I hope I did this correctly
Page 3 of 5
Page 3 of 5 • 1, 2, 3, 4, 5
- BelahzurSite Admin
-
OS : 7 Home Premium x64
Posts : 34948
Rubies : 218221
Likes : 18
Select yes to the reboot.
Once back, can you post a new hijack this log?
Once back, can you post a new hijack this log?

Site Admin / Security Administrator
[Prework] - Please PM me if I fail to respond within 24hrs.


- chrisNovice
-
OS : xp
Posts : 31
Rubies : 3436
Likes : 0
your not gonna be happy
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:21:13 PM, on 11/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://windiwsfsearch.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: (no name) - {F3C6B4F7-9DD5-44B8-90AB-E835CFE5A110} - c:\windows\system32\jaahjaa.dll
O2 - BHO: (no name) - {FD36273A-48C9-48D5-95B6-A91B9320FB37} - c:\windows\system32\mejqoubv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [PC Pitstop Optimize Reminder] C:\Program Files\PCPitstop\Optimize2\Reminder.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] -
O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Mobile User VPN.lnk = C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 192.168.2.8
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 192.168.2.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 192.168.2.8
O20 - Winlogon Notify: ttlffzfc - C:\WINDOWS\SYSTEM32\jaahjaa.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
O23 - Service: SafeNet IKE Service (IREIKE) - SafeNet - C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
--
End of file - 7815 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:21:13 PM, on 11/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://windiwsfsearch.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: (no name) - {F3C6B4F7-9DD5-44B8-90AB-E835CFE5A110} - c:\windows\system32\jaahjaa.dll
O2 - BHO: (no name) - {FD36273A-48C9-48D5-95B6-A91B9320FB37} - c:\windows\system32\mejqoubv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [PC Pitstop Optimize Reminder] C:\Program Files\PCPitstop\Optimize2\Reminder.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] -
O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Mobile User VPN.lnk = C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 192.168.2.8
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 192.168.2.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 192.168.2.8
O20 - Winlogon Notify: ttlffzfc - C:\WINDOWS\SYSTEM32\jaahjaa.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
O23 - Service: SafeNet IKE Service (IREIKE) - SafeNet - C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
--
End of file - 7815 bytes
- BelahzurSite Admin
-
OS : 7 Home Premium x64
Posts : 34948
Rubies : 218221
Likes : 18
Can you download combofix from here?
http://www.sendspace.com/file/pdyoa0
http://www.sendspace.com/file/pdyoa0
Site Admin / Security Administrator
[Prework] - Please PM me if I fail to respond within 24hrs.


- chrisNovice
-
OS : xp
Posts : 31
Rubies : 3436
Likes : 0
yes
- BelahzurSite Admin
-
OS : 7 Home Premium x64
Posts : 34948
Rubies : 218221
Likes : 18
Yay, hopefully we can get it running.
- Double click on ComboFix.exe.
- Follow the prompts. NOTE:
- ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan. - The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.
- Allow ComboFix to download the Recovery Console.
- Accept the End-User License Agreement.
- The Recovery Console will be installed.
- You will this next prompt that asks if you want to continue the malware scan, select yes
- Allow combofix to run
- Post C:\combofix.txt back here.
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
Site Admin / Security Administrator
[Prework] - Please PM me if I fail to respond within 24hrs.


- BelahzurSite Admin
-
OS : 7 Home Premium x64
Posts : 34948
Rubies : 218221
Likes : 18
Hello.
I answered your PM with a new link, please download and follow the instructions above.
I answered your PM with a new link, please download and follow the instructions above.

Site Admin / Security Administrator
[Prework] - Please PM me if I fail to respond within 24hrs.


- chrisNovice
-
OS : xp
Posts : 31
Rubies : 3436
Likes : 0
here we go
ComboFix 08-11-18.03 - Administrator 2008-11-25 17:45:11.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.82 [GMT -6:00]
Running from: c:\documents and settings\Administrator\Desktop\-Combo-Fix-.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\My Documents\My Documents.url
c:\documents and settings\Administrator\My Documents\My Music\My Music.url
c:\documents and settings\Administrator\My Documents\My Pictures\My Pictures.url
c:\documents and settings\Administrator\My Documents\My Videos\My Video.url
c:\windows\system32\jaahjaa.dll . . . . failed to delete
c:\windows\system32\mejqoubv.dll . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DUTZULXJ
-------\Service_dutzulxj
((((((((((((((((((((((((( Files Created from 2008-10-25 to 2008-11-25 )))))))))))))))))))))))))))))))
.
2008-11-25 17:33 . 2008-11-25 17:52 d----c--- C:\-Combo-Fix-
2008-11-25 17:11 . 2008-11-25 17:11 d----c--- C:\_OTMoveIt
2008-11-25 16:48 . 2008-11-25 16:48 250 --a------ c:\windows\gmer.ini
2008-11-25 08:31 . 2008-11-25 08:31 d-------- c:\program files\Common Files\Download Manager
2008-11-25 08:19 . 2008-11-25 08:27 d-------- c:\program files\Perfect Uninstaller
2008-11-25 08:19 . 2008-09-16 18:09 30,080 --a------ c:\windows\system32\drivers\RKHit.sys
2008-11-25 08:19 . 2008-11-25 08:19 42 --a------ c:\windows\system32\AK083E209605E394C.lie
2008-11-24 22:28 . 2007-09-02 20:56 1,686,016 --a------ c:\windows\system32\clinetsuitex6.ocx
2008-11-24 22:28 . 2004-03-09 16:45 662,288 --a------ c:\windows\system32\MSCOMCT2.OCX
2008-11-24 22:28 . 2004-06-14 14:56 427,864 --a------ c:\windows\system32\XceedZip.dll
2008-11-24 20:11 . 2008-11-25 17:51 54,156 --ah----- c:\windows\QTFont.qfn
2008-11-24 20:11 . 2008-11-24 20:11 1,409 --a------ c:\windows\QTFont.for
2008-11-24 12:40 . 2008-11-25 11:07 d-------- c:\program files\NoAdware
2008-11-24 11:43 . 2008-11-24 16:33 d-------- c:\program files\Spybot - Search & Destroy
2008-11-24 11:43 . 2008-11-24 19:12 d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-24 11:25 . 2008-11-24 11:25 0 --a------ c:\windows\nsreg.dat
2008-11-24 10:27 . 2008-11-24 10:27 d-------- c:\temp\google
2008-11-24 10:24 . 2008-11-25 12:34 d-------- c:\documents and settings\All Users\Application Data\Google Updater
2008-11-24 09:41 . 2008-11-24 11:45 d-------- c:\documents and settings\All Users\Application Data\SITEguard
2008-11-24 09:40 . 2008-11-24 09:40 d-------- c:\program files\Common Files\iS3
2008-11-24 09:40 . 2008-11-24 12:08 d-------- c:\documents and settings\All Users\Application Data\STOPzilla!
2008-11-24 09:19 . 2008-11-25 14:12 d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-24 09:18 . 2008-11-24 09:45 d-------- c:\windows\system32\512686
2008-11-24 09:18 . 2008-11-24 09:43 d-------- c:\program files\WebMediaViewer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-25 22:30 7,294 ----a-w c:\documents and settings\Administrator\inetconfigs.dll
2008-11-25 14:38 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-24 18:11 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-11-24 17:54 --------- d-----w c:\documents and settings\All Users\Application Data\PCPitstop
2008-11-24 17:31 --------- d-----w c:\program files\Google
2008-10-04 16:37 --------- d-----w c:\program files\JumpStart
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F3C6B4F7-9DD5-44B8-90AB-E835CFE5A110}]
2008-11-25 17:50 105472 --a------ c:\windows\system32\jaahjaa.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD36273A-48C9-48D5-95B6-A91B9320FB37}]
2007-09-04 17:57 100445 --a------ c:\windows\system32\mejqoubv.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-27 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-12 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="-" [X]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Lexmark X74-X75"="c:\program files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 57344]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-26 267064]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Mobile User VPN.lnk - c:\program files\WatchGuard\Mobile User VPN\SafeCfg.exe [2006-06-08 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\WatchGuard\\Mobile User VPN\\IreIKE.exe"=
"c:\program files\WatchGuard\Mobile User VPN\ViewLog.exe"= c:\program files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog
"c:\program files\WatchGuard\Mobile User VPN\CmonApp.exe"= c:\program files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp
"c:\program files\WatchGuard\Mobile User VPN\vpn.exe"= c:\program files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"38750:TCP"= 38750:TCP:@xpsp2res.dll
"2552:TCP"= 2552:TCP:@xpsp2res.dll
"80:TCP"= 80:TCP:@xpsp2res.dll,-22009
"36875:TCP"= 36875:TCP:@xpsp2res.dll
"49480:TCP"= 49480:TCP:@xpsp2res.dll
"7529:TCP"= 7529:TCP:@xpsp2res.dll
"5908:TCP"= 5908:TCP:@xpsp2res.dll
"60232:TCP"= 60232:TCP:@xpsp2res.dll,-22009
"58952:TCP"= 58952:TCP:@xpsp2res.dll,-22009
"60766:TCP"= 60766:TCP:@xpsp2res.dll,-22009
"33272:TCP"= 33272:TCP:@xpsp2res.dll,-22009
"32080:TCP"= 32080:TCP:@xpsp2res.dll,-22009
"36756:TCP"= 36756:TCP:@xpsp2res.dll,-22009
"62486:TCP"= 62486:TCP:@xpsp2res.dll,-22009
"2571:TCP"= 2571:TCP:@xpsp2res.dll,-22009
"50044:TCP"= 50044:TCP:@xpsp2res.dll,-22009
"63081:TCP"= 63081:TCP:@xpsp2res.dll,-22009
"49686:TCP"= 49686:TCP:@xpsp2res.dll,-22009
R0 pppapgge;Microsoft RPC API Helper;c:\windows\system32\drivers\pppapgge.sys [2004-08-12 23424]
R2 Crypto;Crypto;c:\windows\system32\drivers\Crypto.sys [2006-06-08 521786]
R2 IPSECDRV;SafeNet IPSec Plugin;\??\c:\windows\system32\Drivers\IPSECDRV.sys [2006-06-08 119864]
R3 DniVap;SafeNet WAN Miniport (VA);c:\windows\system32\DRIVERS\vap.sys [2006-06-08 36188]
S3 RkHit;RkHit;\??\c:\windows\system32\drivers\RKHit.sys [2008-11-25 30080]
S3 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2007-01-10 24652]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
HKCU-Run-Uniblue Registry Booster2 - c:\program files\Uniblue\RegistryBooster2\RegistryBooster.exe
HKLM-Run-PC Pitstop Optimize Reminder - c:\program files\PCPitstop\Optimize2\Reminder.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\bxof2t8q.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/webhp?hl=en
FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - c:\program files\Google\Google Updater\2.4.1399.3742\npCIDetect13.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPJPI150_07.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPOJI610.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-25 17:51:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WatchGuard\Mobile User VPN\IreIKE.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\WatchGuard\Mobile User VPN\IPSecMon.exe
c:\program files\RealVNC\VNC4\winvnc4.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lexmark X74-X75\lxbbbmon.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-11-25 17:56:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-25 23:56:05
Pre-Run: 11,099,152,384 bytes free
Post-Run: 11,027,812,352 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
173 --- E O F --- 2008-09-20 14:45:28
ComboFix 08-11-18.03 - Administrator 2008-11-25 17:45:11.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.82 [GMT -6:00]
Running from: c:\documents and settings\Administrator\Desktop\-Combo-Fix-.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\My Documents\My Documents.url
c:\documents and settings\Administrator\My Documents\My Music\My Music.url
c:\documents and settings\Administrator\My Documents\My Pictures\My Pictures.url
c:\documents and settings\Administrator\My Documents\My Videos\My Video.url
c:\windows\system32\jaahjaa.dll . . . . failed to delete
c:\windows\system32\mejqoubv.dll . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DUTZULXJ
-------\Service_dutzulxj
((((((((((((((((((((((((( Files Created from 2008-10-25 to 2008-11-25 )))))))))))))))))))))))))))))))
.
2008-11-25 17:33 . 2008-11-25 17:52
2008-11-25 17:11 . 2008-11-25 17:11
2008-11-25 16:48 . 2008-11-25 16:48 250 --a------ c:\windows\gmer.ini
2008-11-25 08:31 . 2008-11-25 08:31
2008-11-25 08:19 . 2008-11-25 08:27
2008-11-25 08:19 . 2008-09-16 18:09 30,080 --a------ c:\windows\system32\drivers\RKHit.sys
2008-11-25 08:19 . 2008-11-25 08:19 42 --a------ c:\windows\system32\AK083E209605E394C.lie
2008-11-24 22:28 . 2007-09-02 20:56 1,686,016 --a------ c:\windows\system32\clinetsuitex6.ocx
2008-11-24 22:28 . 2004-03-09 16:45 662,288 --a------ c:\windows\system32\MSCOMCT2.OCX
2008-11-24 22:28 . 2004-06-14 14:56 427,864 --a------ c:\windows\system32\XceedZip.dll
2008-11-24 20:11 . 2008-11-25 17:51 54,156 --ah----- c:\windows\QTFont.qfn
2008-11-24 20:11 . 2008-11-24 20:11 1,409 --a------ c:\windows\QTFont.for
2008-11-24 12:40 . 2008-11-25 11:07
2008-11-24 11:43 . 2008-11-24 16:33
2008-11-24 11:43 . 2008-11-24 19:12
2008-11-24 11:25 . 2008-11-24 11:25 0 --a------ c:\windows\nsreg.dat
2008-11-24 10:27 . 2008-11-24 10:27
2008-11-24 10:24 . 2008-11-25 12:34
2008-11-24 09:41 . 2008-11-24 11:45
2008-11-24 09:40 . 2008-11-24 09:40
2008-11-24 09:40 . 2008-11-24 12:08
2008-11-24 09:19 . 2008-11-25 14:12
2008-11-24 09:18 . 2008-11-24 09:45
2008-11-24 09:18 . 2008-11-24 09:43
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-25 22:30 7,294 ----a-w c:\documents and settings\Administrator\inetconfigs.dll
2008-11-25 14:38 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-24 18:11 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-11-24 17:54 --------- d-----w c:\documents and settings\All Users\Application Data\PCPitstop
2008-11-24 17:31 --------- d-----w c:\program files\Google
2008-10-04 16:37 --------- d-----w c:\program files\JumpStart
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F3C6B4F7-9DD5-44B8-90AB-E835CFE5A110}]
2008-11-25 17:50 105472 --a------ c:\windows\system32\jaahjaa.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD36273A-48C9-48D5-95B6-A91B9320FB37}]
2007-09-04 17:57 100445 --a------ c:\windows\system32\mejqoubv.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-27 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-12 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="-" [X]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Lexmark X74-X75"="c:\program files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 57344]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-26 267064]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Mobile User VPN.lnk - c:\program files\WatchGuard\Mobile User VPN\SafeCfg.exe [2006-06-08 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\WatchGuard\\Mobile User VPN\\IreIKE.exe"=
"c:\program files\WatchGuard\Mobile User VPN\ViewLog.exe"= c:\program files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog
"c:\program files\WatchGuard\Mobile User VPN\CmonApp.exe"= c:\program files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp
"c:\program files\WatchGuard\Mobile User VPN\vpn.exe"= c:\program files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"38750:TCP"= 38750:TCP:@xpsp2res.dll
"2552:TCP"= 2552:TCP:@xpsp2res.dll
"80:TCP"= 80:TCP:@xpsp2res.dll,-22009
"36875:TCP"= 36875:TCP:@xpsp2res.dll
"49480:TCP"= 49480:TCP:@xpsp2res.dll
"7529:TCP"= 7529:TCP:@xpsp2res.dll
"5908:TCP"= 5908:TCP:@xpsp2res.dll
"60232:TCP"= 60232:TCP:@xpsp2res.dll,-22009
"58952:TCP"= 58952:TCP:@xpsp2res.dll,-22009
"60766:TCP"= 60766:TCP:@xpsp2res.dll,-22009
"33272:TCP"= 33272:TCP:@xpsp2res.dll,-22009
"32080:TCP"= 32080:TCP:@xpsp2res.dll,-22009
"36756:TCP"= 36756:TCP:@xpsp2res.dll,-22009
"62486:TCP"= 62486:TCP:@xpsp2res.dll,-22009
"2571:TCP"= 2571:TCP:@xpsp2res.dll,-22009
"50044:TCP"= 50044:TCP:@xpsp2res.dll,-22009
"63081:TCP"= 63081:TCP:@xpsp2res.dll,-22009
"49686:TCP"= 49686:TCP:@xpsp2res.dll,-22009
R0 pppapgge;Microsoft RPC API Helper;c:\windows\system32\drivers\pppapgge.sys [2004-08-12 23424]
R2 Crypto;Crypto;c:\windows\system32\drivers\Crypto.sys [2006-06-08 521786]
R2 IPSECDRV;SafeNet IPSec Plugin;\??\c:\windows\system32\Drivers\IPSECDRV.sys [2006-06-08 119864]
R3 DniVap;SafeNet WAN Miniport (VA);c:\windows\system32\DRIVERS\vap.sys [2006-06-08 36188]
S3 RkHit;RkHit;\??\c:\windows\system32\drivers\RKHit.sys [2008-11-25 30080]
S3 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2007-01-10 24652]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
HKCU-Run-Uniblue Registry Booster2 - c:\program files\Uniblue\RegistryBooster2\RegistryBooster.exe
HKLM-Run-PC Pitstop Optimize Reminder - c:\program files\PCPitstop\Optimize2\Reminder.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\bxof2t8q.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/webhp?hl=en
FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - c:\program files\Google\Google Updater\2.4.1399.3742\npCIDetect13.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPJPI150_07.dll
FF -: plugin - c:\program files\Java\jre1.5.0_07\bin\NPOJI610.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-25 17:51:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WatchGuard\Mobile User VPN\IreIKE.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\WatchGuard\Mobile User VPN\IPSecMon.exe
c:\program files\RealVNC\VNC4\winvnc4.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lexmark X74-X75\lxbbbmon.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-11-25 17:56:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-25 23:56:05
Pre-Run: 11,099,152,384 bytes free
Post-Run: 11,027,812,352 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
173 --- E O F --- 2008-09-20 14:45:28
- BelahzurSite Admin
-
OS : 7 Home Premium x64
Posts : 34948
Rubies : 218221
Likes : 18
Were actually making progress.
Now open a new notepad file.
Input this into the notepad file:
Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:

This will open combofix.exe again, agree to it's terms and allow it to run, it may want to reboot after it's done. Post the resulting log back here.

Now open a new notepad file.
Input this into the notepad file:
KILLALL::
Driver::
Viewpoint Manager Service
Microsoft RPC API Helper
File::
c:\windows\system32\AK083E209605E394C.lie
c:\documents and settings\Administrator\inetconfigs.dll
c:\windows\system32\jaahjaa.dll
c:\windows\system32\mejqoubv.dll
c:\windows\system32\drivers\pppapgge.sys
Folder::
c:\program files\NoAdware
c:\windows\system32\512686
c:\program files\WebMediaViewer
c:\program files\Viewpoint
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F3C6B4F7-9DD5-44B8-90AB-E835CFE5A110}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD36273A-48C9-48D5-95B6-A91B9320FB37}]
Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:

This will open combofix.exe again, agree to it's terms and allow it to run, it may want to reboot after it's done. Post the resulting log back here.
Site Admin / Security Administrator
[Prework] - Please PM me if I fail to respond within 24hrs.


- chrisNovice
-
OS : xp
Posts : 31
Rubies : 3436
Likes : 0

ComboFix 08-11-26.01 - Administrator 2008-11-25 18:20:12.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.70 [GMT -6:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFscript.txt,.txt
* Created a new restore point
FILE ::
c:\documents and settings\Administrator\inetconfigs.dll
c:\windows\system32\AK083E209605E394C.lie
c:\windows\system32\drivers\pppapgge.sys
c:\windows\system32\jaahjaa.dll
c:\windows\system32\mejqoubv.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\inetconfigs.dll
c:\program files\NoAdware
c:\program files\NoAdware\noadware4_112408.na
c:\program files\Viewpoint
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\program files\Viewpoint\Common\VistaBoot.sdll
c:\program files\Viewpoint\Viewpoint Manager\CPtask.xml
c:\program files\Viewpoint\Viewpoint Manager\VETscriptInterpreter.dll
c:\program files\Viewpoint\Viewpoint Manager\ViewCP.cpl
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\s.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_av.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_cp.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_up.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bg.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bottom.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab_bg.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_off.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_on.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_off.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_on.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vwpt_logo.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\options.ini
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\viewpoint.ico
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\vmctrl.html
c:\program files\Viewpoint\Viewpoint Manager\ViewCPexe.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgrCore.dll
c:\program files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream_0305000D.dll
c:\program files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
c:\program files\Viewpoint\Viewpoint Media Player\ComponentMgr_0305001C.dll
c:\program files\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini
c:\program files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\AtmoHWConfig.txt
c:\program files\Viewpoint\Viewpoint Media Player\Components\atmosphere.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\AvatarsDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\Components\BlueStreak.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\BookmarksDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\Components\DefaultAvatarIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\Components\DefaultWorldIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\Components\ExtremeShot.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\InternetChatHelp.url
c:\program files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\LensFlares.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\Mts2Reader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\ObjectMovie.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\ServiceComponent.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VectorView.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VETsdk.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMgr.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\WaveletReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\ZoomView.dll
c:\program files\Viewpoint\Viewpoint Media Player\DownloadedComponents\atmosphere_Win\AtmoHWConfig.txt
c:\program files\Viewpoint\Viewpoint Media Player\DownloadedComponents\atmosphere_Win\AvatarsDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\DownloadedComponents\atmosphere_Win\BookmarksDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\DownloadedComponents\atmosphere_Win\DefaultAvatarIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\DownloadedComponents\atmosphere_Win\DefaultWorldIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\DownloadedComponents\atmosphere_Win\InternetChatHelp.url
c:\program files\Viewpoint\Viewpoint Media Player\DownLoadHist.ini
c:\program files\Viewpoint\Viewpoint Media Player\HostRegistry.ini
c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
c:\program files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
c:\program files\Viewpoint\Viewpoint Media Player\MTSDownloadSites.txt
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\AtmoHWConfig.txt
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\AvatarsDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\BookmarksDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\Cursors.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\DefaultAvatarIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\DefaultWorldIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\InternetChatHelp.url
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VMPVideo.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VMPVideo2.dll
c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.xpt
c:\program files\WebMediaViewer
c:\program files\WebMediaViewer\browseu.exe
c:\program files\WebMediaViewer\browseul.dll
c:\program files\WebMediaViewer\hpmun.dll
c:\program files\WebMediaViewer\hpmun.exe
c:\program files\WebMediaViewer\myd.ico
c:\program files\WebMediaViewer\mym.ico
c:\program files\WebMediaViewer\myp.ico
c:\program files\WebMediaViewer\myv.ico
c:\program files\WebMediaViewer\ot.ico
c:\program files\WebMediaViewer\qttasku.exe
c:\program files\WebMediaViewer\ts.ico
c:\windows\system32\512686
c:\windows\system32\AK083E209605E394C.lie
c:\windows\system32\drivers\pppapgge.sys
c:\windows\system32\jaahjaa.dll
c:\windows\system32\mejqoubv.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_VIEWPOINT_MANAGER_SERVICE
-------\Service_Viewpoint Manager Service
-------\Legacy_pppapgge
-------\Service_pppapgge
((((((((((((((((((((((((( Files Created from 2008-10-26 to 2008-11-26 )))))))))))))))))))))))))))))))
.
2008-11-25 17:11 . 2008-11-25 17:11
2008-11-25 16:48 . 2008-11-25 16:48 250 --a------ c:\windows\gmer.ini
2008-11-25 08:31 . 2008-11-25 08:31
2008-11-25 08:19 . 2008-11-25 08:27
2008-11-25 08:19 . 2008-09-16 18:09 30,080 --a------ c:\windows\system32\drivers\RKHit.sys
2008-11-24 22:28 . 2007-09-02 20:56 1,686,016 --a------ c:\windows\system32\clinetsuitex6.ocx
2008-11-24 22:28 . 2004-03-09 16:45 662,288 --a------ c:\windows\system32\MSCOMCT2.OCX
2008-11-24 22:28 . 2004-06-14 14:56 427,864 --a------ c:\windows\system32\XceedZip.dll
2008-11-24 20:11 . 2008-11-25 17:51 54,156 --ah----- c:\windows\QTFont.qfn
2008-11-24 20:11 . 2008-11-24 20:11 1,409 --a------ c:\windows\QTFont.for
2008-11-24 11:43 . 2008-11-24 16:33
2008-11-24 11:43 . 2008-11-24 19:12
2008-11-24 11:25 . 2008-11-24 11:25 0 --a------ c:\windows\nsreg.dat
2008-11-24 10:27 . 2008-11-24 10:27
2008-11-24 10:24 . 2008-11-25 12:34
2008-11-24 09:41 . 2008-11-24 11:45
2008-11-24 09:40 . 2008-11-24 09:40
2008-11-24 09:40 . 2008-11-24 12:08
2008-11-24 09:19 . 2008-11-25 14:12
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-25 14:38 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-24 18:11 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-11-24 17:54 --------- d-----w c:\documents and settings\All Users\Application Data\PCPitstop
2008-11-24 17:31 --------- d-----w c:\program files\Google
2008-10-04 16:37 --------- d-----w c:\program files\JumpStart
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-27 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-12 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="-" [X]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Lexmark X74-X75"="c:\program files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 57344]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-26 267064]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Mobile User VPN.lnk - c:\program files\WatchGuard\Mobile User VPN\SafeCfg.exe [2006-06-08 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\WatchGuard\\Mobile User VPN\\IreIKE.exe"=
"c:\program files\WatchGuard\Mobile User VPN\ViewLog.exe"= c:\program files\WatchGuard\Mobile User VPN\ViewLog.exe:127.0.0.1/255.255.255.255:Enabled:ViewLog
"c:\program files\WatchGuard\Mobile User VPN\CmonApp.exe"= c:\program files\WatchGuard\Mobile User VPN\CmonApp.exe:127.0.0.1/255.255.255.255:Enabled:CMonApp
"c:\program files\WatchGuard\Mobile User VPN\vpn.exe"= c:\program files\WatchGuard\Mobile User VPN\vpn.exe:127.0.0.1/255.255.255.255:Enabled:VPN Connection Manager
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"38750:TCP"= 38750:TCP:@xpsp2res.dll
"2552:TCP"= 2552:TCP:@xpsp2res.dll
"80:TCP"= 80:TCP:@xpsp2res.dll,-22009
"36875:TCP"= 36875:TCP:@xpsp2res.dll
"49480:TCP"= 49480:TCP:@xpsp2res.dll
"7529:TCP"= 7529:TCP:@xpsp2res.dll
"5908:TCP"= 5908:TCP:@xpsp2res.dll
"60232:TCP"= 60232:TCP:@xpsp2res.dll,-22009
"58952:TCP"= 58952:TCP:@xpsp2res.dll,-22009
"60766:TCP"= 60766:TCP:@xpsp2res.dll,-22009
"33272:TCP"= 33272:TCP:@xpsp2res.dll,-22009
"32080:TCP"= 32080:TCP:@xpsp2res.dll,-22009
"36756:TCP"= 36756:TCP:@xpsp2res.dll,-22009
"62486:TCP"= 62486:TCP:@xpsp2res.dll,-22009
"2571:TCP"= 2571:TCP:@xpsp2res.dll,-22009
"50044:TCP"= 50044:TCP:@xpsp2res.dll,-22009
"63081:TCP"= 63081:TCP:@xpsp2res.dll,-22009
"49686:TCP"= 49686:TCP:@xpsp2res.dll,-22009
R2 Crypto;Crypto;c:\windows\system32\drivers\Crypto.sys [2006-06-08 521786]
R2 IPSECDRV;SafeNet IPSec Plugin;\??\c:\windows\system32\Drivers\IPSECDRV.sys [2006-06-08 119864]
R3 DniVap;SafeNet WAN Miniport (VA);c:\windows\system32\DRIVERS\vap.sys [2006-06-08 36188]
S3 RkHit;RkHit;\??\c:\windows\system32\drivers\RKHit.sys [2008-11-25 30080]
*Newly Created Service* - PPPAPGGE
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-25 18:24:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WatchGuard\Mobile User VPN\IreIKE.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\WatchGuard\Mobile User VPN\IPSecMon.exe
c:\program files\RealVNC\VNC4\winvnc4.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lexmark X74-X75\lxbbbmon.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-11-25 18:27:00 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-26 00:26:56
ComboFix2.txt 2008-11-25 23:56:20
Pre-Run: 11,011,641,344 bytes free
Post-Run: 10,992,922,624 bytes free
235 --- E O F --- 2008-09-20 14:45:28
- BelahzurSite Admin
-
OS : 7 Home Premium x64
Posts : 34948
Rubies : 218221
Likes : 18
Very well done Chris.
One more round should do it.
Now open a new notepad file.
Input this into the notepad file:
Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:

This will open combofix.exe again, agree to it's terms and allow it to run, it may want to reboot after it's done. Post the resulting log back here.

One more round should do it.
Now open a new notepad file.
Input this into the notepad file:
KILLALL::
Driver::
pppapgge
RkHit
File::
c:\windows\system32\drivers\RKHit.sys
Folder::
C:\_OTMoveIt
Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:

This will open combofix.exe again, agree to it's terms and allow it to run, it may want to reboot after it's done. Post the resulting log back here.
Site Admin / Security Administrator
[Prework] - Please PM me if I fail to respond within 24hrs.


Page 3 of 5 • 1, 2, 3, 4, 5
Similar topics
Create an account or log in to leave a reply
You need to be a member in order to leave a reply.
Page 3 of 5
Permissions in this forum:
You cannot reply to topics in this forum