Malware & Viruses [Please Check The Logs :)] [Closed] |
![]() ![]() |
Malware & Viruses [Please Check The Logs :)] [Closed] |
Jul 5 2009, 02:21 AM
Post
#1
|
|
|
New Member ![]() Posts: 4 From: Cleveland , Ohio OS: Windows 7 Build 7100 |
Hello Geeks to go ,
Ive been having alot of problems on my old machine . Its been running since 2002 Its got Microsoft Windows XP Home SP 3... But ive had alot of issues with it well for first i found a topic here about one of the issues ive had which was CoolWebsSearch . Which has been fully removed by one of the guides i found . But i still have issues ive had Antivirus 2009 which i used a guide and removed .. Heres my HIJACKTHIS log: CODE Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 4:17:56 AM, on 7/5/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe G:\Program Files\trendnet\WinDomainlogon.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\PROGRA~1\PESTPA~1\PPMemCheck.exe C:\PROGRA~1\PESTPA~1\PPControl.exe C:\PROGRA~1\PESTPA~1\CookiePatrol.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Messenger\msmsgs.exe G:\Program Files\CameraMonitor.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\WINDOWS\SYSTEM32\proquota.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe O2 - BHO: Java Plug-In 2 SSV Helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [LexStart] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKCU\..\Run: [Steam] "g:\program files\steam\steam.exe" -silent O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Global Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: ImageMixer 3 SE Camera Monitor for SD.lnk = G:\Program Files\CameraMonitor.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [java_sun] Java (Sun) O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\ O23 - Service: Java Quick Starter (javaquickstarterservice) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Lavasoft Ad-Aware Service (lavasoft ad-aware service) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\ -- End of file - 4027 bytes Also if this is helpful The log i got from Malware-Bytes MALWARE-BYTES LOG: CODE Malwarebytes' Anti-Malware 1.38 Database version: 2375 Windows 5.1.2600 Service Pack 2 7/5/2009 4:07:08 AM mbam-log-2009-07-05 (04-07-03).txt Scan type: Quick Scan Objects scanned: 100899 Time elapsed: 7 minute(s), 40 second(s) Memory Processes Infected: 2 Memory Modules Infected: 0 Registry Keys Infected: 14 Registry Values Infected: 9 Registry Data Items Infected: 7 Folders Infected: 1 Files Infected: 28 Memory Processes Infected: C:\Documents and Settings\RANDYANDAMY\Application Data\Microsoft\Windows\lsass.exe (Trojan.Agent) -> No action taken. C:\WINDOWS\SYSTEM32\winupdate.exe (Trojan.Downloader) -> No action taken. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> No action taken. HKEY_CLASSES_ROOT\TypeLib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> No action taken. HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> No action taken. HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d76ab2a1-00f3-42bd-f434-00bbc39c8953} (Trojan.Agent) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Cognac (Rogue.Multiple) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogo2 (Trojan.Agent) -> No action taken. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Screensavers.com (Adware.Comet) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\AvScan (Malware.Trace) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\ColdWare (Malware.Trace) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dailybucks_install.exe (Security.Hijack) -> No action taken. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\appipat_dlls (Spyware.Agent.H) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\DOWNLOADED PROGRAM FILES\MINIBUGTRANSPORTER.DLL (Adware.Minibug) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Lsass Service (Trojan.Agent) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate.exe (Trojan.Downloader) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\kr_done1 (Malware.Trace) -> No action taken. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\BootStera (Rogue.WinAntiVirus) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\idstrf (Malware.Trace) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WINID (Malware.Trace) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\wallpaper (Hijack.Wallpaper) -> No action taken. Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken. Folders Infected: c:\documents and settings\all users\application data\WinAntiVirus Pro 2006 (Rogue.WinAntiVirus) -> No action taken. Files Infected: C:\WINDOWS\SYSTEM32\nvrsk.dll (Spyware.Agent.H) -> No action taken. C:\WINDOWS\DOWNLOADED PROGRAM FILES\MINIBUGTRANSPORTER.DLL (Adware.Minibug) -> No action taken. c:\WINDOWS\SYSTEM32\wmmest.dll (Trojan.Agent) -> No action taken. c:\WINDOWS\SYSTEM32\gsf83iujid.dll (Trojan.Ertfor) -> No action taken. c:\WINDOWS\SYSTEM32\__c009C7D.dat (Trojan.Vundo) -> No action taken. c:\WINDOWS\SYSTEM32\__c0094432.dat (Trojan.Vundo) -> No action taken. c:\WINDOWS\SYSTEM32\__c00B3CF2.dat (Trojan.Vundo) -> No action taken. c:\WINDOWS\SYSTEM32\__c005151A.dat (Trojan.Vundo) -> No action taken. c:\WINDOWS\SYSTEM32\4736270.dll (Hijack.LSP) -> No action taken. c:\WINDOWS\SYSTEM32\wbem\proquota.exe (Trojan.Dropper) -> No action taken. c:\documents and settings\randyandamy\RANDYANDAMY.exe (Trojan.Agent) -> No action taken. c:\documents and settings\randyandamy\local settings\temporary internet files\Content.IE5\NRZRBGPD\ww1138[1].exe (Trojan.Agent) -> No action taken. c:\documents and settings\randyandamy\local settings\temporary internet files\Content.IE5\NRZRBGPD\ww1138[2].exe (Trojan.Agent) -> No action taken. c:\documents and settings\randyandamy\local settings\temporary internet files\Content.IE5\87IHQXYP\ww1138[1].exe (Trojan.Agent) -> No action taken. c:\documents and settings\randyandamy\application data\microsoft\Windows\update8123.cmp (Trojan.Agent) -> No action taken. C:\WINDOWS\hosts (Trojan.Agent) -> No action taken. C:\Documents and Settings\RANDYANDAMY\Application Data\Microsoft\Windows\lsass.exe (Trojan.Agent) -> No action taken. C:\WINDOWS\SYSTEM32\logon.exe (Trojan.Agent) -> No action taken. C:\WINDOWS\SYSTEM32\winupdate.exe (Trojan.Downloader) -> No action taken. C:\WINDOWS\SYSTEM32\lich.dat (Stolen.data) -> No action taken. c:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> No action taken. C:\WINDOWS\SYSTEM32\msxml71.dll (Trojan.FakeAlert) -> No action taken. C:\WINDOWS\SYSTEM32\kr_done1 (Malware.Trace) -> No action taken. C:\WINDOWS\SYSTEM32\stera.job (Rogue.WinAntiVirus) -> No action taken. C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job (Trojan.Downloader) -> No action taken. c:\documents and settings\RANDYANDAMY\Application Data\wiaserva.log (Malware.Trace) -> No action taken. c:\documents and settings\RANDYANDAMY\Application Data\wiaservg.log (Malware.Trace) -> No action taken. C:\WINDOWS\SYSTEM32\critical_warning.html (Trojan.FakeAlert) -> No action taken. Theres all the logs i got .. Anyway ive also used AVG anti-virus free editon and i did about 3 scans after running avg 10 times . with HouseCall And i get a bunch of random fatal error messages . |
|
|
Jul 5 2009, 05:21 AM
Post
#2
|
|
![]() GeekU Teacher Posts: 34,385 From: Dublin OS: XP |
don't put the logs in code
Download ComboFix from one of these locations: Link 1 Link 2 * IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning for malware. When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply. |
|
|
Jul 5 2009, 03:24 PM
Post
#3
|
|
|
New Member ![]() Posts: 4 From: Cleveland , Ohio OS: Windows 7 Build 7100 |
COMBOFIX LOG:
ComboFix 09-07-05.01 - RANDYANDAMY 07/05/2009 16:47.1 - FAT32x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.767.456 [GMT -4:00] Running from: c:\documents and settings\RANDYANDAMY\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\CTL3D.DLL c:\documents and settings\All Users\Application Data\nsv c:\documents and settings\All Users\Application Data\nsv\cache\294.dfn c:\documents and settings\All Users\Application Data\nsv\cache\400.dfn c:\documents and settings\All Users\Application Data\nsv\cache\404.dfn c:\documents and settings\All Users\Application Data\nsv\keys.dat c:\documents and settings\All Users\Application Data\nsv\wmv0104.dbd c:\documents and settings\All Users\Application Data\nsv\wmv0106.ddx c:\documents and settings\All Users\Application Data\nsv\wmv0204.ddx c:\documents and settings\All Users\Application Data\nsv\wmv0315.ddx c:\documents and settings\All Users\Application Data\nsv\wmv0412.ddx c:\documents and settings\All Users\Application Data\nsv\wmv0504.ddx c:\documents and settings\All Users\Application Data\nsv\wmv0904.ddx c:\documents and settings\All Users\Application Data\nsv\wmv1125.ddx c:\documents and settings\All Users\Application Data\nsv\wmv1204.ddx c:\documents and settings\All Users\Application Data\nsv\wmv1215.dbd c:\documents and settings\All Users\Application Data\nsv\wmv1909.ddx c:\documents and settings\All Users\Application Data\nsv\wmv1920.dbd c:\documents and settings\All Users\Application Data\nsv\wmv2007.dbd c:\documents and settings\RANDYANDAMY\Favorites\Download programs.url c:\documents and settings\RANDYANDAMY\Favorites\Games.url c:\documents and settings\RANDYANDAMY\Favorites\Translator.url c:\documents and settings\RANDYANDAMY\Favorites\Videos.url c:\documents and settings\RANDYANDAMY\Start Menu\Programs\Download programs.url c:\documents and settings\RANDYANDAMY\Start Menu\Programs\Games.url c:\documents and settings\RANDYANDAMY\Start Menu\Programs\Translator.url c:\documents and settings\RANDYANDAMY\Start Menu\Programs\Videos.url C:\MSrev23.dll C:\MSrev43.dll c:\program files\Mozilla Firefox\extensions\{B619E1D9-760A-4173-B3AC-479A0B42AA0F} c:\program files\Mozilla Firefox\extensions\{B619E1D9-760A-4173-B3AC-479A0B42AA0F}\chrome.manifest c:\program files\Mozilla Firefox\extensions\{B619E1D9-760A-4173-B3AC-479A0B42AA0F}\chrome\content\_cfg.js c:\program files\Mozilla Firefox\extensions\{B619E1D9-760A-4173-B3AC-479A0B42AA0F}\chrome\content\c.js c:\program files\Mozilla Firefox\extensions\{B619E1D9-760A-4173-B3AC-479A0B42AA0F}\chrome\content\overlay.xul c:\program files\Mozilla Firefox\extensions\{B619E1D9-760A-4173-B3AC-479A0B42AA0F}\install.rdf c:\windows\Installer\11b56b6.msp c:\windows\Installer\11b56bb.msp c:\windows\Installer\14e248.msi c:\windows\Installer\22395.msi c:\windows\Installer\2b918.msi c:\windows\Installer\2b919.msp c:\windows\Installer\2b91a.msp c:\windows\Installer\2b91b.msp c:\windows\Installer\2b91c.msp c:\windows\Installer\2b91d.msp c:\windows\Installer\2b91e.msp c:\windows\Installer\2b91f.msp c:\windows\Installer\2b920.msp c:\windows\Installer\2b921.msp c:\windows\JAVA\TRUSTLIB\xafelo.bak1 c:\windows\JAVA\TRUSTLIB\xafelo.bak2 c:\windows\JAVA\TRUSTLIB\xafelo.ini c:\windows\patch.exe c:\windows\start.exe c:\windows\system32\11796993342348786433196615334234833423483342348.exe c:\windows\system32\15729153342348786433196615334234833423483342348.exe c:\windows\system32\instsrv.exe c:\windows\Web\default.htt C:\xcrashdump.dat F:\install.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_fci -------\Legacy_ZESOFT ((((((((((((((((((((((((( Files Created from 2009-06-05 to 2009-07-05 ))))))))))))))))))))))))))))))) . 2009-07-05 20:58 . 2009-07-05 20:58 -------- d-----w- c:\windows\LastGood 2009-07-05 09:15 . 2009-07-05 09:15 -------- d-----w- C:\VundoFix Backups 2009-07-05 07:57 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-05 07:57 . 2009-07-05 07:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-07-05 07:57 . 2009-07-05 07:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-07-05 07:57 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-07-02 17:42 . 2009-07-02 17:42 -------- d-----w- c:\program files\CleanUp! 2009-07-02 16:20 . 2009-07-02 16:20 194 ---ha-w- C:\aaw7boot.cmd 2009-07-02 16:19 . 2009-07-02 16:19 -------- d-----w- c:\program files\RegCleaner 2009-07-02 16:13 . 2009-05-21 15:33 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-07-02 15:30 . 2009-07-02 15:29 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-07-02 15:24 . 2009-07-02 15:24 -------- d--h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-07-02 15:24 . 2009-03-12 08:17 2902048 ----a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe 2009-07-02 15:24 . 2009-07-02 15:24 -------- d-----w- c:\program files\Lavasoft 2009-07-02 15:24 . 2009-07-02 15:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2009-07-02 14:29 . 2004-08-04 12:00 5632 ----a-w- c:\windows\system32\dllcache\smimsgif.dll 2009-07-02 14:28 . 2004-08-04 12:00 98304 ----a-w- c:\windows\system32\dllcache\msir3jp.dll 2009-07-02 14:27 . 2004-08-04 12:00 10129408 ----a-w- c:\windows\system32\dllcache\hwxkor.dll 2009-07-02 14:26 . 2004-08-04 12:00 480256 ----a-w- c:\windows\system32\dllcache\cintsetp.exe 2009-07-02 14:25 . 2003-03-24 20:52 16384 ----a-w- c:\windows\system32\dllcache\tcptsat.dll 2009-07-02 14:12 . 2004-08-04 02:31 20992 ----a-w- c:\windows\system32\drivers\RTL8139.sys 2009-07-02 14:09 . 2004-08-04 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll 2009-07-02 14:09 . 2004-08-04 12:00 24661 ----a-w- c:\windows\system32\dllcache\spxcoins.dll 2009-07-02 14:09 . 2004-08-04 12:00 13312 ----a-w- c:\windows\system32\irclass.dll 2009-07-02 14:09 . 2004-08-04 12:00 13312 ----a-w- c:\windows\system32\dllcache\irclass.dll 2009-07-02 02:37 . 2007-08-14 18:04 9216 ----a-w- c:\windows\system32\ffnd.exe 2009-07-02 02:14 . 2009-07-02 02:14 -------- d-----w- c:\documents and settings\RANDYANDAMY\Local Settings\Application Data\FreeFixer 2009-07-02 02:14 . 2009-07-02 02:14 -------- d-----w- c:\program files\FreeFixer 2009-07-01 22:31 . 2009-07-01 22:31 -------- d--h--w- C:\$AVG8.VAULT$ 2009-07-01 12:53 . 2009-07-01 12:53 -------- d-----w- c:\documents and settings\All Users\Application Data\12965564 2009-07-01 09:56 . 2009-07-01 09:56 41984 --sh--w- c:\documents and settings\RANDYANDAMY\Application Data\Microsoft\Windows\ms65.exe 2009-07-01 02:08 . 2004-08-04 12:00 16384 ----a-w- c:\windows\system32\dllcache\isignup.exe 2009-06-30 22:58 . 2009-06-30 22:58 -------- d-----w- c:\program files\Intuit 2009-06-30 13:23 . 2009-06-30 13:23 -------- d-----w- c:\program files\Bazooka Scanner 2009-06-30 12:03 . 2009-06-30 12:03 -------- d-----w- c:\program files\Trend Micro 2009-06-27 08:07 . 2008-10-16 18:06 268648 ----a-w- c:\windows\system32\mucltui.dll 2009-06-26 18:00 . 2009-06-26 18:00 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2 2009-06-26 14:59 . 2009-06-26 14:59 -------- d-----w- c:\windows\system32\scripting 2009-06-26 14:58 . 2009-06-26 14:59 -------- d-----w- c:\windows\system32\en 2009-06-26 14:58 . 2009-06-26 14:59 -------- d-----w- c:\windows\l2schemas 2009-06-26 14:58 . 2009-06-26 14:58 -------- d-----w- c:\windows\system32\bits 2009-06-26 14:56 . 2009-06-26 14:56 -------- d-----w- c:\windows\ServicePackFiles 2009-06-26 14:51 . 2009-06-26 14:51 -------- d-----w- c:\windows\EHome 2009-06-26 13:58 . 2009-06-26 13:59 -------- d-----w- c:\program files\Windows Resource Kits 2009-06-26 02:35 . 2009-06-26 02:35 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe 2009-06-25 17:14 . 2007-08-02 02:47 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys 2009-06-25 02:54 . 2009-06-25 02:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard 2009-06-25 02:49 . 2009-06-25 02:49 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment 2009-06-19 02:09 . 2009-06-19 02:09 -------- d-----w- c:\program files\Doras Carnival 2 - At the Boardwalk 2009-06-19 02:08 . 2009-06-19 02:09 -------- d-----w- c:\program files\bfgclient 2009-06-19 02:08 . 2009-06-19 02:08 2383904 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\Unpack\bfgsetup_s1_l1.exe 2009-06-19 02:08 . 2009-06-19 02:08 -------- d-----w- c:\documents and settings\All Users\Application Data\BigFishGamesCache . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-02 14:19 . 2004-12-27 16:28 23376 ----a-w- c:\windows\system32\emptyregdb.dat 2009-06-30 13:17 . 2004-12-27 16:51 50840 ----a-w- c:\documents and settings\RANDYANDAMY\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-06-26 15:01 . 2004-12-27 16:30 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-05-24 14:12 . 2009-05-24 14:12 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-05-24 14:12 . 2009-05-24 14:12 -------- d-----w- c:\program files\NOS 2009-05-24 13:46 . 2009-05-24 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Avg7 2009-05-19 22:10 . 2009-05-19 22:10 143864 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\stub\dorascarnival2atth_s1_l1_gF1559T1L1_d557309401[1].exe 2009-05-19 22:10 . 2009-05-19 22:10 2319528 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\clientinstaller\bfgsetup_s1_l1.exe 2009-04-20 15:01 . 2009-04-18 13:55 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys 2009-02-12 01:33 . 2009-02-12 01:33 501 ----a-w- c:\program files\Shortcut (2) to Mystery P.I. - The Vegas Heist.lnk 2009-02-12 01:33 . 2009-02-12 01:33 501 ----a-w- c:\program files\Shortcut to Mystery P.I. - The Vegas Heist.lnk 2006-02-03 12:21 . 2006-02-03 12:20 948936 ----a-w- c:\program files\install_flash_player.exe 2004-12-27 16:36 . 2004-12-27 16:36 707 ----a-w- c:\program files\MS-DOS Prompt.LNK 2004-04-11 19:49 . 2004-04-11 19:49 3616400 ----a-w- c:\program files\Install_AIM.exe 2003-08-12 09:02 . 1980-01-01 04:00 384 ----a-w- c:\program files\Internet Explorer.lnk 2003-08-12 09:02 . 1980-01-01 04:00 369 ----a-w- c:\program files\Outlook Express.lnk 2003-08-12 09:02 . 1980-01-01 04:00 295 ----a-w- c:\program files\Windows Explorer.lnk 2002-11-15 01:51 . 2002-11-15 01:51 536018 ----a-w- c:\program files\vp3.rar 2002-10-12 06:27 . 1980-01-01 04:00 11079 ---h--w- c:\program files\folder.htt 2002-10-09 05:48 . 2002-10-09 05:48 0 --sh--r- c:\windows\asbmeidAv.sys 2002-10-09 05:48 . 2002-10-09 05:48 200 --sh--r- c:\windows\SYSTEM\vAdiembsa.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="g:\program files\steam\steam.exe" [2009-06-11 1217784] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PPMemCheck"="c:\progra~1\PESTPA~1\PPMemCheck.exe" [2004-04-02 148480] "PestPatrol Control Center"="c:\progra~1\PESTPA~1\PPControl.exe" [2004-11-15 98304] "CookiePatrol"="c:\progra~1\PESTPA~1\CookiePatrol.exe" [2005-01-10 73728] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696] "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2006-03-15 421888] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648] "LexStart"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888] "SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-12-01 77824] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Webshots.lnk - c:\program files\Webshots\WebshotsTray.exe [2003-7-13 208896] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588] ImageMixer 3 SE Camera Monitor for SD.lnk - g:\program files\CameraMonitor.exe [2008-6-23 253952] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "EditLevel"= 0 (0x0) "NoCommonGroups"= 0 (0x0) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lavasoft ad-aware service] @="Service" HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWC: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWC:\Program Files HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWc:\program files\ISTsvc [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "SAIMON"=c:\windows\SYSTEM32\SaiMon.exe "DisableEHCI"=c:\windows\NoUSB20.EXE "EM_EXEC"=c:\progra~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE "SystemTray"=SysTray.Exe "NvCplDaemon"=RUNDLL32.EXE c:\windows\SYSTEM32\nvcpl.dll,NvStartup "tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" /server /nosystray "PestPatrol Control Center"=c:\progra~1\PESTPA~1\PPControl.exe "PPMemCheck"=c:\progra~1\PESTPA~1\PPMemCheck.exe "MMTray"=MMTray.exe "Cmaudio"=RunDll32 cmicnfg.dll,CMICtrlWnd "nwiz"=nwiz.exe /install "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot "QuickTime Task"="c:\windows\SYSTEM32\qttask.exe" -atboottime "Win Server Updt"=c:\windows\wupdt.exe "*CATDRV"=c:\windows\HELP\CATDRV.EXE [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys] "*OLEFAX"=c:\windows\JAVA\TRUSTLIB\OLEFAX.EXE [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-] "ScriptBlocking"= "SchedulingAgent"=mstask.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Ubi Soft\\IL2 Sturmovik\\il2.exe"= "g:\\Program Files\\Steam\\SteamApps\\waycoolsurfer\\half-life 2 deathmatch\\hl2.exe"= "g:\\Program Files\\Steam\\SteamApps\\waycoolsurfer\\team fortress 2\\hl2.exe"= "c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "g:\\Program Files\\Quake III Arena\\quake3.exe"= "f:\\World of Warcraft\\Launcher.exe"= "f:\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"= "f:\\World of Warcraft\\WoW-3.1.1.9835-to-3.1.2.9901-enUS-downloader.exe"= "c:\\WINDOWS\\system32\\Ati2evxx.exe"= "g:\\Program Files\\trendnet\\WinDomainLogon.exe"= "c:\\Program Files\\Common Files\\LightScribe\\LSSrvc.exe"= "c:\\Program Files\\Canon\\CAL\\CALMAIN.exe"= "c:\\Program Files\\Webshots\\Webshots.scr"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.185\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.186\\FP_AX_CAB_INSTALLER.exe"= "c:\\Program Files\\WinRAR\\WinRAR.exe"= "g:\\program files\\steam\\steam.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.187\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\System32\\taskmgr.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.188\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.189\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.190\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\system32\\dumprep.exe"= "c:\\WINDOWS\\system32\\dwwin.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.191\\FP_AX_CAB_INSTALLER.exe"= "g:\\Program Files\\Rockstar Games\\GTA San Andreas\\samp.exe"= "g:\\Program Files\\Rockstar Games\\GTA San Andreas\\gta_sa.exe"= "c:\\WINDOWS\\System32\\WgaTray.exe"= "c:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe"= "c:\\Program Files\\PestPatrol\\PPMemCheck.exe"= "c:\\Program Files\\PestPatrol\\PPControl.exe"= "c:\\Program Files\\PestPatrol\\CookiePatrol.exe"= "c:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"= "c:\\WINDOWS\\SOUNDMAN.EXE"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\WINDOWS\\system32\\wuauclt.exe"= "c:\\Program Files\\Belkin\\Nostromo\\nost_LM.exe"= "g:\\Program Files\\CameraMonitor.exe"= "c:\\Program Files\\Java\\jre1.6.0_07\\bin\\jucheck.exe"= "c:\\WINDOWS\\system32\\MsiExec.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.204\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.205\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.206\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.207\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.208\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.209\\FP_AX_CAB_INSTALLER.exe"= "c:\\Program Files\\Trend Micro\\HijackThis\\HijackThis.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.210\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\system32\\ntvdm.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.211\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\regedit.exe"= "c:\\WINDOWS\\system32\\regsvr32.exe"= "c:\\WINDOWS\\system32\\netsh.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724 R0 lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [7/2/2009 11:30 AM 64160] R0 tffsport;M-Systems DiskOnChip 2000;c:\windows\SYSTEM32\DRIVERS\tffsport.sys [8/4/2004 12:00 PM 149376] R2 lavasoft ad-aware service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456] R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\SYSTEM32\DRIVERS\rt2870.sys [7/28/2007 2:50 PM 517632] S1 8589ff;8589ff;c:\windows\system32\drivers\8589ff.sys --> c:\windows\system32\drivers\8589ff.sys [?] S3 bcgame;Nostromo HID Device Minidriver;c:\windows\SYSTEM32\DRIVERS\bcgame.sys [7/23/2003 2:16 PM 22821] S3 cpuz130;cpuz130;\??\c:\docume~1\RANDYA~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\RANDYA~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?] S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?] S3 XDva016;XDva016;\??\c:\windows\system32\XDva016.sys --> c:\windows\system32\XDva016.sys [?] S4 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 5:45 AM 13088] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] "c:\progra~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] "c:\progra~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install "c:\progra~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /install [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}] "c:\progra~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}] "c:\progra~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install "c:\progra~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:IE50 /user /install [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] c:\windows\SYSTEM32\updcrl.exe -e -u c:\windows\SYSTEM\verisignpub1.crl . Contents of the 'Scheduled Tasks' folder 2009-07-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 15:29] . - - - - ORPHANS REMOVED - - - - ShellIconOverlayIdentifiers-{7D688A77-C613-11D0-999B-00C04FD655E1} - (no file) HKLM-Run-PrinTray - c:\windows\System32\spool\DRIVERS\W32X86\3\printray.exe ShellExecuteHooks-{6809e580-a3a7-11d1-9a00-00a0c945b006} - (no file) . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchURL,(Default) = hxxp://www.google.com/search?q=%s Trusted Zone: aol.com\free Trusted Zone: turbotax.com DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab DPF: Internet Explorer Classes for Java - file://c:\windows\SYSTEM\iejava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-05 16:58 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(444) c:\windows\system32\WlanGINA.dll c:\windows\system32\Ati2evxx.dll - - - - - - - > 'Explorer.exe'(4756) c:\windows\system32\shdoclc.dll c:\windows\system32\browselc.dll c:\program files\Common Files\Ahead\Lib\NeroDigitalExt.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\program files\Common Files\Seagate\Schedule2\schedul2.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\wbem\unsecapp.exe g:\program files\trendnet\WinDomainLogon.exe c:\program files\PESTPATROL\PPMEMCHECK.EXE c:\program files\PESTPATROL\PPCONTROL.EXE c:\program files\PESTPATROL\COOKIEPATROL.EXE . ************************************************************************** . Completion time: 2009-07-05 17:02 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-05 21:02 Pre-Run: 21,313,126,400 bytes free Post-Run: 21,215,641,600 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect |
|
|
Jul 5 2009, 03:42 PM
Post
#4
|
|
![]() GeekU Teacher Posts: 34,385 From: Dublin OS: XP |
hi
1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: QUOTE File:: c:\documents and settings\RANDYANDAMY\Application Data\Microsoft\Windows\ms65.exe c:\windows\asbmeidAv.sys c:\windows\SYSTEM\vAdiembsa.sys c:\windows\system32\drivers\8589ff.sys Folder:: c:\documents and settings\All Users\Application Data\12965564 Driver:: 8589ff KillAll:: Save this as CFScript.txt, in the same location as ComboFix.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply. |
|
|
Jul 5 2009, 07:38 PM
Post
#5
|
|
|
New Member ![]() Posts: 4 From: Cleveland , Ohio OS: Windows 7 Build 7100 |
COMBOFIX LOG USING CFSCRIPT:
ComboFix 09-07-05.01 - RANDYANDAMY 07/05/2009 21:22.2 - FAT32x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.767.431 [GMT -4:00] Running from: c:\documents and settings\RANDYANDAMY\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\RANDYANDAMY\Desktop\CFScript.txt FILE :: "c:\documents and settings\RANDYANDAMY\Application Data\Microsoft\Windows\ms65.exe" "c:\windows\asbmeidAv.sys" "c:\windows\SYSTEM\vAdiembsa.sys" "c:\windows\system32\drivers\8589ff.sys" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\12965564 c:\documents and settings\RANDYANDAMY\Application Data\Microsoft\Windows\ms65.exe c:\windows\asbmeidAv.sys c:\windows\SYSTEM\vAdiembsa.sys . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_8589ff ((((((((((((((((((((((((( Files Created from 2009-06-06 to 2009-07-06 ))))))))))))))))))))))))))))))) . 2009-07-05 21:17 . 2004-08-04 16:00 25600 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll 2009-07-05 09:15 . 2009-07-05 09:15 -------- d-----w- C:\VundoFix Backups 2009-07-05 07:57 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-05 07:57 . 2009-07-05 07:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-07-05 07:57 . 2009-07-05 07:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-07-05 07:57 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-07-02 17:42 . 2009-07-02 17:42 -------- d-----w- c:\program files\CleanUp! 2009-07-02 16:20 . 2009-07-02 16:20 194 ---ha-w- C:\aaw7boot.cmd 2009-07-02 16:19 . 2009-07-02 16:19 -------- d-----w- c:\program files\RegCleaner 2009-07-02 16:13 . 2009-05-21 15:33 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-07-02 15:30 . 2009-07-02 15:29 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-07-02 15:24 . 2009-07-02 15:24 -------- d--h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-07-02 15:24 . 2009-03-12 08:17 2902048 ----a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe 2009-07-02 15:24 . 2009-07-02 15:24 -------- d-----w- c:\program files\Lavasoft 2009-07-02 15:24 . 2009-07-02 15:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2009-07-02 14:29 . 2004-08-04 12:00 5632 ----a-w- c:\windows\system32\dllcache\smimsgif.dll 2009-07-02 14:28 . 2004-08-04 12:00 98304 ----a-w- c:\windows\system32\dllcache\msir3jp.dll 2009-07-02 14:27 . 2004-08-04 12:00 10129408 ----a-w- c:\windows\system32\dllcache\hwxkor.dll 2009-07-02 14:26 . 2004-08-04 12:00 480256 ----a-w- c:\windows\system32\dllcache\cintsetp.exe 2009-07-02 14:25 . 2003-03-24 20:52 16384 ----a-w- c:\windows\system32\dllcache\tcptsat.dll 2009-07-02 14:12 . 2004-08-04 02:31 20992 ----a-w- c:\windows\system32\drivers\RTL8139.sys 2009-07-02 14:09 . 2004-08-04 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll 2009-07-02 14:09 . 2004-08-04 12:00 24661 ----a-w- c:\windows\system32\dllcache\spxcoins.dll 2009-07-02 14:09 . 2004-08-04 12:00 13312 ----a-w- c:\windows\system32\irclass.dll 2009-07-02 14:09 . 2004-08-04 12:00 13312 ----a-w- c:\windows\system32\dllcache\irclass.dll 2009-07-02 02:37 . 2007-08-14 18:04 9216 ----a-w- c:\windows\system32\ffnd.exe 2009-07-02 02:14 . 2009-07-02 02:14 -------- d-----w- c:\documents and settings\RANDYANDAMY\Local Settings\Application Data\FreeFixer 2009-07-02 02:14 . 2009-07-02 02:14 -------- d-----w- c:\program files\FreeFixer 2009-07-01 22:31 . 2009-07-01 22:31 -------- d--h--w- C:\$AVG8.VAULT$ 2009-07-01 02:08 . 2004-08-04 12:00 16384 ----a-w- c:\windows\system32\dllcache\isignup.exe 2009-06-30 22:58 . 2009-06-30 22:58 -------- d-----w- c:\program files\Intuit 2009-06-30 13:23 . 2009-06-30 13:23 -------- d-----w- c:\program files\Bazooka Scanner 2009-06-30 12:03 . 2009-06-30 12:03 -------- d-----w- c:\program files\Trend Micro 2009-06-27 08:07 . 2008-10-16 18:06 268648 ----a-w- c:\windows\system32\mucltui.dll 2009-06-26 18:00 . 2009-06-26 18:00 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2 2009-06-26 14:59 . 2009-06-26 14:59 -------- d-----w- c:\windows\system32\scripting 2009-06-26 14:58 . 2009-06-26 14:59 -------- d-----w- c:\windows\system32\en 2009-06-26 14:58 . 2009-06-26 14:59 -------- d-----w- c:\windows\l2schemas 2009-06-26 14:58 . 2009-06-26 14:58 -------- d-----w- c:\windows\system32\bits 2009-06-26 14:56 . 2009-06-26 14:56 -------- d-----w- c:\windows\ServicePackFiles 2009-06-26 14:51 . 2009-06-26 14:51 -------- d-----w- c:\windows\EHome 2009-06-26 13:58 . 2009-06-26 13:59 -------- d-----w- c:\program files\Windows Resource Kits 2009-06-26 02:35 . 2009-06-26 02:35 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe 2009-06-25 17:14 . 2007-08-02 02:47 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys 2009-06-25 02:54 . 2009-06-25 02:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard 2009-06-25 02:49 . 2009-06-25 02:49 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment 2009-06-19 02:09 . 2009-06-19 02:09 -------- d-----w- c:\program files\Doras Carnival 2 - At the Boardwalk 2009-06-19 02:08 . 2009-06-19 02:09 -------- d-----w- c:\program files\bfgclient 2009-06-19 02:08 . 2009-06-19 02:08 2383904 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\Unpack\bfgsetup_s1_l1.exe 2009-06-19 02:08 . 2009-06-19 02:08 -------- d-----w- c:\documents and settings\All Users\Application Data\BigFishGamesCache . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-02 14:19 . 2004-12-27 16:28 23376 ----a-w- c:\windows\system32\emptyregdb.dat 2009-06-30 13:17 . 2004-12-27 16:51 50840 ----a-w- c:\documents and settings\RANDYANDAMY\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-06-26 15:01 . 2004-12-27 16:30 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-05-24 14:12 . 2009-05-24 14:12 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-05-24 14:12 . 2009-05-24 14:12 -------- d-----w- c:\program files\NOS 2009-05-24 13:46 . 2009-05-24 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Avg7 2009-05-19 22:10 . 2009-05-19 22:10 143864 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\stub\dorascarnival2atth_s1_l1_gF1559T1L1_d557309401[1].exe 2009-05-19 22:10 . 2009-05-19 22:10 2319528 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\clientinstaller\bfgsetup_s1_l1.exe 2009-04-20 15:01 . 2009-04-18 13:55 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys 2009-02-12 01:33 . 2009-02-12 01:33 501 ----a-w- c:\program files\Shortcut (2) to Mystery P.I. - The Vegas Heist.lnk 2009-02-12 01:33 . 2009-02-12 01:33 501 ----a-w- c:\program files\Shortcut to Mystery P.I. - The Vegas Heist.lnk 2006-02-03 12:21 . 2006-02-03 12:20 948936 ----a-w- c:\program files\install_flash_player.exe 2004-12-27 16:36 . 2004-12-27 16:36 707 ----a-w- c:\program files\MS-DOS Prompt.LNK 2004-04-11 19:49 . 2004-04-11 19:49 3616400 ----a-w- c:\program files\Install_AIM.exe 2003-08-12 09:02 . 1980-01-01 04:00 384 ----a-w- c:\program files\Internet Explorer.lnk 2003-08-12 09:02 . 1980-01-01 04:00 369 ----a-w- c:\program files\Outlook Express.lnk 2003-08-12 09:02 . 1980-01-01 04:00 295 ----a-w- c:\program files\Windows Explorer.lnk 2002-11-15 01:51 . 2002-11-15 01:51 536018 ----a-w- c:\program files\vp3.rar 2002-10-12 06:27 . 1980-01-01 04:00 11079 ---h--w- c:\program files\folder.htt . ((((((((((((((((((((((((((((( SnapShot@2009-07-05_20.58.50 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-06 01:32 . 2009-07-06 01:32 16384 c:\windows\temp\Perflib_Perfdata_52c.dat + 2004-12-28 16:38 . 2008-10-16 18:08 34328 c:\windows\SYSTEM32\wups.dll + 2004-12-27 16:28 . 2008-10-16 18:09 51224 c:\windows\SYSTEM32\wuauclt.exe + 2009-07-05 20:59 . 2008-10-16 18:08 34328 c:\windows\SYSTEM32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll + 2009-07-05 21:48 . 2009-07-05 21:48 84661 c:\windows\SYSTEM32\MACROMED\Flash\uninstall_plugin.exe + 2004-12-27 16:28 . 2008-10-16 18:09 51224 c:\windows\SYSTEM32\dllcache\wuauclt.exe + 2004-12-27 16:28 . 2008-10-16 18:12 323608 c:\windows\SYSTEM32\wucltui.dll + 2004-12-27 16:28 . 2008-10-16 18:12 561688 c:\windows\SYSTEM32\wuapi.dll - 2009-07-02 12:10 . 2009-02-02 22:15 240544 c:\windows\SYSTEM32\MACROMED\Flash\NPSWF32_FlashUtil.exe + 2009-02-03 02:15 . 2009-02-03 02:15 240544 c:\windows\SYSTEM32\MACROMED\Flash\NPSWF32_FlashUtil.exe + 2004-12-27 16:28 . 2008-10-16 18:12 323608 c:\windows\SYSTEM32\dllcache\wucltui.dll + 2004-12-27 16:28 . 2008-10-16 18:13 1809944 c:\windows\SYSTEM32\wuaueng.dll + 2009-02-03 02:15 . 2009-02-03 02:15 3771296 c:\windows\SYSTEM32\MACROMED\Flash\NPSWF32.dll - 2009-07-02 12:10 . 2009-02-02 22:15 3771296 c:\windows\SYSTEM32\MACROMED\Flash\NPSWF32.dll + 2004-12-27 16:28 . 2008-10-16 18:13 1809944 c:\windows\SYSTEM32\dllcache\wuaueng.dll + 2009-02-02 22:07 . 2009-02-02 22:07 1914440 c:\windows\Downloaded Program Files\CONFLICT.219\FP_AX_CAB_INSTALLER.exe + 2009-02-02 22:07 . 2009-02-02 22:07 1914440 c:\windows\Downloaded Program Files\CONFLICT.218\FP_AX_CAB_INSTALLER.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="g:\program files\steam\steam.exe" [2009-06-11 1217784] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PPMemCheck"="c:\progra~1\PESTPA~1\PPMemCheck.exe" [2004-04-02 148480] "PestPatrol Control Center"="c:\progra~1\PESTPA~1\PPControl.exe" [2004-11-15 98304] "CookiePatrol"="c:\progra~1\PESTPA~1\CookiePatrol.exe" [2005-01-10 73728] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696] "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2006-03-15 421888] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648] "LexStart"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888] "SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-12-01 77824] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Webshots.lnk - c:\program files\Webshots\WebshotsTray.exe [2003-7-13 208896] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588] ImageMixer 3 SE Camera Monitor for SD.lnk - g:\program files\CameraMonitor.exe [2008-6-23 253952] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "EditLevel"= 0 (0x0) "NoCommonGroups"= 0 (0x0) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lavasoft ad-aware service] @="Service" HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWC: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWC:\Program Files HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á³# Lh'þ9Óœð3rÅWc:\program files\ISTsvc [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "SAIMON"=c:\windows\SYSTEM32\SaiMon.exe "DisableEHCI"=c:\windows\NoUSB20.EXE "EM_EXEC"=c:\progra~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE "SystemTray"=SysTray.Exe "NvCplDaemon"=RUNDLL32.EXE c:\windows\SYSTEM32\nvcpl.dll,NvStartup "tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" /server /nosystray "PestPatrol Control Center"=c:\progra~1\PESTPA~1\PPControl.exe "PPMemCheck"=c:\progra~1\PESTPA~1\PPMemCheck.exe "MMTray"=MMTray.exe "Cmaudio"=RunDll32 cmicnfg.dll,CMICtrlWnd "nwiz"=nwiz.exe /install "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot "QuickTime Task"="c:\windows\SYSTEM32\qttask.exe" -atboottime "Win Server Updt"=c:\windows\wupdt.exe "*CATDRV"=c:\windows\HELP\CATDRV.EXE [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys] "*OLEFAX"=c:\windows\JAVA\TRUSTLIB\OLEFAX.EXE [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-] "ScriptBlocking"= "SchedulingAgent"=mstask.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Ubi Soft\\IL2 Sturmovik\\il2.exe"= "g:\\Program Files\\Steam\\SteamApps\\waycoolsurfer\\half-life 2 deathmatch\\hl2.exe"= "g:\\Program Files\\Steam\\SteamApps\\waycoolsurfer\\team fortress 2\\hl2.exe"= "c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "g:\\Program Files\\Quake III Arena\\quake3.exe"= "f:\\World of Warcraft\\Launcher.exe"= "f:\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"= "f:\\World of Warcraft\\WoW-3.1.1.9835-to-3.1.2.9901-enUS-downloader.exe"= "c:\\WINDOWS\\system32\\Ati2evxx.exe"= "g:\\Program Files\\trendnet\\WinDomainLogon.exe"= "c:\\Program Files\\Common Files\\LightScribe\\LSSrvc.exe"= "c:\\Program Files\\Canon\\CAL\\CALMAIN.exe"= "c:\\Program Files\\Webshots\\Webshots.scr"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.185\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.186\\FP_AX_CAB_INSTALLER.exe"= "c:\\Program Files\\WinRAR\\WinRAR.exe"= "g:\\program files\\steam\\steam.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.187\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\System32\\taskmgr.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.188\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.189\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.190\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\system32\\dumprep.exe"= "c:\\WINDOWS\\system32\\dwwin.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.191\\FP_AX_CAB_INSTALLER.exe"= "g:\\Program Files\\Rockstar Games\\GTA San Andreas\\samp.exe"= "g:\\Program Files\\Rockstar Games\\GTA San Andreas\\gta_sa.exe"= "c:\\WINDOWS\\System32\\WgaTray.exe"= "c:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe"= "c:\\Program Files\\PestPatrol\\PPMemCheck.exe"= "c:\\Program Files\\PestPatrol\\PPControl.exe"= "c:\\Program Files\\PestPatrol\\CookiePatrol.exe"= "c:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"= "c:\\WINDOWS\\SOUNDMAN.EXE"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\WINDOWS\\system32\\wuauclt.exe"= "c:\\Program Files\\Belkin\\Nostromo\\nost_LM.exe"= "g:\\Program Files\\CameraMonitor.exe"= "c:\\Program Files\\Java\\jre1.6.0_07\\bin\\jucheck.exe"= "c:\\WINDOWS\\system32\\MsiExec.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.204\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.205\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.206\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.207\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.208\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.209\\FP_AX_CAB_INSTALLER.exe"= "c:\\Program Files\\Trend Micro\\HijackThis\\HijackThis.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.210\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\system32\\ntvdm.exe"= "c:\\WINDOWS\\Downloaded Program Files\\CONFLICT.211\\FP_AX_CAB_INSTALLER.exe"= "c:\\WINDOWS\\regedit.exe"= "c:\\WINDOWS\\system32\\regsvr32.exe"= "c:\\WINDOWS\\system32\\netsh.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724 R0 lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [7/2/2009 11:30 AM 64160] R0 tffsport;M-Systems DiskOnChip 2000;c:\windows\SYSTEM32\DRIVERS\tffsport.sys [8/4/2004 12:00 PM 149376] R2 lavasoft ad-aware service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456] R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\SYSTEM32\DRIVERS\rt2870.sys [7/28/2007 2:50 PM 517632] S3 bcgame;Nostromo HID Device Minidriver;c:\windows\SYSTEM32\DRIVERS\bcgame.sys [7/23/2003 2:16 PM 22821] S3 cpuz130;cpuz130;\??\c:\docume~1\RANDYA~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\RANDYA~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?] S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?] S3 XDva016;XDva016;\??\c:\windows\system32\XDva016.sys --> c:\windows\system32\XDva016.sys [?] S4 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 5:45 AM 13088] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] "c:\progra~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] "c:\progra~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install "c:\progra~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /install [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}] "c:\progra~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}] "c:\progra~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install "c:\progra~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:IE50 /user /install [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] c:\windows\SYSTEM32\updcrl.exe -e -u c:\windows\SYSTEM\verisignpub1.crl . Contents of the 'Scheduled Tasks' folder 2009-07-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 15:29] . - - - - ORPHANS REMOVED - - - - ShellExecuteHooks-{6809e580-a3a7-11d1-9a00-00a0c945b006} - (no file) . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchURL,(Default) = hxxp://www.google.com/search?q=%s Trusted Zone: aol.com\free Trusted Zone: turbotax.com DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab DPF: Internet Explorer Classes for Java - file://c:\windows\SYSTEM\iejava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\RANDYANDAMY\Application Data\Mozilla\Firefox\Profiles\gqlk35dz.default\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-05 21:33 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(440) c:\windows\system32\WlanGINA.dll c:\windows\system32\Ati2evxx.dll - - - - - - - > 'Explorer.exe'(4376) c:\windows\system32\shdoclc.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe g:\program files\trendnet\WinDomainLogon.exe c:\program files\Common Files\Seagate\Schedule2\schedul2.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\PESTPATROL\PPMEMCHECK.EXE c:\program files\PESTPATROL\PPCONTROL.EXE c:\program files\PESTPATROL\COOKIEPATROL.EXE c:\program files\LAVASOFT\AD-AWARE\AAWTRAY.EXE . ************************************************************************** . Completion time: 2009-07-06 21:37 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-06 01:37 ComboFix2.txt 2009-07-05 21:02 Pre-Run: 21,164,752,896 bytes free Post-Run: 21,153,120,256 bytes free 355 --- E O F --- 2009-06-27 18:02 |
|
|
Jul 6 2009, 07:30 AM
Post
#6
|
|
![]() GeekU Teacher Posts: 34,385 From: Dublin OS: XP |
hi
Please download OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post. Download TFC to your desktop
Please download Malwarebytes' Anti-Malware from Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Go to Kaspersky website and perform an online antivirus scan.
|
|
|
Jul 11 2009, 09:36 AM
Post
#7
|
|
![]() GeekU Teacher Posts: 34,385 From: Dublin OS: XP |
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
5 / 349 | 7th January 2006 - 04:04 PM paulmarkj started - last by greyknight17 |
|||||
![]() |
2 / 302 | 6th March 2008 - 06:10 PM leex started - last by Rorschach112 |
|||||
![]() |
0 / 43 | 1st September 2009 - 04:40 AM rix1505 started - last by rix1505 |
|||||
![]() |
2 / 96 | 26th October 2009 - 12:12 PM jtfireball started - last by hammerman |
|||||
|
Time is now: 8th November 2009 - 12:13 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising