Hi there,
Welcome to GeeksToGo. My name is RatHat, and I will help you get through the process of cleaning the malware from your computer.
OK firstly, I need you to print out each post I make so that you can refer to it while we fix your computer. This is because there will be times when you are unable to be online to read my instructions, and I will want you to do everything very carefully. I also need you to follow my instructions in the order that they are given. If however, you cannot carry out one of them, please continue on with the next and let me know what you were unsuccessful with. Please ensure you turn off word wrap in Notepad. To do this, open Notepad, choose Format, then Un-check Word Wrap. (Word Wrap makes reading your log difficult).
Next, I would like to make sure that you can view hidden files and folders;
- Click Start.
- Open My Computer.
- Select the Tools menu and click Folder Options.
- Select the View tab.
- Under the Hidden files and folders heading SELECT Show hidden files and folders.
- UNCHECK the Hide protected operating system files (recommended) option.
- UNCHECK the Hide extensions for known file types option.
- Click Yes to confirm.
- Click OK.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please uninstall the following programs:Limewire, and any other P2P programs you currently have installed.
- Go to Start then Settings, then Control Panel
- Choose Add or Remove Programs
- Remove all of the above
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please read this Combofix tutorial before continuing, then follow the instructions below.
Please ensure you read this guide carefully and install the Recovery Console first.
Next, download ComboFix from Here or Here to your Desktop.
Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System.
Download the file & save it as it's originally named, next to ComboFix.exe.
Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.
The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
Once installed, you should see a blue screen prompt that says:
The Recovery Console was successfully installed.
Please continue as follows:
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
- Click Yes to allow ComboFix to continue scanning for malware.
When the tool is finished, it will produce a report for you. Save this log to your desktop as Combofix.txt and post it in your next reply.
(Note: Combofix will also save the report to C:\Combofix.txt)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please download Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.- Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select "Perform Quick Scan", then click Scan.
- The scan may take some time to finish,so please be patient.
- When the scan is complete, click OK, then Show Results to view the results.
- Make sure that everything is checked, and click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please run an online scan with Kaspersky WebScanner. Note: You must use Internet Explorer to run this scan.
Click the Accept button.
You will be promted to install an ActiveX component from Kaspersky, Click Yes.- The program will launch and then begin downloading the latest definition files:
- Once the files have been downloaded click on NEXT
- Now click on Scan Settings
- In the scan settings make that the following are selected:
- Scan using the following Anti-Virus database:
Extended (if available otherwise Standard)
Scan Archives
Scan Mail Bases - Click OK
- Now under select a target to scan:Select My Computer
- This will program will start and scan your system.
- The scan will take a while so be patient and let it run.
- Once the scan is complete it will display the results if your system has been infected.
- Now click on the Save as Text button:
- Save the file to your desktop as Kaspersky.txt.
- Copy and paste that information in your next post.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
So in your next reply, please include the following logs:- The contents of Combofix.txt
- The contents of the MBAM log
- The contents of Kaspersky.txt
Note that you may have to split your replies into two or three posts to ensure that the logs are complete.
Finally, please let me know about Kamus 3000. Is it a cracked copy, as if so it could be infected.
Regards,
RatHat
Thank`s RatHat
After follow for ur instruction this`s my result combofix..
so what ur recommend anti virus can I use ..I`mean anti virus friendly user....
thank`s
ComboFix 08-05-25.4 - Azam 2008-05-26 22:48:56.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.57 [GMT 8:00]
Running from: C:\Documents and Settings\Azam\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Azam\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\network monitor
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\BM2b1af081.xml
C:\WINDOWS\Fonts\'
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\pskt.ini
C:\WINDOWS\QXphbQ\
C:\WINDOWS\system32\jkkHYoPI.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\omxvyyrg.ini
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\VDMVwGgh.ini
C:\WINDOWS\system32\VDMVwGgh.ini2
C:\WINDOWS\system32\xsbvntxq.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
-------\Legacy_NETWORK_MONITOR
-------\Service_cmdService
-------\Service_Network Monitor
((((((((((((((((((((((((( Files Created from 2008-04-26 to 2008-05-26 )))))))))))))))))))))))))))))))
.
2008-05-26 22:02 . 2008-05-26 22:02 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-05-26 22:02 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-05-26 22:01 . 2008-05-26 22:01 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\TuneUp Software
2008-05-26 22:00 . 2008-05-26 22:01 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
2008-05-26 22:00 . 2008-05-26 22:00 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\TuneUp Software
2008-05-26 21:51 . 2008-05-26 21:51 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-26 11:53 . 2008-05-26 11:53 14 --a------ C:\WINDOWS\popcinfo.dat
2008-05-26 11:33 . 2008-05-26 11:33 111,544 --a------ C:\WINDOWS\system32\nnnoMCRK.dll
2008-05-25 22:43 . 2008-05-25 22:44 <DIR> d-------- C:\490f3b84eff4163aa2f9
2008-05-25 12:00 . 2008-05-25 12:27 117,548 --a------ C:\WINDOWS\hpoins11.dat
2008-05-25 11:37 . 2008-05-25 11:37 <DIR> d-------- C:\WINDOWS\system\IOSUBSYS
2008-05-25 11:35 . 2008-05-25 11:35 <DIR> d-------- C:\Program Files\Uniblue
2008-05-25 10:52 . 2008-05-25 10:52 <DIR> d-------- C:\Program Files\Acesoft
2008-05-25 10:52 . 2007-01-23 00:43 277,504 --a------ C:\WINDOWS\system32\oestore.dll
2008-05-25 10:52 . 2004-03-09 00:00 224,016 --a------ C:\WINDOWS\system32\TabCtl32.ocx
2008-05-25 10:39 . 2008-05-25 10:39 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\Uniblue
2008-05-25 10:34 . 2006-08-01 15:02 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-05-25 10:31 . 2008-05-25 10:31 <DIR> d-------- C:\Program Files\Realtek AC97
2008-05-25 10:31 . 2006-12-08 15:20 10,528,768 --a------ C:\WINDOWS\system32\RTLCPL.exe
2008-05-25 10:30 . 2006-10-18 02:53 147,456 --a------ C:\WINDOWS\system32\RtlCPAPI.dll
2008-05-25 10:27 . 2008-05-25 11:52 88,224 --a------ C:\WINDOWS\system32\nvapps.nvb
2008-05-25 10:26 . 2006-10-22 15:06 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-05-25 10:25 . 2008-05-25 10:25 <DIR> d-------- C:\NVIDIA
2008-05-25 09:45 . 2008-05-25 09:46 <DIR> d-------- C:\HJT
2008-05-25 09:14 . 2008-05-25 09:14 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-05-25 09:13 . 2008-05-25 09:13 <DIR> d-------- C:\WINDOWS\Sun
2008-05-25 09:13 . 2008-05-25 09:13 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\SystemRequirementsLab
2008-05-25 08:53 . 2008-05-25 08:53 <DIR> d-------- C:\Program Files\XPC Tools
2008-05-24 01:13 . 2008-05-25 11:58 <DIR> d-------- C:\Program Files\XP Repair Pro 2007
2008-05-24 01:07 . 2008-05-24 01:07 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Ashampoo
2008-05-24 01:06 . 2008-05-24 01:06 <DIR> d-------- C:\Program Files\Ashampoo
2008-05-23 23:57 . 2008-05-23 23:57 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-05-23 23:54 . 2008-05-23 23:54 <DIR> d-------- C:\Program Files\Real
2008-05-23 23:54 . 2008-05-23 23:56 <DIR> d-------- C:\Program Files\Common Files\Real
2008-05-23 00:59 . 2008-05-23 00:59 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\DivX
2008-05-23 00:55 . 2008-05-23 00:56 <DIR> d-------- C:\Program Files\DivX
2008-05-22 23:52 . 2008-05-22 23:53 374,272 --a------ C:\WINDOWS\system32\jkkLDTkl.dll
2008-05-21 22:42 . 2008-05-21 22:42 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-05-21 22:42 . 2008-01-10 13:15 755,027 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-05-21 22:42 . 2007-09-04 17:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2008-05-21 20:00 . 2008-05-26 11:55 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\U3
2008-05-21 19:20 . 2008-05-21 19:20 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\AdobeUM
2008-05-21 18:01 . 2008-05-21 18:16 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\Image Zone Express
2008-05-21 16:43 . 2008-05-18 02:31 117,644 --------- C:\WINDOWS\hpoins11.dat.temp
2008-05-21 16:43 . 2006-05-05 18:10 11,634 --------- C:\WINDOWS\hpomdl11.dat.temp
2008-05-20 22:26 . 2004-08-04 20:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-05-20 22:18 . 2004-08-04 00:56 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2008-05-20 21:24 . 2008-05-20 21:24 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-05-20 21:21 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\
000001_.tmp
2008-05-19 16:07 . 2008-05-19 16:07 <DIR> d-------- C:\Program Files\Alwil Software
2008-05-19 15:40 . 2008-05-19 15:40 45,568 --a------ C:\WINDOWS\system32\avgfwdx.dll
2008-05-19 15:40 . 2008-05-19 15:40 22,528 --a------ C:\WINDOWS\system32\drivers\avgfwdx.sys
2008-05-19 15:27 . 2008-05-19 15:27 687,592 --a------ C:\WINDOWS\system32\atmtd.dll._
2008-05-19 15:27 . 2008-05-19 15:27 687,592 --a------ C:\WINDOWS\system32\atmtd.dll
2008-05-19 15:25 . 2006-01-03 17:45 1,989 --a------ C:\WINDOWS\uninstall_nmon.vbs
2008-05-19 15:24 . 2008-05-19 15:24 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-05-19 15:22 . 2008-05-19 16:27 <DIR> d-------- C:\WINDOWS\system32\zDB
2008-05-19 15:22 . 2008-05-19 15:23 <DIR> d-------- C:\WINDOWS\system32\cs5
2008-05-19 15:21 . 2008-05-19 15:21 <DIR> d-------- C:\WINDOWS\system32\logXv18
2008-05-19 15:21 . 2008-05-19 15:22 <DIR> d-------- C:\Temp\dmpxp32
2008-05-19 15:21 . 2008-05-26 22:49 <DIR> d-------- C:\Temp
2008-05-19 15:21 . 2008-05-19 15:21 86,016 ---hs---- C:\Documents and Settings\Azam\lsass.exe
2008-05-19 06:28 . 2008-05-19 06:29 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-05-19 06:18 . 2008-05-26 21:30 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\LimeWire
2008-05-19 06:13 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-19 06:10 . 2008-05-19 06:13 <DIR> d-------- C:\Program Files\Java
2008-05-19 06:06 . 2008-05-19 06:06 <DIR> d-------- C:\Program Files\Common Files\Java
2008-05-19 06:00 . 2008-05-19 06:00 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\Yahoo!
2008-05-19 06:00 . 2008-05-19 06:00 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2008-05-19 05:48 . 2008-05-26 22:35 <DIR> d-------- C:\Program Files\LimeWire
2008-05-19 03:28 . 2008-05-19 03:28 <DIR> d-------- C:\Program Files\The Name Technology
2008-05-19 03:28 . 2003-08-05 15:21 268,800 --a------ C:\WINDOWS\system32\KamusDialog.dll
2008-05-19 03:28 . 2003-08-06 09:18 199,168 --a------ C:\WINDOWS\system32\dictchk.dll
2008-05-19 03:28 . 2003-01-27 10:59 174,592 --a------ C:\WINDOWS\system32\KamusAnw.dll
2008-05-19 03:28 . 1999-05-07 00:00 140,288 --a------ C:\WINDOWS\system32\ComDlg32.ocx
2008-05-19 03:28 . 2008-05-21 00:28 18 --a------ C:\WINDOWS\krwin.dat
2008-05-19 02:06 . 2008-05-19 02:06 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\Abexo
2008-05-19 00:49 . 2008-05-19 01:00 <DIR> d-------- C:\Program Files\XoftSpySE
2008-05-19 00:08 . 2008-05-19 00:10 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\Antispyware
2008-05-18 23:58 . 2008-05-19 02:19 <DIR> d-------- C:\Program Files\Ares Destiny
2008-05-18 03:19 . 2008-05-21 19:13 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-05-18 03:16 . 2008-05-19 02:06 <DIR> d-------- C:\Program Files\Abexo
2008-05-18 02:43 . 2008-05-18 02:43 1,160 --a------ C:\WINDOWS\mozver.dat
2008-05-18 02:32 . 2008-05-19 06:08 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\AVGTOOLBAR
2008-05-18 02:30 . 2008-05-21 19:06 <DIR> d-------- C:\Documents and Settings\Azam\Application Data\HP
2008-05-18 02:30 . 2008-05-18 02:30 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\HP
2008-05-18 02:29 . 2008-05-24 17:22 <DIR> d-------- C:\Program Files\Common Files\HP
2008-05-18 02:28 . 2008-05-18 02:28 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-05-18 02:27 . 2006-04-10 14:03 48,128 --a------ C:\WINDOWS\system32\hpzll054.dll
2008-05-18 02:27 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-05-18 02:27 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-05-18 02:25 . 2006-03-03 21:03 282,680 --a------ C:\WINDOWS\system32\HPZidr12.dll
2008-05-18 02:25 . 2006-03-03 21:02 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
2008-05-18 02:25 . 2006-03-03 21:02 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
2008-05-18 02:25 . 2006-03-03 21:03 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe
2008-05-18 02:25 . 2006-03-03 21:03 65,536 --a------ C:\WINDOWS\system32\HPZinw12.exe
2008-05-18 02:25 . 2006-03-03 21:02 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
2008-05-18 02:24 . 2008-05-18 02:27 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo!
2008-05-18 02:24 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-05-18 02:24 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-05-18 02:22 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-05-18 02:22 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-05-18 02:21 . 2008-05-25 12:13 <DIR> d-------- C:\Program Files\HP
2008-05-18 02:21 . 2008-05-18 02:29 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-05-18 02:20 . 2008-05-18 02:22 211,976 --a------ C:\WINDOWS\hpdj3500.his
2008-05-18 02:20 . 2008-05-18 02:22 10,509 --a------ C:\WINDOWS\hpdj3500.ini
2008-05-18 02:18 . 2008-05-18 02:22 <DIR> d-------- C:\Program Files\Yahoo!
2008-05-18 02:18 . 2008-05-18 02:18 <DIR> d-------- C:\Program Files\CCleaner
2008-05-18 02:06 . 2008-05-18 02:06 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-18 00:59 . 2008-05-18 00:59 21,640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-18 00:59 . 2008-05-18 00:59 37 --a------ C:\WINDOWS\vbaddin.ini
2008-05-18 00:59 . 2008-05-18 00:59 36 --a------ C:\WINDOWS\vb.ini
2008-05-18 00:58 . 2008-05-18 00:58 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-05-18 00:57 . 2004-08-03 23:01 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2008-05-18 00:57 . 2004-08-04 01:01 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2008-05-13 09:53 . 2008-05-13 09:53 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-05-13 09:53 . 2008-05-13 09:53 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2008-05-13 09:53 . 2008-05-13 09:53 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2008-05-13 09:51 . 2008-05-13 09:51 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-05-13 09:51 . 2008-05-13 09:51 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2008-05-13 09:49 . 2008-05-13 09:49 630,784 --a------ C:\WINDOWS\system32\divxdec.ax
2008-05-13 09:49 . 2008-05-13 09:49 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
2008-05-13 09:49 . 2008-05-13 09:49 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-13 09:49 . 2008-05-13 09:49 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-01 16:59 . 2006-04-12 18:02 659,456 --a------ C:\WINDOWS\system32\hpowiax2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-26 14:44 --------- d-----w C:\Documents and Settings\Azam\Application Data\DMCache
2008-05-18 19:27 146 ----a-w C:\Program Files\INSTALL.LOG
2008-05-18 15:41 --------- d-----w C:\Documents and Settings\Azam\Application Data\IDM
2008-05-17 18:39 --------- d-----w C:\Program Files\Internet Download Manager
2008-05-17 17:53 --------- d-----w C:\Program Files\MSXML 6.0
2008-05-17 17:52 --------- d-----w C:\Program Files\MSXML 4.0
2008-05-17 17:47 --------- d-----w C:\Program Files\Microsoft.NET
2008-05-17 17:47 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-05-17 17:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-17 17:36 --------- d-----w C:\Program Files\Silicon Integrated Systems
2008-05-17 17:35 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-17 17:34 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-05-17 17:34 --------- d-----w C:\Program Files\AvRack
2008-05-17 17:28 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\nView_Profiles
2008-05-17 17:04 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-13 01:53 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-05-13 01:53 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-05-13 01:53 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-05-13 01:53 129,784 ----a-w C:\WINDOWS\system32\pxafs.dll
2008-05-13 01:53 120,056 ----a-w C:\WINDOWS\system32\pxcpyi64.exe
2008-05-13 01:53 118,520 ----a-w C:\WINDOWS\system32\pxinsi64.exe
2008-03-26 08:09 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-25 02:20 219,936 ----a-w C:\WINDOWS\system32\msltus40.dll
2008-03-19 09:40 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:03 827,392 ----a-w C:\WINDOWS\system32\wininet.dll
.
------- Sigcheck -------
2004-08-04 00:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\ServicePackFiles\i386\user32.dll
2007-05-24 16:51 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\system32\user32.dll
2007-05-24 16:51 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\system32\dllcache\user32.dll
2007-05-24 16:51 823296 b8f4db39ca7353752f245379d285c80e C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll
2004-08-04 00:56 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\ServicePackFiles\i386\wininet.dll
2008-03-01 21:06 826368 ad21461aef8244edec2ef18e55e1dcf3 C:\WINDOWS\SoftwareDistribution\Download\ceba12074e2ee6f2478e27a2b926a276\SP2GDR\wininet.dll
2008-03-01 21:03 827392 6316c2f0c61271c8abdff7429174879e C:\WINDOWS\SoftwareDistribution\Download\ceba12074e2ee6f2478e27a2b926a276\SP2QFE\wininet.dll
2008-03-01 21:03 827392 6316c2f0c61271c8abdff7429174879e C:\WINDOWS\system32\wininet.dll
2008-03-01 21:03 827392 6316c2f0c61271c8abdff7429174879e C:\WINDOWS\system32\dllcache\wininet.dll
2007-05-24 16:50 360704 e6b15bcc470953e600ef7aded3cab142 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2007-10-31 01:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\SoftwareDistribution\Download\146ae5e7b51a37f45e0e5cf03d0d5e3c\SP2GDR\tcpip.sys
2007-10-31 00:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\SoftwareDistribution\Download\146ae5e7b51a37f45e0e5cf03d0d5e3c\SP2QFE\tcpip.sys
2007-10-31 00:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-31 00:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\system32\drivers\tcpip.sys
2004-08-03 22:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2007-05-24 16:58 2017280 2dfb215e291e3d9b1cf9a6739b3bf16c C:\WINDOWS\system32\ntkrnlpa.exe
2004-08-03 23:20 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2007-05-24 16:50 2137600 e6679c3023b17d8b78946bc5df53fa20 C:\WINDOWS\system32\ntoskrnl.exe
2007-06-13 19:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\explorer.exe
2007-05-24 16:49 1033216 42d32722b805d7df42d30487a0bcbd78 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2004-08-04 00:56 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2007-06-13 18:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\SP2GDR\explorer.exe
2007-06-13 19:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\SP2QFE\explorer.exe
2007-06-13 19:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2007-12-21 07:08 931760]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2008-05-05 12:22 1923352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DefragTaskBar"="C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe" [2007-02-12 12:57 168120]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 20:00 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="regsvr32 /s /n /i:u shell32" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
antiwpa.dll 2006-07-23 06:49 5376 C:\WINDOWS\system32\antiwpa.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
"Uniblue RegistryBooster 2"=C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
"Tracks Eraser Pro"=C:\Program Files\Acesoft\Tracks Eraser Pro\te.exe min
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
"Kamus 3000"=C:\Program Files\The Name Technology\Kamus 3000\Kamus3000.exe
"LSA Shellu"=C:\Documents and Settings\Azam\lsass.exe
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
"nwiz"=nwiz.exe /install
"SoundMan"=SOUNDMAN.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 07:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 07:16]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 20:00]
S3 Avgfwdx;Avgfwdx;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-05-19 15:40]
S3 Avgfwfd;AVG network filter service;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-05-19 15:40]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-26 22:02]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\Auto\command - H:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b15f2c2-2a35-11dd-8b4e-000d879b1443}]
\Shell\Auto\command - G:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8932dc0b-2a0f-11dd-8b4d-000d879b1443}]
\Shell\Auto\command - I:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e4a5948a-2435-11dd-8b26-000d879b1443}]
\Shell\Auto\command - G:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e4a5948b-2435-11dd-8b26-000d879b1443}]
\Shell\Auto\command - H:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-05-26 14:55:01 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-05-26 14:55:04 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2008-05-18 16:49:54 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-26 22:55:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2008-05-26 23:00:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-26 14:59:58
Pre-Run: 33,226,113,024 bytes free
Post-Run: 33,317,134,336 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
340 --- E O F --- 2008-05-26 13:55:08
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~
MBAM
Logs in MBAM.
Malwarebytes' Anti-Malware 1.12
Database version: 788
Scan type: Quick Scan
Objects scanned: 38250
Time elapsed: 4 minute(s), 29 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\antiwpa.dll (Malware.Tool) -> Unloaded module successfully.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\antiwpa (Malware.Tool) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\XPRepairPro2007 (Rogue.XPRepairPro2007) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\atmtd.dll (Adware.TargetSaver) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\atmtd.dll._ (Adware.TargetSaver) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nnnoMCRK.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\uninstall_nmon.vbs (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\antiwpa.dll (Malware.Tool) -> Delete on reboot.
C:\WINDOWS\system32\jkkLDTkl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Azam\lsass.exe (Trojan.Agent) -> Quarantined and deleted successfully.
kaspersky scan online submit u later coz this scan take time bout 1 or 2 hours...
Edited by Norazam, 26 May 2008 - 12:06 PM.