clintz Posted December 2, 2008 Report Share Posted December 2, 2008 MalwareBytes logMalwarebytes' Anti-Malware 1.30Database version: 1445Windows 5.1.2600 Service Pack 312/2/2008 10:33:48 AMmbam-log-2008-12-02 (10-33-48).txtScan type: Quick ScanObjects scanned: 55848Time elapsed: 6 minute(s), 20 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 0Registry Values Infected: 2Registry Data Items Infected: 2Folders Infected: 0Files Infected: 2Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:(No malicious items detected)Registry Values Infected:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pmelamilabe (Trojan.Agent) -> Delete on reboot.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jvovuxabi (Trojan.Agent) -> Quarantined and deleted successfully.Registry Data Items Infected:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.Folders Infected:(No malicious items detected)Files Infected:C:\WINDOWS\Ofaxeguyoyamuzag.dll (Trojan.Agent) -> Delete on reboot.C:\WINDOWS\ojadewil.dll (Trojan.Agent) -> Delete on reboot.Hijack This!Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:42:41 AM, on 12/2/2008Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16735)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\WLTRYSVC.EXEC:\WINDOWS\System32\bcmwltry.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\PnkBstrB.exeC:\WINDOWS\system32\STacSV.exeC:\WINDOWS\Explorer.EXEC:\Program Files\DellTPad\Apoint.exeC:\WINDOWS\system32\rundll32.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\WINDOWS\system32\WLTRAY.exeC:\Program Files\DellTPad\ApMsgFwd.exeC:\Program Files\DellTPad\HidFind.exeC:\Program Files\DellTPad\Apntex.exeC:\Program Files\Dell\QuickSet\quickset.exeC:\WINDOWS\stsystra.exeC:\WINDOWS\system32\KADxMain.exeC:\Program Files\Common Files\InstallShield\UpdateService\issch.exeC:\Program Files\Dell\MediaDirect\PCMService.exeC:\Program Files\Adobe\Adobe Photoshop Lightroom 1.3\apdproxy.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\PowerISO\PWRISOVM.EXEC:\Program Files\Java\jre6\bin\jusched.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Digital Line Detect\DLG.exeC:\Documents and Settings\Clint\My Documents\Downloaded Files\HiJackThis.exeC:\Program Files\Mozilla Firefox\firefox.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3071221R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3071221R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localO1 - Hosts: 67.192.51.202 stage.auctionsound.netO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exeO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installquietO4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,StartO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exeO4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exeO4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exeO4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exeO4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startupO4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -startO4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.3\apdproxy.exe"O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXEO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exeO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exeO23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exeO23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE--End of file - 6274 bytesNow I'm stuck, getting run dll errors on startup regarding 2 files that were removed by malwarebytes.. please help! Quote Link to post Share on other sites
clintz Posted December 2, 2008 Author Report Share Posted December 2, 2008 Ran ComboFix, and here is the log...ComboFix 08-12-01.03 - Clint 2008-12-02 10:49:55.1 - NTFSx86Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1676 [GMT -5:00]Running from: c:\documents and settings\Clint\My Documents\Downloaded Files\ComboFix.exe * Created a new restore pointWARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).c:\documents and settings\Clint\Application Data\inst.exe.((((((((((((((((((((((((( Files Created from 2008-11-02 to 2008-12-02 ))))))))))))))))))))))))))))))).2008-12-02 10:25 . 2008-12-02 10:25 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware2008-12-02 10:25 . 2008-12-02 10:25 <DIR> d-------- c:\documents and settings\Clint\Application Data\Malwarebytes2008-12-02 10:25 . 2008-12-02 10:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes2008-12-02 10:25 . 2008-10-22 16:28 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys2008-12-02 10:25 . 2008-10-22 16:28 15,504 --a------ c:\windows\system32\drivers\mbam.sys2008-12-02 10:21 . 2008-12-02 10:20 410,976 --a------ c:\windows\system32\deploytk.dll2008-12-02 10:21 . 2008-12-02 10:20 73,728 --a------ c:\windows\system32\javacpl.cpl2008-12-01 17:50 . 2008-12-01 17:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\Codemasters2008-12-01 17:12 . 2008-04-28 15:53 805,400 -ra------ c:\windows\system32\tmpA4B.tmp2008-12-01 17:12 . 2008-04-28 15:53 805,400 -ra------ c:\windows\system32\tmpA4A.tmp2008-12-01 16:51 . 2008-12-01 16:51 <DIR> d-------- c:\program files\Codemasters2008-11-26 14:21 . 2008-11-26 14:21 <DIR> d-------- c:\windows\system32\Adobe2008-11-21 12:44 . 2008-11-28 23:07 183,112 --a------ c:\windows\system32\PnkBstrB.exe2008-11-21 12:44 . 2008-11-28 23:08 138,184 --a------ c:\windows\system32\drivers\PnkBstrK.sys2008-11-21 12:44 . 2008-11-21 13:01 66,872 --a------ c:\windows\system32\PnkBstrA.exe2008-11-19 14:56 . 2008-11-19 14:56 <DIR> d-------- c:\documents and settings\Clint\Application Data\Leadertech2008-11-19 14:43 . 2008-11-19 14:43 <DIR> d-------- c:\program files\EA Games2008-11-12 14:25 . 2008-09-04 12:15 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll2008-11-12 14:25 . 2008-10-24 06:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2008-12-02 15:20 --------- d-----w c:\program files\Java2008-12-02 15:10 --------- d-----w c:\documents and settings\Clint\Application Data\.purple2008-12-02 14:30 --------- d-----w c:\program files\Mozilla Thunderbird2008-12-01 22:24 --------- d-----w c:\documents and settings\Clint\Application Data\uTorrent2008-12-01 22:12 444,952 ----a-w c:\windows\system32\wrap_oal.dll2008-12-01 22:12 109,080 ----a-w c:\windows\system32\OpenAL32.dll2008-12-01 22:12 --------- d-----w c:\program files\OpenAL2008-12-01 21:51 --------- d--h--w c:\program files\InstallShield Installation Information2008-11-26 19:17 --------- d-----w c:\documents and settings\Clint\Application Data\Vso2008-11-24 15:56 --------- d-----w c:\documents and settings\Clint\Application Data\GrabIt2008-11-21 17:41 --------- d-----w c:\documents and settings\Clint\Application Data\gtk-2.02008-11-05 21:54 --------- d-----w c:\documents and settings\Clint\Application Data\OpenOffice.org22008-11-04 17:59 --------- d-----w c:\documents and settings\Clint\Application Data\FileZilla2008-10-28 13:19 --------- d-----w c:\program files\Pidgin2008-10-28 13:18 --------- d-----w c:\program files\Common Files\GTK2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys2008-10-20 14:36 256 ----a-w c:\documents and settings\Clint\pool.bin2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll2008-10-16 19:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll2008-10-16 19:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll2008-10-16 19:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll2008-10-16 19:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe2008-10-16 19:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll2008-10-16 19:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll2008-10-15 16:34 337,408 ------w c:\windows\system32\dllcache\netapi32.dll2008-10-03 17:41 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll2008-09-30 21:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys2008-09-15 12:12 1,846,400 ------w c:\windows\system32\dllcache\win32k.sys2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll2008-09-10 01:14 1,307,648 ------w c:\windows\system32\dllcache\msxml6.dll2008-09-08 10:41 333,824 ------w c:\windows\system32\dllcache\srv.sys2008-09-06 03:30 241,704 ------w c:\windows\system32\dllcache\wgaLogon.dll2008-09-06 03:29 917,032 ------w c:\windows\system32\dllcache\WgaTray.exe2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll2008-07-09 19:17 47,360 ----a-w c:\documents and settings\Clint\Application Data\pcouffin.sys.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-09-23 159744]"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-23 8466432]"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-23 81920]"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-05-09 1392640]"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-09-07 1236992]"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]"Adobe Photo Downloader"="c:\program files\Adobe\Adobe Photoshop Lightroom 1.3\apdproxy.exe" [2007-11-05 61440]"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-06-16 167936]"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-02 136600]"nwiz"="nwiz.exe" [2007-09-23 c:\windows\system32\nwiz.exe]"NVHotkey"="nvHotkey.dll" [2007-09-23 c:\windows\system32\nvhotkey.dll]"SigmatelSysTrayApp"="stsystra.exe" [2007-09-16 c:\windows\stsystra.exe]c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-20 50688][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]@="Driver"[HKEY_LOCAL_MACHINE\software\microsoft\security center]"AntiVirusDisableNotify"=dword:00000001"UpdatesDisableNotify"=dword:00000001[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]"EnableFirewall"= 0 (0x0)[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"="c:\\Program Files\\uTorrent\\uTorrent.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe"="c:\\Program Files\\Bonjour\\mDNSResponder.exe"="c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=*Newly Created Service* - PROCEXP90.- - - - ORPHANS REMOVED - - - -MSConfigStartUp-NodLogin - c:\program files\ESET\ESET NOD32 Antivirus\nodlogin.exe.------- Supplementary Scan -------.FireFox -: Profile - c:\documents and settings\Clint\Application Data\Mozilla\Firefox\Profiles\pffffdoc.default\FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dllFF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dllFF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll..------- File Associations -------.txtfile=notepad.exe "%1".**************************************************************************catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-12-02 10:54:33Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ...scanning hidden files ... **************************************************************************.Completion time: 2008-12-02 10:56:19ComboFix-quarantined-files.txt 2008-12-02 15:55:02Pre-Run: 17,120,411,648 bytes freePost-Run: 18,738,995,200 bytes free151 --- E O F --- 2008-11-12 19:56:37 Quote Link to post Share on other sites
clintz Posted December 2, 2008 Author Report Share Posted December 2, 2008 (edited) I ended up finding this link which is the exact issue I'm seeing. took care of it for now, I hope someone gets to the root of the issue though..http://forums.mozillazine.org/viewtopic Edited December 2, 2008 by Clint Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.