Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Vundo trojan (log included)- help appreciated! [RESOLVED]


  • This topic is locked This topic is locked

#16
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

1. Close any open browsers.


Download the attached CFScript text file to your desktop and drag it into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt", attach this log in your reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

  • 0

Advertisements


#17
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
ComboFix 08-02.05.3 - Rinita 2008-02-09 17:36:00.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.374 [GMT -5:00]
Running from: C:\Documents and Settings\Rinita\My Documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\Rinita\My Documents\cfscript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\Program Files\McAfee.com\Agent\mcupdate .exe
C:\Program Files\McAfee\SpamKiller\MS0516~4 .EXE
C:\Program Files\McAfee\SpamKiller\MS162B~1 .EXE
C:\Program Files\McAfee\SpamKiller\MS18BE~2 .EXE
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\McAfee.com\Agent\mcupdate .exe
C:\Program Files\McAfee\SpamKiller\MS0516~4 .EXE
C:\Program Files\McAfee\SpamKiller\MS162B~1 .EXE
C:\Program Files\McAfee\SpamKiller\MS18BE~2 .EXE
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\McAfee.com\Agent\mcupdate .exe
C:\Program Files\McAfee\SpamKiller\MS0516~4 .EXE
C:\Program Files\McAfee\SpamKiller\MS162B~1 .EXE
C:\Program Files\McAfee\SpamKiller\MS18BE~2 .EXE
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe

.
((((((((((((((((((((((((( Files Created from 2008-01-09 to 2008-02-09 )))))))))))))))))))))))))))))))
.

2008-02-08 20:22 . 2004-08-10 14:00 388,608 --a------ C:\kmd.exe
2008-02-08 17:13 . 2008-02-08 17:13 279 --a------ C:\Shortcut to Local Disk ©.lnk
2008-02-08 15:10 . 2008-02-08 15:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-07 20:15 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\RkPavProc.sys
2008-02-07 20:06 . 2008-02-07 20:06 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-07 20:06 . 2008-02-07 20:06 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-02-07 16:21 . 2008-02-07 20:41 <DIR> d-------- C:\VundoFix Backups
2008-02-07 15:59 . 2008-02-07 15:59 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-07 15:59 . 2008-02-07 15:59 <DIR> d-------- C:\Documents and Settings\Rinita\Application Data\SUPERAntiSpyware.com
2008-02-07 14:39 . 2008-02-07 20:11 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-07 14:39 . 2008-02-07 14:39 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-07 14:31 . 2008-02-09 16:45 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-28 20:00 . 2008-01-28 20:04 81 --a------ C:\WINDOWS\QTW.INI
2008-01-19 17:38 . 2008-02-07 16:19 406,016 --a------ C:\WINDOWS\system32\PSDrvCheck.exe
2008-01-19 17:38 . 2008-02-07 16:19 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-01-19 17:37 . 2008-01-27 11:14 64,512 --a--c--- C:\WINDOWS\system32\dllcache\ehtray.exe
2008-01-17 18:31 . 2008-01-17 18:31 0 --a------ C:\WINDOWS\OpPrintServer.INI
2008-01-17 18:26 . 2008-01-17 18:26 <DIR> d-------- C:\WINDOWS\StartHtmico
2008-01-17 18:26 . 2008-01-17 18:26 <DIR> d-------- C:\WINDOWS\IP4000,3000
2008-01-17 18:26 . 2004-04-23 00:00 116,736 --a------ C:\WINDOWS\system32\CNMLM64.DLL
2008-01-17 18:26 . 2004-03-11 11:06 86,016 -ra------ C:\WINDOWS\system32\CNMCP64.exe
2008-01-17 18:26 . 2004-04-23 00:00 7,680 --a------ C:\WINDOWS\system32\CNMVS64.DLL
2008-01-17 16:02 . 2008-01-17 16:19 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-14 13:14 . 2005-11-21 00:48 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2008-01-14 13:14 . 2005-11-21 00:48 16,512 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-01-14 13:13 . 2008-01-14 13:17 <DIR> d-------- C:\Program Files\BitZipper
2008-01-14 13:13 . 2008-01-14 13:13 <DIR> d-------- C:\Documents and Settings\Rinita\Application Data\BitZipper
2008-01-14 12:45 . 2008-01-04 16:58 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-01-14 12:45 . 2008-01-04 16:58 120,056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-01-14 12:45 . 2008-01-04 16:58 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2008-01-13 09:30 . 2008-01-13 09:30 <DIR> d-------- C:\Documents and Settings\Rinita\Application Data\Viewpoint

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 22:36 --------- d-----w C:\Program Files\QuickTime
2008-02-09 01:22 --------- d-----w C:\Program Files\iTunes
2008-02-09 01:22 --------- d-----w C:\Program Files\Digital Media Reader
2008-02-08 01:16 --------- d-----w C:\Program Files\Google
2008-02-07 20:14 --------- d-----w C:\Documents and Settings\Rinita\Application Data\Azureus
2008-01-17 23:32 --------- d-----w C:\Program Files\Canon
2008-01-14 18:05 --------- d-----w C:\Documents and Settings\Rinita\Application Data\LimeWire
2008-01-14 00:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-04 21:58 43,528 ------w C:\windows\system32\drivers\pxhelp20.sys
2007-12-31 16:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-29 16:37 --------- d-----w C:\Program Files\Quicken
2007-12-29 16:37 --------- d-----w C:\Program Files\Microsoft Works
2007-12-28 16:47 --------- d-----w C:\Program Files\Microsoft.NET
2007-12-25 23:54 --------- d-----w C:\Program Files\InterActual
2007-12-25 15:54 --------- d-----w C:\Documents and Settings\Rinita\Application Data\CyberLink
2007-12-19 00:09 --------- d-----w C:\Program Files\LiveMath
2007-12-10 22:34 --------- d-----w C:\Documents and Settings\Rinita\Application Data\U3
2007-11-16 02:56 46 ----a-w C:\Documents and Settings\Rinita\Application Data\wklnhst.dat
2007-10-24 18:58 299,288 ----a-w C:\Program Files\GmailInstaller.exe
2007-10-02 18:59 1,164,456 ----a-w C:\Program Files\install_flash_player.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-19 17:38 1694208]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-22 14:30 68856]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [ ]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2004-08-10 14:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-08 15:04 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2008-01-27 11:14 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 18:19 77312 C:\WINDOWS\arpwrmsg.exe]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2008-01-29 14:33 139264]
"CHotkey"="zHotkey.exe" [2004-12-08 19:57 550912 C:\WINDOWS\zHotkey.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-09 07:14 15473664 C:\WINDOWS\RTHDCPL.exe]
"HostManager"="C:\Program Files\Common Files\AOL\1157372527\EE\AOLHostManager.exe" [2008-01-22 14:30 125528]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2008-02-08 15:04 79448]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-30 09:02 7311360]
"nwiz"="nwiz.exe" [2005-11-30 09:02 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-11-30 09:02 86016]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2008-02-08 15:04 151552]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2008-01-31 14:43 53248]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2008-02-08 15:04 303104]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [ ]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MS849B~1.EXE" [ ]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2008-02-07 20:45 1121280]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2008-02-08 15:04 163840]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2008-02-08 15:04 1005096]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2008-02-07 16:19 406016]
"EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-02-08 15:04 98304]
"Auto EPSON Stylus CX3800 Series on ACER-56FB35423D"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-02-08 15:04 98304]
"\\ACER-56FB35423D\EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-02-08 15:04 98304]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2008-02-07 16:19 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-08 15:04 257088]
"EPSON Stylus CX3800 Series (Copy 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-02-08 15:04 98304]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2008-02-08 15:04 479232]
"win32"="win32.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"win32"="win32.exe" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 20:17 443968]

C:\Documents and Settings\Rinita\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2006-09-04 07:20:23 2168360]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R3 BENDER;Pinnacle DV/AV Capture;C:\windows\system32\drivers\bender.sys [2006-11-21 13:34]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-06 21:40:01 C:\windows\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-06 12:29:01 C:\windows\Tasks\Uniblue SpyEraser Nag.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2007-11-04 13:53:11 C:\windows\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************

disk not found C:\

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

disk not found C:\

**************************************************************************

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"\\\\ACER-56FB35423D\\EPSON Stylus CX3800 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIACA.EXE /P44 \"\\\\ACER-56FB35423D\\EPSON Stylus CX3800 Series\" /O6 \"USB001\" /M \"Stylus CX3800\""
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\windows\system32\RUNDLL32.EXE
C:\PROGRA~1\COMMON~1\AOL\115737~1\EE\AOLHOS~1.EXE
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\COMMON~1\AOL\115737~1\EE\AOLServiceHost.exe
C:\WINDOWS\eHome\ehmsas.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
.
**************************************************************************
.
Completion time: 2008-02-09 17:41:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-09 22:40:58
ComboFix2.txt 2008-02-08 22:17:35
ComboFix3.txt 2008-02-08 20:55:51
.
2008-01-08 22:46:15 --- E O F ---
  • 0

#18
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Nearly done now

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"win32"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"win32"=-


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall




Also post a new HijackThis log
  • 0

#19
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
ComboFix 08-02.05.3 - Rinita 2008-02-09 20:51:34.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.488 [GMT -5:00]
Running from: C:\Documents and Settings\Rinita\My Documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\Rinita\My Documents\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-10 to 2008-02-10 )))))))))))))))))))))))))))))))
.

2008-02-09 17:35 . 2004-08-10 14:00 388,608 --a------ C:\kmd.exe
2008-02-08 17:13 . 2008-02-08 17:13 279 --a------ C:\Shortcut to Local Disk ©.lnk
2008-02-08 15:10 . 2008-02-08 15:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-07 20:15 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\RkPavProc.sys
2008-02-07 20:06 . 2008-02-07 20:06 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-07 20:06 . 2008-02-07 20:06 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-02-07 16:21 . 2008-02-07 20:41 <DIR> d-------- C:\VundoFix Backups
2008-02-07 15:59 . 2008-02-07 15:59 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-07 15:59 . 2008-02-07 15:59 <DIR> d-------- C:\Documents and Settings\Rinita\Application Data\SUPERAntiSpyware.com
2008-02-07 14:39 . 2008-02-07 20:11 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-07 14:39 . 2008-02-07 14:39 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-07 14:31 . 2008-02-09 16:45 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-28 20:00 . 2008-01-28 20:04 81 --a------ C:\WINDOWS\QTW.INI
2008-01-19 17:38 . 2008-02-07 16:19 406,016 --a------ C:\WINDOWS\system32\PSDrvCheck.exe
2008-01-19 17:38 . 2008-02-07 16:19 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-01-19 17:37 . 2008-01-27 11:14 64,512 --a--c--- C:\WINDOWS\system32\dllcache\ehtray.exe
2008-01-17 18:31 . 2008-01-17 18:31 0 --a------ C:\WINDOWS\OpPrintServer.INI
2008-01-17 18:26 . 2008-01-17 18:26 <DIR> d-------- C:\WINDOWS\StartHtmico
2008-01-17 18:26 . 2008-01-17 18:26 <DIR> d-------- C:\WINDOWS\IP4000,3000
2008-01-17 18:26 . 2004-04-23 00:00 116,736 --a------ C:\WINDOWS\system32\CNMLM64.DLL
2008-01-17 18:26 . 2004-03-11 11:06 86,016 -ra------ C:\WINDOWS\system32\CNMCP64.exe
2008-01-17 18:26 . 2004-04-23 00:00 7,680 --a------ C:\WINDOWS\system32\CNMVS64.DLL
2008-01-17 16:02 . 2008-01-17 16:19 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-14 13:14 . 2005-11-21 00:48 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2008-01-14 13:14 . 2005-11-21 00:48 16,512 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-01-14 13:13 . 2008-01-14 13:17 <DIR> d-------- C:\Program Files\BitZipper
2008-01-14 13:13 . 2008-01-14 13:13 <DIR> d-------- C:\Documents and Settings\Rinita\Application Data\BitZipper
2008-01-14 12:45 . 2008-01-04 16:58 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-01-14 12:45 . 2008-01-04 16:58 120,056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-01-14 12:45 . 2008-01-04 16:58 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2008-01-13 09:30 . 2008-01-13 09:30 <DIR> d-------- C:\Documents and Settings\Rinita\Application Data\Viewpoint

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 22:36 --------- d-----w C:\Program Files\QuickTime
2008-02-09 01:22 --------- d-----w C:\Program Files\iTunes
2008-02-09 01:22 --------- d-----w C:\Program Files\Digital Media Reader
2008-02-08 01:16 --------- d-----w C:\Program Files\Google
2008-02-07 20:14 --------- d-----w C:\Documents and Settings\Rinita\Application Data\Azureus
2008-01-17 23:32 --------- d-----w C:\Program Files\Canon
2008-01-14 18:05 --------- d-----w C:\Documents and Settings\Rinita\Application Data\LimeWire
2008-01-14 00:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-04 21:58 43,528 ------w C:\windows\system32\drivers\pxhelp20.sys
2008-01-04 21:56 156,992 ----a-w C:\windows\system32\DivXCodecVersionChecker.exe
2007-12-31 16:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-29 16:37 --------- d-----w C:\Program Files\Quicken
2007-12-29 16:37 --------- d-----w C:\Program Files\Microsoft Works
2007-12-28 16:47 --------- d-----w C:\Program Files\Microsoft.NET
2007-12-25 23:54 --------- d-----w C:\Program Files\InterActual
2007-12-25 15:54 --------- d-----w C:\Documents and Settings\Rinita\Application Data\CyberLink
2007-12-19 00:09 --------- d-----w C:\Program Files\LiveMath
2007-12-10 22:34 --------- d-----w C:\Documents and Settings\Rinita\Application Data\U3
2007-11-16 02:56 46 ----a-w C:\Documents and Settings\Rinita\Application Data\wklnhst.dat
2007-10-24 18:58 299,288 ----a-w C:\Program Files\GmailInstaller.exe
2007-10-02 18:59 1,164,456 ----a-w C:\Program Files\install_flash_player.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-19 17:38 1694208]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-22 14:30 68856]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [ ]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2004-08-10 14:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-08 15:04 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2008-01-27 11:14 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 18:19 77312 C:\WINDOWS\arpwrmsg.exe]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2008-01-29 14:33 139264]
"CHotkey"="zHotkey.exe" [2004-12-08 19:57 550912 C:\WINDOWS\zHotkey.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-09 07:14 15473664 C:\WINDOWS\RTHDCPL.exe]
"HostManager"="C:\Program Files\Common Files\AOL\1157372527\EE\AOLHostManager.exe" [2008-01-22 14:30 125528]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2008-02-08 15:04 79448]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-30 09:02 7311360]
"nwiz"="nwiz.exe" [2005-11-30 09:02 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-11-30 09:02 86016]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2008-02-08 15:04 151552]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2008-01-31 14:43 53248]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2008-02-08 15:04 303104]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [ ]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MS849B~1.EXE" [ ]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2008-02-07 20:45 1121280]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2008-02-08 15:04 163840]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2008-02-08 15:04 1005096]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2008-02-07 16:19 406016]
"EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-02-08 15:04 98304]
"Auto EPSON Stylus CX3800 Series on ACER-56FB35423D"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-02-08 15:04 98304]
"\\ACER-56FB35423D\EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-02-08 15:04 98304]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2008-02-07 16:19 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-08 15:04 257088]
"EPSON Stylus CX3800 Series (Copy 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2008-02-08 15:04 98304]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2008-02-08 15:04 479232]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 20:17 443968]

C:\Documents and Settings\Rinita\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2006-09-04 07:20:23 2168360]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R3 BENDER;Pinnacle DV/AV Capture;C:\windows\system32\drivers\bender.sys [2006-11-21 13:34]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-06 21:40:01 C:\windows\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-06 12:29:01 C:\windows\Tasks\Uniblue SpyEraser Nag.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2007-11-04 13:53:11 C:\windows\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************

disk not found C:\

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

disk not found C:\

**************************************************************************

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"\\\\ACER-56FB35423D\\EPSON Stylus CX3800 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIACA.EXE /P44 \"\\\\ACER-56FB35423D\\EPSON Stylus CX3800 Series\" /O6 \"USB001\" /M \"Stylus CX3800\""
.
Completion time: 2008-02-09 20:54:36
ComboFix-quarantined-files.txt 2008-02-10 01:53:43
ComboFix2.txt 2008-02-09 22:41:50
ComboFix3.txt 2008-02-08 22:17:35
ComboFix4.txt 2008-02-08 20:55:51
.
2008-01-08 22:46:15 --- E O F ---
  • 0

#20
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:58:53 PM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\windows\system32\svchost.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\windows\ARPWRMSG.EXE
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\windows\zHotkey.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\windows\RTHDCPL.EXE
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\windows\system32\RUNDLL32.EXE
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\COMMON~1\AOL\115737~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\115737~1\EE\AOLServiceHost.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\BigFix\bigfix.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\windows\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.c...h...DTP&M=T6540
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.c...h...DTP&M=T6540
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.c...h...DTP&M=T6540
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1157372527\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MS849B~1.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O5 "LPT1:" /M "Stylus CX3800"
O4 - HKLM\..\Run: [Auto EPSON Stylus CX3800 Series on ACER-56FB35423D] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P50 "Auto EPSON Stylus CX3800 Series on ACER-56FB35423D" /O31 "\\ACER-56FB35423D\RinitaPrinter" /M "Stylus CX3800"
O4 - HKLM\..\Run: [\\ACER-56FB35423D\EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P44 "\\ACER-56FB35423D\EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P35 "EPSON Stylus CX3800 Series (Copy 1)" /O6 "USB001" /M "Stylus CX3800"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.goo...7/uploader2.cab
O16 - DPF: {483912CF-8995-4434-AD61-6163756E05DF} (AXTNS Control) - http://download.live...tivex/AXTNS.ocx
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--
End of file - 9706 bytes
  • 0

#21
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.


Also tell me how your PC is running
  • 0

#22
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
my computer seems to be running fine

no pop-ups anymore

although my firefox keeps freezing every time i try to paste this scan

that may be because of the size, but i'm not sure

i'll post the scan in the next reply just to get this message across.
  • 0

#23
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
so i tried to paste the scan into word, and it comes out to 2105 pages

should i attach the text file to my reply?
  • 0

#24
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Yes try attach it, if that fails don't worry

Also let me know how your PC is running
  • 0

#25
cocacola23

cocacola23

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
i think my browser froze simply because of the size of the text

so everything is as fast as it should be

so i kept trying to upload the file, but it said that i never attached one

thank you very much!
  • 0

Advertisements


#26
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
No need to worry, your logs are clean ! We need to do a few things

Now lets uninstall Combofix:
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
The above procedure will do the following:
  • Delete ComboFix and its associated files and folders.
  • Delete VundoFix backups, if present
  • Delete the C:\Deckard folder, if present
  • Delete the C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.



Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
SpywareBlaster protects against bad ActiveX
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here

* SpywareGuard offers realtime protection from spyware installation attempts.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

Thank you for your patience, and performing all of the procedures requested.
  • 0

#27
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP