Nuqel.E (I think?)

View previous topic View next topic Go down

Nuqel.E (I think?)

Post by spm88spm on 28th May 2009, 10:43 pm

Hello - newbie but you all look very helpful. This is my work laptop, but my IT could not get it working. I'd love to fix it with your help rather than have to ship it across the country to be rebuilt. I did try to clear this virus myself following steps I found on the Internet...I no longer get the pop-ups but my Internet is still wacky and my McAfee does not seem to be working.

Here is the info from HijackThis. Thank you - Steph

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:40:27 PM, on 5/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\System32\ibmsmbus.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IBM\Director\bin\twgipcsv.exe
C:\Program Files\IBM\Director\bin\twgipc.exe
C:\Program Files\IBM\Director\cimom\bin\wmicimserver.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\FedMenu.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\FLFMSPM\Desktop\Hijack(GP)This.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
O1 - Hosts: ::1 localhost
O1 - Hosts: 94.232.248.66 browser-security.microsoft.com
O1 - Hosts: 94.232.248.66 antivaresys.com
O1 - Hosts: 94.232.248.66 [You must be registered and logged in to see this link.]
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BHO - {BAD4551D-9B24-42cb-9BCD-818CA2DA7B63} - C:\WINDOWS\system32\iehelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [system tool] C:\WINDOWS\sysguard.exe
O4 - HKLM\..\Policies\Explorer\Run: [1] cmd /c %APPSERVE%\logondir\polfixit-ad9a.bat
O4 - HKLM\..\Policies\Explorer\Run: [2] reg add HKLM\System\CurrentControlSet\Control\Lsa\Kerberos\Parameters /v MaxTokenSize /t REG_DWORD /d 64000 /f
O4 - HKLM\..\Policies\Explorer\Run: [3] reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v POLFixit /f
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: CleanUser.vbs
O4 - Global Startup: FEDMENU.LNK = ?
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - [You must be registered and logged in to see this link.]
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.] Files\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O14 - IERESET.INF: START_PAGE_URL=http://intrafl
O15 - Trusted Zone: [You must be registered and logged in to see this link.]
O16 - DPF: Yahoo! Euchre - [You must be registered and logged in to see this link.]
O16 - DPF: Yahoo! Literati - [You must be registered and logged in to see this link.]
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - [You must be registered and logged in to see this link.]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = federated.fds
O17 - HKLM\Software\..\Telephony: DomainName = federated.fds
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = federated.fds
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = federated.fds
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: SMBus Upgrade Service for Windows 2000 and above (ibmsmbus) - International Business Machines Corp. - C:\WINDOWS\System32\ibmsmbus.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Program Files\lotus\notes\ntmulti.exe
O23 - Service: IBM Director Support Program (TWGIPC) - IBM Corporation - C:\Program Files\IBM\Director\bin\twgipcsv.exe
O23 - Service: IBM Director Agent WMI CIM Server (wmicimserver) - Unknown owner - C:\Program Files\IBM\Director\cimom\bin\wmicimserver.exe

--
End of file - 7346 bytes

spm88spm
Novice
Novice

Posts Posts : 9
Joined Joined : 2009-05-28
OS OS : XP
Points Points : 27521
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by spm88spm on 29th May 2009, 2:33 am

When I posted the file above I saw what appears to be "bad stuff" on lines O1 under Hosts...so I went to that folder under C\Windows\System32\Drivers\Etc and deleted those lines (opened in Notepad, deleted, rebooted). Internet is still redirecting, so I clearly didn't fix it. :-)

spm88spm
Novice
Novice

Posts Posts : 9
Joined Joined : 2009-05-28
OS OS : XP
Points Points : 27521
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by spm88spm on 29th May 2009, 3:17 am

Well nevermind...i did delete those lines but they are back now...I won't do anything else until i get directions from your team.

spm88spm
Novice
Novice

Posts Posts : 9
Joined Joined : 2009-05-28
OS OS : XP
Points Points : 27521
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by Belahzur on 29th May 2009, 3:38 pm

Hello.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O1 - Hosts: ::1 localhost
    O1 - Hosts: 94.232.248.66 browser-security.microsoft.com
    O1 - Hosts: 94.232.248.66 antivaresys.com
    O1 - Hosts: 94.232.248.66 [You must be registered and logged in to see this link.]
    O2 - BHO: BHO - {BAD4551D-9B24-42cb-9BCD-818CA2DA7B63} - C:\WINDOWS\system32\iehelper.dll
    O4 - HKCU\..\Run: [system tool] C:\WINDOWS\sysguard.exe
    O4 - HKLM\..\Policies\Explorer\Run: [1] cmd /c %APPSERVE%\logondir\polfixit-ad9a.bat
    O4 - HKLM\..\Policies\Explorer\Run: [2] reg add HKLM\System\CurrentControlSet\Control\Lsa\Kerberos\Parameters /v MaxTokenSize /t REG_DWORD /d 64000 /f
    O4 - HKLM\..\Policies\Explorer\Run: [3] reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v POLFixit /f
    O4 - Global Startup: CleanUser.vbs


  • Press "Fix Checked"
  • Close Hijack This.

Remove the Proxy setting in Internet Explorer and/or in FireFox.

    In Internet Explorer
  1. Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox
  1. Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection > Choose "No Proxy"
  2. Click the apply button and restart that computer in normal mode.


Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by spm88spm on 29th May 2009, 4:09 pm

Hello Belahzur,

Thanks for helping me. I completed the HijackThis system scan - seemed to work fine.

I checked my proxy settings in both IE and FF, neither one of them had the proxy enabled, but I rebooted anyway.

I downloaded Malwarebytes no problem (via FF). When I click the .exe file I get the prompt asking if I want to run it. I click Run. Then nothing happens. I tried this twice. Any ideas?

Thanks again - Steph

spm88spm
Novice
Novice

Posts Posts : 9
Joined Joined : 2009-05-28
OS OS : XP
Points Points : 27521
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by spm88spm on 30th May 2009, 9:34 pm

Hello Again -

I kept trying to double click the Malwarebytes .exe file, and I did eventually get it to install (very slowly). However, when I try to run it from my desktop nothing happens.

Thanks - Steph

spm88spm
Novice
Novice

Posts Posts : 9
Joined Joined : 2009-05-28
OS OS : XP
Points Points : 27521
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by Origin on 30th May 2009, 9:36 pm

1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to Combo-Fix as follows:





3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.
See [You must be registered and logged in to see this link.] for how to disable your AV..

  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31503
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by spm88spm on 31st May 2009, 12:48 am

Thanks Origin - ComboFix ran without issue, here is the log:

ComboFix 09-05-30.03 - FLFMSPM 05/30/2009 20:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.687 [GMT -4:00]
Running from: c:\documents and settings\FLFMSPM\Desktop\Combo-Fix.exe
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\drivers\fad.sys
c:\windows\system32\drivers\UACxfenxjaltiyemyd.sys
c:\windows\system32\iehelper.dll
c:\windows\system32\mdm.exe
c:\windows\system32\UACaabhnqjwvmiuufu.log
c:\windows\system32\UACeggxbhwgvkmpxmp.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACoexcikdluaybysy.dat
c:\windows\system32\UACtlrlnltufsgxctp.dll
c:\windows\system32\UACvxxptvkawdpccjc.dll
c:\windows\system32\UACwyqfmtvihitjhtj.log
c:\windows\system32\UACxdmlbnysmlkjivx.dll
c:\windows\system32\UACyfrwmiyobqotbnm.dll
c:\windows\system32\UACyverpgtoyapkuyn.log

----- BITS: Possible infected sites -----

[You must be registered and logged in to see this link.]
c:\windows\system32\proquota.exe . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-31 )))))))))))))))))))))))))))))))
.

2009-05-30 01:43 . 2009-05-26 17:20 40160 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-30 01:42 . 2009-05-30 01:42 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-30 01:42 . 2009-05-30 01:43 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-30 01:42 . 2009-05-26 17:19 19096 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-29 17:36 . 2009-05-29 17:36 -------- d-----w c:\program files\Citrix
2009-05-28 12:30 . 2009-04-21 14:37 1914000 ----a-w c:\temp\Install Flash Player 10 ActiveX.exe
2009-05-26 14:54 . 2009-05-12 20:08 266400 ----a-r c:\documents and settings\FLFMSPM\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll
2009-05-26 12:21 . 2009-05-26 12:21 -------- d-----w c:\windows\system32\Adobe
2009-05-26 12:09 . 2009-04-21 14:37 1878888 ----a-w c:\temp\Install Flash Player 10 Plugin.exe
2009-05-22 14:21 . 2009-05-22 14:34 -------- d-----w c:\windows\4 priorities dir
2009-05-21 01:44 . 2009-05-21 01:44 -------- d-----w c:\documents and settings\FLFMSPM\Application Data\McAfee
2009-05-21 01:44 . 2009-05-21 01:44 49152 ----a-r c:\documents and settings\FLFMSPM\Application Data\Microsoft\Installer\{FCC07EEA-FA18-4A21-9105-9666603C6885}\IconFCC07EEA1.exe
2009-05-21 01:44 . 2009-05-21 01:44 49152 ----a-r c:\documents and settings\FLFMSPM\Application Data\Microsoft\Installer\{FCC07EEA-FA18-4A21-9105-9666603C6885}\IconFCC07EEA.exe
2009-05-21 01:21 . 2009-05-21 01:21 186 ----a-w c:\documents and settings\FLFMSPM\Application Data\asd.bat
2009-05-02 05:38 . 2009-05-31 00:32 -------- d-----w C:\Quarantine

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-29 17:30 . 2009-03-24 11:35 88920 ----a-w c:\documents and settings\FLFMSPM\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-29 11:13 . 2009-03-25 23:51 -------- d-----w c:\documents and settings\FLFMSPM\Application Data\.purple
2009-05-22 14:21 . 2009-04-21 12:17 201728 ----a-w c:\windows\4 priorities.scr
2009-05-21 01:43 . 2009-04-20 16:36 -------- d-----w c:\program files\McAfee
2009-05-21 01:43 . 2009-04-20 16:36 -------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2009-05-19 18:10 . 2009-03-23 21:53 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-19 18:10 . 2009-05-19 18:10 -------- d-----w c:\program files\Cheetah
2009-05-18 18:49 . 2009-03-31 21:35 -------- d-----w c:\program files\CentraOne
2009-05-16 14:35 . 2009-03-24 15:10 1890 --sha-w c:\windows\system32\KGyGaAvL.sys
2009-04-28 13:32 . 2009-04-28 13:32 186496 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-24 03:38 . 2009-04-24 03:38 -------- d-----w c:\documents and settings\All Users\Application Data\PopCap
2009-04-23 00:24 . 2009-04-23 00:24 499392 ----a-w c:\windows\java\Packages\8CFFL7T7.ZIP
2009-04-22 23:36 . 2009-04-22 23:36 485146 ----a-w c:\windows\java\Packages\QQSD73P7.ZIP
2009-04-20 16:55 . 2009-04-20 16:55 -------- d-----w c:\program files\Common Files\McAfee
2009-04-20 16:45 . 2009-03-23 21:52 -------- d-----w c:\program files\CA
2009-04-20 16:36 . 2009-04-20 16:36 -------- d-----w c:\program files\Common Files\Cisco Systems
2009-04-09 12:12 . 2009-04-09 12:12 -------- d-----w c:\documents and settings\FLFMSPM\Application Data\IBMERS
2009-04-09 12:12 . 2009-04-09 12:12 -------- d-----w c:\documents and settings\All Users\Application Data\IBMERS
2009-04-06 17:35 . 2009-04-06 17:35 -------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-04-02 18:27 . 2009-03-24 11:13 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-02 13:42 . 2009-04-02 13:42 -------- d-----w c:\program files\Manhattan Associates
2009-03-27 03:52 . 2009-03-27 03:52 0 ----a-w c:\windows\nsreg.dat
2009-03-25 20:41 . 2009-03-23 21:46 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-23 22:12 . 2009-03-23 22:12 29696 ----a-w c:\windows\system32\drivers\smbushc.sys
2009-03-23 22:12 . 2009-03-23 22:12 11648 ----a-w c:\windows\system32\drivers\smbusdh.sys
2009-03-23 22:12 . 2009-03-23 22:12 10240 ----a-w c:\windows\system32\drivers\smbgen.sys
2009-03-23 22:05 . 2009-03-23 21:54 29696 ----a-w c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
2009-03-23 22:00 . 2009-03-23 22:00 2678 ----a-w c:\windows\java\Packages\Data\579RPRHZ.DAT
2009-03-23 22:00 . 2009-03-23 22:00 2678 ----a-w c:\windows\java\Packages\Data\PN53JNBH.DAT
2009-03-23 22:00 . 2009-03-23 22:00 2678 ----a-w c:\windows\java\Packages\Data\RVV5BF5R.DAT
2009-03-23 22:00 . 2009-03-23 22:00 2678 ----a-w c:\windows\java\Packages\Data\JD3DBX75.DAT
2009-03-23 22:00 . 2009-03-23 22:00 2678 ----a-w c:\windows\java\Packages\Data\NJBXNLNX.DAT
2009-03-23 21:44 . 2009-03-23 21:44 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-20 18:50 . 2009-03-20 18:50 3358720 ----a-w c:\windows\system32\GPhotos.scr
2009-03-06 14:44 . 2009-03-23 23:30 283648 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2009-03-23 23:30 826368 ----a-w c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-03-10 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-03-10 126976]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-02 106496]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2009-01-16 136512]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-01-28 111952]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2009-3-23 1425424]
FEDMENU.LNK - c:\windows\FedMenu.exe [2009-3-23 212992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=Wireless1.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=\\federated.fds\sysvol\federated.fds\scripts\computer\TimezoneSet.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\2\0]
"Script"=\\federated.fds\SysVol\federated.fds\Policies\{ZA000011-11Z1-4ZZ2-22Z2-0ZZCC010234}\ResetPassword2.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="1"
"UpdatesDisableNotify"="1"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 GENERICSMB;IBM - Generic SMB Device Controller;c:\windows\system32\drivers\smbgen.sys [3/23/2009 6:12 PM 10240]
R2 TWGIPC;IBM Director Support Program;c:\program files\IBM\Director\bin\twgipcsv.exe [2/1/2005 1:58 PM 53327]
R2 TWGSYSIN;TWGSYSIN;c:\windows\system32\drivers\twgsysin.sys [2/1/2005 1:58 PM 7476]
R2 wmicimserver;IBM Director Agent WMI CIM Server;c:\program files\IBM\Director\cimom\bin\wmicimserver.exe [2/3/2005 6:53 PM 401408]
R3 SMBusDH;IBM - SMB Hub Controller;c:\windows\system32\drivers\smbusdh.sys [3/23/2009 6:12 PM 11648]
R3 SMBusHC;SMBus Host Controller;c:\windows\system32\drivers\smbushc.sys [3/23/2009 6:12 PM 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

Notify-WgaLogon - (no file)
SafeBoot-procexp90.Sys


.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office\Office12\EXCEL.EXE/3000
Trusted Zone: eddiebauer.com\www
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: Yahoo! Euchre - [You must be registered and logged in to see this link.]
DPF: Yahoo! Literati - [You must be registered and logged in to see this link.]
DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} - [You must be registered and logged in to see this link.]
DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} - [You must be registered and logged in to see this link.]
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - [You must be registered and logged in to see this link.]
FF - ProfilePath - c:\documents and settings\FLFMSPM\Application Data\Mozilla\Firefox\Profiles\uj4a5myj.default\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-05-30 20:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\windows\system32\ibmsmbus.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\vstskmgr.exe
c:\program files\Lotus\Notes\ntmulti.exe
c:\windows\system32\snmp.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\IBM\Director\bin\twgipc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\CCM\clicomp\RemCtrl\Wuser32.exe
c:\windows\system32\CCM\CcmExec.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\msiexec.exe
c:\program files\IBM\Director\cimom\bin\PegasusProviderAdapter.exe
c:\program files\IBM\Director\cimom\bin\umssmart.exe
c:\program files\McAfee\Common Framework\McTray.exe
.
**************************************************************************
.
Completion time: 2009-05-31 20:47 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-31 00:47

Pre-Run: 25,719,291,904 bytes free
Post-Run: 25,989,611,520 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

198

Thanks again.

spm88spm
Novice
Novice

Posts Posts : 9
Joined Joined : 2009-05-28
OS OS : XP
Points Points : 27521
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by Belahzur on 31st May 2009, 12:53 am

Hello.
One of your system files is infected, do you have your XP disc?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by spm88spm on 31st May 2009, 12:56 am

Hi Belahzur -

I do not since it's a corporate laptop...I can take it into my IT department at work at some point to be completely rebuilt. Is that my best option at this point?

Thanks - Steph

spm88spm
Novice
Novice

Posts Posts : 9
Joined Joined : 2009-05-28
OS OS : XP
Points Points : 27521
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by Belahzur on 31st May 2009, 1:01 am

Please download SystemLook from one of the links below and save it to your Desktop.
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]


  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Code:

    :filefind
    proquota.exe

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by spm88spm on 31st May 2009, 1:03 am

Hi Belahzur,

Great thanks, here are the results:

SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 21:02 on 30/05/2009 by FLFMSPM (Limited User)

========== filefind ==========

Searching for "proquota.exe"
No files found.

-=End Of File=-

spm88spm
Novice
Novice

Posts Posts : 9
Joined Joined : 2009-05-28
OS OS : XP
Points Points : 27521
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by Belahzur on 31st May 2009, 1:13 am

Darn.
I fear that you may need to get yourself the XP disc that this OS came from, or format completely. A system file is modified and we don't have anything to replace it.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Nuqel.E (I think?)

Post by spm88spm on 31st May 2009, 1:27 am

Thanks Belahzur -

I will have it rebuilt - I appreciate your help.

- Steph

spm88spm
Novice
Novice

Posts Posts : 9
Joined Joined : 2009-05-28
OS OS : XP
Points Points : 27521
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum