Author Topic: Win32-Trojan-gen {Other}  (Read 5344 times)

0 Members and 1 Guest are viewing this topic.

Offline theroadmanager

  • Newbie
  • *
  • Posts: 10
Win32-Trojan-gen {Other}
« on: May 05, 2008, 12:01:56 AM »
Hey,

For the last couple of days my Avast On-Access keeps popping up a warning that says: Sign of "Win32-Trojan-gen{Other} has been found in "C:\Windows\System32\SoftwareDistribution32\Setup\ctfmon.exe" file.  This happens about every 30 mins or so.  I have done some searching and see that this is a legit file from Microsoft.  Ctfmon.exe activates the Alternative User Input Text Input Processor (TIP) and the Microsoft Office Language Bar.  I have scanned my computer with Avast, Spybot, Ewido, Adaware and can't seem to find any type of virus or Trojan on my computer.  I have downloaded Hijack This as it seems that is the first question asked here is to post the log of what it finds. Any help would be greatly appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:54:57 PM, on 5/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SoftwareDistribution32\mmc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Internet Content Filter\SafeEyes.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\CMS Products\BounceBack Express\BBLauncher.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Brian Persall\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\FDCatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\ACT for Windows\Act8.exe" -preload
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [ICF] "C:\Program Files\Internet Content Filter\SafeEyes.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [FIREBOX] C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX Control.exe
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: BounceBack Launcher.lnk = ?
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: FreshDownload - {D6226514-AE1F-495A-8EEF-65B021C380FE} - C:\Program Files\FreshDevices\FreshDownload\fd.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1196920725302
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O20 - Winlogon Notify: winrmj32 - C:\WINDOWS\SYSTEM32\winrmj32.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NeatReceipts Database Controller - Digital Business Processes - C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 8573 bytes

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Win32-Trojan-gen {Other}
« Reply #1 on: May 05, 2008, 02:07:05 AM »
Hi, theroadmanager.  Welcome to LandzDown Forum.

You've done your homework.  Although you are correct about ctfmon.exe, the "C:\Windows\System32\SoftwareDistribution32\Setup\ctfmon.exe" you refer to does not appear legitimate. 

First, please install HijackThis in a permanent folder; i.e., C:\Program Files\HijackThis, so that any backups won't be removed when temp files are cleaned.

Please follow these instructions carefully: 

Download Combofix from any of the links below, and save it to your desktop.  For information regarding this download, please visit this webpage: http://www.bleepingcomputer.com/combofix/how-to-use-combofix

            Link 1
            Link 2
            Link 3


**Note:  It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.  (This includes Avast, WinPatrol and SpyBotSD Teatimer.)

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
    When finished, it will produce a report for you. 
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log (from its new location in a permanent folder) for further review.
Note: Do not mouse click the combofix window while it is running. That may cause it to stall.  ONLY run ComboFix one time.

,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline theroadmanager

  • Newbie
  • *
  • Posts: 10
Re: Win32-Trojan-gen {Other}
« Reply #2 on: May 06, 2008, 01:40:32 PM »
Corrine,

Thanks for the help.  I followed your instructions.  Here is my Combofix and HijackThis logs.  The scary part was after combofix ran, the big blue screen appeared and the only option was to shut off the computer and reboot it.  I did and everything seems to be working fine.  Haven't seem my alert from avast so maybe we got rid of it??

Thanks again

Brian

COMBOFIX:

ComboFix 08-05-01.3 - Brian Persall 2008-05-05 21:50:43.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.504 [GMT -5:00]
Running from: C:\Documents and Settings\Brian Persall\Desktop\ComboFix.exe
.

(((((((((((((((((((((((((   Files Created from 2008-04-06 to 2008-05-06  )))))))))))))))))))))))))))))))
.

2008-05-05 16:46 . 2008-05-05 19:47   <DIR>   d--------   C:\WINDOWS\BounceBack
2008-05-05 16:22 . 2007-08-31 12:39   10,240   --a------   C:\WINDOWS\system32\drivers\portd64.sys
2008-05-04 19:41 . 2008-05-04 20:30   13   --a------   C:\WINDOWS\system32\WinSys32.crc
2008-05-04 19:40 . 2004-11-22 20:56   913,560   --a------   C:\WINDOWS\system32\wodFtpDLX.ocx
2008-05-04 19:40 . 1999-03-22 12:29   233,472   --a------   C:\WINDOWS\system32\Ilda32.dll
2008-05-04 19:40 . 1998-06-17 04:00   18,944   --a------   C:\WINDOWS\system32\BORLNDMM.DLL
2008-05-04 17:29 . 2008-05-04 17:29   <DIR>   d--------   C:\!KillBox
2008-05-02 19:59 . 2008-05-02 19:59   <DIR>   d--------   C:\Kaspersky
2008-05-02 19:55 . 2008-05-02 19:55   <DIR>   d--------   C:\quarantine
2008-05-01 22:39 . 2008-05-01 22:39   <DIR>   d--------   C:\Program Files\Lavasoft
2008-05-01 22:39 . 2008-05-02 21:03   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-01 16:16 . 2008-05-01 16:14   102,664   --a------   C:\WINDOWS\system32\drivers\tmcomm.sys
2008-05-01 16:14 . 2008-05-01 16:35   <DIR>   d--------   C:\Documents and Settings\Brian Persall\.housecall6.6
2008-04-29 19:28 . 2008-04-29 19:46   <DIR>   d--------   C:\Documents and Settings\Brian Persall\k5nCal
2008-04-28 21:21 . 2008-04-28 21:21   <DIR>   d--------   C:\Documents and Settings\Brian Persall\Application Data\Uniblue
2008-04-27 19:21 . 2008-05-05 15:47   <DIR>   d--------   C:\Program Files\Spybot - Search & Destroy
2008-04-27 19:21 . 2008-05-05 15:43   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-27 15:53 . 2008-04-27 15:53   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\HotSync
2008-04-27 15:49 . 2008-04-27 15:49   <DIR>   d--------   C:\Documents and Settings\Brian Persall\Application Data\HotSync
2008-04-26 20:11 . 2008-05-04 18:13   <DIR>   d--------   C:\WINDOWS\system32\SoftwareDistribution32
2008-04-26 20:11 . 2008-04-26 20:11   26   --a------   C:\WINDOWS\ODBCNFG.INI
2008-04-22 09:50 . 2008-04-22 09:50   664   --a------   C:\WINDOWS\system32\d3d9caps.dat
2008-04-18 15:55 . 2008-04-18 15:55   552   --a------   C:\WINDOWS\system32\d3d8caps.dat
2008-04-14 18:24 . 2008-04-14 18:24   <DIR>   d--------   C:\Documents and Settings\Brian Persall\Application Data\Northwoods Software
2008-04-09 13:51 . 2008-04-27 15:53   41,602   --a------   C:\crash.dmp

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-06 02:28   ---------   d-----w   C:\Program Files\Mozilla Thunderbird
2008-05-06 00:39   1,682   ----a-w   C:\WINDOWS\system32\KGyGaAvL.sys
2008-05-05 21:22   ---------   d-----r   C:\Program Files\CMS Products
2008-05-05 20:46   90   ----a-w   C:\WINDOWS\Fonts\verdanaz._ttf
2008-05-05 20:25   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\Skype
2008-05-05 20:14   260   ----a-w   C:\WINDOWS\Fonts\webdings._ttf
2008-05-05 18:51   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\skypePM
2008-05-05 01:54   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\FileZilla
2008-05-05 01:26   ---------   d-----w   C:\Program Files\CoffeeCup Software
2008-05-03 12:55   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\U3
2008-04-30 20:26   ---------   d-----w   C:\Program Files\FileZilla FTP Client
2008-04-27 20:53   ---------   d-----w   C:\Program Files\Palm
2008-04-27 20:51   53,248   ----a-w   C:\WINDOWS\PalmDevC.dll
2008-04-27 20:51   16,694   ----a-w   C:\WINDOWS\system32\drivers\PalmUSBD.sys
2008-04-27 01:11   72,704   ----a-w   C:\WINDOWS\Fonts\mmc.exe
2008-04-27 01:11   2,147   ----a-w   C:\WINDOWS\Fonts\FontsInst.vbs
2008-04-04 03:57   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Sage Software SB, Inc
2008-04-03 00:06   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\Sprint
2008-04-03 00:01   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Sprint
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Sprint
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Sierra Wireless
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Common Files\Research in Motion
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Common Files\Motorola Shared
2008-04-02 04:29   24,320   ------w   C:\Documents and Settings\Brian Persall\Application Data\GDIPFONTCACHEV1.DAT
2008-03-27 23:49   ---------   d-----w   C:\Program Files\Common Files\Adobe
2008-03-19 09:47   1,845,248   ------w   C:\WINDOWS\system32\win32k.sys
2008-03-09 02:51   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\SuperNZB
2008-03-09 01:33   ---------   d-----w   C:\Program Files\Dealio
2008-03-09 01:33   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\Search Settings
2008-03-09 01:32   ---------   d-----w   C:\Program Files\Search Settings
2008-03-09 01:32   ---------   d-----w   C:\Program Files\Common Files\SWF Studio
2008-03-06 00:39   ---------   d-----w   C:\Program Files\Java
2008-03-05 23:10   61,440   ----a-r   C:\WINDOWS\system32\pxfhwmcp.dll
2008-03-05 23:10   138,016   ----a-r   C:\WINDOWS\system32\PCTIN50.dll
2008-03-05 20:36   32,408   ----a-w   C:\WINDOWS\system32\PCTINDIS5.sys
2008-03-01 13:06   826,368   ----a-w   C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51   282,624   ----a-w   C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32   45,568   ----a-w   C:\WINDOWS\system32\dnsrslvr.dll
2008-01-06 21:41   32   ----a-w   C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-18 18:17   31   -c----w   C:\Documents and Settings\Brian Persall\RUNME.bat
2007-12-07 03:28   56   --sh--r   C:\WINDOWS\system32\286691527A.sys
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 13:37 79224]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-07 03:02 77824]
"Act! Preloader"="C:\Program Files\ACT\ACT for Windows\Act8.exe" [2006-04-05 18:30 1015808]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-10-26 11:06 292152]
"ICF"="C:\Program Files\Internet Content Filter\SafeEyes.exe" [2007-06-05 11:17 1237504]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 12:19 819200]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 12:17 970752]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"FIREBOX"="C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX Control.exe" [2005-01-28 17:04 1003520]
"Sprint SmartView"="C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" [2008-03-10 09:09 17672]

C:\Documents and Settings\Brian Persall\Start Menu\Programs\Startup\
BounceBack Launcher.lnk - C:\Program Files\CMS Products\BounceBack Professional\BBStartup.exe [2008-05-05 16:22:28 40960]
PowerReg Scheduler.exe [2007-12-07 02:52:31 233472]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-03-27 18:49:40 113664]
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 22:16:46 24576]
HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2004-06-09 14:27:34 471040]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrmj32]
winrmj32.dll 2008-02-02 14:18 1535 C:\WINDOWS\system32\winrmj32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= xgusb.cpl
"midi5"= xgusb.cpl
"midi8"= xgusb.cpl

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\ACT\\ACT for Windows\\Act8.exe"=
"C:\\Program Files\\Palm\\HOTSYNC.EXE"=
"C:\\Program Files\\SecondLife\\SLVoice.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"C:\\Program Files\\FreshDevices\\FreshDownload\\fdgo.exe"=
"C:\\Program Files\\Internet Content Filter\\Pop3Proxy.exe"=
"C:\\Program Files\\Harman Pro\\System Architect 1.60\\SystemArchitect.exe"=
"C:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2078:TCP"= 2078:TCP:brianpersall.com
"2077:TCP"= 2077:TCP:brianpersall.com

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 13:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 13:35]
R2 BBWatcherService;BBWatcherService;"C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe" [2008-01-04 09:46]
R2 DComEx;COM+ System Executer;C:\WINDOWS\System32\SoftwareDistribution32\mmc.exe [2008-04-26 20:11]
R2 MSSQL$ACT7;MSSQL$ACT7;C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe [2003-05-31 19:02]
R2 NeatReceipts Database Controller;NeatReceipts Database Controller;"C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe" [2008-02-05 14:03]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 06:29]
R3 Nmea;Sprint Connection Manager - emulates the NMEA ports;C:\WINDOWS\system32\DRIVERS\pctnullport.sys [2008-03-05 15:41]
R3 NWADI;NWADI Bus Enumerator;C:\WINDOWS\system32\DRIVERS\NWADIenum.sys [2007-04-19 12:09]
R3 portio;CMS Openfile Service;C:\WINDOWS\system32\DRIVERS\portd64.sys [2007-08-31 12:39]
R3 swmsflt;swmsflt;C:\WINDOWS\system32\drivers\swmsflt.sys [2008-03-05 15:41]
S3 MSSQL$NR2007;SQL Server (NR2007);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sNR2007 []
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2007-11-15 19:40]
S3 ps_1394;ps_1394;C:\WINDOWS\system32\Drivers\ps_1394.sys [2004-10-14 16:33]
S3 ps_avs;ps_avs;C:\WINDOWS\system32\Drivers\ps_avs.sys [2004-10-14 16:33]
S3 SprintRcAppSvc;Sprint RcAppSvc;"C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe" /n "SprintRcAppSvc" []
S3 SQLAgent$ACT7;SQLAgent$ACT7;C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlagent.EXE [2002-12-17 17:23]
S3 usbvm328;HP Camera;C:\WINDOWS\system32\Drivers\usbvm326.sys [2006-10-12 19:42]
S3 vmfilter323;VC0326 filter service for Serome;C:\WINDOWS\system32\drivers\vmfilter323.sys [2006-08-10 23:00]

*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-05 21:52:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\ICF.dll
.
Completion time: 2008-05-05 21:53:22
ComboFix-quarantined-files.txt  2008-05-06 02:53:17

Pre-Run: 30,751,133,696 bytes free
Post-Run: 31,444,684,800 bytes free

168   --- E O F ---   2008-04-09 17:38:29

======================================================

HIJACKTHIS:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:02, on 2008-05-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe
C:\WINDOWS\System32\SoftwareDistribution32\mmc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Internet Content Filter\SafeEyes.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\CMS Products\BounceBack Professional\BBLauncher.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HijackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\FDCatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\ACT for Windows\Act8.exe" -preload
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [ICF] "C:\Program Files\Internet Content Filter\SafeEyes.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [FIREBOX] C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX Control.exe
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - Startup: BounceBack Launcher.lnk = ?
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: FreshDownload - {D6226514-AE1F-495A-8EEF-65B021C380FE} - C:\Program Files\FreshDevices\FreshDownload\fd.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1196920725302
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O20 - Winlogon Notify: winrmj32 - C:\WINDOWS\SYSTEM32\winrmj32.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BBWatcherService - CMS Products™, Inc. - C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NeatReceipts Database Controller - Digital Business Processes - C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe
O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 8246 bytes

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Win32-Trojan-gen {Other}
« Reply #3 on: May 07, 2008, 01:48:18 AM »
Hi, theroadmanager.  Let's try Combofix again, but this time, in addition to disabling WinPatrol and SpyBot Teatimer, please disable Avast's self-defense module:



1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.  (This includes Avast, WinPatrol and SpyBotSD Teatimer.)

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
    When finished, it will produce a report for you. 
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
Note: Do not mouse click the combofix window while it is running. That may cause it to stall.  ONLY run ComboFix one time.

,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline theroadmanager

  • Newbie
  • *
  • Posts: 10
Re: Win32-Trojan-gen {Other}
« Reply #4 on: May 09, 2008, 01:55:55 AM »
Hey Corrine,

Sorry for not getting back sooner.  I had to go out of town for a couple of days and just got back.  I had everything disabled in Avast as far as I could see, so after searching thru it again to see if there was something that I missed, I just uninstalled it to make sure it wasn't there.  I had stopped everything I could, but nothing was different than what I did last time.  Again, here is the Combofix and HijackThis files.  FYI, the last 2 days, I hadn't been getting my alert like I normally did.  Let me know how to proceed after this.  THanks for your help.  Much appreciated.

Brian

===========================================

COMBOFIX:

ComboFix 08-05-01.3 - Brian Persall 2008-05-08 19:42:18.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.587 [GMT -5:00]
Running from: C:\Documents and Settings\Brian Persall\Desktop\ComboFix.exe
.

(((((((((((((((((((((((((   Files Created from 2008-04-09 to 2008-05-09  )))))))))))))))))))))))))))))))
.

2008-05-08 19:31 . 2008-05-08 19:31   1,024   --ah-----   C:\WINDOWS\system32\config\systemprofile\NtUser.dat.LOG
2008-05-05 16:46 . 2008-05-05 21:55   <DIR>   d--------   C:\WINDOWS\BounceBack
2008-05-05 16:22 . 2007-08-31 12:39   10,240   --a------   C:\WINDOWS\system32\drivers\portd64.sys
2008-05-04 19:41 . 2008-05-04 20:30   13   --a------   C:\WINDOWS\system32\WinSys32.crc
2008-05-04 19:40 . 2004-11-22 20:56   913,560   --a------   C:\WINDOWS\system32\wodFtpDLX.ocx
2008-05-04 19:40 . 1999-03-22 12:29   233,472   --a------   C:\WINDOWS\system32\Ilda32.dll
2008-05-04 19:40 . 1998-06-17 04:00   18,944   --a------   C:\WINDOWS\system32\BORLNDMM.DLL
2008-05-04 17:29 . 2008-05-04 17:29   <DIR>   d--------   C:\!KillBox
2008-05-02 19:59 . 2008-05-02 19:59   <DIR>   d--------   C:\Kaspersky
2008-05-02 19:55 . 2008-05-02 19:55   <DIR>   d--------   C:\quarantine
2008-05-01 22:39 . 2008-05-01 22:39   <DIR>   d--------   C:\Program Files\Lavasoft
2008-05-01 22:39 . 2008-05-02 21:03   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-01 16:16 . 2008-05-01 16:14   102,664   --a------   C:\WINDOWS\system32\drivers\tmcomm.sys
2008-05-01 16:14 . 2008-05-01 16:35   <DIR>   d--------   C:\Documents and Settings\Brian Persall\.housecall6.6
2008-04-29 19:28 . 2008-04-29 19:46   <DIR>   d--------   C:\Documents and Settings\Brian Persall\k5nCal
2008-04-28 21:21 . 2008-04-28 21:21   <DIR>   d--------   C:\Documents and Settings\Brian Persall\Application Data\Uniblue
2008-04-27 19:21 . 2008-05-05 15:47   <DIR>   d--------   C:\Program Files\Spybot - Search & Destroy
2008-04-27 19:21 . 2008-05-05 15:43   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-27 15:53 . 2008-04-27 15:53   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\HotSync
2008-04-27 15:49 . 2008-04-27 15:49   <DIR>   d--------   C:\Documents and Settings\Brian Persall\Application Data\HotSync
2008-04-26 20:11 . 2008-05-04 18:13   <DIR>   d--------   C:\WINDOWS\system32\SoftwareDistribution32
2008-04-26 20:11 . 2008-04-26 20:11   26   --a------   C:\WINDOWS\ODBCNFG.INI
2008-04-22 09:50 . 2008-04-22 09:50   664   --a------   C:\WINDOWS\system32\d3d9caps.dat
2008-04-18 15:55 . 2008-04-18 15:55   552   --a------   C:\WINDOWS\system32\d3d8caps.dat
2008-04-14 18:24 . 2008-04-14 18:24   <DIR>   d--------   C:\Documents and Settings\Brian Persall\Application Data\Northwoods Software
2008-04-09 13:51 . 2008-04-27 15:53   41,602   --a------   C:\crash.dmp

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-09 00:34   1,734   ----a-w   C:\WINDOWS\system32\KGyGaAvL.sys
2008-05-08 23:43   ---------   d-----w   C:\Program Files\Mozilla Thunderbird
2008-05-05 21:22   ---------   d-----r   C:\Program Files\CMS Products
2008-05-05 20:46   90   ----a-w   C:\WINDOWS\Fonts\verdanaz._ttf
2008-05-05 20:25   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\Skype
2008-05-05 20:14   260   ----a-w   C:\WINDOWS\Fonts\webdings._ttf
2008-05-05 18:51   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\skypePM
2008-05-05 01:54   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\FileZilla
2008-05-05 01:26   ---------   d-----w   C:\Program Files\CoffeeCup Software
2008-05-03 12:55   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\U3
2008-04-30 20:26   ---------   d-----w   C:\Program Files\FileZilla FTP Client
2008-04-27 20:53   ---------   d-----w   C:\Program Files\Palm
2008-04-27 20:51   53,248   ----a-w   C:\WINDOWS\PalmDevC.dll
2008-04-27 20:51   16,694   ----a-w   C:\WINDOWS\system32\drivers\PalmUSBD.sys
2008-04-27 01:11   72,704   ----a-w   C:\WINDOWS\Fonts\mmc.exe
2008-04-27 01:11   2,147   ----a-w   C:\WINDOWS\Fonts\FontsInst.vbs
2008-04-04 03:57   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Sage Software SB, Inc
2008-04-03 00:06   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\Sprint
2008-04-03 00:01   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Sprint
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Sprint
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Sierra Wireless
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Common Files\Research in Motion
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Common Files\Motorola Shared
2008-04-02 04:29   24,320   ------w   C:\Documents and Settings\Brian Persall\Application Data\GDIPFONTCACHEV1.DAT
2008-03-27 23:49   ---------   d-----w   C:\Program Files\Common Files\Adobe
2008-03-19 09:47   1,845,248   ------w   C:\WINDOWS\system32\win32k.sys
2008-03-09 02:51   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\SuperNZB
2008-03-09 01:33   ---------   d-----w   C:\Program Files\Dealio
2008-03-09 01:33   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\Search Settings
2008-03-09 01:32   ---------   d-----w   C:\Program Files\Search Settings
2008-03-09 01:32   ---------   d-----w   C:\Program Files\Common Files\SWF Studio
2008-03-05 23:10   61,440   ----a-r   C:\WINDOWS\system32\pxfhwmcp.dll
2008-03-05 23:10   138,016   ----a-r   C:\WINDOWS\system32\PCTIN50.dll
2008-03-05 20:36   32,408   ----a-w   C:\WINDOWS\system32\PCTINDIS5.sys
2008-03-01 13:06   826,368   ----a-w   C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51   282,624   ----a-w   C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32   45,568   ----a-w   C:\WINDOWS\system32\dnsrslvr.dll
2008-01-06 21:41   32   ----a-w   C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-18 18:17   31   -c----w   C:\Documents and Settings\Brian Persall\RUNME.bat
2007-12-07 03:28   56   --sh--r   C:\WINDOWS\system32\286691527A.sys
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-07 03:02 77824]
"Act! Preloader"="C:\Program Files\ACT\ACT for Windows\Act8.exe" [2006-04-05 18:30 1015808]
"ICF"="C:\Program Files\Internet Content Filter\SafeEyes.exe" [2007-06-05 11:17 1237504]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 12:19 819200]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 12:17 970752]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"FIREBOX"="C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX Control.exe" [2005-01-28 17:04 1003520]
"Sprint SmartView"="C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" [2008-03-10 09:09 17672]

C:\Documents and Settings\Brian Persall\Start Menu\Programs\Startup\
BounceBack Launcher.lnk - C:\Program Files\CMS Products\BounceBack Professional\BBStartup.exe [2008-05-05 16:22:28 40960]
PowerReg Scheduler.exe [2007-12-07 02:52:31 233472]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-03-27 18:49:40 113664]
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 22:16:46 24576]
HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2004-06-09 14:27:34 471040]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrmj32]
winrmj32.dll 2008-02-02 14:18 1535 C:\WINDOWS\system32\winrmj32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= xgusb.cpl
"midi5"= xgusb.cpl
"midi8"= xgusb.cpl

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\ACT\\ACT for Windows\\Act8.exe"=
"C:\\Program Files\\Palm\\HOTSYNC.EXE"=
"C:\\Program Files\\SecondLife\\SLVoice.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"C:\\Program Files\\FreshDevices\\FreshDownload\\fdgo.exe"=
"C:\\Program Files\\Internet Content Filter\\Pop3Proxy.exe"=
"C:\\Program Files\\Harman Pro\\System Architect 1.60\\SystemArchitect.exe"=
"C:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2078:TCP"= 2078:TCP:brianpersall.com
"2077:TCP"= 2077:TCP:brianpersall.com

R2 BBWatcherService;BBWatcherService;"C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe" [2008-01-04 09:46]
R2 DComEx;COM+ System Executer;C:\WINDOWS\System32\SoftwareDistribution32\mmc.exe [2008-04-26 20:11]
R2 MSSQL$ACT7;MSSQL$ACT7;C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe [2003-05-31 19:02]
R2 NeatReceipts Database Controller;NeatReceipts Database Controller;"C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe" [2008-02-05 14:03]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 06:29]
R3 Nmea;Sprint Connection Manager - emulates the NMEA ports;C:\WINDOWS\system32\DRIVERS\pctnullport.sys [2008-03-05 15:41]
R3 NWADI;NWADI Bus Enumerator;C:\WINDOWS\system32\DRIVERS\NWADIenum.sys [2007-04-19 12:09]
R3 portio;CMS Openfile Service;C:\WINDOWS\system32\DRIVERS\portd64.sys [2007-08-31 12:39]
R3 swmsflt;swmsflt;C:\WINDOWS\system32\drivers\swmsflt.sys [2008-03-05 15:41]
S3 MSSQL$NR2007;SQL Server (NR2007);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sNR2007 []
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2007-11-15 19:40]
S3 ps_1394;ps_1394;C:\WINDOWS\system32\Drivers\ps_1394.sys [2004-10-14 16:33]
S3 ps_avs;ps_avs;C:\WINDOWS\system32\Drivers\ps_avs.sys [2004-10-14 16:33]
S3 SprintRcAppSvc;Sprint RcAppSvc;"C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe" /n "SprintRcAppSvc" []
S3 SQLAgent$ACT7;SQLAgent$ACT7;C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlagent.EXE [2002-12-17 17:23]
S3 usbvm328;HP Camera;C:\WINDOWS\system32\Drivers\usbvm326.sys [2006-10-12 19:42]
S3 vmfilter323;VC0326 filter service for Serome;C:\WINDOWS\system32\drivers\vmfilter323.sys [2006-08-10 23:00]

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-08 19:44:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\ICF.dll
.
Completion time: 2008-05-08 19:46:13
ComboFix-quarantined-files.txt  2008-05-09 00:45:44
ComboFix2.txt  2008-05-06 02:53:23

Pre-Run: 30,703,079,424 bytes free
Post-Run: 30,692,401,152 bytes free

164   --- E O F ---   2008-04-09 17:38:29


=======================================================

HIJACKTHIS:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:47:47 PM, on 5/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe
C:\WINDOWS\System32\SoftwareDistribution32\mmc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Internet Content Filter\SafeEyes.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\CMS Products\BounceBack Professional\BBLauncher.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\FDCatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\ACT for Windows\Act8.exe" -preload
O4 - HKLM\..\Run: [ICF] "C:\Program Files\Internet Content Filter\SafeEyes.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [FIREBOX] C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX Control.exe
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - Startup: BounceBack Launcher.lnk = ?
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: FreshDownload - {D6226514-AE1F-495A-8EEF-65B021C380FE} - C:\Program Files\FreshDevices\FreshDownload\fd.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1196920725302
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O20 - Winlogon Notify: winrmj32 - C:\WINDOWS\SYSTEM32\winrmj32.dll
O23 - Service: BBWatcherService - CMS Products™, Inc. - C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NeatReceipts Database Controller - Digital Business Processes - C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 7442 bytes

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Win32-Trojan-gen {Other}
« Reply #5 on: May 11, 2008, 08:48:23 PM »
Hi, theroadmanager.  Sorry for my delay also.  I've been tied up with weekend chores. 

There are very few search results for C:\WINDOWS\system32\SoftwareDistribution32.  Although mmc.exe is for Microsoft Management Console, I would not expect to find it in a directory in system32.   Just to be on the safe side, please go to: http://virusscan.jotti.org/

Upload the filepath shown below into the "File to upload & scan" box at the upper left:

C:\WINDOWS\System32\SoftwareDistribution32\mmc.exe

Let us know what Jotti has to say in your reply.

I would also like to see a Kaspersky scan.  Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online Scanner

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
        • Scan Mail Bases[/b]
    • Click OK & have it scan My Computer
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
    * Turn off the real time scanner of any existing antivirus program while performing the online scan *

    Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.

    =====================

    Open HijackThis and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here.

    =====================

    Logs Required
    Jotti results
    Kaspersky Scan Log
    Hijackthis Log


,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline theroadmanager

  • Newbie
  • *
  • Posts: 10
Re: Win32-Trojan-gen {Other}
« Reply #6 on: May 12, 2008, 12:14:16 AM »
Corrine,

Here are the results for the virusscan.jotti.org.  I will post the others you have requested as each scan is finished.  Thanks again for the help.  Looks like we might be getting somewhere.

Brian

VIRUSSCAN.JOTTI.ORG

 Scan taken on 11 May 2008 23:06:56 (GMT)
A-Squared - Found nothing
AntiVir - Found TR/Crypt.FKM.Gen
ArcaVir - Found nothing
Avast - Found nothing
AVG Antivirus - Found nothing
BitDefender - Found nothing
ClamAV - Found nothing
CPsecure - Found nothing
Dr.Web - Found nothing
F-Prot Antivirus - Found Possibly a new variant of W32/Threat-SysVenFak-based!Maximus
F-Secure Anti-Virus - Found Trojan-Downloader.Win32.Delf.crq
Fortinet - Found nothing
Ikarus - Found Suspect code-parts (probable variant)
Kaspersky Anti-Virus - Found Trojan-Downloader.Win32.Delf.crq
NOD32 - Found nothing
Norman Virus Control - Found nothing
Panda Antivirus - Found nothing
Sophos Antivirus - Found Mal/Packer
VirusBuster - Found nothing
VBA32 - Found Win32 Shadow Service Install (probable variant)

Offline theroadmanager

  • Newbie
  • *
  • Posts: 10
Re: Win32-Trojan-gen {Other}
« Reply #7 on: May 12, 2008, 06:53:52 PM »
Corrine,

Here is the Kaspersky Scan.

Brian


-------------------------------------------------------------------------------
 KASPERSKY ONLINE SCANNER REPORT
 Monday, May 12, 2008 1:53:50 AM
 Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
 Kaspersky Online Scanner version: 5.0.98.0
 Kaspersky Anti-Virus database last update: 12/05/2008
 Kaspersky Anti-Virus database records: 760853
-------------------------------------------------------------------------------

Scan Settings:
   Scan using the following antivirus database: extended
   Scan Archives: true
   Scan Mail Bases: true

Scan Target - My Computer:
   C:\
   D:\

Scan Statistics:
   Total number of scanned objects: 60921
   Number of viruses found: 2
   Number of infected objects: 2
   Number of suspicious objects: 12
   Duration of the scan process: 03:17:07

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Documents\ACT\ACT for Windows 8\Databases\ACT8Demo.ADF   Object is locked   skipped
C:\Documents and Settings\All Users\Documents\ACT\ACT for Windows 8\Databases\ACT8Demo.ALF   Object is locked   skipped
C:\Documents and Settings\Brian Persall\Application Data\Sprint\Sprint SmartView\diagnostics.txt   Object is locked   skipped
C:\Documents and Settings\Brian Persall\Application Data\Thunderbird\Profiles\7nja0ojb.default\Mail\Local Folders\Inbox/[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED/[From "Kerry Mann" <IradereferenceStevenson@starpulse.com>][Date Mon, 21 Apr 2008 20:17:23 +0600]/text/[From "Bank of America" <auto_notify.id1022061cert@bankofamerica.com>][Date Tue, 22 Apr 2008 03:31:37 +0100]/html   Suspicious: Trojan-Spy.HTML.Fraud.gen   skipped
C:\Documents and Settings\Brian Persall\Application Data\Thunderbird\Profiles\7nja0ojb.default\Mail\Local Folders\Inbox/[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED/[From "Kerry Mann" <IradereferenceStevenson@starpulse.com>][Date Mon, 21 Apr 2008 20:17:23 +0600]/text   Suspicious: Trojan-Spy.HTML.Fraud.gen   skipped
C:\Documents and Settings\Brian Persall\Application Data\Thunderbird\Profiles\7nja0ojb.default\Mail\Local Folders\Inbox/[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED   Suspicious: Trojan-Spy.HTML.Fraud.gen   skipped
C:\Documents and Settings\Brian Persall\Application Data\Thunderbird\Profiles\7nja0ojb.default\Mail\Local Folders\Inbox   MailBerkeleymboxx: suspicious - 3   skipped
C:\Documents and Settings\Brian Persall\Application Data\Thunderbird\Profiles\7nja0ojb.default\Mail\Local Folders\Junk/[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED/[From "Kerry Mann" <IradereferenceStevenson@starpulse.com>][Date Mon, 21 Apr 2008 20:17:23 +0600]/text/[From "Junko reybold" <Junko-bambukep@angkordreams.com>][Date Tue, 22 Apr 2008 13:58:06 +0200]/UNNAMED/[From "holt kit" <wdwkpo@adelphia.com>][Date Tue, 22 Apr 2008 11:06:51 +0000]/UNNAMED/[F ... /[From "Bank of America" <auto_notify.id1022061cert@bankofamerica.com>][Date Tue, 22 Apr 2008 03:31:37 +0100]/html   Suspicious: Trojan-Spy.HTML.Fraud.gen   skipped
C:\Documents and Settings\Brian Persall\Application Data\Thunderbird\Profiles\7nja0ojb.default\Mail\Local Folders\Junk/[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED/[From "Kerry Mann" <IradereferenceStevenson@starpulse.com>][Date Mon, 21 Apr 2008 20:17:23 +0600]/text/[From "Junko reybold" <Junko-bambukep@angkordreams.com>][Date Tue, 22 Apr 2008 13:58:06 +0200]/UNNAMED/[From "holt kit" <wdwkpo@adelphia.com>][Date Tue, 22 Apr 2008 11:06:51 +0000]/UNNAMED/[From "Callie Eastman" <Bobbi ... /[From "Donn" <drugstorea0travis@gmail.com>][Date Tue, 22 Apr 2008 04:45:05 -0400]/text   Suspicious: Trojan-Spy.HTML.Fraud.gen   skipped
C:\Documents and Settings\Brian Persall\Application Data\Thunderbird\Profiles\7nja0ojb.default\Mail\Local Folders\Junk/[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED/[From "Kerry Mann" <IradereferenceStevenson@starpulse.com>][Date Mon, 21 Apr 2008 20:17:23 +0600]/text/[From "Junko reybold" <Junko-bambukep@angkordreams.com>][Date Tue, 22 Apr 2008 13:58:06 +0200]/UNNAMED/[From "holt kit" <wdwkpo@adelphia.com>][Date Tue, 22 Apr 2008 11:06:51 +0000]/UNNAMED/[From "Callie Eastman" <BobbifibYoungblood@roughtype.com>][Date Tue, 22 Apr 2008 15:17:19 -0100]/text   Suspicious: Trojan-Spy.HTML.Fraud.gen   skipped
C:\Documents and Settings\Brian Persall\Application Data\Thunderbird\Profiles\7nja0ojb.default\Mail\Local Folders\Junk/[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED/[From "Kerry Mann" <IradereferenceStevenson@starpulse.com>][Date Mon, 21 Apr 2008 20:17:23 +0600]/text/[From "Junko reybold" <Junko-bambukep@angkordreams.com>][Date Tue, 22 Apr 2008 13:58:06 +0200]/UNNAMED/[From "holt kit" <wdwkpo@adelphia.com>][Date Tue, 22 Apr 2008 11:06:51 +0000]/UNNAMED   Suspicious: Trojan-Spy.HTML.Fraud.gen   skipped
C:\Documents and Settings\Brian Persall\Application Data\Thunderbird\Profiles\7nja0ojb.default\Mail\Local Folders\Junk/[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED/[From "Kerry Mann" <IradereferenceStevenson@starpulse.com>][Date Mon, 21 Apr 2008 20:17:23 +0600]/text/[From "Junko reybold" <Junko-bambukep@angkordreams.com>][Date Tue, 22 Apr 2008 13:58:06 +0200]/UNNAMED   Suspicious: Trojan-Spy.HTML.Fraud.gen   skipped
C:\Documents and Settings\Brian Persall\Application Data\Thunderbird\Profiles\7nja0ojb.default\Mail\Local Folders\Junk/[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED/[From "Kerry Mann" <IradereferenceStevenson@starpulse.com>][Date Mon, 21 Apr 2008 20:17:23 +0600]/text   Suspicious: Trojan-Spy.HTML.Fraud.gen   skipped
C:\Documents and Settings\Brian Persall\Application Data\Thunderbird\Profiles\7nja0ojb.default\Mail\Local Folders\Junk/[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED   Suspicious: Trojan-Spy.HTML.Fraud.gen   skipped
C:\Documents and Settings\Brian Persall\Application Data\Thunderbird\Profiles\7nja0ojb.default\Mail\Local Folders\Junk   MailBerkeleymboxx: suspicious - 7   skipped
C:\Documents and Settings\Brian Persall\Cookies\index.dat   Object is locked   skipped
C:\Documents and Settings\Brian Persall\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat   Object is locked   skipped
C:\Documents and Settings\Brian Persall\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG   Object is locked   skipped
C:\Documents and Settings\Brian Persall\Local Settings\History\History.IE5\index.dat   Object is locked   skipped
C:\Documents and Settings\Brian Persall\Local Settings\Temporary Internet Files\Content.IE5\index.dat   Object is locked   skipped
C:\Documents and Settings\Brian Persall\NTUSER.DAT   Object is locked   skipped
C:\Documents and Settings\Brian Persall\ntuser.dat.LOG   Object is locked   skipped
C:\Documents and Settings\LocalService\Cookies\index.dat   Object is locked   skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat   Object is locked   skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG   Object is locked   skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat   Object is locked   skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat   Object is locked   skipped
C:\Documents and Settings\LocalService\NTUSER.DAT   Object is locked   skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG   Object is locked   skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat   Object is locked   skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG   Object is locked   skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT   Object is locked   skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG   Object is locked   skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat   Object is locked   skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db   Object is locked   skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int   Object is locked   skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswAr.log   Object is locked   skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log   Object is locked   skipped
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Data\master.mdf   Object is locked   skipped
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Data\mastlog.ldf   Object is locked   skipped
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Data\model.mdf   Object is locked   skipped
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Data\modellog.ldf   Object is locked   skipped
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Data\tempdb.mdf   Object is locked   skipped
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Data\templog.ldf   Object is locked   skipped
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\LOG\ERRORLOG   Object is locked   skipped
C:\System Volume Information\MountPointManagerRemoteDatabase   Object is locked   skipped
C:\System Volume Information\_restore{71E280D8-E80D-419D-97D8-225C69010FBF}\RP4\change.log   Object is locked   skipped
C:\WINDOWS\Debug\PASSWD.LOG   Object is locked   skipped
C:\WINDOWS\Fonts\mmc.exe   Infected: Trojan-Downloader.Win32.Delf.crq   skipped
C:\WINDOWS\SchedLgU.Txt   Object is locked   skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log   Object is locked   skipped
C:\WINDOWS\Sti_Trace.log   Object is locked   skipped
C:\WINDOWS\system32\CatRoot2\edb.log   Object is locked   skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb   Object is locked   skipped
C:\WINDOWS\system32\config\Antivirus.Evt   Object is locked   skipped
C:\WINDOWS\system32\config\AppEvent.Evt   Object is locked   skipped
C:\WINDOWS\system32\config\default   Object is locked   skipped
C:\WINDOWS\system32\config\default.LOG   Object is locked   skipped
C:\WINDOWS\system32\config\Internet.evt   Object is locked   skipped
C:\WINDOWS\system32\config\NRAutoBK.evt   Object is locked   skipped
C:\WINDOWS\system32\config\SAM   Object is locked   skipped
C:\WINDOWS\system32\config\SAM.LOG   Object is locked   skipped
C:\WINDOWS\system32\config\SecEvent.Evt   Object is locked   skipped
C:\WINDOWS\system32\config\SECURITY   Object is locked   skipped
C:\WINDOWS\system32\config\SECURITY.LOG   Object is locked   skipped
C:\WINDOWS\system32\config\software   Object is locked   skipped
C:\WINDOWS\system32\config\software.LOG   Object is locked   skipped
C:\WINDOWS\system32\config\SysEvent.Evt   Object is locked   skipped
C:\WINDOWS\system32\config\system   Object is locked   skipped
C:\WINDOWS\system32\config\system.LOG   Object is locked   skipped
C:\WINDOWS\system32\h323log.txt   Object is locked   skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl   Object is locked   skipped
C:\WINDOWS\system32\SoftwareDistribution32\mmc.exe   Infected: Trojan-Downloader.Win32.Delf.crq   skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR   Object is locked   skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP   Object is locked   skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER   Object is locked   skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP   Object is locked   skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP   Object is locked   skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA   Object is locked   skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP   Object is locked   skipped
C:\WINDOWS\Temp\Perflib_Perfdata_6fc.dat   Object is locked   skipped
C:\WINDOWS\Temp\Perflib_Perfdata_7f0.dat   Object is locked   skipped
C:\WINDOWS\wiadebug.log   Object is locked   skipped
C:\WINDOWS\wiaservc.log   Object is locked   skipped
C:\WINDOWS\WindowsUpdate.log   Object is locked   skipped

Scan process completed.

Offline theroadmanager

  • Newbie
  • *
  • Posts: 10
Re: Win32-Trojan-gen {Other}
« Reply #8 on: May 12, 2008, 06:57:27 PM »
Corrine,

Here is the HIJACKTHIS Log.  Let me know what we need to do next.  It appears from the Kaspersky log that there are 2 infected files we need to get rid of.  Thanks again for your help,

Brian




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:55:18 PM, on 5/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe
C:\WINDOWS\System32\SoftwareDistribution32\mmc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\CMS Products\BounceBack Professional\BBLauncher.exe
C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe
C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\ABBYY PDF Transformer 2.0\PDF X-Change\pdfSaver\pdfSaver3a.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Content Filter\SafeEyes.exe
C:\Program Files\HijackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\FDCatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\ACT for Windows\Act8.exe" -preload
O4 - HKLM\..\Run: [ICF] "C:\Program Files\Internet Content Filter\SafeEyes.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [FIREBOX] C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX Control.exe
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - Startup: BounceBack Launcher.lnk = ?
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: FreshDownload - {D6226514-AE1F-495A-8EEF-65B021C380FE} - C:\Program Files\FreshDevices\FreshDownload\fd.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1196920725302
O17 - HKLM\System\CCS\Services\Tcpip\..\{2D022BE2-EA45-4E83-9263-53D951727416}: NameServer = 68.28.154.92 68.28.146.92
O17 - HKLM\System\CS1\Services\Tcpip\..\{2D022BE2-EA45-4E83-9263-53D951727416}: NameServer = 68.28.154.92 68.28.146.92
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O20 - Winlogon Notify: winrmj32 - C:\WINDOWS\SYSTEM32\winrmj32.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BBWatcherService - CMS Products™, Inc. - C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NeatReceipts Database Controller - Digital Business Processes - C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 8645 bytes

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Win32-Trojan-gen {Other}
« Reply #9 on: May 12, 2008, 11:46:03 PM »
Hi, Brian. 

Please start with your Thunderbird mail folder.  Empty the junk mail folder and then locate and delete the following from your inbox (do not open them).  I don't know if the from will show abbey ross or one of the other names in the list.  I bolded the last time/date shown in the KAV scan:

[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED/[From "Kerry Mann" <IradereferenceStevenson@starpulse.com>][Date Mon, 21 Apr 2008 20:17:23 +0600]/text/[From "Bank of America" <auto_notify.id1022061cert@bankofamerica.com>][Date Tue, 22 Apr 2008 03:31:37 +0100]/html   <------Trojan-Spy.HTML.Fraud.gen 

[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED/[From "Kerry Mann" <IradereferenceStevenson@starpulse.com>][Date Mon, 21 Apr 2008 20:17:23 +0600]/text   <------Trojan-Spy.HTML.Fraud.gen 

[From "abbey ross" <pomu@web.pt>][Date Mon, 21 Apr 2008 22:18:43 +0000]/UNNAMED   <------Trojan-Spy.HTML.Fraud.gen 
 MailBerkeleymboxx: suspicious - 3 

After that, let's have ComboFix do its work. 

Custom CFScript
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

Code: [Select]
Folder::
C:\WINDOWS\system32\SoftwareDistribution32

File::
C:\WINDOWS\ODBCNFG.INI
C:\crash.dmp
C:\WINDOWS\Fonts\verdanaz._ttf
C:\WINDOWS\Fonts\webdings._ttf
C:\WINDOWS\Fonts\mmc.exe
C:\WINDOWS\Fonts\FontsInst.vbs
C:\WINDOWS\system32\286691527A.sys
C:\WINDOWS\system32\winrmj32.dll

Driver::
C:\WINDOWS\system32\drivers\portd64.sys

  • Save this as CFScript.txt and place it on your desktop.
  • Close any open browsers
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


         


       
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
       
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply along with yet another fresh HijackThis log.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


Please let us know how the computer is working now.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline theroadmanager

  • Newbie
  • *
  • Posts: 10
Re: Win32-Trojan-gen {Other}
« Reply #10 on: May 13, 2008, 02:44:49 AM »
Corrine,

Here is the latest COMBOFIX log abd HIJACKTHIS.  Let me know if there is anything else we need to do.  Thanks for the help,

Brian


COMBOFIX:

ComboFix 08-05-01.3 - Brian Persall 2008-05-12 20:28:24.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.587 [GMT -5:00]
Running from: C:\Documents and Settings\Brian Persall\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Brian Persall\Desktop\CFScript.txt
 * Created a new restore point

FILE ::
C:\crash.dmp
C:\WINDOWS\Fonts\FontsInst.vbs
C:\WINDOWS\Fonts\mmc.exe
C:\WINDOWS\Fonts\verdanaz._ttf
C:\WINDOWS\Fonts\webdings._ttf
C:\WINDOWS\ODBCNFG.INI
C:\WINDOWS\system32\286691527A.sys
C:\WINDOWS\system32\winrmj32.dll
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\crash.dmp
C:\WINDOWS\Fonts\FontsInst.vbs
C:\WINDOWS\Fonts\mmc.exe
C:\WINDOWS\Fonts\verdanaz._ttf
C:\WINDOWS\Fonts\webdings._ttf
C:\WINDOWS\ODBCNFG.INI
C:\WINDOWS\system32\286691527A.sys
C:\WINDOWS\system32\SoftwareDistribution32
C:\WINDOWS\system32\SoftwareDistribution32\cour._ttf
C:\WINDOWS\system32\SoftwareDistribution32\mmc.exe
C:\WINDOWS\system32\winrmj32.dll

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_DComEx
-------\Service_DComEx


(((((((((((((((((((((((((   Files Created from 2008-04-13 to 2008-05-13  )))))))))))))))))))))))))))))))
.

2008-05-11 18:20 . 2008-05-11 18:20   <DIR>   d--------   C:\WINDOWS\system32\Kaspersky Lab
2008-05-11 18:20 . 2008-05-11 18:20   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-08 19:31 . 2008-05-12 20:19   1,024   --ah-----   C:\WINDOWS\system32\config\systemprofile\NtUser.dat.LOG
2008-05-05 16:46 . 2008-05-05 21:55   <DIR>   d--------   C:\WINDOWS\BounceBack
2008-05-05 16:22 . 2007-08-31 12:39   10,240   --a------   C:\WINDOWS\system32\drivers\portd64.sys
2008-05-04 19:41 . 2008-05-04 20:30   13   --a------   C:\WINDOWS\system32\WinSys32.crc
2008-05-04 19:40 . 2004-11-22 20:56   913,560   --a------   C:\WINDOWS\system32\wodFtpDLX.ocx
2008-05-04 19:40 . 1999-03-22 12:29   233,472   --a------   C:\WINDOWS\system32\Ilda32.dll
2008-05-04 19:40 . 1998-06-17 04:00   18,944   --a------   C:\WINDOWS\system32\BORLNDMM.DLL
2008-05-02 19:59 . 2008-05-02 19:59   <DIR>   d--------   C:\Kaspersky
2008-05-02 19:55 . 2008-05-02 19:55   <DIR>   d--------   C:\quarantine
2008-05-01 22:39 . 2008-05-01 22:39   <DIR>   d--------   C:\Program Files\Lavasoft
2008-05-01 22:39 . 2008-05-02 21:03   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-01 16:16 . 2008-05-01 16:14   102,664   --a------   C:\WINDOWS\system32\drivers\tmcomm.sys
2008-05-01 16:14 . 2008-05-01 16:35   <DIR>   d--------   C:\Documents and Settings\Brian Persall\.housecall6.6
2008-04-29 19:28 . 2008-04-29 19:46   <DIR>   d--------   C:\Documents and Settings\Brian Persall\k5nCal
2008-04-28 21:21 . 2008-04-28 21:21   <DIR>   d--------   C:\Documents and Settings\Brian Persall\Application Data\Uniblue
2008-04-27 19:21 . 2008-05-05 15:47   <DIR>   d--------   C:\Program Files\Spybot - Search & Destroy
2008-04-27 19:21 . 2008-05-05 15:43   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-27 15:53 . 2008-04-27 15:53   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\HotSync
2008-04-27 15:49 . 2008-04-27 15:49   <DIR>   d--------   C:\Documents and Settings\Brian Persall\Application Data\HotSync
2008-04-22 09:50 . 2008-04-22 09:50   664   --a------   C:\WINDOWS\system32\d3d9caps.dat
2008-04-18 15:55 . 2008-04-18 15:55   552   --a------   C:\WINDOWS\system32\d3d8caps.dat
2008-04-14 18:24 . 2008-04-14 18:24   <DIR>   d--------   C:\Documents and Settings\Brian Persall\Application Data\Northwoods Software

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-13 00:55   ---------   d-----w   C:\Program Files\Mozilla Thunderbird
2008-05-10 01:52   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\Skype
2008-05-09 21:05   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\skypePM
2008-05-05 21:22   ---------   d-----r   C:\Program Files\CMS Products
2008-05-05 01:54   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\FileZilla
2008-05-05 01:26   ---------   d-----w   C:\Program Files\CoffeeCup Software
2008-05-03 12:55   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\U3
2008-04-30 20:26   ---------   d-----w   C:\Program Files\FileZilla FTP Client
2008-04-27 20:53   ---------   d-----w   C:\Program Files\Palm
2008-04-27 20:51   53,248   ----a-w   C:\WINDOWS\PalmDevC.dll
2008-04-27 20:51   16,694   ----a-w   C:\WINDOWS\system32\drivers\PalmUSBD.sys
2008-04-04 03:57   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Sage Software SB, Inc
2008-04-03 00:06   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\Sprint
2008-04-03 00:01   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Sprint
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Sprint
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Sierra Wireless
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Common Files\Research in Motion
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Common Files\Motorola Shared
2008-04-02 04:29   24,320   ------w   C:\Documents and Settings\Brian Persall\Application Data\GDIPFONTCACHEV1.DAT
2008-03-27 23:49   ---------   d-----w   C:\Program Files\Common Files\Adobe
2008-01-06 21:41   32   ----a-w   C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-18 18:17   31   -c----w   C:\Documents and Settings\Brian Persall\RUNME.bat
.

(((((((((((((((((((((((((((((   snapshot@2008-05-08_19.45.38.29   )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-09 00:33:29   2,048   ----a-w   C:\WINDOWS\bootstat.dat
+ 2008-05-13 01:32:43   2,048   ----a-w   C:\WINDOWS\bootstat.dat
+ 2005-10-21 01:02:28   163,328   ----a-w   C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2005-05-24 17:27:16   213,048   ----a-w   C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20   94,208   ----a-w   C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54   950,272   ----a-w   C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-05-09 00:34:22   1,734   ----a-w   C:\WINDOWS\system32\KGyGaAvL.sys
+ 2008-05-13 01:33:50   1,734   ----a-w   C:\WINDOWS\system32\KGyGaAvL.sys
+ 2008-05-13 01:32:51   16,384   ----atw   C:\WINDOWS\Temp\Perflib_Perfdata_2a0.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-07 03:02 77824]
"Act! Preloader"="C:\Program Files\ACT\ACT for Windows\Act8.exe" [2006-04-05 18:30 1015808]
"ICF"="C:\Program Files\Internet Content Filter\SafeEyes.exe" [2007-06-05 11:17 1237504]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 12:19 819200]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 12:17 970752]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"FIREBOX"="C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX Control.exe" [2005-01-28 17:04 1003520]
"Sprint SmartView"="C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" [2008-03-10 09:09 17672]

C:\Documents and Settings\Brian Persall\Start Menu\Programs\Startup\
BounceBack Launcher.lnk - C:\Program Files\CMS Products\BounceBack Professional\BBStartup.exe [2008-05-05 16:22:28 40960]
PowerReg Scheduler.exe [2007-12-07 02:52:31 233472]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-03-27 18:49:40 113664]
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 22:16:46 24576]
HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2004-06-09 14:27:34 471040]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrmj32]
winrmj32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= xgusb.cpl
"midi5"= xgusb.cpl
"midi8"= xgusb.cpl

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\ACT\\ACT for Windows\\Act8.exe"=
"C:\\Program Files\\Palm\\HOTSYNC.EXE"=
"C:\\Program Files\\SecondLife\\SLVoice.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"C:\\Program Files\\FreshDevices\\FreshDownload\\fdgo.exe"=
"C:\\Program Files\\Internet Content Filter\\Pop3Proxy.exe"=
"C:\\Program Files\\Harman Pro\\System Architect 1.60\\SystemArchitect.exe"=
"C:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2078:TCP"= 2078:TCP:brianpersall.com
"2077:TCP"= 2077:TCP:brianpersall.com

R2 BBWatcherService;BBWatcherService;"C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe" [2008-01-04 09:46]
R2 MSSQL$ACT7;MSSQL$ACT7;C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe [2003-05-31 19:02]
R2 NeatReceipts Database Controller;NeatReceipts Database Controller;"C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe" [2008-02-05 14:03]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 06:29]
R3 Nmea;Sprint Connection Manager - emulates the NMEA ports;C:\WINDOWS\system32\DRIVERS\pctnullport.sys [2008-03-05 15:41]
R3 NWADI;NWADI Bus Enumerator;C:\WINDOWS\system32\DRIVERS\NWADIenum.sys [2007-04-19 12:09]
R3 portio;CMS Openfile Service;C:\WINDOWS\system32\DRIVERS\portd64.sys [2007-08-31 12:39]
R3 swmsflt;swmsflt;C:\WINDOWS\system32\drivers\swmsflt.sys [2008-03-05 15:41]
S3 MSSQL$NR2007;SQL Server (NR2007);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sNR2007 []
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2007-11-15 19:40]
S3 ps_1394;ps_1394;C:\WINDOWS\system32\Drivers\ps_1394.sys [2004-10-14 16:33]
S3 ps_avs;ps_avs;C:\WINDOWS\system32\Drivers\ps_avs.sys [2004-10-14 16:33]
S3 SprintRcAppSvc;Sprint RcAppSvc;"C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe" /n "SprintRcAppSvc" []
S3 SQLAgent$ACT7;SQLAgent$ACT7;C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlagent.EXE [2002-12-17 17:23]
S3 usbvm328;HP Camera;C:\WINDOWS\system32\Drivers\usbvm326.sys [2006-10-12 19:42]
S3 vmfilter323;VC0326 filter service for Serome;C:\WINDOWS\system32\drivers\vmfilter323.sys [2006-08-10 23:00]

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-12 20:33:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\ICF.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FireBox.exe
C:\Program Files\CMS Products\BounceBack Professional\BBLauncher.exe
.
**************************************************************************
.
Completion time: 2008-05-12 20:37:31 - machine was rebooted
ComboFix-quarantined-files.txt  2008-05-13 01:37:17
ComboFix2.txt  2008-05-09 00:46:14
ComboFix3.txt  2008-05-06 02:53:23

Pre-Run: 30,599,639,040 bytes free
Post-Run: 30,514,077,696 bytes free

198   --- E O F ---   2008-04-09 17:38:29



==========================================================

HIJACKTHIS:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:43:14 PM, on 5/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Internet Content Filter\SafeEyes.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\CMS Products\BounceBack Professional\BBLauncher.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe
C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\FDCatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\ACT for Windows\Act8.exe" -preload
O4 - HKLM\..\Run: [ICF] "C:\Program Files\Internet Content Filter\SafeEyes.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [FIREBOX] C:\Program Files\PreSonus\1394AudioDriver_FIREBox\FIREBOX Control.exe
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - Startup: BounceBack Launcher.lnk = ?
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: FreshDownload - {D6226514-AE1F-495A-8EEF-65B021C380FE} - C:\Program Files\FreshDevices\FreshDownload\fd.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1196920725302
O17 - HKLM\System\CCS\Services\Tcpip\..\{2D022BE2-EA45-4E83-9263-53D951727416}: NameServer = 68.28.154.92 68.28.146.92
O17 - HKLM\System\CS1\Services\Tcpip\..\{2D022BE2-EA45-4E83-9263-53D951727416}: NameServer = 68.28.154.92 68.28.146.92
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O20 - Winlogon Notify: winrmj32 - winrmj32.dll (file missing)
O23 - Service: BBWatcherService - CMS Products™, Inc. - C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NeatReceipts Database Controller - Digital Business Processes - C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 7895 bytes


Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Win32-Trojan-gen {Other}
« Reply #11 on: May 14, 2008, 12:59:55 AM »
Hi, Brian.  Yes, another run of ComboFix and then I believe we can tidy up.  This was my oversight (Thanks Clark76 for catching it).  Sorry. 
Custom CFScript
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

Code: [Select]
Driver::
C:\WINDOWS\system32\drivers\portd64.sys

File::
C:\WINDOWS\system32\drivers\portd64.sys
  • Save this as CFScript.txt and place it on your desktop.
  • Close any open browsers
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.



   
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
       
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

Please download ATF Cleaner by Atribune from http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25 .  Save it to your Desktop.

Run ATF Cleaner
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
  • Click Exit on the Main menu to close the program.
  • Shutdown/restart the computer.
Start HijackThis, close all open windows leaving only HijackThis running. Place a check against the following, if found, and press "Fix Checked":

O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O20 - Winlogon Notify: winrmj32 - winrmj32.dll (file missing)


Please post the ComboFix log and a fresh HijackThis log.  Make sure that you re-install your antivirus software. 
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline theroadmanager

  • Newbie
  • *
  • Posts: 10
Re: Win32-Trojan-gen {Other}
« Reply #12 on: May 14, 2008, 08:49:42 PM »
Corrine,

Here is the latest COMBOFIX Log and a fresh HIJACKTHIS.  I did delete those items on the first HIJACKTHIS scan I did and should reflect that they are gone in the HJT Log I posted below.  Anything else we need to do?

Brian


COMBOFIX:


ComboFix 08-05-12.1 - Brian Persall 2008-05-13 21:51:21.4 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.597 [GMT -5:00]
Running from: C:\Documents and Settings\Brian Persall\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Brian Persall\Desktop\CFScript.txt
 * Created a new restore point

FILE ::
C:\WINDOWS\system32\drivers\portd64.sys
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\portd64.sys

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_portio


(((((((((((((((((((((((((   Files Created from 2008-04-14 to 2008-05-14  )))))))))))))))))))))))))))))))
.

2008-05-11 18:20 . 2008-05-11 18:20   <DIR>   d--------   C:\WINDOWS\system32\Kaspersky Lab
2008-05-11 18:20 . 2008-05-11 18:20   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-08 19:31 . 2008-05-13 21:51   1,024   --ah-----   C:\WINDOWS\system32\config\systemprofile\NtUser.dat.LOG
2008-05-05 16:46 . 2008-05-05 21:55   <DIR>   d--------   C:\WINDOWS\BounceBack
2008-05-04 19:41 . 2008-05-04 20:30   13   --a------   C:\WINDOWS\system32\WinSys32.crc
2008-05-04 19:40 . 2004-11-22 20:56   913,560   --a------   C:\WINDOWS\system32\wodFtpDLX.ocx
2008-05-04 19:40 . 1999-03-22 12:29   233,472   --a------   C:\WINDOWS\system32\Ilda32.dll
2008-05-04 19:40 . 1998-06-17 04:00   18,944   --a------   C:\WINDOWS\system32\BORLNDMM.DLL
2008-05-02 19:59 . 2008-05-02 19:59   <DIR>   d--------   C:\Kaspersky
2008-05-02 19:55 . 2008-05-02 19:55   <DIR>   d--------   C:\quarantine
2008-05-01 22:39 . 2008-05-01 22:39   <DIR>   d--------   C:\Program Files\Lavasoft
2008-05-01 22:39 . 2008-05-02 21:03   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-01 16:16 . 2008-05-01 16:14   102,664   --a------   C:\WINDOWS\system32\drivers\tmcomm.sys
2008-05-01 16:14 . 2008-05-01 16:35   <DIR>   d--------   C:\Documents and Settings\Brian Persall\.housecall6.6
2008-04-29 19:28 . 2008-04-29 19:46   <DIR>   d--------   C:\Documents and Settings\Brian Persall\k5nCal
2008-04-28 21:21 . 2008-04-28 21:21   <DIR>   d--------   C:\Documents and Settings\Brian Persall\Application Data\Uniblue
2008-04-27 19:21 . 2008-05-05 15:47   <DIR>   d--------   C:\Program Files\Spybot - Search & Destroy
2008-04-27 19:21 . 2008-05-05 15:43   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-27 15:53 . 2008-04-27 15:53   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\HotSync
2008-04-27 15:49 . 2008-04-27 15:49   <DIR>   d--------   C:\Documents and Settings\Brian Persall\Application Data\HotSync
2008-04-22 09:50 . 2008-04-22 09:50   664   --a------   C:\WINDOWS\system32\d3d9caps.dat
2008-04-18 15:55 . 2008-04-18 15:55   552   --a------   C:\WINDOWS\system32\d3d8caps.dat
2008-04-14 18:24 . 2008-04-14 18:24   <DIR>   d--------   C:\Documents and Settings\Brian Persall\Application Data\Northwoods Software

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-13 22:49   ---------   d-----w   C:\Program Files\Mozilla Thunderbird
2008-05-10 01:52   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\Skype
2008-05-09 21:05   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\skypePM
2008-05-05 21:22   ---------   d-----r   C:\Program Files\CMS Products
2008-05-05 01:54   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\FileZilla
2008-05-05 01:26   ---------   d-----w   C:\Program Files\CoffeeCup Software
2008-05-03 12:55   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\U3
2008-04-30 20:26   ---------   d-----w   C:\Program Files\FileZilla FTP Client
2008-04-27 20:53   ---------   d-----w   C:\Program Files\Palm
2008-04-27 20:51   53,248   ----a-w   C:\WINDOWS\PalmDevC.dll
2008-04-27 20:51   16,694   ----a-w   C:\WINDOWS\system32\drivers\PalmUSBD.sys
2008-04-04 03:57   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Sage Software SB, Inc
2008-04-03 00:06   ---------   d-----w   C:\Documents and Settings\Brian Persall\Application Data\Sprint
2008-04-03 00:01   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Sprint
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Sprint
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Sierra Wireless
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Common Files\Research in Motion
2008-04-02 23:58   ---------   d-----w   C:\Program Files\Common Files\Motorola Shared
2008-04-02 04:29   24,320   ------w   C:\Documents and Settings\Brian Persall\Application Data\GDIPFONTCACHEV1.DAT
2008-03-27 23:49   ---------   d-----w   C:\Program Files\Common Files\Adobe
2008-01-06 21:41   32   ----a-w   C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-18 18:17   31   -c----w   C:\Documents and Settings\Brian Persall\RUNME.bat
.

(((((((((((((((((((((((((((((   snapshot@2008-05-08_19.45.38.29   )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-09 00:33:29   2,048   ----a-w   C:\WINDOWS\bootstat.dat
+ 2008-05-14 02:55:38   2,048   ----a-w   C:\WINDOWS\bootstat.dat
+ 2005-10-21 01:02:28   163,328   ----a-w   C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2005-05-24 17:27:16   213,048   ----a-w   C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20   94,208   ----a-w   C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54   950,272   ----a-w   C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-05-09 00:34:22   1,734   ----a-w   C:\WINDOWS\system32\KGyGaAvL.sys
+ 2008-05-14 02:56:42   1,734   ----a-w   C:\WINDOWS\system32\KGyGaAvL.sys
+ 2008-05-14 02:55:45   16,384   ----atw   C:\WINDOWS\Temp\Perflib_Perfdata_29c.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36 114688]
"Act! Preloader"="C:\Program Files\ACT\ACT for Windows\Act8.exe" [2006-04-05 18:30 1015808]
"ICF"="C:\Program Files\Internet Content Filter\SafeEyes.exe" [2007-06-05 11:17 1237504]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 12:19 819200]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 12:17 970752]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"Sprint SmartView"="C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" [2008-03-10 09:09 17672]
"QuickTime Task"="C:\PROGRAM FILES\QUICKTIME\QTTASK.exe" [2007-12-07 03:02 77824]

C:\Documents and Settings\Brian Persall\Start Menu\Programs\Startup\
BounceBack Launcher.lnk - C:\Program Files\CMS Products\BounceBack Professional\BBStartup.exe [2008-05-05 16:22:28 40960]
PowerReg Scheduler.exe [2007-12-07 02:52:31 233472]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-03-27 18:49:40 113664]
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 22:16:46 24576]
HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2004-06-09 14:27:34 471040]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrmj32]
winrmj32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= xgusb.cpl
"midi5"= xgusb.cpl
"midi8"= xgusb.cpl

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\ACT\\ACT for Windows\\Act8.exe"=
"C:\\Program Files\\Palm\\HOTSYNC.EXE"=
"C:\\Program Files\\SecondLife\\SLVoice.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"C:\\Program Files\\FreshDevices\\FreshDownload\\fdgo.exe"=
"C:\\Program Files\\Internet Content Filter\\Pop3Proxy.exe"=
"C:\\Program Files\\Harman Pro\\System Architect 1.60\\SystemArchitect.exe"=
"C:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2078:TCP"= 2078:TCP:brianpersall.com
"2077:TCP"= 2077:TCP:brianpersall.com

R2 BBWatcherService;BBWatcherService;"C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe" [2008-01-04 09:46]
R2 MSSQL$ACT7;MSSQL$ACT7;C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe [2003-05-31 19:02]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 06:29]
R3 Nmea;Sprint Connection Manager - emulates the NMEA ports;C:\WINDOWS\system32\DRIVERS\pctnullport.sys [2008-03-05 15:41]
R3 NWADI;NWADI Bus Enumerator;C:\WINDOWS\system32\DRIVERS\NWADIenum.sys [2007-04-19 12:09]
R3 swmsflt;swmsflt;C:\WINDOWS\system32\drivers\swmsflt.sys [2008-03-05 15:41]
S3 MSSQL$NR2007;SQL Server (NR2007);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sNR2007 []
S3 NeatReceipts Database Controller;NeatReceipts Database Controller;"C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe" [2008-02-05 14:03]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2007-11-15 19:40]
S3 ps_1394;ps_1394;C:\WINDOWS\system32\Drivers\ps_1394.sys [2004-10-14 16:33]
S3 ps_avs;ps_avs;C:\WINDOWS\system32\Drivers\ps_avs.sys [2004-10-14 16:33]
S3 SprintRcAppSvc;Sprint RcAppSvc;"C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe" /n "SprintRcAppSvc" []
S3 SQLAgent$ACT7;SQLAgent$ACT7;C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlagent.EXE [2002-12-17 17:23]
S3 usbvm328;HP Camera;C:\WINDOWS\system32\Drivers\usbvm326.sys [2006-10-12 19:42]
S3 vmfilter323;VC0326 filter service for Serome;C:\WINDOWS\system32\drivers\vmfilter323.sys [2006-08-10 23:00]

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-13 21:56:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\ICF.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\CMS Products\BounceBack Professional\BBLauncher.exe
.
**************************************************************************
.
Completion time: 2008-05-13 22:00:05 - machine was rebooted
ComboFix-quarantined-files.txt  2008-05-14 02:59:50
ComboFix2.txt  2008-05-13 01:37:31
ComboFix3.txt  2008-05-09 00:46:14
ComboFix4.txt  2008-05-06 02:53:23

Pre-Run: 30,438,825,984 bytes free
Post-Run: 30,427,836,416 bytes free

176   --- E O F ---   2008-04-09 17:38:29


===========================================================================

HIJACKTHIS:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:13:21 PM, on 5/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Content Filter\SafeEyes.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\CMS Products\BounceBack Professional\BBLauncher.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\FDCatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\ACT for Windows\Act8.exe" -preload
O4 - HKLM\..\Run: [ICF] "C:\Program Files\Internet Content Filter\SafeEyes.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE" -atboottime
O4 - Startup: BounceBack Launcher.lnk = ?
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: FreshDownload - {D6226514-AE1F-495A-8EEF-65B021C380FE} - C:\Program Files\FreshDevices\FreshDownload\fd.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1196920725302
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O23 - Service: BBWatcherService - CMS Products™, Inc. - C:\Program Files\CMS Products\BounceBack Professional\BBWatcherService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NeatReceipts Database Controller - Digital Business Processes - C:\Program Files\Common Files\NeatReceipts\DB Controller\NeatReceiptsDBController.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 6635 bytes

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Win32-Trojan-gen {Other}
« Reply #13 on: May 14, 2008, 11:25:48 PM »
Hi, Brian. 

First, let's take care of ComboFix and the files that CF has quarantined. Please do the following:
  • Click START then RUN
  • Now type Combofix /u in the runbox  and click OK.  Note the space between the X and the U, it needs to be there.


Now, you can put WinPatrol back in startup and you definitely need to re-install your Antivirus software.  Although no software is perfect, Avast has been receiving very high praise.  Even if you are behind a router, a software firewall is highly recommended.   The following firewall software is free for personal use:

Agnitum Outpost Firewall
Comodo Free Firewall
Kerio Personal Firewall
Online Armor Free

Please let us know if you have any further questions.  :rose:
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline theroadmanager

  • Newbie
  • *
  • Posts: 10
Re: Win32-Trojan-gen {Other}
« Reply #14 on: May 15, 2008, 12:42:25 AM »
Corrine,

Thanks again for the help!   :gwave:  Your Awesome!  Ok, so I have a few questions about what we did and the whole process.  First of all, any idea on what kind of trojan / malware / virus thing I had and what it was doing?  The files we deleted with Combofix, were those related to the virus or files that were infected and needed to be removed?  Are the files that were deleted reinstalled during the process clean or do I need to do something about that?  Reason being, the database I use is ACT and can be kind of glitchy at times, althought I have tested it and seems to be operating normally, just wanted to double check and be sure.  Everything seems to be working fine.  Avast hasn't been giving me any alarms for about 3 days now.

Again, appreciate your help with this!

Brian