Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Infected with Trojan Horse and something else
   
BullGuard Antivirus Forum > General Security > Spyware > Infected with Trojan Horse and something else  
Forum Quick Jump
 
New Topic Locked Topic Printable version of : Infected with Trojan Horse and something else
[ << Previous Thread | Next Thread >> ]

squrrilslayer
New Member


Date Joined Mar 2007
Total Posts : 16
 
   Posted 7-4-2008 7:27 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else
Hi.
I have just eliminated a vundo infection i had on my computer however Norton360 tells me that there are still 2 Trojan Horses and a Info.<something...> stealer. Um, I need help to eliminate them because Norton doesn't know how.

My HJT:
Logfile of HijackThis v1.99.1
Scan saved at 3:25:38 PM, on 4/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\SWAS.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Samsung\Samsung CLX-3160 Series\SPanel\PSU\Scan2pc.exe
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\program files\ncsoft\launcher\NCLauncher.exe
C:\Program Files\iriver\iriver plus 2\iAgent2.exe
C:\Program Files\Octoshape Streaming Services\John Geddes\OctoshapeClient.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\FRAPS\FRAPS.EXE
C:\Program Files\Logitech\SetPoint II\SetpointII.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\John Geddes\Desktop\Security\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {71532D48-66A9-4CE2-9710-8A053A7FC886} - C:\WINDOWS\system32\vtUnOfdd.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {EE8D31A2-A856-416E-9BFF-24A8771CC3BF} - C:\WINDOWS\msagent\intl\awvenod.dll (file missing)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IRIS_S2P] C:\Program Files\Samsung\Samsung CLX-3160 Series\SPanel\PSU\Scan2pc.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKLM\..\Run: [NSCSysTrayUI] "C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe" /HIDEUI
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [EVGAPrecision] "C:\Program Files\EVGA Precision\EVGAPrecision.exe" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [8451701c] rundll32.exe "C:\WINDOWS\system32\nljkkbys.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlayNC Launcher] C:\program files\ncsoft\launcher\NCLauncher.exe /Minimized
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [iPlusAgent2] "C:\Program Files\iriver\iriver plus 2\iAgent2.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Program Files\Octoshape Streaming Services\John Geddes\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - Global Startup: SetPointII.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O11 - Options group: [INTERNATIONAL] International*
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A65FE59-308F-4C53-8FDF-0FA9C88A52D2}: NameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5AB867B-7BDE-4456-80D1-D1D9753A4557}: NameServer = 192.168.2.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: SyncThru Web Admin Service (SWAS_Core) - Unknown owner - C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\SWAS.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe



During this infection, i had been getting execution 0xc0000005 errors everywhere. It's fixed now since the removal of the vundo's.

Thanks.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13131
 
   Posted 7-4-2008 7:59 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else
Hello smile
 
 
Please download Combofix:
 
 
And save to the desktop.

Close all other browser windows.
 
 
 
Important-> Temporarily disable your anti-virus, real-time protection before performing a scan. They can interfere with combofix or remove some of its embedded files which may cause "unpredictable results".
 
 
Go to Start->Run and copy/paste: ComboFix /snapshot and hit OK. It should run Combofix.
 
Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.

 When finished, it will produce a logfile located at C:\combofix.txt.
 

Post the contents of that log in your next reply with a new hijackthis log.
 
Please copy and paste your log files. DO NOT add it as an attachment
Kindly do not annotate or format the log with color or font changes.



NB. If you are using any P2P (file sharing) programs, please remove them before we clean your computer.. We do not clean logs that have P2P applications installed as this can cause reinfection during your cleaning.


Do NOT post your problem in someone elses thread.

Back to Top
 

squrrilslayer
New Member


Date Joined Mar 2007
Total Posts : 16
 
   Posted 7-4-2008 1:56 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else
ok. here is the log.txt from combofix~

ComboFix 08-07-03.5 - John Geddes 2008-07-04 21:36:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1505 [GMT 10:00]
Running from: C:\Documents and Settings\John Geddes\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BM87624380.txt
C:\WINDOWS\system32\ddfOnUtv.ini
C:\WINDOWS\system32\ddfOnUtv.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\rnooobkf.ini
C:\WINDOWS\system32\Skinlib.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-04 to 2008-07-04 )))))))))))))))))))))))))))))))
.

2008-07-03 21:55 . 2008-07-03 21:55 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-07-03 21:17 . 2008-07-03 22:25 <DIR> d-------- C:\VundoFix Backups
2008-07-03 21:17 . 2008-07-03 22:24 209 --a------ C:\WINDOWS\wininit.ini
2008-07-03 20:56 . 2008-07-03 20:56 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-03 20:56 . 2008-07-03 22:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-03 16:31 . 2008-07-03 21:08 196,608 --a------ C:\WINDOWS\SysNotifier.exe
2008-07-03 15:23 . 2008-07-03 15:23 294,912 --a------ C:\WINDOWS\system32\reaiexwo.exe
2008-07-02 22:12 . 2008-07-02 22:12 <DIR> d-------- C:\Documents and Settings\John Geddes\Application Data\Apple Computer
2008-07-02 22:11 . 2008-07-02 22:11 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-02 22:11 . 2008-07-02 22:11 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-02 14:56 . 2008-07-03 16:15 110,419 --a------ C:\WINDOWS\BM87624380.xml
2008-07-01 17:33 . 2008-07-01 17:33 <DIR> d-------- C:\Program Files\Everstrike Software
2008-07-01 17:33 . 2008-07-01 17:33 <DIR> d-------- C:\Program Files\Common Files\Everstrike Software
2008-06-29 20:03 . 2008-06-29 20:03 <DIR> d-------- C:\Program Files\Octoshape Streaming Services
2008-06-29 15:44 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-06-29 15:44 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-06-28 13:33 . 2008-06-28 13:33 <DIR> d-------- C:\Program Files\Common Files\EasyInfo
2008-06-27 18:26 . 2008-06-27 18:26 <DIR> d-------- C:\Program Files\Real Alternative
2008-06-27 18:26 . 2008-06-27 18:26 <DIR> d-------- C:\Documents and Settings\John Geddes\Application Data\Media Player Classic
2008-06-25 16:17 . 2008-07-04 07:55 2,145,386,496 --a------ C:\WINDOWS\MEMORY.DMP
2008-06-20 08:11 . 2008-06-20 08:11 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-06-18 21:02 . 2008-06-18 21:02 <DIR> d-------- C:\Program Files\CCleaner
2008-06-12 18:24 . 2006-02-16 17:52 143 --a------ C:\WINDOWS\system32\Z004.pid
2008-06-12 07:27 . 2008-06-12 18:24 <DIR> d-------- C:\Program Files\Solstar Games
2008-06-12 07:27 . 2006-09-13 14:09 1,497,272 --a------ C:\WINDOWS\system32\Codejock.CommandBars.v10.3.1.ocx
2008-06-12 07:27 . 2007-01-13 04:51 454,656 --a------ C:\WINDOWS\system32\SCIVBX.ocx
2008-06-12 07:27 . 2000-05-22 05:00 203,976 --a------ C:\WINDOWS\system32\RICHTX32.OCX
2008-06-12 07:27 . 2006-09-18 05:58 83,968 --a------ C:\WINDOWS\system32\RCToolbar.ocx
2008-06-12 07:27 . 2005-08-11 23:22 17 --a------ C:\WINDOWS\guiinfo.dat
2008-06-11 18:10 . 2008-06-11 18:10 <DIR> d-------- C:\Documents and Settings\John Geddes\Application Data\Radmin
2008-06-11 18:09 . 2008-06-11 18:09 <DIR> d-------- C:\Program Files\Radmin Viewer 3
2008-06-11 18:07 . 2008-06-13 23:10 272,128 --a--c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-08 15:41 . 2008-06-08 15:42 <DIR> d-------- C:\Documents and Settings\Kay Geddes\Application Data\uTorrent
2008-06-04 19:11 . 2008-05-31 08:14 <DIR> d-------- C:\Documents and Settings\Kay Geddes\Application Data\DivX
2008-06-04 19:11 . 2008-06-04 19:11 <DIR> d-------- C:\Documents and Settings\Kay Geddes
2008-06-04 07:13 . 2008-02-26 21:59 294,912 --a--c--- C:\WINDOWS\system32\dllcache\msctf.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-04 11:45 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-04 11:31 --------- d-----w C:\Program Files\uTorrent
2008-07-04 04:33 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-03 10:58 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-07-02 06:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-07-01 07:30 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\uTorrent
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-02 01:36 --------- d-----w C:\Program Files\Common Files\INCA Shared
2008-05-31 07:31 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\Nexon
2008-05-30 22:25 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-05-30 22:25 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-30 22:25 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-05-30 22:25 --------- d-----w C:\Program Files\Symantec
2008-05-30 07:18 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\Orbit
2008-05-30 06:37 98,304 ----a-w C:\WINDOWS\DUMP6de4.tmp
2008-05-29 21:27 --------- d-----w C:\Program Files\Samsung Network Printer Utilities
2008-05-26 11:06 --------- d-----w C:\Program Files\EVGA Precision
2008-05-25 11:30 --------- d-----w C:\Program Files\EleFun Desktops
2008-05-25 11:30 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\elefundesktops
2008-05-25 11:29 --------- d-----w C:\Program Files\Active Volcano 3D Screensaver
2008-05-25 11:29 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\TERMINAL Studio
2008-05-25 03:49 --------- d-----w C:\Program Files\SpeedFan
2008-05-19 08:43 --------- d-----w C:\Program Files\Alcohol Soft
2008-05-19 07:41 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\Ahead
2008-05-19 07:35 --------- d-----w C:\Program Files\MagicDVDRipper
2008-05-17 03:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-12 08:56 --------- d-----w C:\Program Files\QuickTime
2008-05-12 08:56 --------- d-----w C:\Program Files\Apple Software Update
2008-05-12 08:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-12 08:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-05-11 07:04 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-05-09 09:24 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\mIRC
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-06 09:20 --------- d-----w C:\Program Files\iriver
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"PlayNC Launcher"="C:\program files\ncsoft\launcher\NCLauncher.exe" [2008-06-19 07:09 38128]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 19:25 81920]
"iPlusAgent2"="C:\Program Files\iriver\iriver plus 2\iAgent2.exe" [2005-09-20 18:14 245760]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-05-19 18:44 4608]
"Octoshape Streaming Services"="C:\Program Files\Octoshape Streaming Services\John Geddes\OctoshapeClient.exe" [2008-05-22 23:59 156944]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"Fraps"="C:\FRAPS\FRAPS.EXE" [2008-01-14 22:18 3182248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 15:59 115816]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
"Launch LCDMon"="C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2007-07-18 09:30 1687824]
"Launch LGDCore"="C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2007-07-18 10:08 2094352]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"IRIS_S2P"="C:\Program Files\Samsung\Samsung CLX-3160 Series\SPanel\PSU\Scan2pc.exe" [2006-12-07 21:02 253952]
"Samsung PanelMgr"="C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe" [2007-08-17 16:17 524288]
"NSCSysTrayUI"="C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe" [2006-09-14 18:16 270336]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"EVGAPrecision"="C:\Program Files\EVGA Precision\EVGAPrecision.exe" [2008-05-21 03:43 199696]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-07-17 17:39 55824 C:\WINDOWS\KHALMNPR.Exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-03-26 16:14 16859136 C:\WINDOWS\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
SetPointII.lnk - C:\Program Files\Logitech\SetPoint II\SetpointII.exe [2007-08-30 18:13:06 319488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Samsung\\NetworkScan\\NSCSysTrayUI.exe"=
"C:\\Program Files\\NCsoft\\Exteel\\System\\Exteel.exe"=
"C:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"=
"C:\\Documents and Settings\\John Geddes\\Desktop\\mIRC - English.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"C:\\Program Files\\Octoshape Streaming Services\\John Geddes\\OctoshapeClient.exe"=
"C:\\WINDOWS\\system32\\ftp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2774:UDP"= 2774:UDP:Windows Media Format SDK (iexplore.exe)
"2775:UDP"= 2775:UDP:Windows Media Format SDK (iexplore.exe)

R0 nvgts;nvgts;C:\WINDOWS\system32\DRIVERS\nvgts.sys [2007-08-09 11:11]
R2 LF30FS;LF30FS;C:\Program Files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [2004-11-19 18:07]
R2 SWAS_Core;SyncThru Web Admin Service;C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\SWAS.exe [2007-07-17 23:24]
R3 RTCore32;RTCore32;C:\Program Files\EVGA Precision\RTCore32.sys [2005-05-26 04:39]
S2 SSPORT;SSPORT;C:\WINDOWS\system32\Drivers\SSPORT.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4a55450-edc4-11dc-84c8-00044b14b238}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

*Newly Created Service* - RTCORE32
.
Contents of the 'Scheduled Tasks' folder
"2008-05-27 22:26:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -

BHO-{71532D48-66A9-4CE2-9710-8A053A7FC886} - C:\WINDOWS\system32\vtUnOfdd.dll
BHO-{EE8D31A2-A856-416E-9BFF-24A8771CC3BF} - C:\WINDOWS\msagent\intl\awvenod.dll
HKCU-Run-EleFunAnimatedWallpaper - (no file)
HKLM-Run-8451701c - C:\WINDOWS\system32\nljkkbys.dll
HKLM-Run-Amazing3DAquariumWallpaper - (no file)
HKLM-Run-L!!!ent - (no file)


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-04 21:44:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SQLBrowser]
"ImagePath"="\"c:XProgram Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe\""
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\savedump.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2008-07-04 21:48:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-04 11:48:05

Pre-Run: 728,207,855,616 bytes free
Post-Run: 728,106,012,672 bytes free

214 --- E O F --- 2008-06-19 22:11:23
Back to Top
 

squrrilslayer
New Member


Date Joined Mar 2007
Total Posts : 16
 
   Posted 7-4-2008 1:59 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else
actually i just realized that reading through that log that there is still utorrent installed in another account on my computer. That account hasn't been used for a while and probably won't be used, do i still have to uninstall it off there?
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13131
 
   Posted 7-5-2008 7:45 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else
You decide if you will remove utorrent ;-)
 
 
Open notepad and copy/paste the text in the quote box below into it:
Quote:
-----------------------------------------------------
KILLALL::
 
Snapshot::
 
File::
C:\WINDOWS\SysNotifier.exe
C:\WINDOWS\system32\reaiexwo.exe
C:\WINDOWS\guiinfo.dat
C:\WINDOWS\system32\vtUnOfdd.dll
C:\WINDOWS\msagent\intl\awvenod.dll
C:\WINDOWS\system32\nljkkbys.dll
 
----------------------------------------------
 
 
Save this as CFScript.txt
 
 
At this point, You MUST EXIT ALL BROWSERS NOW before continuing!
Referring to the picture above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system.
It may reboot your system when it finishes. This is normal.
 
 
Post new hijackthis log along with fresh combofix log
 


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

squrrilslayer
New Member


Date Joined Mar 2007
Total Posts : 16
 
   Posted 7-5-2008 9:21 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else
ok thanks.

here is the new ComboFix Log:

ComboFix 08-07-03.5 - John Geddes 2008-07-05 17:08:05.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1640 [GMT 10:00]
Running from: C:\Documents and Settings\John Geddes\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\John Geddes\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\guiinfo.dat
C:\WINDOWS\msagent\intl\awvenod.dll
C:\WINDOWS\SysNotifier.exe
C:\WINDOWS\system32\nljkkbys.dll
C:\WINDOWS\system32\reaiexwo.exe
C:\WINDOWS\system32\vtUnOfdd.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BM87624380.xml
C:\WINDOWS\guiinfo.dat
C:\WINDOWS\SysNotifier.exe
C:\WINDOWS\system32\reaiexwo.exe

.
((((((((((((((((((((((((( Files Created from 2008-06-05 to 2008-07-05 )))))))))))))))))))))))))))))))
.

2008-07-03 21:55 . 2008-07-03 21:55 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-07-03 21:17 . 2008-07-03 22:25 <DIR> d-------- C:\VundoFix Backups
2008-07-03 21:17 . 2008-07-03 22:24 209 --a------ C:\WINDOWS\wininit.ini
2008-07-03 20:56 . 2008-07-03 20:56 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-03 20:56 . 2008-07-03 22:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-02 22:12 . 2008-07-02 22:12 <DIR> d-------- C:\Documents and Settings\John Geddes\Application Data\Apple Computer
2008-07-02 22:11 . 2008-07-05 10:09 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-02 22:11 . 2008-07-02 22:11 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-01 17:33 . 2008-07-01 17:33 <DIR> d-------- C:\Program Files\Everstrike Software
2008-07-01 17:33 . 2008-07-01 17:33 <DIR> d-------- C:\Program Files\Common Files\Everstrike Software
2008-06-29 20:03 . 2008-06-29 20:03 <DIR> d-------- C:\Program Files\Octoshape Streaming Services
2008-06-29 15:44 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-06-29 15:44 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-06-28 13:33 . 2008-06-28 13:33 <DIR> d-------- C:\Program Files\Common Files\EasyInfo
2008-06-27 18:26 . 2008-06-27 18:26 <DIR> d-------- C:\Program Files\Real Alternative
2008-06-27 18:26 . 2008-06-27 18:26 <DIR> d-------- C:\Documents and Settings\John Geddes\Application Data\Media Player Classic
2008-06-25 16:17 . 2008-07-04 22:51 2,145,386,496 --a------ C:\WINDOWS\MEMORY.DMP
2008-06-20 08:11 . 2008-06-20 08:11 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-06-18 21:02 . 2008-06-18 21:02 <DIR> d-------- C:\Program Files\CCleaner
2008-06-12 18:24 . 2006-02-16 17:52 143 --a------ C:\WINDOWS\system32\Z004.pid
2008-06-12 07:27 . 2008-06-12 18:24 <DIR> d-------- C:\Program Files\Solstar Games
2008-06-12 07:27 . 2006-09-13 14:09 1,497,272 --a------ C:\WINDOWS\system32\Codejock.CommandBars.v10.3.1.ocx
2008-06-12 07:27 . 2007-01-13 04:51 454,656 --a------ C:\WINDOWS\system32\SCIVBX.ocx
2008-06-12 07:27 . 2000-05-22 05:00 203,976 --a------ C:\WINDOWS\system32\RICHTX32.OCX
2008-06-12 07:27 . 2006-09-18 05:58 83,968 --a------ C:\WINDOWS\system32\RCToolbar.ocx
2008-06-11 18:10 . 2008-06-11 18:10 <DIR> d-------- C:\Documents and Settings\John Geddes\Application Data\Radmin
2008-06-11 18:09 . 2008-06-11 18:09 <DIR> d-------- C:\Program Files\Radmin Viewer 3
2008-06-11 18:07 . 2008-06-13 23:10 272,128 --a--c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-08 15:41 . 2008-06-08 15:42 <DIR> d-------- C:\Documents and Settings\Kay Geddes\Application Data\uTorrent

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-05 07:13 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-05 02:46 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-03 10:58 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-07-02 06:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-02 01:36 --------- d-----w C:\Program Files\Common Files\INCA Shared
2008-05-31 07:31 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\Nexon
2008-05-30 22:25 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-05-30 22:25 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-30 22:25 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-05-30 22:25 --------- d-----w C:\Program Files\Symantec
2008-05-30 22:14 --------- d-----w C:\Documents and Settings\Kay Geddes\Application Data\DivX
2008-05-30 07:18 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\Orbit
2008-05-30 06:37 98,304 ----a-w C:\WINDOWS\DUMP6de4.tmp
2008-05-29 21:27 --------- d-----w C:\Program Files\Samsung Network Printer Utilities
2008-05-26 11:06 --------- d-----w C:\Program Files\EVGA Precision
2008-05-25 11:30 --------- d-----w C:\Program Files\EleFun Desktops
2008-05-25 11:30 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\elefundesktops
2008-05-25 11:29 --------- d-----w C:\Program Files\Active Volcano 3D Screensaver
2008-05-25 11:29 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\TERMINAL Studio
2008-05-25 03:49 --------- d-----w C:\Program Files\SpeedFan
2008-05-19 08:43 --------- d-----w C:\Program Files\Alcohol Soft
2008-05-19 07:41 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\Ahead
2008-05-19 07:35 --------- d-----w C:\Program Files\MagicDVDRipper
2008-05-17 03:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-12 08:56 --------- d-----w C:\Program Files\QuickTime
2008-05-12 08:56 --------- d-----w C:\Program Files\Apple Software Update
2008-05-12 08:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-12 08:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-05-11 07:04 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-05-09 09:24 --------- d-----w C:\Documents and Settings\John Geddes\Application Data\mIRC
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-06 09:20 --------- d-----w C:\Program Files\iriver
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"PlayNC Launcher"="C:\program files\ncsoft\launcher\NCLauncher.exe" [2008-06-19 07:09 38128]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 19:25 81920]
"iPlusAgent2"="C:\Program Files\iriver\iriver plus 2\iAgent2.exe" [2005-09-20 18:14 245760]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-05-19 18:44 4608]
"Octoshape Streaming Services"="C:\Program Files\Octoshape Streaming Services\John Geddes\OctoshapeClient.exe" [2008-05-22 23:59 156944]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"Fraps"="C:\FRAPS\FRAPS.EXE" [2008-01-14 22:18 3182248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 15:59 115816]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
"Launch LCDMon"="C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2007-07-18 09:30 1687824]
"Launch LGDCore"="C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2007-07-18 10:08 2094352]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"IRIS_S2P"="C:\Program Files\Samsung\Samsung CLX-3160 Series\SPanel\PSU\Scan2pc.exe" [2006-12-07 21:02 253952]
"Samsung PanelMgr"="C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe" [2007-08-17 16:17 524288]
"NSCSysTrayUI"="C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe" [2006-09-14 18:16 270336]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"EVGAPrecision"="C:\Program Files\EVGA Precision\EVGAPrecision.exe" [2008-05-21 03:43 199696]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-07-17 17:39 55824 C:\WINDOWS\KHALMNPR.Exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-03-26 16:14 16859136 C:\WINDOWS\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
SetPointII.lnk - C:\Program Files\Logitech\SetPoint II\SetpointII.exe [2007-08-30 18:13:06 319488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Samsung\\NetworkScan\\NSCSysTrayUI.exe"=
"C:\\Program Files\\NCsoft\\Exteel\\System\\Exteel.exe"=
"C:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"=
"C:\\Documents and Settings\\John Geddes\\Desktop\\mIRC - English.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"C:\\Program Files\\Octoshape Streaming Services\\John Geddes\\OctoshapeClient.exe"=
"C:\\WINDOWS\\system32\\ftp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2774:UDP"= 2774:UDP:Windows Media Format SDK (iexplore.exe)
"2775:UDP"= 2775:UDP:Windows Media Format SDK (iexplore.exe)

R0 nvgts;nvgts;C:\WINDOWS\system32\DRIVERS\nvgts.sys [2007-08-09 11:11]
R2 LF30FS;LF30FS;C:\Program Files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [2004-11-19 18:07]
R2 SWAS_Core;SyncThru Web Admin Service;C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\SWAS.exe [2007-07-17 23:24]
R3 RTCore32;RTCore32;C:\Program Files\EVGA Precision\RTCore32.sys [2005-05-26 04:39]
S2 SSPORT;SSPORT;C:\WINDOWS\system32\Drivers\SSPORT.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d4a55450-edc4-11dc-84c8-00044b14b238}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-05-27 22:26:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-05 17:13:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SQLBrowser]
"ImagePath"="\"c:XProgram Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe\""
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\savedump.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2008-07-05 17:17:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-05 07:17:04
ComboFix2.txt 2008-07-04 11:48:09

Pre-Run: 729,207,332,864 bytes free
Post-Run: 729,191,157,760 bytes free

208 --- E O F --- 2008-06-19 22:11:23
Back to Top
 

squrrilslayer
New Member


Date Joined Mar 2007
Total Posts : 16
 
   Posted 7-5-2008 9:22 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else
and here is my new HJT:

Logfile of HijackThis v1.99.1
Scan saved at 5:20:37 PM, on 5/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\SWAS.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Samsung\Samsung CLX-3160 Series\SPanel\PSU\Scan2pc.exe
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe
C:\Program Files\EVGA Precision\EVGAPrecision.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\ncsoft\launcher\NCLauncher.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\iriver\iriver plus 2\iAgent2.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Octoshape Streaming Services\John Geddes\OctoshapeClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\FRAPS\FRAPS.EXE
C:\Program Files\Logitech\SetPoint II\SetpointII.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\John Geddes\Desktop\Security\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IRIS_S2P] C:\Program Files\Samsung\Samsung CLX-3160 Series\SPanel\PSU\Scan2pc.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKLM\..\Run: [NSCSysTrayUI] "C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe" /HIDEUI
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [EVGAPrecision] "C:\Program Files\EVGA Precision\EVGAPrecision.exe" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlayNC Launcher] C:\program files\ncsoft\launcher\NCLauncher.exe /Minimized
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [iPlusAgent2] "C:\Program Files\iriver\iriver plus 2\iAgent2.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Program Files\Octoshape Streaming Services\John Geddes\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - Global Startup: SetPointII.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O11 - Options group: [INTERNATIONAL] International*
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A65FE59-308F-4C53-8FDF-0FA9C88A52D2}: NameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5AB867B-7BDE-4456-80D1-D1D9753A4557}: NameServer = 192.168.2.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: SyncThru Web Admin Service (SWAS_Core) - Unknown owner - C:\Program Files\Samsung Network Printer Utilities\SyncThru Web Admin Service\SWAS.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13131
 
   Posted 7-5-2008 9:28 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else
Looks clean smile
 
 
Seems to, you have tried to uninstall Norton ?
 
 
How are things running now ?


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

squrrilslayer
New Member


Date Joined Mar 2007
Total Posts : 16
 
   Posted 7-5-2008 10:39 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else
everything is running fine now thanks! It'll be a couple hours for norton to finish rescanning. Until then, thank you very much for your help.
Back to Top
 

squrrilslayer
New Member


Date Joined Mar 2007
Total Posts : 16
 
   Posted 7-5-2008 11:42 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else


Norton says they are still there. Also my computer is starting to run slowly again.
"Get Help" does nothing for me. The so called 'help center' is anything but. I've run Spybot S&D and cleaned up everything with that but those 3 things are still there!
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13131
 
   Posted 7-5-2008 12:46 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else
Have you filename and path of the infections ?


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

squrrilslayer
New Member


Date Joined Mar 2007
Total Posts : 16
 
   Posted 7-5-2008 1:52 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else
thats the annoying thing. It wont give me specifics or i don't know how to get them. All it keeps telling me is that im infected...
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13131
 
   Posted 7-5-2008 2:12 (GMT +2)    Quote: Infected with Trojan Horse and something elseAlert an admin about: Infected with Trojan Horse and something else
Have you pay for Norton ?  rolleyes
 
Let´s hope they are in systemrestore -
 
To completely and immediately remove any infected file or files in the data store, turn off and then turn on System Restore. To do so, follow these steps:
System Restore
 
 


Do NOT post your problem in someone elses thread.