My colleague in the next cublicle at work as contracted the "A Better Internet" malware. ABetterInternet.Transponde
r.VX2 Microsoft's antispyware beta says it's related to the ceres.dll version. We've tried everything. HijackThis, Microsoft Beta AntiSpyware, Spy Sweeper, Adaware, SpyBot S&D, Spy Hunter, they all detect it, none of them seem to successfully remove it (though they say they are). He still gets those poppuppers windows all the time and he seems to keep automatically downloading new Trojans on a regular basis as well (his McAfee Security Centre keeps deleting them as they appear throughout his system). I'm sure he installed some spyware related EXE by mistake and I think it's all related. I've saved a copy of his hijack this log. Mayvbe you guys can help??
Logfile of HijackThis v1.95.1
Scan saved at 9:22:04 AM, on 2/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\csrss.
exe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.e
xe
C:\Inetpub\CFusionMX\runti
me\bin\jru
nsvc.exe
C:\Inetpub\CFusionMX\db\sl
server52\b
in\swagent
.exe
C:\Inetpub\CFusionMX\runti
me\bin\jru
n.exe
C:\Inetpub\CFusionMX\db\sl
server52\b
in\swstrtr
.exe
C:\Inetpub\CFusionMX\db\sl
server52\b
in\swsoc.e
xe
C:\WINDOWS\System32\CTsvcC
DA.exe
C:\Program Files\Executive Software\Diskeeper\DkServi
ce.exe
C:\WINDOWS\System32\gearse
c.exe
C:\PROGRA~1\Symantec\NORTO
N~1\GHOSTS
~2.EXE
C:\WINDOWS\System32\inetsr
v\inetinfo
.exe
c:\PROGRA~1\mcafee.com\vso
\mcvsrte.e
xe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\Program Files\Adobe\Adobe Version Cue\data\database\pbds.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentr
y.exe
C:\Program Files\Creative\SBAudigy2\S
urround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\D
VDAudio\CT
DVDDet.EXE
C:\WINDOWS\system32\CTHELP
ER.EXE
C:\Program Files\D-Tools\daemon.exe
C:\PROGRA~1\Logitech\MOUSE
W~1\SYSTEM
\EM_EXEC.E
XE
C:\PROGRA~1\mcafee.com\vso
\mcvsshld.
exe
C:\PROGRA~1\mcafee.com\age
nt\mcagent
.exe
c:\progra~1\mcafee.com\vso
\mcvsescn.
exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\windows\system32\makpkf
s.exe
C:\WINDOWS\a64sddd.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\CleanMyPC\Registry Cleaner\RCScheduler.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\InterVideo\Common\Bi
n\WinCinem
aMgr.exe
C:\windows\system32\calc.e
xe
C:\PROGRA~1\ICQ\ICQ.exe
c:\progra~1\mcafee.com\vso
\mcvsftsn.
exe
C:\Program Files\Adobe\Adobe Version Cue\tomcat\webapps\ROOT\WE
B-INF\comp
onents\com
.adobe.bau
haus.nativ
ecomm\res\
VCNative.e
xe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\wdfmgr
.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSP
Sv.exe
c:\PROGRA~1\mcafee.com\vso
\mcshield.
exe
C:\WINDOWS\System32\alg.ex
e
C:\Program Files\Macromedia\Dreamweav
er MX 2004\Dreamweaver.exe
C:\DOCUME~1\DSIMON~1\LOCAL
S~1\Temp\~
e5d141.tmp
C:\DOCUME~1\DSIMON~1\LOCAL
S~1\Temp\~
e5d141.tmp
C:\Program Files\Common Files\AOL\ACS\acsd.exe
C:\WINDOWS\system32\dllhos
t.exe
C:\WINDOWS\System32\dllhos
t.exe
C:\WINDOWS\System32\msdtc.
exe
C:\Program Files\Qualcomm\Eudora\Eudo
ra.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\D Simone\Application Data\Microsoft\Internet Explorer\Quick Launch\HijackThis.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://google.ca/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.
htm
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.
htm
N1 - Netscape 4: user_pref("browser.startup
.homepage"
, "
http://www/"); (C:\Program Files\Netscape\Users\daphn
e_simone\p
refs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIE
Helper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0
445EE16191
0} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClien
t.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
819E2EAAC9
3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClien
t.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-9
05236F6F65
5} - c:\progra~1\mcafee.com\vso
\mcvsshl.d
ll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentr
y.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\S
urround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\D
VDAudio\CT
DVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSE
W~1\SYSTEM
\EM_EXEC.E
XE
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vs
o\mcmnhdlr
.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vs
o\mcvsshld
.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age
nt\mcagent
.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\age
nt\mcupdat
e.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [makpkfs] c:\windows\system32\makpkf
s.exe
O4 - HKLM\..\Run: [popuppers64] C:\WINDOWS\a64sddd.exe
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.
exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Registry Cleaner Scheduler] "C:\Program Files\CleanMyPC\Registry Cleaner\RCScheduler.exe" /startup
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
obe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bi
n\WinCinem
aMgr.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
1.dll/cmse
arch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
1.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
1.dll/cmca
che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
1.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
1.dll/cmtr
ans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O16 - DPF: {0246ECA8-996F-11D1-BE2F-0
0A0C9037DF
E} -
O16 - DPF: {02BCC737-B171-4746-94C9-0
D8A0B2C008
9} -
O16 - DPF: {14B87622-7E19-4EA8-93B3-9
7215F77A6B
C} -
O16 - DPF: {166B1BCA-3F9C-11CF-8075-4
4455354000
0} (Shockwave ActiveX Control) -
http://active.macromedia.com/director/cabs/sw.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5
A1EDB1D8A2
1} (McAfee.com Operating System Class) -
http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,76/mcinsctl.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0
050DA18DE7
1} -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4
DFAD1796A8
D} -
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-2
2031317559
2} -
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C
18E1ADA438
9} (DwnldGroupMgr Class) -
http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,19/mcgdmgr.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab