PDA

View Full Version : Please help with a PWS.LDPinchIE infection



seseeley
2009-07-04, 04:28
When surfing the web my wifes PC is now going to sites other than directed. Spybot reports that its a PWS.LDPinchIE trojan.

I can't run regedit to check that's auto starting/ed. I get a dialog stating "Registry editing has been disabled by your administrator". ???

Also when choosing to boot to safemode the PC just reboots. I can never make it to safe mode.

The PC is now disconnected from our home network.

I've copied HJT 2.02 to her PC and ran a scan and got this error:

Please help us improve HijackThis by reporting this error
Click 'Yes' to submit
Error Details:
An unexpected error has occurred at procedure: modRegistry_IniGetString(sFile=system.ini, sSection=boot, sValue=Shell)
Error #5 - Invalid procedure call or argument
Windows version: Windows NT 5.01.2600
MSIE version: 6.0.2900.5512
HijackThis version: 2.0.2

However I ran HJT again and got this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:03:46 PM, on 7/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\windows\ld12.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\DOCUME~1\Nora\LOCALS~1\Temp\vz735ap.exe
C:\DOCUME~1\Nora\LOCALS~1\Temp\vz735ap.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\DOCUME~1\Nora\LOCALS~1\Temp\vz735ap.exe
C:\DOCUME~1\Nora\LOCALS~1\Temp\vz735ap.exe
C:\DOCUME~1\Nora\LOCALS~1\Temp\vz735ap.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\System32\wiaacmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://finance.yahoo.com/q/cq?d=v1&s=lltc+intc+avnr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: C:\WINDOWS\system32\gsf83iujid.dll - {D76AB2A1-00F3-42BD-F434-00BBC39C8953} - C:\WINDOWS\system32\gsf83iujid.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld12.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [A00F33A19322.exe] C:\DOCUME~1\Nora\LOCALS~1\Temp\_A00F33A19322.exe
O4 - HKCU\..\Run: [LowRiskFileTypes] C:\WINDOWS\sysguard.exe
O4 - HKCU\..\Run: [] C:\DOCUME~1\Nora\LOCALS~1\Temp\vz735ap.exe
O4 - HKCU\..\Run: [hsf7husjnfg98gi498aejhiugjkdg4] C:\DOCUME~1\Nora\LOCALS~1\Temp\vz735ap.exe
O4 - HKCU\..\Run: [Windows System Recover!] C:\DOCUME~1\Nora\LOCALS~1\Temp\taskmgr.exe
O4 - S-1-5-18 Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe (User 'Default user')
O4 - .DEFAULT User Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1192885861250
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://longsdrugs.digitalcameradeveloping.com/upload/FujifilmUploadClient.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: __c007D775 - C:\WINDOWS\system32\__c007D775.dat
O22 - SharedTaskScheduler: rtasgvfu76ew8ndkfno94 - {D76AB2A1-00F3-42BD-F434-00BBC39C8953} - C:\WINDOWS\system32\gsf83iujid.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
O24 - Desktop Component 0: (no name) - http://www.syfabrics.com/ProductPhotos/Medium/b138[1].jpg

--
End of file - 9440 bytes

Shaba
2009-07-05, 11:31
Hi seseeley

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
If you need help to disable your protection programs see here. (http://www.bleepingcomputer.com/forums/topic114351.html)

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.

seseeley
2009-07-06, 08:03
Hi Shaba,

Thanks for helping. I disabled all of the security SW. Ran ComboFix. ComboFix installed MS Recover SW. However there is no ComboFix.txt file at the C:\ drive.

I ran ComboFix a second time. CF displays a little progress bar then kill the taskmanager window and dies itself. Any idea on what is going on?

Thanks again,
Steve

Shaba
2009-07-06, 08:08
Please run combofix again in safe mode.

seseeley
2009-07-06, 08:29
Hi Shaba,

Every time I choose to boot to safe mode via F8 I see drivers loading, then the system reboots and the Dell logo displays again with the option of getting into the BIOS settings. Any other ways to boot to safe mode or run ComboFix?

My wifes PC must be a mess?

Thanks,
Steve

Shaba
2009-07-06, 10:28
Yes but it is not safe way so we try something else.

Please rename combofix.exe to something else and try again.

seseeley
2009-07-06, 22:34
Hi Shaba,

I'm happy to report that I got ComboFix to run after renaming it to TestIt. On start up after the progress bar finished the Taskmanager window closed. I opened Taskmanager quickly to see what processes where running and as soon as Taskmanager started the ComboFix window displayed.

Here then is the ComboFix and HJT logs

Thanks again for all the help,
Steve

ComboFix.txt:
ComboFix 09-07-03.03 - Nora 07/06/2009 9:02.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.767.403 [GMT -7:00]
Running from: c:\documents and settings\Nora\Desktop\testit.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Nora\LOCALS~1\Temp\csrss.exe
c:\docume~1\Nora\LOCALS~1\Temp\lsass.exe
c:\docume~1\Nora\LOCALS~1\Temp\taskmgr.exe
c:\docume~1\Nora\LOCALS~1\Temp\winlogon.exe
c:\windows\010112010146118114.dat
c:\windows\0101120101464849.dat
c:\windows\Installer\33a0d7e9.msi
c:\windows\ld12.exe
c:\windows\strt_1246633401.exe
c:\windows\strt_1246649983.exe
c:\windows\sysguard.exe
c:\windows\system32\__c007D775.dat
c:\windows\system32\gsf83iujid.dll
c:\windows\system32\iehelper.dll
c:\windows\system32\wbem\proquota.exe
C:\xcrashdump.dat

c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}


((((((((((((((((((((((((( Files Created from 2009-06-06 to 2009-07-06 )))))))))))))))))))))))))))))))
.

2009-07-06 16:07 . 2008-04-14 13:42 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2009-07-06 16:07 . 2008-04-14 13:42 50176 ----a-w- c:\windows\system32\proquota.exe
2009-07-06 05:23 . 2009-07-06 05:50 -------- d-s---w- C:\ComboFix
2009-07-04 01:33 . 2009-07-04 01:33 -------- d-----w- c:\program files\Trend Micro
2009-07-03 13:46 . 2009-07-03 13:46 26112 ----a-w- C:\jsrtadqg.exe
2009-07-03 13:45 . 2009-07-03 13:46 28672 ----a-w- C:\kkfwg.exe
2009-07-03 13:45 . 2009-07-03 13:45 96768 ----a-w- C:\fdvjfx.exe
2009-07-03 13:45 . 2009-07-03 13:45 219645 ----a-w- C:\gklrwl.exe
2009-07-03 13:42 . 2009-07-03 13:43 39424 ----a-w- C:\tcburi.exe
2009-07-03 13:42 . 2009-07-03 13:42 7680 ----a-w- C:\gswrij.exe
2009-07-03 13:42 . 2009-07-03 13:43 24576 ----a-w- C:\ttrw.exe
2009-06-30 14:16 . 2009-06-30 14:16 -------- d-----w- c:\documents and settings\Nora\Local Settings\Application Data\Yahoo
2009-06-07 16:37 . 2009-06-07 16:37 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-06-07 16:36 . 2009-06-07 16:36 -------- d-----w- c:\program files\NOS
2009-06-07 12:59 . 2009-06-07 12:59 -------- d-----w- c:\program files\Photo Story 3 for Windows
2009-06-06 22:24 . 2009-06-06 22:24 5271552 ----a-w- c:\program files\PStory.msi

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-30 14:23 . 2007-09-15 15:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-06-30 14:15 . 2007-09-15 15:11 -------- d-----w- c:\documents and settings\Nora\Application Data\Yahoo!
2009-06-30 14:15 . 2007-09-15 15:11 -------- d-----w- c:\docume~1\Nora\APPLIC~1\Yahoo!
2009-05-30 00:36 . 2009-05-30 00:36 262144 ----a-w- C:\ntuser.dat
2009-05-30 00:36 . 2007-09-15 15:06 -------- d-----w- c:\program files\Yahoo!
2009-05-30 00:36 . 2007-09-15 15:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-05-07 15:32 . 2001-08-23 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:46 . 2001-08-23 12:00 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2007-07-12 05:19 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2001-08-23 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2001-08-23 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-06 13:43 . 2009-04-06 13:43 20098288 ----a-w- c:\program files\ie8-setup-full.exe
2009-03-08 14:27 . 2009-03-08 14:27 11784984 ----a-w- c:\program files\setup-2020optin.exe
2008-10-08 13:53 . 2008-10-08 13:53 1011568 ----a-w- c:\program files\MoveMediaPlayer_071101000055.exe
2007-12-30 22:59 . 2007-12-30 22:59 21321008 ----a-w- c:\program files\QuickTimeInstaller.exe
2007-12-30 22:53 . 2007-12-30 22:53 1394568 ----a-w- c:\program files\install_easyshare.exe
2007-12-23 01:09 . 2007-08-28 00:34 25755448 ----a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2007-12-02 16:02 . 2007-12-02 16:02 6219320 ----a-w- c:\program files\picasaweb-current-setup.exe
2007-11-12 01:10 . 2007-11-12 01:10 17208 ----a-w- c:\program files\free806.zip
2007-11-11 23:23 . 2007-11-11 23:23 17460625 ----a-w- c:\program files\AmbassadorSetup.exe
2007-07-21 15:06 . 2007-07-21 15:07 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-07-21 15:01 . 2007-07-21 15:01 482512 ----a-w- c:\program files\realarcade_readersdi_stub.exe
2001-08-23 12:00 . 2001-08-23 12:00 94784 --sha-w- c:\windows\twain.dll
2008-04-14 13:42 . 2001-08-23 12:00 50688 --sha-w- c:\windows\twain_32.dll
2008-04-14 13:41 . 2001-08-23 12:00 1028096 --sha-w- c:\windows\system32\mfc42.dll
2008-04-14 13:42 . 2001-08-23 12:00 57344 --sha-w- c:\windows\system32\msvcirt.dll
2008-04-14 13:42 . 2001-08-23 12:00 413696 --sha-w- c:\windows\system32\msvcp60.dll
2008-04-14 13:42 . 2001-08-23 12:00 343040 --sha-w- c:\windows\system32\msvcrt.dll
2008-04-14 13:42 . 2001-08-23 12:00 551936 --sha-w- c:\windows\system32\oleaut32.dll
2008-04-14 13:42 . 2001-08-23 12:00 84992 --sha-w- c:\windows\system32\olepro32.dll
2008-04-14 13:42 . 2001-08-23 12:00 11776 --sha-w- c:\windows\system32\regsvr32.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-23 94208]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 139320]
"Network Associates Error Reporting Service"="c:\program files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 147514]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-08-23 196608]
"HPHmon03"="c:\windows\system32\hphmon03.exe" [2001-08-23 311296]
"CXMon"="c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-08-10 45056]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
Camio Viewer.lnk - c:\program files\Sierra Imaging\Image Expert\IXApplet.exe [2007-12-30 103424]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Camio Viewer.lnk - c:\program files\Sierra Imaging\Image Expert\IXApplet.exe [2007-12-30 103424]

c:\documents and settings\Nora\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2009-3-29 368640]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [7/16/2007 12:05 PM 58464]
R3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [8/23/2001 4:24 AM 18864]
.
Contents of the 'Scheduled Tasks' folder

2009-07-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-LowRiskFileTypes - c:\windows\sysguard.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://finance.yahoo.com/q/cq?d=v1&s=lltc+intc+avnr
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: turbotax.com
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-06 09:10
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2920)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Network Associates\Common Framework\FrameworkService.exe
c:\program files\Network Associates\VirusScan\mcshield.exe
c:\progra~1\NETWOR~1\COMMON~1\naPrdMgr.exe
c:\program files\Network Associates\VirusScan\vstskmgr.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\devldr32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-06 9:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-06 16:14

Pre-Run: 59,474,817,024 bytes free
Post-Run: 59,490,766,848 bytes free

167 --- E O F --- 2009-06-23 10:05

HJT.log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:22:14 AM, on 7/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://finance.yahoo.com/q/cq?d=v1&s=lltc+intc+avnr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - S-1-5-18 Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe (User 'Default user')
O4 - .DEFAULT User Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1192885861250
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://longsdrugs.digitalcameradeveloping.com/upload/FujifilmUploadClient.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
O24 - Desktop Component 0: (no name) - http://www.syfabrics.com/ProductPhotos/Medium/b138[1].jpg

--
End of file - 7906 bytes

Shaba
2009-07-07, 11:24
Good :)


Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


File::
C:\jsrtadqg.exe
C:\kkfwg.exe
C:\fdvjfx.exe
C:\gklrwl.exe
C:\tcburi.exe
C:\gswrij.exe
C:\ttrw.exe


Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

seseeley
2009-07-08, 06:36
Hi Shaba,

ComboFix ran find. Ask me to connect to the internet to upload files for analysis. Here's the new log file

ComboFix 09-07-03.03 - Nora 07/07/2009 20:42.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.767.481 [GMT -7:00]
Running from: c:\documents and settings\Nora\Desktop\testit.exe
Command switches used :: A:\CFScript.txt

FILE ::
"C:\fdvjfx.exe"
"C:\gklrwl.exe"
"C:\gswrij.exe"
"C:\jsrtadqg.exe"
"C:\kkfwg.exe"
"C:\tcburi.exe"
"C:\ttrw.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\fdvjfx.exe
C:\gklrwl.exe
C:\gswrij.exe
C:\jsrtadqg.exe
C:\kkfwg.exe
C:\tcburi.exe
C:\ttrw.exe

.
((((((((((((((((((((((((( Files Created from 2009-06-08 to 2009-07-08 )))))))))))))))))))))))))))))))
.

2009-07-06 16:07 . 2008-04-14 13:42 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2009-07-06 16:07 . 2008-04-14 13:42 50176 ----a-w- c:\windows\system32\proquota.exe
2009-07-06 05:23 . 2009-07-06 05:50 -------- d-s---w- C:\ComboFix
2009-07-04 01:33 . 2009-07-04 01:33 -------- d-----w- c:\program files\Trend Micro
2009-06-30 14:16 . 2009-06-30 14:16 -------- d-----w- c:\documents and settings\Nora\Local Settings\Application Data\Yahoo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-30 14:23 . 2007-09-15 15:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-06-30 14:15 . 2007-09-15 15:11 -------- d-----w- c:\documents and settings\Nora\Application Data\Yahoo!
2009-06-30 14:15 . 2007-09-15 15:11 -------- d-----w- c:\docume~1\Nora\APPLIC~1\Yahoo!
2009-06-07 16:37 . 2009-06-07 16:37 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-06-07 16:36 . 2009-06-07 16:36 -------- d-----w- c:\program files\NOS
2009-06-07 12:59 . 2009-06-07 12:59 -------- d-----w- c:\program files\Photo Story 3 for Windows
2009-06-06 22:24 . 2009-06-06 22:24 5271552 ----a-w- c:\program files\PStory.msi
2009-05-30 00:36 . 2009-05-30 00:36 262144 ----a-w- C:\ntuser.dat
2009-05-30 00:36 . 2007-09-15 15:06 -------- d-----w- c:\program files\Yahoo!
2009-05-30 00:36 . 2007-09-15 15:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-05-07 15:32 . 2001-08-23 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:46 . 2001-08-23 12:00 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2007-07-12 05:19 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2001-08-23 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2001-08-23 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-06 13:43 . 2009-04-06 13:43 20098288 ----a-w- c:\program files\ie8-setup-full.exe
2009-03-08 14:27 . 2009-03-08 14:27 11784984 ----a-w- c:\program files\setup-2020optin.exe
2008-10-08 13:53 . 2008-10-08 13:53 1011568 ----a-w- c:\program files\MoveMediaPlayer_071101000055.exe
2007-12-30 22:59 . 2007-12-30 22:59 21321008 ----a-w- c:\program files\QuickTimeInstaller.exe
2007-12-30 22:53 . 2007-12-30 22:53 1394568 ----a-w- c:\program files\install_easyshare.exe
2007-12-23 01:09 . 2007-08-28 00:34 25755448 ----a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2007-12-02 16:02 . 2007-12-02 16:02 6219320 ----a-w- c:\program files\picasaweb-current-setup.exe
2007-11-12 01:10 . 2007-11-12 01:10 17208 ----a-w- c:\program files\free806.zip
2007-11-11 23:23 . 2007-11-11 23:23 17460625 ----a-w- c:\program files\AmbassadorSetup.exe
2007-07-21 15:06 . 2007-07-21 15:07 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-07-21 15:01 . 2007-07-21 15:01 482512 ----a-w- c:\program files\realarcade_readersdi_stub.exe
2001-08-23 12:00 . 2001-08-23 12:00 94784 --sha-w- c:\windows\twain.dll
2008-04-14 13:42 . 2001-08-23 12:00 50688 --sha-w- c:\windows\twain_32.dll
2008-04-14 13:41 . 2001-08-23 12:00 1028096 --sha-w- c:\windows\system32\mfc42.dll
2008-04-14 13:42 . 2001-08-23 12:00 57344 --sha-w- c:\windows\system32\msvcirt.dll
2008-04-14 13:42 . 2001-08-23 12:00 413696 --sha-w- c:\windows\system32\msvcp60.dll
2008-04-14 13:42 . 2001-08-23 12:00 343040 --sha-w- c:\windows\system32\msvcrt.dll
2008-04-14 13:42 . 2001-08-23 12:00 551936 --sha-w- c:\windows\system32\oleaut32.dll
2008-04-14 13:42 . 2001-08-23 12:00 84992 --sha-w- c:\windows\system32\olepro32.dll
2008-04-14 13:42 . 2001-08-23 12:00 11776 --sha-w- c:\windows\system32\regsvr32.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-23 94208]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 139320]
"Network Associates Error Reporting Service"="c:\program files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 147514]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-08-23 196608]
"HPHmon03"="c:\windows\system32\hphmon03.exe" [2001-08-23 311296]
"CXMon"="c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-08-10 45056]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
Camio Viewer.lnk - c:\program files\Sierra Imaging\Image Expert\IXApplet.exe [2007-12-30 103424]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Camio Viewer.lnk - c:\program files\Sierra Imaging\Image Expert\IXApplet.exe [2007-12-30 103424]

c:\documents and settings\Nora\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2009-3-29 368640]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [7/16/2007 12:05 PM 58464]
R3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [8/23/2001 4:24 AM 18864]
.
Contents of the 'Scheduled Tasks' folder

2009-07-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://finance.yahoo.com/q/cq?d=v1&s=lltc+intc+avnr
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: turbotax.com
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-07 20:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-07-08 20:50
ComboFix-quarantined-files.txt 2009-07-08 03:50
ComboFix2.txt 2009-07-06 16:15

Pre-Run: 59,464,007,680 bytes free
Post-Run: 59,456,446,464 bytes free

132 --- E O F --- 2009-06-23 10:05

Shaba
2009-07-08, 08:20
Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply along with a fresh HijackThis log.

seseeley
2009-07-09, 07:42
Hi Shaba,

looks like some infections were found. Here is the log files for KASPERSKY and HJT.

Thanks again,
Steve

KASPERSKY log:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Wednesday, July 8, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Thursday, July 09, 2009 04:22:08
Records in database: 2446161
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 72265
Threat name: 11
Infected objects: 20
Suspicious objects: 0
Duration of the scan: 02:27:51


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\gswrij.exe.vir Infected: Trojan-Downloader.Win32.Small.jyk 1
C:\Qoobox\Quarantine\C\WINDOWS\ld12.exe.vir Infected: Trojan-Downloader.Win32.Injecter.dbz 1
C:\Qoobox\Quarantine\C\WINDOWS\sysguard.exe.vir Infected: not-a-virus:FraudTool.Win32.WinSpywareProtect.xd 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\gsf83iujid.dll.vir Infected: Trojan-Downloader.Win32.BHO.nby 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\iehelper.dll.vir Infected: Trojan.Win32.BHO.vkp 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\wbem\proquota.exe.vir Infected: Trojan.Win32.Inject.afhr 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\___c007D775_.dat.zip Infected: Trojan-Downloader.Win32.Clopack.a 1
C:\Qoobox\Quarantine\[4]-Submit_2009-07-07_20.42.47.zip Infected: P2P-Worm.Win32.Palevo.hfo 1
C:\Qoobox\Quarantine\[4]-Submit_2009-07-07_20.42.47.zip Infected: Backdoor.Win32.NewRest.an 1
C:\Qoobox\Quarantine\[4]-Submit_2009-07-07_20.42.47.zip Infected: Trojan-Downloader.Win32.Small.jyk 1
C:\Qoobox\Quarantine\[4]-Submit_2009-07-07_20.42.47.zip Infected: Trojan.Win32.FraudPack.pda 1
C:\Qoobox\Quarantine\[4]-Submit_2009-07-07_20.42.47.zip Infected: Trojan.Win32.Inject.aesq 1
C:\Qoobox\Quarantine\[4]-Submit_2009-07-07_20.42.47.zip Infected: Trojan-Downloader.Win32.Clopack.a 1
C:\System Volume Information\_restore{3C118ED2-0C68-4725-BC43-5B09A6FC1328}\RP1\A0000025.exe Infected: Trojan-Downloader.Win32.Injecter.dbz 1
C:\System Volume Information\_restore{3C118ED2-0C68-4725-BC43-5B09A6FC1328}\RP1\A0000028.exe Infected: not-a-virus:FraudTool.Win32.WinSpywareProtect.xd 1
C:\System Volume Information\_restore{3C118ED2-0C68-4725-BC43-5B09A6FC1328}\RP1\A0000029.dll Infected: Trojan-Downloader.Win32.BHO.nby 1
C:\System Volume Information\_restore{3C118ED2-0C68-4725-BC43-5B09A6FC1328}\RP1\A0000030.dll Infected: Trojan.Win32.BHO.vkp 1
C:\System Volume Information\_restore{3C118ED2-0C68-4725-BC43-5B09A6FC1328}\RP1\A0000031.exe Infected: Trojan.Win32.Inject.afhr 1
C:\System Volume Information\_restore{3C118ED2-0C68-4725-BC43-5B09A6FC1328}\RP2\A0000142.exe Infected: P2P-Worm.Win32.Palevo.hfo 1
C:\System Volume Information\_restore{3C118ED2-0C68-4725-BC43-5B09A6FC1328}\RP2\A0000144.exe Infected: Trojan-Downloader.Win32.Small.jyk 1

The selected area was scanned.

HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:34:22 PM, on 7/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\wiaacmgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Nora\Local Settings\Temp\jkos-Nora\binaries\ScanningProcess.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://finance.yahoo.com/q/cq?d=v1&s=lltc+intc+avnr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - S-1-5-18 Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe (User 'Default user')
O4 - .DEFAULT User Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1192885861250
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://longsdrugs.digitalcameradeveloping.com/upload/FujifilmUploadClient.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
O24 - Desktop Component 0: (no name) - http://www.syfabrics.com/ProductPhotos/Medium/b138[1].jpg

--
End of file - 7945 bytes

Shaba
2009-07-09, 10:37
Yes but they are in combofix quarantine and in system restore.

Empty this folder:

C:\Qoobox\Quarantine

Empty Recycle Bin.

Still problems?

seseeley
2009-07-10, 07:36
Hi Shaba,

The symtoms of IE going off and surffing on its own and SpyBotSD dialogs popping up indicating that something is trying to install or change the registry is no longer evident. I tested this by going to microsoft and intel dot com. I think the worst is behind us now.

I need to turn on virus and firewall protection.

I'm trying to decide between buying McAfee family because it has automatic updating that my wife and son need (lack of desipline) or is there a freeware solution that is as good and a no brainer?

On the firewall topic I also have a question. We've been using MS FW which I know is not good enough on its own. But I also have a FW in my LinkSys router. But maybe the LS router is not setup correctly by default. I don't have a warm fuzzy because I've never had to open a port on the router for my son who plays WoW and 2nd Life?

Thanks for your help and any recommendation you may have,
Steve Seeley

Shaba
2009-07-10, 18:17
I think that McAfee should be fine.

Using hardware FW and MS FW should be ok.

Are you ready for final instructions?

seseeley
2009-07-11, 01:14
We are ready to get this PC back on the network ...

Shaba
2009-07-11, 11:11
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:


Now lets uninstall ComboFix:

Click START then RUN
Now type Combofix /u in the runbox and click OK

Next we remove all used tools.

Please download OTCleanIt (http://download.bleepingcomputer.com/oldtimer/OTCleanIt.exe) and save it to desktop.

Double-click OTCleanIt.exe.
Click the CleanUp! button.
Select Yes when the "Begin cleanup Process?" prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTCleanIt attempting to contact the internet, please allow it to do so.

Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html)

Re-enable system restore with instructions from tutorial above

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt

Change the Download unsigned ActiveX controls to Disable

Change the Initialize and script ActiveX controls not marked as safe to Disable

Change the Installation of desktop items to Prompt

Change the Launching programs and files in an IFRAME to Prompt

Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Update your AntiVirus Software and keep your other programs up-to-date Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
You can use one of these sites to check if any updates are needed for your pc.
Secunia Software Inspector (http://secunia.com/software_inspector/)
F-secure Health Check (http://www.f-secure.com/weblog/archives/00001356.html)

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com (http://www.windowsupdate.com) regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
totally free but for real-time protection you will have to pay a small one-time fee. Tutorial on installing & using this product can be found below:

Malwarebytes' Anti-Malware Setup Guide (http://www.bfccomputers.com/forum/index.php?showtopic=1644)

Malwarebytes' Anti-Malware Scanning Guide (http://www.bfccomputers.com/forum/index.php?showtopic=1645)


Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/tutorials/tutorial49.html)


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer. See also a hosts file tutorial here (http://malwareremoval.com/forum/viewtopic.php?t=22187)
Winpatrol (http://www.winpatrol.com/) <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

Stand Up and Be Counted ---> Malware Complaints (http://www.malwarecomplaints.info/index.php) <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place (http://forums.spybot.info/showthread.php?t=279)

Happy surfing and stay clean! :bigthumb:

seseeley
2009-07-11, 19:24
Hi Shaba,

I couldn't download OTCleanIt.exe on the system we've been working on. So I downloaded it on another PC and copied over to the system. However I couldn't run it. Just a DOS looking window pops up for a second and disapears. No processes in the Task Manager window for OTCleanIt.exe either.

I was able to get into XP safe mode but got the same results. I also tried renaming OTCleanIt.exe to testit2.exe but this didn't help either.

Have any ideas on what I should try next.

Thanks,
Steve

Shaba
2009-07-12, 10:57
If you were able to run combofix /u, you can ignore that step :)

seseeley
2009-07-12, 18:42
Can I skip OTCleanup? Sorry my responses are slow but we must be on far differnent time schedules.

Once again thanks for helping,
Steve Seeley
Shingle Springs, CA (between Sacramento and Tahoe on Hiway 50)

Shaba
2009-07-12, 19:02
Yes you can if you ran combofix /u :)

seseeley
2009-07-15, 17:09
Hi Shaba,

Thanks for all the help. Just finished getting everything installed and running. I'm running all three Adaware, Malwarebytes and Spybot S&D. Adaware and Spybot S&D are real time protection. Do you think this is over kill?

Doing some reading about the firewall in the Linksys router and trying to decide if I should be using something more that Microsoft FW?

Once again thanks for the help,
Steve
Shingle Springs, CA (between Sacramento and Tahoe on Hiway 50)

Shaba
2009-07-15, 20:07
I don't see that Spybot and Ad-Aware would have real-time protection on?

You can use both hardware firewall and windows firewall.

seseeley
2009-07-16, 21:18
I thought the Tea Timer that comes with Spybot S&D was real time checking for malware?

Shaba
2009-07-16, 21:43
Ah yes, my bad.

Only one should be on so either TeaTimer or Ad-Watch :)

Shaba
2009-07-25, 11:14
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.