It is currently Tue Sep 01, 2026 4:22 pm


Smitfraud-C.CoreService

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Smitfraud-C.CoreService

Postby Buck Pete » Thu Jan 31, 2008 3:56 pm

Hi Folks, Hope somebody out here can help me

I seem to have picked up the Smitfraud Malware bug that is effecting the C:\WINDOWS\system32\drivers\core.cach.dsk

Spybot S&D found this but cannot get rid of it.

Please see attached HiJackThis.log

There a few poker programs on my PC as i am a pro Poker player and the dam pop-ups this Smitfraud is creating is seriously ruining my game :D

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:46:51, on 31/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ngvpnmgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\PokerStars\PokerStars.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\RunOnce: [SpybotDeletingA6124] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4691] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3908] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6718] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk_tobedeleted"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Paddy Power Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\PADDYP~1\client.exe (file missing)
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra button: Stan James Poker.com Poker - {7F2F6F5A-CAE2-4954-A461-36B3757B2BFB} - C:\Program Files\stanjamesgibMPP\MPPoker.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Program Files\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 3996640186
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 3996629389
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Aventail VPN Client (NgVpnMgr) - Aventail Corporation - C:\WINDOWS\system32\ngvpnmgr.exe

--
End of file - 5454 bytes
Buck Pete
Newbie
Newbie
 
Posts: 5
Joined: Thu Jan 31, 2008 3:48 pm

Thanks given:0
Thanks received:0
Top

Postby Gecko » Fri Feb 01, 2008 2:14 am

Hello Buck Pete, and welcome to our forum.

Please download

1. Double click on SmitfraudFix.exe.
2. Press 1 then hit the Enter key.
3. It will create a report named rapport.txt, usually at C drive.
4. Please post back this log in your next reply.

Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool";
it is not a virus, but a program used to stop system processes.
Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Buck Pete » Fri Feb 01, 2008 12:49 pm

Hi Gecko

Thanks for the swift response.

Attached is the contents of rapport.txt

Thanks

Pete


SmitFraudFix v2.277

Scan done at 23:34:39.82, 31/01/2008
Run from C:\Documents and Settings\pete\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ngvpnmgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Poker\BlueSquare Poker\casino.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\iTunes\iTunes.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\pete


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\pete\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\pete\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components



»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Marvell Yukon 88E8001/8003/8010 PCI Gigabit Ethernet Controller - Packet Scheduler Miniport
DNS Server Search Order: 192.168.0.1

Description: Marvell Yukon 88E8001/8003/8010 PCI Gigabit Ethernet Controller - Packet Scheduler Miniport
DNS Server Search Order: 192.168.0.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{4367A37C-BB0B-4145-BE64-F4127D93720F}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{7BC51A8B-84D0-44BF-B995-D196489C94D3}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{4367A37C-BB0B-4145-BE64-F4127D93720F}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{7BC51A8B-84D0-44BF-B995-D196489C94D3}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{4367A37C-BB0B-4145-BE64-F4127D93720F}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{7BC51A8B-84D0-44BF-B995-D196489C94D3}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
Buck Pete
Newbie
Newbie
 
Posts: 5
Joined: Thu Jan 31, 2008 3:48 pm

Thanks given:0
Thanks received:0
Top

Postby Gecko » Fri Feb 01, 2008 10:00 pm

Buck Pete,

That did not have the results I expected.

Please download to your desktop.

Double click combofix.exe and follow the prompts.

When it's done running it will produce a log for you. Please post that log in your next reply.

Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Buck Pete » Sat Feb 02, 2008 12:57 am

Geko

I ran Combofix and here is the contents of the generated file combofix.txt

ComboFix 08-02.01.6 - pete 2008-02-01 23:44:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1374 [GMT 0:00]
Running from: C:\Documents and Settings\pete\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\temp\tn3
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

----- BITS: Possible infected sites -----

hxxp://au.download.windowsupdate.com
.
((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.

2008-02-05 16:21 . 2008-02-05 16:21 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
2008-02-05 16:20 . 2008-02-05 16:20 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-02-05 16:20 . 2008-02-05 16:20 669,184 --a------ C:\WINDOWS\system32\pbsvc.exe
2008-02-05 16:20 . 2008-02-05 16:20 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-02-05 16:20 . 2008-02-05 16:20 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-02-05 16:20 . 2008-02-05 16:20 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-05 16:20 . 2008-02-05 16:20 22,328 --a------ C:\Documents and Settings\pete\Application Data\PnkBstrK.sys
2008-02-05 15:55 . 2008-02-05 15:55 <DIR> d-------- C:\Program Files\Electronic Arts
2008-02-01 23:50 . 2008-02-01 23:50 <DIR> d-------- C:\Temp\tn3
2008-02-01 14:44 . 2008-02-01 14:44 <DIR> d-------- C:\Program Files\sixteen tons entertainment
2008-01-31 13:47 . 2008-01-31 13:47 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-31 13:20 . 2008-01-31 13:24 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-31 12:15 . 2008-01-31 23:34 1,568 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-31 09:50 . 2008-01-31 09:50 <DIR> d-------- C:\Program Files\Aventail Connect
2008-01-31 09:50 . 2008-01-31 09:50 <DIR> d-------- C:\Documents and Settings\pete\Application Data\Aventail
2008-01-31 09:50 . 2008-01-31 09:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Aventail
2008-01-30 23:47 . 2008-01-30 23:47 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-30 23:47 . 2008-01-30 23:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-30 23:37 . 2008-01-30 23:37 <DIR> d-------- C:\Program Files\CCleaner
2008-01-30 19:13 . 2008-01-30 22:54 <DIR> d-------- C:\Program Files\STOPzilla!
2008-01-30 19:13 . 2008-01-30 19:13 <DIR> d-------- C:\Program Files\Common Files\iS3
2008-01-30 19:13 . 2008-01-30 22:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-01-30 14:54 . 2008-01-30 14:54 167,545 --a------ C:\WINDOWS\system32\drivers\core.cache.dsk
2008-01-30 14:54 . 2008-01-30 14:54 86,144 --a------ C:\WINDOWS\system32\drivers\usbehcii.sys
2008-01-30 13:27 . 2008-02-01 09:53 <DIR> d-------- C:\Documents and Settings\pete\Application Data\AVG7
2008-01-30 13:25 . 2008-01-30 13:25 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-30 13:25 . 2008-01-30 13:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-30 13:25 . 2008-01-31 09:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-01-22 15:16 . 2008-01-22 15:16 <DIR> d-------- C:\Program Files\SubmachineZero_at
2008-01-18 18:53 . 2008-01-18 19:04 <DIR> d-------- C:\Program Files\DTD Poker
2008-01-17 20:36 . 2008-01-17 20:36 14,941 --a------ C:\Credit card statement.JPG
2008-01-17 14:58 . 2008-01-17 14:58 557,056 --a------ C:\Documents and Settings\pete\GoToAssist_phone__319_en.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-01 14:44 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-01 12:18 --------- d-----w C:\Program Files\PokerStars
2008-02-01 10:53 --------- d-----w C:\Documents and Settings\pete\Application Data\uTorrent
2008-01-31 13:30 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-31 10:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-30 23:47 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-30 23:05 --------- d-----w C:\Program Files\EA GAMES
2008-01-30 23:00 --------- d-----w C:\Program Files\Symantec
2008-01-30 23:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-30 10:45 --------- d-----w C:\Program Files\DAEMON Tools Pro
2008-01-29 23:08 --------- d-----w C:\Program Files\Full Tilt Poker
2008-01-29 19:49 --------- d-----w C:\Program Files\CoralPoker
2008-01-29 14:19 --------- d-----w C:\Program Files\GalaPoker
2008-01-26 20:17 --------- d-----w C:\Documents and Settings\pete\Application Data\Bioshock
2008-01-26 19:25 --------- d-----w C:\Program Files\LimeWire
2008-01-15 09:54 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-15 05:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-14 09:58 --------- d-----w C:\Program Files\HollywoodPoker
2008-01-12 18:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-30 14:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2007-12-29 19:21 --------- d-----w C:\Program Files\The Witcher
2007-12-29 18:46 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2007-12-29 18:46 25,416 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys
2007-12-29 18:32 --------- d-----w C:\Documents and Settings\pete\Application Data\DAEMON Tools Pro
2007-12-29 18:15 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-12-23 17:48 --------- d-----w C:\Program Files\PokerRoom.com
2007-12-18 13:25 --------- d-----w C:\Program Files\iTunes
2007-12-18 13:25 --------- d-----w C:\Program Files\iPod
2007-12-18 13:24 --------- d-----w C:\Program Files\QuickTime
2007-12-15 13:41 --------- d-----w C:\Program Files\Littlewoods Poker
2007-12-13 12:16 --------- d-----w C:\Documents and Settings\pete\Application Data\Symantec
2007-12-11 17:25 --------- d-----w C:\Program Files\Common Files\Ahead
2007-12-05 15:21 --------- d-----w C:\Program Files\Titan Poker
2007-11-20 19:57 808,638 ----a-w C:\WINDOWS\Commando1001.zip
2007-11-02 13:43 1 ----a-w C:\Documents and Settings\pete\SI.bin
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 13:08 136136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-02-09 08:54 65024 C:\WINDOWS\SOUNDMAN.EXE]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-10-05 12:25 868352]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-07-13 06:12 729088]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-30 13:27 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-30 13:25 219136]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-06 22:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AsusServiceProvider]
-ra------ 2006-10-23 13:28 593920 C:\Program Files\ASUS\AASP\1.00.12\aaCenter.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AsusStartupHelp]
-ra------ 2006-10-30 08:07 362496 C:\Program Files\ASUS\AASP\1.00.12\AsRunHelp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-10-28 16:25 94208 C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
--a------ 2007-09-06 13:08 136136 C:\Program Files\DAEMON Tools Pro\DTProAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE]
--a------ 2007-10-19 19:50 958464 C:\Program Files\Labtec\Desktop\V5.1\moffice.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 12:10 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OFFICEKB]
--a------ 2007-10-19 19:50 387584 C:\Program Files\Labtec\Desktop\V5.1\kbdap32a.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 10:56 286720 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2005-10-26 15:17 159744 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2006-11-10 12:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 00:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2006-02-17 04:30 35328 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"SandraTheSrv"=3 (0x3)
"SandraDataSrv"=3 (0x3)
"PnkBstrA"=2 (0x2)
"ose"=3 (0x3)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"awhost32"=3 (0x3)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"Apple Mobile Device"=2 (0x2)

R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys [2007-03-18 17:05]
R1 usbehcii;usbehcii;C:\WINDOWS\system32\drivers\usbehcii.sys [2008-01-30 14:54]
R1 waclient;waclient;C:\WINDOWS\system32\drivers\waclient.sys [2006-12-18 10:50]
R2 NgVpnMgr;Aventail VPN Client;C:\WINDOWS\system32\ngvpnmgr.exe [2005-08-12 09:47]
R3 Net6IM;Net6;C:\WINDOWS\system32\DRIVERS\net6im51.sys [2006-07-11 05:56]
R3 NgLog;Aventail VPN Logging;C:\WINDOWS\system32\DRIVERS\nglog.sys [2005-08-12 09:46]
R3 NgVpn;Aventail VPN Adapter;C:\WINDOWS\system32\DRIVERS\ngvpn.sys [2005-08-12 09:41]
S3 NgFilter;Aventail VPN Filter;C:\WINDOWS\system32\DRIVERS\ngfilter.sys [2005-08-12 09:46]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d9a2fa4b-b6e5-11dc-8501-001a924b0108}]
\Shell\AutoRun\command - I:\InstallTomTomHOME.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-01 22:10:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-01 23:50:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ngvpnmgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
.
**************************************************************************
.
Completion time: 2008-02-01 23:54:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-01 23:54:25
.
2008-01-16 03:01:23 --- E O F ---
Buck Pete
Newbie
Newbie
 
Posts: 5
Joined: Thu Jan 31, 2008 3:48 pm

Thanks given:0
Thanks received:0
Top

Postby Gecko » Sat Feb 02, 2008 2:38 am

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Buck Pete » Sat Feb 02, 2008 12:52 pm

Geko

Followed your instructions.

Attached is latest ComboFix.txt and HijackThis log

ComboFix 08-02.01.6 - pete 2008-02-02 11:37:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1450 [GMT 0:00]
Running from: C:\Documents and Settings\pete\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\pete\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\usbehcii.bak
C:\WINDOWS\system32\drivers\usbehcii.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\usbehcii.sys
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\All Users\Application Data\TEMP
C:\temp\tn3
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\usbehcii.sys

----- BITS: Possible infected sites -----

hxxp://au.download.windowsupdate.com
.
((((((((((((((((((((((((( Files Created from 2008-01-02 to 2008-02-02 )))))))))))))))))))))))))))))))
.

2008-02-05 16:21 . 2008-02-05 16:21 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
2008-02-05 16:20 . 2008-02-05 16:20 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-02-05 16:20 . 2008-02-05 16:20 669,184 --a------ C:\WINDOWS\system32\pbsvc.exe
2008-02-05 16:20 . 2008-02-05 16:20 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-02-05 16:20 . 2008-02-05 16:20 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-02-05 16:20 . 2008-02-05 16:20 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-05 16:20 . 2008-02-05 16:20 22,328 --a------ C:\Documents and Settings\pete\Application Data\PnkBstrK.sys
2008-02-05 15:55 . 2008-02-05 15:55 <DIR> d-------- C:\Program Files\Electronic Arts
2008-02-01 14:44 . 2008-02-01 14:44 <DIR> d-------- C:\Program Files\sixteen tons entertainment
2008-01-31 13:47 . 2008-01-31 13:47 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-31 12:15 . 2008-01-31 23:34 1,568 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-31 09:50 . 2008-01-31 09:50 <DIR> d-------- C:\Program Files\Aventail Connect
2008-01-31 09:50 . 2008-01-31 09:50 <DIR> d-------- C:\Documents and Settings\pete\Application Data\Aventail
2008-01-31 09:50 . 2008-01-31 09:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Aventail
2008-01-30 23:47 . 2008-01-30 23:47 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-30 23:47 . 2008-01-30 23:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-30 23:37 . 2008-01-30 23:37 <DIR> d-------- C:\Program Files\CCleaner
2008-01-30 19:13 . 2008-01-30 22:54 <DIR> d-------- C:\Program Files\STOPzilla!
2008-01-30 19:13 . 2008-01-30 19:13 <DIR> d-------- C:\Program Files\Common Files\iS3
2008-01-30 19:13 . 2008-01-30 22:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-01-30 13:27 . 2008-02-02 09:48 <DIR> d-------- C:\Documents and Settings\pete\Application Data\AVG7
2008-01-30 13:25 . 2008-01-30 13:25 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-30 13:25 . 2008-01-30 13:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-30 13:25 . 2008-01-31 09:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-01-22 15:16 . 2008-01-22 15:16 <DIR> d-------- C:\Program Files\SubmachineZero_at
2008-01-18 18:53 . 2008-01-18 19:04 <DIR> d-------- C:\Program Files\DTD Poker
2008-01-17 20:36 . 2008-01-17 20:36 14,941 --a------ C:\Credit card statement.JPG
2008-01-17 14:58 . 2008-01-17 14:58 557,056 --a------ C:\Documents and Settings\pete\GoToAssist_phone__319_en.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-01 14:44 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-01 12:18 --------- d-----w C:\Program Files\PokerStars
2008-02-01 10:53 --------- d-----w C:\Documents and Settings\pete\Application Data\uTorrent
2008-01-31 13:30 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-31 10:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-30 23:47 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-30 23:05 --------- d-----w C:\Program Files\EA GAMES
2008-01-30 23:00 --------- d-----w C:\Program Files\Symantec
2008-01-30 23:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-30 10:45 --------- d-----w C:\Program Files\DAEMON Tools Pro
2008-01-29 23:08 --------- d-----w C:\Program Files\Full Tilt Poker
2008-01-29 19:49 --------- d-----w C:\Program Files\CoralPoker
2008-01-29 14:19 --------- d-----w C:\Program Files\GalaPoker
2008-01-26 20:17 --------- d-----w C:\Documents and Settings\pete\Application Data\Bioshock
2008-01-26 19:25 --------- d-----w C:\Program Files\LimeWire
2008-01-15 09:54 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-15 05:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-14 09:58 --------- d-----w C:\Program Files\HollywoodPoker
2008-01-12 18:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-30 14:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2007-12-29 19:21 --------- d-----w C:\Program Files\The Witcher
2007-12-29 18:46 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2007-12-29 18:46 25,416 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys
2007-12-29 18:32 --------- d-----w C:\Documents and Settings\pete\Application Data\DAEMON Tools Pro
2007-12-29 18:15 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-12-23 17:48 --------- d-----w C:\Program Files\PokerRoom.com
2007-12-18 13:25 --------- d-----w C:\Program Files\iTunes
2007-12-18 13:25 --------- d-----w C:\Program Files\iPod
2007-12-18 13:24 --------- d-----w C:\Program Files\QuickTime
2007-12-15 13:41 --------- d-----w C:\Program Files\Littlewoods Poker
2007-12-13 12:16 --------- d-----w C:\Documents and Settings\pete\Application Data\Symantec
2007-12-11 17:25 --------- d-----w C:\Program Files\Common Files\Ahead
2007-12-05 15:21 --------- d-----w C:\Program Files\Titan Poker
2007-11-20 19:57 808,638 ----a-w C:\WINDOWS\Commando1001.zip
2007-11-02 13:43 1 ----a-w C:\Documents and Settings\pete\SI.bin
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 13:08 136136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-02-09 08:54 65024 C:\WINDOWS\SOUNDMAN.EXE]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-10-05 12:25 868352]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-07-13 06:12 729088]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-30 13:27 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-30 13:25 219136]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-06 22:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AsusServiceProvider]
-ra------ 2006-10-23 13:28 593920 C:\Program Files\ASUS\AASP\1.00.12\aaCenter.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AsusStartupHelp]
-ra------ 2006-10-30 08:07 362496 C:\Program Files\ASUS\AASP\1.00.12\AsRunHelp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-10-28 16:25 94208 C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
--a------ 2007-09-06 13:08 136136 C:\Program Files\DAEMON Tools Pro\DTProAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE]
--a------ 2007-10-19 19:50 958464 C:\Program Files\Labtec\Desktop\V5.1\moffice.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 12:10 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OFFICEKB]
--a------ 2007-10-19 19:50 387584 C:\Program Files\Labtec\Desktop\V5.1\kbdap32a.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 10:56 286720 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2005-10-26 15:17 159744 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2006-11-10 12:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 00:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2006-02-17 04:30 35328 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"SandraTheSrv"=3 (0x3)
"SandraDataSrv"=3 (0x3)
"PnkBstrA"=2 (0x2)
"ose"=3 (0x3)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"awhost32"=3 (0x3)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"Apple Mobile Device"=2 (0x2)

R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys [2007-03-18 17:05]
R1 waclient;waclient;C:\WINDOWS\system32\drivers\waclient.sys [2006-12-18 10:50]
R2 NgVpnMgr;Aventail VPN Client;C:\WINDOWS\system32\ngvpnmgr.exe [2005-08-12 09:47]
R3 Net6IM;Net6;C:\WINDOWS\system32\DRIVERS\net6im51.sys [2006-07-11 05:56]
R3 NgLog;Aventail VPN Logging;C:\WINDOWS\system32\DRIVERS\nglog.sys [2005-08-12 09:46]
R3 NgVpn;Aventail VPN Adapter;C:\WINDOWS\system32\DRIVERS\ngvpn.sys [2005-08-12 09:41]
S1 usbehcii;usbehcii;C:\WINDOWS\system32\drivers\usbehcii.sys []
S3 NgFilter;Aventail VPN Filter;C:\WINDOWS\system32\DRIVERS\ngfilter.sys [2005-08-12 09:46]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d9a2fa4b-b6e5-11dc-8501-001a924b0108}]
\Shell\AutoRun\command - I:\InstallTomTomHOME.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-01 22:10:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-02 11:44:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ngvpnmgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
.
**************************************************************************
.
Completion time: 2008-02-02 11:49:07 - machine was rebooted [pete]
ComboFix-quarantined-files.txt 2008-02-02 11:49:05
ComboFix2.txt 2008-02-01 23:54:27
.
2008-01-16 03:01:23 --- E O F ---


----------------------------------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:53:32, on 02/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ngvpnmgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Paddy Power Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\PADDYP~1\client.exe (file missing)
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra button: Stan James Poker.com Poker - {7F2F6F5A-CAE2-4954-A461-36B3757B2BFB} - C:\Program Files\stanjamesgibMPP\MPPoker.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Program Files\ladbrokesMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 3996640186
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 3996629389
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Aventail VPN Client (NgVpnMgr) - Aventail Corporation - C:\WINDOWS\system32\ngvpnmgr.exe

--
End of file - 5190 bytes
Buck Pete
Newbie
Newbie
 
Posts: 5
Joined: Thu Jan 31, 2008 3:48 pm

Thanks given:0
Thanks received:0
Top

Postby Gecko » Sat Feb 02, 2008 1:05 pm

Buck Pete,

Your log is clean.

How is it running now?
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Buck Pete » Sat Feb 02, 2008 11:53 pm

Absolutly fine now Gecko!!

Thanks very very much

Many thanks from England

take care mate

Pete.

PS. What AV/Spyware solution do you suggest for the future?
Buck Pete
Newbie
Newbie
 
Posts: 5
Joined: Thu Jan 31, 2008 3:48 pm

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 0 guests

cron