Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

trojandownloader.xs , hijackthis log [RESOLVED]


  • This topic is locked This topic is locked

#1
silver0808

silver0808

    New Member

  • Member
  • Pip
  • 6 posts
Hello, recently have started getting pop-ups that tell me that my system is vunerable to spware, it then prompts me to click on the message and then directs me via windows explorer to a website selling anti - spyware products
The icons on my desktop have been surrounded by a purple colour and my task manager has been blocked.

below is my hijackthis log

Any hlep will be greatly appreciated

Thankyou
silver0808

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:43:12 AM, on 4/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Acer\eManager\anbmServ.exe
C:\Documents and Settings\All Users\Application Data\fuzazgda\jifylylc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\acer\epm\epm-dm.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\IPFax\FaxMonitor.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\rgdetmja.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0B46DBDF-8C1B-5527-864D-08F21D44C40C} - C:\WINDOWS\system32\ComGenAct.dll
O2 - BHO: (no name) - {1C049E76-EDFE-33D1-547B-00E246A03779} - C:\WINDOWS\system32\admdsccmd.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: (no name) - {58F6A823-E0EB-303C-3841-02D629236E70} - C:\WINDOWS\system32\smartcmdsh.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [FaxMonitor] C:\Program Files\IPFax\FaxMonitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [BitTorrent] "E:\Program Files\bittorent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [axcyhber] C:\WINDOWS\system32\rgdetmja.exe
O4 - HKCU\..\Run: [mqcwcyoi] C:\WINDOWS\system32\fcdczgxa.exe
O4 - HKCU\..\Run: [xsegnwwb] C:\WINDOWS\system32\typuzaba.exe
O4 - HKLM\..\Policies\Explorer\Run: [2bjgBMOR31] C:\Documents and Settings\All Users\Application Data\fuzazgda\jifylylc.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1202793658718
O16 - DPF: {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_07) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{17B1390D-108C-4B64-B6CF-D67F6816E3CD}: NameServer = 202.179.64.1,202.179.64.2
O21 - SSODL: CheckWeb - {C111CF13-545F-6FF1-51AC-F623D452C63D} - C:\WINDOWS\system32\cryper.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: apcsvra32 - Unknown owner - C:\Program Files\Common Files\System\apcsvra.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe (file missing)
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe

--
End of file - 9364 bytes
  • 0

Advertisements


#2
Stamper19

Stamper19

    Expert

  • Expert
  • 1,992 posts
Hi Silver0808,

Welcome to Geeks to Go!

My name is Stamper19 and I will be helping you with your Malware problem. During the course of our interactions please be sure to follow all instructions carefully, and ask questions if you are unsure of how to proceed at any point. :)

----------------------------------------------------------------

Please download Deckard's System Scanner (DSS) to your Desktop.

  • Close all applications and windows.
  • Double-click on DSS.exe to run it, and follow the prompts.
  • The scan may take a minute. When the scan is complete, two text files will open - Main.txt and Extra.txt

Extra Note: When running DSS, some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so. Also, it may happen that your Antivirus flags DSS as suspicious. Please allow the Deckard's System Scanner to run and don't let your Antivirus delete it. (In this case, it may be better to temporary disable your Antivirus)

Post the main.txt and extra.txt from the C:\Deckard\System Scanner folder into your next reply.

----------------------------------------------------------------

Information to include in your next post:
  • main.txt and extra.txt from DSS

  • 0

#3
silver0808

silver0808

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi,
Thank you so much for your cooperation. Please find the logs below.

Regards,
silver0808

MAIN.TXT

Deckard's System Scanner v20071014.68
Run by Dhiraj Jadhav on 2008-04-22 01:46:55
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
10: 2008-04-22 06:47:02 UTC - RP166 - Deckard's System Scanner Restore Point
9: 2008-04-21 13:06:39 UTC - RP165 - Removed Paint.NET v3.10
8: 2008-04-21 13:05:41 UTC - RP164 - Removed Opera 9.27
7: 2008-04-21 07:31:03 UTC - RP163 - ComboFix created restore point
6: 2008-04-21 06:46:12 UTC - RP162 - ComboFix created restore point


-- First Restore Point --
1: 2008-04-09 02:48:50 UTC - RP157 - Installed VeohTV BETA


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 503 MiB (512 MiB recommended).


-- HijackThis (run as Dhiraj Jadhav.exe) ---------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:48:04 AM, on 4/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\All Users\Application Data\fuzazgda\jifylylc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\acer\epm\epm-dm.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\IPFax\FaxMonitor.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\rgdetmja.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Dhiraj Jadhav\Desktop\dss.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Dhiraj Jadhav.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0B46DBDF-8C1B-5527-864D-08F21D44C40C} - C:\WINDOWS\system32\ComGenAct.dll
O2 - BHO: (no name) - {1C049E76-EDFE-33D1-547B-00E246A03779} - C:\WINDOWS\system32\admdsccmd.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: (no name) - {58F6A823-E0EB-303C-3841-02D629236E70} - C:\WINDOWS\system32\smartcmdsh.dll
O2 - BHO: (no name) - {6F3E2E2A-4EB7-E8A8-204C-048E2AC9BB3F} - C:\WINDOWS\system32\SrvAppHlp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [FaxMonitor] C:\Program Files\IPFax\FaxMonitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [xutwzuno] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\xutwzuno.dll"
O4 - HKCU\..\Run: [BitTorrent] "E:\Program Files\bittorent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [axcyhber] C:\WINDOWS\system32\rgdetmja.exe
O4 - HKCU\..\Run: [mqcwcyoi] C:\WINDOWS\system32\fcdczgxa.exe
O4 - HKCU\..\Run: [xsegnwwb] C:\WINDOWS\system32\typuzaba.exe
O4 - HKCU\..\Run: [frncpexs] C:\WINDOWS\system32\ngxwhetq.exe
O4 - HKLM\..\Policies\Explorer\Run: [2bjgBMOR31] C:\Documents and Settings\All Users\Application Data\fuzazgda\jifylylc.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1202793658718
O16 - DPF: {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_07) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{17B1390D-108C-4B64-B6CF-D67F6816E3CD}: NameServer = 202.179.64.1,202.179.64.2
O21 - SSODL: CheckWeb - {C111CF13-545F-6FF1-51AC-F623D452C63D} - C:\WINDOWS\system32\cryper.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: apcsvra32 - Unknown owner - C:\Program Files\Common Files\System\apcsvra.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe (file missing)
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe

--
End of file - 9662 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.1.6.0) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.1.6.0>
R2 EpmPsd (Acer EPM Power Scheme Driver) - c:\windows\system32\drivers\epm-psd.sys <Not Verified; Acer Value Labs, USA; Acer EPM Power Scheme Driver>
R2 EpmShd (Acer EPM System Hardware Driver) - c:\windows\system32\drivers\epm-shd.sys <Not Verified; Acer Value Labs, USA; Acer EPM System Hardware Driver>
R2 osaio - c:\windows\system32\drivers\osaio.sys <Not Verified; OSA Technologies, An Avocent Company; Windows ® 2000 DDK driver>
R2 osanbm - c:\windows\system32\drivers\osanbm.sys <Not Verified; Windows ® 2000 DDK provider; OSA int15 Driver>
R2 s24trans (WLAN Transport) - c:\windows\system32\drivers\s24trans.sys <Not Verified; Intel Corporation; Intel Wireless LAN Packet Driver>
R3 apcsvra - c:\program files\common files\system\apcsvra.dll

S3 catchme - c:\combofix\catchme.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 anbmService (Notebook Manager Service) - c:\acer\emanager\anbmserv.exe <Not Verified; OSA Technologies Inc.; Acer eManager for Notebook>
R2 OwnershipProtocol - c:\program files\intel\wireless\bin\oprotsvc.exe <Not Verified; Intel Corporation; Intel PROSet/Wireless>
R2 RegSrvc - c:\program files\intel\wireless\bin\regsrvc.exe <Not Verified; Intel Corporation; RegSrvc Module>

S2 apcsvra32 - c:\program files\common files\system\apcsvra.exe
S3 aspnet_state (ASP.NET State Service) - c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe (file missing)
S3 Tomcat5 (Apache Tomcat) - "c:\program files\apache software foundation\tomcat 5.5\bin\tomcat5.exe" //rs//tomcat5 (file missing)
S3 wampapache - "c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe" -k runservice <Not Verified; Apache Software Foundation; Apache HTTP Server>
S3 wampmysqld - c:\wamp\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe wampmysqld


-- Device Manager: Disabled ----------------------------------------------------

Class GUID:
Description: Modem Device on High Definition Audio Bus
Device ID: HDAUDIO\FUNC_02&VEN_14F1&DEV_2BFA&SUBSYS_1025008F&REV_0900\4&58EF957&0&0102
Manufacturer:
Name: Modem Device on High Definition Audio Bus
PNP Device ID: HDAUDIO\FUNC_02&VEN_14F1&DEV_2BFA&SUBSYS_1025008F&REV_0900\4&58EF957&0&0102
Service:


-- Scheduled Tasks -------------------------------------------------------------

2008-03-01 01:45:00 240 --a------ C:\WINDOWS\Tasks\explorer.job


-- Files created between 2008-03-22 and 2008-04-22 -----------------------------

2008-04-22 01:27:32 118784 --a------ C:\WINDOWS\system32\SrvAppHlp.dll
2008-04-22 01:27:32 118784 --a------ C:\Documents and Settings\All Users\Application Data\xutwzuno.dll
2008-04-22 01:27:26 94208 --a------ C:\WINDOWS\system32\ngxwhetq.exe
2008-04-21 02:22:02 102400 --a------ C:\WINDOWS\system32\smartcmdsh.dll
2008-04-21 02:22:02 102400 --a------ C:\Documents and Settings\All Users\Application Data\nszsfijy.dll
2008-04-21 02:22:01 110592 --a------ C:\WINDOWS\system32\typuzaba.exe
2008-04-21 02:21:30 0 d-------- C:\Program Files\Trend Micro
2008-04-21 01:45:44 68096 --a------ C:\WINDOWS\zip.exe
2008-04-21 01:45:44 49152 --a------ C:\WINDOWS\VFind.exe
2008-04-21 01:45:44 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-04-21 01:45:44 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-04-21 01:45:44 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-04-21 01:45:44 98816 --a------ C:\WINDOWS\sed.exe
2008-04-21 01:45:44 80412 --a------ C:\WINDOWS\grep.exe
2008-04-21 01:45:44 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-04-16 04:09:47 126976 --a------ C:\WINDOWS\system32\ComGenAct.dll
2008-04-16 04:09:47 126976 --a------ C:\Documents and Settings\All Users\Application Data\itidsvgv.dll
2008-04-16 04:09:46 98304 --a------ C:\WINDOWS\system32\fcdczgxa.exe
2008-04-15 19:25:26 118784 --a------ C:\Documents and Settings\All Users\Application Data\zuzebqfa.dll
2008-04-15 19:25:26 0 d-------- C:\Documents and Settings\All Users\Application Data\fuzazgda
2008-04-15 19:25:25 118784 --a------ C:\WINDOWS\system32\admdsccmd.dll
2008-04-15 19:25:24 102400 --a------ C:\WINDOWS\system32\rgdetmja.exe
2008-04-14 00:55:06 0 d-------- C:\Program Files\11view
2008-04-14 00:34:23 0 d-------- C:\Documents and Settings\Dhiraj Jadhav\Application Data\Flickr
2008-04-14 00:32:20 0 d-------- C:\Program Files\Flickr Uploadr
2008-04-08 04:56:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-04-08 04:49:43 0 d-------- C:\Program Files\Windows Media Connect 2
2008-04-08 04:39:35 0 d-------- C:\Documents and Settings\Dhiraj Jadhav\Application Data\Opera
2008-04-08 04:39:28 0 d-------- C:\Program Files\Opera
2008-04-08 01:47:44 2560 --a------ C:\WINDOWS\system32\bitcometres.dll <Not Verified; BitComet; BitComet BCTP Helper>
2008-04-08 01:47:44 0 d-------- C:\Downloads
2008-04-08 01:47:25 0 d-------- C:\Program Files\BitComet
2008-04-05 03:55:41 0 --a------ C:\WINDOWS\system32\lich.dat
2008-04-03 04:11:47 261632 --a------ C:\WINDOWS\system32\cryper.dll
2008-04-02 00:49:04 17408 --a------ C:\Program Files\~.exe
2008-03-23 03:07:42 0 d-------- C:\Documents and Settings\Dhiraj Jadhav\Application Data\phpDesigner 2008
2008-03-23 02:55:41 0 d-------- C:\wamp
2008-03-23 02:19:14 0 d-------- C:\Program Files\MySQL
2008-03-23 02:17:47 0 d-------- C:\Program Files\PHP


-- Find3M Report ---------------------------------------------------------------

2008-04-21 01:46:54 0 d-------- C:\Program Files\Common Files
2008-04-10 18:53:48 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-10 18:50:02 0 d-------- C:\Program Files\Crimson Editor
2008-04-08 02:32:39 0 d-------- C:\Documents and Settings\Dhiraj Jadhav\Application Data\BitTorrent
2008-03-28 03:15:49 0 d-------- C:\Program Files\Mp3 My Mp3 2.0
2008-03-23 02:48:22 0 d-------- C:\Program Files\Swapper
2008-03-23 02:39:32 0 d-------- C:\Program Files\Java
2008-03-17 04:03:42 0 d-------- C:\Program Files\DivX
2008-03-17 03:46:30 0 d-------- C:\Documents and Settings\Dhiraj Jadhav\Application Data\.Torrent Swapper
2008-03-05 03:20:21 0 d-------- C:\Program Files\Real
2008-03-03 04:43:10 0 d-------- C:\Program Files\Audacity
2008-03-02 16:10:33 0 d-------- C:\Program Files\Google
2008-02-20 21:05:44 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-02-20 21:04:16 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-02-20 21:04:16 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-02-20 21:04:04 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-02-20 21:04:04 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-02-20 21:04:04 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-02-20 21:04:04 682496 --a------ C:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-02-20 21:03:24 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0B46DBDF-8C1B-5527-864D-08F21D44C40C}]
04/16/2008 04:09 AM 126976 --a------ C:\WINDOWS\system32\ComGenAct.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C049E76-EDFE-33D1-547B-00E246A03779}]
04/15/2008 07:25 PM 118784 --a------ C:\WINDOWS\system32\admdsccmd.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{58F6A823-E0EB-303C-3841-02D629236E70}]
04/21/2008 02:22 AM 102400 --a------ C:\WINDOWS\system32\smartcmdsh.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6F3E2E2A-4EB7-E8A8-204C-048E2AC9BB3F}]
04/22/2008 01:27 AM 118784 --a------ C:\WINDOWS\system32\SrvAppHlp.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [10/15/2004 10:27 AM]
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [10/15/2004 10:31 AM]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [01/12/2006 07:52 PM]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [08/11/2005 06:21 PM]
"ePowerManagement"="C:\Acer\ePM\ePM.exe" [03/15/2005 09:03 AM]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [01/07/2005 04:07 PM C:\WINDOWS\system32\HdAShCut.exe]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [06/11/2005 06:51 PM]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [06/08/2005 10:02 AM]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [06/08/2005 09:59 AM]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [06/08/2005 10:03 AM]
"RTHDCPL"="RTHDCPL.EXE" [08/09/2005 02:17 PM C:\WINDOWS\RTHDCPL.EXE]
"FaxMonitor"="C:\Program Files\IPFax\FaxMonitor.exe" [01/21/2002 01:45 PM]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 12:50 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [09/01/2006 04:57 PM]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [01/11/2008 06:54 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 05:25 AM]
"xutwzuno"="regsvr32 /u C:\Documents and Settings\All Users\Application Data\xutwzuno.dll" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent"="E:\Program Files\bittorent\bittorrent.exe" []
"axcyhber"="C:\WINDOWS\system32\rgdetmja.exe" [04/15/2008 07:25 PM]
"mqcwcyoi"="C:\WINDOWS\system32\fcdczgxa.exe" [04/16/2008 04:09 AM]
"xsegnwwb"="C:\WINDOWS\system32\typuzaba.exe" [04/21/2008 02:22 AM]
"frncpexs"="C:\WINDOWS\system32\ngxwhetq.exe" [04/22/2008 01:27 AM]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
"DisableTaskMgr"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"2bjgBMOR31"=C:\Documents and Settings\All Users\Application Data\fuzazgda\jifylylc.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"CheckWeb"= {C111CF13-545F-6FF1-51AC-F623D452C63D} - C:\WINDOWS\system32\cryper.dll [04/03/2008 04:11 AM 261632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 10/15/2004 10:27 AM 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{950ea23e-544e-11dc-8494-00c09fcf34df}]
AutoRun\command- G:\LaunchU3.exe -a




-- End of Deckard's System Scanner: finished at 2008-04-22 01:49:14 ------------


EXTRA.TXT

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® M processor 1.60GHz
Percentage of Memory in Use: 57%
Physical Memory (total/avail): 502.05 MiB / 211.67 MiB
Pagefile Memory (total/avail): 1227.13 MiB / 923.39 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1936.16 MiB

C: is Fixed (NTFS) - 10.58 GiB total, 3.28 GiB free.
D: is Fixed (NTFS) - 35.99 GiB total, 8.37 GiB free.
E: is Fixed (NTFS) - 25.03 GiB total, 5.74 GiB free.
F: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - IC25N080ATMR04-0 - 74.53 GiB - 4 partitions
\PARTITION0 - Unknown - 2.93 GiB
\PARTITION1 (bootable) - Installable File System - 10.58 GiB - C:
\PARTITION2 - Installable File System - 25.03 GiB - E:
\PARTITION3 - Extended w/Extended Int 13 - 35.99 GiB - D:



-- Security Center -------------------------------------------------------------

AUOptions is disabled.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.


[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Dhiraj Jadhav\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.5.0_09\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=VV-BF8856B926C9
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Dhiraj Jadhav
JAVA_HOME=C:\Sun\SDK\jdk
JDKHOME=C:\Sun\SDK\jdk
LOGONSERVER=\\VV-BF8856B926C9
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Sun\SDK\bin;C:\Sun\SDK\jdk\bin;C:\Program Files\Java\jre1.5.0_09\bin;C:\Program Files\QuickTime\QTSystem;C:\Sun\SDK\bin;;;C:\Sun\SDK\jdk\bin;C:\Program Files\Java\jre1.5.0_09\bin
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 8, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0d08
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.5.0_09\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\DHIRAJ~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\DHIRAJ~1\LOCALS~1\Temp
USERDOMAIN=VV-BF8856B926C9
USERNAME=Dhiraj Jadhav
USERPROFILE=C:\Documents and Settings\Dhiraj Jadhav
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI


-- User Profiles ---------------------------------------------------------------

Dhiraj Jadhav (admin)
Administrator (new local, admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
11view 3.0a --> "C:\Program Files\11view\Uninstall.exe" "C:\Program Files\11view\install.log"
Acer eManager for Notebook --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{827289F5-B44F-4E49-9993-840741585A62}
Acer ePowerManagement --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{58E5844B-7CE2-413D-83D1-99294BF6C74F}\Setup.exe" -l0x9
Ad-Aware 2007 --> MsiExec.exe /X{0E6AB9FC-76C2-431B-9C06-6C1CFFFEA8EB}
Adobe Acrobat 7.0.9 Professional --> msiexec /I {AC76BA86-1033-0000-7760-000000000002}
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe -q
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Audacity 1.2.6 --> "C:\Program Files\Audacity\unins000.exe"
BitComet 1.00 --> C:\Program Files\BitComet\uninst.exe
CommuniKate 2.0 Video Conferencing --> MsiExec.exe /X{BE35F900-AA44-4655-88FC-C872AF2AF384}
Compatibility Pack for the 2007 Office system --> MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader --> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DVD to VCD AVI DivX Converter v3.2 (build 069) --> C:\PROGRA~1\MAGICD~1\UNWISE.EXE C:\PROGRA~1\MAGICD~1\INSTALL.LOG
Flash CD & DVD Burner --> "C:\Program Files\Flash CD & DVD Burner\unins000.exe"
Flickr Uploadr 3.0.5 --> "C:\Program Files\Flickr Uploadr\uninstall.exe"
Free CD to MP3 Converter --> C:\PROGRA~1\CDTOMP~1\UNWISE.EXE C:\PROGRA~1\CDTOMP~1\INSTALL.LOG
Free DVD Maker --> "C:\Program Files\FunnySoft\Free DVD Maker\unins000.exe"
GujaratiPad 1.2 --> "C:\Program Files\PublicSoft\GujaratiPad\unins000.exe"
High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Intel® Graphics Media Accelerator Driver for Mobile --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2792 PCI\VEN_8086&DEV_2592
Intel® PROSet/Wireless Software --> C:\WINDOWS\Installer\iProInst.exe
IPFax --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FAC19E84-F3D2-4437-A104-8DB80E36973C}\setup.exe"
Java™ 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
mCore --> MsiExec.exe /I{6DE14BE4-6F04-4935-8ABD-A0A19FE2E55A}
mDriver --> MsiExec.exe /I{28DA872A-0848-48CF-B749-19A198157A2A}
mDrWiFi --> MsiExec.exe /I{F6090A17-0967-4A8A-B3C3-422A1B514D49}
mEoU.msi --> MsiExec.exe /I{B502B428-3386-40A9-98DB-079AAB72E64F}
mHelp --> MsiExec.exe /I{8C6BB412-D3A8-4AAE-A01B-35B681789D68}
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 --> "C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
mIWA --> MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F}
mIWCA --> MsiExec.exe /I{6FFFE74E-3FBD-4E2E-97F9-5E9A2A077626}
mLogView --> MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}
mMHouse --> MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
Mozilla Firefox (2.0.0.14) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MP3 CD Converter Professional 5.03 --> C:\Program Files\MP3 CD Converter Professional\uninst.exe
mPfMgr --> MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
mPfWiz --> MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9}
mProSafe --> MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
MSXML 6.0 Parser (KB927977) --> MsiExec.exe /I{5A710547-B58E-488B-828D-CA9A25A0533C}
mWlsSafe --> MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
mXML --> MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401}
mZConfig --> MsiExec.exe /I{94658027-9F16-4509-BBD7-A59FE57C3023}
Nero 6 Ultra Edition --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
Paint.NET v3.10 --> MsiExec.exe /X{5E749AEB-5A19-43BA-BB20-3CBB37539FE4}
PIMSync 4 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5D67B9C8-5716-4D4C-8C14-D3FA83153181}\setup.exe"
PlayFLV --> "C:\Program Files\PlayFLV\uninstall.exe"
QuickTime --> MsiExec.exe /I{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Rhapsody Player Engine --> MsiExec.exe /I{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}
SC Audio CD creator 3.3.0.0 --> "C:\Program Files\SoftwareClub.ws\SC Audio CD creator\unins000.exe"
Serif 3DPlus 2.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A36638C0-D8B9-11D3-9801-00A0CC555167}\setup.exe"
Serif PhotoPlus 8.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0F6D55D8-89AA-4C1D-BC4C-ACBBDE8BE57A}\setup.exe"
Serif PhotoPlus Association File Formats --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F8650CB3-89F1-4AE0-81AC-917423C58DB8}\setup.exe"
Sothink Movie DVD Maker --> "C:\Program Files\SourceTec\Sothink Movie DVD Maker\unins000.exe"
Sun™ Download Manager 2.0 --> C:\Program Files\SDM20\Uninstal.exe
VideoLAN VLC media player 0.8.6a --> C:\Program Files\VideoLAN\VLC\uninstall.exe
WampServer 2.0 --> "c:\wamp\unins000.exe"
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
Zune --> MsiExec.exe /X{7583239A-D4BE-48CA-A253-396122B3D3E9}
Zune Language Pack (ES) --> MsiExec.exe /X{EE4ACABF-531E-419A-9225-B8E0FA4955AF}
Zune Language Pack (FR) --> MsiExec.exe /X{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}


-- Application Event Log -------------------------------------------------------

Event Record #/Type5243 / Error
Event Submitted/Written: 04/21/2008 08:06:39 AM
Event ID/Source: 11721 / MsiInstaller
Event Description:
Product: Paint.NET v3.10 -- Error 1721. There is a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support personnel or package vendor. Action: _8FBBBB09_39E3_48BB_9E6C_620898EF3CD9, location: C:\Program Files\Paint.NET\SetupNgen.exe, command: /delete DESKTOPSHORTCUT= PDNUPDATING= SKIPCLEANUP= "PROGRAMSGROUP=" QUEUENGEN=

Event Record #/Type5187 / Error
Event Submitted/Written: 04/16/2008 04:02:41 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application opera.exe, version 9.27.8841.0, faulting module kernel32.dll, version 5.1.2600.2180, fault address 0x0000979d.
Processing media-specific event for [opera.exe!ws!]

Event Record #/Type5174 / Error
Event Submitted/Written: 04/14/2008 11:48:17 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.
Processing media-specific event for [drwtsn32.exe!ws!]

Event Record #/Type5173 / Error
Event Submitted/Written: 04/14/2008 11:48:08 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application explorer.exe, version 6.0.2900.2180, faulting module shdocvw.dll, version 6.0.2900.2180, fault address 0x00086dbe.
Processing media-specific event for [explorer.exe!ws!]

Event Record #/Type5141 / Error
Event Submitted/Written: 04/11/2008 04:20:47 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application firefox.exe, version 1.8.20080.31114, faulting module firefox.exe, version 1.8.20080.31114, fault address 0x00361966.
Processing media-specific event for [firefox.exe!ws!]



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type23251 / Error
Event Submitted/Written: 04/19/2008 00:39:07 PM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The Computer Browser service terminated with the following error:
%%1460

Event Record #/Type23234 / Error
Event Submitted/Written: 04/19/2008 00:35:04 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The Task Scheduler service failed to start due to the following error:
%%1053

Event Record #/Type23233 / Error
Event Submitted/Written: 04/19/2008 00:35:04 PM
Event ID/Source: 7009 / Service Control Manager
Event Description:
Timeout (30000 milliseconds) waiting for the Task Scheduler service to connect.

Event Record #/Type23227 / Error
Event Submitted/Written: 04/19/2008 01:29:15 AM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The Computer Browser service terminated with the following error:
%%1460

Event Record #/Type23210 / Error
Event Submitted/Written: 04/19/2008 01:25:13 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The Task Scheduler service failed to start due to the following error:
%%1053



-- End of Deckard's System Scanner: finished at 2008-04-22 01:49:14 ------------
  • 0

#4
Stamper19

Stamper19

    Expert

  • Expert
  • 1,992 posts
Hi Silver0808,

First, I see that you are running, or have previously installed, BitComet. Although this application is not malware itself, the files downloaded with it are often a major source of infection. Hence, I strongly advise that it be removed. If you choose to do so, go to the Add/Remove Programs option in the Control Panel, and Uninstall BitComet.

----------------------------------------------------------------

I notice that you do not seem to be running Antivirus software and a Firewall. This is extremely dangerous in today's digital world.
That's why I want you to install them first!


Avira OR AVG are good FREE antivirus programs. Install either of the two, but not both.
Never install more than one antivirusscanner or firewall on your system! Several together can give problems and seriously decrease reliability!

Comodo OR ZoneAlarm are FREE firewalls. Again, install either, but not both.

Please read Understanding and using firewalls

Scan with your Antivirus and let it remove anything it is finding.
Then reboot.

----------------------------------------------------------------

Please download VundoFix.exe to your desktop

  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.

Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

----------------------------------------------------------------

Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall

----------------------------------------------------------------

Information to include in your next post:
  • Any log from running your new AntiVirus program
  • VundoFix.txt
  • Combofix Log

  • 0

#5
silver0808

silver0808

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi,
This is what you had asked for...

* Any log from running your new AntiVirus program
* VundoFix.txt
* Combofix Log

I downloaded AVG and scanned my computer. It detected and deleted some files but I do not see any log files.

The VundoFix could not find anything and gave a message saying something similar.

Here is the combofix and the hijackthis log

COMBOFIX:

ComboFix 08-04-20.2 - Dhiraj Jadhav 2008-04-24 3:39:37.3 - NTFSx86
Running from: C:\Documents and Settings\Dhiraj Jadhav\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-03-24 to 2008-04-24 )))))))))))))))))))))))))))))))
.

2008-04-23 06:03 . 2008-04-23 06:03 <DIR> d-------- C:\VundoFix Backups
2008-04-23 05:30 . 2008-04-24 03:43 178,208 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-23 05:30 . 2008-04-23 06:34 4,172 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-23 05:23 . 2008-04-23 05:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-04-23 05:23 . 2008-04-02 21:07 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-04-23 05:23 . 2004-04-27 05:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-04-23 05:23 . 2008-04-23 05:27 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-04-23 05:21 . 2008-04-23 05:23 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-04-23 05:21 . 2008-04-23 05:21 <DIR> d-------- C:\Program Files\Zone Labs
2008-04-23 05:21 . 2008-04-02 21:07 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2008-04-23 05:21 . 2008-04-24 02:38 352,918 --a------ C:\WINDOWS\system32\vsconfig.xml
2008-04-23 05:04 . 2008-04-24 03:34 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-04-22 16:26 . 2008-04-22 18:15 <DIR> dr-h----- C:\$VAULT$.AVG
2008-04-22 16:18 . 2008-04-22 16:18 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-22 16:18 . 2008-04-22 16:32 <DIR> d-------- C:\Documents and Settings\Dhiraj Jadhav\Application Data\AVG7
2008-04-22 16:17 . 2008-04-22 16:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-22 16:17 . 2008-04-22 16:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-22 01:46 . 2008-04-22 01:46 <DIR> d-------- C:\Deckard
2008-04-22 01:27 . 2008-04-22 01:27 118,784 --a------ C:\WINDOWS\system32\SrvAppHlp.dll
2008-04-22 01:27 . 2008-04-22 01:27 118,784 --a------ C:\Documents and Settings\All Users\Application Data\xutwzuno.dll
2008-04-21 02:22 . 2008-04-21 02:22 102,400 --a------ C:\WINDOWS\system32\smartcmdsh.dll
2008-04-21 02:22 . 2008-04-21 02:22 102,400 --a------ C:\Documents and Settings\All Users\Application Data\nszsfijy.dll
2008-04-21 02:21 . 2008-04-21 02:21 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-16 04:09 . 2008-04-16 04:09 126,976 --a------ C:\WINDOWS\system32\ComGenAct.dll
2008-04-16 04:09 . 2008-04-16 04:09 126,976 --a------ C:\Documents and Settings\All Users\Application Data\itidsvgv.dll
2008-04-15 19:25 . 2008-04-15 19:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\fuzazgda
2008-04-15 19:25 . 2008-04-15 19:25 118,784 --a------ C:\WINDOWS\system32\admdsccmd.dll
2008-04-15 19:25 . 2008-04-15 19:25 118,784 --a------ C:\Documents and Settings\All Users\Application Data\zuzebqfa.dll
2008-04-14 00:55 . 2008-04-14 00:55 <DIR> d-------- C:\Program Files\11view
2008-04-14 00:34 . 2008-04-14 00:34 <DIR> d-------- C:\Documents and Settings\Dhiraj Jadhav\Application Data\Flickr
2008-04-14 00:32 . 2008-04-14 01:25 <DIR> d-------- C:\Program Files\Flickr Uploadr
2008-04-08 04:49 . 2008-04-08 04:49 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-04-08 04:49 . 2004-08-04 07:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-08 01:47 . 2008-04-22 16:14 <DIR> d-------- C:\Program Files\BitComet
2008-04-08 01:47 . 2008-04-10 19:08 <DIR> d-------- C:\Downloads
2008-04-05 03:55 . 2008-04-05 03:55 0 --a------ C:\WINDOWS\system32\lich.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-22 22:16 --------- d-----w C:\Documents and Settings\Dhiraj Jadhav\Application Data\dvdcss
2008-04-16 08:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-10 23:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-10 23:50 --------- d-----w C:\Program Files\Crimson Editor
2008-04-08 07:32 --------- d-----w C:\Documents and Settings\Dhiraj Jadhav\Application Data\BitTorrent
2008-03-28 08:15 --------- d-----w C:\Program Files\Mp3 My Mp3 2.0
2008-03-23 08:11 --------- d-----w C:\Documents and Settings\Dhiraj Jadhav\Application Data\phpDesigner 2008
2008-03-23 07:48 --------- d-----w C:\Program Files\Swapper
2008-03-23 07:48 --------- d-----w C:\Program Files\PHP
2008-03-23 07:39 --------- d-----w C:\Program Files\Java
2008-03-23 07:19 --------- d-----w C:\Program Files\MySQL
2008-03-23 05:59 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-03-23 05:59 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-03-23 05:59 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-03-20 07:23 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Intel
2008-03-17 09:03 --------- d-----w C:\Program Files\DivX
2008-03-17 08:46 --------- d-----w C:\Documents and Settings\Dhiraj Jadhav\Application Data\.Torrent Swapper
2008-03-05 08:20 --------- d-----w C:\Program Files\Real
2008-03-04 23:10 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-03 09:43 --------- d-----w C:\Program Files\Audacity
2008-03-02 21:10 --------- d-----w C:\Program Files\Google
2008-02-21 02:05 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-02-21 02:05 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-02-21 02:03 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-21 02:03 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-08-05 09:21 88 ----a-w C:\Documents and Settings\Dhiraj Jadhav\tomstart.bat
2007-06-03 13:35 60 ----a-w C:\Documents and Settings\Dhiraj Jadhav\ip.bat
2005-07-29 20:24 472 --sha-r C:\WINDOWS\RGhpcmFqIEIgSmFkaGF2\l31DwAINKHK0mAI4u3IZ.vbs
.

((((((((((((((((((((((((((((( snapshot@2008-04-21_ 1.53.26.73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-21 06:50:23 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-24 07:37:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-22 21:17:53 821,856 ----a-w C:\WINDOWS\system32\drivers\avg7core.sys
+ 2008-04-22 21:17:58 4,224 ----a-w C:\WINDOWS\system32\drivers\avg7rsw.sys
+ 2008-04-22 21:17:59 27,776 ----a-w C:\WINDOWS\system32\drivers\avg7rsxp.sys
+ 2008-04-22 21:17:59 10,760 ----a-w C:\WINDOWS\system32\drivers\avgclean.sys
+ 2008-04-22 21:17:59 26,952 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2007-07-19 21:10:28 127,768 ----a-w C:\WINDOWS\system32\drivers\klif.sys
+ 2008-04-03 02:07:36 796,048 ----a-w C:\WINDOWS\system32\libeay32_0.9.6l.dll
- 2008-04-07 06:35:41 61,612 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-21 06:55:23 61,612 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-04-07 06:35:41 400,846 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-21 06:55:23 400,846 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-03 02:07:40 83,432 ----a-w C:\WINDOWS\system32\vsdata.dll
+ 2008-04-03 02:08:00 394,952 ----a-w C:\WINDOWS\system32\vsdatant.sys
+ 2008-04-03 02:07:40 157,160 ----a-w C:\WINDOWS\system32\vsinit.dll
+ 2008-04-03 02:07:40 103,912 ----a-w C:\WINDOWS\system32\vsmonapi.dll
+ 2008-04-03 02:07:40 275,944 ----a-w C:\WINDOWS\system32\vspubapi.dll
+ 2008-04-03 02:07:42 71,144 ----a-w C:\WINDOWS\system32\vsregexp.dll
+ 2008-04-03 02:07:42 472,552 ----a-w C:\WINDOWS\system32\vsutil.dll
+ 2008-04-03 02:07:42 46,568 ----a-w C:\WINDOWS\system32\vswmi.dll
+ 2008-04-03 02:07:42 99,816 ----a-w C:\WINDOWS\system32\vsxml.dll
+ 2008-04-03 02:07:44 83,432 ----a-w C:\WINDOWS\system32\zlcomm.dll
+ 2008-04-03 02:07:44 71,144 ----a-w C:\WINDOWS\system32\zlcommdb.dll
+ 2008-04-03 02:07:32 370,208 ----a-w C:\WINDOWS\system32\ZoneLabs\av.dll
+ 2007-05-31 06:03:30 65,248 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\aphish.dat
+ 2006-06-30 20:47:36 21,568 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\avcmhk4.dll
+ 2007-05-31 06:03:30 1,628 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\pdmkl.dat
+ 2007-05-31 06:03:16 77,824 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHComm.dll
+ 2007-05-31 06:03:16 110,592 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHrule.dll
+ 2007-05-31 06:03:16 331,776 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHUM.dll
+ 2007-05-31 06:03:16 38,400 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\FSSync.dll
+ 2006-09-20 05:12:14 208,960 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\inv.dll
+ 2007-12-03 20:53:58 282,624 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\kave.dll
+ 2006-12-20 00:13:52 1,093,632 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\libeay32.dll
+ 2007-05-31 06:03:20 548,864 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcp80.dll
+ 2007-05-31 06:03:20 626,688 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcr80.dll
+ 2007-05-31 06:03:18 184,320 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prloader.dll
+ 2007-05-31 06:03:22 90,112 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\prremote.dll
+ 2007-12-03 20:53:58 139,264 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
+ 2006-12-20 00:13:52 200,704 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\ssleay32.dll
+ 2008-04-03 02:07:32 99,816 ----a-w C:\WINDOWS\system32\ZoneLabs\camupd.dll
+ 2004-01-30 18:35:08 813,568 ----a-w C:\WINDOWS\system32\ZoneLabs\dbghelp.dll
+ 2008-04-03 02:07:34 128,480 ----a-w C:\WINDOWS\system32\ZoneLabs\fbl.dll
+ 2008-04-03 02:07:34 38,376 ----a-w C:\WINDOWS\system32\ZoneLabs\featuremap.dll
+ 2008-04-03 02:07:34 321,016 ----a-w C:\WINDOWS\system32\ZoneLabs\imsecure.dll
+ 2008-04-03 02:08:02 288,144 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\ConfigWizard.zip.dll
+ 2008-04-03 02:08:02 152,976 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\licenseui.zip.dll
+ 2008-04-03 02:08:02 26,000 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zlsvc.zip.dll
+ 2008-04-03 02:08:02 1,361,296 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zpy.zip.dll
+ 2008-04-03 02:08:02 71,056 ----a-w C:\WINDOWS\system32\ZoneLabs\lib\zui.zip.dll
+ 2008-04-03 02:09:10 30,184 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\rpc_server\rpc_server.dll
+ 2008-04-03 02:09:12 30,216 ----a-w C:\WINDOWS\system32\ZoneLabs\plugins\vsmon_plugin\vsmon_plugin.dll
+ 2008-02-27 09:10:26 714,208 ----a-w C:\WINDOWS\system32\ZoneLabs\qrbase.dll
+ 2008-02-27 09:10:28 792,032 ----a-w C:\WINDOWS\system32\ZoneLabs\qrsrecl.dll
+ 2008-04-03 02:07:38 173,544 ----a-w C:\WINDOWS\system32\ZoneLabs\scheduler.dll
+ 2008-01-21 14:34:36 7,603,688 ----a-w C:\WINDOWS\system32\ZoneLabs\spyware.dat
+ 2008-02-27 09:10:32 1,504,736 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.dll
+ 2008-02-27 09:10:44 51,176 ----a-w C:\WINDOWS\system32\ZoneLabs\srescan.sys
+ 2008-04-03 02:07:38 456,168 ----a-w C:\WINDOWS\system32\ZoneLabs\ssleay32.dll
+ 2008-04-03 02:09:12 214,528 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
+ 2008-04-03 02:09:14 3,266,040 ----a-w C:\WINDOWS\system32\ZoneLabs\streamapi\imslsp\imslsp.dll
+ 2006-09-05 02:59:14 503,875 ----a-w C:\WINDOWS\system32\ZoneLabs\upd_core.dll
+ 2007-10-11 22:50:32 832,984 ----a-w C:\WINDOWS\system32\ZoneLabs\updating.dll
+ 2008-04-03 02:07:54 144,936 ----a-w C:\WINDOWS\system32\ZoneLabs\updclient.exe
+ 2007-01-11 23:31:06 286,787 ----a-w C:\WINDOWS\system32\ZoneLabs\updtrsdk.dll
+ 2008-04-03 02:07:40 108,008 ----a-w C:\WINDOWS\system32\ZoneLabs\vsavpro.dll
+ 2008-04-03 02:07:40 83,432 ----a-w C:\WINDOWS\system32\ZoneLabs\vsdb.dll
+ 2008-04-03 02:07:54 75,304 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmon.exe
+ 2008-04-03 02:07:40 2,029,032 ----a-w C:\WINDOWS\system32\ZoneLabs\vsmondll.dll
+ 2008-04-03 02:07:42 1,361,384 ----a-w C:\WINDOWS\system32\ZoneLabs\vsruledb.dll
+ 2008-04-03 02:07:42 239,080 ----a-w C:\WINDOWS\system32\ZoneLabs\vsvault.dll
+ 2008-01-21 14:34:36 7,603,688 ----a-w C:\WINDOWS\system32\ZoneLabs\zlasdbup.dat
+ 2008-04-03 02:07:44 177,640 ----a-w C:\WINDOWS\system32\ZoneLabs\zlparser.dll
+ 2008-04-03 02:07:44 79,344 ----a-w C:\WINDOWS\system32\ZoneLabs\zlquarantine.dll
+ 2008-04-03 02:07:46 382,440 ----a-w C:\WINDOWS\system32\ZoneLabs\zlsre.dll
+ 2008-04-03 02:07:46 120,296 ----a-w C:\WINDOWS\system32\ZoneLabs\zlupdate.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0B46DBDF-8C1B-5527-864D-08F21D44C40C}]
2008-04-16 04:09 126976 --a------ C:\WINDOWS\system32\ComGenAct.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C049E76-EDFE-33D1-547B-00E246A03779}]
2008-04-15 19:25 118784 --a------ C:\WINDOWS\system32\admdsccmd.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{58F6A823-E0EB-303C-3841-02D629236E70}]
2008-04-21 02:22 102400 --a------ C:\WINDOWS\system32\smartcmdsh.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6F3E2E2A-4EB7-E8A8-204C-048E2AC9BB3F}]
2008-04-22 01:27 118784 --a------ C:\WINDOWS\system32\SrvAppHlp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent"="E:\Program Files\bittorent\bittorrent.exe" [ ]
"frncpexs"="C:\WINDOWS\system32\ngxwhetq.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 10:27 385024]
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 10:31 356352]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 19:52 483328]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-08-11 18:21 200704]
"ePowerManagement"="C:\Acer\ePM\ePM.exe" [2005-03-15 09:03 2893824]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 16:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 18:51 53248]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-08 10:02 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-08 09:59 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-08 10:03 114688]
"RTHDCPL"="RTHDCPL.EXE" [2005-08-09 14:17 14743552 C:\WINDOWS\RTHDCPL.EXE]
"FaxMonitor"="C:\Program Files\IPFax\FaxMonitor.exe" [2002-01-21 13:45 61440]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 16:57 282624]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2008-01-11 18:54 166304]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-22 16:17 579584]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 21:07 919016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-04-22 16:17 219136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 07:00 53760 C:\WINDOWS\system32\narrator.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"2bjgBMOR31"= C:\Documents and Settings\All Users\Application Data\fuzazgda\jifylylc.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"CheckWeb"= {C111CF13-545F-6FF1-51AC-F623D452C63D} - C:\WINDOWS\system32\cryper.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-10-15 10:27 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13962:TCP"= 13962:TCP:BitComet 13962 TCP
"13962:UDP"= 13962:UDP:BitComet 13962 UDP

R2 EpmPsd;Acer EPM Power Scheme Driver;C:\WINDOWS\system32\drivers\epm-psd.sys [2004-07-19 12:10]
R2 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\drivers\epm-shd.sys [2005-04-07 17:08]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 15:58]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 14:57]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-01-11 18:39]
R2 ZuneBusEnum;Zune Bus Enumerator;C:\WINDOWS\system32\ZuneBusEnum.exe [2008-01-11 18:54]
S2 apcsvra32;apcsvra32;C:\Program Files\Common Files\System\apcsvra.exe []
S3 apcsvra;apcsvra;C:\Program Files\Common Files\System\apcsvra.dll []
S3 Tomcat5;Apache Tomcat;"C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 []
S3 wampapache;wampapache;"c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe" -k runservice []
S3 wampmysqld;wampmysqld;c:\wamp\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe wampmysqld []
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;C:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-01-11 18:54]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{950ea23e-544e-11dc-8494-00c09fcf34df}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-03-01 06:45:00 C:\WINDOWS\Tasks\explorer.job"
- C:\WINDOWS\explorer.scf
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-24 03:43:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-24 3:45:29
ComboFix-quarantined-files.txt 2008-04-24 08:45:10
ComboFix2.txt 2008-04-21 07:34:31
ComboFix3.txt 2008-04-21 06:53:50

Pre-Run: 3,479,789,568 bytes free
Post-Run: 3,649,437,696 bytes free

266

HIJACKTHIS:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:48:11 AM, on 4/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\All Users\Application Data\fuzazgda\jifylylc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\acer\epm\epm-dm.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\IPFax\FaxMonitor.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\regsvr32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0B46DBDF-8C1B-5527-864D-08F21D44C40C} - C:\WINDOWS\system32\ComGenAct.dll
O2 - BHO: (no name) - {1C049E76-EDFE-33D1-547B-00E246A03779} - C:\WINDOWS\system32\admdsccmd.dll
O2 - BHO: (no name) - {58F6A823-E0EB-303C-3841-02D629236E70} - C:\WINDOWS\system32\smartcmdsh.dll
O2 - BHO: (no name) - {6F3E2E2A-4EB7-E8A8-204C-048E2AC9BB3F} - C:\WINDOWS\system32\SrvAppHlp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [FaxMonitor] C:\Program Files\IPFax\FaxMonitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [BitTorrent] "E:\Program Files\bittorent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [frncpexs] C:\WINDOWS\system32\ngxwhetq.exe
O4 - HKLM\..\Policies\Explorer\Run: [2bjgBMOR31] C:\Documents and Settings\All Users\Application Data\fuzazgda\jifylylc.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1202793658718
O16 - DPF: {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_07) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{17B1390D-108C-4B64-B6CF-D67F6816E3CD}: NameServer = 202.179.64.1,202.179.64.2
O21 - SSODL: CheckWeb - {C111CF13-545F-6FF1-51AC-F623D452C63D} - C:\WINDOWS\system32\cryper.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: apcsvra32 - Unknown owner - C:\Program Files\Common Files\System\apcsvra.exe (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.51a\bin\mysqld-nt.exe

--
End of file - 9845 bytes


Thanks and Regards,
silver0808
  • 0

#6
Stamper19

Stamper19

    Expert

  • Expert
  • 1,992 posts
Hi silver0808,

Lets run one more tool and then we'll clean up whateever is left by hand.

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
  • 0

#7
silver0808

silver0808

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi stamper19,
Thank you so much for patiently guiding me through all this.

Regards,
silver0808

Here is the log:

Malwarebytes' Anti-Malware 1.11
Database version: 679

Scan type: Quick Scan
Objects scanned: 33493
Time elapsed: 11 minute(s), 23 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 9
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
C:\Documents and Settings\All Users\Application Data\fuzazgda\jifylylc.exe (Trojan.FakeAlert) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{c111cf13-545f-6ff1-51ac-f623d452c63d} (Spyware.Delf) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\mslagent (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Golden Palace Casino NEW (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\2bjgBMOR31 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\CheckWeb (Spyware.Delf) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\All Users\Application Data\fuzazgda\jifylylc.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\explorer.job (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
  • 0

#8
Stamper19

Stamper19

    Expert

  • Expert
  • 1,992 posts
Hi Silver0808,

Thank you so much for patiently guiding me through all this.


You are very welcome :)
----------------------------------------------------------------

We are going to use ComboFix to delete some things.

  • Copy the entire contents of the Code Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop
File::
C:\WINDOWS\system32\SrvAppHlp.dll
C:\Documents and Settings\All Users\Application Data\xutwzuno.dll
C:\WINDOWS\system32\smartcmdsh.dll
C:\Documents and Settings\All Users\Application Data\nszsfijy.dll
C:\WINDOWS\system32\ComGenAct.dll
C:\Documents and Settings\All Users\Application Data\itidsvgv.dll
C:\WINDOWS\system32\admdsccmd.dll
C:\Documents and Settings\All Users\Application Data\zuzebqfa.dll

Folder::
C:\Documents and Settings\All Users\Application Data\fuzazgda

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0B46DBDF-8C1B-5527-864D-08F21D44C40C}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C049E76-EDFE-33D1-547B-00E246A03779}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{58F6A823-E0EB-303C-3841-02D629236E70}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"frncpexs"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"2bjgBMOR31"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"CheckWeb"=-

Posted Image

Once saved, refering to the picture above, drag CFScript.txt into ComboFix.exe, and post back the resulting report.

----------------------------------------------------------------

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

----------------------------------------------------------------

Information to include in your next post:
  • ComboFix Log
  • Kapersky Scan Log

  • 0

#9
silver0808

silver0808

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
HI Stamper19,

Here are the logs you asked for..

Thanks and regards,
silver0808

Combofix:
ComboFix 08-04-20.2 - Dhiraj Jadhav 2008-04-25 17:10:01.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.150 [GMT -5:00]
Running from: C:\Documents and Settings\Dhiraj Jadhav\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dhiraj Jadhav\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\All Users\Application Data\itidsvgv.dll
C:\Documents and Settings\All Users\Application Data\nszsfijy.dll
C:\Documents and Settings\All Users\Application Data\xutwzuno.dll
C:\Documents and Settings\All Users\Application Data\zuzebqfa.dll
C:\WINDOWS\system32\admdsccmd.dll
C:\WINDOWS\system32\ComGenAct.dll
C:\WINDOWS\system32\smartcmdsh.dll
C:\WINDOWS\system32\SrvAppHlp.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\fuzazgda
C:\Documents and Settings\All Users\Application Data\itidsvgv.dll
C:\Documents and Settings\All Users\Application Data\nszsfijy.dll
C:\Documents and Settings\All Users\Application Data\xutwzuno.dll
C:\Documents and Settings\All Users\Application Data\zuzebqfa.dll
C:\WINDOWS\system32\admdsccmd.dll
C:\WINDOWS\system32\ComGenAct.dll
C:\WINDOWS\system32\smartcmdsh.dll
C:\WINDOWS\system32\SrvAppHlp.dll

.
((((((((((((((((((((((((( Files Created from 2008-03-25 to 2008-04-25 )))))))))))))))))))))))))))))))
.

2008-04-25 00:46 . 2008-04-25 07:46 <DIR> d-------- C:\Program Files\Opera
2008-04-24 23:51 . 2008-04-24 23:51 <DIR> d-------- C:\Documents and Settings\Dhiraj Jadhav\Application Data\Malwarebytes
2008-04-24 23:50 . 2008-04-24 23:50 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-24 23:50 . 2008-04-24 23:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-23 06:03 . 2008-04-23 06:03 <DIR> d-------- C:\VundoFix Backups
2008-04-23 05:30 . 2008-04-25 17:13 753,696 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-23 05:30 . 2008-04-25 08:14 12,680 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-23 05:23 . 2008-04-23 05:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-04-23 05:23 . 2008-04-02 21:07 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-04-23 05:23 . 2004-04-27 05:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-04-23 05:23 . 2008-04-23 05:27 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-04-23 05:21 . 2008-04-23 05:23 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-04-23 05:21 . 2008-04-23 05:21 <DIR> d-------- C:\Program Files\Zone Labs
2008-04-23 05:21 . 2008-04-02 21:07 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2008-04-23 05:21 . 2008-04-25 16:52 352,918 --a------ C:\WINDOWS\system32\vsconfig.xml
2008-04-23 05:04 . 2008-04-25 17:05 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-04-22 16:26 . 2008-04-22 18:15 <DIR> dr-h----- C:\$VAULT$.AVG
2008-04-22 16:18 . 2008-04-22 16:18 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-22 16:18 . 2008-04-22 16:32 <DIR> d-------- C:\Documents and Settings\Dhiraj Jadhav\Application Data\AVG7
2008-04-22 16:17 . 2008-04-22 16:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-22 16:17 . 2008-04-22 16:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-22 01:46 . 2008-04-22 01:46 <DIR> d-------- C:\Deckard
2008-04-21 02:21 . 2008-04-21 02:21 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-14 00:55 . 2008-04-14 00:55 <DIR> d-------- C:\Program Files\11view
2008-04-14 00:34 . 2008-04-14 00:34 <DIR> d-------- C:\Documents and Settings\Dhiraj Jadhav\Application Data\Flickr
2008-04-14 00:32 . 2008-04-14 01:25 <DIR> d-------- C:\Program Files\Flickr Uploadr
2008-04-08 04:49 . 2008-04-08 04:49 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-04-08 04:49 . 2004-08-04 07:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-08 01:47 . 2008-04-22 16:14 <DIR> d-------- C:\Program Files\BitComet
2008-04-08 01:47 . 2008-04-10 19:08 <DIR> d-------- C:\Downloads
2008-04-05 03:55 . 2008-04-05 03:55 0 --a------ C:\WINDOWS\system32\lich.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-22 22:16 --------- d-----w C:\Documents and Settings\Dhiraj Jadhav\Application Data\dvdcss
2008-04-16 08:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-10 23:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-10 23:50 --------- d-----w C:\Program Files\Crimson Editor
2008-04-08 07:32 --------- d-----w C:\Documents and Settings\Dhiraj Jadhav\Application Data\BitTorrent
2008-03-28 08:15 --------- d-----w C:\Program Files\Mp3 My Mp3 2.0
2008-03-23 08:11 --------- d-----w C:\Documents and Settings\Dhiraj Jadhav\Application Data\phpDesigner 2008
2008-03-23 07:48 --------- d-----w C:\Program Files\Swapper
2008-03-23 07:48 --------- d-----w C:\Program Files\PHP
2008-03-23 07:39 --------- d-----w C:\Program Files\Java
2008-03-23 07:19 --------- d-----w C:\Program Files\MySQL
2008-03-23 05:59 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-03-23 05:59 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-03-23 05:59 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-03-20 07:23 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Intel
2008-03-17 09:03 --------- d-----w C:\Program Files\DivX
2008-03-17 08:46 --------- d-----w C:\Documents and Settings\Dhiraj Jadhav\Application Data\.Torrent Swapper
2008-03-05 08:20 --------- d-----w C:\Program Files\Real
2008-03-04 23:10 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-03 09:43 --------- d-----w C:\Program Files\Audacity
2008-03-02 21:10 --------- d-----w C:\Program Files\Google
2008-02-21 02:05 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-02-21 02:05 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-02-21 02:03 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-21 02:03 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-08-05 09:21 88 ----a-w C:\Documents and Settings\Dhiraj Jadhav\tomstart.bat
2007-06-03 13:35 60 ----a-w C:\Documents and Settings\Dhiraj Jadhav\ip.bat
2005-07-29 20:24 472 --sha-r C:\WINDOWS\RGhpcmFqIEIgSmFkaGF2\l31DwAINKHK0mAI4u3IZ.vbs
.

((((((((((((((((((((((((((((( snapshot_2008-04-24_ 3.44.42.75 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-24 07:37:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-25 21:51:53 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent"="E:\Program Files\bittorent\bittorrent.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 10:27 385024]
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 10:31 356352]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 19:52 483328]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-08-11 18:21 200704]
"ePowerManagement"="C:\Acer\ePM\ePM.exe" [2005-03-15 09:03 2893824]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 16:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 18:51 53248]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-08 10:02 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-08 09:59 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-08 10:03 114688]
"RTHDCPL"="RTHDCPL.EXE" [2005-08-09 14:17 14743552 C:\WINDOWS\RTHDCPL.EXE]
"FaxMonitor"="C:\Program Files\IPFax\FaxMonitor.exe" [2002-01-21 13:45 61440]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 16:57 282624]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2008-01-11 18:54 166304]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-22 16:17 579584]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 21:07 919016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-04-22 16:17 219136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 07:00 53760 C:\WINDOWS\system32\narrator.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-10-15 10:27 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13962:TCP"= 13962:TCP:BitComet 13962 TCP
"13962:UDP"= 13962:UDP:BitComet 13962 UDP

R2 EpmPsd;Acer EPM Power Scheme Driver;C:\WINDOWS\system32\drivers\epm-psd.sys [2004-07-19 12:10]
R2 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\drivers\epm-shd.sys [2005-04-07 17:08]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 15:58]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 14:57]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-01-11 18:39]
R2 ZuneBusEnum;Zune Bus Enumerator;C:\WINDOWS\system32\ZuneBusEnum.exe [2008-01-11 18:54]
S2 apcsvra32;apcsvra32;C:\Program Files\Common Files\System\apcsvra.exe []
S3 apcsvra;apcsvra;C:\Program Files\Common Files\System\apcsvra.dll []
S3 Tomcat5;Apache Tomcat;"C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 []
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;C:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-01-11 18:54]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{950ea23e-544e-11dc-8494-00c09fcf34df}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-25 17:13:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-25 17:14:40
ComboFix-quarantined-files.txt 2008-04-25 22:14:28
ComboFix2.txt 2008-04-24 08:45:32
ComboFix3.txt 2008-04-21 07:34:31
ComboFix4.txt 2008-04-21 06:53:50

Pre-Run: 3,498,958,848 bytes free
Post-Run: 3,725,963,264 bytes free

189



Kaspersky:
KASPERSKY ONLINE SCANNER REPORT
Saturday, April 26, 2008 2:02:59 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/04/2008
Kaspersky Anti-Virus database records: 725571
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
F:\
Scan Statistics
Total number of scanned objects 58509
Number of viruses found 3
Number of infected objects 9
Number of suspicious objects 0
Duration of the scan process 02:48:30

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Mozilla\Firefox\Profiles\5exxuhst.default\cert8.db Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Mozilla\Firefox\Profiles\5exxuhst.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Mozilla\Firefox\Profiles\5exxuhst.default\history.dat Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Mozilla\Firefox\Profiles\5exxuhst.default\key3.db Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Mozilla\Firefox\Profiles\5exxuhst.default\parent.lock Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Mozilla\Firefox\Profiles\5exxuhst.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Mozilla\Firefox\Profiles\5exxuhst.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-2afc8601-67e751ac.zip/vmain.class Infected: Exploit.Java.Gimsh.b skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-2afc8601-67e751ac.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-6ca1606f.zip/vmain.class Infected: Exploit.Java.Gimsh.b skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-6ca1606f.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-b825669-1e6b17b9.zip/vmain.class Infected: Exploit.Java.Gimsh.b skipped
C:\Documents and Settings\Dhiraj Jadhav\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-b825669-1e6b17b9.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Dhiraj Jadhav\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Local Settings\Application Data\Mozilla\Firefox\Profiles\5exxuhst.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Local Settings\Application Data\Mozilla\Firefox\Profiles\5exxuhst.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Local Settings\Application Data\Mozilla\Firefox\Profiles\5exxuhst.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Local Settings\Application Data\Mozilla\Firefox\Profiles\5exxuhst.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Local Settings\Application Data\Mozilla\Firefox\Profiles\5exxuhst.default\XUL.mfl Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Dhiraj Jadhav\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\Web\def.htm.vir Infected: not-virus:Hoax.HTML.Secureinvites.c skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Tempo\ZLT07d66.TMP Object is locked skipped
C:\Tempo\ZLT07d69.TMP Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\Internet Logs\VV-BF8856B926C9.ldb Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{C9B7CCEF-8392-44FB-91AC-86BE0F0C4207}\RP1\A0000790.exe Object is locked skipped
E:\RECYCLER\S-1-5-21-436374069-1292428093-725345543-1004\De1.exe/file10 Infected: not-a-virus:AdWare.Win32.MyWay.ac skipped
E:\RECYCLER\S-1-5-21-436374069-1292428093-725345543-1004\De1.exe Inno: infected - 1 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
  • 0

#10
Stamper19

Stamper19

    Expert

  • Expert
  • 1,992 posts
Hi Silver0808,

Looking better. We've still a couple of things to clean up.

----------------------------------------------------------------

Please clean out your temp files.

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

----------------------------------------------------------------

Lets clean out your Java cache

Clearing Cache
  • Go to Start > Control Panel double-click on the Java Icon (coffee cup) in the Control Panel.
  • It will say "Java Plug-in" under the icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.

----------------------------------------------------------------

How is the computer running?
  • 0

#11
silver0808

silver0808

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi Stamper19,
With all your guidance the computer seems to be working great.
Is there anything else that I would need to do. Please let me know.

Thanks and regards,
silver0808
  • 0

#12
Stamper19

Stamper19

    Expert

  • Expert
  • 1,992 posts
Hi silver0808,

Congrats - your logs are all clean :)

There are still a couple of things you should do for the sake of cleaning up.

---------------------------------------------------------------

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK


    • Posted Image

  • When shown the disclaimer, Select "2"

The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.
----------------------------------------------------------------

Otherwise, unless you have any questions, you are all set. Included below are some tips for keeping your computer malware free in the future.

Cheers,
Stamper :)

----------------------------------------------------------------

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

here are some additional utilities that will enhance your safety

  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
  • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
    Using Winpatrol to protect your computer from malicious software

  • 0

#13
Stamper19

Stamper19

    Expert

  • Expert
  • 1,992 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP