Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Browsers opening sites very slowly


  • Please log in to reply

#16
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
5th May 2008

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/04/2008 at 10:42 PM

Application Version : 4.0.1154

Core Rules Database Version : 3451
Trace Rules Database Version: 1443

Scan type : Complete Scan
Total Scan Time : 00:27:47

Memory items scanned : 440
Memory threats detected : 0
Registry items scanned : 5042
Registry threats detected : 0
File items scanned : 40417
File threats detected : 7

Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@partner2profit[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
  • 0

Advertisements


#17
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
2nd May 2008

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/02/2008 at 01:26 AM

Application Version : 4.0.1154

Core Rules Database Version : 3451
Trace Rules Database Version: 1443

Scan type : Complete Scan
Total Scan Time : 00:12:01

Memory items scanned : 445
Memory threats detected : 0
Registry items scanned : 5049
Registry threats detected : 0
File items scanned : 9949
File threats detected : 6

Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@specificclick[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@advertising[2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
  • 0

#18
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
29th April 2008
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 04/29/2008 at 04:42 PM

Application Version : 4.0.1154

Core Rules Database Version : 3442
Trace Rules Database Version: 1434

Scan type : Complete Scan
Total Scan Time : 00:28:38

Memory items scanned : 421
Memory threats detected : 0
Registry items scanned : 5048
Registry threats detected : 0
File items scanned : 38716
File threats detected : 10

Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@advertising[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt

Adware.Vundo-Variant/Small-A
C:\SYSTEM VOLUME INFORMATION\_RESTORE{66607BC1-78A2-49B4-B84D-4BE991028379}\RP208\A0044884.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{66607BC1-78A2-49B4-B84D-4BE991028379}\RP202\A0040581.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{66607BC1-78A2-49B4-B84D-4BE991028379}\RP211\A0047020.DLL

Trojan.Vundo-Variant/F
C:\WINDOWS\SYSTEM32\MIBARETJ.DLL
C:\WINDOWS\SYSTEM32\RCWVDXFC.DLL
C:\WINDOWS\SYSTEM32\UCKHCHPH.DLL
C:\WINDOWS\SYSTEM32\VECPXITX.DLL
  • 0

#19
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
24th April 2008

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 04/24/2008 at 04:13 PM

Application Version : 4.0.1154

Core Rules Database Version : 3442
Trace Rules Database Version: 1434

Scan type : Complete Scan
Total Scan Time : 00:11:57

Memory items scanned : 412
Memory threats detected : 0
Registry items scanned : 5048
Registry threats detected : 0
File items scanned : 13823
File threats detected : 5

Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@advertising[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
  • 0

#20
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
19th April 2008
SUPERAntiSpyware Scan Log
Generated 04/19/2008 at 07:05 PM

Application Version : 3.6.1000

Core Rules Database Version : 3442
Trace Rules Database Version: 1434

Scan type : Complete Scan
Total Scan Time : 03:13:16

Memory items scanned : 423
Memory threats detected : 0
Registry items scanned : 5475
Registry threats detected : 0
File items scanned : 37792
File threats detected : 6

Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@advertising[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt

Adware.Vundo Variant/Rel
C:\WINDOWS\SYSTEM32\MCRH.TMP
  • 0

#21
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
ComboFix 08-05-08.1 - Administrator 2008-05-09 14:15:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.166 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\autorun.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\afboxtsg.ini
C:\WINDOWS\system32\coifreue.ini
C:\WINDOWS\system32\dcbrcblb.ini
C:\WINDOWS\system32\exjujvsb.ini
C:\WINDOWS\system32\gwawblgh.ini
C:\WINDOWS\system32\lmmorvru.ini
C:\WINDOWS\system32\watbjlao.ini
C:\WINDOWS\system32\yxmffnql.ini

.
((((((((((((((((((((((((( Files Created from 2008-04-09 to 2008-05-09 )))))))))))))))))))))))))))))))
.

2009-03-22 22:58 . 2009-03-22 22:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2009-03-22 22:35 . 2009-03-22 22:35 <DIR> d-------- C:\Program Files\Alwil Software
2009-03-22 18:45 . 2007-11-15 10:06 301,656 --a------ C:\WINDOWS\system32\BtCoreIf.dll
2009-03-22 18:44 . 2009-03-22 18:45 <DIR> d-------- C:\Program Files\Common Files\Logishrd
2009-03-22 18:44 . 2009-03-22 18:44 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InstallShield
2009-03-22 15:32 . 2009-03-22 23:40 <DIR> d-------- C:\Program Files\eREAD6.0
2008-05-09 14:15 . 2008-05-09 14:15 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-05-02 01:10 . 2008-05-02 01:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-30 19:38 . 2008-04-30 19:38 <DIR> d-------- C:\Deckard
2008-04-26 01:26 . 2008-04-26 01:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-04-23 16:19 . 2008-04-23 16:23 <DIR> d-------- C:\Program Files\uTorrentSpeedOptimizer
2008-04-23 16:19 . 2001-09-06 10:00 1,700,352 --a------ C:\WINDOWS\system32\gdiplus.dll
2008-04-23 16:11 . 2008-04-23 16:14 <DIR> d-------- C:\Program Files\EZ Boosters
2008-04-23 15:56 . 2008-04-23 16:06 <DIR> d-------- C:\Program Files\FlashGet
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\VundoFix Backups
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\Program Files\Stardock
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-21 21:50 . 2008-04-21 21:50 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-04-20 17:31 . 2008-04-22 06:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Logitech
2008-04-20 17:29 . 2007-01-30 01:46 163,840 --a------ C:\WINDOWS\system32\kemutb.dll
2008-04-20 17:29 . 2007-01-30 01:46 135,168 --a------ C:\WINDOWS\system32\KemUtil.dll
2008-04-20 17:29 . 2007-01-30 01:46 110,592 --a------ C:\WINDOWS\system32\KemWnd.dll
2008-04-20 17:29 . 2007-01-30 01:46 69,632 --a------ C:\WINDOWS\system32\KemXML.dll
2008-04-20 17:28 . 2008-04-22 06:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-04-20 16:16 . 2008-04-20 16:16 0 --------- C:\WINDOWS\WB.ini
2008-04-20 16:04 . 2007-07-11 14:06 42,672 --------- C:\WINDOWS\system32\wbsys.dll
2008-04-20 15:33 . 2006-12-03 17:15 111,104 --a------ C:\WINDOWS\system32\uharc.exe
2008-04-20 15:33 . 2004-09-03 23:43 199 --a------ C:\WINDOWS\system32\paypal.url
2008-04-20 15:33 . 2006-05-26 22:54 83 --a------ C:\WINDOWS\system32\winx.url
2008-04-19 19:42 . 2008-04-19 19:42 182 --a------ C:\WINDOWS\ulead32.ini
2008-04-19 15:46 . 2008-04-22 06:42 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-04-19 15:46 . 2008-04-19 15:46 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-04-19 02:16 . 2008-04-19 02:16 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-19 02:16 . 2008-04-19 02:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-19 02:16 . 2008-04-19 02:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-04-19 02:15 . 2008-04-19 02:15 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-04-15 17:17 . 2008-04-15 17:18 <DIR> d-------- C:\Documents and Settings\Administrator\Sahil
2008-04-13 19:35 . 2008-04-13 19:42 <DIR> d-------- C:\Program Files\MessengerDiscovery
2008-04-13 19:35 . 2004-03-08 23:00 152,848 --a------ C:\WINDOWS\system32\comdlg32.OCX
2008-04-13 19:35 . 2004-03-09 01:00 124,688 --a------ C:\WINDOWS\system32\MSWINSCK.ocx
2008-04-13 15:21 . 2008-04-13 15:21 0 --a------ C:\WINDOWS\BM0f33d01b.xml
2008-04-13 00:04 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-04-13 00:04 . 2004-08-03 23:08 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-04-13 00:04 . 2008-04-13 00:04 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-04-13 00:04 . 2008-04-13 00:04 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-04-12 23:59 . 2008-02-01 15:17 138,112 --a------ C:\WINDOWS\system32\drivers\nmwcdnsu.sys
2008-04-12 23:59 . 2008-02-01 15:17 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdnsuc.sys
2008-04-12 23:58 . 2008-04-12 23:58 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-04-12 23:58 . 2007-11-29 10:33 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-04-12 23:58 . 2007-11-29 10:39 95,744 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-04-12 23:58 . 2007-11-29 10:39 19,328 --a------ C:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-04-12 23:58 . 2007-11-29 10:39 16,896 --a------ C:\WINDOWS\system32\drivers\ccdcmb.sys
2008-04-12 23:58 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
2008-04-12 23:58 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-04-09 16:12 . 2008-04-10 23:17 7,680 --ahs---- C:\WINDOWS\Thumbs.db

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-22 22:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2009-03-22 13:42 --------- d-----w C:\Program Files\PS2 Keyboard English Edition 2.0
2009-03-22 13:42 --------- d-----w C:\Program Files\Mouse
2009-03-22 13:03 --------- d-----w C:\Program Files\Java
2009-03-22 12:32 --------- d-----w C:\Program Files\Real
2008-05-09 11:20 404,512 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-09 11:20 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-05-09 11:19 12,388,128 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-09 11:18 45,188 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-09 11:18 170,072 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-30 13:49 --------- d-----w C:\Program Files\uTorrent
2008-04-23 12:33 360,064 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-04-22 03:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-22 03:42 --------- d-----w C:\Program Files\Logitech
2008-04-20 14:28 --------- d-----w C:\Program Files\Common Files\Logitech
2008-04-12 20:59 --------- d-----w C:\Program Files\Nokia
2008-04-12 20:54 --------- d-----w C:\Program Files\Common Files\Nokia
2008-04-12 20:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-04-12 11:10 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Vso
2008-04-07 14:50 --------- d-----w C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-04-02 19:03 --------- d-----w C:\Program Files\MegauploadToolbar
2008-04-02 19:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MegauploadToolbar
2008-03-30 23:27 --------- d-----w C:\Program Files\VideoLAN
2008-03-24 19:59 --------- d-----w C:\Program Files\Kaspersky Lab
2008-03-20 00:19 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-03-20 00:18 --------- d-----w C:\Program Files\Real Alternative
2008-03-20 00:08 --------- d-----w C:\Program Files\Common Files\Real
2008-03-18 20:12 --------- d-----w C:\Program Files\Azureus
2008-03-18 20:10 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Azureus
2008-03-18 11:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-03-17 01:50 --------- d-----w C:\Program Files\Total Video Converter
2008-03-13 18:18 --------- d-----w C:\Program Files\LimeWire
2008-03-04 14:19 87,608 ----a-w C:\Documents and Settings\Administrator\Application Data\inst.exe
2008-03-04 14:19 47,360 ----a-w C:\Documents and Settings\Administrator\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-14 22:46 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 15:00 15360]
"WhatPulse"="C:\Program Files\WhatPulse\WhatPulse.exe" [2006-08-21 20:48 665600]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-04-20 14:20 1481968]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2008-04-30 16:49 219952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 23:36 14854144 C:\WINDOWS\RTHDCPL.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CAMTRAY.EXE" [2004-07-30 11:04 245760]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 15:10 271360]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe]
"kav"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2006-03-24 19:09 139367]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 10:17 1241088]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-04-20 17:29:06 688128]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2008-04-20 14:20 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll 2007-11-15 10:10 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyxyxur]
xxyxyxur.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23381:UDP"= 23381:UDP:Utorrent

S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2008-02-01 15:17]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2008-02-01 15:17]
S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39]
S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39]
S3 V0090VID;Creative WebCam Vista Plus;C:\WINDOWS\system32\DRIVERS\V0090Vid.sys [2005-04-14 04:00]

.
Contents of the 'Scheduled Tasks' folder
"2008-05-09 10:54:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-09 14:19:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-05-09 14:21:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-09 11:21:50

Pre-Run: 30,911,033,344 bytes free
Post-Run: 30,823,124,992 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

217 --- E O F --- 2008-04-18 09:42:49

  • 0

#22
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:30:00 PM, on 5/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WhatPulse\WhatPulse.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WhatPulse] C:\Program Files\WhatPulse\WhatPulse.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - http://gfx2.hotmail....es/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - http://upload.facebo...toUploader3.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1198184679890
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: xxyxyxur - xxyxyxur.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Unknown owner - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 8012 bytes
  • 0

#23
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
Sari are you there??
  • 0

#24
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts

Sari are you there??


  • 0

#25
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts

Sari are you there??


  • 0

Advertisements


#26
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/12/2008 at 04:59 PM

Application Version : 4.0.1154

Core Rules Database Version : 3458
Trace Rules Database Version: 1449

Scan type : Complete Scan
Total Scan Time : 00:28:04

Memory items scanned : 428
Memory threats detected : 0
Registry items scanned : 5031
Registry threats detected : 0
File items scanned : 39639
File threats detected : 2

Adware.Tracking Cookie
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt

Trojan.Dropper/Multi-MBAD
C:\WINDOWS\MOTA113.EXE
  • 0

#27
sari

sari

    GeekU Admin

  • Community Leader
  • 21,806 posts
  • MVP
sahil,

I'm sorry - very busy weekend with a lot of personal things to attend to. I will respond first thing tomorrow morning.

sari
  • 0

#28
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts

sahil,

I'm sorry - very busy weekend with a lot of personal things to attend to. I will respond first thing tomorrow morning.

sari



ok no problem :)
  • 0

#29
sari

sari

    GeekU Admin

  • Community Leader
  • 21,806 posts
  • MVP
sahil,

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\uharc.exe
C:\WINDOWS\system32\paypal.url
C:\WINDOWS\system32\winx.url
C:\WINDOWS\BM0f33d01b.xml
C:\WINDOWS\MOTA113.EXE



3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Thanks,

sari
  • 0

#30
sahil2397

sahil2397

    Member

  • Topic Starter
  • Member
  • PipPip
  • 50 posts
ComboFix 08-05-08.1 - Administrator 2008-05-13 23:50:55.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.186 [GMT 3:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\BM0f33d01b.xml
C:\WINDOWS\MOTA113.EXE
C:\WINDOWS\system32\paypal.url
C:\WINDOWS\system32\uharc.exe
C:\WINDOWS\system32\winx.url
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Application Data\inst.exe
C:\WINDOWS\BM0f33d01b.xml
C:\WINDOWS\system32\paypal.url
C:\WINDOWS\system32\uharc.exe
C:\WINDOWS\system32\winx.url

.
((((((((((((((((((((((((( Files Created from 2008-04-13 to 2008-05-13 )))))))))))))))))))))))))))))))
.

2009-03-22 22:58 . 2009-03-22 22:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2009-03-22 22:35 . 2009-03-22 22:35 <DIR> d-------- C:\Program Files\Alwil Software
2009-03-22 18:45 . 2007-11-15 10:06 301,656 --a------ C:\WINDOWS\system32\BtCoreIf.dll
2009-03-22 18:44 . 2009-03-22 18:45 <DIR> d-------- C:\Program Files\Common Files\Logishrd
2009-03-22 18:44 . 2009-03-22 18:44 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InstallShield
2009-03-22 15:32 . 2009-03-22 23:40 <DIR> d-------- C:\Program Files\eREAD6.0
2008-05-09 14:15 . 2008-05-09 14:15 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-05-02 01:10 . 2008-05-02 01:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-30 19:38 . 2008-04-30 19:38 <DIR> d-------- C:\Deckard
2008-04-26 01:26 . 2008-04-26 01:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-04-23 16:19 . 2008-04-23 16:23 <DIR> d-------- C:\Program Files\uTorrentSpeedOptimizer
2008-04-23 16:19 . 2001-09-06 10:00 1,700,352 --a------ C:\WINDOWS\system32\gdiplus.dll
2008-04-23 16:11 . 2008-04-23 16:14 <DIR> d-------- C:\Program Files\EZ Boosters
2008-04-23 15:56 . 2008-04-23 16:06 <DIR> d-------- C:\Program Files\FlashGet
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\VundoFix Backups
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\Program Files\Stardock
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-22 06:42 . 2008-04-22 06:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-21 21:50 . 2008-04-21 21:50 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-04-20 17:31 . 2008-04-22 06:42 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Logitech
2008-04-20 17:29 . 2007-01-30 01:46 163,840 --a------ C:\WINDOWS\system32\kemutb.dll
2008-04-20 17:29 . 2007-01-30 01:46 135,168 --a------ C:\WINDOWS\system32\KemUtil.dll
2008-04-20 17:29 . 2007-01-30 01:46 110,592 --a------ C:\WINDOWS\system32\KemWnd.dll
2008-04-20 17:29 . 2007-01-30 01:46 69,632 --a------ C:\WINDOWS\system32\KemXML.dll
2008-04-20 17:28 . 2008-04-22 06:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-04-20 16:16 . 2008-04-20 16:16 0 --------- C:\WINDOWS\WB.ini
2008-04-20 16:04 . 2007-07-11 14:06 42,672 --------- C:\WINDOWS\system32\wbsys.dll
2008-04-19 19:42 . 2008-04-19 19:42 182 --a------ C:\WINDOWS\ulead32.ini
2008-04-19 15:46 . 2008-04-22 06:42 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-04-19 15:46 . 2008-04-19 15:46 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-04-19 02:16 . 2008-04-19 02:16 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-19 02:16 . 2008-04-19 02:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-19 02:16 . 2008-04-19 02:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-04-19 02:15 . 2008-04-19 02:15 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-04-15 17:17 . 2008-04-15 17:18 <DIR> d-------- C:\Documents and Settings\Administrator\Sahil
2008-04-13 19:35 . 2008-04-13 19:42 <DIR> d-------- C:\Program Files\MessengerDiscovery
2008-04-13 19:35 . 2004-03-08 23:00 152,848 --a------ C:\WINDOWS\system32\comdlg32.OCX
2008-04-13 19:35 . 2004-03-09 01:00 124,688 --a------ C:\WINDOWS\system32\MSWINSCK.ocx
2008-04-13 00:04 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-04-13 00:04 . 2004-08-03 23:08 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-04-13 00:04 . 2008-04-13 00:04 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-04-13 00:04 . 2008-04-13 00:04 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-22 22:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2009-03-22 13:42 --------- d-----w C:\Program Files\PS2 Keyboard English Edition 2.0
2009-03-22 13:42 --------- d-----w C:\Program Files\Mouse
2009-03-22 13:03 --------- d-----w C:\Program Files\Java
2009-03-22 12:32 --------- d-----w C:\Program Files\Real
2008-05-13 20:52 430,112 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-13 20:52 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-05-13 20:51 13,268,000 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-13 03:41 47,180 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-13 03:41 180,296 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-30 13:49 --------- d-----w C:\Program Files\uTorrent
2008-04-23 12:33 360,064 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-04-22 03:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-22 03:42 --------- d-----w C:\Program Files\Logitech
2008-04-20 14:28 --------- d-----w C:\Program Files\Common Files\Logitech
2008-04-12 20:59 --------- d-----w C:\Program Files\Nokia
2008-04-12 20:58 --------- d-----w C:\Program Files\MSXML 6.0
2008-04-12 20:54 --------- d-----w C:\Program Files\Common Files\Nokia
2008-04-12 20:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-04-12 11:10 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Vso
2008-04-07 14:50 --------- d-----w C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-04-02 19:03 --------- d-----w C:\Program Files\MegauploadToolbar
2008-04-02 19:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\MegauploadToolbar
2008-04-01 10:23 129,784 ----a-w C:\WINDOWS\system32\pxafs.dll
2008-04-01 10:23 118,056 ----a-w C:\WINDOWS\system32\pxcpyi64.exe
2008-03-30 23:27 --------- d-----w C:\Program Files\VideoLAN
2008-03-24 19:59 --------- d-----w C:\Program Files\Kaspersky Lab
2008-03-20 00:19 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-03-20 00:18 --------- d-----w C:\Program Files\Real Alternative
2008-03-20 00:08 --------- d-----w C:\Program Files\Common Files\Real
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-18 20:12 --------- d-----w C:\Program Files\Azureus
2008-03-18 20:10 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Azureus
2008-03-18 11:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-03-17 01:50 --------- d-----w C:\Program Files\Total Video Converter
2008-03-13 18:18 --------- d-----w C:\Program Files\LimeWire
2008-03-11 16:21 756,736 ----a-w C:\WINDOWS\system32\ir41_32.dll
2008-03-11 16:21 56,832 ----a-w C:\WINDOWS\system32\iyvu9_32.dll
2008-03-11 16:21 143,872 ----a-w C:\WINDOWS\system32\iacenc.dll
2008-03-04 14:19 47,360 ----a-w C:\Documents and Settings\Administrator\Application Data\pcouffin.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
.

((((((((((((((((((((((((((((( snapshot@2008-05-09_14.21.32.20 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-09 11:19:04 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-13 11:04:10 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2009-03-23 09:12:22 9,032 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{79370C96-6709-4F4F-B861-E8704C8AEB9A}.bin
+ 2009-03-23 09:12:22 9,670 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{79370C96-6709-4F4F-B861-E8704C8AEB9A}.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-14 22:46 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 15:00 15360]
"WhatPulse"="C:\Program Files\WhatPulse\WhatPulse.exe" [2006-08-21 20:48 665600]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-04-20 14:20 1481968]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2008-04-30 16:49 219952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 23:36 14854144 C:\WINDOWS\RTHDCPL.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CAMTRAY.EXE" [2004-07-30 11:04 245760]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 15:10 271360]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe]
"kav"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2006-03-24 19:09 139367]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 10:17 1241088]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-04-20 17:29:06 688128]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2008-04-20 14:20 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll 2007-11-15 10:10 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyxyxur]
xxyxyxur.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23381:UDP"= 23381:UDP:Utorrent

S3 nmwcdnsu;Nokia USB Flashing Phone Parent;C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2008-02-01 15:17]
S3 nmwcdnsuc;Nokia USB Flashing Generic;C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2008-02-01 15:17]
S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39]
S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39]
S3 V0090VID;Creative WebCam Vista Plus;C:\WINDOWS\system32\DRIVERS\V0090Vid.sys [2005-04-14 04:00]

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-05-13 19:54:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-13 23:52:31
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-13 23:53:20
ComboFix-quarantined-files.txt 2008-05-13 20:53:15
ComboFix2.txt 2008-05-09 11:21:55

Pre-Run: 30,676,955,136 bytes free
Post-Run: 30,668,681,216 bytes free

206 --- E O F --- 2008-04-18 09:42:49
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP