Mal_Otorun1 [RESOLVED] |
![]() ![]() |
Mal_Otorun1 [RESOLVED] |
Oct 4 2008, 06:19 AM
Post
#1
|
|
|
New Member ![]() Posts: 4 OS: XP |
I'm running Trend Micro and it's up to date. Every 5 seconds or so it comes up with a warning: infected file: D:\autorun.inf Name: Mal_Otorun1 Action taken: remove this file I changed it from quarantine because it was filling up so fast with these files so now it auto-deletes them. When I look in the D: drive - there is nothing there. I have everything in the C drive. I cannot see a link for 'show hidden files' although I can see there is 1gig or so of stuf in the D drive. I have followed steps 1-4 before posting this log.... Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:22:01, on 04/10/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\system32\brsvc01a.exe C:\WINDOWS\system32\brss01a.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe C:\Program Files\Trend Micro\Internet Security\TmProxy.exe C:\Program Files\Apoint\Apoint.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\ICO.EXE C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Sony\VAIO Power Management\SPMgr.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\system32\WDBtnMgr.exe C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Huawei technologies\Mobile Connect\HuaWeiEVDO.exe C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Google\Google Updater\GoogleUpdater.exe C:\Program Files\Google\Google Updater\2.4.1368.5602\GoogleUpdaterInstallMgr.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\wuauclt.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/ O15 - Trusted Zone: *.remote.boosey.com O15 - Trusted Zone: remote.boosey.com O15 - Trusted Zone: *.boosey.com O15 - Trusted Zone: *.sony-europe.com O15 - Trusted Zone: *.sonystyle-europe.com O15 - Trusted Zone: *.vaio-link.com O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - https://remote.boosey.com/CitrixSessionInit...AWEB/icaweb.cab O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://access.boosey.com/dana-cached/setup...oterisSetup.cab O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6416C78A-E810-445C-8712-1785809FA433} (CCAOControl Object) - https://remote.boosey.com/CitrixLogonPoint/...t/EPAClient.exe O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {6E48946B-934D-47F5-865E-546711F2D423} - https://remote.boosey.com/CitrixFEI/Cabs/LiveEdit.exe O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{B3C17C89-6126-400D-B0E0-AD0EA57C3D75}: NameServer = 41.221.96.67 41.221.96.68 O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe -- End of file - 14244 bytes |
|
|
Oct 4 2008, 09:23 AM
Post
#2
|
|
|
Malware Expert Posts: 15,811 From: New York OS: Windows 98, XP, Vista, Mac OS X |
Welcome to GTG.
Download the Flash Disinfector at http://www.techsupportforum.com/sectools/s...Disinfector.exe and save it to your desktop. Double-click on it to run it and follow the on-screen instructions. 1. Download combofix at http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe or http://download.bleepingcomputer.com/sUBs/ComboFix.exe Save it to your Desktop before you run it. 2. Double-click combofix.exe & follow the prompts. 3. When finished, it will produce a log for you. Post that log in your next reply. Note: Do not click on combofix's window while it's running. That may cause it to stall. |
|
|
Oct 6 2008, 01:25 AM
Post
#3
|
|
|
New Member ![]() Posts: 4 OS: XP |
Hi
I have run the flash disinfector on all external drives and flash USB pens. I have also run Malwarebytes' anti-malware across everything. Since then it seems to have worked (?!) because trend is no longer flashing up the Mal_otorun1 warning every 10seconds. I have tried downloading the ComboFix program but Trend hates it. According to Trend software on my computer it carries a very dangerous trojan virus. So I have deleted this for now pending further instructions.. many thanks for your help so far! M |
|
|
Oct 6 2008, 05:53 PM
Post
#4
|
|
|
Malware Expert Posts: 15,811 From: New York OS: Windows 98, XP, Vista, Mac OS X |
Can you add Combofix to be one of the files to exclude or in the exceptions list? If not, disable TrendMicro and download Combofix. Disconnect from the internet once you do this and then run Combofix. Post the log here when ready.
|
|
|
Oct 7 2008, 08:59 AM
Post
#5
|
|
|
New Member ![]() Posts: 4 OS: XP |
OK thanks. Done it. Here you go:
ComboFix 08-10-05.05 - Michael Shaw 2008-10-07 16:47:34.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.508 [GMT 2:00] Running from: C:\Documents and Settings\Michael Shaw\Desktop\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ADS - WINDOWS: deleted 24 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\yew.bat D:\otyh.cmd D:\yew.bat . ((((((((((((((((((((((((( Files Created from 2008-09-07 to 2008-10-07 ))))))))))))))))))))))))))))))) . 2008-11-01 10:12 . 2008-11-01 10:12 <DIR> d----c--- C:\Documents and Settings\Michael Shaw\Application Data\dvdcss 2008-10-30 17:28 . 2008-10-30 17:40 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak 2008-10-07 14:12 . 2008-10-07 14:12 <DIR> d--hsc--- C:\Documents and Settings\Michael Shaw\UserData 2008-10-06 14:48 . 2008-10-06 14:48 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2 2008-10-06 09:03 . 2008-07-18 22:07 270,880 --a------ C:\WINDOWS\system32\mucltui.dll 2008-10-06 09:03 . 2008-07-18 22:07 29,728 --a------ C:\WINDOWS\system32\mucltui.dll.mui 2008-10-04 15:35 . 2008-10-04 15:35 0 --a------ C:\WINDOWS\system32\drivers\trrb.sys 2008-10-04 15:29 . 2008-10-04 15:29 <DIR> d-------- C:\Program Files\ERUNT 2008-10-04 15:08 . 2008-10-04 15:08 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-10-04 15:08 . 2008-10-04 15:08 <DIR> d----c--- C:\Documents and Settings\Michael Shaw\Application Data\Malwarebytes 2008-10-04 15:08 . 2008-10-04 15:08 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-10-04 15:08 . 2008-09-10 01:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-10-04 15:08 . 2008-09-10 01:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-10-04 15:06 . 2008-10-04 15:06 <DIR> d-------- C:\Program Files\Common Files\Download Manager 2008-10-04 13:43 . 2008-10-04 13:43 <DIR> d-------- C:\Program Files\Google 2008-10-04 13:43 . 2008-10-07 07:48 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Google Updater 2008-10-04 13:17 . 2008-10-04 15:36 <DIR> d-------- C:\WINDOWS\SxsCaPendDel 2008-10-04 11:30 . 2008-10-04 11:30 42,273,429 --a------ C:\Temp\3420-enu-win2k_xp.zip 2008-10-02 11:56 . 2008-10-02 11:56 16,384 --a------ C:\WINDOWS\DCEBoot.exe 2008-09-29 09:16 . 2008-09-29 09:16 <DIR> d-------- C:\Program Files\Huawei technologies 2008-09-29 09:16 . 2006-06-21 22:29 65,152 --a------ C:\WINDOWS\system32\drivers\ewusbser.sys 2008-09-29 09:16 . 2006-06-21 22:29 65,152 --a------ C:\WINDOWS\system32\drivers\ewusbmdm.sys 2008-09-29 09:16 . 2006-06-21 22:29 65,152 --a------ C:\WINDOWS\system32\drivers\ewusbapp.sys 2008-09-29 09:16 . 2004-08-04 00:08 17,024 --a------ C:\WINDOWS\system32\drivers\usbohci.sys 2008-09-29 09:16 . 2004-08-04 00:08 17,024 --a--c--- C:\WINDOWS\system32\dllcache\usbohci.sys 2008-09-27 11:25 . 2008-09-29 13:36 <DIR> d----c--- C:\Documents and Settings\Michael Shaw\Application Data\ZTEEVDO . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-10-05 09:58 --------- d-----w C:\Program Files\Duplicate Finder 2008-10-04 12:19 --------- d-----w C:\Program Files\Trend Micro 2008-10-04 11:17 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-10-04 10:16 --------- d-----w C:\Program Files\Sony 2008-09-04 07:10 --------- dc----w C:\Documents and Settings\Michael Shaw\Application Data\Netscape 2008-09-04 07:10 --------- dc----w C:\Documents and Settings\Michael Shaw\Application Data\Citrix 2008-09-03 19:38 --------- dc----w C:\Documents and Settings\All Users\Application Data\Seagate 2008-09-03 19:37 --------- d-----w C:\Program Files\MSXML 6.0 2008-08-23 18:31 --------- d-----w C:\Program Files\iTunes 2008-08-23 18:31 --------- d-----w C:\Program Files\iPod 2008-08-23 18:23 --------- dc--a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-08-16 15:40 --------- d-----w C:\Program Files\Handbrake 2008-08-15 17:41 --------- dc----w C:\Documents and Settings\Michael Shaw\Application Data\DivX 2008-08-13 20:19 --------- d-----w C:\Program Files\Microsoft Works 2008-08-13 20:19 --------- d-----w C:\Program Files\Common Files\Sonic Shared 2008-08-13 20:18 --------- d-----w C:\Program Files\hp deskjet 3420 series 2008-08-13 19:17 --------- d-----w C:\Program Files\Java 2008-08-12 22:07 --------- d-----w C:\Program Files\Apple Software Update 2008-08-10 18:34 --------- dc----w C:\Documents and Settings\Michael Shaw\Application Data\vlc 2008-08-10 18:29 --------- d-----w C:\Program Files\VideoLAN 2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll 2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe 2008-07-18 21:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll 2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll 2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll 2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll 2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll 2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll 2008-07-18 21:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll 2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll 2007-04-23 10:17 3,606,784 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_19509473.reg 2007-02-14 22:39 3,558,928 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_1760304.reg 2007-01-31 15:00 3,559,350 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_12159142.reg 2006-12-30 10:52 3,555,478 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_16805237.reg 2006-12-29 11:05 3,555,478 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_26392982.reg 2006-09-11 18:39 3,537,406 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_2814081.reg 2006-09-11 09:58 3,537,406 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_18734302.reg 2006-07-25 13:13 3,523,584 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_29987161.reg 2006-07-23 13:28 3,522,632 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_15582114.reg 2006-07-10 09:33 3,519,662 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_3912376.reg 2006-06-19 17:31 3,518,696 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_26194423.reg 2006-06-08 21:41 3,513,310 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_7652266.reg 2006-05-01 19:02 3,502,578 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_4729123.reg 2006-04-29 01:44 3,499,882 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_23503403.reg 2006-04-28 01:32 3,499,882 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_18926678.reg 2006-04-24 00:22 3,498,570 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_19736127.reg 2006-04-21 16:29 3,498,570 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_10690075.reg 2006-04-21 02:50 3,498,570 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_1117233.reg 2006-04-19 22:43 3,498,518 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_28420709.reg 2006-04-17 18:20 3,497,994 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_10711912.reg 2006-04-17 18:09 3,497,994 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_471035.reg 2006-03-27 21:49 3,465,370 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_30911772.reg 2006-03-25 18:43 3,437,704 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_31476927.reg 2006-03-25 17:21 3,437,782 -c--a-w C:\Documents and Settings\Michael Shaw\neoteris_read_5612344.reg . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15360] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208] "OE"="C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2008-03-07 492808] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [X] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-29 7335936] "Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-11-17 118784] "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512] "VAIOCameraUtility"="C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-01 69632] "SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2005-11-28 217088] "ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768] "Switcher.exe"="C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-11-24 167936] "VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-11 151552] "Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2005-03-03 483328] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-05-14 188416] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-22 180269] "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-03-19 228088] "UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024] "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 413696] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064] "Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 C:\WINDOWS\system32\ico.exe] "WD Button Manager"="WDBtnMgr.exe" [2007-12-12 C:\WINDOWS\system32\WDBtnMgr.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 15360] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon] 2005-05-20 19:42 73728 C:\WINDOWS\system32\VESWinlogon.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll "msacm.ac3filter"= ac3filter.acm "vidc.hfyu"= huffyuv.dll "msacm.divxa32"= DivXa32.acm "msacm.l3codec"= l3codecp.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe"= "C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 7520337] R3 hwcdcmdm0;HUAWEI Mobile Connect - 3G Modem;C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2006-06-21 65152] R3 hwusbapp;HUAWEI Mobile Connect - 3G PC UI Interface;C:\WINDOWS\system32\DRIVERS\ewusbapp.sys [2006-06-21 65152] R3 hwusbser;HUAWEI Mobile Connect - 3G Application Interface;C:\WINDOWS\system32\DRIVERS\ewusbser.sys [2006-06-21 65152] R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2005-10-04 217472] S3 RimSerPort;RIM Virtual Serial Port;C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 26496] S3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2005-11-30 28800] S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 311872] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{530ede5c-8df6-11dd-846f-0013020db7e6}] \Shell\AutoRun\command - G:\fe.bat \Shell\explore\Command - G:\ \Shell\open\Command - G:\fe.bat [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57acc898-6423-11db-836d-0013a90ebe60}] \Shell\AutoRun\command - G:\fe.bat \Shell\explore\Command - G:\fe.bat \Shell\open\Command - G:\fe.bat [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0e80c08-79ef-11dd-8465-0013a90ebe60}] \Shell\AutoRun\command - H:\Launch.exe /run [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb391169-a8c1-11dc-8411-0013a90ebe60}] \Shell\AutoRun\command - G:\wd_windows_tools\setup.exe *Newly Created Service* - PROCEXP90 . Contents of the 'Scheduled Tasks' folder 2008-09-09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34] 2008-10-04 C:\WINDOWS\Tasks\User_Feed_Synchronization-{7011CBC4-158F-4880-9485-C114101B1A8C}.job - C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 13:58] . . ------- Supplementary Scan ------- . FireFox -: Profile - C:\Documents and Settings\Michael Shaw\Application Data\Mozilla\Firefox\Profiles\ska6qstr.default\ . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-10-07 16:51:00 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ASP.NET] "ImagePath"="" . Completion time: 2008-10-07 16:53:05 ComboFix-quarantined-files.txt 2008-10-07 14:52:59 Pre-Run: 25,700,913,152 bytes free Post-Run: 26,194,882,560 bytes free 205 --- E O F --- 2008-10-06 12:48:56 |
|
|
Oct 7 2008, 10:51 AM
Post
#6
|
|
|
Malware Expert Posts: 15,811 From: New York OS: Windows 98, XP, Vista, Mac OS X |
Good job. Your log is clean.
To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided. Are there any problems now? If none, go to Start->Run, copy/paste in combofix /u and hit OK to remove it. You should be set to go. |
|
|
Oct 8 2008, 03:51 AM
Post
#7
|
|
|
New Member ![]() Posts: 4 OS: XP |
great - thanks very much!!!!!!!!!!
|
|
|
Oct 8 2008, 07:44 PM
Post
#8
|
|
|
Malware Expert Posts: 15,811 From: New York OS: Windows 98, XP, Vista, Mac OS X |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
36 / 762 | 53 minutes ago SKousik started - last by Rorschach112 |
|||||
![]() |
28 / 1,626 | 19th September 2008 - 02:57 AM ih8orangepezzz started - last by Mike |
|||||
![]() |
10 / 1,476 | 28th September 2008 - 10:13 AM chromejael started - last by Essexboy |
|||||
![]() |
26 / 216 | Today, 03:55 PM ricci_27 started - last by Jimmy2012 |
|||||
|
Time is now: 2nd December 2008 - 05:38 PM |
| Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. |