It is currently Tue Sep 01, 2026 4:19 pm


win32 cryptor virus removal

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

win32 cryptor virus removal

Postby global » Mon May 18, 2009 12:52 am

Hi i got this virus from myspace and cant get rid of it with avg. I hope u can help please.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:45:50 PM, on 5/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\Bailee\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Bailee\Start Menu\Programs\UltimateBet\UltimateBet.lnk
O9 - Extra 'Tools' menuitem: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Bailee\Start Menu\Programs\UltimateBet\UltimateBet.lnk
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (file missing)
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0F733F27-5BBB-4D03-8D6B-19E2143880BF} (SkillGround Game Manager) - http://www1.skillground.com/cab1830/SkillGround.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/ ... .6.108.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 7097 bytes
global
Newbie
Newbie
 
Posts: 5
Joined: Mon May 18, 2009 12:48 am

Thanks given:0
Thanks received:0
Top

Re: win32 cryptor virus removal

Postby Gecko » Mon May 18, 2009 11:51 am

global,

Please download to your desktop.

Double click combofix.exe and follow the prompts.

Do not exit Combofix while it is running you my loose all your personal settings!
Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.

When it's done running it will produce a log for you. Please post that log in your next reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: win32 cryptor virus removal

Postby global » Mon May 18, 2009 1:27 pm

Hi Gecko,
I have downloaded combofix and double clicked the exe file. Then a dialog comes up and asks me to run...I click run and nothing else happens. I have tried it a few times and re-dl'd it, but it never does anything after that, and it never prompts me to do anything after "run".
Thanks
global
Newbie
Newbie
 
Posts: 5
Joined: Mon May 18, 2009 12:48 am

Thanks given:0
Thanks received:0
Top

Re: win32 cryptor virus removal

Postby Gecko » Mon May 18, 2009 9:26 pm

global,

Try renaming it to CBF.exe and see if you get different results.

Are you sure you are letting it run long enough?
Once the blue command box comes up it can take quite some time before you see anything on the screen.
It is performing the first scan and if you have a lot of files it can take up to 20 minutes.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: win32 cryptor virus removal

Postby global » Tue May 19, 2009 1:31 am

Thanks Gecko,
Changing the file name worked...yay. Here is the log.

ComboFix 09-05-18.02 - Bailee 05/18/2009 20:45.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.217 [GMT -4:00]
Running from: C:\CBF.exe.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\alexa toolbar
c:\program files\Essentials Codec Pack
c:\program files\Essentials Codec Pack\ac3filter.ax
c:\program files\Essentials Codec Pack\AviSplitter.ax
c:\program files\Essentials Codec Pack\cddareader.ax
c:\program files\Essentials Codec Pack\cdxareader.ax
c:\program files\Essentials Codec Pack\CLVSD.AX
c:\program files\Essentials Codec Pack\CoreAAC.ax
c:\program files\Essentials Codec Pack\CoreFLACDecoder.ax
c:\program files\Essentials Codec Pack\CoreVorbis.ax
c:\program files\Essentials Codec Pack\ffdshow\audxlib.dll
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\andreas_78er.matrix.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\andreas_doppelte_99er.matrix.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\andreas_einfache_99er.matrix.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\Bulletproof's Heavy Compression Matrix.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\Bulletproof's High Quality Matrix.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\CG-Animation Matrix.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\hvs-best-picture.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\hvs-better-picture.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\hvs-good-picture.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\Low Bitrate Matrix.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\MPEG.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\pvcd.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\Soulhunters V3.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\Soulhunters V5.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\Standard.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\Ultimate Matrix.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\Ultra Low Bitrate Matrix.xcm
c:\program files\Essentials Codec Pack\ffdshow\custom matrices\Very Low Bitrate Matrix.xcm
c:\program files\Essentials Codec Pack\ffdshow\ff_kernelDeint.dll
c:\program files\Essentials Codec Pack\ffdshow\ff_liba52.dll
c:\program files\Essentials Codec Pack\ffdshow\ff_libdts.dll
c:\program files\Essentials Codec Pack\ffdshow\ff_libfaad2.dll
c:\program files\Essentials Codec Pack\ffdshow\ff_libmad.dll
c:\program files\Essentials Codec Pack\ffdshow\ff_realaac.dll
c:\program files\Essentials Codec Pack\ffdshow\ff_samplerate.dll
c:\program files\Essentials Codec Pack\ffdshow\ff_theora.dll
c:\program files\Essentials Codec Pack\ffdshow\ff_tremor.dll
c:\program files\Essentials Codec Pack\ffdshow\ff_unrar.dll
c:\program files\Essentials Codec Pack\ffdshow\ff_wmv9.dll
c:\program files\Essentials Codec Pack\ffdshow\ff_x264.dll
c:\program files\Essentials Codec Pack\ffdshow\ffdshow.ax
c:\program files\Essentials Codec Pack\ffdshow\ffdshow.ax.manifest
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1026.bg
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1028.tc
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1029.cz
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1031.de
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1033.en
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1034.es
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1036.fr
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1038.hu
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1040.it
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1041.ja
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1041.jp
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1045.pl
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1046.br
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1049.ru
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1051.sk
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.1053.se
c:\program files\Essentials Codec Pack\ffdshow\languages\ffdshow.2052.sc
c:\program files\Essentials Codec Pack\ffdshow\libavcodec.dll
c:\program files\Essentials Codec Pack\ffdshow\libmpeg2_ff.dll
c:\program files\Essentials Codec Pack\ffdshow\libmplayer.dll
c:\program files\Essentials Codec Pack\ffdshow\TomsMoComp_ff.dll
c:\program files\Essentials Codec Pack\FLVSplitter.ax
c:\program files\Essentials Codec Pack\iccvid.dll
c:\program files\Essentials Codec Pack\l3codecp.acm
c:\program files\Essentials Codec Pack\l3codecx.ax
c:\program files\Essentials Codec Pack\lame.ax
c:\program files\Essentials Codec Pack\MatroskaSplitter.ax
c:\program files\Essentials Codec Pack\MonkeySource.ax
c:\program files\Essentials Codec Pack\MP4Splitter.ax
c:\program files\Essentials Codec Pack\MpaSplitter.ax
c:\program files\Essentials Codec Pack\Mpeg2DecFilter.ax
c:\program files\Essentials Codec Pack\MpegSplitter.ax
c:\program files\Essentials Codec Pack\OggSplitter.ax
c:\program files\Essentials Codec Pack\RealMediaSplitter.ax
c:\program files\Essentials Codec Pack\RLMPCDec.ax
c:\program files\Essentials Codec Pack\RLOFRDec.ax
c:\program files\Essentials Codec Pack\shoutcastsource.ax
c:\program files\Essentials Codec Pack\uninst.exe
c:\program files\Essentials Codec Pack\update.exe
c:\program files\Essentials Codec Pack\vorbis.acm
c:\program files\Essentials Codec Pack\VSFilter.dll
c:\program files\Essentials Codec Pack\WavPackDSDecoder.ax
c:\program files\Essentials Codec Pack\WavPackDSSplitter.ax
c:\program files\Essentials Codec Pack\Windows Essentials Media Codec Pack.url
c:\program files\Essentials Codec Pack\xvid.ax
c:\program files\Essentials Codec Pack\xvidcore.dll
c:\program files\Essentials Codec Pack\xvidvfw.dll
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\ieocx.dll
c:\windows\system32\drivers\UAClxobrrnthkwkslm.sys
c:\windows\system32\UACbxvqxyxteoliesq.dat
c:\windows\system32\UACcjaptsnlmkqjpoj.log
c:\windows\system32\UACeylkdvjbpxnssww.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjmywwuegbctreqi.log
c:\windows\system32\UACjvijesdejqqfpnr.dll
c:\windows\system32\UACqxomxqpfmjbnmpf.dll
c:\windows\system32\UACtridwtxriwymiir.log
c:\windows\system32\UACuigbbhhxdcptewq.dll
c:\windows\system32\UACxkokcrxtpbmtyxm.dll

----- BITS: Possible infected sites -----

hxxp://softwaredownloadcentercom.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-04-19 to 2009-05-19 )))))))))))))))))))))))))))))))
.

2009-05-18 13:23 . 2009-05-19 00:07 2989003 ----a-r C:\CBF.exe.exe
2009-05-17 21:15 . 2009-05-17 21:15 -------- d-sh--w c:\documents and settings\Bailee\IECompatCache
2009-05-17 05:42 . 2009-05-17 05:42 -------- d-sh--w c:\windows\system32\config\systemprofile\IETldCache
2009-05-17 05:42 . 2009-05-17 05:42 183 ----a-w c:\documents and settings\Bailee\Application Data\asd.bat
2009-05-14 20:23 . 2009-05-14 20:23 -------- d-sh--w c:\documents and settings\Bailee\PrivacIE
2009-05-14 20:17 . 2009-05-14 20:17 -------- d-sh--w c:\documents and settings\Bailee\IETldCache
2009-05-14 19:59 . 2009-05-14 19:59 -------- d-----w c:\windows\system32\XPSViewer
2009-05-14 19:59 . 2009-05-14 19:59 -------- d-----w c:\program files\MSBuild
2009-05-14 19:59 . 2009-05-14 19:59 -------- d-----w c:\program files\Reference Assemblies
2009-05-14 19:58 . 2008-07-06 12:06 117760 ------w c:\windows\system32\prntvpt.dll
2009-05-14 19:58 . 2008-07-06 12:06 89088 ------w c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-05-14 19:58 . 2008-07-06 10:50 597504 ------w c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-05-14 19:58 . 2008-07-06 12:06 575488 ------w c:\windows\system32\dllcache\xpsshhdr.dll
2009-05-14 19:58 . 2008-07-06 12:06 575488 ------w c:\windows\system32\xpsshhdr.dll
2009-05-14 19:57 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\dllcache\xpssvcs.dll
2009-05-14 19:57 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\xpssvcs.dll
2009-05-14 19:55 . 2009-05-14 20:14 -------- d-----w c:\windows\SxsCaPendDel
2009-05-14 19:46 . 2009-05-14 19:46 -------- d-----w c:\windows\ie8updates
2009-05-14 19:46 . 2009-04-25 05:30 102400 ------w c:\windows\system32\dllcache\iecompat.dll
2009-05-14 19:43 . 2009-05-14 19:46 -------- dc-h--w c:\windows\ie8
2009-05-06 16:22 . 2008-04-17 16:12 107368 ----a-w c:\windows\system32\GEARAspi.dll
2009-05-06 16:22 . 2009-03-19 20:32 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-06 16:21 . 2009-05-06 16:21 -------- d-----w c:\program files\iPod
2009-05-06 16:21 . 2009-05-06 16:22 -------- d-----w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-06 16:21 . 2009-05-06 16:22 -------- d-----w c:\program files\iTunes
2009-05-06 16:16 . 2009-05-06 16:16 -------- d-----w c:\program files\Safari

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-14 20:20 . 2008-03-06 20:31 25296 ----a-w c:\documents and settings\Bailee\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-06 16:21 . 2008-03-17 19:16 -------- d-----w c:\program files\Common Files\Apple
2009-05-06 00:16 . 2008-03-06 21:27 -------- d-----w c:\program files\Bonjour
2009-05-05 22:53 . 2008-03-10 16:44 -------- d-----w c:\program files\QuickTime
2009-05-05 12:22 . 2008-05-30 21:12 11952 ----a-w c:\windows\system32\avgrsstx.dll
2009-05-05 12:22 . 2008-05-30 21:12 325896 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-05 12:22 . 2008-05-30 21:12 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-27 22:23 . 2009-01-26 23:42 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-04-27 22:23 . 2009-01-26 23:22 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-04-12 23:34 . 2008-07-24 01:08 25296 ----a-w c:\documents and settings\Bailee\Application Data\GDIPFONTCACHEV1.DAT
2009-03-23 17:03 . 2009-02-05 02:41 -------- d-----w c:\program files\SecondLife
2009-03-11 21:15 . 2009-03-11 21:15 0 ----a-w c:\windows\ativpsrm.bin
2009-03-08 08:34 . 2007-06-13 05:47 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 08:34 . 2007-05-12 12:09 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 08:33 . 2007-05-12 12:10 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 08:33 . 2007-05-12 12:09 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 08:32 . 2007-05-12 12:08 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 08:32 . 2007-05-12 12:09 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 08:31 . 2007-05-12 12:09 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 08:31 . 2007-05-12 12:09 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 08:31 . 2007-05-12 12:09 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 08:22 . 2007-05-12 12:09 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2004-08-04 12:00 284160 ----a-w c:\windows\system32\pdh.dll
2008-04-07 06:59 . 2008-06-02 02:16 67696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-04-07 06:59 . 2008-06-02 02:16 54376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-04-07 06:59 . 2008-06-02 02:16 34952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-04-07 06:59 . 2008-06-02 02:16 46720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-04-07 06:59 . 2008-06-02 02:16 172144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-05 12:22 11952 ----a-w c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Autotyping
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVScan

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ACS"=2 (0x2)
"AdobeActiveFileMonitor6.0"=2 (0x2)
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"MDM"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"PnkBstrA"=2 (0x2)
"Lavasoft Ad-Aware Service"=2 (0x2)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
"aawservice"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LeapFTP\\LeapFTP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield Vietnam\\bfvietnam.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\CCP\\EVE\\bin\\ExeFile.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\SecondLife\\SLVoice.exe"=
"c:\\Program Files\\SecondLife\\SecondLife.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/26/2009 7:22 PM 64160]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/30/2008 5:12 PM 325896]
R1 GearAspiSys;GearAspiSys;c:\windows\system32\drivers\GEARASPISYS.SYS [5/19/2008 1:20 PM 53412]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/30/2008 5:12 PM 108552]
S4 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [10/2/2007 3:46 PM 124832]
S4 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/3/2008 6:27 PM 908568]
S4 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/3/2008 6:27 PM 298776]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 953168]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-05-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 22:23]

2009-05-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{10F055B8-F443-4adf-948A-EC551E9DBCE4} - c:\documents and settings\Bailee\Start Menu\Programs\UltimateBet\UltimateBet.lnk
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - c:\windows\web\related.htm
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-18 20:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(712)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-05-19 20:54
ComboFix-quarantined-files.txt 2009-05-19 00:52

Pre-Run: 2,804,486,144 bytes free
Post-Run: 6,083,301,376 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

287 --- E O F --- 2008-12-18 05:17
global
Newbie
Newbie
 
Posts: 5
Joined: Mon May 18, 2009 12:48 am

Thanks given:0
Thanks received:0
Top

Re: win32 cryptor virus removal

Postby Gecko » Tue May 19, 2009 12:34 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: win32 cryptor virus removal

Postby global » Tue May 19, 2009 4:52 pm

Hi Gecko,
After dragging the text file to cfb.exe it told me there was a newer version. Same thing it said yesterday, i guess they update often. Anyways heres the logs.

ComboFix 09-05-18.06 - Bailee 05/19/2009 12:32.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.167 [GMT -4:00]
Running from: C:\CBF.exe.exe
Command switches used :: C:\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
c:\documents and settings\Bailee\Application Data\asd.bat
c:\documents and settings\Bailee\Start Menu\Programs\UltimateBet\UltimateBet.lnk
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Bailee\Application Data\asd.bat
c:\documents and settings\Bailee\Start Menu\Programs\UltimateBet\UltimateBet.lnk

.
((((((((((((((((((((((((( Files Created from 2009-04-19 to 2009-05-19 )))))))))))))))))))))))))))))))
.

2009-05-18 13:23 . 2009-05-19 16:30 2989125 ----a-r C:\CBF.exe.exe
2009-05-17 21:15 . 2009-05-17 21:15 -------- d-sh--w c:\documents and settings\Bailee\IECompatCache
2009-05-17 05:42 . 2009-05-17 05:42 -------- d-sh--w c:\windows\system32\config\systemprofile\IETldCache
2009-05-14 20:23 . 2009-05-14 20:23 -------- d-sh--w c:\documents and settings\Bailee\PrivacIE
2009-05-14 20:17 . 2009-05-14 20:17 -------- d-sh--w c:\documents and settings\Bailee\IETldCache
2009-05-14 19:59 . 2009-05-14 19:59 -------- d-----w c:\windows\system32\XPSViewer
2009-05-14 19:59 . 2009-05-14 19:59 -------- d-----w c:\program files\MSBuild
2009-05-14 19:59 . 2009-05-14 19:59 -------- d-----w c:\program files\Reference Assemblies
2009-05-14 19:58 . 2008-07-06 12:06 117760 ------w c:\windows\system32\prntvpt.dll
2009-05-14 19:58 . 2008-07-06 12:06 89088 ------w c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-05-14 19:58 . 2008-07-06 10:50 597504 ------w c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-05-14 19:58 . 2008-07-06 12:06 575488 ------w c:\windows\system32\dllcache\xpsshhdr.dll
2009-05-14 19:58 . 2008-07-06 12:06 575488 ------w c:\windows\system32\xpsshhdr.dll
2009-05-14 19:57 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\dllcache\xpssvcs.dll
2009-05-14 19:57 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\xpssvcs.dll
2009-05-14 19:55 . 2009-05-14 20:14 -------- d-----w c:\windows\SxsCaPendDel
2009-05-14 19:46 . 2009-05-14 19:46 -------- d-----w c:\windows\ie8updates
2009-05-14 19:46 . 2009-04-25 05:30 102400 ------w c:\windows\system32\dllcache\iecompat.dll
2009-05-14 19:43 . 2009-05-14 19:46 -------- dc-h--w c:\windows\ie8
2009-05-06 16:22 . 2008-04-17 16:12 107368 ----a-w c:\windows\system32\GEARAspi.dll
2009-05-06 16:22 . 2009-03-19 20:32 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-06 16:21 . 2009-05-06 16:21 -------- d-----w c:\program files\iPod
2009-05-06 16:21 . 2009-05-06 16:22 -------- d-----w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-06 16:21 . 2009-05-06 16:22 -------- d-----w c:\program files\iTunes
2009-05-06 16:16 . 2009-05-06 16:16 -------- d-----w c:\program files\Safari

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-14 20:20 . 2008-03-06 20:31 25296 ----a-w c:\documents and settings\Bailee\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-06 16:21 . 2008-03-17 19:16 -------- d-----w c:\program files\Common Files\Apple
2009-05-06 00:16 . 2008-03-06 21:27 -------- d-----w c:\program files\Bonjour
2009-05-05 22:53 . 2008-03-10 16:44 -------- d-----w c:\program files\QuickTime
2009-05-05 12:22 . 2008-05-30 21:12 11952 ----a-w c:\windows\system32\avgrsstx.dll
2009-05-05 12:22 . 2008-05-30 21:12 325896 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-05 12:22 . 2008-05-30 21:12 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-27 22:23 . 2009-01-26 23:42 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-04-27 22:23 . 2009-01-26 23:22 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-04-12 23:34 . 2008-07-24 01:08 25296 ----a-w c:\documents and settings\Bailee\Application Data\GDIPFONTCACHEV1.DAT
2009-03-23 17:03 . 2009-02-05 02:41 -------- d-----w c:\program files\SecondLife
2009-03-11 21:15 . 2009-03-11 21:15 0 ----a-w c:\windows\ativpsrm.bin
2009-03-08 08:34 . 2007-06-13 05:47 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 08:34 . 2007-05-12 12:09 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 08:33 . 2007-05-12 12:10 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 08:33 . 2007-05-12 12:09 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 08:32 . 2007-05-12 12:08 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 08:32 . 2007-05-12 12:09 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 08:31 . 2007-05-12 12:09 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 08:31 . 2007-05-12 12:09 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 08:31 . 2007-05-12 12:09 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 08:22 . 2007-05-12 12:09 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2004-08-04 12:00 284160 ----a-w c:\windows\system32\pdh.dll
2008-04-07 06:59 . 2008-06-02 02:16 67696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-04-07 06:59 . 2008-06-02 02:16 54376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-04-07 06:59 . 2008-06-02 02:16 34952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-04-07 06:59 . 2008-06-02 02:16 46720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-04-07 06:59 . 2008-06-02 02:16 172144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-05 12:22 11952 ----a-w c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ACS"=2 (0x2)
"AdobeActiveFileMonitor6.0"=2 (0x2)
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"MDM"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"PnkBstrA"=2 (0x2)
"Lavasoft Ad-Aware Service"=2 (0x2)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
"aawservice"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LeapFTP\\LeapFTP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield Vietnam\\bfvietnam.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\CCP\\EVE\\bin\\ExeFile.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\SecondLife\\SLVoice.exe"=
"c:\\Program Files\\SecondLife\\SecondLife.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/26/2009 7:22 PM 64160]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/30/2008 5:12 PM 325896]
R1 GearAspiSys;GearAspiSys;c:\windows\system32\drivers\GEARASPISYS.SYS [5/19/2008 1:20 PM 53412]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/30/2008 5:12 PM 108552]
S4 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [10/2/2007 3:46 PM 124832]
S4 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/3/2008 6:27 PM 908568]
S4 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/3/2008 6:27 PM 298776]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 953168]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-05-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 22:23]

2009-05-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{10F055B8-F443-4adf-948A-EC551E9DBCE4} - c:\documents and settings\Bailee\Start Menu\Programs\UltimateBet\UltimateBet.lnk
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - c:\windows\web\related.htm
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-19 12:36
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-05-19 12:39
ComboFix-quarantined-files.txt 2009-05-19 16:38
ComboFix2.txt 2009-05-19 00:54

Pre-Run: 6,061,862,912 bytes free
Post-Run: 6,049,546,240 bytes free

170 --- E O F --- 2008-12-18 05:17


----------------------------------------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:48:20 PM, on 5/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Bailee\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Bailee\Start Menu\Programs\UltimateBet\UltimateBet.lnk (file missing)
O9 - Extra 'Tools' menuitem: UltimateBet - {10F055B8-F443-4adf-948A-EC551E9DBCE4} - C:\Documents and Settings\Bailee\Start Menu\Programs\UltimateBet\UltimateBet.lnk (file missing)
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (file missing)
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0F733F27-5BBB-4D03-8D6B-19E2143880BF} (SkillGround Game Manager) - http://www1.skillground.com/cab1830/SkillGround.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/ ... .6.108.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

--
End of file - 5598 bytes
global
Newbie
Newbie
 
Posts: 5
Joined: Mon May 18, 2009 12:48 am

Thanks given:0
Thanks received:0
Top

Re: win32 cryptor virus removal

Postby Gecko » Tue May 19, 2009 10:00 pm

global ,

Your logs look clean, how's it running now?
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: win32 cryptor virus removal

Postby global » Tue May 19, 2009 11:09 pm

Thanks Gecko,
Everything seems to be running good.
I really appreciate the help.
:rock:
global
Newbie
Newbie
 
Posts: 5
Joined: Mon May 18, 2009 12:48 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 0 guests

cron