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-29 23:35 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-05-29 23:26 83,552 --a------ C:\WINDOWS\system32\LMIRfsClientNP.dll
2007-05-29 23:26 46,112 --a------ C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
2007-05-29 23:26 <DIR> d-------- C:\Program Files\LogMeIn
2007-05-29 23:05 <DIR> d-------- C:\Program Files\Picasa2
2007-05-26 00:08 <DIR> d-------- C:\Program Files\Yapta
2007-05-26 00:08 <DIR> d-------- C:\DOCUME~1\Redhat\APPLIC~1\Yapta


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-25 01:59:18 -------- d-----w C:\Program Files\Symantec AntiVirus
2007-06-13 03:35:38 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-06-13 02:29:57 5 ----a-w C:\WINDOWS\system32\SySVid.dat
2007-06-13 02:27:04 3,082 ----a-w C:\WINDOWS\system32\affv11300p4now.sys
2007-06-12 22:22:50 14,912 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-06-07 04:02:25 -------- d-----w C:\Program Files\X-Charge
2007-06-07 04:01:24 -------- d-----w C:\Program Files\Common Files\Intuit
2007-06-07 04:01:01 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-07 03:46:00 -------- d-----w C:\Program Files\Microsoft.NET
2007-06-07 03:44:40 -------- d-----w C:\Program Files\Microsoft SQL Server
2007-06-07 03:39:45 -------- d-----w C:\Program Files\Google
2007-05-26 04:28:46 6,852 ----a-w C:\WINDOWS\mozver.dat
2007-05-25 19:22:10 26,176 ----a-w C:\WINDOWS\system32\LMIport.dll
2007-05-25 19:22:08 10,304 ----a-w C:\WINDOWS\system32\LMImirr2.dll
2007-05-25 19:22:06 24,000 ----a-w C:\WINDOWS\system32\LMImirr.dll
2007-05-25 19:22:04 63,040 ----a-w C:\WINDOWS\system32\LMIinit.dll
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-13 19:19:52 7,680 ----a-w C:\WINDOWS\system32\lsdelete.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{0E83ED5E-08D3-401B-9F6B-FFB237F50C64}=C:\WINDOWS\system32\jkhhf.dll []
{2020dfef-8c87-4229-aa41-549d82210355}=C:\Program Files\Yapta\YaptaOverlay.dll [2007-05-17 15:11]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-03-12 15:18]
"QuickTime Task"="P:\Program Files\QuickTime\qttask.exe" [2005-09-14 23:33]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"Acrobat Assistant 7.0"="P:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52]
"AtiPTA"="atiptaxx.exe" [2001-10-27 01:32 C:\WINDOWS\system32\atiptaxx.exe]
"EEventManager"="C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2005-04-08 15:09]
"LogMeIn GUI"="P:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03]
"Yapta Tracker"="C:\Program Files\Yapta\YaptaClient.exe" [2007-05-17 15:11]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-05-02 02:08]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"H/PC Connection Agent"="P:\PROGRA~1\MICROS~2\wcescomm.exe" [2006-11-13 13:39]
"ATI Scheduler"="P:\Program Files\ATI Multimedia\main\ATISched.EXE" [2001-10-02 16:19]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ ]
 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{256baa93-24a0-11da-8415-806d6172696f}]
AutoRun\command- I:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{256baa94-24a0-11da-8415-806d6172696f}]
AutoRun\command- J:\setup.exe


Contents of the 'Scheduled Tasks' folder
2007-06-24 06:16:30 C:\WINDOWS\tasks\MP Scheduled Scan.job
2006-07-03 05:34:48 C:\WINDOWS\tasks\TV.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-24 21:58:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001105-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]


Completion time: 2007-06-24 22:01:14 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-24 22:00
C:\ComboFix2.txt ... 2007-06-21 23:13
C:\ComboFix3.txt ... 2007-06-18 21:07

--- E O F ---





I created the file and ran it as you instructed. When I pasted the code in I got random box characters which I deleted next to the omega and funky A. I'll wait for the next step. Thanks again.

#13 Chancellor

Chancellor

    Forum Deity

  • Emeritus
  • PipPipPipPipPip
  • 3,020 posts

Posted 26 June 2007 - 06:07 PM

Hello,

Thanks for doing that - unfortunately, as you deleted the random characters from the script, those keys still exist in your system's Registry.

Normally, we would fix them using HijackThis, but as those lines don't show up in the HijackThis log, could you please run the instructions again from my previous post using the script below:

REGISTRY::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ ]
Please don't delete the characters at the end!

Once you have done that, could I see the ComboFix log and a fresh HijackThis log?

Thanks :)
Chancellor

Please consider a donation to help Support SWI
Malware Complaints - Report them here and fight back!
Member of ASAP Since 2006 (Alliance of Security Analysis Professionals)
Please read the FAQ and the article "So how did I get infected in the first place?".

#14 redhat1283

redhat1283

    Member

  • Full Member
  • Pip
  • 9 posts

Posted 26 June 2007 - 10:35 PM

ComboFix 07-06-18 - C:\Documents and Settings\Redhat\Desktop\ComboFix.exe
"Redhat" - 2007-06-26 23:25:14 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\Redhat\Desktop\ComboFix-Do.txt


((((((((((((((((((((((((( Files Created from 2007-05-27 to 2007-06-27 )))))))))))))))))))))))))))))))


2007-06-22 11:15 1,901,003 --ahs---- C:\WINDOWS\system32\fhhkj.bak2
2007-06-21 23:33 <DIR> d-------- C:\DOCUME~1\Redhat\DoctorWeb
2007-06-21 23:15 6,530 --ahs---- C:\WINDOWS\system32\fhhkj.bak1
2007-06-18 21:20 2,560 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-18 20:59 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-10 22:24 30,592 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2007-06-10 22:24 12,800 --------- C:\WINDOWS\system32\drivers\usb8023x.sys
2007-06-09 01:38 <DIR> d-------- C:\DOCUME~1\Redhat\APPLIC~1\SUPERAntiSpyware.com
2007-06-09 01:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-06-09 01:10 <DIR> d-------- C:\Program Files\Windows Defender
2007-06-08 21:59 <DIR> d--hs---- C:\WINDOWS\system32\Sys32
2007-06-08 21:56 <DIR> d-------- C:\DOCUME~1\Redhat\APPLIC~1\Photodex
2007-06-08 17:40 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-06-08 15:31 <DIR> d-------- C:\VundoFix Backups
2007-06-07 22:56 <DIR> d-------- C:\Program Files\Lavasoft
2007-06-07 22:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-07 22:55 164 --a------ C:\install.dat
2007-06-07 16:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-06-07 00:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-04 15:18 9,344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 15:17 8,320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 15:14 6,272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-29 23:35 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-05-29 23:26 83,552 --a------ C:\WINDOWS\system32\LMIRfsClientNP.dll
2007-05-29 23:26 46,112 --a------ C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
2007-05-29 23:26 <DIR> d-------- C:\Program Files\LogMeIn
2007-05-29 23:05 <DIR> d-------- C:\Program Files\Picasa2
2007-05-26 00:08 <DIR> d-------- C:\Program Files\Yapta
2007-05-26 00:08 <DIR> d-------- C:\DOCUME~1\Redhat\APPLIC~1\Yapta


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-25 01:59:20 -------- d-----w C:\Program Files\Symantec AntiVirus
2007-06-13 03:35:38 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-06-13 02:29:57 5 ----a-w C:\WINDOWS\system32\SySVid.dat
2007-06-13 02:27:04 3,082 ----a-w C:\WINDOWS\system32\affv11300p4now.sys
2007-06-12 22:22:50 14,912 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-06-07 04:02:25 -------- d-----w C:\Program Files\X-Charge
2007-06-07 04:01:24 -------- d-----w C:\Program Files\Common Files\Intuit
2007-06-07 04:01:01 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-07 03:46:00 -------- d-----w C:\Program Files\Microsoft.NET
2007-06-07 03:44:40 -------- d-----w C:\Program Files\Microsoft SQL Server
2007-06-07 03:39:45 -------- d-----w C:\Program Files\Google
2007-05-26 04:28:46 6,852 ----a-w C:\WINDOWS\mozver.dat
2007-05-25 19:22:10 26,176 ----a-w C:\WINDOWS\system32\LMIport.dll
2007-05-25 19:22:08 10,304 ----a-w C:\WINDOWS\system32\LMImirr2.dll
2007-05-25 19:22:06 24,000 ----a-w C:\WINDOWS\system32\LMImirr.dll
2007-05-25 19:22:04 63,040 ----a-w C:\WINDOWS\system32\LMIinit.dll
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-13 19:19:52 7,680 ----a-w C:\WINDOWS\system32\lsdelete.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{0E83ED5E-08D3-401B-9F6B-FFB237F50C64}=C:\WINDOWS\system32\jkhhf.dll []
{2020dfef-8c87-4229-aa41-549d82210355}=C:\Program Files\Yapta\YaptaOverlay.dll [2007-05-17 15:11]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-03-12 15:18]
"QuickTime Task"="P:\Program Files\QuickTime\qttask.exe" [2005-09-14 23:33]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"Acrobat Assistant 7.0"="P:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52]
"AtiPTA"="atiptaxx.exe" [2001-10-27 01:32 C:\WINDOWS\system32\atiptaxx.exe]
"EEventManager"="C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2005-04-08 15:09]
"LogMeIn GUI"="P:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03]
"Yapta Tracker"="C:\Program Files\Yapta\YaptaClient.exe" [2007-05-17 15:11]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-05-02 02:08]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"H/PC Connection Agent"="P:\PROGRA~1\MICROS~2\wcescomm.exe" [2006-11-13 13:39]
"ATI Scheduler"="P:\Program Files\ATI Multimedia\main\ATISched.EXE" [2001-10-02 16:19]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ ]
 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{256baa93-24a0-11da-8415-806d6172696f}]
AutoRun\command- I:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{256baa94-24a0-11da-8415-806d6172696f}]
AutoRun\command- J:\setup.exe


Contents of the 'Scheduled Tasks' folder
2007-06-26 05:38:17 C:\WINDOWS\tasks\MP Scheduled Scan.job
2006-07-03 05:34:48 C:\WINDOWS\tasks\TV.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-26 23:26:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

cmd.exe [1600]


scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001105-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]


Completion time: 2007-06-26 23:27:58
C:\ComboFix-quarantined-files.txt ... 2007-06-26 23:27
C:\ComboFix2.txt ... 2007-06-24 22:01
C:\ComboFix3.txt ... 2007-06-21 23:13

--- E O F ---




I copied and pasted the code exactly. The last time I did it it brought up those little boxes like there were unrecognized characters that it couldn't display.

#15 Chancellor

Chancellor

    Forum Deity

  • Emeritus
  • PipPipPipPipPip
  • 3,020 posts

Posted 30 June 2007 - 04:49 AM

Hello again and sorry for the delay in my reply.

To get rid of that last entry, please follow these steps:
  • Click Start Run type: Notepad OK
  • Copy (Ctrl+C) and paste (Ctrl+V) the following text inside the quote box below (starting with REGEDIT4) to Notepad.

    REGEDIT4
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ ]
    
    
  • Make sure there are no black spaces before REGEDIT4 and there should be one blank line at the end.
  • Click File at the top and then choose Save As.
  • Change Save As Type to All Files.
  • Name it FixME.reg and save it on your desktop.
  • Its icon should look like this : Posted Image
  • Double click FixME.reg. It will ask you if you want to merge it to the registry, click Yes.
Once you have done that, please can I see a fresh HijackThis log?

Thanks :D
Chancellor

Please consider a donation to help Support SWI
Malware Complaints - Report them here and fight back!
Member of ASAP Since 2006 (Alliance of Security Analysis Professionals)
Please read the FAQ and the article "So how did I get infected in the first place?".

#16 redhat1283

redhat1283

    Member

  • Full Member
  • Pip
  • 9 posts

Posted 30 June 2007 - 08:48 AM

Logfile of HijackThis v1.99.1
Scan saved at 9:51:26 AM, on 6/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
P:\Program Files\LogMeIn\x86\RaMaint.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
P:\Program Files\LogMeIn\x86\LogMeIn.exe
P:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
P:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Yapta\YaptaClient.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
P:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
P:\PROGRA~1\MICROS~2\wcescomm.exe
P:\Program Files\ATI Multimedia\main\ATISched.EXE
P:\PROGRA~1\MICROS~2\rapimgr.exe
C:\WINDOWS\System32\svchost.exe
P:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
P:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - P:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0E83ED5E-08D3-401B-9F6B-FFB237F50C64} - C:\WINDOWS\system32\jkhhf.dll (file missing)
O2 - BHO: Yapta Tagger - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "P:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "P:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "P:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [Yapta Tracker] C:\Program Files\Yapta\YaptaClient.exe /onstartup
O4 - HKLM\..\Run: [Picasa Media Detector] "C:\Program Files\Picasa2\PicasaMediaDetector.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] P:\PROGRA~1\MICROS~2\wcescomm.exe
O4 - HKCU\..\Run: [ATI Scheduler] "P:\Program Files\ATI Multimedia\main\ATISched.EXE"
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://P:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yapta.com - {0094A600-9BDD-4019-BAFE-487284F7D476} - http://www.yapta.com/user (file missing)
O9 - Extra button: Yapta Tagger Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra 'Tools' menuitem: Yapta Tagger Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - P:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - P:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - P:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{C633BB70-A5EE-4B22-99E3-158660FF1EDC}: NameServer = 192.168.0.1
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify:   -   (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - P:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - P:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScsiAccess - Unknown owner - P:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe



Thanks for all the help.

#17 Chancellor

Chancellor

    Forum Deity

  • Emeritus
  • PipPipPipPipPip
  • 3,020 posts

Posted 30 June 2007 - 01:07 PM

Hi,

Thanks for that, we are getting there!

Please run HijackThis again and put a check next to the following entries:

O2 - BHO: (no name) - {0E83ED5E-08D3-401B-9F6B-FFB237F50C64} - C:\WINDOWS\system32\jkhhf.dll (file missing)
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - (no file)
O20 - Winlogon Notify:   -   (file missing)


Now, having checked those entries, close all other open windows and browsers EXCEPT HijackThis and click on the Fix checked button.

Then please re-boot your computer and post what should be a final HijackThis log!

Ill look out for your reply.

:)
Chancellor

Please consider a donation to help Support SWI
Malware Complaints - Report them here and fight back!
Member of ASAP Since 2006 (Alliance of Security Analysis Professionals)
Please read the FAQ and the article "So how did I get infected in the first place?".

#18 redhat1283

redhat1283

    Member

  • Full Member
  • Pip
  • 9 posts

Posted 01 July 2007 - 10:51 AM

Logfile of HijackThis v1.99.1
Scan saved at 11:54:17 AM, on 7/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
P:\Program Files\LogMeIn\x86\RaMaint.exe
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
P:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
P:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
P:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Yapta\YaptaClient.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Windows Defender\MSASCui.exe
P:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
P:\PROGRA~1\MICROS~2\wcescomm.exe
P:\Program Files\ATI Multimedia\main\ATISched.EXE
P:\PROGRA~1\MICROS~2\rapimgr.exe
C:\WINDOWS\System32\svchost.exe
P:\Program Files\Mozilla Firefox\firefox.exe
P:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
P:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - P:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yapta Tagger - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "P:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "P:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "P:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [Yapta Tracker] C:\Program Files\Yapta\YaptaClient.exe /onstartup
O4 - HKLM\..\Run: [Picasa Media Detector] "C:\Program Files\Picasa2\PicasaMediaDetector.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] P:\PROGRA~1\MICROS~2\wcescomm.exe
O4 - HKCU\..\Run: [ATI Scheduler] "P:\Program Files\ATI Multimedia\main\ATISched.EXE"
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://P:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://P:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yapta.com - {0094A600-9BDD-4019-BAFE-487284F7D476} - http://www.yapta.com/user (file missing)
O9 - Extra button: Yapta Tagger Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra 'Tools' menuitem: Yapta Tagger Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - P:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - P:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - P:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{C633BB70-A5EE-4B22-99E3-158660FF1EDC}: NameServer = 192.168.0.1
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - P:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - P:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScsiAccess - Unknown owner - P:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe




Thank you very much for all of your help. It seems as if everything is cleaned up now. Thanks again.

#19 Chancellor

Chancellor

    Forum Deity

  • Emeritus
  • PipPipPipPipPip
  • 3,020 posts

Posted 01 July 2007 - 01:08 PM

Hello and congratulations - your log looks clean :hyper:

There are just a few remaining steps before we let you go!

Firstly, you should update your Sun Java Runtime Environment as the previous versions are vulnerable to malware:

Although, before updating Java, you need to uninstall the previous version; To do that:
  • Click on Start > Control Panel
  • Select Add or Remove Programs
  • Search the list for any previous versions of Java(The J2SE Runtime Environment)
  • It should have a Posted Image icon next to it
  • Select it and click Remove
  • Once you have done that, you can download the latest version from HERE
Next, run Disk Cleanup
  • Go to Start > Run and type the command Cleanmgr > then click OK
  • If you have more than one hard drive, select the drive Windows is installed on and click OK
  • When Disk Cleanup opens, select the More Options tab
  • In the System Restore section (bottom of window), click Cleanup
  • Then in the confirmation window that opens, click Yes
  • Now click on the Disk Cleanup tab and select the following items:
    • Downloaded Program Files
    • Temporary Internet Files
    • Recycle Bin
    • Temporary Files
  • Click OK
  • Finally, in the confirmation window, select Yes (Disk Cleanup will then close).
Then, create a Restore Point
  • Go to Start > Programs > Accessories > System Tools > System Restore
  • Choose Create a Restore Point and then click Next.
  • In the box for Restore point description, enter a descriptive name and click Create
  • When the Restore Point Created window appears, click Close
Also, there are several free utilities you can use to help keep malware off your system:

A HOSTS file will prevent Internet Explorer from communicating with sites known to be associated with adware or spyware. A good regularly updated HOST file is the MVPS HOSTS File, available from http://www.mvps.org/...p2002/hosts.htm.

IE/SPYAD adds sites associated with ads and spyware to your Internet Explorers Restricted Zone and you can download that at http://www.spywarewa...uc/resource.htm.

SpywareBlaster by JavaCool is a free non-resident utility to prevent the installation of ActiveX-based malware. For real-time protection, there is SpywareGuard. Both are available from http://www.javacools...m/products.html.

In conclusion, you should also read the article So how did I get infected in the first place?

Once you've taken these precautions, if you find that you have any lingering problems or if you've experienced any difficulties since the fix, please let me know and post a fresh log for me to have a look at!

With best wishes for the future,

:D
Chancellor

Please consider a donation to help Support SWI
Malware Complaints - Report them here and fight back!
Member of ASAP Since 2006 (Alliance of Security Analysis Professionals)
Please read the FAQ and the article "So how did I get infected in the first place?".

#20 Chancellor

Chancellor

    Forum Deity

  • Emeritus
  • PipPipPipPipPip
  • 3,020 posts

Posted 07 July 2007 - 04:01 AM

Glad we could help :)

If you need this topic reopened, please tell the moderating team by replying here with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Chancellor

Please consider a donation to help Support SWI
Malware Complaints - Report them here and fight back!
Member of ASAP Since 2006 (Alliance of Security Analysis Professionals)
Please read the FAQ and the article "So how did I get infected in the first place?".




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button