Author Topic: Er......this really sucks. Help, please?  (Read 70282 times)

0 Members and 5 Guests are viewing this topic.


  • Guest
Re: Er......this really sucks. Help, please?
« Reply #60 on: October 24, 2007, 06:11:08 AM »
I agree that this is not clean yet - at least not according to what she's posted in this thread.  But Alex is working on her own too and maybe an updated SAS or other program has solved this for her.

In any event the ball is in her court at the moment ...


  • Guest
Re: Er......this really sucks. Help, please?
« Reply #61 on: October 25, 2007, 08:17:43 AM »
Ok, will have to split my responses to the last few posts in multiple posts.

That's why it's important you don't delete/fix anything until requested. We have to be able to see what you are seeing.
Sorry, the last time I had entries like that I was told to fix them, so I did this time as well.

Do you remember if sivnbypf.dll had file missing behind it? ie both 020 lines had (file missing)

Bo you recall if it was DSS that had the problem or something else. Was a reboot involved?
No reboot was involved. It was one of the dialog boxes that popped, I get them for other programs as well, they usually say "X program has encountered an error and needs to close. Sorry for the inconvenience."

I'd like you to upload these two files to

D:\WINDOWS\system32\lfonpnnv.dll    D:\WINDOWS\system32\lugaadol.dll

File lfonpnnv.dll received on 10.25.2007 07:56:00 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 15/32 (46.88%)
AhnLab-V3   2007.10.25.0   2007.10.25   -
AntiVir   2007.10.24   ADSPY/SecToolBar.H.3
Authentium   4.93.8   2007.10.24   -
Avast   4.7.1074.0   2007.10.25   -
AVG   2007.10.24   Adware Generic2.UCQ
BitDefender   7.2   2007.10.25   -
CAT-QuickHeal   9.00   2007.10.23   AdWare.SecToolBar.h (Not a Virus)
ClamAV   0.91.2   2007.10.25   -
DrWeb   2007.10.24   Trojan.Hammer
eSafe   2007.10.22   -
eTrust-Vet   31.2.5239   2007.10.25   -
Ewido   4.0   2007.10.24   -
FileAdvisor   1   2007.10.25   -
Fortinet   2007.10.19   -
F-Prot   2007.10.24   -
F-Secure   6.70.13030.0   2007.10.25   -
Ikarus   T3.1.1.12   2007.10.25   not-a-virus:AdWare.Win32.SecToolBar.h
Kaspersky   2007.10.25   not-a-virus:AdWare.Win32.SecToolBar.h
McAfee   5148   2007.10.24   -
Microsoft   1.2908   2007.10.25   -
NOD32v2   2614   2007.10.24   a variant of Win32/Adware.SecToolbar
Norman   5.80.02   2007.10.24   W32/SecToolBar.D
Panda   2007.10.25   Spyware/Virtumonde
Prevx1   V2   2007.10.25   Malware.Gen
Rising   2007.10.25   -
Sophos   4.22.0   2007.10.25   Mal/Behav-010
Sunbelt   2.2.907.0   2007.10.24   -
Symantec   10   2007.10.25   Trojan.Vundo
TheHacker   2007.10.25   Adware/SecToolBar.h
VBA32   2007.10.24   AdWare.Win32.SecToolBar.h
VirusBuster   4.3.26:9   2007.10.24   -
Webwasher-Gateway   6.6.1   2007.10.25   Ad-Spyware.SecToolBar.H.3
Additional information
File size: 340032 bytes
MD5: 66e98b5eee8448d55c22d8d2e7eadbdf
SHA1: ae0f0f1856da8757779c463284b18793124bdbce
Prevx info:

File lugaadol.dll received on 10.25.2007 08:08:41 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 15/32 (46.88%)
Antivirus     Version     Last Update     Result
AhnLab-V3   2007.10.25.0   2007.10.25   -
AntiVir   2007.10.25   ADSPY/SecToolBar.H.2
Authentium   4.93.8   2007.10.24   -
Avast   4.7.1074.0   2007.10.25   -
AVG   2007.10.24   Adware Generic2.UCQ
BitDefender   7.2   2007.10.25   -
CAT-QuickHeal   9.00   2007.10.23   AdWare.SecToolBar.h (Not a Virus)
ClamAV   0.91.2   2007.10.25   -
DrWeb   2007.10.24   Trojan.Hammer
eSafe   2007.10.22   -
eTrust-Vet   31.2.5239   2007.10.25   -
Ewido   4.0   2007.10.24   -
FileAdvisor   1   2007.10.25   -
Fortinet   2007.10.19   -
F-Prot   2007.10.24   -
F-Secure   6.70.13030.0   2007.10.25   -
Ikarus   T3.1.1.12   2007.10.25   not-a-virus:AdWare.Win32.SecToolBar.h
Kaspersky   2007.10.25   not-a-virus:AdWare.Win32.SecToolBar.h
McAfee   5148   2007.10.24   -
Microsoft   1.2908   2007.10.25   -
NOD32v2   2614   2007.10.24   a variant of Win32/Adware.SecToolbar
Norman   5.80.02   2007.10.24   W32/SecToolBar.C
Panda   2007.10.25   Spyware/Virtumonde
Prevx1   V2   2007.10.25   Malware.Gen
Rising   2007.10.25   -
Sophos   4.22.0   2007.10.25   Mal/Behav-010
Sunbelt   2.2.907.0   2007.10.24   -
Symantec   10   2007.10.25   Trojan.Vundo
TheHacker   2007.10.25   Adware/SecToolBar.h
VBA32   2007.10.24   AdWare.Win32.SecToolBar.h
VirusBuster   4.3.26:9   2007.10.24   -
Webwasher-Gateway   6.6.1   2007.10.25   Ad-Spyware.SecToolBar.H.2
Additional information
File size: 340032 bytes
MD5: 2066d9a6e38a877b1b30bf6457045b19
SHA1: d2186bfe4acca39fad034b5862fdfe78f0cdf8bf
Prevx info:

alex after you submit the files to virustotal move them to the chest

1. In the Virus Chest, switch to user file category.
2. In main menu, select File ® Add.
3.Browse the folders and select the file you want to add.
4.Choose Open

then delete them from their original location and out of the recyle bin. Don't worry, the chest is a safe place for the files. They can't run or be accessed from outside the chest.
Will do. Want me to send them to avast too?

Quote from: alex1234 on October 23, 2007, 05:42:05 AM
I'm currently running it on my hard drives as well, but that will take a long while. So far it has found one virus on my other drive (C), I'm thinking it's probably unrelated to this.

Let us know what turns up. It may be related.
I've uploaded the log as html so it's easier to read:
« Last Edit: October 25, 2007, 08:24:26 AM by alex1234 »


  • Guest
Re: Er......this really sucks. Help, please?
« Reply #62 on: October 25, 2007, 08:39:55 AM »
Also got a notice from avast a couple hours ago about a Trojan again (only an alert from avast though, no symptoms of infection have come up yet).
Here's the full log from avast:

2007-10-15 18:45   Administrator   1456   Sign of "Win32:MoSucker-044 [trj]" has been found in "D:\Documents and Settings\Administrator\Local Settings\Temp\lsass.exe" file. 
2007-10-17 13:12   SYSTEM   1456   Sign of "Win32:Agent-LAP [trj]" has been found in "D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\gobcqdyi.exe" file. 
2007-10-18 13:11   Administrator   1448   Sign of "Win32:Tiny-IF [trj]" has been found in "D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ycraeyuj.exe" file. 
2007-10-18 13:17   Administrator   1448   Sign of "Win32:Tiny-IF [trj]" has been found in "D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ndqsgwqc.exe" file. 
2007-10-19 13:20   SYSTEM   1464   Sign of "Win32:Tiny-IF [trj]" has been found in "D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jmlxafhw.exe" file. 
2007-10-20 18:50   SYSTEM   1424   Sign of "Win32:Tiny-IF [trj]" has been found in "D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mruwycel.exe" file. 
2007-10-21 02:19   SYSTEM   1588   Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142. 
2007-10-21 02:19   SYSTEM   1588   An error has occured while attempting to update. Please check the logs. 
2007-10-21 14:14   SYSTEM   1588   Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142. 
2007-10-21 14:14   SYSTEM   1588   An error has occured while attempting to update. Please check the logs. 
2007-10-24 18:33   SYSTEM   1396   Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004. 
2007-10-24 18:36   SYSTEM   1396   An error has occured while attempting to update. Please check the logs. 
2007-10-24 23:24   SYSTEM   1396   Sign of "Win32:MoSucker-044 [trj]" has been found in "D:\Documents and Settings\Administrator\Local Settings\Temp\lsass.exe" file.

Ok, trying to be methodical about this. This is the HJTAlex log I just ran, BEFORE attempting to run a new, renamed and updated copy of ComboFix. I tried to download a fresh copy of HJT too but the site seems to be down where I linked to in post#2 to get the program.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:28, on 2007-10-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Program Files\Comodo\Firewall\cmdagent.exe
D:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
D:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
D:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\HP DeskJet 690C Series\ereg\Remind32.exe
D:\Program Files\MSN Messenger\usnsvc.exe
D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
D:\Program Files\Comodo\Firewall\cpf.exe
D:\Program Files\D-Tools\daemon.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Trend Micro\HijackThis\HijackThisAlex.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [Motive SmartBridge] D:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [RemoteControl] "D:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [MimBoot] D:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NBKeyScan] "D:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [hpfsched] D:\WINDOWS\hpfsched.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "D:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [Microsoft task tray monitor] ctray.exe
O4 - HKLM\..\RunServices: [Microsoft task tray monitor] ctray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Reminder-hpc41001.lnk = D:\Program Files\HP DeskJet 690C Series\ereg\Remind32.exe
O4 - Global Startup: TELUS eCare.lnk = D:\Program Files\TELUS eCare\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - D:\Program Files\Comodo\Firewall\cmdagent.exe

End of file - 6610 bytes

And now, off to run renamed ComboFix...
« Last Edit: October 25, 2007, 09:29:53 AM by alex1234 »


  • Guest
Re: Er......this really sucks. Help, please?
« Reply #63 on: October 25, 2007, 09:20:23 AM »
Okay, I renamed it as Combo25.exe. It was running, but then after the restart, it said that it was preparing the log file and not to open any programs until it was done. A couple minutes later, my cursor froze, which is a good indication that my PC had frozen, but I waited about 5 more minutes anyways and it was still frozen. I didn't really think it'd take that long to create a text file, so I rebooted and this is the new ComboFix log that I have in its entirety, whether it is complete or not is your guys' call but it still looks incomplete to me:

ComboFix 07-10-23.1 - Administrator 2007-10-25  0:44:58.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1084 [GMT -6:00]
Running from: D:\Documents and Settings\Administrator\Desktop\Combo25.exe
 * Created a new restore point

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

D:\Documents and Settings\Administrator\Favorites\Online Security Guide.lnk

(((((((((((((((((((((((((   Files Created from 2007-09-25 to 2007-10-25  )))))))))))))))))))))))))))))))

Hopefully I hadn't interrupted it while it was still going but I'm fairly certain it was stalled since my PC stalls quite a bit and I can recognize the signs.

This is the HJTAlex log AFTER I did this second run of ComboFix:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:17, on 2007-10-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Program Files\Comodo\Firewall\cmdagent.exe
D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
D:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Comodo\Firewall\CPF.exe
D:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
D:\Program Files\MSN Messenger\MsnMsgr.Exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\HP DeskJet 690C Series\ereg\Remind32.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\MSN Messenger\usnsvc.exe
D:\Program Files\Trend Micro\HijackThis\HijackThisAlex.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Microsoft task tray monitor] ctray.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [Motive SmartBridge] D:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [RemoteControl] "D:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [MimBoot] D:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NBKeyScan] "D:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [hpfsched] D:\WINDOWS\hpfsched.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "D:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\RunServices: [Microsoft task tray monitor] ctray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Reminder-hpc41001.lnk = D:\Program Files\HP DeskJet 690C Series\ereg\Remind32.exe
O4 - Global Startup: TELUS eCare.lnk = D:\Program Files\TELUS eCare\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - D:\Program Files\Comodo\Firewall\cmdagent.exe

End of file - 6434 bytes

Now if it seems to you guys that ComboFix still hasn't run to completion then I shall run WinPFind3u.exe tomorrow, thanks. I'm also completely willing to try running ComboFix again if advised to. Could there be something wrong with my hardware that's causing it to not run completely?
« Last Edit: October 25, 2007, 09:27:19 AM by alex1234 »

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Er......this really sucks. Help, please?
« Reply #64 on: October 25, 2007, 12:00:38 PM »
Hi alex

The combofix log is incomplete, but the description you gave may indicate it did in fact complete the scan. Unfortunately the log ends just when it is getting to the important part. But it does show one file it removed that your last SAS log showed as quarintined.(I don't recognize the extention though) I think this confirms my belief of backups that we haven't been able to get to.

I think we have to move past combofix for now. Go ahead and run WinPFind3u.exe . Follow mauserme's instructions. I'm going to hand him the wheel and let him drive for awhile. (the windows cleaner on the passenger side.  ;D )

I'll try to address the rest of your post. (excuse my thinking out loud)  :-X

Will do. Want me to send them to avast too?

Yes, mail them to avast as they didn't detect them during the online scan. Open the chest, right click on the files, select mail to alwil software. Give a brief description and maybe a link to this topic. No need to zip when sending from the chest. Make sure the dot is beside "mapi".

Quote from: alex1234 on October 23, 2007, 05:42:05 AM
I'm currently running it on my hard drives as well, but that will take a long while. So far it has found one virus on my other drive (C), I'm thinking it's probably unrelated to this.

Let us know what turns up. It may be related.
I've uploaded the log as html so it's easier to read:

re: c drive- a toolbar in nero and a nero update that came in a 7zip file

Looking at the d:\ detections, it looks like your first run of combofix did remove some vundo, but none with the .bak extention. However, I do see a jkhhh.dll that was in 7zip folder in the comdofix quarintine. I'm tempted to say that vundo came via the nero update. (maybe a phoney update)

**What say you mauserme? I'll note that  SAS quit detecting jkhhh after the first combofix run, but started it stared detecting another random letter file The majority of the detections where in combofix and vundofix quarintine.

Also got a notice from avast a couple hours ago about a Trojan again (only an alert from avast though, no symptoms of infection have come up yet).
Here's the full log from avast:

Did you move it to the chest?

I can see detections going back to the 15th oct. and a lot from the 17th to the 20th.

I also see that avast stopped updating on the 21st. I don't know if it's one of these critters or your firewall. Does comdo allow avast.setup internet access?

hijackthis logs

Did you add a internet explorer plugin?

O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

Could there be something wrong with my hardware that's causing it to not run completely?

I honestly can't say. you mention a lot of freezes, maybe just bad timing.

Are you still experiencing the countdown timer?

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Er......this really sucks. Help, please?
« Reply #65 on: October 25, 2007, 12:43:31 PM »

this should not be running in your temp files

2007-10-24 23:24   SYSTEM   1396   Sign of "Win32:MoSucker-044 [trj]" has been found in "D:\Documents and Settings\Administrator\Local Settings\Temp\lsass.exe" file

Please clear the temp files

See images below...are these what you see?

You said you recently formatted and reinstalled windows, can you recall the date?

When you reinstalled what level where the disks you used at? ie: xp no service packs, sp1 or sp2

If you weren't at sp2 how did you get there, online, disks ?

When did these freezes, programs stopping start to happen?
« Last Edit: October 25, 2007, 09:51:59 PM by oldman »


  • Guest
Re: Er......this really sucks. Help, please?
« Reply #66 on: October 25, 2007, 02:23:35 PM »
I think we have to move past combofix for now. Go ahead and run WinPFind3u.exe .

But first open HJTAlex and click Open the Misc. Tools Section, then click Open Uninstall Manager.  Now click Save List and post the list here.

After posting the uninstall list run WinPFind.  I'll include the directions again below to make it easier for you to find (and with a little correction):

Download WinPFind3u.exe  to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
  • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
  • Under Additional Scans click the checkboxes in front of the following items to select them:
      NonMicrosft Only
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
This log will be quite long.  You can either use multiple post or attach the log file if its easier.  In either case make sure the last line is < End of Report >.

Looking at the d:\ detections, it looks like your first run of combofix did remove some vundo, but none with the .bak extention. However, I do see a jkhhh.dll that was in 7zip folder in the comdofix quarintine. I'm tempted to say that vundo came via the nero update. (maybe a phoney update)

**What say you mauserme? I'll note that  SAS quit detecting jkhhh after the first combofix run, but started it stared detecting another random letter file The majority of the detections where in combofix and vundofix quarintine.
I think we still have Vundo plus the junk its downloading, but if the Nero update was done from the Nero web site its probably OK.  Keep in mind too that malware backups may not always have a .bak extension.  Often they are .sys or .dll, sometimes other things.  They don't necessarily follow our naming conventions.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Er......this really sucks. Help, please?
« Reply #67 on: October 25, 2007, 03:04:15 PM »
Agreed, I think vundo is still hiding somewhere.

Having looked at the kaspersky log again, I think the nero update is alright, probably just the toolbar. The quarintined file (D:\qoobox\Quarantine\, in the smaller print I didn't see the . between the 7 and zip.



  • Guest
Re: Er......this really sucks. Help, please?
« Reply #68 on: October 26, 2007, 05:18:18 AM »
Quote from: mauserme
But first open HJTAlex and click Open the Misc. Tools Section, then click Open Uninstall Manager.  Now click Save List and post the list here.

Quote from: oldman
Please clear the temp files
Done, except a few things would not clear because I got an alert saying they're being used by a program. Please see jpg attachment.

Quote from: oldman
See images below...are these what you see?
What I saw, yes, although for the first one there, I am not sure if that bit about lsass.exe was there.

Quote from: oldman
You said you recently formatted and reinstalled windows, can you recall the date?
Yes, it was the day before I installed avast and got the first Trojan alert, so Oct. 14 was the day.

Quote from: oldman
When you reinstalled what level where the disks you used at? ie: xp no service packs, sp1 or sp2

Quote from: oldman
When did these freezes, programs stopping start to happen?
Months ago, it was mostly games doing the freezing and it was more or less fixed after I opened up the case and cleaned the dust off my fans.  ;D But then I started having problems with booting XP, and then (as now) my system freezes while the OS loads.

Quote from: oldman
Did you move it to the chest?
Yes, just got another one in fact and moved it to the chest as well. To be honest, I think your Nero theory is coming close to the truth because when the alert came yesterday it was right after I ran a Nero keygen (yes, I know...may all my toenails fall off...) and today I ran it again and when I closed it, up pops an alert from avast. And considering what's in the jpg attachment, ie. one of the files that couldn't be cleared out of Local Settings/Temp ... enough said. But the upgrade exe itself came from the Nero site.

Quote from: oldman
I also see that avast stopped updating on the 21st. I don't know if it's one of these critters or your firewall. Does comdo allow avast.setup internet access?
The firewall, I believe that was when I started booting up with my modem turned off.

Quote from: oldman
Did you add a internet explorer plugin?

O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
I don't actively remember this but then I might have added it to view some website, not sure to be honest.

Quote from: oldman
Are you still experiencing the countdown timer?
No, I only got that once when I first tried to run ComboFix.

Edit: The WinPFind3 log is attached too, thanks.
« Last Edit: October 26, 2007, 05:35:05 AM by alex1234 »

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Er......this really sucks. Help, please?
« Reply #69 on: October 26, 2007, 06:54:15 AM »
Thanks for the info alex. I was trying to establish a timeline, mostly for myself.

As for the countdown, was trying to find some clues, just in case I encounter it again or find a situation where it might happen, could the at least include the abort command in the pre scan instructions. Maybe mauserme can comment on it.

Is avast updated now?

To be honest, I think your Nero theory is coming close to the truth because when the alert came yesterday it was right after I ran a Nero keygen (yes, I know...may all my toenails fall off...) and today I ran it again and when I closed it, up pops an alert from avast. And considering what's in the jpg attachment, ie. one of the files that couldn't be cleared out of Local Settings/Temp ... enough said. But the upgrade exe itself came from the Nero site.

No, I think I'm off base with that. I missed the dot and read it as 7zip. The nero detectionsby kav online are probably just the toolbar. The file, in temp,  may have been still in use by something you hadn't closed yet.

edit to add bold
« Last Edit: October 26, 2007, 10:06:31 PM by oldman »

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Er......this really sucks. Help, please?
« Reply #70 on: October 26, 2007, 11:04:06 PM »
Hi alex

While mauserme is checking over the WinPFind log, I've got couple of more questions.

When you reinstalled, did you do a format and full reinstall or just a repair install of windows?

I'm asking because there's few folder dates prior to the install date.

Did you restore some folders/programs from a backup source after your reinstall?

Also, could you check which version of UTORRENT you are using.

When mauserme checks in we should know more.

Hang in there.  ;D

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Er......this really sucks. Help, please?
« Reply #71 on: October 27, 2007, 02:35:24 AM »

Hi alex

A bit of homework for you. We need some files checked at virustotal

D:\Program Files\uTorrent\uTorrent.exe


D:\program files\Frostwire.exe

I'm just guessing frostwire.exe is in the program files, it could be located elsewhere.(the info I have is a poosible 500 paths). Please do a search and record each instance. You can submit each to virustotal, I can't really see there being more than 1 though.

« Last Edit: October 27, 2007, 08:00:55 AM by oldman »


  • Guest
Re: Er......this really sucks. Help, please?
« Reply #72 on: October 27, 2007, 05:14:46 PM »
I've been though the WinPFind log several times and I'm not seeing anything I can identify as malware.  The log is long since you reinstalled the OS so its possible I'm missing something, but after 3 times through I don't think I've missed anything.

I do have several observations that lead to some questions:

In your initial post you say you reformatted the D: drive and the WinPFind log confirms that the OS was reinstalled on 14 October.  Yet I also see files with modified dates prior the 14 October.  Are you sure you reformatted, or did you do a repair install instead?

Also in your initial post you included a screen shot thats shows a Windows Security Center warning icon and a red line through the avast! icon.  Do these still appear this way?  If so what is the Windows warning and what part(s) of avast! are not functioning?

I'm beginning to think the re-infection is coming form somewhere other than your D: drive.  Have you been downloading via uTorrent or Frostwire while we're trying to clean this?  I see uTorrent as a running process in 2 of your HJT logs so I suppose you must have been, but I don't like to make assumptions. 

And did you install uTorrent?  While I saw it running I do not see it in the uninstall list.

What type of network are you in?  If wireless is it password protected?

Please post the answers to oldman's and my questions, then see if you can run ComboFix from the C: partition.
« Last Edit: October 27, 2007, 06:44:03 PM by mauserme »


  • Guest
Re: Er......this really sucks. Help, please?
« Reply #73 on: October 28, 2007, 09:20:36 PM »
Hello all,
I did a reformat of my D drive but restored some important files that I had previously backed up onto my C drive because I didn't want to lose them. Yes, avast is now updated.
I have uTorrent 1.7.5 build 4602.

Quote from: mauserme
Also in your initial post you included a screen shot thats shows a Windows Security Center warning icon and a red line through the avast! icon.  Do these still appear this way?  If so what is the Windows warning and what part(s) of avast! are not functioning?
No, the avast icon now alternates between spinning and staying still, no red line through it. I don't know why it had the red line through it before, I'm guessing when that happens it means it's disabled but I don't recall disabling it at the time. I don't think there's anything not functioning. As for the Windows Security Center thing, I assume you meant the yellow shield icon in the picture. No it is not appearing any longer, I think it had something to do with security updates that it wanted me to download since I had just freshly installed XP.

Quote from: mauserme
Have you been downloading via uTorrent or Frostwire while we're trying to clean this?
uTorrent yes, Frostwire no. Yes I had to reinstall both of them after reformatting.

Quote from: mauserme
What type of network are you in?  If wireless is it password protected?
I have ADSL home internet, not wireless. Is that what you mean?

Quote from: mauserme
see if you can run ComboFix from the C: partition.
Just to clarify, you want me to save ComboFix to my C partition and run it just like that?
Because I also have a second copy of XP on C which means I can also boot up my computer with that copy, assuming it wants to that is.

Ran a search, only found one Frostwire.exe in D:\Program Files\Frostwire\

VirusTotal results:

File uTorrent.exe received on 10.28.2007 20:42:38 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 1/30 (3.34%)
AhnLab-V3   2007.10.27.0   2007.10.26   -
AntiVir   2007.10.26   -
Authentium   4.93.8   2007.10.28   -
Avast   4.7.1074.0   2007.10.28   -
AVG   2007.10.28   -
BitDefender   7.2   2007.10.28   -
CAT-QuickHeal   9.00   2007.10.26   -
ClamAV   0.91.2   2007.10.28   -
DrWeb   2007.10.28   -
eSafe   2007.10.28   suspicious Trojan/Worm
eTrust-Vet   31.2.5244   2007.10.26   -
Ewido   4.0   2007.10.28   -
FileAdvisor   1   2007.10.28   -
Fortinet   2007.10.19   -
F-Prot   2007.10.26   -
F-Secure   6.70.13030.0   2007.10.28   -
Kaspersky   2007.10.28   -
McAfee   5150   2007.10.26   -
Microsoft   1.2908   2007.10.28   -
NOD32v2   2621   2007.10.28   -
Norman   5.80.02   2007.10.26   -
Prevx1   V2   2007.10.28   -
Rising   2007.10.28   -
Sophos   4.23.0   2007.10.28   -
Sunbelt   2.2.907.0   2007.10.27   -
Symantec   10   2007.10.28   -
TheHacker   2007.10.27   -
VBA32   2007.10.28   -
VirusBuster   4.3.26:9   2007.10.28   -
Webwasher-Gateway   6.6.1   2007.10.28   -
Additional information
File size: 219952 bytes
MD5: 8df7f16f3da69893cef9f74dddb767fd
SHA1: 24ccb90f3fbddbd5a45e8b336266267f77950ce8
packers: UPX_LZMA

File imsins.BAK received on 10.28.2007 21:04:23 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/32 (0%)
AhnLab-V3   2007.10.27.0   2007.10.26   -
AntiVir   2007.10.26   -
Authentium   4.93.8   2007.10.28   -
Avast   4.7.1074.0   2007.10.28   -
AVG   2007.10.28   -
BitDefender   7.2   2007.10.28   -
CAT-QuickHeal   9.00   2007.10.26   -
ClamAV   0.91.2   2007.10.28   -
DrWeb   2007.10.28   -
eSafe   2007.10.28   -
eTrust-Vet   31.2.5244   2007.10.26   -
Ewido   4.0   2007.10.28   -
FileAdvisor   1   2007.10.28   -
Fortinet   2007.10.19   -
F-Prot   2007.10.26   -
F-Secure   6.70.13030.0   2007.10.28   -
Ikarus   T3.1.1.12   2007.10.28   -
Kaspersky   2007.10.28   -
McAfee   5150   2007.10.26   -
Microsoft   1.2908   2007.10.28   -
NOD32v2   2621   2007.10.28   -
Norman   5.80.02   2007.10.26   -
Panda   2007.10.28   -
Prevx1   V2   2007.10.28   -
Rising   2007.10.28   -
Sophos   4.23.0   2007.10.28   -
Sunbelt   2.2.907.0   2007.10.27   -
Symantec   10   2007.10.28   -
TheHacker   2007.10.27   -
VBA32   2007.10.28   -
VirusBuster   4.3.26:9   2007.10.28   -
Webwasher-Gateway   6.6.1   2007.10.28   -
Additional information
File size: 1393 bytes
MD5: 50953e631c4527786e20e8d3042374e0
SHA1: 3f745b261a476751a4b726df25d89b412c43f029

File FrostWire.exe received on 10.28.2007 21:16:46 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/32 (0%)
AhnLab-V3   2007.10.27.0   2007.10.26   -
AntiVir   2007.10.26   -
Authentium   4.93.8   2007.10.28   -
Avast   4.7.1074.0   2007.10.28   -
AVG   2007.10.28   -
BitDefender   7.2   2007.10.28   -
CAT-QuickHeal   9.00   2007.10.26   -
ClamAV   0.91.2   2007.10.28   -
DrWeb   2007.10.28   -
eSafe   2007.10.28   -
eTrust-Vet   31.2.5244   2007.10.26   -
Ewido   4.0   2007.10.28   -
FileAdvisor   1   2007.10.28   -
Fortinet   2007.10.19   -
F-Prot   2007.10.26   -
F-Secure   6.70.13030.0   2007.10.28   -
Ikarus   T3.1.1.12   2007.10.28   -
Kaspersky   2007.10.28   -
McAfee   5150   2007.10.26   -
Microsoft   1.2908   2007.10.28   -
NOD32v2   2621   2007.10.28   -
Norman   5.80.02   2007.10.26   -
Panda   2007.10.28   -
Prevx1   V2   2007.10.28   -
Rising   2007.10.28   -
Sophos   4.23.0   2007.10.28   -
Sunbelt   2.2.907.0   2007.10.27   -
Symantec   10   2007.10.28   -
TheHacker   2007.10.27   -
VBA32   2007.10.28   -
VirusBuster   4.3.26:9   2007.10.28   -
Webwasher-Gateway   6.6.1   2007.10.28   -
Additional information
File size: 114688 bytes
MD5: 4939d0506630168e691c7d389435a773
SHA1: 07b98d813387de30dfe82a1033fa7c851d3cfdec


  • Guest
Re: Er......this really sucks. Help, please?
« Reply #74 on: October 28, 2007, 09:41:03 PM »
Also, about what I said earlier:
I think your Nero theory is coming close to the truth because when the alert came yesterday it was right after I ran a Nero keygen (yes, I know...may all my toenails fall off...) and today I ran it again and when I closed it, up pops an alert from avast.
Maybe it's just a coincidence that two notices from avast about a Trojan came up just as I finished running the keygen but I uploaded the file to VirusTotal just now and came out with this, is it significant?

File keygen.exe received on 10.28.2007 21:27:35 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 3/32 (9.38%)
AhnLab-V3   2007.10.27.0   2007.10.26   -
AntiVir   2007.10.26   -
Authentium   4.93.8   2007.10.28   -
Avast   4.7.1074.0   2007.10.28   -
AVG   2007.10.28   -
BitDefender   7.2   2007.10.28   -
CAT-QuickHeal   9.00   2007.10.26   -
ClamAV   0.91.2   2007.10.28   -
DrWeb   2007.10.28   -
eSafe   2007.10.28   -
eTrust-Vet   31.2.5244   2007.10.26   -
Ewido   4.0   2007.10.28   -
FileAdvisor   1   2007.10.28   -
Fortinet   2007.10.19   -
F-Prot   2007.10.26   -
F-Secure   6.70.13030.0   2007.10.28   -
Ikarus   T3.1.1.12   2007.10.28   Backdoor.Win32.Bifrose.aci
Kaspersky   2007.10.28   -
McAfee   5150   2007.10.26   -
Microsoft   1.2908   2007.10.28   -
NOD32v2   2621   2007.10.28   -
Norman   5.80.02   2007.10.26   W32/Ardamax.DED
Panda   2007.10.28   -
Prevx1   V2   2007.10.28   -
Rising   2007.10.28   -
Sophos   4.23.0   2007.10.28   -
Sunbelt   2.2.907.0   2007.10.27   -
Symantec   10   2007.10.28   -
TheHacker   2007.10.27   -
VBA32   2007.10.28   Backdoor.Win32.Bifrose.aci
VirusBuster   4.3.26:9   2007.10.28   -
Webwasher-Gateway   6.6.1   2007.10.28   -
Additional information
File size: 328400 bytes
MD5: eb2aea484fdd151885994ebcb4fdb59f
SHA1: ff0d4a62291f902d1f691a98d6f82752f6667096