Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Another vipdown.exe infection


  • This topic is locked This topic is locked

#1
Red_6

Red_6

    Member

  • Member
  • PipPip
  • 76 posts
I was going to follow the instructions to remove it from another post but I thought I better get it checked with one of you experts first.

Thanks in advance.


Logfile of HijackThis v1.99.1
Scan saved at 03:40:41, on 04/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\RUNDLL.EXE
C:\WINDOWS\BJH\server.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\vsapidmv1.exe
C:\WINDOWS\System32\winasse.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\UPDATE2\Update.exe
C:\WINDOWS\command\rundll32.exe
C:\Program Files\Microsoft\svhost32.exe
C:\WINDOWS\System32\svchqs.exe
C:\WINDOWS\System32\Realplayer.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\WINDOWS\realupdate.exe
C:\WINDOWS\winampc.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Tools\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.c...msearch-en.html
F2 - REG:system.ini: Shell=Explorer.exe vsapidmv1.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: 5940bar BHO - {15953528-6C01-481A-8DB4-01888FB85B7D} - C:\WINDOWS\system32\CN5940~1.DLL
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5059.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: ÐÅÏ¢¼ìË÷ - {CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} - C:\WINDOWS\system32\IEHelper.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 5940bar - {1A45F0FB-9586-4742-8343-8732C7AAFB88} - C:\WINDOWS\system32\CN5940~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [iPodManager] C:\Program Files\iPod\bin\iPodManager.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [wdfmgr32] C:\WINDOWS\System32\wdfmgr32.exe
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE2\Update.exe
O4 - HKLM\..\Run: [Tray] C:\WINDOWS\command\rundll32.exe
O4 - HKLM\..\Run: [ms] C:\Program Files\Microsoft\svhost32.exe
O4 - HKLM\..\Run: [jiahus] C:\WINDOWS\System32\svchqs.exe
O4 - HKLM\..\Run: [Realplayer.exe] C:\WINDOWS\System32\Realplayer.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updatereal] C:\WINDOWS\realupdate.exe other
O4 - HKCU\..\Run: [msnnt] C:\WINDOWS\winampc.exe
O4 - HKCU\..\Run: [MyShares] c:\program Files\Òä¶à¶à\MyShares.exe /tray
O4 - HKCU\..\Run: [Realplayer.exe] C:\WINDOWS\System32\Realplayer.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KSD2Service - Unknown owner - C:\WINDOWS\System32\SVCH0ST.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Network Logons (NetWorkLogons) - Unknown owner - rundll32.exe (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Distributed Link Tracking Clientbjh (ServiceBJH) - Unknown owner - C:\WINDOWS\BJH\server.exe
  • 0

Advertisements


#2
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
We can definitely help you, but first you need to help us. The first step in this process is to apply Service Pack 1a for Windows XP. Without this update, you're wide open to re-infection, and we're both just wasting our time.
Click here: http://www.microsoft...&DisplayLang=en
Apply the update, reboot, and post a fresh Hijack This log.
  • 0

#3
Red_6

Red_6

    Member

  • Topic Starter
  • Member
  • PipPip
  • 76 posts
Update Done.
----------------

Logfile of HijackThis v1.99.1
Scan saved at 03:32:07, on 05/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\RUNDLL.EXE
C:\WINDOWS\BJH\server.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\system32\vsapidmv1.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\winasse.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\wdfmgr32.exe
C:\Program Files\Common Files\UPDATE2\Update.exe
C:\WINDOWS\command\rundll32.exe
C:\Program Files\Microsoft\svhost32.exe
C:\WINDOWS\System32\svchqs.exe
C:\WINDOWS\System32\Realplayer.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\WINDOWS\realupdate.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\Explorer.exe
C:\Tools\HijackThis.exe
C:\WINDOWS\win1\vipdown.exe
C:\WINDOWS\win1\setup134.exe
C:\WINDOWS\win1\bind_40004.exe
C:\WINDOWS\win1\Setup-227.exe
C:\WINDOWS\win1\1753.exe
C:\WINDOWS\win1\198994004.exe
C:\WINDOWS\win1\4126ther.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.7939.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.c...msearch-en.html
F2 - REG:system.ini: Shell=Explorer.exe vsapidmv1.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: 5940bar BHO - {15953528-6C01-481A-8DB4-01888FB85B7D} - C:\WINDOWS\system32\CN5940~1.DLL
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5059.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: ÐÅÏ¢¼ìË÷ - {CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} - C:\WINDOWS\system32\IEHelper.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: 5940bar - {1A45F0FB-9586-4742-8343-8732C7AAFB88} - C:\WINDOWS\system32\CN5940~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [iPodManager] C:\Program Files\iPod\bin\iPodManager.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [wdfmgr32] C:\WINDOWS\System32\wdfmgr32.exe
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE2\Update.exe
O4 - HKLM\..\Run: [Tray] C:\WINDOWS\command\rundll32.exe
O4 - HKLM\..\Run: [ms] C:\Program Files\Microsoft\svhost32.exe
O4 - HKLM\..\Run: [jiahus] C:\WINDOWS\System32\svchqs.exe
O4 - HKLM\..\Run: [Realplayer.exe] C:\WINDOWS\System32\Realplayer.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updatereal] C:\WINDOWS\realupdate.exe other
O4 - HKCU\..\Run: [msnnt] C:\WINDOWS\winampc.exe
O4 - HKCU\..\Run: [MyShares] c:\program Files\Òä¶à¶à\MyShares.exe /tray
O4 - HKCU\..\Run: [Realplayer.exe] C:\WINDOWS\System32\Realplayer.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\quartz32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KSD2Service - Unknown owner - C:\WINDOWS\System32\SVCH0ST.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Network Logons (NetWorkLogons) - Unknown owner - rundll32.exe (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Distributed Link Tracking Clientbjh (ServiceBJH) - Unknown owner - C:\WINDOWS\BJH\server.exe
  • 0

#4
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Please post each requested log with a new reply so that the logs don't get cut off.

Create a Startup List
  • Please boot into safe mode by tapping the F8 key just before Windows starts to load.
  • Once in safe mode, open HiJackThis
  • Click on the "Config..." button on the bottom right
  • Click on the tab "Misc Tools"
  • Put a check to the 2 boxes next to the Box that says "Generate StartupList log"
  • Click on the button "Generate StartupList log"
  • Copy and paste the StartupList from the notepad into your next post. (it will be saved in the same folder with HijackThis)
Next,

Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.

Next,

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
  • 0

#5
Red_6

Red_6

    Member

  • Topic Starter
  • Member
  • PipPip
  • 76 posts
startuplist.txt
---------------

StartupList report, 5/10/2006, 4:53:59
StartupList version: 1.52.2
Started from : C:\Tools\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\vsapidmv1.exe
C:\Tools\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Administrator\Start Menu\Programs\Startup]
*No files*

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
D-Link AirPlus.lnk = ?

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\System32\Userinit.exe

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

IMJPMIG8.1 = C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
PHIME2002ASync = C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
LTSMMSG = LTSMMSG.exe
AtiPTA = atiptaxx.exe
NeroCheck = C:\WINDOWS\system32\NeroCheck.exe
SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
iTunesHelper = C:\Program Files\iTunes\iTunesHelper.exe
iPodManager = C:\Program Files\iPod\bin\iPodManager.exe
MMTray = C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
mmtask = C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
wdfmgr32 = C:\WINDOWS\System32\wdfmgr32.exe
Update = C:\Program Files\Common Files\UPDATE2\Update.exe
Tray = C:\WINDOWS\command\rundll32.exe
ms = C:\Program Files\Microsoft\svhost32.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\System32\ctfmon.exe

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
*No values found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

--------------------------------------------------

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\System32\mshta.exe "%1" %*

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\INF\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}]
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{5945c046-1e7d-11d1-bc44-00c04fd912be}]
StubPath = rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%\INF\msmsgs.inf,BLC.Install.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}]
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}]
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}]
StubPath = %SystemRoot%\system32\ie4uinit.exe

--------------------------------------------------

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe vsapidmv1.exe
SCRNSAVE.EXE=%SystemRoot%\System32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

--------------------------------------------------

Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
5940bar BHO - C:\WINDOWS\system32\CN5940~1.DLL - {15953528-6C01-481A-8DB4-01888FB85B7D}
(no name) - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5059.dll - {16B770A0-0E87-4278-B748-2460D64A8386}
(no name) - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - c:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\WINDOWS\system32\IEHelper.dll - {CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004}

--------------------------------------------------

Enumerating Task Scheduler jobs:

*No jobs found*

--------------------------------------------------

Enumerating Download Program Files:

[Java Plug-in 1.5.0_02]
InProcServer32 = C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Java Plug-in 1.5.0_02]
InProcServer32 = C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash8a.ocx
CODEBASE = http://download.macr...ash/swflash.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
Protocol #1: C:\WINDOWS\System32\quartz32.dll
Protocol #2: C:\WINDOWS\System32\ultra32.dll
Protocol #3: C:\WINDOWS\System32\ultra32.dll
Protocol #4: C:\WINDOWS\system32\mswsock.dll
Protocol #5: C:\WINDOWS\system32\mswsock.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\rsvpsp.dll
Protocol #8: C:\WINDOWS\system32\rsvpsp.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll
Protocol #16: C:\WINDOWS\system32\mswsock.dll
Protocol #17: C:\WINDOWS\system32\mswsock.dll
Protocol #18: C:\WINDOWS\system32\mswsock.dll
Protocol #19: C:\WINDOWS\system32\mswsock.dll
Protocol #20: C:\WINDOWS\system32\mswsock.dll
Protocol #21: C:\WINDOWS\system32\mswsock.dll
Protocol #22: C:\WINDOWS\system32\mswsock.dll
Protocol #23: C:\WINDOWS\System32\quartz32.dll

--------------------------------------------------

Enumerating Windows NT/2000/XP services

NT Data Provider: C:\WINDOWS\SYSTEM32\RUNDLL.EXE C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL,Export 1087 (autostart)
Intel® 82801 Audio Driver Install Service (WDM): system32\drivers\ac97intc.sys (manual start)
Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
Microsoft Embedded Controller Driver: System32\DRIVERS\ACPIEC.sys (system)
Adobe LM Service: "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" (manual start)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD Networking Support Environment: \SystemRoot\System32\drivers\afd.sys (autostart)
Intel AGP Bus Filter: System32\DRIVERS\agp440.sys (system)
D-Link AirPlus Wireless Adapter: System32\DRIVERS\airplus.sys (manual start)
Alerter: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
1394 ARP Client Protocol: System32\DRIVERS\arp1394.sys (manual start)
RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys (system)
Ati HotKey Poller: %SystemRoot%\System32\Ati2evxx.exe (autostart)
ati2mtag: System32\DRIVERS\ati2mtag.sys (manual start)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Computer Browser: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
CD-ROM Driver: System32\DRIVERS\cdrom.sys (system)
Indexing Service: C:\WINDOWS\System32\cisvc.exe (manual start)
ClipBook: %SystemRoot%\system32\clipsrv.exe (manual start)
Microsoft AC Adapter Driver: System32\DRIVERS\CmBatt.sys (manual start)
Microsoft Composite Battery Driver: System32\DRIVERS\compbatt.sys (system)
COM+ System Application: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Crystal WDM Audio Codec Driver: system32\drivers\cwawdm.sys (manual start)
DefWatch: C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe (autostart)
DHCP Client: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Disk Driver: System32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sys (disabled)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
Intel® PRO Adapter Driver: System32\DRIVERS\e100b325.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Floppy Disk Controller Driver: System32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: System32\DRIVERS\flpydisk.sys (manual start)
FsVga: System32\DRIVERS\fsvga.sys (system)
Volume Manager Driver: System32\DRIVERS\ftdisk.sys (system)
GEAR CDRom Filter: SYSTEM32\DRIVERS\GEARAspiWDM.sys (manual start)
ggeedgcg: \??\C:\WINDOWS\system32\drivers\ggeedgcg.sys (system)
Generic Packet Classifier: System32\DRIVERS\msgpc.sys (manual start)
gwemjqm: \??\C:\DOCUME~1\dam\LOCALS~1\Temp\gwemjqmxfd (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Microsoft HID Class Driver: System32\DRIVERS\hidusb.sys (manual start)
IEEE-1284.4 Driver HPZid412: System32\DRIVERS\HPZid412.sys (manual start)
Print Class Driver for IEEE-1284.4 HPZipr12: System32\DRIVERS\HPZipr12.sys (manual start)
USB to IEEE-1284.4 Translation Driver HPZius12: System32\DRIVERS\HPZius12.sys (manual start)
i8042 Keyboard and PS/2 Mouse Port Driver: System32\DRIVERS\i8042prt.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\System32\imapi.exe (manual start)
IntelIde: System32\DRIVERS\intelide.sys (system)
IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
iPod Service: C:\Program Files\iPod\bin\iPodService.exe (manual start)
IPSEC driver: System32\DRIVERS\ipsec.sys (system)
IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: System32\DRIVERS\isapnp.sys (system)
Sony Ericsson 750 driver (WDM): System32\DRIVERS\k750bus.sys (manual start)
Sony Ericsson 750 USB WMC Modem Filter: System32\DRIVERS\k750mdfl.sys (manual start)
Sony Ericsson 750 USB WMC Modem Drivers: System32\DRIVERS\k750mdm.sys (manual start)
Sony Ericsson 750 USB WMC Device Management Drivers: System32\DRIVERS\k750mgmt.sys (manual start)
Sony Ericsson 750 USB WMC OBEX Interface Drivers: System32\DRIVERS\k750obex.sys (manual start)
Keyboard Class Driver: System32\DRIVERS\kbdclass.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
KSD2Service: C:\WINDOWS\System32\SVCH0ST.exe (autostart)
Server: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Registry Protect: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
SENS LT56ADW Modem: System32\DRIVERS\LTSM.sys (manual start)
Macromedia Licensing Service: "C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe" (manual start)
Messenger: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
mfobap: \??\C:\DOCUME~1\dam\LOCALS~1\Temp\mfobaptkp (manual start)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
Mouse Class Driver: System32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: System32\DRIVERS\mouhid.sys (manual start)
WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
Windows Installer: C:\WINDOWS\System32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
NAVAP: \??\C:\PROGRA~1\SYMANT~1\SYMANT~1\NAVAP.sys (manual start)
NAVAPEL: \??\C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\NAVAPEL.SYS (autostart)
NAVENG: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20041208.018\NAVENG.sys (manual start)
NAVEX15: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20041208.018\NAVEX15.sys (manual start)
Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: System32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: System32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: System32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (manual start)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (manual start)
Net Logon: %SystemRoot%\System32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Network Logons: rundll32.exe KB27861001.log,start (autostart)
1394 Net Driver: System32\DRIVERS\nic1394.sys (manual start)
Network Location Awareness (NLA): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Symantec AntiVirus Client: C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe (manual start)
Netgroup Packet Filter: System32\DRIVERS\npf.sys (manual start)
NT LM Security Support Provider: %SystemRoot%\System32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
nwlnksipx: \??\C:\WINDOWS\System32\drivers\nwlnksipx.sys (autostart)
OHCI Compliant IEEE 1394 Host Controller: System32\DRIVERS\ohci1394.sys (system)
Office Source Engine: C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (manual start)
Parallel port driver: System32\DRIVERS\parport.sys (manual start)
PCI Bus Driver: System32\DRIVERS\pci.sys (system)
Pcmcia: System32\DRIVERS\pcmcia.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\System32\lsass.exe (autostart)
WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
Processor Driver: System32\DRIVERS\processr.sys (system)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
QoS Packet Scheduler: System32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
PxHelp20: System32\DRIVERS\PxHelp20.sys (system)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: System32\DRIVERS\raspti.sys (manual start)
Rdbss: System32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
RGWatch: system32\DRIVERS\RGWatch.sys (system)
Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
SBP-2 Transport/Protocol Bus Driver: System32\DRIVERS\sbp2port.sys (system)
Smart Card Helper: %SystemRoot%\System32\SCardSvr.exe (manual start)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secdrv: System32\DRIVERS\secdrv.sys (manual start)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: System32\DRIVERS\serenum.sys (manual start)
Serial port driver: System32\DRIVERS\serial.sys (system)
Distributed Link Tracking Clientbjh: C:\WINDOWS\BJH\server.exe (autostart)
Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
System Restore Filter Driver: System32\DRIVERS\sr.sys (system)
System Restore Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Srv: System32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
Software Bus Driver: System32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{20494B39-F3F4-43D5-8274-0236DBA05F37} (manual start)
SymEvent: \??\C:\Program Files\Symantec\SYMEVENT.SYS (manual start)
SYMTDI: \??\C:\WINDOWS\System32\Drivers\SYMTDI.SYS (system)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: System32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: System32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Windows User Mode Driver Framework: C:\WINDOWS\System32\wdfmgr.exe (autostart)
Microcode Update Driver: System32\DRIVERS\update.sys (manual start)
Upload Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Universal Plug and Play Device Host: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
Microsoft USB Generic Parent Driver: System32\DRIVERS\usbccgp.sys (manual start)
USB2 Enabled Hub: System32\DRIVERS\usbhub.sys (manual start)
Microsoft USB PRINTER Class: System32\DRIVERS\usbprint.sys (manual start)
USB Scanner Driver: System32\DRIVERS\usbscan.sys (manual start)
USB Mass Storage Driver: System32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: System32\DRIVERS\usbuhci.sys (manual start)
VGA Display Controller.: \SystemRoot\System32\drivers\vga.sys (system)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
Windows Socket 2.0 Non-IFS Service Provider Support Environment: \SystemRoot\System32\drivers\ws2ifsl.sys (manual start)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)


--------------------------------------------------

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

Alexa = C:\WINDOWS\System32\qproecss.exe
Ver = 2006.07.20

--------------------------------------------------

End of report, 33,358 bytes
Report generated in 0.200 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
  • 0

#6
Red_6

Red_6

    Member

  • Topic Starter
  • Member
  • PipPip
  • 76 posts
uninstall_list.txt
------------------

1.0
ABC (remove only)
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Creative Suite
Adobe Download Manager 2.0 (Remove Only)
Adobe InDesign CS
Adobe Photoshop Album 2.0 Starter Edition
Adobe Reader 6.0.1
Adobe SVG Viewer 3.0
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
AudibleManager
Azureus
BitTorrent 3.4.2
Booby
Canon i865
Chinese Navigation2.4.0.10
CleanUp!
CoolSign
D-Link AirPlus
Google Toolbar for Internet Explorer
HijackThis 1.99.1
iPod for Windows
iPod for Windows 2005-01-11
iPod for Windows User Guide
iPod System Software Updater 2.0.1
IrfanView (remove only)
iTunes
J2SE Runtime Environment 5.0 Update 2
Java 2 Runtime Environment Standard Edition v1.2.2
Java 2 Runtime Environment, SE v1.4.2_05
Kazaa Lite K++ v2.4.3
K-Lite Codec Pack 2.24 Full
LiveUpdate 1.80 (Symantec Corporation)
Macromedia Dreamweaver MX 2004
Macromedia Extension Manager
Macromedia Fireworks MX 2004
Macromedia Flash MX 2004
Macromedia Flash Player 8
Macromedia FreeHand MXa
Macromedia Shockwave Player
Microsoft Data Access Components KB870669
Microsoft Office FrontPage 2003
Microsoft Office Professional Edition 2003
Microsoft XML Parser and SDK
Mozilla Firefox (1.0.4)
MSN Messenger 7.5
MUSICMATCH iPod Plug-in
MUSICMATCH?Jukebox
Nero - Burning Rom (Web installer)
Outlook Express Q823353
PowerDVD
pucca_02
QuarkXPress 6.1
QuickTime
RealPlayer
SENS LT56ADW Modem
Sony Ericsson PC Suite
Spybot - Search & Destroy 1.4
Symantec AntiVirus Client
VideoLAN VLC media player 0.7.2
Winamp (remove only)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB823182
Windows XP Hotfix - KB823559
Windows XP Hotfix - KB824105
Windows XP Hotfix - KB825119
Windows XP Hotfix - KB828035
Windows XP Hotfix - KB828741
Windows XP Hotfix - KB833407
Windows XP Hotfix - KB833987
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB837001
Windows XP Hotfix - KB839645
Windows XP Hotfix - KB840315
Windows XP Hotfix - KB840374
Windows XP Hotfix - KB840987
Windows XP Hotfix - KB841356
Windows XP Hotfix - KB841533
Windows XP Hotfix - KB841873
Windows XP Hotfix - KB842773
Windows XP Hotfix - KB873376
Windows XP Hotfix - KB887822
Windows XP Hotfix (SP2) [See Q329048 for more information]
Windows XP Hotfix (SP2) [See Q329115 for more information]
Windows XP Hotfix (SP2) [See Q329390 for more information]
Windows XP Hotfix (SP2) [See Q329834 for more information]
Windows XP Hotfix (SP2) Q329170
Windows XP Hotfix (SP2) Q329441
Windows XP Hotfix (SP2) Q810577
Windows XP Hotfix (SP2) Q810833
Windows XP Hotfix (SP2) Q815021
Windows XP Hotfix (SP2) Q817606
Windows XP Hotfix (SP2) Q819696
Windows XP Service Pack 1a
WinRAR archiver
WinWAP 3.1 PRO
WinZip
  • 0

#7
Red_6

Red_6

    Member

  • Topic Starter
  • Member
  • PipPip
  • 76 posts
ComboFix.txt
---------------

Administrator - 06-10-05 4:56:29.92 Service Pack 1
ComboFix 06.09.28 - Running from: "C:\Tools"

((((((((((((((((((((((((((((((( Files Created from 2006-09-05 to 2006-10-05 ))))))))))))))))))))))))))))))))))


2006-10-05 03:38 77,824 --a------ C:\WINDOWS\system32\engt32c.dll
2006-10-05 03:33 11,776 --a------ C:\WINDOWS\~tmp9258.exe
2006-10-05 03:33 106,496 --a------ C:\WINDOWS\system32\IEHelper.dll
2006-10-05 03:32 86,016 --a------ C:\WINDOWS\system32\ultra32.dll
2006-10-05 03:32 178,440 --a------ C:\WINDOWS\system32\drivers\cdnprot.sys
2006-10-05 02:28 86,016 --a------ C:\WINDOWS\system32\xactsrv.dll
2006-10-05 02:27 9,216 --a------ C:\WINDOWS\system32\wuauserv.dll
2006-10-05 02:27 77,824 --a------ C:\WINDOWS\system32\wmpstub.exe
2006-10-05 02:27 56,832 --a------ C:\WINDOWS\system32\wzcdlg.dll
2006-10-05 02:27 446,464 --a------ C:\WINDOWS\system32\wmvdmoe.dll
2006-10-05 02:27 38,912 --a------ C:\WINDOWS\system32\wsnmp32.dll
2006-10-05 02:27 311,327 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2006-10-05 02:27 296,448 --a------ C:\WINDOWS\system32\wmstream.dll
2006-10-05 02:27 264,704 --a------ C:\WINDOWS\system32\wzcsvc.dll
2006-10-05 02:27 23,552 --a------ C:\WINDOWS\system32\wzcsapi.dll
2006-10-05 02:27 17,408 --a------ C:\WINDOWS\system32\wtsapi32.dll
2006-10-05 02:27 13,312 --a------ C:\WINDOWS\system32\wship6.dll
2006-10-05 02:27 118,784 --a------ C:\WINDOWS\system32\wmsdmoe.dll
2006-10-05 02:26 86,528 --a------ C:\WINDOWS\system32\wlnotify.dll
2006-10-05 02:26 51,200 --a------ C:\WINDOWS\system32\wmerrenu.dll
2006-10-05 02:26 48,128 --a------ C:\WINDOWS\system32\winsta.dll
2006-10-05 02:26 266,752 --a------ C:\WINDOWS\winhlp32.exe
2006-10-05 02:26 171,520 --a------ C:\WINDOWS\system32\winmm.dll
2006-10-05 02:26 168,448 --a------ C:\WINDOWS\system32\wldap32.dll
2006-10-05 02:25 61,952 --a------ C:\WINDOWS\system32\webclnt.dll
2006-10-05 02:25 60,416 --a------ C:\WINDOWS\system32\wextract.exe
2006-10-05 02:25 48,640 --a------ C:\WINDOWS\system32\vdmredir.dll
2006-10-05 02:25 479,261 --a------ C:\WINDOWS\system32\vbscript.dll
2006-10-05 02:25 47,616 --a------ C:\WINDOWS\system32\utilman.exe
2006-10-05 02:25 409,088 --a------ C:\WINDOWS\system32\vssapi.dll
2006-10-05 02:25 339,456 --a------ C:\WINDOWS\system32\usp10.dll
2006-10-05 02:25 316,416 --a------ C:\WINDOWS\system32\wiaservc.dll
2006-10-05 02:25 258,048 --a------ C:\WINDOWS\system32\webcheck.dll
2006-10-05 02:25 203,264 --a------ C:\WINDOWS\system32\uxtheme.dll
2006-10-05 02:25 165,376 --a------ C:\WINDOWS\system32\w32time.dll
2006-10-05 02:25 16,384 --a------ C:\WINDOWS\system32\watchdog.sys
2006-10-05 02:25 124,928 --a------ C:\WINDOWS\system32\webvw.dll
2006-10-05 02:25 119,808 --a------ C:\WINDOWS\system32\wiadss.dll
2006-10-05 02:24 9,856 --------- C:\WINDOWS\system32\drivers\tunmp.sys
2006-10-05 02:24 88,064 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2006-10-05 02:24 82,944 --a------ C:\WINDOWS\system32\smlogsvc.exe
2006-10-05 02:24 81,920 --a------ C:\WINDOWS\system32\trkwks.dll
2006-10-05 02:24 71,168 --a------ C:\WINDOWS\system32\telnet.exe
2006-10-05 02:24 71,168 --a------ C:\WINDOWS\system32\storprop.dll
2006-10-05 02:24 667,648 --a------ C:\WINDOWS\system32\ss3dfo.scr
2006-10-05 02:24 66,560 --a------ C:\WINDOWS\system32\spoolss.dll
2006-10-05 02:24 66,048 --a------ C:\WINDOWS\system32\sigverif.exe
2006-10-05 02:24 638,976 --a------ C:\WINDOWS\system32\sstext3d.scr
2006-10-05 02:24 63,488 --a------ C:\WINDOWS\system32\srclient.dll
2006-10-05 02:24 62,976 --a------ C:\WINDOWS\system32\shgina.dll
2006-10-05 02:24 61,952 --a------ C:\WINDOWS\system32\sti.dll
2006-10-05 02:24 60,416 --a------ C:\WINDOWS\system32\shimeng.dll
2006-10-05 02:24 569,344 --a------ C:\WINDOWS\system32\sspipes.scr
2006-10-05 02:24 534,016 --a------ C:\WINDOWS\system32\spider.exe
2006-10-05 02:24 5,504 --------- C:\WINDOWS\system32\drivers\smbali.sys
2006-10-05 02:24 43,008 --a------ C:\WINDOWS\system32\ssdpsrv.dll
2006-10-05 02:24 420,864 --a------ C:\WINDOWS\system32\shimgvw.dll
2006-10-05 02:24 40,960 --a------ C:\WINDOWS\system32\tscupgrd.exe
2006-10-05 02:24 385,024 --a------ C:\WINDOWS\system32\sqlsrv32.dll
2006-10-05 02:24 384,000 --a------ C:\WINDOWS\system32\themeui.dll
2006-10-05 02:24 364,544 --a------ C:\WINDOWS\system32\ssflwbox.scr
2006-10-05 02:24 334,848 --a------ C:\WINDOWS\system32\smlogcfg.dll
2006-10-05 02:24 33,280 --a------ C:\WINDOWS\system32\shmgrate.exe
2006-10-05 02:24 32,256 --a------ C:\WINDOWS\system32\umandlg.dll
2006-10-05 02:24 27,136 --a------ C:\WINDOWS\system32\ssdpapi.dll
2006-10-05 02:24 251,904 --a------ C:\WINDOWS\system32\strmdll.dll
2006-10-05 02:24 24,064 --a------ C:\WINDOWS\system32\skeys.exe
2006-10-05 02:24 233,984 --a------ C:\WINDOWS\system32\tapisrv.dll
2006-10-05 02:24 231,424 --a------ C:\WINDOWS\system32\upnpui.dll
2006-10-05 02:24 22,528 --a------ C:\WINDOWS\system32\slayerxp.dll
2006-10-05 02:24 22,528 --a------ C:\WINDOWS\system32\shfolder.dll
2006-10-05 02:24 22,016 --a------ C:\WINDOWS\system32\udhisapi.dll
2006-10-05 02:24 200,192 --a------ C:\WINDOWS\system32\termsrv.dll
2006-10-05 02:24 19,456 --a------ C:\WINDOWS\system32\ssmarque.scr
2006-10-05 02:24 18,944 --a------ C:\WINDOWS\system32\ssbezier.scr
2006-10-05 02:24 17,408 --a------ C:\WINDOWS\system32\ssmyst.scr
2006-10-05 02:24 165,376 --a------ C:\WINDOWS\system32\tapi32.dll
2006-10-05 02:24 164,864 --a------ C:\WINDOWS\system32\upnphost.dll
2006-10-05 02:24 16,896 --a------ C:\WINDOWS\system32\snmpapi.dll
2006-10-05 02:24 16,384 --a------ C:\WINDOWS\system32\ups.exe
2006-10-05 02:24 158,720 --a------ C:\WINDOWS\system32\srsvc.dll
2006-10-05 02:24 130,560 --a------ C:\WINDOWS\system32\sti_ci.dll
2006-10-05 02:24 13,312 --a------ C:\WINDOWS\system32\ssstars.scr
2006-10-05 02:24 128,512 --a------ C:\WINDOWS\system32\taskmgr.exe
2006-10-05 02:24 120,320 --a------ C:\WINDOWS\system32\upnp.dll
2006-10-05 02:24 117,760 --a------ C:\WINDOWS\system32\stobject.dll
2006-10-05 02:24 116,224 --a------ C:\WINDOWS\system32\shsvcs.dll
2006-10-05 02:24 11,776 --a------ C:\WINDOWS\system32\sigtab.dll
2006-10-05 02:24 107,008 --a------ C:\WINDOWS\system32\umpnpmgr.dll
2006-10-05 02:24 106,496 --a------ C:\WINDOWS\system32\url.dll
2006-10-05 02:24 10,752 --a------ C:\WINDOWS\system32\tracert.exe
2006-10-05 02:23 98,304 --a------ C:\WINDOWS\system32\oleprn.dll
2006-10-05 02:23 94,208 --a------ C:\WINDOWS\system32\odbccp32.dll
2006-10-05 02:23 91,136 --a------ C:\WINDOWS\system32\rastls.dll
2006-10-05 02:23 891,711 --------- C:\WINDOWS\system32\drivers\nv4_mini.sys
2006-10-05 02:23 87,304 --a------ C:\WINDOWS\system32\rdpdd.dll
2006-10-05 02:23 82,944 --a------ C:\WINDOWS\system32\psbase.dll
2006-10-05 02:23 8,192 --a------ C:\WINDOWS\system32\scrnsave.scr
2006-10-05 02:23 75,912 --a------ C:\WINDOWS\system32\rdpwsx.dll
2006-10-05 02:23 74,240 --a------ C:\WINDOWS\system32\rtcshare.exe
2006-10-05 02:23 71,168 --a------ C:\WINDOWS\system32\sdbinst.exe
2006-10-05 02:23 686,080 --a------ C:\WINDOWS\system32\opengl32.dll
2006-10-05 02:23 61,440 --a------ C:\WINDOWS\system32\odbccu32.dll
2006-10-05 02:23 61,440 --a------ C:\WINDOWS\system32\odbccr32.dll
2006-10-05 02:23 6,144 --a------ C:\WINDOWS\system32\sensapi.dll
2006-10-05 02:23 58,880 --a------ C:\WINDOWS\system32\pautoenr.dll
2006-10-05 02:23 57,856 --a------ C:\WINDOWS\system32\raschap.dll
2006-10-05 02:23 56,320 --a------ C:\WINDOWS\system32\remotepg.dll
2006-10-05 02:23 53,248 --a------ C:\WINDOWS\system32\packager.exe
2006-10-05 02:23 53,248 --a------ C:\WINDOWS\system32\odbcconf.exe
2006-10-05 02:23 52,224 --a------ C:\WINDOWS\system32\secur32.dll
2006-10-05 02:23 48,128 --a------ C:\WINDOWS\system32\reg.exe
2006-10-05 02:23 44,032 --a------ C:\WINDOWS\system32\regapi.dll
2006-10-05 02:23 44,032 --a------ C:\WINDOWS\system32\rdpclip.exe
2006-10-05 02:23 423,424 --a------ C:\WINDOWS\system32\riched20.dll
2006-10-05 02:23 36,352 --a------ C:\WINDOWS\system32\sens.dll
2006-10-05 02:23 34,304 --a------ C:\WINDOWS\system32\rcimlby.exe
2006-10-05 02:23 328,704 --a------ C:\WINDOWS\system32\oakley.dll
2006-10-05 02:23 32,768 --a------ C:\WINDOWS\system32\odbcad32.exe
2006-10-05 02:23 3,338 --a------ C:\WINDOWS\system32\redir.exe
2006-10-05 02:23 297,984 --a------ C:\WINDOWS\system32\scesrv.dll
2006-10-05 02:23 254,976 --a------ C:\WINDOWS\system32\pdh.dll
2006-10-05 02:23 24,576 --a------ C:\WINDOWS\system32\odbcbcp.dll
2006-10-05 02:23 212,480 --a------ C:\WINDOWS\system32\osk.exe
2006-10-05 02:23 200,704 --a------ C:\WINDOWS\system32\odbc32.dll
2006-10-05 02:23 20,992 --a------ C:\WINDOWS\system32\setup.exe
2006-10-05 02:23 193,536 --a------ C:\WINDOWS\system32\rasppp.dll
2006-10-05 02:23 174,592 --a------ C:\WINDOWS\system32\scecli.dll
2006-10-05 02:23 171,008 --a------ C:\WINDOWS\system32\sccsccp.dll
2006-10-05 02:23 17,408 --a------ C:\WINDOWS\system32\psapi.dll
2006-10-05 02:23 169,984 --a------ C:\WINDOWS\system32\sccbase.dll
2006-10-05 02:23 16,384 --a------ C:\WINDOWS\system32\ping.exe
2006-10-05 02:23 16,384 --a------ C:\WINDOWS\system32\odbc32gt.dll
2006-10-05 02:23 147,456 --a------ C:\WINDOWS\system32\odbctrac.dll
2006-10-05 02:23 14,848 --a------ C:\WINDOWS\system32\rdpsnd.dll
2006-10-05 02:23 135,680 --a------ C:\WINDOWS\system32\rdchost.dll
2006-10-05 02:23 134,144 --a------ C:\WINDOWS\regedit.exe
2006-10-05 02:23 133,632 --a------ C:\WINDOWS\system32\rsaenh.dll
2006-10-05 02:23 133,120 --a------ C:\WINDOWS\system32\sfc_os.dll
2006-10-05 02:23 13,824 --a------ C:\WINDOWS\system32\rassapi.dll
2006-10-05 02:23 122,880 --a------ C:\WINDOWS\system32\odbcconf.dll
2006-10-05 02:23 12,800 --a------ C:\WINDOWS\system32\runonce.exe
2006-10-05 02:23 12,288 --a------ C:\WINDOWS\system32\rdsaddin.exe
2006-10-05 02:23 12,288 --a------ C:\WINDOWS\system32\odbcp32r.dll
2006-10-05 02:23 109,568 --a------ C:\WINDOWS\system32\offfilt.dll
2006-10-05 02:23 1,349,120 --a------ C:\WINDOWS\system32\query.dll
2006-10-05 02:23 1,157,632 --a------ C:\WINDOWS\system32\sfcfiles.dll
2006-10-05 02:22 95,744 --a------ C:\WINDOWS\system32\nlhtml.dll
2006-10-05 02:22 63,663 --------- C:\WINDOWS\system32\drivers\atinrvxx.sys
2006-10-05 02:22 6,912 --------- C:\WINDOWS\system32\drivers\hidir.sys
2006-10-05 02:22 56,591 --------- C:\WINDOWS\system32\drivers\atinbtxx.sys
2006-10-05 02:22 504,832 --------- C:\WINDOWS\system32\msftedit.dll
2006-10-05 02:22 5,120 --------- C:\WINDOWS\system32\hccoin.dll
2006-10-05 02:22 49,152 --a------ C:\WINDOWS\system32\npptools.dll
2006-10-05 02:22 403,456 --------- C:\WINDOWS\system32\winbrand.dll
2006-10-05 02:22 392,704 --a------ C:\WINDOWS\system32\ntmssvc.dll
2006-10-05 02:22 38,400 --a------ C:\WINDOWS\system32\ntmsapi.dll
2006-10-05 02:22 38,400 --a------ C:\WINDOWS\system32\ntlanman.dll
2006-10-05 02:22 377,984 --------- C:\WINDOWS\system32\ati2dvaa.dll
2006-10-05 02:22 36,463 --------- C:\WINDOWS\system32\drivers\atintuxx.sys
2006-10-05 02:22 34,735 --------- C:\WINDOWS\system32\drivers\atinxsxx.sys
2006-10-05 02:22 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2006-10-05 02:22 326,656 --a------ C:\WINDOWS\system32\netsetup.exe
2006-10-05 02:22 30,671 --------- C:\WINDOWS\system32\drivers\atinraxx.sys
2006-10-05 02:22 3,584 --------- C:\WINDOWS\system32\dsprpres.dll
2006-10-05 02:22 3,494,303 --------- C:\WINDOWS\system32\nv4_disp.dll
2006-10-05 02:22 29,455 --------- C:\WINDOWS\system32\drivers\atinxbxx.sys
2006-10-05 02:22 26,367 --------- C:\WINDOWS\system32\drivers\atinsnxx.sys
2006-10-05 02:22 24,576 --a------ C:\WINDOWS\system32\nmmkcert.dll
2006-10-05 02:22 238,080 --a------ C:\WINDOWS\system32\newdev.dll
2006-10-05 02:22 218,112 --------- C:\WINDOWS\system32\sbe.dll
2006-10-05 02:22 21,343 --------- C:\WINDOWS\system32\drivers\atinttxx.sys
2006-10-05 02:22 19,328 --------- C:\WINDOWS\system32\drivers\usbehci.sys
2006-10-05 02:22 187,904 --------- C:\WINDOWS\system32\xpsp1res.dll
2006-10-05 02:22 18,944 --------- C:\WINDOWS\system32\faxpatch.exe
2006-10-05 02:22 172,032 --------- C:\WINDOWS\system32\mssap.dll
2006-10-05 02:22 165,888 --a------ C:\WINDOWS\system32\ntmsdba.dll
2006-10-05 02:22 155,648 --------- C:\WINDOWS\system32\encdec.dll
2006-10-05 02:22 137,216 --a------ C:\WINDOWS\system32\ntshrui.dll
2006-10-05 02:22 13,056 --------- C:\WINDOWS\system32\drivers\wacompen.sys
2006-10-05 02:22 12,047 --------- C:\WINDOWS\system32\drivers\atinpdxx.sys
2006-10-05 02:22 112,128 --a------ C:\WINDOWS\system32\ntmarta.dll
2006-10-05 02:22 110,080 --------- C:\WINDOWS\system32\sbeio.dll
2006-10-05 02:22 11,904 --------- C:\WINDOWS\system32\drivers\mutohpen.sys
2006-10-05 02:22 11,615 --------- C:\WINDOWS\system32\drivers\atinmdxx.sys
2006-10-05 02:22 1,677,312 --------- C:\WINDOWS\system32\wmvcore2.dll
2006-10-05 02:22 1,622,528 --a------ C:\WINDOWS\system32\netshell.dll
2006-10-05 02:21 857,600 --a------ C:\WINDOWS\system32\netplwiz.dll
2006-10-05 02:21 81,408 --a------ C:\WINDOWS\system32\msoert2.dll
2006-10-05 02:21 699,392 --a------ C:\WINDOWS\system32\msxml2.dll
2006-10-05 02:21 598,016 --a------ C:\WINDOWS\system32\mstscax.dll
2006-10-05 02:21 584,192 --a------ C:\WINDOWS\system32\netcfgx.dll
2006-10-05 02:21 42,496 --a------ C:\WINDOWS\system32\ncobjapi.dll
2006-10-05 02:21 401,462 --a------ C:\WINDOWS\system32\msvcp60.dll
2006-10-05 02:21 399,360 --a------ C:\WINDOWS\system32\netlogon.dll
2006-10-05 02:21 39,424 --a------ C:\WINDOWS\system32\net.exe
2006-10-05 02:21 388,608 --a------ C:\WINDOWS\system32\mstsc.exe
2006-10-05 02:21 339,968 --a------ C:\WINDOWS\system32\mspaint.exe
2006-10-05 02:21 323,072 --a------ C:\WINDOWS\system32\msvcrt.dll
2006-10-05 02:21 319,760 --a------ C:\WINDOWS\system32\msnsspc.dll
2006-10-05 02:21 241,725 --a------ C:\WINDOWS\system32\msuni11.dll
2006-10-05 02:21 228,864 --a------ C:\WINDOWS\system32\msoeacct.dll
2006-10-05 02:21 182,784 --a------ C:\WINDOWS\system32\msutb.dll
2006-10-05 02:21 154,112 --a------ C:\WINDOWS\system32\netman.dll
2006-10-05 02:21 131,072 --a------ C:\WINDOWS\system32\msorcl32.dll
2006-10-05 02:21 115,200 --a------ C:\WINDOWS\system32\net1.exe
2006-10-05 02:21 113,664 --a------ C:\WINDOWS\system32\msvfw32.dll
2006-10-05 02:21 10,240 --a------ C:\WINDOWS\system32\msrle32.dll
2006-10-05 02:21 1,122,304 --a------ C:\WINDOWS\system32\msxml3.dll
2006-10-05 02:20 64,512 --a------ C:\WINDOWS\system32\msiexec.exe
2006-10-05 02:20 56,320 --a------ C:\WINDOWS\system32\mshtmler.dll
2006-10-05 02:20 4,608 --a------ C:\WINDOWS\system32\msimg32.dll
2006-10-05 02:20 368,710 --a------ C:\WINDOWS\system32\msisam11.dll
2006-10-05 02:20 305,664 --a------ C:\WINDOWS\system32\msihnd.dll
2006-10-05 02:20 229,888 --a------ C:\WINDOWS\system32\msieftp.dll
2006-10-05 02:20 22,528 --a------ C:\WINDOWS\system32\mslbui.dll
2006-10-05 02:20 2,086,400 --a------ C:\WINDOWS\system32\msi.dll
2006-10-05 02:20 143,872 --a------ C:\WINDOWS\system32\msimtf.dll
2006-10-05 02:19 4,126 --a------ C:\WINDOWS\system32\msdxmlc.dll
2006-10-05 02:18 72,192 --a------ C:\WINDOWS\system32\uniime.dll
2006-10-05 02:18 68,096 --a------ C:\WINDOWS\system32\mscms.dll
2006-10-05 02:18 67,584 --a------ C:\WINDOWS\system32\msctfp.dll
2006-10-05 02:18 65,536 --a------ C:\WINDOWS\system32\msconf.dll
2006-10-05 02:18 57,856 --a------ C:\WINDOWS\system32\licwmi.dll
2006-10-05 02:18 504,320 --a------ C:\WINDOWS\system32\logonui.exe
2006-10-05 02:18 381,440 --a------ C:\WINDOWS\system32\lmrt.dll
2006-10-05 02:18 32,256 --a------ C:\WINDOWS\system32\mnmdd.dll
2006-10-05 02:18 266,752 --a------ C:\WINDOWS\system32\msctf.dll
2006-10-05 02:18 233,472 --a------ C:\WINDOWS\system32\mpg4dmod.dll
2006-10-05 02:18 219,648 --a------ C:\WINDOWS\system32\logon.scr
2006-10-05 02:18 210,944 --a------ C:\WINDOWS\system32\moricons.dll
2006-10-05 02:18 196,096 --a------ C:\WINDOWS\system32\mobsync.dll
2006-10-05 02:18 19,456 --a------ C:\WINDOWS\system32\licmgr10.dll
2006-10-05 02:18 163,840 --a------ C:\WINDOWS\system32\mindex.dll
2006-10-05 02:18 126,976 --a------ C:\WINDOWS\system32\msdart.dll
2006-10-05 02:18 12,288 --a------ C:\WINDOWS\system32\mscpx32r.dll
2006-10-05 02:18 116,736 --a------ C:\WINDOWS\system32\mplay32.exe
2006-10-05 02:18 10,240 --a------ C:\WINDOWS\system32\localui.dll
2006-10-05 02:18 1,128,960 --a------ C:\WINDOWS\system32\mmcndmgr.dll
2006-10-05 02:14 827,438 --a------ C:\WINDOWS\system32\imjp81k.dll
2006-10-05 02:14 7,040 --a------ C:\WINDOWS\system32\kd1394.dll
2006-10-05 02:14 42,537 --a------ C:\WINDOWS\system32\keyboard.sys
2006-10-05 02:14 272,896 --a------ C:\WINDOWS\system32\kerberos.dll
2006-10-05 02:13 91,648 --a------ C:\WINDOWS\system32\iuctl.dll
2006-10-05 02:13 9,216 --a------ C:\WINDOWS\system32\icaapi.dll
2006-10-05 02:13 73,728 --a------ C:\WINDOWS\system32\ils.dll
2006-10-05 02:13 60,928 --a------ C:\WINDOWS\system32\ipv6.exe
2006-10-05 02:13 59,392 --a------ C:\WINDOWS\system32\iesetup.dll
2006-10-05 02:13 587,776 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-10-05 02:13 51,712 --a------ C:\WINDOWS\system32\ipconfig.exe
2006-10-05 02:13 49,664 --a------ C:\WINDOWS\system32\ixsso.dll
2006-10-05 02:13 36,922 --a------ C:\WINDOWS\system32\imeshare.dll
2006-10-05 02:13 318,464 --a------ C:\WINDOWS\system32\ippromon.dll
2006-10-05 02:13 30,208 --a------ C:\WINDOWS\system32\imgutil.dll
2006-10-05 02:13 294,912 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-10-05 02:13 28,672 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-10-05 02:13 27,648 --a------ C:\WINDOWS\system32\pidgen.dll
2006-10-05 02:13 240,640 --a------ C:\WINDOWS\system32\hnetcfg.dll
2006-10-05 02:13 236,032 --a------ C:\WINDOWS\system32\icm32.dll
2006-10-05 02:13 204,288 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-10-05 02:13 155,648 --a------ C:\WINDOWS\system32\ipsecsvc.dll
2006-10-05 02:13 134,144 --a------ C:\WINDOWS\system32\ipv6mon.dll
2006-10-05 02:13 126,976 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-10-05 02:13 123,904 --a------ C:\WINDOWS\system32\imapi.exe
2006-10-05 02:13 115,200 --a------ C:\WINDOWS\system32\dpcdll.dll
2006-10-05 02:13 114,176 --a------ C:\WINDOWS\system32\input.dll
2006-10-05 02:13 113,152 --a------ C:\WINDOWS\system32\idq.dll
2006-10-05 02:13 103,936 --a------ C:\WINDOWS\system32\imm32.dll
2006-10-05 02:12 8,832 --a------ C:\WINDOWS\system32\framebuf.dll
2006-10-05 02:11 9,216 --a------ C:\WINDOWS\system32\dumprep.exe
2006-10-05 02:11 802,304 --a------ C:\WINDOWS\system32\dxmrtp.dll
2006-10-05 02:11 66,560 --a------ C:\WINDOWS\system32\faultrep.dll
2006-10-05 02:11 498,205 --a------ C:\WINDOWS\system32\dxmasf.dll
2006-10-05 02:11 49,152 --a------ C:\WINDOWS\system32\eventlog.dll
2006-10-05 02:11 263,680 --a------ C:\WINDOWS\system32\duser.dll
2006-10-05 02:11 227,840 --a------ C:\WINDOWS\system32\dsquery.dll
2006-10-05 02:11 212,992 --ahs---- C:\WINDOWS\system32\mskey32.dll
2006-10-05 02:11 19,456 --a------ C:\WINDOWS\system32\fontview.exe
2006-10-05 02:11 19,456 --a------ C:\WINDOWS\system32\ersvc.dll
2006-10-05 02:11 180,224 --a------ C:\WINDOWS\system32\dwwin.exe
2006-10-05 02:11 178,688 --a------ C:\WINDOWS\system32\eudcedit.exe
2006-10-05 02:11 165,376 --a------ C:\WINDOWS\system32\els.dll
2006-10-05 02:11 16,384 --a------ C:\WINDOWS\system32\ds32gt.dll
2006-10-05 02:11 135,680 --a------ C:\WINDOWS\system32\dsprop.dll
2006-10-05 02:11 124,928 --a------ C:\WINDOWS\system32\dssenh.dll
2006-10-05 02:11 1,004,032 --a------ C:\WINDOWS\explorer.exe
2006-10-05 02:10 76,288 --a------ C:\WINDOWS\system32\dfrgfat.exe
2006-10-05 02:10 70,656 --a------ C:\WINDOWS\system32\defrag.exe
2006-10-05 02:10 70,144 --a------ C:\WINDOWS\system32\cryptdlg.dll
2006-10-05 02:10 61,440 --a------ C:\WINDOWS\system32\dbnetlib.dll
2006-10-05 02:10 55,296 --a------ C:\WINDOWS\system32\digest.dll
2006-10-05 02:10 53,248 --a------ C:\WINDOWS\system32\cryptsvc.dll
2006-10-05 02:10 489,984 --a------ C:\WINDOWS\system32\dbghelp.dll
2006-10-05 02:10 45,568 --a------ C:\WINDOWS\system32\docprop2.dll
2006-10-05 02:10 35,328 --a------ C:\WINDOWS\system32\dfrgsnap.dll
2006-10-05 02:10 307,712 --a------ C:\WINDOWS\system32\cscui.dll
2006-10-05 02:10 28,672 --a------ C:\WINDOWS\system32\dbnmpntw.dll
2006-10-05 02:10 263,168 --a------ C:\WINDOWS\system32\devmgr.dll
2006-10-05 02:10 25,600 --a------ C:\WINDOWS\system32\dfsshlex.dll
2006-10-05 02:10 24,576 --a------ C:\WINDOWS\system32\dbmsvinn.dll
2006-10-05 02:10 24,576 --a------ C:\WINDOWS\system32\dbmsrpcn.dll
2006-10-05 02:10 20,480 --a------ C:\WINDOWS\system32\dbmsadsn.dll
2006-10-05 02:10 168,960 --a------ C:\WINDOWS\system32\dinput8.dll
2006-10-05 02:10 151,552 --a------ C:\WINDOWS\system32\dinput.dll
2006-10-05 02:10 13,312 --a------ C:\WINDOWS\system32\ctfmon.exe
2006-10-05 02:10 113,152 --a------ C:\WINDOWS\system32\dfrgui.dll
2006-10-05 02:10 103,424 --a------ C:\WINDOWS\system32\dgnet.dll
2006-10-05 02:09 98,816 --a------ C:\WINDOWS\system32\clipbrd.exe
2006-10-05 02:09 71,680 --a------ C:\WINDOWS\system32\browsewm.dll
2006-10-05 02:09 64,512 --a------ C:\WINDOWS\system32\ciodm.dll
2006-10-05 02:09 59,904 --a------ C:\WINDOWS\system32\cabinet.dll
2006-10-05 02:09 54,272 --a------ C:\WINDOWS\system32\clusapi.dll
2006-10-05 02:09 41,472 --a------ C:\WINDOWS\system32\cmdl32.exe
2006-10-05 02:09 324,608 --a------ C:\WINDOWS\system32\cmdial32.dll
2006-10-05 02:09 32,768 --a------ C:\WINDOWS\system32\cfgbkend.dll
2006-10-05 02:09 24,576 --a------ C:\WINDOWS\system32\conime.exe
2006-10-05 02:09 238,592 --a------ C:\WINDOWS\system32\compatui.dll
2006-10-05 02:09 186,880 --a------ C:\WINDOWS\system32\certcli.dll
2006-10-05 02:09 158,720 --a------ C:\WINDOWS\system32\credui.dll
2006-10-05 02:08 8,192 --a------ C:\WINDOWS\system32\autolfn.exe
2006-10-05 02:08 76,288 --a------ C:\WINDOWS\system32\avifil32.dll
2006-10-05 02:08 74,810 --a------ C:\WINDOWS\system32\atl.dll
2006-10-05 02:08 62,976 --a------ C:\WINDOWS\system32\browselc.dll
2006-10-05 02:08 6,656 --a------ C:\WINDOWS\system32\batt.dll
2006-10-05 02:08 49,152 --a------ C:\WINDOWS\system32\browser.dll
2006-10-05 02:08 38,912 --a------ C:\WINDOWS\system32\audiosrv.dll
2006-10-05 02:08 22,528 --a------ C:\WINDOWS\system32\at.exe
2006-10-05 02:08 14,366 --a------ C:\WINDOWS\system32\asfsipc.dll
2006-10-05 02:07 91,648 --a------ C:\WINDOWS\system32\ahui.exe
2006-10-05 02:07 91,136 --a------ C:\WINDOWS\system32\advpack.dll
2006-10-05 02:07 62,464 --a------ C:\WINDOWS\system32\adsmsext.dll
2006-10-05 02:07 59,392 --a------ C:\WINDOWS\system32\6to4svc.dll
2006-10-05 02:07 41,984 --a------ C:\WINDOWS\system32\alg.exe
2006-10-05 02:07 32,512 --------- C:\WINDOWS\system32\drivers\amdk7.sys
2006-10-05 02:07 239,616 --a------ C:\WINDOWS\system32\adsnt.dll
2006-10-05 02:07 162,816 --a------ C:\WINDOWS\system32\adsldp.dll
2006-10-05 02:07 139,776 --a------ C:\WINDOWS\system32\adsldpc.dll
2006-10-05 02:07 115,712 --a------ C:\WINDOWS\system32\apphelp.dll
2006-10-05 02:01 10,752 --a------ C:\WINDOWS\system32\cnscheck001.dll
2006-10-02 20:22 31,744 --a------ C:\WINDOWS\system32\Realplayer.exe
2006-10-02 20:22 16,384 --------- C:\WINDOWS\system32\Rsvtub.dll
2006-10-02 18:45 34 --a------ C:\WINDOWS\vbarun.dll
2006-10-02 18:45 14,465 ---hs---- C:\WINDOWS\system32\winasse.exe
2006-10-02 18:32 10,752 --a------ C:\WINDOWS\system32\cnscheck010.dll
2006-10-02 18:24 800 --a------ C:\WINDOWS\system32\drivers\modol.sys
2006-10-02 18:24 11,776 --a------ C:\WINDOWS\system32\cnscheck.dll
2006-10-02 18:18 4,558 --a------ C:\WINDOWS\1Sy.exe
2006-10-02 18:08 38,216 --a------ C:\WINDOWS\system32\svchqs.exe
2006-10-02 18:07 94,208 --a------ C:\WINDOWS\Dll.dll
2006-10-02 18:07 92,160 --a------ C:\WINDOWS\system32\provbmind.dll
2006-10-02 18:07 92,160 --a------ C:\WINDOWS\system32\avibiosm.dll
2006-10-02 18:07 77,312 --a------ C:\WINDOWS\system32\11.exe
2006-10-02 18:07 77,312 --a------ C:\WINDOWS\rundl132.exe
2006-10-02 18:07 568,832 --a------ C:\WINDOWS\system32\vsapidmv1.exe
2006-10-02 18:07 568,832 --a------ C:\WINDOWS\system32\asrp1.exe
2006-10-02 18:07 38,216 --a------ C:\WINDOWS\system32\hx.exe
2006-10-02 18:07 32,512 --a------ C:\WINDOWS\system32\drivers\npf.sys
2006-10-02 18:07 18,432 --a------ C:\WINDOWS\winampc.exe
2006-10-02 18:06 53,248 --a------ C:\WINDOWS\system32\myztr.dll
2006-10-02 18:06 147,456 --a------ C:\WINDOWS\system32\cs.exe
2006-10-02 17:59 61,568 --a------ C:\WINDOWS\system32\nmhxy.exe
2006-10-02 17:59 57,344 --a------ C:\WINDOWS\system32\nmhxy.dll
2006-10-02 17:59 50,688 --a------ C:\WINDOWS\system32\msdll.dll
2006-10-02 17:59 33,280 --a------ C:\WINDOWS\system32\dllwm.dll
2006-10-02 17:58 39,936 --a------ C:\WINDOWS\system32\tdll.dll
2006-10-02 17:58 39,424 --a------ C:\WINDOWS\system32\ztdll.dll
2006-10-02 17:58 3,584 --a------ C:\WINDOWS\system32\a.exe
2006-10-02 17:57 20,516 --a------ C:\cmd.exe
2006-10-02 09:02 2,048 -r-hs---- C:\WINDOWS\system32\sysldr.dll
2006-10-02 09:02 12,636 -r-hs---- C:\WINDOWS\system32\dumpreps.dll
2006-10-02 09:01 1,660,804 --a------ C:\WINDOWS\edodo_install.exe
2006-10-02 07:30 114,688 --a------ C:\WINDOWS\system32\wshcon32.dll
2006-10-02 03:11 176,640 --a------ C:\WINDOWS\system32\ctfmoon.exe
2006-10-02 03:06 8,796 --a------ C:\WINDOWS\system32\SVCH0ST.exe
2006-10-02 03:06 32 --a------ C:\WINDOWS\system32\bat.bat
2006-10-02 03:06 26,112 --a------ C:\WINDOWS\system32\drivers\RGWatch.sys
2006-10-02 03:06 19,968 --a------ C:\WINDOWS\realupdate.exe
2006-10-02 03:06 188,416 --------- C:\WINDOWS\system32\cn5940barToolbar.dll
2006-10-02 03:06 18,432 --a------ C:\WINDOWS\winampb.exe
2006-10-02 03:06 114,688 --a------ C:\WINDOWS\system32\quartz32.dll
2006-10-02 03:03 5,165 --a------ C:\WINDOWS\system32\wdfmgr32.exe
2006-10-02 03:03 2,000,529 --a------ C:\WINDOWS\system32\0.exe
2006-10-01 06:31 21,070 --a------ C:\WINDOWS\system32\rayess.exe
2006-09-25 16:47 10,240 --a------ C:\WINDOWS\system32\rundll.exe
2006-09-20 05:37 178,440 --a------ C:\WINDOWS\system32\drivers\ggeedgcg.sys


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-05 04:45 -------- d-------- C:\Program Files\coolsign
2006-10-05 04:45 -------- d-------- C:\Program Files\Common Files\UPDATE2
2006-10-05 04:41 -------- d-------- C:\Program Files\Internet Explorer
2006-10-05 03:33 11776 --a------ C:\WINDOWS\~tmp9258.exe
2006-10-05 03:32 -------- d-------- C:\Program Files\CNNIC
2006-10-05 03:10 -------- d-------- C:\Program Files\NetMeeting
2006-10-05 02:40 -------- d-------- C:\Program Files\Movie Maker
2006-10-05 02:40 -------- d-------- C:\Program Files\Messenger
2006-10-05 02:39 -------- d-------- C:\Program Files\Windows Media Player
2006-10-05 02:39 -------- d-------- C:\Program Files\Outlook Express
2006-10-05 02:39 -------- d-------- C:\Program Files\Common Files\System
2006-10-04 04:06 -------- d-------- C:\Program Files\CleanUp!
2006-10-04 02:52 -------- d-------- C:\Program Files\Lavasoft
2006-10-02 18:21 -------- d-------- C:\Program Files\Google
2006-10-02 18:08 9 ---hs---- C:\Program Files\_desktop.ini
2006-10-02 18:08 -------- d-------- C:\Program Files\Adobe
2006-10-02 18:08 -------- d-------- C:\Program Files\ABC
2006-10-02 17:59 31010 --a------ C:\Program Files\xxxsvhost32.exe
2006-10-02 17:59 -------- d-------- C:\Program Files\Microsoft
2006-10-02 03:06 -------- d-------- C:\Program Files\Common Files
2006-08-31 16:56 5800 --a------ C:\WINDOWS\system32\nt.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\System32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
"PHIME2002ASync"="C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"LTSMMSG"="LTSMMSG.exe"
"AtiPTA"="atiptaxx.exe"
"NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_02\\bin\\jusched.exe"
"iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe"
"iPodManager"="C:\\Program Files\\iPod\\bin\\iPodManager.exe"
"MMTray"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mm_tray.exe"
"mmtask"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mmtask.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"wdfmgr32"="C:\\WINDOWS\\System32\\wdfmgr32.exe"
"Update"="C:\\Program Files\\Common Files\\UPDATE2\\Update.exe"
"Tray"="C:\\WINDOWS\\command\\rundll32.exe"
"ms"="C:\\Program Files\\Microsoft\\svhost32.exe"
"jiahus"="C:\\WINDOWS\\System32\\svchqs.exe"
"Realplayer.exe"="C:\\WINDOWS\\System32\\Realplayer.exe"
"CdnCtr"="C:\\Program Files\\CNNIC\\Cdn\\cdnup.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3c,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,68,02,00,00,1f,00,00,00,a8,00,00,00,9e,00,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Start Upping"="qtask.exe"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"Start Upping"="qtask.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{8A238B14-A6FF-11E0-9A84-00C04FD8DBD8}"=""
"{6E44887F-5214-41F2-AB46-4728735C4CC6}"=""
"{11760322-2400-4AC3-9605-6CAF086E809E}"=""
"{9A0CFC58-5A6F-41ba-9FFE-4320F4F62FB1}"=""
"{9A0CFC58-5A6F-41ba-9FFE-4320F4F62111}"=""
"{9A0CFC58-5A6F-41ba-9FFE-4320F4F62F1A}"=""
"{9A0CFC58-5A6F-41ba-9FFE-4320F4F621BA}"=""
"{99F1D023-7CEB-4586-80F7-BB1A98DB7602}"=""
"{E4C3C044-CE6A-4117-9D18-C1EBEC80D2C9}"=""
"{FEB94F5A-69F3-4645-8C2B-9E71D270AF2E}"=""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run]
"Alexa"="C:\\WINDOWS\\System32\\qproecss.exe"
"Ver"="2006.07.20"
"CheckFaultKernel"="C:\\WINDOWS\\System32\\mswdm.exe"
"9"="C:\\WINDOWS\\System32\\Ravdm.exe"
"KernelCheck"="C:\\WINDOWS\\System32\\winasse.exe"

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Completion time: Thu 05/10/2006 4:57:40.53
ComboFix.txt
  • 0

#8
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Ok, I soptted many bad services there, we will need to get the service names for those.

Please go here:
http://www.billsway.com/vbspage/

Scroll down the page
and download the "Registry Search Tool"

Unzip RegSrch.zip to the desktop

Double click on RegSrch.vbs

If you get a warning from your Anti Virus please ignore it and allow this to run.

When it starts, you will be prompted to enter a search phrase.

Please enter this:

NT Data Provider

Click OK, it will disappear and won't look as if it's doing anything. When it's done searching, a prompt will come up saying how many instances it found. Click OK, and a notepad will open up. Please copy the contents of that notepad and paste it here.

Make a search for each one of these listed items and post those results as well:

ggeedgcg
gwemjqm
mfobap
nwlnksipx
RGWatch
Netgroup Packet Filter


And I have to mention that some of the trojans have password stealing capabilities. Therefore, if you are using the computer for any financial purposes like online banking etc. go to another clean computer and change all your logins and passwords. Then don't use the new ones on this computer until we clean this up.
  • 0

#9
Red_6

Red_6

    Member

  • Topic Starter
  • Member
  • PipPip
  • 76 posts
NT Data Provider
----------------

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "NT Data Provider" 06/10/2006 01:58:24

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_8NASCAR\0000]
"DeviceDesc"="NT Data Provider"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\8NASCAR]
"DisplayName"="NT Data Provider"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_8NASCAR\0000]
"DeviceDesc"="NT Data Provider"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\8NASCAR]
"DisplayName"="NT Data Provider"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_8NASCAR\0000]
"DeviceDesc"="NT Data Provider"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\8NASCAR]
"DisplayName"="NT Data Provider"



ggeedgcg
--------
No Instance



gwemjqm
-------

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "gwemjqm" 06/10/2006 02:07:20

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gwemjqm]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gwemjqm]
"DisplayName"="gwemjqm"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gwemjqm\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\gwemjqm]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\gwemjqm]
"DisplayName"="gwemjqm"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\gwemjqm\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gwemjqm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gwemjqm]
"DisplayName"="gwemjqm"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gwemjqm\Security]



mfobap
--------

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "mfobap" 06/10/2006 02:38:09

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mfobap]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mfobap]
"DisplayName"="mfobap"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mfobap\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\mfobap]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\mfobap]
"DisplayName"="mfobap"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\mfobap\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mfobap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mfobap]
"DisplayName"="mfobap"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mfobap\Security]


nwlnksipx
---------

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "nwlnksipx" 06/10/2006 02:41:02

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWLNKSIPX]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWLNKSIPX\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWLNKSIPX\0000]
"Service"="nwlnksipx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWLNKSIPX\0000]
"DeviceDesc"="nwlnksipx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWLNKSIPX\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NWLNKSIPX\0000\Control]
"ActiveService"="nwlnksipx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nwlnksipx]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nwlnksipx]
"DisplayName"="nwlnksipx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nwlnksipx\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nwlnksipx\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\nwlnksipx\Enum]
"0"="Root\\LEGACY_NWLNKSIPX\\0000"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NWLNKSIPX]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NWLNKSIPX\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NWLNKSIPX\0000]
"Service"="nwlnksipx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NWLNKSIPX\0000]
"DeviceDesc"="nwlnksipx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\nwlnksipx]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\nwlnksipx]
"DisplayName"="nwlnksipx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\nwlnksipx\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NWLNKSIPX]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NWLNKSIPX\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NWLNKSIPX\0000]
"Service"="nwlnksipx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NWLNKSIPX\0000]
"DeviceDesc"="nwlnksipx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NWLNKSIPX\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NWLNKSIPX\0000\Control]
"ActiveService"="nwlnksipx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nwlnksipx]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nwlnksipx]
"DisplayName"="nwlnksipx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nwlnksipx\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nwlnksipx\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nwlnksipx\Enum]
"0"="Root\\LEGACY_NWLNKSIPX\\0000"


RGWatch
-------

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "RGWatch" 06/10/2006 02:43:05

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RGWATCH]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RGWATCH\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RGWATCH\0000]
"Service"="RGWatch"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RGWATCH\0000]
"DeviceDesc"="RGWatch"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RGWATCH\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RGWATCH\0000\Control]
"ActiveService"="RGWatch"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RGWatch]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RGWatch]
"DisplayName"="RGWatch"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RGWatch]
"Description"="RGWatch Filter"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RGWatch\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RGWatch\Enum]
"0"="Root\\LEGACY_RGWATCH\\0000"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_RGWATCH]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_RGWATCH\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_RGWATCH\0000]
"Service"="RGWatch"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_RGWATCH\0000]
"DeviceDesc"="RGWatch"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\RGWatch]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\RGWatch]
"DisplayName"="RGWatch"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\RGWatch]
"Description"="RGWatch Filter"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RGWATCH]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RGWATCH\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RGWATCH\0000]
"Service"="RGWatch"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RGWATCH\0000]
"DeviceDesc"="RGWatch"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RGWATCH\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RGWATCH\0000\Control]
"ActiveService"="RGWatch"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RGWatch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RGWatch]
"DisplayName"="RGWatch"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RGWatch]
"Description"="RGWatch Filter"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RGWatch\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RGWatch\Enum]
"0"="Root\\LEGACY_RGWATCH\\0000"



Netgroup Packet Filter
----------------------

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "Netgroup Packet Filter" 06/10/2006 02:45:13

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NPF\0000]
"DeviceDesc"="Netgroup Packet Filter"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NPF]
"DisplayName"="Netgroup Packet Filter"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NPF\0000]
"DeviceDesc"="Netgroup Packet Filter"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\NPF]
"DisplayName"="Netgroup Packet Filter"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NPF\0000]
"DeviceDesc"="Netgroup Packet Filter"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NPF]
"DisplayName"="Netgroup Packet Filter"
  • 0

#10
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Please both print these instructions and also save the Avenger script to Notepad on your desktop cause you will need to do some copying/pasting in safe mode and then on a reboot you will need a hard copy.

I may be removing some programs I am not so sure about, but may be legit. I am not taking any chances, if you are sure that any of them are clean, you can reinstall them again later if you were using them.

Go to Add/Remove Programs and uninstall:

ABC
Booby
Chinese Navigation2.4.0.10
CoolSign
pucca_02


Do not reboot yet!

Please download ATF Cleaner by Atribune. Do not run it yet.

Download AVG Anti-Spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.

Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C) and then save it on Notepad. (Do not copy the header where it says CODE)

Files to delete:

C:\WINDOWS\System32\quartz32.dll
C:\WINDOWS\System32\ultra32.dll
C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL
C:\WINDOWS\System32\qproecss.exe
C:\WINDOWS\system32\engt32c.dll
C:\WINDOWS\~tmp9258.exe
C:\WINDOWS\system32\IEHelper.dll
C:\WINDOWS\system32\drivers\cdnprot.sys
C:\WINDOWS\system32\cnscheck001.dll
C:\WINDOWS\system32\Realplayer.exe
C:\WINDOWS\system32\Rsvtub.dll
C:\WINDOWS\vbarun.dll
C:\WINDOWS\system32\winasse.exe
C:\WINDOWS\system32\cnscheck010.dll
C:\WINDOWS\system32\drivers\modol.sys
C:\WINDOWS\system32\cnscheck.dll
C:\WINDOWS\1Sy.exe
C:\WINDOWS\system32\svchqs.exe
C:\WINDOWS\Dll.dll
C:\WINDOWS\system32\provbmind.dll
C:\WINDOWS\system32\avibiosm.dll
C:\WINDOWS\system32\11.exe
C:\WINDOWS\rundl132.exe
C:\WINDOWS\system32\vsapidmv1.exe
C:\WINDOWS\system32\asrp1.exe
C:\WINDOWS\system32\hx.exe
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\winampc.exe
C:\WINDOWS\system32\myztr.dll
C:\WINDOWS\system32\cs.exe
C:\WINDOWS\system32\nmhxy.exe
C:\WINDOWS\system32\nmhxy.dll
C:\WINDOWS\system32\msdll.dll
C:\WINDOWS\system32\dllwm.dll
C:\WINDOWS\system32\tdll.dll
C:\WINDOWS\system32\ztdll.dll
C:\WINDOWS\system32\a.exe
C:\cmd.exe
C:\WINDOWS\system32\sysldr.dll
C:\WINDOWS\system32\dumpreps.dll
C:\WINDOWS\edodo_install.exe
C:\WINDOWS\system32\wshcon32.dll
C:\WINDOWS\system32\ctfmoon.exe
C:\WINDOWS\system32\SVCH0ST.exe
C:\WINDOWS\system32\bat.bat
C:\WINDOWS\system32\drivers\RGWatch.sys
C:\WINDOWS\realupdate.exe
C:\WINDOWS\system32\cn5940barToolbar.dll
C:\WINDOWS\winampb.exe
C:\WINDOWS\system32\quartz32.dll
C:\WINDOWS\system32\wdfmgr32.exe
C:\WINDOWS\system32\0.exe
C:\WINDOWS\system32\rayess.exe
C:\WINDOWS\system32\rundll.exe
C:\WINDOWS\system32\drivers\ggeedgcg.sys
C:\Program Files\xxxsvhost32.exe
C:\WINDOWS\qtask.exe
C:\WINDOWS\System32\qtask.exe
C:\WINDOWS\System32\mswdm.exe
C:\WINDOWS\System32\Ravdm.exe
C:\Program Files\Microsoft\svhost32.exe
C:\WINDOWS\command\rundll32.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5059.dll
C:\WINDOWS\system32\drivers\ggeedgcg.sys
C:\DOCUME~1\dam\LOCALS~1\Temp\gwemjqmxfd
C:\DOCUME~1\dam\LOCALS~1\Temp\mfobaptkp
C:\WINDOWS\System32\drivers\nwlnksipx.sys
C:\WINDOWS\system32\DRIVERS\RGWatch.sys
C:\WINDOWS\System32\DRIVERS\npf.sys

Folders to delete:

C:\Program Files\coolsign
C:\Program Files\Common Files\UPDATE2
C:\Program Files\CNNIC
C:\Program Files\ABC
c:\program Files\Òä¶à¶à
C:\WINDOWS\BJH
 
Drivers to unload:

8NASCAR
gwemjqm
mfobap
nwlnksipx
RGWatch
NPF
KSD2Service
NetWorkLogons
ServiceBJH
ggeedgcg
cdnprot

Programs to launch on reboot:

C:\Tools\HijackThis.exe


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


Next,

A malicious .DLL file is disrupting the LSP chain on your computer. We need to get rid of it.
  • Please download LSPFix from here.
  • Disconnect from the internet and run the LSPFix.exe that you have just finished downloading.
  • Check the I know what I'm doing box.
  • In the Keep box you should see one or more instances of quartz32.dll and ultra32.dll
  • Select every instance of quartz32.dll and ultra32.dll and move each one to the Remove box by clicking the >> button.
  • When you are done click Finish>>.
Reboot your computer into SafeMode. You can do this by restarting your computer and tapping the F8 key just before Windows starts to load, until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.

Double-click ATF-Cleaner.exe to run the program.

Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser

Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close AVG Anti-Spyware
Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • Again on reboot, HijackThis will open. When it opens, put a check next to the following items, click Fix Checked, and then close HijackThis.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.7939.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.c...msearch-en.html
    F2 - REG:system.ini: Shell=Explorer.exe vsapidmv1.exe
    O2 - BHO: 5940bar BHO - {15953528-6C01-481A-8DB4-01888FB85B7D} - C:\WINDOWS\system32\CN5940~1.DLL
    O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5059.dll
    O2 - BHO: ÐÅÏ¢¼ìË÷ - {CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} - C:\WINDOWS\system32\IEHelper.dll (file missing)
    O3 - Toolbar: 5940bar - {1A45F0FB-9586-4742-8343-8732C7AAFB88} - C:\WINDOWS\system32\CN5940~1.DLL
    O4 - HKLM\..\Run: [wdfmgr32] C:\WINDOWS\System32\wdfmgr32.exe
    O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE2\Update.exe
    O4 - HKLM\..\Run: [Tray] C:\WINDOWS\command\rundll32.exe
    O4 - HKLM\..\Run: [ms] C:\Program Files\Microsoft\svhost32.exe
    O4 - HKLM\..\Run: [jiahus] C:\WINDOWS\System32\svchqs.exe
    O4 - HKLM\..\Run: [Realplayer.exe] C:\WINDOWS\System32\Realplayer.exe
    O4 - HKCU\..\Run: [updatereal] C:\WINDOWS\realupdate.exe other
    O4 - HKCU\..\Run: [msnnt] C:\WINDOWS\winampc.exe
    O4 - HKCU\..\Run: [MyShares] c:\program Files\Òä¶à¶à\MyShares.exe /tray
    O4 - HKCU\..\Run: [Realplayer.exe] C:\WINDOWS\System32\Realplayer.exe
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log and the Ewido log by using Add/Reply. Make different posts for each log.
  • 0

Advertisements


#11
Red_6

Red_6

    Member

  • Topic Starter
  • Member
  • PipPip
  • 76 posts
This is the report after the first scan. The program crashed during the Apply All Actions so I ran it again.

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 22:41:47 08/10/2006

+ Scan result:



C:\WINDOWS\system32\drivers\RGWatch.sys -> Adware.Agent : No action taken.
C:\WINDOWS\system32\quartz32.dll -> Adware.Agent : No action taken.
C:\WINDOWS\system32\wshcon32.dll -> Adware.Agent : No action taken.
C:\WINDOWS\win1\Setup-227.exe -> Adware.Agent : No action taken.
C:\Program Files\CNNIC\Cdn\cdnaux.dll -> Adware.Cdn : No action taken.
C:\Program Files\CNNIC\Cdn\cdnunins.exe -> Adware.Cdn : No action taken.
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj -> Adware.CoolWebSearch : No action taken.
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1 -> Adware.CoolWebSearch : No action taken.
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer -> Adware.CoolWebSearch : No action taken.
HKLM\SOFTWARE\Classes\TypeLib\{2511DE40-34A3-4C6A-B1B2-C5C92A2F00BE} -> Adware.Generic : No action taken.
C:\WINDOWS\win1\5059.exe -> Adware.IEHlpr : No action taken.
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0000002.dll -> Downloader.Agent.apj : No action taken.
C:\WINDOWS\v20060910.rar -> Downloader.Agent.aqr : No action taken.
C:\WINDOWS\win1\198994004.exe -> Downloader.Agent.ayn : No action taken.
C:\WINDOWS\system32\rayess.exe -> Downloader.Agent.ayo : No action taken.
C:\Program Files\Common Files\UPDATE2\Update.exe.1 -> Downloader.QQHelper.ap : No action taken.
C:\WINDOWS\system32\nmhxy.dll -> Trojan.Agent.iu : No action taken.
C:\WINDOWS\system32\nmhxy.exe -> Trojan.Agent.iu : No action taken.
C:\WINDOWS\msetup\5009vost.exe/realupdate.exe -> Trojan.Agent.tl : No action taken.
C:\WINDOWS\system32\A4SOFT\baisoc\avpc.exe/realupdate.exe -> Trojan.Agent.tl : No action taken.
C:\WINDOWS\system32\A4SOFT\baisoc\realupdate.exe -> Trojan.Agent.tl : No action taken.
C:\WINDOWS\system32\A4\baisob\avpb.exe/realupdate.exe -> Trojan.Agent.tl : No action taken.
C:\WINDOWS\system32\A4\baisob\realupdate.exe -> Trojan.Agent.tl : No action taken.
C:\WINDOWS\win1\4126ther.exe/realupdate.exe -> Trojan.Agent.tl : No action taken.
C:\Program Files\Internet Explorer\IEXPLORE.jmp -> Trojan.Delf.pj : No action taken.
C:\Program Files\Internet Explorer\1Sy.exe -> Trojan.Lineage.alw : No action taken.
C:\WINDOWS\system32\vpcrm.exe -> Trojan.Lmir.bbd : No action taken.
C:\TROKINGHM\TROKINGHM.DLL -> Trojan.OnLineGames.g : No action taken.
C:\WINDOWS\system32\cs.exe -> Trojan.WOW.da : No action taken.
C:\WINDOWS\~tmp9258.exe -> Worm.Detnat.e : No action taken.
C:\WINDOWS\system32\11.exe -> Worm.Viking.aj : No action taken.
C:\Adobe Acrobat 5.0\Setup.exe -> Worm.Viking.an : No action taken.
C:\Others\setup.exe -> Worm.Viking.an : No action taken.
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig705\ENU\setup.exe -> Worm.Viking.an : No action taken.
C:\WINDOWS\rundl132.exe -> Worm.Viking.an : No action taken.
C:\dlink\Setup.exe -> Worm.Viking.an : No action taken.
C:\drv\Modem\setup.exe -> Worm.Viking.an : No action taken.
C:\drv\Sound\Setup.exe -> Worm.Viking.an : No action taken.
C:\drv\Touchpad\Setup.exe -> Worm.Viking.an : No action taken.
C:\drv\Video\Setup.exe -> Worm.Viking.an : No action taken.


::Report end
  • 0

#12
Red_6

Red_6

    Member

  • Topic Starter
  • Member
  • PipPip
  • 76 posts
Second scan with Quarantine applied.

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 00:22:52 09/10/2006

+ Scan result:



C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002033.sys -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002034.dll -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0003072.dll -> Adware.Agent : Cleaned with backup (quarantined).
C:\WINDOWS\win1\Setup-227.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\avenger\backup.zip/avenger/wshcon32.dll -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002031.dll -> Adware.Cdn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002032.exe -> Adware.Cdn : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1 -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TypeLib\{2511DE40-34A3-4C6A-B1B2-C5C92A2F00BE} -> Adware.Generic : Cleaned with backup (quarantined).
C:\WINDOWS\win1\5059.exe -> Adware.IEHlpr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002029.exe -> Downloader.Agent.ayn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002027.exe -> Downloader.Agent.ayo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002025.dll -> Trojan.Agent.iu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002026.exe -> Trojan.Agent.iu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002017.exe/realupdate.exe -> Trojan.Agent.tl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002018.exe/realupdate.exe -> Trojan.Agent.tl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002019.exe -> Trojan.Agent.tl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002020.exe/realupdate.exe -> Trojan.Agent.tl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002021.exe -> Trojan.Agent.tl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002022.exe/realupdate.exe -> Trojan.Agent.tl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002015.exe -> Trojan.Lineage.alw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002028.exe -> Trojan.Lmir.bbd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002016.DLL -> Trojan.OnLineGames.g : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002024.exe -> Trojan.WOW.da : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002030.exe -> Worm.Detnat.e : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002023.exe -> Worm.Viking.aj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002006.exe -> Worm.Viking.an : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002007.exe -> Worm.Viking.an : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002008.exe -> Worm.Viking.an : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002009.exe -> Worm.Viking.an : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002010.exe -> Worm.Viking.an : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002011.exe -> Worm.Viking.an : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002012.exe -> Worm.Viking.an : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002013.exe -> Worm.Viking.an : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FC1EF438-71CA-46DC-A9C5-E412664AD2E5}\RP1\A0002014.exe -> Worm.Viking.an : Cleaned with backup (quarantined).


::Report end
  • 0

#13
Red_6

Red_6

    Member

  • Topic Starter
  • Member
  • PipPip
  • 76 posts
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\mebaafmw

*******************

Script file located at: \??\C:\Documents and Settings\xtfgqiub.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\WINDOWS\System32\quartz32.dll not found!
Deletion of file C:\WINDOWS\System32\quartz32.dll failed!

Could not process line:
C:\WINDOWS\System32\quartz32.dll
Status: 0xc0000034

File C:\WINDOWS\System32\ultra32.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\WBEM\SMTPCONFS.DLL deleted successfully.


File C:\WINDOWS\System32\qproecss.exe not found!
Deletion of file C:\WINDOWS\System32\qproecss.exe failed!

Could not process line:
C:\WINDOWS\System32\qproecss.exe
Status: 0xc0000034

File C:\WINDOWS\system32\engt32c.dll deleted successfully.


File C:\WINDOWS\~tmp9258.exe not found!
Deletion of file C:\WINDOWS\~tmp9258.exe failed!

Could not process line:
C:\WINDOWS\~tmp9258.exe
Status: 0xc0000034

File C:\WINDOWS\system32\IEHelper.dll deleted successfully.
File C:\WINDOWS\system32\drivers\cdnprot.sys deleted successfully.
File C:\WINDOWS\system32\cnscheck001.dll deleted successfully.


File C:\WINDOWS\system32\Realplayer.exe not found!
Deletion of file C:\WINDOWS\system32\Realplayer.exe failed!

Could not process line:
C:\WINDOWS\system32\Realplayer.exe
Status: 0xc0000034



File C:\WINDOWS\system32\Rsvtub.dll not found!
Deletion of file C:\WINDOWS\system32\Rsvtub.dll failed!

Could not process line:
C:\WINDOWS\system32\Rsvtub.dll
Status: 0xc0000034

File C:\WINDOWS\vbarun.dll deleted successfully.


File C:\WINDOWS\system32\winasse.exe not found!
Deletion of file C:\WINDOWS\system32\winasse.exe failed!

Could not process line:
C:\WINDOWS\system32\winasse.exe
Status: 0xc0000034

File C:\WINDOWS\system32\cnscheck010.dll deleted successfully.
File C:\WINDOWS\system32\drivers\modol.sys deleted successfully.


File C:\WINDOWS\system32\cnscheck.dll not found!
Deletion of file C:\WINDOWS\system32\cnscheck.dll failed!

Could not process line:
C:\WINDOWS\system32\cnscheck.dll
Status: 0xc0000034

File C:\WINDOWS\1Sy.exe deleted successfully.
File C:\WINDOWS\system32\svchqs.exe deleted successfully.
File C:\WINDOWS\Dll.dll deleted successfully.
File C:\WINDOWS\system32\provbmind.dll deleted successfully.
File C:\WINDOWS\system32\avibiosm.dll deleted successfully.


File C:\WINDOWS\system32\11.exe not found!
Deletion of file C:\WINDOWS\system32\11.exe failed!

Could not process line:
C:\WINDOWS\system32\11.exe
Status: 0xc0000034



File C:\WINDOWS\rundl132.exe not found!
Deletion of file C:\WINDOWS\rundl132.exe failed!

Could not process line:
C:\WINDOWS\rundl132.exe
Status: 0xc0000034



File C:\WINDOWS\system32\vsapidmv1.exe not found!
Deletion of file C:\WINDOWS\system32\vsapidmv1.exe failed!

Could not process line:
C:\WINDOWS\system32\vsapidmv1.exe
Status: 0xc0000034

File C:\WINDOWS\system32\asrp1.exe deleted successfully.
File C:\WINDOWS\system32\hx.exe deleted successfully.
File C:\WINDOWS\system32\drivers\npf.sys deleted successfully.
File C:\WINDOWS\winampc.exe deleted successfully.


File C:\WINDOWS\system32\myztr.dll not found!
Deletion of file C:\WINDOWS\system32\myztr.dll failed!

Could not process line:
C:\WINDOWS\system32\myztr.dll
Status: 0xc0000034



File C:\WINDOWS\system32\cs.exe not found!
Deletion of file C:\WINDOWS\system32\cs.exe failed!

Could not process line:
C:\WINDOWS\system32\cs.exe
Status: 0xc0000034



File C:\WINDOWS\system32\nmhxy.exe not found!
Deletion of file C:\WINDOWS\system32\nmhxy.exe failed!

Could not process line:
C:\WINDOWS\system32\nmhxy.exe
Status: 0xc0000034



File C:\WINDOWS\system32\nmhxy.dll not found!
Deletion of file C:\WINDOWS\system32\nmhxy.dll failed!

Could not process line:
C:\WINDOWS\system32\nmhxy.dll
Status: 0xc0000034



File C:\WINDOWS\system32\msdll.dll not found!
Deletion of file C:\WINDOWS\system32\msdll.dll failed!

Could not process line:
C:\WINDOWS\system32\msdll.dll
Status: 0xc0000034

File C:\WINDOWS\system32\dllwm.dll deleted successfully.


File C:\WINDOWS\system32\tdll.dll not found!
Deletion of file C:\WINDOWS\system32\tdll.dll failed!

Could not process line:
C:\WINDOWS\system32\tdll.dll
Status: 0xc0000034

File C:\WINDOWS\system32\ztdll.dll deleted successfully.
File C:\WINDOWS\system32\a.exe deleted successfully.


File C:\cmd.exe not found!
Deletion of file C:\cmd.exe failed!

Could not process line:
C:\cmd.exe
Status: 0xc0000034

File C:\WINDOWS\system32\sysldr.dll deleted successfully.
File C:\WINDOWS\system32\dumpreps.dll deleted successfully.
File C:\WINDOWS\edodo_install.exe deleted successfully.
File C:\WINDOWS\system32\wshcon32.dll deleted successfully.
File C:\WINDOWS\system32\ctfmoon.exe deleted successfully.


File C:\WINDOWS\system32\SVCH0ST.exe not found!
Deletion of file C:\WINDOWS\system32\SVCH0ST.exe failed!

Could not process line:
C:\WINDOWS\system32\SVCH0ST.exe
Status: 0xc0000034

File C:\WINDOWS\system32\bat.bat deleted successfully.


File C:\WINDOWS\system32\drivers\RGWatch.sys not found!
Deletion of file C:\WINDOWS\system32\drivers\RGWatch.sys failed!

Could not process line:
C:\WINDOWS\system32\drivers\RGWatch.sys
Status: 0xc0000034



File C:\WINDOWS\realupdate.exe not found!
Deletion of file C:\WINDOWS\realupdate.exe failed!

Could not process line:
C:\WINDOWS\realupdate.exe
Status: 0xc0000034

File C:\WINDOWS\system32\cn5940barToolbar.dll deleted successfully.
File C:\WINDOWS\winampb.exe deleted successfully.


File C:\WINDOWS\system32\quartz32.dll not found!
Deletion of file C:\WINDOWS\system32\quartz32.dll failed!

Could not process line:
C:\WINDOWS\system32\quartz32.dll
Status: 0xc0000034



File C:\WINDOWS\system32\wdfmgr32.exe not found!
Deletion of file C:\WINDOWS\system32\wdfmgr32.exe failed!

Could not process line:
C:\WINDOWS\system32\wdfmgr32.exe
Status: 0xc0000034

File C:\WINDOWS\system32\0.exe deleted successfully.


File C:\WINDOWS\system32\rayess.exe not found!
Deletion of file C:\WINDOWS\system32\rayess.exe failed!

Could not process line:
C:\WINDOWS\system32\rayess.exe
Status: 0xc0000034

File C:\WINDOWS\system32\rundll.exe deleted successfully.


File C:\WINDOWS\system32\drivers\ggeedgcg.sys not found!
Deletion of file C:\WINDOWS\system32\drivers\ggeedgcg.sys failed!

Could not process line:
C:\WINDOWS\system32\drivers\ggeedgcg.sys
Status: 0xc0000034

File C:\Program Files\xxxsvhost32.exe deleted successfully.


File C:\WINDOWS\qtask.exe not found!
Deletion of file C:\WINDOWS\qtask.exe failed!

Could not process line:
C:\WINDOWS\qtask.exe
Status: 0xc0000034



File C:\WINDOWS\System32\qtask.exe not found!
Deletion of file C:\WINDOWS\System32\qtask.exe failed!

Could not process line:
C:\WINDOWS\System32\qtask.exe
Status: 0xc0000034

File C:\WINDOWS\System32\mswdm.exe deleted successfully.
File C:\WINDOWS\System32\Ravdm.exe deleted successfully.


File C:\Program Files\Microsoft\svhost32.exe not found!
Deletion of file C:\Program Files\Microsoft\svhost32.exe failed!

Could not process line:
C:\Program Files\Microsoft\svhost32.exe
Status: 0xc0000034



File C:\WINDOWS\command\rundll32.exe not found!
Deletion of file C:\WINDOWS\command\rundll32.exe failed!

Could not process line:
C:\WINDOWS\command\rundll32.exe
Status: 0xc0000034

File C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5059.dll deleted successfully.


File C:\WINDOWS\system32\drivers\ggeedgcg.sys not found!
Deletion of file C:\WINDOWS\system32\drivers\ggeedgcg.sys failed!

Could not process line:
C:\WINDOWS\system32\drivers\ggeedgcg.sys
Status: 0xc0000034



File C:\DOCUME~1\dam\LOCALS~1\Temp\gwemjqmxfd not found!
Deletion of file C:\DOCUME~1\dam\LOCALS~1\Temp\gwemjqmxfd failed!

Could not process line:
C:\DOCUME~1\dam\LOCALS~1\Temp\gwemjqmxfd
Status: 0xc0000034



File C:\DOCUME~1\dam\LOCALS~1\Temp\mfobaptkp not found!
Deletion of file C:\DOCUME~1\dam\LOCALS~1\Temp\mfobaptkp failed!

Could not process line:
C:\DOCUME~1\dam\LOCALS~1\Temp\mfobaptkp
Status: 0xc0000034

File C:\WINDOWS\System32\drivers\nwlnksipx.sys deleted successfully.


File C:\WINDOWS\system32\DRIVERS\RGWatch.sys not found!
Deletion of file C:\WINDOWS\system32\DRIVERS\RGWatch.sys failed!

Could not process line:
C:\WINDOWS\system32\DRIVERS\RGWatch.sys
Status: 0xc0000034



File C:\WINDOWS\System32\DRIVERS\npf.sys not found!
Deletion of file C:\WINDOWS\System32\DRIVERS\npf.sys failed!

Could not process line:
C:\WINDOWS\System32\DRIVERS\npf.sys
Status: 0xc0000034

Folder C:\Program Files\coolsign deleted successfully.
Folder C:\Program Files\Common Files\UPDATE2 deleted successfully.
Folder C:\Program Files\CNNIC deleted successfully.


Folder C:\Program Files\ABC not found!
Deletion of folder C:\Program Files\ABC failed!

Could not process line:
C:\Program Files\ABC
Status: 0xc0000034



Folder c:\program Files\Òä¶à¶à not found!
Deletion of folder c:\program Files\Òä¶à¶à failed!

Could not process line:
c:\program Files\Òä¶à¶à
Status: 0xc0000034

Folder C:\WINDOWS\BJH deleted successfully.
Driver 8NASCAR unloaded successfully.
Driver gwemjqm unloaded successfully.
Driver mfobap unloaded successfully.
Driver nwlnksipx unloaded successfully.
Driver RGWatch unloaded successfully.
Driver NPF unloaded successfully.
Driver KSD2Service unloaded successfully.
Driver NetWorkLogons unloaded successfully.
Driver ServiceBJH unloaded successfully.


Registry key \Registry\Machine\System\CurrentControlSet\Services\ggeedgcg not found!
Unload of driver ggeedgcg failed!

Could not process line:
ggeedgcg
Status: 0xc0000034

Driver cdnprot unloaded successfully.
Program C:\Tools\HijackThis.exe successfully set up to run once on reboot.

Completed script processing.

*******************

Finished! Terminate.
  • 0

#14
Red_6

Red_6

    Member

  • Topic Starter
  • Member
  • PipPip
  • 76 posts
Not all of the entries that you asked me to delete were available.


Logfile of HijackThis v1.99.1
Scan saved at 00:26:57, on 09/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\explorer.exe
C:\Tools\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://client.jogo.c...esearch-en.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.c...msearch-en.html
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O1 - Hosts: 219.139.58.97 www.hao123.com
O1 - Hosts: 219.139.58.97 hao123.com
O1 - Hosts: 219.139.58.97 www.7b.com.cn
O1 - Hosts: 219.139.58.97 7b.com.cn
O1 - Hosts: 219.139.58.97 www.7939.com
O1 - Hosts: 219.139.58.97 www.maohehe.com
O1 - Hosts: 219.139.58.97 www.sina-baidu.com
O1 - Hosts: 219.139.58.97 sina-baidu.com
O1 - Hosts: 219.139.58.97 www.maipao.com
O1 - Hosts: 219.139.58.97 update.virussky.com
O1 - Hosts: 219.139.58.97 down.virussky.com
O1 - Hosts: 219.139.58.97 www.ycdy.com
O1 - Hosts: 219.139.58.97 ycdy.com
O1 - Hosts: 219.139.58.97 www.2tu.cn
O1 - Hosts: 219.139.58.97 2tu.cn
O1 - Hosts: 219.139.58.97 www.91tu.cn
O1 - Hosts: 219.139.58.97 91tu.cn
O1 - Hosts: 219.139.58.97 www.haotop.com
O1 - Hosts: 219.139.58.97 news01.virussky.com
O1 - Hosts: 219.139.58.97 news02.virussky.com
O1 - Hosts: 219.139.58.97 news03.virussky.com
O1 - Hosts: 219.139.58.97 news04.virussky.com
O1 - Hosts: 219.139.58.97 www.an85.com
O1 - Hosts: 219.139.58.97 an85.com
O1 - Hosts: 219.139.58.97 www.360safe.com
O1 - Hosts: 219.139.58.97 360safe.com
O1 - Hosts: 219.139.58.97 dl.360safe.com
O1 - Hosts: 219.139.58.97 bbs.360safe.com
O1 - Hosts: 219.139.58.97 www.gao58.com
O1 - Hosts: 219.139.58.97 count18.51yes.com
O1 - Hosts: 219.139.58.97 www.ok538.com
O1 - Hosts: 219.139.58.97 www.3000sss.com
O1 - Hosts: 219.139.58.97 3000sss.com
O1 - Hosts: 219.139.58.97 www.qq658.com
O1 - Hosts: 219.139.58.97 www.53679.com
O1 - Hosts: 219.139.58.97 www.17587.net
O1 - Hosts: 219.139.58.97 www.17587.com
O1 - Hosts: 219.139.58.97 www.an188.com
O1 - Hosts: 219.139.58.97 cwzwxm.3322.org
O1 - Hosts: 219.139.58.97 www.onediy.net
O1 - Hosts: 219.139.58.97 sohu.fswan.com
O1 - Hosts: 219.139.58.97 www.hewdq.com
O1 - Hosts: 219.139.58.97 go.ipcenter.cn
O1 - Hosts: 219.139.58.97 www.32666.com
O1 - Hosts: 219.139.58.97 show.googleadsenseagent.com
O1 - Hosts: 219.139.58.97 www.2yin.cn
O1 - Hosts: 219.139.58.97 2yin.cn
O1 - Hosts: 219.139.58.97 www.84442.com
O1 - Hosts: 219.139.58.97 www.898333.com
O1 - Hosts: 219.139.58.97 hewdq.com
O1 - Hosts: 219.139.58.97 84442.com
O1 - Hosts: 219.139.58.97 wwww.systeel.com.cn
O1 - Hosts: 219.139.58.97 go.baibaoxiang.cn
O1 - Hosts: 219.139.58.97 www.btbaicai.com
O1 - Hosts: 219.139.58.97 btbaicai.com
O1 - Hosts: 219.139.58.97 www.2t2t.cn
O1 - Hosts: 219.139.58.97 2t2t.cn
O1 - Hosts: 219.139.58.97 3.a.kal.cn
O1 - Hosts: 219.139.58.97 www.222978.com
O1 - Hosts: 219.139.58.97 www.5yaowan.com
O1 - Hosts: 219.139.58.97 show.roogoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: 5940bar BHO - {15953528-6C01-481A-8DB4-01888FB85B7D} - (no file)
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5059.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [iPodManager] C:\Program Files\iPod\bin\iPodManager.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [jiahus] C:\WINDOWS\System32\svchqs.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [R] C:\WINDOWS\System32\rundll32.exe mvlib.dll s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnnt] C:\WINDOWS\winampb.exe
O4 - HKCU\..\Run: [Syss] C:\DOCUME~1\dam\LOCALS~1\Temp\setup.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\wshcon32.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
  • 0

#15
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Looks better, but we still have way to go..in your next reply let me know of how the computer is behaving, any anomalies left?

Download the Hoster Here

Unzip Hoster to your desktop

Open up the Hoster program.
  • Make sure that the "make hosts writable?" button in the upper right corner is enabled.
  • Click back up Host files
  • then click Restore orginal host files
  • close program
Open HijackThis and click Scan. Put a check next to these:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://client.jogo.c...esearch-en.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.c...msearch-en.html
R3 - Default URLSearchHook is missing
O2 - BHO: 5940bar BHO - {15953528-6C01-481A-8DB4-01888FB85B7D} - (no file)
O2 - BHO: MyIEHelper Class - {16B770A0-0E87-4278-B748-2460D64A8386} - C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5059.dll (file missing)
O2 - BHO: (no name) - {CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} - (no file)
O4 - HKLM\..\Run: [jiahus] C:\WINDOWS\System32\svchqs.exe
O4 - HKLM\..\Run: [R] C:\WINDOWS\System32\rundll32.exe mvlib.dll s
O4 - HKCU\..\Run: [msnnt] C:\WINDOWS\winampb.exe
O4 - HKCU\..\Run: [Syss] C:\DOCUME~1\dam\LOCALS~1\Temp\setup.exe


Close all other windows except HijackThis and click Fix Checked.

Now let's reset your restore points.

Click Start Menu > All Programs > Accessories > System Tools > SystemRestore

Press OK. Choose 'Create a Restore Point' then Next. Name it and press 'Create' then when the confirmation screen shows the restore point has been created click 'Close'

Next goto Start Menu > Run > type

cleanmgr

click OK, when Disk Cleanup opens goto the 'More Options' tab and press 'Cleanup' on the system restore area which will remove all the restore points except the one we just created. To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.


A malicious .DLL file is disrupting the LSP chain on your computer. We need to get rid of it.
  • Disconnect from the internet and run the LSPFix.exe.
  • Check the I know what I'm doing box.
  • In the Keep box you should see one or more instances of wshcon32.dll.
  • Select every instance of wshcon32.dll and move each one to the Remove box by clicking the >> button.
  • When you are done click Finish>>.
Reboot when done. After that post the following logs, again seperately.

1) A new HijackThis log

2) A new combofix log

3)Download F-Secure Blacklight (blbeta.exe) to your C:\ drive.
- Open a command window. (Start>Run and type: cmd)
- Copy paste or type the following in the command window:

C:\blbeta.exe /expert

- Accept the user agreement.
- Click Scan.
After the scan finishes, click on Next, then Exit.

BlackLight will create a log in your C:\ drive with the name "fsbl-xxxxxxx.log". Please post that log.


4)Please do an online scan with Kaspersky WebScanner. If you have any quarantined items in your antivirus, please delete those archives before the scan.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Also please do this:

Locate this folder:

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine

and right click it then choose Send To then Compressed (zipped) folder) this will add a second folder there named Quarantine.zip,

Please go here:
The Spy Killer Forum
  • Click on "New Topic"
  • Put your name, e-mail address, and this as the title: "Chinese bundle"
  • Put a link to this Geeks to Go topic in the description box.
  • Then next to the file box, at the bottom, click the browse button, then navigate to this file:

    • C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine.zip
  • Click Open.
  • Click Post.
  • In the same topic upload this file as well:

    C:\avenger\backup.zip
Thank you!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP