I could use you assistance::red:
Basic info (in sequential order of actions taken):
1) McAfee Security Center first detected infection as MewMalware.bx, but could not fix it. McAfee could only display the name in the result window, but gave no indication of ‘fix’ (no quarantine indicated, the checkbox could not be toggled, etc.).
2) System Mechanic both in normal mode and safe mode was either disabled (exception errors stopped it from loading, or was not functional in safe mode) so my option for loading a very recent Registry backup was blocked.
3) A new Antivirus program magically appeared in the system tray and ‘popping’ up as a program, saying the computer was infected. (The computer has had no internet connection since about 1 hour after McAfee had detected malware. I am using my desk top to communicated or download)
4) The System Restore made dysfunctional: After allowing selection of restore point the ‘Next’ (start restore) button produced no results.
5) Even with 2 to 3 week old update, Spybot did detect 6 unknown problems initially & and one common adware. It reported it fix all but one, Fraud.XPAntivirus. Re-running Spybot a few times in Safe mode has consistently reported detection of two problems labeled Fraud.XPAntivirus and PWS.LDPinchIE. Each time it reports the latter problem was fix, but the Fraud.XPAntivirus required a Registry problem to be fix with Spyboat running on a re-start. Spybot also had odd behavior I’ll not bore you with here, suffice it to say the Malware had had some affect on it , but did not stop it from running in SafeMode.
6) I printed SaferNetworking’s Manual Removal Guide for Fraud.XPAntivirus. The Malware is not simply Fraud.XPAntivirus, but a variant RootTootKit, which I’ll name ‘Игра ''Сапер''’. Attempting to the Manual Removal Guide was informative, e.g., finding files that could not be removed ( Shredder or otherwise in SafeMode). It led me to downloading RootAlyzer, which further confirms a RootToolKit infection.
7) As I can have not been able to remove or even find some of the obvious problem file or Registry malicious items found by RootAlyzer I turn to you for help.
Thanks,
Ron
Included below are first an HJT file and the RootAlyzer log.
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:59:05 PM, on 4/29/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\Program Files\iolo\System Mechanic\IoloSGCtrl.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee\msc\mcupdmgr.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\PROGRA~1\mcafee\msc\mcshell.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=localhost:8118;http=localhost:8118;https=localhost:8118;socks=localhost:9050
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;127.0.0.1;*.local
O2 - BHO: C:\WINDOWS\system32\yhs783ijfo3fe.dll - {B2BA40A2-74F0-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\yhs783ijfo3fe.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Digital Line Detect.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O16 - DPF: vzTCPConfig -
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1158564998625
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/app/ocx/UpgradeVerify.ocx
O22 - SharedTaskScheduler: jso8joigm409gopgmrlgd - {B2BA40A2-74F0-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\yhs783ijfo3fe.dll
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic\IoloSGCtrl.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - Unknown owner - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 9857 bytes
RA log
File::
C:\WINDOWS\system32\ovfsthxhyijnomy.dat
C:\WINDOWS\system32\ovfsthxrobjxtqa.dll
C:\WINDOWS\system32\ovfsthxudjxilmk.dat
C:\WINDOWS\system32\ovfsthxvbuyxmac.dll
C:\WINDOWS\system32\ovfsthxxuwwlskb.dll
C:\WINDOWS\Temp\ovfsthxaqfmenjpyf.tmp
C:\WINDOWS\system32\9AA07EEAE2.sys
C:\WINDOWS\system32\E2EA7EA09A.sys
C:\WINDOWS\system32\KGyGaAvL.sys
C:\WINDOWS\system32\ovfsthxhyijnomy.dat
C:\WINDOWS\system32\ovfsthxrobjxtqa.dll
C:\WINDOWS\system32\ovfsthxudjxilmk.dat
C:\WINDOWS\system32\ovfsthxvbuyxmac.dll
C:\WINDOWS\system32\ovfsthxxuwwlskb.dll
C:\WINDOWS\system32\drivers\ovfsthxpxwskwba.sys
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\desktop.ini
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\01_Music_auto_rated_at_5_stars.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\02_Music_added_in_the_last_month.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\03_Music_rated_at_4_or_5_stars.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\04_Music_played_in_the_last_month.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\05_Pictures_taken_in_the_last_month.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\06_Pictures_rated_4_or_5_stars.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\07_TV_recorded_in_the_last_week.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\08_Video_rated_at_4_or_5_stars.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\09_Music_played_the_most.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\10_All_Music.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\11_All_Pictures.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\12_All_Video.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\desktop.ini
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- 4 and 5 star rated.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- Have not heard recently.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- Listen to late at night.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- Listen to on Weekdays.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- Listen to on Weekends.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- One Audio CD worth.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- One Data CD-R worth.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Fresh tracks -- yet to be played.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Fresh tracks -- yet to be rated.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Fresh tracks.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\High bitrate media in my library.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Low bitrate media in my library.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Music tracks I dislike.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Music tracks I have not rated.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Music tracks with content protection.wpl
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\download.cfg
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\pfWDPF.08
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\pmWDPF.08
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\Sydvrs18.x00
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\tmpscreen.htm
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\Update\lver.txt
C:\Documents and Settings\All Users\Application Data\Symantec\hpc:468323563:$DATA
Folder::
C:\RECYCLER\S-1-5-21-2345041157-3355378873-843990181-1006\Dc395
C:\RECYCLER\S-1-5-21-2345041157-3355378873-843990181-1006\Dc396
C:\RECYCLER\S-1-5-21-2345041157-3355378873-843990181-1006\Dc397
C:\RECYCLER\S-1-5-21-2345041157-3355378873-843990181-1006\Dc396\convert
C:\RECYCLER\S-1-5-21-2345041157-3355378873-843990181-1006\Dc396\drivedir
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F
C:\Documents and Settings\All Users\Application Data\TaxCut\2008
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\Update
Registry::
[-HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\SAC\0]
// Attention: entries with a zero character will not be displayed correctly and may not work!
[-HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\SAI\0]
// Attention: entries with a zero character will not be displayed correctly and may not work!
[-HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\SCM:{3D14228D-FBE1-11D0-995D-00C04FD919C1}\0]
// Attention: entries with a zero character will not be displayed correctly and may not work!
Basic info (in sequential order of actions taken):
1) McAfee Security Center first detected infection as MewMalware.bx, but could not fix it. McAfee could only display the name in the result window, but gave no indication of ‘fix’ (no quarantine indicated, the checkbox could not be toggled, etc.).
2) System Mechanic both in normal mode and safe mode was either disabled (exception errors stopped it from loading, or was not functional in safe mode) so my option for loading a very recent Registry backup was blocked.
3) A new Antivirus program magically appeared in the system tray and ‘popping’ up as a program, saying the computer was infected. (The computer has had no internet connection since about 1 hour after McAfee had detected malware. I am using my desk top to communicated or download)
4) The System Restore made dysfunctional: After allowing selection of restore point the ‘Next’ (start restore) button produced no results.
5) Even with 2 to 3 week old update, Spybot did detect 6 unknown problems initially & and one common adware. It reported it fix all but one, Fraud.XPAntivirus. Re-running Spybot a few times in Safe mode has consistently reported detection of two problems labeled Fraud.XPAntivirus and PWS.LDPinchIE. Each time it reports the latter problem was fix, but the Fraud.XPAntivirus required a Registry problem to be fix with Spyboat running on a re-start. Spybot also had odd behavior I’ll not bore you with here, suffice it to say the Malware had had some affect on it , but did not stop it from running in SafeMode.
6) I printed SaferNetworking’s Manual Removal Guide for Fraud.XPAntivirus. The Malware is not simply Fraud.XPAntivirus, but a variant RootTootKit, which I’ll name ‘Игра ''Сапер''’. Attempting to the Manual Removal Guide was informative, e.g., finding files that could not be removed ( Shredder or otherwise in SafeMode). It led me to downloading RootAlyzer, which further confirms a RootToolKit infection.
7) As I can have not been able to remove or even find some of the obvious problem file or Registry malicious items found by RootAlyzer I turn to you for help.
Thanks,
Ron
Included below are first an HJT file and the RootAlyzer log.
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:59:05 PM, on 4/29/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\Program Files\iolo\System Mechanic\IoloSGCtrl.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee\msc\mcupdmgr.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\PROGRA~1\mcafee\msc\mcshell.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=localhost:8118;http=localhost:8118;https=localhost:8118;socks=localhost:9050
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;127.0.0.1;*.local
O2 - BHO: C:\WINDOWS\system32\yhs783ijfo3fe.dll - {B2BA40A2-74F0-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\yhs783ijfo3fe.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Digital Line Detect.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O16 - DPF: vzTCPConfig -
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1158564998625
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/app/ocx/UpgradeVerify.ocx
O22 - SharedTaskScheduler: jso8joigm409gopgmrlgd - {B2BA40A2-74F0-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\yhs783ijfo3fe.dll
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic\IoloSGCtrl.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - Unknown owner - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 9857 bytes
RA log
File::
C:\WINDOWS\system32\ovfsthxhyijnomy.dat
C:\WINDOWS\system32\ovfsthxrobjxtqa.dll
C:\WINDOWS\system32\ovfsthxudjxilmk.dat
C:\WINDOWS\system32\ovfsthxvbuyxmac.dll
C:\WINDOWS\system32\ovfsthxxuwwlskb.dll
C:\WINDOWS\Temp\ovfsthxaqfmenjpyf.tmp
C:\WINDOWS\system32\9AA07EEAE2.sys
C:\WINDOWS\system32\E2EA7EA09A.sys
C:\WINDOWS\system32\KGyGaAvL.sys
C:\WINDOWS\system32\ovfsthxhyijnomy.dat
C:\WINDOWS\system32\ovfsthxrobjxtqa.dll
C:\WINDOWS\system32\ovfsthxudjxilmk.dat
C:\WINDOWS\system32\ovfsthxvbuyxmac.dll
C:\WINDOWS\system32\ovfsthxxuwwlskb.dll
C:\WINDOWS\system32\drivers\ovfsthxpxwskwba.sys
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\desktop.ini
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\01_Music_auto_rated_at_5_stars.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\02_Music_added_in_the_last_month.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\03_Music_rated_at_4_or_5_stars.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\04_Music_played_in_the_last_month.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\05_Pictures_taken_in_the_last_month.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\06_Pictures_rated_4_or_5_stars.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\07_TV_recorded_in_the_last_week.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\08_Video_rated_at_4_or_5_stars.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\09_Music_played_the_most.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\10_All_Music.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\11_All_Pictures.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F\12_All_Video.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\desktop.ini
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- 4 and 5 star rated.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- Have not heard recently.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- Listen to late at night.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- Listen to on Weekdays.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- Listen to on Weekends.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- One Audio CD worth.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Favorites -- One Data CD-R worth.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Fresh tracks -- yet to be played.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Fresh tracks -- yet to be rated.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Fresh tracks.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\High bitrate media in my library.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Low bitrate media in my library.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Music tracks I dislike.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Music tracks I have not rated.wpl
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Music tracks with content protection.wpl
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\download.cfg
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\pfWDPF.08
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\pmWDPF.08
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\Sydvrs18.x00
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\tmpscreen.htm
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\Update\lver.txt
C:\Documents and Settings\All Users\Application Data\Symantec\hpc:468323563:$DATA
Folder::
C:\RECYCLER\S-1-5-21-2345041157-3355378873-843990181-1006\Dc395
C:\RECYCLER\S-1-5-21-2345041157-3355378873-843990181-1006\Dc396
C:\RECYCLER\S-1-5-21-2345041157-3355378873-843990181-1006\Dc397
C:\RECYCLER\S-1-5-21-2345041157-3355378873-843990181-1006\Dc396\convert
C:\RECYCLER\S-1-5-21-2345041157-3355378873-843990181-1006\Dc396\drivedir
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0003A46F
C:\Documents and Settings\All Users\Application Data\TaxCut\2008
C:\Documents and Settings\All Users\Application Data\TaxCut\2008\Update
Registry::
[-HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\SAC\0]
// Attention: entries with a zero character will not be displayed correctly and may not work!
[-HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\SAI\0]
// Attention: entries with a zero character will not be displayed correctly and may not work!
[-HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\SCM:{3D14228D-FBE1-11D0-995D-00C04FD919C1}\0]
// Attention: entries with a zero character will not be displayed correctly and may not work!