Google redirect and MSN messenger automatically logs off [Solved], Malware removal |
![]() ![]() |
Google redirect and MSN messenger automatically logs off [Solved], Malware removal |
Jul 13 2009, 04:44 PM
Post
#1
|
|
|
New Member ![]() Posts: 6 OS: windows XP |
Hi,
I am new to this so please bare with me. Currently my google easerch results end up being redirected if I click on the link but if I open in a new window it seems ok. Real pain the behind I must say! Also my MSn messenger when I log into it it logs on and then automatically logs me off (in les than a minute). Can you please help me with this as I have looked at other places and no one can seem to figure it out! When I ran Malwarebytes most recently this is the log file I got: Malwarebytes' Anti-Malware 1.38 Database version: 2297 Windows 5.1.2600 Service Pack 3 7/13/2009 5:42:56 PM mbam-log-2009-07-13 (17-42-56).txt Scan type: Quick Scan Objects scanned: 172268 Time elapsed: 25 minute(s), 37 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Delete on reboot. After the rebott it still redirects my google search. Also note that I had to rename Mbam in order to run the program. Thanks, C |
|
|
Jul 13 2009, 04:53 PM
Post
#2
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
hi
Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall** |
|
|
Jul 13 2009, 06:27 PM
Post
#3
|
|
|
New Member ![]() Posts: 6 OS: windows XP |
Thanks for the quick response!
Here is my Combo-Fix file: Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1021.648 [GMT -4:00] Running from: c:\old comp\Combo-Fix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\recycler\S-1-5-21-1250142486-3434264103-3943782276-500 c:\windows\system32\dbxDgrevCheck.dll c:\windows\system32\Drivers\iisxrg.sys c:\windows\system32\drivers\UACevirwrktvtevrncko.sys c:\windows\system32\Drivers\yrrem.sys c:\windows\system32\Ijl11.dll c:\windows\system32\UACmxepabweisfubhxrd.dat c:\windows\system32\UACpygnmxxxdgjxgnwxn.dll c:\windows\system32\uactmp.db c:\windows\system32\UACtrbpfuclpxoswnswr.db D:\Autorun.inf . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_UACd.sys ((((((((((((((((((((((((( Files Created from 2009-06-14 to 2009-07-14 ))))))))))))))))))))))))))))))) . 2009-07-13 16:21 . 2009-07-13 16:21 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes 2009-07-13 14:09 . 2009-07-13 14:09 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes 2009-07-13 13:50 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-13 13:50 . 2009-07-13 14:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-07-13 13:50 . 2009-07-13 13:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-07-13 13:50 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-07-12 13:35 . 2009-07-12 13:35 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Symantec 2009-07-12 13:01 . 2009-07-12 13:01 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache 2009-07-12 13:01 . 2009-07-12 13:01 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE 2009-07-12 13:01 . 2009-07-12 13:01 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2009-07-12 04:15 . 2009-07-12 04:15 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-06-26 18:19 . 2009-06-26 18:19 -------- d--h--w- C:\VJVod_Cache 2009-06-26 18:19 . 2009-06-26 18:19 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\nagasoft 2009-06-21 13:58 . 2009-06-21 13:58 -------- d-----w- c:\windows\system32\nagasoft . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-13 03:23 . 2009-07-13 03:23 156 ----a-w- c:\program files\zgvsk.txt 2009-06-03 15:53 . 2009-06-03 15:53 390664 ----a-w- c:\documents and settings\Owner\Application Data\Real\RealPlayer\Update\RealPlayer11.exe 2009-05-13 05:15 . 2006-01-11 19:21 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-07 15:32 . 2006-01-11 19:19 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-17 12:26 . 2006-01-11 19:21 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2006-01-11 19:20 585216 ----a-w- c:\windows\system32\rpcrt4.dll 2007-07-10 04:55 . 2007-07-10 04:55 3655608 ----a-w- c:\program files\FLV PlayerRCATSetup.exe 2007-07-10 04:55 . 2007-07-10 04:54 25990432 ----a-w- c:\program files\FLV PlayerRCSetup.exe . ((((((((((((((((((((((((((((((((((((((((((((( AWF )))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2006-01-11 20:14 . 2004-11-03 04:24 32768 c:\program files\CyberLink\PowerDVD\bak\PDVDServ.exe 2006-01-11 20:14 . 2008-02-13 08:04 0 c:\program files\CyberLink\PowerDVD\PDVDServ.exe 2004-11-15 23:04 . 2004-11-15 23:04 135168 c:\program files\Digital Media Reader\bak\shwiconem.exe 2006-01-11 20:13 . 2005-07-20 08:55 7090176 c:\program files\Intel Audio Studio\bak\IntelAudioStudio.exe 2006-01-11 20:13 . 2008-02-13 08:04 0 c:\program files\Intel Audio Studio\IntelAudioStudio.exe 2007-11-02 11:35 . 2007-09-25 05:11 132496 c:\program files\Java\jre1.6.0_03\bin\bak\jusched.exe 2007-11-02 11:35 . 2008-02-13 08:04 0 c:\program files\Java\jre1.6.0_03\bin\jusched.exe 2006-01-11 20:10 . 2006-01-11 20:10 98304 c:\program files\QuickTime\bak\qttask.exe 2006-09-01 19:57 . 2006-09-01 19:57 282624 c:\program files\QuickTime\qttask.exe 2003-05-21 05:21 . 2003-05-21 05:21 90112 c:\program files\Symantec_Client_Security\Symantec AntiVirus\bak\vptray.exe 2003-05-21 06:21 . 2003-05-21 06:21 90112 c:\program files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe 2007-05-14 22:22 . 2007-05-14 22:22 35328 c:\program files\Winamp\bak\winampa.exe 2007-05-14 22:22 . 2008-02-13 08:04 0 c:\program files\Winamp\winampa.exe 2004-10-28 01:13 . 2004-08-10 18:04 59392 c:\windows\ehome\bak\ehtray.exe 2006-01-11 19:18 . 2004-08-10 19:00 15360 c:\windows\system32\bak\ctfmon.exe 2006-01-11 19:18 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe 2006-01-11 20:30 . 2005-04-25 18:29 77824 c:\windows\system32\bak\hkcmd.exe 2006-01-11 20:30 . 2008-02-13 08:04 0 c:\windows\system32\hkcmd.exe 2006-01-11 20:30 . 2005-04-25 18:32 114688 c:\windows\system32\bak\igfxpers.exe 2006-01-11 20:30 . 2008-02-13 08:04 0 c:\windows\system32\igfxpers.exe 2006-01-11 20:30 . 2005-04-25 18:32 94208 c:\windows\system32\bak\igfxtray.exe 2006-01-11 19:53 . 2001-07-09 19:50 155648 c:\windows\system32\bak\NeroCheck.exe 2006-01-11 19:53 . 2008-02-13 08:03 0 c:\windows\system32\NeroCheck.exe 2006-11-23 14:00 . 2005-02-02 03:00 98304 c:\windows\system32\spool\drivers\w32x86\3\bak\E_FATIADA.EXE 2006-11-23 14:00 . 2008-02-13 08:04 0 c:\windows\system32\spool\drivers\w32x86\3\E_FATIADA.EXE . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-17 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2008-02-13 0] "SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [N/A] "IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2008-02-13 0] "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2008-02-13 0] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-07 8523776] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-07 81920] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2008-02-13 0] "EPSON Stylus CX4800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE" [2008-02-13 0] "vptray"="c:\program files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe" [2003-05-21 90112] "CHotkey"="zHotkey.exe" - c:\windows\zHotkey.exe [2005-05-03 543232] "SigmatelSysTrayApp"="sttray.exe" [N/A] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-11-07 1626112] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk backup=c:\windows\pss\BigFix.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Install Pending Files.LNK] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Install Pending Files.LNK backup=c:\windows\pss\Install Pending Files.LNKCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= S2 obre;obre;c:\windows\system32\drivers\ojfsg.sys --> c:\windows\system32\drivers\ojfsg.sys [?] S2 ycsf;ycsf;c:\windows\system32\drivers\ogetb.sys --> c:\windows\system32\drivers\ogetb.sys [?] S3 DMUSBUSBDCam;Dual Mode USB Camera;c:\windows\system32\drivers\dualpcam.sys [3/11/2006 3:43 PM 173952] S3 mr7911;Photo Viewer ;c:\windows\system32\drivers\mr7911.sys [12/24/2008 12:00 AM 39552] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] vvdsvc REG_MULTI_SZ vvdsvc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-07-13 c:\windows\Tasks\Symantec NetDetect.job - c:\program files\Symantec\LiveUpdate\NDetect.exe [2007-05-17 13:04] . . ------- Supplementary Scan ------- . uStart Page = hxxp://soccernet.espn.go.com/?cc=5901 uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/ IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} - hxxp://www.digitalwebbooks.com/reader/dbplugin.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-13 20:18 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... c:\windows\system32\drivers\hjgruinnsjbjdc.sys 67584 bytes executable c:\docume~1\Owner\LOCALS~1\Temp\hjgrui000 0 bytes c:\windows\system32\hjgruibmqtmsxc.dat 91 bytes c:\windows\system32\hjgruigmaaosqj.dat 120210 bytes c:\windows\system32\hjgruinqaslxua.dll 42496 bytes executable c:\windows\system32\hjgruitlnblfkv.dll 18944 bytes executable scan completed successfully hidden files: 6 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hjgruirrdcrfaw] "imagepath"="\systemroot\system32\drivers\hjgruinnsjbjdc.sys" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(716) c:\windows\system32\WININET.dll c:\windows\system32\igfxdev.dll - - - - - - - > 'lsass.exe'(780) c:\windows\system32\WININET.dll . Completion time: 2009-07-14 20:23 ComboFix-quarantined-files.txt 2009-07-14 00:23 Pre-Run: 161,769,312,256 bytes free Post-Run: 163,522,461,696 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINNT="Windows XP Media Center Edition" /noexecute=optin /fastdetect 182 --- E O F --- 2009-06-10 11:28 |
|
|
Jul 14 2009, 12:37 PM
Post
#4
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
hi
1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: QUOTE KillAll:: Rootkit:: c:\windows\system32\drivers\hjgruinnsjbjdc.sys c:\docume~1\Owner\LOCALS~1\Temp\hjgrui000 c:\windows\system32\hjgruibmqtmsxc.dat c:\windows\system32\hjgruigmaaosqj.dat c:\windows\system32\hjgruinqaslxua.dll c:\windows\system32\hjgruitlnblfkv.dll Driver:: obre ycsf hjgruirrdcrfaw File:: c:\program files\zgvsk.txt c:\windows\system32\drivers\ojfsg.sys c:\windows\system32\drivers\ogetb.sys AWF:: c:\program files\CyberLink\PowerDVD\bak\PDVDServ.exe c:\program files\Digital Media Reader\bak\shwiconem.exe c:\program files\Intel Audio Studio\bak\IntelAudioStudio.exe c:\program files\Java\jre1.6.0_03\bin\bak\jusched.exe c:\program files\QuickTime\bak\qttask.exe c:\program files\Symantec_Client_Security\Symantec AntiVirus\bak\vptray.exe c:\program files\Winamp\bak\winampa.exe c:\windows\ehome\bak\ehtray.exe c:\windows\system32\bak\ctfmon.exe c:\windows\system32\bak\hkcmd.exe c:\windows\system32\bak\igfxpers.exe c:\windows\system32\bak\igfxtray.exe c:\windows\system32\bak\NeroCheck.exe c:\windows\system32\spool\drivers\w32x86\3\bak\E_FATIADA.EXE NetSvc:: vvdsvc Save this as CFScript.txt, in the same location as ComboFix.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply. |
|
|
Jul 14 2009, 04:10 PM
Post
#5
|
|
|
New Member ![]() Posts: 6 OS: windows XP |
Here is the latest.
ComboFix 09-07-13.01 - Owner 07/14/2009 17:51.2.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1021.725 [GMT -4:00] Running from: c:\old comp\Combo-Fix.exe Command switches used :: c:\old comp\CFScript.txt FILE :: "c:\program files\zgvsk.txt" "c:\windows\system32\drivers\ogetb.sys" "c:\windows\system32\drivers\ojfsg.sys" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\zgvsk.txt c:\windows\system32\drivers\hjgruinnsjbjdc.sys c:\windows\system32\hjgruibmqtmsxc.dat c:\windows\system32\hjgruigmaaosqj.dat c:\windows\system32\hjgruinqaslxua.dll c:\windows\system32\hjgruitlnblfkv.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_hjgruirrdcrfaw -------\Legacy_OBRE -------\Legacy_YCSF -------\Service_obre -------\Service_ycsf ((((((((((((((((((((((((( Files Created from 2009-06-14 to 2009-07-14 ))))))))))))))))))))))))))))))) . 2009-07-13 16:21 . 2009-07-13 16:21 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes 2009-07-13 14:09 . 2009-07-13 14:09 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes 2009-07-13 13:50 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-13 13:50 . 2009-07-13 14:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-07-13 13:50 . 2009-07-13 13:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-07-13 13:50 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-07-12 13:35 . 2009-07-12 13:35 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Symantec 2009-07-12 13:01 . 2009-07-12 13:01 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache 2009-07-12 13:01 . 2009-07-12 13:01 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE 2009-07-12 13:01 . 2009-07-12 13:01 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2009-07-12 04:15 . 2009-07-12 04:15 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-06-26 18:19 . 2009-06-26 18:19 -------- d--h--w- C:\VJVod_Cache 2009-06-26 18:19 . 2009-06-26 18:19 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\nagasoft 2009-06-21 13:58 . 2009-06-21 13:58 -------- d-----w- c:\windows\system32\nagasoft . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-14 22:00 . 2006-04-15 18:40 -------- d-----w- c:\program files\Winamp 2009-07-14 22:00 . 2006-01-11 20:10 -------- d-----w- c:\program files\QuickTime 2009-07-14 22:00 . 2006-01-11 19:56 -------- d-----w- c:\program files\Digital Media Reader 2009-07-14 21:51 . 2006-01-11 20:13 -------- d-----w- c:\program files\Intel Audio Studio 2009-06-03 15:53 . 2009-06-03 15:53 390664 ----a-w- c:\documents and settings\Owner\Application Data\Real\RealPlayer\Update\RealPlayer11.exe 2009-05-13 05:15 . 2006-01-11 19:21 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-07 15:32 . 2006-01-11 19:19 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-17 12:26 . 2006-01-11 19:21 1847168 ----a-w- c:\windows\system32\win32k.sys 2007-07-10 04:55 . 2007-07-10 04:55 3655608 ----a-w- c:\program files\FLV PlayerRCATSetup.exe 2007-07-10 04:55 . 2007-07-10 04:54 25990432 ----a-w- c:\program files\FLV PlayerRCSetup.exe . ((((((((((((((((((((((((((((( SnapShot@2009-07-14_00.18.21 ))))))))))))))))))))))))))))))))))))))))) . + 2006-11-23 14:00 . 2005-02-02 03:00 98304 c:\windows\system32\spool\drivers\w32x86\3\E_FATIADA.EXE + 2006-01-11 20:30 . 2005-04-25 18:32 94208 c:\windows\system32\igfxtray.exe + 2006-01-11 20:30 . 2005-04-25 18:29 77824 c:\windows\system32\hkcmd.exe + 2004-10-28 01:13 . 2004-08-10 18:04 59392 c:\windows\system32\dllcache\ehtray.exe + 2006-01-11 19:18 . 2008-04-14 00:12 15360 c:\windows\system32\dllcache\ctfmon.exe + 2004-10-28 01:24 . 2009-07-14 09:40 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2004-10-28 01:24 . 2009-07-14 00:00 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2009-07-12 04:15 . 2009-07-14 00:00 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat + 2009-07-12 04:15 . 2009-07-14 09:40 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat - 2004-10-28 01:24 . 2009-07-14 00:00 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2004-10-28 01:24 . 2009-07-14 09:40 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2004-10-28 01:13 . 2004-08-10 18:04 59392 c:\windows\ehome\ehtray.exe + 2006-01-11 19:53 . 2001-07-09 19:50 155648 c:\windows\system32\NeroCheck.exe + 2006-01-11 20:30 . 2005-04-25 18:32 114688 c:\windows\system32\igfxpers.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-17 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168] "IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2005-07-20 7090176] "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-07 8523776] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-07 81920] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-11 98304] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496] "EPSON Stylus CX4800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE" [2005-02-02 98304] "vptray"="c:\program files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe" [2003-05-21 90112] "CHotkey"="zHotkey.exe" - c:\windows\zHotkey.exe [2005-05-03 543232] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-11-07 1626112] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk backup=c:\windows\pss\BigFix.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Install Pending Files.LNK] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Install Pending Files.LNK backup=c:\windows\pss\Install Pending Files.LNKCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= S3 DMUSBUSBDCam;Dual Mode USB Camera;c:\windows\system32\drivers\dualpcam.sys [3/11/2006 3:43 PM 173952] S3 mr7911;Photo Viewer ;c:\windows\system32\drivers\mr7911.sys [12/24/2008 12:00 AM 39552] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] vvdsvc REG_MULTI_SZ vvdsvc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-07-14 c:\windows\Tasks\Symantec NetDetect.job - c:\program files\Symantec\LiveUpdate\NDetect.exe [2007-05-17 13:04] . - - - - ORPHANS REMOVED - - - - HKLM-Run-SigmatelSysTrayApp - sttray.exe . ------- Supplementary Scan ------- . uStart Page = hxxp://soccernet.espn.go.com/?cc=5901 uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/ IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} - hxxp://www.digitalwebbooks.com/reader/dbplugin.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-14 18:00 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(2272) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll . ------------------------ Other Running Processes ------------------------ . c:\progra~1\SYMANT~1\SYMANT~1\DefWatch.exe c:\windows\ehome\ehRecvr.exe c:\windows\ehome\ehSched.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\progra~1\SYMANT~1\SYMANT~1\Rtvscan.exe c:\windows\system32\nvsvc32.exe c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS c:\windows\system32\wdfmgr.exe c:\windows\system32\dllhost.exe c:\windows\system32\rundll32.exe c:\windows\system32\wscntfy.exe c:\program files\Java\jre1.6.0_03\bin\jucheck.exe . ************************************************************************** . Completion time: 2009-07-14 18:08 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-14 22:08 ComboFix2.txt 2009-07-14 00:23 Pre-Run: 163,439,132,672 bytes free Post-Run: 163,436,187,648 bytes free 179 --- E O F --- 2009-06-10 11:28 Thanks for all your help in this. C |
|
|
Jul 14 2009, 04:39 PM
Post
#6
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
hi
Download TFC to your desktop
Please download Malwarebytes' Anti-Malware from Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Go to Kaspersky website and perform an online antivirus scan.
|
|
|
Jul 14 2009, 08:10 PM
Post
#7
|
|
|
New Member ![]() Posts: 6 OS: windows XP |
Thanks for the quick response again.
Here is the 2 files: MALWARE LOG: Malwarebytes' Anti-Malware 1.39 Database version: 2421 Windows 5.1.2600 Service Pack 3 7/14/2009 7:07:12 PM mbam-log-2009-07-14 (19-07-12).txt Scan type: Quick Scan Objects scanned: 107876 Time elapsed: 3 minute(s), 27 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\documents and settings\Owner\Desktop\avenger.exe (Trojan.Agent) -> Quarantined and deleted successfully. KASPER LOG: -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0 REPORT Tuesday, July 14, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Tuesday, July 14, 2009 23:51:05 Records in database: 2468838 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ I:\ J:\ K:\ L:\ Scan statistics: Files scanned: 148639 Threat name: 17 Infected objects: 18 Suspicious objects: 0 Duration of the scan: 02:35:52 File name / Threat name / Threats count C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02880000.VBN Infected: Trojan-Downloader.Java.OpenStream.ac 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02880002.VBN Infected: Packed.JS.Agent.n 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04600000.VBN Infected: Exploit.JS.Pdfka.ms 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04A00000.VBN Infected: Exploit.Win32.Pidief.acv 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05F40000.VBN Infected: Exploit.JS.XMLPars.y 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0C880000.VBN Infected: Exploit.Win32.Pidief.aar 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0CA80000.VBN Infected: Exploit.Win32.Pidief.gx 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0CB40000.VBN Infected: Trojan-Downloader.VBS.Psyme.ga 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0D600000.VBN Infected: Exploit.JS.Pdfka.ma 1 C:\Documents and Settings\Owner\My Documents\mirc635.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 C:\Old comp\received files\setup_ares.exe Infected: not-a-virus:AdWare.Win32.NavExcel.d 1 C:\Old comp\received files\setup_ares.exe Infected: not-a-virus:AdWare.Win32.NavExcel.g 1 C:\Old comp\received files\setup_ares.exe Infected: not-a-virus:AdWare.Win32.NavExcel 1 C:\Old comp\received files\setup_ares.exe Infected: not-a-virus:AdWare.Win32.NavExcel.b 1 C:\Old comp\received files\setup_ares.exe Infected: not-a-virus:AdWare.Win32.NavExcel.i 1 C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\dbxDgrevCheck.dll.vir Infected: not-a-virus:AdWare.Win32.Agent.cb 1 D:\i386\APPS\App13914\comps\toolbar\toolbr.exe Infected: not-a-virus:AdWare.Win32.SearchIt.t 1 The selected area was scanned. |
|
|
Jul 15 2009, 06:04 AM
Post
#8
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
hi
Please download OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post. CLICK HERE to download the HijackThis Installer:
|
|
|
Jul 15 2009, 11:21 AM
Post
#9
|
|
|
New Member ![]() Posts: 6 OS: windows XP |
********** OTM LOG: ******************
All processes killed ========== PROCESSES ========== ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\Old comp\received files\setup_ares.exe moved successfully. D:\i386\APPS\App13914\comps\toolbar\toolbr.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes User: Kathryn ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes User: LocalService File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 16786 bytes User: NetworkService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes User: Owner ->Temp folder emptied: 76356840 bytes ->Temporary Internet Files folder emptied: 36078063 bytes ->Java cache emptied: 130719 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 664 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 107.46 mb OTM by OldTimer - Version 3.0.0.5 log created on 07152009_081903 Files moved on Reboot... Registry entries deleted on Reboot... ************ HIJackTHIS LOG: *********************** Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:27:57 AM, on 7/15/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\notepad.exe C:\Program Files\Digital Media Reader\shwiconem.exe C:\WINDOWS\zHotkey.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://soccernet.espn.go.com/?cc=5901 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/ O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe O4 - HKLM\..\Run: [CHotkey] zHotkey.exe O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800" O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1137096291562 O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cheezer0.spaces.live.com/PhotoUpload/MsnPUpld.cab O16 - DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} (KooPlayer Control) - http://www.ooxtv.com/stream.ocx O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} (VodClient Control Class) - http://www.tvucricket.com/player/vjocx-en-black.cab O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://www.easypix.ca/upload/activex/v2_0_...upv2.0.0.10.cab? O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing) O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS -- End of file - 9590 bytes |
|
|
Jul 15 2009, 12:46 PM
Post
#10
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
Your logs are clean
Follow these steps to uninstall Combofix and tools used in the removal of malware
Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here : http://www.adobe.com/products/acrobat/readstep2.html Please download JavaRa to your desktop and unzip it to its own folder
Below I have included a number of recommendations for how to protect your computer against malware infections.
Thank you for your patience, and performing all of the procedures requested. |
|
|
Jul 15 2009, 08:48 PM
Post
#11
|
|
|
New Member ![]() Posts: 6 OS: windows XP |
This was great!
Thank you for all the help it was well worth the wait even though you guys were real quick! I like the added on security features at the end too. Keep up the great work. |
|
|
Jul 16 2009, 06:57 AM
Post
#12
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
8 / 498 | 28th April 2009 - 01:41 PM Tidalstock started - last by Essexboy |
|||||
![]() |
39 / 577 | 29th October 2009 - 12:37 PM lastchance started - last by Rorschach112 |
|||||
![]() |
14 / 228 | 1st November 2009 - 07:57 PM jbneufeld started - last by Rorschach112 |
|||||
![]() |
60 / 935 | 17th November 2009 - 03:19 PM zalgud started - last by heir |
|||||
|
Time is now: 21st November 2009 - 08:04 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising