It is currently Tue Sep 01, 2026 3:19 pm


trojan horse dropper agent GIT

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

trojan horse dropper agent GIT

Postby Dinsy » Sun Jan 06, 2008 2:36 am

heres the logfile.
thanks for any help you can give me!

Logfile of HijackThis v1.99.1
Scan saved at 2:34:16 PM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\usrserv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
C:\Program Files\HijackThis\HijackThis.exe

F3 - REG:win.ini: load=C:\WINDOWS\system32\wvust.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NoteBurner] C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence
O4 - HKLM\..\Run: [Windows Live Servicer] usrserv.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 3689109279
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Dinsy
Newbie
Newbie
 
Posts: 5
Joined: Sun Jan 06, 2008 2:18 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Sun Jan 06, 2008 12:09 pm

Hello Dinsy, and welcome to our forum.

Warning these instructions are for this thread only!
You should never attempt to use them for anything else!


Please copy this to Notepad and save it to your desktop or print it. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.
You should not have any other open windows when you are following the procedures below.

Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following:
(They may or may not be there)
usrserv.exe

Start HijackThis and click "Do a system scan only" put a check next to each of the following entries:
O4 - HKLM\..\Run: [Windows Live Servicer] usrserv.exe

Now click the "Fixed checked" button and then close HijackThis

Click Start, click My computer and then right click on your C: drive and select "Properties"
Now click the "Disk cleanup" button, in the next window put a check next to Recycle Bin, Temporary Internet Files and Temporary Files click OK and then click yes in the popup window.

Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' is enabled. Also make sure that Display the contents of System Folders' is checked. Remember to reset these when done.
Delete the following Files/Folders if they exist:

C:\WINDOWS\system32\usrserv.exe

If you cannot delete these file(s)then:
Start HijackThis and click the Open the misc tools section now click Delete a file on reboot
Select the following file to be deleted on reboot:

C:\WINDOWS\system32\usrserv.exe

Click open and click yes to reboot now do

Restart your computer and post a new HiJackThis log when you reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Dinsy » Sun Jan 06, 2008 2:12 pm

Logfile of HijackThis v1.99.1
Scan saved at 2:11:25 AM, on 1/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

F3 - REG:win.ini: load=C:\WINDOWS\system32\wvust.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NoteBurner] C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 3689109279
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Dinsy
Newbie
Newbie
 
Posts: 5
Joined: Sun Jan 06, 2008 2:18 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Sun Jan 06, 2008 2:38 pm

Dinsy,

Please download to your desktop.

Double click combofix.exe and follow the prompts.

When it's done running it will produce a log for you. Please post that log in your next reply.

Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Dinsy » Mon Jan 07, 2008 7:39 am

ComboFix 08-01-04.1 - Freddie 2008-01-07 19:30:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.413 [GMT 13:00]
Running from: C:\Documents and Settings\Freddie\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\ddccaya.dll
C:\WINDOWS\system32\tsuvw.ini
C:\WINDOWS\system32\tsuvw.ini2
C:\WINDOWS\system32\wvust.dll

.
((((((((((((((((((((((((( Files Created from 2007-12-07 to 2008-01-07 )))))))))))))))))))))))))))))))
.

2008-01-07 19:28 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-07 18:03 . 2006-10-05 03:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-01-07 18:03 . 2006-10-05 03:06 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-01-07 18:03 . 2006-10-05 03:06 217,118 -----c--- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-01-07 18:02 . 2004-08-04 00:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-01-07 18:01 . 2008-01-07 18:01 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-01-07 17:56 . 2008-01-07 17:56 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-01-07 17:56 . 2008-01-07 17:58 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-01-07 17:56 . 2008-01-07 18:03 1,355 --a------ C:\WINDOWS\imsins.BAK
2008-01-07 02:10 . 2008-01-07 02:10 3,584 --a------ C:\WINDOWS\system32\wvust.exe
2008-01-06 14:48 . 2008-01-06 14:48 <DIR> d-------- C:\Program Files\CCleaner
2008-01-05 23:00 . 2008-01-05 23:00 12,291,535 --------- C:\AVG7QT.DAT
2008-01-05 22:56 . 2008-01-06 06:43 61,952 -rahs---- C:\WINDOWS\system32\usrserv.exe
2008-01-04 17:29 . 2008-01-04 17:29 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-04 17:28 . 2008-01-04 17:33 <DIR> d-------- C:\Program Files\NoteBurner
2007-12-28 23:35 . 2008-01-01 22:14 <DIR> d-------- C:\Documents and Settings\Freddie\Application Data\dvdcss
2007-12-25 03:14 . 2008-01-07 18:14 <DIR> d-------- C:\Documents and Settings\Freddie\Shared
2007-12-25 03:14 . 2008-01-07 18:16 <DIR> d-------- C:\Documents and Settings\Freddie\Incomplete
2007-12-25 03:12 . 2007-12-25 03:12 <DIR> d-------- C:\Program Files\LimeWire
2007-12-25 03:12 . 2008-01-05 14:32 <DIR> d-------- C:\Documents and Settings\Freddie\Application Data\LimeWire
2007-12-18 00:48 . 2007-12-18 00:48 <DIR> d-------- C:\WINDOWS\Sun
2007-12-18 00:47 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-18 00:46 . 2007-12-18 00:47 <DIR> d-------- C:\Program Files\Java
2007-12-18 00:42 . 2007-12-18 00:42 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-17 17:53 . 2007-12-17 17:53 <DIR> d-------- C:\Program Files\IrfanView
2007-12-17 17:14 . 2007-12-17 17:14 268 --ah----- C:\sqmdata00.sqm
2007-12-17 17:14 . 2007-12-17 17:14 244 --ah----- C:\sqmnoopt00.sqm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-06 02:12 --------- d-----w C:\Program Files\iTunes
2008-01-06 01:47 --------- d-----w C:\Program Files\QuickTime
2008-01-06 00:58 --------- d-----w C:\Documents and Settings\Freddie\Application Data\AVG7
2008-01-05 10:46 --------- d-----w C:\Documents and Settings\Freddie\Application Data\Skype
2008-01-04 04:31 --------- d-----w C:\Documents and Settings\Freddie\Application Data\Apple Computer
2007-12-31 17:56 --------- d-----w C:\Documents and Settings\Freddie\Application Data\Azureus
2007-12-27 08:57 --------- d-----w C:\Program Files\Azureus
2007-12-24 14:25 --------- d-----w C:\Program Files\VirtualDJ
2007-11-30 16:22 --------- d-----w C:\Program Files\Serato
2007-11-22 05:32 --------- d-----w C:\Program Files\Jfkreloaded
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [ ]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"AGRSMMSG"="AGRSMMSG.exe" [2004-08-24 11:19 88363 C:\WINDOWS\AGRSMMSG.exe]
"NoteBurner"="C:\Program Files\NoteBurner\VTBurnerGUI.exe" [ ]
"MP10_EnsureFileVer"="C:\WINDOWS\inf\unregmp2.exe" [2004-08-04 00:56 208896]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-29 16:55 219136]

C:\Documents and Settings\Freddie\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2007-12-04 10:35:53]

R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys [2003-07-29 00:49]
R3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys [2003-07-24 14:50]
R3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5211.sys [2004-04-18 16:45]
S0 ntcdrdrv;ntcdrdrv;C:\WINDOWS\system32\DRIVERS\ntcdrdrv.sys []

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-07 19:36:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-07 19:38:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-07 06:38:51
.
2008-01-04 21:12:02 --- E O F ---
Dinsy
Newbie
Newbie
 
Posts: 5
Joined: Sun Jan 06, 2008 2:18 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Mon Jan 07, 2008 12:58 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Dinsy » Tue Jan 08, 2008 11:24 am

ComboFix 08-01-04.1 - Freddie 2008-01-08 23:18:12.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.187 [GMT 13:00]
Running from: C:\Documents and Settings\Freddie\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Freddie\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\imsins.BAK
C:\WINDOWS\imsins.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\imsins.BAK

.
((((((((((((((((((((((((( Files Created from 2007-12-08 to 2008-01-08 )))))))))))))))))))))))))))))))
.

2008-01-08 17:25 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-01-08 17:25 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-01-08 17:25 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-01-07 20:29 . 2008-01-08 17:25 <DIR> d-------- C:\WINDOWS\LastGood
2008-01-07 20:23 . 2008-01-07 20:29 <DIR> d-------- C:\Program Files\Windows Live
2008-01-07 20:23 . 2008-01-07 20:28 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-07 20:23 . 2008-01-07 20:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-07 19:28 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-07 18:03 . 2006-10-05 03:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-01-07 18:03 . 2006-10-05 03:06 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-01-07 18:03 . 2006-10-05 03:06 217,118 -----c--- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-01-07 18:02 . 2004-08-04 00:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-01-07 18:01 . 2008-01-07 18:01 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-01-07 17:56 . 2008-01-07 17:56 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-01-07 17:56 . 2008-01-07 17:58 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-01-07 02:10 . 2008-01-07 02:10 3,584 --a------ C:\WINDOWS\system32\wvust.exe
2008-01-06 14:48 . 2008-01-06 14:48 <DIR> d-------- C:\Program Files\CCleaner
2008-01-05 23:00 . 2008-01-05 23:00 12,291,535 --------- C:\AVG7QT.DAT
2008-01-05 22:56 . 2008-01-06 06:43 61,952 -rahs---- C:\WINDOWS\system32\usrserv.exe
2008-01-04 17:29 . 2008-01-04 17:29 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-04 17:28 . 2008-01-04 17:33 <DIR> d-------- C:\Program Files\NoteBurner
2007-12-28 23:35 . 2008-01-01 22:14 <DIR> d-------- C:\Documents and Settings\Freddie\Application Data\dvdcss
2007-12-25 03:14 . 2008-01-07 19:37 <DIR> d-------- C:\Documents and Settings\Freddie\Shared
2007-12-25 03:14 . 2008-01-07 19:37 <DIR> d-------- C:\Documents and Settings\Freddie\Incomplete
2007-12-25 03:12 . 2007-12-25 03:12 <DIR> d-------- C:\Program Files\LimeWire
2007-12-25 03:12 . 2008-01-05 14:32 <DIR> d-------- C:\Documents and Settings\Freddie\Application Data\LimeWire
2007-12-18 00:48 . 2007-12-18 00:48 <DIR> d-------- C:\WINDOWS\Sun
2007-12-18 00:47 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-18 00:46 . 2007-12-18 00:47 <DIR> d-------- C:\Program Files\Java
2007-12-18 00:42 . 2007-12-18 00:42 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-17 17:53 . 2007-12-17 17:53 <DIR> d-------- C:\Program Files\IrfanView
2007-12-17 17:14 . 2007-12-17 17:14 268 --ah----- C:\sqmdata00.sqm
2007-12-17 17:14 . 2007-12-17 17:14 244 --ah----- C:\sqmnoopt00.sqm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-08 10:19 --------- d-----w C:\Documents and Settings\Freddie\Application Data\Azureus
2008-01-06 02:12 --------- d-----w C:\Program Files\iTunes
2008-01-06 01:47 --------- d-----w C:\Program Files\QuickTime
2008-01-06 00:58 --------- d-----w C:\Documents and Settings\Freddie\Application Data\AVG7
2008-01-05 10:46 --------- d-----w C:\Documents and Settings\Freddie\Application Data\Skype
2008-01-04 04:31 --------- d-----w C:\Documents and Settings\Freddie\Application Data\Apple Computer
2007-12-27 08:57 --------- d-----w C:\Program Files\Azureus
2007-12-24 14:25 --------- d-----w C:\Program Files\VirtualDJ
2007-11-30 16:22 --------- d-----w C:\Program Files\Serato
2007-11-22 05:32 --------- d-----w C:\Program Files\Jfkreloaded
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 02:47 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2007-10-29 02:47 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2007-10-17 22:31 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll
.

((((((((((((((((((((((((((((( snapshot@2008-01-07_19.38.40.87 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-07 07:28:55 29,926 ----a-r C:\WINDOWS\Installer\{508CE775-4BA4-4748-82DF-FE28DA9F03B0}\MsblIco.Exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [ ]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"AGRSMMSG"="AGRSMMSG.exe" [2004-08-24 11:19 88363 C:\WINDOWS\AGRSMMSG.exe]
"NoteBurner"="C:\Program Files\NoteBurner\VTBurnerGUI.exe" [ ]
"MP10_EnsureFileVer"="C:\WINDOWS\inf\unregmp2.exe" [2004-08-04 00:56 208896]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-29 16:55 219136]

C:\Documents and Settings\Freddie\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2007-12-04 10:35:53]

R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys [2003-07-29 00:49]
R3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys [2003-07-24 14:50]
R3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5211.sys [2004-04-18 16:45]
S0 ntcdrdrv;ntcdrdrv;C:\WINDOWS\system32\DRIVERS\ntcdrdrv.sys []

*Newly Created Service* - USNJSVC
*Newly Created Service* - WLSETUPSVC
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-08 23:20:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-08 23:21:05
ComboFix-quarantined-files.txt 2008-01-08 10:20:50
ComboFix2.txt 2008-01-07 06:39:00
.
2008-01-04 21:12:02 --- E O F ---


and

Logfile of HijackThis v1.99.1
Scan saved at 11:23:41 PM, on 1/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\installer\WLSetupSvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Azureus\Azureus.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NoteBurner] C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence
O4 - HKLM\..\Run: [MP10_EnsureFileVer] C:\WINDOWS\inf\unregmp2.exe /EnsureFileVersions
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 3689109279
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Dinsy
Newbie
Newbie
 
Posts: 5
Joined: Sun Jan 06, 2008 2:18 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Tue Jan 08, 2008 12:01 pm

Dinsy,

Yous log is clean

How's it running now?
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Dinsy » Thu Jan 10, 2008 6:21 am

everything seems to be running perfect.

thanks alot! :D :D :D
Dinsy
Newbie
Newbie
 
Posts: 5
Joined: Sun Jan 06, 2008 2:18 am

Thanks given:0
Thanks received:0
Top

Postby dado69 » Wed Jan 23, 2008 8:29 am

dado69
Newbie
Newbie
 
Posts: 6
Joined: Wed Jan 23, 2008 8:25 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Wed Jan 23, 2008 12:03 pm

Hello dado69 and welcome to our forum.

It is always best to start your own thread when posting a problem.
That way there is less confusion and you will get the help you need.

With that said please follow the below instructions:

Please download HijackThis http://downloads.malwareremoval.com/hijackthis.zip and save it to your desktop.

To extract HijackThis:

1. Right-click your file HijackThis.zip and from the menu select "Extract All".
2. The Extraction Wizard Window will appear, Click "Next".
3. Click Browse and navigate to "C:\" or the "C:\Program Files" and click "Create A New Folder" and call it "HJT" or "HijackThis" or whatever that is easy to remember and then click OK.
4. Click the Extract button.
5. Close the HijackThis.zip dialogue box.

Now double-click on hijackthis.exe and when the window opens, Press the Scan now and save a logfile button and then when it is done, copy and paste the contents of the notepad it opens as and start a new thread
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: trojan horse dropper agent GIT

Postby Gecko » Wed Jun 16, 2010 12:25 pm

alshidaa,

It is always best to start your own thread when posting a problem.
That way there is less confusion and you will get the help you need.

Some vundo infection are not easily removed by most anti virus programs.

Please download HijackThis http://downloads.malwareremoval.com/hijackthis.zip and save it to your desktop.

To extract HijackThis:

1. Right-click your file HijackThis.zip and from the menu select "Extract All".
2. The Extraction Wizard Window will appear, Click "Next".
3. Click Browse and navigate to "C:\" or the "C:\Program Files" and click "Create A New Folder" and call it "HJT" or "HijackThis" or whatever that is easy to remember and then click OK.
4. Click the Extract button.
5. Close the HijackThis.zip dialogue box.

Now double-click on hijackthis.exe and when the window opens, Press the Scan now and save a logfile button and then when it is done, copy and paste the contents of the notepad it opens and start a new thread
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron