Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Trojan Horse PSW.OnlineGames [RESOLVED]


  • This topic is locked This topic is locked

#46
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts

Bad news... as usual I am unable to run OTScanIt.exe. Do I continue with the rest of the procedures?


Yup :)
  • 0

Advertisements


#47
mercurius

mercurius

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
Alright, I only have the AVZ report here.
http://www.2shared.c...o_syscheck.html
  • 0

#48
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hi.. your AVZ log looks very good.. Lets do another scan before I can set you online..


Please download RUNSCANNER to your desktop and run it.
  • When the first page comes up select Beginner Mode
  • On the next page select Save a binary .Run file (Recommended) then click Start full scan at the top.
  • At this time Runscanner.exe may request access to the Internet through your firewall please allow it to do so, it will then run for two or three minutes.
  • It will then ask you to save two files, the .run file and the log. Save both of them in your Desktop.
  • You will see the .run file on your desktop. Please zip the .run file and attach it in your next reply

Then upload that as an attachment in your next post.
  • 0

#49
mercurius

mercurius

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
Some problems attaching the zip file so I uploaded unto 2shared.com... Here's the link
http://www.2shared.c...runscanner.html

hope this gives good news.
  • 0

#50
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts

hope this gives good news.


Me too... Lets go online and do this..


Please delete your version of ComboFix and download a fresh copy from either links below.. Save it to your Desktop.. DO NOT do anything with it yet, we will run it later..
Link 1
Link 2
Link 3



NEXT


I noticed that you already have Malwarebytes' Anti-Malware.. Please run and update it..
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.





NEXT


Please do an online scan with BitDefender Online Scan.
  • Click on I Agree
  • Allow the ActiveX control to install when prompted.
  • Click on I Agree again. It will then start the updating process
  • Click Click here to scan to begin the scan.
  • Please refrain from using the computer until the scan is finished. This might take a while to run, but it is important that nothing else is running while you scan.
  • When the scan is finished, click on Click here to export the scan results.
  • Save the report to your desktop so you can post it in your next reply.
Please note that this scan ONLY works with Internet Explorer




NEXT


Lets run F-Secure online scan for Viruses, Spyware and RootKits:
  • Scroll to the bottom of the page and click the Start scanning button. A window will pop up.
  • Allow the Active X control to be installed on your computer, then click the Accept button
  • Click Full System Scan and allow the components to download and the scan to complete.
  • If malware is found, check Submit samples to F-Secure then select Automatic cleaning
  • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
If Automatic cleaning with Submit samples hangs, click Cancel, then New Scan
  • When the cleaning option is presented, Uncheck Submit samples to F-Secure
  • Click Automatic cleaning
  • When cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)
  • Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this post
Notes:
  • This scan will only work with Internet Explorer
  • You must have administrator rights to run this scan
  • This scan can take several hours, so please be patient





After that, please run ComboFix and then post these logs here.. Post each log in separate post.. Or upload it to 2shared if necessary..

1. Malwarebytes'
2. BitDefender Online Scan
3. F-Secure Online Scan
4. ComboFix


Regards
fenzodahl512
  • 0

#51
mercurius

mercurius

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
Malwarebytes' Anti-Malware 1.25
Database version: 1062
Windows 5.1.2600 Service Pack 2

18:48:30 22/08/2008
mbam-log-08-22-2008 (18-48-30).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 160447
Time elapsed: 1 hour(s), 17 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 38

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e7bd74f-2b8d-469e-ccb0-b130eedbe97c} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4e7bd74f-2b8d-469e-ccb0-b130eedbe97c} (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051599.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051602.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051603.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051604.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051606.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051608.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051795.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051768.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051770.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051772.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051774.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051776.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051778.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051780.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051782.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051797.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051798.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051802.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C80A0E31-CFB6-43C8-806D-D60328756522}\RP241\A0051804.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00038.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00040.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00041.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00042.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00043.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00044.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00045.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00046.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00047.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00048.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00049.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00050.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00051.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00052.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00053.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00054.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00055.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\AdminNUS\Desktop\avz4\Quarantine\2008-08-13\avz00056.dta (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\MegauploadToolbar\megauploadtoolbar.dll (Trojan.BHO) -> Quarantined and deleted successfully.
  • 0

#52
mercurius

mercurius

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
F-Secure

Scanning Report
Friday, August 22, 2008 20:17:43 - 22:01:05

Computer name: U0607818
Scanning type: Scan system for malware, rootkits
Target: C:\ D:\
Result: 3 malware found
TrackingCookie.Atdmt (spyware)

* System

TrackingCookie.Doubleclick (spyware)

* System

TrackingCookie.Webtrends (spyware)

* System

Statistics
Scanned:

* Files: 72882
* System: 5258
* Not scanned: 8

Actions:

* Disinfected: 0
* Renamed: 0
* Deleted: 0
* None: 3
* Submitted: 0

Files not scanned:

* C:\HIBERFIL.SYS
* C:\PAGEFILE.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\WINDOWS\SYSTEM32\CONFIG\SAM
* C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
* C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
* C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
* C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{DA8A259D-8CE2-462A-9483-679FB73CA376}.BIN

Options
Scanning engines:

* F-Secure USS: 2.30.0
* F-Secure Blacklight: 1.0.68
* F-Secure Hydra: 2.8.8110, 2008-08-22
* F-Secure Pegasus: 1.20.0, 2008-04-15
* F-Secure AVP: 7.0.171, 2008-08-21

Scanning options:

* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
* Use Advanced heuristics

Copyright © 1998-2007 Product support |Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
  • 0

#53
mercurius

mercurius

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
ComboFix 08-08-21.02 - cx 2008-08-22 22:11:47.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.464 [GMT 8:00]
Running from: C:\Documents and Settings\AdminNUS\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\dao350.dll
C:\WINDOWS\system32\tdfhex.dll.LoG

.
((((((((((((((((((((((((( Files Created from 2008-07-22 to 2008-08-22 )))))))))))))))))))))))))))))))
.

2008-08-22 20:09 . 2008-08-22 20:09 <DIR> d-------- C:\fsaua.data
2008-08-22 18:52 . 2008-08-22 19:55 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-08-18 16:25 . 2008-08-18 16:25 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-08-18 16:25 . 2008-08-18 16:25 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-08-18 12:27 . 2008-08-18 12:27 <DIR> d-------- C:\Program Files\CleanUp!
2008-08-18 12:08 . 2008-08-18 12:08 <DIR> d-------- C:\Documents and Settings\AdminNUS\Application Data\PCToolsFirewallPlus
2008-08-18 12:01 . 2008-08-18 12:08 <DIR> d-------- C:\Program Files\PC Tools Firewall Plus
2008-08-18 12:01 . 2008-08-18 12:01 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-08-18 12:01 . 2008-07-28 11:29 160,792 --a------ C:\WINDOWS\system32\drivers\pctfw2.sys
2008-08-18 12:01 . 2008-07-17 16:53 93,952 --a------ C:\WINDOWS\system32\drivers\pctfw.sys
2008-08-18 12:01 . 2008-08-05 15:58 58,136 --a------ C:\WINDOWS\system32\drivers\FWAuthdriver.sys
2008-08-11 22:48 . 2008-08-11 22:53 <DIR> d-------- C:\Documents and Settings\AdminNUS\DoctorWeb
2008-08-09 21:14 . 2008-08-09 21:14 250 --a------ C:\WINDOWS\gmer.ini
2008-08-06 14:57 . 2008-08-06 14:57 <DIR> d-------- C:\Deckard
2008-08-06 14:54 . 2004-08-04 20:00 95,744 --a------ C:\WINDOWS\system32\scardsvr.exe
2008-08-06 14:54 . 2004-08-04 20:00 95,744 --a------ C:\WINDOWS\system32\dllcache\scardsvr.exe
2008-08-05 10:30 . 2008-08-05 10:30 <DIR> d-------- C:\_OTMoveIt
2008-08-02 09:52 . 2008-08-02 09:52 <DIR> d-------- C:\Program Files\SpyZooka
2008-07-31 12:42 . 2008-08-17 15:01 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-31 12:42 . 2008-08-17 15:01 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-22 10:48 --------- d-----w C:\Program Files\MegauploadToolbar
2008-08-22 09:13 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-08-22 09:05 --------- d-----w C:\Program Files\Folding@Home
2008-08-21 14:23 --------- d-----w C:\Documents and Settings\AdminNUS\Application Data\OpenOffice.org2
2008-08-20 03:31 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-02 01:52 --------- d-----w C:\Program Files\Enigma Software Group
2008-08-01 13:32 --------- d-----w C:\Program Files\Common Files\Download Manager
2008-07-31 13:14 --------- d-----w C:\Documents and Settings\AdminNUS\Application Data\EaseDic
2008-07-31 04:29 4,224 ----a-w C:\WINDOWS\system32\drivers\beep.sys
2008-07-28 04:00 --------- d-----w C:\Documents and Settings\AdminNUS\Application Data\U3
2008-07-17 05:38 --------- d-----w C:\Program Files\Java
2008-06-24 15:01 --------- d-----w C:\Documents and Settings\AdminNUS\Application Data\AVGTOOLBAR
2008-02-25 07:56 54,184 ----a-w C:\Documents and Settings\AdminNUS\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot@2008-08-03_23.36.16.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-22 10:53:43 181,760 ----a-w C:\WINDOWS\BDOSCAN8\bdcore.dll
+ 2008-01-09 07:01:48 118,784 ----a-w C:\WINDOWS\BDOSCAN8\bdupd.dll
+ 2008-01-09 07:01:48 53,248 ----a-w C:\WINDOWS\BDOSCAN8\ipsupd.dll
+ 2008-08-22 10:53:50 142,848 ----a-w C:\WINDOWS\BDOSCAN8\libfn.dll
+ 2008-01-09 07:01:48 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
+ 2008-02-27 07:59:28 290,816 ----a-w C:\WINDOWS\Downloaded Program Files\auc_lib.dll
+ 2008-01-09 07:01:48 118,784 ----a-w C:\WINDOWS\Downloaded Program Files\bdupd.dll
+ 2008-02-27 07:59:28 495,616 ----a-w C:\WINDOWS\Downloaded Program Files\daas_s.dll
+ 2008-02-27 08:00:12 262,144 ----a-w C:\WINDOWS\Downloaded Program Files\fscax.dll
+ 2008-02-27 07:59:16 588,392 ----a-w C:\WINDOWS\Downloaded Program Files\gatelauncher.exe
+ 2008-01-09 07:01:48 53,248 ----a-w C:\WINDOWS\Downloaded Program Files\ipsupd.dll
+ 2008-08-09 13:14:09 884,736 ----a-w C:\WINDOWS\gmer.dll
+ 2008-04-17 13:13:02 811,008 ----a-w C:\WINDOWS\gmer.exe
+ 2008-08-05 15:23:02 3,072 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\neodesk\d4bca03d\b6361190\okoizxcq.dll
- 2008-08-03 15:28:13 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-08-11 14:46:42 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-08-03 15:28:13 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-08-11 14:46:42 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-08-03 15:28:13 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-08-11 14:46:42 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2001-08-17 05:52:30 18,688 ----a-w C:\WINDOWS\system32\dllcache\cdaudio.sys
- 2004-08-04 13:00:00 18,688 ----a-w C:\WINDOWS\system32\drivers\cdaudio.sys
+ 2001-08-17 05:52:30 18,688 ----a-w C:\WINDOWS\system32\drivers\cdaudio.sys
+ 2008-08-09 13:14:09 85,969 ----a-w C:\WINDOWS\system32\drivers\gmer.sys
- 2008-04-22 12:45:07 63,930 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-08-22 09:10:04 63,930 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-04-22 12:45:07 406,896 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-08-22 09:10:05 406,896 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2006-03-17 00:38:01 28,672 ------w C:\WINDOWS\system32\verclsid.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 00:24 1694208]
"Desktop Calendar"="C:\Program Files\Desktop Calendar\Desktop Calendar.exe" [2003-10-31 12:38 442368]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 21:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATSwpNav"="C:\Program Files\Fingerprint Sensor\ATSwpNav -run" [X]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-01-05 17:03 761946]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-03 15:22 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-03 15:26 118784]
"IndicatorUtility"="C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2005-08-10 02:53 81920]
"LoadFUJ02E3"="C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe" [2005-06-09 01:20 69632]
"LoadBtnHnd"="C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe" [2005-11-05 06:48 61440]
"LoadFujitsuQuickTouch"="C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe" [2005-07-22 06:21 242688]
"DispSwitchLauncher"="C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe" [2005-07-21 07:23 90112]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-08-01 20:10 122940]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 20:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 20:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 20:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 20:00 455168]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe" [2006-01-17 21:26 988654]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-01-17 21:26 118784]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 22:32 53248]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 21:00 158208]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-08 22:49 15691264 C:\WINDOWS\RTHDCPL.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2006-01-17 13:26 88365 C:\WINDOWS\AGRSMMSG.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 21:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 01:43 69632 C:\WINDOWS\Alcmtr.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2005-05-12 12:40 4167376]

C:\Documents and Settings\AdminNUS\Start Menu\Programs\Startup\
Folding@Home 5.03.lnk - C:\Program Files\Folding@Home\winFAH.exe [2007-12-26 20:40:55 323584]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
Post-itr Software Notes Lite.lnk - C:\Program Files\3M\PSNLite\PsnLite.exe [2004-06-02 13:04:58 1622016]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office Communicator\\communicator.exe"=
"C:\\Program Files\\Gizmo Project\\mDNSResponder.exe"=
"C:\\Program Files\\Gizmo Project\\Gizmo.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20244:TCP"= 20244:TCP:BitComet 20244 TCP
"20244:UDP"= 20244:UDP:BitComet 20244 UDP

R0 FJGPNV;FJGPNV;C:\WINDOWS\system32\drivers\FJGPNV.SYS [2005-02-02 15:34]
R0 O2MDRDR;O2MDRDR;C:\WINDOWS\system32\DRIVERS\o2media.sys [2005-07-09 06:06]
R0 O2SDRDR;O2SDRDR;C:\WINDOWS\system32\DRIVERS\o2sd.sys [2005-09-23 23:48]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-02 12:03]
R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2008-07-28 11:29]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-02 12:03]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-02 12:03]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-02 12:03]
R2 FlashDrv;FlashDrv;C:\PROGRA~1\Fujitsu\FlashAid\FlashDrv.sys [2005-07-22 06:56]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;C:\WINDOWS\system32\DRIVERS\FUJ02E3.sys [2004-01-17 20:15]
R3 FWAuth;FWAuth Driver;C:\WINDOWS\system32\drivers\FWAuthDriver.sys [2008-08-05 15:58]
S3 FUJ02E1;%FUJ02E1.DeviceDesc%;C:\WINDOWS\system32\Drivers\FUJ02E1.sys [2001-09-07 01:01]
S3 RapFile;RapFile;C:\WINDOWS\system32\drivers\RapFile.sys [2003-06-20 06:40]
S3 RapNet;RapNet;C:\WINDOWS\system32\drivers\RapNet.sys [2003-06-20 06:40]
S4 black;black;C:\WINDOWS\system32\drivers\BlackDrv.sys [2004-09-09 22:30]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e73d2111-3058-11dd-93e2-001302ad0ccf}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2008-08-01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-AVG7_CC - C:\PROGRA~1\Grisoft\AVG7\avgcc.exe


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\AdminNUS\Application Data\Mozilla\Firefox\Profiles\6pik8vzg.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com.sg/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-22 22:17:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Gizmo Project\mDNSResponder.exe
C:\Program Files\NUS-VPN\cvpnd.exe
C:\WINDOWS\system32\o2flash.exe
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Fingerprint Sensor\ATSwpNav.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
.
**************************************************************************
.
Completion time: 2008-08-22 22:26:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-22 14:25:20
ComboFix2.txt 2008-08-08 06:52:32
ComboFix3.txt 2008-08-07 04:40:47
ComboFix4.txt 2008-08-05 02:26:32
ComboFix5.txt 2008-08-22 14:10:57

Pre-Run: 12,869,414,912 bytes free
Post-Run: 12,952,793,088 bytes free

209 --- E O F --- 2008-08-18 04:37:55
  • 0

#54
mercurius

mercurius

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
the bit defender scan report turns out to be empty, i'm not sure why but the file contains 0 byte.
  • 0

#55
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hi... your latest logs look very good to me.. How is your computer now? :)
  • 0

Advertisements


#56
mercurius

mercurius

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
feels okay, haven't got any notification from AVG but there seems to be some problems with the registry where my S&D Bot resident keeps detecting a change in registry and AVG do not seem to run automatically at startup even when all seems okay from msconfig.
  • 0

#57
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts

feels okay, haven't got any notification from AVG but there seems to be some problems with the registry where my S&D Bot resident keeps detecting a change in registry and AVG do not seem to run automatically at startup even when all seems okay from msconfig.


Can you tell me what exactly the S&D Bot detected?.. A screenshot would be nice.. Not sure why your AVG behaves like that.. Can you post me a fresh DSS log as well? :)

Edited by fenzodahl512, 25 August 2008 - 03:18 AM.

  • 0

#58
mercurius

mercurius

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
No more notification from S&D so far, but main changes I've detected is that my AVG no longer runs on startup but S&D does. Here's a log from S&D:


17/02/2008 15:14:06 Allowed (based on user decision) value "SpyHunter Security Suite" (new data: "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe") added in System Startup global entry!
17/02/2008 15:58:10 Allowed (based on user decision) value "SpyHunter Security Suite" (new data: "") deleted in System Startup global entry!
17/02/2008 16:06:46 Allowed (based on user decision) value "{4B3803EA-5230-4DC3-A7FC-33638F3D3542}" (new data: "hex:00") added in Global browser toolbar!
17/02/2008 16:06:51 Allowed (based on user decision) value "{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}" (new data: "") added in Browser Helper Object!
17/02/2008 16:11:42 Allowed (based on user decision) value "Crawler Search" (new data: "") added in Browser menu extension!
17/02/2008 16:13:38 Denied (based on user decision) value "{4B3803EA-5230-4DC3-A7FC-33638F3D3542}" (new data: "hex:EA,03,38,4B,30,52,C3,4D,A7,FC,33,63,8F,3D,35,42") added in User-specific browser toolbar!
17/02/2008 16:51:17 Denied (based on user decision) value "BootExecute" (new data: "autocheck autochk *
C:\DOCUME~1\ALLUSE~1\APPLIC~1\SPYWAR~1\sp_rsdel.exe "\??\C:\DOCUME~1\ALLUSE~1\APPLIC~1\SPYWAR~1\sp_rsdel.dat

") changed in Session manager!
17/02/2008 16:51:34 Allowed (based on user decision) value "{8BD4438C-2511-4B93-AD34-2BDCD0FF78D2}" (new data: "") deleted in Browser Helper Object!
17/02/2008 16:54:27 Allowed (based on user decision) value "{7E853D72-626A-48EC-A868-BA8D5E23E045}" (new data: "") deleted in Browser Helper Object!
17/02/2008 16:56:21 Allowed (based on user decision) value "{81705D67-3F73-4983-859B-97D0922E5ABE}" (new data: "") deleted in Global browser toolbar!
17/02/2008 17:21:49 Denied (based on user decision) value "{81705D67-3F73-4983-859B-97D0922E5ABE}" (new data: "") deleted in User-specific browser toolbar!
17/02/2008 17:21:58 Allowed (based on user decision) value "{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383}" (new data: "") deleted in Browser Helper Object!
17/02/2008 17:23:08 Allowed (based on user decision) value "{4B3803EA-5230-4DC3-A7FC-33638F3D3542}" (new data: "") deleted in Global browser toolbar!
17/02/2008 17:23:19 Allowed (based on user decision) value "{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}" (new data: "") deleted in Browser Helper Object!
17/02/2008 17:23:20 Allowed (based on user decision) value "Crawler Search" (new data: "") deleted in Browser menu extension!
17/02/2008 17:23:24 Allowed (based on user decision) value "Uninstall_CToolbar" (new data: ""C:\WINDOWS\Temp\CTun.exe" "/remove"") added in System Startup global entry!
17/02/2008 17:26:40 Allowed (based on user decision) value "Uninstall_CToolbar" (new data: "") deleted in System Startup global entry!
19/02/2008 20:04:21 Allowed (based on user decision) value "Adobe Reader Speed Launcher" (new data: "") deleted in System Startup global entry!
19/02/2008 20:04:23 Allowed (based on user decision) value "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}" (new data: "") deleted in Browser Helper Object!
19/02/2008 20:05:01 Allowed (based on user decision) value "Adobe Reader Speed Launcher" (new data: ""C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"") added in System Startup global entry!
19/02/2008 20:05:04 Allowed (based on user decision) value "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}" (new data: "") added in Browser Helper Object!
27/02/2008 17:02:44 Allowed (based on user decision) value "{81705D67-3F73-4983-859B-97D0922E5ABE}" (new data: "") deleted in User-specific browser toolbar!
27/02/2008 17:08:56 Allowed (based on user decision) value "{9030D464-4C02-4ABF-8ECC-5164760863C6}" (new data: "") added in Browser Helper Object!
27/02/2008 17:09:25 Allowed (based on user decision) value "msnmsgr" (new data: ""C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background") changed in System Startup user entry!
27/02/2008 17:09:27 Allowed (based on user decision) value "{7E853D72-626A-48EC-A868-BA8D5E23E045}" (new data: "") added in Browser Helper Object!
04/03/2008 23:22:55 Allowed (based on user decision) value "SpybotSD TeaTimer" (new data: "") deleted in System Startup user entry!
04/03/2008 23:22:56 Allowed (based on user decision) value "QuickTime Task" (new data: "") deleted in System Startup global entry!
04/03/2008 23:22:57 Allowed (based on user decision) value "Adobe Photo Downloader" (new data: "") deleted in System Startup global entry!
04/03/2008 23:23:47 Allowed (based on user decision) value "Sony Ericsson PC Suite" (new data: "") deleted in System Startup global entry!
04/03/2008 23:23:51 Allowed (based on user decision) value "MSConfig" (new data: "C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto") added in System Startup global entry!
20/08/2008 11:31:59 Allowed (based on authenticode whitelist) value "SpybotSD TeaTimer" (new data: "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe") added in System Startup user entry!
20/08/2008 11:32:33 Denied (based on user decision) value "SunJavaUpdateSched" (new data: ""C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"") changed in System Startup global entry!
20/08/2008 11:32:34 Denied (based on user decision) value "AVG8_TRAY" (new data: "C:\PROGRA~1\AVG\AVG8\avgtray.exe") added in System Startup global entry!
20/08/2008 11:32:35 Denied (based on user decision) value "00PCTFW" (new data: ""C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s") added in System Startup global entry!
20/08/2008 11:32:36 Denied (based on user decision) value "Sony Ericsson PC Suite" (new data: ""C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions") added in System Startup global entry!
20/08/2008 11:32:37 Denied (based on user decision) value "QuickTime Task" (new data: ""C:\Program Files\QuickTime\QTTask.exe" -atboottime") added in System Startup global entry!
20/08/2008 11:32:37 Denied (based on user decision) value "Adobe Photo Downloader" (new data: ""C:\Program Files\Sony Ericsson\3.0\Apps\apdproxy.exe"") added in System Startup global entry!
20/08/2008 11:32:38 Denied (based on user decision) value "Alcmtr" (new data: "") deleted in System Startup global entry!
20/08/2008 11:32:38 Denied (based on user decision) value "" (new data: "") deleted in System Startup global entry!
20/08/2008 11:32:39 Denied (based on user decision) value "AVG7_CC" (new data: "") deleted in System Startup global entry!
20/08/2008 11:32:41 Denied (based on user decision) value "MSConfig" (new data: "") deleted in System Startup global entry!
20/08/2008 11:39:13 Denied (based on user decision) value "MSConfig" (new data: "") deleted in System Startup global entry!
21/08/2008 22:23:47 Denied (based on user decision) value "MSConfig" (new data: "") deleted in System Startup global entry!
22/08/2008 17:06:29 Denied (based on user blacklist) value "MSConfig" (new data: "") deleted in System Startup global entry!
2008-08-22 22:19:19 Denied (based on user decision) value "Alcmtr" (new data: "") deleted in System Startup global entry!
2008-08-22 22:19:27 Denied (based on user decision) value "" (new data: "") deleted in System Startup global entry!
2008-08-22 22:19:27 Denied (based on user blacklist) value "MSConfig" (new data: "") deleted in System Startup global entry!
22/08/2008 22:47:24 Denied (based on user decision) value "AVG7_CC" (new data: "") deleted in System Startup global entry!
22/08/2008 22:47:50 Denied (based on user decision) value "Alcmtr" (new data: "") deleted in System Startup global entry!
22/08/2008 22:47:56 Denied (based on user decision) value "" (new data: "") deleted in System Startup global entry!
22/08/2008 22:47:56 Denied (based on user blacklist) value "MSConfig" (new data: "") deleted in System Startup global entry!
22/08/2008 22:52:15 Allowed (based on user decision) value "MSConfig" (new data: "") deleted in System Startup global entry!
  • 0

#59
mercurius

mercurius

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
DSS log

Deckard's System Scanner v20071014.68
Run by cx on 2008-08-26 19:38:40
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as cx.exe) --------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:38:52, on 26/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Gizmo Project\mDNSResponder.exe
C:\Program Files\NUS-VPN\cvpnd.exe
C:\WINDOWS\system32\o2flash.exe
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Fingerprint Sensor\ATSwpNav.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Desktop Calendar\Desktop Calendar.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Folding@Home\winFAH.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Folding@Home\FahCore_82.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\AdminNUS\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\cx.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.c...uth.srf?lc=1033
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LoadFUJ02E3] C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [DispSwitchLauncher] C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ATSwpNav] "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Desktop Calendar] C:\Program Files\Desktop Calendar\Desktop Calendar.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'Default user')
O4 - Startup: Folding@Home 5.03.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.nus.edu.sg
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1152237826813
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1152237878563
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-sec...m/ols/fscax.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = stu.nus.edu.sg
O17 - HKLM\Software\..\Telephony: DomainName = stu.nus.edu.sg
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = stu.nus.edu.sg
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = stu.nus.edu.sg
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Gizmo Project\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\NUS-VPN\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\WINDOWS\system32\o2flash.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\RapApp.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 11475 bytes

-- Files created between 2008-07-26 and 2008-08-26 -----------------------------

2008-08-22 20:09:53 0 d-------- C:\fsaua.data
2008-08-22 18:52:49 0 d-------- C:\WINDOWS\BDOSCAN8
2008-08-18 16:25:29 0 d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-08-18 16:25:16 0 d-------- C:\Program Files\DVDVideoSoft
2008-08-18 12:08:25 0 d-------- C:\Documents and Settings\AdminNUS\Application Data\PCToolsFirewallPlus
2008-08-18 12:01:30 93952 --a------ C:\WINDOWS\system32\drivers\pctfw.sys <Not Verified; PC Tools; PC Tools NDIS Driver>
2008-08-18 12:01:29 0 d-------- C:\Program Files\Common Files\PC Tools
2008-08-18 12:01:28 0 d-------- C:\Program Files\PC Tools Firewall Plus
2008-08-11 22:48:44 0 d-------- C:\Documents and Settings\AdminNUS\DoctorWeb
2008-08-04 23:41:34 0 d-------- C:\cmdcons
2008-08-04 23:40:16 68096 --a------ C:\WINDOWS\zip.exe
2008-08-04 23:40:16 49152 --a------ C:\WINDOWS\VFind.exe
2008-08-04 23:40:16 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-08-04 23:40:16 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-08-04 23:40:16 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-08-04 23:40:16 98816 --a------ C:\WINDOWS\sed.exe
2008-08-04 23:40:16 80412 --a------ C:\WINDOWS\grep.exe
2008-08-04 23:40:16 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-08-02 09:52:15 0 d-------- C:\Program Files\SpyZooka


-- Find3M Report ---------------------------------------------------------------

2008-08-25 23:47:01 12 --a------ C:\WINDOWS\bthservsdp.dat
2008-08-22 22:14:02 0 d-------- C:\Program Files\Common Files
2008-08-22 18:48:30 0 d-------- C:\Program Files\MegauploadToolbar
2008-08-22 17:13:15 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-22 17:05:51 0 d-------- C:\Program Files\Folding@Home
2008-08-21 22:23:31 0 d-------- C:\Documents and Settings\AdminNUS\Application Data\OpenOffice.org2
2008-08-02 09:52:20 0 d-------- C:\Program Files\Enigma Software Group
2008-08-01 21:32:26 0 d-------- C:\Program Files\Common Files\Download Manager
2008-07-31 21:14:48 0 d-------- C:\Documents and Settings\AdminNUS\Application Data\EaseDic
2008-07-28 12:00:54 0 d-------- C:\Documents and Settings\AdminNUS\Application Data\U3
2008-07-24 20:17:40 0 d-------- C:\Documents and Settings\AdminNUS\Application Data\Macromedia
2008-07-17 13:38:24 0 d-------- C:\Program Files\Java


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
02/06/2008 12:03 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [02/06/2008 12:03 2050816]

[-HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [05/01/2006 17:03]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [03/11/2005 15:22]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [03/11/2005 15:26]
"RTHDCPL"="RTHDCPL.EXE" [08/12/2005 22:49 C:\WINDOWS\RTHDCPL.exe]
"IndicatorUtility"="C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [10/08/2005 02:53]
"LoadFUJ02E3"="C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe" [09/06/2005 01:20]
"LoadBtnHnd"="C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe" [05/11/2005 06:48]
"LoadFujitsuQuickTouch"="C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe" [22/07/2005 06:21]
"DispSwitchLauncher"="C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe" [21/07/2005 07:23]
"AGRSMMSG"="AGRSMMSG.exe" [17/01/2006 13:26 C:\WINDOWS\AGRSMMSG.exe]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [01/08/2005 20:10]
"ATSwpNav"="C:\Program Files\Fingerprint Sensor\ATSwpNav -run" []
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [04/08/2004 20:00]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [04/08/2004 20:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [04/08/2004 20:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [04/08/2004 20:00]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [25/09/2007 01:11]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe" [17/01/2006 21:26]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [17/01/2006 21:26]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [04/02/2002 22:32]
"BluetoothAuthenticationAgent"="bthprops.cpl" [04/08/2004 21:00 C:\WINDOWS\system32\bthprops.cpl]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 22:16]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" []
"Alcmtr"="ALCMTR.EXE" [03/05/2005 01:43 C:\WINDOWS\Alcmtr.exe]
"@"="" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18/10/2007 11:34]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [14/10/2004 00:24]
"Desktop Calendar"="C:\Program Files\Desktop Calendar\Desktop Calendar.exe" [31/10/2003 12:38]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 21:00]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 11:43]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe"

C:\Documents and Settings\AdminNUS\Start Menu\Programs\Startup\
Folding@Home 5.03.lnk - C:\Program Files\Folding@Home\winFAH.exe [26/12/2007 20:40:55]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [13/02/2001 01:01:04]
Post-itr Software Notes Lite.lnk - C:\Program Files\3M\PSNLite\PsnLite.exe [02/06/2004 13:04:58]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e73d2111-3058-11dd-93e2-001302ad0ccf}]
AutoRun\command- F:\LaunchU3.exe -a




-- End of Deckard's System Scanner: finished at 2008-08-26 19:39:17 ------------
  • 0

#60
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts

20/08/2008 11:32:34 Denied (based on user decision) value "AVG8_TRAY" (new data: "C:\PROGRA~1\AVG\AVG8\avgtray.exe") added in System Startup global entry!
20/08/2008 11:32:35 Denied (based on user decision) value "00PCTFW" (new data: ""C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s") added in System Startup global entry!


Why do you denied the AVG8 and PC Tools firewall start-up in Spybot S&D?

By the way, your log looks clean to me.. Have you try to uninstall >> Re-install AVG8? Tell me more about it..
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP