View Single Post
Old 05-09-2008, 06:16 AM   #1 (permalink)
Bcubbe
Registered User
 
Join Date: Apr 2008
Posts: 15
OS: Windows XP SP2


Vundo & Virtumonde

Hey, I have problem with this types of malware. I also got plenty of tracking cookies. I tried to install a fresh copy of Windows from original disc, but when I start the setup, fill blanks (CD-KEY, choose options) and start installation process, a warning comes out: "Restart your computer before continuing setup". I do restart and - the same thing again! A problem occurs also when I try to open a folder with image files arranged as thumbnails. It starts to reload previews of pictures but then crushes. PC pops up an error report: "Windows Explorer encountered an error and needs to be closed".
I tried to remove Vundo with VundoFix several times, but sometimes it doesn't even find it. Also tried to remove in safe mode with SuperAntiSpyware, but when I restart computer, the Vundo is back again

I've attached reports of Panda Activescan and Deckard's System Scanner.


Deckard's System Scanner v20071014.68
Run by Kolja on 2008-05-09 15:50:49
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
69: 2008-05-09 12:51:08 UTC - RP615 - Deckard's System Scanner Restore Point
68: 2008-05-07 16:20:00 UTC - RP614 - System Checkpoint
67: 1980-05-07 13:18:30 UTC - RP613 - System Checkpoint
66: 2080-05-06 16:14:32 UTC - RP612 - System Checkpoint
65: 1980-05-04 13:19:49 UTC - RP611 - System Checkpoint


-- First Restore Point --
1: 2008-04-13 18:59:56 UTC - RP547 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 511 MiB (512 MiB recommended).


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-05-09 15:57:32
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\WINDOWS\soundman.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\D-Tools\daemon.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe
C:\Documents and Settings\Kolja.HOME-F1AJP86A99\Desktop\Inga dokumendid\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\livemessenger.com
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Kolja.HOME-F1AJP86A99\Desktop\dss.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neti.ee/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=;gopher=;http=127.0.0.1:30;https=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {BED2D08D-8F0E-4A56-87F1-D4C5ED23DB1B} - (no file)
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [BlockChecker] C:\Program Files\Block Checker\block-checker.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender9\bdmcon.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "C:\Program Files\Softwin\BitDefender9\bdnagent.exe"
O4 - HKLM\..\Run: [BDSwitchAgent] "C:\Program Files\Softwin\BitDefender9\bdswitch.exe"
O4 - HKLM\..\Run: [OM_Monitor] D:\Olympus Master\FirstStart.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Windows live Messenger] msn.com
O4 - HKLM\..\Run: [744b2221] rundll32.exe "C:\WINDOWS\system32\mkqgclfh.dll",b
O4 - HKLM\..\Run: [BM777811bd] Rundll32.exe "C:\WINDOWS\system32\eecspycn.dll",s
O4 - HKLM\..\Run: [Microsoft Update] livemessenger.com
O4 - HKLM\..\RunOnceEx: [Microsoft Update] livemessenger.com
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PowerBar] "C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - HKCU\..\Run: [OM_Monitor] D:\Olympus Master\Monitor.exe -NoStart
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Documents and Settings\Kolja.HOME-F1AJP86A99\Desktop\Inga dokumendid\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Policies\Explorer\Run: [{744B228E-0643-1033-0817-050508100001}] "C:\Program Files\Common Files\{744B228E-0643-1033-0817-050508100001}\Update.exe" mc-110-12-0000904
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\nwprovau.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1140367992796
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1140535017671
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://cam.raad.tartu.ee/activex/AxisCamControl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Unknown owner - C:\Program
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender9\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
O24 - Desktop Component 0: - http://pics.rate.ee/pics/skins/d1/back.gif

--
End of file - 12698 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 cdrbsdrv - c:\windows\system32\drivers\cdrbsdrv.sys <Not Verified; B.H.A Corporation; B's Recorder GOLD7>
R1 VIAPFD - c:\windows\system32\drivers\viapfd.sys <Not Verified; VIA Technologies. Inc.; VIA PFD driver>
R2 io.sys (IO.DLL Driver) - c:\windows\system32\drivers\io.sys
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>

S1 xpdx (xpdx system driver) - c:\windows\system32\xpdx.sys (file missing)
S2 BDRSDRV - c:\program files\softwin\bitdefender9\bdrsdrv.sys (file missing)
S3 AvFlt (Antivirus Filter Driver) - c:\windows\system32\drivers\av5flt.sys (file missing)
S3 bdfdll - c:\program files\softwin\bitdefender9\bdfdll.sys (file missing)
S3 BDFSDRV - c:\program files\softwin\bitdefender9\bdfsdrv.sys (file missing)
S3 SABProcEnum - c:\progra~1\mozill~1\sabprocenum.sys (file missing)
S3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S3 XTrapD12 - c:\windows\system32\xtrapd12.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

S2 bdss (BitDefender Scan Server) - "c:\program files\common files\softwin\bitdefender scan server\bdss.exe" /service (file missing)
S3 Boonty Games - "c:\program files\common files\boonty shared\service\boonty.exe" <Not Verified; BOONTY; Boonty Games>


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Files created between 2008-04-09 and 2008-05-09 -----------------------------

2008-05-09 15:42:34 0 d-------- C:\Program Files\SpywareBlaster
2008-04-25 14:46:02 0 d-------- C:\VundoFix Backups
2008-04-25 14:09:38 0 d-------- C:\$WIN_NT$.~BT
2008-04-24 16:30:25 0 d-------- C:\WINDOWS\pss
2008-04-24 16:20:04 96320 --a------ C:\WINDOWS\system32\ioeiluib.dll
2008-04-24 15:57:12 96320 --a------ C:\WINDOWS\system32\caqkivyy.dll
2008-04-24 14:37:22 96320 --a------ C:\WINDOWS\system32\arsoiiwm.dll
2008-04-24 07:38:26 95808 --a------ C:\WINDOWS\system32\eeitgmfd.dll
2008-04-23 22:05:23 95808 --a------ C:\WINDOWS\system32\eyqlnymo.dll
2008-04-23 14:17:56 95808 --a------ C:\WINDOWS\system32\jrwvteay.dll
2008-04-23 07:31:33 97856 --a------ C:\WINDOWS\system32\hlssxqlt.dll
2008-04-22 19:20:15 97856 --a------ C:\WINDOWS\system32\brkfspuc.dll
2008-04-22 17:24:09 87616 --a------ C:\WINDOWS\system32\okpyvhko.dll
2008-04-22 17:22:32 97856 --a------ C:\WINDOWS\system32\jieciufl.dll
2008-04-22 14:00:23 97856 --a------ C:\WINDOWS\system32\wfttgiwg.dll
2008-04-22 07:36:55 97344 --a------ C:\WINDOWS\system32\ybreaqcn.dll
2008-04-21 15:13:36 97344 --a------ C:\WINDOWS\system32\moyyldej.dll
2008-04-21 07:33:33 96320 --a------ C:\WINDOWS\system32\asbscooo.dll
2008-04-20 22:12:13 96320 --a------ C:\WINDOWS\system32\sukkdgat.dll
2008-04-20 22:11:51 186820 --ahs---- C:\WINDOWS\system32\lnorrtwa.ini2
2008-04-20 21:54:55 0 d-------- C:\WINDOWS\system32\SuperAdBlocker.com
2008-04-20 19:45:40 96320 --a------ C:\WINDOWS\system32\xwrmondg.dll
2008-04-20 19:43:41 38400 --a------ C:\WINDOWS\system32\ljJCvtqP.dll
2008-04-20 12:07:29 38400 --a------ C:\WINDOWS\system32\nnnnKefC.dll
2008-04-20 10:49:13 38400 --a------ C:\WINDOWS\system32\urqNEwVP.dll
2008-04-19 21:04:13 38400 --a------ C:\WINDOWS\system32\urqRJDWM.dll
2008-04-19 13:05:35 557056 --a------ C:\WINDOWS\system32\WONshell.dll <Not Verified; World Opponent Network\r\nA division of Havas Interactive; World Opponent Network WONshell>
2008-04-19 13:05:35 196608 --a------ C:\WINDOWS\system32\WONauth.dll <Not Verified; WON.net; a division of Havas Interactive; WON.net WONauth>
2008-04-19 13:05:35 233472 --a------ C:\WINDOWS\system32\SNWValid.dll <Not Verified; Havas Interactive; World Opponent Network WONplay>
2008-04-19 13:05:35 24928 --a------ C:\WINDOWS\system32\Sigres.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows NT(R) Operating System>
2008-04-19 13:05:35 1204224 --a------ C:\WINDOWS\system32\SierraNW.dll <Not Verified; Havas Interactive; World Opponent Network WONplay>
2008-04-19 13:05:35 44544 --a------ C:\WINDOWS\system32\GIF89.DLL <Not Verified; ; Gif89 Module>
2008-04-19 12:58:37 37888 --a------ C:\WINDOWS\system32\fccywwur.dll
2008-04-18 18:09:21 37888 --a------ C:\WINDOWS\system32\khfDsRIX.dll
2008-04-18 15:39:14 37888 --a------ C:\WINDOWS\system32\rqRIYQhh.dll
2008-04-18 12:04:39 37888 --a------ C:\WINDOWS\system32\efcDWQhe.dll
2008-04-18 09:10:02 204317 --ahs---- C:\WINDOWS\system32\SuxFNXbc.ini2
2008-04-13 21:59:35 157575 --ahs---- C:\WINDOWS\system32\vxIOnnmp.ini2
2008-04-09 19:57:38 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SweetIM


-- Find3M Report ---------------------------------------------------------------

2080-05-06 21:25:08 0 d-------- C:\Documents and Settings\Kolja.HOME-F1AJP86A99\Application Data\Skype
2008-05-09 15:36:11 0 d-------- C:\Program Files\LimeWire
2008-05-09 15:27:55 0 d-------- C:\Program Files\Incomplete
2008-05-09 14:36:24 0 d-------- C:\Documents and Settings\Kolja.HOME-F1AJP86A99\Application Data\LimeWire
2008-05-02 20:19:45 39936 -rahs---- C:\WINDOWS\livemessenger.com
2008-04-29 16:21:29 0 d-------- C:\Documents and Settings\Kolja.HOME-F1AJP86A99\Application Data\U3
2008-04-27 21:43:18 21472 --a------ C:\Documents and Settings\Kolja.HOME-F1AJP86A99\Application Data\GDIPFONTCACHEV1.DAT
2008-04-24 16:15:01 0 d-------- C:\Program Files\Sierra On-Line
2008-04-24 16:14:41 0 d-------- C:\Program Files\Windows Live
2008-04-24 16:14:30 0 d-------- C:\Program Files\MSN Messenger
2008-04-24 16:14:17 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-04-24 16:02:54 0 d-------- C:\Program Files\Windows Live Toolbar
2008-04-17 17:45:06 0 d-------- C:\Documents and Settings\Kolja.HOME-F1AJP86A99\Application Data\SUPERAntiSpyware.com
2008-04-17 17:44:31 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-08 14:50:49 907 --a------ C:\WINDOWS\eReg.dat
2008-04-06 22:01:53 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-06 18:07:39 0 d-------- C:\Program Files\Infogrames
2008-04-04 15:40:19 0 d-------- C:\Documents and Settings\Kolja.HOME-F1AJP86A99\Application Data\BearShare
2008-02-28 13:05:18 47104 --a------ C:\WINDOWS\system32\KMVIDC32.DLL


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BED2D08D-8F0E-4A56-87F1-D4C5ED23DB1B}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [02/22/2005 09:05 PM]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [06/10/2005 05:20 PM]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 12:50 PM]
"SoundMan"="SOUNDMAN.EXE" [01/20/2005 03:04 PM C:\WINDOWS\soundman.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [03/14/2007 03:43 AM]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" []
"BlockChecker"="C:\Program Files\Block Checker\block-checker.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [07/10/2006 12:35 PM]
"BDMCon"="C:\Program Files\Softwin\BitDefender9\bdmcon.exe" []
"BDNewsAgent"="C:\Program Files\Softwin\BitDefender9\bdnagent.exe" []
"BDSwitchAgent"="C:\Program Files\Softwin\BitDefender9\bdswitch.exe" []
"OM_Monitor"="D:\Olympus Master\FirstStart.exe" [05/16/2006 05:50 PM]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [08/22/2004 05:05 PM]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [06/08/2005 04:24 PM]
"LogitechGalleryRepair"="C:\Program Files\Logitech\ImageStudio\ISStart.exe" [12/10/2002 07:32 PM]
"LogitechImageStudioTray"="C:\Program Files\Logitech\ImageStudio\LogiTray.exe" [12/10/2002 07:31 PM]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [07/19/2005 06:32 PM]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [06/08/2005 04:14 PM]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [02/07/2007 04:24 PM]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [02/07/2007 04:21 PM]
"@"="" []
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [10/26/2005 05:17 PM]
"Windows live Messenger"="msn.com" []
"744b2221"="C:\WINDOWS\system32\mkqgclfh.dll" []
"BM777811bd"="C:\WINDOWS\system32\eecspycn.dll" []
"Microsoft Update"="livemessenger.com" [05/02/2008 08:19 PM C:\WINDOWS\livemessenger.com]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 10:56 AM]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 11:34 AM]
"PowerBar"="C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" [04/21/2004 11:26 AM]
"OM_Monitor"="D:\Olympus Master\Monitor.exe" [05/16/2006 05:51 PM]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" []
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [06/08/2005 03:44 PM]
"DNA"="C:\Program Files\BitTorrent_DNA\dna.exe" []
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" []
"Picasa Media Detector"="C:\Documents and Settings\Kolja.HOME-F1AJP86A99\Desktop\Inga dokumendid\Picasa2\PicasaMediaDetector.exe" [10/24/2007 12:18 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/29/2008 04:03 PM]

C:\Documents and Settings\Kolja.HOME-F1AJP86A99\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [3/16/2005 8:16:50 PM]
PowerReg Scheduler V3.exe [6/6/2006 1:28:56 PM]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [12/25/2006 5:13:41 PM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 2:01:04 AM]
VIA RAID TOOL.lnk - C:\Program Files\VIA\RAID\raid_tool.exe [12/15/2005 6:24:10 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=1 (0x1)
"DisableRegistrytools"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"{744B228E-0643-1033-0817-050508100001}"="C:\Program Files\Common Files\{744B228E-0643-1033-0817-050508100001}\Update.exe" mc-110-12-0000904

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 nwprovau C:\WINDOWS\system32\awtrronl
"Notification Packages"= :\WINDOWS\SYSTE

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"




-- End of Deckard's System Scanner: finished at 2008-05-09 15:59:31 ------------
Attached Files
File Type: txt ActiveScan.txt (36.8 KB, 0 views)
File Type: txt main.txt (25.2 KB, 3 views)

Last edited by tetonbob : 05-15-2008 at 07:59 PM.
Bcubbe is offline   Reply With Quote