PDA

View Full Version : Infected w/PC Privacy Cleaner, 2008 Virus Remover, Google Redirect



RexRegum
2008-10-27, 17:34
I've been experiencing the above-listed problems for the past week. I have run Malware Bytes' Antimalware program and Combofix. Please help me decipher whether I am still infected. Here is the Combofix log:

ComboFix 08-10-26.01 - Christine 2008-10-27 11:28:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.835 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Christine\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\dao350.dll
C:\WINDOWS\system32\msdjf.dll
C:\xcrashdump.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_IPRIP
-------\Service_Iprip


((((((((((((((((((((((((( Files Created from 2008-09-27 to 2008-10-27 )))))))))))))))))))))))))))))))
.

2008-10-24 21:20 . 2008-10-15 12:34 337,408 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-23 23:06 . 2008-10-23 23:06 <DIR> d-------- C:\Documents and Settings\Christine\Application Data\MailFrontier
2008-10-23 22:54 . 2008-10-09 14:25 1,221,008 --a------ C:\WINDOWS\SYSTEM32\zpeng25.dll
2008-10-22 22:20 . 2008-10-22 22:20 <DIR> d-------- C:\Program Files\ERUNT
2008-10-19 14:36 . 2008-10-19 14:36 <DIR> d-------- C:\Documents and Settings\Christine\Application Data\Malwarebytes
2008-10-19 14:35 . 2008-10-22 18:26 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-19 14:35 . 2008-10-19 14:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-19 14:35 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-10-19 14:35 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
2008-10-18 13:03 . 2008-10-18 13:03 <DIR> d-------- C:\WINDOWS\SYSTEM32\scripting
2008-10-18 13:03 . 2008-10-18 13:03 <DIR> d-------- C:\WINDOWS\SYSTEM32\en
2008-10-18 13:03 . 2008-10-18 13:03 <DIR> d-------- C:\WINDOWS\l2schemas
2008-10-14 14:49 . 2008-09-15 08:12 1,846,400 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\win32k.sys
2008-10-14 14:49 . 2008-09-08 06:41 333,824 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\srv.sys
2008-10-14 14:48 . 2008-08-14 06:11 2,189,184 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntoskrnl.exe
2008-10-14 14:48 . 2008-08-14 06:09 2,145,280 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrnlmp.exe
2008-10-14 14:48 . 2008-08-14 05:33 2,066,048 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrnlpa.exe
2008-10-14 14:48 . 2008-08-14 05:33 2,023,936 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrpamp.exe
2008-09-29 11:00 . 2005-06-10 13:39 53,248 --a------ C:\WINDOWS\SYSTEM32\CNAS0MMK.DLL
2008-09-29 10:57 . 2006-07-05 13:01 200,704 --a------ C:\WINDOWS\SYSTEM32\CNCC4100.DLL
2008-09-29 10:57 . 2006-07-05 13:01 131,072 --a------ C:\WINDOWS\SYSTEM32\CNCLSD23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 110,592 --a------ C:\WINDOWS\SYSTEM32\CNCLST23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 110,592 --a------ C:\WINDOWS\SYSTEM32\CNCLSI23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 98,304 --a------ C:\WINDOWS\SYSTEM32\CNCLSU23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 77,824 --a------ C:\WINDOWS\SYSTEM32\CNCLSC23.DLL
2008-09-29 10:57 . 2006-07-05 13:01 73,728 --a------ C:\WINDOWS\SYSTEM32\CNCL4100.DLL
2008-09-29 10:57 . 2006-07-05 13:01 69,632 --a------ C:\WINDOWS\SYSTEM32\CNCI4100.DLL
2008-09-29 10:57 . 2006-07-05 13:02 49,152 --a------ C:\WINDOWS\SYSTEM32\cncilsc.dll
2008-09-29 10:57 . 2006-04-04 17:42 332 --a------ C:\WINDOWS\SYSTEM32\CNCMFP23.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-27 15:51 27,197,216 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-27 15:38 360,140 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-26 19:59 44,822 ----a-w C:\Documents and Settings\Christine\Application Data\wklnhst.dat
2008-10-24 02:55 22,251,195 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_10_23_22_54_18_full.dmp.zip
2008-10-21 15:58 85,320 ----a-w C:\Documents and Settings\Christine\Application Data\GDIPFONTCACHEV1.DAT
2008-10-15 19:19 --------- d-----w C:\Program Files\Yahoo!
2008-10-11 17:40 2,140,672 ----a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2008-10-11 17:40 1,802,240 ----a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2008-10-09 18:25 73,104 ----a-w C:\WINDOWS\zllsputility.exe
2008-09-24 20:44 --------- d-----w C:\Documents and Settings\Christine\Application Data\Canon
2008-09-24 20:28 --------- d-----w C:\Documents and Settings\Christine\Application Data\NewSoft
2008-09-22 00:40 2,099,200 ----a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2008-09-14 12:44 --------- d-----w C:\Program Files\NAIC Classic
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-02 13:19 --------- d-----w C:\Program Files\Audible
2008-08-30 15:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-29 02:58 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2008-08-29 02:57 --------- d-----w C:\Documents and Settings\Christine\Application Data\Creative
2008-08-29 02:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-29 02:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-08-29 01:35 --------- d-----w C:\Program Files\Creative
2008-08-29 01:30 --------- d--h--w C:\Program Files\Creative Installation Information
2008-08-29 01:27 --------- d-----w C:\Program Files\Common Files\Creative
2008-08-29 00:55 --------- d-----w C:\Program Files\illiminable
2008-08-29 00:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo
2008-08-29 00:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Creative
2008-08-15 01:12 2,197,504 ----a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2008-04-23 03:30 60,968 ----a-w C:\Documents and Settings\Christine\GoToAssistDownloadHelper.exe
2006-07-07 02:33 136 ----a-w C:\Documents and Settings\June\Application Data\wklnhst.dat
2006-05-15 17:43 8 ----a-w C:\Documents and Settings\Christine\Application Data\usb.dat.bin
2006-05-03 19:42 3,414,632 ----a-w C:\Program Files\msgrplus.exe
2006-05-03 18:54 6,109,920 ----a-w C:\Program Files\clj2550pcl6win2kxp2003-en.exe
2005-06-16 16:42 1,951,432 ----a-w C:\Program Files\Powerpoint Viewer.exe
2004-12-10 22:49 16,706,160 -c--a-w C:\Program Files\AdbeRdr60_enu_full.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-09-28 700416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-02-25 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-25 118784]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 32881]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-04-22 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-04-22 507904]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-09-01 77824]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-04-19 53248]
"DwlClient"="c:\Program Files\Common Files\Dell\EUSW\Support.exe" [2004-05-27 323584]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-12-05 50688]
"Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-05-02 270336]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 802816]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"WrtMon.exe"="C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-05-11 185896]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-10-09 981904]

C:\Documents and Settings\Christine\Start Menu\Programs\Startup\
Cyber-shot Viewer Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2006-09-08 155648]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2004-09-01 36953]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2004-09-01 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 54512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-04-22 23:31 10792 C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

S3 flash;flash;C:\WINDOWS\system32\drivers\flash.sys [2003-08-29 7040]
S3 GoToAssist;GoToAssist;C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe Start=service [ ]
.
Contents of the 'Scheduled Tasks' folder

2004-09-11 C:\WINDOWS\Tasks\ISP signup reminder 1.job
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE [2008-04-13 20:12]
.
- - - - ORPHANS REMOVED - - - -

BHO-{043D69B3-B916-426B-93C4-2C6127AD6EE3} - C:\WINDOWS\system32\msdjf.dll
BHO-{295CEBE4-488D-4B05-B51A-2C6AAEF5BCB9} - C:\WINDOWS\system32\msdjf.dll
BHO-{3C2DB88B-0CB4-44BF-9421-BA862A5411A3} - C:\WINDOWS\system32\msdjf.dll
BHO-{6854AE89-1FEB-4696-8DC6-FBE81B121C95} - C:\WINDOWS\system32\msdjf.dll
BHO-{9296DBA9-FD3D-4D61-9611-065038F95DCF} - C:\WINDOWS\system32\msdjf.dll
BHO-{AE9A9601-045E-4573-9667-A688E47EEADC} - C:\WINDOWS\system32\msdjf.dll
BHO-{BA767C30-A901-405E-9F4D-FD230087FEB2} - C:\WINDOWS\system32\msdjf.dll
BHO-{DAE96E3C-DD63-4D3B-BC18-FAA61E6CAE3E} - C:\WINDOWS\system32\msdjf.dll
BHO-{E4713CA9-BD2F-44E3-9A26-5BCA91373C2E} - C:\WINDOWS\system32\msdjf.dll
HKCU-Run-MsnMsgr - C:\Program Files\MSN Messenger\MsnMsgr.Exe
HKCU-Run-Aim6 - C:\Program Files\AIM6\aim6.exe


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.aol.com/
R0 -: HKLM-Main,Start Page = hxxp://www.comcast.net/
R0 -: HKLM-Main,Window Title = Windows Internet Explorer provided by Comcast
O8 -: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html -
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-27 11:48:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\ScanningProcess.exe
C:\WINDOWS\SYSTEM32\LEXBCES.EXE
C:\WINDOWS\SYSTEM32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\SYSTEM32\TCPSVCS.EXE
C:\WINDOWS\SYSTEM32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\WrtProc.exe
C:\WINDOWS\SYSTEM32\WBEM\wmiapsrv.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
.
**************************************************************************
.
Completion time: 2008-10-27 11:53:39 - machine was rebooted [Christine]
ComboFix-quarantined-files.txt 2008-10-27 15:53:30

Pre-Run: 34,449,137,664 bytes free
Post-Run: 34,904,899,584 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

216 --- E O F --- 2008-10-25 14:00:49

pskelley
2008-10-28, 15:32
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance) http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

Start by reading the directions posted above and pinned (sticky) to the top of this forum so you can see stuff like this:

Do NOT run 'FIXES' before helpers have analyzed the HJT log
http://forums.spybot.info/showthread.php?t=16806

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own. This tool is not a toy and not for everyday use

Once you have read the directions, post a HJT log and I will be glad to take a look.

Thanks

pskelley
2008-11-04, 23:30
Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.

Everyone else please begin a New Topic.