PDA

View Full Version : Virtumonde problems



ITFox
2008-04-30, 23:13
Please can you help with solving my problems with virtumonde?
For several days the virtumonde keeps coming back after cleaning my PC with Spybot.
Since yesterday I also lost the internet connection, although e-mail downloads are possible and the network connection seems busy.
On the last Spybot run virtumonde was not found anymore.
I ran Kaspersky Online Scan several days ago but it did not finish.
I also was able to download Hijackthis before I lost my internet connection.
Please find the HJT log here.
Thank you very much in advance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:40:03, on 30-4-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
E:\ProgramFilesOpE\Nikon\NkbMonitor.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {24e9519b-3f70-429b-99bc-4b2b49b96f66} - C:\WINDOWS\SYSTEM32\ssqPjghf.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7583897b-814f-4e89-b578-62e286d62da3} - C:\WINDOWS\system32\mlJBqpNE.dll (disabled by BHODemon)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8ec52dd5-ea49-4997-be65-a54fe00ca6ef} - C:\WINDOWS\system32\xxyayVME.dll (file missing)
O2 - BHO: (no name) - {a92c32f3-42ec-4b80-b9f9-3a64dcf4aac4} - C:\WINDOWS\system32\xxywVMdB.dll (disabled by BHODemon)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: (no name) - {e418e98e-11b6-4833-8ea0-69893ea1cc50} - C:\WINDOWS\system32\wvUMffFY.dll (disabled by BHODemon)
O2 - BHO: (no name) - {ec591c61-9c3f-4f33-956d-1259e1b02c1d} - C:\WINDOWS\system32\iifdEwwV.dll (disabled by BHODemon)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\RunOnce: [SpybotDeletingC3817] cmd /c del "C:\WINDOWS\system32\hqmjduij.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1063] command /c del "C:\WINDOWS\system32\hqmjduij.dll_old"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
O4 - HKCU\..\RunOnce: [SpybotDeletingD9078] cmd /c del "C:\WINDOWS\system32\hqmjduij.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9034] command /c del "C:\WINDOWS\system32\hqmjduij.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1394] cmd /c del "C:\WINDOWS\system32\wvUMffFY.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB205] command /c del "C:\WINDOWS\system32\wvUMffFY.dll_old"
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = E:\ProgramFilesOpE\Nikon\NkbMonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.paradigit.nl
O16 - DPF: {0eb0e74a-2a76-4ab3-a7fb-9bd8c29f7f75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188749819875
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://fotoservice.tntpost.nl/TNT/UserControls/Part/Upload/ImageUploader4.cab
O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} (Navigram Control) - http://www.navigram.com/engine/v911/Navigram.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D83C1BD1-DCBB-11D4-9425-0050BF33FA6E} (CycloScopeLite Control) - http://www.cyclomedia.nl/download/components/CycloScopeLite.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://193.172.162.99:8080/activex/AMC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://webaccess.minvenw.nl/dana-cached/setup/JuniperSetupSP1.cab
O20 - Winlogon Notify: ssqPjghf - C:\WINDOWS\SYSTEM32\ssqPjghf.dll
O20 - Winlogon Notify: wlctrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 9423 bytes

Rorschach112
2008-04-30, 23:25
Hello

Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.

ITFox
2008-05-01, 00:51
Thank you very much for your quick reply.
I copied both combofix and Windows Recovery to the infected machine.
Installed Windows Recovery through Combofix. Ran Combofix and HJT.
Here are the logs.

Greetings
Gerrit

ComboFix 08-04-29.5 - Gerrit 2008-05-01 0:21:44.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.666 [GMT 2:00]
Gestart vanuit: K:\ComboFix.exe
Command switches used :: C:\Documents and Settings\Gerrit\Bureaublad\WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe
* Nieuw herstelpunt werd aangemaakt
.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\BdMVwyxx.ini
C:\WINDOWS\system32\BdMVwyxx.ini2
C:\WINDOWS\system32\dcassygc.dll
C:\WINDOWS\system32\dqecahxw.dll
c:\windows\system32\Drivers\Dey81.sys
C:\WINDOWS\system32\drivers\grande48.sys
C:\WINDOWS\system32\drivers\tvb35.sys
C:\WINDOWS\system32\EMVyayxx.ini
C:\WINDOWS\system32\EMVyayxx.ini2
C:\WINDOWS\system32\ENpqBJlm.ini
C:\WINDOWS\system32\ENpqBJlm.ini2
C:\WINDOWS\system32\fccdExWq.dll
C:\WINDOWS\system32\iifdaAtT.dll
C:\WINDOWS\system32\ssqOGwUk.dll
C:\WINDOWS\system32\ssqPjghf.dll
C:\WINDOWS\system32\ssqrrRJA.dll
C:\WINDOWS\system32\VwwEdfii.ini
C:\WINDOWS\system32\VwwEdfii.ini2
C:\WINDOWS\system32\WLCtrl32.dll
C:\WINDOWS\system32\wtyjoltt.dll
C:\WINDOWS\system32\YFffMUvw.ini
C:\WINDOWS\system32\YFffMUvw.ini2
C:\WINDOWS\zeqbqwp.sys
F:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_dey81
-------\Legacy_tvb35
-------\Service_dey81
-------\Service_Dey81
-------\Service_tvb35
-------\Service_zeqbqwp


(((((((((((((((((((( Bestanden Gemaakt van 2008-03-28 to 2008-04-30 ))))))))))))))))))))))))))))))
.

2008-04-27 12:36 . 2008-04-27 23:53 294 ---hsc--- C:\WINDOWS\system32\botdxyeb.ini
2008-04-26 14:44 . 2008-04-26 14:45 534 ---hsc--- C:\WINDOWS\system32\kmcwdnyt.ini
2008-04-18 10:03 . 2008-04-26 14:33 474 ---hsc--- C:\WINDOWS\system32\iiasjeoj.ini
2008-04-15 19:19 . 2008-04-15 19:19 294 ---hsc--- C:\WINDOWS\system32\rwehoanj.ini
2008-04-15 19:07 . 2008-04-15 19:07 <DIR> d----c--- C:\WINDOWS\system32\Kaspersky Lab
2008-04-15 19:07 . 2008-04-15 19:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-13 23:53 . 2008-04-13 23:53 <DIR> d----c--- C:\Program Files\Trend Micro
2008-04-12 20:24 . 2008-04-13 12:06 294 ---hsc--- C:\WINDOWS\system32\nktpxmip.ini
2008-04-12 13:15 . 2008-04-12 13:56 406 ---hsc--- C:\WINDOWS\system32\bnhydiox.ini
2008-04-11 23:03 . 2004-08-04 10:03 221,184 --a--c--- C:\WINDOWS\system32\wmpns.dll
2008-04-11 15:55 . 2008-04-27 14:32 101,160 --a--c--- C:\WINDOWS\BMd3887a5c.xml
2008-04-10 19:57 . 2008-04-10 19:57 <DIR> d----c--- C:\Program Files\ZoneAlarmSB
2008-04-10 19:55 . 2008-03-13 23:11 1,086,952 --a--c--- C:\WINDOWS\system32\zpeng24.dll
2008-04-10 15:55 . 2008-04-27 23:54 962 --a--c--- C:\WINDOWS\wininit.ini
2008-04-10 14:46 . 2008-04-10 14:45 691,545 --a--c--- C:\WINDOWS\unins000.exe
2008-04-10 14:46 . 2008-04-10 14:46 2,548 --a--c--- C:\WINDOWS\unins000.dat
2008-04-10 13:53 . 2008-04-10 13:53 29 --a--c--- C:\WINDOWS\system32\pggqrtta.tmp
2008-04-10 13:52 . 2008-04-10 13:52 58,880 --a------ C:\mxuxc.exe
2008-04-10 13:52 . 2008-04-10 13:52 2 --a------ C:\-793032337
2008-04-03 17:51 . 2008-04-03 17:51 5,539,678 --a--c--- C:\Documents and Settings\Gerrit\neoteris_read_13228332.reg
2008-04-01 20:06 . 2008-04-01 20:06 664 --a--c--- C:\WINDOWS\system32\d3d9caps.dat
2008-04-01 07:58 . 2008-04-01 07:58 268 --ah----- C:\sqmdata14.sqm
2008-04-01 07:58 . 2008-04-01 07:58 244 --ah----- C:\sqmnoopt14.sqm
2008-03-31 21:51 . 2008-03-31 21:51 268 --ah----- C:\sqmdata13.sqm
2008-03-31 21:51 . 2008-03-31 21:51 244 --ah----- C:\sqmnoopt13.sqm
2008-03-31 18:34 . 2008-03-31 21:46 <DIR> d-------- C:\Documents and Settings\Rick\Sjablonen
2008-03-31 18:34 . 2008-03-31 21:46 <DIR> d-------- C:\Documents and Settings\Rick\Favorieten
2008-03-31 18:34 . 2008-03-31 18:34 <DIR> d-------- C:\Documents and Settings\Rick\Application Data\Ipswitch
2008-03-31 18:34 . 2008-03-31 21:46 <DIR> d---s---- C:\Documents and Settings\Rick
2008-03-31 18:34 . 2008-05-01 00:20 1,024 --ah----- C:\Documents and Settings\Rick\ntuser.dat.LOG
2008-03-31 15:41 . 2008-03-31 15:41 244 --ah----- C:\sqmnoopt12.sqm
2008-03-31 15:41 . 2008-03-31 15:41 232 --ah----- C:\sqmdata12.sqm
2008-03-30 17:29 . 2008-03-30 17:29 <DIR> d----c--- C:\Program Files\LEGO Media
2008-03-28 12:03 . 2008-03-28 12:03 0 --a--c--- C:\WINDOWS\webica.ini
2008-03-28 12:01 . 2008-03-28 12:01 <DIR> d----c--- C:\WINDOWS\system32\Resource
2008-03-28 12:01 . 2008-03-28 12:01 <DIR> d----c--- C:\Program Files\Citrix
2008-03-28 12:01 . 2008-03-28 12:04 <DIR> d----c--- C:\Documents and Settings\Gerrit\Application Data\ICAClient
2008-03-25 03:14 . 2008-03-25 03:14 47,104 --ahsc--- C:\WINDOWS\Thumbs.db
2008-03-25 03:14 . 2008-03-25 03:14 5,632 --ahsc--- C:\WINDOWS\system32\Thumbs.db
2008-03-24 14:49 . 2008-03-24 14:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-24 14:47 . 2008-03-24 14:47 <DIR> d----c--- C:\Program Files\Apple Software Update
2008-03-24 14:47 . 2008-03-24 14:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-03-23 16:41 . 2008-03-23 16:55 <DIR> d----c--- C:\Documents and Settings\Bart\.freemind
2008-03-22 18:46 . 1998-09-18 12:55 27,648 --a--c--- C:\WINDOWS\system32\qtuninst.dll
2008-03-22 18:45 . 1998-09-09 13:07 302,592 --a--c--- C:\WINDOWS\unin0413.exe
2008-03-19 18:55 . 2008-03-19 18:55 5,539,570 --a--c--- C:\Documents and Settings\Gerrit\neoteris_read_22279806.reg
2008-03-15 16:55 . 2008-03-15 16:55 <DIR> d----c--- C:\Program Files\directx
2008-03-15 16:54 . 2000-05-17 18:59 198,640 --a--c--- C:\WINDOWS\system32\Mci32.ocx
2008-03-15 16:54 . 2000-05-17 18:59 40,448 --a--c--- C:\WINDOWS\system32\regobj.dll
2008-03-02 20:51 . 2008-03-02 20:51 <DIR> d----c--- C:\Documents and Settings\Margreet.WOONKAMER.000\Application Data\Ipswitch

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-30 22:36 2,754,592 -csha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-30 22:36 13,460 -csha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-30 17:46 8,209,359 -c--a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_04_30_09_00_15_full.dmp.zip
2008-04-30 07:00 918,016 -c--a-w C:\WINDOWS\Internet Logs\xDB20.tmp
2008-04-27 21:58 104,960 -c--a-w C:\WINDOWS\Internet Logs\xDB1F.tmp
2008-04-27 08:27 332,288 -c--a-w C:\WINDOWS\Internet Logs\xDB1D.tmp
2008-04-27 08:27 1,387,008 -c--a-w C:\WINDOWS\Internet Logs\xDB1E.tmp
2008-04-16 00:17 49,076 -c--a-w C:\Documents and Settings\Gerrit\Application Data\wklnhst.dat
2008-04-15 21:37 98,816 -c--a-w C:\WINDOWS\Internet Logs\xDB1B.tmp
2008-04-15 21:37 1,386,496 -c--a-w C:\WINDOWS\Internet Logs\xDB1C.tmp
2008-04-15 21:21 972,800 -c--a-w C:\WINDOWS\Internet Logs\xDB1A.tmp
2008-04-15 17:08 435,200 -c--a-w C:\WINDOWS\Internet Logs\xDB18.tmp
2008-04-15 17:08 1,385,984 -c--a-w C:\WINDOWS\Internet Logs\xDB19.tmp
2008-04-14 11:34 239,616 -c--a-w C:\WINDOWS\Internet Logs\xDB17.tmp
2008-04-13 18:36 1,420,800 -c--a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2008-04-11 19:48 222,720 -c--a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2008-04-11 19:48 1,362,432 -c--a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2008-04-11 17:50 196,608 -c--a-w C:\WINDOWS\Internet Logs\xDB12.tmp
2008-04-11 17:50 1,358,848 -c--a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2008-04-11 17:02 336,384 -c--a-w C:\WINDOWS\Internet Logs\xDB10.tmp
2008-04-11 17:02 1,356,288 -c--a-w C:\WINDOWS\Internet Logs\xDB11.tmp
2008-04-11 15:30 200,704 -c--a-w C:\WINDOWS\Internet Logs\xDBF.tmp
2008-04-11 14:01 768,512 -c--a-w C:\WINDOWS\Internet Logs\xDBE.tmp
2008-04-10 13:58 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-10 11:09 --------- dc-h--w C:\Program Files\InstallShield Installation Information
2008-03-30 20:32 73,736 -c--a-w C:\Documents and Settings\Gerrit\Application Data\GDIPFONTCACHEV1.DAT
2008-03-26 17:05 3,630 -c--a-w C:\Documents and Settings\Bart\Application Data\wklnhst.dat
2008-03-22 16:41 --------- dc----w C:\Program Files\LimewirePlus
2008-03-20 08:10 1,845,376 -c--a-w C:\WINDOWS\system32\win32k.sys
2008-03-16 16:22 --------- dc----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-03-16 14:32 --------- dc----w C:\Program Files\Java
2008-03-13 21:11 75,248 -c--a-w C:\WINDOWS\zllsputility.exe
2008-03-01 13:05 826,368 -c--a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 -c--a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:39 45,568 -c--a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-12 00:47 2,188 -c--a-w C:\Documents and Settings\Margreet.WOONKAMER.000\Application Data\wklnhst.dat
2007-10-04 15:25 734 -c--a-w C:\Documents and Settings\Annick.WOONKAMER\Application Data\wklnhst.dat
2007-09-05 18:10 71,712 -c--a-w C:\Documents and Settings\Annick.WOONKAMER\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7583897b-814f-4e89-b578-62e286d62da3}]
C:\WINDOWS\system32\mlJBqpNE.dll__BHODemonDisabled

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8ec52dd5-ea49-4997-be65-a54fe00ca6ef}]
C:\WINDOWS\system32\xxyayVME.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a92c32f3-42ec-4b80-b9f9-3a64dcf4aac4}]
C:\WINDOWS\system32\xxywVMdB.dll__BHODemonDisabled

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e418e98e-11b6-4833-8ea0-69893ea1cc50}]
C:\WINDOWS\system32\wvUMffFY.dll__BHODemonDisabled

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ec591c61-9c3f-4f33-956d-1259e1b02c1d}]
C:\WINDOWS\system32\iifdEwwV.dll__BHODemonDisabled

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 10:03 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-03 19:57 68856]
"InstantTray"="C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe" [2003-10-22 15:03 746496]
"IW_Drop_Icon"="C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe" [2003-11-19 13:36 1134080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-10-06 15:16 5058560]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 10:03 15360]
"NvMediaCenter"="C:\WINDOWS\System32\NVMCTRAY.DLL" [2003-10-06 15:16 49152]
"InstantTray"="C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe" [2003-10-22 15:03 746496]
"IW_Drop_Icon"="C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe" [2003-11-19 13:36 1134080]

C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 10:15:56 65588]
NkbMonitor.exe.lnk - E:\ProgramFilesOpE\Nikon\NkbMonitor.exe [2007-09-06 19:40:21 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.IV41"= C:\WINDOWS\system32\Ir41_32.ax

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BMd3887a5c"=Rundll32.exe "C:\WINDOWS\system32\qspwnleh.dll",s

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"=

R0 fasttrak;fasttrak;C:\WINDOWS\system32\DRIVERS\fasttrak.sys [2002-02-25 21:45]
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-09-05 18:25]
R0 VOBID;VOBID;C:\WINDOWS\system32\DRIVERS\vobid.sys [2003-08-01 14:47]
R1 vobcom;vobcom;C:\WINDOWS\system32\drivers\vobcom.sys [2001-10-04 11:53]
R1 vobiw;vobiw;C:\WINDOWS\system32\drivers\vobiw.sys [2003-08-29 13:51]
R3 cdrdrv;Cdrdrv;C:\WINDOWS\system32\Drivers\Cdrdrv.sys [2002-12-13 18:33]

*Newly Created Service* - ENTDRV51
*Newly Created Service* - PAVDRV
*Newly Created Service* - PAVPROC
*Newly Created Service* - PAVPRSRV
*Newly Created Service* - PAVSRV
*Newly Created Service* - RASMAN
*Newly Created Service* - SHLDDRV
.
Inhoud van de 'Gedeelde Taken' map
"2008-04-01 06:25:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-30 22:25:00 C:\WINDOWS\Tasks\Controleren op updates voor Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-01 00:38:34
Windows 5.1.2600 Service Pack 2 NTFS

scannen van verborgen processen ...

scannen van verborgen autostart items ...

scannen van verborgen bestanden ...

Scan succesvol afgerond
verborgen bestanden: 0

**************************************************************************
"ImagePath"="SYSTEM32\DRIVERS\viasraid.sys\00.13.01.3196
[Signed]\00|ICH5US"

.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Voltooingstijd: 2008-05-01 0:42:53 - machine was rebooted [Gerrit]
ComboFix-quarantined-files.txt 2008-04-30 22:42:44

Pre-Run: 2,154,799,104 bytes beschikbaar
Post-Run: 3,951,853,568 bytes beschikbaar

WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

235 --- E O F --- 2008-04-10 06:48:15



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0:44:14, on 1-5-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
E:\ProgramFilesOpE\Nikon\NkbMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7583897b-814f-4e89-b578-62e286d62da3} - C:\WINDOWS\system32\mlJBqpNE.dll (disabled by BHODemon)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8ec52dd5-ea49-4997-be65-a54fe00ca6ef} - C:\WINDOWS\system32\xxyayVME.dll (file missing)
O2 - BHO: (no name) - {a92c32f3-42ec-4b80-b9f9-3a64dcf4aac4} - C:\WINDOWS\system32\xxywVMdB.dll (disabled by BHODemon)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: (no name) - {e418e98e-11b6-4833-8ea0-69893ea1cc50} - C:\WINDOWS\system32\wvUMffFY.dll (disabled by BHODemon)
O2 - BHO: (no name) - {ec591c61-9c3f-4f33-956d-1259e1b02c1d} - C:\WINDOWS\system32\iifdEwwV.dll (disabled by BHODemon)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = E:\ProgramFilesOpE\Nikon\NkbMonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.paradigit.nl
O16 - DPF: {0eb0e74a-2a76-4ab3-a7fb-9bd8c29f7f75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188749819875
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://fotoservice.tntpost.nl/TNT/UserControls/Part/Upload/ImageUploader4.cab
O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} (Navigram Control) - http://www.navigram.com/engine/v911/Navigram.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D83C1BD1-DCBB-11D4-9425-0050BF33FA6E} (CycloScopeLite Control) - http://www.cyclomedia.nl/download/components/CycloScopeLite.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://193.172.162.99:8080/activex/AMC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://webaccess.minvenw.nl/dana-cached/setup/JuniperSetupSP1.cab
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 8589 bytes

Rorschach112
2008-05-01, 00:54
Hello

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:


File::
C:\WINDOWS\system32\botdxyeb.ini
C:\WINDOWS\system32\kmcwdnyt.ini
C:\WINDOWS\system32\iiasjeoj.ini
C:\WINDOWS\system32\rwehoanj.ini
C:\WINDOWS\system32\nktpxmip.ini
C:\WINDOWS\system32\bnhydiox.ini
C:\WINDOWS\BMd3887a5c.xml
C:\WINDOWS\system32\pggqrtta.tmp
C:\mxuxc.exe
C:\-793032337
C:\WINDOWS\system32\qspwnleh.dll

Folder::

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BMd3887a5c"=-

Driver::



Save this as CFScript.txt, in the same location as ComboFix.exe


http://i266.photobucket.com/albums/ii277/sUBs_/Combo-Do.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall



Reboot and post a new HijackThis log

ITFox
2008-05-01, 01:13
Dear Rorschach112,

Please find the 2 logs asked for.

ComboFix 08-04-29.5 - Gerrit 2008-05-01 1:00:09.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.747 [GMT 2:00]
Gestart vanuit: K:\ComboFix.exe
Command switches used :: C:\Documents and Settings\Gerrit\Bureaublad\CFscript.txt
* Nieuw herstelpunt werd aangemaakt

FILE ::
C:\-793032337
C:\mxuxc.exe
C:\WINDOWS\BMd3887a5c.xml
C:\WINDOWS\system32\bnhydiox.ini
C:\WINDOWS\system32\botdxyeb.ini
C:\WINDOWS\system32\iiasjeoj.ini
C:\WINDOWS\system32\kmcwdnyt.ini
C:\WINDOWS\system32\nktpxmip.ini
C:\WINDOWS\system32\pggqrtta.tmp
C:\WINDOWS\system32\qspwnleh.dll
C:\WINDOWS\system32\rwehoanj.ini
.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\-793032337
C:\mxuxc.exe
C:\WINDOWS\BMd3887a5c.xml
C:\WINDOWS\system32\bnhydiox.ini
C:\WINDOWS\system32\botdxyeb.ini
C:\WINDOWS\system32\iiasjeoj.ini
C:\WINDOWS\system32\kmcwdnyt.ini
C:\WINDOWS\system32\nktpxmip.ini
C:\WINDOWS\system32\pggqrtta.tmp
C:\WINDOWS\system32\rwehoanj.ini

.
(((((((((((((((((((( Bestanden Gemaakt van 2008-03-28 to 2008-04-30 ))))))))))))))))))))))))))))))
.

2008-04-15 19:07 . 2008-04-15 19:07 <DIR> d----c--- C:\WINDOWS\system32\Kaspersky Lab
2008-04-15 19:07 . 2008-04-15 19:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-13 23:53 . 2008-04-13 23:53 <DIR> d----c--- C:\Program Files\Trend Micro
2008-04-11 23:03 . 2004-08-04 10:03 221,184 --a--c--- C:\WINDOWS\system32\wmpns.dll
2008-04-10 19:57 . 2008-04-10 19:57 <DIR> d----c--- C:\Program Files\ZoneAlarmSB
2008-04-10 19:55 . 2008-03-13 23:11 1,086,952 --a--c--- C:\WINDOWS\system32\zpeng24.dll
2008-04-10 15:55 . 2008-04-27 23:54 962 --a--c--- C:\WINDOWS\wininit.ini
2008-04-10 14:46 . 2008-04-10 14:45 691,545 --a--c--- C:\WINDOWS\unins000.exe
2008-04-10 14:46 . 2008-04-10 14:46 2,548 --a--c--- C:\WINDOWS\unins000.dat
2008-04-03 17:51 . 2008-04-03 17:51 5,539,678 --a--c--- C:\Documents and Settings\Gerrit\neoteris_read_13228332.reg
2008-04-01 20:06 . 2008-04-01 20:06 664 --a--c--- C:\WINDOWS\system32\d3d9caps.dat
2008-04-01 07:58 . 2008-04-01 07:58 268 --ah----- C:\sqmdata14.sqm
2008-04-01 07:58 . 2008-04-01 07:58 244 --ah----- C:\sqmnoopt14.sqm
2008-03-31 21:51 . 2008-03-31 21:51 268 --ah----- C:\sqmdata13.sqm
2008-03-31 21:51 . 2008-03-31 21:51 244 --ah----- C:\sqmnoopt13.sqm
2008-03-31 18:34 . 2008-03-31 21:46 <DIR> d-------- C:\Documents and Settings\Rick\Sjablonen
2008-03-31 18:34 . 2008-03-31 21:46 <DIR> d-------- C:\Documents and Settings\Rick\Favorieten
2008-03-31 18:34 . 2008-03-31 18:34 <DIR> d-------- C:\Documents and Settings\Rick\Application Data\Ipswitch
2008-03-31 18:34 . 2008-03-31 21:46 <DIR> d---s---- C:\Documents and Settings\Rick
2008-03-31 18:34 . 2008-05-01 00:20 1,024 --ah----- C:\Documents and Settings\Rick\ntuser.dat.LOG
2008-03-31 15:41 . 2008-03-31 15:41 244 --ah----- C:\sqmnoopt12.sqm
2008-03-31 15:41 . 2008-03-31 15:41 232 --ah----- C:\sqmdata12.sqm
2008-03-30 17:29 . 2008-03-30 17:29 <DIR> d----c--- C:\Program Files\LEGO Media
2008-03-28 12:03 . 2008-03-28 12:03 0 --a--c--- C:\WINDOWS\webica.ini
2008-03-28 12:01 . 2008-03-28 12:01 <DIR> d----c--- C:\WINDOWS\system32\Resource
2008-03-28 12:01 . 2008-03-28 12:01 <DIR> d----c--- C:\Program Files\Citrix
2008-03-28 12:01 . 2008-03-28 12:04 <DIR> d----c--- C:\Documents and Settings\Gerrit\Application Data\ICAClient
2008-03-25 03:14 . 2008-03-25 03:14 47,104 --ahsc--- C:\WINDOWS\Thumbs.db
2008-03-25 03:14 . 2008-03-25 03:14 5,632 --ahsc--- C:\WINDOWS\system32\Thumbs.db
2008-03-24 14:49 . 2008-03-24 14:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-24 14:47 . 2008-03-24 14:47 <DIR> d----c--- C:\Program Files\Apple Software Update
2008-03-24 14:47 . 2008-03-24 14:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-03-23 16:41 . 2008-03-23 16:55 <DIR> d----c--- C:\Documents and Settings\Bart\.freemind
2008-03-22 18:46 . 1998-09-18 12:55 27,648 --a--c--- C:\WINDOWS\system32\qtuninst.dll
2008-03-22 18:45 . 1998-09-09 13:07 302,592 --a--c--- C:\WINDOWS\unin0413.exe
2008-03-19 18:55 . 2008-03-19 18:55 5,539,570 --a--c--- C:\Documents and Settings\Gerrit\neoteris_read_22279806.reg
2008-03-15 16:55 . 2008-03-15 16:55 <DIR> d----c--- C:\Program Files\directx
2008-03-15 16:54 . 2000-05-17 18:59 198,640 --a--c--- C:\WINDOWS\system32\Mci32.ocx
2008-03-15 16:54 . 2000-05-17 18:59 40,448 --a--c--- C:\WINDOWS\system32\regobj.dll
2008-03-02 20:51 . 2008-03-02 20:51 <DIR> d----c--- C:\Documents and Settings\Margreet.WOONKAMER.000\Application Data\Ipswitch

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-30 22:36 2,754,592 -csha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-30 22:36 13,460 -csha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-30 17:46 8,209,359 -c--a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_04_30_09_00_15_full.dmp.zip
2008-04-30 07:00 918,016 -c--a-w C:\WINDOWS\Internet Logs\xDB20.tmp
2008-04-27 21:58 104,960 -c--a-w C:\WINDOWS\Internet Logs\xDB1F.tmp
2008-04-27 08:27 332,288 -c--a-w C:\WINDOWS\Internet Logs\xDB1D.tmp
2008-04-27 08:27 1,387,008 -c--a-w C:\WINDOWS\Internet Logs\xDB1E.tmp
2008-04-16 00:17 49,076 -c--a-w C:\Documents and Settings\Gerrit\Application Data\wklnhst.dat
2008-04-15 21:37 98,816 -c--a-w C:\WINDOWS\Internet Logs\xDB1B.tmp
2008-04-15 21:37 1,386,496 -c--a-w C:\WINDOWS\Internet Logs\xDB1C.tmp
2008-04-15 21:21 972,800 -c--a-w C:\WINDOWS\Internet Logs\xDB1A.tmp
2008-04-15 17:08 435,200 -c--a-w C:\WINDOWS\Internet Logs\xDB18.tmp
2008-04-15 17:08 1,385,984 -c--a-w C:\WINDOWS\Internet Logs\xDB19.tmp
2008-04-14 11:34 239,616 -c--a-w C:\WINDOWS\Internet Logs\xDB17.tmp
2008-04-13 18:36 1,420,800 -c--a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2008-04-11 19:48 222,720 -c--a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2008-04-11 19:48 1,362,432 -c--a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2008-04-11 17:50 196,608 -c--a-w C:\WINDOWS\Internet Logs\xDB12.tmp
2008-04-11 17:50 1,358,848 -c--a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2008-04-11 17:02 336,384 -c--a-w C:\WINDOWS\Internet Logs\xDB10.tmp
2008-04-11 17:02 1,356,288 -c--a-w C:\WINDOWS\Internet Logs\xDB11.tmp
2008-04-11 15:30 200,704 -c--a-w C:\WINDOWS\Internet Logs\xDBF.tmp
2008-04-11 14:01 768,512 -c--a-w C:\WINDOWS\Internet Logs\xDBE.tmp
2008-04-10 13:58 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-10 11:09 --------- dc-h--w C:\Program Files\InstallShield Installation Information
2008-03-30 20:32 73,736 -c--a-w C:\Documents and Settings\Gerrit\Application Data\GDIPFONTCACHEV1.DAT
2008-03-26 17:05 3,630 -c--a-w C:\Documents and Settings\Bart\Application Data\wklnhst.dat
2008-03-22 16:41 --------- dc----w C:\Program Files\LimewirePlus
2008-03-20 08:10 1,845,376 -c--a-w C:\WINDOWS\system32\win32k.sys
2008-03-16 16:22 --------- dc----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-03-16 14:32 --------- dc----w C:\Program Files\Java
2008-03-13 21:11 75,248 -c--a-w C:\WINDOWS\zllsputility.exe
2008-03-01 13:05 826,368 -c--a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 -c--a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:39 45,568 -c--a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-12 00:47 2,188 -c--a-w C:\Documents and Settings\Margreet.WOONKAMER.000\Application Data\wklnhst.dat
2007-10-04 15:25 734 -c--a-w C:\Documents and Settings\Annick.WOONKAMER\Application Data\wklnhst.dat
2007-09-05 18:10 71,712 -c--a-w C:\Documents and Settings\Annick.WOONKAMER\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7583897b-814f-4e89-b578-62e286d62da3}]
C:\WINDOWS\system32\mlJBqpNE.dll__BHODemonDisabled

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8ec52dd5-ea49-4997-be65-a54fe00ca6ef}]
C:\WINDOWS\system32\xxyayVME.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a92c32f3-42ec-4b80-b9f9-3a64dcf4aac4}]
C:\WINDOWS\system32\xxywVMdB.dll__BHODemonDisabled

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e418e98e-11b6-4833-8ea0-69893ea1cc50}]
C:\WINDOWS\system32\wvUMffFY.dll__BHODemonDisabled

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ec591c61-9c3f-4f33-956d-1259e1b02c1d}]
C:\WINDOWS\system32\iifdEwwV.dll__BHODemonDisabled

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 10:03 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-03 19:57 68856]
"InstantTray"="C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe" [2003-10-22 15:03 746496]
"IW_Drop_Icon"="C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe" [2003-11-19 13:36 1134080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-10-06 15:16 5058560]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 10:03 15360]
"NvMediaCenter"="C:\WINDOWS\System32\NVMCTRAY.DLL" [2003-10-06 15:16 49152]
"InstantTray"="C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe" [2003-10-22 15:03 746496]
"IW_Drop_Icon"="C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe" [2003-11-19 13:36 1134080]

C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 10:15:56 65588]
NkbMonitor.exe.lnk - E:\ProgramFilesOpE\Nikon\NkbMonitor.exe [2007-09-06 19:40:21 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.IV41"= C:\WINDOWS\system32\Ir41_32.ax

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"=

R0 fasttrak;fasttrak;C:\WINDOWS\system32\DRIVERS\fasttrak.sys [2002-02-25 21:45]
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-09-05 18:25]
R0 VOBID;VOBID;C:\WINDOWS\system32\DRIVERS\vobid.sys [2003-08-01 14:47]
R1 vobcom;vobcom;C:\WINDOWS\system32\drivers\vobcom.sys [2001-10-04 11:53]
R1 vobiw;vobiw;C:\WINDOWS\system32\drivers\vobiw.sys [2003-08-29 13:51]
R3 cdrdrv;Cdrdrv;C:\WINDOWS\system32\Drivers\Cdrdrv.sys [2002-12-13 18:33]

*Newly Created Service* - ENTDRV51
*Newly Created Service* - PAVDRV
*Newly Created Service* - PAVPROC
*Newly Created Service* - PAVPRSRV
*Newly Created Service* - PAVSRV
*Newly Created Service* - RASMAN
*Newly Created Service* - SHLDDRV
.
Inhoud van de 'Gedeelde Taken' map
"2008-04-01 06:25:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-30 22:25:00 C:\WINDOWS\Tasks\Controleren op updates voor Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-01 01:02:44
Windows 5.1.2600 Service Pack 2 NTFS

scannen van verborgen processen ...

scannen van verborgen autostart items ...

scannen van verborgen bestanden ...

Scan succesvol afgerond
verborgen bestanden: 0

**************************************************************************
"ImagePath"="SYSTEM32\DRIVERS\viasraid.sys\00.13.01.3196
[Signed]\00|ICH5US"

.
Voltooingstijd: 2008-05-01 1:04:19
ComboFix-quarantined-files.txt 2008-04-30 23:04:05
ComboFix2.txt 2008-04-30 22:42:56

Pre-Run: 5,146,099,712 bytes beschikbaar
Post-Run: 5,112,119,296 bytes beschikbaar

191 --- E O F --- 2008-04-10 06:48:15



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:09:00, on 1-5-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
E:\ProgramFilesOpE\Nikon\NkbMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7583897b-814f-4e89-b578-62e286d62da3} - C:\WINDOWS\system32\mlJBqpNE.dll (disabled by BHODemon)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8ec52dd5-ea49-4997-be65-a54fe00ca6ef} - C:\WINDOWS\system32\xxyayVME.dll (file missing)
O2 - BHO: (no name) - {a92c32f3-42ec-4b80-b9f9-3a64dcf4aac4} - C:\WINDOWS\system32\xxywVMdB.dll (disabled by BHODemon)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: (no name) - {e418e98e-11b6-4833-8ea0-69893ea1cc50} - C:\WINDOWS\system32\wvUMffFY.dll (disabled by BHODemon)
O2 - BHO: (no name) - {ec591c61-9c3f-4f33-956d-1259e1b02c1d} - C:\WINDOWS\system32\iifdEwwV.dll (disabled by BHODemon)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = E:\ProgramFilesOpE\Nikon\NkbMonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.paradigit.nl
O16 - DPF: {0eb0e74a-2a76-4ab3-a7fb-9bd8c29f7f75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188749819875
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://fotoservice.tntpost.nl/TNT/UserControls/Part/Upload/ImageUploader4.cab
O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} (Navigram Control) - http://www.navigram.com/engine/v911/Navigram.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D83C1BD1-DCBB-11D4-9425-0050BF33FA6E} (CycloScopeLite Control) - http://www.cyclomedia.nl/download/components/CycloScopeLite.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://193.172.162.99:8080/activex/AMC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://webaccess.minvenw.nl/dana-cached/setup/JuniperSetupSP1.cab
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 8523 bytes

Rorschach112
2008-05-01, 01:21
Hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {7583897b-814f-4e89-b578-62e286d62da3} - C:\WINDOWS\system32\mlJBqpNE.dll (disabled by BHODemon)
O2 - BHO: (no name) - {8ec52dd5-ea49-4997-be65-a54fe00ca6ef} - C:\WINDOWS\system32\xxyayVME.dll (file missing)
O2 - BHO: (no name) - {a92c32f3-42ec-4b80-b9f9-3a64dcf4aac4} - C:\WINDOWS\system32\xxywVMdB.dll (disabled by BHODemon)
O2 - BHO: (no name) - {e418e98e-11b6-4833-8ea0-69893ea1cc50} - C:\WINDOWS\system32\wvUMffFY.dll (disabled by BHODemon)
O2 - BHO: (no name) - {ec591c61-9c3f-4f33-956d-1259e1b02c1d} - C:\WINDOWS\system32\iifdEwwV.dll (disabled by BHODemon)


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.




Please download Malwarebytes' Anti-Malware from Here (http://www.besttechie.net/tools/mbam-setup.exe) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Full Scan", then click Scan. Check all the boxes and click Start Scan
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Reboot and post a new HijackThis log and tell me how your PC is running

ITFox
2008-05-01, 07:58
Dear Rorschach112,

Sorry for the delay in replying, since the MBAM scan took quite a while I had it run overnight.
I found and fix checked all 5 entries mentioned.
The MBAM log is included here together with a HJT log after reboot.
The PC feels normal again, with the exception of the internet connection. I don't have internet connection still although the network is on and far less busy as at the start of our conservation. It is also possible to download e-mail with outlook express.

Malwarebytes' Anti-Malware 1.11
Database versie: 599

Scan type: Volledige Scan (C:\|D:\|E:\|F:\|I:\|)
Objecten gescand: 472855
Verstreken tijd: 3 hour(s), 10 minute(s), 24 second(s)

Geheugenprocessen geïnfecteerd: 0
Geheugenmodulen geïnfecteerd: 0
Registersleutels geïnfecteerd: 2
Registerwaarden geïnfecteerd: 0
Registerdata bestanden geïnfecteerd: 0
Mappen geïnfecteerd: 0
Bestanden geïnfecteerd: 2

Geheugenprocessen geïnfecteerd:
(Geen kwaadaardige items gevonden)

Geheugenmodulen geïnfecteerd:
(Geen kwaadaardige items gevonden)

Registersleutels geïnfecteerd:
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.

Registerwaarden geïnfecteerd:
(Geen kwaadaardige items gevonden)

Registerdata bestanden geïnfecteerd:
(Geen kwaadaardige items gevonden)

Mappen geïnfecteerd:
(Geen kwaadaardige items gevonden)

Bestanden geïnfecteerd:
F:\Program Files\Common Files\riwq\riwqd\class-barrel (Malware.Trace) -> Quarantined and deleted successfully.
F:\Program Files\Common Files\riwq\riwqd\vocabulary (Malware.Trace) -> Quarantined and deleted successfully.

----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:40:16, on 1-5-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
E:\ProgramFilesOpE\Nikon\NkbMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = E:\ProgramFilesOpE\Nikon\NkbMonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.paradigit.nl
O16 - DPF: {0eb0e74a-2a76-4ab3-a7fb-9bd8c29f7f75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {426784E5-24B2-4708-820D-117342FAD009} (Cimporter Object) - http://www.hyves.nl/cab/outlookaddressbook.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188749819875
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://fotoservice.tntpost.nl/TNT/UserControls/Part/Upload/ImageUploader4.cab
O16 - DPF: {6E718D87-6909-4FCE-92D4-EDCB2F725727} (Navigram Control) - http://www.navigram.com/engine/v911/Navigram.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D83C1BD1-DCBB-11D4-9425-0050BF33FA6E} (CycloScopeLite Control) - http://www.cyclomedia.nl/download/components/CycloScopeLite.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://193.172.162.99:8080/activex/AMC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://webaccess.minvenw.nl/dana-cached/setup/JuniperSetupSP1.cab
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 7962 bytes

Rorschach112
2008-05-01, 14:05
Your logs are clean ! We need to do a few things

Follow these steps to uninstall Combofix and tools used in the removal of malware

Click START then RUN
Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
http://i189.photobucket.com/albums/z176/EPL47/CF_Cleanup.png




You now need to update your Java and remove your older versions.

Please follow these steps to remove older version Java components.

* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.

Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here (http://java.sun.com/javase/downloads/index.jsp)



Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
SpywareBlaster (http://www.javacoolsoftware.com/sbdownload.html) protects against bad ActiveX
IE-SPYAD (http://www.spywarewarrior.com/uiuc/res/ie-spyad.exe) puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here (http://www.bleepingcomputer.com/tutorials/tutorial53.html)

* SpywareGuard (http://www.javacoolsoftware.com/sgdownload.html) offers realtime protection from spyware installation attempts.

Make Internet Explorer more secure

Click Start > Run
Type Inetcpl.cpl & click OK
Click on the Security tab
Click Reset all zones to default level
Make sure the Internet Zone is selected & Click Custom level
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
Next Click OK, then Apply button and then OK to exit the Internet Properties page.


* MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here (http://www.mozilla.org/products/firefox/)

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here (http://forums.spywareinfo.com/index.php?showtopic=60955)

Thank you for your patience, and performing all of the procedures requested.

ITFox
2008-05-01, 15:29
Thanks very much!
Your help has been great.

Combofix is removed and Java Runtime Environment (JRE) installed.
In the Add/Remove Programs section there are no items with Java Runtime Environment (JRE) in the name, but there are 2 Java(TM) 6 updates 3 and 5. Do I need to remove these as well?

I also still don't have my internet connection back although both the network (the 2 screens in the right bottom corner) and e-mail are working. Is there still something wrong in teh IE setup?

Kind regards,
Gerrit

Rorschach112
2008-05-01, 16:08
Yes those are the java ones you want to remove

Not sure about your internet problem, its weird since emails work. Maybe your firewall is blocking it. Can you get the net working in Safe Mode ?

ITFox
2008-05-01, 16:29
Thanks once more.
I removed both old Java updates.
I also restarted Zonealarm and I have internet connection again. Actually I am writing this from the infgected machine.

I will have a good reading through your recommendations for how to protect my computer against malware infections.

The speed of the PC also seems quite a bit betyter,
Is there something else I need to do?

Greetings,
Gerrit

Rorschach112
2008-05-01, 16:36
I would say ZoneAlarm was causing your internet problems, have come across that before

Nope we are all done :)


Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.

ITFox
2008-05-01, 16:39
Then thanks very much for all your help.
This is a great service and I hope you can keep up this good work.

Kind regards,
Gerrit

Rorschach112
2008-05-01, 17:24
Ok good luck

Closing the topic now :)