Page 1 of 5 12345 LastLast
Results 1 to 10 of 44

Thread: Win32.Zafi.B & Downloader.MisleadApp-HJT Scan

  1. #1
    Senior Member
    Join Date
    Jan 2008
    Posts
    111

    Default Win32.Zafi.B & Downloader.MisleadApp-HJT Scan

    Infected with Win32.Zafi.B & Downloader.MisleadApp. Please help.

    Thanks,

    Mike

    -----
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:29:28 PM, on 1/28/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    C:\Documents and Settings\Thomas\Application Data\Google\cijwg16225165.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
    C:\Program Files\Symantec\Symantec Endpoint Protection\SavUI.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Documents and Settings\Thomas\Desktop\HiJackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [realteke] "C:\Documents and Settings\Thomas\Application Data\Google\cijwg16225165.exe" 2
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
    O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
    O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
    O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

    --
    End of file - 6671 bytes

  2. #2
    Emeritus
    Join Date
    Aug 2007
    Posts
    1,875

    Default

    Hello and welcome to Safer Networking.

    My name is km2357 and I will be helping you to remove any infection(s) that you may have.

    I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

    If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.

    Please do not start another thread or topic, I will assist you at this thread until we solve your problems.

    Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.

    Sorry for the delay in replying, the forum is very busy. If you still need help, please post a fresh HiJackThis Log
    Malware Removal University Master
    Member of ASAP & UNITE

  3. #3
    Senior Member
    Join Date
    Jan 2008
    Posts
    111

    Default HJT 2:52:14 PM, on 2/1/2009

    Sounds Great and thanks. Here ya go:

    --------------------------------
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:52:14 PM, on 2/1/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    C:\Documents and Settings\Thomas\Application Data\Google\cijwg16225165.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Symantec\Symantec Endpoint Protection\SavUI.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Thomas\Desktop\HiJackThis.exe
    C:\Program Files\Mozilla Firefox\firefox.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [realteke] "C:\Documents and Settings\Thomas\Application Data\Google\cijwg16225165.exe" 2
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
    O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
    O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
    O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

    --
    End of file - 6716 bytes

  4. #4
    Emeritus
    Join Date
    Aug 2007
    Posts
    1,875

    Default

    Step # 1: Make an uninstall list using HijackThis
    To access the Uninstall Manager you would do the following:

    1. Start HijackThis
    2. Click on the Config button
    3. Click on the Misc Tools button
    4. Click on the Open Uninstall Manager button.
    5. Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.


    Step # 2: Download and Run ComboFix

    We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

    http://www.bleepingcomputer.com/comb...o-use-combofix

    *Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    * IMPORTANT !!! Save ComboFix.exe to your Desktop

    When finished, it shall produce a log for you. Please include the Uninstall List,C:\ComboFix.txt and a fresh HiJackThis Log in your next reply.

    Use multiple posts if you can't fit everything into one post.
    Malware Removal University Master
    Member of ASAP & UNITE

  5. #5
    Senior Member
    Join Date
    Jan 2008
    Posts
    111

    Default Ok

    I will post these results this evening (2/2/09)

    Thanks,

    ~Mike

  6. #6
    Senior Member
    Join Date
    Jan 2008
    Posts
    111

    Default HJT Uninstall List

    32 Bit HP CIO Components Installer
    ABBYY FineReader 6.0 Sprint
    Adobe Flash Player Plugin
    Adobe Reader 9
    AIM 6
    AnswerWorks 4.0 Runtime - English
    Apple Mobile Device Support
    Apple Software Update
    ArcSoft Panorama Maker 3
    Bonjour
    BuddyList Ops 1.0.0.1
    Cisco Systems VPN Client 5.0.00.0340
    Compatibility Pack for the 2007 Office system
    HijackThis 2.0.2
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    Intel(R) Extreme Graphics 2 Driver
    Intel(R) PRO Network Adapters and Drivers
    iTunes
    Java(TM) 6 Update 11
    LimeWire 4.16.7
    Linksys Wireless-G PCI Adapter
    LiveUpdate 3.3 (Symantec Corporation)
    Microsoft .NET Framework 2.0 Service Pack 1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Professional Edition 2003
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    MobileMe Control Panel
    Mozilla Firefox (3.0.5)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    Nikon Message Center
    PictureProject
    QuickTime
    Registry Clean Pro
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    SoundMAX
    Symantec Endpoint Protection
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Viewpoint Media Player
    Windows Media Format 11 runtime
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Media Player 11
    Windows XP Service Pack 3

  7. #7
    Senior Member
    Join Date
    Jan 2008
    Posts
    111

    Default ComboFix

    ComboFix 09-02-02.03 - Thomas 2009-02-02 18:11:24.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.542 [GMT -5:00]
    Running from: c:\documents and settings\Thomas\Desktop\ComboFix.exe
    AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated)
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Thomas\Application Data\Google\cijwg16225165.exe
    c:\windows\system32\AutoRun.inf
    c:\windows\system32\TDSSfpmp.dll
    c:\windows\system32\TDSSnrsr.dll
    c:\windows\system32\TDSSoexh.dll
    c:\windows\system32\TDSSosvd.dat
    c:\windows\system32\TDSSriqp.dll
    c:\windows\system32\TDSStkdv.log

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_TDSSSERV.SYS
    -------\Service_TDSSserv.sys


    ((((((((((((((((((((((((( Files Created from 2009-01-02 to 2009-02-02 )))))))))))))))))))))))))))))))
    .

    2009-01-19 15:21 . 2009-01-21 17:21 53,874 --a------ c:\windows\Sysvxd.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-01-28 18:27 --------- d-----w c:\documents and settings\Thomas\Application Data\LimeWire
    2009-01-19 18:39 --------- d-----w c:\documents and settings\Thomas\Application Data\ArcSoft
    2009-01-19 18:39 --------- d-----w c:\documents and settings\Thomas\Application Data\Apple Computer
    2009-01-19 18:39 --------- d-----w c:\documents and settings\Thomas\Application Data\acccore
    2009-01-19 18:39 --------- d-----w c:\documents and settings\Thomas\Application Data\5000 Series
    2009-01-01 04:23 --------- d-----w c:\program files\Common Files\Adobe
    2008-12-31 23:39 --------- d-----w c:\program files\Common Files\Symantec Shared
    2008-12-31 23:39 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
    2008-12-31 23:38 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
    2008-12-31 23:38 123,952 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
    2008-12-31 23:38 10,563 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
    2008-12-31 23:38 --------- d-----w c:\program files\Symantec
    2008-12-31 23:35 --------- d-----w c:\program files\Common Files\Software Center
    2008-12-31 23:32 --------- d-----w c:\program files\Java
    2008-12-31 23:31 --------- d-----w c:\program files\QuickTime
    2008-12-31 23:31 --------- d-----w c:\program files\LimeWire
    2008-12-31 23:31 --------- d-----w c:\program files\HP
    2008-12-25 13:24 --------- d-----w c:\documents and settings\Kelly\Application Data\LimeWire
    2008-12-21 15:58 --------- d-----w c:\documents and settings\Thomas\Application Data\U3
    2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
    2008-02-16 19:28 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
    2008-10-26 17:34 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102620081027\index.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-31 136600]
    "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-08-14 115560]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

    c:\documents and settings\Kelly\Start Menu\Programs\Startup\
    LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-04-18 147456]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-02-16 118784]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\WINDOWS\\system32\\mmc.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AIM6\\aim6.exe"=
    "c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
    "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
    "c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
    "%windir%\\system32\\drivers\\svchost.exe"=

    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-01-24 24652]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-31 99376]
    S3 WlanUIG;2Wire 802.11g USB Driver;c:\windows\system32\drivers\WlanUIG.sys [2004-04-08 347648]

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - GTNDIS5

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
    \Shell\AutoRun\command - E:\LaunchU3.exe -a

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f821370f-cf6f-11dd-b30e-0012178c2d12}]
    \Shell\AutoRun\command - E:\LaunchU3.exe -a
    .
    Contents of the 'Scheduled Tasks' folder

    2009-01-27 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-Aim6 - (no file)
    HKLM-Run-realteke - c:\documents and settings\Thomas\Application Data\Google\cijwg16225165.exe
    Notify-NavLogon - (no file)
    SafeBoot-Symantec Antvirus


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.aol.com/?src=aim
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    Trusted Zone: turbotax.com
    FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\irdw59wb.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.myspace.com/
    FF - plugin: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\irdw59wb.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07075003.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npampx3.0.84.2.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-02-02 18:14:42
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
    c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Cisco Systems\VPN Client\cvpnd.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
    c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
    c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Completion time: 2009-02-02 18:16:18 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-02-02 23:16:15

    Pre-Run: 98,546,843,648 bytes free
    Post-Run: 98,637,557,760 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    167 --- E O F --- 2009-01-14 08:01:58

  8. #8
    Senior Member
    Join Date
    Jan 2008
    Posts
    111

    Default HijackThis 6:19:00 PM, on 2/2/2009

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:19:00 PM, on 2/2/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\Thomas\Desktop\HiJackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
    O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
    O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

    --
    End of file - 6354 bytes

  9. #9
    Emeritus
    Join Date
    Aug 2007
    Posts
    1,875

    Default

    IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

    LimeWire 4.16.7

    I'd like you to read the Guidelines for P2P Programs where we explain why it's not a good idea to have them.

    Also available here.

    My recommendation is you go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).


    Registry Cleaners

    Re. Registry Clean Pro

    I don't personally recommend the use of ANY registry cleaners.
    Here is an excerpt from a discussion on regcleaners:

    Most reg cleaners aren't "bad" as such, but they aren't perfect and even the best have been known to cause problems. The point we are trying to make is that the risk of using one far outweighs any benefit. If it does work perfectly you will not see any difference. If it doesn't work properly you may end up with an expensive doorstop.
    http://forums.whatthetech.com/Regcleaner_t42862.html

    I recommend that you uninstall Registry Clean Pro from your computer.



    Step # 1: Run CFScript

    • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

      Code:
      KILLALL::
      
      File::
      
      c:\documents and settings\Kelly\Start Menu\Programs\Startup\LimeWire On Startup.lnk
      c:\Windows\System32\drivers\svchost.exe
      
      Folder::
      
      c:\documents and settings\Thomas\Application Data\LimeWire
      c:\program files\LimeWire
      c:\documents and settings\Kelly\Application Data\LimeWire
      
      Registry::
      
      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "c:\\Program Files\\LimeWire\\LimeWire.exe"=-
      "%windir%\\system32\\drivers\\svchost.exe"=-
      [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
      [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f821370f-cf6f-11dd-b30e-0012178c2d12}]
    • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.







      Note: This CFScript is for use on k8fox1's computer only! Do not use it on your computer.

    • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
    • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
    • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.


    CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

    In your next post/reply, I need to see the following:

    1. The ComboFix Log that appears after Step 1 has been completed.
    2. A fresh HiJackThis Log taken after Step 1 has been completed.
    Malware Removal University Master
    Member of ASAP & UNITE

  10. #10
    Senior Member
    Join Date
    Jan 2008
    Posts
    111

    Default ComboFix 09-02-02.04

    ComboFix 09-02-02.04 - Thomas 2009-02-03 21:43:15.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.623 [GMT -5:00]
    Running from: c:\documents and settings\Thomas\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Thomas\Desktop\CFScript.txt
    AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated)
    * Created a new restore point

    FILE ::
    c:\documents and settings\Kelly\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    c:\windows\System32\drivers\svchost.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Kelly\Application Data\LimeWire
    c:\documents and settings\Kelly\Application Data\LimeWire\createtimes.cache
    c:\documents and settings\Kelly\Application Data\LimeWire\fileurns.bak
    c:\documents and settings\Kelly\Application Data\LimeWire\fileurns.cache
    c:\documents and settings\Kelly\Application Data\LimeWire\gnutella.net
    c:\documents and settings\Kelly\Application Data\LimeWire\installation.props
    c:\documents and settings\Kelly\Application Data\LimeWire\library.dat
    c:\documents and settings\Kelly\Application Data\LimeWire\limewire.props
    c:\documents and settings\Kelly\Application Data\LimeWire\mojito.props
    c:\documents and settings\Kelly\Application Data\LimeWire\questions.props
    c:\documents and settings\Kelly\Application Data\LimeWire\responses.cache
    c:\documents and settings\Kelly\Application Data\LimeWire\simpp.xml
    c:\documents and settings\Kelly\Application Data\LimeWire\spam.dat
    c:\documents and settings\Kelly\Application Data\LimeWire\tables.props
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme.lwtp
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\01_star.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\02_star.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\03_star.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\04_star.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\05_star.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\chat.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\forward_up.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\kill.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\kill_on.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\logo.png
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\notsearching.png
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\pause_up.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\play_dn.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\play_up.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\question.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\searching.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\stop_up.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\theme.txt
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\version.txt
    c:\documents and settings\Kelly\Application Data\LimeWire\themes\windows_theme\warning.gif
    c:\documents and settings\Kelly\Application Data\LimeWire\version.xml
    c:\documents and settings\Kelly\Start Menu\Programs\Startup\LimeWire On Startup.lnk
    c:\documents and settings\Thomas\Application Data\LimeWire
    c:\documents and settings\Thomas\Application Data\LimeWire\createtimes.cache
    c:\documents and settings\Thomas\Application Data\LimeWire\fileurns.bak
    c:\documents and settings\Thomas\Application Data\LimeWire\fileurns.cache
    c:\documents and settings\Thomas\Application Data\LimeWire\filters.props
    c:\documents and settings\Thomas\Application Data\LimeWire\gnutella.net
    c:\documents and settings\Thomas\Application Data\LimeWire\installation.props
    c:\documents and settings\Thomas\Application Data\LimeWire\library.dat
    c:\documents and settings\Thomas\Application Data\LimeWire\limewire.props
    c:\documents and settings\Thomas\Application Data\LimeWire\mojito.props
    c:\documents and settings\Thomas\Application Data\LimeWire\questions.props
    c:\documents and settings\Thomas\Application Data\LimeWire\responses.cache
    c:\documents and settings\Thomas\Application Data\LimeWire\simpp.xml
    c:\documents and settings\Thomas\Application Data\LimeWire\spam.dat
    c:\documents and settings\Thomas\Application Data\LimeWire\tables.props
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme.lwtp
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\01_star.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\02_star.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\03_star.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\04_star.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\05_star.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\chat.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\forward_up.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\kill.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\kill_on.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\logo.png
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\notsearching.png
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\pause_up.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\play_dn.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\play_up.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\question.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\searching.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\stop_up.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\theme.txt
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\version.txt
    c:\documents and settings\Thomas\Application Data\LimeWire\themes\windows_theme\warning.gif
    c:\documents and settings\Thomas\Application Data\LimeWire\ttrees.cache
    c:\documents and settings\Thomas\Application Data\LimeWire\ttroot.cache
    c:\documents and settings\Thomas\Application Data\LimeWire\version.xml
    c:\documents and settings\Thomas\Application Data\LimeWire\xml\data\audio.sxml
    c:\program files\LimeWire
    c:\program files\LimeWire\.NetworkShare\LimeWireWin4.16.7.exe
    c:\program files\LimeWire\Buy LimeWire PRO.url
    c:\program files\LimeWire\COPYING
    c:\program files\LimeWire\data.ser
    c:\program files\LimeWire\install.log
    c:\program files\LimeWire\kimmies playlistttttt.m3u
    c:\program files\LimeWire\language.prop
    c:\program files\LimeWire\lib\aopalliance.jar
    c:\program files\LimeWire\lib\clink.jar
    c:\program files\LimeWire\lib\commons-httpclient.jar
    c:\program files\LimeWire\lib\commons-logging.jar
    c:\program files\LimeWire\lib\commons-net.jar
    c:\program files\LimeWire\lib\commons-pool.jar
    c:\program files\LimeWire\lib\daap.jar
    c:\program files\LimeWire\lib\forms.jar
    c:\program files\LimeWire\lib\foxtrot.jar
    c:\program files\LimeWire\lib\gettext-commons.jar
    c:\program files\LimeWire\lib\guice-1.0.jar
    c:\program files\LimeWire\lib\hashes
    c:\program files\LimeWire\lib\httpcore-nio.jar
    c:\program files\LimeWire\lib\httpcore.jar
    c:\program files\LimeWire\lib\icu4j.jar
    c:\program files\LimeWire\lib\id3v2.jar
    c:\program files\LimeWire\lib\jcraft.jar
    c:\program files\LimeWire\lib\jdic.dll
    c:\program files\LimeWire\lib\jdic.jar
    c:\program files\LimeWire\lib\jdic_stub.jar
    c:\program files\LimeWire\lib\jflac.jar
    c:\program files\LimeWire\lib\jl.jar
    c:\program files\LimeWire\lib\jmdns.jar
    c:\program files\LimeWire\lib\jogg.jar
    c:\program files\LimeWire\lib\jorbis.jar
    c:\program files\LimeWire\lib\LimeWire.ico
    c:\program files\LimeWire\lib\LimeWire.jar
    c:\program files\LimeWire\lib\log4j.jar
    c:\program files\LimeWire\lib\log4j.properties
    c:\program files\LimeWire\lib\looks.jar
    c:\program files\LimeWire\lib\messages.jar
    c:\program files\LimeWire\lib\mp3spi.jar
    c:\program files\LimeWire\lib\ProgressTabs.jar
    c:\program files\LimeWire\lib\swt.jar
    c:\program files\LimeWire\lib\SystemUtilities.dll
    c:\program files\LimeWire\lib\SystemUtilitiesA.dll
    c:\program files\LimeWire\lib\themes.jar
    c:\program files\LimeWire\lib\tray.dll
    c:\program files\LimeWire\lib\tritonus.jar
    c:\program files\LimeWire\lib\vorbisspi.jar
    c:\program files\LimeWire\LimeWire On Startup.lnk
    c:\program files\LimeWire\LimeWire.exe
    c:\program files\LimeWire\LimeWire.ico
    c:\program files\LimeWire\limewire.m3u
    c:\program files\LimeWire\pmf.ico
    c:\program files\LimeWire\root\magnet10\badge.img
    c:\program files\LimeWire\root\magnet10\canHandle.img
    c:\program files\LimeWire\root\magnet10\limewire.gif
    c:\program files\LimeWire\root\magnet10\options.js
    c:\program files\LimeWire\root\magnet10\silentdetect.js
    c:\program files\LimeWire\SOURCE
    c:\program files\LimeWire\spacer.gif
    c:\program files\LimeWire\uninstall.exe
    c:\program files\LimeWire\unpack.log

    .
    ((((((((((((((((((((((((( Files Created from 2009-01-04 to 2009-02-04 )))))))))))))))))))))))))))))))
    .

    2009-01-19 15:21 . 2009-01-21 17:21 53,874 --a------ c:\windows\Sysvxd.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-01-19 18:39 --------- d-----w c:\documents and settings\Thomas\Application Data\ArcSoft
    2009-01-19 18:39 --------- d-----w c:\documents and settings\Thomas\Application Data\Apple Computer
    2009-01-19 18:39 --------- d-----w c:\documents and settings\Thomas\Application Data\acccore
    2009-01-19 18:39 --------- d-----w c:\documents and settings\Thomas\Application Data\5000 Series
    2009-01-01 04:23 --------- d-----w c:\program files\Common Files\Adobe
    2008-12-31 23:39 --------- d-----w c:\program files\Common Files\Symantec Shared
    2008-12-31 23:39 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
    2008-12-31 23:38 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
    2008-12-31 23:38 123,952 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
    2008-12-31 23:38 10,563 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
    2008-12-31 23:38 --------- d-----w c:\program files\Symantec
    2008-12-31 23:35 --------- d-----w c:\program files\Common Files\Software Center
    2008-12-31 23:32 --------- d-----w c:\program files\Java
    2008-12-31 23:31 --------- d-----w c:\program files\QuickTime
    2008-12-31 23:31 --------- d-----w c:\program files\HP
    2008-12-21 15:58 --------- d-----w c:\documents and settings\Thomas\Application Data\U3
    2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
    2008-02-16 19:28 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
    2008-10-26 17:34 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102620081027\index.dat
    .

    ((((((((((((((((((((((((((((( snapshot@2009-02-02_18.15.34.89 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2005-10-20 12:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
    + 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
    + 2009-02-04 02:46:09 16,384 ----atw c:\windows\temp\Perflib_Perfdata_51c.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-31 136600]
    "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-08-14 115560]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-02-16 118784]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\WINDOWS\\system32\\mmc.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AIM6\\aim6.exe"=
    "c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
    "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
    "c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=

    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-01-24 24652]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-31 99376]
    S3 WlanUIG;2Wire 802.11g USB Driver;c:\windows\system32\drivers\WlanUIG.sys [2004-04-08 347648]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    .
    Contents of the 'Scheduled Tasks' folder

    2009-02-03 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.aol.com/?src=aim
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    Trusted Zone: turbotax.com
    FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\irdw59wb.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.myspace.com/
    FF - plugin: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\irdw59wb.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07075003.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npampx3.0.84.2.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-02-03 21:46:34
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
    c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Cisco Systems\VPN Client\cvpnd.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
    c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
    c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Completion time: 2009-02-03 21:48:15 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-02-04 02:48:12
    ComboFix2.txt 2009-02-02 23:16:20

    Pre-Run: 98,679,541,760 bytes free
    Post-Run: 98,667,196,416 bytes free

    290 --- E O F --- 2009-01-14 08:01:58

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •