Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 06-05-2008, 02:32 PM   #1 (permalink)
Registered User
 
Join Date: Jun 2008
Posts: 7
OS: XP


Pulling my hair out.

Explorer dies, random pop ups fly, and Norton scream Trojan.Lowzones.

MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\veqwfjga.dll",s
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

Please help, thanks in advance.
kniteshift is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 06-05-2008, 10:42 PM   #2 (permalink)
Registered User
 
Join Date: Jun 2008
Posts: 7
OS: XP


Re: Pulling my hair out.

I also tried to use the pandasecurity scan but Mozilla and IE kept on crashing with 10510515025 pop ups everytime it tries to scan. I've also followed the five steps but I can't access the downloads at all because again my mozilla and I.E. both end up crashing, at boot up I can access this page and very few other pages, for some reason I'm limited to a lot of other pages like google, or yahoo.
kniteshift is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-05-2008, 10:46 PM   #3 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,792
OS: WinXP and Vista


Re: Pulling my hair out.

Hello kniteshift,

Do you have access to another computer whereby you can download the necessary tools to a flash drive, then transfer to this infected computer?
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-06-2008, 02:02 AM   #4 (permalink)
Registered User
 
Join Date: Jun 2008
Posts: 7
OS: XP


Re: Pulling my hair out.

Deckard's System Scanner v20071014.68
Run by <insname> on 2008-06-04 21:56:33
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 2 Restore Point(s) --
2: 2008-06-05 04:56:41 UTC - RP2 - Deckard's System Scanner Restore Point
1: 2008-06-04 21:38:18 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

System Drive C: has 24.21 GiB (less than 15%) free.


-- HijackThis (run as Chung.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:59:28 PM, on 2008-06-04
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Chung\My Documents\dss.exe
C:\WINDOWS\explorer.exe
C:\DOCUME~1\Chung\MYDOCU~1\download\FREEKN~1\HIJACK~1\Chung.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {487C9905-26A8-42C8-8033-C58AD3D2AEC3} - C:\WINDOWS\system32\mlJCRlkI.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {E931BDB3-013B-4D15-9186-6B23B5929E9F} - C:\WINDOWS\system32\mlJApqpp.dll
O2 - BHO: {2a3b4dad-1c6b-0138-ada4-7d043f9030af} - {fa0309f3-40d7-4ada-8310-b6c1dad4b3a2} - C:\WINDOWS\system32\gjfqavsn.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: mlJCRlkI - C:\WINDOWS\SYSTEM32\mlJCRlkI.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 7240 bytes

-- HijackThis Fixed Entries (C:\DOCUME~1\Chung\MYDOCU~1\download\FREEKN~1\HIJACK~1\backups\) --------------------------------------------------------------------------------

backup-20080603-020404-195 O4 - HKLM\..\Run: [300f9797] rundll32.exe "C:\WINDOWS\system32\cpurvlbg.dll",b
backup-20080603-020404-589 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\opultmvl.dll",s
backup-20080604-080755-625 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\veqwfjga.dll",s
backup-20080604-080755-792 O4 - HKLM\..\Run: [300f9797] rundll32.exe "C:\WINDOWS\system32\tacrmnqv.dll",b
backup-20080604-080918-852 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\veqwfjga.dll",s
backup-20080604-080933-339 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\veqwfjga.dll",s
backup-20080604-082035-667 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\veqwfjga.dll",s
backup-20080604-104921-755 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\cbxtvbje.dll",s
backup-20080604-132817-637 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\aexymhqk.dll",s
backup-20080604-195957-981 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\aexymhqk.dll",s
backup-20080604-214549-930 O4 - HKLM\..\Run: [300f9797] rundll32.exe "C:\WINDOWS\system32\jjseltbq.dll",b

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>

S2 ProtexisLicensing -
S3 AresChatServer (Ares Chatroom server) - c:\program files\ares\chatserver.exe <Not Verified; Ares Development Group; Ares Chat Server>
S3 FLEXnet Licensing Service -
S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: RAID Controller
Device ID: PCI\VEN_105A&DEV_3373&SUBSYS_80F51043&REV_02\4&2E98101C&0&20F0
Manufacturer:
Name: RAID Controller
PNP Device ID: PCI\VEN_105A&DEV_3373&SUBSYS_80F51043&REV_02\4&2E98101C&0&20F0
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Ethernet Controller
Device ID: PCI\VEN_11AB&DEV_4320&SUBSYS_811A1043&REV_13\4&2E98101C&0&28F0
Manufacturer:
Name: Ethernet Controller
PNP Device ID: PCI\VEN_11AB&DEV_4320&SUBSYS_811A1043&REV_13\4&2E98101C&0&28F0
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Multimedia Audio Controller
Device ID: PCI\VEN_8086&DEV_24D5&SUBSYS_812A1043&REV_02\3&267A616A&0&FD
Manufacturer:
Name: Multimedia Audio Controller
PNP Device ID: PCI\VEN_8086&DEV_24D5&SUBSYS_812A1043&REV_02\3&267A616A&0&FD
Service:


-- Scheduled Tasks -------------------------------------------------------------

2008-06-03 17:19:02 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


-- Files created between 2008-05-04 and 2008-06-04 -----------------------------

2008-06-04 18:27:24 86016 --a------ C:\WINDOWS\system32\cttele.dll <Not Verified; Creative Technology Ltd; Creative Common Proxy Stud>
2008-06-04 18:19:17 2560 --a------ C:\WINDOWS\CTXFIRES.DLL <Not Verified; ; CTxfiRes Dynamic Link Library>
2008-06-04 18:12:57 0 d-------- C:\Program Files\Panda Security
2008-06-04 13:31:00 133120 --a------ C:\WINDOWS\system32\gjfqavsn.dll
2008-06-04 13:28:13 117248 --a------ C:\WINDOWS\system32\jjseltbq.dll
2008-06-04 13:25:47 126976 --a------ C:\WINDOWS\system32\aexymhqk.dll
2008-06-04 13:24:59 796598 --ahs---- C:\WINDOWS\system32\ppqpAJlm.ini2
2008-06-04 13:24:49 372736 --a------ C:\WINDOWS\system32\mlJApqpp.dll
2008-06-04 1138 53248 --a------ C:\WINDOWS\PSEXESVC.EXE <Not Verified; Sysinternals; Sysinternals PsExec>
2008-06-04 10:49:16 0 d-------- C:\Documents and Settings\Administrator\Application Data\Simply Super Software
2008-06-03 22:22:34 68096 --a------ C:\WINDOWS\zip.exe
2008-06-03 22:22:34 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-06-03 22:22:34 98816 --a------ C:\WINDOWS\sed.exe
2008-06-03 22:22:34 80412 --a------ C:\WINDOWS\grep.exe
2008-06-03 22:22:34 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-06-03 22:22:33 49152 --a------ C:\WINDOWS\VFind.exe
2008-06-03 22:22:33 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-06-03 22:22:33 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-06-03 21:27:38 0 d-------- C:\Program Files\Lavasoft
2008-06-03 21:27:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-03 21:14:11 153088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-06-03 21:14:11 75264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-06-03 21:14:08 0 d-------- C:\Program Files\Trojan Remover
2008-06-03 21:14:08 0 d-------- C:\Documents and Settings\Chung\Application Data\Simply Super Software
2008-06-03 14:14:43 0 d-------- C:\Documents and Settings\Chung\Application Data\HouseCall 6.6
2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-06-03 11:22:45 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-06-03 11:22:45 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-06-03 11:22:45 1048576 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-06-03 11:22:45 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-06-03 11:22:45 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-06-03 11:22:45 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-06-03 11:22:33 0 d-------- C:\WINDOWS\CSC
2008-06-03 11:09:20 0 d-------- C:\Documents and Settings\LocalService\Application Data\Macromedia
2008-06-03 10:56:29 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-06-03 03:24:20 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-03 03:23:05 0 d-------- C:\Program Files\Spyware Doctor
2008-06-02 20:37:34 57344 --a------ C:\WINDOWS\system32\mlJCRlkI.dll
2008-06-01 18:45:23 76166 --a------ C:\WINDOWS\War3Unin.dat
2008-06-01 18:45:22 2829 --a------ C:\WINDOWS\War3Unin.pif
2008-06-01 18:45:22 139264 --a------ C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2008-05-29 15:10:07 0 d-------- C:\Program Files\iPod
2008-05-29 15:09:45 0 d-------- C:\Program Files\iTunes
2008-05-15 01:49:26 0 d-------- C:\Documents and Settings\All Users\Application Data\media center programs
2008-05-14 22:14:13 0 d-------- C:\Program Files\Funcom
2008-05-14 21:33:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Funcom
2008-05-11 20:21:08 0 d-------- C:\Documents and Settings\Chung\Application Data\SystemRequirementsLab
2008-05-11 20:11:47 0 d-------- C:\WINDOWS\system32\Futuremark
2008-05-11 20:11:46 0 d-------- C:\Program Files\Common Files\Futuremark Shared
2008-05-11 20:11:36 0 d-------- C:\Documents and Settings\Chung\Application Data\InstallShield
2008-05-10 19:40:01 0 d-------- C:\Documents and Settings\Default User\Application Data\Apple Computer


-- Find3M Report ---------------------------------------------------------------

2008-06-04 18:36:24 0 d-------- C:\Program Files\Symantec AntiVirus
2008-06-04 18:27:53 0 d-------- C:\Program Files\Creative Professional
2008-06-04 18:23:19 409600 --a------ C:\WINDOWS\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
2008-06-04 18:23:19 114688 --a------ C:\WINDOWS\system32\OpenAL32.dll <Not Verified; Portions (C) Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL(TM) Library>
2008-06-04 18:14:29 0 d-------- C:\Program Files\Viewpoint
2008-06-03 21:26:36 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-03 21:21:45 0 d-------- C:\Program Files\Google
2008-06-03 20:52:35 0 d-------- C:\Documents and Settings\Chung\Application Data\uTorrent
2008-06-03 11:19:43 0 d-------- C:\Program Files\Common Files
2008-06-03 08:32:08 0 d-------- C:\Program Files\Warcraft III
2008-06-02 22:32:45 0 d-------- C:\Documents and Settings\Chung\Application Data\Adobe
2008-06-02 21:03:07 0 d-------- C:\Program Files\Common Files\Adobe
2008-06-01 17:20:12 0 d-------- C:\Program Files\Apple Software Update
2008-05-29 15:05:53 0 d-------- C:\Program Files\QuickTime
2008-05-22 22:51:17 0 d-------- C:\Program Files\World of Warcraft
2008-05-18 14:14:05 0 d-------- C:\Program Files\mIRC
2008-05-15 23:28:24 0 d-------- C:\Program Files\Common Files\AOL
2008-05-15 23:28:24 0 d-------- C:\Program Files\AIM
2008-05-11 20:11:44 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-01 01:40:43 0 d-------- C:\Program Files\AIM6
2008-04-12 08:19:24 0 d-------- C:\Program Files\Anti Keylogger Shield
2008-03-20 15:36:48 43520 --a------ C:\WINDOWS\system32\CTBurst.dll <Not Verified; ; CTBurst Module>
2008-03-20 15:35:52 34816 --a------ C:\WINDOWS\system32\a3d.dll <Not Verified; ; a3dx5>
2008-03-20 15:35:38 27648 --a------ C:\WINDOWS\system32\ac3api.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:35:14 41472 --a------ C:\WINDOWS\system32\CTxfiBtn.dll <Not Verified; Creative Technology Ltd; CTXFIBTN Dynamic Link Library>
2008-03-20 15:35:10 40960 --a------ C:\WINDOWS\system32\CTxfiSpk.dll <Not Verified; Creative Technology Ltd; Ctxfispk Dynamic Link Library>
2008-03-20 15:35:10 23552 --a------ C:\WINDOWS\system32\Ctxfihlp.exe <Not Verified; Creative Technology Ltd; CTXfiHlp Application>
2008-03-20 15:35:06 41472 --a------ C:\WINDOWS\system32\psconv.exe
2008-03-20 15:35:04 23040 --a------ C:\WINDOWS\system32\CtHelper.exe <Not Verified; Creative Technology Ltd; CtHelper Application>
2008-03-20 15:35:02 12800 --a------ C:\WINDOWS\system32\CTAGENT.DLL <Not Verified; Creative Technology Ltd; ctagent>
2008-03-20 15:35:00 38912 --a------ C:\WINDOWS\system32\CTSPKHLP.DLL <Not Verified; Creative Technology Ltd; CtSpkHlp Dynamic Link Library>
2008-03-20 15:34:58 51200 --a------ C:\WINDOWS\system32\CTpcmcia.dll <Not Verified; Creative Technology Ltd; CTPCMCIA Dynamic Link Library>
2008-03-20 15:34:58 17920 --a------ C:\WINDOWS\system32\ctmmep.dll <Not Verified; Creative Technology Ltd; Ctmmep Dynamic Link Library>
2008-03-20 15:34:50 36864 --a------ C:\WINDOWS\system32\ctthxcal.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:34:50 8704 --a------ C:\WINDOWS\system32\ctpres.dll <Not Verified; Creative Technology Ltd; CtPanel Resource>
2008-03-20 15:34:48 46592 --a------ C:\WINDOWS\system32\ctscal.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:34:46 145408 --a------ C:\WINDOWS\system32\CTDCIFCE.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:34:46 343040 --a------ C:\WINDOWS\system32\ctdc0001.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:34:44 10240 --a------ C:\WINDOWS\system32\ctdcres.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:34:44 230400 --a------ C:\WINDOWS\system32\ctdc0000.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:34:44 10240 --a------ C:\WINDOWS\CTDCRES.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:31:22 46592 --a------ C:\WINDOWS\system32\Ctxfireg.exe <Not Verified; Creative Technology Ltd; CTXFIREG>
2008-03-20 15:31:20 15360 --a------ C:\WINDOWS\system32\Ct20xspi.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:31:14 1119744 --a------ C:\WINDOWS\system32\CTxfispi.exe <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:25:22 46273 --a------ C:\WINDOWS\system32\ctdnlstr.dat
2008-03-20 15:25:22 325821 --a------ C:\WINDOWS\system32\ctdlang.dat
2008-03-20 15:24:54 114688 --a------ C:\WINDOWS\system32\ctemupia.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:50 22016 --a------ C:\WINDOWS\system32\ctedasio.dll <Not Verified; Creative Technology, Ltd; Creative Audio Product>
2008-03-20 15:22:48 50688 --a------ C:\WINDOWS\system32\ctasio.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:48 151040 --a------ C:\WINDOWS\system32\ct_oal.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:44 53248 --a------ C:\WINDOWS\system32\CTDPROXY.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:30 74240 --a------ C:\WINDOWS\system32\CTOSUSER.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:28 10240 --a------ C:\WINDOWS\system32\sfman32.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:26 108544 --a------ C:\WINDOWS\system32\SFMS32.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:24 16384 --a------ C:\WINDOWS\system32\regplib.exe
2008-03-20 15:22:22 68608 --a------ C:\WINDOWS\system32\PIAPROXY.DLL <Not Verified; Creative Technology Ltd; E-mu PIA>
2008-03-20 15:21:58 149838 --a------ C:\WINDOWS\system32\ctbas2w.dat
2008-03-20 15:20:12 274587 --a------ C:\WINDOWS\system32\ctsbas2w.dat
2008-03-20 15:20:02 115166 --a------ C:\WINDOWS\system32\CTBASICW.DAT
2008-03-20 15:20:00 241084 --a------ C:\WINDOWS\system32\CTSBASW.DAT
2008-03-20 15:19:44 313207 --a------ C:\WINDOWS\system32\ctstatic.dat
2008-03-20 15:19:44 53932 --a------ C:\WINDOWS\system32\ctdaught.dat
2008-03-20 15:19:42 7680 --a------ C:\WINDOWS\system32\enlocstr.exe
2008-03-20 15:19:40 12800 --a------ C:\WINDOWS\system32\killapps.exe <Not Verified; ; killapps>
2008-03-20 15:19:26 31232 --a------ C:\WINDOWS\system32\MIDIDEF.EXE <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:19:26 36864 --a------ C:\WINDOWS\system32\devreg.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{487C9905-26A8-42C8-8033-C58AD3D2AEC3}]
2008-06-02 08:37 PM 57344 --a------ C:\WINDOWS\system32\mlJCRlkI.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E931BDB3-013B-4D15-9186-6B23B5929E9F}]
2008-06-04 01:24 PM 372736 --a------ C:\WINDOWS\system32\mlJApqpp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fa0309f3-40d7-4ada-8310-b6c1dad4b3a2}]
2008-06-04 01:31 PM 133120 --a------ C:\WINDOWS\system32\gjfqavsn.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 AM]
"nwiz"="nwiz.exe" [2007-12-05 02:41 AM C:\WINDOWS\system32\nwiz.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 08:26 PM]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 09:33 PM]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 AM]
"CTHelper"="CTHELPER.EXE" [2008-03-20 03:35 PM C:\WINDOWS\system32\CtHelper.exe]
"CTxfiHlp"="CTXFIHLP.EXE" [2008-03-20 03:35 PM C:\WINDOWS\system32\Ctxfihlp.exe]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:56 AM]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 08:44 PM]
"SetDefaultMIDI"="MIDIDef.exe" [2008-03-20 03:19 PM C:\WINDOWS\system32\MIDIDEF.EXE]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{487C9905-26A8-42C8-8033-C58AD3D2AEC3}"= C:\WINDOWS\system32\mlJCRlkI.dll [2008-06-02 08:37 PM 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJCRlkI]
mlJCRlkI.dll 2008-06-02 08:37 PM 57344 C:\WINDOWS\system32\mlJCRlkI.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mlJApqpp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk]
path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk
backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\300f9797]
rundll32.exe "C:\WINDOWS\system32\ytoyancc.dll",b

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
"C:\Program Files\Ares\Ares.exe" -h

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM333ca40b]
Rundll32.exe "C:\WINDOWS\system32\ylkufogk.dll",s

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
C:\Program Files\Trojan Remover\Trjscan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}]
C:\Program Files\Google\Gmail Notifier\gnotify.exe


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7dbe02d0-6a35-11dc-be2b-00904b2bc814}]
AutoRun\command- ie.exe
explore\Command- ie.exe
open\Command- ie.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc69911f-934e-11dc-be2d-00904b2bc814}]
AutoRun\command- F:\setupSNK.exe




-- End of Deckard's System Scanner: finished at 2008-06-04 22:00:55 ------------

That's with deckard, the only thing I could get running :\
kniteshift is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-06-2008, 07:41 AM   #5 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,792
OS: WinXP and Vista


Re: Pulling my hair out.

You did fine, knightshift.

This will require more than one round to properly eradicate. Please stay with me until given the 'all clear' even if symptoms seemingly abate.

Read through this entire procedure and if you have any questions, please ask them before you begin. Then either print out, or copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.


It's IMPORTANT to carry out the instructions in the sequence listed below.


***************************************************

Download ComboFix.exe from any of the links below:

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Go to Microsoft's website => http://support.microsoft.com/kb/310994

Select the download that's appropriate for your Operating System




Download the file & save it as it's originally named, next to ComboFix.exe.






--------------------------------------------------------------------

If you used another computer to download the above, please transfer all files you just downloaded, to the desktop of the infected computer.

--------------------------------------------------------------------

Now close all open windows and programs, including all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Drag the setup package onto ComboFix.exe and drop it.
  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.



  • At the next prompt, click 'Yes' to run the full ComboFix scan.
  • When the tool is finished, it will produce a report for you.
Please post the C:\ComboFix.txt along with a new HijackThis log for further review.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-06-2008, 12:00 PM   #6 (permalink)
Registered User
 
Join Date: Jun 2008
Posts: 7
OS: XP


Re: Pulling my hair out.

Thanks for your help! Here's the log from ComboFix.

ComboFix 08-05-25.5 - Chung 2008-06-05 10:30:52.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1073 [GMT -7:00]
Running from: C:\Documents and Settings\Chung\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Chung\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BM333ca40b.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bkrlcsnn.ini
C:\WINDOWS\system32\gfffwsjx.ini
C:\WINDOWS\system32\mTuvDfhk.ini
C:\WINDOWS\system32\mTuvDfhk.ini2
C:\WINDOWS\system32\nnsclrkb.dll
C:\WINDOWS\system32\tvvwvyxx.ini
C:\WINDOWS\system32\tvvwvyxx.ini2
C:\WINDOWS\system32\wsqtuksj.dll

.
((((((((((((((((((((((((( Files Created from 2008-05-05 to 2008-06-05 )))))))))))))))))))))))))))))))
.

2008-06-05 10:35 . 2008-06-05 10:35 11,564 --a------ C:\WINDOWS\system32\DVCState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx
2008-06-05 10:35 . 2008-06-05 10:35 1,524 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx
2008-06-05 10:35 . 2008-06-05 10:35 1,524 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx
2008-06-05 10:35 . 2008-06-05 10:35 64 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx
2008-06-05 10:35 . 2008-06-05 10:35 64 --a------ C:\WINDOWS\system32\BMXState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx
2008-06-05 10:22 . 2008-06-05 10:22 125,952 --a------ C:\WINDOWS\system32\cdolfjcs.dll
2008-06-05 10:21 . 2008-06-05 10:21 373,760 --a------ C:\WINDOWS\system32\xxyvwvvt.dll
2008-06-05 09:33 . 2008-06-05 09:34 321 --a------ C:\WINDOWS\wininit.ini
2008-06-05 00:40 . 2008-06-05 00:40 133,120 --a------ C:\WINDOWS\system32\mrvotahb.dll
2008-06-05 00:39 . 2008-06-05 00:39 117,248 --a------ C:\WINDOWS\system32\xjswfffg.dll
2008-06-05 00:38 . 2008-06-05 00:38 126,976 --a------ C:\WINDOWS\system32\lagrvrbj.dll
2008-06-05 00:32 . 2008-06-05 00:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-06-04 22:14 . 2008-06-04 22:14 <DIR> d-------- C:\Program Files\CCleaner
2008-06-04 21:56 . 2008-06-04 21:56 <DIR> d-------- C:\Deckard
2008-06-04 18:27 . 2006-11-14 15:28 86,016 --a------ C:\WINDOWS\system32\cttele.dll
2008-06-04 18:19 . 2008-03-20 15:35 2,560 --a------ C:\WINDOWS\CTXFIRES.DLL
2008-06-04 18:12 . 2008-06-04 18:17 <DIR> d-------- C:\Program Files\Panda Security
2008-06-04 10:49 . 2008-06-04 10:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Simply Super Software
2008-06-03 21:27 . 2008-06-03 21:27 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-03 21:27 . 2008-06-03 21:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-03 21:14 . 2008-06-03 11:30 <DIR> d-------- C:\Program Files\Trojan Remover
2008-06-03 21:14 . 2008-06-03 21:14 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\Simply Super Software
2008-06-03 21:14 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-06-03 21:14 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-06-03 15:13 . 2008-06-03 15:12 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-03 14:14 . 2008-06-03 14:14 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\HouseCall 6.6
2008-06-03 11:22 . 2008-05-10 19:40 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-06-03 11:22 . 2008-06-04 22:22 <DIR> d-------- C:\Documents and Settings\Administrator
2008-06-03 03:24 . 2008-06-04 22:27 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-03 03:23 . 2008-06-03 21:38 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-06-02 20:37 . 2008-06-02 20:37 57,344 --a------ C:\WINDOWS\system32\mlJCRlkI.dll
2008-06-01 18:45 . 2008-06-01 18:53 139,264 --a------ C:\WINDOWS\War3Unin.exe
2008-06-01 18:45 . 2008-06-01 18:59 76,166 --a------ C:\WINDOWS\War3Unin.dat
2008-06-01 18:45 . 2008-06-01 18:53 2,829 --a------ C:\WINDOWS\War3Unin.pif
2008-05-29 15:10 . 2008-05-29 15:10 <DIR> d-------- C:\Program Files\iPod
2008-05-29 15:09 . 2008-05-29 15:10 <DIR> d-------- C:\Program Files\iTunes
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\system32\lsdelete.exe
2008-05-15 01:52 . 2008-03-05 15:56 3,786,760 --a------ C:\WINDOWS\system32\D3DX9_37.dll
2008-05-15 01:52 . 2008-03-05 15:56 1,420,824 --a------ C:\WINDOWS\system32\D3DCompiler_37.dll
2008-05-15 01:52 . 2008-03-05 16:03 479,752 --a------ C:\WINDOWS\system32\XAudio2_0.dll
2008-05-15 01:52 . 2008-02-05 23:07 462,864 --a------ C:\WINDOWS\system32\d3dx10_37.dll
2008-05-15 01:52 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll
2008-05-15 01:52 . 2008-03-05 16:03 238,088 --a------ C:\WINDOWS\system32\xactengine3_0.dll
2008-05-15 01:52 . 2008-03-05 16:00 25,608 --a------ C:\WINDOWS\system32\X3DAudio1_3.dll
2008-05-15 01:49 . 2008-05-15 01:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\media center programs
2008-05-14 22:14 . 2008-05-14 22:14 <DIR> d-------- C:\Program Files\Funcom
2008-05-14 21:33 . 2008-05-14 21:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Funcom
2008-05-11 20:21 . 2008-05-11 20:21 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\SystemRequirementsLab
2008-05-11 20:11 . 2008-05-11 20:11 <DIR> d-------- C:\WINDOWS\system32\Futuremark
2008-05-11 20:11 . 2008-05-11 20:11 <DIR> d-------- C:\Program Files\Common Files\Futuremark Shared
2008-05-11 20:11 . 2008-05-11 20:11 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\InstallShield
2008-05-11 20:11 . 2007-08-20 11:05 27,672 -ra------ C:\WINDOWS\system32\drivers\Entech.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-05 17:37 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-06-05 01:27 --------- d-----w C:\Program Files\Creative Professional
2008-06-05 01:23 409,600 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-06-05 01:23 114,688 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-06-05 01:14 --------- d-----w C:\Program Files\Viewpoint
2008-06-05 01:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-06-04 04:26 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-04 04:21 --------- d-----w C:\Program Files\Google
2008-06-04 03:52 --------- d-----w C:\Documents and Settings\Chung\Application Data\uTorrent
2008-06-03 15:32 --------- d-----w C:\Program Files\Warcraft III
2008-06-03 04:03 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-02 00:20 --------- d-----w C:\Program Files\Apple Software Update
2008-05-29 22:05 --------- d-----w C:\Program Files\QuickTime
2008-05-23 05:51 --------- d-----w C:\Program Files\World of Warcraft
2008-05-18 21:14 --------- d-----w C:\Program Files\mIRC
2008-05-16 06:28 --------- d-----w C:\Program Files\Common Files\AOL
2008-05-16 06:28 --------- d-----w C:\Program Files\AIM
2008-05-12 03:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-01 08:40 --------- d-----w C:\Program Files\AIM6
2008-05-01 08:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-04-29 18:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 18:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 18:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-12 15:19 --------- d-----w C:\Program Files\Anti Keylogger Shield
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 22:36 86,016 ----a-w C:\WINDOWS\system32\ctcoinst.dll
2008-03-20 22:36 43,520 ----a-w C:\WINDOWS\system32\CTBurst.dll
2008-03-20 22:36 163,328 ----a-w C:\WINDOWS\system32\ctdvinst.dll
2008-03-20 22:36 11,776 ----a-w C:\WINDOWS\system32\inres.dll
2008-03-20 22:36 11,776 ----a-w C:\WINDOWS\INRES.DLL
2008-03-20 22:35 42,496 ----a-w C:\WINDOWS\system32\readreg.exe
2008-03-20 22:35 41,472 ----a-w C:\WINDOWS\system32\psconv.exe
2008-03-20 22:35 41,472 ----a-w C:\WINDOWS\system32\CTxfiBtn.dll
2008-03-20 22:35 40,960 ----a-w C:\WINDOWS\system32\CTxfiSpk.dll
2008-03-20 22:35 38,912 ----a-w C:\WINDOWS\system32\CTSPKHLP.DLL
2008-03-20 22:35 34,816 ----a-w C:\WINDOWS\system32\a3d.dll
2008-03-20 22:35 27,648 ----a-w C:\WINDOWS\system32\ac3api.dll
2008-03-20 22:35 23,552 ----a-w C:\WINDOWS\system32\Ctxfihlp.exe
2008-03-20 22:35 23,040 ----a-w C:\WINDOWS\system32\CtHelper.exe
2008-03-20 22:35 12,800 ----a-w C:\WINDOWS\system32\CTAGENT.DLL
2008-03-20 22:34 8,704 ----a-w C:\WINDOWS\system32\ctpres.dll
2008-03-20 22:34 51,200 ----a-w C:\WINDOWS\system32\CTpcmcia.dll
2008-03-20 22:34 46,592 ----a-w C:\WINDOWS\system32\ctscal.dll
2008-03-20 22:34 36,864 ----a-w C:\WINDOWS\system32\ctthxcal.dll
2008-03-20 22:34 343,040 ----a-w C:\WINDOWS\system32\ctdc0001.dll
2008-03-20 22:34 230,400 ----a-w C:\WINDOWS\system32\ctdc0000.dll
2008-03-20 22:34 17,920 ----a-w C:\WINDOWS\system32\ctmmep.dll
2008-03-20 22:34 145,408 ----a-w C:\WINDOWS\system32\CTDCIFCE.DLL
2008-03-20 22:34 10,240 ----a-w C:\WINDOWS\system32\ctdcres.dll
2008-03-20 22:34 10,240 ----a-w C:\WINDOWS\CTDCRES.DLL
2008-03-20 22:31 46,592 ----a-w C:\WINDOWS\system32\Ctxfireg.exe
2008-03-20 22:31 15,360 ----a-w C:\WINDOWS\system32\Ct20xspi.dll
2008-03-20 22:31 1,119,744 ----a-w C:\WINDOWS\system32\CTxfispi.exe
2008-03-20 22:24 114,688 ----a-w C:\WINDOWS\system32\ctemupia.dll
2008-03-20 22:22 74,240 ----a-w C:\WINDOWS\system32\CTOSUSER.DLL
2008-03-20 22:22 68,608 ----a-w C:\WINDOWS\system32\PIAPROXY.DLL
2008-03-20 22:22 53,248 ----a-w C:\WINDOWS\system32\CTDPROXY.DLL
2008-03-20 22:22 50,688 ----a-w C:\WINDOWS\system32\ctasio.dll
2008-03-20 22:22 22,016 ----a-w C:\WINDOWS\system32\ctedasio.dll
2008-03-20 22:22 16,384 ----a-w C:\WINDOWS\system32\regplib.exe
2008-03-20 22:22 151,040 ----a-w C:\WINDOWS\system32\ct_oal.dll
2008-03-20 22:22 108,544 ----a-w C:\WINDOWS\system32\SFMS32.DLL
2008-03-20 22:22 10,240 ----a-w C:\WINDOWS\system32\sfman32.dll
2008-03-20 22:19 7,680 ----a-w C:\WINDOWS\system32\enlocstr.exe
2008-03-20 22:19 36,864 ----a-w C:\WINDOWS\system32\devreg.dll
2008-03-20 22:19 31,232 ----a-w C:\WINDOWS\system32\MIDIDEF.EXE
2008-03-20 22:19 12,800 ----a-w C:\WINDOWS\system32\killapps.exe
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2007-01-31 07:26 88 --sha-r C:\WINDOWS\system32\BD56F95BB8.sys
2007-01-31 07:26 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot_2008-06-04_23.53.03.73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-05 06:14:14 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-05 17:36:52 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{487C9905-26A8-42C8-8033-C58AD3D2AEC3}]
2008-06-02 20:37 57344 --a------ C:\WINDOWS\system32\mlJCRlkI.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{80539493-39F8-4EED-9C95-6F7644E3136A}]
C:\WINDOWS\system32\khfDvuTm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E32AB07F-1D8F-4A50-A8FB-7235153B7D6F}]
2008-06-05 10:21 373760 --a------ C:\WINDOWS\system32\xxyvwvvt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 20:44 1200128]
"SetDefaultMIDI"="MIDIDef.exe" [2008-03-20 15:19 31232 C:\WINDOWS\system32\MIDIDEF.EXE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 20:26 52896]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 21:33 125168]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
"CTHelper"="CTHELPER.EXE" [2008-03-20 15:35 23040 C:\WINDOWS\system32\CtHelper.exe]
"CTxfiHlp"="CTXFIHLP.EXE" [2008-03-20 15:35 23552 C:\WINDOWS\system32\Ctxfihlp.exe]
"BM333ca40b"="C:\WINDOWS\system32\cdolfjcs.dll" [2008-06-05 10:22 125952]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{487C9905-26A8-42C8-8033-C58AD3D2AEC3}"= C:\WINDOWS\system32\mlJCRlkI.dll [2008-06-02 20:37 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJCRlkI]
mlJCRlkI.dll 2008-06-02 20:37 57344 C:\WINDOWS\system32\mlJCRlkI.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk]
path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk
backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\300f9797]
C:\WINDOWS\system32\ytoyancc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-07 00:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2006-11-07 08:29 50736 C:\Program Files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2007-04-07 18:08 947200 C:\Program Files\Ares\Ares.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM333ca40b]
C:\WINDOWS\system32\ylkufogk.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-02-05 00:03 157696 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2005-11-15 20:44 1200128 C:\Program Files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2003-10-23 20:51 233472 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-17 00:11 49152 C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2003-11-10 16:04 188416 C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-02-16 17:15 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-02-16 17:15 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 12:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2006-07-26 03:03 49263 C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
--a------ 2007-01-17 04:23 342112 C:\Program Files\Trojan Remover\Trjscan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}]
C:\Program Files\Google\Gmail Notifier\gnotify.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\HKBN 2b\\bin\\SMC.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R3 COMMONFX.SYS;COMMONFX.SYS;C:\WINDOWS\system32\drivers\COMMONFX.SYS [2008-03-20 17:23]
R3 CTEDSPFX.SYS;CTEDSPFX.SYS;C:\WINDOWS\system32\drivers\CTEDSPFX.SYS [2008-03-20 17:32]
R3 CTEDSPIO.SYS;CTEDSPIO.SYS;C:\WINDOWS\system32\drivers\CTEDSPIO.SYS [2008-03-20 17:38]
R3 CTEDSPSY.SYS;CTEDSPSY.SYS;C:\WINDOWS\system32\drivers\CTEDSPSY.SYS [2008-03-20 17:37]
R3 PRISM_USB;Dell TrueMobile 1180 Wireless USB Adapter;C:\WINDOWS\system32\DRIVERS\DELUSB_51.sys [2002-08-09 15:46]
S3 COMMONFX;COMMONFX;C:\WINDOWS\system32\drivers\COMMONFX.SYS [2008-03-20 17:23]
S3 CT20XUT.SYS;CT20XUT.SYS;C:\WINDOWS\system32\drivers\CT20XUT.SYS [2008-03-20 17:36]
S3 CT20XUT;CT20XUT;C:\WINDOWS\system32\drivers\CT20XUT.SYS [2008-03-20 17:36]
S3 CTAUDFX.SYS;CTAUDFX.SYS;C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2008-03-20 17:23]
S3 CTAUDFX;CTAUDFX;C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2008-03-20 17:23]
S3 CTEAPSFX.SYS;CTEAPSFX.SYS;C:\WINDOWS\system32\drivers\CTEAPSFX.SYS [2008-03-20 17:26]
S3 CTEAPSFX;CTEAPSFX;C:\WINDOWS\system32\drivers\CTEAPSFX.SYS [2008-03-20 17:26]
S3 CTEDSPFX;CTEDSPFX;C:\WINDOWS\system32\drivers\CTEDSPFX.SYS [2008-03-20 17:32]
S3 CTEDSPIO;CTEDSPIO;C:\WINDOWS\system32\drivers\CTEDSPIO.SYS [2008-03-20 17:38]
S3 CTEDSPSY;CTEDSPSY;C:\WINDOWS\system32\drivers\CTEDSPSY.SYS [2008-03-20 17:37]
S3 CTERFXFX.SYS;CTERFXFX.SYS;C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2008-03-20 17:36]
S3 CTERFXFX;CTERFXFX;C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2008-03-20 17:36]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\WINDOWS\system32\drivers\CTEXFIFX.SYS [2008-03-20 17:40]
S3 CTEXFIFX;CTEXFIFX;C:\WINDOWS\system32\drivers\CTEXFIFX.SYS [2008-03-20 17:40]
S3 CTHWIUT.SYS;CTHWIUT.SYS;C:\WINDOWS\system32\drivers\CTHWIUT.SYS [2008-03-20 17:37]
S3 CTHWIUT;CTHWIUT;C:\WINDOWS\system32\drivers\CTHWIUT.SYS [2008-03-20 17:37]
S3 CTSBLFX.SYS;CTSBLFX.SYS;C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2008-03-20 17:25]
S3 CTSBLFX;CTSBLFX;C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2008-03-20 17:25]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7dbe02d0-6a35-11dc-be2b-00904b2bc814}]
\Shell\AutoRun\command - ie.exe
\Shell\explore\Command - ie.exe
\Shell\open\Command - ie.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc69911f-934e-11dc-be2d-00904b2bc814}]
\Shell\AutoRun\command - F:\setupSNK.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-06-04 00:19:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-05 10:44:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\mlJCRlkI.dll

PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\cdolfjcs.dll
-> ?:\WINDOWS\System32\CSCDLL.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
.
**************************************************************************
.
Completion time: 2008-06-05 10:49:46 - machine was rebooted [Chung]
ComboFix-quarantined-files.txt 2008-06-05 17:49:25
ComboFix2.txt 2008-06-05 07:16:19
ComboFix3.txt 2008-06-05 06:55:59
ComboFix4.txt 2008-06-04 18:23:28
ComboFix5.txt 2008-06-04 15:48:45

Pre-Run: 26,006,482,944 bytes free
Post-Run: 25,971,109,888 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

349 --- E O F --- 2008-05-30 01:55:36
kniteshift is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-06-2008, 01:36 PM   #7 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,792
OS: WinXP and Vista


Re: Pulling my hair out.

Hi knightshift,

You've used an older version of ComboFix. Please delete your existing version and download the latest copy using the links I gave you earlier.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. If you are unsure how to do this, please see this link http://www.bleepingcomputer.com/forums/topic114351.html

--------------------------------------------------------------------

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a new HijackThis log for further review.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-06-2008, 03:12 PM   #8 (permalink)
Registered User
 
Join Date: Jun 2008
Posts: 7
OS: XP


Re: Pulling my hair out.

I tried to close Symanetic and the other programs but explorer just kept on crashing and so did TaskManager, although I was able to turn off auto-protect. Here you go, thanks again!

ComboFix 08-06-06.2 - Chung 2008-06-05 12:50:01.9 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1012 [GMT -7:00]
Running from: C:\Documents and Settings\Chung\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\cdolfjcs.dll
C:\WINDOWS\system32\gthitvsr.dll
C:\WINDOWS\system32\gyxgbmxj.dll
C:\WINDOWS\system32\jxmbgxyg.ini
C:\WINDOWS\system32\lagrvrbj.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlJCRlkI.dll
C:\WINDOWS\system32\mrvotahb.dll
C:\WINDOWS\system32\nwqpndto.dll
C:\WINDOWS\system32\tvvwvyxx.ini
C:\WINDOWS\system32\tvvwvyxx.ini2
C:\WINDOWS\system32\xjswfffg.dll
C:\WINDOWS\system32\xxyvwvvt.dll

.
((((((((((((((((((((((((( Files Created from 2008-05-06 to 2008-06-06 )))))))))))))))))))))))))))))))
.

2008-06-05 10:49 . 2008-06-05 10:49 0 --a------ C:\WINDOWS\BM333ca40b.xml
2008-06-05 10:35 . 2008-06-06 12:54 11,564 --a------ C:\WINDOWS\system32\DVCState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx
2008-06-05 10:35 . 2008-06-06 12:54 1,524 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx
2008-06-05 10:35 . 2008-06-06 12:54 1,524 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx
2008-06-05 10:35 . 2008-06-06 12:54 64 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx
2008-06-05 10:35 . 2008-06-06 12:54 64 --a------ C:\WINDOWS\system32\BMXState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx
2008-06-05 09:33 . 2008-06-05 09:34 321 --a------ C:\WINDOWS\wininit.ini
2008-06-05 00:32 . 2008-06-05 00:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-06-04 22:14 . 2008-06-04 22:14 <DIR> d-------- C:\Program Files\CCleaner
2008-06-04 21:56 . 2008-06-04 21:56 <DIR> d-------- C:\Deckard
2008-06-04 18:27 . 2006-11-14 15:28 86,016 --a------ C:\WINDOWS\system32\cttele.dll
2008-06-04 18:19 . 2008-03-20 15:35 2,560 --a------ C:\WINDOWS\CTXFIRES.DLL
2008-06-04 18:12 . 2008-06-04 18:17 <DIR> d-------- C:\Program Files\Panda Security
2008-06-04 10:49 . 2008-06-04 10:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Simply Super Software
2008-06-03 21:27 . 2008-06-03 21:27 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-03 21:27 . 2008-06-03 21:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-03 21:14 . 2008-06-03 11:30 <DIR> d-------- C:\Program Files\Trojan Remover
2008-06-03 21:14 . 2008-06-03 21:14 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\Simply Super Software
2008-06-03 21:14 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-06-03 21:14 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-06-03 15:13 . 2008-06-03 15:12 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-03 14:14 . 2008-06-03 14:14 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\HouseCall 6.6
2008-06-03 11:22 . 2008-05-10 19:40 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-06-03 11:22 . 2008-06-04 22:22 <DIR> d-------- C:\Documents and Settings\Administrator
2008-06-03 03:24 . 2008-06-04 22:27 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-03 03:23 . 2008-06-03 21:38 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-06-01 18:45 . 2008-06-01 18:53 139,264 --a------ C:\WINDOWS\War3Unin.exe
2008-06-01 18:45 . 2008-06-01 18:59 76,166 --a------ C:\WINDOWS\War3Unin.dat
2008-06-01 18:45 . 2008-06-01 18:53 2,829 --a------ C:\WINDOWS\War3Unin.pif
2008-05-29 15:10 . 2008-05-29 15:10 <DIR> d-------- C:\Program Files\iPod
2008-05-29 15:09 . 2008-05-29 15:10 <DIR> d-------- C:\Program Files\iTunes
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\system32\lsdelete.exe
2008-05-15 01:52 . 2008-03-05 15:56 3,786,760 --a------ C:\WINDOWS\system32\D3DX9_37.dll
2008-05-15 01:52 . 2008-03-05 15:56 1,420,824 --a------ C:\WINDOWS\system32\D3DCompiler_37.dll
2008-05-15 01:52 . 2008-03-05 16:03 479,752 --a------ C:\WINDOWS\system32\XAudio2_0.dll
2008-05-15 01:52 . 2008-02-05 23:07 462,864 --a------ C:\WINDOWS\system32\d3dx10_37.dll
2008-05-15 01:52 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll
2008-05-15 01:52 . 2008-03-05 16:03 238,088 --a------ C:\WINDOWS\system32\xactengine3_0.dll
2008-05-15 01:52 . 2008-03-05 16:00 25,608 --a------ C:\WINDOWS\system32\X3DAudio1_3.dll
2008-05-15 01:49 . 2008-05-15 01:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\media center programs
2008-05-14 22:14 . 2008-05-14 22:14 <DIR> d-------- C:\Program Files\Funcom
2008-05-14 21:33 . 2008-05-14 21:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Funcom
2008-05-11 20:21 . 2008-05-11 20:21 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\SystemRequirementsLab
2008-05-11 20:11 . 2008-05-11 20:11 <DIR> d-------- C:\WINDOWS\system32\Futuremark
2008-05-11 20:11 . 2008-05-11 20:11 <DIR> d-------- C:\Program Files\Common Files\Futuremark Shared
2008-05-11 20:11 . 2008-05-11 20:11 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\InstallShield
2008-05-11 20:11 . 2007-08-20 11:05 27,672 -ra------ C:\WINDOWS\system32\drivers\Entech.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-06 19:57 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-06-05 01:27 --------- d-----w C:\Program Files\Creative Professional
2008-06-05 01:14 --------- d-----w C:\Program Files\Viewpoint
2008-06-05 01:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-06-04 04:26 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-04 04:21 --------- d-----w C:\Program Files\Google
2008-06-04 03:52 --------- d-----w C:\Documents and Settings\Chung\Application Data\uTorrent
2008-06-03 15:32 --------- d-----w C:\Program Files\Warcraft III
2008-06-03 04:03 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-02 00:20 --------- d-----w C:\Program Files\Apple Software Update
2008-05-29 22:05 --------- d-----w C:\Program Files\QuickTime
2008-05-23 05:51 --------- d-----w C:\Program Files\World of Warcraft
2008-05-18 21:14 --------- d-----w C:\Program Files\mIRC
2008-05-16 06:28 --------- d-----w C:\Program Files\Common Files\AOL
2008-05-16 06:28 --------- d-----w C:\Program Files\AIM
2008-05-12 03:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-01 08:40 --------- d-----w C:\Program Files\AIM6
2008-05-01 08:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-04-29 18:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 18:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 18:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-12 15:19 --------- d-----w C:\Program Files\Anti Keylogger Shield
2008-03-20 22:36 11,776 ----a-w C:\WINDOWS\INRES.DLL
2008-03-20 22:34 10,240 ----a-w C:\WINDOWS\CTDCRES.DLL
2007-01-31 07:26 88 --sha-r C:\WINDOWS\system32\BD56F95BB8.sys
2007-01-31 07:26 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot_2008-06-04_23.53.03.73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-05 06:14:14 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-06 19:55:58 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{80539493-39F8-4EED-9C95-6F7644E3136A}]
C:\WINDOWS\system32\khfDvuTm.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 20:44 1200128]
"SetDefaultMIDI"="MIDIDef.exe" [2008-03-20 15:19 31232 C:\WINDOWS\system32\MIDIDEF.EXE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 20:26 52896]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 21:33 125168]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920]
"CTHelper"="CTHELPER.EXE" [2008-03-20 15:35 23040 C:\WINDOWS\system32\CtHelper.exe]
"CTxfiHlp"="CTXFIHLP.EXE" [2008-03-20 15:35 23552 C:\WINDOWS\system32\Ctxfihlp.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk]
path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk
backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\300f9797]
C:\WINDOWS\system32\ytoyancc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-07 00:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2006-11-07 08:29 50736 C:\Program Files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2007-04-07 18:08 947200 C:\Program Files\Ares\Ares.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM333ca40b]
C:\WINDOWS\system32\ylkufogk.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-02-05 00:03 157696 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2005-11-15 20:44 1200128 C:\Program Files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2003-10-23 20:51 233472 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-17 00:11 49152 C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2003-11-10 16:04 188416 C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-02-16 17:15 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-02-16 17:15 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 12:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2006-07-26 03:03 49263 C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
--a------ 2007-01-17 04:23 342112 C:\Program Files\Trojan Remover\Trjscan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}]
C:\Program Files\Google\Gmail Notifier\gnotify.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\HKBN 2b\\bin\\SMC.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R3 COMMONFX.SYS;COMMONFX.SYS;C:\WINDOWS\system32\drivers\COMMONFX.SYS [2008-03-20 17:23]
R3 CTEDSPFX.SYS;CTEDSPFX.SYS;C:\WINDOWS\system32\drivers\CTEDSPFX.SYS [2008-03-20 17:32]
R3 CTEDSPIO.SYS;CTEDSPIO.SYS;C:\WINDOWS\system32\drivers\CTEDSPIO.SYS [2008-03-20 17:38]
R3 CTEDSPSY.SYS;CTEDSPSY.SYS;C:\WINDOWS\system32\drivers\CTEDSPSY.SYS [2008-03-20 17:37]
R3 PRISM_USB;Dell TrueMobile 1180 Wireless USB Adapter;C:\WINDOWS\system32\DRIVERS\DELUSB_51.sys [2002-08-09 15:46]
S3 COMMONFX;COMMONFX;C:\WINDOWS\system32\drivers\COMMONFX.SYS [2008-03-20 17:23]
S3 CT20XUT.SYS;CT20XUT.SYS;C:\WINDOWS\system32\drivers\CT20XUT.SYS [2008-03-20 17:36]
S3 CT20XUT;CT20XUT;C:\WINDOWS\system32\drivers\CT20XUT.SYS [2008-03-20 17:36]
S3 CTAUDFX.SYS;CTAUDFX.SYS;C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2008-03-20 17:23]
S3 CTAUDFX;CTAUDFX;C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2008-03-20 17:23]
S3 CTEAPSFX.SYS;CTEAPSFX.SYS;C:\WINDOWS\system32\drivers\CTEAPSFX.SYS [2008-03-20 17:26]
S3 CTEAPSFX;CTEAPSFX;C:\WINDOWS\system32\drivers\CTEAPSFX.SYS [2008-03-20 17:26]
S3 CTEDSPFX;CTEDSPFX;C:\WINDOWS\system32\drivers\CTEDSPFX.SYS [2008-03-20 17:32]
S3 CTEDSPIO;CTEDSPIO;C:\WINDOWS\system32\drivers\CTEDSPIO.SYS [2008-03-20 17:38]
S3 CTEDSPSY;CTEDSPSY;C:\WINDOWS\system32\drivers\CTEDSPSY.SYS [2008-03-20 17:37]
S3 CTERFXFX.SYS;CTERFXFX.SYS;C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2008-03-20 17:36]
S3 CTERFXFX;CTERFXFX;C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2008-03-20 17:36]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\WINDOWS\system32\drivers\CTEXFIFX.SYS [2008-03-20 17:40]
S3 CTEXFIFX;CTEXFIFX;C:\WINDOWS\system32\drivers\CTEXFIFX.SYS [2008-03-20 17:40]
S3 CTHWIUT.SYS;CTHWIUT.SYS;C:\WINDOWS\system32\drivers\CTHWIUT.SYS [2008-03-20 17:37]
S3 CTHWIUT;CTHWIUT;C:\WINDOWS\system32\drivers\CTHWIUT.SYS [2008-03-20 17:37]
S3 CTSBLFX.SYS;CTSBLFX.SYS;C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2008-03-20 17:25]
S3 CTSBLFX;CTSBLFX;C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2008-03-20 17:25]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7dbe02d0-6a35-11dc-be2b-00904b2bc814}]
\Shell\AutoRun\command - ie.exe
\Shell\explore\Command - ie.exe
\Shell\open\Command - ie.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc69911f-934e-11dc-be2d-00904b2bc814}]
\Shell\AutoRun\command - F:\setupSNK.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-06-04 00:19:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-06 12:57:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> C:\PROGRA~1\Google\GOOGLE~1\GOA66E~1.DLL
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-06-06 13:03:18 - machine was rebooted [Chung]
ComboFix-quarantined-files.txt 2008-06-06 20:02:56
ComboFix2.txt 2008-06-05 17:49:48
ComboFix3.txt 2008-06-05 07:16:19
ComboFix4.txt 2008-06-05 06:55:59
ComboFix5.txt 2008-06-04 18:23:28

Pre-Run: 26,034,200,576 bytes free
Post-Run: 26,020,372,480 bytes free

282 --- E O F --- 2008-05-30 01:55:36

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:10:19 PM, on 2008-06-06
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {80539493-39F8-4EED-9C95-6F7644E3136A} - C:\WINDOWS\system32\khfDvuTm.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 6862 bytes
kniteshift is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-06-2008, 08:27 PM   #9 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,792
OS: WinXP and Vista


Re: Pulling my hair out.

Much better.

Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

Also be sure to carry out the instructions in the sequence listed below.

***************************************************

Using 'My Computer', navigate to and delete the following File (Right click and select 'Delete'):

C:\WINDOWS\BM333ca40b.xml

--------------------------------------------------------------------

Go to Start->Run and type in regedit and hit OK.

Open notepad and copy/paste the entire text in the quote box below: (don't forget to copy and paste REGEDIT4)

Quote:
REGEDIT4

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{80539493-39F8-4EED-9C95-6F7644E3136A}]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\300f9797]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM333ca40b]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7dbe02d0-6a35-11dc-be2b-00904b2bc814}]


Save the file as "delete.reg". Make sure to save it with the quotes. Choose to "Save type as - All Files"
It should look like this:

Double click on the delete.reg file and choose Yes to merge/add it to the registry. You may delete the file afterwards.

--------------------------------------------------------------------

It's important to run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course:

Using Internet Explorer, visit http://www.kaspersky.com/kos/eng/par...avwebscan.html

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.



  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply

**Note**

To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan

---------------------------------------------------------------

Run a new scan with dss.exe.

---------------------------------------------------------------

Please include the following in your next reply:

Kaspersky results
New main.txt
Update on system behavior
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-07-2008, 10:58 AM   #10 (permalink)
Registered User
 
Join Date: Jun 2008
Posts: 7
OS: XP


Re: Pulling my hair out.

So far, everything seems to be running smoothly like it used to be before this virus. I appreciate all your help :)

Deckard's System Scanner v20071014.68
Run by Chung on 2008-06-07 09:54:07
Computer is in Normal Mode.
--------------------------------------------------------------------------------

System Drive C: has 24.13 GiB (less than 15%) free.


-- HijackThis (run as Chung.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:54:15 AM, on 2008-06-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Chung\My Documents\dss.exe
C:\DOCUME~1\Chung\MYDOCU~1\download\FREEKN~1\HIJACK~1\Chung.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} - http://iebar.t2t2.com/iebar.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 6919 bytes

-- Files created between 2008-05-07 and 2008-06-07 -----------------------------

2008-06-06 23:57:44 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-06 23:57:43 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-06-06 23:57:42 0 d-------- C:\WINDOWS\LastGood
2008-06-05 10:30:21 0 d-------- C:\cmdcons
2008-06-05 10:27:09 68096 --a------ C:\WINDOWS\zip.exe
2008-06-05 10:27:09 49152 --a------ C:\WINDOWS\VFind.exe
2008-06-05 10:27:09 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-06-05 10:27:09 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-06-05 10:27:09 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-06-05 10:27:09 98816 --a------ C:\WINDOWS\sed.exe
2008-06-05 10:27:09 80412 --a------ C:\WINDOWS\grep.exe
2008-06-05 10:27:09 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-06-05 00:32:44 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-06-04 22:45:34 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-06-04 22:22:56 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-06-04 22:14:23 0 d-------- C:\Program Files\CCleaner
2008-06-04 18:27:24 86016 --a------ C:\WINDOWS\system32\cttele.dll <Not Verified; Creative Technology Ltd; Creative Common Proxy Stud>
2008-06-04 18:19:17 2560 --a------ C:\WINDOWS\CTXFIRES.DLL <Not Verified; ; CTxfiRes Dynamic Link Library>
2008-06-04 18:12:57 0 d-------- C:\Program Files\Panda Security
2008-06-04 10:49:16 0 d-------- C:\Documents and Settings\Administrator\Application Data\Simply Super Software <SIMPLY~1>
2008-06-03 21:27:38 0 d-------- C:\Program Files\Lavasoft
2008-06-03 21:27:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-03 21:14:11 153088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-06-03 21:14:11 75264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-06-03 21:14:08 0 d-------- C:\Program Files\Trojan Remover
2008-06-03 21:14:08 0 d-------- C:\Documents and Settings\Chung\Application Data\Simply Super Software <SIMPLY~1>
2008-06-03 14:14:43 0 d-------- C:\Documents and Settings\Chung\Application Data\HouseCall 6.6
2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-06-03 11:22:45 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-06-03 11:22:45 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-06-03 11:22:45 2359296 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-06-03 11:22:45 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-06-03 11:22:45 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-06-03 11:22:45 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-06-03 11:22:33 0 d-------- C:\WINDOWS\CSC
2008-06-03 11:09:20 0 d-------- C:\Documents and Settings\LocalService\Application Data\Macromedia
2008-06-03 10:56:29 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-06-03 03:24:20 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-03 03:23:05 0 d-------- C:\Program Files\Spyware Doctor
2008-06-01 18:45:23 76166 --a------ C:\WINDOWS\War3Unin.dat
2008-06-01 18:45:22 2829 --a------ C:\WINDOWS\War3Unin.pif
2008-06-01 18:45:22 139264 --a------ C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2008-05-29 15:10:07 0 d-------- C:\Program Files\iPod
2008-05-29 15:09:45 0 d-------- C:\Program Files\iTunes
2008-05-15 01:49:26 0 d-------- C:\Documents and Settings\All Users\Application Data\media center programs
2008-05-14 22:14:13 0 d-------- C:\Program Files\Funcom
2008-05-14 21:33:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Funcom
2008-05-11 20:21:08 0 d-------- C:\Documents and Settings\Chung\Application Data\SystemRequirementsLab
2008-05-11 20:11:47 0 d-------- C:\WINDOWS\system32\Futuremark
2008-05-11 20:11:46 0 d-------- C:\Program Files\Common Files\Futuremark Shared
2008-05-11 20:11:36 0 d-------- C:\Documents and Settings\Chung\Application Data\InstallShield
2008-05-10 19:40:01 0 d-------- C:\Documents and Settings\Default User\Application Data\Apple Computer


-- Find3M Report ---------------------------------------------------------------

2008-06-07 01:00:29 0 d-------- C:\Program Files\Symantec AntiVirus
2008-06-06 18:40:53 0 d-------- C:\Documents and Settings\Chung\Application Data\uTorrent
2008-06-06 16:40:07 0 d-------- C:\Program Files\Warcraft III
2008-06-04 18:27:53 0 d-------- C:\Program Files\Creative Professional
2008-06-04 18:23:19 409600 --a------ C:\WINDOWS\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
2008-06-04 18:23:19 114688 --a------ C:\WINDOWS\system32\OpenAL32.dll <Not Verified; Portions (C) Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL(TM) Library>
2008-06-04 18:14:29 0 d-------- C:\Program Files\Viewpoint
2008-06-03 21:26:36 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-03 21:21:45 0 d-------- C:\Program Files\Google
2008-06-03 11:19:43 0 d-------- C:\Program Files\Common Files
2008-06-02 22:32:45 0 d-------- C:\Documents and Settings\Chung\Application Data\Adobe
2008-06-02 21:03:07 0 d-------- C:\Program Files\Common Files\Adobe
2008-06-01 17:20:12 0 d-------- C:\Program Files\Apple Software Update
2008-05-29 15:05:53 0 d-------- C:\Program Files\QuickTime
2008-05-22 22:51:17 0 d-------- C:\Program Files\World of Warcraft
2008-05-18 14:14:05 0 d-------- C:\Program Files\mIRC
2008-05-15 23:28:24 0 d-------- C:\Program Files\Common Files\AOL
2008-05-15 23:28:24 0 d-------- C:\Program Files\AIM
2008-05-11 20:11:44 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-01 01:40:43 0 d-------- C:\Program Files\AIM6
2008-04-12 08:19:24 0 d-------- C:\Program Files\Anti Keylogger Shield
2008-03-20 15:36:48 43520 --a------ C:\WINDOWS\system32\CTBurst.dll <Not Verified; ; CTBurst Module>
2008-03-20 15:35:52 34816 --a------ C:\WINDOWS\system32\a3d.dll <Not Verified; ; a3dx5>
2008-03-20 15:35:38 27648 --a------ C:\WINDOWS\system32\ac3api.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:35:14 41472 --a------ C:\WINDOWS\system32\CTxfiBtn.dll <Not Verified; Creative Technology Ltd; CTXFIBTN Dynamic Link Library>
2008-03-20 15:35:10 40960 --a------ C:\WINDOWS\system32\CTxfiSpk.dll <Not Verified; Creative Technology Ltd; Ctxfispk Dynamic Link Library>
2008-03-20 15:35:10 23552 --a------ C:\WINDOWS\system32\Ctxfihlp.exe <Not Verified; Creative Technology Ltd; CTXfiHlp Application>
2008-03-20 15:35:06 41472 --a------ C:\WINDOWS\system32\psconv.exe
2008-03-20 15:35:04 23040 --a------ C:\WINDOWS\system32\CtHelper.exe <Not Verified; Creative Technology Ltd; CtHelper Application>
2008-03-20 15:35:02 12800 --a------ C:\WINDOWS\system32\CTAGENT.DLL <Not Verified; Creative Technology Ltd; ctagent>
2008-03-20 15:35:00 38912 --a------ C:\WINDOWS\system32\CTSPKHLP.DLL <Not Verified; Creative Technology Ltd; CtSpkHlp Dynamic Link Library>
2008-03-20 15:34:58 51200 --a------ C:\WINDOWS\system32\CTpcmcia.dll <Not Verified; Creative Technology Ltd; CTPCMCIA Dynamic Link Library>
2008-03-20 15:34:58 17920 --a------ C:\WINDOWS\system32\ctmmep.dll <Not Verified; Creative Technology Ltd; Ctmmep Dynamic Link Library>
2008-03-20 15:34:50 36864 --a------ C:\WINDOWS\system32\ctthxcal.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:34:50 8704 --a------ C:\WINDOWS\system32\ctpres.dll <Not Verified; Creative Technology Ltd; CtPanel Resource>
2008-03-20 15:34:48 46592 --a------ C:\WINDOWS\system32\ctscal.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:34:46 145408 --a------ C:\WINDOWS\system32\CTDCIFCE.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:34:46 343040 --a------ C:\WINDOWS\system32\ctdc0001.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:34:44 10240 --a------ C:\WINDOWS\system32\ctdcres.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:34:44 230400 --a------ C:\WINDOWS\system32\ctdc0000.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:34:44 10240 --a------ C:\WINDOWS\CTDCRES.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:31:22 46592 --a------ C:\WINDOWS\system32\Ctxfireg.exe <Not Verified; Creative Technology Ltd; CTXFIREG>
2008-03-20 15:31:20 15360 --a------ C:\WINDOWS\system32\Ct20xspi.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:31:14 1119744 --a------ C:\WINDOWS\system32\CTxfispi.exe <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:25:22 46273 --a------ C:\WINDOWS\system32\ctdnlstr.dat
2008-03-20 15:25:22 325821 --a------ C:\WINDOWS\system32\ctdlang.dat
2008-03-20 15:24:54 114688 --a------ C:\WINDOWS\system32\ctemupia.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:50 22016 --a------ C:\WINDOWS\system32\ctedasio.dll <Not Verified; Creative Technology, Ltd; Creative Audio Product>
2008-03-20 15:22:48 50688 --a------ C:\WINDOWS\system32\ctasio.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:48 151040 --a------ C:\WINDOWS\system32\ct_oal.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:44 53248 --a------ C:\WINDOWS\system32\CTDPROXY.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:30 74240 --a------ C:\WINDOWS\system32\CTOSUSER.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:28 10240 --a------ C:\WINDOWS\system32\sfman32.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:26 108544 --a------ C:\WINDOWS\system32\SFMS32.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:22:24 16384 --a------ C:\WINDOWS\system32\regplib.exe
2008-03-20 15:22:22 68608 --a------ C:\WINDOWS\system32\PIAPROXY.DLL <Not Verified; Creative Technology Ltd; E-mu PIA>
2008-03-20 15:21:58 149838 --a------ C:\WINDOWS\system32\ctbas2w.dat
2008-03-20 15:20:12 274587 --a------ C:\WINDOWS\system32\ctsbas2w.dat
2008-03-20 15:20:02 115166 --a------ C:\WINDOWS\system32\CTBASICW.DAT
2008-03-20 15:20:00 241084 --a------ C:\WINDOWS\system32\CTSBASW.DAT
2008-03-20 15:19:44 313207 --a------ C:\WINDOWS\system32\ctstatic.dat
2008-03-20 15:19:44 53932 --a------ C:\WINDOWS\system32\ctdaught.dat
2008-03-20 15:19:42 7680 --a------ C:\WINDOWS\system32\enlocstr.exe
2008-03-20 15:19:40 12800 --a------ C:\WINDOWS\system32\killapps.exe <Not Verified; ; killapps>
2008-03-20 15:19:26 31232 --a------ C:\WINDOWS\system32\MIDIDEF.EXE <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-20 15:19:26 36864 --a------ C:\WINDOWS\system32\devreg.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 AM]
"nwiz"="nwiz.exe" [2007-12-05 02:41 AM C:\WINDOWS\system32\nwiz.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 08:26 PM]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 09:33 PM]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 AM]
"CTHelper"="CTHELPER.EXE" [2008-03-20 03:35 PM C:\WINDOWS\system32\CtHelper.exe]
"CTxfiHlp"="CTXFIHLP.EXE" [2008-03-20 03:35 PM C:\WINDOWS\system32\Ctxfihlp.exe]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:56 AM]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 08:44 PM]
"SetDefaultMIDI"="MIDIDef.exe" [2008-03-20 03:19 PM C:\WINDOWS\system32\MIDIDEF.EXE]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk]
path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk
backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
"C:\Program Files\Ares\Ares.exe" -h

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
C:\Program Files\Trojan Remover\Trjscan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}]
C:\Program Files\Google\Gmail Notifier\gnotify.exe


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc69911f-934e-11dc-be2d-00904b2bc814}]
AutoRun\command- F:\setupSNK.exe

*Newly Created Service* - CATCHME



-- End of Deckard's System Scanner: finished at 2008-06-07 09:54:41 ------------

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2008-06-07 9:52:41 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 7/06/2008
Kaspersky Anti-Virus database records: 836505
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 94935
Number of viruses found: 10
Number of infected objects: 81
Number of suspicious objects: 0
Duration of the scan process: 02:49:03

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01F00000\47FCD7F6.VBN/MagicApplet.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01F00000\47FCD7F6.VBN/OwnClassLoader.class Infected: Trojan.Java.ClassLoader.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01F00000\47FCD7F6.VBN/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01F00000\47FCD7F6.VBN ZIP: infected - 3 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01F00000\47FCD7F6.VBN CryptZ: infected - 3 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02100001.VBN/vmain.class Infected: Exploit.Java.Gimsh.b skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02100001.VBN ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02100001.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EF40000\4EFD62B5.VBN Infected: Trojan-Downloader.JS.Small.fh skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280000\4F6CBBC5.VBN Infected: Trojan.BAT.Regger.b skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280001\4F6CBC16.VBN Infected: Trojan.BAT.Regger.b skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280002\4F6CBC44.VBN Infected: Trojan.BAT.Regger.b skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280003\4F6CBC9A.VBN Infected: Trojan.BAT.Regger.b skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280004\4F6D153D.VBN/data0000 Infected: Backdoor.Win32.VB.brg skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280004\4F6D153D.VBN/data0001 Infected: Trojan-Downloader.Win32.Agent.bl skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280004\4F6D153D.VBN EmbeddedEXE: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280004\4F6D153D.VBN UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280004\4F6D153D.VBN PE_Patch.UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280004\4F6D153D.VBN CryptZ: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280005\4F6D1580.VBN/data0000 Infected: Backdoor.Win32.VB.brg skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280005\4F6D1580.VBN/data0001 Infected: Trojan-Downloader.Win32.Agent.bl skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280005\4F6D1580.VBN EmbeddedEXE: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280005\4F6D1580.VBN UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280005\4F6D1580.VBN PE_Patch.UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280005\4F6D1580.VBN CryptZ: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280006\4F6D15C5.VBN/data0000 Infected: Backdoor.Win32.VB.brg skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280006\4F6D15C5.VBN/data0001 Infected: Trojan-Downloader.Win32.Agent.bl skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280006\4F6D15C5.VBN EmbeddedEXE: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280006\4F6D15C5.VBN UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280006\4F6D15C5.VBN PE_Patch.UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280006\4F6D15C5.VBN CryptZ: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280007\4F6D161B.VBN/data0000 Infected: Backdoor.Win32.VB.brg skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280007\4F6D161B.VBN/data0001 Infected: Trojan-Downloader.Win32.Agent.bl skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280007\4F6D161B.VBN EmbeddedEXE: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280007\4F6D161B.VBN UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280007\4F6D161B.VBN PE_Patch.UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280007\4F6D161B.VBN CryptZ: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280008\4F6D1665.VBN/data0000 Infected: Backdoor.Win32.VB.brg skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280008\4F6D1665.VBN/data0001 Infected: Trojan-Downloader.Win32.Agent.bl skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280008\4F6D1665.VBN EmbeddedEXE: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280008\4F6D1665.VBN UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280008\4F6D1665.VBN PE_Patch.UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280008\4F6D1665.VBN CryptZ: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280009\4F6D1699.VBN/data0000 Infected: Backdoor.Win32.VB.brg skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280009\4F6D1699.VBN/data0001 Infected: Trojan-Downloader.Win32.Agent.bl skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280009\4F6D1699.VBN EmbeddedEXE: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280009\4F6D1699.VBN UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280009\4F6D1699.VBN PE_Patch.UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280009\4F6D1699.VBN CryptZ: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F28000A\4F6D1ABB.VBN Infected: Backdoor.Win32.VB.brg skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F28000B\4F6D1B4F.VBN Infected: Backdoor.Win32.VB.brg skipped
C:\Documents and Settings\Chung\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\Chung\Application Data\Aim\freekniteshift\cert8.db Object is locked skipped
C:\Documents and Settings\Chung\Application Data\Aim\freekniteshift\key3.db Object is locked skipped
C:\Documents and Settings\Chung\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Chung\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Chung\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Chung\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Chung\Local Settings\temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\Chung\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Chung\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-000345-835.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped
C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-000448-409.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped
C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-000519-969.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped
C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-000535-128.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped
C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-002900-342.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped
C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-100212-243.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped
C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-100212-577.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Chung\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Chung\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0860NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0869NAV~.TMP Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\cdolfjcs.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\lagrvrbj.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mlJApqpp.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mlJCRlkI.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mrvotahb.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ssqQgHWP.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\wvUNFVom.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\xjswfffg.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\xxyvwvvt.dll.vir Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP10\A0000802.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP10\A0000805.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP10\A0000806.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP10\A0000807.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP10\A0000809.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP10\A0000810.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP11\change.log Object is locked skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP2\A0000293.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP2\A0000294.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP2\A0000313.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP2\A0000328.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP2\A0000329.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP2\A0000330.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP5\A0000429.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\HTTPERR\httperr1.log Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
kniteshift is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-07-2008, 02:41 PM   #11 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,792
OS: WinXP and Vista


Re: Pulling my hair out.

Hi kniteshift,

Kaspersky is only reporting backups created during the course of this fix, and items located in C:\System Volume Information\, which is where System Restore's cache is stored. Whatever is in there can't harm you unless you choose to perform a manual restore. Nevertheless, we shall be resetting/clearing the cache shortly.


Your logs are clean. If there aren't any more problems, please continue with these final instructions and helpful links:

The following procedure will clear out the backups and quarantines created by the fix. It will also reset your System Restore by flushing out previous restore points (which contain the infections) and create a new restore point.

Click Start > Run and copy/paste, or type the following bolded text into the Run box and click OK:

ComboFix /u

--------------------------------------------------------------------


To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:

McAfee Site Advisor--free version. The folks there check out websites and based on their findings, rate it as Safe, Unknown, Caution, or Bad.

SpywareBlaster 4.0 to help prevent spyware from installing in the first place. Install & update SpywareBlaster with the latest definitions. After you have updated, click the button - enable protection for all unprotected items.
  • It will block any bad ActiveX from running in Internet Explorer and Firefox if it's listed in their database (which you should update frequently). To view their database and list of restricted sites, launch the program and click on each of the tabs on the main display page.

IESpyAD Zoned Out to block access to malicious websites so you cannot be redirected to them from an infected site or email. This severely impairs attempts to infect your system as it basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.


Update, and scan with your onboard Anti Malware and Anti Virus programs regularly. Without regular updates you will not be protected when new malicious programs are released.


In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:

PC Safety and Security--What Do I Need?
Think Prevention


HOW DID I GET INFECTED IN THE FIRST PLACE? by Tony Klein
MAKING INTERNET EXPLORER SAFER
Understanding and Using Firewalls


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

-----------------------------------------------------

Follow the list above and the potential for infection will reduce dramatically.


**Kindly respond one more time and let me know if we may consider this thread resolved.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-08-2008, 03:20 AM   #12 (permalink)
Registered User
 
Join Date: Jun 2008
Posts: 7
OS: XP


Re: Pulling my hair out.

Thanks a lot, I really appreciate all the help you've given me. God bless :)
kniteshift is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 06-08-2008, 07:04 AM   #13 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,792
OS: WinXP and Vista


Re: Pulling my hair out.

You're welcome.


Take care, kniteshift.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 07:58 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85