PDA

View Full Version : Keep getting redirected to other websites.



Fritsc
2009-09-21, 04:53
Hi.

I cannot surf properly because I keep getting to advertising websites. I hope this can be fix. I'm also using Windows on Mac. I've scanned using AVG, but nothing was detected. If I remember sometimes ago, AVG has suddenly just pop up saying a Threat Detected, and if I'm not wrong the description wrote Rootkit. Thanks.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:51:18 PM, on 9/20/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe
C:\Program Files\Parallels\Parallels Tools\prl_cc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools.exe
C:\WINDOWS\system32\usbctl.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [Parallels Shared Internet Applications] "C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" /start
O4 - HKLM\..\Run: [Parallels Tools Center] "C:\Program Files\Parallels\Parallels Tools\prl_cc.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [calc] rundll32.exe C:\WINDOWS\system32\calc.dll,_IWMPEvents@0
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [calc] rundll32.exe C:\DOCUME~1\ADMINI~1\protect.dll,_IWMPEvents@0
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [calc] rundll32.exe C:\DOCUME~1\NETWOR~1\protect.dll,_IWMPEvents@0 (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [calc] rundll32.exe C:\DOCUME~1\NETWOR~1\protect.dll,_IWMPEvents@0 (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: scandisk.dll
O4 - Startup: scandisk.lnk = ?
O4 - Startup: Warkeys Update.lnk = C:\Program Files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Parallels Coherence Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
O23 - Service: Parallels Tools Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe

--
End of file - 4776 bytes


Thanks again.

Cheers,
Fritsc

Shaba
2009-09-24, 20:33
Hi Fritsc

Download gmer.zip (http://gmer.net/gmer.zip) and save to your desktop.
alternate download site (http://hype.free.googlepages.com/gmer.zip)

Unzip/extract the file to its own folder. (Click here (http://www.bleepingcomputer.com/tutorials/tutorial105.html) for information on how to do this if not sure. Win 2000 users click here (http://www.bleepingcomputer.com/tutorials/tutorial106.html).
When you have done this, disconnect from the Internet and close all running programs.
There is a small chance this application may crash your computer so save any work you have open.
Double-click on Gmer.exe to start the program.
Allow the gmer.sys driver to load if asked.
If it gives you a warning at program start about rootkit activity and asks if you want to run a scan...click NO.
Click on the Rootkit tab.
Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
Make sure all other boxes on the right of the screen are checked, EXCEPT for "Show All".
Click on the "Scan" and wait for the scan to finish.
Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan.
When completed, click on the Copy button and right-click on your Desktop, choose "New" > Text document. Once the file is created, open it and right-click again and choose Paste or Ctrl+V. Save the file as gmer.txt and copy the information in your next reply.
Note: If you have any problems, try running GMER in SAFE MODE (http://www.bleepingcomputer.com/forums/tutorial61.html)"
Important! Please do not select the "Show all" checkbox during the scan..

Fritsc
2009-09-25, 01:14
Hi Shaba.
Thanks for helping again.

Here's the log.

GMER 1.0.15.15087 - http://www.gmer.net
Rootkit scan 2009-09-24 16:09:22
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ugkcqpow.sys


---- System - GMER 1.0.15 ----

SSDT spjy.sys ZwCreateKey [0xF842F0E0]
SSDT spjy.sys ZwEnumerateKey [0xF844DCA4]
SSDT spjy.sys ZwEnumerateValueKey [0xF844E032]
SSDT spjy.sys ZwOpenKey [0xF842F0C0]
SSDT spjy.sys ZwQueryKey [0xF844E10A]
SSDT spjy.sys ZwQueryValueKey [0xF844DF8A]
SSDT spjy.sys ZwSetValueKey [0xF844E19C]

INT 0x62 ? 823DEBF8
INT 0x94 ? 8222ABF8
INT 0xA4 ? 8222ABF8

---- Kernel code sections - GMER 1.0.15 ----

.text ntoskrnl.exe!KiDispatchInterrupt + 154 804DB9C8 6 Bytes JMP F87EA100
.text ntoskrnl.exe!KiDispatchInterrupt + 29F 804DBB13 6 Bytes JMP F87EB000
? spjy.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F81DA8AC 5 Bytes JMP 8222A1D8

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe[476] USER32.dll!ReleaseDC 7E41868D 5 Bytes JMP 00402D30 C:\Program Files\Parallels\Parallels Tools\Services\prl_hook.dll (Parallels Helper Hook/Parallels, Inc.)
.text C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe[476] USER32.dll!EndPaint 7E41B60D 5 Bytes JMP 00402D60 C:\Program Files\Parallels\Parallels Tools\Services\prl_hook.dll (Parallels Helper Hook/Parallels, Inc.)
.text C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe[476] USER32.dll!SetLayeredWindowAttributes 7E41E4DA 5 Bytes JMP 00402D90 C:\Program Files\Parallels\Parallels Tools\Services\prl_hook.dll (Parallels Helper Hook/Parallels, Inc.)
.text C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe[476] USER32.dll!UpdateLayeredWindow 7E41E873 5 Bytes JMP 00402F20 C:\Program Files\Parallels\Parallels Tools\Services\prl_hook.dll (Parallels Helper Hook/Parallels, Inc.)
.text \\.psf\Home\Documents\Downloads\gmer\gmer.exe[1572] ADVAPI32.dll!RegDeleteValueA 77DDEDE5 6 Bytes PUSH 10001A28; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text \\.psf\Home\Documents\Downloads\gmer\gmer.exe[1572] ADVAPI32.dll!RegDeleteValueW 77DDEEF1 6 Bytes PUSH 10001A51; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text C:\WINDOWS\Explorer.EXE[1588] ADVAPI32.dll!RegDeleteValueA 77DDEDE5 6 Bytes PUSH 10001A28; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text C:\WINDOWS\Explorer.EXE[1588] ADVAPI32.dll!RegDeleteValueW 77DDEEF1 6 Bytes PUSH 10001A51; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe[1892] ADVAPI32.dll!RegDeleteValueA 77DDEDE5 6 Bytes PUSH 10001A28; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe[1892] ADVAPI32.dll!RegDeleteValueW 77DDEEF1 6 Bytes PUSH 10001A51; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text C:\Program Files\Parallels\Parallels Tools\prl_cc.exe[1900] ADVAPI32.dll!RegDeleteValueA 77DDEDE5 6 Bytes PUSH 10001A28; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text C:\Program Files\Parallels\Parallels Tools\prl_cc.exe[1900] ADVAPI32.dll!RegDeleteValueW 77DDEEF1 6 Bytes PUSH 10001A51; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text C:\WINDOWS\system32\rundll32.exe[1928] ADVAPI32.dll!RegDeleteValueA 77DDEDE5 6 Bytes PUSH 10001A28; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text C:\WINDOWS\system32\rundll32.exe[1928] ADVAPI32.dll!RegDeleteValueW 77DDEEF1 6 Bytes PUSH 10001A51; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text C:\WINDOWS\system32\ctfmon.exe[1948] ADVAPI32.dll!RegDeleteValueA 77DDEDE5 6 Bytes PUSH 10001A28; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text C:\WINDOWS\system32\ctfmon.exe[1948] ADVAPI32.dll!RegDeleteValueW 77DDEEF1 6 Bytes PUSH 10001A51; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text C:\WINDOWS\system32\wuauclt.exe[3888] ADVAPI32.dll!RegDeleteValueA 77DDEDE5 6 Bytes PUSH 10001A28; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)
.text C:\WINDOWS\system32\wuauclt.exe[3888] ADVAPI32.dll!RegDeleteValueW 77DDEEF1 6 Bytes PUSH 10001A51; RET C:\WINDOWS\system32\calc.dll (Application/Microsoft)

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 823742D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F8460C4C] spjy.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F8460CA0] spjy.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F8430042] spjy.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F843013E] spjy.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F84300C0] spjy.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F8430800] spjy.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F84306D6] spjy.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 8222A2D8
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F843FE9C] spjy.sys

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 823701F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{1E587243-A7AB-4B64-8055-9830B5B19354} 8202F1F8

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBPDO-0 822291F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 823721F8
Device \Driver\dmio \Device\DmControl\DmConfig 823721F8
Device \Driver\dmio \Device\DmControl\DmPnP 823721F8
Device \Driver\dmio \Device\DmControl\DmInfo 823721F8
Device \Driver\usbehci \Device\USBPDO-1 821791F8

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Ftdisk \Device\HarddiskVolume1 823DF1F8
Device \Driver\Cdrom \Device\CdRom0 821651F8
Device \Driver\atapi \Device\Ide\IdePort0 823DE1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 823DE1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 823DE1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8202F1F8
Device \Driver\NetBT \Device\NetbiosSmb 8202F1F8

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBFDO-0 822291F8
Device \Driver\usbehci \Device\USBFDO-1 821791F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 820111F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 820111F8
Device \Driver\Ftdisk \Device\FtControl 823DF1F8
Device \FileSystem\Cdfs \Cdfs 81F171F8

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x1C 0xDC 0x3C 0x82 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x1C 0xDC 0x3C 0x82 ...

---- EOF - GMER 1.0.15 ----


And here's the new HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:13:53 PM, on 9/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe
C:\Program Files\Parallels\Parallels Tools\prl_cc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools.exe
C:\WINDOWS\system32\usbctl.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Documents and Settings\LocalService\Application Data\seres.exe
C:\Documents and Settings\LocalService\Application Data\svcst.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe
C:\WINDOWS\system32\rundll32.exe
\.psf\Home\Documents\Downloads\gmer\gmer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [Parallels Shared Internet Applications] "C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" /start
O4 - HKLM\..\Run: [Parallels Tools Center] "C:\Program Files\Parallels\Parallels Tools\prl_cc.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [calc] rundll32.exe C:\WINDOWS\system32\calc.dll,_IWMPEvents@0
O4 - HKLM\..\Run: [Antivirus Pro 2010] "C:\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe" /hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [calc] rundll32.exe C:\DOCUME~1\ADMINI~1\protect.dll,_IWMPEvents@0
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [calc] rundll32.exe C:\DOCUME~1\NETWOR~1\protect.dll,_IWMPEvents@0 (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [calc] rundll32.exe C:\DOCUME~1\NETWOR~1\protect.dll,_IWMPEvents@0 (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: scandisk.dll
O4 - Startup: scandisk.lnk = ?
O4 - Startup: Warkeys Update.lnk = C:\Program Files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Parallels Coherence Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
O23 - Service: Parallels Tools Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
O23 - Service: Microsoft USB Bus Controller (usbctl) - Unknown owner - C:\WINDOWS\system32\usbctl.exe

--
End of file - 5099 bytes


Thanks for helping again.

Shaba
2009-09-25, 06:15
We will continue with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
If you need help to disable your protection programs see here. (http://www.bleepingcomputer.com/forums/topic114351.html)

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.

Fritsc
2009-09-25, 07:04
Hi,

Here's the log for the ComboFix


ComboFix 09-09-23.02 - Administrator 09/24/2009 21:54.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.271 [GMT -7:00]
Running from: \\.psf\Home\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\protect.dll
c:\documents and settings\All Users\Application Data\enudabur.sys
c:\documents and settings\All Users\Application Data\ihobaxur.ban
c:\documents and settings\All Users\Application Data\kydijelily.lib
c:\documents and settings\All Users\Documents\idowuwuzo.com
c:\documents and settings\All Users\Documents\juraxo.dl
c:\documents and settings\All Users\Documents\ygab.sys
c:\documents and settings\All Users\Documents\ysarob.dl
c:\documents and settings\LocalService\Application Data\minyga.bat
c:\documents and settings\LocalService\Application Data\otufityveg.ban
c:\documents and settings\LocalService\Application Data\sigixuzesu.bin
c:\documents and settings\LocalService\Cookies\didihisi.lib
c:\documents and settings\LocalService\Cookies\ikizik.lib
c:\documents and settings\LocalService\Cookies\nesyrulefe.pif
c:\documents and settings\LocalService\Local Settings\Application Data\ihaqofa.bin
c:\documents and settings\LocalService\Local Settings\Application Data\wihon.pif
c:\documents and settings\LocalService\Local Settings\Temporary Internet Files\oderikejy.dl
c:\documents and settings\LocalService\Local Settings\Temporary Internet Files\rubykabyt.dl
c:\documents and settings\LocalService\Local Settings\Temporary Internet Files\vuny.dll
c:\documents and settings\LocalService\protect.dll
c:\documents and settings\NetworkService\protect.dll
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg
c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe
c:\program files\AntivirusPro_2010\AVEngn.dll
c:\program files\AntivirusPro_2010\data\daily.cvd
c:\program files\AntivirusPro_2010\htmlayout.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcm80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcp80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcr80.dll
c:\program files\AntivirusPro_2010\pthreadVC2.dll
c:\program files\AntivirusPro_2010\Uninstall.exe
c:\program files\AntivirusPro_2010\wscui.cpl
c:\program files\Common Files\yxyt.bat
c:\windows\dyzediro.pif
c:\windows\filebup.dl
c:\windows\system32\_scui.cpl
c:\windows\system32\avebu.pif
c:\windows\system32\oluj._dl
c:\windows\system32\uxuhi.dl
c:\windows\vyta.bin

.
((((((((((((((((((((((((( Files Created from 2009-08-25 to 2009-09-25 )))))))))))))))))))))))))))))))
.

2009-09-24 22:50 . 2009-09-24 22:50 14830 ----a-w- c:\windows\cima.com
2009-09-24 22:50 . 2009-09-24 22:50 14045 ----a-w- c:\windows\jyrizuv.dat
2009-09-24 22:50 . 2009-09-24 22:50 -------- d-----w- C:\AntivirusPro_2010
2009-09-21 02:48 . 2009-09-21 02:48 -------- d-----w- c:\program files\Trend Micro
2009-09-19 08:51 . 2009-09-25 02:58 -------- d-----w- C:\$AVG8.VAULT$
2009-09-19 07:21 . 2009-09-22 05:33 22528 --sha-w- c:\windows\system32\calc.dll
2009-09-19 05:43 . 2005-12-21 18:23 14592 ----a-w- c:\windows\system32\drivers\Usbicp.sys
2009-09-19 05:43 . 2009-09-19 05:43 -------- d-----w- c:\program files\DIFX
2009-09-19 05:43 . 2007-08-08 18:04 12032 ----a-w- c:\windows\system32\drivers\Lachesis.sys
2009-09-19 01:43 . 2009-09-19 01:44 -------- d-----w- c:\program files\Warkeys
2009-09-19 01:22 . 2009-09-19 01:30 97817 ----a-w- c:\windows\War3Unin.dat
2009-09-19 01:21 . 2009-09-19 01:24 2829 ----a-w- c:\windows\War3Unin.pif
2009-09-19 01:21 . 2009-09-19 01:24 139264 ----a-w- c:\windows\War3Unin.exe
2009-09-19 01:20 . 2009-09-25 04:16 -------- d-----w- c:\program files\Warcraft III
2009-09-19 01:16 . 2009-09-19 01:16 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-09-19 01:16 . 2009-09-19 05:29 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-09-19 01:14 . 2009-09-19 01:14 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-19 01:14 . 2009-09-19 01:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\DAEMON Tools Lite
2009-09-17 08:45 . 2005-01-01 09:43 4682 ----a-w- c:\windows\system32\npptNT2.sys
2009-09-17 08:44 . 2009-09-17 08:44 -------- d-----w- c:\program files\Common Files\INCA Shared
2009-09-17 08:44 . 2009-09-17 08:44 -------- d-----w- c:\windows\system32\LogFiles
2009-09-17 08:42 . 2009-09-17 08:54 -------- d-----w- c:\documents and settings\All Users\Application Data\ijjigame
2009-09-17 08:32 . 2009-09-17 08:32 -------- d--h--w- c:\documents and settings\Administrator\Application Data\ijjigame
2009-09-17 08:06 . 2009-09-17 08:06 -------- d-----w- c:\program files\ijji
2009-09-17 07:06 . 2004-08-04 05:58 14848 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-09-17 07:06 . 2004-08-04 05:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2009-09-17 07:06 . 2001-08-17 20:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-09-17 07:06 . 2001-08-17 20:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-09-17 07:06 . 2001-08-17 21:02 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-09-17 07:06 . 2001-08-17 21:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-09-17 07:06 . 2004-08-04 06:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-09-17 07:06 . 2004-08-04 06:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-09-17 06:31 . 2009-09-25 03:28 -------- d-----w- c:\program files\Garena
2009-09-17 06:28 . 2009-09-17 06:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-17 06:28 . 2009-09-17 06:28 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-17 06:28 . 2009-09-17 06:28 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-17 06:28 . 2009-09-17 06:28 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-17 06:27 . 2009-09-24 22:50 -------- d-----w- c:\windows\system32\drivers\Avg
2009-09-17 06:27 . 2009-09-17 06:27 -------- d-----w- c:\program files\AVG
2009-09-17 06:27 . 2009-09-17 06:27 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-17 06:27 . 2009-09-17 06:27 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-17 06:26 . 2009-09-17 06:28 -------- d-----w- c:\program files\SpywareBlaster
2009-09-17 06:26 . 2005-08-26 02:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-09-17 06:22 . 2009-09-17 06:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\AVG8
2009-09-17 05:38 . 2009-09-17 05:38 0 ----a-w- c:\windows\nsreg.dat
2009-09-17 05:38 . 2009-09-17 05:38 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-09-17 05:00 . 2009-09-17 05:00 12328 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-17 03:05 . 2009-09-17 03:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Parallels
2009-09-17 03:05 . 2009-09-17 03:05 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-09-17 03:04 . 2008-11-08 19:21 22848 ----a-w- c:\windows\system32\drivers\prl_tg.sys
2009-09-17 03:04 . 2008-11-08 19:20 17728 ----a-w- c:\windows\system32\drivers\prl_eth5.sys
2009-09-17 03:04 . 2008-11-08 19:21 19904 ----a-w- c:\windows\system32\drivers\prl_vamp.sys
2009-09-17 03:04 . 2008-11-08 19:21 64448 ----a-w- c:\windows\system32\prl_vadd.dll
2009-09-17 03:04 . 2008-11-08 19:15 151040 ----a-w- c:\windows\system32\prl_gl.dll
2009-09-17 03:04 . 2008-11-08 19:21 15552 ----a-w- c:\windows\system32\drivers\prl_mouf.sys
2009-09-17 03:04 . 2009-09-19 05:59 -------- dc----w- c:\windows\system32\DRVSTORE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-25 04:58 . 2009-09-25 04:58 22528 --sha-w- c:\documents and settings\Administrator\protect.dll
2009-09-24 22:50 . 2009-09-24 22:50 16078 ----a-w- c:\program files\Common Files\wyqelaxer.db
2009-09-24 22:49 . 2009-09-24 22:49 159344 ----a-w- c:\documents and settings\LocalService\Application Data\lizkavd.exe
2009-09-24 22:48 . 2009-09-24 22:48 13312 ----a-w- c:\documents and settings\LocalService\Application Data\svcst.exe
2009-09-24 22:48 . 2009-09-24 22:48 13312 ----a-w- c:\documents and settings\LocalService\Application Data\seres.exe
2009-09-17 03:04 . 2009-09-17 03:04 -------- d-----w- c:\program files\Parallels
2009-09-17 02:54 . 2009-09-17 02:54 -------- d-----w- c:\program files\microsoft frontpage
2009-09-17 02:52 . 2009-09-17 02:52 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-17 02:52 . 2009-09-17 02:51 -------- d-----w- c:\program files\Windows Media Connect 2
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"calc"="c:\docume~1\ADMINI~1\protect.dll" [2009-09-25 22528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Parallels Shared Internet Applications"="c:\program files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" [2008-11-08 67520]
"Parallels Tools Center"="c:\program files\Parallels\Parallels Tools\prl_cc.exe" [2008-11-08 90560]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-17 2007832]
"calc"="c:\windows\system32\calc.dll" [2009-09-22 22528]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
scandisk.dll [2009-9-19 22528]
scandisk.lnk - c:\windows\system32\rundll32.exe [2004-8-4 33280]
Warkeys Update.lnk - c:\program files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe [2009-5-3 244736]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-17 06:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PurpleBean.exe"=

R0 prl_pv32;prl_pv32;c:\windows\system32\drivers\prl_pv32.sys [11/8/2008 4:47 AM 101312]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/16/2009 11:28 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/16/2009 11:28 PM 108552]
R1 prl_boot;prl_boot;c:\windows\system32\drivers\prl_boot.sys [11/8/2008 12:20 PM 32576]
R1 prl_fs;Parallels Shared Folders;c:\windows\system32\drivers\prl_fs.sys [11/8/2008 12:20 PM 148288]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/16/2009 11:27 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/16/2009 11:27 PM 297752]
R2 Parallels Coherence Service;Parallels Coherence Service;c:\program files\Parallels\Parallels Tools\Services\coherence.exe [11/8/2008 12:21 PM 28096]
R2 Parallels Tools Service;Parallels Tools Service;c:\program files\Parallels\Parallels Tools\Services\prl_tools_service.exe [11/8/2008 12:20 PM 916928]
R2 prl_time;Parallels Time Synchronization Helper;c:\windows\system32\drivers\prl_time.sys [9/16/2009 8:04 PM 15680]
R3 prl_eth5;Parallels Ethernet Adapter;c:\windows\system32\drivers\prl_eth5.sys [9/16/2009 8:04 PM 17728]
R3 prl_mouf;Parallels Mouse Synchronization Device;c:\windows\system32\drivers\prl_mouf.sys [9/16/2009 8:04 PM 15552]
R3 prl_tg;Parallels Tool Device;c:\windows\system32\drivers\prl_tg.sys [9/16/2009 8:04 PM 22848]
R3 prl_va;Parallels Video Adapter;c:\windows\system32\drivers\prl_vamp.sys [9/16/2009 8:04 PM 19904]
S2 usbctl;Microsoft USB Bus Controller;c:\windows\system32\usbctl.exe --> c:\windows\system32\usbctl.exe [?]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\OFY2.tmp --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\OFY2.tmp [?]
S3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [9/18/2009 10:43 PM 12032]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
.
------- Supplementary Scan -------
.
Trusted Zone: .psf
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\kji1ut4x.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-calc - c:\docume~1\NETWOR~1\protect.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-24 21:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\OFY2.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2988)
c:\windows\system32\calc.dll
c:\windows\System32\prl_np.dll
c:\program files\Parallels\Parallels Tools\ShellIntHook.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Parallels\Parallels Tools\Services\prl_tools.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-25 21:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-25 04:59

Pre-Run: 29,715,595,264 bytes free
Post-Run: 29,895,774,208 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

231
/QUOTE]


And here's the HJT log,
[QUOTE]Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:01:30 PM, on 9/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe
C:\Program Files\Parallels\Parallels Tools\prl_cc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [Parallels Shared Internet Applications] "C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" /start
O4 - HKLM\..\Run: [Parallels Tools Center] "C:\Program Files\Parallels\Parallels Tools\prl_cc.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [calc] rundll32.exe C:\WINDOWS\system32\calc.dll,_IWMPEvents@0
O4 - HKCU\..\Run: [calc] rundll32.exe C:\DOCUME~1\ADMINI~1\protect.dll,_IWMPEvents@0
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: scandisk.dll
O4 - Startup: scandisk.lnk = ?
O4 - Startup: Warkeys Update.lnk = C:\Program Files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Parallels Coherence Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
O23 - Service: Parallels Tools Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
O23 - Service: Microsoft USB Bus Controller (usbctl) - Unknown owner - C:\WINDOWS\system32\usbctl.exe (file missing)

--
End of file - 4175 bytes


Thanks again!

Shaba
2009-09-25, 18:14
Please click this link-->Jotti (http://virusscan.jotti.org/)

Copy/paste file on the list into the white Upload a file box and click Submit/Send (depends on which one you are using Jotti or VirusTotal).

c:\windows\system32\calc.dll

Please post back the results of the scan in your next post.

If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/

Fritsc
2009-09-25, 22:50
Hi,

I didn't receive any log from Jotti, so I'm not sure if I copied the right one.
Anyway, here's the result of the scan


[ArcaVir]
2009-09-25 Found nothing
[G DATA]
2009-09-25 Trojan.Opachki.D
[A-Squared]
2009-09-25 Trojan.Win32.Opachki!IK
[Ikarus]
2009-09-25 Trojan.Win32.Opachki
[Avast! antivirus]
2009-09-25 Found nothing
[Kaspersky Anti-Virus]
2009-09-25 Found nothing
[Grisoft AVG Anti-Virus]
2009-09-25 Generic14.BFSE
[ESET NOD32]
2009-09-25 Win32/Agent.QCP
[Avira AntiVir]
2009-09-25 HEUR/Crypted
[Norman Virus Control]
2009-09-25 Found nothing
[Softwin BitDefender]
2009-09-25 Trojan.Opachki.D
[Panda Antivirus]
2009-09-25 Found nothing
[ClamAV]
2009-09-25 Found nothing
[Quick Heal]
2009-09-25 Found nothing
[CPsecure]
2009-09-25 Found nothing
[Sophos]
2009-09-25 Found nothing
[Dr.Web]
2009-09-25 Found nothing
[VirusBlokAda VBA32]
2009-09-25 Found nothing
[Frisk F-Prot Antivirus]
2009-09-25 Found nothing
[VirusBuster]
2009-09-25 Found nothing
[F-Secure Anti-Virus]
2009-09-25 Found nothing



And HJT log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:50:17 PM, on 9/25/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe
C:\Program Files\Parallels\Parallels Tools\prl_cc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Garena\Garena.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [Parallels Shared Internet Applications] "C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" /start
O4 - HKLM\..\Run: [Parallels Tools Center] "C:\Program Files\Parallels\Parallels Tools\prl_cc.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [calc] rundll32.exe C:\WINDOWS\system32\calc.dll,_IWMPEvents@0
O4 - HKCU\..\Run: [calc] rundll32.exe C:\DOCUME~1\ADMINI~1\protect.dll,_IWMPEvents@0
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: scandisk.dll
O4 - Startup: scandisk.lnk = ?
O4 - Startup: Warkeys Update.lnk = C:\Program Files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Parallels Coherence Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
O23 - Service: Parallels Tools Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
O23 - Service: Microsoft USB Bus Controller (usbctl) - Unknown owner - C:\WINDOWS\system32\usbctl.exe (file missing)

--
End of file - 4272 bytes


Thanks.

Shaba
2009-09-26, 09:13
Please download combofix again, run it and post back fresh logs :)

Fritsc
2009-09-26, 10:56
Here's the fresh logs.

ComboFix 09-09-25.01 - Administrator 09/26/2009 1:49.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.273 [GMT -7:00]
Running from: \\.psf\Home\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\protect.dll

.
((((((((((((((((((((((((( Files Created from 2009-08-26 to 2009-09-26 )))))))))))))))))))))))))))))))
.

2009-09-24 22:50 . 2009-09-24 22:50 14830 ----a-w- c:\windows\cima.com
2009-09-24 22:50 . 2009-09-24 22:50 14045 ----a-w- c:\windows\jyrizuv.dat
2009-09-24 22:50 . 2009-09-24 22:50 -------- d-----w- C:\AntivirusPro_2010
2009-09-21 02:48 . 2009-09-21 02:48 -------- d-----w- c:\program files\Trend Micro
2009-09-19 08:51 . 2009-09-25 02:58 -------- d-----w- C:\$AVG8.VAULT$
2009-09-19 07:21 . 2009-09-25 09:21 22528 --sha-w- c:\windows\system32\calc.dll
2009-09-19 05:43 . 2005-12-21 18:23 14592 ----a-w- c:\windows\system32\drivers\Usbicp.sys
2009-09-19 05:43 . 2009-09-19 05:43 -------- d-----w- c:\program files\DIFX
2009-09-19 05:43 . 2007-08-08 18:04 12032 ----a-w- c:\windows\system32\drivers\Lachesis.sys
2009-09-19 01:43 . 2009-09-19 01:44 -------- d-----w- c:\program files\Warkeys
2009-09-19 01:22 . 2009-09-19 01:30 97817 ----a-w- c:\windows\War3Unin.dat
2009-09-19 01:21 . 2009-09-19 01:24 2829 ----a-w- c:\windows\War3Unin.pif
2009-09-19 01:21 . 2009-09-19 01:24 139264 ----a-w- c:\windows\War3Unin.exe
2009-09-19 01:20 . 2009-09-25 22:48 -------- d-----w- c:\program files\Warcraft III
2009-09-19 01:16 . 2009-09-19 01:16 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-09-19 01:16 . 2009-09-19 05:29 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-09-19 01:14 . 2009-09-19 01:14 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-19 01:14 . 2009-09-19 01:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\DAEMON Tools Lite
2009-09-17 08:45 . 2005-01-01 09:43 4682 ----a-w- c:\windows\system32\npptNT2.sys
2009-09-17 08:44 . 2009-09-17 08:44 -------- d-----w- c:\program files\Common Files\INCA Shared
2009-09-17 08:44 . 2009-09-17 08:44 -------- d-----w- c:\windows\system32\LogFiles
2009-09-17 08:42 . 2009-09-17 08:54 -------- d-----w- c:\documents and settings\All Users\Application Data\ijjigame
2009-09-17 08:32 . 2009-09-17 08:32 -------- d--h--w- c:\documents and settings\Administrator\Application Data\ijjigame
2009-09-17 08:06 . 2009-09-17 08:06 -------- d-----w- c:\program files\ijji
2009-09-17 07:06 . 2004-08-04 05:58 14848 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-09-17 07:06 . 2004-08-04 05:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2009-09-17 07:06 . 2001-08-17 20:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-09-17 07:06 . 2001-08-17 20:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-09-17 07:06 . 2001-08-17 21:02 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-09-17 07:06 . 2001-08-17 21:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-09-17 07:06 . 2004-08-04 06:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-09-17 07:06 . 2004-08-04 06:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-09-17 06:31 . 2009-09-25 20:43 -------- d-----w- c:\program files\Garena
2009-09-17 06:28 . 2009-09-17 06:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-17 06:28 . 2009-09-17 06:28 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-17 06:28 . 2009-09-17 06:28 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-17 06:28 . 2009-09-17 06:28 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-17 06:27 . 2009-09-25 20:42 -------- d-----w- c:\windows\system32\drivers\Avg
2009-09-17 06:27 . 2009-09-17 06:27 -------- d-----w- c:\program files\AVG
2009-09-17 06:27 . 2009-09-17 06:27 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-17 06:27 . 2009-09-17 06:27 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-17 06:26 . 2009-09-17 06:28 -------- d-----w- c:\program files\SpywareBlaster
2009-09-17 06:26 . 2005-08-26 02:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-09-17 06:22 . 2009-09-17 06:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\AVG8
2009-09-17 05:38 . 2009-09-17 05:38 0 ----a-w- c:\windows\nsreg.dat
2009-09-17 05:38 . 2009-09-17 05:38 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-09-17 05:00 . 2009-09-17 05:00 12328 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-17 03:05 . 2009-09-17 03:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Parallels
2009-09-17 03:05 . 2009-09-17 03:05 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-09-17 03:04 . 2008-11-08 19:21 22848 ----a-w- c:\windows\system32\drivers\prl_tg.sys
2009-09-17 03:04 . 2008-11-08 19:20 17728 ----a-w- c:\windows\system32\drivers\prl_eth5.sys
2009-09-17 03:04 . 2008-11-08 19:21 19904 ----a-w- c:\windows\system32\drivers\prl_vamp.sys
2009-09-17 03:04 . 2008-11-08 19:21 64448 ----a-w- c:\windows\system32\prl_vadd.dll
2009-09-17 03:04 . 2008-11-08 19:15 151040 ----a-w- c:\windows\system32\prl_gl.dll
2009-09-17 03:04 . 2008-11-08 19:21 15552 ----a-w- c:\windows\system32\drivers\prl_mouf.sys
2009-09-17 03:04 . 2009-09-19 05:59 -------- dc----w- c:\windows\system32\DRVSTORE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-26 08:53 . 2009-09-26 08:53 22528 --sha-w- c:\documents and settings\Administrator\protect.dll
2009-09-24 22:50 . 2009-09-24 22:50 16078 ----a-w- c:\program files\Common Files\wyqelaxer.db
2009-09-24 22:49 . 2009-09-24 22:49 159344 ----a-w- c:\documents and settings\LocalService\Application Data\lizkavd.exe
2009-09-24 22:48 . 2009-09-24 22:48 13312 ----a-w- c:\documents and settings\LocalService\Application Data\svcst.exe
2009-09-24 22:48 . 2009-09-24 22:48 13312 ----a-w- c:\documents and settings\LocalService\Application Data\seres.exe
2009-09-17 03:04 . 2009-09-17 03:04 -------- d-----w- c:\program files\Parallels
2009-09-17 02:54 . 2009-09-17 02:54 -------- d-----w- c:\program files\microsoft frontpage
2009-09-17 02:52 . 2009-09-17 02:52 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-17 02:52 . 2009-09-17 02:51 -------- d-----w- c:\program files\Windows Media Connect 2
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"calc"="c:\docume~1\ADMINI~1\protect.dll" [2009-09-26 22528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Parallels Shared Internet Applications"="c:\program files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" [2008-11-08 67520]
"Parallels Tools Center"="c:\program files\Parallels\Parallels Tools\prl_cc.exe" [2008-11-08 90560]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-17 2007832]
"calc"="c:\windows\system32\calc.dll" [2009-09-25 22528]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
scandisk.dll [2009-9-19 22528]
scandisk.lnk - c:\windows\system32\rundll32.exe [2004-8-4 33280]
Warkeys Update.lnk - c:\program files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe [2009-5-3 244736]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-17 06:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PurpleBean.exe"=

R0 prl_pv32;prl_pv32;c:\windows\system32\drivers\prl_pv32.sys [11/8/2008 4:47 AM 101312]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/16/2009 11:28 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/16/2009 11:28 PM 108552]
R1 prl_boot;prl_boot;c:\windows\system32\drivers\prl_boot.sys [11/8/2008 12:20 PM 32576]
R1 prl_fs;Parallels Shared Folders;c:\windows\system32\drivers\prl_fs.sys [11/8/2008 12:20 PM 148288]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/16/2009 11:27 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/16/2009 11:27 PM 297752]
R2 Parallels Coherence Service;Parallels Coherence Service;c:\program files\Parallels\Parallels Tools\Services\coherence.exe [11/8/2008 12:21 PM 28096]
R2 Parallels Tools Service;Parallels Tools Service;c:\program files\Parallels\Parallels Tools\Services\prl_tools_service.exe [11/8/2008 12:20 PM 916928]
R2 prl_time;Parallels Time Synchronization Helper;c:\windows\system32\drivers\prl_time.sys [9/16/2009 8:04 PM 15680]
R3 prl_eth5;Parallels Ethernet Adapter;c:\windows\system32\drivers\prl_eth5.sys [9/16/2009 8:04 PM 17728]
R3 prl_mouf;Parallels Mouse Synchronization Device;c:\windows\system32\drivers\prl_mouf.sys [9/16/2009 8:04 PM 15552]
R3 prl_tg;Parallels Tool Device;c:\windows\system32\drivers\prl_tg.sys [9/16/2009 8:04 PM 22848]
R3 prl_va;Parallels Video Adapter;c:\windows\system32\drivers\prl_vamp.sys [9/16/2009 8:04 PM 19904]
S2 usbctl;Microsoft USB Bus Controller;c:\windows\system32\usbctl.exe --> c:\windows\system32\usbctl.exe [?]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\BTK1.tmp --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\BTK1.tmp [?]
S3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [9/18/2009 10:43 PM 12032]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
.
------- Supplementary Scan -------
.
Trusted Zone: .psf
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\kji1ut4x.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-26 01:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\BTK1.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2580)
c:\windows\system32\calc.dll
c:\windows\System32\prl_np.dll
c:\program files\Parallels\Parallels Tools\ShellIntHook.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Parallels\Parallels Tools\Services\prl_tools.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-26 1:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-26 08:55
ComboFix2.txt 2009-09-25 04:59

Pre-Run: 29,875,073,024 bytes free
Post-Run: 29,849,214,976 bytes free

181


And HJT logs

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:56:19 AM, on 9/26/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe
C:\Program Files\Parallels\Parallels Tools\prl_cc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [Parallels Shared Internet Applications] "C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" /start
O4 - HKLM\..\Run: [Parallels Tools Center] "C:\Program Files\Parallels\Parallels Tools\prl_cc.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [calc] rundll32.exe C:\WINDOWS\system32\calc.dll,_IWMPEvents@0
O4 - HKCU\..\Run: [calc] rundll32.exe C:\DOCUME~1\ADMINI~1\protect.dll,_IWMPEvents@0
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: scandisk.dll
O4 - Startup: scandisk.lnk = ?
O4 - Startup: Warkeys Update.lnk = C:\Program Files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Parallels Coherence Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
O23 - Service: Parallels Tools Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
O23 - Service: Microsoft USB Bus Controller (usbctl) - Unknown owner - C:\WINDOWS\system32\usbctl.exe (file missing)

--
End of file - 4174 bytes

Shaba
2009-09-26, 19:00
Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


File::
c:\windows\cima.com
c:\windows\jyrizuv.dat
c:\windows\system32\calc.dll
c:\documents and settings\Administrator\protect.dll
c:\program files\Common Files\wyqelaxer.db
c:\documents and settings\LocalService\Application Data\lizkavd.exe
c:\documents and settings\LocalService\Application Data\svcst.exe
c:\documents and settings\LocalService\Application Data\seres.exe
c:\documents and settings\Administrator\Start Menu\Programs\Startup\scandisk.dll
c:\documents and settings\Administrator\Start Menu\Programs\Startup\scandisk.lnk

Folder::
C:\AntivirusPro_2010


Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Fritsc
2009-09-26, 22:09
Hi.

Here's the log.


ComboFix 09-09-25.01 - Administrator 09/26/2009 13:03.4.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.269 [GMT -7:00]
Running from: \\.psf\Home\Desktop\ComboFix.exe
Command switches used :: \\.psf\Home\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\documents and settings\Administrator\protect.dll"
"c:\documents and settings\Administrator\Start Menu\Programs\Startup\scandisk.dll"
"c:\documents and settings\Administrator\Start Menu\Programs\Startup\scandisk.lnk"
"c:\documents and settings\LocalService\Application Data\lizkavd.exe"
"c:\documents and settings\LocalService\Application Data\seres.exe"
"c:\documents and settings\LocalService\Application Data\svcst.exe"
"c:\program files\Common Files\wyqelaxer.db"
"c:\windows\cima.com"
"c:\windows\jyrizuv.dat"
"c:\windows\system32\calc.dll"
.

((((((((((((((((((((((((( Files Created from 2009-08-26 to 2009-09-26 )))))))))))))))))))))))))))))))
.

2009-09-21 02:48 . 2009-09-21 02:48 -------- d-----w- c:\program files\Trend Micro
2009-09-19 08:51 . 2009-09-25 02:58 -------- d-----w- C:\$AVG8.VAULT$
2009-09-19 05:43 . 2005-12-21 18:23 14592 ----a-w- c:\windows\system32\drivers\Usbicp.sys
2009-09-19 05:43 . 2009-09-19 05:43 -------- d-----w- c:\program files\DIFX
2009-09-19 05:43 . 2007-08-08 18:04 12032 ----a-w- c:\windows\system32\drivers\Lachesis.sys
2009-09-19 01:43 . 2009-09-19 01:44 -------- d-----w- c:\program files\Warkeys
2009-09-19 01:22 . 2009-09-19 01:30 97817 ----a-w- c:\windows\War3Unin.dat
2009-09-19 01:21 . 2009-09-19 01:24 2829 ----a-w- c:\windows\War3Unin.pif
2009-09-19 01:21 . 2009-09-19 01:24 139264 ----a-w- c:\windows\War3Unin.exe
2009-09-19 01:20 . 2009-09-25 22:48 -------- d-----w- c:\program files\Warcraft III
2009-09-19 01:16 . 2009-09-19 01:16 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-09-19 01:16 . 2009-09-19 05:29 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-09-19 01:14 . 2009-09-19 01:14 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-19 01:14 . 2009-09-19 01:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\DAEMON Tools Lite
2009-09-17 08:45 . 2005-01-01 09:43 4682 ----a-w- c:\windows\system32\npptNT2.sys
2009-09-17 08:44 . 2009-09-17 08:44 -------- d-----w- c:\program files\Common Files\INCA Shared
2009-09-17 08:44 . 2009-09-17 08:44 -------- d-----w- c:\windows\system32\LogFiles
2009-09-17 08:42 . 2009-09-17 08:54 -------- d-----w- c:\documents and settings\All Users\Application Data\ijjigame
2009-09-17 08:32 . 2009-09-17 08:32 -------- d--h--w- c:\documents and settings\Administrator\Application Data\ijjigame
2009-09-17 08:06 . 2009-09-17 08:06 -------- d-----w- c:\program files\ijji
2009-09-17 07:06 . 2004-08-04 05:58 14848 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-09-17 07:06 . 2004-08-04 05:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2009-09-17 07:06 . 2001-08-17 20:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-09-17 07:06 . 2001-08-17 20:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-09-17 07:06 . 2001-08-17 21:02 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-09-17 07:06 . 2001-08-17 21:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-09-17 07:06 . 2004-08-04 06:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-09-17 07:06 . 2004-08-04 06:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-09-17 06:31 . 2009-09-25 20:43 -------- d-----w- c:\program files\Garena
2009-09-17 06:28 . 2009-09-17 06:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-17 06:28 . 2009-09-17 06:28 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-17 06:28 . 2009-09-17 06:28 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-17 06:28 . 2009-09-17 06:28 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-17 06:27 . 2009-09-26 19:34 -------- d-----w- c:\windows\system32\drivers\Avg
2009-09-17 06:27 . 2009-09-17 06:27 -------- d-----w- c:\program files\AVG
2009-09-17 06:27 . 2009-09-17 06:27 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-17 06:27 . 2009-09-17 06:27 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-17 06:26 . 2009-09-17 06:28 -------- d-----w- c:\program files\SpywareBlaster
2009-09-17 06:26 . 2005-08-26 02:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-09-17 06:22 . 2009-09-17 06:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\AVG8
2009-09-17 05:38 . 2009-09-17 05:38 0 ----a-w- c:\windows\nsreg.dat
2009-09-17 05:38 . 2009-09-17 05:38 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-09-17 05:00 . 2009-09-17 05:00 12328 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-17 03:05 . 2009-09-17 03:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Parallels
2009-09-17 03:05 . 2009-09-17 03:05 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-09-17 03:04 . 2008-11-08 19:21 22848 ----a-w- c:\windows\system32\drivers\prl_tg.sys
2009-09-17 03:04 . 2008-11-08 19:20 17728 ----a-w- c:\windows\system32\drivers\prl_eth5.sys
2009-09-17 03:04 . 2008-11-08 19:21 19904 ----a-w- c:\windows\system32\drivers\prl_vamp.sys
2009-09-17 03:04 . 2008-11-08 19:21 64448 ----a-w- c:\windows\system32\prl_vadd.dll
2009-09-17 03:04 . 2008-11-08 19:15 151040 ----a-w- c:\windows\system32\prl_gl.dll
2009-09-17 03:04 . 2008-11-08 19:21 15552 ----a-w- c:\windows\system32\drivers\prl_mouf.sys
2009-09-17 03:04 . 2009-09-19 05:59 -------- dc----w- c:\windows\system32\DRVSTORE
2009-09-17 03:04 . 2008-11-08 19:21 15680 ----a-w- c:\windows\system32\drivers\prl_time.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-17 03:04 . 2009-09-17 03:04 -------- d-----w- c:\program files\Parallels
2009-09-17 02:54 . 2009-09-17 02:54 -------- d-----w- c:\program files\microsoft frontpage
2009-09-17 02:52 . 2009-09-17 02:52 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-17 02:52 . 2009-09-17 02:51 -------- d-----w- c:\program files\Windows Media Connect 2
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Parallels Shared Internet Applications"="c:\program files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" [2008-11-08 67520]
"Parallels Tools Center"="c:\program files\Parallels\Parallels Tools\prl_cc.exe" [2008-11-08 90560]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-17 2007832]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Warkeys Update.lnk - c:\program files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe [2009-5-3 244736]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-17 06:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PurpleBean.exe"=

R0 prl_pv32;prl_pv32;c:\windows\system32\drivers\prl_pv32.sys [11/8/2008 4:47 AM 101312]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/16/2009 11:28 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/16/2009 11:28 PM 108552]
R1 prl_boot;prl_boot;c:\windows\system32\drivers\prl_boot.sys [11/8/2008 12:20 PM 32576]
R1 prl_fs;Parallels Shared Folders;c:\windows\system32\drivers\prl_fs.sys [11/8/2008 12:20 PM 148288]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/16/2009 11:27 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/16/2009 11:27 PM 297752]
R2 Parallels Coherence Service;Parallels Coherence Service;c:\program files\Parallels\Parallels Tools\Services\coherence.exe [11/8/2008 12:21 PM 28096]
R2 Parallels Tools Service;Parallels Tools Service;c:\program files\Parallels\Parallels Tools\Services\prl_tools_service.exe [11/8/2008 12:20 PM 916928]
R2 prl_time;Parallels Time Synchronization Helper;c:\windows\system32\drivers\prl_time.sys [9/16/2009 8:04 PM 15680]
R3 prl_eth5;Parallels Ethernet Adapter;c:\windows\system32\drivers\prl_eth5.sys [9/16/2009 8:04 PM 17728]
R3 prl_mouf;Parallels Mouse Synchronization Device;c:\windows\system32\drivers\prl_mouf.sys [9/16/2009 8:04 PM 15552]
R3 prl_tg;Parallels Tool Device;c:\windows\system32\drivers\prl_tg.sys [9/16/2009 8:04 PM 22848]
R3 prl_va;Parallels Video Adapter;c:\windows\system32\drivers\prl_vamp.sys [9/16/2009 8:04 PM 19904]
S2 usbctl;Microsoft USB Bus Controller;c:\windows\system32\usbctl.exe --> c:\windows\system32\usbctl.exe [?]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\BTK1.tmp --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\BTK1.tmp [?]
S3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [9/18/2009 10:43 PM 12032]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
.
------- Supplementary Scan -------
.
Trusted Zone: .psf
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\kji1ut4x.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-26 13:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\BTK1.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(792)
c:\windows\System32\prl_np.dll
c:\program files\Parallels\Parallels Tools\ShellIntHook.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Completion time: 2009-09-26 13:07
ComboFix-quarantined-files.txt 2009-09-26 20:07
ComboFix2.txt 2009-09-26 19:47
ComboFix3.txt 2009-09-26 08:55
ComboFix4.txt 2009-09-25 04:59

Pre-Run: 29,823,287,296 bytes free
Post-Run: 29,816,967,168 bytes free

167


And a fresh HJT log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:08:48 PM, on 9/26/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe
C:\Program Files\Parallels\Parallels Tools\prl_cc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O4 - HKLM\..\Run: [Parallels Shared Internet Applications] "C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" /start
O4 - HKLM\..\Run: [Parallels Tools Center] "C:\Program Files\Parallels\Parallels Tools\prl_cc.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: Warkeys Update.lnk = C:\Program Files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Parallels Coherence Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
O23 - Service: Parallels Tools Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
O23 - Service: Microsoft USB Bus Controller (usbctl) - Unknown owner - C:\WINDOWS\system32\usbctl.exe (file missing)

--
End of file - 3879 bytes

Shaba
2009-09-27, 13:37
Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply along with a fresh HijackThis log.

Fritsc
2009-09-28, 15:19
Hi Shaba.

Seems like there's a problem with the Kapersky Online Scanner.
It was stuck at 99%, and I noticed the files that it was scanning was the same. So basically it keep scanning the same thing over and over, hence stuck at the 99%.

However, I think the scan can be called a complete one already. Anyway I cannot get the log because I stopped the scan. But, here's what I can get form the 'View Report'. By the way, I can do another scan if you want me to, of course with a different online scanner. Anyway, as you can see it took me 10 hours to scan my computer.


--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Monday, September 28, 2009
Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Monday, September 28, 2009 03:56:08
Records in database: 2929184
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
Y:\
Z:\

Scan statistics:
Objects scanned: 1122307
Threats found: 4
Infected objects found: 15
Suspicious objects found: 0
Scan duration: 09:49:36


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe.vir Infected: Trojan.Win32.Vilsel.gjx 1
C:\Qoobox\Quarantine\[4]-Submit_2009-09-26_12.40.59.zip Infected: Trojan-Downloader.Win32.FraudLoad.wsqq 2
C:\System Volume Information\_restore{C1222DAB-A80C-4A3B-8AD0-AA055DA8AC96}\RP12\A0008237.exe Infected: Net-Worm.Win32.Aspxor.fp 1
C:\System Volume Information\_restore{C1222DAB-A80C-4A3B-8AD0-AA055DA8AC96}\RP13\A0016367.exe Infected: Net-Worm.Win32.Aspxor.fp 1
C:\System Volume Information\_restore{C1222DAB-A80C-4A3B-8AD0-AA055DA8AC96}\RP14\A0018415.exe Infected: Trojan.Win32.Vilsel.gjx 1
Y:\Documents\Downloads\LachesisEnglish.zip Infected: Trojan-Dropper.Win32.Joiner.jm 1
Y:\Documents\Downloads\LachesisFirmwareUpdaterv1.91.zip Infected: Trojan-Dropper.Win32.Joiner.jm 1
Y:\Documents\Downloads\New Folder\Lachesis Firmware updater v1.91\Lachesis-v1.91-080918-MPv13-APIv5.exe Infected: Trojan-Dropper.Win32.Joiner.jm 1
Y:\Documents\Parallels\Windows XP Pro SP2.pvm\Windows Disks\C\Qoobox\Quarantine\[4]-Submit_2009-09-26_12.40.59.zip Infected: Trojan-Downloader.Win32.FraudLoad.wsqq 2
Y:\Documents\Parallels\Windows XP Pro SP2.pvm\Windows Disks\C\Qoobox\Quarantine\C\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe.vir Infected: Trojan.Win32.Vilsel.gjx 1
Y:\Documents\Parallels\Windows XP Pro SP2.pvm\Windows Disks\C\System Volume Information\_restore{C1222DAB-A80C-4A3B-8AD0-AA055DA8AC96}\RP12\A0008237.exe Infected: Net-Worm.Win32.Aspxor.fp 1
Y:\Documents\Parallels\Windows XP Pro SP2.pvm\Windows Disks\C\System Volume Information\_restore{C1222DAB-A80C-4A3B-8AD0-AA055DA8AC96}\RP13\A0016367.exe Infected: Net-Worm.Win32.Aspxor.fp 1
Y:\Documents\Parallels\Windows XP Pro SP2.pvm\Windows Disks\C\System Volume Information\_restore{C1222DAB-A80C-4A3B-8AD0-AA055DA8AC96}\RP14\A0018415.exe Infected: Trojan.Win32.Vilsel.gjx 1

Scanning stopped by the user.


And a fresh HJT log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:18:30 AM, on 9/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe
C:\Program Files\Parallels\Parallels Tools\prl_cc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Parallels Shared Internet Applications] "C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" /start
O4 - HKLM\..\Run: [Parallels Tools Center] "C:\Program Files\Parallels\Parallels Tools\prl_cc.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: Warkeys Update.lnk = C:\Program Files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Parallels Coherence Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
O23 - Service: Parallels Tools Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
O23 - Service: Microsoft USB Bus Controller (usbctl) - Unknown owner - C:\WINDOWS\system32\usbctl.exe (file missing)

--
End of file - 4609 bytes


Thanks.

Shaba
2009-09-28, 16:29
Is Y your backup drive?

Fritsc
2009-09-28, 23:56
I'm not sure, since I'm not the one who installed Windows on Mac.
Is there any way to check?

Shaba
2009-09-29, 08:07
Could you maybe ask someone who did it to be sure?

Fritsc
2009-09-30, 03:18
Hi Shaba.

I've asked him about the Y drive, and sadly, he too doesn't know.

What do I do now?

Thanks.

Shaba
2009-09-30, 07:47
Well then we delete bad items from there.

Empty these folders:

C:\Qoobox\Quarantine
Y:\Documents\Parallels\Windows XP Pro SP2.pvm\Windows Disks\C\Qoobox\Quarantine

Delete these unless you recognize them:

Y:\Dcuments\Downloads\LachesisEnglish.zip
Y:\Documents\Downloads\LachesisFirmwareUpdaterv1.91.zip
Y:\Documents\Downloads\New Folder\Lachesis Firmware updater v1.91

Empty Recycle Bin.

Still problems?

Fritsc
2009-09-30, 16:43
Hi Shaba.

Deleted those items, and after browsing for around 10 minutes.
There seems to be no problem at all.

Thanks.

Shaba
2009-09-30, 20:02
Good :)

Before final instructions, let's clean one leftover.

Go to start - run.

Type sc stop usbct and click ok
then sc delete usbct and click ok.

Reboot and post back a fresh HijackThis log, please.

Fritsc
2009-10-01, 02:17
Hi Shaba.
What does that do??
I already type what you asked me to in run and a window with black screen appear for a second and disappear again. I hope that is right.

Here's the fresh HJT log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:53:43 PM, on 9/30/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe
C:\Program Files\Parallels\Parallels Tools\prl_cc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Parallels Shared Internet Applications] "C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" /start
O4 - HKLM\..\Run: [Parallels Tools Center] "C:\Program Files\Parallels\Parallels Tools\prl_cc.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: Warkeys Update.lnk = C:\Program Files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Parallels Coherence Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
O23 - Service: Parallels Tools Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
O23 - Service: Microsoft USB Bus Controller (usbctl) - Unknown owner - C:\WINDOWS\system32\usbctl.exe (file missing)

--
End of file - 4500 bytes


I also have a question regarding Windows in Mac. Does surfing in Mac (Let's say the webpage the Mac is surfing is infected, but the Mac is not infected by any virus), will the Windows get infected instead?

Thanks

Shaba
2009-10-01, 06:26
I have no experience about Mac in Windows so I can't help with that issue, unfortunately.

It was supposed to remove one leftover but it didn't work.

Open HijackThis, click do a system scan only and checkmark this:

O23 - Service: Microsoft USB Bus Controller (usbctl) - Unknown owner - C:\WINDOWS\system32\usbctl.exe (file missing)

Close all windows including browser and press fix checked.

Reboot.

Post back a fresh HijackThis log, please.

Fritsc
2009-10-01, 09:39
Hi,

That's okay then :)

Here's a new HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:38:17 AM, on 10/1/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe
C:\Program Files\Parallels\Parallels Tools\prl_cc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Parallels Shared Internet Applications] "C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" /start
O4 - HKLM\..\Run: [Parallels Tools Center] "C:\Program Files\Parallels\Parallels Tools\prl_cc.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: Warkeys Update.lnk = C:\Program Files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Parallels Coherence Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
O23 - Service: Parallels Tools Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
O23 - Service: Microsoft USB Bus Controller (usbctl) - Unknown owner - C:\WINDOWS\system32\usbctl.exe (file missing)

--
End of file - 4501 bytes

Shaba
2009-10-01, 09:43
And still there.

Please do the same procedure in safe mode and post back fresh HijackThis log afterwards.

Fritsc
2009-10-01, 10:57
Hi,

I went into safe mode, check it, and fix it.
But it's still there..
What should I do now?

Thanks.

Shaba
2009-10-01, 19:05
Please then disable AVG and try again.

Fritsc
2009-10-02, 00:50
Hi Shaba,

Disabled AVG, tried to fix it, still the same.
Then I uninstall AVG and tried to fix it again, still the same.
I tried in Safe Mode too after uninstalling AVG and it still stays the same.
What do we do now?

Thanks.

Shaba
2009-10-02, 06:18
Then we use combofix.


Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


Driver::
usbctl


Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Fritsc
2009-10-02, 07:34
Hi,
Seems like it works after using ComboFix :)

Here's the log

ComboFix 09-10-01.01 - Administrator 10/01/2009 22:18.5.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.397 [GMT -7:00]
Running from: \\.psf\Home\Desktop\ComboFix.exe
Command switches used :: \\.psf\Home\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_USBCTL
-------\Service_usbctl


((((((((((((((((((((((((( Files Created from 2009-09-02 to 2009-10-02 )))))))))))))))))))))))))))))))
.

2009-10-01 23:23 . 2009-10-02 05:16 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-10-01 23:16 . 2009-08-26 00:04 75264 ----a-w- c:\windows\system32\uc_holybeast_launching.dll
2009-10-01 23:10 . 2009-10-01 23:10 -------- d-----w- C:\ijji
2009-10-01 22:58 . 2009-10-01 23:08 -------- d-----w- C:\Downloads
2009-10-01 22:57 . 2009-10-01 23:11 -------- d-----w- c:\documents and settings\Administrator\Application Data\Orbit
2009-10-01 22:57 . 2009-10-01 22:57 -------- d-----w- c:\program files\Orbitdownloader
2009-10-01 22:55 . 2009-07-03 07:34 710064 ----a-w- c:\windows\system32\ijjiSetup.exe
2009-10-01 22:55 . 2009-07-03 07:34 58800 ----a-w- c:\windows\system32\ijjiProcessRestarter.exe
2009-10-01 22:55 . 2009-07-03 07:34 58800 ----a-w- c:\windows\system32\ijjiPlugin2.dll
2009-10-01 22:55 . 2009-07-01 17:25 61440 ----a-w- c:\windows\system32\uc_atlantica_launching.dll
2009-10-01 22:55 . 2009-06-23 20:21 64000 ----a-w- c:\windows\system32\uc_sfighters_launching.dll
2009-10-01 22:55 . 2009-04-01 00:43 53248 ----a-w- c:\windows\system32\uc_luminary_launching.dll
2009-10-01 22:55 . 2009-03-12 01:20 208384 ----a-w- c:\windows\system32\uc_rohan_launching.dll
2009-10-01 22:55 . 2009-01-29 18:53 87472 ----a-w- c:\windows\system32\ijjiChannelingPlugin.dll
2009-10-01 22:55 . 2009-10-01 22:55 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-28 05:03 . 2009-09-28 05:03 -------- d-----w- c:\program files\VideoLAN
2009-09-28 02:54 . 2009-09-28 02:54 -------- d-----w- c:\windows\Sun
2009-09-28 02:53 . 2009-09-28 02:53 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-09-28 02:53 . 2009-09-28 02:53 -------- d-----w- c:\program files\Java
2009-09-21 02:48 . 2009-09-21 02:48 -------- d-----w- c:\program files\Trend Micro
2009-09-19 08:51 . 2009-09-25 02:58 -------- d-----w- C:\$AVG8.VAULT$
2009-09-19 05:43 . 2005-12-21 18:23 14592 ----a-w- c:\windows\system32\drivers\Usbicp.sys
2009-09-19 05:43 . 2009-09-19 05:43 -------- d-----w- c:\program files\DIFX
2009-09-19 05:43 . 2007-08-08 18:04 12032 ----a-w- c:\windows\system32\drivers\Lachesis.sys
2009-09-19 01:43 . 2009-09-19 01:44 -------- d-----w- c:\program files\Warkeys
2009-09-19 01:22 . 2009-09-19 01:30 97817 ----a-w- c:\windows\War3Unin.dat
2009-09-19 01:21 . 2009-09-19 01:24 2829 ----a-w- c:\windows\War3Unin.pif
2009-09-19 01:21 . 2009-09-19 01:24 139264 ----a-w- c:\windows\War3Unin.exe
2009-09-19 01:20 . 2009-10-02 05:06 -------- d-----w- c:\program files\Warcraft III
2009-09-19 01:16 . 2009-09-19 01:16 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-09-19 01:16 . 2009-09-19 05:29 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-09-19 01:14 . 2009-09-19 01:14 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-19 01:14 . 2009-09-19 01:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\DAEMON Tools Lite
2009-09-17 08:45 . 2005-01-01 09:43 4682 ----a-w- c:\windows\system32\npptNT2.sys
2009-09-17 08:44 . 2009-09-17 08:44 -------- d-----w- c:\program files\Common Files\INCA Shared
2009-09-17 08:44 . 2009-09-17 08:44 -------- d-----w- c:\windows\system32\LogFiles
2009-09-17 08:42 . 2009-09-17 08:54 -------- d-----w- c:\documents and settings\All Users\Application Data\ijjigame
2009-09-17 08:32 . 2009-09-17 08:32 -------- d--h--w- c:\documents and settings\Administrator\Application Data\ijjigame
2009-09-17 08:06 . 2009-09-17 08:06 -------- d-----w- c:\program files\ijji
2009-09-17 07:06 . 2004-08-04 05:58 14848 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-09-17 07:06 . 2004-08-04 05:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2009-09-17 07:06 . 2001-08-17 20:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-09-17 07:06 . 2001-08-17 20:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-09-17 07:06 . 2001-08-17 21:02 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-09-17 07:06 . 2001-08-17 21:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-09-17 07:06 . 2004-08-04 06:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-09-17 07:06 . 2004-08-04 06:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-09-17 06:31 . 2009-10-02 05:07 -------- d-----w- c:\program files\Garena
2009-09-17 06:27 . 2009-09-17 06:27 -------- d-----w- c:\program files\AVG
2009-09-17 06:27 . 2009-10-01 22:20 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-17 06:27 . 2009-09-17 06:27 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-17 06:26 . 2009-09-17 06:28 -------- d-----w- c:\program files\SpywareBlaster
2009-09-17 06:26 . 2005-08-26 02:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-09-17 06:22 . 2009-09-17 06:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\AVG8
2009-09-17 05:38 . 2009-09-17 05:38 0 ----a-w- c:\windows\nsreg.dat
2009-09-17 05:38 . 2009-09-17 05:38 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-09-17 05:00 . 2009-09-17 05:00 12328 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-17 03:05 . 2009-09-17 03:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Parallels
2009-09-17 03:05 . 2009-09-17 03:05 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-09-17 03:04 . 2008-11-08 19:21 22848 ----a-w- c:\windows\system32\drivers\prl_tg.sys
2009-09-17 03:04 . 2008-11-08 19:20 17728 ----a-w- c:\windows\system32\drivers\prl_eth5.sys
2009-09-17 03:04 . 2008-11-08 19:21 19904 ----a-w- c:\windows\system32\drivers\prl_vamp.sys
2009-09-17 03:04 . 2008-11-08 19:21 64448 ----a-w- c:\windows\system32\prl_vadd.dll
2009-09-17 03:04 . 2008-11-08 19:15 151040 ----a-w- c:\windows\system32\prl_gl.dll
2009-09-17 03:04 . 2008-11-08 19:21 15552 ----a-w- c:\windows\system32\drivers\prl_mouf.sys
2009-09-17 03:04 . 2009-09-19 05:59 -------- dc----w- c:\windows\system32\DRVSTORE
2009-09-17 03:04 . 2008-11-08 19:21 15680 ----a-w- c:\windows\system32\drivers\prl_time.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-17 03:04 . 2009-09-17 03:04 -------- d-----w- c:\program files\Parallels
2009-09-17 02:54 . 2009-09-17 02:54 -------- d-----w- c:\program files\microsoft frontpage
2009-09-17 02:52 . 2009-09-17 02:52 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-17 02:52 . 2009-09-17 02:51 -------- d-----w- c:\program files\Windows Media Connect 2
.

((((((((((((((((((((((((((((( SnapShot@2009-09-25_04.58.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-02 05:22 . 2009-10-02 05:22 16384 c:\windows\temp\Perflib_Perfdata_77c.dat
+ 2009-10-01 23:23 . 2009-10-01 23:23 88589 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-10-01 22:55 . 2009-07-03 07:34 87472 c:\windows\Downloaded Program Files\ijjiPreStarter2.exe
+ 2009-10-01 22:55 . 2009-07-03 07:34 79280 c:\windows\Downloaded Program Files\ijjiPreNotify2.exe
+ 2009-10-01 22:55 . 2009-07-03 07:34 50608 c:\windows\Downloaded Program Files\ijjiNotify2.exe
+ 2009-07-18 03:12 . 2009-07-18 03:12 257440 c:\windows\system32\Macromed\Flash\FlashUtil10c.exe
+ 2009-09-28 02:53 . 2009-09-28 02:53 148888 c:\windows\system32\javaws.exe
+ 2009-09-28 02:53 . 2009-09-28 02:53 144792 c:\windows\system32\javaw.exe
+ 2009-09-28 02:53 . 2009-09-28 02:53 144792 c:\windows\system32\java.exe
+ 2009-09-28 02:53 . 2009-09-28 02:53 536576 c:\windows\Installer\5cdf96.msi
+ 2009-10-01 22:55 . 2009-07-03 07:34 579032 c:\windows\Downloaded Program Files\PLauncher.exe
+ 2009-10-01 22:55 . 2009-07-03 07:34 480688 c:\windows\Downloaded Program Files\ijjistarter2.exe
+ 2009-10-01 22:55 . 2009-07-03 07:34 112048 c:\windows\Downloaded Program Files\ijjiSetup1010.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Parallels Shared Internet Applications"="c:\program files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" [2008-11-08 67520]
"Parallels Tools Center"="c:\program files\Parallels\Parallels Tools\prl_cc.exe" [2008-11-08 90560]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-28 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Warkeys Update.lnk - c:\program files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe [2009-5-3 244736]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleNetIDList"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PurpleBean.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=

R0 prl_pv32;prl_pv32;c:\windows\system32\drivers\prl_pv32.sys [11/8/2008 4:47 AM 101312]
R1 prl_boot;prl_boot;c:\windows\system32\drivers\prl_boot.sys [11/8/2008 12:20 PM 32576]
R1 prl_fs;Parallels Shared Folders;c:\windows\system32\drivers\prl_fs.sys [11/8/2008 12:20 PM 148288]
R2 Parallels Coherence Service;Parallels Coherence Service;c:\program files\Parallels\Parallels Tools\Services\coherence.exe [11/8/2008 12:21 PM 28096]
R2 Parallels Tools Service;Parallels Tools Service;c:\program files\Parallels\Parallels Tools\Services\prl_tools_service.exe [11/8/2008 12:20 PM 916928]
R2 prl_time;Parallels Time Synchronization Helper;c:\windows\system32\drivers\prl_time.sys [9/16/2009 8:04 PM 15680]
R3 prl_eth5;Parallels Ethernet Adapter;c:\windows\system32\drivers\prl_eth5.sys [9/16/2009 8:04 PM 17728]
R3 prl_mouf;Parallels Mouse Synchronization Device;c:\windows\system32\drivers\prl_mouf.sys [9/16/2009 8:04 PM 15552]
R3 prl_tg;Parallels Tool Device;c:\windows\system32\drivers\prl_tg.sys [9/16/2009 8:04 PM 22848]
R3 prl_va;Parallels Video Adapter;c:\windows\system32\drivers\prl_vamp.sys [9/16/2009 8:04 PM 19904]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\GMO184.tmp --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\GMO184.tmp [?]
S3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [9/18/2009 10:43 PM 12032]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
.
------- Supplementary Scan -------
.
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
Trusted Zone: .psf
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\kji1ut4x.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-01 22:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\GMO184.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2652)
c:\windows\System32\prl_np.dll
c:\program files\Parallels\Parallels Tools\ShellIntHook.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Parallels\Parallels Tools\Services\prl_tools.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-10-02 22:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-02 05:23
ComboFix2.txt 2009-09-26 20:07
ComboFix3.txt 2009-09-26 19:47
ComboFix4.txt 2009-09-26 08:55
ComboFix5.txt 2009-10-02 05:18

Pre-Run: 28,969,046,016 bytes free
Post-Run: 29,011,746,816 bytes free

218


And a fresh HJT log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:34:04 PM, on 10/1/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe
C:\Program Files\Parallels\Parallels Tools\prl_cc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe
C:\Program Files\Parallels\Parallels Tools\Services\prl_tools.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Parallels Shared Internet Applications] "C:\Program Files\Parallels\Parallels Tools\SIA\SharedIntApp.exe" /start
O4 - HKLM\..\Run: [Parallels Tools Center] "C:\Program Files\Parallels\Parallels Tools\prl_cc.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: Warkeys Update.lnk = C:\Program Files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Parallels Coherence Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\coherence.exe
O23 - Service: Parallels Tools Service - Parallels, Inc. - C:\Program Files\Parallels\Parallels Tools\Services\prl_tools_service.exe

--
End of file - 4225 bytes


Thanks.

Shaba
2009-10-02, 19:16
Yes :)

Still something?

Fritsc
2009-10-02, 22:57
Afternoon Shaba,

Everything's working fine right now :)
And, I'm just wondering what virus has infected me, and what it does.
Also, what do we do now to make sure everything is safe and protected again.

Thanks

Shaba
2009-10-03, 12:15
It was a rogue program along with friends :)

See below for my tips:

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Looking over your log, it seems you don't have any evidence of a third party firewall.

As the term conveys, a firewall is an extra layer of security installed onto computers, which restricts access to systems from the outside world. Firewalls protect against hackers and malicious intruders. I want you to download a free firewall NOW from one of these excellent vendors:

1) Comodo (http://www.personalfirewall.comodo.com/download_firewall.html) (Uncheck during installation "Install COMODO Antivirus (Recommended)"!, "Install Comodo HopSurf..", Make Comodo my default search provider" and "Make HopSurf my homepage")
2) Online Armor (http://www.tallemu.com/online_armor_free.html)
3) PC Tools (http://www.pctools.com/firewall/download/)
4) Sunbelt/Kerio (http://www.sunbelt-software.com/Kerio-Download.cfm)
5) ZoneAlarm (http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?dc=12bms&ctry=US&lang=en&lid=nav_za) (uncheck ZoneAlarm Spy Blocker during installation if you choose this one)

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

Now lets uninstall ComboFix:

Click START then RUN
Now type Combofix /u in the runbox and click OK

Next we remove all used tools.

Please download OTCleanIt (http://oldtimer.geekstogo.com/OTC.exe) and save it to desktop.

Double-click OTCleanIt.exe.
Click the CleanUp! button.
Select Yes when the "Begin cleanup Process?" prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTCleanIt attempting to contact the internet, please allow it to do so.

Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html)

Re-enable system restore with instructions from tutorial above

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt

Change the Download unsigned ActiveX controls to Disable

Change the Initialize and script ActiveX controls not marked as safe to Disable

Change the Installation of desktop items to Prompt

Change the Launching programs and files in an IFRAME to Prompt

Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Update your AntiVirus Software and keep your other programs up-to-date Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
You can use one of these sites to check if any updates are needed for your pc.
Secunia Software Inspector (http://secunia.com/software_inspector/)
F-secure Health Check (http://www.f-secure.com/weblog/archives/00001356.html)

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com (http://www.windowsupdate.com) regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
totally free but for real-time protection you will have to pay a small one-time fee. Tutorial on installing & using this product can be found below:

Malwarebytes' Anti-Malware Setup Guide (http://www.lognrock.com/forum/index.php?showtopic=6926)

Malwarebytes' Anti-Malware Scanning Guide (http://www.lognrock.com/forum/index.php?showtopic=6913)


Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/tutorials/tutorial49.html)


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer. See also a hosts file tutorial here (http://malwareremoval.com/forum/viewtopic.php?t=22187)
Winpatrol (http://www.winpatrol.com/) <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

Stand Up and Be Counted ---> Malware Complaints (http://www.malwarecomplaints.info/index.php) <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place (http://forums.spybot.info/showthread.php?t=279)

Happy surfing and stay clean! :bigthumb:

Fritsc
2009-10-04, 10:37
Hi Shaba.

Done everything :)

Thanks a lot :rockon:

You can close this thread now if you want to now.

Shaba
2009-10-11, 15:08
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.