Help - Search - Members - Calendar
Full Version: infected with psw game trojan
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
korb
hi,i have used twister antivirus,malewarebite and sas to scanned and quarantine most of the psw game trojan,but still having problem with some .exe trying to run in my system

here is my log file.thanks in advance

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:53:23 PM, on 6/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\geswall\gswserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SuRun.exe
C:\Program Files\geswall\gswui.exe
C:\WINDOWS\pbfz.exe
C:\WINDOWS\system32\explorer.exe
C:\Program Files\Filseclab\Twister\twister.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Filseclab\FilMsg.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\System32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Program Files\geswall\gswui.exe,
O2 - BHO: tisqatyu.dll - {18093456-9012-4568-9076-908765467181} - C:\WINDOWS\system32\tisqatyu.dll (file missing)
O2 - BHO: ietzbpaq.dll - {29109876-7619-9101-7012-901938475192} - C:\WINDOWS\system32\ietzbpaq.dll (file missing)
O2 - BHO: cdwsbkop.dll - {2A095412-A568-B258-C587-D148E148F0A2} - C:\WINDOWS\system32\cdwsbkop.dll (file missing)
O2 - BHO: apzhbtde.dll - {2D698451-2015-6358-9871-2015987452D2} - C:\WINDOWS\system32\apzhbtde.dll (file missing)
O2 - BHO: skqncbib.dll - {32023698-6984-8541-9654-698745012523} - C:\WINDOWS\system32\skqncbib.dll (file missing)
O2 - BHO: yxcschlp.dll - {35671234-7890-ABCD-CDEF-567801237653} - C:\WINDOWS\system32\yxcschlp.dll (file missing)
O2 - BHO: nhmxcjkl.dll - {37AC9076-C898-B098-D098-A18319080973} - C:\WINDOWS\system32\nhmxcjkl.dll (file missing)
O2 - BHO: mpmydapi.dll - {4629FF4F-ACDB-5C90-A098-FACB3456A264} - C:\WINDOWS\system32\mpmydapi.dll (file missing)
O2 - BHO: lofsdjbo.dll - {470165F1-9F65-569F-F895-F14F58F41074} - C:\WINDOWS\system32\lofsdjbo.dll (file missing)
O2 - BHO: zycbdime.dll - {4A698102-5904-AFD0-20DF-CD1A65829CA4} - C:\WINDOWS\system32\zycbdime.dll (file missing)
O2 - BHO: mndhddwd.dll - {4C648541-1025-9650-9057-6541258720C4} - C:\WINDOWS\system32\mndhddwd.dll (file missing)
O2 - BHO: zptlcsys.dll - {50940F85-F015-14F1-A05F-F69858AC6D05} - C:\WINDOWS\system32\zptlcsys.dll (file missing)
O2 - BHO: ptjhehlp.dll - {528DF602-9541-A985-210A-984A698C6F25} - C:\WINDOWS\system32\ptjhehlp.dll (file missing)
O2 - BHO: mpwdeapi.dll - {55694105-5108-9405-3695-954187462155} - C:\WINDOWS\system32\mpwdeapi.dll (file missing)
O2 - BHO: ozfyebyt.dll - {5A069845-2036-6084-9054-6087502480A5} - C:\WINDOWS\system32\ozfyebyt.dll (file missing)
O2 - BHO: oohxdbyt.dll - {5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5} - C:\WINDOWS\system32\oohxdbyt.dll (file missing)
O2 - BHO: apsgejba.dll - {5FD45A54-9875-698F-E56E-65102358FDF5} - C:\WINDOWS\system32\apsgejba.dll (file missing)
O2 - BHO: zywmfime.dll - {6319A1F1-9410-9654-3201-345FFA349136} - C:\WINDOWS\system32\zywmfime.dll (file missing)
O2 - BHO: zxmscwin.dll - {6A041F13-A111-12A3-B0CF-F99818AA68A6} - C:\WINDOWS\system32\zxmscwin.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: mndsgsrv.dll - {77FD640A-158F-48AC-FD14-1597F14A9777} - C:\WINDOWS\system32\mndsgsrv.dll (file missing)
O2 - BHO: mnmhgsrv.dll - {7C8D1401-A58D-A81C-CD24-A5915C4517C7} - C:\WINDOWS\system32\mnmhgsrv.dll (file missing)
O2 - BHO: ypdjfbmp.dll - {81954FAC-1023-154F-895A-1458258AD818} - C:\WINDOWS\system32\ypdjfbmp.dll (file missing)
O2 - BHO: yxfhcjpg.dll - {83BA45AF-FAAA-CDDD-BEEE-BCDE1234AB38} - C:\WINDOWS\system32\yxfhcjpg.dll (file missing)
O2 - BHO: zxptejpg.dll - {91698482-6555-3666-1222-954784129019} - C:\WINDOWS\system32\zxptejpg.dll (file missing)
O2 - BHO: yzztimsn.dll - {9490415F-65F8-B5C5-D8BA-9405FB120549} - C:\WINDOWS\system32\yzztimsn.dll (file missing)
O2 - BHO: zyzxjime.dll - {AA59145F-315D-BC23-AC1F-145DF81A34AA} - C:\WINDOWS\system32\zyzxjime.dll (file missing)
O4 - HKLM\..\Run: [SuRun System Menu Extension] C:\WINDOWS\SuRun.exe /SYSMENUHOOK
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Twister] "C:\Program Files\Filseclab\Twister\twister.exe" -a
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Filseclab Messenger.lnk = ?
O8 - Extra context menu item: FlashSprite - C:\Program Files\Besta\PSH2.0\BFS\ie.htm
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: FlashSprite - {51f101a6-3884-4eb7-a832-340ba9104288} - C:\Program Files\Besta\PSH2.0\BFS\ie.htm (file missing)
O9 - Extra 'Tools' menuitem: FlashSprite - {51f101a6-3884-4eb7-a832-340ba9104288} - C:\Program Files\Besta\PSH2.0\BFS\ie.htm (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: C4BD72E6 - Unknown owner - C:\WINDOWS\system32\BD42264.EXE (file missing)
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: GeSWall service (gswserv) - GentleSecurity S.a.r.l. - C:\Program Files\geswall\gswserv.exe
O23 - Service: Super User Run (SuRun) Service - http://kay-bruns.de - C:\WINDOWS\SuRun.exe

--
End of file - 7330 bytes
LoPhatPhuud
First:
Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application. (If using Windows Vista, be sure to "Run As Administrator")
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Acan" option is selected.
    • Then click on the Scan button.
  • The next screen will ask you to select the drives to scan. Leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Second:
Download Combofix from any of the links below, and save it to your desktop. For information regarding this download, please visit this webpage: http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
    When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.


Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall

korb
hi admin, just follow your instruction,below are the log file
still one suspisious process running C:\WINDOWS\ybef.exe. thanks




ComboFix 08-06-12.2 - kob 2008-06-15 20:20:01.1 - NTFSx86
Running from: C:\Documents and Settings\kob\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\ciwdaapi.sys
C:\windows\system32\explorer.exe
C:\WINDOWS\system32\fstlbsys.sys
C:\WINDOWS\system32\fxwmbime.sys
C:\WINDOWS\system32\fxzxbime.sys
C:\WINDOWS\system32\fzmsbwin.sys
C:\WINDOWS\system32\fzptbjpg.sys
C:\WINDOWS\system32\gpsgajba.sys
C:\WINDOWS\system32\gsdhadwd.sys
C:\WINDOWS\system32\ijsgajba.sys
C:\WINDOWS\system32\jashbbty.sys
C:\WINDOWS\system32\pmjhbhlp.sys
C:\WINDOWS\system32\pzwmaime.sys
C:\WINDOWS\system32\smhxbbyt.sys
C:\WINDOWS\system32\smmhbsrv.sys
C:\WINDOWS\system32\spmybapi.sys
C:\WINDOWS\system32\spwdbapi.sys
C:\WINDOWS\system32\toqnabib.sys
C:\WINDOWS\system32\wymxajkl.sys
C:\WINDOWS\system32\xfztbmsn.sys
C:\WINDOWS\system32\xzcsbhlp.sys
C:\WINDOWS\system32\xzfhbjpg.sys

Infected copy of C:\WINDOWS\explorer.exe was found & disinfected
Restored copy from - C:\WINDOWS\system32\dllcache\explorer.exe


.
((((((((((((((((((((((((( Files Created from 2008-05-15 to 2008-06-15 )))))))))))))))))))))))))))))))
.

2008-06-15 20:20 . 2004-08-04 00:56 1,032,192 --a------ C:\WINDOWS\ybef.exe
2008-06-15 20:20 . 2008-06-15 20:20 6,736 --a------ C:\WINDOWS\system32\drivers\PROCEXP90.SYS
2008-06-15 19:41 . 2004-08-04 00:56 1,032,192 --a------ C:\WINDOWS\knpp.exe
2008-06-14 23:32 . 2008-06-14 23:39 <DIR> d-------- C:\Program Files\MegauploadToolbar
2008-06-14 23:32 . 2008-06-15 20:17 <DIR> d-------- C:\Documents and Settings\kob\Application Data\MegauploadToolbar
2008-06-14 22:40 . 2008-06-14 22:40 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-11 22:16 . 2008-06-11 22:16 1,215 --a------ C:\tmp.dat
2008-06-11 21:56 . 2008-06-11 21:56 <DIR> d-------- C:\Documents and Settings\warren\Application Data\Comodo
2008-06-11 21:26 . 2008-06-11 21:26 <DIR> d-------- C:\Program Files\COMODO
2008-06-11 21:26 . 2008-06-11 21:26 <DIR> d-------- C:\Documents and Settings\kob\Application Data\Comodo
2008-06-11 21:26 . 2008-06-11 21:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-06-11 21:26 . 2008-06-11 21:26 143,104 --a------ C:\WINDOWS\system32\guard32.dll
2008-06-11 21:26 . 2008-06-11 21:26 87,056 --a------ C:\WINDOWS\system32\drivers\cmdguard.sys
2008-06-11 21:26 . 2008-06-11 21:26 24,208 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-06-11 20:52 . 2008-06-11 20:52 38 --a------ C:\WINDOWS\avisplitter.INI
2008-06-11 20:09 . 2008-06-11 20:38 <DIR> d-------- C:\WINDOWS\geswall
2008-06-11 20:09 . 2008-06-11 20:38 <DIR> d-------- C:\Program Files\geswall
2008-06-11 18:53 . 2008-06-11 18:53 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-06-11 18:53 . 2008-06-11 18:53 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-11 18:53 . 2008-06-11 18:53 <DIR> d-------- C:\Documents and Settings\kob\Application Data\SUPERAntiSpyware.com
2008-06-11 18:53 . 2008-06-11 18:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-11 11:34 . 2008-06-11 11:34 <DIR> d-------- C:\Program Files\QT Lite
2008-06-11 11:34 . 2008-06-11 11:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-11 11:34 . 2008-05-27 10:50 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-06-11 11:34 . 2008-05-27 10:50 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-06-11 11:14 . 2008-06-11 11:15 <DIR> d-------- C:\Documents and Settings\kob\Application Data\DivX
2008-06-11 10:41 . 2008-06-11 10:41 <DIR> d-------- C:\Documents and Settings\kob\Application Data\vlc
2008-06-11 10:39 . 2008-06-11 10:39 <DIR> d-------- C:\Program Files\VideoLAN
2008-06-08 11:06 . 2008-06-11 22:13 24 --a------ C:\WINDOWS\system32\qbhxaklo.sys
2008-06-08 11:06 . 2008-06-11 22:13 24 --a------ C:\WINDOWS\system32\ijzhatde.sys
2008-06-08 11:05 . 2008-06-11 20:00 1,032,192 --a------ C:\WINDOWS\system32\explorera.exe
2008-06-04 20:08 . 2008-06-04 20:09 <DIR> d-------- C:\Program Files\Image Grabber II
2008-06-04 13:21 . 2008-06-04 13:21 <DIR> d-------- C:\Documents and Settings\kob\Application Data\DefenseWall HIPS
2008-06-04 00:45 . 2008-06-04 00:45 <DIR> d-------- C:\Program Files\Filseclab
2008-06-04 00:45 . 2008-06-04 10:31 <DIR> d-------- C:\Program Files\Common Files\Filseclab
2008-06-03 22:15 . 2008-06-03 22:15 72,192 -ra------ C:\WINDOWS\cadkasdeinst01e.exe
2008-06-03 11:33 . 2008-06-03 11:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Martau
2008-06-03 11:32 . 2008-06-03 11:32 <DIR> d-------- C:\Program Files\Total Uninstall 4
2008-05-29 20:12 . 2008-05-29 20:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\4D
2008-05-27 16:01 . 2008-05-27 16:01 <DIR> d-------- C:\Documents and Settings\warren\Application Data\Samsung
2008-05-27 15:49 . 2006-05-03 22:53 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2008-05-27 15:47 . 2008-05-27 15:59 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2008-05-27 15:38 . 2008-05-27 15:38 <DIR> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2008-05-27 15:38 . 2007-05-02 11:12 109,704 --a------ C:\WINDOWS\system32\drivers\ssm_mdm.sys
2008-05-27 15:38 . 2007-05-02 11:12 83,592 --a------ C:\WINDOWS\system32\drivers\ssm_bus.sys
2008-05-27 15:38 . 2007-05-02 11:12 15,112 --a------ C:\WINDOWS\system32\drivers\ssm_mdfl.sys
2008-05-27 15:38 . 2007-05-02 11:12 12,424 --a------ C:\WINDOWS\system32\drivers\ssm_whnt.sys
2008-05-27 15:38 . 2007-05-02 11:12 12,424 --a------ C:\WINDOWS\system32\drivers\ssm_wh.sys
2008-05-27 15:38 . 2007-05-02 11:12 12,424 --a------ C:\WINDOWS\system32\drivers\ssm_cmnt.sys
2008-05-27 15:38 . 2007-05-02 11:12 12,424 --a------ C:\WINDOWS\system32\drivers\ssm_cm.sys
2008-05-27 15:38 . 2005-08-28 20:51 766 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-05-27 15:37 . 2008-05-27 15:37 <DIR> d-------- C:\Program Files\Samsung
2008-05-23 17:05 . 2008-05-23 17:05 <DIR> d-------- C:\Program Files\Common Files\SourceTec
2008-05-23 17:05 . 2007-09-27 08:00 1,233,920 --a------ C:\WINDOWS\system32\msxml4.dll
2008-05-23 17:05 . 2007-09-27 08:00 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2008-05-23 17:05 . 2007-09-27 08:00 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-05-23 17:04 . 2008-05-23 17:04 <DIR> d-------- C:\Program Files\SourceTec
2008-05-22 22:14 . 2008-05-22 22:14 <DIR> d-------- C:\Documents and Settings\kob\Application Data\Shinycore
2008-05-22 13:50 . 2008-05-22 13:54 <DIR> d-------- C:\Documents and Settings\warren\Application Data\PhotoChances
2008-05-22 13:49 . 1999-12-17 09:13 86,016 --a------ C:\WINDOWS\unvise32.exe
2008-05-19 13:05 . 2008-05-19 13:05 <DIR> d-------- C:\Documents and Settings\kob\DoctorWeb
2008-05-19 12:50 . 2008-05-27 15:36 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-05-19 12:49 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-19 12:49 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-15 04:44 --------- d-----w C:\Documents and Settings\kob\Application Data\foobar2000
2008-06-12 04:22 --------- d-----w C:\Program Files\Opera
2008-06-11 12:36 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-06-11 03:31 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-06-11 02:31 --------- d-----w C:\Documents and Settings\kob\Application Data\OpenOffice.org2
2008-06-10 15:58 --------- d-----w C:\Documents and Settings\warren\Application Data\foobar2000
2008-06-07 03:12 --------- d-----w C:\Documents and Settings\kob\Application Data\UltraGet
2008-06-04 02:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\ulslirin
2008-06-03 16:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-03 02:54 --------- d-----w C:\Documents and Settings\warren\Application Data\Auslogics
2008-06-02 15:55 --------- d---a-w C:\Program Files\CCleaner
2008-05-29 11:58 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-22 05:51 --------- d-----w C:\Program Files\Replay Converter
2008-05-09 09:45 --------- d-----w C:\Program Files\Haali
2008-05-09 09:37 --------- d-----w C:\Documents and Settings\warren\Application Data\Media Player Classic
2008-05-09 09:33 --------- d-----w C:\Program Files\BurnAware Free Edition
2008-05-08 12:18 --------- d-----w C:\Program Files\Almeza
2008-05-05 04:15 --------- d-----w C:\Documents and Settings\warren\Application Data\OpenOffice.org2
2008-05-05 04:11 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-05-05 04:10 --------- d-----w C:\Program Files\Java
2008-05-04 06:54 --------- d-----w C:\Program Files\RingJone
2008-04-28 09:38 --------- d-----w C:\Documents and Settings\kob\Application Data\Malwarebytes
2004-08-08 14:07 520 --sh--w C:\WINDOWS\system32\aoqnabib.sys
2005-07-14 19:31 27,648 --sha-w C:\WINDOWS\system32\AVSredirect.dll
2004-08-08 14:07 520 --sh--w C:\WINDOWS\system32\cgsqatyu.sys
2005-06-26 22:32 616,448 --sha-r C:\WINDOWS\system32\cygwin1.dll
2004-08-08 14:06 7,280 --sh--w C:\WINDOWS\system32\fxcbbime.sys
2004-08-08 14:07 6,240 --sh--w C:\WINDOWS\system32\ghwsbkop.sys
2004-08-08 12:19 520 --sh--w C:\WINDOWS\system32\gpfoadet.sys
2004-08-08 14:06 1,040 --sh--w C:\WINDOWS\system32\gpzhatde.sys
2004-08-08 14:07 520 --sh--w C:\WINDOWS\system32\nttzapaq.sys
2004-08-08 14:07 1,040 --sh--w C:\WINDOWS\system32\rnmxajkl.sys
2004-08-08 14:06 1,040 --sh--w C:\WINDOWS\system32\smdsbsrv.sys
2004-08-08 14:07 520 --sh--w C:\WINDOWS\system32\snfybbyt.sys
2004-08-08 14:07 7,280 --sh--w C:\WINDOWS\system32\vlhxaklo.sys
2004-08-08 14:07 7,280 --sh--w C:\WINDOWS\system32\xbfsbjbo.sys
2004-08-08 14:07 1,560 --sh--w C:\WINDOWS\system32\xscqbhlp.sys
2004-08-08 14:06 7,800 --sh--w C:\WINDOWS\system32\xsdjbbmp.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{29109876-7619-9101-7012-901938475192}]
C:\WINDOWS\system32\ietzbpaq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5A069845-2036-6084-9054-6087502480A5}]
C:\WINDOWS\system32\ozfyebyt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{77FD640A-158F-48AC-FD14-1597F14A9777}]
C:\WINDOWS\system32\mndsgsrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GeSWall]
@={F6ACC71C-420B-4a95-905C-C7534706813C}

[HKEY_CLASSES_ROOT\CLSID\{F6ACC71C-420B-4a95-905C-C7534706813C}]
2008-01-18 21:31 815104 --a------ C:\Program Files\geswall\gswshext.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuRun System Menu Extension"="C:\WINDOWS\SuRun.exe" [2008-03-11 17:13 319488]
"Twister"="C:\Program Files\Filseclab\Twister\twister.exe" [2008-01-01 17:49 565248]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-06-11 21:26 1655552]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:56 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Filseclab Messenger.lnk - C:\Program Files\Common Files\Filseclab\FilMsg.exe [2008-06-04 00:45:51 319488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{2C7B6088-5A77-4d48-BE43-30337DCA9A86}"= SuRunExt.dll [ ]
"{F6ACC71C-420B-4a95-905C-C7534706813C}"= C:\Program Files\geswall\gswshext.dll [2008-01-18 21:31 815104]
"{5A069845-2036-6084-9054-6087502480A5}"= C:\WINDOWS\system32\ozfyebyt.dll [ ]
"{29109876-7619-9101-7012-901938475192}"= C:\WINDOWS\system32\ietzbpaq.dll [ ]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]
"{77FD640A-158F-48AC-FD14-1597F14A9777}"= C:\WINDOWS\system32\mndsgsrv.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= L3codecp.acm

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R0 GeSWall;GeSWall;C:\WINDOWS\system32\drivers\GeSWall.sys [2008-01-03 08:33]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-06-11 21:26]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-06-11 21:26]
R1 filar;Filseclab Dynamic Defense System Driver;C:\PROGRA~1\COMMON~1\FILSEC~1\filar.sys [2007-12-18 17:56]
R3 filpp;filpp;C:\PROGRA~1\COMMON~1\FILSEC~1\filpp.sys [2007-12-19 21:47]
R3 IMMDRV;IMMDRV;C:\PROGRA~1\FILSEC~1\Twister\immdrv.sys [2007-11-26 20:24]
S2 C4BD72E6;C4BD72E6;C:\WINDOWS\system32\BD42264.EXE []
S2 gswserv;GeSWall service;"C:\Program Files\geswall\gswserv.exe" [2008-01-19 22:21]
S2 Super User Run (SuRun) Service;Super User Run (SuRun) Service;C:\WINDOWS\SuRun.exe [2008-03-11 17:13]
S3 devkxrmsghookdrv;kX-Ray Msg Hook Enum Drv;C:\WINDOWS\system32\drivers\kxrmsghookdrv.sys [2005-06-10 20:56]

*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-15 20:22:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\geswall\gswshext.dll
.
Completion time: 2008-06-15 20:24:58
ComboFix-quarantined-files.txt 2008-06-15 12:24:27

Pre-Run: 21,608,628,224 bytes free
Post-Run: 21,592,686,592 bytes free

213



---------------------------------------------------------------------------

hjt log




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:28:05 PM, on 6/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
E:\software\security\utilities\ProcX.exe
C:\WINDOWS\ybef.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: ietzbpaq.dll - {29109876-7619-9101-7012-901938475192} - C:\WINDOWS\system32\ietzbpaq.dll (file missing)
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: ozfyebyt.dll - {5A069845-2036-6084-9054-6087502480A5} - C:\WINDOWS\system32\ozfyebyt.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: mndsgsrv.dll - {77FD640A-158F-48AC-FD14-1597F14A9777} - C:\WINDOWS\system32\mndsgsrv.dll (file missing)
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [SuRun System Menu Extension] C:\WINDOWS\SuRun.exe /SYSMENUHOOK
O4 - HKLM\..\Run: [Twister] "C:\Program Files\Filseclab\Twister\twister.exe" -a
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Filseclab Messenger.lnk = ?
O8 - Extra context menu item: FlashSprite - C:\Program Files\Besta\PSH2.0\BFS\ie.htm
O8 - Extra context menu item: Post Image to Blog - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\Program Files\ImageShackToolbar\ImageShackToolbar.dll/5001
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: FlashSprite - {51f101a6-3884-4eb7-a832-340ba9104288} - C:\Program Files\Besta\PSH2.0\BFS\ie.htm (file missing)
O9 - Extra 'Tools' menuitem: FlashSprite - {51f101a6-3884-4eb7-a832-340ba9104288} - C:\Program Files\Besta\PSH2.0\BFS\ie.htm (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: C4BD72E6 - Unknown owner - C:\WINDOWS\system32\BD42264.EXE (file missing)
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: GeSWall service (gswserv) - GentleSecurity S.a.r.l. - C:\Program Files\geswall\gswserv.exe
O23 - Service: Super User Run (SuRun) Service - http://kay-bruns.de - C:\WINDOWS\SuRun.exe

--
End of file - 4702 bytes
LoPhatPhuud
There is also a log file with MBAM that I need to see. See my previous instructions. Please take the time to completely read the instructions to avoid unnecessary delays in fixing your computer.
korb
ok here is the log


Malwarebytes' Anti-Malware 1.17
Database version: 856

8:16:59 PM 6/15/2008
mbam-log-6-15-2008 (20-16-54).txt

Scan type: Quick Scan
Objects scanned: 40998
Time elapsed: 7 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 46
Registry Values Infected: 23
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{6319a1f1-9410-9654-3201-345ffa349136} (Spyware.Passwords) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6319a1f1-9410-9654-3201-345ffa349136} (Spyware.Passwords) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{35671234-7890-abcd-cdef-567801237653} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35671234-7890-abcd-cdef-567801237653} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{37ac9076-c898-b098-d098-a18319080973} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{37ac9076-c898-b098-d098-a18319080973} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{50940f85-f015-14f1-a05f-f69858ac6d05} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50940f85-f015-14f1-a05f-f69858ac6d05} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{55694105-5108-9405-3695-954187462155} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{55694105-5108-9405-3695-954187462155} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{5b1aef69-ddae-fdad-dcab-698f026abdb5} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5b1aef69-ddae-fdad-dcab-698f026abdb5} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{5fd45a54-9875-698f-e56e-65102358fdf5} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5fd45a54-9875-698f-e56e-65102358fdf5} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6a041f13-a111-12a3-b0cf-f99818aa68a6} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6a041f13-a111-12a3-b0cf-f99818aa68a6} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7c8d1401-a58d-a81c-cd24-a5915c4517c7} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7c8d1401-a58d-a81c-cd24-a5915c4517c7} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{83ba45af-faaa-cddd-beee-bcde1234ab38} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83ba45af-faaa-cddd-beee-bcde1234ab38} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9490415f-65f8-b5c5-d8ba-9405fb120549} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9490415f-65f8-b5c5-d8ba-9405fb120549} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{aa59145f-315d-bc23-ac1f-145df81a34aa} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{aa59145f-315d-bc23-ac1f-145df81a34aa} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2a095412-a568-b258-c587-d148e148f0a2} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2a095412-a568-b258-c587-d148e148f0a2} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{81954fac-1023-154f-895a-1458258ad818} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{81954fac-1023-154f-895a-1458258ad818} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4629ff4f-acdb-5c90-a098-facb3456a264} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4629ff4f-acdb-5c90-a098-facb3456a264} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2d698451-2015-6358-9871-2015987452d2} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2d698451-2015-6358-9871-2015987452d2} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{528df602-9541-a985-210a-984a698c6f25} (Spyware.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{528df602-9541-a985-210a-984a698c6f25} (Spyware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{91698482-6555-3666-1222-954784129019} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91698482-6555-3666-1222-954784129019} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{18093456-9012-4568-9076-908765467181} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18093456-9012-4568-9076-908765467181} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{32023698-6984-8541-9654-698745012523} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32023698-6984-8541-9654-698745012523} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{470165f1-9f65-569f-f895-f14f58f41074} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{470165f1-9f65-569f-f895-f14f58f41074} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4a698102-5904-afd0-20df-cd1a65829ca4} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4a698102-5904-afd0-20df-cd1a65829ca4} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{4c648541-1025-9650-9057-6541258720c4} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4c648541-1025-9650-9057-6541258720c4} (Trojan.Vundo) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6319a1f1-9410-9654-3201-345ffa349136} (Spyware.Passwords) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{35671234-7890-abcd-cdef-567801237653} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{37ac9076-c898-b098-d098-a18319080973} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{50940f85-f015-14f1-a05f-f69858ac6d05} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{55694105-5108-9405-3695-954187462155} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{5b1aef69-ddae-fdad-dcab-698f026abdb5} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{5fd45a54-9875-698f-e56e-65102358fdf5} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6a041f13-a111-12a3-b0cf-f99818aa68a6} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{7c8d1401-a58d-a81c-cd24-a5915c4517c7} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{83ba45af-faaa-cddd-beee-bcde1234ab38} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{9490415f-65f8-b5c5-d8ba-9405fb120549} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{aa59145f-315d-bc23-ac1f-145df81a34aa} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{2a095412-a568-b258-c587-d148e148f0a2} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{81954fac-1023-154f-895a-1458258ad818} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{4629ff4f-acdb-5c90-a098-facb3456a264} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{2d698451-2015-6358-9871-2015987452d2} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{528df602-9541-a985-210a-984a698c6f25} (Spyware.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{91698482-6555-3666-1222-954784129019} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{18093456-9012-4568-9076-908765467181} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{32023698-6984-8541-9654-698745012523} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{470165f1-9f65-569f-f895-f14f58f41074} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{4a698102-5904-afd0-20df-cd1a65829ca4} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{4c648541-1025-9650-9057-6541258720c4} (Trojan.Vundo) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
LoPhatPhuud
First:
1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
KillAll::

File::
C:\WINDOWS\ybef.exe
C:\WINDOWS\knpp.exe
C:\WINDOWS\system32\qbhxaklo.sys
C:\WINDOWS\system32\ijzhatde.sys
C:\WINDOWS\system32\explorera.exe
C:\WINDOWS\cadkasdeinst01e.exe
C:\WINDOWS\system32\aoqnabib.sys
C:\WINDOWS\system32\cgsqatyu.sys
C:\WINDOWS\system32\cygwin1.dll
C:\WINDOWS\system32\fxcbbime.sys
C:\WINDOWS\system32\ghwsbkop.sys
C:\WINDOWS\system32\gpfoadet.sys
C:\WINDOWS\system32\gpzhatde.sys
C:\WINDOWS\system32\nttzapaq.sys
C:\WINDOWS\system32\rnmxajkl.sys
C:\WINDOWS\system32\smdsbsrv.sys
C:\WINDOWS\system32\snfybbyt.sys
C:\WINDOWS\system32\vlhxaklo.sys
C:\WINDOWS\system32\xbfsbjbo.sys
C:\WINDOWS\system32\xscqbhlp.sys
C:\WINDOWS\system32\xsdjbbmp.sys
C:\WINDOWS\system32\ietzbpaq.dll
C:\WINDOWS\system32\ozfyebyt.dll
C:\WINDOWS\system32\mndsgsrv.dll

Registry::
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5A069845-2036-6084-9054-6087502480A5}"=-
"{29109876-7619-9101-7012-901938475192}"=-
"{77FD640A-158F-48AC-FD14-1597F14A9777}"=-


Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall



Second:

Run HiJackThis and press the Scan' button

When the scan is finished:
Check the following items in HijackThis.
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: ietzbpaq.dll - {29109876-7619-9101-7012-901938475192} - C:\WINDOWS\system32\ietzbpaq.dll (file missing)
O2 - BHO: ozfyebyt.dll - {5A069845-2036-6084-9054-6087502480A5} - C:\WINDOWS\system32\ozfyebyt.dll (file missing)
O2 - BHO: mndsgsrv.dll - {77FD640A-158F-48AC-FD14-1597F14A9777} - C:\WINDOWS\system32\mndsgsrv.dll (file missing)

Close all windows except HijackThis and click Fix checked.

Reboot in normal mode

Run HiJackThis again and post a new log in this thread.


Third:
Please submit the following file(s) to VirusTotal for analysis: http://virustotal.com

C:\WINDOWS\system32\BD42264.EXE


Be sure to post the results in this thread.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.