1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Active Another Google hijack victim

Discussion in 'Malware and Virus Removal Archive' started by twofanman, 2008/12/22.

  1. 2008/12/22
    twofanman Lifetime Subscription

    twofanman Inactive Thread Starter

    Joined:
    2008/12/22
    Messages:
    31
    Likes Received:
    0
    [Active] Another Google hijack victim

    So my google page suddenly has larger font and when I click on links on the page, I get sent to spam sites. Also, hovering over a link on the Google page won't show the URL I'm to be directed to. Just updated my computer with all kinds of microsoft updates a few days ago. Also updated JAVA.

    After some research today, I see that others are having the same problems as me. One thing I saw was that JAVA might be a portal and was recommended to remove. So I did that this morning with Microsoft Uninstall utility. Still no help.

    Then I found this site and read a few threads. I'm impressed with the generous help available here. So, having made my introductions, I'm hoping you can help. TIA. Downloaded RSIT and ComboFix and ran them. Couldn't install Recovery Console.

    Here is my RSIT log file:

    Logfile of random's system information tool 1.05 (written by random/random)
    Run by WP Lanius at 2008-12-22 13:58:49
    Microsoft Windows XP Professional Service Pack 3
    System drive C: has 69 GB (43%) free of 160 GB
    Total RAM: 2047 MB (82% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:58:53 PM, on 12/22/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\Documents and Settings\WP Lanius\Desktop\RSIT.exe
    C:\Program Files\trend micro\WP Lanius.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe "
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.3\IExifMap.htm
    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.3\IExifCom.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
    O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
    O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe

    --
    End of file - 5711 bytes

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll [2008-10-08 652784]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "SoundMAXPnP "=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-05-17 843776]
    "JMB36X Configure "=C:\WINDOWS\system32\JMRaidTool.exe [2006-06-02 385024]
    "NeroFilterCheck "=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
    "NvCplDaemon "=C:\WINDOWS\system32\NvCpl.dll [2006-08-11 7630848]
    "nwiz "=nwiz.exe /install []
    "NvMediaCenter "=C:\WINDOWS\system32\NvMcTray.dll [2006-08-11 86016]
    "QuickTime Task "=C:\Program Files\QuickTime\qttask.exe [2007-06-29 286720]
    "Adobe Reader Speed Launcher "=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
    "RoxWatchTray "=C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2007-08-16 236016]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    NkvMon.exe.lnk - C:\Program Files\Nikon\NkView6\NkvMon.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername "=0
    "legalnoticecaption "=
    "legalnoticetext "=
    "shutdownwithoutlogon "=1
    "undockwithoutlogon "=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun "=323
    "NoDriveAutoRun "=67108863
    "NoDrives "=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveAutoRun "=
    "NoDriveTypeAutoRun "=
    "NoDrives "=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "
    "C:\Program Files\Ipswitch\WS_FTP Professional\wsftpgui.exe "= "C:\Program Files\Ipswitch\WS_FTP Professional\wsftpgui.exe:*:Enabled:WS_FTP Pro Application "

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "

    ======List of files/folders created in the last 1 months======

    2008-12-22 13:58:49 ----D---- C:\rsit
    2008-12-22 13:58:49 ----D---- C:\Program Files\trend micro
    2008-12-22 13:50:53 ----A---- C:\log200812221350 rambofix.txt
    2008-12-22 13:48:38 ----D---- C:\WINDOWS\temp
    2008-12-22 13:48:37 ----A---- C:\ComboFix.txt
    2008-12-22 13:35:44 ----A---- C:\WINDOWS\zip.exe
    2008-12-22 13:35:44 ----A---- C:\WINDOWS\VFIND.exe
    2008-12-22 13:35:44 ----A---- C:\WINDOWS\SWXCACLS.exe
    2008-12-22 13:35:44 ----A---- C:\WINDOWS\SWSC.exe
    2008-12-22 13:35:44 ----A---- C:\WINDOWS\SWREG.exe
    2008-12-22 13:35:44 ----A---- C:\WINDOWS\sed.exe
    2008-12-22 13:35:44 ----A---- C:\WINDOWS\NIRCMD.exe
    2008-12-22 13:35:44 ----A---- C:\WINDOWS\grep.exe
    2008-12-22 13:35:44 ----A---- C:\WINDOWS\fdsv.exe
    2008-12-22 13:35:33 ----D---- C:\RamboFix
    2008-12-22 13:35:06 ----D---- C:\WINDOWS\ERDNT
    2008-12-22 13:35:06 ----D---- C:\Qoobox
    2008-12-20 08:15:16 ----A---- C:\WINDOWS\system32\deploytk.dll
    2008-12-20 08:07:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
    2008-12-20 08:07:06 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
    2008-12-20 08:07:02 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
    2008-12-20 08:06:58 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
    2008-12-20 08:06:53 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
    2008-12-20 08:05:24 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
    2008-12-20 08:05:20 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
    2008-12-20 08:05:15 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
    2008-12-20 08:04:59 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
    2008-12-20 08:04:36 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
    2008-12-20 08:04:33 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
    2008-12-20 08:04:29 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
    2008-12-20 08:04:25 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
    2008-12-20 08:04:21 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
    2008-12-20 08:04:16 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$

    ======List of files/folders modified in the last 1 months======

    2008-12-22 13:58:49 ----RD---- C:\Program Files
    2008-12-22 13:52:33 ----D---- C:\WINDOWS\Prefetch
    2008-12-22 13:48:39 ----D---- C:\WINDOWS\system32
    2008-12-22 13:48:38 ----D---- C:\WINDOWS
    2008-12-22 13:46:18 ----A---- C:\WINDOWS\system.ini
    2008-12-22 13:44:16 ----D---- C:\WINDOWS\system32\drivers
    2008-12-22 13:44:14 ----D---- C:\WINDOWS\AppPatch
    2008-12-22 13:44:14 ----D---- C:\Program Files\Common Files
    2008-12-22 13:41:54 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-12-22 10:36:38 ----SHD---- C:\WINDOWS\Installer
    2008-12-22 10:36:38 ----HD---- C:\Config.Msi
    2008-12-22 10:36:38 ----D---- C:\Program Files\Java
    2008-12-22 09:34:27 ----D---- C:\Program Files\Mozilla Firefox
    2008-12-21 10:39:26 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-12-21 02:31:36 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
    2008-12-20 08:07:12 ----HD---- C:\WINDOWS\inf
    2008-12-20 08:07:11 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2008-12-20 08:07:10 ----HD---- C:\WINDOWS\$hf_mig$
    2008-12-20 08:07:09 ----A---- C:\WINDOWS\imsins.BAK
    2008-12-20 08:06:47 ----D---- C:\Program Files\Internet Explorer
    2008-12-20 08:06:32 ----D---- C:\WINDOWS\system32\CatRoot
    2008-12-20 08:04:34 ----D---- C:\WINDOWS\WinSxS
    2008-12-17 15:50:39 ----A---- C:\WINDOWS\win.ini
    2008-12-17 14:34:12 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
    2008-12-13 09:28:28 ----D---- C:\Documents and Settings\WP Lanius\Application Data\Lasersoft Imaging
    2008-12-12 23:40:02 ----A---- C:\WINDOWS\system32\mshtml.dll
    2008-12-09 15:24:38 ----A---- C:\WINDOWS\system32\MRT.exe
    2008-11-23 12:52:25 ----D---- C:\Photo Mechanic

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
    R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
    R3 ADIDTSFiltService;ADI DTS Filter Service; C:\WINDOWS\system32\drivers\adidts.sys [2006-06-15 142464]
    R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2006-05-02 229376]
    R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-04-26 93824]
    R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
    R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
    R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    R3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\LNE100V5.sys [2001-10-24 36224]
    R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
    R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-12 5810]
    R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-08-11 3958496]
    R3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 26496]
    R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2006-02-28 5888]
    R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    R4 catchme;catchme; \??\C:\RamboFix\catchme.sys []
    S3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-03 36224]
    S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-10-30 49920]
    S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-10-30 16496]
    S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-10-30 21568]
    S3 RimUsb;BlackBerry Smartphone; C:\WINDOWS\System32\Drivers\RimUsb.sys [2007-05-31 22656]
    S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
    S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
    S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
    S3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-05-23 245248]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-08 168432]
    R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-08-11 155715]
    R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
    R2 ScsiAccess;ScsiAccess; C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe [2007-11-27 181312]
    R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
    S2 Roxio Upnp Server 9;Roxio Upnp Server 9; C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe [2007-07-24 358896]
    S2 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe [2007-08-16 309744]
    S2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2007-08-16 166384]
    S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2007-04-18 72704]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
    S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-10-12 654848]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
    S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-06-22 208896]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 Roxio UPnP Renderer 9;Roxio UPnP Renderer 9; C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe [2007-07-24 88560]
    S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-08-16 1092080]
    S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]

    -----------------EOF-----------------
     
  2. 2008/12/22
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Welcome to WindowsBBS twofanman :)

    Please post the contents of the C:\ComboFix.txt log here. Give us an update on the computer's behavior after running ComboFix too, if you don't mind.
     

  3. to hide this advert.

  4. 2008/12/23
    twofanman Lifetime Subscription

    twofanman Inactive Thread Starter

    Joined:
    2008/12/22
    Messages:
    31
    Likes Received:
    0
    Hello and thanks for your warm welcome. I didn't see my thread post to the forum right away yesterday and then I had to go out. I've had a chance to check out the computer this morning and all appears to be working good so far. It's also seems to be much quicker. I didn't understand that ComboFix was actually a cleaner. I thought it was just a diagnostic tool. I ran that before I ran RSIT. Anyway here is the ComboFix log. Any other suggestions for other malware you see would be most appreciated.

    ComboFix 08-12-21.04 - WP Lanius 2008-12-22 13:42:27.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1734 [GMT -7:00]
    Running from: c:\documents and settings\WP Lanius\Desktop\RamboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\LocalService\Application Data\twain_32
    c:\documents and settings\LocalService\Application Data\twain_32\user.ds
    c:\windows\system32\drivers\TDSSpqxt.sys
    c:\windows\system32\TDSScfum.dll
    c:\windows\system32\TDSSlxwp.dll
    c:\windows\system32\TDSSnmxh.log
    c:\windows\system32\TDSSnrsr.dll
    c:\windows\system32\TDSSofxh.dll
    c:\windows\system32\TDSSosvd.dat
    c:\windows\system32\TDSSrhym.log
    c:\windows\system32\TDSSriqp.dll
    c:\windows\system32\TDSSsihc.dll
    c:\windows\system32\TDSStkdv.log
    c:\windows\system32\twain_32
    c:\windows\system32\twain_32\local.ds
    c:\windows\system32\twain_32\user.ds
    c:\windows\system32\twain_32\user.ds.cla
    c:\windows\system32\twext.exe

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_TDSSSERV.SYS
    -------\Legacy_TDSSSERV.SYS


    ((((((((((((((((((((((((( Files Created from 2008-11-22 to 2008-12-22 )))))))))))))))))))))))))))))))
    .

    2008-12-20 08:15 . 2008-12-20 08:15 410,984 --a------ c:\windows\system32\deploytk.dll
    2008-12-20 08:01 . 2008-09-15 05:12 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys
    2008-12-20 08:01 . 2008-09-08 03:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
    2008-12-20 08:00 . 2008-08-14 03:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
    2008-12-20 08:00 . 2008-08-14 03:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
    2008-12-20 08:00 . 2008-08-14 02:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
    2008-12-20 08:00 . 2008-08-14 02:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
    2008-12-20 08:00 . 2008-09-04 10:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
    2008-12-20 08:00 . 2008-10-24 04:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
    2008-12-20 08:00 . 2008-10-15 09:34 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-22 17:36 --------- d-----w c:\program files\Java
    2008-12-21 09:31 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
    2008-12-17 21:34 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2008-12-17 21:13 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLbz.DAT
    2008-12-17 21:13 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLbx.DAT
    2008-12-17 21:13 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLbw.DAT
    2008-12-13 16:28 --------- d-----w c:\documents and settings\WP Lanius\Application Data\Lasersoft Imaging
    2008-12-11 17:41 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLea.DAT
    2008-11-23 00:55 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT
    2008-11-13 01:13 --------- d-----w c:\program files\NCH Swift Sound
    2008-11-13 01:13 --------- d-----w c:\documents and settings\WP Lanius\Application Data\NCH Swift Sound
    2008-11-13 01:13 --------- d-----w c:\documents and settings\All Users\Application Data\NCH Swift Sound
    2008-11-13 01:00 --------- d-----w c:\documents and settings\WP Lanius\Application Data\Audacity
    2008-10-30 19:12 --------- d-----w c:\documents and settings\All Users\Application Data\Ultima_T15
    2008-10-30 19:12 --------- d-----w c:\documents and settings\All Users\Application Data\EnterNHelp
    2008-10-30 19:12 --------- d-----w c:\documents and settings\All Users\Application Data\Applause and Laugher
    2008-10-28 15:22 --------- d-----w c:\program files\Common Files\HP
    2008-10-28 14:43 --------- d-----w c:\program files\HP
    2008-10-27 23:32 --------- d-----w c:\documents and settings\WP Lanius\Application Data\HP
    2008-10-27 23:10 --------- d-----w c:\documents and settings\All Users\Application Data\WEBREG
    2008-10-27 23:08 --------- d-----w c:\documents and settings\All Users\Application Data\HP
    2008-10-27 22:46 --------- d-----w c:\documents and settings\All Users\Application Data\Hewlett-Packard
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
    2008-10-16 21:13 202,776 ----a-w c:\windows\system32\wuweb.dll
    2008-10-16 21:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
    2008-10-16 21:12 561,688 ----a-w c:\windows\system32\wuapi.dll
    2008-10-16 21:12 323,608 ----a-w c:\windows\system32\wucltui.dll
    2008-10-16 21:09 92,696 ----a-w c:\windows\system32\cdm.dll
    2008-10-16 21:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
    2008-10-16 21:09 43,544 ----a-w c:\windows\system32\wups2.dll
    2008-10-16 21:08 34,328 ----a-w c:\windows\system32\wups.dll
    2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
    2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
    2008-09-30 23:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
    2008-09-01 15:27 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLck.DAT
    2006-06-23 06:48 32,768 ----a-r c:\windows\inf\UpdateUSB.exe
    2008-04-07 06:59 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
    2008-04-07 06:59 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
    2008-04-07 06:59 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
    2008-04-07 06:59 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
    2008-04-07 06:59 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMAXPnP "= "c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-17 843776]
    "JMB36X Configure "= "c:\windows\system32\JMRaidTool.exe" [2006-06-02 385024]
    "NeroFilterCheck "= "c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
    "NvMediaCenter "= "c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
    "QuickTime Task "= "c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
    "Adobe Reader Speed Launcher "= "c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
    "RoxWatchTray "= "c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
    "nwiz "= "nwiz.exe" [2006-08-11 c:\windows\system32\nwiz.exe]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2007-04-24 49254]
    NkvMon.exe.lnk - c:\program files\Nikon\NkView6\NkvMon.exe [2007-04-28 233472]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\Ipswitch\\WS_FTP Professional\\wsftpgui.exe "=

    R3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\system32\DRIVERS\LNE100V5.sys [2007-04-17 36224]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

    *Newly Created Service* - PROCEXP90
    .
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-NWEReboot - (no file)


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.foxnews.com/
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Locate Spot on Map by GPS - c:\program files\Opanda\IExif 2.3\IExifMap.htm
    IE: View Exif/GPS/IPTC with IExif - c:\program files\Opanda\IExif 2.3\IExifCom.htm
    FF - ProfilePath - c:\documents and settings\WP Lanius\Application Data\Mozilla\Firefox\Profiles\szgbk7n1.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.foxnews.com/
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-22 13:46:02
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys]
    "imagepath "= "\systemroot\system32\drivers\TDSSpqxt.sys "
    .
    Completion time: 2008-12-22 13:48:36
    ComboFix-quarantined-files.txt 2008-12-22 20:47:28

    Pre-Run: 71,659,630,592 bytes free
    Post-Run: 72,057,970,688 bytes free

    148 --- E O F --- 2008-12-20 15:07:12
     
  5. 2008/12/23
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Logs look good, but lets get an online scan to be sure there's nothing else lurking about. Please do an online scan with Kaspersky Online Scanner

    Click Accept, when prompted to download and install the program files and database of malware definitions.
    • Click Run at the Security prompt.
    • The program will then begin downloading and installing and will also update the database.
    • Please be patient as this can take several minutes.
    • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Click View scan report at the bottom.
    • Click the Save Report As... button.
    • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply.
    **Note**

    To optimize scanning time and produce a more sensible report for review:
    • Close any open programs.
    • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.

    Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.


    Post the Kaspersky log here.
     
  6. 2008/12/29
    twofanman Lifetime Subscription

    twofanman Inactive Thread Starter

    Joined:
    2008/12/22
    Messages:
    31
    Likes Received:
    0
    Hi,

    Sorry it's taken so long to get back to you. I ran Kaspersky and although my computer seems to be running fine, Kaspersky turned up 6 infections. I stopped the scan after it had completed my system drive C and was working on one of my many outbopard drives. Here is the log. Since I started to read the threads here, I must say you guys are an amazing resource and incredibly patient. Thanks again for your help.

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7 REPORT
    Monday, December 29, 2008
    Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Monday, December 29, 2008 19:09:58
    Records in database: 1529398
    --------------------------------------------------------------------------------

    Scan settings:
    Scan using the following database: extended
    Scan archives: yes
    Scan mail databases: yes

    Scan area - My Computer:
    A:\
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\
    I:\
    J:\
    K:\
    L:\
    M:\

    Scan statistics:
    Files scanned: 148156
    Threat name: 6
    Infected objects: 5
    Suspicious objects: 1
    Duration of the scan: 01:53:26


    File name / Threat name / Threats count
    C:\Documents and Settings\WP Lanius\Local Settings\Application Data\Microsoft\Outlook\archive.pst Suspicious: Trojan-Spy.HTML.Fraud.gen 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\TDSSpqxt.sys.vir Infected: Backdoor.Win32.TDSS.bkw 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\TDSScfum.dll.vir Infected: Trojan.Win32.Agent.arvz 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\TDSSnrsr.dll.vir Infected: Backdoor.Win32.TDSS.asz 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\TDSSofxh.dll.vir Infected: Backdoor.Win32.TDSS.blh 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\TDSSriqp.dll.vir Infected: Backdoor.Win32.TDSS.atb 1

    The scan was stopped by the user.
     
  7. 2008/12/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Only one item of concern .... an infected Outlook email.

    C:\Documents and Settings\WP Lanius\Local Settings\Application Data\Microsoft\Outlook\archive.pst

    I cannot tell you which email unforunately, only that it appears to be an archived email rather than a current one. The other infections have been quarantined by ComboFix. Lets clean that up now.


    Click Start>Run and type ComboFix /u then hit Enter to uninstall ComboFix and remove the files it has quarantined. This action will also reset the System Restore points, removing any infected files there as well.
    Verify the C:\Qoobox and C:\ComboFix folders were removed, as well as the C:\ComboFix.txt file.
    Delete RSIT.exe and the C:\rsit folder then empty the recycle bin.
    You can delete any other logs that were created/saved too.

    If everything appears to be working properly, we're finished here.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.