Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Spyware ads, Task manager blocked, slow, popups, etc. [RESOLVED]


  • This topic is locked This topic is locked

#16
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
===========================================
Please do an online scan with Kaspersky WebScanner
(This scanner is for use with internet explorer only)
Click on "Accept"

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as an html document button:
  • Save the file to your desktop.
  • Attach that information in your next post.

  • 0

Advertisements


#17
vegimo

vegimo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
KASPERSKY ONLINE SCANNER REPORT
Wednesday, April 09, 2008 5:31:16 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 9/04/2008
Kaspersky Anti-Virus database records: 692913


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\

Scan Statistics
Total number of scanned objects 50121
Number of viruses found 24
Number of infected objects 328
Number of suspicious objects 0
Duration of the scan process 01:17:13

Infected Object Name Virus Name Last Action
C:\Deckard\System Scanner\backup\DOCUME~1\MARKEV~1\LOCALS~1\Temp\wavvsnet.exe Infected: Trojan-Downloader.Win32.Small.gwf skipped

C:\Deckard\System Scanner\backup\DOCUME~1\MARKEV~1\LOCALS~1\Temp\xrun.exe Infected: Trojan-Downloader.Win32.Agent.brq skipped

C:\Deckard\System Scanner\backup\WINDOWS\Downloaded Program Files\webinst.dll Infected: not-virus:Hoax.Win32.Renos.asm skipped

C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Output\meverett\~Running.ping Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\mark everett\Application Data\Sun\Java\Deployment\cache\6.0\32\50c2ce60-23ef5de7/BnnnnBaa.class Infected: Trojan.Java.ClassLoader.as skipped

C:\Documents and Settings\mark everett\Application Data\Sun\Java\Deployment\cache\6.0\32\50c2ce60-23ef5de7/VaannnaaBaa.class Infected: Trojan.Java.ClassLoader.as skipped

C:\Documents and Settings\mark everett\Application Data\Sun\Java\Deployment\cache\6.0\32\50c2ce60-23ef5de7/Bnnnnn.class Infected: Trojan.Java.ClassLoader.as skipped

C:\Documents and Settings\mark everett\Application Data\Sun\Java\Deployment\cache\6.0\32\50c2ce60-23ef5de7 ZIP: infected - 3 skipped

C:\Documents and Settings\mark everett\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\mark everett\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\mark everett\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\mark everett\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\mark everett\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\mark everett\My Documents\FabGuard Support Installs\VNC\vnc-4.0-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

C:\Documents and Settings\mark everett\My Documents\FabGuard Support Installs\VNC\vnc-4.0-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

C:\Documents and Settings\mark everett\My Documents\FabGuard Support Installs\VNC\vnc-4.0-x86_win32.exe/data0006 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

C:\Documents and Settings\mark everett\My Documents\FabGuard Support Installs\VNC\vnc-4.0-x86_win32.exe Inno: infected - 3 skipped

C:\Documents and Settings\mark everett\My Documents\FabGuard Support Installs\VNC\vnc-4.0-x86_win32_viewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

C:\Documents and Settings\mark everett\My Documents\Support Files for FabGuard\VNC\vnc-3.3.3r9_x86_win32.zip/vnc_x86_win32/vncviewer/vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped

C:\Documents and Settings\mark everett\My Documents\Support Files for FabGuard\VNC\vnc-3.3.3r9_x86_win32.zip ZIP: infected - 1 skipped

C:\Documents and Settings\mark everett\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\mark everett\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Lightspeed Systems\SecurityAgent\tmp\Actions.txt Object is locked skipped

C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

C:\QooBox\Quarantine\C\Program Files\Bat\Info.dll.vir Infected: not-a-virus:AdWare.Win32.Rabio.m skipped

C:\QooBox\Quarantine\C\WINDOWS\default.htm.vir Infected: not-virus:Hoax.HTML.Secureinvites.b skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\apfakggp.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\apkdpwqe.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\avpjamft.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\axesrxbm.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\bcnafxfj.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\bqkxkhig.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\bscjthdj.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\bytpdfnn.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\celwfkgx.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\cetnfmsn.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\cftqscfp.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\cfxjlniw.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\clifsucm.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jxa skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\dbrdhykj.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\dhwrsluc.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\dirkccxk.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\djelulrb.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\dpksukxm.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\eearvsgq.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\eewtdmuh.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ejjlaiik.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ejtxsise.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\euatjeiu.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\euiklssi.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\expwgths.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\fcllxhqd.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\fcxlxbee.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\fiwtjbjj.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\fkdllnhv.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\fobanyrp.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\fuqjiuaa.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\fvqfwcyf.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\fxxodspc.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\fygvbntr.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\fytwydwd.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\gjcysikv.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\gpygfeyo.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\gsemkiwp.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\gtaactpt.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\gteexowo.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\gwhfgyvu.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\gwpxgpfd.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\hevnyotx.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\hgotdcua.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\hjorgkpg.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\hlcqnfmh.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.mvn skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\hpcyjdaf.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\hqqgjjsn.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\hwufpbye.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.kp skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ibnlnoxf.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\imqrbrfn.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\iqpbuprf.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\jhlcbscx.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\jirdxjxi.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\jpdvavax.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\jvqewfeh.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\kmvobopu.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ldvvnehm.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ljgcuvtk.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ltqbcsrg.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\luildlah.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\lxqmtcao.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\mhvxrdou.dll.vir Infected: Backdoor.Win32.Agent.dlj skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\mirxhlru.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\mypqyfwn.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\nagklfrx.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\nbqorqxp.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\nfyynelw.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\nknxeyxp.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\nmyrfoyu.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\nqclhtgh.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\nsagpass.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\nsggppwx.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\nxxjieig.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\obwjnosj.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\oibjlhpy.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\osfcvmlo.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\otrhigrn.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\otsfdspn.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\oxbbmkmv.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\pbkmhutj.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\pbmqcxvb.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\plvtxnsk.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\pwvpjepl.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\qvnaffee.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\rbjohatu.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\rgbsafqr.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\rlavvcrp.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\rlaxlpsv.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\rokhnrfa.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\rroggpkq.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\sgcbmwkh.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\shailahf.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\smxvrxno.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\tfwakdfc.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\tgpysyyy.dll.vir Infected: Trojan.Win32.BHO.zo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\thjrhqoy.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\thmvbsth.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\tjytjmye.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gip skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\tkoskknk.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\tnulikpv.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\tvhnadjp.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\uafeaeoh.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ubnlnehg.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\uckchqbq.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\uroeukpo.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\utvethdl.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\vaqyqqkq.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\vnvvymub.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\vphpexew.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\vyiwsjci.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\wbvmaemt.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\wdduboqp.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\wftfugym.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\wgellrna.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\wgxggumi.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.msm skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\wimkuskk.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\wljllqre.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\wonbyhaf.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\wtsumkgq.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\wvahmrrg.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\xajuhhec.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\xidsmnsm.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\xsmwkdvn.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ybukhsnm.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.mwq skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\yftsvaec.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\yjdxjxgd.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\yrvxqfen.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\yvtuuqhy.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\yxcjjyew.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\yxrnxmxh.dll.vir Infected: Packed.Win32.Monder.gen skipped

C:\QooBox\Quarantine\catchme2008-04-08_132743.65.zip/Documents and Settings/mark everett/Desktop/catchme.zip/khfDwttQ.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mxi skipped

C:\QooBox\Quarantine\catchme2008-04-08_132743.65.zip/Documents and Settings/mark everett/Desktop/catchme.zip Infected: not-a-virus:AdWare.Win32.Virtumonde.mxi skipped

C:\QooBox\Quarantine\catchme2008-04-08_132743.65.zip ZIP: infected - 2 skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP454\A0034765.exe Infected: Trojan-Downloader.Win32.VB.ccs skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP454\A0034766.exe Infected: Trojan-Downloader.Win32.Small.eqn skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP454\A0034767.exe Infected: Trojan-Downloader.Win32.VB.cho skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP454\A0035786.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mhf skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035853.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035854.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035855.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035856.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035857.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035858.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035859.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035860.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035861.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035862.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jxa skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035863.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035864.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035865.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035866.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035867.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035868.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035869.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035870.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035871.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035872.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035873.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035874.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035875.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035876.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035877.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035878.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035879.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035880.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035881.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035882.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035883.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035884.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035885.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035886.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035887.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035888.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mvn skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035889.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035890.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035891.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.kp skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035892.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035893.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035894.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035895.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035896.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035897.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035898.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035899.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035900.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035901.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035902.dll Infected: Backdoor.Win32.Agent.dlj skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035903.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035904.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035905.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035906.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035907.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035908.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035909.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035910.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035911.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035912.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035913.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035914.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035915.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035916.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035917.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035918.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035919.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035920.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035921.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035922.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035923.dll Infected: Trojan.Win32.BHO.zo skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035924.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035925.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035926.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gip skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035927.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035928.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035929.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035930.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035931.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035932.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035933.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035934.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035935.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035936.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035937.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035938.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035939.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035940.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035941.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035942.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.msm skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035943.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035944.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035945.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035946.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035947.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035948.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035949.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035950.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035951.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mwq skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035952.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP456\A0035953.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP458\A0036154.dll Infected: not-a-virus:AdWare.Win32.Rabio.m skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036441.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036442.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036443.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036444.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036445.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036446.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036447.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036448.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036449.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036450.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036451.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036452.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036453.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036454.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036455.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036456.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036457.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036458.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036459.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036460.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036461.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036462.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036463.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036464.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036465.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036466.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036467.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036468.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036469.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP461\A0036470.dll Infected: Packed.Win32.Monder.gen skipped

C:\System Volume Information\_restore{BF3FE299-69A3-4A2F-AFD6-76A865DC0766}\RP462\change.log Object is locked skipped

C:\WINDOWS\CSC\00000001 Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{31559F6B-2A45-4452-8E29-56AC21EC3FDB}.bin Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\aufoxjal.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\axyucxcb.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\bxyvslxl.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\ciexxwrm.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\cwgwakov.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\eaotspru.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\elxoiyel.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\esljwogr.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\glhkjmrr.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\gmdymrlj.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\gsybdfgo.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.is skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\hmsfiawo.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\homfbxcc.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\huvpvufe.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\ipaovedd.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\irtfqowk.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\iufiodgp.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\iykpyory.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\jyobdywe.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\kbglmppo.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\kruuuxrs.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\lkdiokwr.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\mvbmhqiw.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\nhiwgnmp.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\ognfhjwe.dll Infected: Trojan.Win32.BHO.abs skipped

C:\WINDOWS\system32\oojojrud.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\psxglxnl.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\qbjydmul.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\rnjqjanr.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\ryydgcbx.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\ulyftckp.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\uncysxbw.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\vbwchpvf.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\vbyokjmq.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\system32\xhofkdya.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\xishfkuc.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\xkuuqnmr.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\yejkwvew.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\system32\ysixuqlf.dll Infected: Packed.Win32.Monder.gen skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
  • 0

#18
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:


http://www.geekstogo.com/forum/Spyware-ads-Task-manager-blocked-slow-popups-etc-t194132.html

Collect::
C:\WINDOWS\system32\cwgwakov.dll 
C:\WINDOWS\system32\eaotspru.dll 
C:\WINDOWS\system32\elxoiyel.dll  
C:\WINDOWS\system32\esljwogr.dll 
C:\WINDOWS\system32\glhkjmrr.dll  
C:\WINDOWS\system32\gmdymrlj.dll 
C:\WINDOWS\system32\gsybdfgo.dll 
C:\WINDOWS\system32\hmsfiawo.dll  
C:\WINDOWS\system32\homfbxcc.dll  
C:\WINDOWS\system32\huvpvufe.dll  
C:\WINDOWS\system32\ipaovedd.dll  
C:\WINDOWS\system32\irtfqowk.dll  
C:\WINDOWS\system32\iufiodgp.dll  
C:\WINDOWS\system32\iykpyory.dll  
C:\WINDOWS\system32\jyobdywe.dll  
C:\WINDOWS\system32\kbglmppo.dll  
C:\WINDOWS\system32\kruuuxrs.dll
C:\WINDOWS\system32\lkdiokwr.dll 
C:\WINDOWS\system32\mvbmhqiw.dll
C:\WINDOWS\system32\nhiwgnmp.dll  
C:\WINDOWS\system32\ognfhjwe.dll 
C:\WINDOWS\system32\oojojrud.dll 
C:\WINDOWS\system32\psxglxnl.dll 
C:\WINDOWS\system32\qbjydmul.dll 
C:\WINDOWS\system32\rnjqjanr.dll 
C:\WINDOWS\system32\ryydgcbx.dll  
C:\WINDOWS\system32\ulyftckp.dll 
C:\WINDOWS\system32\uncysxbw.dll 
C:\WINDOWS\system32\vbwchpvf.dll
C:\WINDOWS\system32\vbyokjmq.dll 
C:\WINDOWS\system32\bxyvslxl.dll 
C:\WINDOWS\system32\axyucxcb.dll 
C:\WINDOWS\system32\aufoxjal.dll 
C:\WINDOWS\system32\xhofkdya.dll 
C:\WINDOWS\system32\xishfkuc.dll 
C:\WINDOWS\system32\xkuuqnmr.dll 
C:\WINDOWS\system32\yejkwvew.dll 
C:\WINDOWS\system32\ysixuqlf.dll
3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. Additonally, ComboFix will generate the following files on your desktop
  • A zipped file on your desktop called Submit [Date Time].zip
  • And another file named - CF-Submit.htm
6. ComboFix may need to reboot to finish its work. Let it.

7. When CF has finished running, it will generate the ComboFix.log which will appear on your screen.

8. If CF-Submit.htm is detected, ComboFix will generate this message box:

Posted Image

Clicking OK will cause the machine's browser to load CF-Submit.htm

Posted Image

9. Click the "Browse" button and locate the Submit [Date Time].zip file on your desktop.
  • Click on the file to Select it.
  • Submit the file by clicking "OK"
10. Once the file has been submitted, please DELETE both files on your desktop.

11. Post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log (run after ComboFix has finished its work.)

  • 0

#19
vegimo

vegimo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
I submittet the .zip file successfully

here are the new logs:

ComboFix 08-04-08.4 - meverett 2008-04-09 21:34:02.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.668 [GMT -5:00]
Running from: C:\Documents and Settings\mark everett\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\mark everett\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\aufoxjal.dll
C:\WINDOWS\system32\axyucxcb.dll
C:\WINDOWS\system32\bxyvslxl.dll
C:\WINDOWS\system32\cwgwakov.dll
C:\WINDOWS\system32\eaotspru.dll
C:\WINDOWS\system32\elxoiyel.dll
C:\WINDOWS\system32\esljwogr.dll
C:\WINDOWS\system32\glhkjmrr.dll
C:\WINDOWS\system32\gmdymrlj.dll
C:\WINDOWS\system32\gsybdfgo.dll
C:\WINDOWS\system32\hmsfiawo.dll
C:\WINDOWS\system32\homfbxcc.dll
C:\WINDOWS\system32\huvpvufe.dll
C:\WINDOWS\system32\ipaovedd.dll
C:\WINDOWS\system32\irtfqowk.dll
C:\WINDOWS\system32\iufiodgp.dll
C:\WINDOWS\system32\iykpyory.dll
C:\WINDOWS\system32\jyobdywe.dll
C:\WINDOWS\system32\kbglmppo.dll
C:\WINDOWS\system32\kruuuxrs.dll
C:\WINDOWS\system32\lkdiokwr.dll
C:\WINDOWS\system32\mvbmhqiw.dll
C:\WINDOWS\system32\nhiwgnmp.dll
C:\WINDOWS\system32\ognfhjwe.dll
C:\WINDOWS\system32\oojojrud.dll
C:\WINDOWS\system32\psxglxnl.dll
C:\WINDOWS\system32\qbjydmul.dll
C:\WINDOWS\system32\rnjqjanr.dll
C:\WINDOWS\system32\ryydgcbx.dll
C:\WINDOWS\system32\ulyftckp.dll
C:\WINDOWS\system32\uncysxbw.dll
C:\WINDOWS\system32\vbwchpvf.dll
C:\WINDOWS\system32\vbyokjmq.dll
C:\WINDOWS\system32\xhofkdya.dll
C:\WINDOWS\system32\xishfkuc.dll
C:\WINDOWS\system32\xkuuqnmr.dll
C:\WINDOWS\system32\yejkwvew.dll
C:\WINDOWS\system32\ysixuqlf.dll

.
((((((((((((((((((((((((( Files Created from 2008-03-10 to 2008-04-10 )))))))))))))))))))))))))))))))
.

2008-04-09 15:40 . 2008-04-09 15:40 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-09 15:40 . 2008-04-09 15:40 <DIR> d-------- C:\WINDOWS\LastGood
2008-04-09 15:40 . 2008-04-09 15:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-09 12:15 . 2008-04-09 12:15 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-09 12:15 . 2008-04-09 12:15 <DIR> d-------- C:\Documents and Settings\mark everett\Application Data\Malwarebytes
2008-04-09 12:15 . 2008-04-09 12:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-08 12:44 . 2008-04-08 12:44 <DIR> d-------- C:\Deckard
2008-04-08 08:48 . 2008-04-08 08:48 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-08 08:34 . 2008-04-08 08:35 <DIR> d-------- C:\Program Files\Panda Security
2008-03-18 11:46 . 2008-03-18 11:46 0 --a------ C:\WINDOWS\FabGuardExecutive.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-10 00:20 --------- d-----w C:\Program Files\PokerStars.NET
2008-04-09 18:09 8,706,256 ----a-w C:\WINDOWS\system32\drivers\FileIntegrity
2008-04-08 13:31 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-03-24 15:06 8,704,774 ----a-w C:\WINDOWS\system32\drivers\FileIntegrity.bak3
2008-03-24 15:06 23,040 ----a-w C:\WINDOWS\system32\drivers\IpmSecurityAgent1.sys
2008-03-24 15:06 113,152 ----a-w C:\WINDOWS\system32\drivers\IpmSecurityAgent2.sys
2008-03-20 14:09 8,704,280 ----a-w C:\WINDOWS\system32\drivers\FileIntegrity.bak2
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-18 16:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 08:59 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-14 14:39 --------- d-----w C:\Program Files\UBNet
2008-02-13 19:14 23,200 ----a-w C:\WINDOWS\system32\drivers\FileID.idx
2008-02-13 19:14 14,070,906 ----a-w C:\WINDOWS\system32\drivers\FileID.dat
2008-02-13 19:14 1,825,471 ----a-w C:\WINDOWS\system32\drivers\FileID.def
2008-02-13 19:13 37,388,889 ----a-w C:\WINDOWS\system32\drivers\VirusSignatures
2008-02-13 19:12 8,701,658 ----a-w C:\WINDOWS\system32\drivers\FileIntegrity.bak1
1998-12-09 02:53 99,840 ----a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-09 02:53 70,144 ----a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-09 02:53 48,640 ----a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-09 02:53 31,744 ----a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-09 02:53 186,368 ----a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-09 02:53 17,920 ----a-w C:\Program Files\Common Files\IRASRIAL.DLL
.

((((((((((((((((((((((((((((( snapshot@2008-04-08_13.31.11.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-20 21:04:32 1,523,536 ----a-w C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
- 2007-12-07 01:07:12 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll
+ 2008-02-16 08:59:34 1,023,488 ----a-w C:\WINDOWS\system32\browseui.dll
- 2007-12-07 01:07:12 151,040 ----a-w C:\WINDOWS\system32\cdfview.dll
+ 2008-02-16 08:59:35 151,040 ----a-w C:\WINDOWS\system32\cdfview.dll
- 2007-12-07 01:07:12 1,054,208 ----a-w C:\WINDOWS\system32\danim.dll
+ 2008-02-16 08:59:35 1,054,208 ----a-w C:\WINDOWS\system32\danim.dll
- 2007-12-07 01:07:12 1,023,488 -c--a-w C:\WINDOWS\system32\dllcache\browseui.dll
+ 2008-02-16 08:59:34 1,023,488 -c--a-w C:\WINDOWS\system32\dllcache\browseui.dll
- 2007-12-07 01:07:12 151,040 -c--a-w C:\WINDOWS\system32\dllcache\cdfview.dll
+ 2008-02-16 08:59:35 151,040 -c--a-w C:\WINDOWS\system32\dllcache\cdfview.dll
- 2007-12-07 01:07:12 1,054,208 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
+ 2008-02-16 08:59:35 1,054,208 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
- 2006-06-26 17:37:10 148,480 -c--a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
+ 2008-02-20 05:32:43 148,992 -c--a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
- 2004-08-04 10:00:00 45,568 -c--a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
+ 2008-02-20 05:32:43 45,568 -c--a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
- 2007-12-07 01:07:12 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-02-16 08:59:35 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2007-12-07 01:07:12 205,312 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-02-16 08:59:35 205,312 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2007-12-07 01:07:12 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-02-16 08:59:35 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2007-06-19 13:31:19 282,112 -c--a-w C:\WINDOWS\system32\dllcache\gdi32.dll
+ 2008-02-20 06:51:05 282,624 -c--a-w C:\WINDOWS\system32\dllcache\gdi32.dll
- 2007-12-06 13:07:07 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
+ 2008-02-15 09:23:37 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
- 2007-12-07 01:07:12 251,392 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
+ 2008-02-16 08:59:35 251,392 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
- 2007-12-07 01:07:12 96,256 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
+ 2008-02-16 08:59:35 96,256 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
- 2007-11-14 07:26:56 450,560 -c--a-w C:\WINDOWS\system32\dllcache\jscript.dll
+ 2007-12-18 14:40:58 450,560 -c--a-w C:\WINDOWS\system32\dllcache\jscript.dll
- 2007-12-07 01:07:12 16,384 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-02-16 08:59:35 16,384 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
- 2007-12-07 14:37:14 3,059,200 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-02-16 22:29:38 3,059,712 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2007-12-07 01:07:13 449,024 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-02-16 08:59:37 449,024 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2007-12-07 01:07:13 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-02-16 08:59:37 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2007-12-07 01:07:13 532,480 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-02-16 08:59:37 532,480 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2007-12-07 01:07:13 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-02-16 08:59:37 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2007-12-07 01:07:13 1,494,528 -c--a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
+ 2008-02-16 08:59:38 1,494,528 -c--a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
- 2007-12-07 01:07:13 474,112 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
+ 2008-02-16 08:59:38 474,112 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
- 2007-12-07 01:07:14 615,424 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-02-16 08:59:38 615,936 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2004-08-04 10:00:00 417,792 -c--a-w C:\WINDOWS\system32\dllcache\vbscript.dll
+ 2007-12-18 14:40:58 417,792 -c--a-w C:\WINDOWS\system32\dllcache\vbscript.dll
- 2007-03-08 13:47:48 1,843,584 -c--a-w C:\WINDOWS\system32\dllcache\win32k.sys
+ 2008-03-19 09:47:00 1,845,248 -c--a-w C:\WINDOWS\system32\dllcache\win32k.sys
- 2007-12-07 01:07:14 659,456 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-02-16 08:59:39 659,456 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
- 2006-06-26 17:37:10 148,480 ----a-w C:\WINDOWS\system32\dnsapi.dll
+ 2008-02-20 05:32:43 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll
- 2007-12-07 01:07:12 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-02-16 08:59:35 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2007-12-07 01:07:12 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-02-16 08:59:35 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2007-12-07 01:07:12 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2008-02-16 08:59:35 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
- 2007-04-04 20:58:15 136,464 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-04-09 18:15:50 136,464 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2007-12-07 01:07:12 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll
+ 2008-02-16 08:59:35 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll
- 2007-12-07 01:07:12 96,256 ----a-w C:\WINDOWS\system32\inseng.dll
+ 2008-02-16 08:59:35 96,256 ----a-w C:\WINDOWS\system32\inseng.dll
- 2007-11-14 07:26:56 450,560 ----a-w C:\WINDOWS\system32\jscript.dll
+ 2007-12-18 14:40:58 450,560 ----a-w C:\WINDOWS\system32\jscript.dll
- 2007-12-07 01:07:12 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2008-02-16 08:59:35 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2005-05-24 17:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-04-06 21:39:48 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-04-08 20:40:32 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
- 2008-03-05 16:30:54 19,148,408 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-04-06 05:56:20 19,836,024 ----a-w C:\WINDOWS\system32\MRT.exe
- 2007-12-07 14:37:14 3,059,200 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-02-16 22:29:38 3,059,712 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2007-12-07 01:07:13 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-02-16 08:59:37 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2007-12-07 01:07:13 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2008-02-16 08:59:37 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
- 2007-12-07 01:07:13 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2008-02-16 08:59:37 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
- 2007-12-07 01:07:13 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-02-16 08:59:37 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2007-12-07 01:07:13 1,494,528 ----a-w C:\WINDOWS\system32\shdocvw.dll
+ 2008-02-16 08:59:38 1,494,528 ----a-w C:\WINDOWS\system32\shdocvw.dll
- 2007-12-07 01:07:13 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
+ 2008-02-16 08:59:38 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
- 2007-12-07 01:07:14 615,424 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-02-16 08:59:38 615,936 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2004-08-04 10:00:00 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll
+ 2007-12-18 14:40:58 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll
- 2007-12-06 09:38:31 350,720 ----a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2008-02-15 09:06:21 351,744 ----a-w C:\WINDOWS\system32\xpsp3res.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 21:10 339968]
"PRONoMgr.exe"="c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2003-12-19 12:49 86016]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-13 01:05 122939]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 01:01 110592]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-14 00:37 282624]
"eFax 4.3"="C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" [2007-03-06 12:21 116224]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 12:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
c:\WINDOWS\system32\LgNotify.dll 2004-01-13 15:17 110592 c:\WINDOWS\system32\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\National Instruments\\MAX\\NIMax.exe"=
"C:\\Inficon\\FabGuardExecutive.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:VNC
"1305:TCP"= 1305:TCP:Lightspeed Security Agent (TCP)
"1305:UDP"= 1305:UDP:Lightspeed Security Agent (UDP)

R0 NIPALK;NIPALK;C:\WINDOWS\system32\drivers\NIPALK.sys [2002-01-07 21:01]
R1 IpmSecurityAgent1;Security Agent Filter Driver;C:\WINDOWS\system32\drivers\IpmSecurityAgent1.sys [2008-03-24 10:06]
R1 IpmSecurityAgent2;Security Agent Driver;C:\WINDOWS\system32\drivers\IpmSecurityAgent2.sys [2008-03-24 10:06]
R2 IpmSecurityAgentService;Security Agent Service;C:\Program Files\Lightspeed Systems\SecurityAgent\SecurityAgent.exe [2008-03-11 16:34]
R2 niarbk;niarbk;C:\WINDOWS\system32\drivers\niarbk.dll [2002-01-28 13:59]
R2 nibffrk;nibffrk;C:\WINDOWS\system32\drivers\nibffrk.dll [2002-01-28 13:59]
R2 Nidaq32k;Nidaq32k;C:\WINDOWS\system32\drivers\Nidaq32k.sys [2002-01-28 15:40]
R2 nidmmk;NI DMM and Data Logger Kernel Driver;C:\WINDOWS\system32\drivers\nidmmk.dll [2002-01-28 15:41]
R2 nimdsk;nimdsk;C:\WINDOWS\system32\drivers\nimdsk.dll [2002-01-28 14:02]
R2 nistck;nistck;C:\WINDOWS\system32\drivers\nistck.dll [2002-01-28 14:04]
R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2005-04-21 20:58]

*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-09 21:35:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-04-09 21:37:03
ComboFix-quarantined-files.txt 2008-04-10 02:36:42
ComboFix2.txt 2008-04-09 16:31:56
ComboFix3.txt 2008-04-09 12:27:17
ComboFix4.txt 2008-04-09 02:58:23
ComboFix5.txt 2008-04-08 18:31:47
Pre-Run: 46,064,832,512 bytes free
Post-Run: 46,050,557,952 bytes free
.
2008-04-09 18:10:32 --- E O F ---







Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:41:33 PM, on 4/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nslsvice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Lightspeed Systems\SecurityAgent\SecurityAgent.exe
C:\lotus\notes\ntmulti.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\1XConfig.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Lightspeed Systems\SecurityAgent\SAAlert.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwgate0.freescale.net:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1; *.freescale.net; *.freescale.com;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfi...IOS/tgctlcm.cab
O16 - DPF: {032B436A-1BA6-47D9-B183-A0E013C94A25} (FgIoOcx Control) - http://172.18.2.66/F...Dll/FgIoOcx.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/...UI.cab55579.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/...nx.1.0.0.87.cab
O16 - DPF: {3A2BF2DC-FDE5-4026-99B4-60F2999137AD} (FgConfigExecOcx Control) - http://172.18.2.66/F...nfigExecOcx.cab
O16 - DPF: {3AED1953-E7E9-418F-888C-7B497E038B77} (FgViewOcx Control) - http://172.18.2.66/F...l/FgViewOcx.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/...dy.cab55579.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://zone.msn.com/...bGameLoader.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1006.cab
O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - http://zone.msn.com/...rs.1.0.0.39.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} (PopCapLoaderCtrl Class) - http://zone.msn.com/...pcaploader1.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/...at.cab55579.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {5FF6BD84-D9FA-497E-BD43-FAA0DE338754} (FgStartupOcx Control) - http://172.18.2.66/F...gStartupOcx.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/...h2.1.0.0.68.cab
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/...t/atomaders.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/...mjolauncher.cab
O16 - DPF: {8C63DABA-CBA8-4B5D-A0F7-AE00F2920929} (Bridge Installer) - http://cdn2.zone.msn...s/heartbeat.cab
O16 - DPF: {921DB7E5-1292-460F-AA99-217245A44330} (FgRawOcx Control) - http://172.18.2.66/F...ll/FgRawOcx.cab
O16 - DPF: {94279BAD-0B3C-4747-8869-8FBF27A675F8} (FgRecipeOcx Control) - http://172.18.2.66/F...FgRecipeOcx.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://cdn2.zone.msn...gr.cab31267.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (ZPA_TexasHoldem Object) - http://zone.msn.com/...he.cab55579.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius....tiveXPlugin.cab
O16 - DPF: {A97CF130-1C5E-4E07-A3FF-14BBE848DAC9} (FgAlarmOcx Control) - http://172.18.8.23/F.../FgAlarmOcx.cab
O16 - DPF: {B84BBE57-87E8-4335-8FD0-4B45A50E055E} (FgDbReportOcx Control) - http://172.18.2.66/F...DbReportOcx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn...ro.cab56649.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://zone.msn.com/...tg.1.0.0.37.cab
O16 - DPF: {C7E002D6-324B-4500-883D-84B620FD8640} (Bridge Installer) - http://cdn2.zone.msn...6/heartbeat.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://zone.msn.com/...ol.cab42858.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/...outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/.../default/ct.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/...xy.cab55579.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/...WebLauncher.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/...sh.1.0.0.98.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mwmus.webex....eck/ieatgpc.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} (CPlayFirstSweetopiaControl Object) - http://zone.msn.com/...ia.1.0.0.46.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 10.211.1.10 10.211.1.8
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 10.211.1.10 10.211.1.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 10.211.1.10 10.211.1.8
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Security Agent Service (IpmSecurityAgentService) - Lightspeed Systems - C:\Program Files\Lightspeed Systems\SecurityAgent\SecurityAgent.exe
O23 - Service: Lotus Notes Single Logon - IBM Corp - C:\WINDOWS\system32\nslsvice.exe
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\lotus\notes\ntmulti.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--
End of file - 10272 bytes
  • 0

#20
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please update your Java:
Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Ugrading Java:After that
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
===============
Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    Posted Image

Delete\uninstall anything left over.
======================
After that your log is clean. :)

The following is a list of tools and utilities that I like to suggest to people.
You do not have to have all or any of them they are only suggestions.
This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.

Spybot Search & Destroy-Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.

Ad-Aware-Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.

Spyware Blaster - Great prevention tool to keep nasties from installing on your system.

Spywareguard-Works as a Spyware "Shield" to protect your computer from getting malware in the first place.

IE-SPYAD- puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

Tony Klein article To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.
  • 0

#21
vegimo

vegimo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Yes, it looks good. Spybot even alerted me that my registry was changing when I changed my password.

Thank you for your help.
  • 0

#22
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
You are welcome :)


Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

#23
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP