![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jun 2008
Posts: 7
OS: XP
|
Pulling my hair out.
Explorer dies, random pop ups fly, and Norton scream Trojan.Lowzones.
MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\CTHELPER.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\PROGRA~1\MICROS~3\rapimgr.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe C:\Program Files\AIM\aim.exe C:\Program Files\Winamp\winamp.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\veqwfjga.dll",s O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} - http://iebar.t2t2.com/iebar.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe Please help, thanks in advance. |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Registered User
Join Date: Jun 2008
Posts: 7
OS: XP
|
Re: Pulling my hair out.
I also tried to use the pandasecurity scan but Mozilla and IE kept on crashing with 10510515025 pop ups everytime it tries to scan. I've also followed the five steps but I can't access the downloads at all because again my mozilla and I.E. both end up crashing, at boot up I can access this page and very few other pages, for some reason I'm limited to a lot of other pages like google, or yahoo.
|
|
|
|
|
#3 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,549
OS: WinXP and Vista
|
Re: Pulling my hair out.
Hello kniteshift,
Do you have access to another computer whereby you can download the necessary tools to a flash drive, then transfer to this infected computer? |
|
|
|
|
#4 (permalink) |
|
Registered User
Join Date: Jun 2008
Posts: 7
OS: XP
|
Re: Pulling my hair out.
Deckard's System Scanner v20071014.68
Run by <insname> on 2008-06-04 21:56:33 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 2 Restore Point(s) -- 2: 2008-06-05 04:56:41 UTC - RP2 - Deckard's System Scanner Restore Point 1: 2008-06-04 21:38:18 UTC - RP1 - System Checkpoint Backed up registry hives. Performed disk cleanup. System Drive C: has 24.21 GiB (less than 15%) free. -- HijackThis (run as Chung.exe) ----------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:59:28 PM, on 2008-06-04 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\CTHELPER.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\PROGRA~1\MICROS~3\rapimgr.exe C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\AIM\aim.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Chung\My Documents\dss.exe C:\WINDOWS\explorer.exe C:\DOCUME~1\Chung\MYDOCU~1\download\FREEKN~1\HIJACK~1\Chung.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: (no name) - {487C9905-26A8-42C8-8033-C58AD3D2AEC3} - C:\WINDOWS\system32\mlJCRlkI.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O2 - BHO: (no name) - {E931BDB3-013B-4D15-9186-6B23B5929E9F} - C:\WINDOWS\system32\mlJApqpp.dll O2 - BHO: {2a3b4dad-1c6b-0138-ada4-7d043f9030af} - {fa0309f3-40d7-4ada-8310-b6c1dad4b3a2} - C:\WINDOWS\system32\gjfqavsn.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} - http://iebar.t2t2.com/iebar.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O20 - Winlogon Notify: mlJCRlkI - C:\WINDOWS\SYSTEM32\mlJCRlkI.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- End of file - 7240 bytes -- HijackThis Fixed Entries (C:\DOCUME~1\Chung\MYDOCU~1\download\FREEKN~1\HIJACK~1\backups\) -------------------------------------------------------------------------------- backup-20080603-020404-195 O4 - HKLM\..\Run: [300f9797] rundll32.exe "C:\WINDOWS\system32\cpurvlbg.dll",b backup-20080603-020404-589 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\opultmvl.dll",s backup-20080604-080755-625 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\veqwfjga.dll",s backup-20080604-080755-792 O4 - HKLM\..\Run: [300f9797] rundll32.exe "C:\WINDOWS\system32\tacrmnqv.dll",b backup-20080604-080918-852 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\veqwfjga.dll",s backup-20080604-080933-339 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\veqwfjga.dll",s backup-20080604-082035-667 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\veqwfjga.dll",s backup-20080604-104921-755 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\cbxtvbje.dll",s backup-20080604-132817-637 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\aexymhqk.dll",s backup-20080604-195957-981 O4 - HKLM\..\Run: [BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\aexymhqk.dll",s backup-20080604-214549-930 O4 - HKLM\..\Run: [300f9797] rundll32.exe "C:\WINDOWS\system32\jjseltbq.dll",b -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell> -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service> S2 ProtexisLicensing - S3 AresChatServer (Ares Chatroom server) - c:\program files\ares\chatserver.exe <Not Verified; Ares Development Group; Ares Chat Server> S3 FLEXnet Licensing Service - S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe -- Device Manager: Disabled ---------------------------------------------------- Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: RAID Controller Device ID: PCI\VEN_105A&DEV_3373&SUBSYS_80F51043&REV_02\4&2E98101C&0&20F0 Manufacturer: Name: RAID Controller PNP Device ID: PCI\VEN_105A&DEV_3373&SUBSYS_80F51043&REV_02\4&2E98101C&0&20F0 Service: Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Ethernet Controller Device ID: PCI\VEN_11AB&DEV_4320&SUBSYS_811A1043&REV_13\4&2E98101C&0&28F0 Manufacturer: Name: Ethernet Controller PNP Device ID: PCI\VEN_11AB&DEV_4320&SUBSYS_811A1043&REV_13\4&2E98101C&0&28F0 Service: Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Multimedia Audio Controller Device ID: PCI\VEN_8086&DEV_24D5&SUBSYS_812A1043&REV_02\3&267A616A&0&FD Manufacturer: Name: Multimedia Audio Controller PNP Device ID: PCI\VEN_8086&DEV_24D5&SUBSYS_812A1043&REV_02\3&267A616A&0&FD Service: -- Scheduled Tasks ------------------------------------------------------------- 2008-06-03 17:19:02 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -- Files created between 2008-05-04 and 2008-06-04 ----------------------------- 2008-06-04 18:27:24 86016 --a------ C:\WINDOWS\system32\cttele.dll <Not Verified; Creative Technology Ltd; Creative Common Proxy Stud> 2008-06-04 18:19:17 2560 --a------ C:\WINDOWS\CTXFIRES.DLL <Not Verified; ; CTxfiRes Dynamic Link Library> 2008-06-04 18:12:57 0 d-------- C:\Program Files\Panda Security 2008-06-04 13:31:00 133120 --a------ C:\WINDOWS\system32\gjfqavsn.dll 2008-06-04 13:28:13 117248 --a------ C:\WINDOWS\system32\jjseltbq.dll 2008-06-04 13:25:47 126976 --a------ C:\WINDOWS\system32\aexymhqk.dll 2008-06-04 13:24:59 796598 --ahs---- C:\WINDOWS\system32\ppqpAJlm.ini2 2008-06-04 13:24:49 372736 --a------ C:\WINDOWS\system32\mlJApqpp.dll 2008-06-04 11 38 53248 --a------ C:\WINDOWS\PSEXESVC.EXE <Not Verified; Sysinternals; Sysinternals PsExec>2008-06-04 10:49:16 0 d-------- C:\Documents and Settings\Administrator\Application Data\Simply Super Software 2008-06-03 22:22:34 68096 --a------ C:\WINDOWS\zip.exe 2008-06-03 22:22:34 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor> 2008-06-03 22:22:34 98816 --a------ C:\WINDOWS\sed.exe 2008-06-03 22:22:34 80412 --a------ C:\WINDOWS\grep.exe 2008-06-03 22:22:34 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; > 2008-06-03 22:22:33 49152 --a------ C:\WINDOWS\VFind.exe 2008-06-03 22:22:33 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists> 2008-06-03 22:22:33 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller> 2008-06-03 21:27:38 0 d-------- C:\Program Files\Lavasoft 2008-06-03 21:27:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-06-03 21:14:11 153088 --a------ C:\WINDOWS\system32\UNRAR3.dll 2008-06-03 21:14:11 75264 --a------ C:\WINDOWS\system32\unacev2.dll 2008-06-03 21:14:08 0 d-------- C:\Program Files\Trojan Remover 2008-06-03 21:14:08 0 d-------- C:\Documents and Settings\Chung\Application Data\Simply Super Software 2008-06-03 14:14:43 0 d-------- C:\Documents and Settings\Chung\Application Data\HouseCall 6.6 2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\Templates 2008-06-03 11:22:45 0 dr------- C:\Documents and Settings\Administrator\Start Menu 2008-06-03 11:22:45 0 dr-h----- C:\Documents and Settings\Administrator\SendTo 2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\Recent 2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\PrintHood 2008-06-03 11:22:45 1048576 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT 2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\NetHood 2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\My Documents 2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\Local Settings 2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\Favorites 2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\Desktop 2008-06-03 11:22:45 0 d--hs---- C:\Documents and Settings\Administrator\Cookies 2008-06-03 11:22:45 0 dr-h----- C:\Documents and Settings\Administrator\Application Data 2008-06-03 11:22:45 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft 2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer 2008-06-03 11:22:33 0 d-------- C:\WINDOWS\CSC 2008-06-03 11:09:20 0 d-------- C:\Documents and Settings\LocalService\Application Data\Macromedia 2008-06-03 10:56:29 0 dr------- C:\Documents and Settings\LocalService\Favorites 2008-06-03 03:24:20 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP 2008-06-03 03:23:05 0 d-------- C:\Program Files\Spyware Doctor 2008-06-02 20:37:34 57344 --a------ C:\WINDOWS\system32\mlJCRlkI.dll 2008-06-01 18:45:23 76166 --a------ C:\WINDOWS\War3Unin.dat 2008-06-01 18:45:22 2829 --a------ C:\WINDOWS\War3Unin.pif 2008-06-01 18:45:22 139264 --a------ C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller> 2008-05-29 15:10:07 0 d-------- C:\Program Files\iPod 2008-05-29 15:09:45 0 d-------- C:\Program Files\iTunes 2008-05-15 01:49:26 0 d-------- C:\Documents and Settings\All Users\Application Data\media center programs 2008-05-14 22:14:13 0 d-------- C:\Program Files\Funcom 2008-05-14 21:33:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Funcom 2008-05-11 20:21:08 0 d-------- C:\Documents and Settings\Chung\Application Data\SystemRequirementsLab 2008-05-11 20:11:47 0 d-------- C:\WINDOWS\system32\Futuremark 2008-05-11 20:11:46 0 d-------- C:\Program Files\Common Files\Futuremark Shared 2008-05-11 20:11:36 0 d-------- C:\Documents and Settings\Chung\Application Data\InstallShield 2008-05-10 19:40:01 0 d-------- C:\Documents and Settings\Default User\Application Data\Apple Computer -- Find3M Report --------------------------------------------------------------- 2008-06-04 18:36:24 0 d-------- C:\Program Files\Symantec AntiVirus 2008-06-04 18:27:53 0 d-------- C:\Program Files\Creative Professional 2008-06-04 18:23:19 409600 --a------ C:\WINDOWS\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32> 2008-06-04 18:23:19 114688 --a------ C:\WINDOWS\system32\OpenAL32.dll <Not Verified; Portions (C) Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL(TM) Library> 2008-06-04 18:14:29 0 d-------- C:\Program Files\Viewpoint 2008-06-03 21:26:36 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-06-03 21:21:45 0 d-------- C:\Program Files\Google 2008-06-03 20:52:35 0 d-------- C:\Documents and Settings\Chung\Application Data\uTorrent 2008-06-03 11:19:43 0 d-------- C:\Program Files\Common Files 2008-06-03 08:32:08 0 d-------- C:\Program Files\Warcraft III 2008-06-02 22:32:45 0 d-------- C:\Documents and Settings\Chung\Application Data\Adobe 2008-06-02 21:03:07 0 d-------- C:\Program Files\Common Files\Adobe 2008-06-01 17:20:12 0 d-------- C:\Program Files\Apple Software Update 2008-05-29 15:05:53 0 d-------- C:\Program Files\QuickTime 2008-05-22 22:51:17 0 d-------- C:\Program Files\World of Warcraft 2008-05-18 14:14:05 0 d-------- C:\Program Files\mIRC 2008-05-15 23:28:24 0 d-------- C:\Program Files\Common Files\AOL 2008-05-15 23:28:24 0 d-------- C:\Program Files\AIM 2008-05-11 20:11:44 0 d--h----- C:\Program Files\InstallShield Installation Information 2008-05-01 01:40:43 0 d-------- C:\Program Files\AIM6 2008-04-12 08:19:24 0 d-------- C:\Program Files\Anti Keylogger Shield 2008-03-20 15:36:48 43520 --a------ C:\WINDOWS\system32\CTBurst.dll <Not Verified; ; CTBurst Module> 2008-03-20 15:35:52 34816 --a------ C:\WINDOWS\system32\a3d.dll <Not Verified; ; a3dx5> 2008-03-20 15:35:38 27648 --a------ C:\WINDOWS\system32\ac3api.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:35:14 41472 --a------ C:\WINDOWS\system32\CTxfiBtn.dll <Not Verified; Creative Technology Ltd; CTXFIBTN Dynamic Link Library> 2008-03-20 15:35:10 40960 --a------ C:\WINDOWS\system32\CTxfiSpk.dll <Not Verified; Creative Technology Ltd; Ctxfispk Dynamic Link Library> 2008-03-20 15:35:10 23552 --a------ C:\WINDOWS\system32\Ctxfihlp.exe <Not Verified; Creative Technology Ltd; CTXfiHlp Application> 2008-03-20 15:35:06 41472 --a------ C:\WINDOWS\system32\psconv.exe 2008-03-20 15:35:04 23040 --a------ C:\WINDOWS\system32\CtHelper.exe <Not Verified; Creative Technology Ltd; CtHelper Application> 2008-03-20 15:35:02 12800 --a------ C:\WINDOWS\system32\CTAGENT.DLL <Not Verified; Creative Technology Ltd; ctagent> 2008-03-20 15:35:00 38912 --a------ C:\WINDOWS\system32\CTSPKHLP.DLL <Not Verified; Creative Technology Ltd; CtSpkHlp Dynamic Link Library> 2008-03-20 15:34:58 51200 --a------ C:\WINDOWS\system32\CTpcmcia.dll <Not Verified; Creative Technology Ltd; CTPCMCIA Dynamic Link Library> 2008-03-20 15:34:58 17920 --a------ C:\WINDOWS\system32\ctmmep.dll <Not Verified; Creative Technology Ltd; Ctmmep Dynamic Link Library> 2008-03-20 15:34:50 36864 --a------ C:\WINDOWS\system32\ctthxcal.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:34:50 8704 --a------ C:\WINDOWS\system32\ctpres.dll <Not Verified; Creative Technology Ltd; CtPanel Resource> 2008-03-20 15:34:48 46592 --a------ C:\WINDOWS\system32\ctscal.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:34:46 145408 --a------ C:\WINDOWS\system32\CTDCIFCE.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:34:46 343040 --a------ C:\WINDOWS\system32\ctdc0001.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:34:44 10240 --a------ C:\WINDOWS\system32\ctdcres.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:34:44 230400 --a------ C:\WINDOWS\system32\ctdc0000.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:34:44 10240 --a------ C:\WINDOWS\CTDCRES.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:31:22 46592 --a------ C:\WINDOWS\system32\Ctxfireg.exe <Not Verified; Creative Technology Ltd; CTXFIREG> 2008-03-20 15:31:20 15360 --a------ C:\WINDOWS\system32\Ct20xspi.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:31:14 1119744 --a------ C:\WINDOWS\system32\CTxfispi.exe <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:25:22 46273 --a------ C:\WINDOWS\system32\ctdnlstr.dat 2008-03-20 15:25:22 325821 --a------ C:\WINDOWS\system32\ctdlang.dat 2008-03-20 15:24:54 114688 --a------ C:\WINDOWS\system32\ctemupia.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:50 22016 --a------ C:\WINDOWS\system32\ctedasio.dll <Not Verified; Creative Technology, Ltd; Creative Audio Product> 2008-03-20 15:22:48 50688 --a------ C:\WINDOWS\system32\ctasio.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:48 151040 --a------ C:\WINDOWS\system32\ct_oal.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:44 53248 --a------ C:\WINDOWS\system32\CTDPROXY.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:30 74240 --a------ C:\WINDOWS\system32\CTOSUSER.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:28 10240 --a------ C:\WINDOWS\system32\sfman32.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:26 108544 --a------ C:\WINDOWS\system32\SFMS32.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:24 16384 --a------ C:\WINDOWS\system32\regplib.exe 2008-03-20 15:22:22 68608 --a------ C:\WINDOWS\system32\PIAPROXY.DLL <Not Verified; Creative Technology Ltd; E-mu PIA> 2008-03-20 15:21:58 149838 --a------ C:\WINDOWS\system32\ctbas2w.dat 2008-03-20 15:20:12 274587 --a------ C:\WINDOWS\system32\ctsbas2w.dat 2008-03-20 15:20:02 115166 --a------ C:\WINDOWS\system32\CTBASICW.DAT 2008-03-20 15:20:00 241084 --a------ C:\WINDOWS\system32\CTSBASW.DAT 2008-03-20 15:19:44 313207 --a------ C:\WINDOWS\system32\ctstatic.dat 2008-03-20 15:19:44 53932 --a------ C:\WINDOWS\system32\ctdaught.dat 2008-03-20 15:19:42 7680 --a------ C:\WINDOWS\system32\enlocstr.exe 2008-03-20 15:19:40 12800 --a------ C:\WINDOWS\system32\killapps.exe <Not Verified; ; killapps> 2008-03-20 15:19:26 31232 --a------ C:\WINDOWS\system32\MIDIDEF.EXE <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:19:26 36864 --a------ C:\WINDOWS\system32\devreg.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{487C9905-26A8-42C8-8033-C58AD3D2AEC3}] 2008-06-02 08:37 PM 57344 --a------ C:\WINDOWS\system32\mlJCRlkI.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E931BDB3-013B-4D15-9186-6B23B5929E9F}] 2008-06-04 01:24 PM 372736 --a------ C:\WINDOWS\system32\mlJApqpp.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fa0309f3-40d7-4ada-8310-b6c1dad4b3a2}] 2008-06-04 01:31 PM 133120 --a------ C:\WINDOWS\system32\gjfqavsn.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 AM] "nwiz"="nwiz.exe" [2007-12-05 02:41 AM C:\WINDOWS\system32\nwiz.exe] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 08:26 PM] "vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 09:33 PM] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 AM] "CTHelper"="CTHELPER.EXE" [2008-03-20 03:35 PM C:\WINDOWS\system32\CtHelper.exe] "CTxfiHlp"="CTXFIHLP.EXE" [2008-03-20 03:35 PM C:\WINDOWS\system32\Ctxfihlp.exe] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:56 AM] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 08:44 PM] "SetDefaultMIDI"="MIDIDef.exe" [2008-03-20 03:19 PM C:\WINDOWS\system32\MIDIDEF.EXE] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "DisableRegistryTools"=0 (0x0) "HideLegacyLogonScripts"=0 (0x0) "HideLogoffScripts"=0 (0x0) "RunLogonScriptSync"=1 (0x1) "RunStartupScriptSync"=0 (0x0) "HideStartupScripts"=0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "HideLegacyLogonScripts"=0 (0x0) "HideLogoffScripts"=0 (0x0) "RunLogonScriptSync"=1 (0x1) "RunStartupScriptSync"=0 (0x0) "HideStartupScripts"=0 (0x0) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{487C9905-26A8-42C8-8033-C58AD3D2AEC3}"= C:\WINDOWS\system32\mlJCRlkI.dll [2008-06-02 08:37 PM 57344] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJCRlkI] mlJCRlkI.dll 2008-06-02 08:37 PM 57344 C:\WINDOWS\system32\mlJCRlkI.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] "Authentication Packages"= msv1_0 C:\WINDOWS\system32\mlJApqpp [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] @="Volume shadow copy" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk] path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\300f9797] rundll32.exe "C:\WINDOWS\system32\ytoyancc.dll",b [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares] "C:\Program Files\Ares\Ares.exe" -h [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM333ca40b] Rundll32.exe "C:\WINDOWS\system32\ylkufogk.dll",s [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F] AutoRun\command- F:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7dbe02d0-6a35-11dc-be2b-00904b2bc814}] AutoRun\command- ie.exe explore\Command- ie.exe open\Command- ie.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc69911f-934e-11dc-be2d-00904b2bc814}] AutoRun\command- F:\setupSNK.exe -- End of Deckard's System Scanner: finished at 2008-06-04 22:00:55 ------------ That's with deckard, the only thing I could get running :\ |
|
|
|
|
#5 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,549
OS: WinXP and Vista
|
Re: Pulling my hair out.
You did fine, knightshift.
![]() This will require more than one round to properly eradicate. Please stay with me until given the 'all clear' even if symptoms seemingly abate. Read through this entire procedure and if you have any questions, please ask them before you begin. Then either print out, or copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions. It's IMPORTANT to carry out the instructions in the sequence listed below. *************************************************** Download ComboFix.exe from any of the links below: Link 1 Link 2 Link 3 **Note: It is important that it is saved directly to your desktop** -------------------------------------------------------------------- With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time. Go to Microsoft's website => http://support.microsoft.com/kb/310994 Select the download that's appropriate for your Operating System ![]() Download the file & save it as it's originally named, next to ComboFix.exe. ![]() -------------------------------------------------------------------- If you used another computer to download the above, please transfer all files you just downloaded, to the desktop of the infected computer. -------------------------------------------------------------------- Now close all open windows and programs, including all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
|
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: Jun 2008
Posts: 7
OS: XP
|
Re: Pulling my hair out.
Thanks for your help! Here's the log from ComboFix.
ComboFix 08-05-25.5 - Chung 2008-06-05 10:30:52.8 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1073 [GMT -7:00] Running from: C:\Documents and Settings\Chung\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Chung\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\BM333ca40b.xml C:\WINDOWS\cookies.ini C:\WINDOWS\pskt.ini C:\WINDOWS\system32\bkrlcsnn.ini C:\WINDOWS\system32\gfffwsjx.ini C:\WINDOWS\system32\mTuvDfhk.ini C:\WINDOWS\system32\mTuvDfhk.ini2 C:\WINDOWS\system32\nnsclrkb.dll C:\WINDOWS\system32\tvvwvyxx.ini C:\WINDOWS\system32\tvvwvyxx.ini2 C:\WINDOWS\system32\wsqtuksj.dll . ((((((((((((((((((((((((( Files Created from 2008-05-05 to 2008-06-05 ))))))))))))))))))))))))))))))) . 2008-06-05 10:35 . 2008-06-05 10:35 11,564 --a------ C:\WINDOWS\system32\DVCState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx 2008-06-05 10:35 . 2008-06-05 10:35 1,524 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx 2008-06-05 10:35 . 2008-06-05 10:35 1,524 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx 2008-06-05 10:35 . 2008-06-05 10:35 64 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx 2008-06-05 10:35 . 2008-06-05 10:35 64 --a------ C:\WINDOWS\system32\BMXState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx 2008-06-05 10:22 . 2008-06-05 10:22 125,952 --a------ C:\WINDOWS\system32\cdolfjcs.dll 2008-06-05 10:21 . 2008-06-05 10:21 373,760 --a------ C:\WINDOWS\system32\xxyvwvvt.dll 2008-06-05 09:33 . 2008-06-05 09:34 321 --a------ C:\WINDOWS\wininit.ini 2008-06-05 00:40 . 2008-06-05 00:40 133,120 --a------ C:\WINDOWS\system32\mrvotahb.dll 2008-06-05 00:39 . 2008-06-05 00:39 117,248 --a------ C:\WINDOWS\system32\xjswfffg.dll 2008-06-05 00:38 . 2008-06-05 00:38 126,976 --a------ C:\WINDOWS\system32\lagrvrbj.dll 2008-06-05 00:32 . 2008-06-05 00:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion 2008-06-04 22:14 . 2008-06-04 22:14 <DIR> d-------- C:\Program Files\CCleaner 2008-06-04 21:56 . 2008-06-04 21:56 <DIR> d-------- C:\Deckard 2008-06-04 18:27 . 2006-11-14 15:28 86,016 --a------ C:\WINDOWS\system32\cttele.dll 2008-06-04 18:19 . 2008-03-20 15:35 2,560 --a------ C:\WINDOWS\CTXFIRES.DLL 2008-06-04 18:12 . 2008-06-04 18:17 <DIR> d-------- C:\Program Files\Panda Security 2008-06-04 10:49 . 2008-06-04 10:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Simply Super Software 2008-06-03 21:27 . 2008-06-03 21:27 <DIR> d-------- C:\Program Files\Lavasoft 2008-06-03 21:27 . 2008-06-03 21:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-06-03 21:14 . 2008-06-03 11:30 <DIR> d-------- C:\Program Files\Trojan Remover 2008-06-03 21:14 . 2008-06-03 21:14 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\Simply Super Software 2008-06-03 21:14 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll 2008-06-03 21:14 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll 2008-06-03 15:13 . 2008-06-03 15:12 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2008-06-03 14:14 . 2008-06-03 14:14 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\HouseCall 6.6 2008-06-03 11:22 . 2008-05-10 19:40 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer 2008-06-03 11:22 . 2008-06-04 22:22 <DIR> d-------- C:\Documents and Settings\Administrator 2008-06-03 03:24 . 2008-06-04 22:27 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP 2008-06-03 03:23 . 2008-06-03 21:38 <DIR> d-------- C:\Program Files\Spyware Doctor 2008-06-02 20:37 . 2008-06-02 20:37 57,344 --a------ C:\WINDOWS\system32\mlJCRlkI.dll 2008-06-01 18:45 . 2008-06-01 18:53 139,264 --a------ C:\WINDOWS\War3Unin.exe 2008-06-01 18:45 . 2008-06-01 18:59 76,166 --a------ C:\WINDOWS\War3Unin.dat 2008-06-01 18:45 . 2008-06-01 18:53 2,829 --a------ C:\WINDOWS\War3Unin.pif 2008-05-29 15:10 . 2008-05-29 15:10 <DIR> d-------- C:\Program Files\iPod 2008-05-29 15:09 . 2008-05-29 15:10 <DIR> d-------- C:\Program Files\iTunes 2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\system32\lsdelete.exe 2008-05-15 01:52 . 2008-03-05 15:56 3,786,760 --a------ C:\WINDOWS\system32\D3DX9_37.dll 2008-05-15 01:52 . 2008-03-05 15:56 1,420,824 --a------ C:\WINDOWS\system32\D3DCompiler_37.dll 2008-05-15 01:52 . 2008-03-05 16:03 479,752 --a------ C:\WINDOWS\system32\XAudio2_0.dll 2008-05-15 01:52 . 2008-02-05 23:07 462,864 --a------ C:\WINDOWS\system32\d3dx10_37.dll 2008-05-15 01:52 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll 2008-05-15 01:52 . 2008-03-05 16:03 238,088 --a------ C:\WINDOWS\system32\xactengine3_0.dll 2008-05-15 01:52 . 2008-03-05 16:00 25,608 --a------ C:\WINDOWS\system32\X3DAudio1_3.dll 2008-05-15 01:49 . 2008-05-15 01:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\media center programs 2008-05-14 22:14 . 2008-05-14 22:14 <DIR> d-------- C:\Program Files\Funcom 2008-05-14 21:33 . 2008-05-14 21:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Funcom 2008-05-11 20:21 . 2008-05-11 20:21 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\SystemRequirementsLab 2008-05-11 20:11 . 2008-05-11 20:11 <DIR> d-------- C:\WINDOWS\system32\Futuremark 2008-05-11 20:11 . 2008-05-11 20:11 <DIR> d-------- C:\Program Files\Common Files\Futuremark Shared 2008-05-11 20:11 . 2008-05-11 20:11 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\InstallShield 2008-05-11 20:11 . 2007-08-20 11:05 27,672 -ra------ C:\WINDOWS\system32\drivers\Entech.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-05 17:37 --------- d-----w C:\Program Files\Symantec AntiVirus 2008-06-05 01:27 --------- d-----w C:\Program Files\Creative Professional 2008-06-05 01:23 409,600 ----a-w C:\WINDOWS\system32\wrap_oal.dll 2008-06-05 01:23 114,688 ----a-w C:\WINDOWS\system32\OpenAL32.dll 2008-06-05 01:14 --------- d-----w C:\Program Files\Viewpoint 2008-06-05 01:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint 2008-06-04 04:26 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-06-04 04:21 --------- d-----w C:\Program Files\Google 2008-06-04 03:52 --------- d-----w C:\Documents and Settings\Chung\Application Data\uTorrent 2008-06-03 15:32 --------- d-----w C:\Program Files\Warcraft III 2008-06-03 04:03 --------- d-----w C:\Program Files\Common Files\Adobe 2008-06-02 00:20 --------- d-----w C:\Program Files\Apple Software Update 2008-05-29 22:05 --------- d-----w C:\Program Files\QuickTime 2008-05-23 05:51 --------- d-----w C:\Program Files\World of Warcraft 2008-05-18 21:14 --------- d-----w C:\Program Files\mIRC 2008-05-16 06:28 --------- d-----w C:\Program Files\Common Files\AOL 2008-05-16 06:28 --------- d-----w C:\Program Files\AIM 2008-05-12 03:11 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-05-01 08:40 --------- d-----w C:\Program Files\AIM6 2008-05-01 08:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads 2008-04-29 18:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys 2008-04-29 18:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys 2008-04-29 18:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys 2008-04-12 15:19 --------- d-----w C:\Program Files\Anti Keylogger Shield 2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll 2008-03-20 22:36 86,016 ----a-w C:\WINDOWS\system32\ctcoinst.dll 2008-03-20 22:36 43,520 ----a-w C:\WINDOWS\system32\CTBurst.dll 2008-03-20 22:36 163,328 ----a-w C:\WINDOWS\system32\ctdvinst.dll 2008-03-20 22:36 11,776 ----a-w C:\WINDOWS\system32\inres.dll 2008-03-20 22:36 11,776 ----a-w C:\WINDOWS\INRES.DLL 2008-03-20 22:35 42,496 ----a-w C:\WINDOWS\system32\readreg.exe 2008-03-20 22:35 41,472 ----a-w C:\WINDOWS\system32\psconv.exe 2008-03-20 22:35 41,472 ----a-w C:\WINDOWS\system32\CTxfiBtn.dll 2008-03-20 22:35 40,960 ----a-w C:\WINDOWS\system32\CTxfiSpk.dll 2008-03-20 22:35 38,912 ----a-w C:\WINDOWS\system32\CTSPKHLP.DLL 2008-03-20 22:35 34,816 ----a-w C:\WINDOWS\system32\a3d.dll 2008-03-20 22:35 27,648 ----a-w C:\WINDOWS\system32\ac3api.dll 2008-03-20 22:35 23,552 ----a-w C:\WINDOWS\system32\Ctxfihlp.exe 2008-03-20 22:35 23,040 ----a-w C:\WINDOWS\system32\CtHelper.exe 2008-03-20 22:35 12,800 ----a-w C:\WINDOWS\system32\CTAGENT.DLL 2008-03-20 22:34 8,704 ----a-w C:\WINDOWS\system32\ctpres.dll 2008-03-20 22:34 51,200 ----a-w C:\WINDOWS\system32\CTpcmcia.dll 2008-03-20 22:34 46,592 ----a-w C:\WINDOWS\system32\ctscal.dll 2008-03-20 22:34 36,864 ----a-w C:\WINDOWS\system32\ctthxcal.dll 2008-03-20 22:34 343,040 ----a-w C:\WINDOWS\system32\ctdc0001.dll 2008-03-20 22:34 230,400 ----a-w C:\WINDOWS\system32\ctdc0000.dll 2008-03-20 22:34 17,920 ----a-w C:\WINDOWS\system32\ctmmep.dll 2008-03-20 22:34 145,408 ----a-w C:\WINDOWS\system32\CTDCIFCE.DLL 2008-03-20 22:34 10,240 ----a-w C:\WINDOWS\system32\ctdcres.dll 2008-03-20 22:34 10,240 ----a-w C:\WINDOWS\CTDCRES.DLL 2008-03-20 22:31 46,592 ----a-w C:\WINDOWS\system32\Ctxfireg.exe 2008-03-20 22:31 15,360 ----a-w C:\WINDOWS\system32\Ct20xspi.dll 2008-03-20 22:31 1,119,744 ----a-w C:\WINDOWS\system32\CTxfispi.exe 2008-03-20 22:24 114,688 ----a-w C:\WINDOWS\system32\ctemupia.dll 2008-03-20 22:22 74,240 ----a-w C:\WINDOWS\system32\CTOSUSER.DLL 2008-03-20 22:22 68,608 ----a-w C:\WINDOWS\system32\PIAPROXY.DLL 2008-03-20 22:22 53,248 ----a-w C:\WINDOWS\system32\CTDPROXY.DLL 2008-03-20 22:22 50,688 ----a-w C:\WINDOWS\system32\ctasio.dll 2008-03-20 22:22 22,016 ----a-w C:\WINDOWS\system32\ctedasio.dll 2008-03-20 22:22 16,384 ----a-w C:\WINDOWS\system32\regplib.exe 2008-03-20 22:22 151,040 ----a-w C:\WINDOWS\system32\ct_oal.dll 2008-03-20 22:22 108,544 ----a-w C:\WINDOWS\system32\SFMS32.DLL 2008-03-20 22:22 10,240 ----a-w C:\WINDOWS\system32\sfman32.dll 2008-03-20 22:19 7,680 ----a-w C:\WINDOWS\system32\enlocstr.exe 2008-03-20 22:19 36,864 ----a-w C:\WINDOWS\system32\devreg.dll 2008-03-20 22:19 31,232 ----a-w C:\WINDOWS\system32\MIDIDEF.EXE 2008-03-20 22:19 12,800 ----a-w C:\WINDOWS\system32\killapps.exe 2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys 2007-01-31 07:26 88 --sha-r C:\WINDOWS\system32\BD56F95BB8.sys 2007-01-31 07:26 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((( snapshot_2008-06-04_23.53.03.73 ))))))))))))))))))))))))))))))))))))))))) . - 2008-06-05 06:14:14 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-06-05 17:36:52 2,048 --s-a-w C:\WINDOWS\bootstat.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{487C9905-26A8-42C8-8033-C58AD3D2AEC3}] 2008-06-02 20:37 57344 --a------ C:\WINDOWS\system32\mlJCRlkI.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{80539493-39F8-4EED-9C95-6F7644E3136A}] C:\WINDOWS\system32\khfDvuTm.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E32AB07F-1D8F-4A50-A8FB-7235153B7D6F}] 2008-06-05 10:21 373760 --a------ C:\WINDOWS\system32\xxyvwvvt.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 20:44 1200128] "SetDefaultMIDI"="MIDIDef.exe" [2008-03-20 15:19 31232 C:\WINDOWS\system32\MIDIDEF.EXE] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776] "nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 20:26 52896] "vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 21:33 125168] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920] "CTHelper"="CTHELPER.EXE" [2008-03-20 15:35 23040 C:\WINDOWS\system32\CtHelper.exe] "CTxfiHlp"="CTXFIHLP.EXE" [2008-03-20 15:35 23552 C:\WINDOWS\system32\Ctxfihlp.exe] "BM333ca40b"="C:\WINDOWS\system32\cdolfjcs.dll" [2008-06-05 10:22 125952] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{487C9905-26A8-42C8-8033-C58AD3D2AEC3}"= C:\WINDOWS\system32\mlJCRlkI.dll [2008-06-02 20:37 57344] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJCRlkI] mlJCRlkI.dll 2008-06-02 20:37 57344 C:\WINDOWS\system32\mlJCRlkI.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk] path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\300f9797] C:\WINDOWS\system32\ytoyancc.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] --a------ 2005-06-07 00:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6] --a------ 2006-11-07 08:29 50736 C:\Program Files\AIM6\aim6.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares] --a------ 2007-04-07 18:08 947200 C:\Program Files\Ares\Ares.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM333ca40b] C:\WINDOWS\system32\ylkufogk.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search] --a------ 2007-02-05 00:03 157696 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent] --a------ 2005-11-15 20:44 1200128 C:\Program Files\Microsoft ActiveSync\wcescomm.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager] --a------ 2003-10-23 20:51 233472 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] --a------ 2005-02-17 00:11 49152 C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility] --a------ 2003-11-10 16:04 188416 C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] --a------ 2005-02-16 17:15 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] --a------ 2005-02-16 17:15 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] --a------ 2007-01-19 13:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] -rahs---- 2008-01-28 12:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2006-07-26 03:03 49263 C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner] --a------ 2007-01-17 04:23 342112 C:\Program Files\Trojan Remover\Trjscan.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] --a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "C:\\Program Files\\AIM\\aim.exe"= "C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"= "C:\\Program Files\\HKBN 2b\\bin\\SMC.exe"= "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\livecall.exe"= "C:\\Program Files\\uTorrent\\uTorrent.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service R3 COMMONFX.SYS;COMMONFX.SYS;C:\WINDOWS\system32\drivers\COMMONFX.SYS [2008-03-20 17:23] R3 CTEDSPFX.SYS;CTEDSPFX.SYS;C:\WINDOWS\system32\drivers\CTEDSPFX.SYS [2008-03-20 17:32] R3 CTEDSPIO.SYS;CTEDSPIO.SYS;C:\WINDOWS\system32\drivers\CTEDSPIO.SYS [2008-03-20 17:38] R3 CTEDSPSY.SYS;CTEDSPSY.SYS;C:\WINDOWS\system32\drivers\CTEDSPSY.SYS [2008-03-20 17:37] R3 PRISM_USB;Dell TrueMobile 1180 Wireless USB Adapter;C:\WINDOWS\system32\DRIVERS\DELUSB_51.sys [2002-08-09 15:46] S3 COMMONFX;COMMONFX;C:\WINDOWS\system32\drivers\COMMONFX.SYS [2008-03-20 17:23] S3 CT20XUT.SYS;CT20XUT.SYS;C:\WINDOWS\system32\drivers\CT20XUT.SYS [2008-03-20 17:36] S3 CT20XUT;CT20XUT;C:\WINDOWS\system32\drivers\CT20XUT.SYS [2008-03-20 17:36] S3 CTAUDFX.SYS;CTAUDFX.SYS;C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2008-03-20 17:23] S3 CTAUDFX;CTAUDFX;C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2008-03-20 17:23] S3 CTEAPSFX.SYS;CTEAPSFX.SYS;C:\WINDOWS\system32\drivers\CTEAPSFX.SYS [2008-03-20 17:26] S3 CTEAPSFX;CTEAPSFX;C:\WINDOWS\system32\drivers\CTEAPSFX.SYS [2008-03-20 17:26] S3 CTEDSPFX;CTEDSPFX;C:\WINDOWS\system32\drivers\CTEDSPFX.SYS [2008-03-20 17:32] S3 CTEDSPIO;CTEDSPIO;C:\WINDOWS\system32\drivers\CTEDSPIO.SYS [2008-03-20 17:38] S3 CTEDSPSY;CTEDSPSY;C:\WINDOWS\system32\drivers\CTEDSPSY.SYS [2008-03-20 17:37] S3 CTERFXFX.SYS;CTERFXFX.SYS;C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2008-03-20 17:36] S3 CTERFXFX;CTERFXFX;C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2008-03-20 17:36] S3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\WINDOWS\system32\drivers\CTEXFIFX.SYS [2008-03-20 17:40] S3 CTEXFIFX;CTEXFIFX;C:\WINDOWS\system32\drivers\CTEXFIFX.SYS [2008-03-20 17:40] S3 CTHWIUT.SYS;CTHWIUT.SYS;C:\WINDOWS\system32\drivers\CTHWIUT.SYS [2008-03-20 17:37] S3 CTHWIUT;CTHWIUT;C:\WINDOWS\system32\drivers\CTHWIUT.SYS [2008-03-20 17:37] S3 CTSBLFX.SYS;CTSBLFX.SYS;C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2008-03-20 17:25] S3 CTSBLFX;CTSBLFX;C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2008-03-20 17:25] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F] \Shell\AutoRun\command - F:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7dbe02d0-6a35-11dc-be2b-00904b2bc814}] \Shell\AutoRun\command - ie.exe \Shell\explore\Command - ie.exe \Shell\open\Command - ie.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc69911f-934e-11dc-be2d-00904b2bc814}] \Shell\AutoRun\command - F:\setupSNK.exe . Contents of the 'Scheduled Tasks' folder "2008-06-04 00:19:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-05 10:44:12 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\system32\winlogon.exe -> C:\WINDOWS\system32\mlJCRlkI.dll PROCESS: C:\WINDOWS\explorer.exe -> C:\WINDOWS\system32\cdolfjcs.dll -> ?:\WINDOWS\System32\CSCDLL.dll . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\MICROS~3\rapimgr.exe C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe . ************************************************************************** . Completion time: 2008-06-05 10:49:46 - machine was rebooted [Chung] ComboFix-quarantined-files.txt 2008-06-05 17:49:25 ComboFix2.txt 2008-06-05 07:16:19 ComboFix3.txt 2008-06-05 06:55:59 ComboFix4.txt 2008-06-04 18:23:28 ComboFix5.txt 2008-06-04 15:48:45 Pre-Run: 26,006,482,944 bytes free Post-Run: 25,971,109,888 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons 349 --- E O F --- 2008-05-30 01:55:36 |
|
|
|
|
#7 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,549
OS: WinXP and Vista
|
Re: Pulling my hair out.
Hi knightshift,
You've used an older version of ComboFix. Please delete your existing version and download the latest copy using the links I gave you earlier. 1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. If you are unsure how to do this, please see this link http://www.bleepingcomputer.com/forums/topic114351.html -------------------------------------------------------------------- Double click on ComboFix.exe & follow the prompts.
|
|
|
|
|
#8 (permalink) |
|
Registered User
Join Date: Jun 2008
Posts: 7
OS: XP
|
Re: Pulling my hair out.
I tried to close Symanetic and the other programs but explorer just kept on crashing and so did TaskManager, although I was able to turn off auto-protect. Here you go, thanks again!
ComboFix 08-06-06.2 - Chung 2008-06-05 12:50:01.9 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1012 [GMT -7:00] Running from: C:\Documents and Settings\Chung\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\pskt.ini C:\WINDOWS\system32\cdolfjcs.dll C:\WINDOWS\system32\gthitvsr.dll C:\WINDOWS\system32\gyxgbmxj.dll C:\WINDOWS\system32\jxmbgxyg.ini C:\WINDOWS\system32\lagrvrbj.dll C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\mlJCRlkI.dll C:\WINDOWS\system32\mrvotahb.dll C:\WINDOWS\system32\nwqpndto.dll C:\WINDOWS\system32\tvvwvyxx.ini C:\WINDOWS\system32\tvvwvyxx.ini2 C:\WINDOWS\system32\xjswfffg.dll C:\WINDOWS\system32\xxyvwvvt.dll . ((((((((((((((((((((((((( Files Created from 2008-05-06 to 2008-06-06 ))))))))))))))))))))))))))))))) . 2008-06-05 10:49 . 2008-06-05 10:49 0 --a------ C:\WINDOWS\BM333ca40b.xml 2008-06-05 10:35 . 2008-06-06 12:54 11,564 --a------ C:\WINDOWS\system32\DVCState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx 2008-06-05 10:35 . 2008-06-06 12:54 1,524 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx 2008-06-05 10:35 . 2008-06-06 12:54 1,524 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx 2008-06-05 10:35 . 2008-06-06 12:54 64 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx 2008-06-05 10:35 . 2008-06-06 12:54 64 --a------ C:\WINDOWS\system32\BMXState-{00000002-00000000-0000000B-00001102-00000004-40011102}.rfx 2008-06-05 09:33 . 2008-06-05 09:34 321 --a------ C:\WINDOWS\wininit.ini 2008-06-05 00:32 . 2008-06-05 00:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion 2008-06-04 22:14 . 2008-06-04 22:14 <DIR> d-------- C:\Program Files\CCleaner 2008-06-04 21:56 . 2008-06-04 21:56 <DIR> d-------- C:\Deckard 2008-06-04 18:27 . 2006-11-14 15:28 86,016 --a------ C:\WINDOWS\system32\cttele.dll 2008-06-04 18:19 . 2008-03-20 15:35 2,560 --a------ C:\WINDOWS\CTXFIRES.DLL 2008-06-04 18:12 . 2008-06-04 18:17 <DIR> d-------- C:\Program Files\Panda Security 2008-06-04 10:49 . 2008-06-04 10:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Simply Super Software 2008-06-03 21:27 . 2008-06-03 21:27 <DIR> d-------- C:\Program Files\Lavasoft 2008-06-03 21:27 . 2008-06-03 21:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-06-03 21:14 . 2008-06-03 11:30 <DIR> d-------- C:\Program Files\Trojan Remover 2008-06-03 21:14 . 2008-06-03 21:14 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\Simply Super Software 2008-06-03 21:14 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll 2008-06-03 21:14 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll 2008-06-03 15:13 . 2008-06-03 15:12 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2008-06-03 14:14 . 2008-06-03 14:14 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\HouseCall 6.6 2008-06-03 11:22 . 2008-05-10 19:40 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer 2008-06-03 11:22 . 2008-06-04 22:22 <DIR> d-------- C:\Documents and Settings\Administrator 2008-06-03 03:24 . 2008-06-04 22:27 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP 2008-06-03 03:23 . 2008-06-03 21:38 <DIR> d-------- C:\Program Files\Spyware Doctor 2008-06-01 18:45 . 2008-06-01 18:53 139,264 --a------ C:\WINDOWS\War3Unin.exe 2008-06-01 18:45 . 2008-06-01 18:59 76,166 --a------ C:\WINDOWS\War3Unin.dat 2008-06-01 18:45 . 2008-06-01 18:53 2,829 --a------ C:\WINDOWS\War3Unin.pif 2008-05-29 15:10 . 2008-05-29 15:10 <DIR> d-------- C:\Program Files\iPod 2008-05-29 15:09 . 2008-05-29 15:10 <DIR> d-------- C:\Program Files\iTunes 2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\system32\lsdelete.exe 2008-05-15 01:52 . 2008-03-05 15:56 3,786,760 --a------ C:\WINDOWS\system32\D3DX9_37.dll 2008-05-15 01:52 . 2008-03-05 15:56 1,420,824 --a------ C:\WINDOWS\system32\D3DCompiler_37.dll 2008-05-15 01:52 . 2008-03-05 16:03 479,752 --a------ C:\WINDOWS\system32\XAudio2_0.dll 2008-05-15 01:52 . 2008-02-05 23:07 462,864 --a------ C:\WINDOWS\system32\d3dx10_37.dll 2008-05-15 01:52 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll 2008-05-15 01:52 . 2008-03-05 16:03 238,088 --a------ C:\WINDOWS\system32\xactengine3_0.dll 2008-05-15 01:52 . 2008-03-05 16:00 25,608 --a------ C:\WINDOWS\system32\X3DAudio1_3.dll 2008-05-15 01:49 . 2008-05-15 01:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\media center programs 2008-05-14 22:14 . 2008-05-14 22:14 <DIR> d-------- C:\Program Files\Funcom 2008-05-14 21:33 . 2008-05-14 21:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Funcom 2008-05-11 20:21 . 2008-05-11 20:21 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\SystemRequirementsLab 2008-05-11 20:11 . 2008-05-11 20:11 <DIR> d-------- C:\WINDOWS\system32\Futuremark 2008-05-11 20:11 . 2008-05-11 20:11 <DIR> d-------- C:\Program Files\Common Files\Futuremark Shared 2008-05-11 20:11 . 2008-05-11 20:11 <DIR> d-------- C:\Documents and Settings\Chung\Application Data\InstallShield 2008-05-11 20:11 . 2007-08-20 11:05 27,672 -ra------ C:\WINDOWS\system32\drivers\Entech.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-06 19:57 --------- d-----w C:\Program Files\Symantec AntiVirus 2008-06-05 01:27 --------- d-----w C:\Program Files\Creative Professional 2008-06-05 01:14 --------- d-----w C:\Program Files\Viewpoint 2008-06-05 01:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint 2008-06-04 04:26 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-06-04 04:21 --------- d-----w C:\Program Files\Google 2008-06-04 03:52 --------- d-----w C:\Documents and Settings\Chung\Application Data\uTorrent 2008-06-03 15:32 --------- d-----w C:\Program Files\Warcraft III 2008-06-03 04:03 --------- d-----w C:\Program Files\Common Files\Adobe 2008-06-02 00:20 --------- d-----w C:\Program Files\Apple Software Update 2008-05-29 22:05 --------- d-----w C:\Program Files\QuickTime 2008-05-23 05:51 --------- d-----w C:\Program Files\World of Warcraft 2008-05-18 21:14 --------- d-----w C:\Program Files\mIRC 2008-05-16 06:28 --------- d-----w C:\Program Files\Common Files\AOL 2008-05-16 06:28 --------- d-----w C:\Program Files\AIM 2008-05-12 03:11 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-05-01 08:40 --------- d-----w C:\Program Files\AIM6 2008-05-01 08:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads 2008-04-29 18:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys 2008-04-29 18:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys 2008-04-29 18:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys 2008-04-12 15:19 --------- d-----w C:\Program Files\Anti Keylogger Shield 2008-03-20 22:36 11,776 ----a-w C:\WINDOWS\INRES.DLL 2008-03-20 22:34 10,240 ----a-w C:\WINDOWS\CTDCRES.DLL 2007-01-31 07:26 88 --sha-r C:\WINDOWS\system32\BD56F95BB8.sys 2007-01-31 07:26 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((( snapshot_2008-06-04_23.53.03.73 ))))))))))))))))))))))))))))))))))))))))) . - 2008-06-05 06:14:14 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-06-06 19:55:58 2,048 --s-a-w C:\WINDOWS\bootstat.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{80539493-39F8-4EED-9C95-6F7644E3136A}] C:\WINDOWS\system32\khfDvuTm.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 20:44 1200128] "SetDefaultMIDI"="MIDIDef.exe" [2008-03-20 15:19 31232 C:\WINDOWS\system32\MIDIDEF.EXE] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776] "nwiz"="nwiz.exe" [2007-12-05 02:41 1626112 C:\WINDOWS\system32\nwiz.exe] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 20:26 52896] "vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 21:33 125168] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 81920] "CTHelper"="CTHELPER.EXE" [2008-03-20 15:35 23040 C:\WINDOWS\system32\CtHelper.exe] "CTxfiHlp"="CTXFIHLP.EXE" [2008-03-20 15:35 23552 C:\WINDOWS\system32\Ctxfihlp.exe] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk] path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\300f9797] C:\WINDOWS\system32\ytoyancc.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] --a------ 2005-06-07 00:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6] --a------ 2006-11-07 08:29 50736 C:\Program Files\AIM6\aim6.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares] --a------ 2007-04-07 18:08 947200 C:\Program Files\Ares\Ares.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM333ca40b] C:\WINDOWS\system32\ylkufogk.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search] --a------ 2007-02-05 00:03 157696 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent] --a------ 2005-11-15 20:44 1200128 C:\Program Files\Microsoft ActiveSync\wcescomm.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager] --a------ 2003-10-23 20:51 233472 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] --a------ 2005-02-17 00:11 49152 C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility] --a------ 2003-11-10 16:04 188416 C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] --a------ 2005-02-16 17:15 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] --a------ 2005-02-16 17:15 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] --a------ 2007-01-19 13:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] -rahs---- 2008-01-28 12:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2006-07-26 03:03 49263 C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner] --a------ 2007-01-17 04:23 342112 C:\Program Files\Trojan Remover\Trjscan.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] --a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\LimeWire\\LimeWire.exe"= "C:\\Program Files\\AIM\\aim.exe"= "C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"= "C:\\Program Files\\HKBN 2b\\bin\\SMC.exe"= "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\livecall.exe"= "C:\\Program Files\\uTorrent\\uTorrent.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service R3 COMMONFX.SYS;COMMONFX.SYS;C:\WINDOWS\system32\drivers\COMMONFX.SYS [2008-03-20 17:23] R3 CTEDSPFX.SYS;CTEDSPFX.SYS;C:\WINDOWS\system32\drivers\CTEDSPFX.SYS [2008-03-20 17:32] R3 CTEDSPIO.SYS;CTEDSPIO.SYS;C:\WINDOWS\system32\drivers\CTEDSPIO.SYS [2008-03-20 17:38] R3 CTEDSPSY.SYS;CTEDSPSY.SYS;C:\WINDOWS\system32\drivers\CTEDSPSY.SYS [2008-03-20 17:37] R3 PRISM_USB;Dell TrueMobile 1180 Wireless USB Adapter;C:\WINDOWS\system32\DRIVERS\DELUSB_51.sys [2002-08-09 15:46] S3 COMMONFX;COMMONFX;C:\WINDOWS\system32\drivers\COMMONFX.SYS [2008-03-20 17:23] S3 CT20XUT.SYS;CT20XUT.SYS;C:\WINDOWS\system32\drivers\CT20XUT.SYS [2008-03-20 17:36] S3 CT20XUT;CT20XUT;C:\WINDOWS\system32\drivers\CT20XUT.SYS [2008-03-20 17:36] S3 CTAUDFX.SYS;CTAUDFX.SYS;C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2008-03-20 17:23] S3 CTAUDFX;CTAUDFX;C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2008-03-20 17:23] S3 CTEAPSFX.SYS;CTEAPSFX.SYS;C:\WINDOWS\system32\drivers\CTEAPSFX.SYS [2008-03-20 17:26] S3 CTEAPSFX;CTEAPSFX;C:\WINDOWS\system32\drivers\CTEAPSFX.SYS [2008-03-20 17:26] S3 CTEDSPFX;CTEDSPFX;C:\WINDOWS\system32\drivers\CTEDSPFX.SYS [2008-03-20 17:32] S3 CTEDSPIO;CTEDSPIO;C:\WINDOWS\system32\drivers\CTEDSPIO.SYS [2008-03-20 17:38] S3 CTEDSPSY;CTEDSPSY;C:\WINDOWS\system32\drivers\CTEDSPSY.SYS [2008-03-20 17:37] S3 CTERFXFX.SYS;CTERFXFX.SYS;C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2008-03-20 17:36] S3 CTERFXFX;CTERFXFX;C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2008-03-20 17:36] S3 CTEXFIFX.SYS;CTEXFIFX.SYS;C:\WINDOWS\system32\drivers\CTEXFIFX.SYS [2008-03-20 17:40] S3 CTEXFIFX;CTEXFIFX;C:\WINDOWS\system32\drivers\CTEXFIFX.SYS [2008-03-20 17:40] S3 CTHWIUT.SYS;CTHWIUT.SYS;C:\WINDOWS\system32\drivers\CTHWIUT.SYS [2008-03-20 17:37] S3 CTHWIUT;CTHWIUT;C:\WINDOWS\system32\drivers\CTHWIUT.SYS [2008-03-20 17:37] S3 CTSBLFX.SYS;CTSBLFX.SYS;C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2008-03-20 17:25] S3 CTSBLFX;CTSBLFX;C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2008-03-20 17:25] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F] \Shell\AutoRun\command - F:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7dbe02d0-6a35-11dc-be2b-00904b2bc814}] \Shell\AutoRun\command - ie.exe \Shell\explore\Command - ie.exe \Shell\open\Command - ie.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc69911f-934e-11dc-be2d-00904b2bc814}] \Shell\AutoRun\command - F:\setupSNK.exe . Contents of the 'Scheduled Tasks' folder "2008-06-04 00:19:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-06 12:57:30 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\explorer.exe -> C:\PROGRA~1\Google\GOOGLE~1\GOA66E~1.DLL . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\MICROS~3\rapimgr.exe C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe C:\WINDOWS\system32\wscntfy.exe . ************************************************************************** . Completion time: 2008-06-06 13:03:18 - machine was rebooted [Chung] ComboFix-quarantined-files.txt 2008-06-06 20:02:56 ComboFix2.txt 2008-06-05 17:49:48 ComboFix3.txt 2008-06-05 07:16:19 ComboFix4.txt 2008-06-05 06:55:59 ComboFix5.txt 2008-06-04 18:23:28 Pre-Run: 26,034,200,576 bytes free Post-Run: 26,020,372,480 bytes free 282 --- E O F --- 2008-05-30 01:55:36 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:10:19 PM, on 2008-06-06 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\CTHELPER.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\PROGRA~1\MICROS~3\rapimgr.exe C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O2 - BHO: (no name) - {80539493-39F8-4EED-9C95-6F7644E3136A} - C:\WINDOWS\system32\khfDvuTm.dll (file missing) O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} - http://iebar.t2t2.com/iebar.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- End of file - 6862 bytes |
|
|
|
|
#9 (permalink) | |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,549
OS: WinXP and Vista
|
Re: Pulling my hair out.
Much better.
![]() Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions. Also be sure to carry out the instructions in the sequence listed below. *************************************************** Using 'My Computer', navigate to and delete the following File (Right click and select 'Delete'): C:\WINDOWS\BM333ca40b.xml -------------------------------------------------------------------- Go to Start->Run and type in regedit and hit OK. Open notepad and copy/paste the entire text in the quote box below: (don't forget to copy and paste REGEDIT4) Quote:
Save the file as "delete.reg". Make sure to save it with the quotes. Choose to "Save type as - All Files" It should look like this: ![]() Double click on the delete.reg file and choose Yes to merge/add it to the registry. You may delete the file afterwards. -------------------------------------------------------------------- It's important to run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course: Using Internet Explorer, visit http://www.kaspersky.com/kos/eng/par...avwebscan.html Answer Yes, when prompted to install an ActiveX component.
**Note** To optimize scanning time and produce a more sensible report for review:
--------------------------------------------------------------- Run a new scan with dss.exe. --------------------------------------------------------------- Please include the following in your next reply: Kaspersky results New main.txt Update on system behavior |
|
|
|
|
|
#10 (permalink) |
|
Registered User
Join Date: Jun 2008
Posts: 7
OS: XP
|
Re: Pulling my hair out.
So far, everything seems to be running smoothly like it used to be before this virus. I appreciate all your help :)
Deckard's System Scanner v20071014.68 Run by Chung on 2008-06-07 09:54:07 Computer is in Normal Mode. -------------------------------------------------------------------------------- System Drive C: has 24.13 GiB (less than 15%) free. -- HijackThis (run as Chung.exe) ----------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:54:15 AM, on 2008-06-07 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\CTHELPER.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\PROGRA~1\MICROS~3\rapimgr.exe C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\explorer.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\AIM\aim.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Chung\My Documents\dss.exe C:\DOCUME~1\Chung\MYDOCU~1\download\FREEKN~1\HIJACK~1\Chung.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {56A7DC70-E102-4408-A34A-AE06FEF01586} - http://iebar.t2t2.com/iebar.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- End of file - 6919 bytes -- Files created between 2008-05-07 and 2008-06-07 ----------------------------- 2008-06-06 23:57:44 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2008-06-06 23:57:43 0 d-------- C:\WINDOWS\system32\Kaspersky Lab 2008-06-06 23:57:42 0 d-------- C:\WINDOWS\LastGood 2008-06-05 10:30:21 0 d-------- C:\cmdcons 2008-06-05 10:27:09 68096 --a------ C:\WINDOWS\zip.exe 2008-06-05 10:27:09 49152 --a------ C:\WINDOWS\VFind.exe 2008-06-05 10:27:09 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists> 2008-06-05 10:27:09 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller> 2008-06-05 10:27:09 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor> 2008-06-05 10:27:09 98816 --a------ C:\WINDOWS\sed.exe 2008-06-05 10:27:09 80412 --a------ C:\WINDOWS\grep.exe 2008-06-05 10:27:09 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; > 2008-06-05 00:32:44 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion 2008-06-04 22:45:34 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla 2008-06-04 22:22:56 0 dr-h----- C:\Documents and Settings\Administrator\Recent 2008-06-04 22:14:23 0 d-------- C:\Program Files\CCleaner 2008-06-04 18:27:24 86016 --a------ C:\WINDOWS\system32\cttele.dll <Not Verified; Creative Technology Ltd; Creative Common Proxy Stud> 2008-06-04 18:19:17 2560 --a------ C:\WINDOWS\CTXFIRES.DLL <Not Verified; ; CTxfiRes Dynamic Link Library> 2008-06-04 18:12:57 0 d-------- C:\Program Files\Panda Security 2008-06-04 10:49:16 0 d-------- C:\Documents and Settings\Administrator\Application Data\Simply Super Software <SIMPLY~1> 2008-06-03 21:27:38 0 d-------- C:\Program Files\Lavasoft 2008-06-03 21:27:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-06-03 21:14:11 153088 --a------ C:\WINDOWS\system32\UNRAR3.dll 2008-06-03 21:14:11 75264 --a------ C:\WINDOWS\system32\unacev2.dll 2008-06-03 21:14:08 0 d-------- C:\Program Files\Trojan Remover 2008-06-03 21:14:08 0 d-------- C:\Documents and Settings\Chung\Application Data\Simply Super Software <SIMPLY~1> 2008-06-03 14:14:43 0 d-------- C:\Documents and Settings\Chung\Application Data\HouseCall 6.6 2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\Templates 2008-06-03 11:22:45 0 dr------- C:\Documents and Settings\Administrator\Start Menu 2008-06-03 11:22:45 0 dr-h----- C:\Documents and Settings\Administrator\SendTo 2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\PrintHood 2008-06-03 11:22:45 2359296 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT 2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\NetHood 2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\My Documents 2008-06-03 11:22:45 0 d--h----- C:\Documents and Settings\Administrator\Local Settings 2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\Favorites 2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\Desktop 2008-06-03 11:22:45 0 d--hs---- C:\Documents and Settings\Administrator\Cookies 2008-06-03 11:22:45 0 dr-h----- C:\Documents and Settings\Administrator\Application Data 2008-06-03 11:22:45 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft 2008-06-03 11:22:45 0 d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer 2008-06-03 11:22:33 0 d-------- C:\WINDOWS\CSC 2008-06-03 11:09:20 0 d-------- C:\Documents and Settings\LocalService\Application Data\Macromedia 2008-06-03 10:56:29 0 dr------- C:\Documents and Settings\LocalService\Favorites 2008-06-03 03:24:20 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP 2008-06-03 03:23:05 0 d-------- C:\Program Files\Spyware Doctor 2008-06-01 18:45:23 76166 --a------ C:\WINDOWS\War3Unin.dat 2008-06-01 18:45:22 2829 --a------ C:\WINDOWS\War3Unin.pif 2008-06-01 18:45:22 139264 --a------ C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller> 2008-05-29 15:10:07 0 d-------- C:\Program Files\iPod 2008-05-29 15:09:45 0 d-------- C:\Program Files\iTunes 2008-05-15 01:49:26 0 d-------- C:\Documents and Settings\All Users\Application Data\media center programs 2008-05-14 22:14:13 0 d-------- C:\Program Files\Funcom 2008-05-14 21:33:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Funcom 2008-05-11 20:21:08 0 d-------- C:\Documents and Settings\Chung\Application Data\SystemRequirementsLab 2008-05-11 20:11:47 0 d-------- C:\WINDOWS\system32\Futuremark 2008-05-11 20:11:46 0 d-------- C:\Program Files\Common Files\Futuremark Shared 2008-05-11 20:11:36 0 d-------- C:\Documents and Settings\Chung\Application Data\InstallShield 2008-05-10 19:40:01 0 d-------- C:\Documents and Settings\Default User\Application Data\Apple Computer -- Find3M Report --------------------------------------------------------------- 2008-06-07 01:00:29 0 d-------- C:\Program Files\Symantec AntiVirus 2008-06-06 18:40:53 0 d-------- C:\Documents and Settings\Chung\Application Data\uTorrent 2008-06-06 16:40:07 0 d-------- C:\Program Files\Warcraft III 2008-06-04 18:27:53 0 d-------- C:\Program Files\Creative Professional 2008-06-04 18:23:19 409600 --a------ C:\WINDOWS\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32> 2008-06-04 18:23:19 114688 --a------ C:\WINDOWS\system32\OpenAL32.dll <Not Verified; Portions (C) Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL(TM) Library> 2008-06-04 18:14:29 0 d-------- C:\Program Files\Viewpoint 2008-06-03 21:26:36 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-06-03 21:21:45 0 d-------- C:\Program Files\Google 2008-06-03 11:19:43 0 d-------- C:\Program Files\Common Files 2008-06-02 22:32:45 0 d-------- C:\Documents and Settings\Chung\Application Data\Adobe 2008-06-02 21:03:07 0 d-------- C:\Program Files\Common Files\Adobe 2008-06-01 17:20:12 0 d-------- C:\Program Files\Apple Software Update 2008-05-29 15:05:53 0 d-------- C:\Program Files\QuickTime 2008-05-22 22:51:17 0 d-------- C:\Program Files\World of Warcraft 2008-05-18 14:14:05 0 d-------- C:\Program Files\mIRC 2008-05-15 23:28:24 0 d-------- C:\Program Files\Common Files\AOL 2008-05-15 23:28:24 0 d-------- C:\Program Files\AIM 2008-05-11 20:11:44 0 d--h----- C:\Program Files\InstallShield Installation Information 2008-05-01 01:40:43 0 d-------- C:\Program Files\AIM6 2008-04-12 08:19:24 0 d-------- C:\Program Files\Anti Keylogger Shield 2008-03-20 15:36:48 43520 --a------ C:\WINDOWS\system32\CTBurst.dll <Not Verified; ; CTBurst Module> 2008-03-20 15:35:52 34816 --a------ C:\WINDOWS\system32\a3d.dll <Not Verified; ; a3dx5> 2008-03-20 15:35:38 27648 --a------ C:\WINDOWS\system32\ac3api.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:35:14 41472 --a------ C:\WINDOWS\system32\CTxfiBtn.dll <Not Verified; Creative Technology Ltd; CTXFIBTN Dynamic Link Library> 2008-03-20 15:35:10 40960 --a------ C:\WINDOWS\system32\CTxfiSpk.dll <Not Verified; Creative Technology Ltd; Ctxfispk Dynamic Link Library> 2008-03-20 15:35:10 23552 --a------ C:\WINDOWS\system32\Ctxfihlp.exe <Not Verified; Creative Technology Ltd; CTXfiHlp Application> 2008-03-20 15:35:06 41472 --a------ C:\WINDOWS\system32\psconv.exe 2008-03-20 15:35:04 23040 --a------ C:\WINDOWS\system32\CtHelper.exe <Not Verified; Creative Technology Ltd; CtHelper Application> 2008-03-20 15:35:02 12800 --a------ C:\WINDOWS\system32\CTAGENT.DLL <Not Verified; Creative Technology Ltd; ctagent> 2008-03-20 15:35:00 38912 --a------ C:\WINDOWS\system32\CTSPKHLP.DLL <Not Verified; Creative Technology Ltd; CtSpkHlp Dynamic Link Library> 2008-03-20 15:34:58 51200 --a------ C:\WINDOWS\system32\CTpcmcia.dll <Not Verified; Creative Technology Ltd; CTPCMCIA Dynamic Link Library> 2008-03-20 15:34:58 17920 --a------ C:\WINDOWS\system32\ctmmep.dll <Not Verified; Creative Technology Ltd; Ctmmep Dynamic Link Library> 2008-03-20 15:34:50 36864 --a------ C:\WINDOWS\system32\ctthxcal.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:34:50 8704 --a------ C:\WINDOWS\system32\ctpres.dll <Not Verified; Creative Technology Ltd; CtPanel Resource> 2008-03-20 15:34:48 46592 --a------ C:\WINDOWS\system32\ctscal.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:34:46 145408 --a------ C:\WINDOWS\system32\CTDCIFCE.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:34:46 343040 --a------ C:\WINDOWS\system32\ctdc0001.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:34:44 10240 --a------ C:\WINDOWS\system32\ctdcres.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:34:44 230400 --a------ C:\WINDOWS\system32\ctdc0000.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:34:44 10240 --a------ C:\WINDOWS\CTDCRES.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:31:22 46592 --a------ C:\WINDOWS\system32\Ctxfireg.exe <Not Verified; Creative Technology Ltd; CTXFIREG> 2008-03-20 15:31:20 15360 --a------ C:\WINDOWS\system32\Ct20xspi.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:31:14 1119744 --a------ C:\WINDOWS\system32\CTxfispi.exe <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:25:22 46273 --a------ C:\WINDOWS\system32\ctdnlstr.dat 2008-03-20 15:25:22 325821 --a------ C:\WINDOWS\system32\ctdlang.dat 2008-03-20 15:24:54 114688 --a------ C:\WINDOWS\system32\ctemupia.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:50 22016 --a------ C:\WINDOWS\system32\ctedasio.dll <Not Verified; Creative Technology, Ltd; Creative Audio Product> 2008-03-20 15:22:48 50688 --a------ C:\WINDOWS\system32\ctasio.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:48 151040 --a------ C:\WINDOWS\system32\ct_oal.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:44 53248 --a------ C:\WINDOWS\system32\CTDPROXY.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:30 74240 --a------ C:\WINDOWS\system32\CTOSUSER.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:28 10240 --a------ C:\WINDOWS\system32\sfman32.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:26 108544 --a------ C:\WINDOWS\system32\SFMS32.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:22:24 16384 --a------ C:\WINDOWS\system32\regplib.exe 2008-03-20 15:22:22 68608 --a------ C:\WINDOWS\system32\PIAPROXY.DLL <Not Verified; Creative Technology Ltd; E-mu PIA> 2008-03-20 15:21:58 149838 --a------ C:\WINDOWS\system32\ctbas2w.dat 2008-03-20 15:20:12 274587 --a------ C:\WINDOWS\system32\ctsbas2w.dat 2008-03-20 15:20:02 115166 --a------ C:\WINDOWS\system32\CTBASICW.DAT 2008-03-20 15:20:00 241084 --a------ C:\WINDOWS\system32\CTSBASW.DAT 2008-03-20 15:19:44 313207 --a------ C:\WINDOWS\system32\ctstatic.dat 2008-03-20 15:19:44 53932 --a------ C:\WINDOWS\system32\ctdaught.dat 2008-03-20 15:19:42 7680 --a------ C:\WINDOWS\system32\enlocstr.exe 2008-03-20 15:19:40 12800 --a------ C:\WINDOWS\system32\killapps.exe <Not Verified; ; killapps> 2008-03-20 15:19:26 31232 --a------ C:\WINDOWS\system32\MIDIDEF.EXE <Not Verified; Creative Technology Ltd; Creative Audio Product> 2008-03-20 15:19:26 36864 --a------ C:\WINDOWS\system32\devreg.dll <Not Verified; Creative Technology Ltd; Creative Audio Product> -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 AM] "nwiz"="nwiz.exe" [2007-12-05 02:41 AM C:\WINDOWS\system32\nwiz.exe] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 08:26 PM] "vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 09:33 PM] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 02:41 AM] "CTHelper"="CTHELPER.EXE" [2008-03-20 03:35 PM C:\WINDOWS\system32\CtHelper.exe] "CTxfiHlp"="CTXFIHLP.EXE" [2008-03-20 03:35 PM C:\WINDOWS\system32\Ctxfihlp.exe] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:56 AM] "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 08:44 PM] "SetDefaultMIDI"="MIDIDef.exe" [2008-03-20 03:19 PM C:\WINDOWS\system32\MIDIDEF.EXE] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "DisableRegistryTools"=0 (0x0) "HideLegacyLogonScripts"=0 (0x0) "HideLogoffScripts"=0 (0x0) "RunLogonScriptSync"=1 (0x1) "RunStartupScriptSync"=0 (0x0) "HideStartupScripts"=0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "HideLegacyLogonScripts"=0 (0x0) "HideLogoffScripts"=0 (0x0) "RunLogonScriptSync"=1 (0x1) "RunStartupScriptSync"=0 (0x0) "HideStartupScripts"=0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] @="Volume shadow copy" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Chung^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk] path=C:\Documents and Settings\Chung\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares] "C:\Program Files\Ares\Ares.exe" -h [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F] AutoRun\command- F:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc69911f-934e-11dc-be2d-00904b2bc814}] AutoRun\command- F:\setupSNK.exe *Newly Created Service* - CATCHME -- End of Deckard's System Scanner: finished at 2008-06-07 09:54:41 ------------ ------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT 2008-06-07 9:52:41 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 7/06/2008 Kaspersky Anti-Virus database records: 836505 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 94935 Number of viruses found: 10 Number of infected objects: 81 Number of suspicious objects: 0 Duration of the scan process: 02:49:03 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01F00000\47FCD7F6.VBN/MagicApplet.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01F00000\47FCD7F6.VBN/OwnClassLoader.class Infected: Trojan.Java.ClassLoader.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01F00000\47FCD7F6.VBN/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01F00000\47FCD7F6.VBN ZIP: infected - 3 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01F00000\47FCD7F6.VBN CryptZ: infected - 3 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02100001.VBN/vmain.class Infected: Exploit.Java.Gimsh.b skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02100001.VBN ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02100001.VBN CryptZ: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0EF40000\4EFD62B5.VBN Infected: Trojan-Downloader.JS.Small.fh skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280000\4F6CBBC5.VBN Infected: Trojan.BAT.Regger.b skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280001\4F6CBC16.VBN Infected: Trojan.BAT.Regger.b skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280002\4F6CBC44.VBN Infected: Trojan.BAT.Regger.b skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280003\4F6CBC9A.VBN Infected: Trojan.BAT.Regger.b skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280004\4F6D153D.VBN/data0000 Infected: Backdoor.Win32.VB.brg skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280004\4F6D153D.VBN/data0001 Infected: Trojan-Downloader.Win32.Agent.bl skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280004\4F6D153D.VBN EmbeddedEXE: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280004\4F6D153D.VBN UPX: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280004\4F6D153D.VBN PE_Patch.UPX: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280004\4F6D153D.VBN CryptZ: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280005\4F6D1580.VBN/data0000 Infected: Backdoor.Win32.VB.brg skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280005\4F6D1580.VBN/data0001 Infected: Trojan-Downloader.Win32.Agent.bl skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280005\4F6D1580.VBN EmbeddedEXE: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280005\4F6D1580.VBN UPX: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280005\4F6D1580.VBN PE_Patch.UPX: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280005\4F6D1580.VBN CryptZ: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280006\4F6D15C5.VBN/data0000 Infected: Backdoor.Win32.VB.brg skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280006\4F6D15C5.VBN/data0001 Infected: Trojan-Downloader.Win32.Agent.bl skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280006\4F6D15C5.VBN EmbeddedEXE: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280006\4F6D15C5.VBN UPX: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280006\4F6D15C5.VBN PE_Patch.UPX: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280006\4F6D15C5.VBN CryptZ: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280007\4F6D161B.VBN/data0000 Infected: Backdoor.Win32.VB.brg skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280007\4F6D161B.VBN/data0001 Infected: Trojan-Downloader.Win32.Agent.bl skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280007\4F6D161B.VBN EmbeddedEXE: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280007\4F6D161B.VBN UPX: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280007\4F6D161B.VBN PE_Patch.UPX: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280007\4F6D161B.VBN CryptZ: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280008\4F6D1665.VBN/data0000 Infected: Backdoor.Win32.VB.brg skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280008\4F6D1665.VBN/data0001 Infected: Trojan-Downloader.Win32.Agent.bl skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280008\4F6D1665.VBN EmbeddedEXE: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280008\4F6D1665.VBN UPX: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280008\4F6D1665.VBN PE_Patch.UPX: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280008\4F6D1665.VBN CryptZ: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280009\4F6D1699.VBN/data0000 Infected: Backdoor.Win32.VB.brg skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280009\4F6D1699.VBN/data0001 Infected: Trojan-Downloader.Win32.Agent.bl skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280009\4F6D1699.VBN EmbeddedEXE: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280009\4F6D1699.VBN UPX: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280009\4F6D1699.VBN PE_Patch.UPX: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F280009\4F6D1699.VBN CryptZ: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F28000A\4F6D1ABB.VBN Infected: Backdoor.Win32.VB.brg skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F28000B\4F6D1B4F.VBN Infected: Backdoor.Win32.VB.brg skipped C:\Documents and Settings\Chung\Application Data\$_hpcst$.hpc Object is locked skipped C:\Documents and Settings\Chung\Application Data\Aim\freekniteshift\cert8.db Object is locked skipped C:\Documents and Settings\Chung\Application Data\Aim\freekniteshift\key3.db Object is locked skipped C:\Documents and Settings\Chung\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Chung\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Chung\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Chung\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Chung\Local Settings\temp\WCESLog.log Object is locked skipped C:\Documents and Settings\Chung\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Chung\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-000345-835.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-000448-409.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-000519-969.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-000535-128.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-002900-342.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-100212-243.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped C:\Documents and Settings\Chung\My Documents\download\freekniteshift\HiJackThis\backups\backup-20080605-100212-577.dll Infected: Trojan.Win32.Monder.gen skipped C:\Documents and Settings\Chung\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Chung\NTUSER.DAT.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped C:\Program Files\Symantec AntiVirus\SAVRT\0860NAV~.TMP Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0869NAV~.TMP Object is locked skipped C:\QooBox\Quarantine\C\WINDOWS\system32\cdolfjcs.dll.vir Infected: Trojan.Win32.Monder.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\lagrvrbj.dll.vir Infected: Trojan.Win32.Monder.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\mlJApqpp.dll.vir Infected: Trojan.Win32.Monder.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\mlJCRlkI.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped C:\QooBox\Quarantine\C\WINDOWS\system32\mrvotahb.dll.vir Infected: Trojan.Win32.Monder.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ssqQgHWP.dll.vir Infected: Trojan.Win32.Monder.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\wvUNFVom.dll.vir Infected: Trojan.Win32.Monder.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\xjswfffg.dll.vir Infected: Trojan.Win32.Monder.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\xxyvwvvt.dll.vir Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP10\A0000802.dll Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP10\A0000805.dll Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP10\A0000806.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.wwr skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP10\A0000807.dll Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP10\A0000809.dll Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP10\A0000810.dll Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP11\change.log Object is locked skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP2\A0000293.dll Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP2\A0000294.dll Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP2\A0000313.dll Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP2\A0000328.dll Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP2\A0000329.dll Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP2\A0000330.dll Infected: Trojan.Win32.Monder.gen skipped C:\System Volume Information\_restore{FAC7D46B-54C2-40F4-AFB1-1DBA3AB85AFF}\RP5\A0000429.dll Infected: Trojan.Win32.Monder.gen skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\LogFiles\HTTPERR\httperr1.log Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. |
|
|
|
|
#11 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,549
OS: WinXP and Vista
|
Re: Pulling my hair out.
Hi kniteshift,
Kaspersky is only reporting backups created during the course of this fix, and items located in C:\System Volume Information\, which is where System Restore's cache is stored. Whatever is in there can't harm you unless you choose to perform a manual restore. Nevertheless, we shall be resetting/clearing the cache shortly. Your logs are clean. If there aren't any more problems, please continue with these final instructions and helpful links: The following procedure will clear out the backups and quarantines created by the fix. It will also reset your System Restore by flushing out previous restore points (which contain the infections) and create a new restore point. Click Start > Run and copy/paste, or type the following bolded text into the Run box and click OK: ComboFix /u -------------------------------------------------------------------- To help protect your computer in the future I recommend that you get the following free programs if you do not already have them: McAfee Site Advisor--free version. The folks there check out websites and based on their findings, rate it as Safe, Unknown, Caution, or Bad. SpywareBlaster 4.0 to help prevent spyware from installing in the first place. Install & update SpywareBlaster with the latest definitions. After you have updated, click the button - enable protection for all unprotected items.
IESpyAD Zoned Out to block access to malicious websites so you cannot be redirected to them from an infected site or email. This severely impairs attempts to infect your system as it basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites. Update, and scan with your onboard Anti Malware and Anti Virus programs regularly. Without regular updates you will not be protected when new malicious programs are released. In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles: PC Safety and Security--What Do I Need? Think Prevention HOW DID I GET INFECTED IN THE FIRST PLACE? by Tony Klein MAKING INTERNET EXPLORER SAFER Understanding and Using Firewalls **Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. ----------------------------------------------------- Follow the list above and the potential for infection will reduce dramatically. **Kindly respond one more time and let me know if we may consider this thread resolved. |
|
|
| Thread Tools | |
|
|