Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Antivirus XP 2008 virus  (Read 5353 times)

0 Members and 1 Guest are viewing this topic.

iainmac

    Topic Starter


    Rookie

    Antivirus XP 2008 virus
    « on: August 15, 2008, 11:03:32 AM »
    Hello again,

    I have been infected with this Antivirus XP 2008 nonsense.  It appears as a program in my add/remove control panel, but I cannot uninstall it.  I attempted to remove it using your guide but encountered the following problem:

    When I run SUPERAntiSpyware, it finds around 10 infected files, but then crashes during the scan and I get a blue screen of death (BOOT_STRAP error I think).

    I have run CCleaner and MBAM (log below) but to no avail.

    Please help!!

    Iain

    PS.  I have backed up some files from my infected computer onto my pen drive.  Can I now safely transport them on to my clean computer or could they infect it? (they are just word documents).

    iainmac

      Topic Starter


      Rookie

      Re: Antivirus XP 2008 virus
      « Reply #1 on: August 15, 2008, 11:03:59 AM »
      Malwarebytes' Anti-Malware 1.14
      Database version: 800

      16:47:09 15/08/2008
      mbam-log-8-15-2008 (16-47-09).txt

      Scan type: Quick Scan
      Objects scanned: 61291
      Time elapsed: 14 minute(s), 47 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 1
      Registry Values Infected: 1
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 1

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      C:\WINDOWS\system32\drivers\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Antivirus XP 2008 virus
      « Reply #2 on: August 15, 2008, 11:07:14 AM »
      I need the HijackThis log.

      iainmac

        Topic Starter


        Rookie

        Re: Antivirus XP 2008 virus
        « Reply #3 on: August 15, 2008, 11:43:08 AM »
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:45:08, on 15/08/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16705)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\McAfee.com\Agent\mcagent.exe
        C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
        C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
        C:\Program Files\Analog Devices\Core\smax4pnp.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\WINDOWS\system32\lphce9fj0e19v.exe
        C:\Program Files\rhca9fj0e19v\rhca9fj0e19v.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
        C:\WINDOWS\System32\WScript.exe
        C:\WINDOWS\system32\pphce9fj0e19v.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdiserv.exe
        C:\WINDOWS\system32\lxdicoms.exe
        C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        c:\program files\common files\mcafee\mna\mcnasvc.exe
        c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
        C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        C:\Program Files\McAfee\MPF\MPFSrv.exe
        C:\Program Files\McAfee\MSK\MskSrver.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\System32\svchost.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: McAfee Phishing Filter - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
        O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
        O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
        O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
        O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
        O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [RRT-Auto] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 1 for RRT.zip\RRT.exe auto
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
        O4 - HKLM\..\Run: [lphce9fj0e19v] C:\WINDOWS\system32\lphce9fj0e19v.exe
        O4 - HKLM\..\Run: [SMrhca9fj0e19v] C:\Program Files\rhca9fj0e19v\rhca9fj0e19v.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
        O4 - HKUS\S-1-5-21-1935655697-1682526488-839522115-1007\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'postgres')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
        O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet1\UltimateBet.exe
        O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet1\UltimateBet.exe
        O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Iain\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
        O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Iain\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
        O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1205523236343
        O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O21 - SSODL: KernelCD - {ed9f547e-7725-46f4-a938-95c4abb21edf} - C:\WINDOWS\Resources\KernelCD.dll (file missing)
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
        O23 - Service: lxdi_device -   - C:\WINDOWS\system32\lxdicoms.exe
        O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
        O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
        O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
        O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
        O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
        O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
        O23 - Service: PostgreSQL Database Server 8.2 (pgsql-8.2) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.2\bin\pg_ctl.exe
        O23 - Service: ThreatFire - Unknown owner - C:\Program Files\ThreatFire\TFService.exe (file missing)

        --
        End of file - 9772 bytes

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Antivirus XP 2008 virus
        « Reply #4 on: August 15, 2008, 11:58:48 AM »
        Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

        Link #1
        Link #2

        **Note:  It is important that it is saved directly to your Desktop

        Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

        Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
         
        Double click combofix.exe & follow the prompts.
        When finished ComboFix will produce a log for you.
        Post the ComboFix log and a new HijackThis log in your next reply.

        Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

        Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

        If you have problems with ComboFix usage, see How to use ComboFix

        ----------

        Next post add
        ComboFix log
        New HijackThis log

        iainmac

          Topic Starter


          Rookie

          Re: Antivirus XP 2008 virus
          « Reply #5 on: August 15, 2008, 12:21:08 PM »
          Done that.  It has removed the Antivirus XP 2008 program. Here are the logs:


          ComboFix 08-08-14.05 - Iain 2008-08-15 19:15:56.1 - NTFSx86
          Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.1547 [GMT 1:00]
          Running from: C:\Documents and Settings\Iain\Desktop\ComboFix.exe
           * Created a new restore point

          WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
          .

          (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
          .

          C:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
          C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
          C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
          C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
          C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
          C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
          C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
          C:\Documents and Settings\Iain\Application Data\rhca9fj0e19v
          C:\Documents and Settings\Kirsty\Cookies\[email protected][1].txt
          C:\Documents and Settings\Kirsty\Cookies\[email protected][1].txt
          C:\Documents and Settings\Kirsty\Cookies\[email protected][3].txt
          C:\Documents and Settings\Kirsty\Cookies\kirsty@chtah[2].txt
          C:\Documents and Settings\Kirsty\Cookies\[email protected][2].txt
          C:\Documents and Settings\Kirsty\Cookies\kirsty@fastclick[1].txt
          C:\Documents and Settings\Kirsty\Cookies\[email protected][1].txt
          C:\Documents and Settings\Kirsty\Cookies\kirsty@revsci[2].txt
          C:\Documents and Settings\Kirsty\Cookies\kirsty@serving-sys[2].txt
          C:\Documents and Settings\Kirsty\Cookies\kirsty@tsw0[3].txt
          C:\Documents and Settings\Kirsty\Cookies\[email protected][2].txt
          C:\Documents and Settings\Kirsty\Cookies\[email protected][1].txt
          C:\Documents and Settings\Kirsty\Cookies\[email protected][1].txt
          C:\Documents and Settings\Kirsty\Cookies\[email protected][1].txt
          C:\Documents and Settings\Kirsty\Cookies\[email protected][2].txt
          C:\Documents and Settings\Susanne\Application Data\macromedia\Flash Player\#SharedObjects\XMT9YWLM\interclick.com
          C:\Documents and Settings\Susanne\Application Data\macromedia\Flash Player\#SharedObjects\XMT9YWLM\interclick.com\ud.sol
          C:\Documents and Settings\Susanne\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
          C:\Documents and Settings\Susanne\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
          C:\Documents and Settings\Susanne\Cookies\[email protected][1].txt
          C:\Documents and Settings\Susanne\Cookies\[email protected][3].txt
          C:\Documents and Settings\Susanne\Cookies\susanne@ebay[3].txt
          C:\Documents and Settings\Susanne\Cookies\[email protected][2].txt
          C:\Documents and Settings\Susanne\Cookies\[email protected][2].txt
          C:\Documents and Settings\Susanne\Cookies\[email protected][1].txt
          C:\Documents and Settings\Susanne\Cookies\[email protected][1].txt
          C:\Documents and Settings\Susanne\Cookies\[email protected][2].txt
          C:\Documents and Settings\Susanne\Cookies\[email protected][1].txt
          C:\Documents and Settings\Susanne\Cookies\susanne@tsw0[2].txt
          C:\Documents and Settings\Susanne\Cookies\[email protected][2].txt
          C:\Documents and Settings\Susanne\Cookies\[email protected][3].txt
          C:\Documents and Settings\Susanne\Cookies\susanne@web-stat[2].txt
          C:\Documents and Settings\Susanne\Cookies\[email protected][3].txt
          C:\Documents and Settings\Susanne\Cookies\[email protected][1].txt
          C:\Program Files\rhca9fj0e19v
          C:\WINDOWS\system32\blphce9fj0e19v.scr
          C:\WINDOWS\system32\ffsfmpnc.ini
          C:\WINDOWS\system32\lphce9fj0e19v.exe
          C:\WINDOWS\system32\mcrh.tmp
          C:\WINDOWS\system32\phce9fj0e19v.bmp
          C:\WINDOWS\system32\pphce9fj0e19v.exe
          C:\WINDOWS\system32\PYIllUvw.ini
          C:\WINDOWS\system32\PYIllUvw.ini2
          C:\WINDOWS\system32\wimllcoh.ini

          .
          (((((((((((((((((((((((((   Files Created from 2008-07-15 to 2008-08-15  )))))))))))))))))))))))))))))))
          .

          2008-07-21 01:29 . 2008-07-22 01:05   <DIR>   d--------   C:\Program Files\PokerTracker 3
          2008-07-18 15:15 . 2008-07-18 15:16   <DIR>   d--------   C:\nav_update
          2008-07-18 15:01 . 2008-07-18 15:01   <DIR>   d--------   C:\Program Files\AvantGo Connect
          2008-07-18 15:01 . 2008-07-18 15:01   2,464   --a------   C:\WINDOWS\$_hpcst$.hpc
          2008-07-18 14:59 . 2008-07-18 14:59   <DIR>   d--hs----   C:\WINDOWS\ftpcache
          2008-07-18 13:02 . 2004-12-06 14:07   104,064   --a------   C:\WINDOWS\system32\drivers\wceusbsh.sys
          2008-07-18 13:02 . 2004-12-06 14:07   104,064   --a--c---   C:\WINDOWS\system32\dllcache\wceusbsh.sys
          2008-07-18 12:21 . 2004-08-03 22:58   14,848   --a------   C:\WINDOWS\system32\drivers\kbdhid.sys
          2008-07-18 12:21 . 2004-08-03 22:58   14,848   --a--c---   C:\WINDOWS\system32\dllcache\kbdhid.sys

          .
          ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-08-15 01:03   ---------   d-----w   C:\Program Files\McAfee
          2008-08-10 21:40   ---------   d---a-w   C:\Documents and Settings\All Users\Application Data\TEMP
          2008-08-10 21:39   ---------   d-----w   C:\Program Files\Full Tilt Poker
          2008-08-10 21:30   ---------   d-----w   C:\Program Files\PokerStars
          2008-08-07 18:57   ---------   d-----w   C:\Program Files\UltimateBet1
          2008-08-05 23:17   ---------   d-----w   C:\Documents and Settings\Iain\Application Data\LimeWire
          2008-07-19 17:31   ---------   d-----w   C:\Program Files\Java
          2008-07-18 16:44   ---------   d-----w   C:\Program Files\Poker Tracker V2
          2008-07-18 14:01   ---------   d-----w   C:\Program Files\Microsoft ActiveSync
          2008-07-14 03:31   ---------   d-----w   C:\Documents and Settings\Iain\Application Data\Microgaming
          2008-07-09 21:11   ---------   d-----w   C:\Program Files\Absolute Poker
          2008-07-07 20:32   253,952   ----a-w   C:\WINDOWS\system32\es.dll
          2008-07-05 18:58   ---------   d-----w   C:\Program Files\TryMedia
          2008-07-05 15:51   ---------   d-----w   C:\Documents and Settings\Iain\Application Data\SpinTop
          2008-07-03 18:26   ---------   d-----w   C:\Program Files\_uninstallation_info
          2008-07-03 18:10   ---------   d-----w   C:\Program Files\Bodog Poker
          2008-07-03 18:04   ---------   d-----w   C:\Program Files\MGS FF Helper
          2008-06-24 16:23   74,240   ----a-w   C:\WINDOWS\system32\mscms.dll
          2008-06-23 16:57   826,368   ----a-w   C:\WINDOWS\system32\wininet.dll
          2008-06-22 19:06   ---------   d-----w   C:\Program Files\MSN Messenger
          2008-06-20 17:41   245,248   ----a-w   C:\WINDOWS\system32\mswsock.dll
          2008-06-20 10:45   360,320   ----a-w   C:\WINDOWS\system32\drivers\tcpip.sys
          2008-06-20 10:44   138,368   ----a-w   C:\WINDOWS\system32\drivers\afd.sys
          2008-06-20 09:52   225,920   ----a-w   C:\WINDOWS\system32\drivers\tcpip6.sys
          .

          (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* empty entries & legit default entries are not shown
          REGEDIT4

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 14:56 15360]
          "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-04 11:50 405583]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-11-30 05:42 1164576]
          "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
          "lxdimon.exe"="C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-07-16 17:54 434864]
          "lxdiamon"="C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-07-16 17:54 25264]
          "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 15:42 1404928]
          "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-09 22:05 344064]
          "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
          "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
          "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
          "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-07 19:37 185632]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-12 14:56 15360]

          [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
          "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
          2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
          "MSACM.CEGSM"= mobilev.acm

          [HKEY_LOCAL_MACHINE\software\microsoft\security center]
          "AntiVirusDisableNotify"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
          "DisableMonitoring"=dword:00000001

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "C:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"=
          "C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"=
          "C:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"=
          "C:\\WINDOWS\\system32\\lxdicfg.exe"=
          "C:\\WINDOWS\\system32\\lxdicoms.exe"=
          "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"=
          "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"=
          "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"=
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
          "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
          "C:\\Program Files\\Messenger\\msmsgs.exe"=
          "C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
          "C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
          "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdiwbgw.exe"=
          "C:\\Program Files\\iTunes\\iTunes.exe"=
          "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
          "C:\\Program Files\\MSN Messenger\\livecall.exe"=

          R2 lxdi_device;lxdi_device;C:\WINDOWS\system32\lxdicoms.exe [2007-06-11 15:14]
          R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe [2007-06-11 15:14]
          R2 pgsql-8.2;PostgreSQL Database Server 8.2;C:\Program Files\PostgreSQL\8.2\bin\pg_ctl.exe runservice -w -N pgsql-8.2 -D C:\Program Files\PostgreSQL\8.2\data\ []
          S0 TfFsMon;TfFsMon;C:\WINDOWS\system32\drivers\TfFsMon.sys []
          S0 TfSysMon;TfSysMon;C:\WINDOWS\system32\drivers\TfSysMon.sys []
          S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
          S3 MBAMCatchMe;MBAMCatchMe;C:\WINDOWS\system32\drivers\mbamcatchme.sys [2008-05-30 01:06]
          S3 TfNetMon;TfNetMon;C:\WINDOWS\system32\drivers\TfNetMon.sys []
          .
          Contents of the 'Scheduled Tasks' folder

          2008-06-15 C:\WINDOWS\Tasks\McDefragTask.job
          - c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

          2008-08-01 C:\WINDOWS\Tasks\McQcTask.job
          - c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
          .
          - - - - ORPHANS REMOVED - - - -

          HKLM-Run-RRT-Auto - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 1 for RRT.zip\RRT.exe
          HKLM-Run-lphce9fj0e19v - C:\WINDOWS\system32\lphce9fj0e19v.exe
          HKLM-Run-SMrhca9fj0e19v - C:\Program Files\rhca9fj0e19v\rhca9fj0e19v.exe
          SSODL-KernelCD-{ed9f547e-7725-46f4-a938-95c4abb21edf} - C:\WINDOWS\Resources\KernelCD.dll


          .
          ------- Supplementary Scan -------
          .
          FireFox -: Profile - C:\Documents and Settings\Iain\Application Data\Mozilla\Firefox\Profiles\s6en2zv2.default\
          FireFox -: prefs.js - STARTUP.HOMEPAGE - www.yahoo.co.uk


          **************************************************************************

          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-08-15 19:19:49
          Windows 5.1.2600 Service Pack 2 NTFS

          scanning hidden processes ...

          scanning hidden autostart entries ...

          scanning hidden files ...

          scan completed successfully
          hidden files: 0

          **************************************************************************
          .
          ------------------------ Other Running Processes ------------------------
          .
          C:\WINDOWS\system32\ati2evxx.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdiserv.exe
          C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
          C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
          C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
          C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
          C:\Program Files\McAfee\MPF\MpfSrv.exe
          C:\Program Files\McAfee\MSK\msksrver.exe
          C:\Program Files\PostgreSQL\8.2\bin\pg_ctl.exe
          C:\Program Files\PostgreSQL\8.2\bin\postgres.exe
          C:\Program Files\PostgreSQL\8.2\bin\postgres.exe
          C:\Program Files\PostgreSQL\8.2\bin\postgres.exe
          C:\Program Files\PostgreSQL\8.2\bin\postgres.exe
          C:\Program Files\iPod\bin\iPodService.exe
          .
          **************************************************************************
          .
          Completion time: 2008-08-15 19:21:38 - machine was rebooted
          ComboFix-quarantined-files.txt  2008-08-15 18:21:31

          Pre-Run: 225,899,708,416 bytes free
          Post-Run: 226,272,829,440 bytes free

          213   --- E O F ---   2008-08-13 17:11:02

          iainmac

            Topic Starter


            Rookie

            Re: Antivirus XP 2008 virus
            « Reply #6 on: August 15, 2008, 12:21:36 PM »
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 19:23:10, on 15/08/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16705)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdiserv.exe
            C:\WINDOWS\system32\lxdicoms.exe
            C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
            c:\program files\common files\mcafee\mna\mcnasvc.exe
            c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
            C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
            C:\Program Files\McAfee\MPF\MPFSrv.exe
            C:\Program Files\McAfee\MSK\MskSrver.exe
            C:\Program Files\McAfee.com\Agent\mcagent.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
            C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
            C:\Program Files\Analog Devices\Core\smax4pnp.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
            C:\Program Files\iPod\bin\iPodService.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\explorer.exe
            C:\WINDOWS\system32\notepad.exe
            C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: McAfee Phishing Filter - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
            O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
            O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
            O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
            O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
            O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
            O4 - HKUS\S-1-5-21-1935655697-1682526488-839522115-1007\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'postgres')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
            O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
            O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
            O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet1\UltimateBet.exe
            O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet1\UltimateBet.exe
            O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Iain\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
            O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Iain\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU)
            O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1205523236343
            O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
            O23 - Service: lxdi_device -   - C:\WINDOWS\system32\lxdicoms.exe
            O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
            O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
            O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
            O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
            O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
            O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
            O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
            O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
            O23 - Service: PostgreSQL Database Server 8.2 (pgsql-8.2) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.2\bin\pg_ctl.exe
            O23 - Service: ThreatFire - Unknown owner - C:\Program Files\ThreatFire\TFService.exe (file missing)

            --
            End of file - 9351 bytes

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: Antivirus XP 2008 virus
            « Reply #7 on: August 15, 2008, 12:36:12 PM »
            Download OTMoveIt2 by OldTimer
            • Save it to your desktop.
            Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

            • Double-click OTMoveIt2.exe to run it.
            • Copy the lines in the codebox below.
            Code: [Select]
            [kill explorer]
            C:\nav_update
            EmptyTemp
            [start explorer]
            • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
            • Click the red Moveit! button.
            • Copy everything in the Results window (under the green bar) and paste it in your next reply.
            • Close OTMoveIt2
            .
            ----------

            Open HijackThis and select Do a system scan only.

            Place a check mark next to the following entries: (if there)

            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

            Important: Close all windows except for HijackThis and then click Fix checked.

            Exit HijackThis.

            ----------

            How is everything now?

            iainmac

              Topic Starter


              Rookie

              Re: Antivirus XP 2008 virus
              « Reply #8 on: August 15, 2008, 12:55:39 PM »
              I couldn't post what was in the results window because it prompted me to restart my machine when it was finished.

              Here is the log instead, hope it is just as useful.



              Explorer killed successfully
              C:\nav_update moved successfully.
              < EmptyTemp >
              File delete failed. C:\DOCUME~1\Iain\LOCALS~1\Temp\~e5.0001 scheduled to be deleted on reboot.
              File delete failed. C:\DOCUME~1\Iain\LOCALS~1\Temp\~e5.0001.dir.0000\~df394b.tmp scheduled to be deleted on reboot.
              File delete failed. C:\DOCUME~1\Iain\LOCALS~1\Temp\~e5.0001.dir.0000\~efe2.tmp scheduled to be deleted on reboot.
              File delete failed. C:\WINDOWS\temp\mcmsc_bPa1pLJOTHzUaHL scheduled to be deleted on reboot.
              File delete failed. C:\WINDOWS\temp\sqlite_bxIthif21ZvxxEe scheduled to be deleted on reboot.
              File delete failed. C:\WINDOWS\temp\sqlite_ye11UkYmj0yULdM scheduled to be deleted on reboot.
              Temp folders emptied.
              IE temp folders emptied.
              Explorer started successfully
               
              OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08152008_195429

              Files moved on Reboot...
              C:\DOCUME~1\Iain\LOCALS~1\Temp\~e5.0001 moved successfully.
              C:\DOCUME~1\Iain\LOCALS~1\Temp\~e5.0001.dir.0000\~df394b.tmp moved successfully.
              C:\DOCUME~1\Iain\LOCALS~1\Temp\~e5.0001.dir.0000\~efe2.tmp moved successfully.
              File C:\WINDOWS\temp\mcmsc_bPa1pLJOTHzUaHL not found!
              C:\WINDOWS\temp\sqlite_bxIthif21ZvxxEe moved successfully.
              C:\WINDOWS\temp\sqlite_ye11UkYmj0yULdM moved successfully.


              iainmac

                Topic Starter


                Rookie

                Re: Antivirus XP 2008 virus
                « Reply #9 on: August 15, 2008, 12:58:56 PM »
                My computer seems to be back to normal again. 

                Thanks for all your help,

                Iain

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: Antivirus XP 2008 virus
                « Reply #10 on: August 15, 2008, 01:08:15 PM »
                Let's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done.
                .
                • Click START then RUN
                • Now type Combofix /u in the runbox
                • Make sure there's a space between Combofix and /u
                • Then hit Enter.
                .
                .
                The above procedure will:
                • Delete:
                  • ComboFix and its associated files and folders.
                  • VundoFix backups, if present
                  • The C:\Deckard folder, if present
                  • The C:_OtMoveIt folder, if present
                  • Reset the clock settings.
                  • Hide file extensions, if required.
                  • Hide System/Hidden files, if required.
                  • Set a new, clean Restore Point.
                  .
                  ----------

                  1. Double click OTMoveIt2.exe to launch it.
                  Vista users right click and choose Run As Administrator
                  2. Click on the CleanUp! button.
                  3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
                  4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
                  5. Once complete exit out of OTMoveIt2

                  ----------

                  Set a New Restore Point to prevent possible reinfection from an old one
                  Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
                  • Go to Start > Programs > Accessories > System Tools and click System Restore
                  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
                  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
                  • Next go to Start > Run and type Cleanmgr
                  • Click OK
                  • Click the More Options Tab.
                  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
                  You can find instructions on how to enable and re-enable system restore here:

                  Windows XP System Restore Guide or Windows Vista System Restore Guide
                  .
                  ----------

                  Use the Secunia Software Inspector to check for out of date software.
                  • Click Start Now
                  • Check the box next to Enable thorough system inspection.
                  • Click Start
                  • Allow the scan to finish and scroll down to see if any updates are needed.
                  • Update anything listed.
                  .
                  ----------

                  Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.

                  If you are running any Microsoft Office version go to the Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

                  ----------

                  Please keep these programs up-to-date and run them whenever you suspect a problem. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster can be run with any of them.

                  Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

                  Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

                  To prevent unknown applications from being installed on your computer install WinPatrol 2008
                  * Using Winpatrol to protect your computer from malicious software

                  I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

                  SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
                  * Using SpywareBlaster to protect your computer from Spyware and Malware
                  * If you don't know what ActiveX controls are, see here

                  Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

                  Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.