View Full Version : Virus - Brastk.exe... fakealer.bb
beddall
10-29-2008, 07:40 PM
hey,
It seems i have picked up a virus and very much need help in removing it.
I can only start windows in safe mode.
Trying to start windows in normal mode causes a blue screen and instant restart. I think it might say something about a HARD ERROR C000000### but it disappears before i can read it.
running avira AV in safe mode detects the following...
TR/Dldr.FakeAler.bb
c:\windows\system32\brastk.exe
i've tried 'quarantine' and 'remove' but neither of these seem to work. the virus always seems to be back after a restart.
I can't seem to find any info about this particular nasty little bugger on google. (only reference to it is on the avira website)
I've tried running HiJackThis but it doesn't want to work. (don't know if this has anything to do with running in safe mode or the virus has somehow killed it)
Any help at all would be much appreciated.
cheers.
Rename HijackThis to something like fred.scr, john.com, or some other short filename with an executable extension...(file extension list (http://antiques-internet.com/exe_types.htm))
Then try running it.
It can also be run from a USB drive...
beddall
10-30-2008, 05:17 PM
okay,
got HiJackThis to work and here is the log.
I've run a virus scan again and it found nothing.
but once i booted in normal mode the virus seems to be back :(
hope there's some help out there for me :)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:03:39, on 30/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Belkin F5D8053 N Wireless USB Adapter Utility.lnk = C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.meshcomputers.com
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - [url]http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab[/url]
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - [url]http://download.bitdefender.com/resources/scan8/oscan8.cab[/url]
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - [url]http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab[/url]
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - [url]http://www.pcpitstop.com/mhLbl.cab[/url]
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - [url]http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab[/url]
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - [url]http://support.f-secure.com/ols/fscax.cab[/url]
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - [url]http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab[/url]
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - [url]http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab[/url]
O20 - AppInit_DLLs: karna.dat
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: License Management Service ESD - Unknown owner - C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe
O23 - Service: Mdrfrmtvi - ULi Electronics Inc. - (no file)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 7515 bytes
classicsoftware
10-31-2008, 02:09 AM
First:
How to run a scan with Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware from Here (http://www.besttechie.net/tools/mbam-setup.exe) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.[/QUOTE]
Second:
Please do the following:
Download this file - combofix.exe (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop (it needs to be run from the Desktop). Double click combofix.exe & follow the prompts.
When finished, it will produce a log for you.
Note:
Do not mouseclick Combofix's window while it is running. That may cause the program to stall...
Third:
Re-boot the system
Post the Combofix Log
Post the MBAM log
Post a new HJT log
Tell us how the system is running.
beddall
10-31-2008, 05:26 AM
Thanks for the reply.
I might have trouble updating the software you mentioned as i can only start the computer in safe mode. it's not conected to the internet then.
I could try starting it in safe mode with networking but then wouldn't i be at further risk? (I don't think my firewall is active when in safe mode)
**I'm posting this from another computer that has net access and will be transferring the downloaded programs via usb drive**
Thanks again for the reply
I'll post the logs when they are done :)
classicsoftware
10-31-2008, 10:19 AM
Try safe mode with networking for the update. Then back to regular safe mode for the first scan. If not stick with regular safe mode and we can update after the first scan.
beddall
10-31-2008, 05:37 PM
hey,
I have done as you asked and i have posted the logs.
the system seems to be running ok now. but i have only just finished these logs.
ComboFix 08-10-30.12 - rob beddall 2008-10-31 9:12:46.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2099 [GMT 0:00]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\ROBBED~1\LOCALS~1\Temp\tmp2.tmp
C:\WINDOWS\system32\dao350.dll
C:\WINDOWS\system32\drivers\TDSSpqxt.sys
C:\WINDOWS\system32\drivers\TDSSyaxt.sys
C:\WINDOWS\system32\TDSSbxbs.log
C:\WINDOWS\system32\TDSScfub.dll
C:\WINDOWS\system32\TDSSfpmp.dll
C:\WINDOWS\system32\TDSSnmxh.log
C:\WINDOWS\system32\TDSSoekh.dll
C:\WINDOWS\system32\TDSSosvd.dat
C:\WINDOWS\system32\TDSSprsr.dll
C:\WINDOWS\system32\TDSSroip.dll
C:\WINDOWS\system32\TDSSsbhc.dll
C:\WINDOWS\system32\TDSStotv.log
C:\WINDOWS\system32\TDSSydym.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSserv
-------\Legacy_TDSSserv
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-31 )))))))))))))))))))))))))))))))
.
2008-10-31 08:41 . 2008-10-31 08:41 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-31 08:41 . 2008-10-31 08:41 <DIR> d-------- C:\Documents and Settings\rob beddall\Application Data\Malwarebytes
2008-10-31 08:41 . 2008-10-31 08:41 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
2008-10-31 08:41 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-31 08:41 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-31 08:36 . 2008-10-31 08:36 26,624 --a------ C:\WINDOWS\system32\TDSSvltn.dll
2008-10-30 21:49 . 2008-10-30 21:49 26,624 --a------ C:\WINDOWS\system32\TDSSjjrx.dll
2008-10-30 20:00 . 2008-10-30 20:00 26,624 --a------ C:\WINDOWS\system32\TDSSuyfh.dll
2008-10-30 09:20 . 2008-10-30 09:20 26,624 --a------ C:\WINDOWS\system32\TDSSkcjp.dll
2008-10-30 09:18 . 2008-10-30 09:18 26,624 --a------ C:\WINDOWS\system32\TDSSbivk.dll
2008-10-30 09:17 . 2008-10-30 09:17 26,624 --a------ C:\WINDOWS\system32\TDSSvvbi.dll
2008-10-30 09:16 . 2008-10-30 09:16 26,624 --a------ C:\WINDOWS\system32\TDSSbubx.dll
2008-10-29 22:40 . 2008-10-29 22:40 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-10-29 22:07 . 268,435,456 C:\WINDOWS\system32\temppf.sys
2008-10-29 22:06 . 2008-10-29 22:06 26,624 --a------ C:\WINDOWS\system32\TDSSxbdr.dll
2008-10-29 22:02 . 2008-10-29 22:02 26,624 --a------ C:\WINDOWS\system32\TDSSdhym.dll
2008-10-29 21:10 . 2008-10-29 21:10 26,624 --a------ C:\WINDOWS\system32\TDSSnmxh.dll
2008-10-29 21:05 . 2008-10-29 21:05 26,624 --a------ C:\WINDOWS\system32\TDSSciou.dll
2008-10-29 21:04 . 2008-10-29 21:04 26,624 --a------ C:\WINDOWS\system32\TDSScbqp.dll
2008-10-29 20:39 . 2005-11-25 09:18 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-10-29 20:39 . 2008-10-29 20:39 <DIR> d-------- C:\Documents and Settings\Administrator
2008-10-29 20:34 . 2008-10-29 20:34 26,624 --a------ C:\WINDOWS\system32\TDSSnrse.dll
2008-10-29 20:31 . 2008-10-29 20:31 26,624 --a------ C:\WINDOWS\system32\TDSSosvn.dll
2008-10-29 19:47 . 2008-10-29 19:47 73,728 --a------ C:\WINDOWS\system32\TDSSnrsr.dll
2008-10-29 19:47 . 2008-10-29 19:47 31,232 --a------ C:\WINDOWS\system32\TDSSosvd.dll
2008-10-29 19:47 . 2008-10-29 19:47 29,696 --a------ C:\WINDOWS\system32\TDSSoexh.dll
2008-10-29 19:47 . 2008-10-31 08:38 3,727 --a------ C:\WINDOWS\system32\TDSSriqp.dll
2008-10-29 19:47 . 2008-10-29 19:47 164 --a------ C:\WINDOWS\system32\TDSSpaxt.dat
2008-10-25 12:56 . 2008-10-25 12:59 <DIR> d-------- C:\Program Files\Audacity
2008-10-22 17:46 . 2008-10-25 11:23 <DIR> d--h----- C:\$AVG8.VAULT$
2008-10-22 13:58 . 2008-10-22 13:58 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-22 11:18 . 2008-10-22 11:18 <DIR> d-------- C:\Program Files\Avira
2008-10-22 11:18 . 2008-10-22 11:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
2008-10-21 22:09 . 2008-10-21 22:17 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-10-21 20:36 . 2008-10-21 20:51 <DIR> d--------
beddall
10-31-2008, 05:40 PM
2008-10-21 20:36 . 2008-10-21 20:51 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-10-21 20:36 . 2008-10-21 20:36 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-10-21 20:36 . 2008-10-21 20:36 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-10-21 20:36 . 2008-10-21 20:36 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-10-21 20:12 . 2008-10-21 20:12 <DIR> d-------- C:\Program Files\AVG
2008-10-21 20:12 . 2008-10-21 20:36 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg8
2008-10-21 18:58 . 2008-10-22 16:28 <DIR> d-------- C:\Documents and Settings\rob beddall\.housecall6.6
2008-10-21 18:52 . 2008-10-29 19:47 26,624 --a------ C:\WINDOWS\system32\TDSSoiqh.dll
2008-10-11 10:54 . 2008-10-11 10:54 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2008-10-11 10:53 . 2008-10-11 10:53 <DIR> d-------- C:\Program Files\Belkin
2008-10-11 10:52 . 2008-10-11 10:52 <DIR> d-------- C:\WINDOWS\{6D6098EC-5ED2-48F3-95E8-CBC6337BF3AD}
2008-10-08 19:03 . 2008-10-08 19:03 <DIR> d-------- C:\Program Files\Logitech
2008-10-08 19:03 . 2008-10-08 19:03 <DIR> d-------- C:\Program Files\Common Files\Logitech
2008-10-08 19:03 . 2003-12-17 08:50 152,064 --------- C:\WINDOWS\system32\lmoufrc.dll
2008-10-08 19:03 . 2004-01-08 08:50 104,960 --a------ C:\WINDOWS\system32\COMNCTR.DLL
2008-10-08 19:03 . 2004-01-08 08:50 97,792 --a------ C:\WINDOWS\system32\LGUICOM.DLL
2008-10-08 19:03 . 2003-12-17 08:50 70,801 --a------ C:\WINDOWS\system32\drivers\LMouFlt2.Sys
2008-10-08 19:03 . 2003-12-17 08:50 51,729 --a------ C:\WINDOWS\system32\drivers\L8042pr2.Sys
2008-10-08 19:03 . 2003-12-17 08:50 37,887 --------- C:\WINDOWS\system32\drivers\LHIDUSB.SYS
2008-10-08 19:03 . 2003-12-17 08:50 25,505 --------- C:\WINDOWS\system32\drivers\LHIDFLT2.SYS
2008-10-08 19:03 . 2003-12-17 08:50 23,375 --a------ C:\WINDOWS\system32\LCoInst.Dll
2008-10-08 19:03 . 2003-12-17 08:50 19,968 --------- C:\WINDOWS\LOGI_MWX.EXE
2008-10-08 19:03 . 2004-01-08 08:50 16,896 --a------ C:\WINDOWS\system32\LMOUSE32.DLL
2008-10-08 19:03 . 2003-12-17 08:50 14,095 --------- C:\WINDOWS\system32\drivers\LCCFLTR.SYS
2008-10-08 19:03 . 2004-01-08 08:50 3,568 --a------ C:\WINDOWS\system32\LMOUSE16.DLL
2008-10-02 18:58 . 2008-10-02 18:58 331 --a------ C:\WINDOWS\doom3.ini
2008-09-18 13:00 . 2008-09-18 13:03 <DIR> d-------- C:\WINDOWS\NV35803576.TMP
2008-09-17 21:33 . 2008-09-17 21:34 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-09-17 21:27 . 2008-09-18 13:03 <DIR> d-------- C:\WINDOWS\nview
2008-09-15 17:44 . 2008-10-25 20:32 <DIR> d-------- C:\Warhammer Online - Age of Reckoning
2008-09-13 12:32 . 2008-10-21 19:05 <DIR> d-------- C:\Program Files\StuffPlug3
2008-09-13 12:32 . 2008-09-13 12:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
2008-09-13 12:29 . 2008-09-13 12:29 <DIR> d-------- C:\Program Files\Windows Live
2008-09-13 12:29 . 2008-09-13 12:29 <DIR> d-------- C:\Program Files\Messenger Plus! Live
2008-09-05 21:13 . 2008-09-05 21:14 <DIR> d-------- C:\Program Files\Hamachi
2008-09-05 12:32 . 2008-09-05 12:32 <DIR> d-------- C:\Documents and Settings\rob beddall\Application Data\NSeries
2008-09-05 12:25 . 2008-09-05 12:25 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-09-05 12:25 . 2008-09-05 12:25 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nokia
2008-09-05 12:23 . 2008-09-05 12:26 <DIR> d-------- C:\Documents and Settings\rob beddall\Application Data\Nokia
2008-09-05 12:23 . 2008-09-05 12:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
2008-09-05 12:22 . 2008-09-05 12:22 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-09-05 12:22 . 2008-09-05 12:22 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-09-05 12:22 . 2008-09-05 12:22 <DIR> d-------- C:\Documents and Settings\rob beddall\Application Data\PC Suite
2008-09-05 12:22 . 2007-02-22 09:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys
2008-09-05 12:21 . 2008-09-05 12:25 <DIR> d-------- C:\Program Files\Nokia
2008-09-05 12:21 . 2007-02-22 09:15 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2008-09-05 12:21 . 2007-02-22 09:15 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2008-09-05 12:21 . 2007-02-22 09:15 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-09-05 12:21 . 2007-02-22 09:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2008-09-05 12:21 . 2007-02-22 09:15 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-10-30 21:50 2,810 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-10-25 12:54 --------- d-----w C:\Documents and Settings\rob beddall\Application Data\LimeWire
2008-10-11 18:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-11 18:00 --------- d-----w C:\Program Files\Bethesda Softworks
2008-10-02 18:58 --------- d-----w C:\Program Files\Doom 3
2008-09-18 17:35 --------- d-----w C:\Program Files\BitLord
2008-09-18 17:33 --------- d-----w C:\Program Files\PokerStars
2008-09-18 17:33 --------- d-----w C:\Program Files\Doomsday
2008-09-18 17:32 --------- d-----w C:\Program Files\Prey
2008-09-18 17:26 --------- d-----w C:\Program Files\Sonic Foundry
2008-09-18 17:23 --------- d-----w C:\Program Files\Google
2008-09-18 17:22 --------- d-----w C:\Program Files\CyberLink
2008-09-17 22:15 --------- d-----w C:\Documents and Settings\rob beddall\Application Data\Bioshock
2008-09-15 17:17 --------- d-----w C:\Program Files\Unreal Tournament 3
2008-09-13 12:32 --------- d-----w C:\Program Files\MSN Messenger
2008-09-12 22:19 --------- d-----w C:\Program Files\Starcraft
2008-09-11 18:48 --------- d-----w C:\Program Files\SEGA
2008-09-11 18:45 --------- d-----w C:\Program Files\Jade Empire
2008-09-10 11:22 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-09-06 11:52 --------- d-----w C:\Program Files\Lavasoft
2008-09-06 11:51 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-06 11:50 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2008-09-06 10:22 --------- d-----w C:\Program Files\Pixologic
2008-09-06 10:10 --------- d-----w C:\Program Files\Diablo II
2008-09-05 21:52 --------- d-----w C:\Documents and Settings\rob beddall\Application Data\Hamachi
2008-09-05 21:13 17,480 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-09-05 12:22 --------- d-----w C:\Program Files\DIFX
2008-08-07 20:49 828 ----a-w C:\Documents and Settings\rob beddall\Application Data\wklnhst.dat
2008-07-03 19:55 86,528 ----a-w C:\WINDOWS\bnetunin.exe
2008-07-03 18:24 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-10-10 19:13 22,328 ----a-w C:\Documents and Settings\rob beddall\Application Data\PnkBstrK.sys
2007-09-29 12:15 1 ----a-w C:\Documents and Settings\rob beddall\SI.bin
beddall
10-31-2008, 05:41 PM
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\ahwrlib.dll
2008-07-30 16:39 229376 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093665.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\akhld.dll
2008-07-30 16:39 217088 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093664.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\arf.dll
2008-07-30 16:39 233472 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093663.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\bivouac.dll
2008-07-30 16:39 917504 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093662.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\cerf.dll
2008-07-30 16:39 397312 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093661.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\dcx.dll
2008-07-30 16:39 4485120 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093660.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\dosser.dll
2008-07-30 16:39 577536 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093659.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\EmuLoader.dll
2008-07-30 16:39 24576 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093658.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\GTArcade.dll
2008-07-30 16:39 1511424 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093657.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\jrm.dll
2008-07-30 16:39 2162688 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093656.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\libexpat.dll
2008-07-30 16:39 143360 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093655.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\minsky.dll
2008-07-30 16:39 163840 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093654.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\naur.dll
2008-07-30 16:39 1572864 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093653.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\pcgitl.dll
2008-07-30 16:39 2609152 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093652.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\Pong.dll
2008-07-30 16:39 110592 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093651.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\rill6.dll
2008-07-30 16:39 2605056 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093650.dll
C:\Documents and Settings\All Users\Application Data\GameTap\appdata\bindata\data\wirth.dll
2008-07-30 16:39 438272 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093649.dll
2004-08-04 12:00 25600 C:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2004-08-04 12:00 25600 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093867.dll
2004-08-04 12:00 25600 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP776\A0109335.dll
C:\Documents and Settings\rob beddall\Desktop\warhammeronline\WAREuropeanOpenBet a.exe
2008-09-05 18:45 429104 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093817.exe
2006-06-19 19:12 225280 C:\Documents and Settings\rob beddall\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
2006-06-19 19:12 225280 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP761\A0094014.exe
C:\Program Files\BitLord\BitLord.exe
2005-05-07 00:47 2224128 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093634.exe
C:\Program Files\BitLord\uninst.exe
2007-10-20 12:33 74172 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093635.exe
2008-10-11 17:52 2228224 C:\Program Files\Doom 3\base\gamex86.dll
2008-10-02 19:01 2228224 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP770\A0098246.dll
C:\Program Files\Doomsday\bin\Doomsday.exe
2007-01-09 20:53 1212416 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093569.exe
C:\Program Files\Doomsday\bin\dpDehRead.dll
2007-01-09 20:53 106496 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093562.dll
C:\Program Files\Doomsday\bin\dpMapLoad.dll
2007-01-09 20:53 143360 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093561.dll
C:\Program Files\Doomsday\bin\drD3D.dll
2007-01-09 20:54 327680 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093565.dll
C:\Program Files\Doomsday\bin\drOpenGL.dll
2007-01-09 20:53 90112 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093564.dll
C:\Program Files\Doomsday\bin\dsCompat.dll
2007-01-09 20:54 110592 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093563.dll
C:\Program Files\Doomsday\bin\eax.dll
2001-02-22 11:58 98304 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093558.dll
C:\Program Files\Doomsday\bin\jDoom.dll
2007-01-09 20:54 778240 {54C7A4C0-672A-400F-89D3-264781F4E928}\RP756\A0093568.dll
C:\Program Files\Doomsday\bin\jHeretic.dll
{54C7A4C0-672
beddall
10-31-2008, 05:41 PM
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-25 151597]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 131072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 77824]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"NSLauncher"="C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-09-07 3100672]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 C:\WINDOWS\system32\ptipbmf.dll]
"SoundMan"="SOUNDMAN.EXE" [2005-10-04 C:\WINDOWS\soundman.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 C:\WINDOWS\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
C:\Documents and Settings\rob beddall\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2006-06-19 225280]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Belkin F5D8053 N Wireless USB Adapter Utility.lnk - C:\Program Files\Belkin\F5D8053\Belkinwcui.exe [2007-09-17 1732608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Autodesk\\3dsMax8\\3dsmax.exe"=
"C:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
"C:\\Program Files\\Autodesk\\backburner\\manager.exe"=
"C:\\Program Files\\Autodesk\\backburner\\server.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"C:\\Program Files\\THQ\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"=
"C:\\Program Files\\THQ\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"C:\\Program Files\\Sunbelt Software\\Personal Firewall 4\\kpf4gui.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-10-21 97928]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2005-12-15 274432]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2005-12-15 81920]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-10-21 875288]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-21 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-10-21 76040]
R2 AWISp50;AWISp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\AWISp50.sys [2006-03-15 17664]
R2 ithsgt;ithsgt;C:\WINDOWS\system32\DRIVERS\ithsgt.s ys [2006-05-29 162432]
R2 lilsgt;lilsgt;C:\WINDOWS\system32\DRIVERS\lilsgt.s ys [2006-05-29 12032]
S3 bfastfao;bfastfao;C:\DOCUME~1\ROBBED~1\LOCALS~1\Te mp\bfastfao.sys [ ]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;C:\DOCUME~1\ROBBED~1\LOCALS~1\Temp\Onli neScanner\Anti-Virus\fsgk.sys [ ]
S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sy s [2006-08-28 10664]
S3 imhidusb;Immersion's HID USB Driver;C:\WINDOWS\system32\DRIVERS\imhidusb.sys [2004-08-16 30984]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;C:\WINDOWS\system32\DRIVERS\rt2870.sys [2007-07-28 517632]
S3 SaiHFFB5;SaiHFFB5;C:\WINDOWS\system32\DRIVERS\SaiH FFB5.sys [2004-08-16 56576]
S4 m5287;m5287;C:\WINDOWS\system32\DRIVERS\m5287.sys [2005-02-05 85888]
S4 m5289;m5289;C:\WINDOWS\system32\DRIVERS\m5289.sys [2004-12-01 51840]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Adobe Photo Downloader - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
HKU-Default-Run-brastk - C:\WINDOWS\system32\brastk.exe
SafeBoot-TDSSyaxt.sys
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\DOCUME~1\ROBBED~1\APPLIC~1\Mozilla\Firefox\Prof iles\cns82agj.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.facebook.com/home.php?
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Real\RealOne Player\Netscape6\nppl3260.dll
FF -: plugin - C:\Program Files\Real\RealOne Player\Netscape6\nprjplug.dll
FF -: plugin - C:\Program Files\Real\RealOne Player\Netscape6\nprpjplug.dll
.
beddall
10-31-2008, 05:42 PM
************************************************** ************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-31 09:25:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\T DSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSoiqh.sys"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
.
************************************************** ************************
.
Completion time: 2008-10-31 9:35:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-31 09:34:58
Pre-Run: 38,259,900,416 bytes free
Post-Run: 44,782,379,008 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOW S
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
347 --- E O F --- 2008-02-20 01:26:22
beddall
10-31-2008, 05:42 PM
Malwarebytes' Anti-Malware 1.30
Database version: 1306
Windows 5.1.2600 Service Pack 2
31/10/2008 09:00:46
mbam-log-2008-10-31 (09-00-46).txt
Scan type: Quick Scan
Objects scanned: 66267
Time elapsed: 5 minute(s), 30 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\delself.bat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\rob beddall\Local Settings\Temp\opr32.tmp (Heuristics.Malware) -> Quarantined and deleted successfully.
beddall
10-31-2008, 05:43 PM
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:19:05, on 31/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Belkin F5D8053 N Wireless USB Adapter Utility.lnk = C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.meshcomputers.com
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - [url]http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab[/url]
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - [url]http://download.bitdefender.com/resources/scan8/oscan8.cab[/url]
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - [url]http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab[/url]
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - [url]http://www.pcpitstop.com/mhLbl.cab[/url]
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - [url]http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab[/url]
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - [url]http://support.f-secure.com/ols/fscax.cab[/url]
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - [url]http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab[/url]
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - [url]http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab[/url]
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: License Management Service ESD - Unknown owner - C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe
O23 - Service: Mdrfrmtvi - ULi Electronics Inc. - (no file)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 8318 bytes
beddall
10-31-2008, 05:45 PM
I think thats all the logs :)
does everything look ok?
I will post back in an hour or so to update you on how everything is running.
thankyou for your time and effort
it's very much appreciated
beddall
10-31-2008, 07:50 PM
hi,
everything still appears to be working fine.
thanks again
classicsoftware
11-01-2008, 12:23 AM
Open Hijackthis and place a check next to:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
Close all open program and browser windows except for Hijackthis and click fix checked. Then re-boot.
Now that you are clean, you need to keep it that way. Please follow the rules below. Pay careful attention to number 4. Since the release of Service Pack 2 for Windows XP, Microsoft has greatly improved the security of Windows. The majority of attacks now occur in other software. Adobe Acrobat Reader is the most attacked program right now. You need to keep your software up to date and the Secunia PSI is the best way to go.
You had spyware so it needed to be cleaned anyway, now you need to keep it that way.
How to Protect Yourself While On-Line
Make sure you have an up to date Antivirus. Scan Regularly. There are many free versions:
AVAST (http://www.avast.com/eng/download-avast-home.html)
AVG (http://free.grisoft.com/freeweb.php/doc/2/)
Antivir (http://www.free-av.com/antivirus/allinonen.html)
Make sure you have a software firewall and if you are on broadband, get behind a NAT router. There are also free versions:
Kerio (http://www.sunbelt-software.com/Home-Home-Office/Sunbelt-Personal-Firewall/)
Sygate (http://www.filehippo.com/download_sygate_personal_firewall/)
Zone Alarm (http://www.zonealarm.com/store/content/catalog/products/sku_list_za.jsp%3bjsessionid=BzJnZDxzyCUCcyZMB2t0Q co5IgutuYlrOMI5snmy1ZptQ2vOr1l1!776180791!-1062696904!7551!7552!-2099742426!-1062696903!7551!7552)
Keep Windows up to date. Visit Windows Update (http://windowsupdate.microsoft.com) and Office Update (http://office.microsoft.com/en-us/downloads/default.aspx) regularly.
Keep all of your software up to date. You can check on your software with the Secunia Software Inspector (http://secunia.com/software_inspector/). Sign up for e-mail notification and they will tell you when to check your system again.
Use Firefox (http://www.mozilla.org/products/) with the NoScript (http://noscript.net/) extension as your web browser.
Download, install and keep an updated version of SpywareBlaster (http://www.javacoolsoftware.com/sbdownload.html).
Do NOT click on links in any I.M. program.
Use Thunderbird (http://www.mozilla.com/en-US/thunderbird/) in place of Outlook or Outlook Express.
Use Foxit Reader (http://www.download.com/Foxit-PDF-Reader/3000-2079_4-10313206.html) with the PDF Download (https://addons.mozilla.org/en-US/firefox/addon/636) extension instead of Adobe Acrobat Reader.
DO NOT open attachments from ANYONE. Download them, and scan them with your AV before opening and only if your expect to receive them.
If you use IE download a copy of IE-Spyad (http://www.spywarewarrior.com/uiuc/resource.htm).
beddall
11-01-2008, 08:23 AM
hi,
something seems to have gone a bit wrong somewhere. :(
I ran another virus check this morning it has picked up loads of viruses. it's still running and has so far found 28 and is finding a new one every 2 seconds or so :(
my computer is poorly.
should i post the log from the virus checker?
classicsoftware
11-01-2008, 10:31 AM
Absolutely. I'll have limited availability today so please be patient.
classicsoftware
11-02-2008, 12:17 AM
Still waiting for a list if the infected files...
classicsoftware
11-23-2008, 07:21 PM
hi,
something seems to have gone a bit wrong somewhere. :(
I ran another virus check this morning it has picked up loads of viruses. it's still running and has so far found 28 and is finding a new one every 2 seconds or so :(
my computer is poorly.
should i post the log from the virus checker?
What program is picking them up?
What are they?
Please run MBAM, even if you cant update the program.
vBulletin v3.6.1, Copyright ©2000-2012, Jelsoft Enterprises Ltd.