PDA

View Full Version : Infected machine, can't run any antivirus software, or install any. AVcare, b.exe.



throwway
2009-11-17, 18:19
Main symptoms, spybot can not be launched, even from the .scrs, AVG doesn't run at startup, and can't be run, files can't be downloaded...pictures work, but movies, .exes .rar etc all never arrive in folder try to download them too and can't be found anywhere else. Google search results all redirect to spammy sites, when trying to visit a website am sometimes redirected to (corrupted) google search result for that URL, can't install new programs, some instability and slowdown....but not too much.
IE was also visiting websites in the background constantly, but I uninstalled AVcare from the add/remove programs and turned off some highly suspicious startup files and that has stopped.

I can't open spybot to do anything with tea timer, and can't get to hijackthis....and even if I could, suspect it wouldn't run.

Using Vista, have spybot&AVG installed and were up to date but completely inaccessable atm. Computer remains almost completely useable for non-web activities.

help? :)

Blade81
2009-11-20, 17:30
Hi,


files can't be downloaded...pictures work, but movies, .exes .rar etc all never arrive in folder try to download them too and can't be found anywhere else.
I've seen this kind of symptoms occur in Vista with AVG installed. Could you uninstall it temporarily?

Download DDS and save it to your desktop from here (http://www.techsupportforum.com/sectools/sUBs/dds) or here (http://download.bleepingcomputer.com/sUBs/dds.scr) or here (http://www.forospyware.com/sUBs/dds).
Disable any script blocker, and then double click dds.scr to run the tool.
When done, DDS will open two (2) logs:
DDS.txt
Attach.txt

Save both reports to your desktop. Post them back to your topic.


Download GMER (http://www.gmer.net) here by clicking download exe -button and then saving it your desktop:
Double-click .exe that you downloaded
Click rootkit-tab and then scan.
Don't check
Show All
box while scanning in progress!
When scanning is ready, click Copy.
This copies log to clipboard
Post log in your reply.

throwway
2009-11-23, 01:36
I uninstalled AVg but it didn't change the 'can't download' thing, I'll have to get those files on another PC and transfer...in the meantime don't think I've gone away, thanks for your help :)

Blade81
2009-11-23, 06:58
Ok. Thanks for the heads up :)

throwway
2009-11-27, 01:01
DDS (Ver_09-11-24.02) - NTFSx86
Run by Owner at 23:28:33.95 on 26/11/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1498 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Owner\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.altavista.com/
uWindow Title =
uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=5080820
mDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=5080820
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
StartupFolder: c:\users\owner\appdata\roaming\microsoft\windows\start menu\programs\startup\desk.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\cable&~1.lnk - c:\program files\cable&wireless\c&w_802.11g_utility\C&WWLAN.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: antimalwareguard.com
Trusted Zone: filesmonster.com
Trusted Zone: antimalwareguard.com
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: avgrsstx.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\2esepl9x.trygain\

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-27 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-27 297752]

=============== Created Last 30 ================

2009-11-18 14:30:18 175151692 ----a-w- c:\windows\MEMORY.DMP
2009-11-08 04:53:04 0 d-----w- c:\users\owner\Tracing
2009-11-08 04:52:20 0 d-----w- c:\program files\Microsoft
2009-11-08 04:51:56 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:50:36 0 d-----w- c:\program files\common files\Windows Live

==================== Find3M ====================

2009-09-30 17:13:42 70656 ----a-w- c:\windows\system32\drivers\rotscxqrvwipvj.sys
2009-09-30 11:02:37 44544 ----a-w- c:\windows\system32\rotscxitrpvrtw.dll
2008-10-28 18:09:46 51200 ----a-w- c:\windows\inf\infpub.dat
2008-10-28 18:09:46 143360 ----a-w- c:\windows\inf\infstrng.dat
2008-10-28 18:09:45 86016 ----a-w- c:\windows\inf\infstor.dat
2008-08-20 00:03:01 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-08-20 00:02:56 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 23:29:21.39 ===============



GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-11-26 23:54:46
Windows 6.0.6001 Service Pack 1
Running: pjfdtibk.exe; Driver: C:\Users\Owner\AppData\Local\Temp\kglcypog.sys


---- Kernel code sections - GMER 1.0.15 ----

.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8B006000, 0x1F8CAC, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!DialogBoxIndirectParamW 7676BD25 5 Bytes JMP 71A25BF3 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!DialogBoxParamW 76781FD5 5 Bytes JMP 71A25B7D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!DialogBoxParamA 767A80B2 5 Bytes JMP 71A25BB8 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!DialogBoxIndirectParamA 767A83DD 5 Bytes JMP 71A25C2E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!MessageBoxIndirectA 767BD471 5 Bytes JMP 71A25B39 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!MessageBoxIndirectW 767BD56B 5 Bytes JMP 71A25AF5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!MessageBoxExA 767BD5D1 5 Bytes JMP 71A25ABB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!MessageBoxExW 767BD5F5 5 Bytes JMP 71A25A81 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Services - GMER 1.0.15 ----

Service C:\Windows\system32\drivers\rotscxqrvwipvj.sys (*** hidden *** ) [SYSTEM] rotscxveufmtxr <-- ROOTKIT !!!
Service C:\Windows\system32\drivers\SKYNETqmipfqix.sys (*** hidden *** ) [SYSTEM] SKYNETcycuyxxw <-- ROOTKIT !!!
Service (*** hidden *** ) [SYSTEM] UACd.sys <-- ROOTKIT !!!

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr@imagepath \systemroot\system32\drivers\rotscxqrvwipvj.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr\modules@rotscxrk.sys \systemroot\system32\drivers\rotscxqrvwipvj.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr\modules@rotscxcmd.dll \systemroot\system32\rotscxitrpvrtw.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw@imagepath \systemroot\system32\drivers\SKYNETqmipfqix.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main@aid 10002
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main@sid 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETqmipfqix.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\modules@SKYNETcmd.dll \systemroot\system32\SKYNETbajestwf.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\modules@SKYNETlog.dat \systemroot\system32\SKYNETbdexdosn.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\modules@SKYNETwsp.dll \systemroot\system32\SKYNETtnprdpbe.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\modules@SKYNET.dat \systemroot\system32\SKYNEThempttmt.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@imagepath
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACd
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACc
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacbbr
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacsr
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacmal
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacrem
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacmask
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacserf
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr@imagepath \systemroot\system32\drivers\rotscxqrvwipvj.sys
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr\modules@rotscxrk.sys \systemroot\system32\drivers\rotscxqrvwipvj.sys
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr\modules@rotscxcmd.dll \systemroot\system32\rotscxitrpvrtw.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw@imagepath \systemroot\system32\drivers\SKYNETqmipfqix.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main@aid 10002
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main@sid 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETqmipfqix.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\modules@SKYNETcmd.dll \systemroot\system32\SKYNETbajestwf.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\modules@SKYNETlog.dat \systemroot\system32\SKYNETbdexdosn.dat
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\modules@SKYNETwsp.dll \systemroot\system32\SKYNETtnprdpbe.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\modules@SKYNET.dat \systemroot\system32\SKYNEThempttmt.dat
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@imagepath
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACd
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACc
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacbbr
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacsr
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacmal
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacrem
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacmask
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacserf

---- EOF - GMER 1.0.15 ----



Hope I'm not causing too much of a problem by posting this, but I can not attach it, neither the 'manage attachments' button nor the paperclip or the arrow next to it do anything when clicked.


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-11-24.02)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 19/08/2008 17:12:48
System Uptime: 22/11/2009 15:20:21 (104 hours ago)

Motherboard: Dell Inc. | | 0K216C
Processor: Intel(R) Core(TM)2 Duo CPU E7200 @ 2.53GHz | Socket 775 | 2534/266mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 456 GiB total, 91.599 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 5.832 GiB free.
E: is CDROM (CDFS)

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP486: 06/11/2009 15:49:24 - Avg8 Update
RP488: 07/11/2009 18:03:13 - Scheduled Checkpoint
RP490: 10/11/2009 13:05:03 - Scheduled Checkpoint
RP492: 13/11/2009 00:47:38 - Scheduled Checkpoint
RP494: 14/11/2009 20:37:44 - Scheduled Checkpoint
RP496: 16/11/2009 22:44:22 - Scheduled Checkpoint
RP498: 17/11/2009 15:00:40 - Scheduled Checkpoint
RP500: 18/11/2009 19:56:42 - Scheduled Checkpoint
RP502: 19/11/2009 22:34:41 - Scheduled Checkpoint
RP504: 22/11/2009 14:26:42 - Removed AVG Free 8.5
RP506: 22/11/2009 14:27:34 - Removed AVG Free 8.5
RP508: 23/11/2009 16:19:14 - Scheduled Checkpoint
RP510: 24/11/2009 19:33:33 - Scheduled Checkpoint
RP512: 26/11/2009 16:56:50 - Avg8 Update

==== Installed Programs ======================

7-Zip 4.57
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.0
Apple Software Update
ATI Catalyst Control Center
µTorrent
AutoUpdate
AVG Free 8.5
Cable & Wireless 802.11g Series Wireless LAN USB
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Turkish
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help English
CCC Help French
CCC Help German
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Portuguese
CCC Help Spanish
CCC Help Turkish
Company of Heroes - FAKEMSI
Company of Heroes - Opposing Fronts
Compatibility Pack for the 2007 Office system
Dawn of War - Soulstorm
Dell Getting Started Guide
Dell Support Center
Diablo II
DivX Converter
DivX Player
DivX Web Player
Dracula
EDocs
eMule
FlashDevelop 3.0.4
FLV Player 2.0 (build 25)
Free Music Zilla
Game Maker 7.0
Gmask 1.70 English
GOM Player
GoToAssist 8.0.0.514
Indeo® Software
Intel A/V Codecs V2.0
Intel(R) PRO Network Connections 12.1.11.0
Internet From BT
IrfanView (remove only)
Java(TM) 6 Update 5
Majesty
Medieval II Total War
Microsoft Age of Empires II
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MinGW 5.1.4
Mozilla Firefox (3.0.15)
MSVCRT
Nephi Theora Decoder
Oblivion
Oblivion mod manager 1.1.12
Python 2.5 comtypes-0.5.2
Python 2.5 PIL-1.1.6
Python 2.5 psyco-1.6
Python 2.5 pywin32-212
Python 2.5.2
QuickTime
Real Alternative 1.8.2
RealPlayer
Realtek High Definition Audio Driver
Rome - Total War
SFX Compiler
Skins
Spybot - Search & Destroy
Steam
The Battle for Middle-earth (tm)
Warhammer 40,000: Dawn of War II
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
wxPython 2.8.7.1 (ansi) for Python 2.5
Yahoo! Messenger
Zip Password Finder
Zip Password Recovery - Ver: 1.42

==== End Of File ===========================

Blade81
2009-11-27, 06:23
Hi,

Attaching logs to post as text is totally ok.

IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

µTorrent
eMule


I'd like you to read this thread (http://forums.spybot.info/showthread.php?t=282).

Please go to Control Panel > Programs and Features and uninstall the programs listed above (in red).


Empty Recycle Bin.

After that:


Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.


Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds log.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

throwway
2009-12-01, 01:49
Uninstalled thingys, should be able to get that download tomorrow.

Blade81
2009-12-01, 07:35
Ok. Thanks for the heads up.

throwway
2009-12-02, 14:59
I am sure I uninstalled (or tried to as the case seems) AVG earlier, but combofix has detected it running....and sure enough it is there still in program files (not showing as running anything in task manager though)....trying to uninstall it now just gives an unexpected error message and doesn't work.

Run combofix anyway as AVG doesn't appear to actually be running? delete AVG folder in program files and reboot? :confused:

throwway
2009-12-02, 16:29
So turns out there's no way to cancel combofix, so had to run it anyway....which makes the warnings that I was doing it 'at my own risk' the program gives kinda redundant as it's too late by then....It all seemed to go okay until afterwards though.

Afterwards trying to open any file or run any program (although I only tried a couple) resulted in a 'illegal operation performed on a registry key marked for deletion' error....after restarting PC that seems to have gone, however there is no new DDS report, the old DDS.txt remains on the desktop....but I'm pretty sure it is still the old one, as it seems identical and has the date modified of a week ago...I'll attach it nevertheless, on the off chance...


combofix.txt

ComboFix 09-12-02.01 - Owner 02/12/2009 15:01.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1213 [GMT 0:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1283296827-177754420-2501937510-500
c:\$recycle.bin\S-1-5-21-2773397201-2855733099-4214572315-500
c:\users\Apache\Desktop\AV Care.lnk
c:\windows\run.log
c:\windows\system32\drivers\rotscxqrvwipvj.sys
c:\windows\system32\drivers\SKYNETqmipfqix.sys
c:\windows\system32\drivers\UACd.sys
c:\windows\system32\drivers\ytasfwptdgwvxs.sys
c:\windows\system32\rotscxitrpvrtw.dll
c:\windows\system32\SKYNETbdexdosn.dat
c:\windows\system32\SKYNEThempttmt.dat
c:\windows\system32\UAChstrndiayr.db
c:\windows\system32\ytasfwuniywegf.dat

Infected copy of c:\windows\system32\cngaudit.dll was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_rotscxveufmtxr
-------\Legacy_SKYNETcycuyxxw
-------\Legacy_UACd.sys
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_rotscxveufmtxr
-------\Service_SKYNETcycuyxxw
-------\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-11-02 to 2009-12-02 )))))))))))))))))))))))))))))))
.

2009-12-02 15:05 . 2009-12-02 15:10 -------- d-----w- c:\users\Owner\AppData\Local\temp
2009-12-02 15:05 . 2009-12-02 15:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-02 15:05 . 2009-12-02 15:05 -------- d-----w- c:\users\apache2triad.Shiny-PC\AppData\Local\temp
2009-12-02 15:05 . 2009-12-02 15:05 -------- d-----w- c:\users\Apache\AppData\Local\temp
2009-11-26 16:57 . 2009-11-06 15:49 2064152 ----a-w- c:\programdata\avg8\update\backup\avgcorex.dll
2009-11-26 16:57 . 2009-11-03 12:24 3513624 ----a-w- c:\programdata\avg8\update\backup\avgui.exe
2009-11-26 16:57 . 2009-11-03 12:24 2028312 ----a-w- c:\programdata\avg8\update\backup\avgtray.exe
2009-11-08 04:53 . 2009-11-16 13:29 -------- d-----w- c:\users\Owner\Tracing
2009-11-08 04:52 . 2009-11-08 04:52 -------- d-----w- c:\program files\Microsoft
2009-11-08 04:51 . 2009-11-08 04:51 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:50 . 2009-11-08 04:50 -------- d-----w- c:\program files\Common Files\Windows Live

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-02 13:54 . 2008-08-27 22:58 4096 d-----w- c:\programdata\avg8
2009-11-30 00:26 . 2009-09-20 18:42 0 ----a-w- c:\windows\win32k.sys
2009-11-24 01:37 . 2008-09-06 23:21 16384 d-----w- c:\program files\Diablo II
2009-11-19 16:55 . 2009-06-29 08:08 4096 d-----w- c:\program files\Free Music Zilla
2009-11-12 05:13 . 2009-04-18 02:35 -------- d-----w- c:\users\Owner\AppData\Roaming\IrfanView
2009-11-08 04:51 . 2008-08-28 00:17 4096 d-----w- c:\program files\Windows Live
2009-10-19 07:40 . 2009-10-19 07:40 -------- d-----w- c:\program files\Information Packaging
2009-10-19 07:29 . 2009-10-19 07:29 -------- d-----w- c:\program files\Datahjaelp
2009-10-19 07:10 . 2009-10-19 07:09 4096 d-----w- c:\program files\ZIP PASSWORD FINDER
2009-10-10 19:33 . 2009-10-10 19:32 4096 d-----w- c:\program files\FlashDevelop
2009-10-02 05:53 . 2009-10-24 18:42 47997 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
2008-08-20 00:02 . 2008-08-20 00:02 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-12 185872]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
desk.exe [2009-10-2 47997]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Cable & Wireless 11g Wireless USB.lnk - c:\program files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe [2008-10-28 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-19 15:31 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Free Music Zilla.lnk]
path=c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Free Music Zilla.lnk
backup=c:\windows\pss\Free Music Zilla.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1283296827-177754420-2501937510-1000]
"EnableNotificationsRef"=dword:00000001

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [27/08/2008 22:58 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [27/08/2008 22:58 297752]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
Trusted Zone: filesmonster.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
.
- - - - ORPHANS REMOVED - - - -

AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-Steam App 15620 - c:\program files\Steam\steam.exe steam://uninstall/15620
AddRemove-{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 - c:\program files\Spybot - Search & Destroy\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-02 15:10
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2009-12-02 15:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-02 15:12

Pre-Run: 101,515,718,656 bytes free
Post-Run: 102,191,656,960 bytes free

- - End Of File - - C14C195F17CB53B794CD5E6D7409AAF8


Old (I'm pretty sure) DDS

DDS (Ver_09-11-24.02) - NTFSx86
Run by Owner at 23:28:33.95 on 26/11/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1498 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Owner\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.altavista.com/
uWindow Title =
uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=5080820
mDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=5080820
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
StartupFolder: c:\users\owner\appdata\roaming\microsoft\windows\start menu\programs\startup\desk.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\cable&~1.lnk - c:\program files\cable&wireless\c&w_802.11g_utility\C&WWLAN.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: antimalwareguard.com
Trusted Zone: filesmonster.com
Trusted Zone: antimalwareguard.com
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: avgrsstx.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\2esepl9x.trygain\

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-27 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-27 297752]

=============== Created Last 30 ================

2009-11-18 14:30:18 175151692 ----a-w- c:\windows\MEMORY.DMP
2009-11-08 04:53:04 0 d-----w- c:\users\owner\Tracing
2009-11-08 04:52:20 0 d-----w- c:\program files\Microsoft
2009-11-08 04:51:56 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:50:36 0 d-----w- c:\program files\common files\Windows Live

==================== Find3M ====================

2009-09-30 17:13:42 70656 ----a-w- c:\windows\system32\drivers\rotscxqrvwipvj.sys
2009-09-30 11:02:37 44544 ----a-w- c:\windows\system32\rotscxitrpvrtw.dll
2008-10-28 18:09:46 51200 ----a-w- c:\windows\inf\infpub.dat
2008-10-28 18:09:46 143360 ----a-w- c:\windows\inf\infstrng.dat
2008-10-28 18:09:45 86016 ----a-w- c:\windows\inf\infstor.dat
2008-08-20 00:03:01 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-08-20 00:02:56 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 23:29:21.39 ===============

Blade81
2009-12-02, 17:06
Hi,

To get a fresh dds log you have to run dds again :)

throwway
2009-12-02, 21:56
Oh....well I feel stupid now :red:

Fresh one


DDS (Ver_09-11-24.02) - NTFSx86
Run by Owner at 20:53:22.84 on 02/12/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1397 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Owner\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
StartupFolder: c:\users\owner\appdata\roaming\microsoft\windows\start menu\programs\startup\desk.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\cable&~1.lnk - c:\program files\cable&wireless\c&w_802.11g_utility\C&WWLAN.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: filesmonster.com
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: c:\windows\system32\avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-27 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-27 297752]

=============== Created Last 30 ================

2009-12-02 15:00:36 98816 ----a-w- c:\windows\sed.exe
2009-12-02 15:00:36 77312 ----a-w- c:\windows\MBR.exe
2009-12-02 15:00:36 260608 ----a-w- c:\windows\PEV.exe
2009-12-02 15:00:36 161792 ----a-w- c:\windows\SWREG.exe
2009-11-18 14:30:18 175151692 ----a-w- c:\windows\MEMORY.DMP
2009-11-08 04:53:04 0 d-----w- c:\users\owner\Tracing
2009-11-08 04:52:20 0 d-----w- c:\program files\Microsoft
2009-11-08 04:51:56 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:50:36 0 d-----w- c:\program files\common files\Windows Live

==================== Find3M ====================

2008-10-28 18:09:46 51200 ----a-w- c:\windows\inf\infpub.dat
2008-10-28 18:09:46 143360 ----a-w- c:\windows\inf\infstrng.dat
2008-10-28 18:09:45 86016 ----a-w- c:\windows\inf\infstor.dat
2008-08-20 00:03:01 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-08-20 00:02:56 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 20:53:55.33 ===============

Blade81
2009-12-02, 22:19
Hi again :)

Open notepad and copy/paste the text in the quotebox below into it:



FileLook::
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
DDS::
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
Rootkit::
c:\windows\win32k.sys



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Uninstall old Adobe Reader versions and get the latest one (9.2) here (http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows) or get Foxit Reader here (http://www.foxitsoftware.com/pdf/reader_2/down_reader.htm). Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here (http://pdfreaders.org/).



Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6 Update 17 (http://java.sun.com/javase/downloads/index.jsp).
Click the
Download
button to the right.
Select Windows on platform combobox and check the box that says:
Accept License Agreement. Click continue.

The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version. Uncheck Carbonite online backup trial if it's offered there.



Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) as instructed in the screenshot here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif).


Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log. Any issues left?

throwway
2009-12-05, 20:55
Done and done, yes the symptoms remain.

Fresh DDS

DDS (Ver_09-11-24.02) - NTFSx86
Run by Owner at 19:51:08.87 on 05/12/2009
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1104 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Owner\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\users\owner\appdata\roaming\microsoft\windows\start menu\programs\startup\desk.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\cable&~1.lnk - c:\program files\cable&wireless\c&w_802.11g_utility\C&WWLAN.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: filesmonster.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: c:\windows\system32\avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-27 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-27 297752]

=============== Created Last 30 ================

2009-12-05 16:57:13 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-02 15:00:36 98816 ----a-w- c:\windows\sed.exe
2009-12-02 15:00:36 77312 ----a-w- c:\windows\MBR.exe
2009-12-02 15:00:36 260608 ----a-w- c:\windows\PEV.exe
2009-12-02 15:00:36 161792 ----a-w- c:\windows\SWREG.exe
2009-11-18 14:30:18 175151692 ----a-w- c:\windows\MEMORY.DMP
2009-11-08 04:53:04 0 d-----w- c:\users\owner\Tracing
2009-11-08 04:52:20 0 d-----w- c:\program files\Microsoft
2009-11-08 04:51:56 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:50:36 0 d-----w- c:\program files\common files\Windows Live

==================== Find3M ====================

2008-10-28 18:09:46 51200 ----a-w- c:\windows\inf\infpub.dat
2008-10-28 18:09:46 143360 ----a-w- c:\windows\inf\infstrng.dat
2008-10-28 18:09:45 86016 ----a-w- c:\windows\inf\infstor.dat
2008-08-20 00:03:01 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-08-20 00:02:56 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 19:51:24.58 ===============

Combofix
ComboFix 09-12-02.01 - Owner 03/12/2009 17:53.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1560 [GMT 0:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-11-03 to 2009-12-03 )))))))))))))))))))))))))))))))
.

2009-12-03 17:57 . 2009-12-03 17:57 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-12-03 17:57 . 2009-12-03 17:57 -------- d-----w- c:\users\Owner\AppData\Local\temp
2009-12-03 17:57 . 2009-12-03 17:57 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-03 17:57 . 2009-12-03 17:57 -------- d-----w- c:\users\apache2triad\AppData\Local\temp
2009-12-03 17:57 . 2009-12-03 17:57 -------- d-----w- c:\users\apache2triad.Shiny-PC\AppData\Local\temp
2009-12-03 17:57 . 2009-12-03 17:57 -------- d-----w- c:\users\Apache\AppData\Local\temp
2009-11-26 16:57 . 2009-11-06 15:49 2064152 ----a-w- c:\programdata\avg8\update\backup\avgcorex.dll
2009-11-26 16:57 . 2009-11-03 12:24 3513624 ----a-w- c:\programdata\avg8\update\backup\avgui.exe
2009-11-26 16:57 . 2009-11-03 12:24 2028312 ----a-w- c:\programdata\avg8\update\backup\avgtray.exe
2009-11-08 04:53 . 2009-11-16 13:29 -------- d-----w- c:\users\Owner\Tracing
2009-11-08 04:52 . 2009-11-08 04:52 -------- d-----w- c:\program files\Microsoft
2009-11-08 04:51 . 2009-11-08 04:51 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:50 . 2009-11-08 04:50 -------- d-----w- c:\program files\Common Files\Windows Live

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-02 13:54 . 2008-08-27 22:58 4096 d-----w- c:\programdata\avg8
2009-11-30 00:26 . 2009-09-20 18:42 0 ----a-w- c:\windows\win32k.sys
2009-11-24 01:37 . 2008-09-06 23:21 16384 d-----w- c:\program files\Diablo II
2009-11-19 16:55 . 2009-06-29 08:08 4096 d-----w- c:\program files\Free Music Zilla
2009-11-12 05:13 . 2009-04-18 02:35 -------- d-----w- c:\users\Owner\AppData\Roaming\IrfanView
2009-11-08 04:51 . 2008-08-28 00:17 4096 d-----w- c:\program files\Windows Live
2009-10-19 07:40 . 2009-10-19 07:40 -------- d-----w- c:\program files\Information Packaging
2009-10-19 07:29 . 2009-10-19 07:29 -------- d-----w- c:\program files\Datahjaelp
2009-10-19 07:10 . 2009-10-19 07:09 4096 d-----w- c:\program files\ZIP PASSWORD FINDER
2009-10-10 19:33 . 2009-10-10 19:32 4096 d-----w- c:\program files\FlashDevelop
2009-10-02 05:53 . 2009-10-24 18:42 47997 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
2008-08-20 00:02 . 2008-08-20 00:02 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

--- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe ---
Company: ------
File Description: ------
File Version: ------
Product Name: ------
Copyright: ------
Original Filename: ------
File size: 47997
Created time: 2009-10-24 18:42
Modified time: 2009-10-02 05:53
MD5: !HASH: COULD NOT OPEN FILE !!!!!
SHA1: !HASH: COULD NOT OPEN FILE !!!!!


((((((((((((((((((((((((((((( SnapShot@2009-12-02_15.10.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-12-02 15:20 32478 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-12-02 15:20 70374 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-26 18:31 . 2009-12-02 15:20 8510 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1283296827-177754420-2501937510-1000_UserData.bin
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-12-03 17:59 . 2009-12-03 17:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-12-03 17:59 . 2009-12-03 17:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-09-17 17:21 . 2009-12-03 13:07 233818 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2006-11-02 10:33 . 2009-12-03 18:03 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 105448 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-12-03 18:03 105448 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-12 185872]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
desk.exe [2009-10-2 47997]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Cable & Wireless 11g Wireless USB.lnk - c:\program files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe [2008-10-28 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-19 15:31 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Free Music Zilla.lnk]
path=c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Free Music Zilla.lnk
backup=c:\windows\pss\Free Music Zilla.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1283296827-177754420-2501937510-1000]
"EnableNotificationsRef"=dword:00000001

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [27/08/2008 22:58 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [27/08/2008 22:58 297752]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
Trusted Zone: filesmonster.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
.

**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2009-12-03 18:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-03 18:10
ComboFix2.txt 2009-12-02 15:13

Pre-Run: 101,930,250,240 bytes free
Post-Run: 101,731,139,584 bytes free

- - End Of File - - BCCED85371D1B36DACE75724FEBE24C9


KAS
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Saturday, December 5, 2009
Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, December 05, 2009 16:52:21
Records in database: 3333384
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Objects scanned: 153010
Threats found: 7
Infected objects found: 9
Suspicious objects found: 0
Scan duration: 01:44:41


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\Windows\System32\cngaudit.dll.vir Infected: Trojan.Win32.Sirefef.a 1
C:\Qoobox\Quarantine\C\Windows\System32\drivers\UACd.sys.vir Infected: Rootkit.Win32.Agent.oxr 1
C:\Qoobox\Quarantine\C\Windows\System32\rotscxitrpvrtw.dll.vir Infected: Packed.Win32.TDSS.z 1
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3E6NMF7H\pdf[1].pdf Infected: Exploit.JS.Pdfka.asa 1
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\439TNEL3\index[2].htm Infected: Trojan-Downloader.JS.Kazmet.c 1
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\78fcee10-69d611b8 Infected: Trojan-Downloader.Java.OpenConnection.at 1
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\d1ed7d6-14333b8e Infected: Trojan-Downloader.Java.OpenConnection.at 1
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\4839f1b9-5d176524 Infected: Trojan-Downloader.Java.OpenConnection.at 1
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\345b85c8-60b85a07 Infected: Trojan-Downloader.Java.OpenStream.ad 1

Selected area has been scanned.

Blade81
2009-12-06, 09:48
Hi,

Kindly list remaining symptoms.

Are you familiar with this file: c:\users\owner\appdata\roaming\microsoft\windows\start menu\programs\startup\desk.exe ?

AVG was running during previous ComboFix run. If you don't know how to disable it then uninstall temporarily with this (http://download.avg.com/filedir/util/avg_arm_sup_____.dir/avgremover.exe).

Open notepad and copy/paste the text in the quotebox below into it:



File::
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3E6NMF7H\pdf[1].pdf
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\439TNEL3\index[2].htm
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\78fcee10-69d611b8
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\d1ed7d6-14333b8e
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\4839f1b9-5d176524
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\345b85c8-60b85a07
Rootkit::
c:\windows\win32k.sys



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.

throwway
2009-12-09, 16:18
Pleased to report that since running avgremover all symptoms have gone as far as I can tell, apart from spybot still will not run....and I'd rather not try reinstalling before I get the all clear as last time I got bsod.

I'm familiar with it only as something highly suspicious, I think I tried to turn it off in msconfig before I came here, but not sure of my memory.

Despite running AVGremover apparently successfully....looking in program files the AVG files had gone.....combofix still detected it as running and gave me warning messages.

ComboFix 09-12-02.01 - Owner 09/12/2009 14:59.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1506 [GMT 0:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
- REDUCED FUNCTIONALITY MODE -

FILE ::
"c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3E6NMF7H\pdf[1].pdf"
"c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\439TNEL3\index[2].htm"
"c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\78fcee10-69d611b8"
"c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\d1ed7d6-14333b8e"
"c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\4839f1b9-5d176524"
"c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\345b85c8-60b85a07"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\78fcee10-69d611b8
c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\d1ed7d6-14333b8e
c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\4839f1b9-5d176524
c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\345b85c8-60b85a07

.
((((((((((((((((((((((((( Files Created from 2009-11-09 to 2009-12-09 )))))))))))))))))))))))))))))))
.

2009-12-09 15:01 . 2009-12-09 15:05 -------- d-----w- c:\users\Owner\AppData\Local\temp
2009-12-09 15:01 . 2009-12-09 15:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-09 15:01 . 2009-12-09 15:01 -------- d-----w- c:\users\apache2triad.Shiny-PC\AppData\Local\temp
2009-12-09 15:01 . 2009-12-09 15:01 -------- d-----w- c:\users\Apache\AppData\Local\temp
2009-12-07 17:16 . 2009-12-07 17:18 -------- d-----w- c:\users\Owner\AppData\Local\Adobe
2009-12-06 16:36 . 2009-12-06 16:36 -------- d-----w- c:\users\Owner\AppData\Local\Apple Computer
2009-12-05 16:58 . 2009-12-05 16:58 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-05 16:57 . 2009-12-05 16:57 411368 ----a-w- c:\windows\system32\deploytk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-09 13:36 . 2008-08-27 22:58 4096 d-----w- c:\programdata\avg8
2009-12-08 19:50 . 2008-09-06 23:21 16384 d-----w- c:\program files\Diablo II
2009-12-05 16:56 . 2008-08-19 15:21 4096 d-----w- c:\program files\Java
2009-11-30 00:26 . 2009-09-20 18:42 0 ----a-w- c:\windows\win32k.sys
2009-11-19 16:55 . 2009-06-29 08:08 4096 d-----w- c:\program files\Free Music Zilla
2009-11-12 05:13 . 2009-04-18 02:35 -------- d-----w- c:\users\Owner\AppData\Roaming\IrfanView
2009-11-08 04:52 . 2009-11-08 04:52 -------- d-----w- c:\program files\Microsoft
2009-11-08 04:51 . 2009-11-08 04:51 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:51 . 2008-08-28 00:17 4096 d-----w- c:\program files\Windows Live
2009-11-08 04:50 . 2009-11-08 04:50 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-19 07:40 . 2009-10-19 07:40 -------- d-----w- c:\program files\Information Packaging
2009-10-19 07:29 . 2009-10-19 07:29 -------- d-----w- c:\program files\Datahjaelp
2009-10-19 07:10 . 2009-10-19 07:09 4096 d-----w- c:\program files\ZIP PASSWORD FINDER
2009-10-10 19:33 . 2009-10-10 19:32 4096 d-----w- c:\program files\FlashDevelop
2009-10-02 05:53 . 2009-10-24 18:42 47997 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
2008-08-20 00:02 . 2008-08-20 00:02 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2009-12-02_15.10.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-12-09 15:06 33132 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-12-09 15:06 70414 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-26 18:31 . 2009-12-09 13:38 8930 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1283296827-177754420-2501937510-1000_UserData.bin
+ 2009-12-09 15:04 . 2009-12-09 15:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-12-09 15:04 . 2009-12-09 15:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-09-17 17:21 . 2009-12-09 10:26 234202 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2006-11-02 10:33 . 2009-12-09 13:40 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 105448 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-12-09 13:40 105448 c:\windows\System32\perfc009.dat
+ 2009-12-05 16:57 . 2009-12-05 16:57 149280 c:\windows\System32\javaws.exe
+ 2009-12-05 16:57 . 2009-12-05 16:57 145184 c:\windows\System32\javaw.exe
+ 2009-12-05 16:57 . 2009-12-05 16:57 145184 c:\windows\System32\java.exe
+ 2008-02-03 23:12 . 2009-12-05 16:55 5813397 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2006-11-02 10:22 . 2009-12-09 13:36 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2006-11-02 10:22 . 2009-05-24 02:04 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-12-05 16:58 . 2009-12-05 16:58 3940352 c:\windows\Installer\9fb2400.msi
+ 2009-12-05 16:56 . 2009-12-05 16:56 1757696 c:\windows\Installer\9fb23fc.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-12 185872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-05 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
desk.exe [2009-10-2 47997]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Cable & Wireless 11g Wireless USB.lnk - c:\program files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe [2008-10-28 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-19 15:31 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Free Music Zilla.lnk]
path=c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Free Music Zilla.lnk
backup=c:\windows\pss\Free Music Zilla.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1283296827-177754420-2501937510-1000]
"EnableNotificationsRef"=dword:00000001


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{080ef108-6e09-11dd-b2de-806e6f6e6963}]
\shell\AutoRun\command - E:\Launch.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
Trusted Zone: filesmonster.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-09 15:05
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2009-12-09 15:08 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-09 15:08
ComboFix2.txt 2009-12-03 18:10
ComboFix3.txt 2009-12-02 15:13

Pre-Run: 100,274,991,104 bytes free
Post-Run: 100,960,944,128 bytes free

- - End Of File - - 569D1AB2A8F3B9E94429DCBC2A6A7C89

Blade81
2009-12-09, 17:25
Hi,

Upload c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe file to http://www.virustotal.com and post back the results.

Run ComboFix with the following script (let ComboFix update itself!):

Folder::
c:\programdata\avg8
SecCenter::
{17DDD097-36FF-435F-9E1B-52D74245D6BF}
{17DDD097-36FF-435F-9E1B-52D74245D6BF}
Rootkit::
c:\windows\win32k.sys

Post back the resultant log.

EDIT: I forgot to say that try to reinstall Spybot.

throwway
2009-12-11, 20:53
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.10.09 Trojan-Dropper.Win32.Decay!IK
AhnLab-V3 5.0.0.2 2009.10.09 -
AntiVir 7.9.1.35 2009.10.09 TR/Agent.ckat.1
Antiy-AVL 2.0.3.7 2009.10.09 Trojan/Win32.Agent.gen
Authentium 5.1.2.4 2009.10.10 -
Avast 4.8.1351.0 2009.10.09 Win32:NkCryptor
AVG 8.5.0.420 2009.10.04 PSW.Generic7.ACMC
BitDefender 7.2 2009.10.10 Trojan.Generic.2503197
CAT-QuickHeal 10.00 2009.10.09 -
ClamAV 0.94.1 2009.10.09 Trojan.Agent-123601
Comodo 2552 2009.10.09 -
DrWeb 5.0.0.12182 2009.10.10 Trojan.MulDrop.35597
eSafe 7.0.17.0 2009.10.08 -
eTrust-Vet 35.1.7060 2009.10.09 -
F-Prot 4.5.1.85 2009.10.10 W32/Dropper.AMXE
F-Secure 8.0.14470.0 2009.10.09 Trojan-Dropper.Win32.Decay.wn
Fortinet 3.120.0.0 2009.10.10 W32/BWP.WN!tr
GData 19 2009.10.10 Trojan.Generic.2503197
Ikarus T3.1.1.72.0 2009.10.09 Trojan-Dropper.Win32.Decay
Jiangmin 11.0.800 2009.10.08 Trojan/Agent.czhz
K7AntiVirus 7.10.866 2009.10.09 -
Kaspersky 7.0.0.125 2009.10.10 Trojan-Dropper.Win32.Decay.wn
McAfee 5766 2009.10.09 Downloader-BWP
McAfee+Artemis 5766 2009.10.09 Downloader-BWP
McAfee-GW-Edition 6.8.5 2009.10.10 Heuristic.BehavesLike.Win32.Backdoor.A
Microsoft 1.5101 2009.10.10 -
NOD32 4494 2009.10.09 a variant of Win32/Injector.ABX
Norman 6.01.09 2009.10.09 W32/Obfuscated.I!genr
nProtect 2009.1.8.0 2009.10.09 -
Panda 10.0.2.2 2009.10.09 Bck/Bifrost.gen
PCTools 4.4.2.0 2009.10.09 -
Prevx 3.0 2009.10.10 Medium Risk Malware
Rising 21.50.44.00 2009.10.09 Trojan.DL.Win32.FakeAV.dz
Sophos 4.45.0 2009.10.10 Mal/Behav-043
Sunbelt 3.2.1858.2 2009.10.10 -
Symantec 1.4.4.12 2009.10.10 Trojan Horse
TheHacker 6.5.0.2.035 2009.10.10 -
TrendMicro 8.950.0.1094 2009.10.09 -
VBA32 3.12.10.11 2009.10.09 -
ViRobot 2009.10.9.1978 2009.10.09 Trojan.Win32.Agent.59552
VirusBuster 4.6.5.0 2009.10.09 -
Additional information
File size: 47997 bytes
MD5 : 8e1ce69478e5837ce0caf93f5a0ef976
SHA1 : 3b40459fda674b8f83f8568c646fcdf208a253f2
SHA256: 67b6d9f78951f88f976616679ac188c47ad3ec79bae84427b0b00c4286ee5cfb
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x28A1
timedatestamp.....: 0x4AA00F3C (Thu Sep 3 20:47:24 2009)
machinetype.......: 0x14C (Intel I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1F71 0x2000 6.24 fdaeb5c8bef2e800488534a425780ecc
.rdata 0x3000 0x8A2 0xA00 4.25 85260c4ba1963ec2e498d54df5b26522
.data 0x4000 0x4E0 0x200 4.56 d9a00ed31fcf47d7068e89d1ea171d69
.rsrc 0x5000 0x8892 0x8A00 7.87 a6b16a3c94a1685d4062d2314887cec9

( 2 imports )

> kernel32.dll: GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetStartupInfoA, InterlockedCompareExchange, Sleep, InterlockedExchange, VirtualProtect, LoadLibraryA, GetProcAddress, GetSystemTimeAsFileTime
> msvcr90.dll: __set_app_type, _crt_debugger_hook, _terminate@@YAXXZ, _unlock, _encode_pointer, _lock, _onexit, _decode_pointer, _except_handler4_common, _invoke_watson, _controlfp_s, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _configthreadlocale, _initterm_e, _initterm, _acmdln, exit, _ismbblead, _XcptFilter, _exit, _cexit, __getmainargs, _amsg_exit, __2@YAPAXI@Z, __dllonexit, __3@YAXPAX@Z, memcpy, __CxxFrameHandler3, memset

( 0 exports )

ssdeep: 768:ENykKeU1Vwlo4IMKAjmGtCzoKjobvuhqqQc33hSpjnkcWrrF5q3AOB:EPDldKAjmGtCz70vuRlw6X1OB
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=2DD6F0527D6BDAE8BB6000241B807200732736AC
PEiD : -
RDS : NSRL Reference Data Set
-

throwway
2009-12-11, 21:15
ComboFix 09-12-11.01 - Owner 11/12/2009 19:57:22.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1568 [GMT 0:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\avg8
c:\programdata\avg8\srmcheck.tmp

.
((((((((((((((((((((((((( Files Created from 2009-11-11 to 2009-12-11 )))))))))))))))))))))))))))))))
.

2009-12-11 20:00 . 2009-12-11 20:09 -------- d-----w- c:\users\Owner\AppData\Local\temp
2009-12-11 20:00 . 2009-12-11 20:00 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-12-11 20:00 . 2009-12-11 20:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-11 20:00 . 2009-12-11 20:00 -------- d-----w- c:\users\apache2triad\AppData\Local\temp
2009-12-11 20:00 . 2009-12-11 20:00 -------- d-----w- c:\users\apache2triad.Shiny-PC\AppData\Local\temp
2009-12-11 20:00 . 2009-12-11 20:00 -------- d-----w- c:\users\Apache\AppData\Local\temp
2009-12-07 17:16 . 2009-12-07 17:18 -------- d-----w- c:\users\Owner\AppData\Local\Adobe
2009-12-06 16:36 . 2009-12-06 16:36 -------- d-----w- c:\users\Owner\AppData\Local\Apple Computer
2009-12-05 16:58 . 2009-12-05 16:58 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-05 16:57 . 2009-12-05 16:57 411368 ----a-w- c:\windows\system32\deploytk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-08 19:50 . 2008-09-06 23:21 -------- d-----w- c:\program files\Diablo II
2009-12-05 16:56 . 2008-08-19 15:21 -------- d-----w- c:\program files\Java
2009-11-30 00:26 . 2009-09-20 18:42 0 ----a-w- c:\windows\win32k.sys
2009-11-19 16:55 . 2009-06-29 08:08 -------- d-----w- c:\program files\Free Music Zilla
2009-11-12 05:13 . 2009-04-18 02:35 -------- d-----w- c:\users\Owner\AppData\Roaming\IrfanView
2009-11-08 04:52 . 2009-11-08 04:52 -------- d-----w- c:\program files\Microsoft
2009-11-08 04:51 . 2009-11-08 04:51 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:51 . 2008-08-28 00:17 -------- d-----w- c:\program files\Windows Live
2009-11-08 04:50 . 2009-11-08 04:50 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-19 07:40 . 2009-10-19 07:40 -------- d-----w- c:\program files\Information Packaging
2009-10-19 07:29 . 2009-10-19 07:29 -------- d-----w- c:\program files\Datahjaelp
2009-10-19 07:10 . 2009-10-19 07:09 -------- d-----w- c:\program files\ZIP PASSWORD FINDER
2009-10-02 05:53 . 2009-10-24 18:42 47997 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
2008-08-20 00:02 . 2008-08-20 00:02 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2009-12-02_15.10.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-12-09 15:06 33132 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-12-09 15:06 70414 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-26 18:31 . 2009-12-09 13:38 8930 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1283296827-177754420-2501937510-1000_UserData.bin
+ 2009-12-11 20:02 . 2009-12-11 20:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-12-11 20:02 . 2009-12-11 20:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-09-17 17:21 . 2009-12-11 12:53 234604 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2006-11-02 10:33 . 2009-12-11 20:06 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 105448 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-12-11 20:06 105448 c:\windows\System32\perfc009.dat
+ 2009-12-05 16:57 . 2009-12-05 16:57 149280 c:\windows\System32\javaws.exe
+ 2009-12-05 16:57 . 2009-12-05 16:57 145184 c:\windows\System32\javaw.exe
+ 2009-12-05 16:57 . 2009-12-05 16:57 145184 c:\windows\System32\java.exe
+ 2008-02-03 23:12 . 2009-12-05 16:55 5813397 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2006-11-02 10:22 . 2009-12-09 13:36 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2006-11-02 10:22 . 2009-05-24 02:04 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-12-05 16:58 . 2009-12-05 16:58 3940352 c:\windows\Installer\9fb2400.msi
+ 2009-12-05 16:56 . 2009-12-05 16:56 1757696 c:\windows\Installer\9fb23fc.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-12 185872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-05 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
desk.exe [2009-10-2 47997]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Cable & Wireless 11g Wireless USB.lnk - c:\program files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe [2008-10-28 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-19 15:31 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Free Music Zilla.lnk]
path=c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Free Music Zilla.lnk
backup=c:\windows\pss\Free Music Zilla.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2008-03-11 11:44 16384 ----a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-05-22 14:04 1217784 ----a-w- c:\program files\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-02-12 01:26 185872 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1283296827-177754420-2501937510-1000]
"EnableNotificationsRef"=dword:00000001

.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
Trusted Zone: filesmonster.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-AV Care - c:\program files\AV Care\AvCare.exe
MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
MSConfigStartUp-Monopod - c:\users\Owner\AppData\Local\Temp\e.exe
MSConfigStartUp-NordBull - c:\users\Owner\AppData\Local\Temp\b.exe
MSConfigStartUp-PopRock - c:\users\Owner\AppData\Local\Temp\b.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-11 20:09
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(3524)
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
.
**************************************************************************
.
Completion time: 2009-12-11 20:11:33 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-11 20:11
ComboFix2.txt 2009-12-09 15:08
ComboFix3.txt 2009-12-03 18:10
ComboFix4.txt 2009-12-02 15:13

Pre-Run: 98,702,659,584 bytes free
Post-Run: 99,815,051,264 bytes free

- - End Of File - - 3FDC1B7D05EE3CC9FBD6C1E5B41E5840

Blade81
2009-12-11, 21:43
Hi,

Disable Windows Defender and run ComboFix with this script (have internet connection enabled during the run):


http://forums.spybot.info/showthread.php?p=351198#post351198
Collect::
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
File::
c:\windows\win32k.sys

Post back the results.

throwway
2009-12-12, 21:01
It gave me a warning about spybot being running, but doesn't seem to have done any harm
ComboFix 09-12-11.05 - Owner 12/12/2009 19:52:19.5.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1488 [GMT 0:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\windows\win32k.sys"

file zipped: c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
c:\windows\win32k.sys

.
((((((((((((((((((((((((( Files Created from 2009-11-12 to 2009-12-12 )))))))))))))))))))))))))))))))
.

2009-12-12 19:55 . 2009-12-12 19:56 -------- d-----w- c:\users\Owner\AppData\Local\temp
2009-12-12 19:55 . 2009-12-12 19:55 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-12-12 19:55 . 2009-12-12 19:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-12 19:55 . 2009-12-12 19:55 -------- d-----w- c:\users\apache2triad\AppData\Local\temp
2009-12-12 19:55 . 2009-12-12 19:55 -------- d-----w- c:\users\apache2triad.Shiny-PC\AppData\Local\temp
2009-12-12 19:55 . 2009-12-12 19:55 -------- d-----w- c:\users\Apache\AppData\Local\temp
2009-12-11 20:21 . 2009-12-11 20:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-07 17:16 . 2009-12-07 17:18 -------- d-----w- c:\users\Owner\AppData\Local\Adobe
2009-12-06 16:36 . 2009-12-06 16:36 -------- d-----w- c:\users\Owner\AppData\Local\Apple Computer
2009-12-05 16:58 . 2009-12-05 16:58 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-05 16:57 . 2009-12-05 16:57 411368 ----a-w- c:\windows\system32\deploytk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-11 20:21 . 2008-08-27 22:57 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-12-08 19:50 . 2008-09-06 23:21 -------- d-----w- c:\program files\Diablo II
2009-12-05 16:56 . 2008-08-19 15:21 -------- d-----w- c:\program files\Java
2009-11-19 16:55 . 2009-06-29 08:08 -------- d-----w- c:\program files\Free Music Zilla
2009-11-12 05:13 . 2009-04-18 02:35 -------- d-----w- c:\users\Owner\AppData\Roaming\IrfanView
2009-11-08 04:52 . 2009-11-08 04:52 -------- d-----w- c:\program files\Microsoft
2009-11-08 04:51 . 2009-11-08 04:51 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:51 . 2008-08-28 00:17 -------- d-----w- c:\program files\Windows Live
2009-11-08 04:50 . 2009-11-08 04:50 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-19 07:40 . 2009-10-19 07:40 -------- d-----w- c:\program files\Information Packaging
2009-10-19 07:29 . 2009-10-19 07:29 -------- d-----w- c:\program files\Datahjaelp
2009-10-19 07:10 . 2009-10-19 07:09 -------- d-----w- c:\program files\ZIP PASSWORD FINDER
2008-08-20 00:02 . 2008-08-20 00:02 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2009-12-02_15.10.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-12-12 19:44 34030 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-12-12 19:44 70584 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-26 18:31 . 2009-12-12 19:44 9252 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1283296827-177754420-2501937510-1000_UserData.bin
+ 2009-12-12 19:42 . 2009-12-12 19:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-12-12 19:42 . 2009-12-12 19:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-09-17 17:21 . 2009-12-11 12:53 234604 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2006-11-02 10:33 . 2009-12-12 19:46 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 105448 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-12-12 19:46 105448 c:\windows\System32\perfc009.dat
+ 2009-12-05 16:57 . 2009-12-05 16:57 149280 c:\windows\System32\javaws.exe
+ 2009-12-05 16:57 . 2009-12-05 16:57 145184 c:\windows\System32\javaw.exe
+ 2009-12-05 16:57 . 2009-12-05 16:57 145184 c:\windows\System32\java.exe
+ 2008-02-03 23:12 . 2009-12-05 16:55 5813397 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2006-11-02 10:22 . 2009-12-09 13:36 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2006-11-02 10:22 . 2009-05-24 02:04 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-12-05 16:58 . 2009-12-05 16:58 3940352 c:\windows\Installer\9fb2400.msi
+ 2009-12-05 16:56 . 2009-12-05 16:56 1757696 c:\windows\Installer\9fb23fc.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-12 185872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-05 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Cable & Wireless 11g Wireless USB.lnk - c:\program files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe [2008-10-28 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-19 15:31 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Free Music Zilla.lnk]
path=c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Free Music Zilla.lnk
backup=c:\windows\pss\Free Music Zilla.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2008-03-11 11:44 16384 ----a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-05-22 14:04 1217784 ----a-w- c:\program files\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-02-12 01:26 185872 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1283296827-177754420-2501937510-1000]
"EnableNotificationsRef"=dword:00000001

S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [11/12/2009 20:21 1153368]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
Trusted Zone: filesmonster.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-12 19:56
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-12-12 19:57:57
ComboFix-quarantined-files.txt 2009-12-12 19:57
ComboFix2.txt 2009-12-11 20:11
ComboFix3.txt 2009-12-09 15:08
ComboFix4.txt 2009-12-03 18:10
ComboFix5.txt 2009-12-12 19:51

Pre-Run: 100,886,040,576 bytes free
Post-Run: 101,709,758,464 bytes free

- - End Of File - - DD752BF575AC2B74C21B0128FA1130EA
Upload was successful

Blade81
2009-12-13, 10:17
Good. How's the system running now?

throwway
2009-12-17, 03:32
It seems fine to me.

Blade81
2009-12-17, 06:40
Good. Then it's time to secure your system to prevent against further intrusions.


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

A To disable the System Restore feature:

1. Click on the Start button.
2. Hover over the Computer option, right click on it and then click Properties.
3. On the left hand side, click Advanced Settings.
4. If asked to permit the action, click on Allow.
5. Click on the System Protection tab.
6. Uncheck any checkboxes listed for your hard drives.
7. Press OK.


B. Reboot.

C Turn ON System Restore.
Follow the steps like you did when disabling system restore but on step 6. check any checkboxes listed for your hard drives.



Now lets uninstall ComboFix:

Click START then RUN
Now copy-paste Combofix /uninstall in the runbox and click OK



Please download OTC (http://oldtimer.geekstogo.com/OTC.exe) and save it to desktop.

Double-click OTC.exe.
Click the CleanUp! button.
Select Yes when the
Begin cleanup Process?
prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.


UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site (http://windowsupdate.microsoft.com/) to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.

hosts file:
Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate webpages. We can customize a hosts file so that it blocks certain webpages. However, it can slow down certain computers. This is why using a hosts file is optional!!
Download it here (http://www.mvps.org/winhelp2002/hosts.htm). Make sure you read the instructions on how to install the hosts file. There is a good tutorial here (http://www.bleepingcomputer.com/forums/tutorial51.html)
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button (at the lower left hand corner of your screen) Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then double-click it. On the dropdown box, change the setting from automatic to manual. Click ok
Get Anti Virus Software and keep it updated - Most AVs will update automatically, but if not I would recommend making updating the AV the first job every time the PC is connected to the internet. An AV that is using defs that are seven days old is not going to be much protection. If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out. Good free antivirus programs are:
Antivir (http://free-av.com/en/download/1/download_avira_antivir_personal__free_antivirus.html)
Avast! (http://www.avast.com/eng/download-avast-home.html)
Good commercial ones are from:
Kaspersky (http://www.kaspersky.com/homeuser) and
ESET (http://www.eset.com/products/index.php)



Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Once again, please post and tell me how things are going with your system... problems etc.

Have a great day,
Blade :cool:

throwway
2009-12-21, 17:32
When trying to run windows update

"Error code 8024001B Windows update encountered an unknown error"

Also, I've remembered why I turned updates off on this PC....I tried a few times when it was new, always got a generic error message towards the end of the update process 'unknown error something' and computer wouldn't restart afterwards, had to use system restore to get it working again....



Re anti-virus suggestions.....is AVG not up to much then?

Blade81
2009-12-21, 20:34
Hi,

I recommend to post about that Windows Update issue on Windows Update area (http://social.answers.microsoft.com/Forums/en-US/vistawu/threads) of Microsoft forums.


Re anti-virus suggestions.....is AVG not up to much then?
You may use that one too :)

Blade81
2009-12-28, 15:36
Since malware issue appears to be resolved ... this Topic has been closed. Glad I could help. :)

Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.