Page 4 of 8 FirstFirst 12345678 LastLast
Results 31 to 40 of 73

Thread: Internet Redirect - iexplorer - shutting down select programs - help?

  1. #31
    Member
    Join Date
    Apr 2009
    Posts
    57

    Default update

    GMER ran successfully... log follows... but after a ComboFix scan got the blue screen of death again. Getting good at restore. At next available moment I'm planning to run ComboFix again and try to get a list of the .dll files it says it is deleating.

    Note... though the subs folder under erdnt is the newest recovery file, it also results in a stop error. have to use a slightly older one. does this make sense?

    GMER 1.0.15.14972 - http://www.gmer.net
    Rootkit scan 2009-05-08 19:26:43
    Windows 5.1.2600 Service Pack 3


    ---- System - GMER 1.0.15 ----

    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAC1306B8]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xAC130574]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xAC130A52]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAC13014C]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAC13064E]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAC13008C]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAC1300F0]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAC13076E]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAC13072E]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xAC1308AE]

    ---- User code sections - GMER 1.0.15 ----

    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!TranslateMessage 7E418BF6 6 Bytes PUSH 02C01430; RET
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 42F0F341 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DefWindowProcA 7E42C17E 6 Bytes PUSH 02C01770; RET
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 430A187F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 430A1800 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 430A1844 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 430A178C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 430A17C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 430A18BA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 42F316F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!InternetCloseHandle 7805DA59 6 Bytes PUSH 02BFFB38; RET
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!HttpOpenRequestA 78064341 6 Bytes CALL 3B090335
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!InternetConnectA 7806499A 6 Bytes PUSH 02BFED7C; RET
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!InternetReadFile 7806ABB4 6 Bytes PUSH 02BFF2A8; RET
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!InternetQueryDataAvailable 7806ADF5 6 Bytes PUSH 02BFF810; RET
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!HttpSendRequestA 7806CD40 6 Bytes PUSH 02C00B84; RET
    .text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!HttpSendRequestW 78080825 6 Bytes PUSH 02C00648; RET

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\WINDOWS\system32\services.exe[616] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
    IAT C:\WINDOWS\system32\services.exe[616] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
    AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
    AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SOFTWARE\Classes\CLSID\{210BD7C7-47ED-BBE9-95D0F9FAA3BD0E97}\{C5D4C247-F1D1-D183-A63FC2DFAAC29AA3}\{B55B3474-A2E6-F6F7-4AD088E6434601A2}
    Reg HKLM\SOFTWARE\Classes\CLSID\{210BD7C7-47ED-BBE9-95D0F9FAA3BD0E97}\{C5D4C247-F1D1-D183-A63FC2DFAAC29AA3}\{B55B3474-A2E6-F6F7-4AD088E6434601A2}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
    Reg HKLM\SOFTWARE\Classes\CLSID\{945169D7-C27E-315B-97A3E6913A1C7622}\{06C63AB7-5C18-FA8E-E5D32118C99A5B59}\{F7BD6AFF-A45B-6FB8-BB91AB79C0A3DA53}
    Reg HKLM\SOFTWARE\Classes\CLSID\{945169D7-C27E-315B-97A3E6913A1C7622}\{06C63AB7-5C18-FA8E-E5D32118C99A5B59}\{F7BD6AFF-A45B-6FB8-BB91AB79C0A3DA53}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
    Reg HKLM\SOFTWARE\Classes\CLSID\{A73A7B6D-D5C7-2D01-6A3ED58A203D5FEA}\{958FE6C0-B367-4AD6-C310294BFC5DB709}\{E2E9EAF6-387C-4947-07B2C800F4ACC9F3}
    Reg HKLM\SOFTWARE\Classes\CLSID\{A73A7B6D-D5C7-2D01-6A3ED58A203D5FEA}\{958FE6C0-B367-4AD6-C310294BFC5DB709}\{E2E9EAF6-387C-4947-07B2C800F4ACC9F3}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
    Reg HKLM\SOFTWARE\Classes\CLSID\{BF11F383-757D-CF48-6D213AC2BB6130AD}\{12507465-D6D8-AFB1-97ED5D21195D77D5}\{90E47118-DD98-E716-1AABCD138C042D55}
    Reg HKLM\SOFTWARE\Classes\CLSID\{BF11F383-757D-CF48-6D213AC2BB6130AD}\{12507465-D6D8-AFB1-97ED5D21195D77D5}\{90E47118-DD98-E716-1AABCD138C042D55}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
    Reg HKLM\SOFTWARE\Classes\CLSID\{F2F43379-985D-E7AE-2F5BD6B18999A07F}\{64C9A7C2-676E-3AEC-13AF6B278F65FD89}\{7B815B3C-162E-096A-EBEBEFD33B1AE416}
    Reg HKLM\SOFTWARE\Classes\CLSID\{F2F43379-985D-E7AE-2F5BD6B18999A07F}\{64C9A7C2-676E-3AEC-13AF6B278F65FD89}\{7B815B3C-162E-096A-EBEBEFD33B1AE416}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
    Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E8066BAB-BCF1-46CA-D8AA-605D8DE00F6D}

    ---- EOF - GMER 1.0.15 ----

  2. #32
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    Did you run ComboFix without that cfscript? It's important that you don't use the script but run normally by double-clicking ComboFix.exe file.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #33
    Member
    Join Date
    Apr 2009
    Posts
    57

    Default

    Yes - did not use the script... just double clicked the icon.

  4. #34
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Well, run ComboFix again and try to write down item names seen there during the run.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  5. #35
    Member
    Join Date
    Apr 2009
    Posts
    57

    Default Combofix Log - FINALLY!!

    Ran ComboFix - did not get any indication of deleted files.
    Got Stop Error
    Restored
    Ran ComboFix - did not get any indication of deleted files.
    Got Stop Error
    Rebooted and chose last know settings during bootprocess.
    Successfully booted into Windows. Here is the ComboFix log

    ComboFix 09-05-14.03 - David Wilson 05/14/2009 22:42.1 - FAT32x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1135 [GMT -4:00]
    Running from: c:\documents and settings\David Wilson\Desktop\ComboFix.exe
    AV: avast! antivirus 4.8.1335 [VPS 090514-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    ---- Previous Run -------
    .
    C:\diskfile1
    C:\logicinf.bin
    c:\windows\system32\bnrfil.dll
    c:\windows\system32\bsnlst.dll
    c:\windows\system32\co32andlo.dat
    c:\windows\system32\cocoerrfo.dat
    c:\windows\system32\dllto32to.dat
    c:\windows\system32\gapiyshe.dat
    c:\windows\system32\igefil.dll
    c:\windows\system32\lastupdate.dll
    c:\windows\system32\macfil.dll
    c:\windows\system32\nfil.dll
    c:\windows\system32\orptofo.dat
    c:\windows\system32\picsfil.dll
    c:\windows\system32\snetfil.dll
    c:\windows\system32\srchfrgn.dll
    c:\windows\system32\srchout.dll
    c:\windows\system32\unicodem.exe
    c:\windows\system32\usrgfil.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_DCDISK
    -------\Service_DCDisk
    -------\Service_dcsnap
    -------\Service_efbDisk
    -------\Legacy_DCDISK
    -------\Legacy_IPRIP
    -------\Service_DCDisk
    -------\Service_dcsnap
    -------\Service_efbDisk
    -------\Service_Iprip
    -------\Legacy_DCDISK
    -------\Legacy_IDSVCSPTISRV
    -------\Legacy_IPRIP
    -------\Service_DCDisk
    -------\Service_dcsnap
    -------\Service_efbDisk
    -------\Service_idsvcSPTISRV
    -------\Service_Iprip
    -------\Legacy_DCDISK
    -------\Legacy_IDSVCSPTISRV
    -------\Legacy_IPRIP
    -------\Service_DCDisk
    -------\Service_dcsnap
    -------\Service_efbDisk
    -------\Service_idsvcSPTISRV
    -------\Service_Iprip
    -------\Legacy_DCDISK
    -------\Legacy_IDSVCSPTISRV
    -------\Legacy_IPRIP
    -------\Service_DCDisk
    -------\Service_dcsnap
    -------\Service_efbDisk
    -------\Service_idsvcSPTISRV
    -------\Service_Iprip


    ((((((((((((((((((((((((( Files Created from 2009-04-15 to 2009-05-15 )))))))))))))))))))))))))))))))
    .

    2009-05-15 02:06 . 2009-05-15 02:06 -------- d-----w c:\documents and settings\David Wilson\Local Settings\Application Data\PCHealth
    2009-05-13 11:50 . 2009-05-13 11:50 -------- d-sh--w C:\FOUND.043
    2009-05-08 15:01 . 2009-05-08 15:01 0 --s-a-w c:\windows\system32\148114617.dat
    2009-05-08 02:11 . 2009-05-08 02:11 -------- d-----w c:\program files\Microsoft Money Plus
    2009-05-06 04:10 . 2009-05-06 04:10 -------- d-----w c:\program files\Alwil Software
    2009-05-06 04:03 . 2009-05-06 04:03 147100 ---ha-w c:\windows\system32\mlfcache.dat
    2009-05-06 02:38 . 2009-05-06 02:38 410984 ----a-w c:\windows\system32\deploytk.dll
    2009-05-06 02:11 . 2009-05-06 02:11 2709 ----a-w c:\windows\system32\gibbebx.dat
    2009-05-06 02:10 . 2009-05-15 03:07 15360 ---h--w C:\logicinf.bin
    2009-05-06 01:53 . 2009-05-06 01:53 2709 ----a-w c:\windows\system32\dllgidoor.dat
    2009-04-20 23:43 . 2009-04-20 23:43 -------- d-----w C:\rsit
    2009-04-19 22:34 . 2009-04-19 22:29 360021 ----a-w C:\something.scr
    2009-04-18 18:49 . 2009-04-18 18:49 -------- d-----w c:\program files\ERUNT
    2009-04-18 14:09 . 2009-04-18 14:09 -------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
    2009-04-18 04:21 . 2009-04-18 04:21 -------- d-----w c:\program files\Spybot - Search & Destroy
    2009-04-18 04:21 . 2009-04-18 04:21 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w c:\documents and settings\David Wilson\Application Data\Malwarebytes
    2009-04-18 01:04 . 2009-04-06 19:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
    2009-04-18 01:04 . 2009-04-06 19:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
    2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
    2009-04-17 12:22 . 2009-04-17 12:22 -------- d-----w C:\!KillBox
    2009-04-17 01:53 . 2009-04-17 01:53 184304 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-04-17 01:42 . 2009-04-17 01:42 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Seven Zip
    2009-04-17 01:28 . 2009-04-17 01:28 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
    2009-04-17 01:28 . 2009-04-17 01:28 -------- d-----w c:\documents and settings\Administrator\Application Data\Apple Computer
    2009-04-17 01:19 . 2009-04-17 01:19 -------- d-----w c:\documents and settings\Guest\Local Settings\Application Data\Seven Zip
    2009-04-17 01:18 . 2009-04-17 01:18 -------- d-----w c:\documents and settings\Guest\Application Data\Apple Computer
    2009-04-17 01:18 . 2009-04-17 01:18 -------- d-----w c:\documents and settings\Guest\Local Settings\Application Data\Mozilla
    2009-04-17 01:00 . 2009-04-17 01:00 -------- d-----w c:\documents and settings\All Users\Application Data\{A21E413E-98CC-4ABB-9843-E6AA4F456F61}
    2009-04-17 00:59 . 2009-04-17 00:59 -------- d-----w c:\documents and settings\David Wilson\Local Settings\Application Data\Seven Zip

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-05-06 02:27 . 2009-05-06 02:27 0 ----a-w c:\windows\system32\REN33.tmp
    2009-05-06 02:27 . 2009-05-06 02:27 0 ----a-w c:\windows\system32\REN32.tmp
    2009-05-06 01:54 . 2002-08-14 03:28 39 ----a-w c:\windows\liccyval.dat
    2009-04-22 23:05 . 2003-09-27 00:07 1222 ----a-w c:\windows\system32\usrfil.dll
    2009-04-22 23:04 . 2002-08-14 03:28 5880 ----a-w c:\windows\system32\wfileu.drv
    2009-04-14 13:40 . 2009-04-14 13:40 -------- d-----w c:\program files\Trend Micro
    2009-04-14 01:09 . 2009-04-14 01:09 -------- d-----w c:\program files\AVG
    2001-11-06 04:23 . 2000-05-13 03:43 266 --sh--w c:\program files\desktop.ini
    2001-11-06 04:23 . 2000-05-13 03:43 11079 ---h--w c:\program files\folder.htt
    2001-01-19 16:04 . 2005-02-06 20:12 21841 ----a-w c:\program files\Common Files\tppupd2k.dll
    2001-01-19 15:04 . 2002-02-24 01:38 21329 ------w c:\program files\Common Files\tppupd98.dll
    2007-10-09 05:33 . 2005-04-28 02:53 66408 ----a-w c:\program files\mozilla firefox\components\jar50.dll
    2007-10-09 05:33 . 2005-04-28 02:53 54112 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
    2007-10-09 05:33 . 2007-10-20 14:31 34688 ----a-w c:\program files\mozilla firefox\components\myspell.dll
    2007-10-09 05:33 . 2007-10-20 14:31 46456 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
    2007-10-09 05:33 . 2005-04-28 02:53 171880 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
    2001-11-13 14:18 . 2001-11-13 14:18 8 --sh--w c:\windows\All Users\DRM\pdrm.dat
    2008-05-19 02:07 . 2008-05-19 02:07 0 --sha-w c:\windows\All Users\DRM\Cache\Indiv02.tmp
    .

    ------- Sigcheck -------

    [-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\SYSTEM32\DRIVERS\tcpip.sys
    [-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\SYSTEM32\dllcache\tcpip.sys
    [-] 2008-04-13 19:20 361344 ACCF5A9A1FFAA490F33DBA1C632B95E1 c:\windows\ServicePackFiles\i386\tcpip.sys
    [-] 2005-05-25 19:07 359936 63FDFEA54EB53DE2D863EE454937CE1E c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
    [-] 2006-01-13 16:07 360448 5562CC0A47B2AEF06D3417B733F3C195 c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
    [-] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
    [-] 2007-10-30 15:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
    [7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
    [7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
    [7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
    [7] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\$NtServicePackUninstall$\tcpip.sys
    [7] 2004-08-04 06:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB893066$\tcpip.sys
    [-] 2005-05-25 19:04 359808 88763A98A4C26C409741B4AA162720C9 c:\windows\$NtUninstallKB913446$\tcpip.sys
    [-] 2006-01-13 01:28 359808 583E063FDC888CA30D05C2724B0D7EF4 c:\windows\$NtUninstallKB917953$\tcpip.sys
    [-] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:\windows\$NtUninstallKB941644$\tcpip.sys
    [-] 2007-10-30 16:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
    [7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "LDM"="\Program\BackWeb-8876480.exe" [BU]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "PRISMSVR.EXE"="c:\windows\system32\PRISMSVR.EXE" [2004-04-13 290905]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-14 7700480]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-14 86016]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
    "ezShieldProtector for Px"="c:\windows\system32\ezSP_Px.exe" [2002-08-20 40960]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-06 148888]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
    "SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2009-01-26 5365592]
    "nwiz"="nwiz.exe" - c:\windows\SYSTEM32\nwiz.exe [2007-02-14 1622016]

    c:\documents and settings\David Wilson\Start Menu\Programs\Startup\
    TrayDay.lnk - c:\program files\TrayDay\TrayDay.exe [2003-12-6 204800]
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoFavoritesMenu"= 1 (0x1)

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
    "NoFavoritesMenu"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
    @=""

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorelCENTRAL 10.lnk]
    backup=c:\windows\pss\CorelCENTRAL 10.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^FastCheck Monitoring Utility.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\FastCheck Monitoring Utility.lnk
    backup=c:\windows\pss\FastCheck Monitoring Utility.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
    backup=c:\windows\pss\Sonic CinePlayer Quick Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^David Wilson^Start Menu^Programs^Startup^Dialog Box Assistant.lnk]
    path=c:\documents and settings\David Wilson\Start Menu\Programs\Startup\Dialog Box Assistant.lnk
    backup=c:\windows\pss\Dialog Box Assistant.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^David Wilson^Start Menu^Programs^Startup^Webshots.lnk]
    backup=c:\windows\pss\Webshots.lnkStartup
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "LDM"=\Program\BackWeb-8876480.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "C2K"=c:\windows\cyb2k.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
    "EnsoniqMixer"=starter.exe
    "AtiPTA"=Atiptaxx.exe
    "AtiCwd32"=Aticwd32.exe
    "AtiQiPcl"=AtiQiPcl.exe
    "POINTER"=point32.exe
    "LoadQM"=loadqm.exe
    "LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    "QuickTime Task"=e:\program files\QuickTime\qttask.exe
    "MMTray"=d:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Common Files\\Doppler 10 Pinpoint Alert\\TrueWeather.exe"=
    "c:\\WINDOWS\\System32\\mmc.exe"=
    "c:\\Program Files\\RealVNC\\VNC4\\vncviewer.exe"=
    "f:\\Program Files\\Opera\\Opera.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\EA Games\\Command and Conquer Generals\\patchget.dat"=
    "c:\\WINDOWS\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
    "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVRegistrationService.exe"=
    "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVLibraryService.exe"=
    "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVNetworkService.exe"=
    "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVRecordingEngine.exe"=
    "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVGuideDataLoader.exe"=
    "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVSettingsService.exe"=
    "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVTaskManagerService.exe"=
    "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVD3DShell.exe"=
    "c:\\Program Files\\SnapStream Media\\Beyond TV\\SetupWizard.exe"=
    "c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVWebServiceProxy.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

    R0 amdagp10;AMD IG AGP Bus Filter;c:\windows\SYSTEM32\DRIVERS\amdagp10.sys [3/25/2003 11:19 PM 22994]
    R0 fasttrak;fasttrak;c:\windows\SYSTEM32\DRIVERS\Fasttrak.sys [1/14/2005 11:33 PM 70656]
    R1 aswSP;avast! Self Protection;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [5/6/2009 12:10 AM 114768]
    R1 GhPciScan;GhostPciScanner;c:\program files\Symantec\Norton Ghost 2003\GhPciScan.sys [12/17/2003 3:41 PM 5632]
    R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [5/6/2009 12:10 AM 20560]
    R2 NsService;NovaStor NovaBACKUP Backup/Copy Engine;c:\program files\NovaStor\NovaStor NovaBACKUP\NsService.exe [6/17/2008 4:56 PM 207936]
    R2 Real time Backup Loader;Real time Backup Loader;c:\program files\NovaStor\NovaStor NovaBACKUP\DR\FsLoader.exe [10/11/2008 1:52 PM 93248]
    R3 4mmdat;4mmdat;c:\windows\SYSTEM32\DRIVERS\4mmdat.sys [8/17/2001 1:52 PM 12288]
    S2 Backup Scheduler;Backup Scheduler;c:\program files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe [10/11/2008 1:52 PM 98304]
    S3 ati2mpaa;ati2mpaa;c:\windows\SYSTEM32\DRIVERS\ati2mpaa.sys [3/23/2002 9:50 AM 281856]
    S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);c:\windows\SYSTEM32\DRIVERS\atirtcap.sys [3/23/2002 9:51 AM 49920]
    S3 DDCCI;DDC/CI monitor;c:\windows\SYSTEM32\DRIVERS\Moni2c.sys [3/30/2003 12:19 PM 6494]
    S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [10/4/2008 3:20 PM 33752]
    S3 zremote;zremote;c:\windows\SYSTEM32\DRIVERS\zremote.sys [5/22/2005 1:27 PM 10368]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
    \Shell\AutoRun\command - H:\LaunchU3.exe -a

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}]
    \Shell\AutoRun\command - H:\LaunchU3.exe -a
    .
    Contents of the 'Scheduled Tasks' folder

    2009-05-08 c:\windows\Tasks\Uninstall Expiration Reminder.job
    - c:\windows\System32\OOBE\oobebaln.exe [2003-01-09 00:12]

    2009-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 16:34]
    .
    - - - - ORPHANS REMOVED - - - -

    ShellIconOverlayIdentifiers-{7D688A77-C613-11D0-999B-00C04FD655E1} - (no file)
    ShellExecuteHooks-{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - e:\program files\EUDORA\EUSHLEXT.DLL
    Notify-avgrsstarter - (no file)


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://my.yahoo.com/
    IE: Download with GetRight
    IE: E&xport to Microsoft Excel
    IE: Open with GetRight Browser
    DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab
    DPF: Internet Explorer Classes for Java - file://c:\windows\SYSTEM\iejava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} - hxxp://www.live365.com/players/p365vip.cab
    DPF: {5197842F-0557-48AE-9552-7594F7C98F04} - hxxp://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
    FF - ProfilePath - c:\documents and settings\David Wilson\Application Data\Mozilla\Firefox\Profiles\5nzx41m4.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-05-14 23:12
    Windows 5.1.2600 Service Pack 3 FAT NTAPI

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
    "ImagePath"="\"\""
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\$$$\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)

    [HKEY_USERS\$$$\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E8066BAB-BCF1-46CA-D8AA-605D8DE00F6D}*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{210BD7C7-47ED-BBE9-95D0F9FAA3BD0E97}\{C5D4C247-F1D1-D183-A63FC2DFAAC29AA3}\{B55B3474-A2E6-F6F7-4AD088E6434601A2}*]
    "KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
    7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{945169D7-C27E-315B-97A3E6913A1C7622}\{06C63AB7-5C18-FA8E-E5D32118C99A5B59}\{F7BD6AFF-A45B-6FB8-BB91AB79C0A3DA53}*]
    "KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
    7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A73A7B6D-D5C7-2D01-6A3ED58A203D5FEA}\{958FE6C0-B367-4AD6-C310294BFC5DB709}\{E2E9EAF6-387C-4947-07B2C800F4ACC9F3}*]
    "KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
    7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BF11F383-757D-CF48-6D213AC2BB6130AD}\{12507465-D6D8-AFB1-97ED5D21195D77D5}\{90E47118-DD98-E716-1AABCD138C042D55}*]
    "KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
    7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F2F43379-985D-E7AE-2F5BD6B18999A07F}\{64C9A7C2-676E-3AEC-13AF6B278F65FD89}\{7B815B3C-162E-096A-EBEBEFD33B1AE416}*]
    "KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
    7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(1268)
    c:\windows\system32\nview.dll
    c:\windows\system32\nvwddi.dll
    c:\program files\Windows Media Player\wmpband.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\Shellex.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Alwil Software\Avast4\aswUpdSv.exe
    c:\program files\Alwil Software\Avast4\ashServ.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
    c:\program files\Promise\FastTrak\FtrakSvc.exe
    c:\program files\Symantec\Norton Ghost 2003\GhostStartService.exe
    c:\progra~1\Iomega\System32\AppServices.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Common Files\LightScribe\LSSrvc.exe
    c:\windows\system32\nvsvc32.exe
    c:\windows\System32\tcpsvcs.exe
    c:\windows\System32\snmp.exe
    c:\program files\Iomega\AutoDisk\ADService.exe
    c:\program files\Internet Explorer\IEXPLORE.EXE
    c:\program files\iPod\bin\iPodService.exe
    c:\windows\system32\rundll32.exe
    c:\program files\2Wire 802.11g Wireless\PRISMCFG.exe
    .
    **************************************************************************
    .
    Completion time: 2009-05-15 23:15 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-05-15 03:15
    ComboFix2.txt 2009-04-22 23:01

    Pre-Run: 32,170,213,376 bytes free
    Post-Run: 32,158,941,184 bytes free

    Current=1 Default=1 Failed=3 LastKnownGood=4 Sets=1,2,3,4
    337 --- E O F --- 2009-03-15 07:03

  6. #36
    Member
    Join Date
    Apr 2009
    Posts
    57

    Default Dds.txt

    DDS (Ver_09-03-16.01) - FAT32x86
    Run by David Wilson at 23:18:43.62 on Thu 05/14/2009
    Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1095 [GMT -4:00]

    AV: avast! antivirus 4.8.1335 [VPS 090514-0] *On-access scanning disabled* (Updated)

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
    C:\Program Files\Promise\FastTrak\FtrakSvc.exe
    C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\WINDOWS\System32\snmp.exe
    C:\Program Files\Iomega\AutoDisk\ADService.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\PRISMSVR.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
    C:\Program Files\TrayDay\TrayDay.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\David Wilson\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://my.yahoo.com/
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: bho2gr Class: {31ff080d-12a3-439a-a2ef-4ba95a3148e8} - e:\program files\getright\xx2gr.dll
    BHO: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - __BHODemonDisabled
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} -
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    TB: Plaxo: {81ca3009-6200-4a6d-93c6-f1e9a6821c7f} -
    TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
    TB: {06E58E5E-F8CB-4049-991E-A41C03BD419E} - No File
    EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [LDM] \Program\BackWeb-8876480.exe
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [PRISMSVR.EXE] "c:\windows\system32\PRISMSVR.EXE" /APPLY
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [nwiz] nwiz.exe /install
    mRun: [ezShieldProtector for Px] c:\windows\system32\ezSP_Px.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
    mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe"
    StartupFolder: c:\docume~1\davidw~1\startm~1\programs\startup\trayday.lnk - c:\program files\trayday\TrayDay.exe
    StartupFolder: c:\docume~1\davidw~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - e:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\2wirew~1.lnk - c:\program files\2wire 802.11g wireless\PRISMCFG.exe
    uPolicies-explorer: NoFavoritesMenu = 1 (0x1)
    dPolicies-explorer: NoFavoritesMenu = 1 (0x1)
    IE: Download with GetRight
    IE: E&xport to Microsoft Excel
    IE: Open with GetRight Browser
    IE: {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - c:\program files\hello\PicasaCapture.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: DirectAnimation Java Classes - file://c:\windows\system\dajava.cab
    DPF: Internet Explorer Classes for Java - file://c:\windows\system\iejava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: Yahoo! Checkers - hxxp://download.games.yahoo.com/games/clients/y/kt0_x.cab
    DPF: Yahoo! Chess - hxxp://download.yahoo.com/games/clients/y/cr1_x.cab
    DPF: Yahoo! Hearts - hxxp://download.yahoo.com/games/clients/y/hr1_x.cab
    DPF: Yahoo! Pool 2 - hxxp://download.yahoo.com/games/clients/y/por9_x.cab
    DPF: {00000075-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/voxmsdec.CAB
    DPF: {00000160-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab
    DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
    DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab
    DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
    DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
    DPF: {31564D57-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmvax.cab
    DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} - hxxp://www.live365.com/players/p365vip.cab
    DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
    DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} - hxxps://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
    DPF: {5197842F-0557-48AE-9552-7594F7C98F04} - hxxp://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
    DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - hxxp://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
    DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} - hxxp://entimg.msn.com/client/msnediag3518.cab
    DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} - hxxp://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab
    DPF: {94B82441-A413-4E43-8422-D49930E69764} - hxxp://rtc.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
    DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38079.8121527778
    DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - hxxp://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab
    DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} - hxxps://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
    DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
    DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://support.f-secure.com/ols/fscax.cab
    DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
    DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} - hxxp://www.live365.com/players/play365.cab
    DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} - hxxp://windowsupdate.microsoft.com/R848/V31Controls/x86/w98/en/actsetup.cab
    DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - hxxp://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
    DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - hxxp://entimg.msn.com/client/msnmusax3518.cab
    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\davidw~1\applic~1\mozilla\firefox\profiles\5nzx41m4.default\
    FF - prefs.js: browser.search.selectedEngine - Google

    ============= SERVICES / DRIVERS ===============

    R0 amdagp10;AMD IG AGP Bus Filter;c:\windows\system32\drivers\amdagp10.sys [2003-3-25 22994]
    R0 fasttrak;fasttrak;c:\windows\system32\drivers\Fasttrak.sys [2005-1-14 70656]
    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-5-6 114768]
    R1 Cinemsup;Cinemsup;c:\windows\system32\drivers\cinemsup.sys [2002-7-19 6656]
    R1 GhPciScan;GhostPciScanner;c:\program files\symantec\norton ghost 2003\GhPciScan.sys [2003-12-17 5632]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-6 20560]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-5-6 138680]
    R2 NsService;NovaStor NovaBACKUP Backup/Copy Engine;c:\program files\novastor\novastor novabackup\NsService.exe [2008-6-17 207936]
    R2 Real time Backup Loader;Real time Backup Loader;c:\program files\novastor\novastor novabackup\dr\FsLoader.exe [2008-10-11 93248]
    R3 4mmdat;4mmdat;c:\windows\system32\drivers\4mmdat.sys [2001-8-17 12288]
    RUnknown DCDisk;DCDisk; [x]
    RUnknown dcsnap;dcsnap; [x]
    RUnknown Iprip;Iprip; [x]
    S2 Backup Scheduler;Backup Scheduler;c:\program files\novastor\novastor novabackup\dr\cbp\DCSchdlerSRVC.exe [2008-10-11 98304]
    S3 ati2mpaa;ati2mpaa;c:\windows\system32\drivers\ati2mpaa.sys [2002-3-23 281856]
    S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);c:\windows\system32\drivers\atirtcap.sys [2002-3-23 49920]
    S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-5-6 254040]
    S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-5-6 352920]
    S3 DDCCI;DDC/CI monitor;c:\windows\system32\drivers\Moni2c.sys [2003-3-30 6494]
    S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-10-4 33752]
    S3 hcwPVRP2;Hauppauge WinTV PVR PCI II (Encoder);c:\windows\system32\drivers\hcwPVRP2.sys [2005-5-22 814464]
    S3 zremote;zremote;c:\windows\system32\drivers\zremote.sys [2005-5-22 10368]
    SUnknown idsvcSPTISRV;idsvcSPTISRV; [x]
    UnknownUnknown efbDisk;efbDisk; [x]

    =============== Created Last 30 ================

    2009-05-13 07:50 <DIR> --dsh--- C:\FOUND.043
    2009-05-08 11:01 0 a--s---- c:\windows\system32\148114617.dat
    2009-05-07 22:11 <DIR> --d----- c:\program files\Microsoft Money Plus
    2009-05-06 00:03 147,100 a---h--- c:\windows\system32\mlfcache.dat
    2009-05-05 22:38 410,984 a------- c:\windows\system32\deploytk.dll
    2009-05-05 22:38 73,728 a------- c:\windows\system32\javacpl.cpl
    2009-05-05 22:27 0 a------- c:\windows\system32\REN33.tmp
    2009-05-05 22:27 0 a------- c:\windows\system32\REN32.tmp
    2009-05-05 22:11 2,709 a------- c:\windows\system32\gibbebx.dat
    2009-05-05 22:10 1,024 ----h--- C:\diskfile1
    2009-05-05 22:10 15,360 ----h--- C:\logicinf.bin
    2009-05-05 21:53 2,709 a------- c:\windows\system32\dllgidoor.dat
    2009-04-22 18:53 <DIR> a-dshr-- C:\cmdcons
    2009-04-22 18:52 161,792 a------- c:\windows\SWREG.exe
    2009-04-22 18:52 98,816 a------- c:\windows\sed.exe
    2009-04-19 18:34 360,021 a------- C:\something.scr
    2009-04-18 00:21 <DIR> --d----- c:\program files\Spybot - Search & Destroy
    2009-04-18 00:21 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
    2009-04-17 21:04 <DIR> --d----- c:\docume~1\davidw~1\applic~1\Malwarebytes
    2009-04-17 21:04 15,504 a------- c:\windows\system32\drivers\mbam.sys
    2009-04-17 21:04 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-04-17 21:04 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
    2009-04-17 21:04 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-04-17 19:53 66 a------- c:\windows\wininit.ini
    2009-04-17 08:22 <DIR> --d----- C:\!KillBox
    2009-04-16 21:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{A21E413E-98CC-4ABB-9843-E6AA4F456F61}

    ==================== Find3M ====================

    2009-04-22 19:04 5,880 a------- c:\windows\system32\wfileu.drv
    2008-12-16 19:23 726,008 a------- c:\documents and settings\david wilson\gotomypc_438.exe
    2008-11-06 12:33 726,008 a------- c:\documents and settings\david wilson\gotomypc_437.exe
    2001-11-06 00:23 266 ---sh--- c:\program files\desktop.ini
    2001-11-06 00:23 11,079 ----h--- c:\program files\folder.htt
    2001-01-19 12:04 21,841 a------- c:\program files\common files\tppupd2k.dll
    2001-01-19 11:04 21,329 -------- c:\program files\common files\tppupd98.dll
    2008-10-04 15:44 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100420081005\index.dat
    2001-11-13 10:18 8 ---sh--- c:\windows\all users\drm\pdrm.dat

    ============= FINISH: 23:19:14.06 ===============

  7. #37
    Member
    Join Date
    Apr 2009
    Posts
    57

    Default Symptom Update

    IEXPLORE.EXE still starts with OS. End Process turns it off and it stays off - but process iexplore.ex1 turns on and off continuously.

    Double click My Computer/double click a HD and the IEXPLORE.EXE process starts multiple times again. And if force quite, will start again.

    Script errors continue in IE... for example... if I choose Tools/Organize Favorites - I get an Internet Explorer Script Error... An error has occurred in the script on this page... but no detail in any of the Line/Char/Error/Code/URL fields. Choosing Yes or No has little effect as the box stays in place - clicking on the X in the RH corner about 30 times finally closes the dialog box.

  8. #38
    Member
    Join Date
    Apr 2009
    Posts
    57

    Default One more thing

    Avast just found a Trojan Horse - Win32:Delf-MBA -- but it's struggling to remove it.

    I also noticed after e-mailing last night that my computer is running Internet Explorer from c:/Program Files/Internet Explorer and NOT from c:/Windows/IE7. It's the first directory that has a file called iexplore.ex1. My task manager continues to have an ever expanding number of instances of iexplore.ex1 which start up and then shut down and then start up and then shut down.

  9. #39
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Avast just found a Trojan Horse - Win32:Delf-MBA -- but it's struggling to remove it.
    Where does Avast see the infection in?


    Let's uninstall IE7 for now.

    After that, please download OTListIt2
    Save it to the Desktop
    • Close all windows and double-click on the OTListIt2.exe file
    • OK any warning about running OTListIt.
    • Place a check in the Scan All Users checkbox
    • Click the Run Scan button
    • When the scan is complete, two text files are produced on the Desktop: OTListIt.txt , and Extras.txt

    Please post the OTListIt.txt and Extras.txt in your reply.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  10. #40
    Member
    Join Date
    Apr 2009
    Posts
    57

    Default avast! says

    Sign of "win32:Delf-MBA [Trj]" has been found in "C:\WINDOWS\MEMORY.DMP" file.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •