PDA

View Full Version : virtumonde...



ystempy
2008-07-26, 22:16
hello
this is my previouse post - http://forums.spybot.info/showthread.php?p=216822#post216822
i ran HJT - this is the log:

Logfile of HijackThis v1.99.1
Scan saved at 23:14:07, on 26/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead NERO InCD\InCD\InCDsrv.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\SOUNDMAN.EXE
D:\WINDOWS\system32\VTTimer.exe
D:\WINDOWS\system32\VTtrayp.exe
D:\Program Files\Systerac XP Tools 3\memoryo.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\PROGRA~1\MICROS~2\rapimgr.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
D:\Program Files\ThumbDrive Guard\SmartProtectionService.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Raxco\PerfectDisk\PDSched.exe
D:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - c:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: עוזר הכניסה של Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [Memory Optimizer] "D:\Program Files\Systerac XP Tools 3\memoryo.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead NERO InCD\InCD\InCD.exe
O4 - HKLM\..\Run: [egui] "D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] c:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://D:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: מחקר - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - c:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - c:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: d:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207909629484
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1207909610515
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: ckpNotify - D:\WINDOWS\SYSTEM32\ckpNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead NERO InCD\InCD\InCDsrv.exe
O23 - Service: PDEngine - Raxco Software, Inc. - D:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - D:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: SmartProtection Agent Service (SmartProtection Service) - Unknown owner - D:\Program Files\ThumbDrive Guard\SmartProtectionService.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - D:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - D:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe

THANKS

i should mention that i ran HJT after running (unsupervised) Combofix.
and there are mudh less problems with the pc now (i dont want to jinks it....)

I'm running WinXP btw.

pskelley
2008-07-27, 16:06
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

i should mention that i ran HJT after running (unsupervised) Combofix.
and there are mudh less problems with the pc now (i dont want to jinks it....)
If you want me to make sure you are clean, you need to start by reading the directions carefully which tashi posted for you and I posted again above. Those directions are pinned (sticky) to the top of the forum.
I have to assume you did not read them or else you would not have posted a HJT log from an out of date version of HJT.

3) HiJackThis log - Trend Micro HijackThis 2.0.2
Click here to download HJTInstall.exe
Once you post the correct HJT log, I shall give it and the combofix log a look.

Thanks

ystempy
2008-07-27, 16:43
well, i accept your remakrs...
here is the correct HJT log file:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:40:23, on 27/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead NERO InCD\InCD\InCDsrv.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\SOUNDMAN.EXE
D:\WINDOWS\system32\VTTimer.exe
D:\WINDOWS\system32\VTtrayp.exe
D:\Program Files\Systerac XP Tools 3\memoryo.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Raxco\PerfectDisk\PDSched.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {099AC52C-1CD4-434C-9CC6-FF56DABB5010} - (no file)
O2 - BHO: (no name) - {14F72990-3D28-4A51-AB94-B2B8CB46BF18} - (no file)
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - c:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8AFAF54C-61B8-43E9-9D56-638B3D367BEA} - (no file)
O2 - BHO: עוזר הכניסה של Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: (no name) - {CE830E55-425B-4BB2-A3DD-E2B0DAE26D03} - (no file)
O2 - BHO: (no name) - {F62780DB-E31A-43CE-99C7-CB48D65C2170} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [Memory Optimizer] "D:\Program Files\Systerac XP Tools 3\memoryo.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead NERO InCD\InCD\InCD.exe
O4 - HKLM\..\Run: [egui] "D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] c:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://D:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: מחקר - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - c:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - c:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207909629484
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1207909610515
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead NERO InCD\InCD\InCDsrv.exe
O23 - Service: PDEngine - Raxco Software, Inc. - D:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - D:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - D:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - D:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe

--
End of file - 9242 bytes

pskelley
2008-07-27, 16:56
Added for convenience of viewing information:

ComboFix 08-07-25.7 - Noga&Yonatan 07/26/2008 19:19:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1255.1.1033.18.805 [GMT 2:00]
Running from: D:\Documents and Settings\Noga&Yonatan\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
D:\WINDOWS\BM1bcb48c5.txt
D:\WINDOWS\pskt.ini
D:\WINDOWS\system32\bLTtwyay.ini
D:\WINDOWS\system32\bLTtwyay.ini2
D:\WINDOWS\system32\byXOeCVM.dll
D:\WINDOWS\system32\ldtkbvpx.ini
D:\WINDOWS\system32\mcrh.tmp
D:\WINDOWS\system32\OUBLRXyb.ini
D:\WINDOWS\system32\OUBLRXyb.ini2
D:\WINDOWS\system32\yaywtTLb.dll

----- BITS: Possible infected sites -----

http://j+|Cv+@J:NGD_DQ{ztHG.XaB,Db|I9
.
((((((((((((((((((((((((( Files Created from 2008-06-26 to 2008-07-26 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-26 15:16 --------- d-----w D:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-26 15:15 --------- d-----w D:\Program Files\Common Files\Wise Installation Wizard
2008-07-26 13:02 --------- d-----w D:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-07-26 12:49 --------- d-----w D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-26 12:45 --------- d-----w D:\Program Files\Security Task Manager
2008-07-26 08:08 --------- d-----w D:\Program Files\Lavasoft
2008-07-25 23:29 --------- d-----w D:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-07-25 22:36 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-07-25 08:15 --------- d-----w D:\Documents and Settings\Noga&Yonatan\Application Data\uTorrent
2008-07-23 18:16 --------- d-----w D:\Program Files\CheckPoint
2008-07-12 14:39 2,829 ----a-w D:\WINDOWS\War3Unin.pif
2008-07-12 14:39 139,264 ----a-w D:\WINDOWS\War3Unin.exe
2008-07-04 14:31 --------- d-----w D:\Program Files\Resco
2008-07-04 14:30 --------- d-----w D:\Program Files\Microsoft ActiveSync
2008-06-20 11:39 --------- d-----w D:\Program Files\Common Files\Adobe Systems Shared
2008-06-20 11:39 --------- d-----w D:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-06-20 11:36 --------- d-----w D:\Program Files\Common Files\Adobe
2008-06-20 10:44 360,960 ----a-w D:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w D:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:32 225,920 ----a-w D:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:20 --------- d-----w D:\Documents and Settings\Noga&Yonatan\Application Data\AdobeUM
2008-06-13 21:32 --------- d-----w D:\Documents and Settings\Noga&Yonatan\Application Data\skypePM
2008-06-13 21:32 --------- d-----w D:\Documents and Settings\Noga&Yonatan\Application Data\Skype
2008-06-13 13:10 272,128 ------w D:\WINDOWS\system32\drivers\bthport.sys
2008-06-04 20:04 --------- d-----w D:\Program Files\Skype
2008-06-04 20:04 --------- d-----w D:\Program Files\Common Files\Skype
2008-06-04 20:04 --------- d-----w D:\Documents and Settings\All Users\Application Data\Skype
2008-05-29 21:54 --------- d-----w D:\Program Files\Bonjour
2008-05-29 21:45 --------- d-----w D:\Program Files\Common Files\Macrovision Shared
2008-05-22 19:07 42,474 ----a-w D:\WINDOWS\Encrypted.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [04/16/2008 08:05 PM 68856]
"H/PC Connection Agent"="D:\Program Files\Microsoft ActiveSync\wcescomm.exe" [11/13/2006 12:39 PM 1289000]
"SpybotSD TeaTimer"="c:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [07/07/2008 09:42 AM 2156368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Memory Optimizer"="D:\Program Files\Systerac XP Tools 3\memoryo.exe" [05/02/2005 08:10 PM 1056768]
"InCD"="C:\Program Files\Ahead NERO InCD\InCD\InCD.exe" [03/14/2006 04:06 AM 1397760]
"egui"="D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [12/21/2007 08:21 AM 1443072]
"Acrobat Assistant 7.0"="D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [04/23/2008 02:08 AM 483328]
"SoundMan"="SOUNDMAN.EXE" [02/09/2004 10:54 AM 65024 D:\WINDOWS\SOUNDMAN.EXE]
"VTTimer"="VTTimer.exe" [10/22/2004 10:53 AM 53248 D:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [01/11/2005 06:33 AM 143360 D:\WINDOWS\system32\VTTrayp.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
12/16/2004 03:33 PM 24672 D:\WINDOWS\system32\ckpNotify.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Picasa Media Detector"=c:\Program Files\Picasa2\PicasaMediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"<NO NAME>"=
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
"NeroFilterCheck"=D:\WINDOWS\system32\NeroCheck.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"= D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"= D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"D:\\Program Files\\NetMeeting\\conf.exe"=
"%ProgramFiles%\\SmartProtectionUSB\\Agent_Daemon.exe"=
"%ProgramFiles%\\SmartProtectionUSB\\SmartProtectionVersion.exe"=
"%ProgramFiles%\\SmartProtectionUSB\\SmartProtectionWindowsUpdate.exe"=
"D:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"D:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"D:\\Program Files\\Vmule Kazaa Lite 28\\clean.kmd"=
"D:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SERVICE.EXE"=
"D:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.EXE"=
"D:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SCC.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 Defrag32b;Defrag32Boot;D:\WINDOWS\system32\drivers\Defrag32b.sys [05/12/2005 08:47 AM]
R1 epfwtdir;epfwtdir;D:\WINDOWS\system32\DRIVERS\epfwtdir.sys [12/21/2007 08:21 AM]
R2 Defrag32;Defrag32;D:\WINDOWS\system32\drivers\Defrag32.sys [05/12/2005 08:47 AM]
R2 PDSched;PDScheduler;D:\Program Files\Raxco\PerfectDisk\PDSched.exe [05/12/2005 11:43 AM]
R2 Scap;SecureClient Application Policy Module;D:\WINDOWS\system32\DRIVERS\Scap.sys [12/16/2004 03:33 PM]
R2 SmartProtection Service;SmartProtection Agent Service;D:\Program Files\ThumbDrive Guard\SmartProtectionService.exe [04/19/2006 02:44 PM]
R2 U3SHLPDR200;U3SHLPDR200;D:\WINDOWS\System32\Drivers\U3SHLPDR200.SYS [05/15/2008 08:55 PM]
R2 VPN-1;VPN-1 Module;D:\WINDOWS\system32\drivers\vpn.sys [12/16/2004 03:33 PM]
R3 FW1;SecuRemote Miniport;D:\WINDOWS\system32\DRIVERS\fw.sys [12/16/2004 03:33 PM]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;C:\Program Files\Lavalys\EVEREST Professional\kerneld.wnt [10/21/2004 11:00 PM]
S3 OMVA;VPN-1 SecureClient Adapter;D:\WINDOWS\system32\DRIVERS\OMVA.sys [12/16/2004 03:33 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\autoplay.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\autoplay.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b92cec1e-2292-11dd-bdd2-00115b8f1561}]
\Shell\AutoRun\command - I:\AutoRun.exe
\Shell\configure\command - I:\ThumbDriveGuardSetup.exe
\Shell\install\command - I:\ThumbDriveGuardSetup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4A8258C0-7856-84C5-8BEE-10876FC74123}]
D:\WINDOWS:emulee.exe
.
- - - - ORPHANS REMOVED - - - -

BHO-{099AC52C-1CD4-434C-9CC6-FF56DABB5010} - (no file)
BHO-{14F72990-3D28-4A51-AB94-B2B8CB46BF18} - (no file)
BHO-{8AFAF54C-61B8-43E9-9D56-638B3D367BEA} - D:\WINDOWS\system32\urqopoop.dll
BHO-{CE830E55-425B-4BB2-A3DD-E2B0DAE26D03} - D:\WINDOWS\system32\byXRLBUO.dll
BHO-{F62780DB-E31A-43CE-99C7-CB48D65C2170} - D:\WINDOWS\system32\ddcYOIaw.dll
HKLM-Run-a87758fd - D:\WINDOWS\system32\uetpvhkg.dll


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,Default_Search_URL = hxxp://www.google.com/ie
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie
R0 -: HKLM-Main,Default_Search_URL = hxxp://www.google.com/ie
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
R0 -: HKCU-Search,SearchAssistant = hxxp://www.google.com/ie
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
R0 -: HKLM-Search,SearchAssistant = hxxp://www.google.com/ie
O8 -: &יצא ל- Microsoft Excel - D:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 -: Convert link target to Adobe PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert to existing PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-26 19:25:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\C:\Program Files\Lavalys\EVEREST Professional\kerneld.wnt"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Ahead NERO InCD\InCD\InCDsrv.exe
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
D:\PROGRA~1\MICROS~2\rapimgr.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
D:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 07/26/2008 19:30:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-26 17:30:35

Pre-Run: 34,283,765,760 bytes free
Post-Run: 34,599,047,168 bytes free

192 --- E O F --- 2008-07-10 18:25:57

pskelley
2008-07-27, 17:04
Thanks for returning your HJT log, let's proceed like this:

1) We need first to disable TeaTimer that it doesn't interfere with fixes. You can re-enable it when you're clean again:
* Run Spybot-S&D in Advanced Mode.
* If it is not already set to do this Go to the Mode menu select "Advanced Mode"
* On the left hand side, Click on Tools
* Then click on the Resident Icon in the List
* Uncheck "Resident TeaTimer" and OK any prompts.
* Restart your computer.
(leave TT disabled until we finish)

2) Download ResetTeaTimer.bat to the Desktop
http://downloads.subratam.org/ResetTeaTimer.bat
Double click ResetTeaTimer.bat
to remove all entries set by TeaTimer (and preventing TeaTimer to restore them upon reactivation).

3) Please download ATF Cleaner by Atribune
http://www.atribune.org/public-beta/ATF-Cleaner.exe
Save it to your Desktop. We will use this later.

4) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

(leave this if you set it that way on purpose)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

O2 - BHO: (no name) - {099AC52C-1CD4-434C-9CC6-FF56DABB5010} - (no file)
O2 - BHO: (no name) - {14F72990-3D28-4A51-AB94-B2B8CB46BF18} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8AFAF54C-61B8-43E9-9D56-638B3D367BEA} - (no file)
O2 - BHO: (no name) - {CE830E55-425B-4BB2-A3DD-E2B0DAE26D03} - (no file)
O2 - BHO: (no name) - {F62780DB-E31A-43CE-99C7-CB48D65C2170} - (no file)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

5) Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

6) Download Malwarebytes' Anti-Malware to your Desktop
http://www.besttechie.net/tools/mbam-setup.exe

* Double-click mbam-setup.exe and follow the prompts to install the program.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform FULL SCAN, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
* Please post contents of that file & a new HJT log in your next reply.

How is the computer running? Any malware issues at all?

Thanks

D:\Program Files\Java\jre1.6.0_05\ <<< update your Java program, see this:
http://forums.spybot.info/showpost.php?p=12880&postcount=2

ystempy
2008-07-27, 18:01
4) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

(leave this if you set it that way on purpose)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

O2 - BHO: (no name) - {099AC52C-1CD4-434C-9CC6-FF56DABB5010} - (no file)
O2 - BHO: (no name) - {14F72990-3D28-4A51-AB94-B2B8CB46BF18} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8AFAF54C-61B8-43E9-9D56-638B3D367BEA} - (no file)
O2 - BHO: (no name) - {CE830E55-425B-4BB2-A3DD-E2B0DAE26D03} - (no file)
O2 - BHO: (no name) - {F62780DB-E31A-43CE-99C7-CB48D65C2170} - (no file)


thanks! will do right away!
however - except for the blank homepage - i dont know the meaning of the other items you mentioned - how can i know wether i want to keep them or not?

another question - NOW (before doing the steps u've mentioned) my computer is running without malware issues. should i procees just to make sure it is really clean, or wait untill the malware issues will return? is there any risk following these steps?
thanks

ystempy
2008-07-27, 18:15
i d/l teatimer reset
when running it i'm getting a message :

"Spybot and teatimer nust be closed" (which they are)
"press any key to continue" (i did)
"the system cannot find the path specified"
"finished"

i dont know if it's relevant, but my desktop is on drive d: and the spybot is installed on drive c:\program files\etc..

pskelley
2008-07-27, 18:19
1) DO NOT quote my instructions, it is a waste of space. Scroll back or print them if you need them, I know what I said.

2) All 02 items are orphans (leftover once the files has been removed)

3) Follow the directions as posted.

pskelley
2008-07-27, 18:25
If you can't use ResetTeaTimer.bat as instructed, uninstall Spybot S&D completely, then remove the items with HJT as instructed. Then reinstall Spybot S&D

Make sure you reboot after the uninstall.

Spybot-S&D 1.6 has arrived! 8. July 2008
http://www.safer-networking.org/en/
http://www.safer-networking.org/en/news/2008-07-08.html

ystempy
2008-07-27, 19:37
Malwarebytes' Anti-Malware 1.23
Database version: 998
Windows 5.1.2600 Service Pack 2

20:34:21 27/07/2008
mbam-log-7-27-2008 (20-34-21).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 112678
Time elapsed: 47 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
D:\Program Files\Systerac XP Tools 3\iea.exe (Rogue.PornCleanser) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{2C9B2F26-AAC2-4E99-A89A-26D64756BDB6}\RP147\A0039818.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{2C9B2F26-AAC2-4E99-A89A-26D64756BDB6}\RP147\A0039820.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{2C9B2F26-AAC2-4E99-A89A-26D64756BDB6}\RP147\A0039821.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\VundoFix Backups\iklbyxdd.dll.bad (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\VundoFix Backups\outmvaip.dll.bad (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\VundoFix Backups\tvpbvmbr.dll.bad (Trojan.Vundo) -> Quarantined and deleted successfully.

=====================================================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:35:40, on 27/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead NERO InCD\InCD\InCDsrv.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\SOUNDMAN.EXE
D:\WINDOWS\system32\VTTimer.exe
D:\WINDOWS\system32\VTtrayp.exe
D:\Program Files\Systerac XP Tools 3\memoryo.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Microsoft ActiveSync\Wcescomm.exe
D:\PROGRA~1\MICROS~2\rapimgr.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Raxco\PerfectDisk\PDSched.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\NOTEPAD.EXE
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: עוזר הכניסה של Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [Memory Optimizer] "D:\Program Files\Systerac XP Tools 3\memoryo.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead NERO InCD\InCD\InCD.exe
O4 - HKLM\..\Run: [egui] "D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://D:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: מחקר - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207909629484
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1207909610515
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead NERO InCD\InCD\InCDsrv.exe
O23 - Service: PDEngine - Raxco Software, Inc. - D:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - D:\Program Files\Raxco\PerfectDisk\PDSched.exe

--
End of file - 8428 bytes



===============================================
QUESTION:
can i install spybot now?

thank you.

pskelley
2008-07-27, 19:59
QUESTION: can i install spybot now?
Please wait until we are finished so we don't have to mess with TeaTimer..


How is the computer running? Any malware issues at all?

This is the next step:
I am sure you saw this:
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Review that information to understand Recovery Console. Installation is optional but if you do not have the CD's needed, as is explained, it can be installed before we remove combofix.
If you do not have access to Recovery Console via a Windows CD, I strongly advise you to install this tool.
If you do not wish to install RC, let me know so I can continue with the cleanup.
If you install RC, post the C:\*CF-RC.txt*.

Since we do not need to scan with combofix, click NO

http://img.photobucket.com/albums/v666/sUBs/RC_whatnext.gif

http://img.photobucket.com/albums/v666/sUBs/RC_AllDone.gif

Thanks

ystempy
2008-07-27, 20:57
hello again
i rad about RC and installed it.
i tried to follow your instructions and ran combofix, but did not get the "what's next" msgbox, so it went through the entire scanning... :sad:

anyway, this is the log file of the scanning:
=================================
ComboFix 08-07-27.2 - Noga&Yonatan 07/27/2008 21:40:54.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1255.1.1033.18.813 [GMT 2:00]
Running from: D:\Documents and Settings\Noga&Yonatan\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((( Files Created from 2008-06-27 to 2008-07-27 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-27 19:27 --------- d-----w D:\Program Files\Spybot - Search & Destroy
2008-07-27 19:26 --------- d-----w D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-27 19:03 --------- d-----w D:\Program Files\Systerac XP Tools 3
2008-07-27 17:34 --------- d-----w D:\Program Files\Malwarebytes' Anti-Malware
2008-07-27 17:02 --------- d-----w D:\Program Files\CheckPoint
2008-07-27 16:38 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-07-27 15:42 --------- d-----w D:\Program Files\Microsoft ActiveSync
2008-07-27 15:40 --------- d-----w D:\Program Files\Trend Micro
2008-07-26 21:31 --------- d-----w D:\Program Files\Common Files\InstallShield
2008-07-26 21:31 --------- d-----w D:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-07-26 18:03 --------- d-----w D:\Documents and Settings\Noga&Yonatan\Application Data\Malwarebytes
2008-07-26 18:03 --------- d-----w D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-26 15:16 --------- d-----w D:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-26 15:15 --------- d-----w D:\Program Files\Common Files\Wise Installation Wizard
2008-07-26 12:45 --------- d-----w D:\Program Files\Security Task Manager
2008-07-26 08:08 --------- d-----w D:\Program Files\Lavasoft
2008-07-25 23:29 --------- d-----w D:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-07-25 08:15 --------- d-----w D:\Documents and Settings\Noga&Yonatan\Application Data\uTorrent
2008-07-23 18:09 38,472 ----a-w D:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-23 18:09 17,144 ----a-w D:\WINDOWS\system32\drivers\mbam.sys
2008-07-12 14:39 2,829 ----a-w D:\WINDOWS\War3Unin.pif
2008-07-12 14:39 139,264 ----a-w D:\WINDOWS\War3Unin.exe
2008-07-04 14:31 --------- d-----w D:\Program Files\Resco
2008-06-20 17:36 245,248 ----a-w D:\WINDOWS\system32\mswsock.dll
2008-06-20 11:39 --------- d-----w D:\Program Files\Common Files\Adobe Systems Shared
2008-06-20 11:39 --------- d-----w D:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-06-20 11:36 --------- d-----w D:\Program Files\Common Files\Adobe
2008-06-20 10:44 360,960 ----a-w D:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w D:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:32 225,920 ----a-w D:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:20 --------- d-----w D:\Documents and Settings\Noga&Yonatan\Application Data\AdobeUM
2008-06-13 21:32 --------- d-----w D:\Documents and Settings\Noga&Yonatan\Application Data\skypePM
2008-06-13 21:32 --------- d-----w D:\Documents and Settings\Noga&Yonatan\Application Data\Skype
2008-06-13 13:10 272,128 ------w D:\WINDOWS\system32\drivers\bthport.sys
2008-06-04 20:04 --------- d-----w D:\Program Files\Skype
2008-06-04 20:04 --------- d-----w D:\Program Files\Common Files\Skype
2008-06-04 20:04 --------- d-----w D:\Documents and Settings\All Users\Application Data\Skype
2008-05-29 21:54 --------- d-----w D:\Program Files\Bonjour
2008-05-29 21:45 --------- d-----w D:\Program Files\Common Files\Macrovision Shared
2008-05-22 19:07 42,474 ----a-w D:\WINDOWS\Encrypted.exe
2008-05-16 09:58 12,632 ----a-w D:\WINDOWS\system32\lsdelete.exe
2008-05-07 04:55 1,288,192 ----a-w D:\WINDOWS\system32\quartz.dll
.

((((((((((((((((((((((((((((( snapshot@Sat 07-26-2008_19.30.14.75 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-12-16 13:33:22 69,632 ------w D:\WINDOWS\erase_SR.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\ARPPRODUCTICON.exe
+ 2008-07-27 19:03:31 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\ARPPRODUCTICON.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut1_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:32 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut1_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut10_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:32 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut10_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut11_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:32 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut11_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut12_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:32 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut12_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut13_117C48E62D0A4E9399F816452EA3E300.exe
+ 2008-07-27 19:03:32 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut13_117C48E62D0A4E9399F816452EA3E300.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut14_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:33 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut14_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut15_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:33 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut15_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut16_117C48E62D0A4E9399F816452EA3E300.exe
+ 2008-07-27 19:03:33 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut16_117C48E62D0A4E9399F816452EA3E300.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut17_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:33 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut17_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut18_117C48E62D0A4E9399F816452EA3E300.exe
+ 2008-07-27 19:03:33 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut18_117C48E62D0A4E9399F816452EA3E300.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut19_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:33 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut19_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut2_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:32 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut2_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut20_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:33 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut20_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut21_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:33 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut21_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut22_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:33 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut22_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut4_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:32 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut4_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 57,344 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut5_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:32 57,344 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut5_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut6_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:32 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut6_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut7_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:32 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut7_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut8_117C48E62D0A4E9399F816452EA3E300_1.exe
+ 2008-07-27 19:03:32 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut8_117C48E62D0A4E9399F816452EA3E300_1.exe
- 2008-04-11 12:39:07 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut9_117C48E62D0A4E9399F816452EA3E300.exe
+ 2008-07-27 19:03:32 53,248 ----a-r D:\WINDOWS\Installer\{117C48E6-2D0A-4E93-99F8-16452EA3E300}\NewShortcut9_117C48E62D0A4E9399F816452EA3E300.exe
- 2008-04-11 10:58:56 22,486 ----a-r D:\WINDOWS\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\ARPPRODUCTICON.exe
+ 2008-07-27 15:42:43 22,486 ----a-r D:\WINDOWS\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\ARPPRODUCTICON.exe
- 2008-04-11 10:58:56 22,486 ----a-r D:\WINDOWS\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\WCESMgrIcon.exe
+ 2008-07-27 15:42:43 22,486 ----a-r D:\WINDOWS\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\WCESMgrIcon.exe
+ 2001-07-14 15:32:24 69,632 ----a-w D:\WINDOWS\setupupd\temp\wsdueng.dll
- 2006-11-13 10:38:40 22,824 ----a-w D:\WINDOWS\system32\ceutil.dll
+ 2006-11-13 11:38:40 22,824 ----a-w D:\WINDOWS\system32\ceutil.dll
- 2006-11-13 10:39:28 138,024 ----a-w D:\WINDOWS\system32\rapi.dll
+ 2006-11-13 11:39:28 138,024 ----a-w D:\WINDOWS\system32\rapi.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM 15360]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [04/16/2008 08:05 PM 68856]
"H/PC Connection Agent"="D:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [11/13/2006 01:39 PM 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Memory Optimizer"="D:\Program Files\Systerac XP Tools 3\memoryo.exe" [05/02/2005 08:10 PM 1056768]
"InCD"="C:\Program Files\Ahead NERO InCD\InCD\InCD.exe" [03/14/2006 04:06 AM 1397760]
"egui"="D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [12/21/2007 08:21 AM 1443072]
"Acrobat Assistant 7.0"="D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [04/23/2008 02:08 AM 483328]
"SoundMan"="SOUNDMAN.EXE" [02/09/2004 10:54 AM 65024 D:\WINDOWS\SOUNDMAN.EXE]
"VTTimer"="VTTimer.exe" [10/22/2004 10:53 AM 53248 D:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [01/11/2005 06:33 AM 143360 D:\WINDOWS\system32\VTTrayp.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 01:56 AM 15360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Picasa Media Detector"=c:\Program Files\Picasa2\PicasaMediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"<NO NAME>"=
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
"NeroFilterCheck"=D:\WINDOWS\system32\NeroCheck.exe
"a87758fd"=rundll32.exe "D:\WINDOWS\system32\uetpvhkg.dll",b

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"D:\\Program Files\\NetMeeting\\conf.exe"=
"D:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"D:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"D:\\Program Files\\Vmule Kazaa Lite 28\\clean.kmd"=
"D:\Program Files\Microsoft ActiveSync\rapimgr.exe"= D:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"D:\Program Files\Microsoft ActiveSync\wcescomm.exe"= D:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"D:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= D:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 Defrag32b;Defrag32Boot;D:\WINDOWS\system32\drivers\Defrag32b.sys [05/12/2005 08:47 AM]
R1 epfwtdir;epfwtdir;D:\WINDOWS\system32\DRIVERS\epfwtdir.sys [12/21/2007 08:21 AM]
R2 Defrag32;Defrag32;D:\WINDOWS\system32\drivers\Defrag32.sys [05/12/2005 08:47 AM]
R2 PDSched;PDScheduler;D:\Program Files\Raxco\PerfectDisk\PDSched.exe [05/12/2005 11:43 AM]
R2 U3SHLPDR200;U3SHLPDR200;D:\WINDOWS\System32\Drivers\U3SHLPDR200.SYS [05/15/2008 08:55 PM]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;C:\Program Files\Lavalys\EVEREST Professional\kerneld.wnt [10/21/2004 11:00 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\autoplay.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b92cec1e-2292-11dd-bdd2-00115b8f1561}]
\Shell\AutoRun\command - I:\AutoRun.exe
\Shell\configure\command - I:\ThumbDriveGuardSetup.exe
\Shell\install\command - I:\ThumbDriveGuardSetup.exe

*Newly Created Service* - CATCHME

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4A8258C0-7856-84C5-8BEE-10876FC74123}]
D:\WINDOWS:emulee.exe
.
- - - - ORPHANS REMOVED - - - -

Notify-ckpNotify - (no file)


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
R0 -: HKCU-Main,Default_Search_URL = hxxp://www.google.com/ie
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: &יצא ל- Microsoft Excel - D:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 -: Convert link target to Adobe PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert to existing PDF - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-27 21:43:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\C:\Program Files\Lavalys\EVEREST Professional\kerneld.wnt"
.
Completion time: 07/27/2008 21:43:41
ComboFix-quarantined-files.txt 2008-07-27 19:43:35
ComboFix2.txt 2008-07-26 17:31:00

Pre-Run: 34,480,050,176 bytes free
Post-Run: 34,473,242,624 bytes free

212 --- E O F --- 2008-07-10 18:25:57

ystempy
2008-07-27, 21:11
BTW - i forgot to mention: no malware issues at all. thanks.

pskelley
2008-07-27, 21:21
Thanks for the feedback, appears combofix ran twice? There is no prompt to install so RC must have installed.

Remove combofix from your computer like this:
Click START then RUN
Now type or copy Combofix /u in the runbox and click OK.
Note the space between the X and the U, it needs to be there.

http://i189.photobucket.com/albums/z176/EPL47/CF_Cleanup.png


D:\VundoFix Backups <<< delete that folder and the contents

Clean infected System Restore files like this:
Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Reboot

Turn ON System Restore,
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

Run another MBAM scan to make sure it is clean, no need to post it, just let me know.

Install Spybot S&D
faq's: What is the Resident TeaTimer?
http://www.safer-networking.org/en/faq/33.html


Some good information for you:
http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html
http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/tips/mcgill1.mspx

Here is some great information from experts in this field that will help you stay clean and safe online.
http://users.telenet.be/bluepatchy/miekiemoes/prevention.html
http://forums.spybot.info/showthread.php?t=279
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

http://www.malwarecomplaints.info/

Thanks...pskelley
Safer Networking Forums
http://www.spybot.info/en/donate/index.html
If you are reading this information...thank a teacher,
If you are reading it in English...thank a soldier.

ystempy
2008-07-28, 20:19
i know you told me not to, but the last scan discovered 1 infected file (same as the previous scan). the file was Quarantined.
this is the log:

Malwarebytes' Anti-Malware 1.23
Database version: 998
Windows 5.1.2600 Service Pack 2

21:17:10 28/07/2008
mbam-log-7-28-2008 (21-17-10).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 103324
Time elapsed: 45 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
D:\Program Files\Systerac XP Tools 3\iea.exe (Rogue.PornCleanser) -> Quarantined and deleted successfully.

besides that, it all went well.

THANKS A LOT!

peace on earth and end to war.