  icex _ Premium join:2004-05-22 USA clubs:
·Colane Cable
| reply to CalamityJane Re: [Virus] Virus's and spyware!
It's got the about:blank spyware/adware I think.
Spybot teamtimer popped up saying the new website start page had been changed to about:blank ..
Combofix said something about the findstring being too long.. but anyway.. Heres the combofix log:
"Beth" - 2007-07-03 2:13:41 - ComboFix 07-06-27.7 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Documents and Settings\All Users.\documents\settings C:\Documents and Settings\All Users.\documents\settings\desktop.ini C:\Program Files\Common Files\{348C6~1 C:\Program Files\Common Files\{448C6~1 C:\Program Files\Common Files\{448C6~2 C:\Program Files\Common Files\crosof~1.net C:\Program Files\Common Files\curity~1 C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe C:\temp\0b9 C:\temp\0b9\tmpTF.log C:\temp\tn3 C:\WINDOWS\764.exe C:\WINDOWS\7search.dll C:\WINDOWS\bjam.dll C:\WINDOWS\bokja.exe C:\WINDOWS\cdsm32.dll C:\WINDOWS\cs_cache.ini C:\WINDOWS\flt.dll C:\WINDOWS\mspphe.dll C:\WINDOWS\pbar.dll C:\WINDOWS\rau001978.exe C:\WINDOWS\saiemod.dll C:\WINDOWS\stcloader.exe C:\WINDOWS\swin32.dll C:\WINDOWS\system32\180ax.exe C:\WINDOWS\system32\a3dx8.dll C:\WINDOWS\system32\biprep.exe C:\WINDOWS\system32\ecurit~1 C:\WINDOWS\system32\gtv_sd.bin C:\WINDOWS\system32\msdn_lib.dll C:\WINDOWS\system32\msixu.dll C:\WINDOWS\system32\salm.exe C:\WINDOWS\system32\satmat.exe C:\WINDOWS\system32\susp.exe C:\WINDOWS\system32\T3 C:\WINDOWS\system32\T4 C:\WINDOWS\system32\T6 C:\WINDOWS\system32\updatetc.exe C:\WINDOWS\system32\vxddsk.exe C:\WINDOWS\system32\wer8274.dll C:\WINDOWS\system32\wml.exe C:\WINDOWS\voiceip.dll
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NET_AGENT
((((((((((((((((((((((((( Files Created from 2007-06-03 to 2007-07-03 )))))))))))))))))))))))))))))))
2007-07-02 14:40 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-07-02 00:56 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys 2007-07-02 00:43 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-07-02 00:35 d-------- C:\VundoFix Backups 2007-07-01 21:13 444 --a------ C:\WINDOWS\system32\d3d8caps.dat 2007-06-28 04:06 95,872 --a------ C:\WINDOWS\system32\AvastSS.scr 2007-06-28 04:06 94,552 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-06-28 04:06 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-06-28 04:06 745,600 --a------ C:\WINDOWS\system32\aswBoot.exe 2007-06-28 04:06 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-06-28 04:06 26,888 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-06-28 04:06 23,416 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-06-28 04:06 d-------- C:\Program Files\Alwil Software 2007-06-27 16:52 d--h----- C:\WINDOWS\PIF 2007-06-27 14:44 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy 2007-06-27 14:07 d-------- C:\Program Files\CCleaner 2007-06-25 19:17 d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer 2007-06-07 21:54 0 --a------ C:\WINDOWS\system32\kgctini.dat 2007-06-03 19:06 8,246 --a------ C:\DOCUME~1\Beth\win321.exe 2007-06-03 19:05 969 --a------ C:\DOCUME~1\Beth\dvvln2MBxL.exe 2007-06-03 18:43 8,464 --a------ C:\WINDOWS\system32\sporder.dll 2007-06-03 13:42 d-------- C:\DOCUME~1\Beth\APPLIC~1\U3
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-01 08:24:14 -------- d-----w C:\Program Files\QuickTime 2007-07-01 04:58:26 517,120 ----a-w C:\WINDOWS\system32\winlogon.exe 2007-06-28 08:22:20 -------- d-----w C:\DOCUME~1\Beth\APPLIC~1\The Flag 2007-06-28 05:45:02 -------- d-----w C:\Program Files\Ares 2007-06-27 07:00:24 12 ----a-w C:\WINDOWS\system32\sl.bin 2007-06-27 06:59:55 4 ----a-w C:\WINDOWS\system32\stfv.bin 2007-06-27 05:17:49 -------- d--h--w C:\Program Files\WindowsUpdate 2007-06-27 05:17:49 -------- d-----w C:\Program Files\Online Services 2007-06-26 05:22:23 -------- d-----w C:\Program Files\Microsoft AntiSpyware 2007-06-26 02:44:06 -------- d-----w C:\Program Files\Common Files\qwkr 2007-06-03 23:12:26 -------- d-----w C:\DOCUME~1\Beth\APPLIC~1\ZangoToolbar 2007-06-03 23:07:47 12,800 ----a-w C:\WINDOWS\system32\svchost.exe 2007-06-01 19:52:25 -------- d-----w C:\DOCUME~1\Beth\APPLIC~1\Image Zone Express 2007-05-20 14:37:55 -------- d-----w C:\DOCUME~1\Beth\APPLIC~1\AdobeUM 2007-04-17 05:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-04-17 05:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-04-17 05:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-04-17 05:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-04-17 05:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-04-17 05:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-04-17 05:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-04-17 05:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-04-16 19:39] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 06:43] {9394EDE7-C8B5-483E-8773-474BF36AF6E4}=C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll [2004-08-13 21:42] {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll [2006-01-17 20:04]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 19:44] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 06:41] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 06:43] "AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Watch.exe" [2007-06-27 22:16] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 13:36] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-06-23 16:57] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [] "IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2005-10-19 11:59] "{448C6F08-0701-1033-0826-020409200001}"="C:\Program Files\Common Files\{448C6F08-0701-1033-0826-020409200001}\Update.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2006-01-24 15:37] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 04:04] "ares"="C:\Program Files\Ares\Ares.exe" [2005-04-28 22:29] "Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 22:23] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 12:18]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 08:29]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wsmsge] wsmsge.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\mswsag.sys]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares] "C:\Program Files\Ares\Ares.exe" -h
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3] "\" /WinStart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{448C6F08-0701-1033-0826-020409200001}] "C:\Program Files\Common Files\{448C6F08-0701-1033-0826-020409200001}\Update.exe" te-110-12-0000282
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F146C9B1-VMVQ-A9RC-NUFL-D02300B4E999} C:\WINDOWS\system32\tmrsrv32.exe
Contents of the 'Scheduled Tasks' folder 2007-07-03 06:00:01 C:\WINDOWS\tasks\85D491DD93E32F55.job 2007-07-03 06:00:02 C:\WINDOWS\tasks\AAF587AF918A3BEF.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, »www.gmer.net Rootkit scan 2007-07-03 02:23:25 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
? [520] ? [1060]
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\mswsag.sys C:\WINDOWS\system32\wsmsge.dll C:\WINDOWS\system32\wsmsge.sys C:\WINDOWS\system32\qo.dll C:\WINDOWS\system32\qo.sys C:\WINDOWS\system32\nmk4.dat **************************************************************************
Completion time: 2007-07-03 2:31:31 - machine was rebooted C:\ComboFix-quarantined-files.txt ... 2007-07-03 02:30 C:\ComboFix2.txt ... 2007-07-02 13:33
--- E O F --- -- Team Discovery |
|
  icex _ Premium join:2004-05-22 USA clubs:
·Colane Cable
| Logfile of HijackThis v1.99.0 Scan saved at 5:13:47 AM, on 7/3/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2800.1106)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\System32\CTsvcCDA.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wdfmgr.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Watch.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\hjt\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.103:6588 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Watch.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [{448C6F08-0701-1033-0826-020409200001}] "C:\Program Files\Common Files\{448C6F08-0701-1033-0826-020409200001}\Update.exe" te-110-12-0000282 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - »housecall60.trendmicro.com/house···an60.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - »www.kaspersky.com/downloads/kws/···code.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - »messenger.zone.msn.com/binary/Me···1267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - »go.microsoft.com/fwlink/?linkid=48835 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - »spaces.msn.com/PhotoUpload/MsnPU···,0,911,0 O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - »software-dl.real.com/237ef6a9f56···E601.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - »update.microsoft.com/windowsupda···52978812 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - »a840.g.akamai.net/7/840/537/2004···an53.cab O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - »chat.yahoo.com/cab/yacsui.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - »messenger.msn.com/download/MsnMe···ader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - »messenger.zone.msn.com/binary/ZI···2846.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - »messenger.zone.msn.com/binary/Ba···1267.cab O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - »www.verizon.net/checkmypc/includ···Qual.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: avast! iAVS4 Control Service - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe O23 - Service: ScsiAccess - Unknown - C:\WINDOWS\System32\ScsiAccess.EXE (file missing) -- Team Discovery |
|
  CalamityJane Premium,VIP,MVM join:2002-08-27 Eustis, FL
| reply to icex _ This is probably one of the worst infected computers I've seen in a long while. It's still got yet another rootkit
Download haxfix.exe. »users.telenet.be/marcvn/tools/haxfix.exe Save it to your desktop. Double click on haxfix.exe to install haxfix. (standard installation path is c:\program Files\haxfix) Checkmark "Create a desktop icon". Click "Next". When the installation is completed, make sure that the checkmark "Launch HaxFix" is placed. Click "Finish". A red "dos window" (dos box) will open. Select option 1. Make logfile by typing 1 and then pressing Enter. Haxfix will start scanning the computer. When it is finished a logfile will open. Copy the contents of that logfile and paste it into this thread.
Note: Please do not run any fix options until I've had a chance to review the log. This tool is capable of finding legitimate file as well as infected files, so a log review first is very important and I may not get to that until morning. -- It takes a disaster to make a woman out of a femaleMicrosoft MVP/Windows Security 2003-2007Proud Member of ASAP (Alliance of Security Analysis Professionals) |
|
  icex _ Premium join:2004-05-22 USA clubs:
·Colane Cable
| This computer is so slow, I'm guessing because of the infection and the fact it only has 256mbs of ram.
Heres the log:
HAXFIX logfile - by Marckie
version 4.47 Tue 07/03/2007 11:44:43.79
--- Checking for Haxdoor ---
checking for a3d files a3d files not found
checking for matching notify keys no matching notify keys found
checking for matching services matching services found mswsag
checking for matching safeboot services matching safeboot services found mswsag.sys
checking for other Haxdoor-files no other Haxdoor-files found
--- Checking for Goldun ---
checking for SSODL keys Upperhost
checking for notify keys no notify keys found
checking for services no services found
checking for other Goldun-files no other Goldun-files found
checking iexplore.exe iexplore.exe is not infected
--- Catchme logfile - thank you Gmer ---
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, »www.gmer.net Rootkit scan 2007-07-03 11:44:54 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
? [516] ? [1052]
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Documents and Settings\Beth\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat:KAVICHS 132 bytes hidden from API C:\Documents and Settings\Beth\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG:KAVICHS 36 bytes hidden from API C:\Documents and Settings\Beth\ntuser.dat.LOG:KAVICHS 68 bytes hidden from API C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat:KAVICHS 36 bytes hidden from API C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG:KAVICHS 36 bytes hidden from API C:\Documents and Settings\LocalService\NTUSER.DAT:KAVICHS 36 bytes hidden from API C:\Documents and Settings\LocalService\ntuser.dat.LOG:KAVICHS 36 bytes hidden from API C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat:KAVICHS 36 bytes hidden from API C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG:KAVICHS 36 bytes hidden from API C:\Documents and Settings\NetworkService\NTUSER.DAT:KAVICHS 36 bytes hidden from API C:\Documents and Settings\NetworkService\ntuser.dat.LOG:KAVICHS 36 bytes hidden from API C:\WINDOWS\system32\mswsag.sys C:\WINDOWS\system32\wsmsge.dll C:\WINDOWS\system32\wsmsge.sys C:\WINDOWS\system32\qo.dll C:\WINDOWS\system32\qo.sys C:\WINDOWS\system32\nmk4.dat
scan completed successfully hidden processes: 2 hidden services: 0 hidden files: 17
--- Analysing Catchme logfile ---
matching notify key found: wsmsge matching service found: mswsag matching safeboot services found: mswsag.sys matching service found: wsmsge
Finished! -- Team Discovery |
|
  CalamityJane Premium,VIP,MVM join:2002-08-27 Eustis, FL
| reply to icex _ Run Haxfix again.
A red "dos window" (dos box) will open with options:
1. Make logfile
2. Run auto fix
3. Run manual fix
E. Exit Haxfix
Select option 2. Run auto fix by typing 2 and then pressing Enter
If an infection is found, you'll get a message to close all other open windows.
Close all open windows except the red dos window from haxfix and then press Enter
The computer will reboot
After reboot a logfile will open > (c:\haxfix.txt)
Post the contents of that logfile along with a new HijackThis log. ............ Then please also scan with ComboFix and post a new log from it as well -- It takes a disaster to make a woman out of a femaleMicrosoft MVP/Windows Security 2003-2007Proud Member of ASAP (Alliance of Security Analysis Professionals) |
|
  icex _ Premium join:2004-05-22 USA clubs:
·Colane Cable
| Haxfix log:
HAXFIX logfile - by Marckie
version 4.47 Tue 07/03/2007 21:21:33.48
--- Auto Haxdoorfix ---
searching for files:
searching for services.... service mswsag found [SWSC] DeleteService SUCCESS
--- Goldunfix ---
searching for files:
checking iexplore.exe iexplore.exe is not infected
searching for SSODLkeys: no SSODLkeys found
searching for notifykeys: no notifykeys found
searching for services: no services found
.....rebooting the computer.....
searching for ssodlkeys
not needed
searching for notifykeys
not needed
searching for services
service mswsag not found
searching for safeboot services
safeboot service mswsag.sys not found
searching for files
mswsag.sys exists deleting mswsag.sys mswsag.sys has been deleted
wsmsag.sys exists deleting wsmsag.sys wsmsag.sys has been deleted
checking for other files
kgctini.dat exists deleting kgctini.dat kgctini.dat has been deleted
qo.dll exists deleting qo.dll qo.dll has been deleted
qo.sys exists deleting qo.sys qo.sys has been deleted
nmk4.dat exists deleting nmk4.dat nmk4.dat has been deleted
checking for a3d files
no a3d files found
--- Catchme logfile - thank you Gmer ---
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, »www.gmer.net Rootkit scan 2007-07-03 21:28:03 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Documents and Settings\Beth\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat:KAVICHS 132 bytes hidden from API C:\Documents and Settings\Beth\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG:KAVICHS 36 bytes hidden from API C:\Documents and Settings\Beth\ntuser.dat.LOG:KAVICHS 68 bytes hidden from API C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat:KAVICHS 36 bytes hidden from API C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG:KAVICHS 36 bytes hidden from API C:\Documents and Settings\LocalService\NTUSER.DAT:KAVICHS 36 bytes hidden from API C:\Documents and Settings\LocalService\ntuser.dat.LOG:KAVICHS 36 bytes hidden from API C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat:KAVICHS 36 bytes hidden from API C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG:KAVICHS 36 bytes hidden from API C:\Documents and Settings\NetworkService\NTUSER.DAT:KAVICHS 36 bytes hidden from API C:\Documents and Settings\NetworkService\ntuser.dat.LOG:KAVICHS 36 bytes hidden from API
scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 11
Finished
I will paste the other logs when I get back from the gym. -- Team Discovery |
|
  CalamityJane Premium,VIP,MVM join:2002-08-27 Eustis, FL
| reply to icex _ I have a really bad feeling that by helping you remove the infected files, that I'm giving you a false sense of security and that the original owner of this PC will be left in the dark about how serious this breach of their computer has been and the security implications with running this as a trusted machine in the future.
quote: This computer has two accounts. On the "Mom" account it seems fine. On the other account, (their both admin accounts by the way) all is not fine
Has "Mom" been informed fully that this computer has been hosed to the point that there is no guarantee that these "fixes" will keep their info and data safe in the future and, more importantly, the very real possibility that any sensitive data stored on this PC is now at risk and could very well be in the hands of an attacker?
Some points to note as we are removing infected files and you may NOT notice symptoms of system changes by the attacker: said by Jesper M. Johansson, Ph.D., CISSP, MCSE, MCP+I, Security Program Manager,Microsoft Corporation, Published: May 7, 2004 : So, you didnt protect the system and it got hacked. What to do? Well, lets see:
You cant clean a compromised system by patching it. Patching only removes the vulnerability. Upon getting into your system, the attacker probably ensured that there were several other ways to get back in.
You cant clean a compromised system by removing the back doors. You can never guarantee that you found all the back doors the attacker put in. The fact that you cant find any more may only mean you dont know where to look, or that the system is so compromised that what you are seeing is not actually what is there.
You cant clean a compromised system by using some vulnerability remover. Lets say you had a system hit by Blaster. A number of vendors (including Microsoft) published vulnerability removers for Blaster. Can you trust a system that had Blaster after the tool is run? I wouldnt. If the system was vulnerable to Blaster, it was also vulnerable to a number of other attacks. Can you guarantee that none of those have been run against it? I didnt think so.
You cant clean a compromised system by using a virus scanner. To tell you the truth, a fully compromised system cant be trusted. Even virus scanners must at some level rely on the system to not lie to them. If they ask whether a particular file is present, the attacker may simply have a tool in place that lies about it. Note that if you can guarantee that the only thing that compromised the system was a particular virus or worm and you know that this virus has no back doors associated with it, and the vulnerability used by the virus was not available remotely, then a virus scanner can be used to clean the system. For example, the vast majority of e-mail worms rely on a user opening an attachment. In this particular case, it is possible that the only infection on the system is the one that came from the attachment containing the worm. However, if the vulnerability used by the worm was available remotely without user action, then you cant guarantee that the worm was the only thing that used that vulnerability. It is entirely possible that something else used the same vulnerability. In this case, you cant just patch the system.
You cant clean a compromised system by reinstalling the operating system over the existing installation. Again, the attacker may very well have tools in place that tell the installer lies. If that happens, the installer may not actually remove the compromised files. In addition, the attacker may also have put back doors in non-operating system components.
You cant trust any data copied from a compromised system. Once an attacker gets into a system, all the data on it may be modified. In the best-case scenario, copying data off a compromised system and putting it on a clean system will give you potentially untrustworthy data. In the worst-case scenario, you may actually have copied a back door hidden in the data.
You cant trust the event logs on a compromised system. Upon gaining full access to a system, it is simple for an attacker to modify the event logs on that system to cover any tracks. If you rely on the event logs to tell you what has been done to your system, you may just be reading what the attacker wants you to read.
You may not be able to trust your latest backup. How can you tell when the original attack took place? The event logs cannot be trusted to tell you. Without that knowledge, your latest backup is useless. It may be a backup that includes all the back doors currently on the system.
The only way to clean a compromised system is to flatten and rebuild. Thats right. If you have a system that has been completely compromised, the only thing you can do is to flatten the system (reformat the system disk) and rebuild it from scratch (reinstall Windows and your applications).
The above quote taken from this page: »www.microsoft.com/technet/commun···504.mspx
Not having the original install disk and/or backups prior to the compromise makes this option pretty much impossible. However, continuing to use this PC on the internet as a trusted machine is a risk for future use. It might be time for a new computer and retire this one.
I can tell you that I would not use it after this serious a breach. Give your friend this link if they do not understand what happens when your computer is wide open and under control of a remote access trojan: Invasion of the Computer Snatchers »www.washingtonpost.com/wp-dyn/co···342.html
That is the reality of what we are dealing with here. This PC has been so seriously compromised that I do not want to mislead you into thinking that this "cleaning" will reverse the potential of the damage already done. The fact that it was hosting Multiple rootkits and backdoor trojans makes the breach pretty much a worst case scenerio, with many of these problems you have seen thus far trying to "clean" the system. Security Management - July 2004 Help: I Got Hacked. Now What Do I Do? Part II »www.microsoft.com/technet/commun···704.mspx quote: with a rootkit on the system that makes the system no longer trustworthy. Windows Explorer and the command line will no longer show you the files that are actually on the system. The registry editor is now lying. Account manager tools will not show you all the users. At this stage of an intrusion, you can no longer trust the system to tell you about itself. Thats where you get into a flatten and rebuild (some people call it "nuke and pave") scenario. The system is now completely compromised.
-- It takes a disaster to make a woman out of a femaleMicrosoft MVP/Windows Security 2003-2007Proud Member of ASAP (Alliance of Security Analysis Professionals) |
|
  icex _ Premium join:2004-05-22 USA clubs: | I'm going to call her and see what she wants me to do. I will probaly offer to build her a computer, better and cheaper then dell. -- Team Discovery |
|
  CalamityJane Premium,VIP,MVM join:2002-08-27 Eustis, FL | I think that's a good idea to let her know because this machine IS a security risk even if we try to clean it up. Refer her to this topic and our posts here. |
|
  icex _ Premium join:2004-05-22 USA clubs:
·Colane Cable
| I called and she wasent home. I left a message.
I am going to ask her if she has entered credit cards, or anything like that, and if she has to keep a check on her credit report and possibly alert the credit card company to look for suspicious charges, since her computer was pretty much hacked. I found a keylogger on here to when I first worked on the computer, so that pretty much is a high risk that any passwords, credit card numbers, etc has been logged. -- Team Discovery |
|
  CalamityJane Premium,VIP,MVM join:2002-08-27 Eustis, FL
2 edits | said by icex _ :I called and she wasent home. I left a message. I am going to ask her if she has entered credit cards, or anything like that, and if she has to keep a check on her credit report and possibly alert the credit card company to look for suspicious charges, since her computer was pretty much hacked. I found a keylogger on here to when I first worked on the computer, so that pretty much is a high risk that any passwords, credit card numbers, etc has been logged. Yes, please do follow up on that. If a keylogger was found that further complicates any data at all on that computer. Earlier I linked an FAQ here that should also help: How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud? »Security »How to report ID theft, fraud, drive-by installs, hijacking and malware?
ALL passwords to ANY accounts should be changed and monitored for suspicious activity. That would include, in addition to any personal financial information or accounts but also emails, internet accounts anything at all could have been stolen and you have to assume it was, as badly hacked as this PC was/is (it's still got a rootkit and other nasties lurking on there so make sure this doesn't go on the net anymore). The presence of a keylogger further solidifies the malicious intent of the intruder.
Consider also any other information or records that may belong to others and stored on that PC? The keylogger records keystrokes; those backdoor trojans can steal any documents/info they want and can just access anything (documents, addressbooks, etc.) without the knowledge of the user. -- It takes a disaster to make a woman out of a femaleMicrosoft MVP/Windows Security 2003-2007Proud Member of ASAP (Alliance of Security Analysis Professionals) |
|
  icex _ Premium join:2004-05-22 USA clubs:
·Colane Cable
| I will let you know when she calls back what's going on. She may just say to clean it the best I can and give it to her, or she may say she'll buy a new one. I have wasted a whole week on this thing, pretty much for nothing, because I doubt she's going to pay me for something unfixable. -- Team Discovery |
|
  icex _ Premium join:2004-05-22 USA clubs:
·Colane Cable
| reply to CalamityJane Well, heres an update.
She sent the disks to me today, and told me to just get her pictures, word perfect documents and music and wipe it clean. So thats what I am doing now =) -- Team Discovery |
|
  icex _ Premium join:2004-05-22 USA clubs:
·Colane Cable
| reply to CalamityJane One more thing I forgot to mention, she uses a debit card ALL THE TIME on her computer, so I told her to call the credit card company and the credit bureau or whatever and tell them to watch her credit for a month or two for suspicious activity. -- Team Discovery |
|
  CalamityJane Premium,VIP,MVM join:2002-08-27 Eustis, FL
| reply to icex _ That's a good idea. Backup any documents to removable media and be sure that you scan them with a number of anti-malware apps before putting them onto a clean computer.
SO you do have reinstall disks?
As for getting paid - there is no payment requested nor expected here for the advice we give in cleanups. We are volunteers giving freely of our own time. In fact, we rather resent using our volunteer time to help others if you are going to turn around and charge someone for it so I sure hope you do NOT include any of the time we have spent here! The other thing is that you need to be sure that in your cleaning you keep in mind the total needs of the person you are helping. In the best interest of this person's computer, good security advice would entail letting them know the risks involved and the total picture of future security. As I said earlier, it is a trivial matter in this case to clean off infected files and remove symptoms of the infection, but learning what exactly what that infection has done is important to relay back to the user so they can make an informed decision that will ensure minimal risk of future exposure. Cleaning is not always the ideal remediation. A PC as infected as this one with the most malicious types of malware - it is a prime example of when cleaning is not a recommendation. -- It takes a disaster to make a woman out of a femaleMicrosoft MVP/Windows Security 2003-2007Proud Member of ASAP (Alliance of Security Analysis Professionals) |
|
  icex _ Premium join:2004-05-22 USA clubs:
·Colane Cable
1 edit | No, I do not mean paying anyone at dslreports.com. I have worked on this computer before and never accepted payment, but she gave me $25 for working on it anyway. She asked me how much I would charge and I said I'll see.
I don't realy have time to work on computers hardly anymore. Last year when I worked on this computer that was all I done, was worked on computers, because I enjoyed it. Now, I workout everyday, and I enjoy doing other things, not working on computers much anymore. I hope this post doesent sound sarcastic or anything.
She told me these problems have been going on for along time, and she could only use her daughters account. I am guessing there has been alot of stuff on here -- and it has downloaded all of this new stuff.
Thank you for taking your time to help me though. I realy do appreciate it. If I was still into computers like I use to be, then I probaly wouldent care to fix it for nothing. But like I said, I workout everday and like doing other things. We just got a boat, but I'm trying to fix this, which is taking time from me.
I'm not going to rip someone off when I fix their computer. When I use to work on computers, I never asked for anything, and still don't, they just ask me for a price. I try to be fair; computer shops would charge atleast $120 for what I am doing right now. I hope you understand, and thank you again for your help.
Edit to add: I always give a speech to people about security, and show them how to use their anti virus/anti spyware when I install it. |
|
  CalamityJane Premium,VIP,MVM join:2002-08-27 Eustis, FL
| You're welcome. You sound like good guy so I think you would not take advantage of our volunteer services here. My biggest concern is the severe nature of the infections found on this PC. If it has been going on a while that makes it even worse. -- It takes a disaster to make a woman out of a femaleMicrosoft MVP/Windows Security 2003-2007Proud Member of ASAP (Alliance of Security Analysis Professionals) |
|
  icex _ Premium join:2004-05-22 USA clubs:
·Colane Cable
1 edit | I'm only 16 to be honest. Started doing computer work when I was eleven pretty much, got tired of it last year.
Yes, I don't know if she will or not, but I told her to contact the debit card company, and to watch her credit report for awhile.
And, no I won't take advantage of anyone here. I realy wasent planning on comming here; because I've fixed about 3 computers before with the exact problem, except they dident have backdoors and all that. But this computer is so bad, I had to get professional advice. |
|
  CalamityJane Premium,VIP,MVM join:2002-08-27 Eustis, FL | Glad we could help icex_  |
|
  icex _ Premium join:2004-05-22 USA clubs:
·Colane Cable
| I just want to ask one more thing.
So far I have installed Avast! antivirus, AVG anti spyware, Spybot - Search and destroy, Tea-timer, and Ad-aware. Does avast have automatic protection like AVG? I'm getting ready to install AVG for the real-time protection, if Avast! doesent. -- Team Discovery |
|