PDA

View Full Version : CN.WAqDN


Stonesour73
11-21-2008, 12:37 AM
This is a pain in the butt....done every thing i know how to do so now i am asking you guys. I will post the hjt log in a moment.

Description:
Well...in every file on my computer there is a big !!!read This!!! message...and all my files have been converted to .xnc Spybot found it in the lsass.exe file but has not solved the problem. Would love some help....casue yeh...i am outta ideas.

Stonesour73
11-21-2008, 12:47 AM
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:45:04 PM, on 11/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\services.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Windows Live\installer\WLSetupSvc.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\HJT\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe" /waitservice
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227226864031
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum - C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe

--
End of file - 4047 bytes

classicsoftware
11-21-2008, 01:04 AM
First:
How to run a scan with Malwarebytes' Anti-Malware

Download Malwarebytes' Anti-Malware from Here (http://www.besttechie.net/tools/mbam-setup.exe) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.[/QUOTE]

Second:

Please do the following:


Download this file - combofix.exe (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop (it needs to be run from the Desktop). Double click combofix.exe & follow the prompts.
When finished, it will produce a log for you.


Note:

Do not mouseclick Combofix's window while it is running. That may cause the program to stall...

Third:


Re-boot the system
Post the MBAM log
Post the Combofix log
Post a new HJT log
Tell us how the system is running.

Stonesour73
11-21-2008, 01:24 AM
Malwarebytes' Anti-Malware 1.30
Database version: 1414
Windows 5.1.2600 Service Pack 2

11/20/2008 11:12:03 PM
mbam-log-2008-11-20 (23-12-03).txt

Scan type: Quick Scan
Objects scanned: 42264
Time elapsed: 1 minute(s), 49 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
C:\WINDOWS\services.exe (Heuristics.Reserved.Word.Exploit) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{f146c9b1-vmvq-a9rc-nufl-d0ba00b4e999} (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\services.exe (Backdoor.ProRat) -> Quarantined and deleted successfully.
C:\WINDOWS\lsass.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

Stonesour73
11-21-2008, 01:26 AM
ComboFix 08-11-19.08 - Frank 2008-11-20 23:15:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1866 [GMT -6:00]
Running from: c:\documents and settings\Frank\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\LocalService\Cookies\INDEX.DAT.xnc
c:\windows\system32\e100bmsg.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_VFILT
-------\Service_VFILT


((((((((((((((((((((((((( Files Created from 2008-10-21 to 2008-11-21 )))))))))))))))))))))))))))))))
.

2008-11-20 23:18 . 2008-11-20 23:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\ATI
2008-11-20 23:07 . 2008-11-20 23:07 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-20 23:07 . 2008-11-20 23:07 <DIR> d-------- c:\documents and settings\Frank\Application Data\Malwarebytes
2008-11-20 23:07 . 2008-11-20 23:07 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-20 23:07 . 2008-10-22 16:28 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-20 23:07 . 2008-10-22 16:28 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-20 22:41 . 2008-11-20 22:45 <DIR> d-------- C:\HJT
2008-11-20 22:17 . 2008-11-20 22:17 <DIR> d-------- c:\program files\Common Files\Agnitum Shared
2008-11-20 22:17 . 2008-11-20 22:17 <DIR> d-------- c:\program files\Agnitum
2008-11-20 21:43 . 2008-11-20 21:43 <DIR> d--h----- C:\$AVG8.VAULT$
2008-11-20 21:25 . 2008-11-20 21:26 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-20 21:25 . 2008-11-20 22:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-20 20:43 . 2008-11-20 23:19 <DIR> d-------- c:\program files\ATI
2008-11-20 20:40 . 2008-11-20 20:40 <DIR> d-------- C:\ATI
2008-11-20 20:38 . 2008-11-20 20:38 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-11-20 20:38 . <DIR> c:\windows\LastGood.Tmp
2008-11-20 20:38 . 2008-11-20 20:38 <DIR> d-------- c:\documents and settings\Frank\Contacts
2008-11-20 20:37 . 2008-11-20 21:42 <DIR> d-------- c:\program files\Xfire
2008-11-20 20:37 . 2008-11-20 23:11 <DIR> d-------- c:\documents and settings\Frank\Application Data\Xfire
2008-11-20 20:35 . 2008-11-20 20:37 <DIR> d-------- c:\program files\Windows Live
2008-11-20 20:35 . 2008-11-20 20:37 <DIR> d--hsc--- c:\program files\Common Files\WindowsLiveInstaller
2008-11-20 20:35 . 2008-11-20 20:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-20 20:34 . 2008-11-20 20:34 <DIR> d-------- c:\windows\ShellNew
2008-11-20 20:34 . 2008-11-20 20:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\InstallShield
2008-11-20 20:34 . 2008-11-20 20:34 543 --a------ c:\windows\system32\mapisvc.inf
2008-11-20 20:33 . 2008-11-20 20:34 <DIR> d-------- c:\program files\WordPerfect Office 12
2008-11-20 20:33 . 2008-11-20 20:33 <DIR> d-------- c:\program files\Common Files\Corel
2008-11-20 20:33 . 2008-11-20 20:33 <DIR> d-------- c:\program files\Common Files\Borland Shared
2008-11-20 20:29 . 2008-11-20 20:29 <DIR> d-------- c:\program files\filehippo.com
2008-11-20 19:28 . 2008-11-20 19:28 <DIR> d-------- c:\documents and settings\Frank\Application Data\Ventrilo
2008-11-20 18:36 . 2008-11-20 18:36 <DIR> d-------- c:\documents and settings\Frank\Application Data\Webroot
2008-11-20 18:35 . 2008-11-20 18:35 <DIR> d-------- c:\documents and settings\Frank\Application Data\ATI
2008-11-20 18:34 . 2008-11-20 18:34 0 --a------ c:\windows\ativpsrm.bin
2008-11-20 18:31 . 2008-11-20 18:31 <DIR> d-------- c:\program files\Common Files\ATI Technologies
2008-11-20 18:28 . 2006-12-28 10:44 84,992 -ra------ c:\windows\system32\drivers\AtiHdAud.sys
2008-11-20 18:27 . 2008-11-20 20:43 <DIR> d-------- c:\program files\ATI Technologies
2008-11-20 18:27 . 2008-01-22 14:14 3,107,788 -ra------ c:\windows\system32\ativvaxx.dat
2008-11-20 18:27 . 2008-01-22 14:14 3,107,788 -ra------ c:\windows\system32\ativva5x.dat
2008-11-20 18:27 . 2008-01-22 14:14 887,724 -ra------ c:\windows\system32\ativva6x.dat
2008-11-20 18:27 . 2008-10-28 21:05 593,920 --------- c:\windows\system32\ati2sgag.exe
2008-11-20 18:27 . 2008-10-28 20:23 425,984 --a------ c:\windows\system32\ATIDEMGX.dll
2008-11-20 18:27 . 2008-10-28 19:49 307,200 --a------ c:\windows\system32\atiiiexx.dll
2008-11-20 18:27 . 2008-08-14 11:42 176,214 --a------ c:\windows\system32\atiicdxx.dat
2008-11-20 18:27 . 2008-09-11 21:55 14,849 --a------ c:\windows\atiogl.xml
2008-11-20 18:27 . 2007-08-31 08:20 7,167 -ra------ c:\windows\system32\atifglpf.xml
2008-11-20 18:23 . 2008-11-20 18:23 <DIR> d--h----- c:\windows\$hf_mig$
2008-11-20 18:21 . 2008-10-16 14:09 43,544 --a------ c:\windows\system32\wups2.dll
2008-11-20 18:21 . 2008-10-16 14:09 31,768 --a------ c:\windows\system32\wucltui.dll.mui
2008-11-20 18:21 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuaucpl.cpl.mui
2008-11-20 18:21 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuapi.dll.mui
2008-11-20 18:21 . 2008-10-16 14:07 18,456 --a------ c:\windows\system32\wuaueng.dll.mui
2008-11-20 18:21 . 2008-11-20 23:07 2 --a------ c:\windows\feedback.html
2008-11-20 18:20 . 2008-11-20 18:20 <DIR> d-------- c:\program files\Windows Media Connect 2
2008-11-20 18:19 . 2008-11-20 18:19 <DIR> d-------- C:\4541aed490fafe94051ca91ec13b
2008-11-20 18:19 . 2008-11-20 18:19 3,462 --a------ c:\windows\system32\spupdsvc.inf
2008-11-20 18:18 . 2008-11-20 18:18 <DIR> d-------- c:\windows\system32\LogFiles
2008-11-20 18:18 . 2008-11-20 18:19 <DIR> d-------- c:\windows\system32\drivers\UMDF
2008-11-20 18:18 . 2008-11-20 18:32 <DIR> d-------- c:\windows\system32\drivers\Avg
2008-11-20 18:18 . 2008-11-20 18:18 <DIR> d-------- c:\program files\AVG
2008-11-20 18:18 . 2008-11-20 18:18 <DIR> d---s---- c:\documents and settings\Frank\UserData
2008-11-20 18:18 . 2008-11-20 18:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-20 18:18 . 2008-11-20 18:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2008-11-20 18:18 . 2008-11-20 18:18 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-11-20 18:18 . 2008-11-20 18:18 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys
2008-11-20 18:18 . 2006-09-25 17:58 23,856 --a------ c:\windows\system32\spupdsvc.exe
2008-11-20 18:18 . 2008-11-20 18:18 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-11-20 18:16 . 2008-11-20 18:16 <DIR> d-------- c:\program files\Lavasoft
2008-11-20 18:16 . 2008-11-20 18:16 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-20 18:16 . 2008-11-20 18:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-20 18:15 . 2008-11-20 18:15 <DIR> d-------- c:\program files\Yahoo!
2008-11-20 18:15 . 2008-11-20 18:15 <DIR> d-------- c:\program files\CCleaner
2008-11-20 18:14 . 2008-11-20 18:14 0 --a------ c:\windows\nsreg.dat
2008-11-20 18:13 . 2003-11-03 18:15 1,902 --------- c:\windows\system32\SetupBD.din
2008-11-20 18:12 . 2008-11-20 18:12 <DIR> d-------- c:\program files\torn
2008-11-20 18:12 . 2008-11-20 18:13 <DIR> d-------- C:\drvrtmp
2008-11-20 18:12 . 2008-11-15 12:54 356,606 --a------ c:\windows\NeroDigit32.inf
2008-11-20 18:12 . 2004-10-14 16:30 155,648 --a------ c:\windows\system32\drivers\e100b325.sys
2008-11-20 18:12 . 2004-10-14 16:30 155,648 --a--c--- c:\windows\system32\dllcache\e100b325.sys
2008-11-20 18:12 . 2004-11-16 17:52 126,976 --a------ c:\windows\system32\Prounstl.exe
2008-11-20 18:12 . 2004-10-29 17:01 19,456 --a------ c:\windows\system32\IntelNic.dll
2008-11-20 18:12 . 2004-10-14 16:22 5,110 --a------ c:\windows\system32\e100b325.din
2008-11-20 18:12 . 2008-11-20 18:13 6 --a------ c:\windows\ulodb3.ini
2008-11-20 18:09 . 2008-11-20 18:09 <DIR> d-------- c:\program files\Intel
2008-11-20 18:08 . 2005-03-22 17:20 339,968 --a------ c:\windows\stsystra.exe
2008-11-20 18:08 . 2005-11-16 15:35 159,825 --a------ c:\windows\system32\stac97.cpl
2008-11-20 18:08 . 2004-08-04 00:56 130,048 --a------ c:\windows\system32\ksproxy.ax
2008-11-20 18:08 . 2004-08-04 00:56 130,048 --a--c--- c:\windows\system32\dllcache\ksproxy.ax
2008-11-20 18:08 . 2005-11-16 15:35 112,128 --a------ c:\windows\system32\staco.dll

Stonesour73
11-21-2008, 01:27 AM
2008-11-20 18:08 . 2004-08-03 23:08 60,288 --a------ c:\windows\system32\drivers\drmk.sys
2008-11-20 18:08 . 2004-08-03 23:08 60,288 --a--c--- c:\windows\system32\dllcache\drmk.sys
2008-11-20 18:08 . 2004-08-03 22:58 5,376 --a------ c:\windows\system32\drivers\MSPCLOCK.sys
2008-11-20 18:08 . 2004-08-03 22:58 5,376 --a--c--- c:\windows\system32\dllcache\mspclock.sys
2008-11-20 18:08 . 2004-08-03 22:58 4,992 --a------ c:\windows\system32\drivers\MSPQM.sys
2008-11-20 18:08 . 2004-08-03 22:58 4,992 --a--c--- c:\windows\system32\dllcache\mspqm.sys
2008-11-20 18:08 . 2004-08-04 00:56 4,096 --a------ c:\windows\system32\ksuser.dll
2008-11-20 18:08 . 2004-08-04 00:56 4,096 --a--c--- c:\windows\system32\dllcache\ksuser.dll
2008-11-20 18:07 . 2008-11-20 18:07 <DIR> d-------- c:\program files\SigmaTel
2008-11-20 18:07 . 2008-11-20 18:32 <DIR> d--h----- c:\program files\InstallShield Installation Information
2008-11-20 18:07 . 2008-11-20 20:33 <DIR> d-------- c:\program files\Common Files\InstallShield
2008-11-20 18:07 . 2005-11-16 15:36 1,047,816 --a------ c:\windows\system32\drivers\sthda.sys
2008-11-20 18:07 . 2005-11-16 15:35 172,032 --a------ c:\windows\system32\stacapi.dll
2008-11-20 18:05 . 2008-11-20 20:38 <DIR> d-------- c:\documents and settings\Frank
2008-11-20 18:04 . 2008-11-20 18:04 <DIR> d---s---- c:\windows\system32\Microsoft
2008-11-20 18:04 . 2008-11-20 21:03 <DIR> d--hs---- c:\documents and settings\NetworkService
2008-11-20 18:04 . 2008-11-20 21:03 <DIR> d--hs---- c:\documents and settings\LocalService
2008-11-20 18:04 . 2008-11-20 18:04 8,192 --a------ c:\windows\REGLOCS.OLD
2008-11-20 18:02 . 2004-08-12 07:20 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
2008-11-20 18:01 . 2008-11-20 18:01 <DIR> d-------- c:\windows\system32\xircom
2008-11-20 18:01 . 2008-11-20 18:01 <DIR> d-------- c:\program files\microsoft frontpage
2008-11-20 18:01 . 2008-11-20 21:04 <DIR> d-------- C:\DELL
2008-11-20 18:01 . 2008-11-20 18:19 316,640 --a------ c:\windows\WMSysPr9.prx
2008-11-20 18:01 . 2008-11-20 18:20 23,392 --a------ c:\windows\system32\nscompat.tlb
2008-11-20 18:01 . 2008-11-20 18:20 16,832 --a------ c:\windows\system32\amcompat.tlb
2008-11-20 18:01 . 2008-11-20 18:01 2,577 --a------ c:\windows\system32\CONFIG.NT
2008-11-20 18:01 . 2008-11-20 18:01 0 --a------ c:\windows\control.ini
2008-11-20 18:00 . 2008-11-20 20:34 <DIR> d---s---- c:\windows\Downloaded Program Files
2008-11-20 18:00 . 2008-11-20 21:03 <DIR> d--hs---- c:\documents and settings\All Users\DRM
2008-11-20 18:00 . 2004-08-12 07:24 4,399,505 --a--c--- c:\windows\system32\dllcache\nls302en.lex
2008-11-20 18:00 . 2008-11-20 18:00 749 -rah----- c:\windows\WindowsShell.Manifest
2008-11-20 18:00 . 2008-11-20 18:00 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2008-11-20 18:00 . 2008-11-20 18:00 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2008-11-20 18:00 . 2008-11-20 18:00 749 -rah----- c:\windows\system32\nwc.cpl.manifest
2008-11-20 18:00 . 2008-11-20 18:00 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2008-11-20 18:00 . 2008-11-20 18:00 749 -rah----- c:\windows\system32\cdplayer.exe.manifest
2008-11-20 18:00 . 2008-11-20 18:00 488 -rah----- c:\windows\system32\WindowsLogon.manifest

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-11-15 18:53 32,768 ----a-w c:\windows\UNINSTLV16.exe
2008-10-30 01:25 42,320 ----a-w c:\windows\system32\xfcodec.dll
2008-10-29 03:10 3,341,824 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2008-10-29 02:22 314,880 ----a-w c:\windows\system32\ati2dvag.dll
2008-10-29 02:11 43,520 ----a-w c:\windows\system32\ati2edxx.dll
2008-10-29 02:11 26,112 ----a-w c:\windows\system32\Ati2mdxx.exe
2008-10-29 02:11 188,416 ----a-w c:\windows\system32\atipdlxx.dll
2008-10-29 02:11 147,456 ----a-w c:\windows\system32\Oemdspif.dll
2008-10-29 02:10 143,360 ----a-w c:\windows\system32\ati2evxx.dll
2008-10-29 02:10 10,973,184 ----a-w c:\windows\system32\atioglxx.dll
2008-10-29 02:09 585,728 ----a-w c:\windows\system32\ati2evxx.exe
2008-10-29 02:07 53,248 ----a-w c:\windows\system32\ATIDDC.DLL
2008-10-29 01:57 4,041,472 ----a-w c:\windows\system32\ati3duag.dll
2008-10-29 01:41 2,472,832 ----a-w c:\windows\system32\ativvaxx.dll
2008-10-29 01:25 48,640 ----a-w c:\windows\system32\amdpcom32.dll
2008-10-29 01:21 389,120 ----a-w c:\windows\system32\atikvmag.dll
2008-10-29 01:19 44,032 ----a-w c:\windows\system32\atiadlxx.dll
2008-10-29 01:19 17,408 ----a-w c:\windows\system32\atitvo32.dll
2008-10-29 01:18 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2008-10-29 01:18 253,952 ----a-w c:\windows\system32\atiok3x2.dll
2008-10-29 01:12 577,536 ----a-w c:\windows\system32\ati2cqag.dll
2008-10-21 17:51 118,784 ----a-w c:\windows\system32\atibrtmon.exe
2008-10-21 16:40 81,920 ----a-w c:\windows\system32\ATIODE.exe
2008-10-21 16:40 45,056 ----a-w c:\windows\system32\ATIODCLI.exe
2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 20:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 20:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 20:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 20:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 20:08 34,328 ----a-w c:\windows\system32\wups.dll
.

Stonesour73
11-21-2008, 01:28 AM
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-20 1234712]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"Outpost Firewall"="c:\program files\Agnitum\Outpost Firewall 1.0\outpost.exe" [2002-06-14 78848]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-20 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-11-20 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-20 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-20 76040]
S3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);\??\c:\progra~1\Agnitum\OUTPOS~1.0\k ernel\ADBLOCK.DLL [2008-11-20 15552]
S3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);\??\c:\progra~1\Agnitum\OUTPOS~1.0\k ernel\CONTENT.DLL [2008-11-20 3904]
S3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);\??\c:\progra~1\Agnitum\OUTPOS~1.0\ kernel\DNSCACHE.DLL [2008-11-20 6144]
S3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);\??\c:\progra~1\Agnitum\OUTPOS~1.0\k ernel\FTPFILT.DLL [2008-11-20 6304]
S3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);\??\c:\progra~1\Agnitum\OUTPOS~1.0\ kernel\HTMLFILT.DLL [2008-11-20 7776]
S3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);\??\c:\progra~1\Agnitum\OUTPOS~1.0\ kernel\HTTPFILT.DLL [2008-11-20 9152]
S3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);\??\c:\progra~1\Agnitum\OUTPOS~1.0\ kernel\IMAPFILT.DLL [2008-11-20 7072]
S3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);\??\c:\progra~1\Agnitum\OUTPOS~1.0\ kernel\MAILFILT.DLL [2008-11-20 9920]
S3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);\??\c:\progra~1\Agnitum\OUTPOS~1.0\ kernel\NNTPFILT.DLL [2008-11-20 6656]
S3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);\??\c:\progra~1\Agnitum\OUTPOS~1.0\ kernel\POP3FILT.DLL [2008-11-20 7136]
S3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);\??\c:\progra~1\Agnitum\OUTPOS~1.0\k ernel\PROTECT.DLL [2008-11-20 15584]

[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{208d913d-b760-11dd-b3a6-ccde47cb37c1}]
\Shell\AutoRun\command - h:\tg_root\Uninstall.exe
\Shell\open\command - h:\tg_root\Uninstall.exe

*Newly Created Service* - OUTPOSTFIREWALL

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{Y479C6A0-OTRV-U5KH-S1UE-E0BC10B4E666}]
c:\windows\UNINSTLV16.exe
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Frank\Application Data\Mozilla\Firefox\Profiles\[u]0[/u]oj00rd5.default\
FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
.

************************************************** ************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url]http://www.gmer.net[/url]
Rootkit scan 2008-11-20 23:18:17
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\ati2evxx.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\msiexec.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
.
************************************************** ************************
.
Completion time: 2008-11-20 23:20:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-21 05:19:58

Pre-Run: 74,221,350,912 bytes free
Post-Run: 74,210,156,544 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

266

Stonesour73
11-21-2008, 01:29 AM
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:29:13 PM, on 11/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\stsystra.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe" /waitservice
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227226864031
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum - C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe

--
End of file - 4488 bytes

Stonesour73
11-21-2008, 01:33 AM
all my files are still in xnc format....dunno what else to say on the performance.

classicsoftware
11-21-2008, 09:33 AM
What files are in XNC format?

Stonesour73
11-21-2008, 10:09 AM
It looks seems like all of them. alot of .exe have the .xnc at the end of the file name. The good news is my new installs seem not to be infected.

classicsoftware
11-21-2008, 10:43 AM
Can you rename them?

Stonesour73
11-21-2008, 10:59 AM
yes i am able to rename them but i am not positive on all the names of all the files or the formats they are suppose to be in.

Stonesour73
11-21-2008, 11:05 AM
nvm i see what to do. Is there any way to mass chnage a file type? other wise its gunna be a long day :) any ways. Thank you for the help.

classicsoftware
11-21-2008, 11:30 AM
You cant do a massive re-name as all of them don't have the same extension. Unless they are all .exe files then you coud go to a command prompt, get to the folder in question and type:

rename *.xnc *.exe