1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Active cant access antivirus websites

Discussion in 'Malware and Virus Removal Archive' started by amber04, 2009/09/21.

  1. 2009/09/21
    amber04

    amber04 Inactive Thread Starter

    Joined:
    2009/09/21
    Messages:
    5
    Likes Received:
    0
    [Active] cant access antivirus websites

    hi i cant seem to access any anti virus websites...
    and when i try to download some on other download sites; after installing them they wouldnt update... :confused:
    i dont have any anti virus installed on my computer right now; but i have spybot search and destroy...
    ive read the other post and unlike them i can access reg edit and the task manager.
    i cant log on to yahoo messenger too if that has something to do with it :p... i can log on to yahoo website but not on messenger and ive tried multiple accounts and reinstalled it but still does the same thing...

    edit:
    hi i think the thing got worse, i can no longer log onto my windows live messenger and my internet got really slow that i couldnt test my pc using kaspersky.


    edit 2:
    ive been reading some post so i run hijack this and SDfix too,
    i can post logs if u guys need it


    heres my DDS log:


    DDS (Ver_09-07-30.01) - NTFSx86
    Run by myk at 12:13:20.92 on Tue 09/22/2009
    Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_14
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1471.713 [GMT 8:00]

    AV: AVG Anti-Virus *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
    FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\Program Files\DNA\btdna.exe
    C:\Program Files\Electronic Arts\EADM\Core.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\AVG\AVG8\avgrsx.exe
    C:\Program Files\AVG\AVG8\avgrsx.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\AVG\AVG8\avgscanx.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\myk\My Documents\Downloads\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://facebook.com/
    uInternet Connection Wizard,ShellNext = iexplore
    uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe "
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
    uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe "
    mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
    dRunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {8F60EE6F-DC53-4F9C-9E66-84BD2A545805} - hxxp://hb.getamped.com/start/CsLauncher.cab
    DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    AppInit_DLLs: c:\windows\system32\avgrsstx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\myk\applic~1\mozilla\firefox\profiles\pjbwxatl.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
    FF - plugin: c:\documents and settings\myk\application data\mozilla\firefox\profiles\pjbwxatl.default\extensions\cslauncher@cyberstep.com\plugins\npCsLauncher.dll
    FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
    FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref( "media.enforce_same_site_origin ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "media.cache_size ", 51200);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "media.ogg.enabled ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "media.wave.enabled ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "media.autoplay.enabled ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.urlbar.autocomplete.enabled ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "capability.policy.mailnews.*.wholeText ", "noAccess ");
    c:\program files\mozilla firefox\greprefs\all.js - pref( "dom.storage.default_quota ", 5120);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "content.sink.event_probe_rate ", 3);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.http.prompt-temp-redirect ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "layout.css.dpi ", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "layout.css.devPixelsPerPx ", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "gestures.enable_single_finger_input ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "dom.max_chrome_script_run_time ", 0);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.tcp.sendbuffer ", 131072);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "geo.enabled ", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.remember_cert_checkbox_default_setting ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "browser.search.param.yahoo-fr ", "moz35 ");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "browser.search.param.yahoo-fr-cjkt ", "moz35 ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "extensions.blocklist.level ", 2);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.urlbar.restrict.typed ", "~ ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.urlbar.default.behavior ", 0);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.clearOnShutdown.history ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.clearOnShutdown.formdata ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.clearOnShutdown.passwords ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.clearOnShutdown.downloads ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.clearOnShutdown.cookies ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.clearOnShutdown.cache ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.clearOnShutdown.sessions ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.clearOnShutdown.offlineApps ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.clearOnShutdown.siteSettings ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.cpd.history ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.cpd.formdata ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.cpd.passwords ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.cpd.downloads ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.cpd.cookies ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.cpd.cache ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.cpd.sessions ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.cpd.offlineApps ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.cpd.siteSettings ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "privacy.sanitize.migrateFx3Prefs ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.ssl_override_behavior ", 2);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "security.alternate_certificate_error_page ", "certerror ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.privatebrowsing.autostart ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.privatebrowsing.dont_prompt_on_enter ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "geo.wifi.uri ", "https://www.google.com/loc/json ");

    ============= SERVICES / DRIVERS ===============

    R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-9-22 12936]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-9-22 98440]
    R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-9-22 26824]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-9-22 90632]
    R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-9-22 874776]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-9-22 231704]
    R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-10 602392]
    S2 jjfwnfv;Security Windows;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]

    =============== Created Last 30 ================

    2009-09-22 11:25 <DIR> a-dshr-- C:\cmdcons
    2009-09-22 11:23 229,888 a------- c:\windows\PEV.exe
    2009-09-22 11:23 161,792 a------- c:\windows\SWREG.exe
    2009-09-22 11:23 98,816 a------- c:\windows\sed.exe
    2009-09-22 10:47 12,936 a------- c:\windows\system32\drivers\avgrkx86.sys
    2009-09-22 10:47 10,520 a------- c:\windows\system32\avgrsstx.dll
    2009-09-22 10:47 90,632 a------- c:\windows\system32\drivers\avgtdix.sys
    2009-09-22 10:47 <DIR> --d----- c:\windows\system32\drivers\Avg
    2009-09-22 10:47 98,440 a------- c:\windows\system32\drivers\avgldx86.sys
    2009-09-22 10:27 <DIR> --d----- c:\docume~1\myk\applic~1\ESET
    2009-09-22 03:59 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avg8
    2009-09-22 03:19 <DIR> --d----- c:\program files\AVG
    2009-08-29 18:16 <DIR> --d----- C:\ProgramData
    2009-08-29 18:16 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Electronic Arts
    2009-08-29 18:14 <DIR> --d----- c:\program files\Microsoft WSE
    2009-08-28 16:34 <DIR> --d----- c:\windows\system32\appmgmt
    2009-08-28 15:58 <DIR> --d----- c:\windows\system32\XPSViewer
    2009-08-28 15:57 14,048 -------- c:\windows\system32\spmsg2.dll
    2009-08-28 15:54 23,856 a------- c:\windows\system32\spupdsvc.exe
    2009-08-27 15:41 <DIR> --d----- c:\docume~1\myk\applic~1\DAEMON Tools Pro
    2009-08-27 15:28 685,816 a------- c:\windows\system32\drivers\sptd.sys

    ==================== Find3M ====================

    2009-08-14 01:43 410,984 a------- c:\windows\system32\deploytk.dll
    2009-08-05 18:43 55,656 a------- c:\windows\system32\drivers\avgntflt.sys
    2009-07-25 01:46 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
    2009-07-23 17:43 315,392 a------- c:\windows\HideWin.exe
    2009-07-23 17:28 21,640 a------- c:\windows\system32\emptyregdb.dat
    2007-09-20 12:33 167,324 a--shr-- c:\windows\system32\vvstsrtv.dll

    ============= FINISH: 12:14:04.73 ===============



    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-07-30.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 7/23/2009 5:33:42 PM
    System Uptime: 9/22/2009 11:30:25 AM (1 hours ago)

    Motherboard: JW | | C61S/V(T)
    Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ | Socket M2 | 2612/201mhz
    Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ | Socket M2 | 2612/201mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 75 GiB total, 49.307 GiB free.
    D: is CDROM (UDF)

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP1: 9/4/2009 9:08:18 PM - System Checkpoint
    RP2: 9/6/2009 1:32:43 AM - System Checkpoint
    RP3: 9/7/2009 7:51:18 AM - System Checkpoint
    RP4: 9/8/2009 9:43:01 PM - System Checkpoint
    RP5: 9/10/2009 5:34:07 PM - System Checkpoint
    RP6: 9/14/2009 3:46:48 AM - System Checkpoint
    RP7: 9/15/2009 10:50:32 AM - System Checkpoint
    RP8: 9/16/2009 11:52:40 AM - Installed DirectX
    RP9: 9/16/2009 11:54:20 AM - Installed DirectX
    RP10: 9/16/2009 11:54:56 AM - Installed Steam
    RP11: 9/16/2009 1:40:27 PM - Installed DirectX
    RP12: 9/16/2009 1:47:43 PM - Installed DirectX
    RP13: 9/16/2009 1:50:32 PM - Installed DirectX
    RP14: 9/17/2009 6:55:55 PM - Removed HolyBeast
    RP15: 9/17/2009 6:56:29 PM - Removed Steam
    RP16: 9/17/2009 7:04:07 PM - Removed Microsoft Games for Windows - LIVE Redistributable
    RP17: 9/17/2009 7:04:36 PM - Removed Microsoft Games for Windows - LIVE
    RP18: 9/19/2009 12:30:25 AM - System Checkpoint
    RP19: 9/20/2009 1:05:18 AM - System Checkpoint
    RP20: 9/21/2009 4:23:40 PM - System Checkpoint
    RP21: 9/22/2009 3:19:00 AM - Installed AVG Free 8.0
    RP22: 9/22/2009 3:58:48 AM - Removed AVG Free 8.0
    RP23: 9/22/2009 3:59:43 AM - Installed AVG Free 8.0
    RP24: 9/22/2009 8:39:09 AM - Installed ESET NOD32 Antivirus
    RP25: 9/22/2009 10:26:03 AM - Removed ESET NOD32 Antivirus
    RP26: 9/22/2009 10:26:19 AM - Installed ESET Smart Security
    RP27: 9/22/2009 10:39:09 AM - Removed ESET Smart Security
    RP28: 9/22/2009 10:46:57 AM - Installed AVG 8.0

    ==== Installed Programs ======================

    AAC Decoder
    Adobe Anchor Service CS3
    Adobe Asset Services CS3
    Adobe Bridge CS3
    Adobe Bridge Start Meeting
    Adobe Camera Raw 4.0
    Adobe CMaps
    Adobe Color - Photoshop Specific
    Adobe Color Common Settings
    Adobe Color EU Extra Settings
    Adobe Color JA Extra Settings
    Adobe Color NA Recommended Settings
    Adobe Default Language CS3
    Adobe Device Central CS3
    Adobe ExtendScript Toolkit 2
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Fonts All
    Adobe Help Viewer CS3
    Adobe Linguistics CS3
    Adobe PDF Library Files
    Adobe Photoshop CS3
    Adobe Setup
    Adobe Stock Photos CS3
    Adobe Type Support
    Adobe Update Manager CS3
    Adobe Version Cue CS3 Client
    Adobe WinSoft Linguistics Plugin
    Adobe XMP Panels CS3
    AutoUpdate
    AVG 8.0
    BitTorrent
    Cheat Engine 5.5
    Choice Guard
    CodecInstaller 2.10.2
    DivX Codec
    DivX Converter
    DivX Player
    DivX Plus DirectShow Filters
    DivX Version Checker
    DivX Web Player
    DNA
    Dream Of Mirror Online
    EA Download Manager
    H.264 Decoder
    Java(TM) 6 Update 14
    K-Lite Mega Codec Pack 1.25
    Media Player Codec Pack 3.6.0
    Messenger Plus! Live
    Microsoft .NET Framework 2.0
    Microsoft .NET Framework 3.0
    Microsoft Application Error Reporting
    Microsoft Office Professional Edition 2003
    Microsoft Rise Of Nations
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft WSE 3.0 Runtime
    MKV Splitter
    Mozilla Firefox (3.5.2)
    MSVCRT
    MSXML 6.0 Parser (KB925673)
    MSXML4 Parser
    NVIDIA Drivers
    PDF Settings
    REALTEK GbE & FE Ethernet PCI NIC Driver
    Realtek High Definition Audio Driver
    Segoe UI
    Software Update for Web Folders
    Spybot - Search & Destroy
    The Sims™ 3
    VC80CRTRedist - 8.0.50727.762
    WinAVIVideoConverter
    Windows Communication Foundation
    Windows Imaging Component
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Upload Tool
    Windows Presentation Foundation
    Windows Workflow Foundation
    WinRAR archiver
    XML Paper Specification Shared Components Pack 1.0
    Yahoo! Messenger
    Yahoo! Software Update
    Yahoo! Toolbar

    ==== Event Viewer Messages From Past Week ========

    9/22/2009 5:02:22 AM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.
    9/22/2009 11:29:31 AM, error: PlugPlayManager [11] - The device Root\LEGACY_ASC3360PR\0000 disappeared from the system without first being prepared for removal.
    9/22/2009 11:26:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
    9/22/2009 11:24:10 AM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    9/21/2009 8:38:53 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments " " in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
    9/21/2009 2:47:31 PM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 00E01C0C4223 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    9/17/2009 7:03:39 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments " " in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    9/17/2009 6:32:15 PM, error: Service Control Manager [7023] - The Security Windows service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
    9/16/2009 4:47:06 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

    ==== End Of File ===========================
     
    Last edited: 2009/09/22
  2. 2009/09/21
    amber04

    amber04 Inactive Thread Starter

    Joined:
    2009/09/21
    Messages:
    5
    Likes Received:
    0
    combofix

    and ive read somewhere that i can try to use combofix too
    and renamed it kity.exe (but i also read somewhere that i shouldnt rename :confused: so just incase i need to do it over again without renaming it ill do it if needed)

    ComboFix 09-09-20.04 - myk 09/22/2009 11:26.1.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1471.955 [GMT 8:00]
    Running from: c:\documents and settings\myk\My Documents\Downloads\kity.exe
    AV: AVG Anti-Virus *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
    FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_ASC3360PR
    -------\Service_asc3360pr


    ((((((((((((((((((((((((( Files Created from 2009-08-22 to 2009-09-22 )))))))))))))))))))))))))))))))
    .

    2009-09-22 02:47 . 2009-09-22 02:47 12936 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
    2009-09-22 02:47 . 2009-09-22 02:47 10520 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-09-22 02:47 . 2009-09-22 02:47 90632 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-09-22 02:47 . 2009-09-22 02:47 26824 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-09-22 02:47 . 2009-09-22 02:47 -------- d-----w- c:\windows\system32\drivers\Avg
    2009-09-22 02:47 . 2009-09-22 02:47 98440 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-09-22 02:27 . 2009-09-22 02:27 -------- d-----w- c:\documents and settings\myk\Application Data\ESET
    2009-09-22 00:39 . 2009-09-22 02:26 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
    2009-09-21 19:59 . 2009-09-22 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Avg8
    2009-09-21 19:19 . 2009-09-21 19:19 -------- d-----w- c:\program files\AVG
    2009-09-21 13:11 . 2009-09-21 16:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
    2009-08-31 03:49 . 2009-08-31 08:15 -------- d-----w- c:\documents and settings\myk\Local Settings\Application Data\WMTools Downloaded Files
    2009-08-29 10:16 . 2009-08-29 10:16 -------- d-----w- C:\ProgramData
    2009-08-29 10:16 . 2009-08-29 10:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
    2009-08-29 10:14 . 2009-08-29 10:14 -------- d-----w- c:\program files\Microsoft WSE
    2009-08-29 09:58 . 2009-08-29 10:15 -------- d-----w- c:\program files\Electronic Arts
    2009-08-28 08:00 . 2009-08-28 08:00 -------- d-----w- c:\program files\MSBuild
    2009-08-28 08:00 . 2009-09-17 19:28 152696 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    2009-08-28 07:58 . 2009-08-28 07:58 -------- d-----w- c:\windows\system32\XPSViewer
    2009-08-28 07:57 . 2009-08-28 07:57 -------- d-----w- c:\program files\Reference Assemblies
    2009-08-28 07:57 . 2006-06-29 05:07 14048 ------w- c:\windows\system32\spmsg2.dll
    2009-08-28 07:54 . 2006-10-16 08:10 23856 ----a-w- c:\windows\system32\spupdsvc.exe
    2009-08-27 07:41 . 2009-08-27 07:41 -------- d-----w- c:\documents and settings\myk\Application Data\DAEMON Tools Pro
    2009-08-27 07:28 . 2009-08-27 07:28 685816 ----a-w- c:\windows\system32\drivers\sptd.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-09-22 03:32 . 2009-07-25 02:36 -------- d-----w- c:\program files\DNA
    2009-09-22 03:32 . 2009-07-25 02:36 -------- d-----w- c:\documents and settings\myk\Application Data\DNA
    2009-09-22 02:39 . 2009-07-25 02:37 -------- d-----w- c:\documents and settings\myk\Application Data\BitTorrent
    2009-09-21 22:32 . 2009-08-06 08:04 -------- d-----w- c:\program files\Cheat Engine
    2009-09-21 13:13 . 2009-07-26 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
    2009-09-21 13:11 . 2009-07-26 02:46 -------- d-----w- c:\program files\Yahoo!
    2009-09-21 11:18 . 2009-07-23 11:16 45360 ----a-w- c:\documents and settings\myk\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-09-17 10:55 . 2009-07-23 09:42 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-08-13 17:43 . 2009-08-13 17:43 410984 ----a-w- c:\windows\system32\deploytk.dll
    2009-08-13 17:43 . 2009-08-13 17:43 -------- d-----w- c:\program files\Java
    2009-08-13 17:21 . 2009-08-13 17:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-08-13 17:02 . 2009-08-13 17:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-08-12 07:32 . 2009-08-12 07:32 -------- d-----w- c:\documents and settings\myk\Application Data\Microsoft Games
    2009-08-12 07:29 . 2009-08-12 07:29 -------- d-----w- c:\program files\Microsoft Games
    2009-08-05 10:43 . 2009-07-23 10:40 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2009-08-05 05:40 . 2009-08-05 05:40 -------- d-----w- c:\program files\Microsoft.NET
    2009-08-05 05:40 . 2009-08-05 05:40 -------- d-----w- c:\program files\Microsoft ActiveSync
    2009-08-04 23:30 . 2009-08-04 22:02 -------- d-----w- c:\program files\Common Files\Adobe
    2009-08-04 22:58 . 2009-08-04 22:58 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
    2009-08-04 22:23 . 2009-08-04 22:23 -------- d-----w- c:\program files\Bonjour
    2009-08-04 22:05 . 2009-08-04 22:05 -------- d-----w- c:\program files\Common Files\Macrovision Shared
    2009-08-03 18:40 . 2009-08-03 11:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
    2009-08-03 08:56 . 2009-08-03 08:56 -------- d-----w- c:\program files\Messenger Plus! Live
    2009-07-30 04:34 . 2009-07-30 04:34 -------- d-----w- c:\documents and settings\myk\Application Data\Media Player Classic
    2009-07-27 05:36 . 2009-07-27 04:02 -------- d-----w- c:\documents and settings\myk\Application Data\DivX
    2009-07-27 05:20 . 2009-07-27 05:19 -------- d-----w- c:\program files\DivX
    2009-07-27 05:19 . 2009-07-27 05:19 -------- d-----w- c:\program files\Common Files\DivX Shared
    2009-07-27 04:42 . 2009-07-27 04:42 -------- d-----w- c:\program files\JockerSoft
    2009-07-27 03:33 . 2009-07-27 03:33 -------- d-----w- c:\program files\WinAVIVideoConverter
    2009-07-27 03:32 . 2009-07-27 03:27 -------- d-----w- c:\program files\K-Lite Codec Pack
    2009-07-26 02:48 . 2009-07-26 02:48 -------- d-----w- c:\documents and settings\myk\Application Data\Yahoo!
    2009-07-25 12:37 . 2009-07-25 12:37 0 ----a-w- c:\windows\nsreg.dat
    2009-07-25 02:37 . 2009-07-25 02:36 -------- d-----w- c:\program files\BitTorrent
    2009-07-25 01:49 . 2009-07-23 16:16 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
    2009-07-23 09:43 . 2009-07-23 09:43 315392 ----a-w- c:\windows\HideWin.exe
    2009-07-23 09:28 . 2009-07-23 09:28 21640 ----a-w- c:\windows\system32\emptyregdb.dat
    2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
    2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
    2007-09-20 04:33 . 2007-09-20 04:33 167324 --sha-r- c:\windows\system32\vvstsrtv.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "msnmsgr "= "c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
    "BitTorrent DNA "= "c:\program files\DNA\btdna.exe" [2009-07-25 318272]
    "SpybotSD TeaTimer "= "c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    "EA Core "= "c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
    "Messenger (Yahoo!) "= "c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-26 4351216]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2006-07-12 7626752]
    "NvMediaCenter "= "c:\windows\system32\NvMcTray.dll" [2006-07-12 86016]
    "SunJavaUpdateSched "= "c:\program files\Java\jre6\bin\jusched.exe" [2009-08-13 148888]
    "AVG8_TRAY "= "c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-22 1235736]
    "RTHDCPL "= "RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-05-10 16342528]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "ShowDeskFix "= "shell32" [X]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs "=c:\windows\system32\avgrsstx.dll

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\DNA\\btdna.exe "=
    "c:\\Program Files\\BitTorrent\\bittorrent.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "c:\\Program Files\\Electronic Arts\\EADM\\Core.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgam.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "6056:TCP "= 6056:TCP:mtgkpz

    R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [9/22/2009 10:47 AM 12936]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/22/2009 10:47 AM 98440]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/22/2009 10:47 AM 90632]
    R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/22/2009 10:47 AM 874776]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/22/2009 10:46 AM 231704]
    S2 jjfwnfv;Security Windows;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 7:56 AM 14336]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    jjfwnfv
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://facebook.com/
    uInternet Connection Wizard,ShellNext = iexplore
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    DPF: {8F60EE6F-DC53-4F9C-9E66-84BD2A545805} - hxxp://hb.getamped.com/start/CsLauncher.cab
    FF - ProfilePath - c:\documents and settings\myk\Application Data\Mozilla\Firefox\Profiles\pjbwxatl.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
    FF - plugin: c:\documents and settings\myk\Application Data\Mozilla\Firefox\Profiles\pjbwxatl.default\extensions\CSLauncher@cyberstep.com\plugins\npCsLauncher.dll
    FF - plugin: c:\program files\K-Lite Codec Pack\real\browser\plugins\nppl3260.dll
    FF - plugin: c:\program files\K-Lite Codec Pack\real\browser\plugins\nprpjplug.dll

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true.
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-nwiz - nwiz.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-09-22 11:31
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\jjfwnfv]
    "ServiceDll "= "c:\windows\system32\vvstsrtv.dll "
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
    @Denied: (A 2) (Everyone)
    @= "FlashBroker "
    "LocalizedString "= "@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101 "

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
    "Enabled "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
    @= "c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe "

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
    @Denied: (A 2) (Everyone)
    @= "IFlashBroker3 "

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
    @= "{00020424-0000-0000-C000-000000000046} "

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    "Version "= "1.0 "

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]
    @Denied: (Full) (LocalSystem)
    "OOBETimer "=hex:
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(3420)
    c:\progra~1\WINDOW~2\wmpband.dll
    c:\windows\system32\wpdshserviceobj.dll
    c:\windows\system32\portabledevicetypes.dll
    c:\windows\system32\portabledeviceapi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\nvsvc32.exe
    c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    c:\progra~1\AVG\AVG8\avgam.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    .
    **************************************************************************
    .
    Completion time: 2009-09-22 11:36 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-09-22 03:36

    Pre-Run: 52,857,421,824 bytes free
    Post-Run: 52,927,139,840 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT= "Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS= "Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    213
     

  3. to hide this advert.

  4. 2009/09/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Before we go any further....
    What's your antivirus program situation?
    You said, you don't have any right now, but I can see some traces of AVG and NOD running.
    What was the latest AV program, you used to have?
    Did it stop working?
    Tell me as much, as you can.
     
  5. 2009/09/22
    amber04

    amber04 Inactive Thread Starter

    Joined:
    2009/09/21
    Messages:
    5
    Likes Received:
    0
    oh well,
    when i noticed that i couldnt go to any anti virus website i only had spybot
    and then i got nervous so i tried to download avg somewhere; i was able to install it but it wont update...
    my boyfriend downloaded nod somewhere other than its site too, and same thing happened- it wont update.

    edit:ive already uninstalled nod; idk why its still showing
     
    Last edited: 2009/09/22
  6. 2009/09/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    OK. That's clear.
    You can't run two AV programs at the same time, so please uninstall ESET for now, using ESET NOD32 Removal Tool: http://www.nod32.nl/download/tool/nod32removal.exe

    ====================================================================

    Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.
    Upload following files to http://www.virustotal.com/ for security check:
    HideWin.exe located @ c:\windows
    Post scan results.

    =================================================================

    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\windows\system32\vvstsrtv.dll
    
    
    Folder::
    
    Driver::
    jjfwnfv
    
    
    Registry::
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
     "ShowDeskFix "=-
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\jjfwnfv]
    
    RegLockDel::
    
    

    3. Save the above as CFScript.txt

    4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
    • A new HijackThis log.


    Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Download HijackThis Installer
    Install, and run it.
    Post HijackTHis log.
    Do NOT attempt to fix anything!

    NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator
     
  7. 2009/09/22
    amber04

    amber04 Inactive Thread Starter

    Joined:
    2009/09/21
    Messages:
    5
    Likes Received:
    0
    hi i cant access the first two links... the one for nod and where i should upload the file...

    edit:
    wow ur amazing!
    i was able to access sites already and have removed nod
    ive scanned the hidewin file and idk if this is what you need.
    and oh avg updated! :)
    the combofix and hijack this post says its need to be confirmed by a mod 1st

    Antivirus Version Last Update Result
    a-squared 4.5.0.24 2009.09.18 -
    AhnLab-V3 5.0.0.2 2009.09.17 -
    AntiVir 7.9.1.19 2009.09.17 -
    Antiy-AVL 2.0.3.7 2009.09.18 -
    Authentium 5.1.2.4 2009.09.18 -
    Avast 4.8.1351.0 2009.09.17 -
    AVG 8.5.0.412 2009.09.17 -
    BitDefender 7.2 2009.09.18 -
    CAT-QuickHeal 10.00 2009.09.17 -
    ClamAV 0.94.1 2009.09.17 -
    Comodo 2355 2009.09.18 -
    DrWeb 5.0.0.12182 2009.09.17 -
    eSafe 7.0.17.0 2009.09.17 -
    eTrust-Vet 31.6.6744 2009.09.17 -
    F-Prot 4.5.1.85 2009.09.18 -
    F-Secure 8.0.14470.0 2009.09.18 -
    Fortinet 3.120.0.0 2009.09.18 -
    GData 19 2009.09.18 -
    Ikarus T3.1.1.72.0 2009.09.18 -
    Jiangmin 11.0.800 2009.09.17 -
    K7AntiVirus 7.10.847 2009.09.17 -
    Kaspersky 7.0.0.125 2009.09.18 -
    McAfee 5744 2009.09.17 -
    McAfee+Artemis 5744 2009.09.17 -
    McAfee-GW-Edition 6.8.5 2009.09.17 -
    Microsoft 1.5005 2009.09.17 -
    NOD32 4435 2009.09.17 -
    Norman 6.01.09 2009.09.17 -
    nProtect 2009.1.8.0 2009.09.17 -
    Panda 10.0.2.2 2009.09.17 -
    PCTools 4.4.2.0 2009.09.17 -
    Prevx 3.0 2009.09.18 -
    Rising 21.47.40.00 2009.09.18 -
    Sophos 4.45.0 2009.09.18 -
    Sunbelt 3.2.1858.2 2009.09.18 -
    Symantec 1.4.4.12 2009.09.18 -
    TheHacker 6.3.4.4.404 2009.09.15 -
    TrendMicro 8.950.0.1094 2009.09.18 -
    VBA32 3.12.10.10 2009.09.17 -
    ViRobot 2009.9.18.1942 2009.09.18 -
    VirusBuster 4.6.5.0 2009.09.17 -
    Additional information
    File size: 315392 bytes
    MD5 : 2d65f8db74c36819896cf809e4375f0a
    SHA1 : 3bb8f07c42350509a123b9ad86bb6582856d1f91
    SHA256: a3630d792b7d3b237098d1e608dbbd844a3c31b4ebd4cab1d7d4e440524df000
    PEInfo: PE Structure information

    ( base data )
    entrypointaddress.: 0x1EFA3
    timedatestamp.....: 0x459CD644 (Thu Jan 4 11:26:12 2007)
    machinetype.......: 0x14C (Intel I386)

    ( 4 sections )
    name viradd virsiz rawdsiz ntrpy md5
    .text 0x1000 0x31EA4 0x32000 6.65 1b02d65e0fb9fa24d9818b8c964f2767
    .rdata 0x33000 0xC494 0xD000 4.84 53f0815506b7c5b1941ac02d833421a7
    .data 0x40000 0x6474 0x3000 3.79 a1e344d86ac731c49c35215502406660
    .rsrc 0x47000 0x9324 0xA000 4.97 91774935a4ba8efc53091796c03ca17b

    ( 0 imports )


    ( 0 exports )
    TrID : File type identification
    Win64 Executable Generic (59.6%)
    Win32 Executable MS Visual C++ (generic) (26.2%)
    Win32 Executable Generic (5.9%)
    Win32 Dynamic Link Library (generic) (5.2%)
    Generic Win/DOS Executable (1.3%)
    ThreatExpert: http://www.threatexpert.com/report.aspx?md5=2d65f8db74c36819896cf809e4375f0a
    ssdeep: 6144:glT1ZzXm1fJmpxJhnf+OWkPKZ60diY31DxP78Pf:dQvn2OPXYNWPf
    PEiD : -
    RDS : NSRL Reference Data Set
    -
     
    Last edited: 2009/09/22
  8. 2009/09/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Try again after running Combofix and restarting.
     
  9. 2009/09/22
    amber04

    amber04 Inactive Thread Starter

    Joined:
    2009/09/21
    Messages:
    5
    Likes Received:
    0
    combofix log:

    ComboFix 09-09-22.02 - myk 09/23/2009 11:41.2.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1471.826 [GMT 8:00]
    Running from: c:\documents and settings\myk\My Documents\Downloads\kity.exe
    Command switches used :: c:\documents and settings\myk\Desktop\CFScript.txt
    AV: AVG Anti-Virus *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
    FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

    FILE ::
    "c:\windows\system32\vvstsrtv.dll "
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\vvstsrtv.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_JJFWNFV
    -------\Service_jjfwnfv


    ((((((((((((((((((((((((( Files Created from 2009-08-23 to 2009-09-23 )))))))))))))))))))))))))))))))
    .

    2009-09-22 14:52 . 2009-09-22 14:52 -------- d-----w- c:\windows\ERUNT
    2009-09-22 14:44 . 2009-09-22 15:06 -------- d-----w- C:\SDFix
    2009-09-22 04:27 . 2009-09-22 04:27 -------- d-----w- C:\$AVG8.VAULT$
    2009-09-22 02:47 . 2009-09-22 02:47 12936 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
    2009-09-22 02:47 . 2009-09-22 02:47 10520 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-09-22 02:47 . 2009-09-22 02:47 90632 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-09-22 02:47 . 2009-09-22 02:47 26824 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-09-22 02:47 . 2009-09-22 02:47 -------- d-----w- c:\windows\system32\drivers\Avg
    2009-09-22 02:47 . 2009-09-22 02:47 98440 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-09-22 02:27 . 2009-09-22 02:27 -------- d-----w- c:\documents and settings\myk\Application Data\ESET
    2009-09-22 00:39 . 2009-09-22 02:26 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
    2009-09-21 19:59 . 2009-09-22 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Avg8
    2009-09-21 19:19 . 2009-09-21 19:19 -------- d-----w- c:\program files\AVG
    2009-09-21 13:11 . 2009-09-21 16:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
    2009-08-31 03:49 . 2009-08-31 08:15 -------- d-----w- c:\documents and settings\myk\Local Settings\Application Data\WMTools Downloaded Files
    2009-08-29 10:16 . 2009-08-29 10:16 -------- d-----w- C:\ProgramData
    2009-08-29 10:16 . 2009-08-29 10:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
    2009-08-29 10:14 . 2009-08-29 10:14 -------- d-----w- c:\program files\Microsoft WSE
    2009-08-29 09:58 . 2009-08-29 10:15 -------- d-----w- c:\program files\Electronic Arts
    2009-08-28 08:00 . 2009-08-28 08:00 -------- d-----w- c:\program files\MSBuild
    2009-08-28 08:00 . 2009-09-17 19:28 152696 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    2009-08-28 07:58 . 2009-08-28 07:58 -------- d-----w- c:\windows\system32\XPSViewer
    2009-08-28 07:57 . 2009-08-28 07:57 -------- d-----w- c:\program files\Reference Assemblies
    2009-08-28 07:57 . 2006-06-29 05:07 14048 ------w- c:\windows\system32\spmsg2.dll
    2009-08-28 07:54 . 2006-10-16 08:10 23856 ----a-w- c:\windows\system32\spupdsvc.exe
    2009-08-27 07:41 . 2009-08-27 07:41 -------- d-----w- c:\documents and settings\myk\Application Data\DAEMON Tools Pro
    2009-08-27 07:28 . 2009-08-27 07:28 685816 ----a-w- c:\windows\system32\drivers\sptd.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-09-23 03:45 . 2009-07-25 02:36 -------- d-----w- c:\documents and settings\myk\Application Data\DNA
    2009-09-22 15:06 . 2009-07-25 02:36 -------- d-----w- c:\program files\DNA
    2009-09-22 02:39 . 2009-07-25 02:37 -------- d-----w- c:\documents and settings\myk\Application Data\BitTorrent
    2009-09-21 22:32 . 2009-08-06 08:04 -------- d-----w- c:\program files\Cheat Engine
    2009-09-21 13:13 . 2009-07-26 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
    2009-09-21 13:11 . 2009-07-26 02:46 -------- d-----w- c:\program files\Yahoo!
    2009-09-21 11:18 . 2009-07-23 11:16 45360 ----a-w- c:\documents and settings\myk\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-09-17 10:55 . 2009-07-23 09:42 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-08-13 17:43 . 2009-08-13 17:43 410984 ----a-w- c:\windows\system32\deploytk.dll
    2009-08-13 17:43 . 2009-08-13 17:43 -------- d-----w- c:\program files\Java
    2009-08-13 17:21 . 2009-08-13 17:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-08-13 17:02 . 2009-08-13 17:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-08-12 07:32 . 2009-08-12 07:32 -------- d-----w- c:\documents and settings\myk\Application Data\Microsoft Games
    2009-08-12 07:29 . 2009-08-12 07:29 -------- d-----w- c:\program files\Microsoft Games
    2009-08-05 10:43 . 2009-07-23 10:40 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2009-08-05 05:40 . 2009-08-05 05:40 -------- d-----w- c:\program files\Microsoft.NET
    2009-08-05 05:40 . 2009-08-05 05:40 -------- d-----w- c:\program files\Microsoft ActiveSync
    2009-08-04 23:30 . 2009-08-04 22:02 -------- d-----w- c:\program files\Common Files\Adobe
    2009-08-04 22:58 . 2009-08-04 22:58 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
    2009-08-04 22:23 . 2009-08-04 22:23 -------- d-----w- c:\program files\Bonjour
    2009-08-04 22:05 . 2009-08-04 22:05 -------- d-----w- c:\program files\Common Files\Macrovision Shared
    2009-08-03 18:40 . 2009-08-03 11:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
    2009-08-03 08:56 . 2009-08-03 08:56 -------- d-----w- c:\program files\Messenger Plus! Live
    2009-07-30 04:34 . 2009-07-30 04:34 -------- d-----w- c:\documents and settings\myk\Application Data\Media Player Classic
    2009-07-27 05:36 . 2009-07-27 04:02 -------- d-----w- c:\documents and settings\myk\Application Data\DivX
    2009-07-27 05:20 . 2009-07-27 05:19 -------- d-----w- c:\program files\DivX
    2009-07-27 05:19 . 2009-07-27 05:19 -------- d-----w- c:\program files\Common Files\DivX Shared
    2009-07-27 04:42 . 2009-07-27 04:42 -------- d-----w- c:\program files\JockerSoft
    2009-07-27 03:33 . 2009-07-27 03:33 -------- d-----w- c:\program files\WinAVIVideoConverter
    2009-07-27 03:32 . 2009-07-27 03:27 -------- d-----w- c:\program files\K-Lite Codec Pack
    2009-07-26 02:48 . 2009-07-26 02:48 -------- d-----w- c:\documents and settings\myk\Application Data\Yahoo!
    2009-07-25 12:37 . 2009-07-25 12:37 0 ----a-w- c:\windows\nsreg.dat
    2009-07-23 09:43 . 2009-07-23 09:43 315392 ----a-w- c:\windows\HideWin.exe
    2009-07-23 09:28 . 2009-07-23 09:28 21640 ----a-w- c:\windows\system32\emptyregdb.dat
    2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
    2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-09-22_03.31.38 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-09-22 15:06 . 2009-09-22 15:06 16384 c:\windows\temp\Perflib_Perfdata_ff0.dat
    + 2009-09-23 03:46 . 2009-09-23 03:46 16384 c:\windows\temp\Perflib_Perfdata_1c8.dat
    + 2009-09-22 14:52 . 2009-09-22 14:52 8192 c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
    + 2009-09-22 14:52 . 2009-09-22 14:52 8192 c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
    + 2009-09-22 14:52 . 2009-09-22 14:52 376832 c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
    + 2009-09-22 14:52 . 2008-08-07 07:27 163328 c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
    + 2009-09-22 14:52 . 2009-09-22 14:52 376832 c:\windows\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
    + 2009-09-22 14:52 . 2008-08-07 07:27 163328 c:\windows\ERUNT\SDFIX\ERDNT.EXE
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "msnmsgr "= "c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
    "BitTorrent DNA "= "c:\program files\DNA\btdna.exe" [2009-07-25 318272]
    "SpybotSD TeaTimer "= "c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    "EA Core "= "c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
    "Messenger (Yahoo!) "= "c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-26 4351216]
    "ctfmon.exe "= "c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2006-07-12 7626752]
    "NvMediaCenter "= "c:\windows\system32\NvMcTray.dll" [2006-07-12 86016]
    "SunJavaUpdateSched "= "c:\program files\Java\jre6\bin\jusched.exe" [2009-08-13 148888]
    "AVG8_TRAY "= "c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-22 1235736]
    "RTHDCPL "= "RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-05-10 16342528]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-09-22 02:47 10520 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs "=c:\windows\system32\avgrsstx.dll

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "%windir%\\system32\\sessmgr.exe "=
    "c:\\Program Files\\DNA\\btdna.exe "=
    "c:\\Program Files\\BitTorrent\\bittorrent.exe "=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe "=
    "c:\\Program Files\\Electronic Arts\\EADM\\Core.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgam.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgemc.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "6056:TCP "= 6056:TCP:mtgkpz

    R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [9/22/2009 10:47 AM 12936]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/22/2009 10:47 AM 98440]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/22/2009 10:47 AM 90632]
    R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/22/2009 10:47 AM 874776]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/22/2009 10:46 AM 231704]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://facebook.com/
    uInternet Connection Wizard,ShellNext = iexplore
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    DPF: {8F60EE6F-DC53-4F9C-9E66-84BD2A545805} - hxxp://hb.getamped.com/start/CsLauncher.cab
    FF - ProfilePath - c:\documents and settings\myk\Application Data\Mozilla\Firefox\Profiles\pjbwxatl.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
    FF - plugin: c:\documents and settings\myk\Application Data\Mozilla\Firefox\Profiles\pjbwxatl.default\extensions\CSLauncher@cyberstep.com\plugins\npCsLauncher.dll
    FF - plugin: c:\program files\K-Lite Codec Pack\real\browser\plugins\nppl3260.dll
    FF - plugin: c:\program files\K-Lite Codec Pack\real\browser\plugins\nprpjplug.dll

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true.

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-09-23 11:46
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
    @Denied: (A 2) (Everyone)
    @= "FlashBroker "
    "LocalizedString "= "@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101 "

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
    "Enabled "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
    @= "c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe "

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
    @Denied: (A 2) (Everyone)
    @= "IFlashBroker3 "

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
    @= "{00020424-0000-0000-C000-000000000046} "

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
    @= "{FAB3E735-69C7-453B-A446-B6823C6DF1C9} "
    "Version "= "1.0 "

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]
    @Denied: (Full) (LocalSystem)
    "OOBETimer "=hex:
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(608)
    c:\windows\system32\MPR.dll

    - - - - - - - > 'explorer.exe'(1160)
    c:\progra~1\WINDOW~2\wmpband.dll
    c:\windows\system32\wpdshserviceobj.dll
    c:\windows\system32\portabledevicetypes.dll
    c:\windows\system32\portabledeviceapi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\nvsvc32.exe
    c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    c:\progra~1\AVG\AVG8\avgam.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\AVG\AVG8\avgupd.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\program files\AVG\AVG8\avgrsx.exe
    .
    **************************************************************************
    .
    Completion time: 2009-09-23 11:52 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-09-23 03:52
    ComboFix2.txt 2009-09-22 03:36

    Pre-Run: 52,817,620,992 bytes free
    Post-Run: 52,790,890,496 bytes free

    220

    hijackthis log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:55:07 AM, on 9/23/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.20583)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\DNA\btdna.exe
    C:\Program Files\Electronic Arts\EADM\Core.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\AVG\AVG8\avgupd.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\AVG\AVG8\avgrsx.exe
    C:\Program Files\AVG\AVG8\avgrsx.exe
    C:\Program Files\AVG\AVG8\avgrsx.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Java\jre6\bin\jucheck.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://facebook.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe "
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe "
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {8F60EE6F-DC53-4F9C-9E66-84BD2A545805} (CsLauncher Class) - http://hb.getamped.com/start/CsLauncher.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: C:\WINDOWS\system32\avgrsstx.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

    --
    End of file - 6072 bytes
     
  10. 2009/09/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Uninstall Combofix:
    Go Start > Run
    Type in:
    combofix /u
    Note the space between the "combofix" and the "/u "
    Restart computer.

    ==============================================================

    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    ***VERY IMPORTANT! Make sure, you update Superantispyware, and Malwarebytes before running the scans.***

    STEP 1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes ". If not, update the definitions before scanning by selecting "Check for Updates ". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    PHYSICALLY DISCONNECT FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Click Scan your Computer... button.
    * Click Scanning Preferences/Control Center... button.
    * Under General and Startup tab, make sure, Start SUPERAntiSpyware when Windows starts option is UN-checked.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    - Close browsers before scanning.
    - Terminate memory threats before quarantining.

    * Click the Close button to leave the control center screen.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, choose Perform Complete Scan.
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
    * Make sure everything has a checkmark next to it and click Next.
    * A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
    * If asked if you want to reboot, click Yes.
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    - Click Preferences, then click the Statistics/Logs tab.
    - Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    - If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    - Please copy and paste the Scan Log results in your next reply.

    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    STEP 2. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!


    STEP 3.
    Post fresh HijackThis log.
    NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator
    Do NOT attempt to "fix" anything!


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.