GeekPolice
Would you like to react to this message? Create an account in a few clicks or log in to continue.

GeekPoliceLog in

 


descriptionUnknown malware left hijacked browser(s), can't access network storage unit EmptyUnknown malware left hijacked browser(s), can't access network storage unit

more_horiz
I picked up some awful worm or virus, finally seem to have eradicated it according to both McAfee and Microsoft OneCare, but my browsers/search engines are still hijacked, and also I can't reconnect to my Netgear SC101 network storage drives. I've gone through the 4 steps outlined on the introductory post (updated Java, run JavaRa, update Adobe Reader, Windows, etc.). I have run Hijack This and here is the log result. Can someone help me identify what to remove, and/or what other steps to follow? Thanks, you people are the salt of the Earth.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:31:42 PM, on 6/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\idt\ecsxpv_5902_012208\wdm\STacSV.exe
C:\WINDOWS\SYSTEM32\astsrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NETGEAR\NETGEAR Storage Central Manager Utility\Z-SANService.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Registry Defense\RDAgent.exe
C:\Program Files\Registry Defense\RDListener.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Auslogics\Auslogics BoostSpeed\boostspeed.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Theodore Rigley\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iolo\System Mechanic\SMTrayNotify.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Theodore Rigley\Desktop\hijackgpthis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Seagate Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [RDAgent] C:\Program Files\Registry Defense\RDAgent.exe
O4 - HKLM\..\Run: [RDListener] C:\Program Files\Registry Defense\RDListener.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Auslogics BoostSpeed 4] C:\Program Files\Auslogics\Auslogics BoostSpeed\boostspeed.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Theodore Rigley\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /S
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
O4 - Global Startup: NCProTray.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.ameritrade.com
O15 - Trusted Zone: http://*.mcafee.com
O15 - Trusted Zone: *.tdameritrade.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215757737796
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215757863203
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://unmcnotes05.unmc.edu/dwa7W.cab
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.149,85.255.112.214
O17 - HKLM\System\CS5\Services\Tcpip\Parameters: NameServer = 85.255.112.149,85.255.112.214
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.149,85.255.112.214
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\WINDOWS\SYSTEM32\astsrv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9aff480f9b7e0) (gupdate1c9aff480f9b7e0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Seagate Scheduler2 Service (SgtSch2Svc) - Seagate - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\program files\idt\ecsxpv_5902_012208\wdm\STacSV.exe
O23 - Service: Z-SAN Service (Z-SANService) - Zetera Corporation - C:\Program Files\NETGEAR\NETGEAR Storage Central Manager Utility\Z-SANService.exe

--
End of file - 11079 bytes

descriptionUnknown malware left hijacked browser(s), can't access network storage unit EmptyRe: Unknown malware left hijacked browser(s), can't access network storage unit

more_horiz

  • Open HijackThis.
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O15 - Trusted Zone: *.ameritrade.com
    O15 - Trusted Zone: http://*.mcafee.com
    O15 - Trusted Zone: *.tdameritrade.com
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.149,85.255.112.214
    O17 - HKLM\System\CS5\Services\Tcpip\Parameters: NameServer = 85.255.112.149,85.255.112.214
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.149,85.255.112.214



  • Press "Fix Checked"
  • Close Hijack This.




Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.

descriptionUnknown malware left hijacked browser(s), can't access network storage unit EmptyRe: Unknown malware left hijacked browser(s), can't access network storage unit

more_horiz
Thank you for the help. I didn't think to mention that I had Malwarebytes previously installed, before this worm/virus infection, after which it would no longer run, and it still won't. I did the first part of your instructions, no problem, but even after uninstalling and re-downloading and installing MB it won't run. Similarly, after my infection, I had trouble launching anti-virus software or visiting security-related websites. I await your instructions, thank you.

descriptionUnknown malware left hijacked browser(s), can't access network storage unit EmptyRe: Unknown malware left hijacked browser(s), can't access network storage unit

more_horiz
Hello.

  • Download combofix from here
    Link 1
    Link 2

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:

    Unknown malware left hijacked browser(s), can't access network storage unit CF_download_FF

    Unknown malware left hijacked browser(s), can't access network storage unit CF_download_rename

    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See HERE for how to disable your AV. (Windows one-care)
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.

    Unknown malware left hijacked browser(s), can't access network storage unit Rcauto10

  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes

    Unknown malware left hijacked browser(s), can't access network storage unit Whatne10

  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

descriptionUnknown malware left hijacked browser(s), can't access network storage unit EmptyRe: Unknown malware left hijacked browser(s), can't access network storage unit

more_horiz
I followed your instructions without any problems. Here is the Combo-fix result, posted in 2 sections because of its size:

ComboFix 09-06-11.06 - Theodore Rigley 06/12/2009 7:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1579 [GMT -5:00]
Running from: c:\documents and settings\Theodore Rigley\Desktop\Combo-Fix.exe
AV: Windows Live OneCare *On-access scanning disabled* (Updated) {427ADFC3-B354-4A51-BE34-A9D4218E45C4}
FW: Windows Live OneCare Firewall *disabled* {A3899D22-27E6-4A7E-AE4E-2C106646DAAB}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\INSTALL.LOG
c:\windows\system32\drivers\gxvxcjtxvkbgknsxrprqtklyxmpxfaqbrfuiu.sys
c:\windows\system32\gxvxccount
c:\windows\system32\gxvxclkntehimcwinicjlvsmwqchhariynxfu.dll
c:\windows\system32\gxvxcwkmxdorpiqewdpqvtkihbobomyirtftp.dll
c:\windows\system32\mfc45.dll
c:\windows\system32\prsgrc.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_gxvxcserv.sys


((((((((((((((((((((((((( Files Created from 2009-05-12 to 2009-06-12 )))))))))))))))))))))))))))))))
.

2009-06-12 03:46 . 2009-05-26 18:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-12 03:46 . 2009-06-12 03:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-12 03:46 . 2009-05-26 18:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-11 14:08 . 2009-06-11 14:08 -------- d-----w- c:\windows\ie8updates
2009-06-11 14:03 . 2009-06-11 14:03 -------- d-----w- c:\windows\system32\XPSViewer
2009-06-11 14:03 . 2009-06-11 14:03 -------- d-----w- c:\program files\MSBuild
2009-06-11 14:03 . 2009-06-11 14:03 -------- d-----w- c:\program files\Reference Assemblies
2009-06-11 14:03 . 2009-06-11 14:03 -------- d-----w- C:\dd449ab08d2bba73bae9c092597b
2009-06-11 14:03 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-06-11 14:03 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-06-11 14:03 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-06-11 14:03 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-06-11 14:03 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-06-11 14:03 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-06-11 14:03 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-06-11 14:02 . 2009-06-11 23:06 -------- d-----w- c:\windows\SxsCaPendDel
2009-06-11 12:39 . 2004-08-04 12:00 403 -c----w- c:\windows\system32\dllcache\npdrmv2.zip
2009-06-11 12:39 . 2004-08-04 12:00 22060 -c----w- c:\windows\system32\dllcache\npds.zip
2009-06-11 12:39 . 2008-04-13 17:27 79872 -c----w- c:\windows\system32\dllcache\msxml6r.dll
2009-06-11 12:39 . 2008-04-14 00:11 81920 ------w- c:\windows\system32\ieencode.dll
2009-06-11 12:38 . 2008-04-14 00:12 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2009-06-11 12:21 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-06-11 12:19 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-06-11 12:19 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-06-11 12:19 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-06-11 12:19 . 2008-05-01 14:33 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2009-06-11 12:19 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-06-11 12:18 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-06-11 12:18 . 2008-09-04 17:15 1106944 -c----w- c:\windows\system32\dllcache\msxml3.dll
2009-06-11 12:17 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-06-11 03:05 . 2009-06-11 03:05 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-06-11 02:55 . 2009-06-11 02:55 152576 ----a-w- c:\documents and settings\Theodore Rigley\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-10 06:13 . 2009-06-10 06:13 -------- d-----w- c:\documents and settings\Theodore Rigley\.SunDownloadManager
2009-06-10 01:40 . 2009-06-10 01:40 29352 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\OC\Channels\ch2\HTML\item_templ\common\fixes\HASFix058456.dll
2009-06-10 01:40 . 2009-06-10 01:40 23720 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\OC\Channels\ch2\HTML\item_templ\common\fixes\HelpAndSupport_TestContent.dll
2009-06-10 01:40 . 2009-06-10 01:40 23056 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\OC\Channels\ch2\HTML\item_templ\common\fixes\HASFix101001.dll
2009-06-10 01:40 . 2009-06-10 01:40 221208 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\OC\Channels\ch2\HTML\item_templ\common\fixes\HelpAndSupportCommon.dll
2009-06-10 01:40 . 2009-06-10 01:40 21160 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\OC\Channels\ch2\HTML\item_templ\common\fixes\HASFix056479.dll
2009-06-10 01:40 . 2009-06-10 01:40 110248 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\OC\Channels\ch2\HTML\item_templ\common\fixes\HelpAndSupportInterface.dll
2009-06-10 01:37 . 2009-06-10 01:37 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-06-10 01:26 . 2007-11-28 03:56 91328 ----a-w- c:\windows\system32\drivers\msfwdrv.sys
2009-06-10 01:26 . 2007-11-28 03:56 116416 ----a-w- c:\windows\system32\drivers\msfwhlpr.sys
2009-06-10 01:21 . 2009-06-11 20:28 -------- d-----w- c:\program files\Microsoft Windows OneCare Live
2009-06-10 00:52 . 2009-06-10 00:52 -------- d-----w- c:\program files\Registry Defense
2009-06-09 03:41 . 2009-06-09 03:41 0 ----a-w- c:\windows\nsreg.dat
2009-06-09 03:41 . 2009-06-09 03:41 -------- d-----w- c:\documents and settings\Theodore Rigley\Local Settings\Application Data\Mozilla
2009-06-09 01:04 . 2009-06-09 01:04 -------- d-sh--w- c:\documents and settings\Theodore Rigley\IECompatCache
2009-06-09 01:03 . 2009-06-09 01:03 -------- d-sh--w- c:\documents and settings\Theodore Rigley\PrivacIE
2009-06-09 01:01 . 2009-06-09 01:01 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-09 01:01 . 2009-06-09 01:01 -------- d-sh--w- c:\documents and settings\Theodore Rigley\IETldCache
2009-06-09 00:57 . 2009-06-09 00:59 -------- dc-h--w- c:\windows\ie8
2009-06-08 02:00 . 2009-05-29 20:40 940896 ----a-w- c:\windows\system32\Incinerator.dll
2009-06-08 02:00 . 2009-02-17 16:31 28672 ----a-w- c:\windows\system32\iolobtdfg.exe
2009-06-08 02:00 . 2009-02-17 16:26 8192 ----a-w- c:\windows\system32\smrgdf.exe
2009-06-08 02:00 . 2009-06-08 02:00 -------- d-----w- c:\program files\iolo
2009-06-08 01:34 . 2007-08-09 00:57 12800 ----a-w- c:\windows\system32\drivers\ZetSFD.sys
2009-06-08 01:34 . 2007-08-09 00:57 5120 ----a-w- c:\windows\system32\drivers\ZetMPD.sys
2009-06-08 01:34 . 2007-08-15 02:29 345984 ----a-w- c:\windows\system32\drivers\sfsz.sys
2009-06-08 01:34 . 2007-08-09 00:57 15488 ----a-w- c:\windows\system32\drivers\ZetBus.sys
2009-06-08 01:34 . 2007-08-09 00:55 163927 ----a-w- c:\windows\system32\ZSANCoInst.dll
2009-06-07 21:34 . 2008-05-15 21:15 53168 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2009-06-07 21:25 . 2009-06-07 21:25 -------- d-----w- C:\8d365af66c42be37fe26161b8369
2009-06-07 20:43 . 2009-06-07 23:39 -------- d-----w- c:\program files\Windows Live Safety Center
2009-06-07 18:11 . 2009-06-07 18:11 -------- d-----w- c:\program files\PlayAllDVD
2009-06-07 05:11 . 2009-05-21 16:33 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-07 05:10 . 2009-06-07 05:10 152576 ----a-w- c:\documents and settings\Theodore Rigley\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-04 21:03 . 2009-06-04 21:03 -------- d-----w- c:\documents and settings\Theodore Rigley\WINDOWS
2009-06-01 23:07 . 2009-06-01 23:07 -------- d-----w- c:\program files\Common Files\L&H
2009-06-01 01:33 . 2009-06-01 01:33 -------- d-----w- C:\_hcc_thumbs
2009-06-01 01:33 . 2009-06-01 01:33 -------- d-----w- C:\_db_backups
2009-06-01 01:19 . 2009-06-01 01:54 -------- d-----w- C:\ActiGraphics website
2009-05-21 18:53 . 2009-06-04 21:03 -------- d-----w- c:\windows\BBSTORE
2009-05-21 18:53 . 1996-08-26 07:12 345600 ----a-r- c:\windows\system\QTIM32.DLL
2009-05-21 18:52 . 2009-06-04 21:03 -------- d-----w- c:\program files\The Learning Company
2009-05-21 04:36 . 2009-05-31 18:03 -------- d-----w- C:\Garrison
2009-05-21 03:43 . 2009-05-23 06:28 -------- d-----w- C:\Fontenelle Hills
2009-05-17 02:14 . 2009-05-17 02:14 26044 ---ha-w- c:\windows\system32\mlfcache.dat
2009-05-17 01:10 . 2009-05-17 01:10 -------- d-----w- c:\windows\system32\IOSUBSYS

descriptionUnknown malware left hijacked browser(s), can't access network storage unit EmptyRe: Unknown malware left hijacked browser(s), can't access network storage unit

more_horiz
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-12 03:52 . 2008-08-18 02:59 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-12 03:52 . 2009-04-02 01:45 -------- d-----w- c:\documents and settings\Theodore Rigley\Application Data\OpenOffice.org2
2009-06-11 23:08 . 2008-07-12 19:12 25920 ----a-w- c:\documents and settings\Theodore Rigley\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-11 12:15 . 2008-11-13 03:50 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-06-11 12:15 . 2008-11-13 03:50 -------- d-----w- c:\program files\NOS
2009-06-11 02:59 . 2008-07-16 13:37 -------- d-----w- c:\program files\Java
2009-06-10 06:04 . 2009-03-06 01:10 -------- d-----w- c:\documents and settings\Theodore Rigley\Application Data\EndNote
2009-06-09 05:23 . 2008-07-11 13:54 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-06-08 02:00 . 2008-12-08 03:37 -------- d-----w- c:\documents and settings\All Users\Application Data\iolo
2009-06-08 01:34 . 2008-07-12 06:10 -------- d-----w- c:\program files\NETGEAR
2009-06-07 15:09 . 2009-01-11 20:56 -------- d-----w- c:\program files\Visual Similarity Duplicate Image Finder
2009-06-05 13:47 . 2008-07-12 02:06 -------- d-----w- c:\program files\Google
2009-06-04 03:52 . 2009-03-28 22:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-02 02:37 . 2009-04-01 00:46 -------- d-----w- c:\program files\Auslogics
2009-05-22 18:28 . 2008-07-10 04:50 -------- d-----w- c:\documents and settings\Theodore Rigley\Application Data\AdobeUM
2009-05-20 03:43 . 2009-04-22 03:16 -------- d-----w- c:\documents and settings\Theodore Rigley\Application Data\gtk-2.0
2009-05-17 15:54 . 2008-10-01 02:08 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-05-15 03:48 . 2008-07-12 04:12 -------- d-----w- c:\documents and settings\Theodore Rigley\Application Data\OfficeUpdate12
2009-05-15 00:30 . 2009-04-02 01:46 1 ----a-w- c:\documents and settings\Theodore Rigley\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-05-13 05:15 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
2009-04-22 03:12 . 2009-04-22 03:12 -------- d-----w- c:\documents and settings\Theodore Rigley\Application Data\Inkscape
2009-04-22 03:12 . 2009-04-22 03:10 -------- d-----w- c:\program files\Inkscape
2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-14 05:47 . 2008-11-08 21:59 -------- d-----w- c:\documents and settings\Theodore Rigley\Application Data\uTorrent
2009-04-14 03:10 . 2008-07-12 04:12 264704 ------w- c:\documents and settings\Theodore Rigley\Application Data\OfficeUpdate12\oudetect.dll
2009-04-13 13:21 . 2009-04-13 13:21 -------- d-----w- c:\program files\Total Training
2009-04-11 20:15 . 2009-04-11 20:12 1595740 ----a-w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters\Driver Detective\Downloads\USBDRVEN.EXE
2009-04-08 19:03 . 2009-04-02 23:43 34 ----a-w- c:\documents and settings\Theodore Rigley\jagex_runescape_preferences.dat
2009-03-19 03:08 . 2009-03-19 03:08 1503232 ----a-w- c:\windows\system32\FotoAlbum 6.Scr
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-28 152872]
"Auslogics BoostSpeed 4"="c:\program files\Auslogics\Auslogics BoostSpeed\boostspeed.exe" [2009-03-16 362096]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-28 39408]
"Google Update"="c:\documents and settings\Theodore Rigley\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-03 133104]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2009-06-03 2832280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"DiscWizardMonitor.exe"="c:\program files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2008-06-25 1325848]
"AcronisTimounterMonitor"="c:\program files\Seagate\DiscWizard\TimounterMonitor.exe" [2008-06-25 904768]
"Seagate Scheduler2 Service"="c:\program files\Common Files\Seagate\Schedule2\schedhlp.exe" [2008-06-25 136472]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2009-03-11 611712]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-03-25 442433]
"RDAgent"="c:\program files\Registry Defense\RDAgent.exe" [2009-05-22 211056]
"RDListener"="c:\program files\Registry Defense\RDListener.exe" [2009-05-22 105584]
"OneCareUI"="c:\program files\Microsoft Windows OneCare Live\winssnotify.exe" [2009-03-22 63864]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

c:\documents and settings\Theodore Rigley\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Image Transfer.lnk - c:\program files\Sony Corporation\Image Transfer\SonyTray.exe [2009-2-21 73728]
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2009-2-25 49220]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R0 ZetSFD;ZetSFD;c:\windows\system32\drivers\ZetSFD.sys [6/7/2009 8:34 PM 12800]
R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [6/7/2009 9:00 PM 600944]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [6/7/2009 9:00 PM 600944]
R2 OcHealthMon;Windows Live OneCare Health Monitor;c:\program files\Microsoft Windows OneCare Live\OcHealthMon.exe [3/22/2009 10:59 AM 24936]
R2 SFSZ;DataPlow SFS for Zetera Storage Devices;c:\windows\system32\drivers\sfsz.sys [6/7/2009 8:34 PM 345984]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files\Common Files\Seagate\Schedule2\schedul2.exe [6/24/2008 7:56 PM 431384]
R2 Z-SANService;Z-SAN Service;c:\program files\NETGEAR\NETGEAR Storage Central Manager Utility\Z-SANService.exe [6/7/2009 8:34 PM 376891]
R3 ZetBus;Zetera Virtual Bus;c:\windows\system32\drivers\ZetBus.sys [6/7/2009 8:34 PM 15488]
S2 gupdate1c9aff480f9b7e0;Google Update Service (gupdate1c9aff480f9b7e0);c:\program files\Google\Update\GoogleUpdate.exe [3/28/2009 5:28 PM 133104]
S3 ZetMPD;ZetMPD;c:\windows\system32\drivers\ZetMPD.sys [6/7/2009 8:34 PM 5120]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-12 c:\windows\Tasks\Clean System Memory.job
- c:\windows\system32\CleanMem.exe [2009-03-15 21:05]

2009-06-12 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-28 22:27]

2009-06-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-842925246-630328440-839522115-1003.job
- c:\documents and settings\Theodore Rigley\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-08 15:59]

2009-06-12 c:\windows\Tasks\User_Feed_Synchronization-{1BED86A9-71CC-4CA5-BE49-F96C2F286687}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 09:31]
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-12 07:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(908)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(964)
c:\windows\system32\relog_ap.dll
.
Completion time: 2009-06-12 7:35
ComboFix-quarantined-files.txt 2009-06-12 12:35

Pre-Run: 37,413,556,224 bytes free
Post-Run: 40,337,551,360 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=3 Default=3 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
247 --- E O F --- 2009-05-13 13:45

descriptionUnknown malware left hijacked browser(s), can't access network storage unit EmptyRe: Unknown malware left hijacked browser(s), can't access network storage unit

more_horiz
Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /u

Unknown malware left hijacked browser(s), can't access network storage unit CF_Cleanup

This will also reset your restore points.

How is the machine running now?

descriptionUnknown malware left hijacked browser(s), can't access network storage unit EmptyRe: Unknown malware left hijacked browser(s), can't access network storage unit

more_horiz
Hello Belahzur--

My browser has stopped redirecting to those crappy commercial sites, and MalwareBytes will now run. You have saved me!! Thank you, thank you. I made a donation to help keep you guys going. Thanks, Ted

descriptionUnknown malware left hijacked browser(s), can't access network storage unit EmptyRe: Unknown malware left hijacked browser(s), can't access network storage unit

more_horiz
My network storage unit is now accessible, and all other problems seem to be solved. Thanks very much

descriptionUnknown malware left hijacked browser(s), can't access network storage unit EmptyRe: Unknown malware left hijacked browser(s), can't access network storage unit

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum