Help!

Yahoo search hijacks

 
  

Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs RSS
Next:  Swine Flu_ I R O N Y _ a l e r t  
Author Message
bigbadjonv



Joined: Aug 16, 2009
Posts: 6



PostPosted: Sun Aug 16, 2009 10:10 pm    Post subject: Yahoo search hijacks

Yahoo searches are hijacked, but not Google for some reason. Slowed down computer speeds especially on startup. Browser sometimes unresponsive. Also, sometimes cursor doesn't register clicking, I've also noticed a cmd DOS prompt appear a few times. I've followed the sticky instructions:

Malwarebytes log:
Malwarebytes' Anti-Malware 1.40
Database version: 2635
Windows 5.1.2600 Service Pack 3

8/16/2009 9:12:09 PM
mbam-log-2009-08-16 (21-12-09).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 161802
Time elapsed: 58 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
\\?\globalroot\systemroot\system32\hjgruiuaxikoaj.dll (Trojan.TDSS) -> Delete on reboot.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
\\?\globalroot\systemroot\system32\hjgruiuaxikoaj.dll (Trojan.TDSS) -> Quarantined and deleted successfully.

Super Anti Spyware Log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/16/2009 at 08:21 PM

Application Version : 4.27.1002

Core Rules Database Version : 4058
Trace Rules Database Version: 1998

Scan type : Quick Scan
Total Scan Time : 00:37:09

Memory items scanned : 598
Memory threats detected : 0
Registry items scanned : 417
Registry threats detected : 0
File items scanned : 4899
File threats detected : 1

Adware.Tracking Cookie
C:\Documents and Settings\Jonathan\Cookies\jonathan@atdmt[1].txt

Panda Active Log:
;***********************************************************************************************************************************************************************************
ANALYSIS: 2009-08-16 20:29:41
PROTECTIONS: 2
MALWARE: 1
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
Avira AntiVir PersonalEdition 8.0.1.30 Yes Yes
McAfee VirusScan No Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
02444111 Trj/Alureon.AW Virus/Trojan Yes 1 No No globalroot\systemroot\system32\hjgruiuaxikoaj.dll
;===================================================================================================================================================================================
SUSPECTS
Sent Location o_
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description o_
;===================================================================================================================================================================================
;===================================================================================================================================================================================

HiJackThisLog:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:16:27 PM, on 8/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Jonathan\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe /disabled
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/c...nt/muwe
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 11794 bytes
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Mon Aug 17, 2009 7:22 pm    Post subject:

Welcome to Lockergnome.

Go to http://www.bleepingcomputer.com/combofix/how-to-use-combofix and follow the instructions on how to install the Recovery Console and run ComboFix. Go through all the steps until posting the log part. Post the combofix log here.
Back to top
AIM Address Yahoo Messenger
bigbadjonv



Joined: Aug 16, 2009
Posts: 6



PostPosted: Mon Aug 17, 2009 8:44 pm    Post subject:

ComboFix 09-08-10.06 - Jonathan 08/17/2009 19:29.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.666 [GMT -5:00]
Running from: c:\documents and settings\Jonathan\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: McAfee VirusScan *On-access scanning disabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Installer\3542435.msi
c:\windows\Installer\3542436.msp
c:\windows\Installer\3542437.msp
c:\windows\Installer\3542438.msp
c:\windows\Installer\3542439.msp
c:\windows\Installer\354243a.msp
c:\windows\Installer\354243b.msp
c:\windows\Installer\354243c.msp
c:\windows\Installer\354243d.msp
c:\windows\Installer\354243e.msp
c:\windows\Installer\35424f4.msi
c:\windows\Installer\35424f5.msp
c:\windows\Installer\35424f6.msp
c:\windows\Installer\35424f7.msp
c:\windows\Installer\35424f8.msp
c:\windows\Installer\35424f9.msp
c:\windows\Installer\35424fa.msp
c:\windows\Installer\35424fb.msp
c:\windows\Installer\35424fc.msp
c:\windows\Installer\35424fd.msp
c:\windows\Installer\4f7f631.msp
c:\windows\system32\AutoRun.inf
c:\windows\system32\drivers\hjgruiauifgtaw.sys
c:\windows\system32\hjgruifoptlsoj.dll
c:\windows\system32\hjgruinapcfjem.dat
c:\windows\system32\hjgruirptyvmhl.dat
c:\windows\system32\hjgruiuaxikoaj.dll


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_hjgruimepobfhp
-------\Legacy_hjgruimepobfhp


((((((((((((((((((((((((( Files Created from 2009-07-18 to 2009-08-18 )))))))))))))))))))))))))))))))
.

2009-08-17 04:24 . 2008-03-05 21:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll
2009-08-17 04:21 . 2009-08-17 04:21 152576 ----a-w- c:\documents and settings\Jonathan\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-17 04:20 . 2009-08-17 04:24 -------- d--h--w- c:\windows\msdownld.tmp
2009-08-17 04:20 . 2009-08-17 04:20 -------- d-----w- c:\windows\Logs
2009-08-17 03:53 . 2009-08-17 03:53 -------- d-----w- c:\documents and settings\April\Application Data\Malwarebytes
2009-08-17 00:48 . 2008-06-19 22:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-08-17 00:47 . 2009-08-17 00:47 -------- d-----w- c:\program files\Panda Security
2009-08-16 18:10 . 2009-08-16 18:10 578560 -c--a-w- c:\windows\system32\dllcache\user32.dll
2009-08-16 14:54 . 2009-08-16 14:54 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-16 14:53 . 2009-08-16 14:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-08-16 14:53 . 2009-08-16 14:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-14 23:24 . 2009-08-14 23:24 -------- d-----w- c:\documents and settings\Jonathan\Application Data\TeamViewer
2009-08-14 23:23 . 2009-08-14 23:23 -------- d-----w- c:\program files\TeamViewer
2009-08-14 23:23 . 2009-08-14 23:23 -------- d-----w- c:\documents and settings\Jonathan\temp
2009-08-14 23:22 . 2009-08-14 23:22 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-08-14 23:22 . 2009-08-17 00:40 -------- d-----w- c:\documents and settings\Jonathan\Application Data\skypePM
2009-08-14 23:21 . 2009-08-17 03:59 -------- d-----w- c:\documents and settings\Jonathan\Application Data\Skype
2009-08-14 23:20 . 2009-08-14 23:20 -------- d-----w- c:\program files\Common Files\Skype
2009-08-14 23:20 . 2009-08-14 23:21 -------- d-----r- c:\program files\Skype
2009-08-14 23:20 . 2009-08-14 23:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-08-14 23:17 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\hidserv.dll
2009-08-14 23:16 . 2008-04-13 18:45 60032 ----a-w- c:\windows\system32\drivers\usbaudio.sys
2009-08-14 00:46 . 2009-08-16 00:06 -------- d-----w- c:\windows\ServicePackFiles
2009-08-12 08:06 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-10 00:41 . 2009-08-10 00:41 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-10 00:40 . 2009-08-10 00:40 -------- d-----w- c:\program files\Reference Assemblies
2009-08-10 00:39 . 2009-08-10 00:40 -------- d-----w- C:\494ea76aceb650d086da
2009-08-10 00:39 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-10 00:39 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-10 00:39 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-10 00:39 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-10 00:39 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-10 00:39 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-10 00:39 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-09 05:27 . 2009-08-09 05:27 -------- d-----w- C:\db815cc822d7bc1e28065ccc
2009-08-09 05:27 . 2009-08-09 05:27 -------- d-----w- C:\aca3ca9a529ba60e88b1d70e65
2009-08-06 01:04 . 2009-08-06 01:04 -------- d-----w- c:\windows\ERUNT
2009-08-06 01:03 . 2009-08-16 18:23 -------- d-----w- C:\SDFix
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-05 03:03 . 2009-08-18 00:43 117760 ----a-w- c:\documents and settings\Jonathan\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-05 03:02 . 2009-08-05 03:02 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-05 03:02 . 2009-08-06 23:58 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-08-05 03:02 . 2009-08-05 03:02 -------- d-----w- c:\documents and settings\Jonathan\Application Data\SUPERAntiSpyware.com
2009-08-04 23:12 . 2009-08-16 00:08 -------- d-----w- c:\windows\system32\scripting
2009-08-04 23:12 . 2009-08-16 00:08 -------- d-----w- c:\windows\l2schemas
2009-08-04 23:12 . 2009-08-16 00:08 -------- d-----w- c:\windows\system32\en
2009-08-04 23:12 . 2009-08-16 00:08 -------- d-----w- c:\windows\system32\bits
2009-08-04 23:07 . 2009-08-04 23:07 3942047 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-04 23:02 . 2008-04-14 00:12 226816 -c--a-w- c:\windows\system32\dllcache\npdrmv2.dll
2009-08-04 23:01 . 2008-04-14 00:12 278559 ----a-w- c:\windows\system32\odbcjt32.dll
2009-08-04 23:00 . 2009-06-25 08:25 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-07-30 16:59 . 2009-08-17 04:05 69232 ----a-w- c:\documents and settings\April\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-25 17:17 . 2009-07-25 17:41 -------- d-----w- c:\documents and settings\Jonathan\Application Data\ZipGenius
2009-07-25 17:17 . 2009-07-25 17:17 -------- d-----w- c:\program files\ZipGenius 6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-18 00:42 . 2008-11-04 02:57 -------- d-----w- c:\program files\DNA
2009-08-18 00:42 . 2008-11-04 02:57 -------- d-----w- c:\documents and settings\Jonathan\Application Data\DNA
2009-08-17 04:58 . 2009-07-02 23:20 -------- d-----w- c:\program files\Full Tilt Poker
2009-08-17 04:22 . 2008-11-13 04:10 -------- d-----w- c:\program files\Java
2009-08-17 04:01 . 2008-11-04 02:26 69232 ----a-w- c:\documents and settings\Jonathan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-14 00:50 . 2008-11-07 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-10 00:41 . 2008-11-07 23:57 -------- d-----w- c:\program files\MSBuild
2009-08-06 23:58 . 2009-06-11 22:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-05 09:01 . 2009-08-04 23:02 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 02:48 . 2008-11-04 00:08 77423 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-08-04 23:07 . 2009-05-14 23:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-03 18:36 . 2009-05-14 23:03 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 18:36 . 2009-05-14 23:03 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-30 22:58 . 2009-04-17 01:25 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-26 05:55 . 2008-11-04 02:58 -------- d-----w- c:\documents and settings\Jonathan\Application Data\BitTorrent
2009-07-26 04:06 . 2008-11-04 02:11 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-07-25 10:23 . 2008-11-13 04:10 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2009-08-04 23:02 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2004-08-04 10:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-06 03:08 . 2009-07-06 03:08 -------- d-----w- c:\documents and settings\Jonathan\Application Data\Southwest Airlines
2009-07-06 03:07 . 2009-07-06 03:07 8192 ----a-r- c:\documents and settings\Jonathan\Application Data\Microsoft\Installer\{84031A18-BA9A-4156-A74F-E05B52DDFCE2}\Icon84031A18.exe
2009-07-06 03:07 . 2009-07-06 03:07 -------- d-----w- c:\program files\Southwest Airlines
2009-07-03 03:21 . 2008-11-04 00:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-26 16:50 . 2009-08-04 23:01 666624 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:50 . 2009-08-04 23:03 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-26 05:37 . 2008-11-05 04:34 -------- d-----w- c:\program files\DivX
2009-06-26 05:37 . 2009-06-26 05:37 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-06-25 08:25 . 2009-08-04 23:02 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2009-08-04 23:01 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2009-08-04 23:01 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2009-08-04 23:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2009-08-04 23:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-24 11:18 . 2009-08-04 23:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2009-08-04 23:02 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2009-08-04 23:01 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2009-08-04 23:01 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2009-08-04 23:03 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2009-08-04 23:02 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2009-08-04 23:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2009-08-04 23:01 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-06-02 01:10 . 2009-06-02 01:13 38208 ----a-w- c:\documents and settings\Jonathan\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-05-31 03:37 . 2008-11-04 02:25 75096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-15 342848]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-08-05 1830128]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-06-29 1032192]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Jonathan^Start Menu^Programs^Startup^DING!.lnk]
path=c:\documents and settings\Jonathan\Start Menu\Programs\Startup\DING!.lnk
backup=c:\windows\pss\DING!.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Jonathan^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Jonathan\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [8/16/2009 7:48 PM 28544]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [8/5/2009 4:06 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/5/2009 4:06 PM 74480]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [4/16/2009 8:25 PM 55152]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/5/2009 4:06 PM 7408]
S2 uxthpca;uxthpca;c:\windows\system32\drivers\uomr.sys --> c:\windows\system32\drivers\uomr.sys [?]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 6:08 PM 533360]
S3 NaiFiltr;NaiFiltr;c:\windows\system32\drivers\NaiFiltr.sys [11/3/2008 7:24 PM 23296]
S4 mmgdswm;mmgdswm;c:\windows\system32\drivers\jpewmr.sys --> c:\windows\system32\drivers\jpewmr.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-07-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = www.yahoo.com
uInternet Settings,ProxyOverride = *.local
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\3pzdtdbe.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-17 19:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(652)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3908)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\McAfee.com\Agent\Mcdetect.exe
c:\progra~1\McAfee.com\Agent\McTskshd.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2009-08-18 19:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-18 00:50

Pre-Run: 31,408,054,272 bytes free
Post-Run: 31,360,995,328 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
288 --- E O F --- 2009-08-16 14:37
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Tue Aug 18, 2009 8:28 pm    Post subject:

Open up your Notepad editor (Start->Run, type in notepad and click OK). Copy the text from the quotebox below into Notepad:
Quote:
Driver::
uxthpca
mmgdswm

Save this as CFScript.txt in the same location as the ComboFix.exe tool.
Drag the CFScript.txt into ComboFix.exe
Follow the prompts. When finished, it shall produce a log for you. Post that log in your next reply.

Note: Do not click on combofix's window while it's running. That may cause it to stall.
Back to top
AIM Address Yahoo Messenger
bigbadjonv



Joined: Aug 16, 2009
Posts: 6



PostPosted: Tue Aug 18, 2009 10:40 pm    Post subject:

ComboFix 09-08-10.06 - Jonathan 08/18/2009 21:41.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.466 [GMT -5:00]
Running from: c:\documents and settings\Jonathan\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jonathan\Desktop\CFScript.txt
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
.
- REDUCED FUNCTIONALITY MODE -
.

((((((((((((((((((((((((( Files Created from 2009-07-19 to 2009-08-19 )))))))))))))))))))))))))))))))
.

2009-08-17 04:24 . 2008-03-05 21:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll
2009-08-17 04:21 . 2009-08-17 04:21 152576 ----a-w- c:\documents and settings\Jonathan\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-17 04:20 . 2009-08-17 04:24 -------- d--h--w- c:\windows\msdownld.tmp
2009-08-17 04:20 . 2009-08-17 04:20 -------- d-----w- c:\windows\Logs
2009-08-17 03:53 . 2009-08-17 03:53 -------- d-----w- c:\documents and settings\April\Application Data\Malwarebytes
2009-08-17 00:48 . 2008-06-19 22:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-08-17 00:47 . 2009-08-17 00:47 -------- d-----w- c:\program files\Panda Security
2009-08-16 18:10 . 2009-08-16 18:10 578560 -c--a-w- c:\windows\system32\dllcache\user32.dll
2009-08-16 14:54 . 2009-08-16 14:54 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-16 14:53 . 2009-08-16 14:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-08-16 14:53 . 2009-08-16 14:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-14 23:24 . 2009-08-14 23:24 -------- d-----w- c:\documents and settings\Jonathan\Application Data\TeamViewer
2009-08-14 23:23 . 2009-08-14 23:23 -------- d-----w- c:\program files\TeamViewer
2009-08-14 23:23 . 2009-08-14 23:23 -------- d-----w- c:\documents and settings\Jonathan\temp
2009-08-14 23:22 . 2009-08-14 23:22 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-08-14 23:22 . 2009-08-17 00:40 -------- d-----w- c:\documents and settings\Jonathan\Application Data\skypePM
2009-08-14 23:21 . 2009-08-17 03:59 -------- d-----w- c:\documents and settings\Jonathan\Application Data\Skype
2009-08-14 23:20 . 2009-08-14 23:20 -------- d-----w- c:\program files\Common Files\Skype
2009-08-14 23:20 . 2009-08-14 23:21 -------- d-----r- c:\program files\Skype
2009-08-14 23:20 . 2009-08-14 23:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-08-14 23:17 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\hidserv.dll
2009-08-14 23:16 . 2008-04-13 18:45 60032 ----a-w- c:\windows\system32\drivers\usbaudio.sys
2009-08-14 00:46 . 2009-08-16 00:06 -------- d-----w- c:\windows\ServicePackFiles
2009-08-12 08:06 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-10 00:41 . 2009-08-10 00:41 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-10 00:40 . 2009-08-10 00:40 -------- d-----w- c:\program files\Reference Assemblies
2009-08-10 00:39 . 2009-08-10 00:40 -------- d-----w- C:\494ea76aceb650d086da
2009-08-10 00:39 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-10 00:39 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-10 00:39 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-10 00:39 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-10 00:39 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-10 00:39 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-10 00:39 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-09 05:27 . 2009-08-09 05:27 -------- d-----w- C:\db815cc822d7bc1e28065ccc
2009-08-09 05:27 . 2009-08-09 05:27 -------- d-----w- C:\aca3ca9a529ba60e88b1d70e65
2009-08-06 01:04 . 2009-08-06 01:04 -------- d-----w- c:\windows\ERUNT
2009-08-06 01:03 . 2009-08-16 18:23 -------- d-----w- C:\SDFix
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-05 03:03 . 2009-08-19 02:34 117760 ----a-w- c:\documents and settings\Jonathan\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-05 03:02 . 2009-08-05 03:02 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-05 03:02 . 2009-08-06 23:58 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-08-05 03:02 . 2009-08-05 03:02 -------- d-----w- c:\documents and settings\Jonathan\Application Data\SUPERAntiSpyware.com
2009-08-04 23:12 . 2009-08-16 00:08 -------- d-----w- c:\windows\system32\scripting
2009-08-04 23:12 . 2009-08-16 00:08 -------- d-----w- c:\windows\l2schemas
2009-08-04 23:12 . 2009-08-16 00:08 -------- d-----w- c:\windows\system32\en
2009-08-04 23:12 . 2009-08-16 00:08 -------- d-----w- c:\windows\system32\bits
2009-08-04 23:07 . 2009-08-04 23:07 3942047 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-04 23:02 . 2008-04-14 00:12 226816 -c--a-w- c:\windows\system32\dllcache\npdrmv2.dll
2009-08-04 23:01 . 2008-04-14 00:12 278559 ----a-w- c:\windows\system32\odbcjt32.dll
2009-08-04 23:00 . 2009-06-25 08:25 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-07-30 16:59 . 2009-08-17 04:05 69232 ----a-w- c:\documents and settings\April\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-25 17:17 . 2009-07-25 17:41 -------- d-----w- c:\documents and settings\Jonathan\Application Data\ZipGenius
2009-07-25 17:17 . 2009-07-25 17:17 -------- d-----w- c:\program files\ZipGenius 6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-19 02:42 . 2008-11-04 02:57 -------- d-----w- c:\documents and settings\Jonathan\Application Data\DNA
2009-08-19 02:32 . 2008-11-04 02:57 -------- d-----w- c:\program files\DNA
2009-08-18 04:35 . 2009-07-02 23:20 -------- d-----w- c:\program files\Full Tilt Poker
2009-08-17 04:22 . 2008-11-13 04:10 -------- d-----w- c:\program files\Java
2009-08-17 04:01 . 2008-11-04 02:26 69232 ----a-w- c:\documents and settings\Jonathan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-14 00:50 . 2008-11-07 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-10 00:41 . 2008-11-07 23:57 -------- d-----w- c:\program files\MSBuild
2009-08-06 23:58 . 2009-06-11 22:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-05 09:01 . 2009-08-04 23:02 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 02:48 . 2008-11-04 00:08 77423 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-08-04 23:07 . 2009-05-14 23:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-03 18:36 . 2009-05-14 23:03 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 18:36 . 2009-05-14 23:03 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-30 22:58 . 2009-04-17 01:25 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-26 05:55 . 2008-11-04 02:58 -------- d-----w- c:\documents and settings\Jonathan\Application Data\BitTorrent
2009-07-26 04:06 . 2008-11-04 02:11 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-07-25 10:23 . 2008-11-13 04:10 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2009-08-04 23:02 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2004-08-04 10:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-06 03:08 . 2009-07-06 03:08 -------- d-----w- c:\documents and settings\Jonathan\Application Data\Southwest Airlines
2009-07-06 03:07 . 2009-07-06 03:07 8192 ----a-r- c:\documents and settings\Jonathan\Application Data\Microsoft\Installer\{84031A18-BA9A-4156-A74F-E05B52DDFCE2}\Icon84031A18.exe
2009-07-06 03:07 . 2009-07-06 03:07 -------- d-----w- c:\program files\Southwest Airlines
2009-07-03 03:21 . 2008-11-04 00:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-26 16:50 . 2009-08-04 23:01 666624 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:50 . 2009-08-04 23:03 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-26 05:37 . 2008-11-05 04:34 -------- d-----w- c:\program files\DivX
2009-06-26 05:37 . 2009-06-26 05:37 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-06-25 08:25 . 2009-08-04 23:02 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2009-08-04 23:01 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2009-08-04 23:01 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2009-08-04 23:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2009-08-04 23:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-24 11:18 . 2009-08-04 23:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2009-08-04 23:02 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2009-08-04 23:01 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2009-08-04 23:01 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2009-08-04 23:03 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2009-08-04 23:02 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2009-08-04 23:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2009-08-04 23:01 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-06-02 01:10 . 2009-06-02 01:13 38208 ----a-w- c:\documents and settings\Jonathan\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-05-31 03:37 . 2008-11-04 02:25 75096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot DeleteThis @2009-08-18_00.43.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-19 02:30 . 2009-08-19 02:30 16384 c:\windows\Temp\Perflib_Perfdata_6c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-15 342848]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-08-05 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-06-29 1032192]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Jonathan^Start Menu^Programs^Startup^DING!.lnk]
path=c:\documents and settings\Jonathan\Start Menu\Programs\Startup\DING!.lnk
backup=c:\windows\pss\DING!.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Jonathan^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Jonathan\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [8/16/2009 7:48 PM 28544]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [8/5/2009 4:06 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/5/2009 4:06 PM 74480]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [4/16/2009 8:25 PM 55152]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/5/2009 4:06 PM 7408]
S2 uxthpca;uxthpca;c:\windows\system32\drivers\uomr.sys --> c:\windows\system32\drivers\uomr.sys [?]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 6:08 PM 533360]
S3 NaiFiltr;NaiFiltr;c:\windows\system32\drivers\NaiFiltr.sys [11/3/2008 7:24 PM 23296]
S4 mmgdswm;mmgdswm;c:\windows\system32\drivers\jpewmr.sys --> c:\windows\system32\drivers\jpewmr.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-07-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = www.yahoo.com
uInternet Settings,ProxyOverride = *.local
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\3pzdtdbe.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-18 21:45
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(836)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3640)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-08-19 21:48
ComboFix-quarantined-files.txt 2009-08-19 02:47
ComboFix2.txt 2009-08-18 00:50

Pre-Run: 31,333,691,392 bytes free
Post-Run: 31,328,710,656 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
231 --- E O F --- 2009-08-16 14:37
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Wed Aug 19, 2009 7:12 pm    Post subject:

Did you save those lines in CFScript.txt and then drag/drop it into ComboFix? It didn't look like it was ran successfully. Try it again...refer to my last post.
Back to top
AIM Address Yahoo Messenger
bigbadjonv



Joined: Aug 16, 2009
Posts: 6



PostPosted: Wed Aug 19, 2009 8:29 pm    Post subject:

I'm 100% certain I'm doing what you said, correctly:

----------------------------------------------------------------------------


ComboFix 09-08-10.06 - Jonathan 08/19/2009 19:32.3.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.470 [GMT -5:00]
Running from: c:\documents and settings\Jonathan\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jonathan\Desktop\CFScript.txt
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: McAfee VirusScan *On-access scanning disabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
.
- REDUCED FUNCTIONALITY MODE -
.

((((((((((((((((((((((((( Files Created from 2009-07-20 to 2009-08-20 )))))))))))))))))))))))))))))))
.

2009-08-17 04:24 . 2008-03-05 21:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll
2009-08-17 04:21 . 2009-08-17 04:21 152576 ----a-w- c:\documents and settings\Jonathan\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-17 04:20 . 2009-08-17 04:24 -------- d--h--w- c:\windows\msdownld.tmp
2009-08-17 04:20 . 2009-08-17 04:20 -------- d-----w- c:\windows\Logs
2009-08-17 03:53 . 2009-08-17 03:53 -------- d-----w- c:\documents and settings\April\Application Data\Malwarebytes
2009-08-17 00:48 . 2008-06-19 22:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-08-17 00:47 . 2009-08-17 00:47 -------- d-----w- c:\program files\Panda Security
2009-08-16 18:10 . 2009-08-16 18:10 578560 -c--a-w- c:\windows\system32\dllcache\user32.dll
2009-08-16 14:54 . 2009-08-16 14:54 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-16 14:53 . 2009-08-16 14:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-08-16 14:53 . 2009-08-16 14:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-14 23:24 . 2009-08-14 23:24 -------- d-----w- c:\documents and settings\Jonathan\Application Data\TeamViewer
2009-08-14 23:23 . 2009-08-14 23:23 -------- d-----w- c:\program files\TeamViewer
2009-08-14 23:23 . 2009-08-14 23:23 -------- d-----w- c:\documents and settings\Jonathan\temp
2009-08-14 23:22 . 2009-08-14 23:22 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-08-14 23:22 . 2009-08-17 00:40 -------- d-----w- c:\documents and settings\Jonathan\Application Data\skypePM
2009-08-14 23:21 . 2009-08-17 03:59 -------- d-----w- c:\documents and settings\Jonathan\Application Data\Skype
2009-08-14 23:20 . 2009-08-14 23:20 -------- d-----w- c:\program files\Common Files\Skype
2009-08-14 23:20 . 2009-08-14 23:21 -------- d-----r- c:\program files\Skype
2009-08-14 23:20 . 2009-08-14 23:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-08-14 23:17 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\hidserv.dll
2009-08-14 23:16 . 2008-04-13 18:45 60032 ----a-w- c:\windows\system32\drivers\usbaudio.sys
2009-08-14 00:46 . 2009-08-16 00:06 -------- d-----w- c:\windows\ServicePackFiles
2009-08-12 08:06 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-10 00:41 . 2009-08-10 00:41 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-10 00:40 . 2009-08-10 00:40 -------- d-----w- c:\program files\Reference Assemblies
2009-08-10 00:39 . 2009-08-10 00:40 -------- d-----w- C:\494ea76aceb650d086da
2009-08-10 00:39 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-10 00:39 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-10 00:39 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-10 00:39 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-10 00:39 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-10 00:39 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-10 00:39 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-09 05:27 . 2009-08-09 05:27 -------- d-----w- C:\db815cc822d7bc1e28065ccc
2009-08-09 05:27 . 2009-08-09 05:27 -------- d-----w- C:\aca3ca9a529ba60e88b1d70e65
2009-08-06 01:04 . 2009-08-06 01:04 -------- d-----w- c:\windows\ERUNT
2009-08-06 01:03 . 2009-08-16 18:23 -------- d-----w- C:\SDFix
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-05 03:03 . 2009-08-19 02:34 117760 ----a-w- c:\documents and settings\Jonathan\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-05 03:02 . 2009-08-05 03:02 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-05 03:02 . 2009-08-06 23:58 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-08-05 03:02 . 2009-08-05 03:02 -------- d-----w- c:\documents and settings\Jonathan\Application Data\SUPERAntiSpyware.com
2009-08-04 23:12 . 2009-08-16 00:08 -------- d-----w- c:\windows\system32\scripting
2009-08-04 23:12 . 2009-08-16 00:08 -------- d-----w- c:\windows\l2schemas
2009-08-04 23:12 . 2009-08-16 00:08 -------- d-----w- c:\windows\system32\en
2009-08-04 23:12 . 2009-08-16 00:08 -------- d-----w- c:\windows\system32\bits
2009-08-04 23:07 . 2009-08-04 23:07 3942047 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-04 23:02 . 2008-04-14 00:12 226816 -c--a-w- c:\windows\system32\dllcache\npdrmv2.dll
2009-08-04 23:01 . 2008-04-14 00:12 278559 ----a-w- c:\windows\system32\odbcjt32.dll
2009-08-04 23:00 . 2009-06-25 08:25 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-07-30 16:59 . 2009-08-17 04:05 69232 ----a-w- c:\documents and settings\April\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-25 17:17 . 2009-07-25 17:41 -------- d-----w- c:\documents and settings\Jonathan\Application Data\ZipGenius
2009-07-25 17:17 . 2009-07-25 17:17 -------- d-----w- c:\program files\ZipGenius 6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-20 00:26 . 2008-11-04 02:57 -------- d-----w- c:\documents and settings\Jonathan\Application Data\DNA
2009-08-19 02:32 . 2008-11-04 02:57 -------- d-----w- c:\program files\DNA
2009-08-18 04:35 . 2009-07-02 23:20 -------- d-----w- c:\program files\Full Tilt Poker
2009-08-17 04:22 . 2008-11-13 04:10 -------- d-----w- c:\program files\Java
2009-08-17 04:01 . 2008-11-04 02:26 69232 ----a-w- c:\documents and settings\Jonathan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-14 00:50 . 2008-11-07 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-10 00:41 . 2008-11-07 23:57 -------- d-----w- c:\program files\MSBuild
2009-08-06 23:58 . 2009-06-11 22:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-05 09:01 . 2009-08-04 23:02 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 02:48 . 2008-11-04 00:08 77423 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-08-04 23:07 . 2009-05-14 23:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-03 18:36 . 2009-05-14 23:03 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 18:36 . 2009-05-14 23:03 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-30 22:58 . 2009-04-17 01:25 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-26 05:55 . 2008-11-04 02:58 -------- d-----w- c:\documents and settings\Jonathan\Application Data\BitTorrent
2009-07-26 04:06 . 2008-11-04 02:11 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-07-25 10:23 . 2008-11-13 04:10 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2009-08-04 23:02 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2004-08-04 10:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-06 03:08 . 2009-07-06 03:08 -------- d-----w- c:\documents and settings\Jonathan\Application Data\Southwest Airlines
2009-07-06 03:07 . 2009-07-06 03:07 8192 ----a-r- c:\documents and settings\Jonathan\Application Data\Microsoft\Installer\{84031A18-BA9A-4156-A74F-E05B52DDFCE2}\Icon84031A18.exe
2009-07-06 03:07 . 2009-07-06 03:07 -------- d-----w- c:\program files\Southwest Airlines
2009-07-03 03:21 . 2008-11-04 00:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-26 16:50 . 2009-08-04 23:01 666624 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:50 . 2009-08-04 23:03 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-26 05:37 . 2008-11-05 04:34 -------- d-----w- c:\program files\DivX
2009-06-26 05:37 . 2009-06-26 05:37 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-06-25 08:25 . 2009-08-04 23:02 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2009-08-04 23:01 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2009-08-04 23:01 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2009-08-04 23:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2009-08-04 23:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-24 11:18 . 2009-08-04 23:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2009-08-04 23:02 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2009-08-04 23:01 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2009-08-04 23:01 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2009-08-04 23:03 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2009-08-04 23:02 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2009-08-04 23:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2009-08-04 23:01 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-06-02 01:10 . 2009-06-02 01:13 38208 ----a-w- c:\documents and settings\Jonathan\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-05-31 03:37 . 2008-11-04 02:25 75096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot.TakeThisOut@2009-08-18_00.43.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-19 02:30 . 2009-08-19 02:30 16384 c:\windows\Temp\Perflib_Perfdata_6c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-15 342848]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-08-05 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-06-29 1032192]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Jonathan^Start Menu^Programs^Startup^DING!.lnk]
path=c:\documents and settings\Jonathan\Start Menu\Programs\Startup\DING!.lnk
backup=c:\windows\pss\DING!.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Jonathan^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Jonathan\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [8/16/2009 7:48 PM 28544]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [8/5/2009 4:06 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/5/2009 4:06 PM 74480]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [4/16/2009 8:25 PM 55152]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/5/2009 4:06 PM 7408]
S2 uxthpca;uxthpca;c:\windows\system32\drivers\uomr.sys --> c:\windows\system32\drivers\uomr.sys [?]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 6:08 PM 533360]
S3 NaiFiltr;NaiFiltr;c:\windows\system32\drivers\NaiFiltr.sys [11/3/2008 7:24 PM 23296]
S4 mmgdswm;mmgdswm;c:\windows\system32\drivers\jpewmr.sys --> c:\windows\system32\drivers\jpewmr.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-07-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = www.yahoo.com
uInternet Settings,ProxyOverride = *.local
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\3pzdtdbe.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-19 19:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(836)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(1372)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-08-20 19:36
ComboFix-quarantined-files.txt 2009-08-20 00:35
ComboFix2.txt 2009-08-19 02:48
ComboFix3.txt 2009-08-18 00:50

Pre-Run: 31,347,761,152 bytes free
Post-Run: 31,338,070,016 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
232 --- E O F --- 2009-08-16 14:37
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Fri Aug 21, 2009 7:52 pm    Post subject:

Go to Start->Run and type in cmd and hit OK. Type in each of the following lines hitting ENTER key after each line:

sc stop uxthpca
sc delete uxthpca
sc stop mmgdswm
sc delete mmgdswm


Make sure you get a success message after each sc delete line (two in total).
Back to top
AIM Address Yahoo Messenger
bigbadjonv



Joined: Aug 16, 2009
Posts: 6



PostPosted: Fri Aug 21, 2009 9:57 pm    Post subject:

Done and did receive the success responses on deletes.
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Sat Aug 22, 2009 1:47 pm    Post subject:

Good job. Your log is clean.

To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided.

Are there any problems now? If none, go to Start->Run, copy/paste in combofix /u and hit OK to remove it. You should be set to go.
Back to top
AIM Address Yahoo Messenger
bigbadjonv



Joined: Aug 16, 2009
Posts: 6



PostPosted: Sat Aug 22, 2009 4:23 pm    Post subject:

everything seems to be working fine, thanks so much for your help!
Back to top
Display posts from previous:   
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum