Page 1 of 3 123 LastLast
Results 1 to 10 of 22

Thread: Rootkit Win32.TDSS.ntf-unable to remove SKYNETXXX

  1. #1
    Junior Member
    Join Date
    Sep 2009
    Posts
    14

    Default

    Friends have a knack of breaking things the best..

    when I started his machine it would not run any executables including spybot/avg/SAV ETC..

    used reg file to fix (too long to list but can provide on request) worked great and then I was able to run standard av/spyware tools to clean. many infections removed except the one listed in the title.

    HJT log listed below:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:26:50 AM, on 9/15/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16876)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://83.149.75.33/info.png?cmp=fkf...mrk=1&ver=4057
    R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll (file missing)
    O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-21-1676360506-3534062470-2318509989-1014\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - https://a248.e.akamai.net/f/248/5462...l/SymDlBrg.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/tech...l/SymAData.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: karna.dat,zxovgf.dll,C:\WINDOWS\system32\sovagejo.dll bkviyj.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bomgar Jump Client [1235567581-1235567625] (bomgar-ps-1235567581-1235567625) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe (file missing)
    O23 - Service: Bomgar Jump Client [1236139268-1236139313] (bomgar-ps-1236139268-1236139313) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe (file missing)
    O23 - Service: Bomgar Jump Client [1236139268-1244144831] (bomgar-ps-1236139268-1244144831) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe (file missing)
    O23 - Service: Bomgar Support Customer Client [1235567581] (bomgar-scc-1235567581) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe (file missing)
    O23 - Service: Bomgar Support Customer Client [1236139268] (bomgar-scc-1236139268) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe (file missing)
    O23 - Service: dlbt_device - Dell - C:\WINDOWS\System32\dlbtcoms.exe
    O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe

    --
    End of file - 7488 bytes

    Spybot log listed below


    --- Report generated: 2009-09-15 07:48 ---

    Win32.TDSS.ntf: [SBI $C65DEAB2] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\drivers\SKYNEThoehbqlt.sys
    Properties.size=0
    Properties.md5=AFC2708D353D77D2AC94103D5730F160

    Win32.TDSS.ntf: [SBI $F7C6EF60] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETfumqskwp.dll
    Properties.size=0
    Properties.md5=5B4F59E220FA96D42363E8CAAC34D2D8

    Win32.TDSS.ntf: [SBI $F7C6EF60] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNEToptqxpbu.dll
    Properties.size=0
    Properties.md5=3B0585750AD0EEAA4583F4AFDF696713

    Win32.TDSS.ntf: [SBI $F7C6EF60] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETrjrxloyq.dll
    Properties.size=0
    Properties.md5=3B0585750AD0EEAA4583F4AFDF696713

    Win32.TDSS.ntf: [SBI $F7C6EF60] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETthtvpuyu.dll
    Properties.size=0
    Properties.md5=5B4F59E220FA96D42363E8CAAC34D2D8

    Win32.TDSS.ntf: [SBI $1A7ABF3C] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETqxnopatm.dat
    Properties.size=0
    Properties.md5=0B4FB4690EFA25C5CB5D25A2B291E7F8

    Win32.TDSS.ntf: [SBI $1A7ABF3C] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETrqpoqxyv.dat
    Properties.size=0
    Properties.md5=CEB5FB6784BD4FC72E47C643BAF9958F

    Win32.TDSS.ntf: [SBI $1A7ABF3C] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETxrvngfsx.dat
    Properties.size=0
    Properties.md5=EBA256D5218C6D6314B1B7382AE0C9D9


    --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

    2009-01-26 blindman.exe (1.0.0.8)
    2009-01-26 SDFiles.exe (1.6.1.7)
    2009-01-26 SDMain.exe (1.0.0.6)
    2009-01-26 SDUpdate.exe (1.6.0.12)
    2009-01-26 SpybotSD.exe (1.6.2.46)
    2009-03-05 TeaTimer.exe (1.6.6.32)
    2009-03-12 unins000.exe (51.49.0.0)
    2009-01-26 Update.exe (1.6.0.7)
    2009-07-28 advcheck.dll (1.6.3.17)
    2007-04-02 aports.dll (2.1.0.0)
    2008-06-14 DelZip179.dll (1.79.11.1)
    2009-01-26 SDHelper.dll (1.6.2.14)
    2008-06-19 sqlite3.dll
    2009-01-26 Tools.dll (2.1.6.10)
    2009-01-16 UninsSrv.dll (1.0.0.0)
    2009-05-19 Includes\Adware.sbi (*)
    2009-09-01 Includes\AdwareC.sbi (*)
    2009-01-22 Includes\Cookies.sbi (*)
    2009-05-19 Includes\Dialer.sbi (*)
    2009-09-01 Includes\DialerC.sbi (*)
    2009-01-22 Includes\HeavyDuty.sbi (*)
    2009-05-26 Includes\Hijackers.sbi (*)
    2009-09-01 Includes\HijackersC.sbi (*)
    2009-06-23 Includes\Keyloggers.sbi (*)
    2009-09-01 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2009-08-19 Includes\Malware.sbi (*)
    2009-09-01 Includes\MalwareC.sbi (*)
    2009-03-25 Includes\PUPS.sbi (*)
    2009-09-01 Includes\PUPSC.sbi (*)
    2009-01-22 Includes\Revision.sbi (*)
    2009-01-13 Includes\Security.sbi (*)
    2009-09-01 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2009-04-07 Includes\Spyware.sbi (*)
    2009-09-01 Includes\SpywareC.sbi (*)
    2009-06-08 Includes\Tracks.uti
    2009-08-25 Includes\Trojans.sbi (*)
    2009-09-01 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll

    Spybot and rootalyser are both able to detect it and allegedly remove them but they are detected on the next scan.

    system restore is turned off.
    manually ran msconfig and no files are executing that look suspicious (adobe aol etc)

    first round of scans before these scans posted include
    AVg version 8.5, MalewareBytes, Symantec AV, Spybot s&d, Rootanalyser.3.4.47

    ERUNT has been run and backup taken

    While I wait I am going to scan in safemode to see if that allows the utilities to delete the files.. any assistance is appreciated.

    Thanks,
    --------------------------
    re-ran all scans in safe mode no luck

    any recomendations?
    ============================

    Removed quoted logs

    "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance)
    Last edited by tashi; 2009-09-16 at 04:46. Reason: Merged two posts and provided link to FAQ, please don't add posts before a response :-)

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi jprendergast007

    We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
    This tool is not a toy and not for everyday use.
    ComboFix SHOULD NOT be used unless requested by a forum helper


    http://www.bleepingcomputer.com/comb...o-use-combofix

    Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    If you need help to disable your protection programs see here.

    When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member
    Join Date
    Sep 2009
    Posts
    14

    Default Combofix results

    I have been predisposed working for last 16 hrs, will be getting up in 8 to work on this, will post back then.

  4. #4
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Thank you for update
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #5
    Junior Member
    Join Date
    Sep 2009
    Posts
    14

    Default Combofix First log..

    ComboFix 09-09-18.02 - cyberport 09/19/2009 9:19.1.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2558.2109 [GMT -4:00]
    Running from: c:\drivers\Spybot\combofix\ComboFix.exe
    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\Mozilla Firefox\extensions\{C2A5066A-B7DC-4061-ACDD-A022DDFEFC59}
    c:\program files\Mozilla Firefox\extensions\{C2A5066A-B7DC-4061-ACDD-A022DDFEFC59}\chrome.manifest
    c:\program files\Mozilla Firefox\extensions\{C2A5066A-B7DC-4061-ACDD-A022DDFEFC59}\chrome\content\overlay.xul
    c:\program files\Mozilla Firefox\extensions\{C2A5066A-B7DC-4061-ACDD-A022DDFEFC59}\install.rdf
    c:\windows\Install.txt
    c:\windows\Installer\13400.msi
    c:\windows\Installer\13406.msi
    c:\windows\Installer\fcc231.msi
    c:\windows\run.log
    c:\windows\system32\drivers\SKYNEThoehbqlt.sys
    c:\windows\system32\drivers\Sonyhcp.dll
    c:\windows\system32\ezinuvak.ini
    c:\windows\system32\inf
    c:\windows\system32\ogenubaz.ini
    c:\windows\system32\Packet.dll
    c:\windows\system32\SKYNETftnvxebw.dat
    c:\windows\system32\SKYNETfumqskwp.dll
    c:\windows\system32\SKYNEToptqxpbu.dll
    c:\windows\system32\SKYNETqxnopatm.dat
    c:\windows\system32\SKYNETrjrxloyq.dll
    c:\windows\system32\SKYNETrqpoqxyv.dat
    c:\windows\system32\SKYNETthtvpuyu.dll
    c:\windows\system32\SKYNETxrvngfsx.dat
    c:\windows\system32\test.ttt
    c:\windows\system32\wpcap.dll
    c:\windows\system32\xcchit32.ini
    c:\windows\xccwinsys.ini

    Infected copy of c:\windows\SYSTEM32\winlogon.exe was found and disinfected
    Restored copy from - c:\windows\ServicePackFiles\i386\winlogon.exe

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_SKYNETspwmyciq
    -------\Legacy_SKYNETspwmyciq
    -------\Legacy_6TO4
    -------\Legacy_AFISICX
    -------\Legacy_DEFAULTLIB
    -------\Legacy_MABIDWE
    -------\Legacy_SOFTYINFORWOW1
    -------\Legacy_SOPIDKC
    -------\Service_6to4
    -------\Service_NPF


    ((((((((((((((((((((((((( Files Created from 2009-08-19 to 2009-09-19 )))))))))))))))))))))))))))))))
    .

    2009-09-15 12:24 . 2009-09-15 12:24 -------- d-----w- c:\program files\ERUNT
    2009-09-15 12:24 . 2009-09-15 12:24 -------- d-----w- C:\EruNTRegBackup
    2009-09-15 03:42 . 2009-09-15 03:42 -------- d-----w- c:\program files\Trend Micro
    2009-09-08 05:04 . 2009-09-15 03:47 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2009-09-08 04:44 . 2009-09-08 04:44 -------- d-----w- c:\program files\Enigma Software Group
    2009-09-08 03:02 . 2009-03-06 14:22 284160 ------w- c:\windows\system32\dllcache\pdh.dll
    2009-09-08 03:02 . 2009-02-09 12:10 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
    2009-09-08 03:02 . 2009-02-09 12:10 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
    2009-09-08 03:02 . 2009-02-06 11:11 110592 ------w- c:\windows\system32\dllcache\services.exe
    2009-09-08 03:02 . 2009-02-09 12:10 729088 ------w- c:\windows\system32\dllcache\lsasrv.dll
    2009-09-08 03:02 . 2009-02-09 12:10 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
    2009-09-08 03:02 . 2009-02-09 12:10 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
    2009-09-08 03:02 . 2009-02-09 12:10 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
    2009-09-08 03:02 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
    2009-09-08 03:01 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
    2009-09-08 03:00 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
    2009-09-08 03:00 . 2008-04-21 12:08 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
    2009-09-08 02:41 . 2009-09-08 02:41 -------- d-----w- c:\documents and settings\cyberport\Local Settings\Application Data\PCHealth
    2009-09-08 01:54 . 2009-09-08 01:54 -------- d-----w- c:\program files\Windows Defender
    2009-09-05 03:34 . 2009-09-08 03:33 -------- d-----w- C:\$AVG8.VAULT$
    2009-09-05 03:33 . 2009-09-05 03:33 -------- d-----w- c:\documents and settings\cyberport\Local Settings\Application Data\AVG Security Toolbar
    2009-09-05 03:30 . 2009-09-05 03:30 11952 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-09-05 03:30 . 2009-09-05 03:30 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-09-05 03:30 . 2009-09-05 03:30 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-09-05 03:30 . 2009-09-05 03:30 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-09-05 03:30 . 2009-09-08 03:17 -------- d-----w- c:\windows\system32\drivers\Avg
    2009-09-05 03:30 . 2009-09-08 01:49 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
    2009-09-05 03:13 . 2009-09-05 03:13 -------- d-----w- c:\documents and settings\cyberport\Local Settings\Application Data\Adobe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-09-19 13:26 . 2004-08-17 03:32 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000004-00000000-00000002-00001102-00000004-10031102}.dat
    2009-09-19 13:26 . 2004-08-17 03:32 288 ----a-w- c:\windows\system32\DVCState-{00000004-00000000-00000002-00001102-00000004-10031102}.dat
    2009-09-15 03:49 . 2004-08-17 03:31 -------- d-----w- c:\program files\Viewpoint
    2009-09-05 04:57 . 2008-10-26 01:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-09-05 03:30 . 2009-02-26 03:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Avg8
    2009-09-04 06:42 . 2005-10-02 06:24 -------- d-----w- c:\program files\Google
    2009-08-17 12:02 . 2008-10-26 00:46 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-08-05 09:01 . 2002-12-12 05:14 204800 ----a-w- c:\windows\system32\mswebdvd.dll
    2009-08-03 17:36 . 2008-10-26 01:45 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-08-03 17:36 . 2008-10-26 01:45 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-07-29 04:37 . 2004-03-19 22:43 119808 ----a-w- c:\windows\system32\t2embed.dll
    2009-07-29 04:37 . 2004-03-19 22:37 81920 ----a-w- c:\windows\system32\fontsub.dll
    2009-07-25 15:53 . 2009-07-25 15:32 -------- d-----w- c:\documents and settings\Nick Mattessich\Application Data\Costco Photo Organizer
    2009-07-25 15:42 . 2009-07-25 15:25 -------- d-----w- c:\documents and settings\Nick Mattessich\Application Data\Costco Photo Viewer US
    2009-07-25 15:31 . 2009-07-25 15:31 -------- d-----w- c:\program files\Common Files\HP
    2009-07-25 15:31 . 2009-07-25 15:31 -------- d-----w- c:\program files\Costco
    2009-07-18 18:40 . 2009-07-18 18:40 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
    2009-07-17 19:01 . 2004-03-19 22:33 58880 ----a-w- c:\windows\system32\atl.dll
    2009-07-14 03:43 . 2004-09-22 23:46 286208 ----a-w- c:\windows\system32\wmpdxm.dll
    2009-07-09 01:37 . 2009-07-09 01:37 552 ----a-w- c:\windows\system32\d3d8caps.dat
    2009-06-29 16:12 . 2004-08-24 00:32 827392 ----a-w- c:\windows\system32\wininet.dll
    2009-06-29 16:12 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-06-29 16:12 . 2004-03-19 22:34 17408 ----a-w- c:\windows\system32\corpol.dll
    .

    ------- Sigcheck -------


    [-] 2008-10-14 . 63999D0ABD8DABFD76A9C07F6E104868 . 295424 . . [5.1.2600.5512] . . c:\windows\SYSTEM32\termsrv.dll
    [7] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll
    [7] 2004-08-04 . B60C877D16D9C880B952FDA04ADF16E6 . 295424 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\termsrv.dll

    c:\windows\system32\drivers\beep.sys ... is missing !!
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

    [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
    2009-07-24 13:55 1090816 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

    [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

    [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-26 335872]
    "CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
    "CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-05 2007832]
    "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-08-03 419088]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
    "NoSetActiveDesktop"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-09-05 03:30 11952 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
    backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "afisicx"=2 (0x2)
    "AntipPro2009_12"=2 (0x2)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\1156698762\\ee\\AOLServiceHost.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AIM6\\aim6.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
    "%windir%\\system32\\drivers\\svchost.exe"=

    R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [3/11/2009 7:52 AM 64160]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [9/4/2009 11:30 PM 335240]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [9/4/2009 11:30 PM 108552]
    S0 ydrihvqy;ydrihvqy;c:\windows\SYSTEM32\DRIVERS\xkphewda.sys []
    S2 bomgar-ps-1235567581-1235567625;Bomgar Jump Client [1235567581-1235567625];"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe" -pinned elevated --> c:\documents and settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe [?]
    S2 bomgar-ps-1236139268-1236139313;Bomgar Jump Client [1236139268-1236139313];"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe" -pinned elevated --> c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe [?]
    S2 bomgar-ps-1236139268-1244144831;Bomgar Jump Client [1236139268-1244144831];"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe" -pinned elevated --> c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe [?]
    S2 bomgar-scc-1235567581;Bomgar Support Customer Client [1235567581];"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe" -service:run --> c:\documents and settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe [?]
    S2 bomgar-scc-1236139268;Bomgar Support Customer Client [1236139268];"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe" -service:run --> c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe [?]
    S3 jnv4_mib;jnv4_mib;\??\c:\docume~1\ERICMA~1\LOCALS~1\Temp\jnv4_mib.sys --> c:\docume~1\ERICMA~1\LOCALS~1\Temp\jnv4_mib.sys [?]
    S3 MBAMProtector;MBAMProtector;c:\windows\SYSTEM32\DRIVERS\mbam.sys [10/25/2008 9:45 PM 19096]
    S4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/4/2009 11:30 PM 297752]
    S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/25/2008 9:45 PM 232720]
    S4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-04-06 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]

    2009-07-09 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Nick Mattessich.job
    - c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2008-10-26 17:36]

    2009-07-09 c:\windows\Tasks\Malwarebytes' Scheduled Update for Nick Mattessich.job
    - c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2008-10-26 17:36]

    2009-09-19 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    mStart Page = hxxp://www.google.com
    uInternet Connection Wizard,ShellNext = hxxp://83.149.75.33/info.png?cmp=fkfrt&rid=m20001&affid=178471&mid=lg20&revid=11129&uid=b7d9ef1013f311deafa2178471ffffff&guid=03b19c7c8dd2df439d53b6a8acdae993&mrk=1&ver=4057
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    FF - ProfilePath - c:\documents and settings\cyberport\Application Data\Mozilla\Firefox\Profiles\zrp13z8i.default\
    FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
    FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
    FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
    FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
    FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
    FF - HiddenExtension: XUL Cache: {6BCCB36F-6102-411C-A304-018F2A2EDBB0} - c:\documents and settings\Eric Mattessich\Local Settings\Application Data\{6BCCB36F-6102-411C-A304-018F2A2EDBB0}
    FF - HiddenExtension: XUL Cache: {16ADC5ED-FB9B-4C90-B2AA-73DCB0D81A67} - c:\documents and settings\Christina Mattessich\Local Settings\Application Data\{16ADC5ED-FB9B-4C90-B2AA-73DCB0D81A67}
    FF - HiddenExtension: XUL Cache: {B559E360-0D9B-45B0-9A1C-27A708056906} - c:\documents and settings\Mary Ann Mattessich\Local Settings\Application Data\{B559E360-0D9B-45B0-9A1C-27A708056906}
    FF - HiddenExtension: XUL Cache: {A2BECE79-462E-4C26-8D03-CD3645A77C04} - c:\documents and settings\Nick Mattessich\Local Settings\Application Data\{A2BECE79-462E-4C26-8D03-CD3645A77C04}
    .
    .
    ------- File Associations -------
    .
    txtfile=%windir%\NOTEPAD.EXE %1
    .
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-09-19 09:28
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...


    c:\windows\system32\drivers\xkphewda.sys 25088 bytes executable

    scan completed successfully
    hidden files: 1

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bomgar-scc-1235567581]
    "ImagePath"="\"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe\" -service:run"

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bomgar-scc-1236139268]
    "ImagePath"="\"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe\" -service:run"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(4072)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    c:\program files\Malwarebytes' Anti-Malware\mbamext.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
    c:\progra~1\SPYBOT~1\SDHelper.dll
    c:\program files\Microsoft Office\OFFICE11\msohev.dll
    c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\SYSTEM32\ati2evxx.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Intel\Intel Application Accelerator\IAANTmon.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
    c:\windows\SYSTEM32\MsPMSPSv.exe
    c:\windows\SYSTEM32\wscntfy.exe
    .
    **************************************************************************
    .
    Completion time: 2009-09-19 9:31 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-09-19 13:31

    Pre-Run: 112,983,887,872 bytes free
    Post-Run: 114,197,118,976 bytes free

    272 --- E O F --- 2009-09-19 09:27

    system seems to be running fine, I am going to scan with spybot and av to check if it is infected..

    Thanks for your help in advance..


    Quote Originally Posted by jprendergast007 View Post
    Friends have a knack of breaking things the best..

    when I started his machine it would not run any executables including spybot/avg/SAV ETC..

    used reg file to fix (too long to list but can provide on request) worked great and then I was able to run standard av/spyware tools to clean. many infections removed except the one listed in the title.

    HJT log listed below:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:26:50 AM, on 9/15/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16876)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://83.149.75.33/info.png?cmp=fkf...mrk=1&ver=4057
    R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll (file missing)
    O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-21-1676360506-3534062470-2318509989-1014\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - https://a248.e.akamai.net/f/248/5462...l/SymDlBrg.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/tech...l/SymAData.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: karna.dat,zxovgf.dll,C:\WINDOWS\system32\sovagejo.dll bkviyj.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bomgar Jump Client [1235567581-1235567625] (bomgar-ps-1235567581-1235567625) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe (file missing)
    O23 - Service: Bomgar Jump Client [1236139268-1236139313] (bomgar-ps-1236139268-1236139313) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe (file missing)
    O23 - Service: Bomgar Jump Client [1236139268-1244144831] (bomgar-ps-1236139268-1244144831) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe (file missing)
    O23 - Service: Bomgar Support Customer Client [1235567581] (bomgar-scc-1235567581) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe (file missing)
    O23 - Service: Bomgar Support Customer Client [1236139268] (bomgar-scc-1236139268) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe (file missing)
    O23 - Service: dlbt_device - Dell - C:\WINDOWS\System32\dlbtcoms.exe
    O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe

    --
    End of file - 7488 bytes

    Spybot log listed below


    --- Report generated: 2009-09-15 07:48 ---

    Win32.TDSS.ntf: [SBI $C65DEAB2] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\drivers\SKYNEThoehbqlt.sys
    Properties.size=0
    Properties.md5=AFC2708D353D77D2AC94103D5730F160

    Win32.TDSS.ntf: [SBI $F7C6EF60] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETfumqskwp.dll
    Properties.size=0
    Properties.md5=5B4F59E220FA96D42363E8CAAC34D2D8

    Win32.TDSS.ntf: [SBI $F7C6EF60] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNEToptqxpbu.dll
    Properties.size=0
    Properties.md5=3B0585750AD0EEAA4583F4AFDF696713

    Win32.TDSS.ntf: [SBI $F7C6EF60] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETrjrxloyq.dll
    Properties.size=0
    Properties.md5=3B0585750AD0EEAA4583F4AFDF696713

    Win32.TDSS.ntf: [SBI $F7C6EF60] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETthtvpuyu.dll
    Properties.size=0
    Properties.md5=5B4F59E220FA96D42363E8CAAC34D2D8

    Win32.TDSS.ntf: [SBI $1A7ABF3C] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETqxnopatm.dat
    Properties.size=0
    Properties.md5=0B4FB4690EFA25C5CB5D25A2B291E7F8

    Win32.TDSS.ntf: [SBI $1A7ABF3C] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETrqpoqxyv.dat
    Properties.size=0
    Properties.md5=CEB5FB6784BD4FC72E47C643BAF9958F

    Win32.TDSS.ntf: [SBI $1A7ABF3C] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETxrvngfsx.dat
    Properties.size=0
    Properties.md5=EBA256D5218C6D6314B1B7382AE0C9D9


    --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

    2009-01-26 blindman.exe (1.0.0.8)
    2009-01-26 SDFiles.exe (1.6.1.7)
    2009-01-26 SDMain.exe (1.0.0.6)
    2009-01-26 SDUpdate.exe (1.6.0.12)
    2009-01-26 SpybotSD.exe (1.6.2.46)
    2009-03-05 TeaTimer.exe (1.6.6.32)
    2009-03-12 unins000.exe (51.49.0.0)
    2009-01-26 Update.exe (1.6.0.7)
    2009-07-28 advcheck.dll (1.6.3.17)
    2007-04-02 aports.dll (2.1.0.0)
    2008-06-14 DelZip179.dll (1.79.11.1)
    2009-01-26 SDHelper.dll (1.6.2.14)
    2008-06-19 sqlite3.dll
    2009-01-26 Tools.dll (2.1.6.10)
    2009-01-16 UninsSrv.dll (1.0.0.0)
    2009-05-19 Includes\Adware.sbi (*)
    2009-09-01 Includes\AdwareC.sbi (*)
    2009-01-22 Includes\Cookies.sbi (*)
    2009-05-19 Includes\Dialer.sbi (*)
    2009-09-01 Includes\DialerC.sbi (*)
    2009-01-22 Includes\HeavyDuty.sbi (*)
    2009-05-26 Includes\Hijackers.sbi (*)
    2009-09-01 Includes\HijackersC.sbi (*)
    2009-06-23 Includes\Keyloggers.sbi (*)
    2009-09-01 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2009-08-19 Includes\Malware.sbi (*)
    2009-09-01 Includes\MalwareC.sbi (*)
    2009-03-25 Includes\PUPS.sbi (*)
    2009-09-01 Includes\PUPSC.sbi (*)
    2009-01-22 Includes\Revision.sbi (*)
    2009-01-13 Includes\Security.sbi (*)
    2009-09-01 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2009-04-07 Includes\Spyware.sbi (*)
    2009-09-01 Includes\SpywareC.sbi (*)
    2009-06-08 Includes\Tracks.uti
    2009-08-25 Includes\Trojans.sbi (*)
    2009-09-01 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll

    Spybot and rootalyser are both able to detect it and allegedly remove them but they are detected on the next scan.

    system restore is turned off.
    manually ran msconfig and no files are executing that look suspicious (adobe aol etc)

    first round of scans before these scans posted include
    AVg version 8.5, MalewareBytes, Symantec AV, Spybot s&d, Rootanalyser.3.4.47

    ERUNT has been run and backup taken

    While I wait I am going to scan in safemode to see if that allows the utilities to delete the files.. any assistance is appreciated.

    Thanks,
    --------------------------
    re-ran all scans in safe mode no luck

    any recomendations?
    ============================

    Removed quoted logs

    "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance)

  6. #6
    Junior Member
    Join Date
    Sep 2009
    Posts
    14

    Default First spybot scan came clean

    the first pass of spybot came back clean Thanks for all of your help.. after a couple of more scans is complete on the other profiles I will advise on status..


    Quote Originally Posted by jprendergast007 View Post
    Friends have a knack of breaking things the best..

    when I started his machine it would not run any executables including spybot/avg/SAV ETC..

    used reg file to fix (too long to list but can provide on request) worked great and then I was able to run standard av/spyware tools to clean. many infections removed except the one listed in the title.

    HJT log listed below:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:26:50 AM, on 9/15/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16876)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://83.149.75.33/info.png?cmp=fkf...mrk=1&ver=4057
    R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll (file missing)
    O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-21-1676360506-3534062470-2318509989-1014\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - https://a248.e.akamai.net/f/248/5462...l/SymDlBrg.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/tech...l/SymAData.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: karna.dat,zxovgf.dll,C:\WINDOWS\system32\sovagejo.dll bkviyj.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bomgar Jump Client [1235567581-1235567625] (bomgar-ps-1235567581-1235567625) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe (file missing)
    O23 - Service: Bomgar Jump Client [1236139268-1236139313] (bomgar-ps-1236139268-1236139313) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe (file missing)
    O23 - Service: Bomgar Jump Client [1236139268-1244144831] (bomgar-ps-1236139268-1244144831) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe (file missing)
    O23 - Service: Bomgar Support Customer Client [1235567581] (bomgar-scc-1235567581) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe (file missing)
    O23 - Service: Bomgar Support Customer Client [1236139268] (bomgar-scc-1236139268) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe (file missing)
    O23 - Service: dlbt_device - Dell - C:\WINDOWS\System32\dlbtcoms.exe
    O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe

    --
    End of file - 7488 bytes

    Spybot log listed below


    --- Report generated: 2009-09-15 07:48 ---

    Win32.TDSS.ntf: [SBI $C65DEAB2] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\drivers\SKYNEThoehbqlt.sys
    Properties.size=0
    Properties.md5=AFC2708D353D77D2AC94103D5730F160

    Win32.TDSS.ntf: [SBI $F7C6EF60] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETfumqskwp.dll
    Properties.size=0
    Properties.md5=5B4F59E220FA96D42363E8CAAC34D2D8

    Win32.TDSS.ntf: [SBI $F7C6EF60] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNEToptqxpbu.dll
    Properties.size=0
    Properties.md5=3B0585750AD0EEAA4583F4AFDF696713

    Win32.TDSS.ntf: [SBI $F7C6EF60] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETrjrxloyq.dll
    Properties.size=0
    Properties.md5=3B0585750AD0EEAA4583F4AFDF696713

    Win32.TDSS.ntf: [SBI $F7C6EF60] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETthtvpuyu.dll
    Properties.size=0
    Properties.md5=5B4F59E220FA96D42363E8CAAC34D2D8

    Win32.TDSS.ntf: [SBI $1A7ABF3C] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETqxnopatm.dat
    Properties.size=0
    Properties.md5=0B4FB4690EFA25C5CB5D25A2B291E7F8

    Win32.TDSS.ntf: [SBI $1A7ABF3C] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETrqpoqxyv.dat
    Properties.size=0
    Properties.md5=CEB5FB6784BD4FC72E47C643BAF9958F

    Win32.TDSS.ntf: [SBI $1A7ABF3C] File (File, nothing done)
    C:\WINDOWS\SYSTEM32\SKYNETxrvngfsx.dat
    Properties.size=0
    Properties.md5=EBA256D5218C6D6314B1B7382AE0C9D9


    --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

    2009-01-26 blindman.exe (1.0.0.8)
    2009-01-26 SDFiles.exe (1.6.1.7)
    2009-01-26 SDMain.exe (1.0.0.6)
    2009-01-26 SDUpdate.exe (1.6.0.12)
    2009-01-26 SpybotSD.exe (1.6.2.46)
    2009-03-05 TeaTimer.exe (1.6.6.32)
    2009-03-12 unins000.exe (51.49.0.0)
    2009-01-26 Update.exe (1.6.0.7)
    2009-07-28 advcheck.dll (1.6.3.17)
    2007-04-02 aports.dll (2.1.0.0)
    2008-06-14 DelZip179.dll (1.79.11.1)
    2009-01-26 SDHelper.dll (1.6.2.14)
    2008-06-19 sqlite3.dll
    2009-01-26 Tools.dll (2.1.6.10)
    2009-01-16 UninsSrv.dll (1.0.0.0)
    2009-05-19 Includes\Adware.sbi (*)
    2009-09-01 Includes\AdwareC.sbi (*)
    2009-01-22 Includes\Cookies.sbi (*)
    2009-05-19 Includes\Dialer.sbi (*)
    2009-09-01 Includes\DialerC.sbi (*)
    2009-01-22 Includes\HeavyDuty.sbi (*)
    2009-05-26 Includes\Hijackers.sbi (*)
    2009-09-01 Includes\HijackersC.sbi (*)
    2009-06-23 Includes\Keyloggers.sbi (*)
    2009-09-01 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2009-08-19 Includes\Malware.sbi (*)
    2009-09-01 Includes\MalwareC.sbi (*)
    2009-03-25 Includes\PUPS.sbi (*)
    2009-09-01 Includes\PUPSC.sbi (*)
    2009-01-22 Includes\Revision.sbi (*)
    2009-01-13 Includes\Security.sbi (*)
    2009-09-01 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2009-04-07 Includes\Spyware.sbi (*)
    2009-09-01 Includes\SpywareC.sbi (*)
    2009-06-08 Includes\Tracks.uti
    2009-08-25 Includes\Trojans.sbi (*)
    2009-09-01 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll

    Spybot and rootalyser are both able to detect it and allegedly remove them but they are detected on the next scan.

    system restore is turned off.
    manually ran msconfig and no files are executing that look suspicious (adobe aol etc)

    first round of scans before these scans posted include
    AVg version 8.5, MalewareBytes, Symantec AV, Spybot s&d, Rootanalyser.3.4.47

    ERUNT has been run and backup taken

    While I wait I am going to scan in safemode to see if that allows the utilities to delete the files.. any assistance is appreciated.

    Thanks,
    --------------------------
    re-ran all scans in safe mode no luck

    any recomendations?
    ============================

    Removed quoted logs

    "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance)

  7. #7
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Glad to hear but we are not done

    Please my link how to install recovery console. After that, please rerun combofix and post back a fresh combofix log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  8. #8
    Junior Member
    Join Date
    Sep 2009
    Posts
    14

    Default Re-Ran combo fix and it installed recovery console

    The first time I had the machine disconnected from internet to prevent further infection, so after it was cleaned I connected it back to the internet and re-ran combofix which on the second run installed recovery console.

    here si the results immediately following that..

    ComboFix 09-09-18.02 - cyberport 09/19/2009 10:54.2.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2558.2080 [GMT -4:00]
    Running from: c:\drivers\Spybot\combofix\ComboFix.exe
    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .

    ((((((((((((((((((((((((( Files Created from 2009-08-19 to 2009-09-19 )))))))))))))))))))))))))))))))
    .

    2009-09-15 12:24 . 2009-09-15 12:24 -------- d-----w- c:\program files\ERUNT
    2009-09-15 12:24 . 2009-09-15 12:24 -------- d-----w- C:\EruNTRegBackup
    2009-09-15 03:42 . 2009-09-15 03:42 -------- d-----w- c:\program files\Trend Micro
    2009-09-08 05:04 . 2009-09-15 03:47 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2009-09-08 04:44 . 2009-09-08 04:44 -------- d-----w- c:\program files\Enigma Software Group
    2009-09-08 03:02 . 2009-03-06 14:22 284160 ------w- c:\windows\system32\dllcache\pdh.dll
    2009-09-08 03:02 . 2009-02-09 12:10 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
    2009-09-08 03:02 . 2009-02-09 12:10 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
    2009-09-08 03:02 . 2009-02-06 11:11 110592 ------w- c:\windows\system32\dllcache\services.exe
    2009-09-08 03:02 . 2009-02-09 12:10 729088 ------w- c:\windows\system32\dllcache\lsasrv.dll
    2009-09-08 03:02 . 2009-02-09 12:10 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
    2009-09-08 03:02 . 2009-02-09 12:10 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
    2009-09-08 03:02 . 2009-02-09 12:10 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
    2009-09-08 03:02 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
    2009-09-08 03:01 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
    2009-09-08 03:00 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
    2009-09-08 03:00 . 2008-04-21 12:08 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
    2009-09-08 02:41 . 2009-09-08 02:41 -------- d-----w- c:\documents and settings\cyberport\Local Settings\Application Data\PCHealth
    2009-09-08 01:54 . 2009-09-08 01:54 -------- d-----w- c:\program files\Windows Defender
    2009-09-05 03:34 . 2009-09-08 03:33 -------- d-----w- C:\$AVG8.VAULT$
    2009-09-05 03:33 . 2009-09-05 03:33 -------- d-----w- c:\documents and settings\cyberport\Local Settings\Application Data\AVG Security Toolbar
    2009-09-05 03:30 . 2009-09-05 03:30 11952 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-09-05 03:30 . 2009-09-05 03:30 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-09-05 03:30 . 2009-09-05 03:30 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-09-05 03:30 . 2009-09-05 03:30 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-09-05 03:30 . 2009-09-08 03:17 -------- d-----w- c:\windows\system32\drivers\Avg
    2009-09-05 03:30 . 2009-09-08 01:49 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
    2009-09-05 03:13 . 2009-09-05 03:13 -------- d-----w- c:\documents and settings\cyberport\Local Settings\Application Data\Adobe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-09-19 14:58 . 2004-08-17 03:32 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000004-00000000-00000002-00001102-00000004-10031102}.dat
    2009-09-19 14:58 . 2004-08-17 03:32 288 ----a-w- c:\windows\system32\DVCState-{00000004-00000000-00000002-00001102-00000004-10031102}.dat
    2009-09-15 03:49 . 2004-08-17 03:31 -------- d-----w- c:\program files\Viewpoint
    2009-09-05 04:57 . 2008-10-26 01:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-09-05 03:30 . 2009-02-26 03:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Avg8
    2009-09-04 06:42 . 2005-10-02 06:24 -------- d-----w- c:\program files\Google
    2009-08-17 12:02 . 2008-10-26 00:46 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-08-05 09:01 . 2002-12-12 05:14 204800 ----a-w- c:\windows\system32\mswebdvd.dll
    2009-08-03 17:36 . 2008-10-26 01:45 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-08-03 17:36 . 2008-10-26 01:45 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-07-29 04:37 . 2004-03-19 22:43 119808 ----a-w- c:\windows\system32\t2embed.dll
    2009-07-29 04:37 . 2004-03-19 22:37 81920 ----a-w- c:\windows\system32\fontsub.dll
    2009-07-25 15:53 . 2009-07-25 15:32 -------- d-----w- c:\documents and settings\Nick Mattessich\Application Data\Costco Photo Organizer
    2009-07-25 15:42 . 2009-07-25 15:25 -------- d-----w- c:\documents and settings\Nick Mattessich\Application Data\Costco Photo Viewer US
    2009-07-25 15:31 . 2009-07-25 15:31 -------- d-----w- c:\program files\Common Files\HP
    2009-07-25 15:31 . 2009-07-25 15:31 -------- d-----w- c:\program files\Costco
    2009-07-18 18:40 . 2009-07-18 18:40 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
    2009-07-17 19:01 . 2004-03-19 22:33 58880 ----a-w- c:\windows\system32\atl.dll
    2009-07-14 03:43 . 2004-09-22 23:46 286208 ----a-w- c:\windows\system32\wmpdxm.dll
    2009-07-09 01:37 . 2009-07-09 01:37 552 ----a-w- c:\windows\system32\d3d8caps.dat
    2009-06-29 16:12 . 2004-08-24 00:32 827392 ------w- c:\windows\system32\wininet.dll
    2009-06-29 16:12 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-06-29 16:12 . 2004-03-19 22:34 17408 ----a-w- c:\windows\system32\corpol.dll
    .

    ------- Sigcheck -------


    [-] 2008-10-14 . 63999D0ABD8DABFD76A9C07F6E104868 . 295424 . . [5.1.2600.5512] . . c:\windows\SYSTEM32\termsrv.dll
    [7] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll
    [7] 2004-08-04 . B60C877D16D9C880B952FDA04ADF16E6 . 295424 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\termsrv.dll

    c:\windows\system32\drivers\beep.sys ... is missing !!
    .
    ((((((((((((((((((((((((((((( SnapShot@2009-09-19_13.28.13 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-09-19 14:59 . 2009-09-19 14:59 16384 c:\windows\Temp\Perflib_Perfdata_750.dat
    + 2009-09-19 14:59 . 2009-09-19 14:59 16384 c:\windows\Temp\Perflib_Perfdata_6e8.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

    [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
    2009-07-24 13:55 1090816 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

    [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

    [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-26 335872]
    "CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
    "CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-05 2007832]
    "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-08-03 419088]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
    "NoSetActiveDesktop"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-09-05 03:30 11952 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
    backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "afisicx"=2 (0x2)
    "AntipPro2009_12"=2 (0x2)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\1156698762\\ee\\AOLServiceHost.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AIM6\\aim6.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
    "%windir%\\system32\\drivers\\svchost.exe"=

    R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [3/11/2009 7:52 AM 64160]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [9/4/2009 11:30 PM 335240]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [9/4/2009 11:30 PM 108552]
    S0 ydrihvqy;ydrihvqy;c:\windows\SYSTEM32\DRIVERS\xkphewda.sys []
    S2 bomgar-ps-1235567581-1235567625;Bomgar Jump Client [1235567581-1235567625];"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe" -pinned elevated --> c:\documents and settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe [?]
    S2 bomgar-ps-1236139268-1236139313;Bomgar Jump Client [1236139268-1236139313];"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe" -pinned elevated --> c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe [?]
    S2 bomgar-ps-1236139268-1244144831;Bomgar Jump Client [1236139268-1244144831];"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe" -pinned elevated --> c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe [?]
    S2 bomgar-scc-1235567581;Bomgar Support Customer Client [1235567581];"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe" -service:run --> c:\documents and settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe [?]
    S2 bomgar-scc-1236139268;Bomgar Support Customer Client [1236139268];"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe" -service:run --> c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe [?]
    S3 jnv4_mib;jnv4_mib;\??\c:\docume~1\ERICMA~1\LOCALS~1\Temp\jnv4_mib.sys --> c:\docume~1\ERICMA~1\LOCALS~1\Temp\jnv4_mib.sys [?]
    S3 MBAMProtector;MBAMProtector;c:\windows\SYSTEM32\DRIVERS\mbam.sys [10/25/2008 9:45 PM 19096]
    S4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/4/2009 11:30 PM 297752]
    S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/25/2008 9:45 PM 232720]
    S4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-04-06 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]

    2009-07-09 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Nick Mattessich.job
    - c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2008-10-26 17:36]

    2009-07-09 c:\windows\Tasks\Malwarebytes' Scheduled Update for Nick Mattessich.job
    - c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2008-10-26 17:36]

    2009-09-19 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    mStart Page = hxxp://www.google.com
    uInternet Connection Wizard,ShellNext = hxxp://83.149.75.33/info.png?cmp=fkfrt&rid=m20001&affid=178471&mid=lg20&revid=11129&uid=b7d9ef1013f311deafa2178471ffffff&guid=03b19c7c8dd2df439d53b6a8acdae993&mrk=1&ver=4057
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    FF - ProfilePath - c:\documents and settings\cyberport\Application Data\Mozilla\Firefox\Profiles\zrp13z8i.default\
    FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
    FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
    FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
    FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
    FF - HiddenExtension: XUL Cache: {6BCCB36F-6102-411C-A304-018F2A2EDBB0} - c:\documents and settings\Eric Mattessich\Local Settings\Application Data\{6BCCB36F-6102-411C-A304-018F2A2EDBB0}
    FF - HiddenExtension: XUL Cache: {16ADC5ED-FB9B-4C90-B2AA-73DCB0D81A67} - c:\documents and settings\Christina Mattessich\Local Settings\Application Data\{16ADC5ED-FB9B-4C90-B2AA-73DCB0D81A67}
    FF - HiddenExtension: XUL Cache: {B559E360-0D9B-45B0-9A1C-27A708056906} - c:\documents and settings\Mary Ann Mattessich\Local Settings\Application Data\{B559E360-0D9B-45B0-9A1C-27A708056906}
    FF - HiddenExtension: XUL Cache: {A2BECE79-462E-4C26-8D03-CD3645A77C04} - c:\documents and settings\Nick Mattessich\Local Settings\Application Data\{A2BECE79-462E-4C26-8D03-CD3645A77C04}
    .
    .
    ------- File Associations -------
    .
    txtfile=%windir%\NOTEPAD.EXE %1
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-09-19 11:02
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...


    c:\windows\system32\drivers\xkphewda.sys 25088 bytes executable

    scan completed successfully
    hidden files: 1

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bomgar-scc-1235567581]
    "ImagePath"="\"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49A543DD\bomgar-scc.exe\" -service:run"

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bomgar-scc-1236139268]
    "ImagePath"="\"c:\documents and settings\All Users\Application Data\Bomgar-SCC-49ADFD04\bomgar-scc.exe\" -service:run"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(2476)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\SYSTEM32\ati2evxx.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Intel\Intel Application Accelerator\IAANTmon.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
    c:\windows\SYSTEM32\MsPMSPSv.exe
    c:\windows\SYSTEM32\wscntfy.exe
    .
    **************************************************************************
    .
    Completion time: 2009-09-19 11:05 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-09-19 15:05

    Pre-Run: 114,200,510,464 bytes free
    Post-Run: 114,159,194,112 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

    229 --- E O F --- 2009-09-19 09:27


    Let me know next steps..

    Quote Originally Posted by Shaba View Post
    Glad to hear but we are not done

    Please my link how to install recovery console. After that, please rerun combofix and post back a fresh combofix log.

  9. #9
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    I'd like you to check a file for malware.

    c:\windows\SYSTEM32\termsrv.dll
    • Copy/Paste the file on the list into the white Upload a file box.
    • Click Send/Submit, and the file will upload to VirusTotal/Jotti, where it will be scanned by several anti-virus programmes.
    • After a while, a window will open, with details of what the scans found.
    • Save the complete results in a Notepad/Word document on your desktop.
    • Post back results here, please.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  10. #10
    Junior Member
    Join Date
    Sep 2009
    Posts
    14

    Default That file is infected but I cannot keep the machine running anymore

    while scanning withmalwarebytes the system blue screened and now it is blue screen evry 4-5 minutes, which was just long enough to scan the file just not save the results..


    Quote Originally Posted by Shaba View Post
    I'd like you to check a file for malware.


    • Copy/Paste the file on the list into the white Upload a file box.
    • Click Send/Submit, and the file will upload to VirusTotal/Jotti, where it will be scanned by several anti-virus programmes.
    • After a while, a window will open, with details of what the scans found.
    • Save the complete results in a Notepad/Word document on your desktop.
    • Post back results here, please.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •