Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Infected with Trojan-Downloader.Win32.Bagle.uy [RESOLVED]


  • This topic is locked This topic is locked

#1
KarolF

KarolF

    Member

  • Member
  • PipPip
  • 15 posts
Hi,

I've been infected with a nasty Trojan-Downloader.Win32.Bagle.uy which as far as I can work out has been reported only a couple of days ago:
http://www.kaspersky...?...s=bagle&x=1

The virus has done the following things to my system, which greatly restrict my ability to deal with it:
- disabled ALL anti-virus software. My out-of-date McAfee and my Spybot both got disabled. The virus prevents me from running Kasparsky online scanner. When I try to run HiJack This I get a 'not a valid Win32 application' error. I have tried to reinstal both Spybot and Hijack This and get the same result. I also tried to install the Kasparsky Free Trial to do a scan, and the virus closes down the installer application.
- Windows Safe Mode disabled - I get an error screen whenever I try, both pre- and post- Windows repair install
- Wireless internet disable (but I can still connect through a cable)

Since I can't scan my computer, the only way I was able to identify the virus was to submit the infected file to Kasparsky, which found it to be a Trojan-Downloader.Win32.Bagle.uy

I ran a Windows repair installation, with no result other than my wireless clicked back on, but then on a restart it was disabled once again.

I found some information in another thread about removing the older varient of the Bagle virus, but since this is a new type I'm not sure how to proceed. http://www.geekstogo...on-t195445.html

I used these forums before as a self-help guide to successfully get rid of a Vundo V virus I once had, and I know you guys are really good. I'd greatly appreciate any help/tips you would be able to provide.

Cheers,
Karol.

I forgot to add:
- System restore also has been disabled - it brings up an error on reboot after attempting a restore


Reason for Edit: Merged posts.

Please don't post more than once or bump the topic as Helpers usually first look for threads with no replies.

Edited by Octagonal, 23 July 2008 - 01:51 AM.

  • 0

Advertisements


#2
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello KarolF and welcome at Geekstogo,


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    Posted Image

    Posted Image

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\Combo-Fix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

Thunderbird1988
  • 0

#3
KarolF

KarolF

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Thanks for the quick response.

The Combofix log is below.

The only problem was that when the machine rebooted and Combofix closed its operation, my Spybot/Teatimer came back to life (I had no way of disabling it before running Combofix, since access to it was blocked by the virus). Spybot started popping up and blocking. I don't know if this is a problem or not. Did it interfere with Combofix in any way? I'm reprinting the relevant part of the Spybot log below.


ComboFix 08-07-22.4 - Beans 2008-07-23 19:34:48.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.174 [GMT 10:00]
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\ban_list.txt
C:\WINDOWS\system32\drivers\downld
C:\WINDOWS\system32\drivers\downld\1029828.exe
C:\WINDOWS\system32\drivers\downld\1108609.exe
C:\WINDOWS\system32\drivers\downld\1119531.exe
C:\WINDOWS\system32\drivers\downld\1162890.exe
C:\WINDOWS\system32\drivers\downld\219736578.exe
C:\WINDOWS\system32\drivers\downld\2270140.exe
C:\WINDOWS\system32\drivers\downld\2368062.exe
C:\WINDOWS\system32\drivers\downld\251921.exe
C:\WINDOWS\system32\drivers\downld\316312.exe
C:\WINDOWS\system32\drivers\downld\338312.exe
C:\WINDOWS\system32\drivers\downld\433203.exe
C:\WINDOWS\system32\drivers\downld\440140.exe
C:\WINDOWS\system32\drivers\downld\483328.exe
C:\WINDOWS\system32\drivers\downld\682781.exe
C:\WINDOWS\system32\drivers\downld\721703.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\mdelk.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\wintems.exe

.
((((((((((((((((((((((((( Files Created from 2008-06-23 to 2008-07-23 )))))))))))))))))))))))))))))))
.

2008-07-23 19:40 . 2008-07-23 19:40 <DIR> d-------- C:\WINDOWS\system32\drivers\downld
2008-07-23 12:17 . 2008-07-23 12:17 <DIR> d-------- C:\WINDOWS\dell
2008-07-23 03:13 . 2008-07-23 03:13 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-23 02:44 . 2004-08-04 20:00 111,104 --a--c--- C:\WINDOWS\system32\dllcache\mtstocom.exe
2008-07-23 02:43 . 2004-08-04 20:00 10,096,640 --a--c--- C:\WINDOWS\system32\dllcache\hwxcht.dll
2008-07-23 02:42 . 2004-05-13 00:39 876,653 --a--c--- C:\WINDOWS\system32\dllcache\fp4awel.dll
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-07-23 02:40 . 2008-07-23 02:40 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-07-23 02:39 . 2004-08-04 20:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-07-23 02:28 . 2004-08-04 20:00 1,086,058 -ra------ C:\WINDOWS\SETB9.tmp
2008-07-23 02:28 . 2004-08-04 20:00 1,042,903 -ra------ C:\WINDOWS\SETB6.tmp
2008-07-22 23:22 . 2008-07-23 00:36 813 --a------ C:\WINDOWS\TLMBASIC.INI
2008-07-22 23:21 . 2008-07-22 23:21 <DIR> d-------- C:\Program Files\TLM Basic
2008-07-22 23:21 . 2008-07-22 23:21 <DIR> d-------- C:\Documents and Settings\Beans\Application Data\Progeny
2008-07-22 23:21 . 2008-07-23 18:06 848 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-07-22 23:21 . 2008-07-23 18:06 88 -r-hs---- C:\WINDOWS\system32\CB8232BBC6.sys
2008-06-27 03:22 . 2008-06-27 03:22 <DIR> d-------- C:\WINDOWS\system32\cvirte
2008-06-27 03:22 . 2008-06-27 03:22 <DIR> d-------- C:\BeerIsGood Priming Calculator
2008-06-27 03:22 . 2001-08-01 10:00 1,826,816 --a------ C:\WINDOWS\system32\cvirte.dll
2008-06-27 03:22 . 2001-08-01 10:00 45,056 --a------ C:\WINDOWS\system32\cvirt.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-23 06:02 --------- d-----w C:\Program Files\Imperia Online
2008-07-22 17:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-22 17:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-22 13:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-29 09:32 --------- d-----w C:\Program Files\DOSBox-0.70
2008-03-13 21:48 210 ----a-w C:\Documents and Settings\Beans\HALLFAME.DAT
2007-04-30 00:33 132 ----a-w C:\Documents and Settings\Beans\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2005-10-11 10:08 696320]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 02:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 10:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 07:00 208952]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 03:25 144784]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 12:12 90112]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-09-22 13:47 761947]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-23 11:45 1392640]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 22:29 49152]
"CTSVolFE.exe"="C:\Program Files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 17:57 57344]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 19:30 152144]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 07:20 122940]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 18:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 16:15 81920]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-05-13 11:57 1831936]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\Quickset.exe" [2006-08-23 18:14 1032192]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-17 14:45 185784]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 01:12 483328]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 02:01 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 02:50 1603152]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 12:02 79400]
"SigmatelSysTrayApp"="stsystra.exe" [2006-09-22 13:06 282624 C:\WINDOWS\stsystra.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 11:17 443968]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-12-05 17:39:56 25214]
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Unwired\\UwWiz.exe"=

S3 MSControlService;Microsoft cache control;C:\WINDOWS\system32\windows []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e3bec783-1950-11dc-8567-0019b96a0cfa}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e3bec784-1950-11dc-8567-0019b96a0cfa}]
\Shell\AutoRun\command - G:\nideiect.com
\Shell\explore\Command - G:\nideiect.com
\Shell\open\Command - G:\nideiect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e8207a3b-4037-11dc-8573-0019b96a0cfa}]
\Shell\AutoRun\command - E:\autorun.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eeed78da-5435-11dc-8579-00197e194baa}]
\Shell\auto\command - Knight.exe open
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Knight.exe open
\Shell\explore\command - Knight.exe open
\Shell\find\command - Knight.exe open
\Shell\install\command - Knight.exe open
\Shell\open\command - Knight.exe open

*Newly Created Service* - BITS
.
Contents of the 'Scheduled Tasks' folder
"2008-07-14 15:00:03 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-06-30 15:00:09 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
- - - - ORPHANS REMOVED - - - -

BHO-{B4E2CDF0-F37B-484B-9700-504BA6F36BC8} - C:\WINDOWS\system32\ssqpo.dll
BHO-{C5FB3A7A-E921-40F2-8563-883B396E56D8} - C:\WINDOWS\system32\jkhff.dll
BHO-{DE387A41-7930-41FB-8059-8B5E90276778} - C:\WINDOWS\system32\vtsqq.dll
HKLM-Run-MSPY2002 - C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe
HKLM-Run-PHIME2002ASync - C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
HKLM-Run-PHIME2002A - C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
Notify-fiqisnmy - (no file)


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.agn.gob.mx/guiageneral/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.unwired.com.au/
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: Convert link target to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-23 19:41:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\WINDOWS\system32\wuauclt.exe.wusetup.307843.bak 111104 bytes executable
C:\WINDOWS\system32\wuaucpl.cpl.wusetup.320062.bak 162304 bytes executable
C:\WINDOWS\system32\wuaueng.dll.wusetup.325937.bak 1134592 bytes executable

scan completed successfully
hidden files: 3

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\MSControlService]
"ImagePath"="C:\WINDOWS\system32\windows"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\COMMON~1\McAfee\RedirSvc\RedirSvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
C:\PROGRA~1\McAfee\MPS\mpsevh.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2008-07-23 19:52:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-23 09:52:47
ComboFix2.txt 2008-02-24 12:09:42

Pre-Run: 52,972,322,816 bytes free
Post-Run: 53,300,609,024 bytes free

212 --- E O F --- 2008-06-21 00:35:24






Spybot Resident Log:

23/07/2008 12:37:28 AM Encountered and terminated Win32.Bagle.hi in C:\WINDOWS\system32\drivers\hldrrr.exe!
23/07/2008 12:37:30 AM Allowed (based on authenticode whitelist) value "Spybot - Search & Destroy" (new data: ""C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck") added in System Startup global entry!
23/07/2008 12:37:33 AM Denied (based on Spybot-S&D scan) value "drvsyskit" (new data: "C:\WINDOWS\system32\drivers\hldrrr.exe") added in System Startup user entry!
23/07/2008 7:58:43 PM Denied (based on user decision) value "MSPY2002" (new data: "") deleted in System Startup global entry!
23/07/2008 7:58:54 PM Denied (based on user decision) value "PHIME2002ASync" (new data: "") deleted in System Startup global entry!
23/07/2008 7:58:58 PM Denied (based on user decision) value "PHIME2002A" (new data: "") deleted in System Startup global entry!
23/07/2008 7:59:07 PM Allowed (based on user decision) value "{B4E2CDF0-F37B-484B-9700-504BA6F36BC8}" (new data: "") deleted in Browser Helper Object!
23/07/2008 7:59:13 PM Allowed (based on user decision) value "{C5FB3A7A-E921-40F2-8563-883B396E56D8}" (new data: "") deleted in Browser Helper Object!
23/07/2008 7:59:15 PM Allowed (based on user decision) value "{DE387A41-7930-41FB-8059-8B5E90276778}" (new data: "") deleted in Browser Helper Object!
23/07/2008 7:59:15 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:16 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:17 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:18 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:19 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:20 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:21 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:22 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:23 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:24 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:25 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:26 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:27 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:28 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:29 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:30 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:31 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:32 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:33 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:34 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:35 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:36 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:37 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:38 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:39 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:40 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:41 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:42 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:43 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:44 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:45 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:46 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:47 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:48 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:49 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:50 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:51 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:52 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:54 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:55 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:56 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:57 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:58 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 7:59:59 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:00 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:01 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:02 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:03 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:04 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:05 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:06 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:07 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:08 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:09 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:10 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:11 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:12 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:13 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:14 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:15 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:16 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:17 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:18 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:19 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:20 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:21 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:22 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:23 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:24 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:25 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:26 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:27 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:28 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:29 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:30 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:31 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:32 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:34 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:35 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:36 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:37 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:38 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:39 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:40 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:41 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:42 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:43 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:44 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:45 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:46 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:47 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:48 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:49 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:50 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:51 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:52 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:53 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:54 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:55 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:56 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:57 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:58 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:00:59 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:00 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:01 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:02 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:03 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:05 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:06 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:07 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:08 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:09 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:10 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:11 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:12 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:13 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:14 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:15 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:16 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:17 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:18 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:20 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:21 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:22 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:23 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:24 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:25 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:26 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:27 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:28 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:29 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:30 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:31 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:32 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:33 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:34 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:35 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:36 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:37 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:38 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:39 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:40 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:41 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:42 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:44 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:45 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:46 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:47 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:48 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:49 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:50 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:51 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:52 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:53 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:54 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:55 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:56 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:57 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:58 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:01:59 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:00 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:02 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:03 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:04 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:05 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:06 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:07 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:08 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:09 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:10 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:11 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:12 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:13 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:14 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:15 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:16 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:17 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:18 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:19 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:20 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:21 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:22 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:23 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:24 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:25 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:26 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:27 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:28 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:29 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:30 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:31 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:32 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:34 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:35 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:36 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:37 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:38 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:39 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:40 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:41 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:42 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:43 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:44 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:45 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:46 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:47 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:48 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:49 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:50 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:51 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:52 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:53 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:54 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:55 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:56 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:57 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:58 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:02:59 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:00 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:01 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:02 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:04 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:05 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:06 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:07 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:08 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:09 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:10 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:11 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:12 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:13 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:14 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:15 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:16 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:17 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:18 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:19 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:20 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:21 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:22 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:23 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:24 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:25 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:26 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:27 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:28 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:29 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:30 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:31 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:32 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:33 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:34 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:36 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:37 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:38 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:40 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:41 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:42 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:43 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:44 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:45 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:46 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:47 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:48 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:49 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:50 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:51 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:52 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:54 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:55 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:56 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:58 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:03:59 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:04:00 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:04:01 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:04:02 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:04:03 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:04:04 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:04:05 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:04:07 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
23/07/2008 8:04:11 PM Denied (based on user blacklist) value "fiqisnmy" (new data: "") deleted in Winlogon Notifiers!
  • 0

#4
KarolF

KarolF

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
HiJackThis log (I got rid of the error message after reinstalling it):




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:27:47 PM, on 23/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\Hijack-This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.agn.gob.mx/guiageneral/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=4070424
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.unwired.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe

--
End of file - 11958 bytes
  • 0

#5
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::

C:\WINDOWS\SETB6.tmp
C:\WINDOWS\SETB9.tmp
C:\WINDOWS\system32\CB8232BBC6.sys

Folder::
C:\WINDOWS\system32\drivers\downld

Registry::

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e3bec784-1950-11dc-8567-0019b96a0cfa}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e3bec783-1950-11dc-8567-0019b96a0cfa}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e8207a3b-4037-11dc-8573-0019b96a0cfa}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eeed78da-5435-11dc-8579-00197e194baa}]



3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please run the F-Secure Online Scanner

Note: This Scanner is for Internet Explorer Only!
  • Follow the Instruction Here for installation.
  • Accept the License Agreement.
  • Once the ActiveX installs,Click Full System Scan
  • Once the download completes,the scan will begin automatically.
  • The scan will take some time to finish,so please be patient.
  • When the scan completes, click the Automatic cleaning (recommended) button.
  • Click the Show Report button and Copy&Paste the entire report in your next reply.

Thunderbird1988
  • 0

#6
KarolF

KarolF

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Logs of Combofix, HijackThis and F-Secure scanner:



ComboFix 08-07-22.4 - Beans 2008-07-24 1:40:38.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.140 [GMT 10:00]
Running from: C:\Documents and Settings\Beans\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\Beans\Desktop\cfscript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\SETB6.tmp
C:\WINDOWS\SETB9.tmp
C:\WINDOWS\system32\CB8232BBC6.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\SETB6.tmp
C:\WINDOWS\SETB9.tmp
C:\WINDOWS\system32\CB8232BBC6.sys
C:\WINDOWS\system32\drivers\downld

.
((((((((((((((((((((((((( Files Created from 2008-06-23 to 2008-07-23 )))))))))))))))))))))))))))))))
.

2008-07-23 20:03 . 2008-07-23 20:03 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-07-23 12:17 . 2008-07-23 12:17 <DIR> d-------- C:\WINDOWS\dell
2008-07-23 03:13 . 2008-07-23 20:27 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-23 02:44 . 2004-08-04 20:00 111,104 --a--c--- C:\WINDOWS\system32\dllcache\mtstocom.exe
2008-07-23 02:43 . 2004-08-04 20:00 10,096,640 --a--c--- C:\WINDOWS\system32\dllcache\hwxcht.dll
2008-07-23 02:42 . 2004-05-13 00:39 876,653 --a--c--- C:\WINDOWS\system32\dllcache\fp4awel.dll
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-07-23 02:40 . 2008-07-23 02:40 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-07-23 02:39 . 2004-08-04 20:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-07-22 23:22 . 2008-07-23 00:36 813 --a------ C:\WINDOWS\TLMBASIC.INI
2008-07-22 23:21 . 2008-07-22 23:21 <DIR> d-------- C:\Program Files\TLM Basic
2008-07-22 23:21 . 2008-07-22 23:21 <DIR> d-------- C:\Documents and Settings\Beans\Application Data\Progeny
2008-07-22 23:21 . 2008-07-23 18:06 848 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-06-27 03:22 . 2008-06-27 03:22 <DIR> d-------- C:\WINDOWS\system32\cvirte
2008-06-27 03:22 . 2008-06-27 03:22 <DIR> d-------- C:\BeerIsGood Priming Calculator
2008-06-27 03:22 . 2001-08-01 10:00 1,826,816 --a------ C:\WINDOWS\system32\cvirte.dll
2008-06-27 03:22 . 2001-08-01 10:00 45,056 --a------ C:\WINDOWS\system32\cvirt.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-23 09:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-23 06:02 --------- d-----w C:\Program Files\Imperia Online
2008-07-22 17:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-22 13:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-29 09:32 --------- d-----w C:\Program Files\DOSBox-0.70
2008-03-13 21:48 210 ----a-w C:\Documents and Settings\Beans\HALLFAME.DAT
2007-04-30 00:33 132 ----a-w C:\Documents and Settings\Beans\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2005-10-11 10:08 696320]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 02:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 10:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 07:00 208952]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 03:25 144784]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 12:12 90112]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-09-22 13:47 761947]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-23 11:45 1392640]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 22:29 49152]
"CTSVolFE.exe"="C:\Program Files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 17:57 57344]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 19:30 152144]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 07:20 122940]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 18:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 16:15 81920]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-05-13 11:57 1831936]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\Quickset.exe" [2006-08-23 18:14 1032192]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-17 14:45 185784]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 01:12 483328]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 02:01 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 02:50 1603152]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 12:02 79400]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [BU]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [BU]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [BU]
"SigmatelSysTrayApp"="stsystra.exe" [2006-09-22 13:06 282624 C:\WINDOWS\stsystra.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 11:17 443968]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-12-05 17:39:56 25214]
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Unwired\\UwWiz.exe"=

S3 MSControlService;Microsoft cache control;C:\WINDOWS\system32\windows []

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-07-14 15:00:03 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-06-30 15:00:09 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-24 01:43:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MSControlService]
"ImagePath"="C:\WINDOWS\system32\windows"
.
Completion time: 2008-07-24 1:45:29
ComboFix-quarantined-files.txt 2008-07-23 15:45:18
ComboFix2.txt 2008-07-23 09:52:56
ComboFix3.txt 2008-02-24 12:09:42

Pre-Run: 52,766,711,808 bytes free
Post-Run: 52,755,005,440 bytes free

132 --- E O F --- 2008-06-21 00:35:24







Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:05:38 AM, on 24/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsiExec.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\10\INTEL3~1\IDriver.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\Hijack-This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.agn.gob.mx/guiageneral/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=4070424
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.unwired.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe

--
End of file - 12070 bytes







Scanning Report
Thursday, July 24, 2008 02:47:54 - 11:46:32

Computer name: KAROL
Scanning type: Scan system for malware, rootkits
Target: C:\
Result: 3 malware found
Tracking Cookie (spyware)

* System

Trojan-Downloader.Win32.Bagle (virus)

* System

Trojan-Downloader.Win32.Bagle.uy (virus)

* C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER\GOOGLETOOLBARNOTIFIER.EXE

Statistics
Scanned:

* Files: 53656
* System: 4263
* Not scanned: 15

Actions:

* Disinfected: 0
* Renamed: 0
* Deleted: 0
* None: 3
* Submitted: 0

Files not scanned:

* C:\HIBERFIL.SYS
* C:\PAGEFILE.SYS
* C:\WINDOWS\TEMP\MCMSC_2KTGLOIVUXWIQIB
* C:\WINDOWS\TEMP\MCMSC_3HLX0BW3UYDJODR
* C:\WINDOWS\TEMP\MCMSC_OHI27FKKCTGSI5Q
* C:\WINDOWS\TEMP\MCMSC_VB9BGZRY6SXQCDF
* C:\WINDOWS\TEMP\SQLITE_I3UIZ1AZGSHJMSG
* C:\WINDOWS\TEMP\SQLITE_OAPZ9O1FUSCMWYZ
* C:\WINDOWS\TEMP\SQLITE_QR8EG9YB8SHQME4
* C:\WINDOWS\TEMP\SQLITE_RPXXYLJRLR7UOG5
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\WINDOWS\SYSTEM32\CONFIG\SAM
* C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
* C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
* C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM

Options
Scanning engines:

* F-Secure USS: 2.30.0
* F-Secure Hydra: 2.8.8110, 2008-07-23
* F-Secure AVP: 7.0.171, 2008-07-23
* F-Secure Pegasus: 1.20.0, 2008-04-15
* F-Secure Blacklight: 1.0.68

Scanning options:

* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
* Use Advanced heuristics

Copyright © 1998-2007 Product support |Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
  • 0

#7
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello KarolF,

1. Please download The Avenger by Swandog46 to your Desktop.
  • Right click on the Avenger.zip folder and select "Extract All..."
  • Follow the prompts and extract the avenger folder to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Begin copying here:
Files to delete:
C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER\GOOGLETOOLBARNOTIFIER.EXE

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, open the avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avengerís actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh Hijackthis log .

Thunderbird1988
  • 0

#8
KarolF

KarolF

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Hi Thunderbird1988

The file GOOGLETOOLBARNOTIFIER.EXE no longer exists, but the directory does. I noticed that the exact same thing happened to another user infected with the Bagle virus. http://www.geekstogo...s....html&st=15

Should I do what they did and delete the whole Google folder with Avenger?



Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: file "C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER\GOOGLETOOLBARNOTIFIER.EXE" not found!
Deletion of file "C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER\GOOGLETOOLBARNOTIFIER.EXE" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:41:53 PM, on 24/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\Trend Micro\Hijack-This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.agn.gob.mx/guiageneral/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=4070424
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.unwired.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-sec...m/ols/fscax.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe

--
End of file - 12103 bytes

Edited by KarolF, 24 July 2008 - 08:21 AM.

  • 0

#9
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello KarolF,

No, for now it is good if we only remove the Googletoolbar folder.

1. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Begin copying here:
Folders to Delete:
C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


2. Now, open the avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.
3. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avengerís actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
4. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh Hijackthis log .

Thunderbird1988
  • 0

#10
KarolF

KarolF

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Worked fine. But as soon as the reboot completed, I got a Spybot alert for registry change:

Category: System Startup global entry
Change: Value added
Entry: WinSideBySideSetupCleanup 834199
New data: rundll32 sxs.dll,SxspRunDIIDeleteDirectory C:\WINDOWNS\WinSxS\InstallTemp\834199

Not to sure what to do with this. Is this malware, or part of the Avenger deletion process? I've still got the window open so I can allow or deny.






Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

Folder "C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:14:03 AM, on 25/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\acrobat_sl.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\MsiExec.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\10\INTEL3~1\IDriver.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\Hijack-This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.agn.gob.mx/guiageneral/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=4070424
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.unwired.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll (file missing)
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-sec...m/ols/fscax.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe

--
End of file - 12192 bytes
  • 0

Advertisements


#11
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello KarolF,

It seems from a cleanup program, that wants to remove an old folder. You can allow it.

Please run Combo-Fix again, and post the new log and a new Hijackthislog.

Thunderbird1988
  • 0

#12
KarolF

KarolF

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Hi Thunderbird1988,

The logs for Combofix and HiJackThis:




ComboFix 08-07-22.4 - Beans 2008-07-25 12:20:55.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.68 [GMT 10:00]
Running from: C:\Documents and Settings\Beans\Desktop\Combo-Fix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\downld

.
((((((((((((((((((((((((( Files Created from 2008-06-25 to 2008-07-25 )))))))))))))))))))))))))))))))
.

2008-07-25 00:45 . 2008-07-25 01:07 88 -r-hs---- C:\WINDOWS\system32\CB8232BBC6.sys
2008-07-24 02:11 . 2008-07-24 02:11 <DIR> d-------- C:\fsaua.data
2008-07-23 20:03 . 2008-07-23 20:03 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-07-23 12:17 . 2008-07-23 12:17 <DIR> d-------- C:\WINDOWS\dell
2008-07-23 03:13 . 2008-07-23 20:27 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-23 02:44 . 2004-08-04 20:00 111,104 --a--c--- C:\WINDOWS\system32\dllcache\mtstocom.exe
2008-07-23 02:43 . 2004-08-04 20:00 10,096,640 --a--c--- C:\WINDOWS\system32\dllcache\hwxcht.dll
2008-07-23 02:42 . 2004-05-13 00:39 876,653 --a--c--- C:\WINDOWS\system32\dllcache\fp4awel.dll
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-07-23 02:40 . 2008-07-23 02:40 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-07-23 02:39 . 2004-08-04 20:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-07-22 23:22 . 2008-07-23 00:36 813 --a------ C:\WINDOWS\TLMBASIC.INI
2008-07-22 23:21 . 2008-07-22 23:21 <DIR> d-------- C:\Documents and Settings\Beans\Application Data\Progeny
2008-07-22 23:21 . 2008-07-25 01:07 848 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-06-27 03:22 . 2008-06-27 03:22 <DIR> d-------- C:\WINDOWS\system32\cvirte
2008-06-27 03:22 . 2008-06-27 03:22 <DIR> d-------- C:\BeerIsGood Priming Calculator
2008-06-27 03:22 . 2001-08-01 10:00 1,826,816 --a------ C:\WINDOWS\system32\cvirte.dll
2008-06-27 03:22 . 2001-08-01 10:00 45,056 --a------ C:\WINDOWS\system32\cvirt.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-24 15:10 --------- d-----w C:\Program Files\Google
2008-07-23 09:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-23 06:02 --------- d-----w C:\Program Files\Imperia Online
2008-07-22 17:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-22 13:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-29 09:32 --------- d-----w C:\Program Files\DOSBox-0.70
2008-03-13 21:48 210 ----a-w C:\Documents and Settings\Beans\HALLFAME.DAT
2007-04-30 00:33 132 ----a-w C:\Documents and Settings\Beans\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 02:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 10:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 07:00 208952]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 03:25 144784]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 12:12 90112]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-09-22 13:47 761947]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-23 11:45 1392640]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 22:29 49152]
"CTSVolFE.exe"="C:\Program Files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 17:57 57344]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 19:30 152144]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 07:20 122940]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 18:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 16:15 81920]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-05-13 11:57 1831936]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\Quickset.exe" [2006-08-23 18:14 1032192]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-17 14:45 185784]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 01:12 483328]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 02:01 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 02:50 1603152]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 12:02 79400]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [BU]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [BU]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [BU]
"SigmatelSysTrayApp"="stsystra.exe" [2006-09-22 13:06 282624 C:\WINDOWS\stsystra.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 11:17 443968]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-12-05 17:39:56 25214]
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Unwired\\UwWiz.exe"=

S3 MSControlService;Microsoft cache control;C:\WINDOWS\system32\windows []
.
Contents of the 'Scheduled Tasks' folder
"2008-07-14 15:00:03 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-06-30 15:00:09 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.agn.gob.mx/guiageneral/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.unwired.com.au/
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: Convert link target to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-25 12:24:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MSControlService]
"ImagePath"="C:\WINDOWS\system32\windows"
.
Completion time: 2008-07-25 12:26:59
ComboFix-quarantined-files.txt 2008-07-25 02:26:54
ComboFix2.txt 2008-07-23 15:45:30
ComboFix3.txt 2008-07-23 09:52:56
ComboFix4.txt 2008-02-24 12:09:42

Pre-Run: 52,634,177,536 bytes free
Post-Run: 52,708,470,784 bytes free

140 --- E O F --- 2008-07-25 02:04:38





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:28:01 PM, on 25/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\Hijack-This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.agn.gob.mx/guiageneral/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=4070424
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.unwired.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll (file missing)
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-sec...m/ols/fscax.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe

--
End of file - 12068 bytes
  • 0

#13
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello KarolF,

. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::

C:\WINDOWS\system32\CB8232BBC6.sys



3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please run the F-Secure Online Scanner

Note: This Scanner is for Internet Explorer Only!
  • Follow the Instruction Here for installation.
  • Accept the License Agreement.
  • Once the ActiveX installs,Click Full System Scan
  • Once the download completes,the scan will begin automatically.
  • The scan will take some time to finish,so please be patient.
  • When the scan completes, click the Automatic cleaning (recommended) button.
  • Click the Show Report button and Copy&Paste the entire report in your next reply.

Thunderbird1988
  • 0

#14
KarolF

KarolF

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
Hi Thunderbird1988,

Logs for Combofix and HiJackThis. Attempting to run F-secure scan gives me an error: 'download database file is corrupt! Please close the scanner and try again'. I tried a bunch of things, and also on restart got the same error message.



ComboFix 08-07-22.4 - Beans 2008-07-26 2:43:03.5 - NTFSx86
Running from: C:\Documents and Settings\Beans\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\Beans\Desktop\cfscript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\CB8232BBC6.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\CB8232BBC6.sys

.
((((((((((((((((((((((((( Files Created from 2008-06-25 to 2008-07-25 )))))))))))))))))))))))))))))))
.

2008-07-24 02:11 . 2008-07-24 02:11 <DIR> d-------- C:\fsaua.data
2008-07-23 20:03 . 2008-07-23 20:03 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-07-23 12:17 . 2008-07-23 12:17 <DIR> d-------- C:\WINDOWS\dell
2008-07-23 03:13 . 2008-07-23 20:27 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-23 02:44 . 2004-08-04 20:00 111,104 --a--c--- C:\WINDOWS\system32\dllcache\mtstocom.exe
2008-07-23 02:43 . 2004-08-04 20:00 10,096,640 --a--c--- C:\WINDOWS\system32\dllcache\hwxcht.dll
2008-07-23 02:42 . 2004-05-13 00:39 876,653 --a--c--- C:\WINDOWS\system32\dllcache\fp4awel.dll
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-07-23 02:40 . 2008-07-23 02:40 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-07-23 02:40 . 2008-07-23 02:40 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-07-23 02:39 . 2004-08-04 20:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-07-22 23:22 . 2008-07-23 00:36 813 --a------ C:\WINDOWS\TLMBASIC.INI
2008-07-22 23:21 . 2008-07-22 23:21 <DIR> d-------- C:\Documents and Settings\Beans\Application Data\Progeny
2008-07-22 23:21 . 2008-07-25 01:07 848 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-06-27 03:22 . 2008-06-27 03:22 <DIR> d-------- C:\WINDOWS\system32\cvirte
2008-06-27 03:22 . 2008-06-27 03:22 <DIR> d-------- C:\BeerIsGood Priming Calculator
2008-06-27 03:22 . 2001-08-01 10:00 1,826,816 --a------ C:\WINDOWS\system32\cvirte.dll
2008-06-27 03:22 . 2001-08-01 10:00 45,056 --a------ C:\WINDOWS\system32\cvirt.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-24 15:10 --------- d-----w C:\Program Files\Google
2008-07-23 09:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-23 06:02 --------- d-----w C:\Program Files\Imperia Online
2008-07-22 17:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-22 13:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-29 09:32 --------- d-----w C:\Program Files\DOSBox-0.70
2008-03-13 21:48 210 ----a-w C:\Documents and Settings\Beans\HALLFAME.DAT
2007-04-30 00:33 132 ----a-w C:\Documents and Settings\Beans\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 02:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 10:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 07:00 208952]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 03:25 144784]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 12:12 90112]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-09-22 13:47 761947]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-23 11:45 1392640]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 22:29 49152]
"CTSVolFE.exe"="C:\Program Files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 17:57 57344]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 19:30 152144]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 07:20 122940]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 18:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 16:15 81920]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-05-13 11:57 1831936]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\Quickset.exe" [2006-08-23 18:14 1032192]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-17 14:45 185784]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 01:12 483328]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 02:01 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 02:50 1603152]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 12:02 79400]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [BU]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [BU]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [BU]
"SigmatelSysTrayApp"="stsystra.exe" [2006-09-22 13:06 282624 C:\WINDOWS\stsystra.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 11:17 443968]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-12-05 17:39:56 25214]
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Unwired\\UwWiz.exe"=

S3 MSControlService;Microsoft cache control;C:\WINDOWS\system32\windows []
.
Contents of the 'Scheduled Tasks' folder
"2008-07-14 15:00:03 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-06-30 15:00:09 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-26 02:46:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MSControlService]
"ImagePath"="C:\WINDOWS\system32\windows"
.
Completion time: 2008-07-26 2:48:54
ComboFix-quarantined-files.txt 2008-07-25 16:48:36
ComboFix2.txt 2008-07-25 02:27:04
ComboFix3.txt 2008-07-23 15:45:30
ComboFix4.txt 2008-07-23 09:52:56
ComboFix5.txt 2008-07-25 16:42:16

Pre-Run: 52,690,198,528 bytes free
Post-Run: 52,680,663,040 bytes free

127 --- E O F --- 2008-07-25 02:04:38




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:49:36 AM, on 26/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\Acrobat.exe
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\WINDOWS\system32\CF22073.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\Hijack-This\HijackThis.exe
C:\WINDOWS\Nircmd.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.agn.gob.mx/guiageneral/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row&channel=au&ibd=4070424
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.unwired.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll (file missing)
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-sec...m/ols/fscax.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe

--
End of file - 12333 bytes
  • 0

#15
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello KarolF,

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Thunderbird1988
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP