WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionNuqel.E (I think?) EmptyNuqel.E (I think?)

more_horiz
Hello - newbie but you all look very helpful. This is my work laptop, but my IT could not get it working. I'd love to fix it with your help rather than have to ship it across the country to be rebuilt. I did try to clear this virus myself following steps I found on the Internet...I no longer get the pop-ups but my Internet is still wacky and my McAfee does not seem to be working.

Here is the info from HijackThis. Thank you - Steph

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:40:27 PM, on 5/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\System32\ibmsmbus.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IBM\Director\bin\twgipcsv.exe
C:\Program Files\IBM\Director\bin\twgipc.exe
C:\Program Files\IBM\Director\cimom\bin\wmicimserver.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\FedMenu.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\FLFMSPM\Desktop\Hijack(GP)This.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intrafl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intrafl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intrafl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: ::1 localhost
O1 - Hosts: 94.232.248.66 browser-security.microsoft.com
O1 - Hosts: 94.232.248.66 antivaresys.com
O1 - Hosts: 94.232.248.66 www.antivaresys.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BHO - {BAD4551D-9B24-42cb-9BCD-818CA2DA7B63} - C:\WINDOWS\system32\iehelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [system tool] C:\WINDOWS\sysguard.exe
O4 - HKLM\..\Policies\Explorer\Run: [1] cmd /c %APPSERVE%\logondir\polfixit-ad9a.bat
O4 - HKLM\..\Policies\Explorer\Run: [2] reg add HKLM\System\CurrentControlSet\Control\Lsa\Kerberos\Parameters /v MaxTokenSize /t REG_DWORD /d 64000 /f
O4 - HKLM\..\Policies\Explorer\Run: [3] reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v POLFixit /f
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: CleanUser.vbs
O4 - Global Startup: FEDMENU.LNK = ?
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O14 - IERESET.INF: START_PAGE_URL=http://intrafl
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: Yahoo! Euchre - http://origin.games.yahoo.net/games/clients/y/et3_x.cab
O16 - DPF: Yahoo! Literati - http://origin.games.yahoo.net/games/clients/y/tt5_x.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/48.11/uploader2.cab
O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) - http://centra/SiteRoots/main/Install/CentraDownloader.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://l.yimg.com/jh/games/web_games/sony/bewitched/main.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = federated.fds
O17 - HKLM\Software\..\Telephony: DomainName = federated.fds
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = federated.fds
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = federated.fds
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: SMBus Upgrade Service for Windows 2000 and above (ibmsmbus) - International Business Machines Corp. - C:\WINDOWS\System32\ibmsmbus.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Program Files\lotus\notes\ntmulti.exe
O23 - Service: IBM Director Support Program (TWGIPC) - IBM Corporation - C:\Program Files\IBM\Director\bin\twgipcsv.exe
O23 - Service: IBM Director Agent WMI CIM Server (wmicimserver) - Unknown owner - C:\Program Files\IBM\Director\cimom\bin\wmicimserver.exe

--
End of file - 7346 bytes

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
When I posted the file above I saw what appears to be "bad stuff" on lines O1 under Hosts...so I went to that folder under C\Windows\System32\Drivers\Etc and deleted those lines (opened in Notepad, deleted, rebooted). Internet is still redirecting, so I clearly didn't fix it. :-)

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
Well nevermind...i did delete those lines but they are back now...I won't do anything else until i get directions from your team.

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
Hello.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O1 - Hosts: ::1 localhost
    O1 - Hosts: 94.232.248.66 browser-security.microsoft.com
    O1 - Hosts: 94.232.248.66 antivaresys.com
    O1 - Hosts: 94.232.248.66 www.antivaresys.com
    O2 - BHO: BHO - {BAD4551D-9B24-42cb-9BCD-818CA2DA7B63} - C:\WINDOWS\system32\iehelper.dll
    O4 - HKCU\..\Run: [system tool] C:\WINDOWS\sysguard.exe
    O4 - HKLM\..\Policies\Explorer\Run: [1] cmd /c %APPSERVE%\logondir\polfixit-ad9a.bat
    O4 - HKLM\..\Policies\Explorer\Run: [2] reg add HKLM\System\CurrentControlSet\Control\Lsa\Kerberos\Parameters /v MaxTokenSize /t REG_DWORD /d 64000 /f
    O4 - HKLM\..\Policies\Explorer\Run: [3] reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v POLFixit /f
    O4 - Global Startup: CleanUser.vbs


  • Press "Fix Checked"
  • Close Hijack This.

Remove the Proxy setting in Internet Explorer and/or in FireFox.

    In Internet Explorer
  1. Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox
  1. Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection > Choose "No Proxy"
  2. Click the apply button and restart that computer in normal mode.


Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Nuqel.E (I think?) DXwU4
Nuqel.E (I think?) VvYDg

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
Hello Belahzur,

Thanks for helping me. I completed the HijackThis system scan - seemed to work fine.

I checked my proxy settings in both IE and FF, neither one of them had the proxy enabled, but I rebooted anyway.

I downloaded Malwarebytes no problem (via FF). When I click the .exe file I get the prompt asking if I want to run it. I click Run. Then nothing happens. I tried this twice. Any ideas?

Thanks again - Steph

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
Hello Again -

I kept trying to double click the Malwarebytes .exe file, and I did eventually get it to install (very slowly). However, when I try to run it from my desktop nothing happens.

Thanks - Steph

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to Combo-Fix as follows:

Nuqel.E (I think?) CF_download_FF

Nuqel.E (I think?) CF_download_rename

3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.
See HERE for how to disable your AV..

  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

Nuqel.E (I think?) 2wg6fte

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
Thanks Origin - ComboFix ran without issue, here is the log:

ComboFix 09-05-30.03 - FLFMSPM 05/30/2009 20:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.687 [GMT -4:00]
Running from: c:\documents and settings\FLFMSPM\Desktop\Combo-Fix.exe
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\drivers\fad.sys
c:\windows\system32\drivers\UACxfenxjaltiyemyd.sys
c:\windows\system32\iehelper.dll
c:\windows\system32\mdm.exe
c:\windows\system32\UACaabhnqjwvmiuufu.log
c:\windows\system32\UACeggxbhwgvkmpxmp.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACoexcikdluaybysy.dat
c:\windows\system32\UACtlrlnltufsgxctp.dll
c:\windows\system32\UACvxxptvkawdpccjc.dll
c:\windows\system32\UACwyqfmtvihitjhtj.log
c:\windows\system32\UACxdmlbnysmlkjivx.dll
c:\windows\system32\UACyfrwmiyobqotbnm.dll
c:\windows\system32\UACyverpgtoyapkuyn.log

----- BITS: Possible infected sites -----

hxxp://FD903XSSMS00:80
c:\windows\system32\proquota.exe . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-31 )))))))))))))))))))))))))))))))
.

2009-05-30 01:43 . 2009-05-26 17:20 40160 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-30 01:42 . 2009-05-30 01:42 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-30 01:42 . 2009-05-30 01:43 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-30 01:42 . 2009-05-26 17:19 19096 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-29 17:36 . 2009-05-29 17:36 -------- d-----w c:\program files\Citrix
2009-05-28 12:30 . 2009-04-21 14:37 1914000 ----a-w c:\temp\Install Flash Player 10 ActiveX.exe
2009-05-26 14:54 . 2009-05-12 20:08 266400 ----a-r c:\documents and settings\FLFMSPM\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll
2009-05-26 12:21 . 2009-05-26 12:21 -------- d-----w c:\windows\system32\Adobe
2009-05-26 12:09 . 2009-04-21 14:37 1878888 ----a-w c:\temp\Install Flash Player 10 Plugin.exe
2009-05-22 14:21 . 2009-05-22 14:34 -------- d-----w c:\windows\4 priorities dir
2009-05-21 01:44 . 2009-05-21 01:44 -------- d-----w c:\documents and settings\FLFMSPM\Application Data\McAfee
2009-05-21 01:44 . 2009-05-21 01:44 49152 ----a-r c:\documents and settings\FLFMSPM\Application Data\Microsoft\Installer\{FCC07EEA-FA18-4A21-9105-9666603C6885}\IconFCC07EEA1.exe
2009-05-21 01:44 . 2009-05-21 01:44 49152 ----a-r c:\documents and settings\FLFMSPM\Application Data\Microsoft\Installer\{FCC07EEA-FA18-4A21-9105-9666603C6885}\IconFCC07EEA.exe
2009-05-21 01:21 . 2009-05-21 01:21 186 ----a-w c:\documents and settings\FLFMSPM\Application Data\asd.bat
2009-05-02 05:38 . 2009-05-31 00:32 -------- d-----w C:\Quarantine

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-29 17:30 . 2009-03-24 11:35 88920 ----a-w c:\documents and settings\FLFMSPM\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-29 11:13 . 2009-03-25 23:51 -------- d-----w c:\documents and settings\FLFMSPM\Application Data\.purple
2009-05-22 14:21 . 2009-04-21 12:17 201728 ----a-w c:\windows\4 priorities.scr
2009-05-21 01:43 . 2009-04-20 16:36 -------- d-----w c:\program files\McAfee
2009-05-21 01:43 . 2009-04-20 16:36 -------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2009-05-19 18:10 . 2009-03-23 21:53 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-19 18:10 . 2009-05-19 18:10 -------- d-----w c:\program files\Cheetah
2009-05-18 18:49 . 2009-03-31 21:35 -------- d-----w c:\program files\CentraOne
2009-05-16 14:35 . 2009-03-24 15:10 1890 --sha-w c:\windows\system32\KGyGaAvL.sys
2009-04-28 13:32 . 2009-04-28 13:32 186496 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-24 03:38 . 2009-04-24 03:38 -------- d-----w c:\documents and settings\All Users\Application Data\PopCap
2009-04-23 00:24 . 2009-04-23 00:24 499392 ----a-w c:\windows\java\Packages\8CFFL7T7.ZIP
2009-04-22 23:36 . 2009-04-22 23:36 485146 ----a-w c:\windows\java\Packages\QQSD73P7.ZIP
2009-04-20 16:55 . 2009-04-20 16:55 -------- d-----w c:\program files\Common Files\McAfee
2009-04-20 16:45 . 2009-03-23 21:52 -------- d-----w c:\program files\CA
2009-04-20 16:36 . 2009-04-20 16:36 -------- d-----w c:\program files\Common Files\Cisco Systems
2009-04-09 12:12 . 2009-04-09 12:12 -------- d-----w c:\documents and settings\FLFMSPM\Application Data\IBMERS
2009-04-09 12:12 . 2009-04-09 12:12 -------- d-----w c:\documents and settings\All Users\Application Data\IBMERS
2009-04-06 17:35 . 2009-04-06 17:35 -------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-04-02 18:27 . 2009-03-24 11:13 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-02 13:42 . 2009-04-02 13:42 -------- d-----w c:\program files\Manhattan Associates
2009-03-27 03:52 . 2009-03-27 03:52 0 ----a-w c:\windows\nsreg.dat
2009-03-25 20:41 . 2009-03-23 21:46 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-23 22:12 . 2009-03-23 22:12 29696 ----a-w c:\windows\system32\drivers\smbushc.sys
2009-03-23 22:12 . 2009-03-23 22:12 11648 ----a-w c:\windows\system32\drivers\smbusdh.sys
2009-03-23 22:12 . 2009-03-23 22:12 10240 ----a-w c:\windows\system32\drivers\smbgen.sys
2009-03-23 22:05 . 2009-03-23 21:54 29696 ----a-w c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
2009-03-23 22:00 . 2009-03-23 22:00 2678 ----a-w c:\windows\java\Packages\Data\579RPRHZ.DAT
2009-03-23 22:00 . 2009-03-23 22:00 2678 ----a-w c:\windows\java\Packages\Data\PN53JNBH.DAT
2009-03-23 22:00 . 2009-03-23 22:00 2678 ----a-w c:\windows\java\Packages\Data\RVV5BF5R.DAT
2009-03-23 22:00 . 2009-03-23 22:00 2678 ----a-w c:\windows\java\Packages\Data\JD3DBX75.DAT
2009-03-23 22:00 . 2009-03-23 22:00 2678 ----a-w c:\windows\java\Packages\Data\NJBXNLNX.DAT
2009-03-23 21:44 . 2009-03-23 21:44 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-20 18:50 . 2009-03-20 18:50 3358720 ----a-w c:\windows\system32\GPhotos.scr
2009-03-06 14:44 . 2009-03-23 23:30 283648 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2009-03-23 23:30 826368 ----a-w c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-03-10 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-03-10 126976]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-02 106496]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2009-01-16 136512]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-01-28 111952]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2009-3-23 1425424]
FEDMENU.LNK - c:\windows\FedMenu.exe [2009-3-23 212992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=Wireless1.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=\\federated.fds\sysvol\federated.fds\scripts\computer\TimezoneSet.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\2\0]
"Script"=\\federated.fds\SysVol\federated.fds\Policies\{ZA000011-11Z1-4ZZ2-22Z2-0ZZCC010234}\ResetPassword2.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="1"
"UpdatesDisableNotify"="1"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 GENERICSMB;IBM - Generic SMB Device Controller;c:\windows\system32\drivers\smbgen.sys [3/23/2009 6:12 PM 10240]
R2 TWGIPC;IBM Director Support Program;c:\program files\IBM\Director\bin\twgipcsv.exe [2/1/2005 1:58 PM 53327]
R2 TWGSYSIN;TWGSYSIN;c:\windows\system32\drivers\twgsysin.sys [2/1/2005 1:58 PM 7476]
R2 wmicimserver;IBM Director Agent WMI CIM Server;c:\program files\IBM\Director\cimom\bin\wmicimserver.exe [2/3/2005 6:53 PM 401408]
R3 SMBusDH;IBM - SMB Hub Controller;c:\windows\system32\drivers\smbusdh.sys [3/23/2009 6:12 PM 11648]
R3 SMBusHC;SMBus Host Controller;c:\windows\system32\drivers\smbushc.sys [3/23/2009 6:12 PM 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

Notify-WgaLogon - (no file)
SafeBoot-procexp90.Sys


.
------- Supplementary Scan -------
.
uStart Page = hxxp://intrafl
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\program files\Microsoft Office\Office12\EXCEL.EXE/3000
Trusted Zone: eddiebauer.com\www
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: Yahoo! Euchre - hxxp://origin.games.yahoo.net/games/clients/y/et3_x.cab
DPF: Yahoo! Literati - hxxp://origin.games.yahoo.net/games/clients/y/tt5_x.cab
DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} - hxxp://centra/SiteRoots/main/Install/CentraDownloader.cab
DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} - hxxp://l.yimg.com/jh/games/web_games/sony/bewitched/main.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://l.yimg.com/jh/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
FF - ProfilePath - c:\documents and settings\FLFMSPM\Application Data\Mozilla\Firefox\Profiles\uj4a5myj.default\
FF - prefs.js: browser.startup.homepage - hxxp://intrafl/
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-30 20:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\windows\system32\ibmsmbus.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\vstskmgr.exe
c:\program files\Lotus\Notes\ntmulti.exe
c:\windows\system32\snmp.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\IBM\Director\bin\twgipc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\CCM\clicomp\RemCtrl\Wuser32.exe
c:\windows\system32\CCM\CcmExec.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\msiexec.exe
c:\program files\IBM\Director\cimom\bin\PegasusProviderAdapter.exe
c:\program files\IBM\Director\cimom\bin\umssmart.exe
c:\program files\McAfee\Common Framework\McTray.exe
.
**************************************************************************
.
Completion time: 2009-05-31 20:47 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-31 00:47

Pre-Run: 25,719,291,904 bytes free
Post-Run: 25,989,611,520 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

198

Thanks again.

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
Hello.
One of your system files is infected, do you have your XP disc?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Nuqel.E (I think?) DXwU4
Nuqel.E (I think?) VvYDg

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
Hi Belahzur -

I do not since it's a corporate laptop...I can take it into my IT department at work at some point to be completely rebuilt. Is that my best option at this point?

Thanks - Steph

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2


  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    Code:


    :filefind
    proquota.exe


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Nuqel.E (I think?) DXwU4
Nuqel.E (I think?) VvYDg

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
Hi Belahzur,

Great thanks, here are the results:

SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 21:02 on 30/05/2009 by FLFMSPM (Limited User)

========== filefind ==========

Searching for "proquota.exe"
No files found.

-=End Of File=-

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
Darn.
I fear that you may need to get yourself the XP disc that this OS came from, or format completely. A system file is modified and we don't have anything to replace it.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Nuqel.E (I think?) DXwU4
Nuqel.E (I think?) VvYDg

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
Thanks Belahzur -

I will have it rebuilt - I appreciate your help.

- Steph

descriptionNuqel.E (I think?) EmptyRe: Nuqel.E (I think?)

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum