It is currently Tue Sep 01, 2026 3:22 pm


Hijacked!!! Can't run Spybot, Malwarebytes or HiJackThis

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Hijacked!!! Can't run Spybot, Malwarebytes or HiJackThis

Postby kamsdad09 » Wed Oct 28, 2009 9:18 am

Windows Vista 4GB RAM
IE 7 up to date and all Windows updates current

Installed and tried to run Spybot, Malwarebytes and HiJackThis. Each time the application runs and then either gives an error "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item" or it just dies. I rebooted into SafeMode and put HijackThis into a different folder and renamed it to get it to run.

HiJackThis LOG

Logfile of HijackThis v1.99.1
Scan saved at 3:07:45 AM, on 10/28/2009
Platform: Unknown Windows (WinNT 6.01.2904)
MSIE: Internet Explorer v8.00 (8.00.7000.4138)

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
D:\Crapped\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocach ... .0.1.1.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %PROGRAMFILES%\Windows Media Player\wmpnetwk.exe (file missing)
kamsdad09
Newbie
Newbie
 
Posts: 3
Joined: Wed Oct 28, 2009 8:50 am

Thanks given:0
Thanks received:0
Top

Re: Hijacked!!! Can't run Spybot, Malwarebytes or HiJackThis

Postby Gecko » Wed Oct 28, 2009 4:53 pm

kamsdad09

Please download to your desktop.

Double click combofix.exe and follow the prompts.

Do not exit Combofix while it is running you my loose all your personal settings!
Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.

When it's done running it will produce a log for you. Please post that log in your next reply.

If you can not get Combofix to run, try renaming Combofix.exe to CBF.exe and try it again.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Hijacked!!! Can't run Spybot, Malwarebytes or HiJackThis

Postby kamsdad09 » Thu Oct 29, 2009 2:12 am

ComboFix LOG

ComboFix 09-10-27.08 - Karl Kincheon 10/28/2009 19:32.3.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2815.1743 [GMT -5:00]
Running from: c:\combofix\CBF.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 24 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2718131445-3512824376-2543783650-1001
c:\$recycle.bin\S-1-5-21-2718131445-3512824376-2543783650-1002
c:\$recycle.bin\S-1-5-21-2718131445-3512824376-2543783650-500
c:\$recycle.bin\S-1-5-21-3943012558-1748401313-3045002116-1001
c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\qaxjt1025.exe
c:\windows\system32\iieakote.ini

Infected copy of c:\windows\system32\cngaudit.dll was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}


((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-29 )))))))))))))))))))))))))))))))
.

2009-10-29 00:43 . 2009-10-29 00:47 -------- d-----w- c:\users\Karl Kincheon\AppData\Local\temp
2009-10-29 00:43 . 2009-10-29 00:43 -------- d-----w- c:\users\Guest\AppData\Local\temp
2009-10-29 00:43 . 2009-10-29 00:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-28 08:03 . 2009-10-28 08:08 -------- d-----w- C:\Crapped
2009-10-28 08:02 . 2009-10-28 08:03 -------- d-----w- c:\program files\CheckThis
2009-10-28 07:54 . 2009-10-28 07:54 -------- d-----w- C:\Bugs
2009-10-28 07:29 . 2009-10-28 07:29 -------- d-----w- c:\users\Karl Kincheon\AppData\Roaming\Malwarebytes
2009-10-28 07:29 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-28 07:29 . 2009-10-28 07:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-28 07:29 . 2009-10-28 07:29 -------- d-----w- c:\programdata\Malwarebytes
2009-10-28 07:29 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-28 07:18 . 2009-10-28 07:18 99328 ----a-w- c:\windows\aldi3582.exe
2009-10-28 07:18 . 2009-10-29 00:18 0 ----a-r- c:\windows\win32k.sys
2009-10-28 07:18 . 2009-10-28 07:18 84480 ----a-w- c:\windows\niwc0156.exe
2009-10-28 07:18 . 2009-10-28 07:18 53248 ----a-w- c:\windows\hcqu78545.exe
2009-10-28 07:17 . 2009-10-28 07:17 95744 ----a-w- c:\windows\gdlk26770.exe
2009-10-28 00:47 . 2009-09-10 14:58 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-28 00:47 . 2009-09-10 14:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-17 18:15 . 2009-10-17 18:15 -------- d-----w- C:\drivers
2009-10-15 03:27 . 2009-09-10 16:48 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-15 03:26 . 2009-08-27 12:40 834048 ----a-w- c:\windows\system32\wininet.dll
2009-10-15 03:26 . 2009-08-27 13:29 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-15 03:26 . 2009-08-04 12:34 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-15 03:26 . 2009-08-04 12:34 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-15 03:26 . 2009-09-04 11:41 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-15 03:26 . 2009-09-14 09:29 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-15 03:26 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-10 08:00 . 2009-10-10 08:00 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2009-10-10 03:58 . 2009-10-20 08:03 -------- d-----w- c:\program files\Microsoft Works
2009-10-10 03:58 . 2009-10-10 03:58 -------- d-----w- c:\windows\PCHEALTH
2009-10-10 03:58 . 2009-10-10 03:58 -------- d-----w- c:\program files\Microsoft.NET
2009-10-10 03:56 . 2009-10-10 03:56 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-10-10 03:55 . 2009-10-10 03:55 -------- d-----r- C:\MSOCache
2009-10-08 10:53 . 2009-10-08 10:53 -------- d-----w- c:\users\Karl Kincheon\Office Genuine Advantage
2009-10-08 10:42 . 2009-10-08 10:42 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-10-07 12:32 . 2009-06-15 14:54 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-10-07 12:32 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2009-10-07 12:32 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-10-07 12:32 . 2009-06-15 23:15 439864 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-10-07 12:32 . 2009-06-15 14:53 72704 ----a-w- c:\windows\system32\secur32.dll
2009-10-07 12:32 . 2009-06-15 14:52 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2009-10-07 12:32 . 2009-06-15 12:48 9728 ----a-w- c:\windows\system32\lsass.exe
2009-10-02 23:36 . 2009-10-01 15:29 195440 ------w- c:\windows\system32\MpSigStub.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-29 00:45 . 2008-02-05 07:21 4268 ----a-w- c:\windows\bthservsdp.dat
2009-10-28 07:40 . 2008-01-13 14:10 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-10-28 07:23 . 2008-10-17 03:00 -------- d-----w- c:\users\Karl Kincheon\AppData\Roaming\LimeWire
2009-10-21 04:38 . 2008-01-11 19:33 -------- d-----w- c:\programdata\Microsoft Help
2009-10-20 10:22 . 2007-08-22 10:36 102864 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-10-15 08:10 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-12 17:35 . 2007-11-11 18:22 -------- d-----w- c:\users\Karl Kincheon\AppData\Roaming\Image Zone Express
2009-10-10 03:58 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2009-09-24 06:00 . 2007-08-23 03:33 -------- d-----w- c:\programdata\DVD Shrink
2009-09-19 20:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-09-19 20:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-09-19 20:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-09-19 20:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-09-19 20:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-09-19 20:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-09-19 20:55 . 2009-09-19 20:55 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-09-10 10:33 . 2009-05-16 03:26 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-06 20:13 . 2007-08-25 14:56 -------- d-----w- c:\program files\Java
2009-09-06 18:10 . 2007-12-15 15:28 -------- d-----w- c:\users\Karl Kincheon\AppData\Roaming\Move Networks
2009-09-04 03:19 . 2008-10-19 23:52 -------- d-----w- c:\users\Karl Kincheon\AppData\Roaming\Juniper Networks
2009-09-04 03:19 . 2009-05-31 12:55 -------- d-----w- c:\program files\Juniper Networks
2009-09-02 01:53 . 2009-09-02 01:50 -------- d-----w- c:\users\Karl Kincheon\AppData\Roaming\vlc
2009-09-02 01:51 . 2009-09-02 01:51 -------- d-----w- c:\users\Karl Kincheon\AppData\Roaming\dvdcss
2009-09-02 01:50 . 2009-09-02 01:50 -------- d-----w- c:\program files\VideoLAN
2009-08-29 00:27 . 2009-09-02 21:23 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-02 21:23 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-18 04:33 . 2009-08-18 04:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 16:27 . 2009-09-09 09:47 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 15:53 . 2009-09-09 09:47 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49 . 2009-09-09 09:47 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49 . 2009-09-09 09:47 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49 . 2009-09-09 09:47 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49 . 2009-09-09 09:47 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49 . 2009-09-09 09:47 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49 . 2009-09-09 09:47 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49 . 2009-09-09 09:47 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:48 . 2009-09-09 09:47 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48 . 2009-09-09 09:47 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-03 20:07 . 2009-08-03 20:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 20:07 . 2009-08-03 20:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 20:07 . 2009-08-03 20:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2008-02-08 03:46 . 2008-02-08 03:46 13624 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-02-08 03:46 . 2008-02-08 03:46 87360 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-02-08 03:46 . 2008-02-08 03:46 91448 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2008-02-08 03:46 . 2008-02-08 03:46 21824 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-02-08 03:46 . 2008-02-08 03:46 206136 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-02-08 03:46 . 2008-02-08 03:46 31544 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2008-02-08 03:46 . 2008-02-08 03:46 40248 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2007-03-16 23:27 . 2007-03-16 23:27 479232 ----a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2007-03-16 23:27 . 2007-03-16 23:27 548864 ----a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2007-03-16 23:27 . 2007-03-16 23:27 626688 ----a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2007-07-20 18:47 . 2007-07-20 18:47 981170 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-02-08 03:46 . 2008-02-08 03:46 24384 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2009-04-02 01:44 . 2009-04-02 01:44 0 --sh--w- c:\windows\S0674E01A.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-20 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-20 92704]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"RivaTunerStartupDaemon"="c:\program files\RivaTuner v2.24\RivaTunerWrapper.exe" [2009-02-25 24576]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2008-11-17 827904]
"Atari Launcher"="c:\program files\Hasbro Interactive\Atari Arcade Hits 1\Atari icon.exe" [1999-06-25 49664]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-02-15 4390912]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2008-6-4 25214]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Karl Kincheon^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\users\Karl Kincheon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"VistaSp2"=hex(b):80,48,ac,c5,6c,39,ca,01

R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [1/13/2008 9:10 AM 600912]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\drivers\ASPI32.SYS [3/19/2009 7:22 PM 84832]

--- Other Services/Drivers In Memory ---

*Deregistered* - mbr

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.us.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: pcpitstop.com\www
Trusted Zone: west.com
Trusted Zone: westathome.com
Trusted Zone: westathome.net
Trusted Zone: workathomeagent.net
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://juniper.net/dana-cached/sc/Juni ... Client.cab
FF - ProfilePath - c:\users\Karl Kincheon\AppData\Roaming\Mozilla\Firefox\Profiles\0wsy02to.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.msn.com
FF - plugin: c:\progra~1\MEADCO~1\npmeadax.dll
FF - plugin: c:\progra~1\Palm\PACKAG~1\NPInstal.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\users\Karl Kincheon\AppData\Roaming\Move Networks\plugins\npqmp071503000010.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
HKLM-Run-Bluetooth Connection Assistant - LBTWIZ.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-28 19:47
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\AUDIODG.EXE
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Logitech\Bluetooth\LBTServ.exe
c:\acer\Empowering Technology\ePerformance\MemCheck.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\cbf\CF5148.exe
c:\program files\Logitech\SetPoint\LBTWiz.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\cbf\PEV.cfxxe
.
**************************************************************************
.
Completion time: 2009-10-29 19:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-29 00:55
ComboFix2.txt 2008-01-16 00:58
ComboFix3.txt 2008-01-16 00:00

Pre-Run: 36,949,389,312 bytes free
Post-Run: 38,758,342,656 bytes free

- - End Of File - - FAF1EA99AF76C4B70DBEA8823DB6DE12
kamsdad09
Newbie
Newbie
 
Posts: 3
Joined: Wed Oct 28, 2009 8:50 am

Thanks given:0
Thanks received:0
Top

Re: Hijacked!!! Can't run Spybot, Malwarebytes or HiJackThis

Postby Gecko » Thu Oct 29, 2009 12:37 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Hijacked!!! Can't run Spybot, Malwarebytes or HiJackThis

Postby kamsdad09 » Fri Oct 30, 2009 4:35 am

Unable to run Combo Fix with script. Runs but gets error that says "Combo Fix has detected the presence of rootkit and must reboot". It reboots but never starts up again
kamsdad09
Newbie
Newbie
 
Posts: 3
Joined: Wed Oct 28, 2009 8:50 am

Thanks given:0
Thanks received:0
Top

Re: Hijacked!!! Can't run Spybot, Malwarebytes or HiJackThis

Postby Gecko » Fri Oct 30, 2009 12:15 pm

kamsdad09,

That is real odd, try running CBF.exe without drop and drag of the file just click on it.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron