Hey.
As many others it seems i’ve been infected with this Win32:TratBHO trojan, and been unable to remove it. Also ever since it appeared, on my first reboot, i’ve noticed this .exe : C:\is9.exe , which opens in a cmd promt upon startup (it didnt this time after i ran combofix and had to reboot to regain net connection (i got kicked off the net it seemed))
Hope anyone is able to/willing to help me
ComboFix 08-01-13.1 - Th 2008-01-13 19:14:08.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1030.18.1552 [GMT 1:00]
Running from: C:\Documents and Settings\Th\Skrivebord\ComboFix.exe
- Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Downloaded Program Files\Quarantine
C:\WINDOWS\images.zip
C:\WINDOWS\system32\vtuvtsp.dll
.
((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 )))))))))))))))))))))))))))))))
.
2008-01-13 19:13 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-13 19:00 . 2008-01-13 19:00 d-------- C:\Programmer\Trend Micro
2008-01-13 18:52 . 2008-01-13 18:52 d-------- C:\Documents and Settings\Th\Application Data\Comodo
2008-01-13 18:52 . 2008-01-13 18:52 d-------- C:\Documents and Settings\All Users\Application Data\Comodo
2008-01-13 18:47 . 2006-04-18 17:35 211 --a------ C:\boot.ini.comodofirewall
2008-01-13 18:46 . 2008-01-13 18:46 d-------- C:\Programmer\Comodo
2008-01-13 18:39 . 2008-01-13 18:39 d-------- C:\Programmer\SpywareBlaster
2008-01-13 18:30 . 2008-01-13 18:50 d-------- C:\Programmer\SUPERAntiSpyware
2008-01-13 18:30 . 2008-01-13 18:30 d-------- C:\Documents and Settings\Th\Application Data\SUPERAntiSpyware.com
2008-01-13 18:30 . 2008-01-13 18:30 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-13 17:55 . 2008-01-13 17:55 d–h----- C:\WINDOWS\PIF
2008-01-13 17:40 . 2008-01-13 18:55 5,197 --a------ C:\is9.exe
2008-01-04 18:29 . 2008-01-04 18:29 dr------- C:\Documents and Settings\Th\Application Data\Brother
2008-01-04 18:09 . 2008-01-04 18:17 d-------- C:\Programmer\Brownie
2008-01-04 18:07 . 2008-01-04 18:09 d-------- C:\Programmer\Brother
2008-01-04 18:07 . 2004-10-12 01:24 188,416 --a------ C:\WINDOWS\system32\Pdrvinst.dll
2008-01-04 18:07 . 2002-10-31 01:09 81,920 --a------ C:\WINDOWS\system32\BrWebIns.dll
2008-01-04 18:07 . 2003-07-03 01:08 65,536 --a------ C:\WINDOWS\system32\BRWEBUP.EXE
2008-01-04 16:52 . 2007-12-29 23:00 313,344 -r-hs---- C:\WINDOWS\wkssvr.exe
2007-12-30 17:36 . 2007-12-30 17:36 d-------- C:\Programmer\EVEMon
2007-12-30 17:36 . 2007-12-30 17:52 d-------- C:\Documents and Settings\Th\Application Data\EVEMon
2007-12-28 00:27 . 2007-12-28 00:27 d-------- C:\Programmer\iPod
2007-12-28 00:27 . 2008-01-13 18:52 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-28 00:27 . 2007-12-28 00:28 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-28 00:26 . 2007-12-28 00:26 d-------- C:\Programmer\QuickTime
2007-12-28 00:24 . 2007-12-28 00:24 d-------- C:\Programmer\Fælles filer\Apple
2007-12-28 00:24 . 2007-10-31 14:09 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-13 17:56 --------- d-----w C:\Documents and Settings\Th\Application Data\Skype
2008-01-13 17:29 --------- d-----w C:\Programmer\Fælles filer\Wise Installation Wizard
2008-01-13 16:25 --------- d-----w C:\Documents and Settings\Th\Application Data\uTorrent
2008-01-04 17:17 --------- d–h–w C:\Programmer\InstallShield Installation Information
2008-01-04 17:07 --------- d-----w C:\Programmer\Fælles filer\InstallShield
2007-12-28 00:23 --------- d-----w C:\Programmer\iTunes
2007-12-10 17:16 --------- d-----w C:\Programmer\EFT
2007-12-04 14:56 93,264 ------w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ------w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ------w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ------w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ------w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-11-30 21:33 --------- d-----w C:\Programmer\Pocket Tanks Deluxe
2007-11-27 20:42 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-11-16 13:53 --------- d-----w C:\Programmer\Java
2007-11-13 10:25 20,480 ------w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-07 09:28 723,456 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:44 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2006-03-16 13:05 32 ----a-r C:\Documents and Settings\All Users\hash.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Skype”=“C:\Programmer\Skype\Phone\Skype.exe” [2007-03-30 12:34 25263144]
“MsnMsgr”=“C:\Programmer\MSN Messenger\MsnMsgr.exe” [2007-01-19 11:55 5674352]
“Aim6”=“”
“Utopia Angel”=“C:\Utopia\Angel\Angel.exe”
“DAEMON Tools”=“C:\Programmer\DAEMON Tools\daemon.exe” [2007-04-03 23:29 165784]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-27 13:00 15360]
“SUPERAntiSpyware”=“C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe” [2007-06-21 14:06 1318912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Logitech Hardware Abstraction Layer”=“KHALMNPR.EXE” [2004-12-10 11:45 49152 C:\WINDOWS\KHALMNPR.Exe]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2006-10-22 11:22 7700480]
“nwiz”=“nwiz.exe” [2006-10-22 11:22 1622016 C:\WINDOWS\system32\nwiz.exe]
“SunJavaUpdateSched”=“C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11 132496]
“SsAAD.exe”=“C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe” [2005-01-24 18:58 81920]
“SoundMan”=“SOUNDMAN.EXE” [2006-05-11 13:19 77824 C:\WINDOWS\soundman.exe]
“WebcamMaxMoniter”=“C:\Programmer\WebcamMax\CAMTHINS.exe” [2006-07-20 14:25 73728]
“NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2006-10-22 11:22 86016]
“AVG7_CC”=“C:\PROGRA~1\Grisoft\AVG7\avgcc.exe”
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 14:00 79224]
“QuickTime Task”=“C:\Programmer\QuickTime\QTTask.exe” [2007-12-11 10:56 286720]
“iTunesHelper”=“C:\Programmer\iTunes\iTunesHelper.exe” [2007-12-11 12:10 267048]
“COMODO Firewall Pro”=“C:\Programmer\Comodo\Firewall\CPF.exe” [2008-01-13 18:46 1115728]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-27 13:00 15360]
“AVG7_Run”=“C:\PROGRA~1\Grisoft\AVG7\avgw.exe”
C:\Documents and Settings\All Users\Menuen Start\Programmer\Start
Adobe Reader Hurtigstart.lnk - C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
EVEMon.lnk - C:\Programmer\EVEMon\EVEMon.exe [2007-07-04 00:30:42]
Logitech SetPoint.lnk - C:\Programmer\Logitech\SetPoint\SetPoint.exe [2006-04-18 18:55:31]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
“{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}”= C:\Programmer\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify!SASWinLogon]
C:\Programmer\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programmer\SUPERAntiSpyware\SASWINLO.dll
R1 bbcap;bbcap;C:\WINDOWS\system32\DRIVERS\bbcap.sys [2007-04-01 12:18]
R3 LUsbKbd;Logitech SetPoint USB Keyboard Filter;C:\WINDOWS\system32\Drivers\LUsbKbd.Sys [2004-12-10 11:48]
S2 CamthWDM;WebcamMax, WDM Video Capture;C:\WINDOWS\system32\DRIVERS\CamthWDM.sys [2006-07-03 07:39]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{dc3e5e2a-ed34-11db-8d26-0013d448bbbe}]
\Shell\AutoRun\command - G:\Autorun.exe
Newly Created Service - CMDAGENT
Newly Created Service - CMDMON
Newly Created Service - INSPECT
Newly Created Service - PROCEXP90
.
Contents of the ‘Scheduled Tasks’ folder
“2008-01-04 15:46:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job”
- C:\Programmer\Apple Software Update\SoftwareUpdate.exe
.
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-13 19:20:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
.
Completion time: 2008-01-13 19:20:34
ComboFix-quarantined-files.txt 2008-01-13 18:20:20
.
2008-01-09 12:37:25 — E O F —