Jump to content

Malwarebytes

Vundo keeps coming back

- - - - -

10 replies to this topic

#1
Cboggie

    New Member

  • Members
  • Pip
  • 5 posts
Hey hey,

Im having a problem with vundo.

Ive ran MB and it has removed it several times, however it keeps coming back. Here is my info:

Malwarebytes' Anti-Malware 1.41
Database version: 3027
Windows 5.1.2600 Service Pack 3

10/25/2009 3:18:30 PM
mbam-log-2009-10-25 (15-18-30).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 309316
Time elapsed: 1 hour(s), 58 minute(s), 35 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 2
Files Infected: 10

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Documents and Settings\All Users\Application Data\11428016 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\73831527 (Rogue.Multiple) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\dedovewu.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jatupuni.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pasusowi.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pukoluda.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\virinida.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vugupive.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\7zS38B.tmp\sisa.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dosewomu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jevetedo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lifigote.dll (Trojan.Vundo) -> Quarantined and deleted successfully.



Hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:46:01 PM, on 10/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\pipc\BIN\pilogsrv.exe
C:\Program Files\pipc\BIN\pinetmgr.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\n52te\n52teHid.exe
C:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\pipc\BIN\pimsgss.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\n52te\n52teTra.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\malyware bytes\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gatewaybiz.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gatewaybiz.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Jomantha] C:\Program Files\n52te\n52teHid.exe
O4 - HKLM\..\Run: [SteelSeries World of Warcraft MMO Gaming Mouse] C:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\malyware bytes\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [jasapabiw] Rundll32.exe "c:\windows\system32\folihaho.dll",a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: c:\windows\system32\wugubulu.dll setakiwo.dll c:\windows\system32\folihaho.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 - SSODL: zutumetez - {e81a7026-a994-4352-a73d-191c3e76aa52} - c:\windows\system32\folihaho.dll
O22 - SharedTaskScheduler: gahurihor - {00979b42-384f-496c-817d-3436d06568d6} - (no file)
O22 - SharedTaskScheduler: kupuhivus - {e81a7026-a994-4352-a73d-191c3e76aa52} - c:\windows\system32\folihaho.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: PI-Buffer Server (bufserv) - OSIsoft, Inc. - C:\Program Files\pipc\BIN\bufserv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9eac357cb13be) (gupdate1c9eac357cb13be) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Ghost - Unknown owner - C:\Program Files\Norton Ghost\Agent\VProSvc.exe (file missing)
O23 - Service: PIPC Log Server (pilogsrv) - OSIsoft, Inc. - C:\Program Files\pipc\BIN\pilogsrv.exe
O23 - Service: PI Message Subsystem (pimsgss) - OSIsoft, Inc. - C:\Program Files\pipc\BIN\pimsgss.exe
O23 - Service: PI Network Manager (pinetmgr) - OSIsoft, Inc. - C:\Program Files\pipc\BIN\pinetmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: SymSnapService - Unknown owner - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe (file missing)
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

--
End of file - 9862 bytes

Thanks!

#2
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Hi,

First of all, please update MalwareBytes, because the databaseversion is outdated.

  • Start MalwareBytes and click the Update tab. There click "Check for updates"
  • Once the updates are downloaded, perform a quick scan again.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply along with a fresh HijackThis log, then we'll proceed from there with new steps.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
Cboggie

    New Member

  • Members
  • Pip
  • 5 posts
Hi,

Thanks and here is the info in the log:

Malwarebytes' Anti-Malware 1.41
Database version: 3037
Windows 5.1.2600 Service Pack 3

10/26/2009 5:08:09 PM
mbam-log-2009-10-26 (17-08-09).txt

Scan type: Quick Scan
Objects scanned: 114305
Time elapsed: 8 minute(s), 49 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 4
Registry Keys Infected: 1
Registry Values Infected: 3
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 13

Memory Processes Infected:
C:\WINDOWS\system32\zafufura.exe (Trojan.Dropper) -> Unloaded process successfully.

Memory Modules Infected:
c:\WINDOWS\system32\givijomu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\viyekelo.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\wuvajepe.dll (Trojan.Vundo) -> Delete on reboot.
c:\WINDOWS\system32\folihaho.dll (Trojan.Vundo.N) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{6b3c76fe-aae7-49ea-96be-e8a29d93c962} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jasapabiw (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{6b3c76fe-aae7-49ea-96be-e8a29d93c962} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\yulosehal (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\givijomu.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\givijomu.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.N) -> Data: c:\windows\system32\folihaho.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.N) -> Data: system32\folihaho.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\givijomu.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\zafufura.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tedorova.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rabuvuti.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\7zS25.tmp\sisa.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\7zS2F.tmp\sisa.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\7zS30.tmp\sisa.exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\boyimeta.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\viyekelo.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\wuvajepe.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\zohutuzo.dll (Trojan.Vundo.N) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\siyipino.dll (Trojan.Vundo.N) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\folihaho.dll (Trojan.Vundo.N) -> Delete on reboot.

And a hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:10:48 PM, on 10/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\pipc\BIN\pilogsrv.exe
C:\Program Files\pipc\BIN\pinetmgr.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\n52te\n52teHid.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\pipc\BIN\pimsgss.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe
C:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMTray.exe
C:\Program Files\n52te\n52teTra.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\malyware bytes\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gatewaybiz.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gatewaybiz.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Jomantha] C:\Program Files\n52te\n52teHid.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\malyware bytes\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SteelSeries World of Warcraft MMO Gaming Mouse] C:\Program Files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [jasapabiw] Rundll32.exe "c:\windows\system32\givijomu.dll",a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gatew...r/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: c:\windows\system32\wugubulu.dll ,viyekelo.dll c:\windows\system32\givijomu.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O21 - SSODL: yulosehal - {6b3c76fe-aae7-49ea-96be-e8a29d93c962} - c:\windows\system32\givijomu.dll
O22 - SharedTaskScheduler: gahurihor - {00979b42-384f-496c-817d-3436d06568d6} - (no file)
O22 - SharedTaskScheduler: kupuhivus - {6b3c76fe-aae7-49ea-96be-e8a29d93c962} - c:\windows\system32\givijomu.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: PI-Buffer Server (bufserv) - OSIsoft, Inc. - C:\Program Files\pipc\BIN\bufserv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9eac357cb13be) (gupdate1c9eac357cb13be) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Ghost - Unknown owner - C:\Program Files\Norton Ghost\Agent\VProSvc.exe (file missing)
O23 - Service: PIPC Log Server (pilogsrv) - OSIsoft, Inc. - C:\Program Files\pipc\BIN\pilogsrv.exe
O23 - Service: PI Message Subsystem (pimsgss) - OSIsoft, Inc. - C:\Program Files\pipc\BIN\pimsgss.exe
O23 - Service: PI Network Manager (pinetmgr) - OSIsoft, Inc. - C:\Program Files\pipc\BIN\pinetmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: SymSnapService - Unknown owner - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe (file missing)
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

--
End of file - 10196 bytes

#4
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Hi,

I need to collect some files here as well...

* Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingc...to-use-combofix

Post the log from ComboFix in your next reply.

Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix..This because Security Software may see some components ComboFix uses (prep.com for example) as suspicious and blocks the tool, or even deletes it. Please visit HERE if you don't know how.
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#5
Cboggie

    New Member

  • Members
  • Pip
  • 5 posts
AVG would not delete or uninstall for some reason.




ComboFix 09-10-26.03 - Owner 10/27/2009 9:03.3.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1534.994 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\bakivige.dll
c:\windows\system32\dedavafa.dll.tmp
c:\windows\system32\dukokoyu.dll.tmp
c:\windows\system32\figasibu.dll
c:\windows\system32\fimofago.dll
c:\windows\system32\gowarihi.dll.tmp
c:\windows\system32\hilavabi.dll
c:\windows\system32\huvajolu.exe
c:\windows\system32\jayoriji.dll
c:\windows\system32\kijudawi.dll
c:\windows\system32\lovoduto.dll
c:\windows\system32\lulekosa.dll.tmp
c:\windows\system32\mefozajo.dll
c:\windows\system32\rilaneti.dll
c:\windows\system32\rivonugo.dll
c:\windows\system32\sejosobi.dll
c:\windows\system32\setakiwo.dll.tmp
c:\windows\system32\sezogibe.exe
c:\windows\system32\vulotusa.dll.tmp
c:\windows\system32\wadovobu.dll
c:\windows\system32\wenihubi.dll
c:\windows\system32\yiborewa.dll
c:\windows\system32\zipetepi.dll

.
((((((((((((((((((((((((( Files Created from 2009-09-27 to 2009-10-27 )))))))))))))))))))))))))))))))
.

2009-10-26 14:40 . 2008-04-15 14:05 11136 ----a-w- c:\windows\system32\drivers\Mo3Fltr.sys
2009-10-26 14:39 . 2009-10-26 14:39 -------- d-----w- c:\program files\SteelSeries
2009-10-17 14:08 . 2009-10-17 14:09 -------- d-----w- c:\program files\malyware bytes
2009-10-17 06:13 . 2009-10-17 06:13 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-17 06:10 . 2009-10-17 06:26 -------- d-----w- c:\documents and settings\Administrator.CHADLAPTOP\.housecall6.6
2009-10-17 06:08 . 2009-10-17 06:08 -------- d-----w- c:\documents and settings\Administrator.CHADLAPTOP\Application Data\play2p
2009-10-17 06:06 . 2009-10-17 06:06 -------- d-----w- c:\program files\Get rid11
2009-10-17 06:04 . 2009-10-17 06:05 -------- d-----w- c:\program files\Get rid
2009-10-17 06:02 . 2009-10-17 06:02 -------- d-----w- c:\documents and settings\Administrator.CHADLAPTOP\Application Data\Malwarebytes
2009-10-17 06:02 . 2009-10-17 06:02 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2009-10-17 05:48 . 2009-10-17 05:48 -------- d-----w- c:\documents and settings\Administrator.CHADLAPTOP\Local Settings\Application Data\Mozilla
2009-10-17 04:58 . 2009-10-19 22:14 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-10-17 04:56 . 2009-10-17 04:56 -------- d-----w- c:\program files\Common Files\iS3
2009-10-17 04:56 . 2009-10-21 21:10 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-10-17 04:47 . 2009-10-17 06:10 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-10-17 04:47 . 2009-10-17 04:49 -------- d-----w- c:\documents and settings\Owner\.housecall6.6
2009-10-10 07:35 . 2009-10-10 07:35 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Rawr
2009-09-30 15:40 . 2009-09-30 15:40 -------- d-----w- c:\program files\SystemRequirementsLab
2009-09-30 15:40 . 2009-09-30 15:40 -------- d-----w- c:\documents and settings\Owner\Application Data\SystemRequirementsLab

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-27 13:23 . 2008-12-20 07:09 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-26 21:50 . 2008-09-28 05:05 -------- d-----w- c:\program files\Google
2009-10-21 21:06 . 2009-08-29 17:46 -------- dc-h--w- c:\documents and settings\All Users\Application Data\~0
2009-10-21 21:06 . 2008-12-20 21:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-21 21:04 . 2009-10-21 21:03 1352 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-10-20 17:04 . 2008-09-28 05:31 70400 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-20 07:44 . 2008-09-28 05:04 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-17 06:08 . 2009-06-11 12:57 -------- d--h--w- c:\program files\InstallJammer Registry
2009-10-17 06:01 . 2008-12-21 01:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-16 01:35 . 2008-09-27 23:28 -------- d-----w- c:\program files\World of Warcraft
2009-10-15 08:07 . 2009-06-17 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-07 22:07 . 2008-10-05 21:10 -------- d-----w- c:\program files\Keyclone
2009-09-29 08:06 . 2009-06-17 22:31 -------- d-----w- c:\program files\Microsoft Works
2009-09-25 05:37 . 2004-08-26 16:12 667136 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:37 . 2004-08-26 16:11 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-19 23:47 . 2009-04-03 14:12 -------- d-----w- c:\documents and settings\Owner\Application Data\uTorrent
2009-09-12 22:27 . 2009-09-12 22:27 -------- d-----w- c:\documents and settings\Owner\Application Data\n52te
2009-09-12 22:27 . 2008-10-24 21:00 -------- d-----w- c:\program files\n52te
2009-09-12 22:26 . 2009-09-12 22:26 -------- d-----w- c:\documents and settings\Owner\Application Data\InstallShield
2009-09-11 14:18 . 2004-08-26 16:12 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 04:35 . 2009-04-04 16:29 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-10 19:54 . 2008-12-21 01:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 19:53 . 2008-12-21 01:55 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:03 . 2004-08-26 16:12 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-01 19:24 . 2009-05-12 17:27 -------- d-----w- c:\program files\Yahoo!
2009-08-29 17:45 . 2009-08-29 17:45 -------- d-----w- c:\program files\Lavasoft
2009-08-29 17:43 . 2008-12-09 15:02 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-28 15:03 . 2009-03-04 22:41 -------- d-----w- c:\program files\DivX
2009-08-28 15:02 . 2009-06-11 18:34 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-08-28 13:12 . 2008-12-20 07:10 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-28 13:12 . 2008-12-20 07:10 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-28 13:12 . 2008-12-20 07:10 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-26 08:00 . 2004-08-26 16:12 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 04:33 . 2009-08-18 04:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-05 09:01 . 2004-08-26 16:12 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 01:44 . 2004-08-26 16:12 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-04 05:59 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-07-14 00:16 . 2009-07-14 00:16 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-07-14 00:16 . 2009-07-14 00:16 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-07-25 17:37 . 2009-07-25 17:37 38400 --sha-w- c:\windows\system32\batusoka.dll
2009-07-26 05:37 . 2009-07-26 05:37 89600 --sha-w- c:\windows\system32\dorugeba.dll
2009-07-23 05:35 . 2009-07-23 05:35 37888 --sha-w- c:\windows\system32\hudunini.dll
2009-07-22 05:35 . 2009-07-22 05:35 89088 --sha-w- c:\windows\system32\leliwomu.dll
2009-07-22 05:35 . 2009-07-22 05:35 38400 --sha-w- c:\windows\system32\pufidihu.dll
2009-07-21 17:35 . 2009-07-21 17:35 51200 --sha-w- c:\windows\system32\puzohilo.dll
2009-07-22 17:35 . 2009-07-22 17:35 37888 --sha-w- c:\windows\system32\reditika.dll
2009-07-24 17:37 . 2009-07-24 17:37 38912 --sha-w- c:\windows\system32\retulama.dll
2009-07-26 17:38 . 2009-07-26 17:38 51712 --sha-w- c:\windows\system32\vihobuwu.dll
2009-07-24 05:36 . 2009-07-24 05:36 38400 --sha-w- c:\windows\system32\vubitese.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-29 344064]
"Jomantha"="c:\program files\n52te\n52teHid.exe" [2008-06-13 159744]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\malyware bytes\mbam.exe" [2009-09-10 1312080]
"SteelSeries World of Warcraft MMO Gaming Mouse"="c:\program files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe" [2009-09-09 414720]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-10-10 69632]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-18 4742184]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-11-07 22:41 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 13:12 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Install Pending Files.LNK]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Install Pending Files.LNK
backup=c:\windows\pss\Install Pending Files.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Nostromo Loadout Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Nostromo Loadout Manager.lnk
backup=c:\windows\pss\Nostromo Loadout Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^play2p.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\play2p.lnk
backup=c:\windows\pss\play2p.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^WD Anywhere Backup Launcher.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\WD Anywhere Backup Launcher.lnk
backup=c:\windows\pss\WD Anywhere Backup Launcher.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\Installs, Upgrades, Etc\\WoW-BurningCrusade-enUS-Installer-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.3.0-enUS-downloader.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\Keyclone\\keyclone.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/20/2008 2:10 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/20/2008 2:10 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [12/20/2008 2:09 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/20/2008 2:09 AM 297752]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2/12/2009 11:43 PM 10384]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [8/26/2004 11:11 AM 5120]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [4/24/2009 6:57 AM 92008]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [5/16/2008 5:12 PM 102400]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [9/27/2008 11:54 PM 200192]
R3 JmtFltr;n52te;c:\windows\system32\drivers\JmtFltr.sys [9/12/2009 5:27 PM 48896]
R3 Mo3Fltr;MMO Mouse;c:\windows\system32\drivers\Mo3Fltr.sys [10/26/2009 9:40 AM 11136]
S2 gupdate1c9eac357cb13be;Google Update Service (gupdate1c9eac357cb13be);c:\program files\Google\Update\GoogleUpdate.exe [6/11/2009 1:35 PM 133104]
S3 AMDMSRIO;AMDMSRIO;\??\c:\docume~1\Owner\LOCALS~1\Temp\Safe To Delete 3_0_4_8\AMDMSRIO.sys --> c:\docume~1\Owner\LOCALS~1\Temp\Safe To Delete 3_0_4_8\AMDMSRIO.sys [?]
S3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys [9/27/2008 8:14 PM 23040]
S3 SymSnapService;SymSnapService;"c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe" --> c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [?]

--- Other Services/Drivers In Memory ---

*Deregistered* - mbr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\PI_Install]
"f:\source\Library\Global Packages\PI ProcessBook 3.0.15.7-SDK 1.3.5.338-DataLink 3.1.6\Source\PI DataLink 3.1.6\Source\install_add_in.exe" /s /agregar

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{099C18DA-7ADC-4CC6-9361-EAD433795970}]
"c:\windows\system32\install_add_in.exe" /s /agregar
.
Contents of the 'Scheduled Tasks' folder

2009-10-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2009-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-11 18:34]

2009-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-11 18:34]

2008-09-28 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-26 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.gateway.com/
mStart Page = hxxp://www.gatewaybiz.com
uInternet Connection Wizard,ShellNext = hxxp://www.gatewaybiz.com/
uInternet Settings,ProxyOverride = *.local
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\l5gp6j6u.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.chadandkatie.com/portal.php
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\l5gp6j6u.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

BHO-{cf839829-9fb2-46f5-94e6-d9150693f376} - wuvajepe.dll
Toolbar-SITEguard - (no file)
HKLM-Run-jasapabiw - c:\windows\system32\lovoduto.dll
HKLM-Run-molokedisi - rivonugo.dll
SharedTaskScheduler-{00979b42-384f-496c-817d-3436d06568d6} - (no file)
SharedTaskScheduler-{6fd30227-7503-44ff-b601-75b4418c119c} - c:\windows\system32\lovoduto.dll
SSODL-makesedew-{6fd30227-7503-44ff-b601-75b4418c119c} - c:\windows\system32\lovoduto.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-27 09:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(860)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(3644)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\pipc\BIN\pilogsrv.exe
c:\program files\pipc\BIN\pinetmgr.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\pipc\BIN\pimsgss.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\msdtc.exe
c:\combofix\CF8764.exe
c:\program files\n52te\n52teTra.exe
c:\program files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMTray.exe
c:\combofix\PEV.cfxxe
.
**************************************************************************
.
Completion time: 2009-10-27 9:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-27 14:26
ComboFix2.txt 2009-01-03 04:58
ComboFix3.txt 2008-12-23 16:39

Pre-Run: 10,741,858,304 bytes free
Post-Run: 11,931,320,320 bytes free

- - End Of File - - 52BD33B124880A6964DBF6DD02C3958E

#6
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Hi,

You didn't have to delete or uninstall AVG, just disable it.
Please open the AVG 8 Control Center, by right clicking on the AVG 8 icon on task bar.

* Click on Tools.
* Select Advanced.
* In the left hand pane, scroll down to "Resident Shield".
* In the main pane, deselect the option to "Enable Resident Shield."
* To re-enable AVG 8, please select "Enable Resident Shield" again.

Then, * Open notepad - don't use any other texteditor than notepad or the script will fail.
Copy/paste the text in the quotebox below into notepad:

Quote

Collect::[8]
c:\windows\system32\batusoka.dll
c:\windows\system32\dorugeba.dll
c:\windows\system32\hudunini.dll
c:\windows\system32\leliwomu.dll
c:\windows\system32\pufidihu.dll
c:\windows\system32\puzohilo.dll
c:\windows\system32\reditika.dll
c:\windows\system32\retulama.dll
c:\windows\system32\vihobuwu.dll
c:\windows\system32\vubitese.dll
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
%windir%\\system32\\drivers\\svchost.exe"=-

Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again.
Then, please visit this site:
http://www.bleepingc...e.php?channel=8
Where it says: "Browse to the file you want to submit", use the Browse button to navigate to the following file: C:\Qoobox\Quarantine\[8]-Submit_date_time.zip (date_time will be replaced with the date and time when this file was created)
Then click the "Send File" button below in order to upload it.

After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7
Cboggie

    New Member

  • Members
  • Pip
  • 5 posts
Send the file to bleeping computer..


ComboFix 09-10-26.03 - Owner 10/27/2009 9:50.4.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1534.833 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\cfscript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: c:\windows\system32\batusoka.dll
file zipped: c:\windows\system32\dorugeba.dll
file zipped: c:\windows\system32\hudunini.dll
file zipped: c:\windows\system32\leliwomu.dll
file zipped: c:\windows\system32\pufidihu.dll
file zipped: c:\windows\system32\puzohilo.dll
file zipped: c:\windows\system32\reditika.dll
file zipped: c:\windows\system32\retulama.dll
file zipped: c:\windows\system32\vihobuwu.dll
file zipped: c:\windows\system32\vubitese.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\batusoka.dll
c:\windows\system32\dorugeba.dll
c:\windows\system32\hudunini.dll
c:\windows\system32\leliwomu.dll
c:\windows\system32\pufidihu.dll
c:\windows\system32\puzohilo.dll
c:\windows\system32\reditika.dll
c:\windows\system32\retulama.dll
c:\windows\system32\vihobuwu.dll
c:\windows\system32\vubitese.dll

.
((((((((((((((((((((((((( Files Created from 2009-09-27 to 2009-10-27 )))))))))))))))))))))))))))))))
.

2009-10-26 14:40 . 2008-04-15 14:05 11136 ----a-w- c:\windows\system32\drivers\Mo3Fltr.sys
2009-10-26 14:39 . 2009-10-26 14:39 -------- d-----w- c:\program files\SteelSeries
2009-10-17 14:08 . 2009-10-17 14:09 -------- d-----w- c:\program files\malyware bytes
2009-10-17 06:13 . 2009-10-17 06:13 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-17 06:10 . 2009-10-17 06:26 -------- d-----w- c:\documents and settings\Administrator.CHADLAPTOP\.housecall6.6
2009-10-17 06:08 . 2009-10-17 06:08 -------- d-----w- c:\documents and settings\Administrator.CHADLAPTOP\Application Data\play2p
2009-10-17 06:06 . 2009-10-17 06:06 -------- d-----w- c:\program files\Get rid11
2009-10-17 06:04 . 2009-10-17 06:05 -------- d-----w- c:\program files\Get rid
2009-10-17 06:02 . 2009-10-17 06:02 -------- d-----w- c:\documents and settings\Administrator.CHADLAPTOP\Application Data\Malwarebytes
2009-10-17 06:02 . 2009-10-17 06:02 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2009-10-17 05:48 . 2009-10-17 05:48 -------- d-----w- c:\documents and settings\Administrator.CHADLAPTOP\Local Settings\Application Data\Mozilla
2009-10-17 04:58 . 2009-10-19 22:14 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-10-17 04:56 . 2009-10-17 04:56 -------- d-----w- c:\program files\Common Files\iS3
2009-10-17 04:56 . 2009-10-21 21:10 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-10-17 04:47 . 2009-10-17 06:10 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-10-17 04:47 . 2009-10-17 04:49 -------- d-----w- c:\documents and settings\Owner\.housecall6.6
2009-10-10 07:35 . 2009-10-10 07:35 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Rawr
2009-09-30 15:40 . 2009-09-30 15:40 -------- d-----w- c:\program files\SystemRequirementsLab
2009-09-30 15:40 . 2009-09-30 15:40 -------- d-----w- c:\documents and settings\Owner\Application Data\SystemRequirementsLab

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-27 13:23 . 2008-12-20 07:09 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-26 21:50 . 2008-09-28 05:05 -------- d-----w- c:\program files\Google
2009-10-21 21:06 . 2009-08-29 17:46 -------- dc-h--w- c:\documents and settings\All Users\Application Data\~0
2009-10-21 21:06 . 2008-12-20 21:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-21 21:04 . 2009-10-21 21:03 1352 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-10-20 17:04 . 2008-09-28 05:31 70400 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-20 07:44 . 2008-09-28 05:04 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-17 06:08 . 2009-06-11 12:57 -------- d--h--w- c:\program files\InstallJammer Registry
2009-10-17 06:01 . 2008-12-21 01:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-16 01:35 . 2008-09-27 23:28 -------- d-----w- c:\program files\World of Warcraft
2009-10-15 08:07 . 2009-06-17 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-07 22:07 . 2008-10-05 21:10 -------- d-----w- c:\program files\Keyclone
2009-09-29 08:06 . 2009-06-17 22:31 -------- d-----w- c:\program files\Microsoft Works
2009-09-25 05:37 . 2004-08-26 16:12 667136 ------w- c:\windows\system32\wininet.dll
2009-09-25 05:37 . 2004-08-26 16:11 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-19 23:47 . 2009-04-03 14:12 -------- d-----w- c:\documents and settings\Owner\Application Data\uTorrent
2009-09-12 22:27 . 2009-09-12 22:27 -------- d-----w- c:\documents and settings\Owner\Application Data\n52te
2009-09-12 22:27 . 2008-10-24 21:00 -------- d-----w- c:\program files\n52te
2009-09-12 22:26 . 2009-09-12 22:26 -------- d-----w- c:\documents and settings\Owner\Application Data\InstallShield
2009-09-11 14:18 . 2004-08-26 16:12 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 04:35 . 2009-04-04 16:29 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-10 19:54 . 2008-12-21 01:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 19:53 . 2008-12-21 01:55 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:03 . 2004-08-26 16:12 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-01 19:24 . 2009-05-12 17:27 -------- d-----w- c:\program files\Yahoo!
2009-08-29 17:45 . 2009-08-29 17:45 -------- d-----w- c:\program files\Lavasoft
2009-08-29 17:43 . 2008-12-09 15:02 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-28 15:03 . 2009-03-04 22:41 -------- d-----w- c:\program files\DivX
2009-08-28 15:02 . 2009-06-11 18:34 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-08-28 13:12 . 2008-12-20 07:10 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-28 13:12 . 2008-12-20 07:10 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-28 13:12 . 2008-12-20 07:10 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-26 08:00 . 2004-08-26 16:12 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 04:33 . 2009-08-18 04:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-05 09:01 . 2004-08-26 16:12 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 01:44 . 2004-08-26 16:12 2189184 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-04 05:59 2066048 ------w- c:\windows\system32\ntkrnlpa.exe
2009-07-14 00:16 . 2009-07-14 00:16 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-07-14 00:16 . 2009-07-14 00:16 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-29 344064]
"Jomantha"="c:\program files\n52te\n52teHid.exe" [2008-06-13 159744]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\malyware bytes\mbam.exe" [2009-09-10 1312080]
"SteelSeries World of Warcraft MMO Gaming Mouse"="c:\program files\SteelSeries\World of Warcraft MMO Gaming Mouse\WoWMHID.exe" [2009-09-09 414720]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-10-10 69632]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-18 4742184]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-11-07 22:41 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 13:12 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Install Pending Files.LNK]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Install Pending Files.LNK
backup=c:\windows\pss\Install Pending Files.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Nostromo Loadout Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Nostromo Loadout Manager.lnk
backup=c:\windows\pss\Nostromo Loadout Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^play2p.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\play2p.lnk
backup=c:\windows\pss\play2p.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^WD Anywhere Backup Launcher.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\WD Anywhere Backup Launcher.lnk
backup=c:\windows\pss\WD Anywhere Backup Launcher.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\Installs, Upgrades, Etc\\WoW-BurningCrusade-enUS-Installer-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.3.0-enUS-downloader.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\Keyclone\\keyclone.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/20/2008 2:10 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/20/2008 2:10 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [12/20/2008 2:09 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/20/2008 2:09 AM 297752]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2/12/2009 11:43 PM 10384]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [8/26/2004 11:11 AM 5120]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [4/24/2009 6:57 AM 92008]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [5/16/2008 5:12 PM 102400]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [9/27/2008 11:54 PM 200192]
R3 JmtFltr;n52te;c:\windows\system32\drivers\JmtFltr.sys [9/12/2009 5:27 PM 48896]
R3 Mo3Fltr;MMO Mouse;c:\windows\system32\drivers\Mo3Fltr.sys [10/26/2009 9:40 AM 11136]
S2 gupdate1c9eac357cb13be;Google Update Service (gupdate1c9eac357cb13be);c:\program files\Google\Update\GoogleUpdate.exe [6/11/2009 1:35 PM 133104]
S3 AMDMSRIO;AMDMSRIO;\??\c:\docume~1\Owner\LOCALS~1\Temp\Safe To Delete 3_0_4_8\AMDMSRIO.sys --> c:\docume~1\Owner\LOCALS~1\Temp\Safe To Delete 3_0_4_8\AMDMSRIO.sys [?]
S3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys [9/27/2008 8:14 PM 23040]
S3 SymSnapService;SymSnapService;"c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe" --> c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [?]

--- Other Services/Drivers In Memory ---

*Deregistered* - mbr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\PI_Install]
"f:\source\Library\Global Packages\PI ProcessBook 3.0.15.7-SDK 1.3.5.338-DataLink 3.1.6\Source\PI DataLink 3.1.6\Source\install_add_in.exe" /s /agregar

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{099C18DA-7ADC-4CC6-9361-EAD433795970}]
"c:\windows\system32\install_add_in.exe" /s /agregar
.
Contents of the 'Scheduled Tasks' folder

2009-10-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2009-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-11 18:34]

2009-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-11 18:34]

2008-09-28 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-26 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.gateway.com/
mStart Page = hxxp://www.gatewaybiz.com
uInternet Connection Wizard,ShellNext = hxxp://www.gatewaybiz.com/
uInternet Settings,ProxyOverride = *.local
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\l5gp6j6u.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.chadandkatie.com/portal.php
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\l5gp6j6u.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-27 09:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(860)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2009-10-27 9:58
ComboFix-quarantined-files.txt 2009-10-27 14:57
ComboFix2.txt 2009-10-27 14:26
ComboFix3.txt 2009-01-03 04:58
ComboFix4.txt 2008-12-23 16:39

Pre-Run: 11,915,431,936 bytes free
Post-Run: 11,900,563,456 bytes free

- - End Of File - - A141ABBB5DAE3EE96CE8CD0A359F115E
Upload was successful

#8
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Hi,

Thanks for the files.

This log looks OK again. :blush:

* Go to start > run and copy and paste next command in the field:

ComboFix /Uninstall

Make sure there's a space between Combofix and /
Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

Let me know in your next reply how things are now.
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
Cboggie

    New Member

  • Members
  • Pip
  • 5 posts
i have already noticed a huge difference. I was having serious lag when browsing. Seems great so far, thanks!

#10
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Glad I could help. :)

Please read my Prevention page with lots of info and tips how to prevent this in the future.
And if you want to improve speed/system performance after malware removal, take a look here.
Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan.

Happy Surfing again!
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#11
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Since this issue appears resolved ... this Topic is closed.
If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us