Spybot s&D = http://www.safer-networkin
AVG free = http://free.avg.com/ww.dow
smitfraud fix = http://siri.geekstogo.com/
Smitfraud first
Spybot second
avg third
Main Topics
Browse All TopicsI have a red x in the righ hand corner by the clock. It is a red blick x that keeps saying windows has detected spyware infection.
I have tried a handfull of solutions with no luck.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Spybot s&D = http://www.safer-networkin
AVG free = http://free.avg.com/ww.dow
smitfraud fix = http://siri.geekstogo.com/
Smitfraud first
Spybot second
avg third
Got it to Hj to run by renaming the install file and renaming the exe to h.com and running it fromt the non-default directory.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:43:27 PM, on 7/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\csrss.
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\WLTRYS
C:\WINDOWS\System32\bcmwlt
C:\WINDOWS\system32\spools
C:\WINDOWS\System32\SCardS
C:\Program Files\Broadcom\ASFIPMon\As
C:\WINDOWS\System32\svchos
C:\Program Files\Dell\QuickSet\NICCON
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\StacSV
C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\WINDOWS\system32\dllhos
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\system32\wbem\w
C:\WINDOWS\system32\dllhos
C:\WINDOWS\System32\alg.ex
C:\WINDOWS\system32\msdtc.
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
C:\WINDOWS\system32\wbem\w
C:\WINDOWS\TEMP\WD7F1E.EXE
C:\Program Files\Trend Micro\OfficeScan Client\PCCNTMON.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_07\bin
C:\Program Files\Dell\QuickSet\quicks
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDoc
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
C:\WINDOWS\system32\WLTRAY
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\igfxsr
C:\WINDOWS\system32\KADxMa
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Dell\E-Center\EULALaunc
C:\WINDOWS\system32\hkcmd.
C:\WINDOWS\system32\igfxpe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
C:\Program Files\Trend Micro\h.com
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
F2 - REG:system.ini: UserInit=C:\WINDOWS\system
O1 - Hosts: 192.135.176.8 Commerce.health.state.ny.u
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-D
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quicks
O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDoc
O4 - HKLM\..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMa
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Acrobat Speed Launch] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALaunc
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobs
O4 - HKLM\..\Run: [Acrobat Synchronizer] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSyn
O4 - HKLM\..\Run: [braviax] C:\WINDOWS\system32\bravia
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpe
O4 - HKUS\S-1-5-18\..\Run: [braviax] C:\WINDOWS\system32\bravia
O4 - HKUS\.DEFAULT\..\Run: [braviax] C:\WINDOWS\system32\bravia
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\Software\..\Telephony
O17 - HKLM\System\CS1\Services\T
O20 - AppInit_DLLs: cru629.dat
O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotif
O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\As
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCON
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OracleClientCache80 - Unknown owner - C:\orant\BIN\ONRSD80.EXE
O23 - Service: OracleOra9iClientCache - Unknown owner - c:\Oracle\Ora9i\BIN\ONRSD.
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageServi
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV
O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe
O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentServ
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYS
--
End of file - 9481 bytes
Probably Bagle. Try combofix, but rename the combofix file BEFORE downloading it. This link explains how to use combofix. Just make sure to rename the file as you are downloading it.
http://www.bleepingcompute
I would try Combofix in safemode. It generally works very well. Keep in mind that with all utilities that manipulate or delete files, you might want to consider a backup. Combofix will automatically create a restore point though.
It's a good start to most of the fake-antivirus variants out there. Follow up with Malwarebytes and you might be set.
Combofix : http://www.bleepingcompute
Malwarebytes : http://www.malwarebytes.or
braviax usually patches beep.sys that's where SDFix is good for this infection as it replaces/restores if beep.sys is patched.
The combofix log as InDiGenus had asked should tell us if beep.sys is patched.
I had a combofix log yesterday where combofix didn't delete the C:\WINDOWS\system32\ntos.e
I had this problem before on one of our office computers.... took me few days to remove as none of the mentioned tools worked for me either...!!!!
I was able to solve it after fixing one of Hijackthis entries.
The nasty entries you have as follow analyzed by the hijackthis.de website.
Note:
( You should create a restore point before fixing the items).
F2 - REG:system.ini: UserInit=C:\WINDOWS\system
O1 - Hosts: 192.135.176.8 Commerce.health.state.ny.u
O4 - HKLM\..\Run: [braviax] C:\WINDOWS\system32\bravia
O4 - HKUS\S-1-5-18\..\Run: [braviax] C:\WINDOWS\system32\bravia
O4 - HKUS\.DEFAULT\..\Run: [braviax] C:\WINDOWS\system32\bravia
O20 - AppInit_DLLs: cru629.dat
After you fix these entries, you must check if fixing the Entry ( - F2 - REG:system.ini: UserInit=C:\WINDOWS\system
[HKEY_LOCAL_MACHINE\SOFTWA
"Userinit"="C:\\Windows\\s
I suggest after fixing the items you use the tool (System file checker) to restore the good system files if the malware has replaced or infected any of them as rpggamergirl has referred to.
Goto Start
Click run
type sfc /scannow then enter (You will be prompted for the original CD for Windows XP)
After the scan is done, you may try to restart and check if the red x is gone.!
If that didn't work I suggest that you try the free version of Threatfire antivirus...
Combo fix log
ComboFix 08-07-21.2 - debm 2008-07-22 16:09:57.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.
Running from: C:\Documents and Settings\DebM\Desktop\comi
.
((((((((((((((((((((((((((
.
[color=red]C:\WINDOWS\syst
[color=red]C:\WINDOWS\syst
C:\WINDOWS\system32\bravia
C:\WINDOWS\system32\DelSel
C:\WINDOWS\system32\ntos.e
C:\WINDOWS\system32\winivs
C:\WINDOWS\system32\wsnpoe
C:\WINDOWS\system32\wsnpoe
C:\WINDOWS\system32\wsnpoe
C:\WINDOWS\system32\x64
.
((((((((((((((((((((((((( Files Created from 2008-06-22 to 2008-07-22 ))))))))))))))))))))))))))
.
2008-07-22 15:48 . 2008-07-22 15:48 4,864 --a------ C:\WINDOWS\system32\tmp.re
2008-07-22 15:24 . 2008-07-22 15:24 <DIR> d---s---- C:\Documents and Settings\ycadmin\UserData
2008-07-22 14:45 . 2008-02-15 20:45 172,032 --a------ C:\WINDOWS\system32\igfxre
2008-07-22 11:53 . 2008-02-15 21:11 1,843,784 --a------ C:\WINDOWS\system32\igklg4
2008-07-22 11:53 . 2008-02-15 21:11 1,399,880 --a------ C:\WINDOWS\system32\igklg4
2008-07-22 11:53 . 2008-02-15 21:21 147,456 --a------ C:\WINDOWS\system32\igfxCo
2008-07-22 11:53 . 2008-02-15 21:11 104,636 --a------ C:\WINDOWS\system32\igmedc
2008-07-22 11:52 . 2008-07-22 11:52 <DIR> d-------- C:\Intel
2008-07-22 10:46 . 2008-07-22 15:33 9,216 --a------ C:\WINDOWS\system32\burito
2008-07-22 10:46 . 2008-07-22 15:33 6,144 --a------ C:\WINDOWS\system32\karina
2008-07-22 10:46 . 2008-07-22 15:33 6,144 --a------ C:\WINDOWS\karina.dat
2008-07-22 10:45 . 2008-07-22 15:33 9,216 --a------ C:\WINDOWS\buritos.exe
2008-07-22 10:44 . 2004-08-04 06:00 4,224 --a------ C:\WINDOWS\system32\dllcac
2008-07-22 10:25 . 2008-07-22 10:25 <DIR> d---s---- C:\Documents and Settings\DebM\UserData
2008-07-22 10:23 . 2008-07-22 10:23 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-22 10:23 . 2008-07-22 10:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-22 10:07 . 2008-07-22 10:07 118 --a------ C:\WINDOWS\system32\MRT.IN
2008-07-07 14:36 . 2008-07-07 14:36 23 --a------ C:\WINDOWS\bo9040cn.ini
2008-07-03 12:09 . 2008-07-03 12:09 <DIR> d-------- C:\Program Files\AskSBar
2008-07-03 12:05 . 2008-07-22 10:24 <DIR> d-------- C:\Program Files\AWS
2008-07-03 11:58 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\driver
2008-07-03 11:58 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\dllcac
2008-07-03 11:57 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\driver
2008-07-03 11:57 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\dllcac
2008-07-03 11:57 . 2008-07-03 11:57 4,128 --a------ C:\INFCACHE.1
2008-07-03 10:56 . 2008-07-03 10:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Brother
2008-07-03 10:56 . 2008-07-07 14:36 426 --a------ C:\WINDOWS\BRWMARK.INI
2008-07-03 10:56 . 2008-07-03 10:56 26 --a------ C:\WINDOWS\BRPP2KA.INI
2008-07-03 10:27 . 2008-07-03 10:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESRI
2008-07-03 10:24 . 2008-07-03 10:24 <DIR> d-------- C:\Program Files\Common Files\AnswerWorks 4.0
2008-07-03 10:23 . 2008-07-03 11:24 <DIR> d-------- C:\Program Files\ArcGIS
2008-06-23 13:57 . 2005-03-30 09:14 1,867,776 --a------ C:\WINDOWS\system32\python
2008-06-23 13:39 . 2008-06-23 13:39 <DIR> d-------- C:\Program Files\Leica Geosystems
2008-06-23 13:37 . 2008-06-23 13:57 <DIR> d-------- C:\Python24
2008-06-23 12:16 . 2008-07-03 10:58 <DIR> d-------- C:\Documents and Settings\DebM\Application Data\ESRI
2008-06-23 12:05 . 2008-06-23 12:08 <DIR> d-------- C:\gis
.
((((((((((((((((((((((((((
.
2008-07-22 19:43 --------- d-----w C:\Program Files\Trend Micro
2008-07-22 14:02 --------- d-----w C:\Program Files\Java
2008-07-09 15:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-03 14:37 --------- d-----w C:\Program Files\ESRI
2008-07-03 14:27 --------- d-----w C:\Program Files\Common Files\ESRI
2008-06-23 16:36 --------- d-----w C:\Documents and Settings\ycadmin\Applicati
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\driver
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\driver
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\driver
2008-06-19 19:55 --------- d-----w C:\Program Files\MSXML 4.0
2008-06-19 18:28 --------- d-----w C:\Documents and Settings\DebM\Application Data\CyberLink
2008-06-19 18:24 --------- d-----w C:\Program Files\Centers for Disease Control and Prevention
2008-06-19 18:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-19 18:16 --------- d-----w C:\Program Files\3M Home Health Systems
2008-06-19 17:56 --------- d-----w C:\Program Files\Oracle
2008-06-19 17:42 --------- d-----w C:\Documents and Settings\ycadmin\Applicati
2008-06-19 16:58 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-06-19 16:56 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-19 16:52 --------- d-----w C:\Documents and Settings\DebM\Application Data\Dell
2008-06-19 13:48 --------- d-----w C:\Documents and Settings\ycadmin\Applicati
2008-06-19 13:47 --------- d-----w C:\Program Files\Google
2008-06-19 13:20 --------- d-----w C:\Documents and Settings\temp\Application Data\Dell
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\driver
2008-06-12 03:24 --------- d-----w C:\Program Files\Microsoft Small Business
2008-06-12 03:18 --------- d-----w C:\Program Files\Dell
2008-06-12 03:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-12 03:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-06-12 03:17 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-06-12 03:14 --------- d-----w C:\Program Files\Microsoft Works
2008-06-12 03:10 --------- d-----w C:\Program Files\CyberLink
2008-06-12 03:10 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-12 03:08 --------- d-----w C:\Program Files\Sigmatel
2008-06-12 03:08 --------- d-----w C:\Program Files\CONEXANT
2008-06-12 03:04 --------- d-----w C:\Program Files\Wave Systems Corp
2008-06-12 03:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Wave Systems Corp
2008-06-12 03:03 --------- d-----w C:\Documents and Settings\ycadmin\Applicati
2008-06-12 03:03 --------- d-----w C:\Documents and Settings\temp\Application Data\Wave Systems Corp
2008-06-12 03:03 --------- d-----w C:\Documents and Settings\DebM\Application Data\Wave Systems Corp
2008-06-12 03:03 --------- d-----w C:\Documents and Settings\Administrator\App
2008-06-12 03:00 --------- d-----w C:\Program Files\Fingerprint Sensor
2008-06-12 02:59 --------- d-----w C:\Program Files\Gemplus
2008-06-12 02:56 --------- d-----w C:\Program Files\NTRU Cryptosystems
2008-06-12 02:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\NTRU Cryptosystems
2008-06-12 02:52 --------- d-----w C:\Program Files\NetWaiting
2008-06-12 02:52 --------- d-----w C:\Program Files\Modem Diagnostic Tool
2008-06-12 02:52 --------- d-----w C:\Program Files\Digital Line Detect
2008-06-12 02:52 --------- d-----w C:\Program Files\Broadcom
2008-06-12 02:52 --------- d-----w C:\Documents and Settings\ycadmin\Applicati
2008-06-12 02:52 --------- d-----w C:\Documents and Settings\temp\Application Data\InstallShield
2008-06-12 02:52 --------- d-----w C:\Documents and Settings\DebM\Application Data\InstallShield
2008-06-12 02:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-06-12 02:52 --------- d-----w C:\Documents and Settings\Administrator\App
2008-06-12 02:50 --------- d-----w C:\Program Files\Common Files\Java
2008-06-12 02:34 --------- d-----w C:\Program Files\Apoint
2008-06-12 02:30 6,796 ----a-w C:\WINDOWS\system32\driver
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
"ctfmon.exe"="C:\WINDOWS\s
[HKEY_LOCAL_MACHINE\SOFTWA
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2007-01-25 03:34 159744]
"SunJavaUpdateSched"="C:\P
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quicks
"WavXMgr"="C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDoc
"SecureUpgrade"="C:\Progra
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\W
"KADxMain"="C:\WINDOWS\sys
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 12:56 124200]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"Acrobat Speed Launch"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
"ECenter"="C:\Dell\E-Cente
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2007-05-08 01:43 702072]
"Acrobat Synchronizer"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSyn
"IgfxTray"="C:\WINDOWS\sys
"HotKeysCmds"="C:\WINDOWS\
"Persistence"="C:\WINDOWS\
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-06-11 22:52:32 50688]
[HKEY_LOCAL_MACHINE\softwa
2006-11-16 16:20 73728 C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotif
[HKEY_LOCAL_MACHINE\system
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\yatescounty.loc
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\yatescounty.loc
[HKEY_LOCAL_MACHINE\softwa
"AntiVirusDisableNotify"=d
"UpdatesDisableNotify"=dwo
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
[HKLM\~\services\sharedacc
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
"%windir%\\system32\\sessm
"C:\\Program Files\\CyberLink\\PowerDVD
"C:\\Program Files\\CyberLink\\PowerDVD
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.
R0 PBADRV;PBADRV;C:\WINDOWS\s
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;C:\Program Files\Broadcom\ASFIPMon\As
R2 TdmService;TdmService;C:\P
R2 Wave UCSPlus;Wave UCSPlus;C:\WINDOWS\system3
R2 WavxDMgr;WavxDMgr;C:\WINDO
R3 DXEC01;DXEC01;C:\WINDOWS\s
R3 WaveFDE;Wave System Power Monitor Device Driver;C:\WINDOWS\system32
S3 OracleClientCache80;Oracle
S3 OracleOra9iClientCache;Ora
S3 SecureStorageService;Secur
S3 WaveEnrollmentService;Wave
[HKEY_LOCAL_MACHINE\softwa
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.google.com/ig/d
O8 -: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Offic
**************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-22 16:13:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\WLTRYS
C:\WINDOWS\system32\BCMWLT
C:\WINDOWS\system32\scards
C:\Program Files\Dell\QuickSet\NicCon
C:\WINDOWS\system32\stacsv
C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
C:\WINDOWS\system32\msdtc.
C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\hidfind.exe
C:\Program Files\Apoint\ApntEx.exe
C:\WINDOWS\system32\igfxsr
C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe
C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
C:\WINDOWS\temp\RE9304.EXE
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
C:\WINDOWS\system32\wbem\w
.
**************************
.
Completion time: 2008-07-22 16:16:46 - machine was rebooted [debm]
ComboFix-quarantined-files
Pre-Run: 62,886,752,256 bytes free
Post-Run: 63,663,267,840 bytes free
227 --- E O F --- 2008-07-22 14:07:18
Hijack log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:21:53, on 7/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\WLTRYS
C:\WINDOWS\System32\bcmwlt
C:\WINDOWS\system32\spools
C:\Program Files\Broadcom\ASFIPMon\As
C:\WINDOWS\System32\svchos
C:\Program Files\Dell\QuickSet\NICCON
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\StacSV
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\WINDOWS\system32\dllhos
C:\WINDOWS\system32\dllhos
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_07\bin
C:\Program Files\Dell\QuickSet\quicks
C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDoc
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
C:\WINDOWS\system32\WLTRAY
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\KADxMa
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Dell\E-Center\EULALaunc
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\hkcmd.
C:\WINDOWS\system32\igfxpe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\igfxsr
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPA
C:\Program Files\Trend Micro\h.com
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-D
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quicks
O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDoc
O4 - HKLM\..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMa
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Acrobat Speed Launch] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALaunc
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobs
O4 - HKLM\..\Run: [Acrobat Synchronizer] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSyn
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpe
O4 - HKUS\S-1-5-21-823518204-68
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\Software\..\Telephony
O17 - HKLM\System\CS1\Services\T
O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotif
O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\As
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCON
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OracleClientCache80 - Unknown owner - C:\orant\BIN\ONRSD80.EXE
O23 - Service: OracleOra9iClientCache - Unknown owner - c:\Oracle\Ora9i\BIN\ONRSD.
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageServi
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV
O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe
O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentServ
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYS
--
End of file - 9050 bytes
I ran trend antivirus last night and it picked up and quarantineed 5 viruses...
-another improvement I can run hijack this from the start program menu.
I just ran combfix again from safe mode and here is the log:
ComboFix 08-07-21.2 - Administrator 2008-07-23 10:29:03.2 - NTFSx86 MINIMAL
Running from: C:\Documents and Settings\Administrator\Des
.
((((((((((((((((((((((((( Files Created from 2008-06-23 to 2008-07-23 ))))))))))))))))))))))))))
.
2008-07-23 10:21 . 2008-07-23 10:21 <DIR> d--h----- C:\WINDOWS\PIF
2008-07-22 15:48 . 2008-07-22 15:48 4,864 --a------ C:\WINDOWS\system32\tmp.re
2008-07-22 15:24 . 2008-07-22 15:24 <DIR> d---s---- C:\Documents and Settings\ycadmin\UserData
2008-07-22 14:45 . 2008-02-15 20:45 172,032 --a------ C:\WINDOWS\system32\igfxre
2008-07-22 11:53 . 2008-02-15 21:11 1,843,784 --a------ C:\WINDOWS\system32\igklg4
2008-07-22 11:53 . 2008-02-15 21:11 1,399,880 --a------ C:\WINDOWS\system32\igklg4
2008-07-22 11:53 . 2008-02-15 21:21 147,456 --a------ C:\WINDOWS\system32\igfxCo
2008-07-22 11:53 . 2008-02-15 21:11 104,636 --a------ C:\WINDOWS\system32\igmedc
2008-07-22 11:52 . 2008-07-22 11:52 <DIR> d-------- C:\Intel
2008-07-22 10:46 . 2008-07-22 15:33 9,216 --a------ C:\WINDOWS\system32\burito
2008-07-22 10:45 . 2008-07-22 15:33 9,216 --a------ C:\WINDOWS\buritos.exe
2008-07-22 10:44 . 2004-08-04 06:00 4,224 --a------ C:\WINDOWS\system32\dllcac
2008-07-22 10:25 . 2008-07-22 10:25 <DIR> d---s---- C:\Documents and Settings\DebM\UserData
2008-07-22 10:23 . 2008-07-22 10:23 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-22 10:23 . 2008-07-22 10:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-22 10:07 . 2008-07-22 10:07 118 --a------ C:\WINDOWS\system32\MRT.IN
2008-07-07 14:36 . 2008-07-07 14:36 23 --a------ C:\WINDOWS\bo9040cn.ini
2008-07-03 12:09 . 2008-07-03 12:09 <DIR> d-------- C:\Program Files\AskSBar
2008-07-03 12:05 . 2008-07-22 10:24 <DIR> d-------- C:\Program Files\AWS
2008-07-03 11:58 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\driver
2008-07-03 11:58 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\dllcac
2008-07-03 11:57 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\driver
2008-07-03 11:57 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\dllcac
2008-07-03 11:57 . 2008-07-03 11:57 4,128 --a------ C:\INFCACHE.1
2008-07-03 10:56 . 2008-07-03 10:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Brother
2008-07-03 10:56 . 2008-07-07 14:36 426 --a------ C:\WINDOWS\BRWMARK.INI
2008-07-03 10:56 . 2008-07-03 10:56 26 --a------ C:\WINDOWS\BRPP2KA.INI
2008-07-03 10:27 . 2008-07-03 10:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESRI
2008-07-03 10:24 . 2008-07-03 10:24 <DIR> d-------- C:\Program Files\Common Files\AnswerWorks 4.0
2008-07-03 10:23 . 2008-07-03 11:24 <DIR> d-------- C:\Program Files\ArcGIS
2008-06-23 13:57 . 2005-03-30 09:14 1,867,776 --a------ C:\WINDOWS\system32\python
2008-06-23 13:39 . 2008-06-23 13:39 <DIR> d-------- C:\Program Files\Leica Geosystems
2008-06-23 13:37 . 2008-06-23 13:57 <DIR> d-------- C:\Python24
2008-06-23 12:16 . 2008-07-03 10:58 <DIR> d-------- C:\Documents and Settings\DebM\Application Data\ESRI
2008-06-23 12:05 . 2008-06-23 12:08 <DIR> d-------- C:\gis
.
((((((((((((((((((((((((((
.
2008-07-23 14:21 --------- d-----w C:\Program Files\Trend Micro
2008-07-22 14:02 --------- d-----w C:\Program Files\Java
2008-07-09 15:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-03 14:37 --------- d-----w C:\Program Files\ESRI
2008-07-03 14:27 --------- d-----w C:\Program Files\Common Files\ESRI
2008-06-23 16:36 --------- d-----w C:\Documents and Settings\ycadmin\Applicati
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\driver
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\driver
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\driver
2008-06-19 19:55 --------- d-----w C:\Program Files\MSXML 4.0
2008-06-19 18:28 --------- d-----w C:\Documents and Settings\DebM\Application Data\CyberLink
2008-06-19 18:24 --------- d-----w C:\Program Files\Centers for Disease Control and Prevention
2008-06-19 18:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-19 18:16 --------- d-----w C:\Program Files\3M Home Health Systems
2008-06-19 17:56 --------- d-----w C:\Program Files\Oracle
2008-06-19 17:42 --------- d-----w C:\Documents and Settings\ycadmin\Applicati
2008-06-19 16:58 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-06-19 16:56 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-19 16:52 --------- d-----w C:\Documents and Settings\DebM\Application Data\Dell
2008-06-19 13:48 --------- d-----w C:\Documents and Settings\ycadmin\Applicati
2008-06-19 13:47 --------- d-----w C:\Program Files\Google
2008-06-19 13:20 --------- d-----w C:\Documents and Settings\temp\Application Data\Dell
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\driver
2008-06-12 03:24 --------- d-----w C:\Program Files\Microsoft Small Business
2008-06-12 03:18 --------- d-----w C:\Program Files\Dell
2008-06-12 03:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-12 03:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-06-12 03:17 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-06-12 03:14 --------- d-----w C:\Program Files\Microsoft Works
2008-06-12 03:10 --------- d-----w C:\Program Files\CyberLink
2008-06-12 03:10 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-12 03:08 --------- d-----w C:\Program Files\Sigmatel
2008-06-12 03:08 --------- d-----w C:\Program Files\CONEXANT
2008-06-12 03:04 --------- d-----w C:\Program Files\Wave Systems Corp
2008-06-12 03:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Wave Systems Corp
2008-06-12 03:03 --------- d-----w C:\Documents and Settings\ycadmin\Applicati
2008-06-12 03:03 --------- d-----w C:\Documents and Settings\temp\Application Data\Wave Systems Corp
2008-06-12 03:03 --------- d-----w C:\Documents and Settings\DebM\Application Data\Wave Systems Corp
2008-06-12 03:03 --------- d-----w C:\Documents and Settings\Administrator\App
2008-06-12 03:00 --------- d-----w C:\Program Files\Fingerprint Sensor
2008-06-12 02:59 --------- d-----w C:\Program Files\Gemplus
2008-06-12 02:56 --------- d-----w C:\Program Files\NTRU Cryptosystems
2008-06-12 02:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\NTRU Cryptosystems
2008-06-12 02:52 --------- d-----w C:\Program Files\NetWaiting
2008-06-12 02:52 --------- d-----w C:\Program Files\Modem Diagnostic Tool
2008-06-12 02:52 --------- d-----w C:\Program Files\Digital Line Detect
2008-06-12 02:52 --------- d-----w C:\Program Files\Broadcom
2008-06-12 02:52 --------- d-----w C:\Documents and Settings\ycadmin\Applicati
2008-06-12 02:52 --------- d-----w C:\Documents and Settings\temp\Application Data\InstallShield
2008-06-12 02:52 --------- d-----w C:\Documents and Settings\DebM\Application Data\InstallShield
2008-06-12 02:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-06-12 02:52 --------- d-----w C:\Documents and Settings\Administrator\App
2008-06-12 02:50 --------- d-----w C:\Program Files\Common Files\Java
2008-06-12 02:34 --------- d-----w C:\Program Files\Apoint
2008-06-12 02:30 6,796 ----a-w C:\WINDOWS\system32\driver
.
((((((((((((((((((((((((((
.
- 2008-07-22 19:37:41 65,446 ----a-w C:\WINDOWS\system32\perfc0
+ 2008-07-23 14:30:26 65,044 ----a-w C:\WINDOWS\system32\perfc0
- 2008-07-22 19:37:41 411,142 ----a-w C:\WINDOWS\system32\perfh0
+ 2008-07-23 14:30:26 410,574 ----a-w C:\WINDOWS\system32\perfh0
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWA
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2007-01-25 03:34 159744]
"SunJavaUpdateSched"="C:\P
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quicks
"WavXMgr"="C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDoc
"SecureUpgrade"="C:\Progra
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\W
"KADxMain"="C:\WINDOWS\sys
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 12:56 124200]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"Acrobat Speed Launch"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe
"ECenter"="C:\Dell\E-Cente
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2007-05-08 01:43 702072]
"Acrobat Synchronizer"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSyn
"IgfxTray"="C:\WINDOWS\sys
"HotKeysCmds"="C:\WINDOWS\
"Persistence"="C:\WINDOWS\
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-06-11 22:52:32 50688]
[HKEY_LOCAL_MACHINE\softwa
2006-11-16 16:20 73728 C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotif
[HKEY_LOCAL_MACHINE\system
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\yatescounty.loc
[HKEY_LOCAL_MACHINE\softwa
"Script"=\\yatescounty.loc
[HKEY_LOCAL_MACHINE\softwa
"AntiVirusDisableNotify"=d
"UpdatesDisableNotify"=dwo
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
[HKLM\~\services\sharedacc
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
"%windir%\\system32\\sessm
"C:\\Program Files\\CyberLink\\PowerDVD
"C:\\Program Files\\CyberLink\\PowerDVD
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.
R0 PBADRV;PBADRV;C:\WINDOWS\s
S2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;C:\Program Files\Broadcom\ASFIPMon\As
S2 TdmService;TdmService;C:\P
S2 Wave UCSPlus;Wave UCSPlus;C:\WINDOWS\system3
S2 WavxDMgr;WavxDMgr;C:\WINDO
S3 DXEC01;DXEC01;C:\WINDOWS\s
S3 OracleClientCache80;Oracle
S3 OracleOra9iClientCache;Ora
S3 SecureStorageService;Secur
S3 WaveEnrollmentService;Wave
S3 WaveFDE;Wave System Power Monitor Device Driver;C:\WINDOWS\system32
[HKEY_LOCAL_MACHINE\softwa
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = www.google.com/ig/dell?hl=
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
O8 -: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 -: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
**************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-23 10:37:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
.
Completion time: 2008-07-23 10:40:58 - machine was rebooted
ComboFix-quarantined-files
Pre-Run: 63,754,121,216 bytes free
Post-Run: 63,746,818,048 bytes free
194 --- E O F --- 2008-07-22 14:07:18
Hi Philonator
Your hijackthis log looks very clean...!!!
Your combofix log shows the suspicious buritos.exe which is created by the malware/trojan backdoor.win32.Small.eug.
It's recommended that you process the file buritos.exe on your both directories Windows and windows/system32 to www.virustotal.com to check weather it's infected or not.
If they are infected, then you must delete those files ....
Here's an open thread for the same trojan that is still undone yet ...
http://www.experts-exchang
I suggest that you disable your System restore, Restart in safe mode after you fully update your installed antivirus and run a full scan .. You might want to include the Archives (zip, rar..etc) files within the scan and preferably to run a in-depth scan... which will take longer.
Some other files are unidentified and might be created by this trojan too, I'l list them below and you need to do the same thing you have done for the buritos.exe files
bo9040cn.ini
The trojan seems to play with your antivirus and windows registry...It has disabled your Trend micro Monitoring and the security warning in windows security center.
[HKEY_LOCAL_MACHINE\softwa
"AntiVirusDisableNotify"=d
"UpdatesDisableNotify"=dwo
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
You can fix this issue by your self by adjusting the value from 1 to 0... but remember to first export the reg to your desktop or to a safe place/ or just create a restore point after you have restarted from safe mode.
Hope this helps..
Moh10ly, good call on the buritos. I have 5 pcs running this virus now. I have found it on others but not on this one. This computer I thought was fixed but it looks it still has it. I wrote a custom combofix script that works well for getting rid of burritos. I will run it on this machine and repost my comobfix log.
Business Accounts
Answer for Membership
by: PhilonatorPosted on 2008-07-22 at 12:37:14ID: 22062844
I can't get hijack this to run either...in safe mode or reg. tried renaming files for as well