Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

It started as WinSpyware there [RESOLVED]


  • This topic is locked This topic is locked

#16
☼ Klutz ☼

☼ Klutz ☼

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
Here is the combofix log:

ComboFix 08-05-27.4 - Jim 2008-05-28 13:42:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2151 [GMT -4:00]
Running from: C:\Documents and Settings\Jim\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Adsl Software Limited
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\LOG\20080527185644703.log
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\LOG\20080527191717078.log
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\LOG\20080527192406328.log
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\LOG\20080527201101890.log
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\LOG\20080527202831265.log
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\LOG\20080528032006203.log
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\LOG\20080528033738031.log
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe
C:\Documents and Settings\Jim\Favorites\Error Cleaner.url
C:\Documents and Settings\Jim\Favorites\Privacy Protector.url
C:\Documents and Settings\Jim\Favorites\Spyware&Malware Protection.url
C:\WINDOWS\atfxqogp.dll
C:\WINDOWS\boqnrwdmmfv.dll
C:\WINDOWS\egao.exe
C:\WINDOWS\system32\BLUxyGgh.ini
C:\WINDOWS\system32\BLUxyGgh.ini2
C:\WINDOWS\system32\hgGyxULB.dll
C:\WINDOWS\vltdfabw.dll
C:\WINDOWS\xmpstean.exe

.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-28 )))))))))))))))))))))))))))))))
.

2008-05-28 03:49 . 2008-05-28 03:50 1,463,856 --a------ C:\SDFix.exe
2008-05-27 20:32 . 2008-05-27 20:32 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-27 19:57 . 2008-05-27 19:57 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-27 19:57 . 2008-05-28 13:39 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-27 19:57 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-05-27 19:30 . 2008-05-27 19:30 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-27 19:17 . 2008-05-27 20:10 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\TmpRecentIcons
2008-05-27 19:06 . 2008-05-27 19:07 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-05-27 19:06 . 2008-05-27 20:06 <DIR> d-------- C:\Documents and Settings\Jim\.housecall6.6
2008-05-27 19:02 . 2008-05-27 19:02 <DIR> d-------- C:\VundoFix Backups
2008-05-27 18:16 . 2007-02-20 16:04 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2008-05-27 18:16 . 2007-02-20 16:04 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-05-27 18:07 . 2008-05-27 18:07 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-27 17:57 . 2008-05-28 04:14 <DIR> d-------- C:\Program Files\DAEMON Tools Pro
2008-05-27 17:51 . 2008-05-27 17:56 37,888 --a------ C:\WINDOWS\system32\rar.exe
2008-05-27 17:50 . 2008-05-27 17:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2008-05-26 01:13 . 2008-05-26 01:13 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\FFSJ
2008-05-20 18:05 . 2004-01-07 17:04 339,488 --a------ C:\WINDOWS\system32\drivers\WUSB20XP.sys
2008-05-03 23:55 . 2008-05-03 23:55 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\dvdcss
2008-05-03 22:50 . 2008-05-27 18:15 <DIR> d-------- C:\Program Files\Common Files\Adobe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-28 17:52 21,136,672 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-28 17:50 1,587,744 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-28 17:46 297,464 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-28 17:46 160,268 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-28 15:14 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-05-28 15:14 88,262 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-05-28 08:01 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 5
2008-05-28 07:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-28 07:16 --------- d-----w C:\Program Files\LogMeIn
2008-05-28 07:16 --------- d-----w C:\Documents and Settings\Jim\Application Data\Orbit
2008-05-27 21:39 --------- d-----w C:\Program Files\Steam
2008-05-27 20:10 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-27 20:10 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-05-24 03:06 --------- d-----w C:\Program Files\mkv2vob
2008-05-24 03:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-27 06:36 --------- d-----w C:\Documents and Settings\Jim\Application Data\uTorrent
2008-04-26 21:00 --------- d-----w C:\Documents and Settings\Jim\Application Data\Apple Computer
2008-04-23 22:44 24,192 ----a-w C:\Documents and Settings\Jim\usbsermptxp.sys
2008-04-23 22:44 22,768 ----a-w C:\WINDOWS\system32\drivers\usbsermpt.sys
2008-04-23 22:44 22,768 ----a-w C:\Documents and Settings\Jim\usbsermpt.sys
2008-04-22 17:29 --------- d-----w C:\Program Files\iTunes
2008-04-22 17:29 --------- d-----w C:\Program Files\iPod
2008-04-22 17:28 --------- d-----w C:\Program Files\QuickTime
2008-04-22 17:22 --------- d-----w C:\Program Files\Apple Software Update
2008-04-15 20:07 --------- d-----w C:\Program Files\Bonjour
2008-04-15 20:06 --------- d-----w C:\Program Files\Common Files\Apple
2008-04-15 20:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-04-11 07:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-11 07:40 --------- d-----w C:\Program Files\LucasArts
2008-04-10 17:25 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-04-08 22:30 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-08 21:16 --------- d-----w C:\Documents and Settings\Jim\Application Data\Ahead
2008-04-08 21:15 --------- d-----w C:\Program Files\Common Files\Ahead
2008-04-08 21:14 --------- d-----w C:\Program Files\Nero
2008-04-08 00:35 --------- d-----w C:\Program Files\Orbitdownloader
2008-04-06 05:37 --------- d-----w C:\Program Files\uTorrent
2008-04-06 04:26 --------- d-----w C:\Program Files\Stardock
2008-04-06 04:10 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-04-06 04:05 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2008-04-06 04:05 25,416 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys
2008-04-06 03:06 --------- d-----w C:\Documents and Settings\Jim\Application Data\DAEMON Tools Pro
2008-04-05 22:00 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-04-04 02:54 --------- d-----w C:\Program Files\Common Files\Deterministic Networks
2008-04-04 02:54 --------- d-----w C:\Program Files\Cisco Systems
2008-04-03 17:45 --------- d-----w C:\Documents and Settings\Jim\Application Data\InstallShield Installation Information
2008-04-03 17:31 --------- d-----w C:\Program Files\Unreal Tournament 3
2008-04-03 17:30 --------- d-----w C:\Program Files\AGEIA Technologies
2008-04-03 00:26 --------- d-----w C:\Program Files\RivaTuner v2.08
2008-04-02 23:16 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-04-02 23:16 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-02 23:15 --------- d-----w C:\Program Files\NVIDIA nTune Performance Application
2008-03-29 03:08 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-03-28 19:30 --------- d-----w C:\Program Files\Java
2008-03-28 19:29 --------- d-----w C:\Program Files\Common Files\Java
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54018E98-10E3-46C6-9673-2999253F9C65}]
C:\WINDOWS\system32\efcYQJbX.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 19:25 81920]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 09:08 136136]
"WinSpywareProtect (ver. 5.1)"="C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-10-08 16:02 1036288]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 15:09 63048]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

C:\Documents and Settings\Jim\Start Menu\Programs\Startup\
DTProAgent.lnk - C:\Program Files\DAEMON Tools Pro\DTProAgent.exe [2007-09-06 09:08:02 136136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2008-04-03 22:54:49 1528880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"PromptRunasInstallNetPath"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRunasInstallPrompt"= 0 (0x0)
"NoDesktopCleanupWizard"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{54018E98-10E3-46C6-9673-2999253F9C65}"= C:\WINDOWS\system32\efcYQJbX.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcYQJbX]
efcYQJbX.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-11-15 18:46 87352 C:\WINDOWS\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 2008-04-06 00:29 210168 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"=
"C:\\Program Files\\ApexDC++\\ApexDC.exe"=
"C:\\Program Files\\Steam\\steamapps\\[email protected]\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Steam\\steamapps\\common\\call of duty 4\\iw3mp.exe"=
"C:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 nvgts;nvgts;C:\WINDOWS\system32\DRIVERS\nvgts.sys [2007-08-08 23:11]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2007-08-03 15:09]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-08-03 15:09]
S3 Fadpu16E;Fadpu16E;C:\DOCUME~1\Jim\LOCALS~1\Temp\Fadpu16E.sys []

.
Contents of the 'Scheduled Tasks' folder
"2008-05-22 00:20:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-28 13:50:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\LogMeIn\x86\ramaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-05-28 14:00:58 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-28 18:00:50

Pre-Run: 110,045,380,608 bytes free
Post-Run: 110,975,037,440 bytes free

216 --- E O F --- 2008-05-20 22:09:45



AND

Here is the Hijack this log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:05: VIRUS ALERT!, on 5/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarerefer...=...6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {54018E98-10E3-46C6-9673-2999253F9C65} - C:\WINDOWS\system32\efcYQJbX.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [WinSpywareProtect (ver. 5.1)] "C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe" /autorun
O4 - Startup: DTProAgent.lnk = C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O20 - Winlogon Notify: efcYQJbX - efcYQJbX.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

--
End of file - 7608 bytes
  • 0

Advertisements


#17
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
1. Please open Notepad
  • Click Start , then Run
  • type in notepad in the Run Box then hit ok.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\rar.exe
Folder::
C:\WINDOWS\privacy_danger
C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54018E98-10E3-46C6-9673-2999253F9C65}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinSpywareProtect (ver. 5.1)"=-
[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{54018E98-10E3-46C6-9673-2999253F9C65}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcYQJbX]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000000


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

  • 0

#18
☼ Klutz ☼

☼ Klutz ☼

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
when i open my start menu there is no longer 'run' on the right side. everything is gone except set program defaults and printer fax...
  • 0

#19
☼ Klutz ☼

☼ Klutz ☼

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
i can still get to notepad. i found another way. i'll save the file like u said
  • 0

#20
☼ Klutz ☼

☼ Klutz ☼

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
Here is my ComboFix Log:

ComboFix 08-05-27.4 - Jim 2008-05-28 15:09:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2433 [GMT -4:00]
Running from: C:\Documents and Settings\Jim\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jim\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\rar.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\rar.exe

.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-28 )))))))))))))))))))))))))))))))
.

2008-05-28 03:49 . 2008-05-28 03:50 1,463,856 --a------ C:\SDFix.exe
2008-05-27 20:32 . 2008-05-27 20:32 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-27 19:57 . 2008-05-27 19:57 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-27 19:57 . 2008-05-28 13:39 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-27 19:57 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-05-27 19:30 . 2008-05-27 19:30 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-27 19:17 . 2008-05-27 20:10 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\TmpRecentIcons
2008-05-27 19:06 . 2008-05-27 19:07 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-05-27 19:06 . 2008-05-27 20:06 <DIR> d-------- C:\Documents and Settings\Jim\.housecall6.6
2008-05-27 19:02 . 2008-05-27 19:02 <DIR> d-------- C:\VundoFix Backups
2008-05-27 18:16 . 2007-02-20 16:04 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2008-05-27 18:16 . 2007-02-20 16:04 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-05-27 18:07 . 2008-05-27 18:07 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-27 17:57 . 2008-05-28 04:14 <DIR> d-------- C:\Program Files\DAEMON Tools Pro
2008-05-27 17:50 . 2008-05-27 17:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2008-05-26 01:13 . 2008-05-26 01:13 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\FFSJ
2008-05-20 18:05 . 2004-01-07 17:04 339,488 --a------ C:\WINDOWS\system32\drivers\WUSB20XP.sys
2008-05-03 23:55 . 2008-05-03 23:55 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\dvdcss
2008-05-03 22:50 . 2008-05-27 18:15 <DIR> d-------- C:\Program Files\Common Files\Adobe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-28 19:11 21,244,192 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-28 19:10 1,590,816 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-28 18:05 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 5
2008-05-28 17:46 297,464 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-28 17:46 160,268 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-28 15:14 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-05-28 15:14 88,262 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-05-28 07:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-28 07:16 --------- d-----w C:\Program Files\LogMeIn
2008-05-28 07:16 --------- d-----w C:\Documents and Settings\Jim\Application Data\Orbit
2008-05-27 21:39 --------- d-----w C:\Program Files\Steam
2008-05-27 20:10 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-27 20:10 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-05-24 03:06 --------- d-----w C:\Program Files\mkv2vob
2008-05-24 03:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-27 06:36 --------- d-----w C:\Documents and Settings\Jim\Application Data\uTorrent
2008-04-26 21:00 --------- d-----w C:\Documents and Settings\Jim\Application Data\Apple Computer
2008-04-23 22:44 24,192 ----a-w C:\Documents and Settings\Jim\usbsermptxp.sys
2008-04-23 22:44 22,768 ----a-w C:\WINDOWS\system32\drivers\usbsermpt.sys
2008-04-23 22:44 22,768 ----a-w C:\Documents and Settings\Jim\usbsermpt.sys
2008-04-22 17:29 --------- d-----w C:\Program Files\iTunes
2008-04-22 17:29 --------- d-----w C:\Program Files\iPod
2008-04-22 17:28 --------- d-----w C:\Program Files\QuickTime
2008-04-22 17:22 --------- d-----w C:\Program Files\Apple Software Update
2008-04-15 20:07 --------- d-----w C:\Program Files\Bonjour
2008-04-15 20:06 --------- d-----w C:\Program Files\Common Files\Apple
2008-04-15 20:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-04-11 07:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-11 07:40 --------- d-----w C:\Program Files\LucasArts
2008-04-10 17:25 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-04-08 22:30 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-08 21:16 --------- d-----w C:\Documents and Settings\Jim\Application Data\Ahead
2008-04-08 21:15 --------- d-----w C:\Program Files\Common Files\Ahead
2008-04-08 21:14 --------- d-----w C:\Program Files\Nero
2008-04-08 00:35 --------- d-----w C:\Program Files\Orbitdownloader
2008-04-06 05:37 --------- d-----w C:\Program Files\uTorrent
2008-04-06 04:26 --------- d-----w C:\Program Files\Stardock
2008-04-06 04:10 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-04-06 04:05 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2008-04-06 04:05 25,416 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys
2008-04-06 03:06 --------- d-----w C:\Documents and Settings\Jim\Application Data\DAEMON Tools Pro
2008-04-05 22:00 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-04-04 02:54 --------- d-----w C:\Program Files\Common Files\Deterministic Networks
2008-04-04 02:54 --------- d-----w C:\Program Files\Cisco Systems
2008-04-03 17:45 --------- d-----w C:\Documents and Settings\Jim\Application Data\InstallShield Installation Information
2008-04-03 17:31 --------- d-----w C:\Program Files\Unreal Tournament 3
2008-04-03 17:30 --------- d-----w C:\Program Files\AGEIA Technologies
2008-04-03 00:26 --------- d-----w C:\Program Files\RivaTuner v2.08
2008-04-02 23:16 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-04-02 23:16 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-02 23:15 --------- d-----w C:\Program Files\NVIDIA nTune Performance Application
2008-03-29 03:08 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-03-28 19:30 --------- d-----w C:\Program Files\Java
2008-03-28 19:29 --------- d-----w C:\Program Files\Common Files\Java
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
.

((((((((((((((((((((((((((((( [email protected]_14.00.20.98 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-28 07:41:28 39,992 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-05-28 17:52:45 39,992 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-05-28 07:41:28 311,604 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-05-28 17:52:45 311,604 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 19:25 81920]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 09:08 136136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-10-08 16:02 1036288]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 15:09 63048]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

C:\Documents and Settings\Jim\Start Menu\Programs\Startup\
DTProAgent.lnk - C:\Program Files\DAEMON Tools Pro\DTProAgent.exe [2007-09-06 09:08:02 136136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2008-04-03 22:54:49 1528880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"PromptRunasInstallNetPath"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRunasInstallPrompt"= 0 (0x0)
"NoDesktopCleanupWizard"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-11-15 18:46 87352 C:\WINDOWS\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 2008-04-06 00:29 210168 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"=
"C:\\Program Files\\ApexDC++\\ApexDC.exe"=
"C:\\Program Files\\Steam\\steamapps\\[email protected]\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Steam\\steamapps\\common\\call of duty 4\\iw3mp.exe"=
"C:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 nvgts;nvgts;C:\WINDOWS\system32\DRIVERS\nvgts.sys [2007-08-08 23:11]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2007-08-03 15:09]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-08-03 15:09]
S3 Fadpu16E;Fadpu16E;C:\DOCUME~1\Jim\LOCALS~1\Temp\Fadpu16E.sys []

.
Contents of the 'Scheduled Tasks' folder
"2008-05-22 00:20:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-28 15:10:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-28 15:14:05
ComboFix-quarantined-files.txt 2008-05-28 19:13:22
ComboFix2.txt 2008-05-28 18:00:59

Pre-Run: 110,962,593,792 bytes free
Post-Run: 110,948,188,160 bytes free

173 --- E O F --- 2008-05-20 22:09:45

And

Here is my HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:19: VIRUS ALERT!, on 5/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarerefer...=...6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - Startup: DTProAgent.lnk = C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 7185 bytes
  • 0

#21
☼ Klutz ☼

☼ Klutz ☼

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
This is definitely an improvement. Winspyware protect did not start. I have my ctrl alt del back. my start menu options are still not back and it still says virus alert right next to my clock.
  • 0

#22
☼ Klutz ☼

☼ Klutz ☼

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
if i click start i can now go to all programs. this option was not available before. start > run is still not there
  • 0

#23
☼ Klutz ☼

☼ Klutz ☼

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
if i click start i can now go to all programs. this option was not available before. start > run is still not there.
  • 0

#24
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
We will fix that in a bit.
=====================
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley.
  • 0

#25
☼ Klutz ☼

☼ Klutz ☼

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
its scanning now. I have to go to work i'll post the results when i get home.
  • 0

Advertisements


#26
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
ok.
  • 0

#27
☼ Klutz ☼

☼ Klutz ☼

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
Here is the report:

Malwarebytes' Anti-Malware 1.12
Database version: 794

Scan type: Quick Scan
Objects scanned: 37065
Time elapsed: 2 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{79a70aee-f5f1-4045-ba47-79a4a84d0d9e} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7d8ca158-cbb3-45d8-ac11-3bf48547c6a5} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{6f82e55c-e6eb-4782-8211-83dbb3bf3645} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{0f1574a7-9e7c-440c-b2f1-8fe978cf9754} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Adsl Software Limited (Rogue.MalWarrior) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\atfxqogp.beas (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\atfxqogp.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0

#28
☼ Klutz ☼

☼ Klutz ☼

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
I am off work today so i will be able to correspond back and forth with you all day. at your convenience of course. Thank you for the help it is greatly appreciated
  • 0

#29
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
=======================
Please do an online scan with Kaspersky WebScanner
(This scanner is for use with internet explorer only)
Click on "Accept"

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as button:
  • Save the file in txt format to your desktop.
  • Post that information in your next post.

  • 0

#30
☼ Klutz ☼

☼ Klutz ☼

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 109 posts
ok. sry for waking up so late did not intend to sleep this late. started the scan. it seems it will take a long time its been going for 10min and its still 0%. I guess its because i have 1.8tb of hdd to scan. i'll post the results as soon as i get them
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP