Rogue virus slows things and opening IE constantly

View previous topic View next topic Go down

Rogue virus slows things and opening IE constantly

Post by sossamonster on Fri Jan 15, 2010 8:12 pm

Okay so last night I got one of these horrible fake Security Center malware things. I'm on Vista and use Firefox. I was just using StumbleUpon, wasn't even on a shady site or anything, and then suddenly the pop ups started. Made it seem like Security Center was open and finding Trojans and the usual mess. Somehow I got it to stop opening that completely so I don't have to deal with it. At first, when I would Google anything to do with spyware or anti-malware stuff, when I clicked on a link it would redirect me to those sites to buy their anti-spyware products. So I had to use the cached links in Google for a while and eventually found some things to try.

I tried the whole SmitfraudFix thing... no idea if it did anything, it obviously didn't get rid of the problem. However, Security Center isn't opening anymore and I'm not having any problems with the Google links anymore. Things just seem slow still and laggy. And, of course, I can't run any anti-malware stuff, like Malwarebytes, even in safe mode. I've renamed the files and everything, tried to put it on a flash drive and then on my comp, still can't. Has a runtime error 0 then 404.

Also, the virus seems to open up iexplorer.exe in the task manager, but it doesn't open on my screen for me to see. So IE slowly uses more memory and if I don't go into task manager and end the process, suddenly a random video will start playing. I can't see it, but I just hear this video, and once I close iexplorer.exe in the manager, it stops. So weird.

Sorry for the long bits. Here are my logs from HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:54:08 PM, on 1/15/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Launch Manager\WButton.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\vVX3000.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynMedion.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Launch Manager\OSD.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Users\Admin\Desktop\winlogon.scr

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HotkeyApp] "C:\Program Files\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [VX3000] C:\Windows\vVX3000.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - [You must be registered and logged in to see this link.]
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{4F6F54AA-F55A-4928-9895-664151033C1A}: NameServer = 192.168.1.115
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe

--
End of file - 8053 bytes

sossamonster
Novice
Novice

Posts Posts : 5
Joined Joined : 2010-01-15
OS OS : Windows Vista
Points Points : 25223
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Rogue virus slows things and opening IE constantly

Post by Belahzur on Fri Jan 15, 2010 11:57 pm

Hello.

  • Open HijackThis.
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)



  • Press "Fix Checked"
  • Close Hijack This.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Rogue virus slows things and opening IE constantly

Post by sossamonster on Sat Jan 16, 2010 12:59 am

Thank you. I did this earlier... I finally got it to install from a CD. It deleted a couple of things, one a Trojan, but things still seem a bit weird. Things feel a little slow still... and now MBAM won't even run fully anymore. I will scan it, and it says I have 2 more infected files, but the program messes up in the middle of scanning and says it's Not Responding. So I try to close it in Task Manager and it won't close at all, it just hangs. Also, my Security Center icon is not in the Control Panel anymore and wscui.cpl won't open. Hmm....

Here is the log from MBAM:

Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

1/15/2010 4:55:21 PM
mbam-log-2010-01-15 (16-55-21).txt

Scan type: Quick Scan
Objects scanned: 103606
Time elapsed: 5 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
\\?\globalroot\systemroot\System32\H8SRTwbooabpvai.dll (Trojan.Vundo) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT (Rootkit.TDSS) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
\\?\globalroot\systemroot\System32\H8SRTwbooabpvai.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Admin\Desktop\winlogon.scr (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

sossamonster
Novice
Novice

Posts Posts : 5
Joined Joined : 2010-01-15
OS OS : Windows Vista
Points Points : 25223
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Rogue virus slows things and opening IE constantly

Post by Origin on Sat Jan 16, 2010 1:29 am

Hello.

  • Download combofix from here
    [You must be registered and logged in to see this link.]

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:





    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31473
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Rogue virus slows things and opening IE constantly

Post by sossamonster on Sat Jan 16, 2010 1:40 am

I'm trying to get to that page or find another one, but it's getting worse and not letting me go to Bleeping Computer or any other site to download Combofix....

sossamonster
Novice
Novice

Posts Posts : 5
Joined Joined : 2010-01-15
OS OS : Windows Vista
Points Points : 25223
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Rogue virus slows things and opening IE constantly

Post by sossamonster on Sat Jan 16, 2010 3:16 am

Sorry, I got it downloaded finally. Here is the ComboFix report:

ComboFix 10-01-15.01 - Admin 01/15/2010 20:53:43.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1918.873 [GMT -6:00]
Running from: c:\users\Admin\Desktop\Combo-Fix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1223456165-3023162987-3559189558-500
c:\$recycle.bin\S-1-5-21-3543573761-2107299344-2334331303-500
c:\users\Admin\AppData\Roaming\.#
c:\users\Admin\AppData\Roaming\.#\MBX@1220@2392158.###
c:\users\Admin\AppData\Roaming\.#\MBX@1220@2392168.###
c:\users\Admin\AppData\Roaming\.#\MBX@1D2C@2582158.###
c:\users\Admin\AppData\Roaming\.#\MBX@1D2C@2582168.###
c:\users\Admin\AppData\Roaming\.#\MBX@D3C@2582158.###
c:\users\Admin\AppData\Roaming\.#\MBX@D3C@2582168.###
c:\users\Admin\AppData\Roaming\.#\MBX@EAC@2022158.###
c:\users\Admin\AppData\Roaming\.#\MBX@EAC@2022168.###
c:\users\Admin\Documents\cc_20091025_152046.reg
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\drivers\H8SRTwbsxmvjrdx.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\H8SRTixtqlvvilr.dll
c:\windows\system32\h8srtkrl32mainweq.dll
c:\windows\system32\h8srtshsyst.dll
c:\windows\system32\H8SRTvqpqpogtro.dll
c:\windows\system32\H8SRTwbooabpvai.dll
c:\windows\system32\H8SRTxnfxrvxmhd.dat
c:\windows\system32\H8SRTxsubucinci.dll
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\twain_32.dll
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_H8SRTd.sys
-------\Legacy_H8SRTd.sys


((((((((((((((((((((((((( Files Created from 2009-12-16 to 2010-01-16 )))))))))))))))))))))))))))))))
.

2010-01-16 03:04 . 2010-01-16 03:07 -------- d-----w- c:\users\Admin\AppData\Local\temp
2010-01-16 01:19 . 2010-01-16 01:19 -------- d-----w- C:\VundoFix Backups
2010-01-15 22:48 . 2010-01-15 22:48 -------- d-----w- c:\users\Admin\AppData\Roaming\Malwarebytes
2010-01-15 22:47 . 2010-01-07 22:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-15 22:47 . 2010-01-15 22:48 -------- d-----w- c:\program files\Worknow
2010-01-15 22:47 . 2010-01-07 22:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-15 14:09 . 2010-01-15 14:09 -------- d-----w- C:\found.002
2010-01-15 11:15 . 2010-01-15 11:15 -------- d-----w- c:\programdata\Malwarebytes
2010-01-15 10:35 . 2010-01-15 10:35 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-13 03:57 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 03:57 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-09 19:56 . 2010-01-09 19:56 21495 ----a-w- c:\users\Admin\glyph_i.zip
2010-01-03 21:15 . 2010-01-03 21:20 -------- d-----w- c:\program files\Driver Genius
2010-01-03 21:01 . 2010-01-03 21:01 -------- d-----w- c:\users\Admin\AppData\Local\eSupport.com

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-16 03:07 . 2007-10-28 19:02 13025 ----a-w- c:\users\Admin\AppData\Roaming\nvModes.dat
2010-01-16 03:05 . 2007-11-11 01:23 12 ----a-w- c:\windows\bthservsdp.dat
2010-01-16 02:18 . 2008-12-07 21:54 -------- d-----w- c:\programdata\avg8
2010-01-16 01:24 . 2009-07-05 22:31 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-16 01:22 . 2007-08-24 09:24 -------- d-----w- c:\program files\Java
2010-01-16 00:32 . 2009-07-29 19:06 -------- d-----w- c:\users\Admin\AppData\Roaming\.purple
2010-01-15 23:00 . 2008-03-25 04:09 -------- d-----w- c:\programdata\Google Updater
2010-01-15 21:20 . 2009-11-03 01:32 -------- d-----w- c:\program files\Ask.com
2010-01-15 10:41 . 2010-01-15 10:41 35 ----a-w- c:\users\Admin\AppData\Roaming\SetValue.bat
2010-01-15 10:41 . 2010-01-15 10:41 35 ----a-w- c:\users\Admin\AppData\Roaming\SetValue.bat
2010-01-15 10:41 . 2010-01-15 10:41 691 ----a-w- c:\users\Admin\AppData\Roaming\GetValue.vbs
2010-01-15 04:51 . 2007-11-10 04:15 680 ----a-w- c:\users\Admin\AppData\Local\d3d9caps.dat
2010-01-13 18:48 . 2007-08-14 09:44 -------- d-----w- c:\programdata\Microsoft Help
2010-01-13 18:47 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-03 21:16 . 2007-08-24 09:42 -------- d-----w- c:\program files\Google
2009-12-26 22:03 . 2007-10-28 18:51 118440 ----a-w- c:\users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-21 06:54 . 2009-07-29 19:23 -------- d-----w- c:\users\Admin\AppData\Roaming\gtk-2.0
2009-12-15 22:54 . 2008-03-09 02:48 -------- d-----w- c:\users\Admin\AppData\Roaming\Skype
2009-12-15 22:04 . 2008-03-10 16:28 -------- d-----w- c:\users\Admin\AppData\Roaming\skypePM
2009-12-09 19:37 . 2009-12-09 19:37 52238 ----a-w- c:\users\Admin\UDPixel22_installer.exe
2009-12-09 19:18 . 2009-12-09 19:18 124061 ----a-w- c:\users\Admin\PixelRepairerSetup.exe
2009-11-17 16:58 . 2009-11-17 16:58 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-17 16:57 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-17 16:54 . 2009-11-17 16:54 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-17 16:53 . 2009-11-17 16:53 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-13 21:16 . 2009-11-13 21:16 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-09 12:31 . 2009-12-10 09:06 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-10 09:06 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-10 09:06 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-11-06 08:58 . 2009-11-06 08:58 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-11-03 02:42 . 2009-10-02 20:29 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:17 . 2009-11-26 09:01 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-27 14:11 . 2009-12-09 15:00 834048 ----a-w- c:\windows\system32\wininet.dll
2009-10-27 13:16 . 2009-12-09 15:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2008-12-05 19:54 . 2008-12-05 00:03 1228017202 ----a-w- c:\program files\Microsoft Streets and Trips 2009.rar
2007-04-17 10:11 . 2007-04-17 10:11 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2006-11-09 86016]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-15 857648]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-01-13 90191]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-01-13 81920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-01-13 7766016]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2007-04-16 192512]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-05-05 1466368]
"VX3000"="c:\windows\vVX3000.exe" [2006-12-05 707360]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-06-02 7518752]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-16 149280]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
2009-05-19 05:23 49968 ----a-w- c:\program files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoBoingo]
2009-01-08 02:01 2267 ----a-w- c:\program files\Boingo\GoBoingo\GoBoingo.lnk

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-29 02:21 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-01-12 21:48 275800 ----a-w- c:\program files\Microsoft LifeCam\LifeExp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LMgrOSD]
2006-12-26 18:23 180224 ----a-w- c:\program files\Launch Manager\OSD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 22:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 07:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2008-08-12 23:19 21741864 ----a-r- c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
2006-12-05 19:39 707360 ----a-w- c:\windows\vVX3000.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2007-08-30 22:43 4670704 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):43,28,e9,6a,f2,f0,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4276366396-2740148281-4207089869-1000]
"EnableNotificationsRef"=dword:00000001

R3 athrusb6;Atheros Wireless LAN USB device driver 6 Series;c:\windows\System32\drivers\athru6.sys [9/22/2009 9:23 PM 871936]
R3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [8/13/2007 8:32 AM 118784]
S3 athrusb;Atheros Wireless LAN USB device driver;c:\windows\System32\drivers\athrusb.sys [7/29/2008 3:45 AM 904192]
S3 flash;flash;c:\windows\System32\drivers\flash.sys [8/14/2007 10:04 AM 8064]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [6/5/2008 2:05 AM 21504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvLsp.dll
Trusted Zone: turbotax.com
TCP: {4F6F54AA-F55A-4928-9895-664151033C1A} = 192.168.1.115
FF - ProfilePath - c:\users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\lgjxgib6.default\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - prefs.js: keyword.URL - [You must be registered and logged in to see this link.]
FF - plugin: c:\program files\Common Files\Motive\npMotive.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\lgjxgib6.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-Aim6 - (no file)
HKLM-Run-CtrlVol - c:\program files\Launch Manager\CtrlVol.exe
MSConfigStartUp-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
MSConfigStartUp-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
MSConfigStartUp-toolbar_eula_launcher - c:\program files\GoogleEULA\EULALauncher.exe
AddRemove-HijackThis - c:\users\Admin\Desktop\HijackThis.exe



**************************************************************************
scanning hȋdden processes ...

scanning hȋdden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CtrlVol = c:\program files\Launch Manager\CtrlVol.exe?????H?^???????^??5^??f?w?????5^?????0???$???????d??????wT????????u?wEu?w??????^???^?Cb?u????4???&??v??^?????x?^?t?????A???^???????A??i??Cb?u|????????e@?H???????????0?A???[???????A???@???^??|@???^?xi????@???^????

scanning hȋdden files ...

scan completed successfully
hȋdden files:

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Synaptics\SynTP\SynMedion.exe
c:\windows\System32\rundll32.exe
.
**************************************************************************
.
Completion time: 2010-01-15 21:15:14 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-16 03:15

Pre-Run: 46,985,396,224 bytes free
Post-Run: 47,406,759,936 bytes free

- - End Of File - - CCF291124DA462E5A59B4DB012721EB3

sossamonster
Novice
Novice

Posts Posts : 5
Joined Joined : 2010-01-15
OS OS : Windows Vista
Points Points : 25223
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Rogue virus slows things and opening IE constantly

Post by Belahzur on Sat Jan 16, 2010 9:02 pm


  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:

    File::
    c:\users\Admin\glyph_i.zip

    Folder::
    C:\VundoFix Backups
    C:\found.002
    c:\program files\Ask.com

    RegLock::
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
  4. Save this as CFScript.txt, in the same location as ComboFix.exe



  5. Referring to the picture above, drag CFScript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Rogue virus slows things and opening IE constantly

Post by sossamonster on Sat Jan 16, 2010 10:26 pm

ComboFix 10-01-16.02 - Admin 01/16/2010 16:10:41.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1918.1165 [GMT -6:00]
Running from: C:\Users\Admin\Desktop\Combo-Fix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-12-16 to 2010-01-16 )))))))))))))))))))))))))))))))
.

2010-01-16 22:18:29 . 2010-01-16 22:18:29 -------- d-----w- C:\Users\Public\AppData\Local\temp
2010-01-16 22:18:29 . 2010-01-16 22:18:29 -------- d-----w- C:\Users\Default\AppData\Local\temp
2010-01-16 03:15:17 . 2010-01-16 22:18:36 -------- d-----w- C:\Users\Admin\AppData\Local\temp
2010-01-16 01:19:48 . 2010-01-16 01:19:48 -------- d-----w- C:\VundoFix Backups
2010-01-15 22:48:32 . 2010-01-15 22:48:32 -------- d-----w- C:\Users\Admin\AppData\Roaming\Malwarebytes
2010-01-15 22:47:13 . 2010-01-07 22:07:14 38224 ----a-w- C:\Windows\system32\drivers\mbamswissarmy.sys
2010-01-15 22:47:10 . 2010-01-15 22:48:29 -------- d-----w- C:\Program Files\Worknow
2010-01-15 22:47:10 . 2010-01-07 22:07:04 19160 ----a-w- C:\Windows\system32\drivers\mbam.sys
2010-01-15 14:09:44 . 2010-01-15 14:09:44 -------- d-----w- C:\found.002
2010-01-15 11:15:08 . 2010-01-15 11:15:08 -------- d-----w- C:\ProgramData\Malwarebytes
2010-01-15 10:41:42 . 2010-01-15 10:41:42 35 ----a-w- C:\Users\Admin\AppData\Roaming\SetValue.bat
2010-01-15 10:35:24 . 2010-01-15 10:35:24 -------- d-----w- C:\Program Files\Common Files\Wise Installation Wizard
2010-01-13 03:57:01 . 2009-10-19 13:38:10 156672 ----a-w- C:\Windows\system32\t2embed.dll
2010-01-13 03:57:01 . 2009-10-19 13:35:05 72704 ----a-w- C:\Windows\system32\fontsub.dll
2010-01-09 19:56:42 . 2010-01-09 19:56:46 21495 ----a-w- C:\Users\Admin\glyph_i.zip
2010-01-03 21:15:36 . 2010-01-03 21:20:30 -------- d-----w- C:\Program Files\Driver Genius
2010-01-03 21:01:24 . 2010-01-03 21:01:25 -------- d-----w- C:\Users\Admin\AppData\Local\eSupport.com

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-16 22:11:40 . 2009-07-29 19:06:57 -------- d-----w- C:\Users\Admin\AppData\Roaming\.purple
2010-01-16 18:37:40 . 2007-10-28 19:02:46 13025 ----a-w- C:\Users\Admin\AppData\Roaming\nvModes.dat
2010-01-16 03:05:11 . 2007-11-11 01:23:34 12 ----a-w- C:\Windows\bthservsdp.dat
2010-01-16 02:18:32 . 2008-12-07 21:54:02 -------- d-----w- C:\ProgramData\avg8
2010-01-16 01:24:29 . 2009-07-05 22:31:01 411368 ----a-w- C:\Windows\system32\deploytk.dll
2010-01-16 01:22:07 . 2007-08-24 09:24:31 -------- d-----w- C:\Program Files\Java
2010-01-15 23:00:23 . 2008-03-25 04:09:22 -------- d-----w- C:\ProgramData\Google Updater
2010-01-15 21:20:30 . 2009-11-03 01:32:22 -------- d-----w- C:\Program Files\Ask.com
2010-01-15 10:41:41 . 2010-01-15 10:41:41 691 ----a-w- C:\Users\Admin\AppData\Roaming\GetValue.vbs
2010-01-15 04:51:19 . 2007-11-10 04:15:27 680 ----a-w- C:\Users\Admin\AppData\Local\d3d9caps.dat
2010-01-13 18:48:39 . 2007-08-14 09:44:55 -------- d-----w- C:\ProgramData\Microsoft Help
2010-01-13 18:47:48 . 2006-11-02 11:18:33 -------- d-----w- C:\Program Files\Windows Mail
2010-01-03 21:16:53 . 2007-08-24 09:42:28 -------- d-----w- C:\Program Files\Google
2009-12-26 22:03:55 . 2007-10-28 18:51:58 118440 ----a-w- C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-21 06:54:36 . 2009-07-29 19:23:58 -------- d-----w- C:\Users\Admin\AppData\Roaming\gtk-2.0
2009-12-15 22:54:57 . 2008-03-09 02:48:40 -------- d-----w- C:\Users\Admin\AppData\Roaming\Skype
2009-12-15 22:04:58 . 2008-03-10 16:28:54 -------- d-----w- C:\Users\Admin\AppData\Roaming\skypePM
2009-12-09 19:37:22 . 2009-12-09 19:37:15 52238 ----a-w- C:\Users\Admin\UDPixel22_installer.exe
2009-12-09 19:18:42 . 2009-12-09 19:18:35 124061 ----a-w- C:\Users\Admin\PixelRepairerSetup.exe
2009-11-17 16:57:55 . 2006-11-02 10:25:05 665600 ----a-w- C:\Windows\inf\drvindex.dat
2009-11-13 21:16:10 . 2009-11-13 21:16:10 79144 ----a-w- C:\ProgramData\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-09 12:31:42 . 2009-12-10 09:06:43 24064 ----a-w- C:\Windows\system32\nshhttp.dll
2009-11-09 12:30:03 . 2009-12-10 09:06:42 30720 ----a-w- C:\Windows\system32\httpapi.dll
2009-11-09 10:36:45 . 2009-12-10 09:06:42 411648 ----a-w- C:\Windows\system32\drivers\http.sys
2009-11-06 08:58:34 . 2009-11-06 08:58:34 499712 ----a-w- C:\Windows\system32\msvcp71.dll
2009-11-03 02:42:06 . 2009-10-02 20:29:09 195456 ------w- C:\Windows\system32\MpSigStub.exe
2009-10-29 09:17:42 . 2009-11-26 09:01:38 2048 ----a-w- C:\Windows\system32\tzres.dll
2009-10-27 14:11:14 . 2009-12-09 15:00:44 834048 ----a-w- C:\Windows\system32\wininet.dll
2009-10-27 13:16:28 . 2009-12-09 15:00:39 78336 ----a-w- C:\Windows\system32\ieencode.dll
2008-12-05 19:54:21 . 2008-12-05 00:03:14 1228017202 ----a-w- C:\Program Files\Microsoft Streets and Trips 2009.rar
2007-04-17 10:11:11 . 2007-04-17 10:11:11 8192 --sha-w- C:\Windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wbutton"="C:\Program Files\Launch Manager\Wbutton.exe" [2006-11-09 21:37:52 86016]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-15 19:50:10 857648]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-01-13 08:40:00 90191]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-01-13 08:40:00 81920]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-01-13 08:40:00 7766016]
"HotkeyApp"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2007-04-16 22:24:10 192512]
"LaunchAp"="C:\Program Files\Launch Manager\LaunchAp.exe" [2005-07-25 20:36:40 32768]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-05-05 16:01:46 1466368]
"VX3000"="C:\Windows\vVX3000.exe" [2006-12-05 19:39:00 707360]
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-06-02 23:29:34 7518752]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 06:04:34 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2010-01-16 01:24:30 149280]
"CtrlVol"="C:\Program Files\Launch Manager\CtrlVol.exe" [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\Windows\pss\Logitech Desktop Messenger.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\Windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
2009-05-19 05:23:16 49968 ----a-w- C:\Program Files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoBoingo]
2009-01-08 02:01:41 2267 ----a-w- C:\Program Files\Boingo\GoBoingo\GoBoingo.lnk

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44:34 31072 ----a-w- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-29 02:21:26 141600 ----a-w- C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-01-12 21:48:28 275800 ----a-w- C:\Program Files\Microsoft LifeCam\LifeExp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LMgrOSD]
2006-12-26 18:23:34 180224 ----a-w- C:\Program Files\Launch Manager\OSD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 22:40:44 155648 ----a-w- C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 07:54:42 417792 ----a-w- C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2008-08-12 23:19:02 21741864 ----a-r- C:\Program Files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
2006-12-05 19:39:00 707360 ----a-w- C:\Windows\vVX3000.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38:38 1008184 ----a-w- C:\Program Files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2007-08-30 22:43:18 4670704 ----a-w- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):43,28,e9,6a,f2,f0,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4276366396-2740148281-4207089869-1000]
"EnableNotificationsRef"=dword:00000001

R3 athrusb6;Atheros Wireless LAN USB device driver 6 Series;C:\Windows\System32\drivers\athru6.sys [9/22/2009 9:23:16 PM 871936]
S3 athrusb;Atheros Wireless LAN USB device driver;C:\Windows\System32\drivers\athrusb.sys [7/29/2008 3:45:00 AM 904192]
S3 flash;flash;C:\Windows\System32\drivers\flash.sys [8/14/2007 10:04:24 AM 8064]
S3 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [6/5/2008 2:05:00 AM 21504]
S3 WisLMSvc;WisLMSvc;C:\Program Files\Launch Manager\WisLMSvc.exe [8/13/2007 8:32:08 AM 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-01-16 C:\Windows\Tasks\Google Software Updater.job
- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-03-13 04:17:22 . 2009-03-24 04:57:20]
.

sossamonster
Novice
Novice

Posts Posts : 5
Joined Joined : 2010-01-15
OS OS : Windows Vista
Points Points : 25223
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Rogue virus slows things and opening IE constantly

Post by Belahzur on Sun Jan 17, 2010 1:01 am

Hello.
You ran Combofix normally there by double clicking on it, I need you to use my CFScript I posted for you.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum