Question

Virus/Malware issue

Asked by: b0lsc0tt

AVG continues to find a file called 9129837.exe and "deletes" it at start up.  Next time starting it comes up again though.  File seems to be in the Windows\Prefetch folder and is also in an AVG folder.  Is that file a problem (the prefetch one)?  How can we get rid of it so AVG won't "find" it at start up?

There was an entry for ikowin32.exe in the Startup folder in the Start Menu and in the MSCONFIG area of Startup.  The exe itself was in that folder and has been deleted.  Is there still any trace?  I mention this in case it helps know the infection.  There is still an entry for it in the Registry at ...

HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^scottd^Start Menu^Programs^Startup^ikowin32.exe

That doesn't seem related to the entry in MSCONFIG so should I manually delete it?  How can I remove the entry I see in MSCONFIG?

A HJT log is below.  It was run after manually deleting the file in the StartUp folder and after running MalwareBytes.  I just did a quick scan with MalwareBytes but it is doing a full scan now.  The quick scan found on .LOG file in the ApplicationData folder (e.g.  USER\Application Data).  I believe it removed that file.

The OS is XP.  Virus protection is AVG.  I hope this is still clear but I tried to keep brief and to the point.  Please NO Googled responses or canned replies without first making sure it relates to all I provided here!  I have done research already and relying on the experts here to help me clean the last of this or confirm the machine looks good.

Should I run anything else.  I will let you know the results of the MalwareBytes full scan but it will probably be "tomorrow."  I can provide more info or details if it will help so don't hesitate to ask.  Thanks a lot for your help and time!!

bol

p.s.  I was told a message appeared early in this "infection" about a file called pfdupd.exe .  Is that a problem or concern (or legit)?  There is also a new Windows folder called PSS (e.g. C:\Windows\PSS).  Is that a problem?  Finally, for bonus, is the file in the Prefetch folder something good to delete manually and what is that folder for (simple explanation fine and I will open new Q if needed for more).

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:57:08 PM, on 9/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSAgent.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSWatcher.exe
C:\Program Files\CodeGear\RAD Studio\6.0\bin\BSQLServer.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\bin\AVGIDSUI.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Acesoft\Tracks Eraser Pro\te.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Citrix\GoToMeeting\366\g2mstart.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\bin\AVGIDSMonitor.exe
C:\Program Files\Citrix\GoToMeeting\366\g2mcomm.exe
C:\Program Files\Citrix\GoToMeeting\366\g2mlauncher.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070802
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070802
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [AVGIDS] "C:\Program Files\AVG\AVG8\IdentityProtection\agent\bin\AVGIDSUI.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Tracks Eraser Pro] C:\Program Files\Acesoft\Tracks Eraser Pro\te.exe min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [GoToMeeting] C:\Program Files\Citrix\GoToMeeting\366\g2mstart.exe "/Trigger RunAtLogon"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ESC Trusted Zone: http://www.wise.com
O16 - DPF: {099403A7-2334-4432-BDD0-F496AE3A86B5} (PreVistaEnrollControl Class) - https://secure.digsigtrust.com/ms/IdenTrustCertEnroll.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: HookDLL.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Broadcom ASF IP Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: AVGIDSAgent - AVG - C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSAgent.exe
O23 - Service: AVGIDSWatcher - AVG - C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSWatcher.exe
O23 - Service: BlackfishSQL - CodeGear - C:\Program Files\CodeGear\RAD Studio\6.0\bin\BSQLServer.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9cda534d21190) (gupdate1c9cda534d21190) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
 
--
End of file - 11302 bytes

                                  
1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
18:
19:
20:
21:
22:
23:
24:
25:
26:
27:
28:
29:
30:
31:
32:
33:
34:
35:
36:
37:
38:
39:
40:
41:
42:
43:
44:
45:
46:
47:
48:
49:
50:
51:
52:
53:
54:
55:
56:
57:
58:
59:
60:
61:
62:
63:
64:
65:
66:
67:
68:
69:
70:
71:
72:
73:
74:
75:
76:
77:
78:
79:
80:
81:
82:
83:
84:
85:
86:
87:
88:
89:
90:
91:
92:
93:
94:
95:
96:
97:
98:
99:
100:
101:
102:
103:
104:
105:
106:
107:
108:
109:
110:
111:
112:
113:
114:
115:
116:
117:
118:
119:
120:
121:
122:
123:
124:
125:
126:
127:
128:
129:
130:
131:
132:
133:
134:
135:
136:

Select allOpen in new window

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-09-15 at 17:22:38ID24734910
Tags

Virus

,

HiJackThis

,

Malware

,

MalwareBytes

,

XP

,

AVG

Topics

Anti-Virus

,

AVG

,

HijackThis Software

,

Anti-Spyware

,

Desktop Anti-Virus

Participating Experts
7
Points
500
Comments
40

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. analyze HJT logfile
    Customer has Toshiba satellite notebook home xp. Logfile of HijackThis v1.99.0 Scan saved at 2:38:02 PM, on 2/12/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\w...
  2. about.blank infection HJT analysis
    Hi I think I have an about.blank infection. I ran HJT,and this link is the result of analysis from http://www.hijackthis.de/logfiles/a10a67867a087fad3360b65a8277b0ad.html I have system restore turned off. I ran HJT in safe mode. I tried several times with HJT to fix the...
  3. Virus Infection?
    I have a pc running XP Pro SP2 which is acting up. It is impossible to make hidden files and folders visible. Most spyware and Antivirus software either hangs or refuses to start and some other programs will not start. I am fairly sure that there is or has been a virus causi...
  4. PC infected with  spyware / malware
    Hi Experts! My computer is again infected with spyware. I use Win XP Pro SP2. A month ago, I reformatted the HDD because I was not able to remove all of these spyware. Now they are back and I don't want to reformat the HDD again. My anti-virus software is Panda and it stopp...
  5. Virus or spyware blocking access to support and anti-mal…
    First, I am running this repair remotely on a coworker's computer in another country. I am using the LogMeIn system. It does allow me to remotely reboot and reconnect as needed, but it may add some challenges. Note that LogMeIn processes show as "lmi_" in the regist...
  6. Need Help with HJT
    Happy New Year, I have a Dell Laptop that I think still has something in it that should'nt be. I have run Malwarebytes and Sdfix,Smitfraud,Spybot,Super Anti Virus and probably a couple of others. I have attached the HJT log file in hopes that someone can tell me what else ...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: anil_kumar137Posted on 2009-09-15 at 23:38:31ID: 25342538

Hi, any enties which is in msconfig will be find registry in this path below and also run combofix if its malware it will remove it.

HKLM\SOFTWARE\Microsoft\windows\currentversion\run

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

 

by: StussyexpertPosted on 2009-09-16 at 00:48:38ID: 25342932

The Prefetch folder in your Windows directory is used to store information on the applications that you always open, this will speed up the loading time the next time you open it again. It save to delete the content.

Try this free online virusscanner: http://housecall.trendmicro.com/

 

by: younghvPosted on 2009-09-16 at 03:50:43ID: 25344035

bol -
MBAM is a great product, but we get a much better picture of what is running on a computer from "ComboFix".

Basic download and run comments from 'rpg' here:

Please download ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..


Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

 

by: rxfosterPosted on 2009-09-16 at 06:34:28ID: 25345394

b0lsc0tt, have you tried bringing the machine up in safe mode and disinfecting?

Back in the day, as a last-ditch effort on certain obnoxious viruses (and long before there was the plethora of utilities we have now) we would kill a file, and create a dummy file of the same name in its place, so that when the process went to create that file, it would fail.

You can use this in conjunction with filemon: http://technet.microsoft.com/en-us/sysinternals/bb896642.aspx

So, create that file, reboot, and bring up filemon.  If there is a process continually writing out that file, you will see it being denied in filemon, you can then track it down and destroy it.

 

by: younghvPosted on 2009-09-16 at 11:22:59ID: 25348512

rxfoster,
I too remember the old days of 'Safe Mode' scans being the starting point for anti-malware work. Unfortunately the bad guys have gotten a lot better at what they do.

Both ComboFix and MBAM (and a few others) are specifically written to run in Normal Mode - and to identify the malware processes (and sources) while you are running your computer as you normally would.

When 'bol' posts his ComboFix log, standby to watch 'rpggamergirl' put the hurt on whatever bad stuff is running on that computer. It is a joy to behold.

 

by: b0lsc0ttPosted on 2009-09-16 at 11:24:42ID: 25348522

Thanks for the responses.  An update first.

Full scan using MalwareBytes and then AVG did not find anything.  I have run ComboFix and the log is below.  The message we were getting from AVG everytime the machine started about finding the 9129837.exe file has not come up since ComboFix was run.

How does the ComboFix log look?  Any concerns or something else we should do?  The machine seems to running fine now.  I haven't looked to see if the file was still in the Prefetch folder (with a .pf extension and slightly different name) or if the registry entry was still there.  I can look at those if it is important.

Also I figured you would mention if the HJT log looked bad but it is available in the question body.  I didn't see a response about it so wanted to make sure it wasn't just overlooked.  Disregard it of course if the ComboFix log is better (see below).

Let me know if you need any other info or have a question.  Thanks to all who have posted or looked at this so far!

anil_kumar137,
Thanks for the registry path and the first recommendation for ComboFix.  It is a great program.  As far as the path I now remember that one but had gotten confused about it.  Relates to MSCONFIG and removing entries but probably not worth bringing up here.

Stussyexpert,
Thanks for the info on the Prefetch folder and contents.  If the file doesn't get removed by these clean up steps and programs then I will manually remove it later manually.

younghv,
Thanks for the ComboFix details.  The results are below.  A side note as I ran it.  It was the first time I did it on a machine running AVG.  I did disable the Resident Shield before starting the program but somehow AVG still popped up a message to Allow/(or some other option) about 3 program files related to ComboFix.  It happened right at the start.  The rest seemed to go fine but I was concerned AVG may cause a real problem.  Do you know if I missed something in trying to "shutdown" the virus program?  Some of those really are a pain to disable. :(

rxfoster,
The machine has been working fine in normal mode so I haven't had to result to SafeMode for any steps yet.  Fingers are crossed that we passed the worst of it.  I do know most of what I have run or has been suggested works better in Normal mode so I prefer to avoid Safe Mode unless it is my only option.  As far as FileMon, I am aware of it but honestly it would be a last resort.  I'd rather rely on Virus experts and programs to clean than try to manually chase it down.

bol

ComboFix 09-09-14.02 - scottd 09/16/2009  9:29.1.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2046.1368 [GMT -7:00]
Running from: c:\documents and settings\scottd\Desktop\ComboFix.exe
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
 
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
 
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
 
c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
c:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
c:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
c:\windows\SW_Win2000X16.DLL
c:\windows\SW_Win2000X9.DLL
c:\windows\system32\images
c:\windows\system32\images\toolbar\calendar.gif
c:\windows\system32\images\toolbar\crlogo.gif
c:\windows\system32\images\toolbar\export.gif
c:\windows\system32\images\toolbar\export_over.gif
c:\windows\system32\images\toolbar\exportd.gif
c:\windows\system32\images\toolbar\First.gif
c:\windows\system32\images\toolbar\first_over.gif
c:\windows\system32\images\toolbar\Firstd.gif
c:\windows\system32\images\toolbar\gotopage.gif
c:\windows\system32\images\toolbar\gotopage_over.gif
c:\windows\system32\images\toolbar\gotopaged.gif
c:\windows\system32\images\toolbar\grouptree.gif
c:\windows\system32\images\toolbar\grouptree_over.gif
c:\windows\system32\images\toolbar\grouptreed.gif
c:\windows\system32\images\toolbar\grouptreepressed.gif
c:\windows\system32\images\toolbar\Last.gif
c:\windows\system32\images\toolbar\last_over.gif
c:\windows\system32\images\toolbar\Lastd.gif
c:\windows\system32\images\toolbar\Next.gif
c:\windows\system32\images\toolbar\next_over.gif
c:\windows\system32\images\toolbar\Nextd.gif
c:\windows\system32\images\toolbar\Prev.gif
c:\windows\system32\images\toolbar\prev_over.gif
c:\windows\system32\images\toolbar\Prevd.gif
c:\windows\system32\images\toolbar\print.gif
c:\windows\system32\images\toolbar\print_over.gif
c:\windows\system32\images\toolbar\printd.gif
c:\windows\system32\images\toolbar\Refresh.gif
c:\windows\system32\images\toolbar\refresh_over.gif
c:\windows\system32\images\toolbar\refreshd.gif
c:\windows\system32\images\toolbar\Search.gif
c:\windows\system32\images\toolbar\search_over.gif
c:\windows\system32\images\toolbar\searchd.gif
c:\windows\system32\images\toolbar\up.gif
c:\windows\system32\images\toolbar\up_over.gif
c:\windows\system32\images\toolbar\upd.gif
c:\windows\system32\images\tree\begindots.gif
c:\windows\system32\images\tree\beginminus.gif
c:\windows\system32\images\tree\beginplus.gif
c:\windows\system32\images\tree\blank.gif
c:\windows\system32\images\tree\blankdots.gif
c:\windows\system32\images\tree\dots.gif
c:\windows\system32\images\tree\lastdots.gif
c:\windows\system32\images\tree\lastminus.gif
c:\windows\system32\images\tree\lastplus.gif
c:\windows\system32\images\tree\Magnify.gif
c:\windows\system32\images\tree\minus.gif
c:\windows\system32\images\tree\minusbox.gif
c:\windows\system32\images\tree\plus.gif
c:\windows\system32\images\tree\plusbox.gif
c:\windows\system32\images\tree\singleminus.gif
c:\windows\system32\images\tree\singleplus.gif
c:\windows\twain_16.dll
 
.
(((((((((((((((((((((((((   Files Created from 2009-08-16 to 2009-09-16  )))))))))))))))))))))))))))))))
.
 
2009-09-15 23:56 . 2009-09-15 23:56	--------	d-----w-	c:\program files\Trend Micro
2009-09-15 23:44 . 2009-09-15 23:44	--------	d-----w-	c:\documents and settings\scottd\Application Data\Malwarebytes
2009-09-15 23:44 . 2009-09-10 21:54	38224	----a-w-	c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-15 23:44 . 2009-09-15 23:44	--------	d-----w-	c:\program files\Malwarebytes' Anti-Malware
2009-09-15 23:44 . 2009-09-15 23:44	--------	d-----w-	c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-15 23:44 . 2009-09-10 21:53	19160	----a-w-	c:\windows\system32\drivers\mbam.sys
2009-09-15 23:42 . 2009-09-15 23:42	411368	----a-w-	c:\windows\system32\deploytk.dll
2009-09-15 14:21 . 2009-09-15 14:22	--------	d-----w-	C:\PublishedWebsites
2009-09-11 21:31 . 2009-09-11 21:31	--------	d-----w-	c:\windows\SigPlus
2009-09-11 21:31 . 2009-09-11 21:31	--------	d-----w-	C:\SigPlus
2009-09-10 03:08 . 2009-06-21 21:44	153088	------w-	c:\windows\system32\dllcache\triedit.dll
2009-09-08 22:07 . 2009-09-08 22:07	--------	d-----w-	c:\windows\system32\ViewPDF02.ocx
2009-09-08 22:07 . 2009-09-08 22:07	--------	d-----w-	c:\program files\WPViewPDF
2009-09-08 22:06 . 2009-09-08 22:06	--------	d-----w-	C:\wPDFViewer
2009-08-28 16:51 . 2009-08-28 16:51	--------	d-----w-	C:\08wtbase
2009-08-28 13:40 . 2009-08-28 13:40	--------	d-----w-	c:\documents and settings\scottd\Application Data\AVG8
2009-08-27 15:16 . 2009-09-14 23:10	--------	d-----w-	C:\09testdta
2009-08-21 17:49 . 2009-08-21 18:31	--------	d-----w-	c:\temp\cchdixieDATABASE
2009-08-21 17:48 . 2009-08-21 17:48	1275958	----a-w-	c:\temp\cchdb.zip
2009-08-21 15:51 . 2009-08-21 15:52	--------	d-----w-	C:\vanaccident082009
2009-08-19 22:20 . 2009-09-01 16:59	--------	d-----w-	C:\winfiduc09
2009-08-19 22:20 . 2009-09-10 19:56	--------	d-----w-	C:\winscorp09
2009-08-19 22:20 . 2009-09-10 01:46	--------	d-----w-	C:\wincorp09
2009-08-19 22:20 . 2009-09-14 18:43	--------	d-----w-	C:\winptnr09
 
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-16 15:42 . 2009-05-05 17:28	--------	d-----w-	c:\documents and settings\All Users\Application Data\Google Updater
2009-09-16 15:04 . 2007-08-27 22:21	--------	d-----w-	c:\program files\Mozilla Thunderbird
2009-09-15 23:41 . 2007-08-02 16:48	--------	d-----w-	c:\program files\Java
2009-09-11 13:45 . 2007-08-30 19:16	--------	d-----w-	c:\documents and settings\All Users\Application Data\FLEXnet
2009-09-10 10:10 . 2008-08-22 16:19	--------	d-----w-	c:\program files\Microsoft Silverlight
2009-09-10 10:01 . 2007-08-02 16:55	--------	d-----w-	c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-09 20:28 . 2009-03-19 00:33	--------	d-----w-	c:\documents and settings\All Users\Application Data\Embarcadero
2009-09-08 15:03 . 2007-08-02 16:59	87704	----a-w-	c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-04 16:55 . 2009-08-05 22:05	--------	d---a-w-	c:\documents and settings\All Users\Application Data\TEMP
2009-09-04 15:44 . 2007-08-23 22:06	--------	d-----w-	c:\program files\Gnostice
2009-08-10 15:19 . 2007-10-12 19:03	--------	d-----w-	c:\documents and settings\scottd\Application Data\Canon
2009-08-07 21:42 . 2007-08-23 23:14	--------	d-----w-	c:\program files\HiComponents
2009-08-05 09:01 . 2004-08-11 22:00	204800	----a-w-	c:\windows\system32\mswebdvd.dll
2009-07-29 17:31 . 2009-07-29 17:31	--------	d-----w-	c:\program files\ActiveDBSoft
2009-07-28 21:02 . 2008-07-21 15:54	--------	d-----w-	c:\program files\Common Files\Merge Modules
2009-07-28 17:04 . 2009-03-18 15:19	11952	----a-w-	c:\windows\system32\avgrsstx.dll
2009-07-28 17:04 . 2009-03-18 15:19	335240	----a-w-	c:\windows\system32\drivers\avgldx86.sys
2009-07-28 17:04 . 2007-08-28 20:37	27784	----a-w-	c:\windows\system32\drivers\avgmfx86.sys
2009-07-17 19:01 . 2004-08-11 22:00	58880	----a-w-	c:\windows\system32\atl.dll
2009-07-14 06:43 . 2004-08-11 22:00	286208	----a-w-	c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2004-08-11 22:00	827392	----a-w-	c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-11 22:00	78336	----a-w-	c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-11 22:00	17408	------w-	c:\windows\system32\corpol.dll
.
 
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tracks Eraser Pro"="c:\program files\Acesoft\Tracks Eraser Pro\te.exe" [2007-05-24 1327104]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-05 39408]
"GoToMeeting"="c:\program files\Citrix\GoToMeeting\366\g2mstart.exe" [2009-05-22 31552]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-15 149280]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-12 623992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-12 185896]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-12 2007832]
"AVGIDS"="c:\program files\AVG\AVG8\IdentityProtection\agent\bin\AVGIDSUI.exe" [2009-02-26 1579528]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-03-09 37888]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
 
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
 
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-8-29 113664]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-8-29 113664]
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-28 17:04	11952	----a-w-	c:\windows\system32\avgrsstx.dll
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\DBTools Software\\DBManagerPro\\DWGServer\\DWGServer.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
 
R0 AVGIDSErHr;AVGIDSErHr;c:\windows\system32\drivers\AVGIDSErHr.sys [2/26/2009 12:46 PM 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [3/18/2009 8:19 AM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/18/2009 8:19 AM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/18/2009 8:19 AM 108552]
R1 FSLX;FSLX;c:\windows\system32\drivers\fslx.sys [2/1/2008 4:50 PM 191616]
R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [3/17/2006 3:25 PM 65536]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [4/25/2009 9:14 AM 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/18/2009 8:18 AM 297752]
R2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [4/25/2009 9:14 AM 1370488]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSAgent.exe [2/26/2009 12:46 PM 5576712]
R2 AVGIDSWatcher;AVGIDSWatcher;c:\program files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSWatcher.exe [2/26/2009 12:46 PM 563720]
R2 BlackfishSQL;BlackfishSQL;c:\program files\CodeGear\RAD Studio\6.0\bin\BSQLServer.exe [1/14/2009 1:04 PM 65536]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [3/18/2009 8:18 AM 29208]
R3 AVGIDSDriver;AVGIDSDriver;c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_XP\AVGIDSDriver.sys [2/26/2009 12:46 PM 121352]
R3 AVGIDSFilter;AVGIDSFilter;c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_XP\AVGIDSFilter.sys [2/26/2009 12:46 PM 30216]
R3 AVGIDSShim;AVGIDSShim;c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_XP\AVGIDSShim.sys [2/26/2009 12:46 PM 27232]
R3 dfmirage;dfmirage;c:\windows\system32\drivers\dfmirage.sys [11/25/2005 6:43 PM 31896]
S2 gupdate1c9cda534d21190;Google Update Service (gupdate1c9cda534d21190);c:\program files\Google\Update\GoogleUpdate.exe [5/5/2009 10:16 AM 133104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [3/18/2009 8:18 AM 29208]
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12	REG_MULTI_SZ   	Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
 
2009-09-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 20:42]
 
2009-09-16 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-05 17:28]
 
2009-09-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-05 17:16]
 
2009-09-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-05 17:16]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.foxnews.com/
mStart Page = hxxp://www.foxnews.com/
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {099403A7-2334-4432-BDD0-F496AE3A86B5} - hxxps://secure.digsigtrust.com/ms/IdenTrustCertEnroll.cab
.
- - - - ORPHANS REMOVED - - - -
 
AddRemove-Adobe Photoshop 6.0 - c:\windows\ISUNINST.EXE -fc:\program files\Adobe\Photoshop 6.0\Uninst.isu
AddRemove-Adobe Photoshop 7.0 - c:\windows\ISUNINST.EXE -fc:\program files\Adobe\Photoshop 7.0\Uninst.isu
AddRemove-CBuilder5 - c:\windows\IsUninst.exe -fc:\program files\Borland\CBuilder5\Uninst.isu
AddRemove-Diff Doc_is1 - c:\program files\Softinterface
AddRemove-IDAutomation.com - c:\program files\IDAutomation.com
 
 
 
**************************************************************************
 
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-16 09:44
Windows 5.1.2600 Service Pack 3 NTFS
 
scanning hidden processes ...  
 
scanning hidden autostart entries ... 
 
scanning hidden files ...  
 
scan completed successfully
hidden files: 0
 
**************************************************************************
 
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.0\my.ini\" MySQL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
 
- - - - - - - > 'explorer.exe'(832)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Citrix\GoToMeeting\366\g2mcomm.exe
c:\program files\Citrix\GoToMeeting\366\g2mlauncher.exe
c:\program files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSMonitor.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
.
**************************************************************************
.
Completion time: 2009-09-16  9:55 - machine was rebooted
ComboFix-quarantined-files.txt  2009-09-16 16:55
 
Pre-Run: 8,829,276,160 bytes free
Post-Run: 8,772,386,816 bytes free
 
270	--- E O F ---	2009-09-10 10:04
                                              
1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
18:
19:
20:
21:
22:
23:
24:
25:
26:
27:
28:
29:
30:
31:
32:
33:
34:
35:
36:
37:
38:
39:
40:
41:
42:
43:
44:
45:
46:
47:
48:
49:
50:
51:
52:
53:
54:
55:
56:
57:
58:
59:
60:
61:
62:
63:
64:
65:
66:
67:
68:
69:
70:
71:
72:
73:
74:
75:
76:
77:
78:
79:
80:
81:
82:
83:
84:
85:
86:
87:
88:
89:
90:
91:
92:
93:
94:
95:
96:
97:
98:
99:
100:
101:
102:
103:
104:
105:
106:
107:
108:
109:
110:
111:
112:
113:
114:
115:
116:
117:
118:
119:
120:
121:
122:
123:
124:
125:
126:
127:
128:
129:
130:
131:
132:
133:
134:
135:
136:
137:
138:
139:
140:
141:
142:
143:
144:
145:
146:
147:
148:
149:
150:
151:
152:
153:
154:
155:
156:
157:
158:
159:
160:
161:
162:
163:
164:
165:
166:
167:
168:
169:
170:
171:
172:
173:
174:
175:
176:
177:
178:
179:
180:
181:
182:
183:
184:
185:
186:
187:
188:
189:
190:
191:
192:
193:
194:
195:
196:
197:
198:
199:
200:
201:
202:
203:
204:
205:
206:
207:
208:
209:
210:
211:
212:
213:
214:
215:
216:
217:
218:
219:
220:
221:
222:
223:
224:
225:
226:
227:
228:
229:
230:
231:
232:
233:
234:
235:
236:
237:
238:
239:
240:
241:
242:
243:
244:
245:
246:
247:
248:
249:
250:
251:
252:
253:
254:
255:
256:
257:
258:
259:
260:
261:
262:
263:
264:
265:
266:
267:
268:
269:
270:
271:
272:
273:
274:
275:
276:
277:
278:
279:
280:
281:
282:
283:
284:
285:
286:
287:
288:
289:
290:
291:
292:
293:
294:
295:
296:
297:
298:
299:
300:
301:
302:
303:
304:
305:

Select allOpen in new window

 

by: rxfosterPosted on 2009-09-16 at 12:07:35ID: 25348946

younghv - Excellent, looks like a darn fine program, I will add it to my toolbox... very much appreciated, sir.

b0lsc0tt - One item of interest... the "twain_16.dll" deletion by Combofix, that is from Adware.7000n - so that is one less thing to worry about as well.  You might confirm that everything under Supplementary scan is as you wish it to be.  Also, your home page ROCKS =)

Note: "Safe Mode" simply ensures that certain processes are not automatically initiated on boot.  It doesn't guarantee a fix, but it's certainly not rendered obsolete by some program.

Filemon just shows you what is running, and what it is doing on/to your system.  If you have never run it before, and are an IT professional in the Windows space, I recommend giving it a whirl as it is an invaluable tool in diagnosing everything from permissions issues to memory leaks.  And while it is fine to rely on "Virus experts" and programs to clean your machine, ultimately no one is going to be able to certify that you are 100% operational from a post.  You are going to have to dig in to do a health check and see that any residual issues are not still resident.

That being said, the log looks pretty clean!  


 

by: b0lsc0ttPosted on 2009-09-16 at 12:26:15ID: 25349146

rxfoster,

The machine is actually a coworker's.  I had to check to see what the HomePage was.  Glad you like it but not really something I would choose.  Nothing against the site or page though, just not what I want to have to load everytime I start my browser.

As far as FileMon I agree it is a great tool.  I have actually found it very useful for some of my work related projects.  Speaking of that I have to get back and as long as this can get cleaned without me spending tons of time on it (and my coworker off his machine) I will be VERY happy.  I really do hate virus infections because it seems the machine is often not the same after it.  If it weren't so much work to reformat, etc it would be what I would recommend everytime.  Luckily we do have great tools and there are great experts here so I know if it can be cleaned and "as good as new" they will get me there. :)

Thanks for the feedback on the log and your review.  I will keep this open for others to review and respond but appreciate your input and info.

bol

 

by: younghvPosted on 2009-09-16 at 17:35:33ID: 25351779

bol -
As you can probably guess, the following information is not from me. :)
Please review the information and post any questions you have.

Thanks,
Vic
******************************
There was an infostealer/keylogger in the system so it's a good idea to change passwords etc.

c:\windows\twain_16.dll <-- this file is not of Adware 7000n.com... it is actually an info-stealer so Bol might like to tell the user to change all passwords tht has been used on that pc (using another clean pc).
http://74.125.113.132/search?q=cache:8Xn23ADa98gJ:www.threatexpert.com/report.aspx%3Fmd5%3Dbbd0e2a92e3815641b8174fde2acecb6+twain_16.dll+threatexpert&cd=1&hl=en&ct=clnk&gl=au


 %system%\twain_16.dll <-- this one is the one belonging to 7000n.com, located in the system32 folder whereas the one in Bol's log is located in the Windows folder(the infostealer)
http://74.125.113.132/search?q=cache:xkWLGSZVrDoJ:www.symantec.com/security_response/writeup.jsp%3Fdocid%3D2005-041115-1322-99+twain_16.dll+symantec&cd=6&hl=en&ct=clnk&gl=au

 

The Combofix log looks all right.. the only suspicious entries are those unknown folders in the C:\ (examples below) but then the user might have created or know those folders. Bol can ask the user if they know those folders.
C:\vanaccident082009
C:\winfiduc09
C:\winscorp09
C:\winptnr09

 

by: younghvPosted on 2009-09-16 at 17:36:31ID: 25351803

Note to log in to a 'clean computer' before doing all of the account/password changes.

 

by: b0lsc0ttPosted on 2009-09-16 at 18:34:23ID: 25352139

Vic,

Thanks!  Is there any way to tell when that file started "logging" or was installed?  Would it only log TYPED passwords or what about those "saved" and entered by a program (i.e. an email client that checks email)?

Is the computer now a clean one or what else would need to be done?  I can change the passwords from another computer (or have him) but if it is clean now shouldn't that computer be OK to use too?

The folders are fine and created by the user.  One is probably a personal one (you can guess what it contains) and the others are work related.

Thanks again.

bol

 

by: rpggamergirlPosted on 2009-09-17 at 05:36:49ID: 25355297

bol,

Hard to know when that file started monitoring... though you may find when it was installed/created looking at the properties.

If the system is clean now then it should be okay to change password from that pc.
I would do an online scan also(kaspersky is good) to check if there are other nasties that are missed by MBAM, AVG and Combofix as sometimes some scanners may missed something.

Kaspersky won't remove if it finds any threats so a log needs to be saved if it finds threats.
http://www.kaspersky.com/virusscanner

Or even the Panda Activescan,
http://www.pandasecurity.com/activescan/index/




 

by: b0lsc0ttPosted on 2009-09-17 at 09:09:05ID: 25357757

Thanks!  Is there a way to find the properties AFTER the file was removed by ComboFix?  I believe it is gone now (from the ComboFix log) but I can verify that.  Would I be able to see the attributes looking at the file in ComboFix's backup?

I will run the online scan you recommended.  Thanks for everything!

bol

 

by: b0lsc0ttPosted on 2009-09-17 at 09:34:40ID: 25358070

Oh ... what about how the keylogger works?  Would it get just what was physically typed using a key on the keyboard or does it pickup everything?  E.g.  form filler in browser or third party program and "saved" passwords.  I understand this may be something hard to answer (because of the differences in those loggers) but thought it worth asking.

bol

 

by: rxfosterPosted on 2009-09-17 at 12:21:07ID: 25359887

younhv,

Man, good catch! (Or to whoever sent you that)

I will shut up now =/

 

by: rpggamergirlPosted on 2009-09-17 at 21:23:47ID: 25362925

Sorry my mistake.... original date when that file was created is now gone....

About that keylogger,  I'm sorry but I have no idea what its method of stealing infos whether it just logged keystrokes or some other methods as well.

Some advanced keyloggers can keep track of all programs that have been launched,  the clipboard, chat conversations, all visited websites, e-mails sent and received and can also take snapshots of the screen every few seconds. But I don't know if the info-stealer found in that system also has these functions or whether it's just a plain keystrokes logger.

 

by: b0lsc0ttPosted on 2009-09-17 at 21:27:18ID: 25362931

It does seem like there are some other infections or at least the online scan of Kaspersky found some.  I had to quit it because it was scanning some network drives too (and would've taken forever).  I decided to replace AVG with Kaspersky on that machine (or at least try it since AVG was going to expire soon).  I am having a problem installing Kaspersky though.  Don't know if it is related to the difficulty I had removing AVG, infections, or some conflict or other issue.  I am now doing the online Kaspersky scan (of just important areas) so I can have the log file.  I will see about getting Kaspersky (or something) installed tomorrow since it is too late for help with it now.  After all this time I am really liking my earlier idea of the clean format ...

bol

p.s.  If details of the Kaspersky install error will help someone help me with it then let me know.  I will even be glad to open a new question.

 

by: b0lsc0ttPosted on 2009-09-17 at 21:29:08ID: 25362935

Thanks for the response about that stuff.  I will let him know the program may have been around for awhile.  He was great and quick about responding to the first "virus" signs when he visited a site but I don't know if that was when the file was picked up or if the two are unrelated.  I will hope the first. :(

bol

 

by: anil_kumar137Posted on 2009-09-17 at 21:32:07ID: 25362941

If need to clean pc, try doing your way because the virus keeps coming back once infected...silly virus its like vadafone value "where ever you go i will follow you"

 

by: b0lsc0ttPosted on 2009-09-17 at 21:37:57ID: 25362956

anil_kumar137,

What do you mean "your way" when you mentioned cleaning the virus?  If you mean the clean format I am not at that point yet.  It takes DAYS to set that workers machine (and others like his).  Once they are going it is worth it but I'd rather not start that process if I don't have to and can get this going.

If you meant something else please explain.  Thanks!

bol

 

by: rpggamergirlPosted on 2009-09-17 at 21:42:11ID: 25362968

<<<" After all this time I am really liking my earlier idea of the clean format ...">>>

Yes, when info-stealers/keyloggers or virut are present in the system it's always wise to reformat regardless of whether an info has been stolen or not... for peace of mind.

If the user doesn't want to reformat there's also another tool that's supposed to detect the presence of any keylogger files, just to make sure. It's IceSword.


 

by: anil_kumar137Posted on 2009-09-17 at 21:44:00ID: 25362976

Hi, it was to other question wrong post sorry mate.

 

by: b0lsc0ttPosted on 2009-09-17 at 22:02:15ID: 25363013

rpg,
Do you have a link to IceSword?  Is it free like so many others or is there a cost?

I will pass on the recommendation to reformat.  We might decide that but the Kaspersky scan is almost done (the "Critical areas" scan) and so I may see what that says.  Just 1 found in that scan so far.

bol

 

by: anil_kumar137Posted on 2009-09-17 at 22:08:44ID: 25363036

Hi Bol, i think you have to go with clean installation itself as it will keep affecting the pc which is other problem and later have to do the same circus to remove it.

 

by: rpggamergirlPosted on 2009-09-17 at 22:20:25ID: 25363075

Here's the normal canned for IceSword when scanning for hidden/stealth files where the user is asked to post the logs for the Helper.

Please download and unzip Icesword to its own folder on your desktop


If you get a lot of "red entries" in an IceSword log, don't panic.

Step 1 : Close all windows and run IceSword. Click the Processes tab and watch for processes displayed in red color. A red colored process in this list indicates that it's hidden. Write down the PathName of any processes in red color. Then click on LOG at the top left. It will prompt you to save the log, call this Processes and save it to your desktop.

Step 2 : Click the Win32 Services tab and look out for red colored entries in the services list. Write down the Module name of any services in red color, you will need to expand out the Module tab to see the full name. Then click on LOG. It will prompt you to save the log, call this Services and save it to your desktop.

Step 3 : Click the Startup tab and look out for red colored entries in the startup list. Write down the Path of any startup entries in red color. Then click on LOG. It will prompt you to save the log, call this Startup and save it to your desktop.

Step 4 : Click the SSDT tab and check for red colored entries. If there are any, write down the KModule name.

Step 5 : Click the Message Hooks tab and check for any entries that are underneath Type and labelled WH_KEYBOARD. Write down the Process Path of these entries if present.


Logs can be collected under the headings :

Processes
Win32 Services
Startup
SSDT
Message Hooks




For keyloggers:
To check for the presence of keyloggers, ask the user to check Message Hooks and take note of the Process Path of any entries that are Type WH_KEYBOARD which is the main one to look for.

WH_MSGFILTER
WH_GETMESSAGE
WH_KEYBOARD_LL
WH_JOURNALRECORD

Legitimate programs can use WH_KEYBOARD so be careful what you delete.


 

by: rpggamergirlPosted on 2009-09-17 at 22:23:36ID: 25363079

Yes, IceSword if free.

 

by: b0lsc0ttPosted on 2009-09-17 at 22:40:09ID: 25363123

Thanks for that info.  I hope it will make more sense as I get started.  I may have to wait until tomorrow to do it (just getting too tired now but this is the perfect time to have access to that machine :)).

The result of the Critical Areas scan was just 1 file found.  It is the last file in the list below.  That is a copy/paste from the html log made by the scan (I will attach that file too).

The EchoVNC program is something we installed.  I haven't tried matching that DLL yet but it is a valid one for that program so I suspect that is OK.

The barcode file is also a false positive I would think but maybe I am wrong.  I will have to ask about it tomorrow but I believe, especially from the location, it was downloaded on purpose and part of the developing he does.

Not really many details about what was found in his Inbox but so I am not sure how what to think of that.  Is there any way to narrow it down?  Could it also be something harmless that appears bad?  The names make me wonder, especially since they say "HTML" if it is just some thing with some Javascript that isn't harmful or malicious.  What are your thoughts?

The attached file is the detailed report with a .txt extension added so I could attach it here.  Remove and view in your browser if you wish (honest I didn't mess with the code in it :)).

bol

C:\Documents and Settings\scottd\Application Data\Thunderbird\Profiles\ho5389g6.default\Mail\Local Folders\Inbox Suspicious: Trojan-Spy.HTML.Fraud.gen 57  
 
C:\Documents and Settings\scottd\Application Data\Thunderbird\Profiles\ho5389g6.default\Mail\Local Folders\Inbox Suspicious: Exploit.HTML.Iframe.FileDownload 2  
 
C:\Documents and Settings\scottd\Application Data\Thunderbird\Profiles\ho5389g6.default\Mail\Local Folders\Inbox Infected: Trojan-Spy.HTML.Paylap.bg 1  
 
C:\Documents and Settings\scottd\Application Data\Thunderbird\Profiles\ho5389g6.default\Mail\Local Folders\Inbox Infected: Trojan-Spy.HTML.Paylap.sx 1  
 
C:\Download\barcode.zip Infected: Backdoor.ASP.Ace.gc 1  
 
C:\Download\barcode.zip Infected: Backdoor.ASP.Ace.gq 1  
 
C:\Program Files\EchoVNC\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 1 
                                              
1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:

Select allOpen in new window

 

by: b0lsc0ttPosted on 2009-09-17 at 23:15:19ID: 25363233

Thanks for IceSword.  The instructions were perfect; I was just too tired to realize it until I got going.

Not red entries for Processes, Win32 Services, or Startup.  I do have logs if you want but didn't attach them.

The other 2 had red entries.  It is odd but I got no response from the program when I tried to click on Log to save them.  It seemed like you said that should work but maybe I misunderstood.

SSDT had one item that was listed about 15 times.  Each was in read.  The entry was \??\C:\Windows\system32\drivers\fslx.sys

The Message Hooks section had a number of entires as you said (with the WH_KEYBOARD).  Many seemed legit so I am not sure if you want me to still type them or if there is some other way to get the log.  Explorer (C:\Windows\explorer.exe) was list about 5 times.  One other file in that directory was ctfmon.exe with one entry.  One in the System32 subdirectory named ctfmon.exe.  The others were all in Program Files folders.  Some I didn't know what they were for sure but only a couple.  Of course I don't know if some are really replaced or just named so close that I am missing they are harmful (like that twain file from earlier which I believe has some legit "cousins" in that same folder).  Let me know if you want more details.

Thanks!

bol

 

by: rpggamergirlPosted on 2009-09-18 at 02:57:29ID: 25364270

C:\Windows\system32\drivers\fslx.sys<-- this file seems to be legit one belonging to Altiris SVS Client driver
ctfmon.exe <-- if located in the system32 folder it is legit... but if located in the
Windows folder then it's the info-stealer.

I think all those files that Kaspersky flagged as suspicious or infected are false positives, it happens.

Looks like things are okay then.

 

by: revolution2kk8Posted on 2009-09-18 at 05:44:53ID: 25365321

http://www.spywareterminator.com/download/download.aspx

try this guy its FREE!!! good private group..

this and malwarebytes always seems to work for me..


press F8 at start up and run windows in safe mode with networking to disable virus start up files and to be able to update virus database especially with malwarebytes

http://www.malwarebytes.org/mbam.php  it's only $24 but totally worth every pennie

good luck!!

 

by: SSharmaPosted on 2009-09-18 at 07:44:06ID: 25366482

Hi All,

Maybe i am little late on this, however if the problem is still not resolved you could try the following:
Filename: 9129837.exe is associated with Trojan/ Rootkit named differently by different Anti Virus vendors. For example:

Packed.Generic.234 [Symantec]
Backdoor.Win32.HareBot.ee [Kaspersky Lab]
Generic PWS.y!fr [McAfee]
Troj/FakeAV-VQ [Sophos]
TrojanSpy:Win32/Ursnif.gen!G [Microsoft]
Trojan-Spy.Win32.Ursnif [Ikarus]
Win-Trojan/Haiuy.59392 [AhnLab]

Registry Modifications
The following Registry Keys were created:
HKEY_USERS\.DEFAULT\Software\Microsoft\InetData
HKEY_CURRENT_USER\Software\Microsoft\InetData
The newly created Registry Values are:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
ttool = "%Windir%\9129837.exe"

so that 9129837.exe runs every time Windows starts
[HKEY_CURRENT_USER\Software\Microsoft\InetData]
k1 = 0xE6994594
k2 = 0x470F80CD
version = "10"

Other details
To mark the presence in the system, the following Mutex object was created:
___RHaiuy72Mjtex

The following ports were open in the system:
 1038 UDP 9129837.exe (%Windir%\9129837.exe)
1046 UDP 9129837.exe (%Windir%\9129837.exe)
1126 TCP 9129837.exe (%Windir%\9129837.exe)
1128 TCP 9129837.exe (%Windir%\9129837.exe)
1129 UDP 9129837.exe (%Windir%\9129837.exe)
1848 TCP 9129837.exe (%Windir%\9129837.exe)
12930 TCP 9129837.exe (%Windir%\9129837.exe)
23445 TCP 9129837.exe (%Windir%\9129837.exe)
30195 TCP 9129837.exe (%Windir%\9129837.exe)  

The following Internet Connections were established:
 Server Name      Server PortConnect as UserConnection Password
91.213.29.22        80                                    (null)                        (null)
91.213.29.2         20                                     (null)                        (null)

The following GET requests were made:
cgi-bin/ooo.cgi?user_id=3868804500&version_id=10&passphrase=fkjvhsdvlksdhvlsd&socks=30195&version=126&crc=00000000
cgi-bin/commm.cgi?user_id=3868804500&version_id=10&passphrase=fkjvhsdvlksdhvlsd&socks=30195&version=126&crc=00000000
cgi-bin/ooo.cgi?user_id=3868804500&version_id=10&passphrase=fkjvhsdvlksdhvlsd&socks=23445&version=126&crc=00000000
cgi-bin/commm.cgi?user_id=3868804500&version_id=10&passphrase=fkjvhsdvlksdhvlsd&socks=23445&version=126&crc=00000000
cgi-bin/commm.cgi?user_id=3868804500&version_id=10&passphrase=fkjvhsdvlksdhvlsd&socks=12930&version=126&crc=00000000
cgi-bin/ooo.cgi?user_id=3868804500&version_id=10&passphrase=fkjvhsdvlksdhvlsd&socks=12930&version=126&crc=00000000

I hope this information would help. For removal you could try:
http://www.sophos.com/security/analyses/viruses-and-spyware/trojdwnldrfsa.html

 

by: rxfosterPosted on 2009-09-18 at 09:33:20ID: 25367636

Vee_Mod - "Please do not ever recommend that MalwareBytes be run in "Safe Mode"."

The link to the MBAM forum that you posted states (from nosirrah, MBAM dev member):

"We instruct to use safemode when regular mode is not able to be reached OR a regular mode scan cant be completed for some other reason ."

So, while it is clear that MBAM is different from other vendor offerings that run the same in safe mode and normal mode, it appears that "do not ever recommend" might be a bit strong.

Now, that being said, according to the staff it should "nearly always" be run in normal mode (which was news to me, and I am glad I know that now - thanks to younghv)

 

by: b0lsc0ttPosted on 2009-09-30 at 10:46:57ID: 25461379

All,
Sorry for the delay.  It seems it has been one thing after another although luckily it wasn't too much more with that machine.

SSharma,
Thanks for the info.  It seems that malware/virus is no longer an issue.  I saw no trace of the files or registry entries listed in your post.  I appreciate the details though and nice to know it is gone.

Did the details come from some other page on the Internet or was that something you typed and compiled on your own?  If it was from other source then please let me know what it was.  I am still glad you posted it but it really needs to credit the source and may have been better as a URL since a lot of content was copied.  Of course that also may be your own content; the layout of it just makes me wonder and I also notice you are new here.

revolution2kk8,
Thanks for posting but did you read my posts?  I am already using MalwareBytes and have moved beyond it.  In fact it didn't find anything if I rememeber right.  Still a good recommendation if I wasn't already using it.  I am glad the Moderator pointed out the proper use of it though.  Luckily the computer was really functional so Safe Mode, as a last resort, was not needed for any of this.  Please make sure you read all the comments carefully before posting in the future.  The question and some of my comments referenced running MalwareBytes.

rpggamergirl,
Should I be worried I couldn't save the other log files?  They were actually in areas that would seem to be something worth review.  Thanks for the response on the files and IMO the entries in the 2 areas are OK but it does puzzle me that I couldn't save the log file for either.

Also, since it seemed I was at a point where ComboFix had served its purpose I went to uninstall it.  It seemed to start the process to uninstall but the virus program, AVG, popped up some messages related to the files I had originally removed (I believe one was the file with the numbers in the name).  After that it seemed the program wasn't removed.  I saw no sign that I was really infected but is the virus program seeing what ComboFix removed and so interfering when I try to have it uninstalled?  Is there a good way to uninstall ComboFix?  Is there a chance that process, either the uninstall or the virus program's interference, could mess with sound drivers on the machine?

The latter seems off topic but at some point the machine lost the ability to play sound.  Even to the point I couldn't click the Play button in the Sounds section of Control Panel when I had some Windows event selected.  I was about to do a repair install but luckily a restore fixed things.  Just wanted to provide this detail in case it could be related.

All,
** general info that you could skip **
As far as an update and current status the machine has been running well for a few days now.  I did have to manually fix a registry entry or two that had permissions messed up (no owner, guest account had "full access", and I couldn't access even with Admin rights).  It took a few steps but they seem good now.  In case it matters the one key I remeber, and was causing issues for removing and then reinstalling AVG, was HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows .  The error had to do with creating a registry key there but when I looked I didn't even have access for the reasons I just mentioned.  It is fixed now.  My fingers are still crossed that were the only things messed up in Windows by this.

For general info to maybe help others the Kaspersky install had an issue on that machine.  It was an error 1904 in module adialhk.dll ("failed to register" and "HRESULT -2147024891").  I was able to install the program by leaving out the Spy part of it.  Kaspersky tech support provided that suggestion and it worked great.  Unfortunately Kaspersky was just too "active" in it protection.  The machines I tested it on slowed noticeably for the users.  Too slow and I couldn't get settings in Kaspersky to make a difference (i.e. mark files/folders as "trusted" for certain or all Kaspersky tasks).  I had to go back to AVG on the machines, including the one infected.  While Kaspersky was installed on the machine that was infected it did remove a couple of things.  I believe I listed them above but they didn't seem that major (not like the key logger).
** END **

Hopefully that may be useful to someone.  I am interested if any have follow ups on what I posted.  I will keep this open for a few days at least to hopefully get a response about ComboFix removal and to see if there are any other responses.  Thanks for all the help.  Let me know if anything isn't clear or there is a question.

bol

 

by: rpggamergirlPosted on 2009-09-30 at 21:58:11ID: 25466067

<<<"Should I be worried I couldn't save the other log files?">>>

Which log you couldn't save?
Sorry, my canned states logs but should be data collected as only 3 logs can be collected namely:
1. Processes
2. Win32 Services
3. StartUp

The 2 other sections I asked SSDT and Message Hooks don't produce logs.

I run IceSword on my pc and I was able to save the above 3 logs.



<<<"It seemed to start the process to uninstall but the virus program, AVG, popped up some messages related to the files I had originally removed (I believe one was the file with the numbers in the name).">>>

You mean AVG gave you an alert whether to allow Combofix to remove the random numbered filename that has been deleted?
I would turn off AVG first, though I don't know why AVG would alert about any files in the Qoobox quarantine folder at any time except when AVG was running a scan?
The Combofix log you posted was the result of the second run and that random numbered filename was not listed among the files deleted by CF on that log, though CF could've deleted it in its first run. As I've said the CF log you posted was the result of the second run which only shows the recent deleted files and not the previous ones.
I always use CF uninstall switch when I uninstall Combofix --> ComboFix /u


<<<"either the uninstall or the virus program's interference, could mess with sound drivers on the machine?">>>

I don't think so, not that I know of ... the only times I've known a sound would be affected after cleanup was if some values in the registry was hijacked and the scanner/user deleted the bad file without reseting the registry, there was one thread here at EE.

For example in this key the "aux" value is hijacked if C:\Windows\System32\wdmaud.sys is deleted without fixing the registry then the sound driver may not work.
HKLM\software\microsoft\windows nt\currentversion\drivers32
"aux"="wdmaud.sys"


 

by: b0lsc0ttPosted on 2009-10-08 at 15:36:51ID: 25530941

rpg,
Thanks for clearing up the IceSword program.  Glad it worked for me as it should.

It was a day or two before so I may be leaving out a detail about the message.  It was an AVG one that appeared just as I was running the ComboFix /u command.  It mentioned that numbered file I mentioned above and another message/file or two.  I agreee it is odd since the ComboFix program didn't seem to remove it.  AVG did initially before running ComboFix.  The CF log I posted was actually the first run of that program but after the other "virus" was removed.

I won't worry about it now though.  I will leave CF on the computer.  It just isn't worth the risk of removing even though the sound issue was probably just a coincidence.  I spent enough time trying to fix it before having to use the Restore Point that it just isn't worth the time and CF is fine remaining installed for now.  The coworker won't be bothered by the desktop icon and will leave it alone unless they ask me.

Thanks to all!  I will close this now but really appreciated all those that helped, even in a small way.

bol

 

by: b0lsc0ttPosted on 2009-10-08 at 15:45:28ID: 31629221

Thanks for all the patience and information.  The machine has been working well for a while now and I learned some new stuff.  Best of all it seems no clean install will be needed. :)

 

by: rpggamergirlPosted on 2009-10-08 at 21:47:14ID: 25532373


<<<"The CF log I posted was actually the first run of that program but after the other "virus" was removed.">>>
hmm.. something is wrong somewhere because the log shows it was the result of the second run....maybe CF hang then continue to run? CF scan is numbered and that one had number 2.
Sorry couldn't help much there.

Yes, it's okay to leave Combofix installed as long as the next time it's run it needs to be updated, it has an expiry date where when run it only run on 'reduced functionality' mode.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...