Results 1 to 10 of 10

Thread: Infected by msjduhe.com?

  1. #1
    Member
    Join Date
    Jul 2009
    Posts
    38

    Default Infected by msjduhe.com?

    Hi, I am fighting against a really annoying little bugger. It started yesterday, as Firefox was suddenly shut down. Pop-ups appeared in the lower right corner that looked very similar to the Windows security center and they were telling me that my HDDs were corrupted, everything full of viruses and so on.

    I tried to remove it with AVG free which I have always running, but it did not find anything. MBAM and Spybot (1 and 2) did not find anything neither. I did also try Hijackthis and TrendMicro HouseCall without any result. Normally, this should have helped but it didn't. So I am really desperate

    The content of my second HDD (D) is cloaked, can't access or see it. C does also appear to be mostly empty but I can access installed programs via some detours.

    Thank you VERY much in advance!

    This is the DDS log:


    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
    Run by Stine at 10:58:10 on 2012-03-18
    Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.1980.882 [GMT 1:00]
    .
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Intel\AMT\LMS.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files (x86)\uTorrent\uTorrent.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil64_11_1_102_ActiveX.exe
    C:\Users\Stine\AppData\Local\Temp\HouseCall\housecall.bin
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uSearch Page =
    uSearch Bar =
    uWindows: Load=C:\Users\Stine\LOCALS~1\Temp\msjduhe.com
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    uRun: [MyBrowserCash Automatic Updater] C:\Windows\system32\MyBrowserCashUpdater.exe
    mRun: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363} - hxxp://www.gather.com/imageuploader/GatherUploader5.cab
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    TCP: DhcpNameServer = 192.168.178.1
    TCP: Interfaces\{E2AA6D53-D891-4386-87DF-D895AED8EF0E} : DhcpNameServer = 192.168.178.1
    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
    {DBC80044-A445-435b-BC74-9C25C1C588A9}
    mRun-x64: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    Hosts: 127.0.0.1 www.spywareinfo.com
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Stine\AppData\Roaming\Mozilla\Firefox\Profiles\rqd8rrnh.default\
    FF - prefs.js: browser.search.selectedEngine - Tixuma
    FF - prefs.js: browser.startup.homepage - hxxp://www.klamm.de/
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
    FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    .
    ============= SERVICES / DRIVERS ===============
    .
    R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2011-6-26 2066968]
    R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;C:\Windows\system32\DRIVERS\e1k62x64.sys --> C:\Windows\system32\DRIVERS\e1k62x64.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 Secunia Update Agent;Secunia Update Agent;"C:\Program Files (x86)\Secunia\PSI\sua.exe" --start-service --> C:\Program Files (x86)\Secunia\PSI\sua.exe [?]
    S3 optousb;OPTO ELECTRONICS optousb;C:\Windows\system32\DRIVERS\optousb.sys --> C:\Windows\system32\DRIVERS\optousb.sys [?]
    S3 optovcm;OPTO ELECTRONICS optovcm;C:\Windows\system32\DRIVERS\optovcm.sys --> C:\Windows\system32\DRIVERS\optovcm.sys [?]
    S3 StorSvc;Speicherdienst;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    .
    =============== Created Last 30 ================
    .
    2012-03-18 09:48:52 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
    2012-03-17 18:32:45 -------- d-----w- C:\Windows\IrfanView
    2012-03-17 18:32:22 509952 ----a-w- C:\Windows\System32\ntshrui.dll
    2012-03-17 18:32:22 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
    2012-03-17 18:32:18 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
    2012-03-17 18:32:18 2048 ----a-w- C:\Windows\System32\tzres.dll
    2012-03-17 18:19:41 -------- d-----w- C:\Users\Stine\AppData\Local\WindowsUpdate
    2012-03-17 18:16:00 -------- d-----w- C:\Users\Stine\AppData\Local\Secunia PSI
    2012-03-17 16:41:28 -------- d-----w- C:\Windows\pss
    2012-03-17 16:05:31 347136 ---ha-w- C:\ProgramData\1Ado7CKqiesD67.exe
    2012-03-17 10:25:40 5559152 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2012-03-17 10:25:38 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2012-03-17 10:25:38 3913584 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2012-03-17 10:09:31 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
    2012-03-17 10:08:38 1731920 ----a-w- C:\Windows\System32\ntdll.dll
    2012-03-17 10:08:38 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
    2012-03-17 10:06:51 77312 ----a-w- C:\Windows\System32\packager.dll
    2012-03-17 10:06:50 67072 ----a-w- C:\Windows\SysWow64\packager.dll
    2012-03-17 10:02:03 592824 ----a-w- C:\Program Files (x86)\Mozilla Firefox\gkmedias.dll
    2012-03-17 10:02:03 44472 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
    2012-03-11 09:15:13 -------- d--h--w- C:\Users\Stine\AppData\Roaming\kodak
    2012-03-10 08:01:27 -------- d--h--w- C:\Users\Stine\AppData\Roaming\Ughoahh
    2012-03-10 08:01:27 -------- d--h--w- C:\Users\Stine\AppData\Roaming\Cufiwoe
    2012-03-04 09:26:02 -------- d--h--w- C:\Users\Stine\AppData\Roaming\Syewoce
    2012-03-04 09:26:02 -------- d--h--w- C:\Users\Stine\AppData\Roaming\Axvy
    .
    ==================== Find3M ====================
    .
    2012-03-18 08:11:29 525544 ----a-w- C:\Windows\System32\deployJava1.dll
    2012-03-18 08:07:43 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
    2012-03-18 07:53:13 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-02-17 06:38:26 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
    2012-02-17 05:34:22 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
    2012-02-17 04:58:24 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
    2012-02-17 04:57:32 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
    2012-02-10 06:36:07 1544192 ----a-w- C:\Windows\System32\DWrite.dll
    2012-02-10 05:38:43 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
    2012-02-03 04:34:34 3145728 ----a-w- C:\Windows\System32\win32k.sys
    2012-01-25 06:38:39 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
    2012-01-25 06:38:38 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
    2012-01-25 06:33:30 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
    2011-12-30 06:26:08 515584 ----a-w- C:\Windows\System32\timedate.cpl
    2011-12-30 05:27:56 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
    2011-12-28 03:59:24 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
    2011-12-26 09:34:33 74703 ----a-w- C:\Windows\SysWOW64mfc45.dll
    .
    ============= FINISH: 10:59:33,73 ===============

  2. #2
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    µTorrent


    I'd like you to read this thread.

    Uninstall the programs listed above (in red). When done, post fresh dds logs.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #3
    Member
    Join Date
    Jul 2009
    Posts
    38

    Default

    My wish is your command


    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
    Run by Stine at 17:38:27 on 2012-03-23
    Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.1980.1090 [GMT 1:00]
    .
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Intel\AMT\LMS.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\sppsvc.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uSearch Page =
    uStart Page = hxxp://www.google.de/
    uSearch Bar =
    uWindows: Load=C:\Users\Stine\LOCALS~1\Temp\msjduhe.com
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    uRun: [MyBrowserCash Automatic Updater] C:\Windows\system32\MyBrowserCashUpdater.exe
    mRun: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363} - hxxp://www.gather.com/imageuploader/GatherUploader5.cab
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    TCP: DhcpNameServer = 192.168.178.1
    TCP: Interfaces\{E2AA6D53-D891-4386-87DF-D895AED8EF0E} : DhcpNameServer = 192.168.178.1
    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
    {DBC80044-A445-435b-BC74-9C25C1C588A9}
    mRun-x64: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    Hosts: 127.0.0.1 www.spywareinfo.com
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Stine\AppData\Roaming\Mozilla\Firefox\Profiles\rqd8rrnh.default\
    FF - prefs.js: browser.search.selectedEngine - Tixuma
    FF - prefs.js: browser.startup.homepage - hxxp://www.klamm.de/
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
    FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    .
    ============= SERVICES / DRIVERS ===============
    .
    R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2011-6-26 2066968]
    R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;C:\Windows\system32\DRIVERS\e1k62x64.sys --> C:\Windows\system32\DRIVERS\e1k62x64.sys [?]
    RUnknown SASKUTIL;SASKUTIL; [x]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 Secunia Update Agent;Secunia Update Agent;"C:\Program Files (x86)\Secunia\PSI\sua.exe" --start-service --> C:\Program Files (x86)\Secunia\PSI\sua.exe [?]
    S3 optousb;OPTO ELECTRONICS optousb;C:\Windows\system32\DRIVERS\optousb.sys --> C:\Windows\system32\DRIVERS\optousb.sys [?]
    S3 optovcm;OPTO ELECTRONICS optovcm;C:\Windows\system32\DRIVERS\optovcm.sys --> C:\Windows\system32\DRIVERS\optovcm.sys [?]
    S3 StorSvc;Speicherdienst;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    .
    =============== Created Last 30 ================
    .
    2012-03-18 09:48:52 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
    2012-03-17 18:32:22 509952 ----a-w- C:\Windows\System32\ntshrui.dll
    2012-03-17 18:32:22 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
    2012-03-17 18:32:18 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
    2012-03-17 18:32:18 2048 ----a-w- C:\Windows\System32\tzres.dll
    2012-03-17 18:19:41 -------- d-----w- C:\Users\Stine\AppData\Local\WindowsUpdate
    2012-03-17 18:16:00 -------- d-----w- C:\Users\Stine\AppData\Local\Secunia PSI
    2012-03-17 16:41:28 -------- d-----w- C:\Windows\pss
    2012-03-17 16:05:31 347136 ---ha-w- C:\ProgramData\1Ado7CKqiesD67.exe
    2012-03-17 10:25:40 5559152 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2012-03-17 10:25:38 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2012-03-17 10:25:38 3913584 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2012-03-17 10:09:31 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
    2012-03-17 10:08:38 1731920 ----a-w- C:\Windows\System32\ntdll.dll
    2012-03-17 10:08:38 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
    2012-03-17 10:06:51 77312 ----a-w- C:\Windows\System32\packager.dll
    2012-03-17 10:06:50 67072 ----a-w- C:\Windows\SysWow64\packager.dll
    2012-03-17 10:02:03 592824 ----a-w- C:\Program Files (x86)\Mozilla Firefox\gkmedias.dll
    2012-03-17 10:02:03 44472 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
    2012-03-11 09:15:13 -------- d--h--w- C:\Users\Stine\AppData\Roaming\kodak
    2012-03-10 08:01:27 -------- d--h--w- C:\Users\Stine\AppData\Roaming\Ughoahh
    2012-03-10 08:01:27 -------- d--h--w- C:\Users\Stine\AppData\Roaming\Cufiwoe
    2012-03-04 09:26:02 -------- d--h--w- C:\Users\Stine\AppData\Roaming\Syewoce
    2012-03-04 09:26:02 -------- d--h--w- C:\Users\Stine\AppData\Roaming\Axvy
    .
    ==================== Find3M ====================
    .
    2012-03-18 08:11:29 525544 ----a-w- C:\Windows\System32\deployJava1.dll
    2012-03-18 08:07:43 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
    2012-03-18 07:53:13 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-02-17 06:38:26 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
    2012-02-17 05:34:22 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
    2012-02-17 04:58:24 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
    2012-02-17 04:57:32 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
    2012-02-10 06:36:07 1544192 ----a-w- C:\Windows\System32\DWrite.dll
    2012-02-10 05:38:43 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
    2012-02-03 04:34:34 3145728 ----a-w- C:\Windows\System32\win32k.sys
    2012-01-25 06:38:39 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
    2012-01-25 06:38:38 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
    2012-01-25 06:33:30 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
    2011-12-30 06:26:08 515584 ----a-w- C:\Windows\System32\timedate.cpl
    2011-12-30 05:27:56 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
    2011-12-28 03:59:24 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
    2011-12-26 09:34:33 74703 ----a-w- C:\Windows\SysWOW64mfc45.dll
    .
    ============= FINISH: 17:39:24,25 ===============

  4. #4
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi


    Please visit this webpage for download links, and instructions for running ComboFix tool:

    http://www.bleepingcomputer.com/comb...o-use-combofix

    Please ensure you read this guide carefully first.


    Please continue as follows:

    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
      Remember to re-enable them afterwards.

    2. Click Yes to allow ComboFix to continue scanning for malware.


    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New dds log.


    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  5. #5
    Member
    Join Date
    Jul 2009
    Posts
    38

    Default

    Hi, I have used Combifix. Everything does appear to be ok now. Here are the logs:

    ComboFix 12-03-22.01 - Stine 24.03.2012 6:35.1.2 - x64
    Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.1980.750 [GMT 1:00]
    ausgeführt von:: c:\users\Stine\Downloads\ComboFix.exe
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Neuer Wiederherstellungspunkt wurde erstellt
    .
    .
    (((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\programdata\~1Ado7CKqiesD67
    c:\programdata\~1Ado7CKqiesD67r
    c:\programdata\1Ado7CKqiesD67
    c:\programdata\1Ado7CKqiesD67.exe
    c:\users\Stine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check
    c:\users\Stine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check\System Check.lnk
    c:\users\Stine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check\Uninstall System Check.lnk
    c:\users\Stine\Desktop\System Check.lnk
    c:\windows\SysWOW64mfc45.dll
    C:\WinLogon
    .
    .
    ((((((((((((((((((((((( Dateien erstellt von 2012-02-24 bis 2012-03-24 ))))))))))))))))))))))))))))))
    .
    .
    2012-03-24 05:40 . 2012-03-24 05:40 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-03-18 10:11 . 2012-03-18 10:11 -------- d-----w- c:\program files\7-Zip
    2012-03-18 09:48 . 2012-03-18 09:48 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
    2012-03-18 08:11 . 2012-03-18 08:11 -------- d-----w- c:\program files\Java
    2012-03-18 08:06 . 2012-03-18 08:06 -------- d-----w- c:\program files (x86)\Java
    2012-03-17 18:38 . 2012-03-18 09:50 -------- d-----w- c:\program files (x86)\Microsoft Silverlight
    2012-03-17 18:32 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll
    2012-03-17 18:32 . 2012-01-04 08:58 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
    2012-03-17 18:32 . 2011-11-05 05:32 2048 ----a-w- c:\windows\system32\tzres.dll
    2012-03-17 18:32 . 2011-11-05 04:26 2048 ----a-w- c:\windows\SysWow64\tzres.dll
    2012-03-17 18:19 . 2012-03-17 18:19 -------- d-----w- c:\users\Stine\AppData\Local\WindowsUpdate
    2012-03-17 18:16 . 2012-03-17 18:16 -------- d-----w- c:\users\Stine\AppData\Local\Secunia PSI
    2012-03-17 10:25 . 2011-11-19 15:20 5559152 ----a-w- c:\windows\system32\ntoskrnl.exe
    2012-03-17 10:25 . 2011-11-19 14:50 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
    2012-03-17 10:25 . 2011-11-19 14:50 3913584 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
    2012-03-17 10:09 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
    2012-03-17 10:08 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
    2012-03-17 10:08 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
    2012-03-17 10:06 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
    2012-03-17 10:06 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
    2012-03-17 10:02 . 2012-03-17 10:02 592824 ----a-w- c:\program files (x86)\Mozilla Firefox\gkmedias.dll
    2012-03-17 10:02 . 2012-03-17 10:02 44472 ----a-w- c:\program files (x86)\Mozilla Firefox\mozglue.dll
    2012-03-11 09:15 . 2012-03-11 09:15 -------- d--h--w- c:\users\Stine\AppData\Roaming\kodak
    2012-03-10 08:01 . 2012-03-10 16:57 -------- d--h--w- c:\users\Stine\AppData\Roaming\Cufiwoe
    2012-03-10 08:01 . 2012-03-10 08:02 -------- d--h--w- c:\users\Stine\AppData\Roaming\Ughoahh
    2012-03-04 09:26 . 2012-03-10 16:49 -------- d--h--w- c:\users\Stine\AppData\Roaming\Syewoce
    2012-03-04 09:26 . 2012-03-10 06:49 -------- d--h--w- c:\users\Stine\AppData\Roaming\Axvy
    .
    .
    .
    (((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-03-18 08:11 . 2011-12-03 06:04 525544 ----a-w- c:\windows\system32\deployJava1.dll
    2012-03-18 08:07 . 2011-06-04 09:47 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
    2012-03-18 07:53 . 2011-12-03 06:09 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    .
    .
    (((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-04-23 1314816]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [x]
    R3 optousb;OPTO ELECTRONICS optousb;c:\windows\system32\DRIVERS\optousb.sys [x]
    R3 optovcm;OPTO ELECTRONICS optovcm;c:\windows\system32\DRIVERS\optovcm.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
    S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2009-07-21 2066968]
    S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [x]
    .
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-03 162584]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-06-03 386840]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-03 417560]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x0
    .
    ------- Zusätzlicher Suchlauf -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.google.de/
    mLocal Page = c:\windows\SysWOW64\blank.htm
    TCP: DhcpNameServer = 192.168.178.1
    DPF: {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363} - hxxp://www.gather.com/imageuploader/GatherUploader5.cab
    FF - ProfilePath - c:\users\Stine\AppData\Roaming\Mozilla\Firefox\Profiles\rqd8rrnh.default\
    FF - prefs.js: browser.search.selectedEngine - Tixuma
    FF - prefs.js: browser.startup.homepage - hxxp://www.klamm.de/
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    .
    - - - - Entfernte verwaiste Registrierungseinträge - - - -
    .
    Wow6432Node-HKCU-Run-MyBrowserCash Automatic Updater - c:\windows\system32\MyBrowserCashUpdater.exe
    BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - (no file)
    .
    .
    .
    --------------------- Gesperrte Registrierungsschluessel ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11g_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.10"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11g.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Weitere laufende Prozesse ------------------------
    .
    c:\program files (x86)\Intel\AMT\LMS.exe
    .
    **************************************************************************
    .
    Zeit der Fertigstellung: 2012-03-24 06:48:56 - PC wurde neu gestartet
    ComboFix-quarantined-files.txt 2012-03-24 05:48
    .
    Vor Suchlauf: 6 Verzeichnis(se), 50.030.739.456 Bytes frei
    Nach Suchlauf: 11 Verzeichnis(se), 49.697.304.576 Bytes frei
    .
    - - End Of File - - 5C65631B9A98FCE720C687733F39D80E
    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
    Run by Stine at 6:59:24 on 2012-03-24
    Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.1980.992 [GMT 1:00]
    .
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Intel\AMT\LMS.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\sppsvc.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\vssvc.exe
    C:\Windows\System32\svchost.exe -k swprv
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.de/
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    mRun: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363} - hxxp://www.gather.com/imageuploader/GatherUploader5.cab
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    TCP: DhcpNameServer = 192.168.178.1
    TCP: Interfaces\{E2AA6D53-D891-4386-87DF-D895AED8EF0E} : DhcpNameServer = 192.168.178.1
    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
    {DBC80044-A445-435b-BC74-9C25C1C588A9}
    mRun-x64: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Stine\AppData\Roaming\Mozilla\Firefox\Profiles\rqd8rrnh.default\
    FF - prefs.js: browser.search.selectedEngine - Tixuma
    FF - prefs.js: browser.startup.homepage - hxxp://www.klamm.de/
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
    FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    .
    ============= SERVICES / DRIVERS ===============
    .
    R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2011-6-26 2066968]
    R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;C:\Windows\system32\DRIVERS\e1k62x64.sys --> C:\Windows\system32\DRIVERS\e1k62x64.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 Secunia Update Agent;Secunia Update Agent;"C:\Program Files (x86)\Secunia\PSI\sua.exe" --start-service --> C:\Program Files (x86)\Secunia\PSI\sua.exe [?]
    S3 optousb;OPTO ELECTRONICS optousb;C:\Windows\system32\DRIVERS\optousb.sys --> C:\Windows\system32\DRIVERS\optousb.sys [?]
    S3 optovcm;OPTO ELECTRONICS optovcm;C:\Windows\system32\DRIVERS\optovcm.sys --> C:\Windows\system32\DRIVERS\optovcm.sys [?]
    S3 StorSvc;Speicherdienst;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    .
    =============== Created Last 30 ================
    .
    2012-03-24 05:48:58 -------- d-----w- C:\Users\Stine\AppData\Local\temp
    2012-03-24 05:45:28 -------- d-sh--w- C:\$RECYCLE.BIN
    2012-03-24 05:33:23 98816 ----a-w- C:\Windows\sed.exe
    2012-03-24 05:33:23 518144 ----a-w- C:\Windows\SWREG.exe
    2012-03-24 05:33:23 256000 ----a-w- C:\Windows\PEV.exe
    2012-03-24 05:33:23 208896 ----a-w- C:\Windows\MBR.exe
    2012-03-18 09:48:52 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
    2012-03-17 18:32:22 509952 ----a-w- C:\Windows\System32\ntshrui.dll
    2012-03-17 18:32:22 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
    2012-03-17 18:32:18 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
    2012-03-17 18:32:18 2048 ----a-w- C:\Windows\System32\tzres.dll
    2012-03-17 18:19:41 -------- d-----w- C:\Users\Stine\AppData\Local\WindowsUpdate
    2012-03-17 18:16:00 -------- d-----w- C:\Users\Stine\AppData\Local\Secunia PSI
    2012-03-17 16:41:28 -------- d-----w- C:\Windows\pss
    2012-03-17 10:25:40 5559152 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2012-03-17 10:25:38 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2012-03-17 10:25:38 3913584 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2012-03-17 10:09:31 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
    2012-03-17 10:08:38 1731920 ----a-w- C:\Windows\System32\ntdll.dll
    2012-03-17 10:08:38 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
    2012-03-17 10:06:51 77312 ----a-w- C:\Windows\System32\packager.dll
    2012-03-17 10:06:50 67072 ----a-w- C:\Windows\SysWow64\packager.dll
    2012-03-17 10:02:03 592824 ----a-w- C:\Program Files (x86)\Mozilla Firefox\gkmedias.dll
    2012-03-17 10:02:03 44472 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
    2012-03-11 09:15:13 -------- d-----w- C:\Users\Stine\AppData\Roaming\kodak
    2012-03-10 08:01:27 -------- d-----w- C:\Users\Stine\AppData\Roaming\Ughoahh
    2012-03-10 08:01:27 -------- d-----w- C:\Users\Stine\AppData\Roaming\Cufiwoe
    2012-03-04 09:26:02 -------- d-----w- C:\Users\Stine\AppData\Roaming\Syewoce
    2012-03-04 09:26:02 -------- d-----w- C:\Users\Stine\AppData\Roaming\Axvy
    .
    ==================== Find3M ====================
    .
    2012-03-18 08:11:29 525544 ----a-w- C:\Windows\System32\deployJava1.dll
    2012-03-18 08:07:43 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
    2012-03-18 07:53:13 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-02-17 06:38:26 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
    2012-02-17 05:34:22 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
    2012-02-17 04:58:24 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
    2012-02-17 04:57:32 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
    2012-02-10 06:36:07 1544192 ----a-w- C:\Windows\System32\DWrite.dll
    2012-02-10 05:38:43 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
    2012-02-03 04:34:34 3145728 ----a-w- C:\Windows\System32\win32k.sys
    2012-01-25 06:38:39 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
    2012-01-25 06:38:38 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
    2012-01-25 06:33:30 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
    2011-12-30 06:26:08 515584 ----a-w- C:\Windows\System32\timedate.cpl
    2011-12-30 05:27:56 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
    2011-12-28 03:59:24 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
    .
    ============= FINISH: 6:59:43,44 ===============
    I do hope it also IS ok

  6. #6
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Why did you reinstall uTorrent? If you want me to continue helping to finish the case you have to uninstall it now and then post new DDS logs.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  7. #7
    Member
    Join Date
    Jul 2009
    Posts
    38

    Default

    Hi,

    I did not reinstall it but after Combofix everything had been restored.

    I will uninstall it AGAIN and post new logs.

  8. #8
    Member
    Join Date
    Jul 2009
    Posts
    38

    Default

    Here it is:

    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
    Run by Stine at 11:51:24 on 2012-03-24
    Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.1980.419 [GMT 1:00]
    .
    AV: Panda Cloud Antivirus *Enabled/Updated* {86971480-9989-6750-B122-681A86518D59}
    SP: Panda Cloud Antivirus *Enabled/Updated* {3DF6F564-BFB3-68DE-8B92-5368FDD6C7E4}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Intel\AMT\LMS.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskhost.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files (x86)\MyBrowserCash\MyBrowserCash.exe
    C:\Program Files (x86)\20Dollars2Surf\20dollars2surf.exe
    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
    C:\Program Files (x86)\Paradiesbar\paradiesbar.exe
    C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe
    C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe
    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
    C:\Program Files (x86)\Windows Media Player\wmplayer.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.de/
    BHO: WTBAddon Class: {1630669f-9d0c-4f0b-8aa9-10de8bee1755} - C:\Program Files (x86)\MyBrowserCash\WTBPlugin.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    uRun: [MyBrowserCash] C:\Program Files (x86)\MyBrowserCash\MyBrowserCash.exe
    mRun: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    mRun: [PSUNMain] "C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\20DOLL~1.LNK - C:\Program Files (x86)\20Dollars2Surf\20dollars2surf.exe
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {C8E7CBFB-9F2E-42C7-B4CB-D4B7FC89A363} - hxxp://www.gather.com/imageuploader/GatherUploader5.cab
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    TCP: DhcpNameServer = 192.168.178.1
    TCP: Interfaces\{E2AA6D53-D891-4386-87DF-D895AED8EF0E} : DhcpNameServer = 192.168.178.1
    {1630669F-9D0C-4F0B-8AA9-10DE8BEE1755}
    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
    {DBC80044-A445-435b-BC74-9C25C1C588A9}
    mRun-x64: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
    mRun-x64: [PSUNMain] "C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Stine\AppData\Roaming\Mozilla\Firefox\Profiles\rqd8rrnh.default\
    FF - prefs.js: browser.search.selectedEngine - Tixuma
    FF - prefs.js: browser.startup.homepage - hxxp://www.klamm.de/
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
    FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 PSINKNC;PSINKNC;C:\Windows\system32\DRIVERS\psinknc.sys --> C:\Windows\system32\DRIVERS\psinknc.sys [?]
    R2 NanoServiceMain;Panda Cloud Antivirus Service;C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe [2011-4-28 140608]
    R2 PSINAFLT;PSINAFLT;C:\Windows\system32\DRIVERS\PSINAflt.sys --> C:\Windows\system32\DRIVERS\PSINAflt.sys [?]
    R2 PSINFILE;PSINFILE;C:\Windows\system32\DRIVERS\PSINFile.sys --> C:\Windows\system32\DRIVERS\PSINFile.sys [?]
    R2 PSINPROC;PSINPROC;C:\Windows\system32\DRIVERS\PSINProc.sys --> C:\Windows\system32\DRIVERS\PSINProc.sys [?]
    R2 PSINPROT;PSINPROT;C:\Windows\system32\DRIVERS\PSINProt.sys --> C:\Windows\system32\DRIVERS\PSINProt.sys [?]
    R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2011-6-26 2066968]
    R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;C:\Windows\system32\DRIVERS\e1k62x64.sys --> C:\Windows\system32\DRIVERS\e1k62x64.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 Secunia Update Agent;Secunia Update Agent;"C:\Program Files (x86)\Secunia\PSI\sua.exe" --start-service --> C:\Program Files (x86)\Secunia\PSI\sua.exe [?]
    S3 optousb;OPTO ELECTRONICS optousb;C:\Windows\system32\DRIVERS\optousb.sys --> C:\Windows\system32\DRIVERS\optousb.sys [?]
    S3 optovcm;OPTO ELECTRONICS optovcm;C:\Windows\system32\DRIVERS\optovcm.sys --> C:\Windows\system32\DRIVERS\optovcm.sys [?]
    S3 StorSvc;Speicherdienst;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    .
    =============== Created Last 30 ================
    .
    2012-03-24 09:22:44 -------- d-----w- C:\Users\Stine\AppData\Roaming\Panda Security
    2012-03-24 09:20:51 -------- d-----w- C:\ProgramData\Panda Security
    2012-03-24 09:20:51 -------- d-----w- C:\Program Files (x86)\Panda Security
    2012-03-24 08:01:45 -------- d-----w- C:\ProgramData\AVAST Software
    2012-03-24 08:01:45 -------- d-----w- C:\Program Files\Avast
    2012-03-24 07:58:56 -------- d-----w- C:\Program Files (x86)\Paradiesbar
    2012-03-24 07:55:16 -------- d-----w- C:\Program Files (x86)\MyBrowserCash
    2012-03-24 06:08:13 59904 ----a-w- C:\Windows\SysWow64\wbemdisp.tlb
    2012-03-24 06:08:13 -------- d-----w- C:\Program Files (x86)\20Dollars2Surf
    2012-03-24 05:48:58 -------- d-----w- C:\Users\Stine\AppData\Local\temp
    2012-03-24 05:45:28 -------- d-sh--w- C:\$RECYCLE.BIN
    2012-03-24 05:33:23 98816 ----a-w- C:\Windows\sed.exe
    2012-03-24 05:33:23 518144 ----a-w- C:\Windows\SWREG.exe
    2012-03-24 05:33:23 256000 ----a-w- C:\Windows\PEV.exe
    2012-03-24 05:33:23 208896 ----a-w- C:\Windows\MBR.exe
    2012-03-24 05:18:25 740216 ----a-w- C:\Program Files (x86)\uTorrent.exe
    2012-03-18 09:48:52 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
    2012-03-17 18:32:22 509952 ----a-w- C:\Windows\System32\ntshrui.dll
    2012-03-17 18:32:22 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
    2012-03-17 18:32:18 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
    2012-03-17 18:32:18 2048 ----a-w- C:\Windows\System32\tzres.dll
    2012-03-17 18:19:41 -------- d-----w- C:\Users\Stine\AppData\Local\WindowsUpdate
    2012-03-17 18:16:00 -------- d-----w- C:\Users\Stine\AppData\Local\Secunia PSI
    2012-03-17 16:41:28 -------- d-----w- C:\Windows\pss
    2012-03-17 10:25:40 5559152 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2012-03-17 10:25:38 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2012-03-17 10:25:38 3913584 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2012-03-17 10:09:31 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
    2012-03-17 10:08:38 1731920 ----a-w- C:\Windows\System32\ntdll.dll
    2012-03-17 10:08:38 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
    2012-03-17 10:06:51 77312 ----a-w- C:\Windows\System32\packager.dll
    2012-03-17 10:06:50 67072 ----a-w- C:\Windows\SysWow64\packager.dll
    2012-03-17 10:02:03 592824 ----a-w- C:\Program Files (x86)\Mozilla Firefox\gkmedias.dll
    2012-03-17 10:02:03 44472 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
    2012-03-11 09:15:13 -------- d-----w- C:\Users\Stine\AppData\Roaming\kodak
    2012-03-10 08:01:27 -------- d-----w- C:\Users\Stine\AppData\Roaming\Ughoahh
    2012-03-10 08:01:27 -------- d-----w- C:\Users\Stine\AppData\Roaming\Cufiwoe
    2012-03-04 09:26:02 -------- d-----w- C:\Users\Stine\AppData\Roaming\Syewoce
    2012-03-04 09:26:02 -------- d-----w- C:\Users\Stine\AppData\Roaming\Axvy
    .
    ==================== Find3M ====================
    .
    2012-03-18 08:11:29 525544 ----a-w- C:\Windows\System32\deployJava1.dll
    2012-03-18 08:07:43 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
    2012-03-18 07:53:13 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-02-17 06:38:26 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
    2012-02-17 05:34:22 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
    2012-02-17 04:58:24 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
    2012-02-17 04:57:32 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
    2012-02-10 06:36:07 1544192 ----a-w- C:\Windows\System32\DWrite.dll
    2012-02-10 05:38:43 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
    2012-02-03 04:34:34 3145728 ----a-w- C:\Windows\System32\win32k.sys
    2012-01-25 06:38:39 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
    2012-01-25 06:38:38 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
    2012-01-25 06:33:30 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
    2012-01-05 12:10:11 161032 ----a-w- C:\Windows\System32\drivers\PSINAflt.sys
    2011-12-30 06:26:08 515584 ----a-w- C:\Windows\System32\timedate.cpl
    2011-12-30 05:27:56 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
    2011-12-28 03:59:24 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
    .
    ============= FINISH: 11:52:52,74 ===============

  9. #9
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    DirLook::
    c:\users\Stine\AppData\Roaming\kodak
    c:\users\Stine\AppData\Roaming\Cufiwoe
    c:\users\Stine\AppData\Roaming\Ughoahh
    c:\users\Stine\AppData\Roaming\Syewoce
    c:\users\Stine\AppData\Roaming\Axvy
    File::
    C:\Program Files (x86)\uTorrent.exe

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe (let the tool to update itself if prompted).
    Then post the resultant log.

    * Go here to run an online scanner from ESET.
    • Note: You will need to use Internet explorer for this scan
    • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the activex control to install
    • Click Start
    • Make sure that the option Remove found threats is UNchecked and the option Scan unwanted applications is checkmarked.
    • Click Scan
    • Wait for the scan to finish.



    Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  10. #10
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Due to inactivity, this thread will now be closed.

    Note:If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

    If it has been less than three days since your last response and you need the thread re-opened, please send me or other MOD a private message (pm). A valid, working link to the closed topic is required.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •