![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 28
OS: xp
|
Cannot delete file AUTORUN.INF
DDS (Ver_09-09-29.01) - NTFSx86
Run by Herman Nehru at 19:56:05.95 on Sun 10/11/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1790.1180 [GMT -7:00] AV: Kaspersky Internet Security *On-access scanning enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *enabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe svchost.exe C:\WINDOWS\system32\fsproflt.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\TUProgSt.exe C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\USB Disk Security\USBGuard.exe C:\Program Files\My Lockbox\flockbox.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Internet Download Manager\IEMonitor.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\DOCUME~1\HERMAN~1\LOCALS~1\Temp\RtkBtMnt.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Documents and Settings\Herman Nehru\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.co.id/ mURLSearchHooks: H - No File BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: CDelHotkeys Object: {78875f5c-a685-4405-8dc5-d48dc65452b0} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll BHO: Cooliris Plug-In for Internet Explorer: {eaee5c74-6d0d-4aca-9232-0da4a7b866ba} - c:\program files\piclensie\cooliris.dll BHO: Ask Toolbar BHO: {f4d76f01-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL TB: Delicious Toolbar: {61d1c847-df80-423a-8c6d-dc03b97e6ebe} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll TB: Ask Toolbar: {f4d76f09-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File EB: Delicious Sidebar: {9d19c405-ba93-461b-871f-97992cc45972} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [AzMixerSel] c:\program files\realtek\audio\installshield\AzMixerSel.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [USB Antivirus] c:\program files\usb disk security\USBGuard.exe mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe" mRun: [flockbox] c:\program files\my lockbox\flockbox.exe /a StartupFolder: c:\docume~1\herman~1\startm~1\programs\startup\stardock objectdock.lnk - c:\program files\stardock\objectdock\ObjectDock.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe mPolicies-explorer: <NO NAME> = mPolicies-explorer: NoStartMenuMyMusic = 0 (0x0) mPolicies-explorer: NoSMMyPictures = 0 (0x0) mPolicies-explorer: NoWindowsUpdate = 0 (0x0) mPolicies-explorer: NoViewOnDrive = 0 (0x0) mPolicies-system: <NO NAME> = mPolicies-system: HideFastUserSwitching = 0 (0x0) IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2010\ie_banner_deny.htm IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm IE: Download with IDM - c:\program files\internet download manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {2C887991-08F0-11DC-A9B2-0012F0B227DD} - {B8D8B1D0-83AF-451B-8CD9-8F1BF4ED8FEA} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll IE: {2C887992-08F0-11DC-A9B2-0012F0B227DD} - {9D19C405-BA93-461b-871F-97992CC45972} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll IE: {2C887993-08F0-11DC-A9B2-0012F0B227DD} - {4D3D441F-9543-4941-B664-2EDCF9FC1B56} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - c:\program files\piclensie\cooliris.dll IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/V6/V5Controls/en/x86/client/wuweb_site.cab?1247595412296 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1248583003125 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: klogon - c:\windows\system32\klogon.dll Notify: MCPClient - c:\progra~1\common~1\stardock\mcpstub.dll AppInit_DLLs: c:\progra~1\kaspersky lab\kaspersky internet security 2010\mzvkbd.dll,c:\progra~1\kaspersky lab\kaspersky internet security 2010\mzvkbd3.dll,c:\progra~1\kaspersky lab\kaspersky internet security 2010\kloehk.dll SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~1\common~1\stardock\MCPCore.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\herman~1\applic~1\mozilla\firefox\profiles\nk4rik1i.default\ FF - prefs.js: keyword.URL - hxxp://ide.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_ide&p= FF - component: c:\documents and settings\herman nehru\application data\idm\idmmzcc3\components\idmmzcc.dll FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll FF - plugin: c:\documents and settings\herman nehru\application data\mozilla\firefox\profiles\nk4rik1i.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\np_gp.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\NPOFF12.DLL FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\nppl3260.dll FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\nprpjplug.dll FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\npyaxmpb.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ ---- FIREFOX POLICIES ---- FF - user.js: network.http.max-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 750 FF - user.js: content.notify.interval - 750000 FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [2009-8-19 43792] R0 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2009-5-24 128016] R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-12-15 33808] R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [2009-10-4 17264] R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2009-9-30 296976] R2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe [2009-5-25 303376] R2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [2009-8-19 73392] R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-8-10 603904] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-5-16 19472] R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [2009-7-11 154624] S2 PCMAVRTPService;PCMAV RealTime Protector Service;c:\windows\system32\rtpsvc.exe --> c:\windows\system32\RTPSvc.exe [?] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2009-7-13 36608] S3 getPlusHelper;getPlus(R) Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-3 14336] S3 NTProcDrv;Process creation detector for NT.;\??\c:\windows\temp\drv1.tmp --> c:\windows\temp\drv1.tmp [?] S3 plkusbser;PROLiNKU6 USB Device for Legacy Serial Communication;c:\windows\system32\drivers\plkusbser.sys [2009-7-11 99456] =============== Created Last 30 ================ 2009-10-10 15:19 <DIR> --d----- c:\docume~1\herman~1\applic~1\The Labyrinth Plus! Edition 2009-10-10 15:19 0 a------- c:\windows\RussSqr.INI 2009-10-10 09:49 <DIR> --d----- c:\program files\Microsoft Plus! 2009-10-07 19:55 68 a------- c:\windows\MyProg.ini 2009-10-06 16:53 <DIR> --d----- c:\program files\AskPBar 2009-10-06 16:00 <DIR> --d----- c:\program files\Raxco 2009-10-04 22:14 <DIR> --d----- c:\program files\FreeCommander 2009-10-04 21:50 17,264 a------- c:\windows\system32\drivers\mprifl.sys 2009-10-04 21:50 <DIR> --d----- c:\program files\My Lockbox 2009-10-04 19:03 41,984 a------- c:\windows\system32\dwlGina3.dll 2009-10-04 19:03 3,712 a------- c:\windows\system32\dwlkbf.sys 2009-10-04 19:03 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Deskman9 2009-10-03 23:51 <DIR> --d----- c:\docume~1\herman~1\applic~1\Thinstall 2009-10-03 20:26 387,104 a--sh--- c:\windows\system32\drivers\fidbox.dat 2009-10-03 20:26 5,612 a--sh--- c:\windows\system32\drivers\fidbox.idx 2009-10-03 20:23 148,496 a------- c:\windows\system32\drivers\86909831.sys 2009-10-03 20:06 <DIR> --d----- c:\program files\Vista Start Menu 2009-09-30 23:53 604,140 a--sh--- c:\windows\system32\drivers\ISwift3.dat 2009-09-30 23:44 107,547 a------- c:\windows\system32\drivers\klin.dat 2009-09-30 23:44 95,259 a------- c:\windows\system32\drivers\klick.dat 2009-09-30 23:42 <DIR> --d----- c:\program files\Kaspersky Lab 2009-09-30 23:42 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Kaspersky Lab 2009-09-27 00:39 <DIR> --d----- c:\docume~1\alluse~1\applic~1\The Skins Factory 2009-09-26 23:54 <DIR> --d----- c:\docume~1\herman~1\applic~1\Skinux 2009-09-20 21:53 152 a------- C:\streetflyter.sav 2009-09-19 17:42 <DIR> --d----- c:\program files\Avatar - Path of Zuko 2009-09-19 13:01 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Zbshareware Lab 2009-09-19 13:01 <DIR> --d----- c:\program files\USB Disk Security 2009-09-19 12:38 <DIR> --d----- c:\docume~1\herman~1\applic~1\Merscom 2009-09-19 12:38 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Trymedia 2009-09-19 12:38 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Merscom 2009-09-16 05:26 210,352 a------- c:\windows\system32\idmmbc.dll 2009-09-15 15:55 <DIR> --d----- c:\docume~1\herman~1\applic~1\IDM 2009-09-15 15:54 <DIR> --d----- c:\program files\Internet Download Manager 2009-09-14 21:05 <DIR> --d----- c:\docume~1\herman~1\applic~1\360desktop 2009-09-13 17:56 <DIR> --d----- c:\docume~1\alluse~1\applic~1\McAfee Security Scan 2009-09-12 21:44 <DIR> --d----- c:\program files\Appwalk.com Technologies Canada 2009-09-11 23:35 <DIR> --d----- c:\program files\Youda Camper ==================== Find3M ==================== 2009-10-01 02:03 128,016 a------- c:\windows\system32\drivers\kl1.sys 2009-09-30 23:27 4,212 a---h--- c:\windows\system32\zllictbl.dat 2009-09-13 20:41 1,580,544 a------- c:\windows\system32\SfcFiles.dll 2009-09-13 20:40 219,648 a------- c:\windows\system32\uxtheme.dll 2009-09-07 23:28 288,256 a------- c:\windows\system32\fmodex.dll 2009-09-03 00:47 55,656 a------- c:\windows\system32\drivers\avgntflt.sys 2009-08-31 10:07 81,984 a------- c:\windows\system32\bdod.bin 2009-08-30 01:44 152,904 a------- c:\windows\system32\vghd.scr 2009-08-29 22:22 132 a------- C:\httpdwl.dat 2009-08-21 15:51 126,464 a------- c:\windows\system32\RTPScan.dll 2009-08-16 20:35 272,868 a------- c:\windows\system32\Windows XP Media Center Edition Screen Saver.scr 2009-08-14 19:23 25,600 a------- c:\windows\twunk_32.exe 2009-08-10 18:57 603,904 a------- c:\windows\system32\TUProgSt.exe 2009-08-10 18:57 362,240 a------- c:\windows\system32\TuneUpDefragService.exe 2009-08-06 12:38 13,537,280 a------- c:\windows\system32\nvcpl.dll 2009-08-06 11:29 69,120 a------- c:\windows\NOTEPAD.EXE 2009-08-05 02:11 204,800 a------- c:\windows\system32\mswebdvd.dll 2009-07-27 21:01 7,852 a------- c:\windows\system32\mcdmsg7.dll 2009-07-17 11:55 58,880 a------- c:\windows\system32\atl.dll 2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll 2009-03-16 14:35 525,128 a------- c:\program files\DXSETUP.exe 2009-03-16 14:35 94,024 a------- c:\program files\DSETUP.dll ============= FINISH: 19:56:58.46 =============== I tried to delete file AUTORUN.INF containing a strange subfolder named zhengbo which is unknown to me. After trying deleting it, a message pops up saying: Cannot delete zhengbo: Cannot find the specified file. Make sure you specify the correct path and file name. Actually I have 2 folders that I cannot delete. The other one has the same case when I delete it. I don't know whether it is a virus or trojan behaviour since my computer seems working fine. The folders are all located in drive d. I am using Windows XP SP2 AMD Turion X2. What should I do to this case? Need help. Thanks. |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Posts: 553
OS: N/A
|
Re: Cannot delete file AUTORUN.INF
Hello and welcome to TSF.
I Apologize for the late response. If you still require assistance, we would like to see the latest state of your system. So, please post a fresh DDS log and a new GMER log as described in this topic. In your reply, I would also like to know any symptoms you may still have and how your computer is running at the moment. Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe. Please note that the forum is very busy and if I don’t hear from you in three-five days this thread will be closed. With Regards, Extremeboy |
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 28
OS: xp
|
Cannot delete file AUTORUN.INF
Hello Extremeboy,
Thank you for your reply. Herewith I post a fresh DDS log and GMER log that I scan today at about 09.00 AM (Indonesia time). As you already noticed that I cannot delete the AUTORUN.INF folder and also other folder named 'zzzzz' (such annoying name). I have no idea whether it is a virus or trojan behaviour since my computer seems working fine. I have scanned it with my Kaspersky Internet Security 2010 with latest update and resulted in no infection. For your information, I've ever reinstalled my OS Windows XP SP2 due to failure to boot and the folders have already appeared in the previous installed OS. Once again, my computer is working well (to my knowledge, hope I am right), except the above matter (Folder AUTORUN.INF and zzzzz cannot be deleted) Best Regards, DDS (Ver_09-09-29.01) - NTFSx86 Run by Herman Nehru at 8:56:12.50 on Tue 10/13/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1790.1089 [GMT -7:00] AV: Kaspersky Internet Security *On-access scanning enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *enabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe svchost.exe C:\WINDOWS\system32\fsproflt.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\TUProgSt.exe C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\USB Disk Security\USBGuard.exe C:\Program Files\My Lockbox\flockbox.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\DOCUME~1\HERMAN~1\LOCALS~1\Temp\RtkBtMnt.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Internet Download Manager\IEMonitor.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Documents and Settings\Herman Nehru\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.co.id/ mURLSearchHooks: H - No File BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: CDelHotkeys Object: {78875f5c-a685-4405-8dc5-d48dc65452b0} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll BHO: Cooliris Plug-In for Internet Explorer: {eaee5c74-6d0d-4aca-9232-0da4a7b866ba} - c:\program files\piclensie\cooliris.dll BHO: Ask Toolbar BHO: {f4d76f01-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL TB: Delicious Toolbar: {61d1c847-df80-423a-8c6d-dc03b97e6ebe} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll TB: Ask Toolbar: {f4d76f09-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File EB: Delicious Sidebar: {9d19c405-ba93-461b-871f-97992cc45972} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [AzMixerSel] c:\program files\realtek\audio\installshield\AzMixerSel.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [USB Antivirus] c:\program files\usb disk security\USBGuard.exe mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe" mRun: [flockbox] c:\program files\my lockbox\flockbox.exe /a mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot StartupFolder: c:\docume~1\herman~1\startm~1\programs\startup\stardock objectdock.lnk - c:\program files\stardock\objectdock\ObjectDock.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe mPolicies-explorer: <NO NAME> = mPolicies-explorer: NoStartMenuMyMusic = 0 (0x0) mPolicies-explorer: NoSMMyPictures = 0 (0x0) mPolicies-explorer: NoWindowsUpdate = 0 (0x0) mPolicies-explorer: NoViewOnDrive = 0 (0x0) mPolicies-system: <NO NAME> = mPolicies-system: HideFastUserSwitching = 0 (0x0) IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2010\ie_banner_deny.htm IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm IE: Download with IDM - c:\program files\internet download manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {2C887991-08F0-11DC-A9B2-0012F0B227DD} - {B8D8B1D0-83AF-451B-8CD9-8F1BF4ED8FEA} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll IE: {2C887992-08F0-11DC-A9B2-0012F0B227DD} - {9D19C405-BA93-461b-871F-97992CC45972} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll IE: {2C887993-08F0-11DC-A9B2-0012F0B227DD} - {4D3D441F-9543-4941-B664-2EDCF9FC1B56} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - c:\program files\piclensie\cooliris.dll IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/V6/V5Controls/en/x86/client/wuweb_site.cab?1247595412296 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1248583003125 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: klogon - c:\windows\system32\klogon.dll Notify: MCPClient - c:\progra~1\common~1\stardock\mcpstub.dll AppInit_DLLs: c:\progra~1\kaspersky lab\kaspersky internet security 2010\mzvkbd.dll,c:\progra~1\kaspersky lab\kaspersky internet security 2010\mzvkbd3.dll,c:\progra~1\kaspersky lab\kaspersky internet security 2010\kloehk.dll SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~1\common~1\stardock\MCPCore.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\herman~1\applic~1\mozilla\firefox\profiles\nk4rik1i.default\ FF - prefs.js: keyword.URL - hxxp://ide.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_ide&p= FF - component: c:\documents and settings\herman nehru\application data\idm\idmmzcc3\components\idmmzcc.dll FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll FF - plugin: c:\documents and settings\herman nehru\application data\mozilla\firefox\profiles\nk4rik1i.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\np_gp.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\NPOFF12.DLL FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\nppl3260.dll FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\nprpjplug.dll FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\npyaxmpb.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ ---- FIREFOX POLICIES ---- FF - user.js: network.http.max-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 750 FF - user.js: content.notify.interval - 750000 FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [2009-8-19 43792] R0 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2009-5-24 128016] R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-12-15 33808] R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [2009-10-4 17264] R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2009-9-30 296976] R2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe [2009-5-25 303376] R2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [2009-8-19 73392] R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-8-10 603904] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-5-16 19472] R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [2009-7-11 154624] S2 PCMAVRTPService;PCMAV RealTime Protector Service;c:\windows\system32\rtpsvc.exe --> c:\windows\system32\RTPSvc.exe [?] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2009-7-13 36608] S3 getPlusHelper;getPlus(R) Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-3 14336] S3 NTProcDrv;Process creation detector for NT.;\??\c:\windows\temp\drv1.tmp --> c:\windows\temp\drv1.tmp [?] S3 plkusbser;PROLiNKU6 USB Device for Legacy Serial Communication;c:\windows\system32\drivers\plkusbser.sys [2009-7-11 99456] =============== Created Last 30 ================ 2009-10-13 08:28 <DIR> --d----- c:\docume~1\herman~1\applic~1\WinPatrol 2009-10-13 08:28 <DIR> --d----- c:\program files\BillP Studios 2009-10-12 00:06 <DIR> --d----- c:\program files\PowerISO 2009-10-11 23:18 <DIR> --dsh--- C:\[Smad-Cage] 2009-10-10 15:19 <DIR> --d----- c:\docume~1\herman~1\applic~1\The Labyrinth Plus! Edition 2009-10-10 15:19 0 a------- c:\windows\RussSqr.INI 2009-10-10 09:49 <DIR> --d----- c:\program files\Microsoft Plus! 2009-10-07 19:55 68 a------- c:\windows\MyProg.ini 2009-10-06 16:53 <DIR> --d----- c:\program files\AskPBar 2009-10-06 16:00 <DIR> --d----- c:\program files\Raxco 2009-10-04 22:14 <DIR> --d----- c:\program files\FreeCommander 2009-10-04 21:50 17,264 a------- c:\windows\system32\drivers\mprifl.sys 2009-10-04 21:50 <DIR> --d----- c:\program files\My Lockbox 2009-10-04 19:03 41,984 a------- c:\windows\system32\dwlGina3.dll 2009-10-04 19:03 3,712 a------- c:\windows\system32\dwlkbf.sys 2009-10-04 19:03 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Deskman9 2009-10-03 23:51 <DIR> --d----- c:\docume~1\herman~1\applic~1\Thinstall 2009-10-03 20:26 387,104 a--sh--- c:\windows\system32\drivers\fidbox.dat 2009-10-03 20:26 5,612 a--sh--- c:\windows\system32\drivers\fidbox.idx 2009-10-03 20:23 148,496 a------- c:\windows\system32\drivers\86909831.sys 2009-10-03 20:06 <DIR> --d----- c:\program files\Vista Start Menu 2009-09-30 23:53 604,140 a--sh--- c:\windows\system32\drivers\ISwift3.dat 2009-09-30 23:44 107,547 a------- c:\windows\system32\drivers\klin.dat 2009-09-30 23:44 95,259 a------- c:\windows\system32\drivers\klick.dat 2009-09-30 23:42 <DIR> --d----- c:\program files\Kaspersky Lab 2009-09-30 23:42 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Kaspersky Lab 2009-09-27 00:39 <DIR> --d----- c:\docume~1\alluse~1\applic~1\The Skins Factory 2009-09-26 23:54 <DIR> --d----- c:\docume~1\herman~1\applic~1\Skinux 2009-09-20 21:53 152 a------- C:\streetflyter.sav 2009-09-19 17:42 <DIR> --d----- c:\program files\Avatar - Path of Zuko 2009-09-19 13:01 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Zbshareware Lab 2009-09-19 13:01 <DIR> --d----- c:\program files\USB Disk Security 2009-09-19 12:38 <DIR> --d----- c:\docume~1\herman~1\applic~1\Merscom 2009-09-19 12:38 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Trymedia 2009-09-19 12:38 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Merscom 2009-09-16 05:26 210,352 a------- c:\windows\system32\idmmbc.dll 2009-09-15 15:55 <DIR> --d----- c:\docume~1\herman~1\applic~1\IDM 2009-09-15 15:54 <DIR> --d----- c:\program files\Internet Download Manager 2009-09-14 21:05 <DIR> --d----- c:\docume~1\herman~1\applic~1\360desktop 2009-09-13 17:56 <DIR> --d----- c:\docume~1\alluse~1\applic~1\McAfee Security Scan ==================== Find3M ==================== 2009-10-01 02:03 128,016 a------- c:\windows\system32\drivers\kl1.sys 2009-09-30 23:27 4,212 a---h--- c:\windows\system32\zllictbl.dat 2009-09-13 20:41 1,580,544 a------- c:\windows\system32\SfcFiles.dll 2009-09-13 20:40 219,648 a------- c:\windows\system32\uxtheme.dll 2009-09-07 23:28 288,256 a------- c:\windows\system32\fmodex.dll 2009-09-03 00:47 55,656 a------- c:\windows\system32\drivers\avgntflt.sys 2009-08-31 10:07 81,984 a------- c:\windows\system32\bdod.bin 2009-08-30 01:44 152,904 a------- c:\windows\system32\vghd.scr 2009-08-29 22:22 132 a------- C:\httpdwl.dat 2009-08-21 15:51 126,464 a------- c:\windows\system32\RTPScan.dll 2009-08-16 20:35 272,868 a------- c:\windows\system32\Windows XP Media Center Edition Screen Saver.scr 2009-08-14 19:23 25,600 a------- c:\windows\twunk_32.exe 2009-08-10 18:57 603,904 a------- c:\windows\system32\TUProgSt.exe 2009-08-10 18:57 362,240 a------- c:\windows\system32\TuneUpDefragService.exe 2009-08-06 12:38 13,537,280 a------- c:\windows\system32\nvcpl.dll 2009-08-06 11:29 69,120 a------- c:\windows\NOTEPAD.EXE 2009-08-05 02:11 204,800 a------- c:\windows\system32\mswebdvd.dll 2009-07-27 21:01 7,852 a------- c:\windows\system32\mcdmsg7.dll 2009-07-17 11:55 58,880 a------- c:\windows\system32\atl.dll 2009-03-16 14:35 525,128 a------- c:\program files\DXSETUP.exe 2009-03-16 14:35 94,024 a------- c:\program files\DSETUP.dll ============= FINISH: 8:57:10.21 =============== |
|
|
|
|
#4 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,802
OS: 2000 Pro; XP Pro; XP Home
|
Re: Cannot delete file AUTORUN.INF
Hello, rappokalling -
I believe these logs belong in this topic. I've merged it into this thread. I'm replying only so Extremeboy receives a notification, so he can begin to assist. Please be patient, as there are of course time zones to consider. Please bookmark this topic, and reply here to all requests from Extremeboy. Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe. Back to you, EB!
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#5 (permalink) | |
|
Analyst, Security Team
Join Date: Jan 2009
Posts: 553
OS: N/A
|
Re: Cannot delete file AUTORUN.INF
Thank you TetonBob. I didn't realize this post was posted elsewhere or moved back. Thanks for giving me a bump. :)
-- Sorry for the delay. Let's continue. Thanks for the explanation of the current condition of your system. Quote:
-- We'll start with Combofix followed by flash-drive disinfector. Note, that Flash-drive disinfector will create a hidden autorun.inf folder to prevent future autorun.inf worms or infections related to that. We'll see if that autorun folder is still there afterwards and deal with that. Please visit this webpage for instructions for downloading and running ComboFix: http://www.bleepingcomputer.com/comb...o-use-combofix * Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page on instructions on doing so. Please include the C:\ComboFix.txt in your next reply for further review. Download and Run FlashDisinfector
Thanks. ~Extremeboy |
|
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 28
OS: xp
|
Re: Cannot delete file AUTORUN.INF
Hello Extremeboy and thank you Totenbob for helping me as well,
Extremeboy, the folder zzzzz is located in drive D along with folder AUTORUN.INF, and yes I ever created a folder named zzzzz, but I don,t remember if it is a 'rename' or 'create new' folder and what was inside the folder I stored. As far as I remember it was made last year (previous installed OS (Windows XP SP2)). Now this hidden folder appeared (after using command prompt) containing sub folder named 'zzzzzz.zzz' which contains an icon ( a picture of Paint tool). All of them cannot be deleted. Best Regards, Here is the result of scan by combofix: ComboFix 09-10-14.08 - Herman Nehru 10/15/2009 14:36.1.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1790.1354 [GMT -7:00] Running from: c:\documents and settings\Herman Nehru\Desktop\ComboFix.exe AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Herman Nehru\Application Data\.# c:\documents and settings\Herman Nehru\Application Data\.#\MBX@594@3737C8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@594@3737D8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@594@3737E8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@81C@3737C8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@81C@3737D8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@81C@3737E8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@BC4@3737C8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@BC4@3737D8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@BC4@3737E8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@C14@3737C8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@C14@3737D8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@C14@3737E8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@C78@3737C8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@C78@3737D8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@C78@3737E8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@D30@3737C8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@D30@3737D8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@D30@3737E8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@D90@3737C8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@D90@3737D8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@D90@3737E8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@E04@3737C8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@E04@3737D8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@E04@3737E8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@E30@3737C8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@E30@3737D8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@E30@3737E8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@EC8@3737C8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@EC8@3737D8.### c:\documents and settings\Herman Nehru\Application Data\.#\MBX@EC8@3737E8.### c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013 c:\recycler\S-1-5-21-2052111302-1425521274-725345543-1003 c:\windows\Installer\13996d4.msp c:\windows\system32\Desktop_.ini c:\windows\system32\logs Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected Restored copy from - Kitty ate it :^) . ((((((((((((((((((((((((( Files Created from 2009-09-15 to 2009-10-15 ))))))))))))))))))))))))))))))) . 2009-10-14 18:15 . 2009-10-14 19:42 -------- d-----w- c:\program files\Real Desktop 2009-10-13 20:52 . 2009-10-13 20:52 -------- d-----w- c:\documents and settings\Herman Nehru\1st Security Agent 2009-10-13 20:52 . 2009-10-13 20:52 -------- d-----w- c:\documents and settings\Guest\1st Security Agent 2009-10-13 20:52 . 2009-10-13 20:52 -------- d-----w- c:\documents and settings\Administrator\1st Security Agent 2009-10-13 20:52 . 2009-10-13 20:52 -------- d-----w- C:\1st Security Agent 2009-10-13 20:52 . 2009-10-13 20:52 -------- d-----w- c:\program files\1st Security Agent 2009-10-13 19:05 . 2009-10-13 20:04 -------- d-----w- c:\program files\HÑÑ 2009-10-13 15:28 . 2009-10-13 15:28 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\WinPatrol 2009-10-13 15:28 . 2009-10-13 15:28 -------- d-----w- c:\program files\BillP Studios 2009-10-12 07:06 . 2009-10-12 07:06 -------- d-----w- c:\program files\PowerISO 2009-10-12 06:18 . 2009-10-12 06:18 -------- d-----w- C:\[Smad-Cage] 2009-10-11 18:02 . 2009-10-11 18:02 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2009-10-10 22:48 . 2009-10-10 22:48 -------- d-----w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\WMTools Downloaded Files 2009-10-10 22:19 . 2009-10-10 22:19 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\The Labyrinth Plus! Edition 2009-10-10 16:49 . 2009-10-10 16:49 -------- d-----w- c:\program files\Microsoft Plus! 2009-10-07 02:18 . 2009-10-07 02:18 -------- d-----w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\Google 2009-10-06 23:53 . 2009-10-06 23:53 -------- d-----w- c:\program files\AskPBar 2009-10-06 23:01 . 2009-10-06 23:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Raxco 2009-10-06 23:00 . 2009-10-06 23:01 -------- d-----w- c:\program files\Raxco 2009-10-05 05:14 . 2009-10-05 05:14 -------- d-----w- c:\program files\FreeCommander 2009-10-05 04:50 . 2007-12-14 03:13 17264 ----a-w- c:\windows\system32\drivers\mprifl.sys 2009-10-05 04:50 . 2009-10-05 04:50 -------- d-----w- c:\program files\My Lockbox 2009-10-05 02:03 . 2008-06-20 03:28 41984 ----a-w- c:\windows\system32\dwlGina3.dll 2009-10-05 02:03 . 2007-08-20 17:46 3712 ----a-w- c:\windows\system32\dwlkbf.sys 2009-10-05 02:03 . 2009-10-05 02:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Deskman9 2009-10-04 06:51 . 2009-10-04 06:51 -------- d-----w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\Thinstall 2009-10-04 06:51 . 2009-10-04 06:51 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Thinstall 2009-10-04 03:26 . 2009-10-04 03:31 387104 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-10-04 03:23 . 2008-07-08 21:54 148496 ----a-w- c:\windows\system32\drivers\86909831.sys 2009-10-04 03:06 . 2009-10-15 16:03 -------- d-----w- c:\program files\Vista Start Menu 2009-10-03 07:20 . 2009-10-03 07:20 -------- d-----w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\Opera 2009-10-03 07:19 . 2009-10-03 07:19 -------- d-----w- c:\program files\Opera 2009-10-01 06:53 . 2009-10-01 06:53 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat 2009-10-01 06:44 . 2009-10-15 16:02 108059 ----a-w- c:\windows\system32\drivers\klin.dat 2009-10-01 06:44 . 2009-10-15 16:02 95259 ----a-w- c:\windows\system32\drivers\klick.dat 2009-10-01 06:42 . 2009-10-15 20:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab 2009-10-01 06:42 . 2009-10-01 06:42 -------- d-----w- c:\program files\Kaspersky Lab 2009-09-27 07:39 . 2009-09-27 07:39 -------- d-----w- c:\documents and settings\All Users\Application Data\The Skins Factory 2009-09-27 06:54 . 2009-09-27 06:54 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Skinux 2009-09-27 06:45 . 2009-09-27 06:45 -------- d-----w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\Downloaded Installations 2009-09-20 00:42 . 2009-09-20 00:42 -------- d-----w- c:\program files\Avatar - Path of Zuko 2009-09-19 20:01 . 2009-09-19 20:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Zbshareware Lab 2009-09-19 20:01 . 2009-09-19 20:04 -------- d-----w- c:\program files\USB Disk Security 2009-09-19 19:38 . 2009-09-19 19:38 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Merscom 2009-09-19 19:38 . 2009-09-19 19:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Trymedia 2009-09-19 19:38 . 2009-09-19 19:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Merscom 2009-09-16 12:26 . 2009-09-09 10:43 210352 ----a-w- c:\windows\system32\idmmbc.dll 2009-09-15 22:55 . 2009-10-15 20:52 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\IDM 2009-09-15 22:54 . 2009-10-06 04:45 -------- d-----w- c:\program files\Internet Download Manager . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-15 20:52 . 2009-07-13 19:31 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\DMCache 2009-10-15 20:47 . 2009-07-11 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-10-13 23:42 . 2009-08-16 18:02 862136 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-10-13 19:14 . 2009-07-17 18:13 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Delicious IE Extension 2009-10-10 20:24 . 2009-07-12 03:17 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-10-10 17:23 . 2009-07-20 04:25 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\SoftMaker 2009-10-10 17:22 . 2009-07-19 19:21 -------- d-----w- c:\program files\Flock 2009-10-10 17:22 . 2009-07-19 19:21 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Flock 2009-10-08 02:52 . 2009-08-24 23:49 -------- d-----w- c:\program files\Styler 2009-10-08 02:51 . 2009-08-23 10:29 -------- d-----w- c:\program files\Gish 2009-10-08 02:50 . 2009-07-14 16:29 -------- d-----w- c:\program files\Mobile Partner 2009-10-04 03:31 . 2009-10-04 03:26 5612 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-10-04 01:10 . 2009-07-20 05:06 -------- d-----w- c:\program files\Windows Sidebar 2009-10-01 09:03 . 2009-05-24 22:30 128016 ----a-w- c:\windows\system32\drivers\kl1.sys 2009-10-01 06:38 . 2009-09-09 22:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files 2009-10-01 06:27 . 2009-08-18 22:13 4212 ---ha-w- c:\windows\system32\zllictbl.dat 2009-10-01 06:26 . 2009-09-03 05:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira 2009-09-28 06:44 . 2009-09-12 06:35 -------- d-----w- c:\program files\Youda Camper 2009-09-18 23:24 . 2009-08-08 20:38 -------- d-----w- c:\program files\Altysoft Free Video Converter 2009-09-15 04:51 . 2009-08-17 19:46 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-09-15 04:05 . 2009-09-15 04:05 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\360desktop 2009-09-14 03:41 . 2004-08-03 22:56 1580544 ----a-w- c:\windows\system32\SfcFiles.dll 2009-09-14 03:40 . 2004-08-03 22:56 219648 ----a-w- c:\windows\system32\uxtheme.dll 2009-09-14 01:17 . 2009-09-14 01:17 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2009-09-14 00:56 . 2009-09-14 00:52 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-09-14 00:56 . 2009-09-14 00:56 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan 2009-09-14 00:52 . 2009-09-14 00:52 -------- d-----w- c:\program files\NOS 2009-09-13 23:25 . 2009-08-02 16:47 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\PlayFirst 2009-09-13 23:25 . 2009-08-02 16:47 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst 2009-09-13 04:44 . 2009-09-13 04:44 -------- d-----w- c:\program files\Appwalk.com Technologies Canada 2009-09-12 15:44 . 2009-08-03 17:12 -------- d-----w- c:\program files\Microsoft Silverlight 2009-09-11 14:33 . 2004-08-03 22:56 133632 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-08 06:28 . 2009-09-08 06:28 288256 ----a-w- c:\windows\system32\fmodex.dll 2009-09-08 01:23 . 2009-09-08 01:21 -------- d-----w- c:\program files\Cheatbook Database 2009 2009-09-05 18:39 . 2009-09-05 18:39 -------- d-----w- c:\documents and settings\All Users\Application Data\PopCap Games 2009-09-05 18:39 . 2009-07-12 00:49 -------- d-----w- c:\program files\PopCap Games 2009-09-05 03:04 . 2009-09-04 18:15 -------- d-----w- c:\program files\Training Manager 2008 Enterprise 2009-09-05 02:55 . 2009-09-05 02:55 -------- d-----w- c:\documents and settings\Guest\Application Data\Windows Desktop Search 2009-09-04 22:13 . 2009-08-30 09:03 7 ----a-w- c:\windows\sbacknt.bin 2009-09-04 20:45 . 2004-08-03 22:56 58880 ----a-w- c:\windows\system32\msasn1.dll 2009-09-04 18:15 . 2009-09-04 18:15 -------- d-----w- c:\documents and settings\All Users\Application Data\TrainingManager 2009-09-03 21:59 . 2009-07-12 00:40 -------- d-----w- c:\program files\Tumblebugs 2 2009-09-03 07:47 . 2009-09-03 05:54 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-09-02 16:47 . 2009-09-02 16:24 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\CheckPoint 2009-09-01 23:25 . 2009-07-12 01:36 -------- d-----w- c:\program files\Mozilla Firefox 3.5 Beta 4 2009-09-01 06:21 . 2009-09-01 06:21 -------- d-----w- c:\program files\Alwil Software 2009-08-31 19:13 . 2009-07-12 00:22 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Ahead 2009-08-31 17:21 . 2009-08-31 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET 2009-08-31 17:09 . 2009-08-29 22:30 -------- d-----w- c:\program files\Common Files\BitDefender 2009-08-31 17:07 . 2009-08-30 05:21 81984 ----a-w- c:\windows\system32\bdod.bin 2009-08-31 01:19 . 2009-08-31 01:19 -------- d-----w- c:\program files\MSXML 4.0 2009-08-31 00:05 . 2009-08-30 08:44 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\vghd 2009-08-30 08:44 . 2009-08-30 08:34 152904 ----a-w- c:\windows\system32\vghd.scr 2009-08-30 05:22 . 2009-08-30 05:22 132 ----a-w- C:\httpdwl.dat 2009-08-30 05:07 . 2009-07-17 05:12 -------- d-----w- c:\documents and settings\All Users\Application Data\SecTaskMan 2009-08-26 08:16 . 2004-08-03 22:56 247326 ----a-w- c:\windows\system32\strmdll.dll 2009-08-25 00:08 . 2009-08-11 18:46 -------- d-----w- c:\program files\Common Files\Ulead Systems 2009-08-25 00:08 . 2009-08-11 18:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Ulead Systems 2009-08-24 23:54 . 2009-08-24 23:54 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Styler 2009-08-24 19:15 . 2009-08-24 16:25 -------- d-----w- c:\program files\LockHunter 2009-08-24 18:33 . 2009-08-24 18:33 -------- d-----w- c:\program files\Stardock 2009-08-24 16:25 . 2009-08-24 16:25 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\LockHunter 2009-08-22 16:03 . 2009-08-20 05:23 -------- d-----w- c:\program files\Hide Folders 2009 2009-08-21 22:51 . 2009-07-11 20:49 126464 ----a-w- c:\windows\system32\RTPScan.dll 2009-08-21 07:11 . 2009-08-08 22:57 -------- d-----w- c:\program files\Mozilla Thunderbird 2009-08-21 07:10 . 2009-07-27 02:28 -------- d-----w- c:\program files\DesktopCoral 2009-08-21 07:10 . 2009-07-20 01:22 -------- d-----w- c:\program files\Sidebar 2009-08-21 05:35 . 2009-07-11 22:59 76528 ----a-w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-08-19 22:13 . 2009-08-19 22:13 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Systweak 2009-08-19 22:13 . 2009-08-19 22:12 -------- d-----w- c:\program files\Advanced System Optimizer 2009-08-19 05:59 . 2009-08-19 05:54 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip 2009-08-19 04:46 . 2009-08-14 16:50 2119680 ----a-w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\cooliris-win-ie-release-1.11.2.27471.en-US.msi 2009-08-19 02:38 . 2009-08-17 06:06 10 ----a-w- c:\windows\popcinfo.dat 2009-08-18 06:33 . 2009-08-18 06:33 1193832 ----a-w- c:\windows\system32\FM20.DLL 2009-08-18 06:27 . 2009-08-18 06:27 -------- d-----w- c:\program files\Foxit Software 2009-08-18 05:57 . 2009-07-12 00:09 -------- d-----w- c:\program files\All Office Converter Platinum 2009-08-17 19:49 . 2009-08-17 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith 2009-08-17 19:48 . 2009-08-17 19:48 -------- d-----w- c:\program files\TechSmith 2009-08-17 03:35 . 2009-08-17 03:35 272868 ----a-w- c:\windows\system32\Windows XP Media Center Edition Screen Saver.scr 2009-08-15 02:23 . 2001-08-23 11:00 25600 ----a-w- c:\windows\twunk_32.exe 2009-08-11 01:57 . 2009-08-11 01:57 603904 ----a-w- c:\windows\system32\TUProgSt.exe 2009-08-11 01:57 . 2009-08-11 01:57 362240 ----a-w- c:\windows\system32\TuneUpDefragService.exe 2009-08-06 19:38 . 2008-05-29 11:41 13537280 ----a-w- c:\windows\system32\nvcpl.dll 2009-08-06 18:29 . 2009-07-11 14:58 69120 ----a-w- c:\windows\NOTEPAD.EXE 2009-08-05 09:11 . 2004-08-03 22:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-07-28 04:01 . 2009-07-28 04:01 7852 ----a-w- c:\windows\system32\mcdmsg7.dll 2009-07-27 02:43 . 2009-07-27 02:43 58908 ----a-w- c:\windows\system32\drivers\scdemu.sys 2009-07-27 02:32 . 2009-07-27 02:32 46 ----a-w- c:\windows\system32\DonationCoder_desktopcoral_InstallInfo.dat 2009-07-27 02:32 . 2009-07-27 02:32 46 ----a-w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\DonationCoder_desktopcoral_InstallInfo.dat 2009-07-25 21:27 . 2009-07-12 01:36 335 ----a-w- c:\windows\nsreg.dat 2009-03-16 21:35 . 2009-03-16 21:35 525128 ----a-w- c:\program files\DXSETUP.exe 2009-03-16 21:35 . 2009-03-16 21:35 94024 ----a-w- c:\program files\DSETUP.dll . ------- Sigcheck ------- [-] 2009-09-14 . 1186FB2F052E4890C6C23F420F4BE1BC . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\SfcFiles.dll [-] 2009-09-14 . 1186FB2F052E4890C6C23F420F4BE1BC . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\sfcfiles.dll [-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\sfcfiles.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-10-06 3118512] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2007-07-28 1230848] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-06 13537280] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-29 86016] "AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248] "LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-06-05 821768] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-12 1028096] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "USB Antivirus"="c:\program files\USB Disk Security\USBGuard.exe" [2009-09-12 811008] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-05-25 303376] "flockbox"="c:\program files\My Lockbox\flockbox.exe" [2007-12-14 1071472] "WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832] "00saskda"="c:\program files\1st Security Agent\newlock.exe" [2009-06-18 1457344] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-29 1630208] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-05-13 16862720] c:\documents and settings\Administrator\Start Menu\Programs\Startup\ Hyperdesk_uninst0.lnk - c:\documents and settings\All Users\Application Data\The Skins Factory\Hyperdesk\HyperdeskEngine.exe [2009-9-27 1273856] c:\documents and settings\Guest\Start Menu\Programs\Startup\ Hyperdesk_uninst0.lnk - c:\documents and settings\All Users\Application Data\The Skins Factory\Hyperdesk\HyperdeskEngine.exe [2009-9-27 1273856] c:\documents and settings\Herman Nehru\Start Menu\Programs\Startup\ Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2009-8-24 3581680] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-9-11 576104] Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "HideFastUserSwitching"= 0 (0x0) "HideShutdownScripts"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoStartMenuMyMusic"= 0 (0x0) "NoSMMyPictures"= 0 (0x0) "NoWelcomeScreen"= 0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoChangeAnimation"= 0 (0x0) "RestrictCpl"= 0 (0x0) "DisallowCpl"= 0 (0x0) "RestrictRun"= 0 (0x0) "ForceRecycleBinSize"= 0 (0x0) "NoCustomizeWebView"= 0 (0x0) "NoFileAssociate"= 0 (0x0) "NoDFSTab"= 0 (0x0) "NoCustomizeThisFolder"= 0 (0x0) "NoWebView"= 0 (0x0) "DontShowSuperHidden"= 0 (0x0) "NoOnlinePrintsWizard"= 0 (0x0) "NoPublishingWizard"= 0 (0x0) "NoSMConfigurePrograms"= 0 (0x0) "NoSMMyPictures"= 0 (0x0) "NoStartMenuMyMusic"= 0 (0x0) "NoHelp"= 0 (0x0) "NoCommonGroups"= 0 (0x0) "NoStartMenuEjectPC"= 0 (0x0) "NoSimpleStartMenu"= 0 (0x0) "NoStartMenuSubFolders"= 0 (0x0) "NoDisconnect"= 0 (0x0) "NoNtSecurity"= 0 (0x0) "GreyMSIAds"= 0 (0x0) "ForceMaxRecentDocs"= 0 (0x0) "NoSMBalloonTip"= 0 (0x0) "NoSMBalloonTips"= 0 (0x0) "HideSCAVolume"= 0 (0x0) "HideSCANetwork"= 0 (0x0) "HideSCAPower"= 0 (0x0) "NoTaskGrouping"= 0 (0x0) "NoWebServices"= 0 (0x0) "NoFileUrl"= 0 (0x0) "SpecifyDefaultButtons"= 0 (0x0) "NoRecentDocsNetHood"= 0 (0x0) "PromptRunasInstallNetPath"= 1 (0x1) "NoResolveTrack"= 0 (0x0) "NoDevMgrUpdate"= 0 (0x0) "NoThumbnailCache"= 1 (0x1) "ForceCopyAclwithFile"= 0 (0x0) "StartRunNoHOMEPATH"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient] 2005-01-31 22:13 49152 ----a-w- c:\progra~1\COMMON~1\Stardock\MCPStub.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk * [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\fsproflt] @="Service" [HKLM\~\startupfolder\C:^Documents and Settings^Herman Nehru^Start Menu^Programs^Startup^DesktopVideoPlayer.LNK] backup=c:\windows\pss\DesktopVideoPlayer.LNKStartup [HKLM\~\startupfolder\C:^Documents and Settings^Herman Nehru^Start Menu^Programs^Startup^Styler.lnk] backup=c:\windows\pss\Styler.lnkStartup HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RRT-Auto [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [8/19/2009 22:23 43792] R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [12/15/2008 20:41 33808] R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [10/4/2009 21:50 17264] R2 DeskSaverService;DeskSaverService;c:\program files\1st Security Agent\newlock.exe [10/13/2009 13:52 1457344] R2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [8/19/2009 22:23 73392] R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [8/10/2009 18:57 603904] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [5/16/2009 20:59 19472] R3 plkusbser;PROLiNKU6 USB Device for Legacy Serial Communication;c:\windows\system32\drivers\plkusbser.sys [7/11/2009 15:56 99456] R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [7/11/2009 15:28 154624] S2 PCMAVRTPService;PCMAV RealTime Protector Service;c:\windows\system32\RTPSvc.exe --> c:\windows\system32\RTPSvc.exe [?] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [7/13/2009 18:21 36608] S3 getPlusHelper;getPlus(R) Helper;c:\windows\System32\svchost.exe -k getPlusHelper [8/3/2004 15:56 14336] S3 NTProcDrv;Process creation detector for NT.;\??\c:\windows\TEMP\drv1.tmp --> c:\windows\TEMP\drv1.tmp [?] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] getPlusHelper REG_MULTI_SZ getPlusHelper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}] "c:\program files\Windows Sidebar\sidebar.exe" /RegServer . Contents of the 'Scheduled Tasks' folder 2009-10-15 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 23:28] 2009-10-15 c:\windows\Tasks\User_Feed_Synchronization-{E3CD1275-2939-4B63-B05D-BE902B8818D5}.job - c:\windows\system32\msfeedssync.exe [2007-08-14 11:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.id/ IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm FF - ProfilePath - c:\documents and settings\Herman Nehru\Application Data\Mozilla\Firefox\Profiles\nk4rik1i.default\ FF - prefs.js: keyword.URL - hxxp://ide.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_ide&p= FF - component: c:\documents and settings\Herman Nehru\Application Data\IDM\idmmzcc3\components\idmmzcc.dll FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll FF - plugin: c:\documents and settings\Herman Nehru\Application Data\Mozilla\Firefox\Profiles\nk4rik1i.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll FF - plugin: c:\progra~1\Mozilla Firefox\plugins\np_gp.dll FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\Mozilla Firefox 3.5 Beta 4\plugins\NPOFF12.DLL FF - plugin: c:\program files\Mozilla Firefox 3.5 Beta 4\plugins\nppl3260.dll FF - plugin: c:\program files\Mozilla Firefox 3.5 Beta 4\plugins\nprpjplug.dll FF - plugin: c:\program files\Mozilla Firefox 3.5 Beta 4\plugins\npyaxmpb.dll FF - plugin: c:\program files\Opera\program\plugins\NP_IDM1.dll FF - plugin: c:\program files\Opera\program\plugins\NP_IDM2.dll FF - plugin: c:\program files\Opera\program\plugins\NP_IDM3.dll FF - plugin: c:\program files\Opera\program\plugins\NP_IDM4.dll FF - plugin: c:\program files\Opera\program\plugins\NP_IDM5.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: network.http.max-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 750 FF - user.js: content.notify.interval - 750000 FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: yahoo.homepage.dontask - true. - - - - ORPHANS REMOVED - - - - Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file) Notify-WgaLogon - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-15 14:48 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NTProcDrv] "ImagePath"="\??\c:\windows\TEMP\drv1.tmp" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] @Denied: (Full) (Everyone) "scansk"=hex(0):87,2d,c3,ce,b9,a4,9b,4f,ee,59,ba,03,35,42,2d,61,ea,34,96,06,2c, 65,99,e3,86,40,49,42,37,54,ca,4e,6c,0e,a2,93,7a,c4,10,02,00,00,00,00,00,00,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{fc28d12f-953c-4768-98c7-cebe59a1a05e}] @Denied: (Full) (Everyone) "Model"=dword:00000106 "Therad"=dword:0000000e "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d, df,1c,2f,3b,8a,0a,32,11,89,01,b5,d6,31,95,fc,65,93,df,8b,66,88,7c,1a,78,15,\ . Completion time: 2009-10-15 14:51 ComboFix-quarantined-files.txt 2009-10-15 21:51 Pre-Run: 33,649,029,120 bytes free Post-Run: 33,602,981,888 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 411 --- E O F --- 2009-10-15 20:50 |
|
|
|
|
#7 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Posts: 553
OS: N/A
|
Re: Cannot delete file AUTORUN.INF
Hello.
We'll see what that folder is. Download and run RootRepeal CR Please download RootRepeal from the following location and save it to your desktop.
Download and run MalwareBytes Anti-Malware Please download Malwarebytes Anti-Malware and save it to your desktop. alternate download link 1
For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Thanks. With Regards, Extremeboy |
|
|
|
|
#8 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 28
OS: xp
|
Re: Cannot delete file AUTORUN.INF
Hi,
Thank you for helping me so far. Note that Malwarebytes found one infection called 'explorer.backup' which has been deleted. Could you tell me what it is? How did this malware enter my system? Thank you again, Extremeboy. Here is the scan result of Repeal: ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2009/10/16 09:48 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP2 ================================================== Drivers ------------------- Name: Image Path: Address: 0xBA6E3000 Size: 98304 File Visible: No Signed: - Status: - Name: Image Path: Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xB7BCF000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xBAE00000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xB46D6000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ------------------- Path: D:\PDF Reading\Setup Status: Invisible to the Windows API! Path: \\?\D:\PDF Reading\Setup\* Status: Could not enumerate files with the Windows API (0x00000003)! Path: D:\PDF Reading\Setup\3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\Fresh Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\Middle Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\Movie Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\NAUGHTY AMERICA Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\New Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\New Folder Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\Squirt Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\SUDI Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\Tante Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\UNDER 10 Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\West Status: Invisible to the Windows API! Path: \\?\D:\PDF Reading\Setup\3GP\* Status: Could not enumerate files with the Windows API (0x00000003)! Path: D:\PDF Reading\Setup\3GP\Aceh Membar.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Ai Lin.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Anak Bali.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Anak mitra.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Anak paramadina.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Arisan.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Artis natalia (1).3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Asdy smp 5.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\asia(1_3).3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Asian Hot.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Asoy Geboy Coy.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Belah duren mas.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Bocah 17Thn.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Bocah 18Thn.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Bocah cilik.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Bocah Kampung.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Brakatak.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\BSI Tangerang.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Bunting sex.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Buset Pipis ne.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\busyet...3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\cantik_dientot.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Chantik brow.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\CLIP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Copy of japanese get ****.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\DIAN.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\diatas_sedan_mewah.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\DK21__friend_.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\e-bokep.net---Budak-Melayu.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\e-bokep.net---Cewek-panggilan.mp4 Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\e-bokep.net---Nishfa-Widya.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\e-bokep.net---Tahun-Baru-2008.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Evehe,x.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\expatriatsi_-_www.susuaku.us.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Foreplay Ocha.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\**** with Dog.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Gadis desa000.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\galenrong.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Gede banget.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\good morning.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Goyang Poool..!.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Hanimun pertama hot.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\hesti_si_calon_dokter.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\hihi.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Honda_scandal.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\hospital.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\hotel_abg_2-001.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\ihk.. malu-malu mau.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indekos+bantal+kuning.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3g.com_-_Ajeb2Ngobel.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com - Chika-Anak-band.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_3some+kasur+biru.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_abg+imut+putih+digrepe+dlm+mobil.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_abg+in+love+cekin+kerekam.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_abg+manis+kwalahan+dientot.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_abg+sexy+gatal.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_amoi+malu+malu.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_ANN.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Ann_Anak_Baru+Gede.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_arisan+ibu2.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_ayi.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Bandung_Elevator.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Bar_Fingering.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_belajar+n+praktikum+di+rumah.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_bintan+mall.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_bj_kontak_mata.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_BUSEEEET KASI DAAH.mp4 Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_cakep_lho.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Coitus_Interruptus.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\B 4 NGOR.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\e-bokep.net---Belajar-orgasme.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Hheebboo....3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_ama+tetangga+main+di+tangga.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Cum+onto+her+mouth.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_for_my_ofw_husband.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Mandi.dikali.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_remes_susu.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_smu+bejad.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Jimbaran-Exposed-2.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Local Pagat.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Perawan 1.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Skandal Video Mesum Gresik 01.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_cupang+di+toket+merobek+selaput.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_di+kontrakan+2.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_DiKost_AB.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Dita di mobil.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Empety.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Enam_lawan_satu+GangBang.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Episode+Barunya+Sedes+bin+SMU+Semarang.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_filipino-girl-manila.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Foreplay+khusuk+1.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Foreplay+khusuk+2.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Foreplay+khusuk+3.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Foreplay+khusuk+4.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_****_Me_14.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_girls+dancing+topless.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_izah.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_kamarku_saksi_bisu.mp4 Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Kimi+menyanyi.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_lapar batang.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_ling+Kareena1.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_lumayan+hot.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_mainin+klit.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_manado2.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_manado3.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_manado5.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Manado_new.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Mandi.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_mastur+di+mobil+Liana.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Model.indonesia.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_N80_shared.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_nakal.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Neophyte.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Nonik+Manado+Lagi+neh.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_nyoba+webcam+wkt+horny.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_oohh+yesssh.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Pantai_lhoknga.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_pengen+diatas.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_pesta+sex+anak+kost.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_rambut_pendek.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Ranau_Girl.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Saat2_bersamanya_1.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Saat2_bersamanya_2.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_salome.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_selingkuh_full_edition.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_SENSASIONAL.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_sensasi_sarung.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_Sepasang+Kekasih+di+Banjar.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_SexyMenggemaskan.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_si+putih+melayang+kenikmatan.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_siswa_karimun_1.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_smu+-+kenangan+stelah+pengumuman+kelulusan.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_SMU+-+si+Sayu+ma+Sasi.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_smu+gurumurid.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_SMU+Manaya.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_smu+ml+seiring+irama+musik+siang+bolong.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_strip+ce+gatal+BhMerah+kulit+putih.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_trisakti+hot.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_wina_diy.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\indo3gp.com_-_YAYANK.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\istri byr htng suami.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Ivon Bugil.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\I~The Quick.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Janda Muda.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\JELI.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\jilbab stw.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Jimbaran-Exposed-1.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Jimbaran-Exposed-4.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Jimbaran-Exposed-5.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Jimbaran-Exposed-6.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\kacamata_binal.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\kalau_ker2_yg_ke_3_etan.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Kedokteran 1.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Kedokteran 2.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\kelepun peca.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Kenangan terindahl.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Kendalism_youth.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Kepergok Anak.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\KikiBerani.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Kolor Ijo.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\lagi_bobok.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\like_Ida_Nerina.WMV Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Lin_di_GangBang.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\maen_1.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\malay - papa jahat(2).3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Mandi Madu.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Mantap.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Martha.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\MiripJUPE.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Model Indo.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\nganjuk_membara_lagi..3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Ngapak-ngapak.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Ngiler.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\NIKMAT SEKALI.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\ooh i cum.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Orasah bayar lomas.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Orkes_birahi_Makasar.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Ospek.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\PekanBaru.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Pelatih Basket.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Philipina Pny.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Politehnik Samarinda.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Puncak-bogor.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Renyah_siswi_SMU_2.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Reri+pth+ml+sampe+keluar.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\riomsg3.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Rofica_JB.WMV Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\RumahSewa.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\RumahSewa_Pt.1.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Scandal_anak_kost.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Sexs brutal.....!.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Sexy Dugem.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Siswi Edan.3GP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\siswi smu 1.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\siswi smu 2.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\siswi smu 3.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Skandal Video Mesum Gresik 02.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Sluuurps.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\SMA-Limbunan.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\smaSampit-IndoWet.COM.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\SMU 5.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Smu Ngawi 2.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Smu Sex.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\SMUN TARAKAN.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\sp4.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Spp.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Suster Ngentot.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\TEORI BERCINTA.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Thumbs.db Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Untitled(02).mp4 Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\weah.flv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\Wong uedaaan. . . (1) (1).3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\yg ptg om senang.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\3GP\YOYGA.3GP Status: Invisible to the Windows API! Path: \\?\D:\PDF Reading\Setup\bokep\* Status: Could not enumerate files with the Windows API (0x00000003)! Path: D:\PDF Reading\Setup\bokep\02012006.mp4 Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\11 tahun.rm Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\Anak malang.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\Anak SMP.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\asik1.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\B skandang hot.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\B. 14 thn.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\Banjir ne'.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\Black.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\Bé4$t vîrgìñs.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\Bødy cäntik.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\Cannon In D solo Guitar by Funtwo.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\China Mania.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\En@k Neh.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\Marang jga hadir disi2.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\NITIP Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\tarakan.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\Tarzan X.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\TrickShot.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\tusukn maut.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\VTS_01_1.VOB Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\¤PerkosaanAN¤.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\bokep\ìlmu biologi..3gp Status: Invisible to the Windows API! Path: \\?\D:\PDF Reading\Setup\coy\* Status: Could not enumerate files with the Windows API (0x00000003)! Path: D:\PDF Reading\Setup\coy\( uploadMB.com ) layan2.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\( UploadTech.com ) layan1.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\002.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\0021.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\0031.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\0041.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\01.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\011.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\02.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\03.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\031.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\032.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\033.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\034.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\035.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\036.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\037.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\038.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\039.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\04.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\041.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\042.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\043.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\044.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\045.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\046.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\047.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\048.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\1-33.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\1-38.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\1.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\11.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\1249-video03.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\1249-video04.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\2.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\21.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\22.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\2229_02_tgp1.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\2229_02_tgp3.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\3.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\3.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\31.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\32.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\33.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\4.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\4.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\41.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\42.wmv Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\6.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\702.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\703.mpg Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\ABG_Mastuerbate_diwarnet.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\ABG_Solo_ML_di_KOST_Pake_Bahasa_Jawa_.3gp Status: Invisible to the Windows API! Path: D:\PDF Reading\Setup\coy\alannaackeSSDT ------------------- #: 011 Function Name: NtAdjustPrivilegesToken Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eec36e #: 025 Function Name: NtClose Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeca86 #: 031 Function Name: NtConnectPort Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eed60c #: 035 Function Name: NtCreateEvent Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eedb40 #: 037 Function Name: NtCreateFile Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eecd78 #: 041 Function Name: NtCreateKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeb460 #: 043 Function Name: NtCreateMutant Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeda18 #: 044 Function Name: NtCreateNamedPipeFile Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eead0a #: 045 Function Name: NtCreatePagingFile Status: Hooked by "a347bus.sys" at address 0xba780b00 #: 046 Function Name: NtCreatePort Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eed8d4 #: 050 Function Name: NtCreateSection Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eec102 #: 051 Function Name: NtCreateSemaphore Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eedc72 #: 052 Function Name: NtCreateSymbolicLinkObject Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eef40e #: 053 Function Name: NtCreateThread Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eec886 #: 056 Function Name: NtCreateWaitablePort Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eed976 #: 063 Function Name: NtDeleteKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeba20 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eebcf8 #: 066 Function Name: NtDeviceIoControlFile Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eed21c #: 068 Function Name: NtDuplicateObject Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eef980 #: 071 Function Name: NtEnumerateKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eebe3a #: 073 Function Name: NtEnumerateValueKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eebee4 #: 084 Function Name: NtFsControlFile Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eed016 #: 097 Function Name: NtLoadDriver Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeeea6 #: 098 Function Name: NtLoadKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeb43c #: 099 Function Name: NtLoadKey2 Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeb44e #: 111 Function Name: NtNotifyChangeKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eec030 #: 114 Function Name: NtOpenEvent Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eedbe2 #: 116 Function Name: NtOpenFile Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eecb08 #: 119 Function Name: NtOpenKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeb604 #: 120 Function Name: NtOpenMutant Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eedab0 #: 122 Function Name: NtOpenProcess Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eec56e #: 125 Function Name: NtOpenSection Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eef438 #: 126 Function Name: NtOpenSemaphore Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eedd14 #: 128 Function Name: NtOpenThread Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eec492 #: 160 Function Name: NtQueryKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eebf8e #: 161 Function Name: NtQueryMultipleValueKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eebbb6 #: 177 Function Name: NtQueryValueKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeb8bc #: 180 Function Name: NtQueueApcThread Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eef128 #: 192 Function Name: NtRenameKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eebb34 #: 193 Function Name: NtReplaceKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeb0c2 #: 194 Function Name: NtReplyPort Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eee09e #: 195 Function Name: NtReplyWaitReceivePort Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eedf64 #: 200 Function Name: NtRequestWaitReplyPort Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeec30 #: 204 Function Name: NtRestoreKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeb224 #: 206 Function Name: NtResumeThread Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eef860 #: 207 Function Name: NtSaveKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeaec4 #: 210 Function Name: NtSecureConnectPort Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eed312 #: 213 Function Name: NtSetContextThread Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eec984 #: 230 Function Name: NtSetInformationToken Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eee5f2 #: 237 Function Name: NtSetSecurityObject Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeefa0 #: 240 Function Name: NtSetSystemInformation Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eef4c2 #: 241 Function Name: NtSetSystemPowerState Status: Hooked by "a347bus.sys" at address 0xba78c550 #: 247 Function Name: NtSetValueKey Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeb744 #: 253 Function Name: NtSuspendProcess Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eef5a6 #: 254 Function Name: NtSuspendThread Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eef6d2 #: 255 Function Name: NtSystemDebugControl Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eeedd2 #: 257 Function Name: NtTerminateProcess Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eec6ea #: 258 Function Name: NtTerminateThread Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eec63c #: 277 Function Name: NtWriteVirtualMemory Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7eec7c8 Stealth Objects ------------------- Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ] Process: System Address: 0x8a2fab60 Size: 11 Object: Hidden Code [Driver: a347scsi, IRP_MJ_CREATE] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_CLOSE] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_READ] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_WRITE] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_SET_INFORMATION] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_QUERY_EA] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_SET_EA] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_SHUTDOWN] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_CLEANUP] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_SET_SECURITY] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_POWER] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_SET_QUOTA] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: a347scsi, IRP_MJ_PNP] Process: System Address: 0x89c11380 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_INFORMATION] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_EA] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_EA] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLEANUP] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_SECURITY] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_QUOTA] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP] Process: System Address: 0x89ac4f00 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_READ] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_WRITE] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_SET_INFORMATION] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_EA] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_SET_EA] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_SHUTDOWN] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_CLEANUP] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_SET_SECURITY] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_POWER] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_SET_QUOTA] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: atapi, IRP_MJ_PNP] Process: System Address: 0x89dd77e0 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_CREATE] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_CLOSE] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_READ] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_WRITE] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_SET_INFORMATION] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_QUERY_EA] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_SET_EA] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_SHUTDOWN] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_CLEANUP] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_SET_SECURITY] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_POWER] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_SET_QUOTA] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: usbstor, IRP_MJ_PNP] Process: System Address: 0x89e24b48 Size: 99 Object: Hidden Code [Driver: DefragFS؆䱋慤ం汇歮, IRP_MJ_READ] Process: System Address: 0x89b6b738 Size: 11 Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ] Process: System Address: 0x89af41d0 Size: 11 Object: Hidden Code [Driver: Srv, IRP_MJ_READ] Process: System Address: 0x89461808 Size: 11 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ] Process: System Address: 0x89b76d30 Size: 11 Object: Hidden Code [Driver: sys, IRP_MJ_READ] Process: System Address: 0x8a3891f0 Size: 11 Object: Hidden Code [Driver: Msfsఐ卆浩t, IRP_MJ_READ] Process: System Address: 0x8a384c18 Size: 11 Object: Hidden Code [Driver: Fs_Rec, IRP_MJ_READ] Process: System Address: 0x89bd4ea0 Size: 11 Object: Hidden Code [Driver: Cdfsఅ䱋楳ā, IRP_MJ_READ] Process: System Address: 0x89b74810 Size: 11 Shadow SSDT ------------------- #: 013 Function Name: NtGdiBitBlt Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efc32a #: 227 Function Name: NtGdiMaskBlt Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efc3ee #: 237 Function Name: NtGdiPlgBlt Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efc454 #: 292 Function Name: NtGdiStretchBlt Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efc38a #: 307 Function Name: NtUserAttachThreadInput Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efbec4 #: 323 Function Name: NtUserCallOneParam Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efc242 #: 378 Function Name: NtUserFindWindowEx Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efc0b2 #: 383 Function Name: NtUserGetAsyncKeyState Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efbe2c #: 414 Function Name: NtUserGetKeyboardState Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efc17a #: 416 Function Name: NtUserGetKeyState Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efbe78 #: 460 Function Name: NtUserMessageCall Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efc004 #: 475 Function Name: NtUserPostMessage Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efbf5a #: 476 Function Name: NtUserPostThreadMessage Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efbfae #: 491 Function Name: NtUserRegisterRawInputDevices Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efc10a #: 502 Function Name: NtUserSendInput Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efc064 #: 549 Function Name: NtUserSetWindowsHookEx Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efbd7c #: 552 Function Name: NtUserSetWinEventHook Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xb7efbdd2 ==EOF== The following is a scan from Malwarebytes Anti Malware: Malwarebytes' Anti-Malware 1.41 Database version: 2970 Windows 5.1.2600 Service Pack 2 10/16/2009 11:26:35 mbam-log-2009-10-16 (11-26-35).txt Scan type: Quick Scan Objects scanned: 142046 Time elapsed: 7 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\explorer.backup (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully. And these are DDS and Attach log: DDS (Ver_09-10-13.01) - NTFSx86 Run by Herman Nehru at 13:28:04.09 on Fri 10/16/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1790.1210 [GMT -7:00] AV: Kaspersky Internet Security *On-access scanning enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *enabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\1st Security Agent\newlock.exe C:\WINDOWS\system32\fsproflt.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\TUProgSt.exe C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\USB Disk Security\USBGuard.exe C:\Program Files\My Lockbox\flockbox.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\Program Files\1st Security Agent\newlock.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Program Files\Internet Download Manager\IEMonitor.exe C:\DOCUME~1\HERMAN~1\LOCALS~1\Temp\RtkBtMnt.exe C:\Documents and Settings\Herman Nehru\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.co.id/ mURLSearchHooks: H - No File BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: CDelHotkeys Object: {78875f5c-a685-4405-8dc5-d48dc65452b0} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll BHO: Cooliris Plug-In for Internet Explorer: {eaee5c74-6d0d-4aca-9232-0da4a7b866ba} - c:\program files\piclensie\cooliris.dll BHO: Ask Toolbar BHO: {f4d76f01-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL TB: Delicious Toolbar: {61d1c847-df80-423a-8c6d-dc03b97e6ebe} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll TB: Ask Toolbar: {f4d76f09-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File EB: Delicious Sidebar: {9d19c405-ba93-461b-871f-97992cc45972} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [AzMixerSel] c:\program files\realtek\audio\installshield\AzMixerSel.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [USB Antivirus] c:\program files\usb disk security\USBGuard.exe mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe" mRun: [flockbox] c:\program files\my lockbox\flockbox.exe /a mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot mRun: [00saskda] "c:\program files\1st security agent\newlock.exe" saskda mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\docume~1\herman~1\startm~1\programs\startup\stardock objectdock.lnk - c:\program files\stardock\objectdock\ObjectDock.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe uPolicies-explorer: NoChangeAnimation = 0 (0x0) uPolicies-explorer: RestrictCpl = 0 (0x0) uPolicies-explorer: DisallowCpl = 0 (0x0) uPolicies-explorer: RestrictRun = 0 (0x0) uPolicies-explorer: ForceRecycleBinSize = 0 (0x0) uPolicies-explorer: NoCustomizeWebView = 0 (0x0) uPolicies-explorer: NoFileAssociate = 0 (0x0) uPolicies-explorer: NoDFSTab = 0 (0x0) uPolicies-explorer: NoInstrumentation = 0 (0x0) uPolicies-explorer: NoCustomizeThisFolder = 0 (0x0) uPolicies-explorer: NoWebView = 0 (0x0) uPolicies-explorer: DontShowSuperHidden = 0 (0x0) uPolicies-explorer: NoOnlinePrintsWizard = 0 (0x0) uPolicies-explorer: NoPublishingWizard = 0 (0x0) uPolicies-explorer: NoSMConfigurePrograms = 0 (0x0) uPolicies-explorer: NoSMMyPictures = 0 (0x0) uPolicies-explorer: NoStartMenuMyMusic = 0 (0x0) uPolicies-explorer: NoHelp = 0 (0x0) uPolicies-explorer: NoCommonGroups = 0 (0x0) uPolicies-explorer: NoStartMenuEjectPC = 0 (0x0) uPolicies-explorer: NoSimpleStartMenu = 0 (0x0) uPolicies-explorer: NoStartMenuSubFolders = 0 (0x0) uPolicies-explorer: NoDisconnect = 0 (0x0) uPolicies-explorer: NoNtSecurity = 0 (0x0) uPolicies-explorer: GreyMSIAds = 0 (0x0) uPolicies-explorer: ForceMaxRecentDocs = 0 (0x0) uPolicies-explorer: NoSMBalloonTip = 0 (0x0) uPolicies-explorer: NoSMBalloonTips = 0 (0x0) uPolicies-explorer: HideSCAVolume = 0 (0x0) uPolicies-explorer: HideSCANetwork = 0 (0x0) uPolicies-explorer: HideSCAPower = 0 (0x0) uPolicies-explorer: NoTaskGrouping = 0 (0x0) uPolicies-explorer: NoWebServices = 0 (0x0) uPolicies-explorer: NoFileUrl = 0 (0x0) uPolicies-explorer: SpecifyDefaultButtons = 0 (0x0) uPolicies-explorer: NoRecentDocsNetHood = 0 (0x0) uPolicies-explorer: PromptRunasInstallNetPath = 1 (0x1) uPolicies-explorer: NoResolveTrack = 0 (0x0) uPolicies-explorer: NoDevMgrUpdate = 0 (0x0) uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) uPolicies-explorer: NoThumbnailCache = 1 (0x1) uPolicies-explorer: ForceCopyAclwithFile = 0 (0x0) uPolicies-explorer: StartRunNoHOMEPATH = 0 (0x0) mPolicies-explorer: <NO NAME> = mPolicies-explorer: NoStartMenuMyMusic = 0 (0x0) mPolicies-explorer: NoSMMyPictures = 0 (0x0) mPolicies-explorer: NoWelcomeScreen = 0 (0x0) mPolicies-system: <NO NAME> = mPolicies-system: HideFastUserSwitching = 0 (0x0) mPolicies-system: HideShutdownScripts = 0 (0x0) IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2010\ie_banner_deny.htm IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm IE: Download with IDM - c:\program files\internet download manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {2C887991-08F0-11DC-A9B2-0012F0B227DD} - {B8D8B1D0-83AF-451B-8CD9-8F1BF4ED8FEA} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll IE: {2C887992-08F0-11DC-A9B2-0012F0B227DD} - {9D19C405-BA93-461b-871F-97992CC45972} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll IE: {2C887993-08F0-11DC-A9B2-0012F0B227DD} - {4D3D441F-9543-4941-B664-2EDCF9FC1B56} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - c:\program files\piclensie\cooliris.dll IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/V6/V5Controls/en/x86/client/wuweb_site.cab?1247595412296 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1248583003125 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: klogon - c:\windows\system32\klogon.dll Notify: MCPClient - c:\progra~1\common~1\stardock\mcpstub.dll AppInit_DLLs: c:\progra~1\kaspersky lab\kaspersky internet security 2010\kloehk.dll SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~1\common~1\stardock\MCPCore.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\herman~1\applic~1\mozilla\firefox\profiles\nk4rik1i.default\ FF - prefs.js: keyword.URL - hxxp://ide.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_ide&p= FF - component: c:\documents and settings\herman nehru\application data\idm\idmmzcc3\components\idmmzcc.dll FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll FF - plugin: c:\documents and settings\herman nehru\application data\mozilla\firefox\profiles\nk4rik1i.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\np_gp.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\NPOFF12.DLL FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\nppl3260.dll FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\nprpjplug.dll FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\npyaxmpb.dll FF - plugin: c:\program files\opera\program\plugins\NP_IDM1.dll FF - plugin: c:\program files\opera\program\plugins\NP_IDM2.dll FF - plugin: c:\program files\opera\program\plugins\NP_IDM3.dll FF - plugin: c:\program files\opera\program\plugins\NP_IDM4.dll FF - plugin: c:\program files\opera\program\plugins\NP_IDM5.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ ---- FIREFOX POLICIES ---- FF - user.js: network.http.max-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 750 FF - user.js: content.notify.interval - 750000 FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [2009-8-19 43792] R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-12-15 33808] R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [2009-10-4 17264] R2 DeskSaverService;DeskSaverService;c:\program files\1st security agent\newlock.exe [2009-10-13 1457344] R2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [2009-8-19 73392] R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-8-10 603904] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-5-16 19472] R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [2009-7-11 154624] S2 PCMAVRTPService;PCMAV RealTime Protector Service;c:\windows\system32\rtpsvc.exe --> c:\windows\system32\RTPSvc.exe [?] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2009-7-13 36608] S3 getPlusHelper;getPlus(R) Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-3 14336] S3 NTProcDrv;Process creation detector for NT.;\??\c:\windows\temp\drv1.tmp --> c:\windows\temp\drv1.tmp [?] S3 plkusbser;PROLiNKU6 USB Device for Legacy Serial Communication;c:\windows\system32\drivers\plkusbser.sys [2009-7-11 99456] =============== Created Last 30 ================ 2009-10-16 10:52 <DIR> --d----- c:\docume~1\herman~1\applic~1\Malwarebytes 2009-10-16 10:52 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-16 10:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-10-16 10:52 19,160 a------- c:\windows\system32\drivers\mbam.sys 2009-10-16 10:52 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware 2009-10-15 14:32 <DIR> a-dshr-- C:\cmdcons 2009-10-15 13:59 236,544 a------- c:\windows\PEV.exe 2009-10-15 13:59 161,792 a------- c:\windows\SWREG.exe 2009-10-15 13:59 98,816 a------- c:\windows\sed.exe 2009-10-14 11:15 <DIR> --d----- c:\program files\Real Desktop 2009-10-13 13:52 <DIR> --d----- c:\documents and settings\herman nehru\1st Security Agent 2009-10-13 13:52 <DIR> --d----- C:\1st Security Agent 2009-10-13 13:52 <DIR> --d----- c:\program files\1st Security Agent 2009-10-13 12:05 <DIR> --d----- c:\program files\HÑÑ 2009-10-13 08:28 <DIR> --d----- c:\docume~1\herman~1\applic~1\WinPatrol 2009-10-13 08:28 <DIR> --d----- c:\program files\BillP Studios 2009-10-12 00:06 <DIR> --d----- c:\program files\PowerISO 2009-10-11 23:18 <DIR> --d----- C:\[Smad-Cage] 2009-10-10 15:19 <DIR> --d----- c:\docume~1\herman~1\applic~1\The Labyrinth Plus! Edition 2009-10-10 15:19 0 a------- c:\windows\RussSqr.INI 2009-10-10 09:49 <DIR> --d----- c:\program files\Microsoft Plus! 2009-10-07 19:55 68 a------- c:\windows\MyProg.ini 2009-10-06 16:53 <DIR> --d----- c:\program files\AskPBar 2009-10-06 16:00 <DIR> --d----- c:\program files\Raxco 2009-10-04 22:14 <DIR> --d----- c:\program files\FreeCommander 2009-10-04 21:50 17,264 a------- c:\windows\system32\drivers\mprifl.sys 2009-10-04 21:50 <DIR> --d----- c:\program files\My Lockbox 2009-10-04 19:03 41,984 a------- c:\windows\system32\dwlGina3.dll 2009-10-04 19:03 3,712 a------- c:\windows\system32\dwlkbf.sys 2009-10-04 19:03 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Deskman9 2009-10-03 23:51 <DIR> --d----- c:\docume~1\herman~1\applic~1\Thinstall 2009-10-03 20:26 387,104 a--sh--- c:\windows\system32\drivers\fidbox.dat 2009-10-03 20:26 5,612 a--sh--- c:\windows\system32\drivers\fidbox.idx 2009-10-03 20:23 148,496 a------- c:\windows\system32\drivers\86909831.sys 2009-10-03 20:06 <DIR> --d----- c:\program files\Vista Start Menu 2009-09-30 23:53 604,140 a--sh--- c:\windows\system32\drivers\ISwift3.dat 2009-09-30 23:44 108,059 a------- c:\windows\system32\drivers\klin.dat 2009-09-30 23:44 95,259 a------- c:\windows\system32\drivers\klick.dat 2009-09-30 23:42 <DIR> --d----- c:\program files\Kaspersky Lab 2009-09-30 23:42 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Kaspersky Lab 2009-09-27 00:39 <DIR> --d----- c:\docume~1\alluse~1\applic~1\The Skins Factory 2009-09-26 23:54 <DIR> --d----- c:\docume~1\herman~1\applic~1\Skinux 2009-09-20 21:53 152 a------- C:\streetflyter.sav 2009-09-19 17:42 <DIR> --d----- c:\program files\Avatar - Path of Zuko 2009-09-19 13:01 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Zbshareware Lab 2009-09-19 13:01 <DIR> --d----- c:\program files\USB Disk Security 2009-09-19 12:38 <DIR> --d----- c:\docume~1\herman~1\applic~1\Merscom 2009-09-19 12:38 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Trymedia 2009-09-19 12:38 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Merscom ==================== Find3M ==================== 2009-10-01 02:03 128,016 a------- c:\windows\system32\drivers\kl1.sys 2009-09-30 23:27 4,212 a---h--- c:\windows\system32\zllictbl.dat 2009-09-13 20:41 1,580,544 a------- c:\windows\system32\SfcFiles.dll 2009-09-13 20:40 219,648 a------- c:\windows\system32\uxtheme.dll 2009-09-11 07:33 133,632 a------- c:\windows\system32\msv1_0.dll 2009-09-09 03:43 210,352 a------- c:\windows\system32\idmmbc.dll 2009-09-07 23:28 288,256 a------- c:\windows\system32\fmodex.dll 2009-09-04 13:45 58,880 a------- c:\windows\system32\msasn1.dll 2009-09-03 00:47 55,656 a------- c:\windows\system32\drivers\avgntflt.sys 2009-08-31 10:07 81,984 a------- c:\windows\system32\bdod.bin 2009-08-30 01:44 152,904 a------- c:\windows\system32\vghd.scr 2009-08-29 22:22 132 a------- C:\httpdwl.dat 2009-08-26 01:16 247,326 a------- c:\windows\system32\strmdll.dll 2009-08-21 15:51 126,464 a------- c:\windows\system32\RTPScan.dll 2009-08-17 23:33 1,193,832 a------- c:\windows\system32\FM20.DLL 2009-08-16 20:35 272,868 a------- c:\windows\system32\Windows XP Media Center Edition Screen Saver.scr 2009-08-14 19:23 25,600 a------- c:\windows\twunk_32.exe 2009-08-10 18:57 603,904 a------- c:\windows\system32\TUProgSt.exe 2009-08-10 18:57 362,240 a------- c:\windows\system32\TuneUpDefragService.exe 2009-08-06 12:38 13,537,280 a------- c:\windows\system32\nvcpl.dll 2009-08-06 11:29 69,120 a------- c:\windows\NOTEPAD.EXE 2009-08-05 02:11 204,800 a------- c:\windows\system32\mswebdvd.dll 2009-07-27 21:01 7,852 a------- c:\windows\system32\mcdmsg7.dll 2009-03-16 14:35 525,128 a------- c:\program files\DXSETUP.exe 2009-03-16 14:35 94,024 a------- c:\program files\DSETUP.dll ============= FINISH: 13:28:55.46 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-10-13.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 7/11/2009 15:12:00 System Uptime: 10/16/2009 11:28:45 (2 hours ago) Motherboard: Acer, Inc. | | Grasmoor Processor: AMD Turion(tm) X2 Dual-Core Mobile RM-72 | Socket M2/S1G1 | 2100/133mhz Processor: AMD Turion(tm) X2 Dual-Core Mobile RM-72 | Socket M2/S1G1 | 2100/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 50 GiB total, 31.195 GiB free. D: is FIXED (NTFS) - 99 GiB total, 21.334 GiB free. F: is CDROM () G: is CDROM (CDFS) ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Ethernet Controller Device ID: PCI\VEN_14E4&DEV_1684&SUBSYS_014A1025&REV_10\4&2CBACCCA&0&0098 Manufacturer: Name: Ethernet Controller PNP Device ID: PCI\VEN_14E4&DEV_1684&SUBSYS_014A1025&REV_10\4&2CBACCCA&0&0098 Service: Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Atheros AR5B91 Wireless Network Adapter Device ID: PCI\VEN_168C&DEV_002A&SUBSYS_03031A32&REV_01\4&2C3DDF0&0&00A8 Manufacturer: Atheros Name: Atheros AR5B91 Wireless Network Adapter PNP Device ID: PCI\VEN_168C&DEV_002A&SUBSYS_03031A32&REV_01\4&2C3DDF0&0&00A8 Service: AR5416 Class GUID: Description: Device ID: ROOT\GR_AVGFWMP\SYSTEM Manufacturer: Name: PNP Device ID: ROOT\GR_AVGFWMP\SYSTEM Service: ==== System Restore Points =================== RP1: 10/15/2009 13:59:47 - System Checkpoint RP2: 10/15/2009 21:42:16 - Software Distribution Service 3.0 ==== Installed Programs ====================== .NETSpeedBoost 6.5 Professional Edition 1st Security Agent Adobe AIR Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.1.3 Advanced System Optimizer Alky for Applications (Windows XP) Altysoft Free Video Converter 2.1 Ask Toolbar Atheros for Acer Driver 5.3.0.67_Foxconn Installation Program Avatar - Path of Zuko biohazard 4 CCleaner (remove only) Cheatbook Database 2009 Cooliris for Internet Explorer COWON Media Center - jetAudio Basic Delicious Add-on for Internet Explorer Delta Force - Black Hawk Down Foxit PDF Editor Free Unit Converter 2.11 FreeCommander 2009.02 Gadget Extractor Google Chrome HDAUDIO Soft Data Fax Modem with SmartCP Hide Folders 2009 3.2 for Windows XP/Vista Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB954550-v5) Internet Download Manager K-Lite Codec Pack 5.0.0 (Full) Kaspersky Internet Security 2010 Launch Manager LG PC Suite LG USB Modem driver Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Plus! for Windows XP Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Windows Theme Nunavut Monopoly by Parker Brothers Mozilla Firefox (3.5.3) Mozilla Thunderbird (2.0.0.22) MSXML 4.0 SP2 (KB954430) MSXML 6 Service Pack 2 (KB954459) My Lockbox 1.2 for Windows 2000/XP Nero 7 Essentials Norton 360 NVIDIA Drivers ObjectDock Plus Opera 10.00 PC Connectivity Solution PerfectDisk 10 Professional Photo Story 3 for Windows PHS100 Plants vs. Zombies RocketDock 1.3.5 SAMSUNG Mobile Composite Device Software SAMSUNG Mobile Modem Driver Set Samsung Mobile phone USB driver Software SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software SamsungConnectivityCableDriver Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB969679) Security Update for CAPICOM (KB931906) Security Update for Microsoft Office Excel 2007 (KB969682) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB969693) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Word 2007 (KB969604) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Snagit 9.1.2 Synaptics Pointing Device Driver TuneUp Utilities 2009 Tweak UI UberIcon 1.0.4 Uniblue DriverScanner 2009 Uniblue RegistryBooster 2009 Uniblue SpeedUpMyPC 2009 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office Outlook 2007 (KB969907) Update for Outlook 2007 Junk Email Filter (kb973514) Update for Windows Internet Explorer 8 (KB971930) USB 2.0 Card Reader USB Disk Security 5.2.0.5 VC 9.0 Runtime WebFldrs XP WIDCOMM Bluetooth Software Winamp Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0) Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0) Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0) Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows Sidebar WinPatrol 2009 WinRAR archiver WinZip 12.0 Yahoo! Widgets ==== Event Viewer Messages From Past Week ======== 10/15/2009 14:33:49, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect. 10/15/2009 13:47:54, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Search service to connect. 10/15/2009 13:47:54, error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 10/15/2009 13:47:54, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 10/14/2009 08:18:23, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 8063561c, parameter3 b5a88a90, parameter4 00000000. 10/13/2009 21:43:24, error: PlugPlayManager [12] - The device 'Generic volume' (STORAGE\RemovableMedia\7&d7f206a&0&RM) disappeared from the system without first being prepared for removal. 10/13/2009 21:43:24, error: PlugPlayManager [12] - The device 'Generic- Multi-Card USB Device' (USBSTOR\Disk&Ven_Generic-&Prod_Multi-Card&Rev_1.00\00000) disappeared from the system without first being prepared for removal. 10/13/2009 18:48:49, error: SideBySide [59] - Generate Activation Context failed for C:\games\Zuma's Revenge!\ZumasRevenge.exe. Reference error message: The operation completed successfully. . 10/13/2009 18:48:49, error: SideBySide [58] - Syntax error in manifest or policy file "C:\games\Zuma's Revenge!\ZumasRevenge.exe" on line 0. 10/13/2009 12:19:16, error: Service Control Manager [7000] - The PCMAV RealTime Protector Service service failed to start due to the following error: The system cannot find the file specified. 10/12/2009 21:48:54, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 10/11/2009 12:27:51, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 10/11/2009 12:21:25, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 10/11/2009 12:20:58, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10/11/2009 11:03:08, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdPPM Fips IPSec kl1 klbg KLIF MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip 10/11/2009 11:03:08, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 10/11/2009 11:03:08, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 10/10/2009 10:01:33, error: Srv [2000] - The server's call to a system service failed unexpectedly. ==== End Of File =========================== |
|
|
|
|
#9 (permalink) | |
|
Analyst, Security Team
Join Date: Jan 2009
Posts: 553
OS: N/A
|
Re: Cannot delete file AUTORUN.INF
Hello.
What Malwarebytes detected was "Heuristics.Reserved.Word.Exploit". Sometimes they may be a false-positive. There are several ways how malware can enter your system including simplying viewing exploited pages, downloading executing malicious files, porn, cracks, warez sites, infected flash-drives/removable drive. I can not know exactly how it entered your system though. I see several restrictions/policies applied to the system in the logs: Quote:
Overall the log looks good. How's your computer running at the moment? Run ESET Online Scan
Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Also, let me know how your computer is running and if you have any more problems, issues or symptoms left. Thanks. With Regards, Extremeboy |
|
|
|
|
|
#10 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 28
OS: xp
|
Re: Cannot delete file AUTORUN.INF
Hello
I see ... thank you for your explanation. Right now my system is running well, nothing seems suspicious, except I still cannot delete the folders. Regarding with the restriction/policies, I believe I never modify/change them intentionally , or possibly I did it some but I just don't realize because I am using some fixing softwares, such as 'Tuneup Utilities 2009'. ESET Scanner found 2 malwares. Here is the finding: D:\Master\Eraser\Unlocker 1.8.7\unlocker1.8.7.exe a variant of Win32/Adware.ADON application deleted - quarantined D:\Softwares\Tools\Perfect Disc Pro\CRD\keygen.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined THESE ARE DDS and ATTACH. Hope it looks good too. Best Regards, DDS (Ver_09-10-13.01) - NTFSx86 Run by Herman Nehru at 7 19.78 on Sun 10/18/2009Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1790.1279 [GMT -7:00] AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\1st Security Agent\newlock.exe C:\WINDOWS\system32\fsproflt.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\TUProgSt.exe C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\My Lockbox\flockbox.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\Program Files\1st Security Agent\newlock.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\DOCUME~1\HERMAN~1\LOCALS~1\Temp\RtkBtMnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Program Files\Stardock\ObjectDock\ObjectDock.exe C:\Program Files\Internet Download Manager\IEMonitor.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wscntfy.exe D:\Temporary File\Scan Tech Support\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.co.id/ mURLSearchHooks: H - No File BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: CDelHotkeys Object: {78875f5c-a685-4405-8dc5-d48dc65452b0} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll BHO: Cooliris Plug-In for Internet Explorer: {eaee5c74-6d0d-4aca-9232-0da4a7b866ba} - c:\program files\piclensie\cooliris.dll BHO: Ask Toolbar BHO: {f4d76f01-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL TB: Delicious Toolbar: {61d1c847-df80-423a-8c6d-dc03b97e6ebe} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll TB: Ask Toolbar: {f4d76f09-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File EB: Delicious Sidebar: {9d19c405-ba93-461b-871f-97992cc45972} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [AzMixerSel] c:\program files\realtek\audio\installshield\AzMixerSel.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [USB Antivirus] c:\program files\usb disk security\USBGuard.exe mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe" mRun: [flockbox] c:\program files\my lockbox\flockbox.exe /a mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot mRun: [00saskda] "c:\program files\1st security agent\newlock.exe" saskda mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\docume~1\herman~1\startm~1\programs\startup\stardock objectdock.lnk - c:\program files\stardock\objectdock\ObjectDock.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe uPolicies-explorer: NoChangeAnimation = 0 (0x0) uPolicies-explorer: RestrictCpl = 0 (0x0) uPolicies-explorer: DisallowCpl = 0 (0x0) uPolicies-explorer: RestrictRun = 0 (0x0) uPolicies-explorer: ForceRecycleBinSize = 0 (0x0) uPolicies-explorer: NoCustomizeWebView = 0 (0x0) uPolicies-explorer: NoFileAssociate = 0 (0x0) uPolicies-explorer: NoDFSTab = 0 (0x0) uPolicies-explorer: NoInstrumentation = 0 (0x0) uPolicies-explorer: NoCustomizeThisFolder = 0 (0x0) uPolicies-explorer: NoWebView = 0 (0x0) uPolicies-explorer: DontShowSuperHidden = 0 (0x0) uPolicies-explorer: NoOnlinePrintsWizard = 0 (0x0) uPolicies-explorer: NoPublishingWizard = 0 (0x0) uPolicies-explorer: NoSMConfigurePrograms = 0 (0x0) uPolicies-explorer: NoSMMyPictures = 0 (0x0) uPolicies-explorer: NoStartMenuMyMusic = 0 (0x0) uPolicies-explorer: NoHelp = 0 (0x0) uPolicies-explorer: NoCommonGroups = 0 (0x0) uPolicies-explorer: NoStartMenuEjectPC = 0 (0x0) uPolicies-explorer: NoSimpleStartMenu = 0 (0x0) uPolicies-explorer: NoStartMenuSubFolders = 0 (0x0) uPolicies-explorer: NoDisconnect = 0 (0x0) uPolicies-explorer: NoNtSecurity = 0 (0x0) uPolicies-explorer: GreyMSIAds = 0 (0x0) uPolicies-explorer: ForceMaxRecentDocs = 0 (0x0) uPolicies-explorer: NoSMBalloonTip = 0 (0x0) uPolicies-explorer: NoSMBalloonTips = 0 (0x0) uPolicies-explorer: HideSCAVolume = 0 (0x0) uPolicies-explorer: HideSCANetwork = 0 (0x0) uPolicies-explorer: HideSCAPower = 0 (0x0) uPolicies-explorer: NoTaskGrouping = 0 (0x0) uPolicies-explorer: NoWebServices = 0 (0x0) uPolicies-explorer: NoFileUrl = 0 (0x0) uPolicies-explorer: SpecifyDefaultButtons = 0 (0x0) uPolicies-explorer: NoRecentDocsNetHood = 0 (0x0) uPolicies-explorer: PromptRunasInstallNetPath = 1 (0x1) uPolicies-explorer: NoResolveTrack = 0 (0x0) uPolicies-explorer: NoDevMgrUpdate = 0 (0x0) uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) uPolicies-explorer: NoThumbnailCache = 1 (0x1) uPolicies-explorer: ForceCopyAclwithFile = 0 (0x0) uPolicies-explorer: StartRunNoHOMEPATH = 0 (0x0) mPolicies-explorer: <NO NAME> = mPolicies-explorer: NoStartMenuMyMusic = 0 (0x0) mPolicies-explorer: NoSMMyPictures = 0 (0x0) mPolicies-explorer: NoWelcomeScreen = 0 (0x0) mPolicies-system: <NO NAME> = mPolicies-system: HideFastUserSwitching = 0 (0x0) mPolicies-system: HideShutdownScripts = 0 (0x0) IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm IE: Download with IDM - c:\program files\internet download manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {2C887991-08F0-11DC-A9B2-0012F0B227DD} - {B8D8B1D0-83AF-451B-8CD9-8F1BF4ED8FEA} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll IE: {2C887992-08F0-11DC-A9B2-0012F0B227DD} - {9D19C405-BA93-461b-871F-97992CC45972} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll IE: {2C887993-08F0-11DC-A9B2-0012F0B227DD} - {4D3D441F-9543-4941-B664-2EDCF9FC1B56} - c:\program files\delicious add-on for internet explorer\DeliciousExtension.dll IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - c:\program files\piclensie\cooliris.dll IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/V6/V5Controls/en/x86/client/wuweb_site.cab?1247595412296 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1248583003125 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: klogon - c:\windows\system32\klogon.dll Notify: MCPClient - c:\progra~1\common~1\stardock\mcpstub.dll AppInit_DLLs: c:\progra~1\kaspersky lab\kaspersky internet security 2010\kloehk.dll SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~1\common~1\stardock\MCPCore.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\herman~1\applic~1\mozilla\firefox\profiles\nk4rik1i.default\ FF - prefs.js: keyword.URL - hxxp://ide.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_ide&p= FF - component: c:\documents and settings\herman nehru\application data\idm\idmmzcc3\components\idmmzcc.dll FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll FF - plugin: c:\documents and settings\herman nehru\application data\mozilla\firefox\profiles\nk4rik1i.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\np_gp.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\NPOFF12.DLL FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\nppl3260.dll FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\nprpjplug.dll FF - plugin: c:\program files\mozilla firefox 3.5 beta 4\plugins\npyaxmpb.dll FF - plugin: c:\program files\opera\program\plugins\NP_IDM1.dll FF - plugin: c:\program files\opera\program\plugins\NP_IDM2.dll FF - plugin: c:\program files\opera\program\plugins\NP_IDM3.dll FF - plugin: c:\program files\opera\program\plugins\NP_IDM4.dll FF - plugin: c:\program files\opera\program\plugins\NP_IDM5.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ ---- FIREFOX POLICIES ---- FF - user.js: network.http.max-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 750 FF - user.js: content.notify.interval - 750000 FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [2009-8-19 43792] R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-12-15 33808] R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [2009-10-4 17264] R2 DeskSaverService;DeskSaverService;c:\program files\1st security agent\newlock.exe [2009-10-13 1457344] R2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [2009-8-19 73392] R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-8-10 603904] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-5-16 19472] R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [2009-7-11 154624] S2 PCMAVRTPService;PCMAV RealTime Protector Service;c:\windows\system32\rtpsvc.exe --> c:\windows\system32\RTPSvc.exe [?] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2009-7-13 36608] S3 getPlusHelper;getPlus(R) Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-3 14336] S3 NTProcDrv;Process creation detector for NT.;\??\c:\windows\temp\drv1.tmp --> c:\windows\temp\drv1.tmp [?] S3 plkusbser;PROLiNKU6 USB Device for Legacy Serial Communication;c:\windows\system32\drivers\plkusbser.sys [2009-7-11 99456] =============== Created Last 30 ================ 2009-10-17 20:24 <DIR> --d----- c:\program files\ESET 2009-10-17 15:07 265,785 a------- c:\windows\system32\pixomatic.dll 2009-10-17 15:07 161,280 a------- c:\windows\system32\fmod.dll 2009-10-17 15:07 188,416 a------- c:\windows\system32\eax.dll 2009-10-17 15:07 22,016 a------- c:\windows\system32\borlndmm.dll 2009-10-17 15:07 442,368 a------- c:\windows\system32\vp6vfw.dll 2009-10-17 15:07 <DIR> --d----- C:\Game 2009-10-16 16:49 <DIR> --d----- c:\docume~1\herman~1\applic~1\URSoft 2009-10-16 10:52 <DIR> --d----- c:\docume~1\herman~1\applic~1\Malwarebytes 2009-10-16 10:52 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-16 10:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-10-16 10:52 19,160 a------- c:\windows\system32\drivers\mbam.sys 2009-10-16 10:52 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware 2009-10-15 14:32 <DIR> a-dshr-- C:\cmdcons 2009-10-15 13:59 236,544 a------- c:\windows\PEV.exe 2009-10-15 13:59 161,792 a------- c:\windows\SWREG.exe 2009-10-15 13:59 98,816 a------- c:\windows\sed.exe 2009-10-14 11:15 <DIR> --d----- c:\program files\Real Desktop 2009-10-13 13:52 <DIR> --d----- c:\documents and settings\herman nehru\1st Security Agent 2009-10-13 13:52 <DIR> --d----- C:\1st Security Agent 2009-10-13 13:52 <DIR> --d----- c:\program files\1st Security Agent 2009-10-13 12:05 <DIR> --d----- c:\program files\HÑÑ 2009-10-13 08:28 <DIR> --d----- c:\docume~1\herman~1\applic~1\WinPatrol 2009-10-13 08:28 <DIR> --d----- c:\program files\BillP Studios 2009-10-12 00:06 <DIR> --d----- c:\program files\PowerISO 2009-10-11 23:18 <DIR> --d----- C:\[Smad-Cage] 2009-10-10 15:19 <DIR> --d----- c:\docume~1\herman~1\applic~1\The Labyrinth Plus! Edition 2009-10-10 15:19 0 a------- c:\windows\RussSqr.INI 2009-10-10 09:49 <DIR> --d----- c:\program files\Microsoft Plus! 2009-10-07 19:55 68 a------- c:\windows\MyProg.ini 2009-10-06 16:53 <DIR> --d----- c:\program files\AskPBar 2009-10-06 16:00 <DIR> --d----- c:\program files\Raxco 2009-10-04 22:14 <DIR> --d----- c:\program files\FreeCommander 2009-10-04 21:50 17,264 a------- c:\windows\system32\drivers\mprifl.sys 2009-10-04 21:50 <DIR> --d----- c:\program files\My Lockbox 2009-10-04 19:03 41,984 a------- c:\windows\system32\dwlGina3.dll 2009-10-04 19:03 3,712 a------- c:\windows\system32\dwlkbf.sys 2009-10-04 19:03 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Deskman9 2009-10-03 23:51 <DIR> --d----- c:\docume~1\herman~1\applic~1\Thinstall 2009-10-03 20:26 387,104 a--sh--- c:\windows\system32\drivers\fidbox.dat 2009-10-03 20:26 5,612 a--sh--- c:\windows\system32\drivers\fidbox.idx 2009-10-03 20:23 148,496 a------- c:\windows\system32\drivers\86909831.sys 2009-10-03 20:06 <DIR> --d----- c:\program files\Vista Start Menu 2009-09-30 23:53 604,140 a--sh--- c:\windows\system32\drivers\ISwift3.dat 2009-09-30 23:44 108,059 a------- c:\windows\system32\drivers\klin.dat 2009-09-30 23:44 95,259 a------- c:\windows\system32\drivers\klick.dat 2009-09-30 23:42 <DIR> --d----- c:\program files\Kaspersky Lab 2009-09-30 23:42 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Kaspersky Lab 2009-09-27 00:39 <DIR> --d----- c:\docume~1\alluse~1\applic~1\The Skins Factory 2009-09-26 23:54 <DIR> --d----- c:\docume~1\herman~1\applic~1\Skinux 2009-09-20 21:53 152 a------- C:\streetflyter.sav 2009-09-19 17:42 <DIR> --d----- c:\program files\Avatar - Path of Zuko 2009-09-19 13:01 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Zbshareware Lab 2009-09-19 13:01 <DIR> --d----- c:\program files\USB Disk Security 2009-09-19 12:38 <DIR> --d----- c:\docume~1\herman~1\applic~1\Merscom 2009-09-19 12:38 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Trymedia 2009-09-19 12:38 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Merscom ==================== Find3M ==================== 2009-10-01 02:03 128,016 a------- c:\windows\system32\drivers\kl1.sys 2009-09-30 23:27 4,212 a---h--- c:\windows\system32\zllictbl.dat 2009-09-13 20:41 1,580,544 a------- c:\windows\system32\SfcFiles.dll 2009-09-13 20:40 219,648 a------- c:\windows\system32\uxtheme.dll 2009-09-11 07:33 133,632 a------- c:\windows\system32\msv1_0.dll 2009-09-09 03:43 210,352 a------- c:\windows\system32\idmmbc.dll 2009-09-07 23:28 288,256 a------- c:\windows\system32\fmodex.dll 2009-09-04 13:45 58,880 a------- c:\windows\system32\msasn1.dll 2009-09-03 00:47 55,656 a------- c:\windows\system32\drivers\avgntflt.sys 2009-08-31 10:07 81,984 a------- c:\windows\system32\bdod.bin 2009-08-30 01:44 152,904 a------- c:\windows\system32\vghd.scr 2009-08-29 22:22 132 a------- C:\httpdwl.dat 2009-08-26 01:16 247,326 a------- c:\windows\system32\strmdll.dll 2009-08-21 15:51 126,464 a------- c:\windows\system32\RTPScan.dll 2009-08-17 23:33 1,193,832 a------- c:\windows\system32\FM20.DLL 2009-08-16 20:35 272,868 a------- c:\windows\system32\Windows XP Media Center Edition Screen Saver.scr 2009-08-14 19:23 25,600 a------- c:\windows\twunk_32.exe 2009-08-10 18:57 603,904 a------- c:\windows\system32\TUProgSt.exe 2009-08-10 18:57 362,240 a------- c:\windows\system32\TuneUpDefragService.exe 2009-08-06 12:38 13,537,280 a------- c:\windows\system32\nvcpl.dll 2009-08-06 11:29 69,120 a------- c:\windows\NOTEPAD.EXE 2009-08-05 02:11 204,800 a------- c:\windows\system32\mswebdvd.dll 2009-08-04 06:58 2,136,064 -------- c:\windows\system32\ntoskrnl.exe 2009-08-04 06:13 2,015,744 -------- c:\windows\system32\ntkrnlpa.exe 2009-07-27 21:01 7,852 a------- c:\windows\system32\mcdmsg7.dll 2009-03-16 14:35 525,128 a------- c:\program files\DXSETUP.exe 2009-03-16 14:35 94,024 a------- c:\program files\DSETUP.dll ============= FINISH: 7:07:16.03 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-10-13.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 7/11/2009 15:12:00 System Uptime: 10/18/2009 07:01:21 (0 hours ago) Motherboard: Acer, Inc. | | Grasmoor Processor: AMD Turion(tm) X2 Dual-Core Mobile RM-72 | Socket M2/S1G1 | 2100/133mhz Processor: AMD Turion(tm) X2 Dual-Core Mobile RM-72 | Socket M2/S1G1 | 2100/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 50 GiB total, 28.008 GiB free. D: is FIXED (NTFS) - 99 GiB total, 21.319 GiB free. F: is CDROM () G: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Ethernet Controller Device ID: PCI\VEN_14E4&DEV_1684&SUBSYS_014A1025&REV_10\4&2CBACCCA&0&0098 Manufacturer: Name: Ethernet Controller PNP Device ID: PCI\VEN_14E4&DEV_1684&SUBSYS_014A1025&REV_10\4&2CBACCCA&0&0098 Service: Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Atheros AR5B91 Wireless Network Adapter Device ID: PCI\VEN_168C&DEV_002A&SUBSYS_03031A32&REV_01\4&2C3DDF0&0&00A8 Manufacturer: Atheros Name: Atheros AR5B91 Wireless Network Adapter PNP Device ID: PCI\VEN_168C&DEV_002A&SUBSYS_03031A32&REV_01\4&2C3DDF0&0&00A8 Service: AR5416 Class GUID: Description: Device ID: ROOT\GR_AVGFWMP\SYSTEM Manufacturer: Name: PNP Device ID: ROOT\GR_AVGFWMP\SYSTEM Service: ==== System Restore Points =================== RP1: 10/15/2009 13:59:47 - System Checkpoint RP2: 10/15/2009 21:42:16 - Software Distribution Service 3.0 RP3: 10/16/2009 16:43:21 - Systweak System Optimizer Fri, Oct 16, 09 16:43 RP4: 10/16/2009 17:13:25 - Software Distribution Service 3.0 RP5: 10/17/2009 15:24:34 - Installed DirectX 9.0 RP6: 10/18/2009 01:05:58 - Software Distribution Service 3.0 ==== Installed Programs ====================== .NETSpeedBoost 6.5 Professional Edition 1st Security Agent Adobe AIR Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.1.3 Advanced System Optimizer Alky for Applications (Windows XP) Altysoft Free Video Converter 2.1 Ask Toolbar Atheros for Acer Driver 5.3.0.67_Foxconn Installation Program Avatar - Path of Zuko biohazard 4 CCleaner (remove only) Cheatbook Database 2009 Cooliris for Internet Explorer COWON Media Center - jetAudio Basic Delicious Add-on for Internet Explorer Delta Force - Black Hawk Down ESET Online Scanner v3 Foxit PDF Editor Free Unit Converter 2.11 FreeCommander 2009.02 Gadget Extractor Google Chrome HDAUDIO Soft Data Fax Modem with SmartCP Hide Folders 2009 3.2 for Windows XP/Vista Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB954550-v5) Internet Download Manager K-Lite Codec Pack 5.0.0 (Full) Kaspersky Internet Security 2010 Launch Manager LG PC Suite LG USB Modem driver Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Plus! for Windows XP Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Windows Theme Nunavut Monopoly by Parker Brothers Mozilla Firefox (3.5.3) Mozilla Thunderbird (2.0.0.22) MSXML 4.0 SP2 (KB954430) MSXML 6 Service Pack 2 (KB954459) My Lockbox 1.2 for Windows 2000/XP Need for Speed™ Most Wanted Nero 7 Essentials Norton 360 NVIDIA Drivers ObjectDock Plus Opera 10.00 PC Connectivity Solution PerfectDisk 10 Professional Photo Story 3 for Windows PHS100 Plants vs. Zombies RocketDock 1.3.5 SAMSUNG Mobile Composite Device Software SAMSUNG Mobile Modem Driver Set Samsung Mobile phone USB driver Software SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software SamsungConnectivityCableDriver Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB969679) Security Update for CAPICOM (KB931906) Security Update for Microsoft Office Excel 2007 (KB969682) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB969693) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB969604) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Snagit 9.1.2 Synaptics Pointing Device Driver TuneUp Utilities 2009 Tweak UI UberIcon 1.0.4 Uniblue DriverScanner 2009 Uniblue RegistryBooster 2009 Uniblue SpeedUpMyPC 2009 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office Outlook 2007 (KB969907) Update for Outlook 2007 Junk Email Filter (KB974810) Update for Windows Internet Explorer 8 (KB971930) USB 2.0 Card Reader USB Disk Security 5.2.0.5 VC 9.0 Runtime WebFldrs XP WIDCOMM Bluetooth Software Winamp Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0) Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0) Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0) Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows Sidebar WinPatrol 2009 WinRAR archiver WinZip 12.0 Yahoo! Widgets ==== Event Viewer Messages From Past Week ======== 10/17/2009 15:43:29, error: a347scsi [9] - 10/15/2009 14:33:49, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect. 10/15/2009 13:47:54, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Search service to connect. 10/15/2009 13:47:54, error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 10/15/2009 13:47:54, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 10/14/2009 08:18:23, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 8063561c, parameter3 b5a88a90, parameter4 00000000. 10/14/2009 08:15:46, error: Service Control Manager [7000] - The PCMAV RealTime Protector Service service failed to start due to the following error: The system cannot find the file specified. 10/13/2009 21:43:24, error: PlugPlayManager [12] - The device 'Generic volume' (STORAGE\RemovableMedia\7&d7f206a&0&RM) disappeared from the system without first being prepared for removal. 10/13/2009 21:43:24, error: PlugPlayManager [12] - The device 'Generic- Multi-Card USB Device' (USBSTOR\Disk&Ven_Generic-&Prod_Multi-Card&Rev_1.00\00000) disappeared from the system without first being prepared for removal. 10/13/2009 18:48:49, error: SideBySide [59] - Generate Activation Context failed for C:\games\Zuma's Revenge!\ZumasRevenge.exe. Reference error message: The operation completed successfully. . 10/13/2009 18:48:49, error: SideBySide [58] - Syntax error in manifest or policy file "C:\games\Zuma's Revenge!\ZumasRevenge.exe" on line 0. 10/12/2009 21:48:54, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 10/11/2009 12:27:51, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 10/11/2009 12:21:25, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 10/11/2009 12:20:58, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10/11/2009 11:03:08, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdPPM Fips IPSec kl1 klbg KLIF MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip 10/11/2009 11:03:08, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 10/11/2009 11:03:08, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. ==== End Of File =========================== Last edited by rappokalling; 10-17-2009 at 05:29 PM. |
|
|
|
|
#11 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Posts: 553
OS: N/A
|
Re: Cannot delete file AUTORUN.INF
Hello.
That's good. The log looks fine too; no active infections left. Let me know how's everything running and if all is well, we can wrap up next post. With Regards, Extremeboy |
|
|
|
|
#12 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 28
OS: xp
|
Re: Cannot delete file AUTORUN.INF
Thank you Extremeboy,
My system is running well as you said no infections are left, but anyway, the folders (AUTORUN.INF and zzzzz) still remain undeleted. I have tried to delete them several times but no result. Is there a pure system error happening here? Best Regards, |
|
|
|
|
#13 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 28
OS: xp
|
Re: Cannot delete file AUTORUN.INF
Thank you Extremeboy,
My system is running well as you said no infections are left, but anyway, the folders (AUTORUN.INF and zzzzz) still remain undeleted. I have tried to delete them several times but no result. Is there a pure system error happening here? Best Regards, |
|
|
|
|
#14 (permalink) | |
|
Analyst, Security Team
Join Date: Jan 2009
Posts: 553
OS: N/A
|
Re: Cannot delete file AUTORUN.INF
Hello.
Quote:
Could you give me the exact location of those two folders in question? We'll try to deal with that. Thanks. With Regards, Extremeboy |
|
|
|
|
|
#15 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 28
OS: xp
|
Re: Cannot delete file AUTORUN.INF
Hello,
This is the error message I received when trying to delete the folders: Folder AUTORUN.INF: Cannot delete zhengbo:Cannot find the specified file. Make sure you specify the correct path and file name. Folder zzzzz : Cannot delete uo: Cannot find the specified file. Make sure you specify the correct path and file name. Up to now, deleting the folders above cannot be done The folders are all located in drive D (My Document). Thank you Extremeboy. Best Regards, |
|
|
|
|
#16 (permalink) | |
|
Analyst, Security Team
Join Date: Jan 2009
Posts: 553
OS: N/A
|
Re: Cannot delete file AUTORUN.INF
Thanks.
Please delete your existing Combofix and download a new one. Autorun should be disabled by now when you ran flash-drive disinfector. If not, please run it again... Download and Run FlashDisinfector
Download Combofix from any of the links below, and save it to your desktop. Link 1 Link 2 Please refer to this page for full instructions on how to run ComboFix. Post the log once done. Quote:
With Regards, Extremeboy |
|
|
|
|
|
#17 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 28
OS: xp
|
Re: Cannot delete file AUTORUN.INF
Hi EB,
Yes the folders are in drive D: ... I just put its path in My Document, so whenever I open My Document, it goes to drive D. Hope it's OK. Best Regards, This is the Combo Fix scan: ComboFix 09-10-20.03 - Herman Nehru 10/22/2009 10:01.2.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1790.1204 [GMT -7:00] Running from: c:\documents and settings\Herman Nehru\Desktop\ComboFix.exe AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2009-09-22 to 2009-10-22 ))))))))))))))))))))))))))))))) . 2009-10-20 23:39 . 2009-10-20 23:39 -------- d-----w- C:\Themes 2009-10-19 04:45 . 2009-10-21 06:05 -------- d-----w- c:\program files\COED11 2009-10-18 03:24 . 2009-10-18 03:24 -------- d-----w- c:\program files\ESET 2009-10-17 22:07 . 2004-08-06 20:49 265785 ----a-w- c:\windows\system32\pixomatic.dll 2009-10-17 22:07 . 2004-10-18 21:04 161280 ----a-w- c:\windows\system32\fmod.dll 2009-10-17 22:07 . 2004-01-06 17:43 188416 ----a-w- c:\windows\system32\eax.dll 2009-10-17 22:07 . 2002-02-01 14:00 22016 ----a-w- c:\windows\system32\borlndmm.dll 2009-10-17 22:07 . 2009-10-17 22:07 -------- d-----w- C:\Game 2009-10-17 22:07 . 2004-08-18 19:34 442368 ----a-w- c:\windows\system32\vp6vfw.dll 2009-10-17 00:14 . 2009-10-17 00:14 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help 2009-10-16 23:49 . 2009-10-16 23:49 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\URSoft 2009-10-16 17:52 . 2009-10-16 17:52 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Malwarebytes 2009-10-16 17:52 . 2009-09-10 21:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-16 17:52 . 2009-10-16 17:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-10-16 17:52 . 2009-10-16 17:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-16 17:52 . 2009-09-10 21:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-14 18:15 . 2009-10-14 19:42 -------- d-----w- c:\program files\Real Desktop 2009-10-13 20:52 . 2009-10-13 20:52 -------- d-----w- c:\documents and settings\Herman Nehru\1st Security Agent 2009-10-13 20:52 . 2009-10-13 20:52 -------- d-----w- c:\documents and settings\Guest\1st Security Agent 2009-10-13 20:52 . 2009-10-13 20:52 -------- d-----w- c:\documents and settings\Administrator\1st Security Agent 2009-10-13 20:52 . 2009-10-13 20:52 -------- d-----w- C:\1st Security Agent 2009-10-13 20:52 . 2009-10-13 20:52 -------- d-----w- c:\program files\1st Security Agent 2009-10-13 19:05 . 2009-10-13 20:04 -------- d-----w- c:\program files\HÑÑ 2009-10-13 15:28 . 2009-10-13 15:28 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\WinPatrol 2009-10-13 15:28 . 2009-10-13 15:28 -------- d-----w- c:\program files\BillP Studios 2009-10-12 07:06 . 2009-10-12 07:06 -------- d-----w- c:\program files\PowerISO 2009-10-12 06:18 . 2009-10-12 06:18 -------- d-----w- C:\[Smad-Cage] 2009-10-11 18:02 . 2009-10-11 18:02 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2009-10-10 22:48 . 2009-10-10 22:48 -------- d-----w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\WMTools Downloaded Files 2009-10-10 22:19 . 2009-10-10 22:19 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\The Labyrinth Plus! Edition 2009-10-10 16:49 . 2009-10-10 16:49 -------- d-----w- c:\program files\Microsoft Plus! 2009-10-07 02:18 . 2009-10-07 02:18 -------- d-----w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\Google 2009-10-06 23:53 . 2009-10-06 23:53 -------- d-----w- c:\program files\AskPBar 2009-10-06 23:01 . 2009-10-06 23:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Raxco 2009-10-06 23:00 . 2009-10-06 23:01 -------- d-----w- c:\program files\Raxco 2009-10-05 05:14 . 2009-10-05 05:14 -------- d-----w- c:\program files\FreeCommander 2009-10-05 04:50 . 2007-12-14 03:13 17264 ----a-w- c:\windows\system32\drivers\mprifl.sys 2009-10-05 04:50 . 2009-10-05 04:50 -------- d-----w- c:\program files\My Lockbox 2009-10-05 02:03 . 2008-06-20 03:28 41984 ----a-w- c:\windows\system32\dwlGina3.dll 2009-10-05 02:03 . 2007-08-20 17:46 3712 ----a-w- c:\windows\system32\dwlkbf.sys 2009-10-05 02:03 . 2009-10-05 02:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Deskman9 2009-10-04 06:51 . 2009-10-04 06:51 -------- d-----w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\Thinstall 2009-10-04 06:51 . 2009-10-04 06:51 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Thinstall 2009-10-04 03:26 . 2009-10-04 03:31 387104 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-10-04 03:23 . 2008-07-08 21:54 148496 ----a-w- c:\windows\system32\drivers\86909831.sys 2009-10-04 03:06 . 2009-10-15 16:03 -------- d-----w- c:\program files\Vista Start Menu 2009-10-03 07:20 . 2009-10-03 07:20 -------- d-----w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\Opera 2009-10-03 07:19 . 2009-10-03 07:19 -------- d-----w- c:\program files\Opera 2009-10-01 06:53 . 2009-10-01 06:53 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat 2009-10-01 06:44 . 2009-10-15 16:02 108059 ----a-w- c:\windows\system32\drivers\klin.dat 2009-10-01 06:44 . 2009-10-15 16:02 95259 ----a-w- c:\windows\system32\drivers\klick.dat 2009-10-01 06:42 . 2009-10-22 16:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab 2009-10-01 06:42 . 2009-10-01 06:42 -------- d-----w- c:\program files\Kaspersky Lab 2009-09-27 07:39 . 2009-09-27 07:39 -------- d-----w- c:\documents and settings\All Users\Application Data\The Skins Factory 2009-09-27 06:54 . 2009-09-27 06:54 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Skinux 2009-09-27 06:45 . 2009-09-27 06:45 -------- d-----w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\Downloaded Installations . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-22 15:15 . 2009-09-15 22:55 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\IDM 2009-10-22 15:15 . 2009-07-13 19:31 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\DMCache 2009-10-18 08:08 . 2009-07-11 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-10-13 23:42 . 2009-08-16 18:02 862136 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-10-13 19:14 . 2009-07-17 18:13 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Delicious IE Extension 2009-10-10 20:24 . 2009-07-12 03:17 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-10-10 17:23 . 2009-07-20 04:25 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\SoftMaker 2009-10-10 17:22 . 2009-07-19 19:21 -------- d-----w- c:\program files\Flock 2009-10-10 17:22 . 2009-07-19 19:21 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Flock 2009-10-08 02:52 . 2009-08-24 23:49 -------- d-----w- c:\program files\Styler 2009-10-08 02:51 . 2009-08-23 10:29 -------- d-----w- c:\program files\Gish 2009-10-08 02:50 . 2009-07-14 16:29 -------- d-----w- c:\program files\Mobile Partner 2009-10-06 04:45 . 2009-09-15 22:54 -------- d-----w- c:\program files\Internet Download Manager 2009-10-04 03:31 . 2009-10-04 03:26 5612 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-10-04 01:10 . 2009-07-20 05:06 -------- d-----w- c:\program files\Windows Sidebar 2009-10-01 09:03 . 2009-05-24 22:30 128016 ----a-w- c:\windows\system32\drivers\kl1.sys 2009-10-01 06:38 . 2009-09-09 22:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files 2009-10-01 06:27 . 2009-08-18 22:13 4212 ---ha-w- c:\windows\system32\zllictbl.dat 2009-10-01 06:26 . 2009-09-03 05:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira 2009-09-28 06:44 . 2009-09-12 06:35 -------- d-----w- c:\program files\Youda Camper 2009-09-20 00:42 . 2009-09-20 00:42 -------- d-----w- c:\program files\Avatar - Path of Zuko 2009-09-19 20:04 . 2009-09-19 20:01 -------- d-----w- c:\program files\USB Disk Security 2009-09-19 20:01 . 2009-09-19 20:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Zbshareware Lab 2009-09-19 19:38 . 2009-09-19 19:38 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Merscom 2009-09-19 19:38 . 2009-09-19 19:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Trymedia 2009-09-19 19:38 . 2009-09-19 19:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Merscom 2009-09-18 23:24 . 2009-08-08 20:38 -------- d-----w- c:\program files\Altysoft Free Video Converter 2009-09-15 04:51 . 2009-08-17 19:46 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-09-15 04:05 . 2009-09-15 04:05 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\360desktop 2009-09-14 03:41 . 2004-08-03 22:56 1580544 ----a-w- c:\windows\system32\SfcFiles.dll 2009-09-14 03:40 . 2004-08-03 22:56 219648 ----a-w- c:\windows\system32\uxtheme.dll 2009-09-14 01:17 . 2009-09-14 01:17 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2009-09-14 00:56 . 2009-09-14 00:52 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-09-14 00:56 . 2009-09-14 00:56 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan 2009-09-14 00:52 . 2009-09-14 00:52 -------- d-----w- c:\program files\NOS 2009-09-13 23:25 . 2009-08-02 16:47 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\PlayFirst 2009-09-13 23:25 . 2009-08-02 16:47 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst 2009-09-13 04:44 . 2009-09-13 04:44 -------- d-----w- c:\program files\Appwalk.com Technologies Canada 2009-09-12 15:44 . 2009-08-03 17:12 -------- d-----w- c:\program files\Microsoft Silverlight 2009-09-11 14:33 . 2004-08-03 22:56 133632 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-09 10:43 . 2009-09-16 12:26 210352 ----a-w- c:\windows\system32\idmmbc.dll 2009-09-08 06:28 . 2009-09-08 06:28 288256 ----a-w- c:\windows\system32\fmodex.dll 2009-09-08 01:23 . 2009-09-08 01:21 -------- d-----w- c:\program files\Cheatbook Database 2009 2009-09-05 18:39 . 2009-09-05 18:39 -------- d-----w- c:\documents and settings\All Users\Application Data\PopCap Games 2009-09-05 18:39 . 2009-07-12 00:49 -------- d-----w- c:\program files\PopCap Games 2009-09-05 03:04 . 2009-09-04 18:15 -------- d-----w- c:\program files\Training Manager 2008 Enterprise 2009-09-05 02:55 . 2009-09-05 02:55 -------- d-----w- c:\documents and settings\Guest\Application Data\Windows Desktop Search 2009-09-04 22:13 . 2009-08-30 09:03 7 ----a-w- c:\windows\sbacknt.bin 2009-09-04 20:45 . 2004-08-03 22:56 58880 ----a-w- c:\windows\system32\msasn1.dll 2009-09-04 18:15 . 2009-09-04 18:15 -------- d-----w- c:\documents and settings\All Users\Application Data\TrainingManager 2009-09-03 21:59 . 2009-07-12 00:40 -------- d-----w- c:\program files\Tumblebugs 2 2009-09-03 07:47 . 2009-09-03 05:54 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-09-02 16:47 . 2009-09-02 16:24 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\CheckPoint 2009-09-01 23:25 . 2009-07-12 01:36 -------- d-----w- c:\program files\Mozilla Firefox 3.5 Beta 4 2009-09-01 06:21 . 2009-09-01 06:21 -------- d-----w- c:\program files\Alwil Software 2009-08-31 19:13 . 2009-07-12 00:22 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Ahead 2009-08-31 17:21 . 2009-08-31 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET 2009-08-31 17:09 . 2009-08-29 22:30 -------- d-----w- c:\program files\Common Files\BitDefender 2009-08-31 17:07 . 2009-08-30 05:21 81984 ----a-w- c:\windows\system32\bdod.bin 2009-08-31 01:19 . 2009-08-31 01:19 -------- d-----w- c:\program files\MSXML 4.0 2009-08-31 00:05 . 2009-08-30 08:44 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\vghd 2009-08-30 08:44 . 2009-08-30 08:34 152904 ----a-w- c:\windows\system32\vghd.scr 2009-08-30 05:22 . 2009-08-30 05:22 132 ----a-w- C:\httpdwl.dat 2009-08-30 05:07 . 2009-07-17 05:12 -------- d-----w- c:\documents and settings\All Users\Application Data\SecTaskMan 2009-08-29 08:08 . 2004-08-03 22:56 916480 ----a-w- c:\windows\system32\wininet.dll 2009-08-26 08:16 . 2004-08-03 22:56 247326 ----a-w- c:\windows\system32\strmdll.dll 2009-08-25 00:08 . 2009-08-11 18:46 -------- d-----w- c:\program files\Common Files\Ulead Systems 2009-08-25 00:08 . 2009-08-11 18:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Ulead Systems 2009-08-24 23:54 . 2009-08-24 23:54 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\Styler 2009-08-24 19:15 . 2009-08-24 16:25 -------- d-----w- c:\program files\LockHunter 2009-08-24 18:33 . 2009-08-24 18:33 -------- d-----w- c:\program files\Stardock 2009-08-24 16:25 . 2009-08-24 16:25 -------- d-----w- c:\documents and settings\Herman Nehru\Application Data\LockHunter 2009-08-21 22:51 . 2009-07-11 20:49 126464 ----a-w- c:\windows\system32\RTPScan.dll 2009-08-21 05:35 . 2009-07-11 22:59 76528 ----a-w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-08-19 04:46 . 2009-08-14 16:50 2119680 ----a-w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\cooliris-win-ie-release-1.11.2.27471.en-US.msi 2009-08-19 02:38 . 2009-08-17 06:06 10 ----a-w- c:\windows\popcinfo.dat 2009-08-18 06:33 . 2009-08-18 06:33 1193832 ----a-w- c:\windows\system32\FM20.DLL 2009-08-17 03:35 . 2009-08-17 03:35 272868 ----a-w- c:\windows\system32\Windows XP Media Center Edition Screen Saver.scr 2009-08-15 02:23 . 2001-08-23 11:00 25600 ----a-w- c:\windows\twunk_32.exe 2009-08-11 01:57 . 2009-08-11 01:57 603904 ----a-w- c:\windows\system32\TUProgSt.exe 2009-08-11 01:57 . 2009-08-11 01:57 362240 ----a-w- c:\windows\system32\TuneUpDefragService.exe 2009-08-07 02:24 . 2009-07-11 22:07 327896 ----a-w- c:\windows\system32\wucltui.dll 2009-08-07 02:24 . 2009-07-11 22:07 209632 ----a-w- c:\windows\system32\wuweb.dll 2009-08-07 02:24 . 2009-07-19 23:38 44768 ----a-w- c:\windows\system32\wups2.dll 2009-08-07 02:24 . 2009-07-11 22:07 35552 ----a-w- c:\windows\system32\wups.dll 2009-08-07 02:24 . 2009-07-11 22:07 53472 ----a-w- c:\windows\system32\wuauclt.exe 2009-08-07 02:24 . 2004-08-03 22:56 96480 ----a-w- c:\windows\system32\cdm.dll 2009-08-07 02:23 . 2009-07-11 22:07 575704 ----a-w- c:\windows\system32\wuapi.dll 2009-08-07 02:23 . 2009-07-26 04:45 274288 ----a-w- c:\windows\system32\mucltui.dll 2009-08-07 02:23 . 2009-07-11 22:07 1929952 ----a-w- c:\windows\system32\wuaueng.dll 2009-08-07 02:23 . 2008-10-16 21:07 215920 ----a-w- c:\windows\system32\muweb.dll 2009-08-06 19:38 . 2008-05-29 11:41 13537280 ----a-w- c:\windows\system32\nvcpl.dll 2009-08-06 18:29 . 2009-07-11 14:58 69120 ----a-w- c:\windows\NOTEPAD.EXE 2009-08-05 09:11 . 2004-08-03 22:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-08-04 13:58 . 2004-08-03 21:18 2136064 ------w- c:\windows\system32\ntoskrnl.exe 2009-08-04 13:13 . 2004-08-03 22:59 2015744 ------w- c:\windows\system32\ntkrnlpa.exe 2009-07-28 04:01 . 2009-07-28 04:01 7852 ----a-w- c:\windows\system32\mcdmsg7.dll 2009-07-27 02:43 . 2009-07-27 02:43 58908 ----a-w- c:\windows\system32\drivers\scdemu.sys 2009-07-27 02:32 . 2009-07-27 02:32 46 ----a-w- c:\windows\system32\DonationCoder_desktopcoral_InstallInfo.dat 2009-07-27 02:32 . 2009-07-27 02:32 46 ----a-w- c:\documents and settings\Herman Nehru\Local Settings\Application Data\DonationCoder_desktopcoral_InstallInfo.dat . ------- Sigcheck ------- [-] 2009-09-14 . 1186FB2F052E4890C6C23F420F4BE1BC . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\SfcFiles.dll [-] 2009-09-14 . 1186FB2F052E4890C6C23F420F4BE1BC . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\sfcfiles.dll [-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\sfcfiles.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-10-06 3118512] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2007-07-28 1230848] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-06 13537280] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-29 86016] "AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248] "LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-06-05 821768] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-12 1028096] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "USB Antivirus"="c:\program files\USB Disk Security\USBGuard.exe" [2009-09-12 811008] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-05-25 303376] "flockbox"="c:\program files\My Lockbox\flockbox.exe" [2007-12-14 1071472] "WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832] "00saskda"="c:\program files\1st Security Agent\newlock.exe" [2009-06-18 1457344] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-29 1630208] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-05-13 16862720] c:\documents and settings\Administrator\Start Menu\Programs\Startup\ Hyperdesk_uninst0.lnk - c:\documents and settings\All Users\Application Data\The Skins Factory\Hyperdesk\HyperdeskEngine.exe [2009-9-27 1273856] c:\documents and settings\Guest\Start Menu\Programs\Startup\ Hyperdesk_uninst0.lnk - c:\documents and settings\All Users\Application Data\The Skins Factory\Hyperdesk\HyperdeskEngine.exe [2009-9-27 1273856] c:\documents and settings\Herman Nehru\Start Menu\Programs\Startup\ Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2009-8-24 3581680] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-9-11 576104] Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "HideFastUserSwitching"= 0 (0x0) "HideShutdownScripts"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoStartMenuMyMusic"= 0 (0x0) "NoSMMyPictures"= 0 (0x0) "NoWelcomeScreen"= 0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoChangeAnimation"= 0 (0x0) "RestrictCpl"= 0 (0x0) "DisallowCpl"= 0 (0x0) "RestrictRun"= 0 (0x0) "ForceRecycleBinSize"= 0 (0x0) "NoCustomizeWebView"= 0 (0x0) "NoFileAssociate"= 0 (0x0) "NoDFSTab"= 0 (0x0) "NoCustomizeThisFolder"= 0 (0x0) "NoWebView"= 0 (0x0) "DontShowSuperHidden"= 0 (0x0) "NoOnlinePrintsWizard"= 0 (0x0) "NoPublishingWizard"= 0 (0x0) "NoSMConfigurePrograms"= 0 (0x0) "NoSMMyPictures"= 0 (0x0) "NoStartMenuMyMusic"= 0 (0x0) "NoHelp"= 0 (0x0) "NoCommonGroups"= 0 (0x0) "NoStartMenuEjectPC"= 0 (0x0) "NoSimpleStartMenu"= 0 (0x0) "NoStartMenuSubFolders"= 0 (0x0) "NoDisconnect"= 0 (0x0) "NoNtSecurity"= 0 (0x0) "GreyMSIAds"= 0 (0x0) "ForceMaxRecentDocs"= 0 (0x0) "NoSMBalloonTip"= 0 (0x0) "NoSMBalloonTips"= 0 (0x0) "HideSCAVolume"= 0 (0x0) "HideSCANetwork"= 0 (0x0) "HideSCAPower"= 0 (0x0) "NoTaskGrouping"= 0 (0x0) "NoWebServices"= 0 (0x0) "NoFileUrl"= 0 (0x0) "SpecifyDefaultButtons"= 0 (0x0) "NoRecentDocsNetHood"= 0 (0x0) "PromptRunasInstallNetPath"= 1 (0x1) "NoResolveTrack"= 0 (0x0) "NoDevMgrUpdate"= 0 (0x0) "NoThumbnailCache"= 1 (0x1) "ForceCopyAclwithFile"= 0 (0x0) "StartRunNoHOMEPATH"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient] 2005-01-31 22:13 49152 ----a-w- c:\progra~1\COMMON~1\Stardock\MCPStub.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk * [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\fsproflt] @="Service" [HKLM\~\startupfolder\C:^Documents and Settings^Herman Nehru^Start Menu^Programs^Startup^DesktopVideoPlayer.LNK] backup=c:\windows\pss\DesktopVideoPlayer.LNKStartup [HKLM\~\startupfolder\C:^Documents and Settings^Herman Nehru^Start Menu^Programs^Startup^Styler.lnk] backup=c:\windows\pss\Styler.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [8/19/2009 22:23 43792] R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [12/15/2008 20:41 33808] R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [10/4/2009 21:50 17264] R2 DeskSaverService;DeskSaverService;c:\program files\1st Security Agent\newlock.exe [10/13/2009 13:52 1457344] R2 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [8/19/2009 22:23 73392] R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [8/10/2009 18:57 603904] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [5/16/2009 20:59 19472] R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [7/11/2009 15:28 154624] S2 PCMAVRTPService;PCMAV RealTime Protector Service;c:\windows\system32\RTPSvc.exe --> c:\windows\system32\RTPSvc.exe [?] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [7/13/2009 18:21 36608] S3 getPlusHelper;getPlus(R) Helper;c:\windows\System32\svchost.exe -k getPlusHelper [8/3/2004 15:56 14336] S3 NTProcDrv;Process creation detector for NT.;\??\c:\windows\TEMP\drv1.tmp --> c:\windows\TEMP\drv1.tmp [?] S3 plkusbser;PROLiNKU6 USB Device for Legacy Serial Communication;c:\windows\system32\drivers\plkusbser.sys [7/11/2009 15:56 99456] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] getPlusHelper REG_MULTI_SZ getPlusHelper HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}] "c:\program files\Windows Sidebar\sidebar.exe" /RegServer . Contents of the 'Scheduled Tasks' folder 2009-10-22 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 23:28] 2009-10-22 c:\windows\Tasks\User_Feed_Synchronization-{E3CD1275-2939-4B63-B05D-BE902B8818D5}.job - c:\windows\system32\msfeedssync.exe [2007-08-14 11:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.id/ IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm FF - ProfilePath - c:\documents and settings\Herman Nehru\Application Data\Mozilla\Firefox\Profiles\nk4rik1i.default\ FF - prefs.js: keyword.URL - hxxp://ide.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_ide&p= FF - component: c:\documents and settings\Herman Nehru\Application Data\IDM\idmmzcc3\components\idmmzcc.dll FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll FF - plugin: c:\documents and settings\Herman Nehru\Application Data\Mozilla\Firefox\Profiles\nk4rik1i.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll FF - plugin: c:\progra~1\Mozilla Firefox\plugins\np_gp.dll FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\Mozilla Firefox 3.5 Beta 4\plugins\NPOFF12.DLL FF - plugin: c:\program files\Mozilla Firefox 3.5 Beta 4\plugins\nppl3260.dll FF - plugin: c:\program files\Mozilla Firefox 3.5 Beta 4\plugins\nprpjplug.dll FF - plugin: c:\program files\Mozilla Firefox 3.5 Beta 4\plugins\npyaxmpb.dll FF - plugin: c:\program files\Opera\program\plugins\NP_IDM1.dll FF - plugin: c:\program files\Opera\program\plugins\NP_IDM2.dll FF - plugin: c:\program files\Opera\program\plugins\NP_IDM3.dll FF - plugin: c:\program files\Opera\program\plugins\NP_IDM4.dll FF - plugin: c:\program files\Opera\program\plugins\NP_IDM5.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: network.http.max-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 750 FF - user.js: content.notify.interval - 750000 FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: yahoo.homepage.dontask - true. ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-22 10:07 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NTProcDrv] "ImagePath"="\??\c:\windows\TEMP\drv1.tmp" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] @Denied: (Full) (Everyone) "scansk"=hex(0):87,2d,c3,ce,b9,a4,9b,4f,ee,59,ba,03,35,42,2d,61,ea,34,96,06,2c, 65,99,e3,86,40,49,42,37,54,ca,4e,6c,0e,a2,93,7a,c4,10,02,00,00,00,00,00,00,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{fc28d12f-953c-4768-98c7-cebe59a1a05e}] @Denied: (Full) (Everyone) "Model"=dword:00000106 "Therad"=dword:0000000e "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d, df,1c,2f,3b,8a,0a,32,11,89,01,b5,d6,31,95,fc,65,93,df,8b,66,88,7c,1a,78,15,\ . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(612) c:\progra~1\COMMON~1\Stardock\mcpstub.dll - - - - - - - > 'explorer.exe'(220) c:\windows\system32\WININET.dll c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll c:\windows\system32\btmmhook.dll c:\progra~1\WINDOW~2\wmpband.dll c:\program files\Windows Desktop Search\deskbar.dll c:\program files\Windows Desktop Search\en-us\dbres.dll.mui c:\program files\Windows Desktop Search\dbres.dll c:\program files\Windows Desktop Search\wordwheel.dll c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui c:\program files\Windows Desktop Search\msnlExtRes.dll c:\windows\system32\ieframe.dll c:\progra~1\COMMON~1\Stardock\MCPCore.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2009-10-22 10:09 ComboFix-quarantined-files.txt 2009-10-22 17:09 ComboFix2.txt 2009-10-15 21:51 Pre-Run: 29,230,592,000 bytes free Post-Run: 29,219,909,632 bytes free - - End Of File - - 4C80E8FA2255AE328BB61ACEEDCBCD4D |
|
|
|
|
#18 (permalink) |
|
Analyst, Security Team
Join Date: Jan 2009
Posts: 553
OS: N/A
|
Re: Cannot delete file AUTORUN.INF
Hello.
To make things easy first, let's try using this tool and see if it can remove those two folders, if not then we'll see what we can do afterwards. Download and install this tool here: http://ccollomb.free.fr/unlocker/ Then try to "unlock" (delete) those folders. Reboot your computer and let me know how it goes. ~EB |
|
|
|
|
#19 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 28
OS: xp
|
Re: Cannot delete file AUTORUN.INF
Hello EB,
I've tried the Unlocker and it managed to delete folder AUTORUN.INF but failed to delete the other folder zzzzz. ..... What a stubborn folder! What might cause this folder undeleted? Such annoying folder but interesting to find out why ... I still wish you can help me out here. Best Regards, |
|
|
|
|
#20 (permalink) | |
|
Analyst, Security Team
Join Date: Jan 2009
Posts: 553
OS: N/A
|
Re: Cannot delete file AUTORUN.INF
Hi.
Quote:
Appears to be some permission on the folder. We'll see. ~EB |
|
|
|
| Thread Tools | |
|
|