Antivirus PRO 2008 problem - PLEASE HELP
K1RA New Member Date Joined Jun 2008 Total Posts : 10 Posted 7-14-2008 3:48 (GMT +1)
Hi,
Four nights ago I was downloading Hellboy 2 torrent and clicked on the read me doc that came along with it, it told me to go to a site to download some sort of file so my movie will play but instead I got this annoying virus called Antivirus PRO 2008. (don't worry I learnt my lesson!) I'm trying to be cool about this but deep inside I'm panicking as hell and wish this would go away as my PC is very important to me (as to most of us I'm sure). HELP~!!!
I am not the most computer savvy person in the world, and the people around cant help me either
so here I am asking for some online help.
I have AVG and Adaware free editions but they seem to be useless as they did not detect this was coming
Anyway, here's a list of things the virus has done to my PC.
- I can't access control panel. - I can't access my C: drive as it seems to have dissapeared along with other icons. - 'All programs', 'run' and 'search' are all missing from the start menu as well as other things next to 'Turn off computer' (forgot the names) - I can't open windows explorer. Not even holding the windows key + E helps as it says the administrator has disabled it. - I get constant and annoying alerts saying I have alot of viruses. Then automatically opens up all these websites offering virus protection. - Next to the time in the bottom right it says 'VIRUS ALERT!'. - Also in the bottom right it has a flashing red cross.
I don't want to have to reboot my PC because one I don't have the original Windows XP CD to re-install again as Windows XP just came with the laptop pre-installed. Secondly, I am in Japan and it is very hard to get versions of programs that I need and thirdly, I am not computer savvy.
I'm scared to do anything or go on the internet to check even my email account because someone might be watching me, so I'm taking a risk doing this from my infected PC.
So if there are some 'angels' who can help me perform a miracle, I will be forever grateful.
Kindest Regards and thanks for taking time out to read this,
Ricky
P.S. I was recommended to download Avast (free?) and get rid of my AVG and Adaware free editions. Is having more than one antivirus bad in that it slows down my system? Is Avast better? Please advise.
Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16319 Posted 7-14-2008 4:45 (GMT +1) Hello
Please download Malwarebytes' Anti-Malware:
to your desktop .
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch
Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform full scan , then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location.
Copy and Paste that log into your next reply.
Do NOT post your problem in someone elses thread.
Back to Top
K1RA New Member Date Joined Jun 2008 Total Posts : 10 Posted 7-15-2008 12:47 (GMT +1) Hi Touch,
Thanks for the reply, but when I try to click on that link, it opens up a new window and I get PCPrivacy Cleaner
Then it quickly changes to a message 'Insecure Internet Activity. Threat of virus attack' with the following message below:
Due to insecure Internet browsing your PC can easily get infected with viruses, worms and trojans without your knowledge, and that can lead to system slowdown, freezes and crashes. Also insecure Internet activity can result in revealing your personal information. To get full advanced real-time protection for PC and Internet activity, register KvmSecure.
oh and I'm running this with internet explorer because my Firefox won't open.
Back to Top
K1RA New Member Date Joined Jun 2008 Total Posts : 10 Posted 7-15-2008 1:56 (GMT +1) -UPDATE- Ok, so I managed to download Malwarebytes' Anti-Malware version 1.20 from www.download.com since this was the only site that didn't re-direct me to PCPrivacyCleaner or virusremover2008 websites which I'm guessing causes more problems and are fake. Is this ok Touch? Just want to get your approval before I start doing anything. Cheers, R Back to Top
K1RA New Member Date Joined Jun 2008 Total Posts : 10 Posted 7-15-2008 2:14 (GMT +1) oh now I can't even install the program :( grr problem after problem!!! I double click on it and click run but it won't. Do I have to do this in safe mode or something? Back to Top
K1RA New Member Date Joined Jun 2008 Total Posts : 10 Posted 7-15-2008 3:26 (GMT +1) ok, seems like all I had to do was click the run it option and not save it to my desktop when at the start of downloading it, saving it and clicking run doesn't work. Anyway, here's my log below, most things are restored on my system, except a few icons on my desktop and other things that I probably don't know about. Also my system performance is still slower than normal. Malwarebytes' Anti-Malware 1.20 Database version: 950 Windows 5.1.2600 Service Pack 2 11:09:22 AM 15/07/2008 mbam-log-7-15-2008 (11-09-22).txt Scan type: Full Scan (C:\|) Objects scanned: 107825 Time elapsed: 34 minute(s), 15 second(s) Memory Processes Infected: 1 Memory Modules Infected: 7 Registry Keys Infected: 21 Registry Values Infected: 6 Registry Data Items Infected: 18 Folders Infected: 4 Files Infected: 35 Memory Processes Infected: C:\Program Files\Antivirus 2008 PRO\antivirus-2008pro.exe (Rogue.Installer) -> Unloaded process successfully. Memory Modules Infected: C:\WINDOWS\system32\byXNdaXr.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\iwpnxddg.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\xxywxUol.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\fdxbameg.dll (Trojan.FakeAlert) -> Unloaded module successfully. C:\WINDOWS\fsrpknov.dll (Trojan.FakeAlert) -> Unloaded module successfully. C:\WINDOWS\sqvgnrpx.dll (Trojan.FakeAlert) -> Unloaded module successfully. C:\WINDOWS\wbxdpgferqp.dll (Trojan.FakeAlert) -> Unloaded module successfully. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03e4717e-335c-4762-80d9-32141ae3ec30} (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{03e4717e-335c-4762-80d9-32141ae3ec30} (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{6cf0a05e-7d6b-4e00-b836-b3f23513657c} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6cf0a05e-7d6b-4e00-b836-b3f23513657c} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xxywxuol (Trojan.Vundo) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\antivirus 2008 pro (Rogue.Antivirus2008) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{45158c8e-9e7c-4d61-b56a-14466ea00f8d} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{f7daa83a-8aa6-4431-941b-a25fb6dbffea} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webvideo (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{3c3cf12d-cab9-4f34-a1c7-0cd0fc6c49e7} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a244a95e-b86a-47a3-b876-3094e3d715d2} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{77106b8f-6fb4-48b6-9d18-1e9d71af0db8} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{2f660dd0-182f-4b6f-9332-1265e6eedad3} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2f660dd0-182f-4b6f-9332-1265e6eedad3} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\sqvgnrpx.bblq (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\sqvgnrpx.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\eca4ef67 (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus-2008pro.exe (Rogue.Installer) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6cf0a05e-7d6b-4e00-b836-b3f23513657c} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\fdxbameg (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\fsrpknov (Trojan.FakeAlert) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{a244a95e-b86a-47a3-b876-3094e3d715d2} (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\byxndaxr -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\byxndaxr -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.Homepage) -> Bad: (http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId (Trojan.FakeAlert) -> Bad: (VIRUS ALERT!) Good: (76477-OEM-0011903-00102) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Control Panel\International\sTimeFormat (Trojan.FakeAlert) -> Bad: (HH:mm: VIRUS ALERT!) Good: (h:mm:ss tt) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowControlPanel (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowRun (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoStartMenuMorePrograms (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives (Hijack.Drives) -> Bad: (12) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoToolbarCustomize (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispCPL (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Program Files\Antivirus 2008 PRO (Rogue.Antivirus2008) -> Quarantined and deleted successfully. C:\Program Files\Antivirus 2008 PRO\Infected (Rogue.Antivirus2008) -> Quarantined and deleted successfully. C:\Program Files\Antivirus 2008 PRO\Suspicious (Rogue.Antivirus2008) -> Quarantined and deleted successfully. C:\Documents and Settings\Ricky J\Start Menu\Programs\Antivirus 2008 PRO (Rogue.Antivirus2008) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\byXNdaXr.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\rXadNXyb.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\rXadNXyb.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\iwpnxddg.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\gddxnpwi.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Program Files\Antivirus 2008 PRO\antivirus-2008pro.exe (Rogue.Installer) -> Quarantined and deleted successfully. C:\WINDOWS\system32\xxywxUol.dll (Trojan.Vundo) -> Delete on reboot. C:\Documents and Settings\Ricky J\Local Settings\Application Data\Mozilla\Firefox\Profiles\urx5dwxz.default\Cache\9FACE185d01 (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Ricky J\Local Settings\Temp\dssc32.exe (Rogue.Installer) -> Quarantined and deleted successfully. C:\Documents and Settings\Ricky J\Local Settings\Temporary Internet Files\Content.IE5\0R5COC8B\Antivirus2008PRO.exe (Rogue.Installer) -> Quarantined and deleted successfully. C:\Documents and Settings\Ricky J\Local Settings\Temporary Internet Files\Content.IE5\0R5COC8B\file.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Ricky J\Local Settings\Temporary Internet Files\Content.IE5\BW4E3HNI\kb456456 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP119\A0016784.exe (Rogue.Installer) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP119\A0018935.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP120\A0019003.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP120\A0019126.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP120\A0022166.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\epal.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Program Files\Antivirus 2008 PRO\vscan.tsi (Rogue.Antivirus2008) -> Quarantined and deleted successfully. C:\Program Files\Antivirus 2008 PRO\zlib.dll (Rogue.Antivirus2008) -> Quarantined and deleted successfully. C:\Documents and Settings\Ricky J\Start Menu\Programs\Antivirus 2008 PRO\antivirus-2008pro.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully. C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\clbdll.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\drivers\clbdriver.sys (Rootkit.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\urqPgeEv.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\fdxbameg.dll (Trojan.FakeAlert) -> Delete on reboot. C:\WINDOWS\fsrpknov.dll (Trojan.FakeAlert) -> Delete on reboot. C:\WINDOWS\gpefaowr.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\sqvgnrpx.dll (Trojan.FakeAlert) -> Delete on reboot. C:\WINDOWS\wbxdpgferqp.dll (Trojan.FakeAlert) -> Delete on reboot. C:\Documents and Settings\Ricky J\Application Data\TmpRecentIcons\antivirus-2008pro.lnk (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\Ricky J\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus-2008pro.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully. C:\Documents and Settings\Ricky J\Favorites\Error Cleaner.url (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\Ricky J\Favorites\Privacy Protector.url (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\Ricky J\Favorites\Spyware&Malware Protection.url (Rogue.Link) -> Quarantined and deleted successfully. Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16319 Posted 7-15-2008 7:05 (GMT +1) Good job
Please download Combofix:
And save to the desktop.
Close all other browser windows.
Please connect all your external hard drive/flash drive before running Combofix
Important-> Temporarily disable your anti-virus, real-time protection before performing a scan. They can interfere with combofix or remove some of its embedded files which may cause "unpredictable results".
Go to Start->Run and copy/paste: ComboFix /snapshot and hit OK. It should run Combofix.
Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.
When finished, it will produce a logfile located at C:\combofix.txt.
Post the contents of that log in your next reply with a new hijackthis log.
Please copy and paste your log files. DO NOT add it as an attachment
Do NOT post your problem in someone elses thread.
Back to Top
K1RA New Member Date Joined Jun 2008 Total Posts : 10 Posted 7-15-2008 7:27 (GMT +1) Hi Touch,
thanks for that, umm a question before I continue, what is a new highjackthis log as mentioned?
and I quote - "Post the contents of that log in your next reply with a new hijackthis log ."
Thanks for clarifying in advance.
R
Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16319 Posted 7-16-2008 1:41 (GMT +1) My bad
1. Get this version of Hijackthis from http://danborg.org/spy/hjt/alternativ.exe 2 Save it in a permanent folder of your choice, such as C:\HJT\. To create this specific folder on your hard drive: Double click the 'My Computer' icon on your desktop, then under the category hard disk drives: double click Local Disk:, then select file->New -> Folder and name it HJT
3 Run hijackthis. (alternativ exe). Choose the "Do a system scan and save a log file " option to perform your scan.
HijackThis will analyze your system, and automatically open a notepad textfile containing the HijackThis log when the scan is finished.
Open the text files containing the logs with a text editor and click Edit -> Select All, followed by Edit -> Copy. From within the browser window and with the message body text box selected, click Edit -> Paste.
Do NOT post your problem in someone elses thread.
Back to Top
K1RA New Member Date Joined Jun 2008 Total Posts : 10 Posted 7-16-2008 11:34 (GMT +1) COMBOFIX LOG: ComboFix 08-07-14.2 - Ricky J 2008-07-16 19:15:17.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1408 [GMT 9:00] Running from: C:\Documents and Settings\Ricky J\Desktop\ComboFix.exe * Created a new restore pointWARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\bdnfpowl.ini C:\WINDOWS\system32\caoowcri.ini C:\WINDOWS\system32\clbdll.dll C:\WINDOWS\system32\clbinit.dll C:\WINDOWS\system32\iwpnxddg.dll C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\rXadNXyb.ini C:\WINDOWS\system32\rXadNXyb.ini2 . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_CLBDRIVER -------\Service_clbdriver ((((((((((((((((((((((((( Files Created from 2008-06-16 to 2008-07-16 ))))))))))))))))))))))))))))))) . 2008-07-15 11:29 . 2008-07-15 11:29 <DIR> d-------- C:\Program Files\iPod 2008-07-15 11:22 . 2008-07-15 11:22 <DIR> d-------- C:\Program Files\Safari 2008-07-15 10:31 . 2008-07-15 10:31 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-07-15 10:31 . 2008-07-15 10:31 <DIR> d-------- C:\Documents and Settings\Ricky J\Application Data\Malwarebytes 2008-07-15 10:31 . 2008-07-15 10:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-07-13 02:23 . 2007-12-02 04:54 <DIR> d-------- C:\Documents and Settings\Administrator.RJSTYLZ\Bluetooth Software 2008-07-13 02:23 . 2007-12-02 05:06 <DIR> d-------- C:\Documents and Settings\Administrator.RJSTYLZ\Application Data\Roxio 2008-07-13 02:23 . 2007-12-02 04:52 <DIR> d-------- C:\Documents and Settings\Administrator.RJSTYLZ\Application Data\Intel 2008-07-13 02:23 . 2007-12-02 04:52 <DIR> d-------- C:\Documents and Settings\Administrator.RJSTYLZ\Application Data\InstallShield 2008-07-13 02:23 . 2007-12-02 05:03 <DIR> d-------- C:\Documents and Settings\Administrator.RJSTYLZ\Application Data\GTek 2008-07-13 01:56 . 2007-12-02 05:06 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Roxio 2008-07-13 01:56 . 2007-12-02 04:52 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel 2008-07-13 01:56 . 2007-12-02 05:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\GTek 2008-07-12 02:25 . 2008-07-13 02:06 <DIR> d-------- C:\Program Files\Spyware Doctor 2008-07-12 01:31 . 2008-07-12 01:31 <DIR> d-------- C:\Program Files\Enigma Software Group 2008-07-12 01:27 . 2008-07-12 01:27 <DIR> d-------- C:\Program Files\Common Files\Download Manager 2008-07-09 02:04 . 2008-07-09 02:05 <DIR> d-------- C:\Program Files\QuickTime 2008-07-03 01:15 . 2008-07-03 01:15 <DIR> d-------- C:\Program Files\Apple Software Update 2008-06-18 00:38 . 2008-06-18 00:38 <DIR> d-------- C:\Program Files\AC3Filter 2008-06-17 20:41 . 2008-06-17 20:41 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Apple Computer . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-16 10:28 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-07-15 03:35 --------- d-----w C:\Documents and Settings\Ricky J\Application Data\Apple Computer 2008-07-15 02:29 --------- d-----w C:\Program Files\iTunes 2008-07-15 02:09 33,152 ----a-w C:\WINDOWS\system32\xxywxUol.dll 2008-07-15 02:09 322,304 ----a-w C:\WINDOWS\system32\byXNdaXr.dll 2008-07-14 05:31 1,773,318 --sha-w C:\WINDOWS\system32\bdnfpowl.tmp 2008-07-13 03:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7 2008-07-10 17:10 --------- d-----w C:\Program Files\Bonjour 2008-07-10 16:21 --------- d-----w C:\Documents and Settings\Ricky J\Application Data\LimeWire 2008-07-10 00:35 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys 2008-07-07 08:35 34,296 ----a-w C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-07-07 08:35 17,144 ----a-w C:\WINDOWS\system32\drivers\mbam.sys 2008-06-23 14:57 --------- d-----w C:\Documents and Settings\Ricky J\Application Data\Command & Conquer 3 Tiberium Wars 2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 17:41 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll 2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys 2008-06-17 15:28 --------- d-----w C:\Documents and Settings\Ricky J\Application Data\DivX 2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-11 22:51 --------- d-----w C:\Program Files\DivX 2008-06-11 14:20 --------- d-----w C:\Program Files\Windows Live Safety Center 2008-06-10 15:34 --------- d-----w C:\Program Files\Java 2008-06-06 16:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer 2008-06-06 16:45 --------- d-----w C:\Program Files\Common Files\Apple 2008-06-06 16:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple 2008-05-30 17:22 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe 2008-05-30 17:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2008-05-30 17:22 129,784 ----a-w C:\WINDOWS\system32\PxAFS.DLL 2008-05-30 17:19 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll 2008-05-30 17:19 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll 2008-05-08 12:28 202,752 ------w C:\WINDOWS\system32\dllcache\rmcast.sys 2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-07 05:18 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll 2008-04-23 13:16 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll 2008-04-22 07:40 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe 2008-04-22 07:39 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe 2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll 2007-12-09 14:28 0 ----a-w C:\Documents and Settings\Guest\Application Data\wklnhst.dat 2007-12-01 19:53 76 --sh--r C:\WINDOWS\CT4CET.bin 2007-12-09 08:26 952 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 13:09 460784] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-05 19:23 68856] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 09:34 5724184] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360] "DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 07:23 202544] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-03 15:20 851968] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-06 16:39 8429568] "OEM02Mon.exe"="C:\WINDOWS\OEM02Mon.exe" [2007-08-28 15:54 36864] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 06:00 208952] "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 06:00 59392] "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 06:00 455168] "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 06:00 455168] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 17:32 823296] "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 17:30 974848] "DELL Webcam Manager"="C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 17:43 118784] "Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2007-05-14 15:23 1191936] "KADxMain"="C:\WINDOWS\system32\KADxMain.exe" [2006-11-02 15:05 282624] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920] "PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-09-20 23:07 184320] "dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 07:24 16384] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-08 23:50 29744] "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 09:22 221184] "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-23 01:02 579584] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696] "DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 07:23 202544] "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064] "nwiz"="nwiz.exe" [2007-06-06 16:40 1626112 C:\WINDOWS\system32\nwiz.exe] "NVHotkey"="nvHotkey.dll" [2007-06-06 16:39 67584 C:\WINDOWS\system32\nvhotkey.dll] "NvMediaCenter"="NvMCTray.dll" [2007-06-06 16:39 81920 C:\WINDOWS\system32\nvmctray.dll] "SigmatelSysTrayApp"="stsystra.exe" [2007-05-06 15:10 405504 C:\WINDOWS\stsystra.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 06:00 15360] "AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-07 23:10 219136] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-05-17 16:43:18 568176] Dell Network Assistant.lnk - C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2007-12-02 05:04:19 7168] Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-12-02 04:53:40 50688] WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-04-28 11:20:00 415072] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.ac3filter"= ac3filter.acm [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.0\\cnc3game.dat"= "C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "10421:UDP"= 10421:UDP:SingleClick Discovery Protocol "10426:UDP"= 10426:UDP:SingleClick ICC R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2007-02-08 18:05] R3 OEM02Dev;Creative Camera OEM002 Driver;C:\WINDOWS\system32\DRIVERS\OEM02Dev.sys [2007-08-28 15:54] R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\WINDOWS\system32\DRIVERS\OEM02Vfx.sys [2007-08-28 15:55] S3 GoogleDesktopManager-112407-114954;Google Desktop Manager 5.6.711.24354;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2007-12-08 23:50] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{58c83314-a5fe-11dc-b8a2-001c23ad5559}] \Shell\Auto\command - DLLH0ST.exe \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DLLH0ST.exe . Contents of the 'Scheduled Tasks' folder "2008-07-15 00:25:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-16 19:26:38 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Dell Network Assistant\hnm_svc.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe C:\Program Files\Dell Network Assistant\ezi_hnm2.exe C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe C:\WINDOWS\system32\verclsid.exe . ************************************************************************** . Completion time: 2008-07-16 19:31:39 - machine was rebooted ComboFix-quarantined-files.txt 2008-07-16 10:31:35 Pre-Run: 68,527,112,192 bytes free Post-Run: 68,952,395,776 bytes free 219 --- E O F --- 2008-07-09 04:23:41 Back to Top
K1RA New Member Date Joined Jun 2008 Total Posts : 10 Posted 7-16-2008 11:40 (GMT +1) Hijackthis log: Logfile of HijackThis v1.99.1 Scan saved at 7:37:47 PM, on 16/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Dell Network Assistant\hnm_svc.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\OEM02Mon.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\WINDOWS\system32\KADxMain.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\WINDOWS\stsystra.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\DellSupport\DSAgnt.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe C:\Program Files\Dell Network Assistant\ezi_hnm2.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\HJT\alternativ.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com.au/ig/dell?hl=en&client=dell-row-rel&channel=au&ibd=5071202 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [OEM02Mon.exe] C:\WINDOWS\OEM02Mon.exe O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter O4 - Global Startup: Bluetooth.lnk = ? O4 - Global Startup: Dell Network Assistant.lnk = ? O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://supportapj.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/en/10/install/gtdownde.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: Google Desktop Manager 5.6.711.24354 (GoogleDesktopManager-112407-114954) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16319 Posted 7-16-2008 1:16 (GMT +1) Open notepad and copy/paste the text in the quote box below into it:
Quote:
-----------------------------------------------------
KILLALL::
Snapshot::
File::
C:\WINDOWS\system32\xxywxUol.dll C:\WINDOWS\system32\byXNdaXr.dll
C:\WINDOWS\system32\bdnfpowl.tmp
----------------------------------------------
Save this as CFScript.txt
At this point, You MUST EXIT ALL BROWSERS NOW before continuing!
Referring to the picture above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system.
It may reboot your system when it finishes. This is normal.
Post new combofix log and tell how things are running ?
Do NOT post your problem in someone elses thread.
Back to Top
K1RA New Member Date Joined Jun 2008 Total Posts : 10 Posted 7-16-2008 1:59 (GMT +1) Things seem back to normal now. I'm not taking any chances though, I'm getting rid of AVG and Adaware and downloading Avast, SUPERAntiSpyware and Codomo Firewall for protection. Any advice on my choices Touch? New ComboFix Log below: ComboFix 08-07-14.2 - Ricky J 2008-07-16 21:43:07.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1582 [GMT 9:00] Running from: C:\ComboFix.exe Command switches used :: C:\CFScript.txt * Created a new restore pointWARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE :: C:\WINDOWS\system32\bdnfpowl.tmp C:\WINDOWS\system32\byXNdaXr.dll C:\WINDOWS\system32\xxywxUol.dll . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\bdnfpowl.tmp C:\WINDOWS\system32\byXNdaXr.dll C:\WINDOWS\system32\xxywxUol.dll . ((((((((((((((((((((((((( Files Created from 2008-06-16 to 2008-07-16 ))))))))))))))))))))))))))))))) . 2008-07-16 19:53 . 2008-07-16 19:53 <DIR> d-------- C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP 2008-07-16 19:36 . 2008-07-16 21:21 <DIR> d-------- C:\HJT 2008-07-16 03:19 . 2008-07-16 03:19 2,613,152 --a------ C:\ComboFix.exe 2008-07-15 11:29 . 2008-07-15 11:29 <DIR> d-------- C:\Program Files\iPod 2008-07-15 10:31 . 2008-07-15 10:31 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-07-15 10:31 . 2008-07-15 10:31 <DIR> d-------- C:\Documents and Settings\Ricky J\Application Data\Malwarebytes 2008-07-15 10:31 . 2008-07-15 10:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-07-15 10:31 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-07-15 10:31 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-07-13 02:23 . 2007-12-02 04:54 <DIR> d-------- C:\Documents and Settings\Administrator.RJSTYLZ\Bluetooth Software 2008-07-13 02:23 . 2007-12-02 05:06 <DIR> d-------- C:\Documents and Settings\Administrator.RJSTYLZ\Application Data\Roxio 2008-07-13 02:23 . 2007-12-02 04:52 <DIR> d-------- C:\Documents and Settings\Administrator.RJSTYLZ\Application Data\Intel 2008-07-13 02:23 . 2007-12-02 04:52 <DIR> d-------- C:\Documents and Settings\Administrator.RJSTYLZ\Application Data\InstallShield 2008-07-13 02:23 . 2007-12-02 05:03 <DIR> d-------- C:\Documents and Settings\Administrator.RJSTYLZ\Application Data\GTek 2008-07-13 02:22 . 2008-07-13 02:23 <DIR> d-------- C:\Documents and Settings\Administrator.RJSTYLZ 2008-07-13 01:56 . 2007-12-02 05:06 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Roxio 2008-07-13 01:56 . 2007-12-02 04:52 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel 2008-07-13 01:56 . 2007-12-02 05:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\GTek 2008-07-13 01:56 . 2008-07-13 02:02 <DIR> d---s---- C:\Documents and Settings\Administrator 2008-07-12 02:25 . 2008-07-13 02:06 <DIR> d-------- C:\Program Files\Spyware Doctor 2008-07-12 01:31 . 2008-07-12 01:31 <DIR> d-------- C:\Program Files\Enigma Software Group 2008-07-12 01:27 . 2008-07-12 01:27 <DIR> d-------- C:\Program Files\Common Files\Download Manager 2008-07-11 01:58 . 2004-08-04 06:00 4,224 --a------ C:\WINDOWS\system32\beep.sys 2008-07-09 02:04 . 2008-07-09 02:05 <DIR> d-------- C:\Program Files\QuickTime 2008-07-03 01:17 . 2008-07-08 13:56 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-07-03 01:17 . 2008-07-03 01:17 1,409 --a------ C:\WINDOWS\QTFont.for 2008-07-03 01:15 . 2008-07-03 01:15 <DIR> d-------- C:\Program Files\Apple Software Update 2008-06-21 02:41 . 2008-06-21 02:41 245,248 --------- C:\WINDOWS\system32\dllcache\mswsock.dll 2008-06-20 19:44 . 2008-06-20 19:44 138,368 --------- C:\WINDOWS\system32\dllcache\afd.sys 2008-06-18 00:38 . 2008-06-18 00:38 <DIR> d-------- C:\Program Files\AC3Filter 2008-06-18 00:38 . 2007-08-18 16:54 380,928 --a------ C:\WINDOWS\system32\ac3filter.acm 2008-06-17 20:41 . 2008-06-17 20:41 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Apple Computer . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-16 12:50 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-07-16 11:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip 2008-07-16 10:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7 2008-07-16 10:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-07-15 03:35 --------- d-----w C:\Documents and Settings\Ricky J\Application Data\Apple Computer 2008-07-15 02:29 --------- d-----w C:\Program Files\iTunes 2008-07-10 16:21 --------- d-----w C:\Documents and Settings\Ricky J\Application Data\LimeWire 2008-07-10 00:35 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys 2008-06-23 14:57 --------- d-----w C:\Documents and Settings\Ricky J\Application Data\Command & Conquer 3 Tiberium Wars 2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys 2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys 2008-06-17 15:28 --------- d-----w C:\Documents and Settings\Ricky J\Application Data\DivX 2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-11 22:51 --------- d-----w C:\Program Files\DivX 2008-06-11 14:20 --------- d-----w C:\Program Files\Windows Live Safety Center 2008-06-10 15:34 --------- d-----w C:\Program Files\Java 2008-06-06 16:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer 2008-06-06 16:45 --------- d-----w C:\Program Files\Common Files\Apple 2008-06-06 16:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple 2008-05-30 17:22 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe 2008-05-30 17:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2008-05-30 17:22 129,784 ----a-w C:\WINDOWS\system32\PxAFS.DLL 2008-05-30 17:19 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll 2008-05-30 17:19 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll 2008-05-08 12:28 202,752 ------w C:\WINDOWS\system32\dllcache\rmcast.sys 2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-07 05:18 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll 2008-04-23 13:16 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll 2008-04-22 07:40 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe 2008-04-22 07:39 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe 2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll 2007-12-09 14:28 0 ----a-w C:\Documents and Settings\Guest\Application Data\wklnhst.dat 2007-12-01 19:53 76 --sh--r C:\WINDOWS\CT4CET.bin 2007-12-09 08:26 952 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 13:09 460784] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-05 19:23 68856] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 09:34 5724184] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360] "DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 07:23 202544] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-03 15:20 851968] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-06 16:39 8429568] "OEM02Mon.exe"="C:\WINDOWS\OEM02Mon.exe" [2007-08-28 15:54 36864] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 06:00 208952] "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 06:00 59392] "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 06:00 455168] "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 06:00 455168] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 17:32 823296] "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 17:30 974848] "DELL Webcam Manager"="C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 17:43 118784] "Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2007-05-14 15:23 1191936] "KADxMain"="C:\WINDOWS\system32\KADxMain.exe" [2006-11-02 15:05 282624] "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920] "PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-09-20 23:07 184320] "dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 07:24 16384] "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-08 23:50 29744] "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 09:22 221184] "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-23 01:02 579584] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696] "DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 07:23 202544] "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064] "nwiz"="nwiz.exe" [2007-06-06 16:40 1626112 C:\WINDOWS\system32\nwiz.exe] "NVHotkey"="nvHotkey.dll" [2007-06-06 16:39 67584 C:\WINDOWS\system32\nvhotkey.dll] "NvMediaCenter"="NvMCTray.dll" [2007-06-06 16:39 81920 C:\WINDOWS\system32\nvmctray.dll] "SigmatelSysTrayApp"="stsystra.exe" [2007-05-06 15:10 405504 C:\WINDOWS\stsystra.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 06:00 15360] "AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-07 23:10 219136] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-05-17 16:43:18 568176] Dell Network Assistant.lnk - C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2007-12-02 05:04:19 7168] Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-12-02 04:53:40 50688] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.ac3filter"= ac3filter.acm [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"= "C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.0\\cnc3game.dat"= "C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "10421:UDP"= 10421:UDP:SingleClick Discovery Protocol "10426:UDP"= 10426:UDP:SingleClick ICC R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2007-02-08 18:05] R3 OEM02Dev;Creative Camera OEM002 Driver;C:\WINDOWS\system32\DRIVERS\OEM02Dev.sys [2007-08-28 15:54] R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\WINDOWS\system32\DRIVERS\OEM02Vfx.sys [2007-08-28 15:55] S3 GoogleDesktopManager-112407-114954;Google Desktop Manager 5.6.711.24354;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2007-12-08 23:50] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{58c83314-a5fe-11dc-b8a2-001c23ad5559}] \Shell\Auto\command - DLLH0ST.exe \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL DLLH0ST.exe . Contents of the 'Scheduled Tasks' folder "2008-07-15 00:25:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-16 21:49:14 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Dell Network Assistant\hnm_svc.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\Dell Network Assistant\ezi_hnm2.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe C:\Program Files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2008-07-16 21:53:01 - machine was rebooted ComboFix-quarantined-files.txt 2008-07-16 12:52:57 ComboFix2.txt 2008-07-16 10:31:40 Pre-Run: 68,832,440,320 bytes free Post-Run: 68,824,100,864 bytes free 218 --- E O F --- 2008-07-09 04:23:41 Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16319 Posted 7-16-2008 4:39 (GMT +1) Avast, SUPERAntiSpyware and Codomo Firewall, sounds like a really good choise to Me
Combolog looks clean.
To completely and immediately remove any infected file or files in the data store, turn off and then turn on System Restore. To do so, follow these steps: System Restore
Please read Tony Klein's excellent article about how to prevent against spyware/hijackers in the future
http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html
Do NOT post your problem in someone elses thread.
Back to Top
K1RA New Member Date Joined Jun 2008 Total Posts : 10 Posted 7-16-2008 5:49 (GMT +1) thanks for everything Touch, really appreciate it I did what you said and turned off and then turned on system restore. Although, I don't fully understand how it will remove any infected files from the date store...sorry like I said Im not computer savvy >_< I'll have a read of that article sometime too. Cheers :D R Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16319 Posted 7-16-2008 6:28 (GMT +1) If there are any infected files in systemrestore, they will be flushed out/removed in the process
Since your problem appears to be resolved, this thread will now be closed.
If you need this topic reopened, please PM a Moderator and we will reopen it for you
Do NOT post your problem in someone elses thread.
Back to Top
Forum Information Currently it is Saturday, November 21, 2009 3:10 PM (GMT +1) There are a total of 73.032 posts in 17.116 threads. In the last 3 days there were 14 new threads and 69 reply posts. View Active Threads Who's Online This forum has 30334 registered members. Please welcome our newest member, sushil . 29 Guest(s), 0 Registered Member(s) are currently online. Details 5 Latest Threads