Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Rootkit.Win32.Agent.wt Kaspersky can't delete this trojan [RESOLVE


  • This topic is locked This topic is locked

#1
borhan

borhan

    New Member

  • Member
  • Pip
  • 9 posts
Hello.. Ive got infected with this trojan Rootkit.win32.Agent.wt, Kaspersky detected it and when i try to neutralize the threat, It said the trojan will be deleted when your computer is restarted; but the virus is still there when i reboot. I also think that this trojan been hiding some other virus. Can anyone help me to remove it? I know nothing about registry and i have downloaded Hijack this, but i dont know how to use it..
  • 0

Advertisements


#2
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

  • 0

#3
borhan

borhan

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
hello.. thanks for the reply.. ive done as you instruct, here are the files

main.txt

Deckard's System Scanner v20071014.68
Run by ali on 2008-02-08 01:03:30
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
7: 2008-02-07 17:03:51 UTC - RP7 - Deckard's System Scanner Restore Point
6: 2008-02-07 08:47:51 UTC - RP6 - Removed QuickTime
5: 2008-02-07 08:43:55 UTC - RP5 - Removed Apple Software Update
4: 2008-02-06 10:39:57 UTC - RP4 - System Checkpoint
3: 2008-02-05 03:35:23 UTC - RP3 - System Checkpoint


-- First Restore Point --
1: 2008-02-02 19:04:10 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 224 MiB (512 MiB recommended).


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-02-08 01:05:36
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Program Files\DAP\DAP.exe
C:\Program Files\Yahoo!\Messenger\YServer.exe
C:\Documents and Settings\ali\Desktop\dss.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: SrchHook Class - {F4F10C1D-87C7-404A-B4B3-000000000000} - C:\Program Files\DAP\SBSearch.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {DECFDFCA-956D-4E21-922C-9A11259F416A} - C:\WINDOWS\system32\browsel.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: msn_0801_upd022315.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} () - http://www.apple.com...ex/qtplugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.ma...t/ultrashim.cab
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{D63896AA-E322-4B3D-96B2-29A7B5BE20CA}: NameServer = 202.188.0.133 202.188.1.5
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe


--
End of file - 4938 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 zfjnbims - c:\windows\system32\drivers\olcvmsif.dat
R3 RMSPPPOE (WAN Miniport (PPP over Ethernet Protocol)) - c:\windows\system32\drivers\rmspppoe.sys <Not Verified; Robert Schlabbach; PPP over Ethernet Protocol>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

All services whitelisted.


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Multimedia Audio Controller
Device ID: PCI\VEN_13F6&DEV_0111&SUBSYS_011113F6&REV_10\3&61AAA01&0&58
Manufacturer:
Name: Multimedia Audio Controller
PNP Device ID: PCI\VEN_13F6&DEV_0111&SUBSYS_011113F6&REV_10\3&61AAA01&0&58
Service:


-- Scheduled Tasks -------------------------------------------------------------

2008-02-01 20:10:22 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2008-02-01 17:15:00 386 --a------ C:\WINDOWS\Tasks\1-Click Maintenance.job


-- Files created between 2008-01-08 and 2008-02-08 -----------------------------

2008-02-07 21:07:47 0 dr-h----- C:\Documents and Settings\ali\Recent
2008-02-07 17:16:59 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-02-07 17:16:59 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-02-07 17:16:59 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-02-07 17:16:59 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-02-07 17:16:59 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-02-07 17:16:59 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-02-07 17:16:59 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-02-07 17:16:59 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-02-07 17:16:59 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-02-07 17:16:59 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-02-07 17:16:59 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2008-02-07 17:16:59 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-02-07 17:16:59 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-02-07 17:16:58 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-02-03 00:02:03 19584 --a------ C:\WINDOWS\system32\drivers\olcvmsif.dat
2008-02-02 23:59:18 84992 --a------ C:\WINDOWS\system32\browsel.dll
2008-01-30 23:15:21 0 d-------- C:\Program Files\Audacity
2008-01-24 00:10:49 0 d--h----- C:\WINDOWS\PIF
2008-01-24 00:05:59 0 d--h----- C:\WINDOWS\system32\GroupPolicy
2008-01-23 22:50:05 0 d-------- C:\Documents and Settings\ali\Application Data\Mozilla
2008-01-23 22:15:57 10 --a------ C:\WINDOWS\popcinfo.dat
2008-01-20 20:01:18 0 d-------- C:\Documents and Settings\ali\Application Data\Apple Computer
2008-01-19 22:25:58 0 d-------- C:\Program Files\Apple Software Update
2008-01-19 22:25:57 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-01-16 22:53:52 0 d-------- C:\Program Files\QuickTime


-- Find3M Report ---------------------------------------------------------------

2008-02-07 17:00:44 0 d-------- C:\Program Files\Kaspersky Lab
2008-02-07 16:44:34 0 d-------- C:\Program Files\DivX
2008-02-03 22:35:20 0 d-------- C:\Documents and Settings\ali\Application Data\LimeWire
2008-02-03 02:55:04 0 d-------- C:\Program Files\LimeWire
2008-01-24 07:57:33 0 d-------- C:\Program Files\GRETECH
2008-01-06 02:12:48 0 d-------- C:\Documents and Settings\ali\Application Data\Sun
2008-01-04 23:04:46 0 d-------- C:\Program Files\Java
2008-01-04 22:51:14 0 d-------- C:\Program Files\Common Files
2008-01-04 22:51:14 0 d-------- C:\Program Files\Common Files\Java
2008-01-04 14:35:01 0 d-------- C:\Program Files\DAP
2008-01-04 14:19:52 50688 --a------ C:\WINDOWS\system32\wbhelp2.dll <Not Verified; Stardock.Net, Inc; WindowBlinds for Win32 x86 machines>
2007-12-31 09:15:11 0 d-------- C:\Program Files\ShoppingReport
2007-12-31 09:15:11 0 d-------- C:\Documents and Settings\ali\Application Data\ShoppingReport
2007-12-30 16:16:25 0 d-------- C:\Program Files\VIAudioi
2007-12-30 15:48:54 0 d-------- C:\Program Files\illiminable
2007-12-29 13:23:31 515072 --a------ C:\WINDOWS\system32\logonuiX.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-12-29 08:26:46 0 d-------- C:\Program Files\tmnet streamyx
2007-12-29 08:25:52 286720 -----n--- C:\WINDOWS\Setup1.exe <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Windows>
2007-12-29 08:25:45 73216 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2007-12-14 19:12:37 0 d-------- C:\Program Files\AC3Filter
2007-12-14 19:03:16 22782 --a------ C:\WINDOWS\system32\UninstXviDDec.exe
2007-12-14 18:50:24 0 d-------- C:\Program Files\Ringz Studio
2007-12-14 17:36:51 0 d-------- C:\Documents and Settings\ali\Application Data\Media Player Classic
2007-12-11 19:02:05 0 d-------- C:\Documents and Settings\ali\Application Data\U3
2007-12-08 17:28:45 0 d-------- C:\Program Files\WinCustomize


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DECFDFCA-956D-4E21-922C-9A11259F416A}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [11/09/2006 09:28 AM]
"@"="" []
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [03/04/2005 02:20 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
msn_0801_upd022315.exe [1/4/2008 3:10:02 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"=12 (0xc)
"ClearRecentDocsOnExit"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"WinampAgent"="C:\Program Files\Winamp\winampa.exe"
"DownloadAccelerator"="C:\Program Files\DAP\DAP.EXE" /STARTUP
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a47afc29-bac0-11dc-8748-000d8706a21e}]
Auto\command- sxs.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b2188ff4-90d5-11dc-8def-000d8706a21e}]
Auto\command- H:\autoregistry.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autoregistry.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bfb862e5-9344-11dc-86fc-000d8706a21e}]
Auto\command- H:\setup.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe




-- End of Deckard's System Scanner: finished at 2008-02-08 01:09:42 ------------


Extra.txt

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Celeron® CPU 1.70GHz
Percentage of Memory in Use: 72%
Physical Memory (total/avail): 223.48 MiB / 61.53 MiB
Pagefile Memory (total/avail): 546.5 MiB / 181.48 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1934.5 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 8.04 GiB total, 1.74 GiB free.
D: is Fixed (NTFS) - 9.77 GiB total, 0.51 GiB free.
E: is Fixed (NTFS) - 10.97 GiB total, 8.66 GiB free.
F: is Fixed (FAT32) - 27.48 GiB total, 15.86 GiB free.
G: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - QUANTUM FIREBALLlct15 20 - 19.01 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 8.04 GiB - C:
\PARTITION1 - Extended w/Extended Int 13 - 10.97 GiB - E:

\\.\PHYSICALDRIVE1 - ST340015A - 37.27 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 9.77 GiB - D:
\PARTITION1 - Extended w/Extended Int 13 - 27.49 GiB - F:



-- Security Center -------------------------------------------------------------

AUOptions is disabled.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.

FW: Kaspersky Anti-Virus v6.0.1.411 () Disabled
AV: Kaspersky Anti-Virus v6.0.1.411 (`)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\DAP\\DAP.exe"="C:\\Program Files\\DAP\\DAP.exe:*:Enabled:Download Accelerator Plus (DAP)"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\ali\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=SIGONDRONG
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\ali
LOGONSERVER=\\SIGONDRONG
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 1 Stepping 3, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0103
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\ali\LOCALS~1\Temp
TMP=C:\DOCUME~1\ali\LOCALS~1\Temp
USERDOMAIN=SIGONDRONG
USERNAME=ali
USERPROFILE=C:\Documents and Settings\ali
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

ali (admin)
Administrator (new local, admin)
Guest (guest)


-- Add/Remove Programs ---------------------------------------------------------

--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
AC3Filter (remove only) --> C:\Program Files\AC3Filter\uninstall.exe
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81100000003}
Audacity 1.2.6 --> "C:\Program Files\Audacity\unins000.exe"
AVG Anti-Rootkit Free --> C:\Program Files\GRISOFT\AVG Anti-Rootkit Free\Uninstall.exe
Download Accelerator Plus (DAP) --> C:\PROGRA~1\DAP\DAPREMOVE.EXE
FLAC codecs --> C:\Program Files\illiminable\oggcodecs\uninst.exe
Flag 1024x768 --> C:\Program Files\Flag 1024x768\Uninstall.exe
Guitar Pro 5.0 --> "C:\Program Files\Guitar Pro 5\unins000.exe"
Java™ 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Kaspersky Anti-Virus 6.0 --> MsiExec.exe /I{75193929-9A52-4CA4-98DE-8C7296940920}
LimeWire 4.14.12 --> "C:\Program Files\LimeWire\uninstall.exe"
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Windows Media Video 9 VCM --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmv9vcm.inf, Uninstall
PPP over Ethernet Protocol 0.98 --> C:\WINDOWS\system32\RASPPPOE.EXE /REMOVE
tmnet streamyx --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\tmnet streamyx\ST6UNST.LOG"
TuneUp Utilities 2007 --> MsiExec.exe /I{C8BB4912-12D9-42AE-B571-E580D8CD1B5B}
VIA Vinyl Audio Codecs Driver Setup Program --> RunDll32.exe UnAudioNT.dll,UninstallAudio C:\WINDOWS\IsUninst.exe -y-f"C:\PROGRA~1\VIAudioi\SBASetup\Uninst.isu"
VideoLAN VLC media player 0.8.6b --> C:\Program Files\VideoLAN\VLC\uninstall.exe
Vista Codec Package --> MsiExec.exe /I{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}
Winamp --> "C:\Program Files\Winamp\UninstWA.exe"
Yahoo! Browser Services --> C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S
Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Internet Mail --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type1093 / Error
Event Submitted/Written: 02/07/2008 01:30:54 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application iexplore.exe, version 6.0.2900.2180, faulting module unknown, version 0.0.0.0, fault address 0x011a01bd.
Processing media-specific event for [iexplore.exe!ws!]

Event Record #/Type1087 / Error
Event Submitted/Written: 02/07/2008 00:39:53 AM
Event ID/Source: 0 / ODBC
Event Description:
Failed to load resource DLL odbcint.dll

Event Record #/Type1065 / Warning
Event Submitted/Written: 02/06/2008 01:36:11 PM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event Record #/Type1064 / Error
Event Submitted/Written: 02/06/2008 01:32:21 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application avp.exe, version 6.0.1.411, faulting module Avp1.ppl, version 6.0.1.411, fault address 0x000013c4.
Processing media-specific event for [avp.exe!ws!]

Event Record #/Type1063 / Error
Event Submitted/Written: 02/06/2008 01:32:01 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application avp.exe, version 6.0.1.411, faulting module Avp1.ppl, version 6.0.1.411, fault address 0x000013c4.
Processing media-specific event for [avp.exe!ws!]



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type15414 / Warning
Event Submitted/Written: 02/07/2008 08:49:26 PM
Event ID/Source: 63 / RMSPPPOE
Event Description:
Received a PPPoE Session packet for an unknown session.
Ignoring this packet.

Event Record #/Type15413 / Warning
Event Submitted/Written: 02/07/2008 08:49:26 PM
Event ID/Source: 63 / RMSPPPOE
Event Description:
Received a PPPoE Session packet for an unknown session.
Ignoring this packet.

Event Record #/Type15412 / Warning
Event Submitted/Written: 02/07/2008 08:49:26 PM
Event ID/Source: 63 / RMSPPPOE
Event Description:
Received a PPPoE Session packet for an unknown session.
Ignoring this packet.

Event Record #/Type15411 / Warning
Event Submitted/Written: 02/07/2008 08:49:26 PM
Event ID/Source: 63 / RMSPPPOE
Event Description:
Received a PPPoE Session packet for an unknown session.
Ignoring this packet.

Event Record #/Type15410 / Warning
Event Submitted/Written: 02/07/2008 08:49:25 PM
Event ID/Source: 31 / RMSPPPOE
Event Description:
Received a PPPoE Active Discovery Session-confirmation packet with an unrecognized Host Unique ID, possibly from another PPP over Ethernet implementation running on this machine.
Ignoring this packet.



-- End of Deckard's System Scanner: finished at 2008-02-08 01:09:42 ------------
  • 0

#4
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

CLICK THIS TO LINK TO BE SURE YOU CAN VIEW HIDDEN FILES

Please go here:
The Spy Killer Forum
  • Click on "New Topic"
  • Put your name, e-mail address, and this as the title: "
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\msn_0801_upd022315.exe
    "
  • Put a link to this topic in the description box.
  • Then next to the file box, at the bottom, click the browse button, then navigate to this file:



    • C:\Documents and Settings\All Users\Start Menu\Programs\Startup\msn_0801_upd022315.exe

  • Click Open.
  • Click Post.
Thank you!



  • 1 - Flash Drive Disinfector
    Download Flash_Disinfector.exe by sUBs from >here< and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.




Download ComboFix from one of the locations below, and save it to your Desktop.

Link 1
Link 2
Link 3

Double click combofix.exe and follow the prompts.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
  • 0

#5
borhan

borhan

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Sorry for late reply..
This is the log file from combo fix

ComboFix 08-02.05.3 - ali 2008-02-08 16:42:42.1 - NTFSx86
Running from: C:\Documents and Settings\ali\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\ali\Application Data\ShoppingReport
C:\Documents and Settings\ali\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\ali\My Documents\CruzerLock2\Desktop_.ini
C:\Documents and Settings\ali\My Documents\SecurDataStor\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Music\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Music\My Playlists\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\00140E05\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Videos\Desktop_.ini
C:\Documents and Settings\All Users\Documents\ZAI..!\chapter untuk discussion\2 page je.. okay tak\Boleh la\Desktop_.ini
C:\Documents and Settings\All Users\Documents\ZAI..!\chapter untuk discussion\2 page je.. okay tak\Desktop_.ini
C:\Documents and Settings\All Users\Documents\ZAI..!\chapter untuk discussion\Desktop_.ini
C:\Documents and Settings\All Users\Documents\ZAI..!\Desktop_.ini
C:\Program Files\ShoppingReport
C:\Program Files\ShoppingReport\Uninst.exe
C:\WINDOWS\system32\browsel.dll
C:\WINDOWS\system32\drivers\olcvmsif.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_ZFJNBIMS
-------\zfjnbims


((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.

2008-02-08 01:03 . 2008-02-08 01:03 <DIR> d-------- C:\Deckard
2008-02-06 16:35 . 2007-01-18 20:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-01-30 23:15 . 2008-01-30 23:15 <DIR> d-------- C:\Program Files\Audacity
2008-01-24 00:10 . 2008-01-24 00:10 <DIR> d--h----- C:\WINDOWS\PIF
2008-01-24 00:05 . 2008-01-24 00:05 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-01-23 22:59 . 2008-01-23 22:59 125 --a------ C:\ioSpecial.ini
2008-01-23 22:15 . 2008-01-23 22:15 10 --a------ C:\WINDOWS\popcinfo.dat
2008-01-20 20:01 . 2008-01-20 20:01 <DIR> d-------- C:\Documents and Settings\ali\Application Data\Apple Computer
2008-01-19 22:25 . 2008-01-19 22:26 <DIR> d-------- C:\Program Files\Apple Software Update
2008-01-19 22:25 . 2008-01-19 22:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-01-16 22:53 . 2008-02-07 16:51 <DIR> d-------- C:\Program Files\QuickTime
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 09:04 7,834,656 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-08 09:04 308,256 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-02-08 09:01 32,012 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-02-08 09:01 109,844 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-08 08:41 --------- d-----w C:\Program Files\Kaspersky Lab
2008-02-08 08:36 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-07 08:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-07 08:44 --------- d-----w C:\Program Files\DivX
2008-02-03 14:35 --------- d-----w C:\Documents and Settings\ali\Application Data\LimeWire
2008-02-02 18:55 --------- d-----w C:\Program Files\LimeWire
2008-01-23 23:57 --------- d-----w C:\Program Files\GRETECH
2008-01-04 15:04 --------- d-----w C:\Program Files\Java
2008-01-04 14:51 --------- d-----w C:\Program Files\Common Files\Java
2008-01-04 06:35 --------- d-----w C:\Program Files\DAP
2008-01-04 06:19 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll
2007-12-30 08:16 --------- d-----w C:\Program Files\VIAudioi
2007-12-30 07:48 --------- d-----w C:\Program Files\illiminable
2007-12-29 20:55 --------- d-----w C:\Documents and Settings\Guest\Application Data\Yahoo!
2007-12-29 05:23 515,072 ----a-w C:\WINDOWS\system32\logonuiX.exe
2007-12-29 00:26 --------- d-----w C:\Program Files\tmnet streamyx
2007-12-29 00:25 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-12-29 00:25 286,720 ------w C:\WINDOWS\Setup1.exe
2007-12-14 11:12 --------- d-----w C:\Program Files\AC3Filter
2007-12-14 11:03 22,782 ----a-w C:\WINDOWS\system32\UninstXviDDec.exe
2007-12-14 10:50 --------- d-----w C:\Program Files\Ringz Studio
2007-12-14 09:36 --------- d-----w C:\Documents and Settings\ali\Application Data\Media Player Classic
2007-12-11 11:02 --------- d-----w C:\Documents and Settings\ali\Application Data\U3
2007-12-08 09:28 --------- d-----w C:\Program Files\WinCustomize
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2006-11-09 09:28 155751]
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2005-03-04 14:20 512000]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
msn_0801_upd022315.exe [2008-01-04 15:10:02 93272]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 12 (0xc)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonui.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"WinampAgent"="C:\Program Files\Winamp\winampa.exe"
"DownloadAccelerator"="C:\Program Files\DAP\DAP.EXE" /STARTUP
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS [2002-10-03 16:09]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a47afc29-bac0-11dc-8748-000d8706a21e}]
\Shell\Auto\command - sxs.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bfb862e5-9344-11dc-86fc-000d8706a21e}]
\Shell\Auto\command - H:\setup.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-01 09:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2008-02-01 12:10:22 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-08 17:03:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-02-08 17:08:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-08 09:08:29

This is the Hijackthis log file

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:57:23 PM, on 2/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: SrchHook Class - {F4F10C1D-87C7-404A-B4B3-000000000000} - C:\PROGRA~1\DAP\SBSearch.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: msn_0801_upd022315.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{D63896AA-E322-4B3D-96B2-29A7B5BE20CA}: NameServer = 202.188.0.133 202.188.1.5
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe

--
End of file - 3704 bytes

Thank you..
  • 0

#6
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - Global Startup: msn_0801_upd022315.exe


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\msn_0801_upd022315.exe
H:\setup.exe

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a47afc29-bac0-11dc-8748-000d8706a21e}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bfb862e5-9344-11dc-86fc-000d8706a21e}]


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall



Reboot and post a new HijackThis log
  • 0

#7
borhan

borhan

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Hello..

This is the new hijackthis log after reboot.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:29:18 PM, on 2/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: SrchHook Class - {F4F10C1D-87C7-404A-B4B3-000000000000} - C:\PROGRA~1\DAP\SBSearch.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{D63896AA-E322-4B3D-96B2-29A7B5BE20CA}: NameServer = 202.188.0.133 202.188.1.5
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe

--
End of file - 3631 bytes

Thank you..
  • 0

#8
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Can you post the ComboFix log

Also do this

Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.


And tell me how your PC is running
  • 0

#9
borhan

borhan

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
ill do that right away..
  • 0

#10
borhan

borhan

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Hello..

This is the combofix log.


ComboFix 08-02.05.3 - ali 2008-02-08 22:09:45.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.73 [GMT 8:00]
Running from: C:\Documents and Settings\ali\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\ali\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\msn_0801_upd022315.exe
H:\setup.exe
.

((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.

2008-02-08 19:56 . 2008-02-08 19:56 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-08 01:03 . 2008-02-08 01:03 <DIR> d-------- C:\Deckard
2008-02-06 16:35 . 2007-01-18 20:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-01-30 23:15 . 2008-01-30 23:15 <DIR> d-------- C:\Program Files\Audacity
2008-01-24 00:10 . 2008-01-24 00:10 <DIR> d--h----- C:\WINDOWS\PIF
2008-01-24 00:05 . 2008-01-24 00:05 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-01-23 22:59 . 2008-01-23 22:59 125 --a------ C:\ioSpecial.ini
2008-01-23 22:15 . 2008-01-23 22:15 10 --a------ C:\WINDOWS\popcinfo.dat
2008-01-20 20:01 . 2008-01-20 20:01 <DIR> d-------- C:\Documents and Settings\ali\Application Data\Apple Computer
2008-01-19 22:25 . 2008-01-19 22:26 <DIR> d-------- C:\Program Files\Apple Software Update
2008-01-19 22:25 . 2008-01-19 22:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-01-16 22:53 . 2008-02-07 16:51 <DIR> d-------- C:\Program Files\QuickTime
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 14:18 7,969,056 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-08 14:17 311,840 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-02-08 09:01 32,012 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-02-08 09:01 109,844 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-08 08:41 --------- d-----w C:\Program Files\Kaspersky Lab
2008-02-08 08:36 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-07 08:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-07 08:44 --------- d-----w C:\Program Files\DivX
2008-02-03 14:35 --------- d-----w C:\Documents and Settings\ali\Application Data\LimeWire
2008-02-02 18:55 --------- d-----w C:\Program Files\LimeWire
2008-01-23 23:57 --------- d-----w C:\Program Files\GRETECH
2008-01-04 15:04 --------- d-----w C:\Program Files\Java
2008-01-04 14:51 --------- d-----w C:\Program Files\Common Files\Java
2008-01-04 06:35 --------- d-----w C:\Program Files\DAP
2008-01-04 06:19 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll
2007-12-30 08:16 --------- d-----w C:\Program Files\VIAudioi
2007-12-30 07:48 --------- d-----w C:\Program Files\illiminable
2007-12-29 20:55 --------- d-----w C:\Documents and Settings\Guest\Application Data\Yahoo!
2007-12-29 05:23 515,072 ----a-w C:\WINDOWS\system32\logonuiX.exe
2007-12-29 00:26 --------- d-----w C:\Program Files\tmnet streamyx
2007-12-29 00:25 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-12-29 00:25 286,720 ------w C:\WINDOWS\Setup1.exe
2007-12-14 11:12 --------- d-----w C:\Program Files\AC3Filter
2007-12-14 11:03 22,782 ----a-w C:\WINDOWS\system32\UninstXviDDec.exe
2007-12-14 10:50 --------- d-----w C:\Program Files\Ringz Studio
2007-12-14 09:36 --------- d-----w C:\Documents and Settings\ali\Application Data\Media Player Classic
2007-12-11 11:02 --------- d-----w C:\Documents and Settings\ali\Application Data\U3
2007-12-08 09:28 --------- d-----w C:\Program Files\WinCustomize
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2006-11-09 09:28 155751]
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2005-03-04 14:20 512000]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 12 (0xc)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonui.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"WinampAgent"="C:\Program Files\Winamp\winampa.exe"
"DownloadAccelerator"="C:\Program Files\DAP\DAP.EXE" /STARTUP
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:56]
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS [2002-10-03 16:09]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a47afc29-bac0-11dc-8748-000d8706a21e}]
\Shell\Auto\command - sxs.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bfb862e5-9344-11dc-86fc-000d8706a21e}]
\Shell\Auto\command - H:\setup.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-08 22:17:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-08 22:20:54
ComboFix-quarantined-files.txt 2008-02-08 14:20:39
ComboFix2.txt 2008-02-08 09:08:55

Arigato gozaimasu..
  • 0

Advertisements


#11
borhan

borhan

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Hello..
The scan took a long time because i have a lot of files.
Here is the Scan Log

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/09/2008 at 04:01 AM

Application Version : 3.9.1008

Core Rules Database Version : 3397
Trace Rules Database Version: 1389

Scan type : Complete Scan
Total Scan Time : 04:53:05

Memory items scanned : 311
Memory threats detected : 0
Registry items scanned : 4416
Registry threats detected : 18
File items scanned : 108596
File threats detected : 191

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}
HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}
HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}
HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}\InprocServer32
HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}\InprocServer32#ThreadingModel
HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}\ProgID
HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}\Programmable
HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}\TypeLib
HKCR\CLSID\{F4F10C1D-87C7-404A-B4B3-000000000000}\VersionIndependentProgID
C:\PROGRA~1\DAP\SBSEARCH.DLL
HKU\S-1-5-21-507921405-1383384898-1060284298-1003\Software\Microsoft\Internet Explorer\URLSearchHooks#{F4F10C1D-87C7-404A-B4B3-000000000000}
HKCR\SearchHook.SrchHook.1
HKCR\SearchHook.SrchHook
HKCR\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}
HKCR\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}\1.0
HKCR\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}\1.0\0
HKCR\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}\1.0\0\win32
HKCR\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}\1.0\FLAGS
HKCR\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}\1.0\HELPDIR

Adware.Tracking Cookie
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][3].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][7].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][4].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][3].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][5].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][6].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][4].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][1].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
C:\Documents and Settings\ali\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][2].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt
D:\Documents and Settings\Borhan\Cookies\[email protected][1].txt

Trojan.VXGame/32
D:\WINDOWS\SYSTEM32\DLH9JKDQ8.EXE

Trojan.SearchTool
D:\WINDOWS\SYSTEM32\SEARCHTOOL\NSG13.DLL

Trojan.Downloader-Gen/Win
D:\WINDOWS\SYSTEM32\SVCP.CSV

Trojan.Downloader-Gen
D:\WINDOWS\SYSTEM32\WINSUB.XML

Is my system clean?
How do I know?
  • 0

#12
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Your logs are clean ! We need to do a few things

Now lets uninstall Combofix:
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
The above procedure will do the following:
  • Delete ComboFix and its associated files and folders.
  • Delete VundoFix backups, if present
  • Delete the C:\Deckard folder, if present
  • Delete the C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.




You now need to update your Java and remove your older versions.

Please follow these steps to remove older version Java components.

* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.

Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here



Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
SpywareBlaster protects against bad ActiveX
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here

* SpywareGuard offers realtime protection from spyware installation attempts.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

Thank you for your patience, and performing all of the procedures requested.
  • 0

#13
borhan

borhan

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Hello Rorschach112..

Thank you for all your help..

I`ll follow your suggestion, but what about the current applications installed on my pc:
  • Kaspersky
  • Tune up Utilities 2007

And the previous software you asked to install; dss.exe, Flash_disinfector, SuperAntispyware..

Should I have antivirus programme?
I used tune up utilities to clean my registry, Is there a better application?
Ive Installed Firefox before, But when i try to launch it, nothing happens. I checked in drive C:\Program Files, Mozilla Firefox folder exist. Was it because of virus? I`ll try to install it again..

Edited by borhan, 08 February 2008 - 09:08 AM.

  • 0

#14
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

I`ll follow your suggestion, but what about the current applications installed on my pc:

1. Kaspersky
2. Tune up Utilities 2007

These are good programs, especially Kaspersky

And the previous software you asked to install; dss.exe, Flash_disinfector, SuperAntispyware..

Delete those, but keep SUPERAntiSpyware

Should I have antivirus programme?

You have Kaspersky


Is there a better application?

Not that I know of

But when i try to launch it, nothing happens. I checked in drive C:\Program Files, Mozilla Firefox folder exist. Was it because of virus? I`ll try to install it again..

No it wouldn't be virus related, a re-install may work


Let me know if you have any more questions
  • 0

#15
borhan

borhan

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Hello Rorschach112..

Thanks for the answer..
But I still can`t launch Firefox, At the end of installation it say 'click Finish to launch Firefox' I clicked, my mouse pointer shows sandclock beside it; seems like it was runnig to open. But then the browser didn't open. I double click on the shortcut, still nothing. Ive also tried to reinstall it
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP