Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Need help with virus that takes over admin powers
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Need help with virus that takes over admin powers  
Forum Quick Jump
 
New Topic Post reply to : Need help with virus that takes over admin powers Printable version of : Need help with virus that takes over admin powers
37 posts in this thread.
Viewing Page :
 1  2 
[ << Previous Thread | Next Thread >> ]

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 11-21-2009 7:38 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Ok I have some bizarre virus that has these properties

* Disables both Task Manager and Regedit
* Does not allow me to get into Safe Mode (either get blue screen or comp just restarts)
* The virus always comes back even after format!
* Using a VBS file or whatever to remove registry values such as disable task manger and disable reg edit is useless because the second they get removed, they come back again. Though I have just enough time to open task manager... not much seems out of order in processes
* I cannot use gpedit.msc, dunno if it is my old version of windows or the virus causing that.
* I cannot open many things with the virus active (Yahoo, Raid service, MSN, Spybot, malware bytes etc all get the message "has encountered a problem and needs to close. We are sorry for the inconvenience)
* The virus seems to malfunction when I use msconfig and use diagnostic start up (ei When I delete the disable task manager values in regedit, they don't come back while in diagnostic start up). This makes me beleive it is a running service or start up that is causing the problems

I have 3 hard drives btw, all has been formatted (c:, d: and e:). I have beaten a lot of virus before but this one has me stumped, I dunno what to do. It is my first time here so please forgive me if I have done anything wrong. What should I do?
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 11-22-2009 3:35 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Welcome to BG forums urbane,

Infection that returns even after a reformat suggests an autorun worm, that has infected some external drive you use (including usb/flash/thumb etc.). Once any infected drive is returned to the computer it infects it anew. Let's get some details and take a look.


The malware has included an autorun type component, so if any external drives have been used on this computer recently be sure to install them now, and leave them installed until ALL repairs on it are completed. If not, they will remain infected and can re-infect the computer (or others).


To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.


[Version]
Signature="$Windows NT$"

[DefaultInstall]
DelReg=RemoveRestrictions
AddReg=ResetRegChanges

[ResetRegChanges]
HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowControlPanel,0x10001,0x00000002
HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowHelp,0x10001,0x00000001
HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowMyComputer,0x10001,0x00000002
HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowMyDocs,0x10001,0x00000001
HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowMyMusic,0x10001,0x00000001
HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowMyPics,0x10001,0x00000001
HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowNetPlaces,0x10001,0x00000001
HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowRun,0x10001,0x00000001
HKCU,Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced,Start_ShowSearch,0x10001,0x00000001
HKCU,Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoDrives,0x10001,0x00000000

[RemoveRestrictions]
HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NoSetFolders"
HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NoSetFolders"
HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NoStartMenuMorePrograms"
HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NoStartMenuMorePrograms"
HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NoToolbarCustomize"
HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","NoToolbarCustomize"
HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","StartMenuLogoff"
HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\Explorer","StartMenuLogoff"
HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System","DisableCMD"
HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\System","DisableCMD"
HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System","DisableRegistryTools"
HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\System","DisableRegistryTools"
HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System","DisableTaskMgr"
HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\System","DisableTaskMgr"
HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System","NoDispCPL"
HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\System","NoDispCPL"
HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System","NoDispBackgroundPage"
HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\System","NoDispBackgroundPage"
HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System","NoDispScrSavPage"
HKLM, "Software\Microsoft\Windows\CurrentVersion\Policies\System","NoDispScrSavPage"
HKCU, "Software\Policies\Microsoft\Internet Explorer\Restrictions","NoBrowserOptions"
HKLM, "Software\Policies\Microsoft\Internet Explorer\Restrictions","NoBrowserOptions"
HKCU, "Software\Policies\Microsoft\Windows\system","DisableCMD"
HKLM, "Software\Policies\Microsoft\Windows\system","DisableCMD"

Open Notepad (Start - Run, type Notepad then press OK), and copy the text inside the Code box above and paste it into the open Notepad textbox.

Save this to your desktop as correct.inf

Be sure to include the "" quotes in the name.

Then right-click on correct.inf and select Install.

This may provide some Task Manager and other access improvements there. You can rerun this as needed for now.

---------------

Download RSIT (random's system information tool) from here to your desktop. Then click on the RSIT.exe to open the RSIT display, and click the Continue button.

If necessary allow it to locate or download a copy of HijackThis as needed.

Once the scan completes a textbox will open - copy/paste those contents here for review please. The log can also be found at C:\rsit\log.txt.

RSIT will also create a second log, info.txt, which will be minimized to your taskbar. Post that here as well please (it will also be stored at C:\rsit\info.txt).

You can break logs into parts and use separate posts here when replying and posting the log files, if needed.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 11-22-2009 9:09 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
The INF folder allows me 0.1 seconds to hit ctrl alt delete, if i dont then task manager disabled again lol. My logs is a lot of info. I accidentally closed the second log info.txt and i cant get it back. Here is the first log

Logfile of random's system information tool 1.06 (written by random/random)
Run by Owner at 2009-11-22 17:56:46
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 55 GB (72%) free of 76 GB
Total RAM: 2047 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:56:46 PM, on 11/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Owner\Desktop\RSIT.exe
C:\Program Files\trend micro\Owner.exe

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [D-Link D-Link Wireless G DWA-110] C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe

--
End of file - 2801 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1385808]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-11-15 155648]
"nwiz"=nwiz.exe /installquiet []
"NVRaidService"=C:\WINDOWS\system32\nvraidservice.exe [2004-11-02 166400]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2004-11-15 86016]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2004-11-15 4620288]
"D-Link D-Link Wireless G DWA-110"=C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe [2007-05-04 1736704]
"ANIWZCS2Service"=C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe [2007-01-19 131072]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 113520]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 1009016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"=C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe [2009-11-10 5317944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
"DisableRegistryTools"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\Owner\Desktop\Firefox Setup 3.5.5.exe"="C:\Documents and Settings\Owner\Desktop\Firefox Setup 3.5.5.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\nfar.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\nfar.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\xpjpt.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\xpjpt.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\wscntfy.exe"="C:\WINDOWS\system32\wscntfy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winbqqft.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winbqqft.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\obpmv.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\obpmv.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\DllHost.exe"="C:\WINDOWS\system32\DllHost.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\wincucadj.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wincucadj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\vsnp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\vsnp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winkgacr.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winkgacr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\epfoo.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\epfoo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\ranjd.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\ranjd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winlwesrk.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winlwesrk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\xgqsjp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\xgqsjp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\dslrc.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\dslrc.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winpaglux.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winpaglux.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\wineryhy.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wineryhy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winkstil.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winkstil.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winnrgaa.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winnrgaa.exe:*:Enabled:ipsec"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winudpi.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winudpi.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\fwqvh.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\fwqvh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winyfhxw.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winyfhxw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winlvksf.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winlvksf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\jnvky.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\jnvky.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winnlycq.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winnlycq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\windsttv.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\windsttv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winwoeivm.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winwoeivm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winomhryb.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winomhryb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winuwup.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winuwup.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winfogs.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winfogs.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\delj.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\delj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\xtus.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\xtus.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\vrfwc.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\vrfwc.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\wxar.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wxar.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winvoksk.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winvoksk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\wbpl.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wbpl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\wineyjxd.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wineyjxd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winlfxo.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winlfxo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winjjco.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winjjco.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\wincefjy.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wincefjy.exe:*:Enabled:ipsec"
"C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe"="C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe:*:Enabled:ipsec"
"C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winyhgce.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winyhgce.exe:*:Enabled:ipsec"
"C:\SamRO\RO\VanRO.exe"="C:\SamRO\RO\VanRO.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\taskmgr.exe"="C:\WINDOWS\system32\taskmgr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winktolbk.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winktolbk.exe:*:Enabled:ipsec"
"C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe"="C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\lmtey.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\lmtey.exe:*:Enabled:ipsec"
"D:\My Documents\VanRO\RO\VanRO.exe"="D:\My Documents\VanRO\RO\VanRO.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winwblb.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winwblb.exe:*:Enabled:ipsec"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winxcqanp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winxcqanp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winqlqhyo.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winqlqhyo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\pjamp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\pjamp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\wingniq.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wingniq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\windxfik.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\windxfik.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\cqexd.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\cqexd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\yfey.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\yfey.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\iime.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\iime.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\xdvjfp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\xdvjfp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winvxakgt.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winvxakgt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\qqfki.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\qqfki.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winbeega.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winbeega.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winrkyjiw.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winrkyjiw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winomcfmm.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winomcfmm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winspybl.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winspybl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winhjmks.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winhjmks.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winmjllk.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winmjllk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winyyhdou.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winyyhdou.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winqowk.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winqowk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\nxffp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\nxffp.exe:*:Enabled:ipsec"
"C:\WINDOWS\SOUNDMAN.EXE"="C:\WINDOWS\SOUNDMAN.EXE:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winkrpmd.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winkrpmd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winmiyriv.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winmiyriv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winmgplpi.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winmgplpi.exe:*:Enabled:ipsec"
"C:\SamRO\RO\SamRO.exe"="C:\SamRO\RO\SamRO.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\gcpid.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\gcpid.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winjbxov.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winjbxov.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winacrpkd.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winacrpkd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winkluqd.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winkluqd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\cmvu.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\cmvu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winpalh.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winpalh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\rmftc.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\rmftc.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\pusuu.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\pusuu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\wincbrjrm.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\wincbrjrm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\onxjo.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\onxjo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\lyphqq.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\lyphqq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\cdkpmp.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\cdkpmp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winvrlvh.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winvrlvh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\bmnwgu.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\bmnwgu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\yjxqv.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\yjxqv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\rxyb.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\rxyb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winhvnm.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winhvnm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winbolo.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winbolo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winiqvfxo.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winiqvfxo.exe:*:Enabled:ipsec"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\winlgusds.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\winlgusds.exe:*:Enabled:ipsec"
"C:\DOCUME~1\Owner\LOCALS~1\Temp\uvyiew.exe"="C:\DOCUME~1\Owner\LOCALS~1\Temp\uvyiew.exe:*:Enabled:ipsec"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f1c5b506-d4cd-11de-a144-806d6172696f}]
shell\AutoRun\command - E:\autorun.exe

======List of files/folders created in the last 1 months======

2009-11-22 17:56:07 ----D---- C:\rsit
2009-11-22 17:56:07 ----D---- C:\Program Files\trend micro
2009-11-21 04:52:20 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-11-21 04:52:19 ----A---- C:\Documents and Settings\All Users\Application Data\hpeED.dll
2009-11-21 04:52:13 ----D---- C:\Program Files\Sony Ericsson
2009-11-21 04:52:13 ----D---- C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2009-11-20 19:25:04 ----D---- C:\Documents and Settings\Owner\Application Data\vlc
2009-11-20 19:24:21 ----D---- C:\Program Files\VideoLAN
2009-11-20 18:16:05 ----D---- C:\SamRO
2009-11-20 17:50:48 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-11-20 17:50:48 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-20 17:11:05 ----D---- C:\Documents and Settings\Owner\Application Data\AVG8
2009-11-20 17:10:24 ----D---- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2009-11-20 17:10:20 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-11-20 17:10:20 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-11-20 17:00:27 ----D---- C:\WINDOWS\pss
2009-11-20 03:20:41 ----A---- C:\WINDOWS\system32\h323log.txt
2009-11-20 03:18:26 ----A---- C:\WINDOWS\system32\irmon.dll
2009-11-20 03:18:26 ----A---- C:\WINDOWS\system32\irftp.exe
2009-11-20 03:18:25 ----A---- C:\WINDOWS\system32\wshirda.dll
2009-11-20 03:18:12 ----A---- C:\WINDOWS\system32\usbui.dll
2009-11-20 03:17:17 ----A---- C:\WINDOWS\imsins.BAK
2009-11-20 03:17:15 ----SHD---- C:\WINDOWS\Installer
2009-11-20 03:17:15 ----D---- C:\Program Files\Common Files\ODBC
2009-11-20 03:17:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-11-20 03:17:15 ----A---- C:\WINDOWS\ODBCINST.INI
2009-11-20 03:17:12 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-11-20 03:17:11 ----RD---- C:\Program Files
2009-11-20 03:17:11 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-11-20 03:17:11 ----D---- C:\Program Files\Common Files
2009-11-20 03:17:08 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-11-20 03:17:08 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-11-20 03:17:08 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-11-20 03:17:06 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-11-20 03:17:05 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-11-20 03:17:05 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-11-20 03:17:05 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-11-20 03:17:05 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-11-20 03:17:05 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-11-20 03:17:03 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-11-20 03:17:01 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-11-20 03:17:01 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-11-20 03:17:01 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-11-20 03:17:01 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-11-20 03:17:01 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-11-20 03:16:59 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-11-20 03:16:58 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-11-20 03:16:56 ----A---- C:\WINDOWS\system32\irclass.dll
2009-11-20 03:16:56 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-11-20 03:16:56 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-11-20 03:16:55 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-11-20 03:16:55 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-11-20 03:16:53 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-11-20 03:16:53 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-11-20 03:16:52 ----A---- C:\WINDOWS\system32\batt.dll
2009-11-20 03:16:52 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-11-20 03:16:51 ----A---- C:\WINDOWS\system32\storprop.dll
2009-11-20 03:16:44 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-11-20 03:16:39 ----RA---- C:\WINDOWS\SET8.tmp
2009-11-20 03:16:37 ----RA---- C:\WINDOWS\SET4.tmp
2009-11-20 03:16:35 ----RA---- C:\WINDOWS\SET3.tmp
2009-11-20 03:16:30 ----D---- C:\WINDOWS\system32\CatRoot2
2009-11-20 03:16:30 ----D---- C:\WINDOWS\system32\CatRoot
2009-11-20 03:16:25 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-11-20 03:16:04 ----A---- C:\WINDOWS\setuplog.txt
2009-11-20 03:16:00 ----SHD---- C:\System Volume Information
2009-11-20 03:16:00 ----D---- C:\Documents and Settings
2009-11-20 03:14:31 ----SH---- C:\boot.ini
2009-11-20 03:08:54 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-11-20 03:08:54 ----RSD---- C:\WINDOWS\Fonts
2009-11-20 03:08:54 ----RD---- C:\WINDOWS\Web
2009-11-20 03:08:54 ----HD---- C:\WINDOWS\inf
2009-11-20 03:08:54 ----D---- C:\WINDOWS\WinSxS
2009-11-20 03:08:54 ----D---- C:\WINDOWS\twain_32
2009-11-20 03:08:54 ----D---- C:\WINDOWS\Temp
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\wins
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\wbem
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\usmt
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\spool
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\ShellExt
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\Setup
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\ras
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\oobe
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\npp
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\mui
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\inetsrv
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\IME
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\icsxml
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\ias
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\export
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\drivers
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\dhcp
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\config
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\3com_dmi
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\3076
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\2052
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1054
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1042
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1041
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1037
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1033
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1031
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1028
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32\1025
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system32
2009-11-20 03:08:54 ----D---- C:\WINDOWS\system
2009-11-20 03:08:54 ----D---- C:\WINDOWS\security
2009-11-20 03:08:54 ----D---- C:\WINDOWS\Resources
2009-11-20 03:08:54 ----D---- C:\WINDOWS\repair
2009-11-20 03:08:54 ----D---- C:\WINDOWS\Provisioning
2009-11-20 03:08:54 ----D---- C:\WINDOWS\PeerNet
2009-11-20 03:08:54 ----D---- C:\WINDOWS\pchealth
2009-11-20 03:08:54 ----D---- C:\WINDOWS\mui
2009-11-20 03:08:54 ----D---- C:\WINDOWS\msapps
2009-11-20 03:08:54 ----D---- C:\WINDOWS\msagent
2009-11-20 03:08:54 ----D---- C:\WINDOWS\Media
2009-11-20 03:08:54 ----D---- C:\WINDOWS\java
2009-11-20 03:08:54 ----D---- C:\WINDOWS\ime
2009-11-20 03:08:54 ----D---- C:\WINDOWS\Help
2009-11-20 03:08:54 ----D---- C:\WINDOWS\Driver Cache
2009-11-20 03:08:54 ----D---- C:\WINDOWS\Debug
2009-11-20 03:08:54 ----D---- C:\WINDOWS\Cursors
2009-11-20 03:08:54 ----D---- C:\WINDOWS\Connection Wizard
2009-11-20 03:08:54 ----D---- C:\WINDOWS\Config
2009-11-20 03:08:54 ----D---- C:\WINDOWS\AppPatch
2009-11-20 03:08:54 ----D---- C:\WINDOWS\addins
2009-11-20 03:08:54 ----D---- C:\WINDOWS
2009-11-20 01:44:57 ----D---- C:\Documents and Settings\Owner\Application Data\Yahoo!
2009-11-20 01:42:32 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo!
2009-11-20 01:37:02 ----D---- C:\Program Files\Yahoo!
2009-11-19 18:57:50 ----D---- C:\Documents and Settings\Owner\Application Data\WinRAR
2009-11-19 18:03:41 ----D---- C:\POV pervert disc 1
2009-11-19 17:52:25 ----D---- C:\POV pervert disc 2
2009-11-19 17:43:08 ----D---- C:\Documents and Settings\Owner\Application Data\Media Player Classic
2009-11-19 17:32:32 ----D---- C:\Documents and Settings\Owner\Application Data\Leadertech
2009-11-19 17:28:17 ----D---- C:\Documents and Settings\Owner\Application Data\Macromedia
2009-11-19 17:28:16 ----D---- C:\Documents and Settings\Owner\Application Data\Adobe
2009-11-19 17:25:23 ----D---- C:\NeverwinterNights
2009-11-19 17:24:37 ----D---- C:\WINDOWS\system32\Lang
2009-11-19 17:22:05 ----D---- C:\Program Files\WinRAR
2009-11-19 17:20:38 ----SHD---- C:\RECYCLER
2009-11-19 17:20:10 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-11-19 17:20:05 ----D---- C:\Program Files\Common Files\Adobe
2009-11-19 17:20:05 ----D---- C:\Program Files\Adobe
2009-11-19 17:19:13 ----A---- C:\WINDOWS\system32\unrar.dll
2009-11-19 17:19:13 ----A---- C:\WINDOWS\avisplitter.ini
2009-11-19 17:19:12 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2009-11-19 17:19:12 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2009-11-19 17:19:12 ----A---- C:\WINDOWS\system32\xvidcore.dll
2009-11-19 17:19:11 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2009-11-19 17:19:11 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2009-11-19 17:19:10 ----D---- C:\Program Files\K-Lite Codec Pack
2009-11-19 17:02:53 ----HDC---- C:\WINDOWS\$NtUninstallKB926239$
2009-11-19 17:02:50 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-11-19 17:02:48 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-11-19 17:02:42 ----D---- C:\Program Files\Windows Media Connect 2
2009-11-19 17:02:37 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2009-11-19 17:02:17 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2009-11-19 17:02:03 ----D---- C:\WINDOWS\system32\LogFiles
2009-11-19 17:02:02 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-11-19 17:02:01 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-11-19 17:01:45 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-11-19 17:01:33 ----A---- C:\WINDOWS\system32\wpa.bak
2009-11-19 17:00:24 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla
2009-11-19 17:00:17 ----D---- C:\Program Files\Mozilla Firefox
2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\wnicapi.dll
2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\WlanApp.dll
2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\odSupp_M.dll
2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\JJAKEn.dll
2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\AQCKGen.dll
2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\ANIWZCS2.dll
2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\ANICtl.dll
2009-11-19 16:51:43 ----A---- C:\WINDOWS\system32\aIPH.dll
2009-11-19 16:51:29 ----D---- C:\Program Files\ANI
2009-11-19 16:51:29 ----A---- C:\WINDOWS\system32\ANIOApi.dll
2009-11-19 16:51:02 ----D---- C:\Program Files\D-Link
2009-11-19 16:50:57 ----D---- C:\Documents and Settings\Owner\Application Data\InstallShield
2009-11-19 16:44:07 ----D---- C:\WINDOWS\nview
2009-11-19 16:44:06 ----A---- C:\WINDOWS\system32\nvudisp.exe
2009-11-19 16:44:00 ----A---- C:\WINDOWS\system32\nwiz.exe
2009-11-19 16:43:59 ----A---- C:\WINDOWS\system32\nvwimg.dll
2009-11-19 16:43:59 ----A---- C:\WINDOWS\system32\nvwdmcpl.dll
2009-11-19 16:43:59 ----A---- C:\WINDOWS\system32\nvwddi.dll
2009-11-19 16:43:59 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2009-11-19 16:43:58 ----A---- C:\WINDOWS\system32\nvshell.dll
2009-11-19 16:43:58 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2009-11-19 16:43:58 ----A---- C:\WINDOWS\system32\nvnt4cpl.dll
2009-11-19 16:43:58 ----A---- C:\WINDOWS\system32\nvcodins.dll
2009-11-19 16:43:58 ----A---- C:\WINDOWS\system32\nvcod.dll
2009-11-19 16:43:57 ----A---- C:\WINDOWS\system32\nvdspsch.exe
2009-11-19 16:43:57 ----A---- C:\WINDOWS\system32\nvappbar.exe
2009-11-19 16:43:56 ----A---- C:\WINDOWS\system32\nview.dll
2009-11-19 16:43:56 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2009-11-19 16:43:56 ----A---- C:\WINDOWS\system32\keystone.exe
2009-11-19 16:43:55 ----A---- C:\WINDOWS\system32\nvmctray.dll
2009-11-19 16:43:55 ----A---- C:\WINDOWS\system32\nvcpl.dll
2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrszht.dll
2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrszhc.dll
2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrsptb.dll
2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrsko.dll
2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrsja.dll
2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrsit.dll
2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrsfr.dll
2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrses.dll
2009-11-19 16:43:54 ----A---- C:\WINDOWS\system32\nvwrsde.dll
2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrszht.dll
2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrszhc.dll
2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrsptb.dll
2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrsko.dll
2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrsja.dll
2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrsit.dll
2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrsfr.dll
2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrses.dll
2009-11-19 16:43:53 ----A---- C:\WINDOWS\system32\nvrsde.dll
2009-11-19 16:43:49 ----D---- C:\WINDOWS\system32\WinFast
2009-11-19 16:42:54 ----D---- C:\WINDOWS\system32\WinFox
2009-11-19 16:38:32 ----RA---- C:\WINDOWS\system32\NvSataConnectionzht.dll
2009-11-19 16:38:32 ----RA---- C:\WINDOWS\system32\NvRaidWizardzht.dll
2009-11-19 16:38:32 ----A---- C:\WINDOWS\system32\nvuide.exe
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvSataConnectionzhc.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvSataConnectiontr.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvSataConnectionth.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvSataConnectionsv.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidzht.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidzhc.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidWizardzhc.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidWizardtr.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidWizardth.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidtr.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidth.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidSvzht.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidSvzhc.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidSvtr.dll
2009-11-19 16:38:31 ----RA---- C:\WINDOWS\system32\NvRaidSvth.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvSataConnectionsl.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvSataConnectionsk.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvSataConnectionru.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvSataConnectionptb.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidWizardsv.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidWizardsl.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidWizardsk.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidWizardru.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidSvsv.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidSvsl.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidSvsk.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidSvru.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidsv.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidsl.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidsk.dll
2009-11-19 16:38:30 ----RA---- C:\WINDOWS\system32\NvRaidru.dll
2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvSataConnectionpt.dll
2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvSataConnectionpl.dll
2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvSataConnectionno.dll
2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidWizardptb.dll
2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidWizardpt.dll
2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidWizardpl.dll
2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidSvptb.dll
2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidSvpt.dll
2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidSvpl.dll
2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidptb.dll
2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidpt.dll
2009-11-19 16:38:29 ----RA---- C:\WINDOWS\system32\NvRaidpl.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvSataConnectionnl.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvSataConnectionko.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvSataConnectionja.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidWizardno.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidWizardnl.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidWizardko.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidWizardja.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidSvno.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidSvnl.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidSvko.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidSvja.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidno.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidnl.dll
2009-11-19 16:38:28 ----RA---- C:\WINDOWS\system32\NvRaidko.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvSataConnectionit.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvSataConnectionhu.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvSataConnectionhe.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvSataConnectionfr.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidWizardit.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidWizardhu.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidWizardhe.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidSvit.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidSvhu.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidSvhe.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidja.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidit.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidhu.dll
2009-11-19 16:38:27 ----RA---- C:\WINDOWS\system32\NvRaidhe.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvSataConnectionfi.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvSataConnectiones.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvSataConnectioneng.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidWizardfr.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidWizardfi.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidWizardes.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidWizardeng.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidSvfr.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidSvfi.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidSves.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidSveng.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidfr.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaidfi.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaides.dll
2009-11-19 16:38:26 ----RA---- C:\WINDOWS\system32\NvRaideng.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvSataConnectionel.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvSataConnectionde.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvSataConnectionda.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvSataConnectioncs.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidWizardel.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidWizardde.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidWizardda.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidWizardcs.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidSvel.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidSvde.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidSvda.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidel.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidde.dll
2009-11-19 16:38:25 ----RA---- C:\WINDOWS\system32\NvRaidda.dll
2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvSataConnectionEnu.dll
2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvSataConnectionar.dll
2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\nvsataconnection.exe
2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidWizardEnu.dll
2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidWizardar.dll
2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidSvEnu.dll
2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidSvcs.dll
2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidSvar.dll
2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\nvraidservice.exe
2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidEnu.dll
2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidcs.dll
2009-11-19 16:38:24 ----RA---- C:\WINDOWS\system32\NvRaidar.dll
2009-11-19 16:38:23 ----RA---- C:\WINDOWS\system32\NvRaidWizard.dll
2009-11-19 16:38:23 ----RA---- C:\WINDOWS\system32\NvRaidMan.exe
2009-11-19 16:38:17 ----RA---- C:\WINDOWS\system32\nvraidco.dll
2009-11-19 16:38:17 ----A---- C:\WINDOWS\system32\nvraiins.dll
2009-11-19 16:38:11 ----RA---- C:\WINDOWS\system32\idecoi.dll
2009-11-19 16:36:34 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-11-19 16:36:31 ----D---- C:\Program Files\Realtek Sound Manager
2009-11-19 16:36:28 ----N---- C:\WINDOWS\avrack.ini
2009-11-19 16:36:28 ----D---- C:\Program Files\AvRack
2009-11-19 16:36:23 ----A---- C:\WINDOWS\system32\RTLCPAPI.dll
2009-11-19 16:36:22 ----N---- C:\WINDOWS\system32\ChCfg.exe
2009-11-19 16:36:22 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2009-11-19 16:36:17 ----A---- C:\WINDOWS\system32\RTLCPL.EXE
2009-11-19 16:36:08 ----N---- C:\WINDOWS\alcupd.exe
2009-11-19 16:36:08 ----N---- C:\WINDOWS\alcrmv.exe
2009-11-19 16:36:07 ----HD---- C:\Program Files\InstallShield Installation Information
2009-11-19 16:33:49 ----RA---- C:\WINDOWS\system32\fdco1ins.dll
2009-11-19 16:33:49 ----RA---- C:\WINDOWS\system32\fdco1.dll
2009-11-19 16:33:47 ----RA---- C:\WINDOWS\system32\nvconrm.dll
2009-11-19 16:33:47 ----RA---- C:\WINDOWS\system32\bdco1ins.dll
2009-11-19 16:33:47 ----RA---- C:\WINDOWS\system32\bdco1.dll
2009-11-19 16:33:47 ----A---- C:\WINDOWS\system32\nvunrm.exe
2009-11-19 16:33:46 ----RA---- C:\WINDOWS\system32\nvusmb.exe
2009-11-19 16:33:46 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2009-11-19 16:33:36 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-11-19 16:33:29 ----D---- C:\Program Files\Common Files\InstallShield
2009-11-19 16:30:26 ----D---- C:\Documents and Settings\Owner\Application Data\Identities
2009-11-19 16:30:24 ----HD---- C:\Program Files\Uninstall Information
2009-11-19 16:30:20 ----ASH---- C:\Documents and Settings\Owner\Application Data\desktop.ini
2009-11-19 16:30:19 ----SD---- C:\Documents and Settings\Owner\Application Data\Microsoft
2009-11-19 16:30:13 ----D---- C:\WINDOWS\SoftwareDistribution
2009-11-19 16:30:12 ----SD---- C:\WINDOWS\system32\Microsoft
2009-11-19 16:30:12 ----D---- C:\WINDOWS\Prefetch
2009-11-19 16:30:12 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-11-19 16:26:34 ----D---- C:\WINDOWS\system32\xircom
2009-11-19 16:26:34 ----D---- C:\Program Files\xerox
2009-11-19 16:26:34 ----D---- C:\Program Files\microsoft frontpage
2009-11-19 16:26:26 ----A---- C:\WINDOWS\control.ini
2009-11-19 16:26:26 ----A---- C:\AUTOEXEC.BAT
2009-11-19 16:26:13 ----A---- C:\WINDOWS\OEWABLog.txt
2009-11-19 16:26:09 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-11-19 16:25:35 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-11-19 16:25:35 ----RD---- C:\WINDOWS\Offline Web Pages
2009-11-19 16:25:35 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-11-19 16:25:30 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-11-19 16:25:27 ----HD---- C:\Program Files\WindowsUpdate
2009-11-19 16:25:07 ----D---- C:\WINDOWS\system32\DirectX
2009-11-19 16:24:44 ----A---- C:\WINDOWS\system32\atrace.dll
2009-11-19 16:24:41 ----A---- C:\WINDOWS\system32\desktop.ini
2009-11-19 16:24:41 ----A---- C:\WINDOWS\desktop.ini
2009-11-19 16:24:33 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-11-19 16:24:32 ----A---- C:\WINDOWS\system32\acctres.dll
2009-11-19 16:24:31 ----D---- C:\Program Files\Common Files\Services
2009-11-19 16:24:28 ----SD---- C:\WINDOWS\Tasks
2009-11-19 16:24:28 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-11-19 16:24:26 ----D---- C:\Program Files\Common Files\MSSoap
2009-11-19 16:24:22 ----D---- C:\WINDOWS\srchasst
2009-11-19 16:24:21 ----D---- C:\WINDOWS\system32\Macromed
2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wups.dll
2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-11-19 16:24:17 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-11-19 16:24:16 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-11-19 16:24:16 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-11-19 16:24:16 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-11-19 16:24:16 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-11-19 16:24:16 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-11-19 16:24:12 ----D---- C:\Program Files\Movie Maker
2009-11-19 16:24:07 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-11-19 16:24:07 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-11-19 16:24:07 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-11-19 16:24:07 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-11-19 16:24:04 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-11-19 16:24:04 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-11-19 16:24:03 ----D---- C:\WINDOWS\system32\Restore
2009-11-19 16:24:03 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-11-19 16:24:03 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-11-19 16:24:03 ----A---- C:\WINDOWS\system32\srclient.dll
2009-11-19 16:24:02 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-11-19 16:24:02 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-11-19 16:24:02 ----A---- C:\WINDOWS\system32\ils.dll
2009-11-19 16:24:01 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-11-19 16:24:01 ----A---- C:\WINDOWS\system32\msconf.dll
2009-11-19 16:24:01 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-11-19 16:23:58 ----D---- C:\Program Files\NetMeeting
2009-11-19 16:23:58 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-11-19 16:23:58 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-11-19 16:23:57 ----A---- C:\WINDOWS\system32\inetres.dll
2009-11-19 16:23:56 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-11-19 16:23:54 ----D---- C:\Program Files\Outlook Express
2009-11-19 16:23:54 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-11-19 16:23:54 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-11-19 16:23:54 ----A---- C:\WINDOWS\system32\mstask.dll
2009-11-19 16:23:53 ----A---- C:\WINDOWS\system32\isign32.dll
2009-11-19 16:23:53 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-11-19 16:23:53 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-11-19 16:23:53 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-11-19 16:23:46 ----D---- C:\Program Files\Common Files\System
2009-11-19 16:23:45 ----D---- C:\Program Files\Internet Explorer
2009-11-19 16:23:33 ----D---- C:\Program Files\ComPlus Applications
2009-11-19 16:23:31 ----A---- C:\WINDOWS\vbaddin.ini
2009-11-19 16:23:31 ----A---- C:\WINDOWS\vb.ini
2009-11-19 16:23:27 ----D---- C:\WINDOWS\Registration
2009-11-19 16:23:05 ----D---- C:\Program Files\Online Services
2009-11-19 16:23:04 ----D---- C:\Program Files\Windows Media Player
2009-11-19 16:23:00 ----D---- C:\Program Files\Messenger
2009-11-19 16:22:56 ----D---- C:\Program Files\MSN Gaming Zone
2009-11-19 16:22:56 ----A---- C:\WINDOWS\system32\write.exe
2009-11-19 16:22:45 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-11-19 16:22:45 ----A---- C:\WINDOWS\system32\hticons.dll
2009-11-19 16:22:44 ----A---- C:\WINDOWS\system32\winchat.exe
2009-11-19 16:22:44 ----A---- C:\WINDOWS\system32\avwav.dll
2009-11-19 16:22:44 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-11-19 16:22:44 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-11-19 16:22:35 ----A---- C:\WINDOWS\system32\getuname.dll
2009-11-19 16:22:35 ----A---- C:\WINDOWS\system32\charmap.exe
2009-11-19 16:22:35 ----A---- C:\WINDOWS\system32\calc.exe
2009-11-19 16:22:34 ----A---- C:\WINDOWS\system32\winmine.exe
2009-11-19 16:22:34 ----A---- C:\WINDOWS\system32\sol.exe
2009-11-19 16:22:34 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\tskill.exe
2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\tscon.exe
2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\shadow.exe
2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\reset.exe
2009-11-19 16:22:33 ----A---- C:\WINDOWS\system32\freecell.exe
2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\regini.exe
2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\msg.exe
2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\logoff.exe
2009-11-19 16:22:32 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-11-19 16:22:31 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-11-19 16:22:31 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-11-19 16:22:30 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-11-19 16:22:30 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-11-19 16:22:30 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-11-19 16:22:30 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-11-19 16:22:30 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-11-19 16:22:29 ----A---- C:\WINDOWS\system32\stclient.dll
2009-11-19 16:22:29 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-11-19 16:22:24 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-11-19 16:22:14 ----D---- C:\Program Files\MSN
2009-11-19 16:22:13 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-11-19 16:22:13 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-11-19 16:22:12 ----D---- C:\Program Files\Windows NT
2009-11-19 16:22:12 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-11-19 16:22:12 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-11-19 16:22:12 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-11-19 16:22:11 ----A---- C:\WINDOWS\system32\spider.exe
2009-11-19 16:22:11 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-11-19 16:22:10 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-11-19 16:22:10 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-11-19 16:22:10 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-11-19 16:22:10 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-11-19 16:22:10 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-11-19 16:22:09 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-11-19 16:22:08 ----D---- C:\WINDOWS\system32\MsDtc
2009-11-19 16:22:08 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-11-19 16:22:08 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-11-19 16:22:08 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-11-19 16:22:08 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-11-19 16:22:08 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-11-19 16:22:07 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-11-19 16:22:07 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-11-19 16:22:07 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-11-19 16:22:07 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-11-19 16:22:07 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-11-19 16:22:06 ----D---- C:\WINDOWS\system32\Com
2009-11-19 16:22:06 ----A---- C:\WINDOWS\system32\colbact.dll
2009-11-19 16:22:06 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-11-19 16:22:05 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-11-19 16:22:05 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-11-19 16:22:05 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-11-19 16:22:04 ----A---- C:\WINDOWS\system32\comuid.dll
2009-11-19 16:22:04 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-11-19 16:22:04 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-11-19 16:21:58 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-11-19 16:21:58 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-11-19 16:21:58 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-11-19 16:21:58 ----A---- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2009-11-20 17:45:34 ----A---- C:\WINDOWS\win.ini
2009-11-20 17:45:34 ----A---- C:\WINDOWS\system.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ANIO;ANIO Service; \??\C:\WINDOWS\system32\ANIO.SYS []
R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424]
R3 abp470n5;abp470n5; \??\C:\WINDOWS\system32\drivers\nhnjln.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-11-17 2297664]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-18 18688]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 npkcrypt;npkcrypt; \??\D:\My Documents\VanRO\RO\npkcrypt.sys []
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-11-15 2826944]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2004-10-20 33280]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2004-10-20 12928]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-18 19584]
R3 RT73;D-Link USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\Dr71WU.sys [2006-12-21 429440]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2004-10-27 223104]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM); C:\WINDOWS\system32\DRIVERS\s1018bus.sys [2009-03-25 86824]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s1018mdfl.sys [2009-03-25 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s1018mdm.sys [2009-03-25 114728]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s1018mgmt.sys [2009-03-25 106208]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS); C:\WINDOWS\system32\DRIVERS\s1018nd5.sys [2009-03-25 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s1018obex.sys [2009-03-25 104744]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM); C:\WINDOWS\system32\DRIVERS\s1018unic.sys [2009-03-25 109864]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;System Restore Filter Driver; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-04 73472]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2004-11-15 127043]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S2 ANIWZCSdService;ANIWZCSd Service; C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe [2007-01-19 126976]
S2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 172032]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 987136]

-----------------EOF-----------------
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 11-22-2009 4:12 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Very active infection. See if you can do the following repair scan, and if not, we will have to go through some manual change steps instead.


To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.

Download ComboFix.exe from here to your desktop, but I would like you to rename the file as you download it (do not download it directly without renaming it - use right click "Save Target/Link As" ). For this, rename the downloading file to 456out.com, then click the renamed 456out.com to run that scan.

Be sure to install the Recovery Console if you are asked to do so. When the scan completes, a text window with your log will open. Please copy and paste that log back here.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 11-23-2009 9:33 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Done, here it is

ComboFix 09-11-22.04 - Owner 11/23/2009 18:22.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2047.1659 [GMT 11:00]
Running from: c:\documents and settings\Owner\Desktop\456out.com.exe
.

((((((((((((((((((((((((( Files Created from 2009-10-23 to 2009-11-23 )))))))))))))))))))))))))))))))
.

2009-11-22 06:56 . 2009-11-22 07:08 -------- d-----w- c:\program files\trend micro
2009-11-22 06:56 . 2009-11-22 06:56 -------- d-----w- C:\rsit
2009-11-20 21:11 . 2009-11-23 06:57 11289 ----a-w- c:\windows\system32\nvModes.dat
2009-11-20 08:25 . 2009-11-23 07:00 -------- d-----w- c:\documents and settings\Owner\Application Data\vlc
2009-11-20 08:24 . 2009-11-20 08:24 -------- d-----w- c:\program files\VideoLAN
2009-11-20 07:16 . 2009-11-20 07:16 -------- d-----w- C:\SamRO
2009-11-20 06:50 . 2009-11-20 07:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-20 06:50 . 2009-11-20 06:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-20 06:11 . 2009-11-20 06:11 -------- d-----w- c:\documents and settings\Owner\Application Data\AVG8
2009-11-20 06:10 . 2009-11-20 06:10 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-11-20 06:10 . 2009-09-10 03:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-20 06:10 . 2009-11-20 06:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-20 06:10 . 2009-11-20 06:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-20 06:10 . 2009-09-10 03:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-21 20:16 . 2009-11-19 05:25 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-20 20:01 . 2009-11-19 14:37 -------- d-----w- c:\program files\Yahoo!
2009-11-20 17:52 . 2009-11-20 17:52 148736 ----a-w- c:\documents and settings\All Users\Application Data\hpeED.dll
2009-11-20 17:52 . 2009-11-20 17:52 148736 ----a-w- c:\documents and settings\All Users\Application Data\hpeED.dll
2009-11-20 17:52 . 2009-11-20 17:52 -------- d-----w- c:\program files\Sony Ericsson
2009-11-20 17:52 . 2009-11-20 17:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony Ericsson
2009-11-20 17:52 . 2009-11-19 05:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-19 14:45 . 2009-11-19 14:44 -------- d-----w- c:\documents and settings\Owner\Application Data\Yahoo!
2009-11-19 14:44 . 2009-11-19 14:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-11-19 06:43 . 2009-11-19 06:43 -------- d-----w- c:\documents and settings\Owner\Application Data\Media Player Classic
2009-11-19 06:35 . 2009-11-19 06:35 12328 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-19 06:32 . 2009-11-19 06:32 -------- d-----w- c:\documents and settings\Owner\Application Data\Leadertech
2009-11-19 06:20 . 2009-11-19 06:20 -------- d-----w- c:\program files\Common Files\Adobe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5317944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1385808]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-11-01 166400]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-11-14 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-11-14 4620288]
"D-Link D-Link Wireless G DWA-110"="c:\program files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe" [2007-05-03 1736704]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 131072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-02 113520]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 1009016]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-11-15 155648]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-11-14 995328]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Owner\\Desktop\\Firefox Setup 3.5.5.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\WINDOWS\\system32\\DllHost.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ANI\\ANIWZCS2 Service\\ANIWZCSdS.exe"=
"c:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"=
"c:\\SamRO\\RO\\VanRO.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\Program Files\\D-Link\\D-Link Wireless G DWA-110\\AirGCFG.exe"=
"d:\\My Documents\\VanRO\\RO\\VanRO.exe"=
"c:\\WINDOWS\\SOUNDMAN.EXE"=
"c:\\SamRO\\RO\\SamRO.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson PC Suite\\SupServ.exe"=

R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\nhnjln.sys --> c:\windows\system32\drivers\nhnjln.sys [?]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [11/21/2009 4:52 AM 27632]
S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [11/21/2009 4:52 AM 172032]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [11/21/2009 4:52 AM 86824]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [11/21/2009 4:52 AM 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [11/21/2009 4:52 AM 114728]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [11/21/2009 4:52 AM 106208]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [11/21/2009 4:52 AM 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [11/21/2009 4:52 AM 104744]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [11/21/2009 4:52 AM 109864]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - NPKCRYPT
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ra4q4zbh.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-23 18:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(628)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-11-23 18:25
ComboFix-quarantined-files.txt 2009-11-23 07:25

Pre-Run: 60,800,569,344 bytes free
Post-Run: 60,957,458,432 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 11E3F9634207DBD20F0D7336091B4A55
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 11-23-2009 3:12 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Not seeing any actual changes by ComboFix just then. But let's act on what shows now, and check one unusual service as well.


Be sure to continue to temporarily disable any protective software when running the scan tools we use here.


Open notepad (go to Start, Run, type notepad and press Enter) and copy/paste the text in the codebox below into it:

KillAll::
Driver::
abp470n5
File::
c:\windows\system32\drivers\nhnjln.sys
c:\documents and settings\All Users\Application Data\hpeED.dll
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Documents and Settings\\Owner\\Desktop\\Firefox Setup 3.5.5.exe"=-
"c:\\WINDOWS\\system32\\wscntfy.exe"=-
"c:\\WINDOWS\\system32\\DllHost.exe"=-
"c:\\WINDOWS\\system32\\taskmgr.exe"=-
"c:\\WINDOWS\\SOUNDMAN.EXE"=-
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=-
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=-
"DisableRegistryTools"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000000
"AntiVirusDisableNotify"=dword:00000000
"FirewallDisableNotify"=dword:00000000
"FirewallOverride"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"UacDisableNotify"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"=-

Save this to your desktop as CFScript.txt


You should now have both ComboFix and that CFScript.txt on the desktop. Just left click/hold on the CFScript.txt file, and drag it into ComboFix to start the scan.

ComboFix will now run as it did before. Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

---------------

@ECHO OFF
if exist winkey.txt del winkey.txt 
REG QUERY "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Irmon\Parameters" /v ServiceDll > winkey.txt 
notepad winkey.txt

Open Notepad (Start - Run, type notepad and press Enter).

Copy/paste the above text into the open text box, then save this to your desktop as "cfgcheck.bat"

Be sure to include the "" quotes in the name. Then click on cfgcheck.bat. When the scan completes a textbox will open - copy/paste those contents back here please.

Post that and the new C:\ComboFix.txt log please.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 11-23-2009 7:52 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
here is the new combo fix with GFScript

ComboFix 09-11-22.08 - Owner 11/24/2009 4:38.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2047.1692 [GMT 11:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt

FILE ::
"c:\documents and settings\All Users\Application Data\hpeED.dll"
"c:\windows\system32\drivers\nhnjln.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\hpeED.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ABP470N5
-------\Service_abp470n5


((((((((((((((((((((((((( Files Created from 2009-10-23 to 2009-11-23 )))))))))))))))))))))))))))))))
.

2009-11-22 06:56 . 2009-11-22 07:08 -------- d-----w- c:\program files\trend micro
2009-11-22 06:56 . 2009-11-22 06:56 -------- d-----w- C:\rsit
2009-11-20 21:11 . 2009-11-23 17:27 11289 ----a-w- c:\windows\system32\nvModes.dat
2009-11-20 08:25 . 2009-11-23 14:33 -------- d-----w- c:\documents and settings\Owner\Application Data\vlc
2009-11-20 08:24 . 2009-11-20 08:24 -------- d-----w- c:\program files\VideoLAN
2009-11-20 07:16 . 2009-11-20 07:16 -------- d-----w- C:\SamRO
2009-11-20 06:50 . 2009-11-20 07:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-20 06:50 . 2009-11-20 06:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-20 06:11 . 2009-11-20 06:11 -------- d-----w- c:\documents and settings\Owner\Application Data\AVG8
2009-11-20 06:10 . 2009-11-20 06:10 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-11-20 06:10 . 2009-09-10 03:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-20 06:10 . 2009-11-20 06:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-20 06:10 . 2009-11-20 06:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-20 06:10 . 2009-09-10 03:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-21 20:16 . 2009-11-19 05:25 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-20 20:01 . 2009-11-19 14:37 -------- d-----w- c:\program files\Yahoo!
2009-11-20 17:52 . 2009-11-20 17:52 -------- d-----w- c:\program files\Sony Ericsson
2009-11-20 17:52 . 2009-11-20 17:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony Ericsson
2009-11-20 17:52 . 2009-11-19 05:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-19 14:45 . 2009-11-19 14:44 -------- d-----w- c:\documents and settings\Owner\Application Data\Yahoo!
2009-11-19 14:44 . 2009-11-19 14:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-11-19 06:43 . 2009-11-19 06:43 -------- d-----w- c:\documents and settings\Owner\Application Data\Media Player Classic
2009-11-19 06:35 . 2009-11-19 06:35 12328 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-19 06:32 . 2009-11-19 06:32 -------- d-----w- c:\documents and settings\Owner\Application Data\Leadertech
2009-11-19 06:20 . 2009-11-19 06:20 -------- d-----w- c:\program files\Common Files\Adobe
.

((((((((((((((((((((((((((((( SnapShot@2009-11-23_07.24.21 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-23 17:42 . 2009-11-23 17:42 16384 c:\windows\temp\Perflib_Perfdata_378.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5317944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-11-01 166400]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-11-14 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-11-14 4620288]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1385808]
"D-Link D-Link Wireless G DWA-110"="c:\program files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe" [2007-05-03 1736704]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 131072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-02 113520]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 1009016]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-11-15 155648]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-11-14 995328]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ANI\\ANIWZCS2 Service\\ANIWZCSdS.exe"=
"c:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"=
"c:\\SamRO\\RO\\VanRO.exe"=
"c:\\Program Files\\D-Link\\D-Link Wireless G DWA-110\\AirGCFG.exe"=
"d:\\My Documents\\VanRO\\RO\\VanRO.exe"=
"c:\\SamRO\\RO\\SamRO.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson PC Suite\\SupServ.exe"=
"c:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe"=

R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [11/21/2009 4:52 AM 172032]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [11/21/2009 4:52 AM 27632]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [11/21/2009 4:52 AM 86824]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [11/21/2009 4:52 AM 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [11/21/2009 4:52 AM 114728]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [11/21/2009 4:52 AM 106208]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [11/21/2009 4:52 AM 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [11/21/2009 4:52 AM 104744]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [11/21/2009 4:52 AM 109864]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - ABP470N5
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ra4q4zbh.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-24 04:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(948)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\docume~1\Owner\LOCALS~1\Temp\catchme.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\dwwin.exe
.
**************************************************************************
.
Completion time: 2009-11-24 04:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-23 17:44
ComboFix2.txt 2009-11-23 07:25

Pre-Run: 60,823,932,928 bytes free
Post-Run: 60,883,009,536 bytes free

- - End Of File - - 8C83C9A969FB46AE435B0A975A8F1AB2
Back to Top
 

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 11-23-2009 7:55 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
the other log.. hmm something seems different, like it is partially fixed. Task manager and Regedit works now. I still cannot use many programs though, any Anti virus, messenger service, raid service etc still doesn't work

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Irmon\Parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\irmon.dll

Post Edited (urbane) : 23-11-2009 17:56:40 GMT

Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 11-24-2009 12:30 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Progress. That Registry check shows that service is legit. Let's see what might be still interfering there.


Click here and download the installer for Gmer to your desktop, then click that file to run Gmer.

If on it's opening scan Gmer locates items shown in red or indicates "hidden" or "rootkit", stop there, and click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please. We don't want any crashes just from taking an initial look at things.

If not, then click on Scan (before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan).

When completed, click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 11-26-2009 3:27 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
ok Regedit and Task manager are disabled again, seems the virus is back in full action. Ok i hope i did this right

GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-11-27 00:20:42
Windows 5.1.2600 Service Pack 2
Running: l0tkxmho.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kxtdipow.sys


---- Kernel code sections - GMER 1.0.15 ----

? C:\WINDOWS\system32\drivers\nhnjln.sys The system cannot find the file specified. !

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)

---- EOF - GMER 1.0.15 ----
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 11-26-2009 5:06 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
An unknown driver loading into kernel areas, but no identification of the actual service name so we can disable/remove it there. As you did allow ComboFix to install the Recovery Console access there, let's see if you can use that to locate that hidden service.


listsvc
dir c:\windows\system32\drivers


Open Notepad (Start - Run, type notepad and press Enter).

Copy/paste the above text (inside the Code box) into the open text box, then save this to your C:\Windows folder as "servcheck.bat"

It should then be C:\Windows\servcheck.bat (important)

-----------------

Then reboot, and at the options screen select the following hilighted option:

Microsoft Windows Recovery Console
Microsoft Windows XP Home Edition

After you enter the number for the appropriate Windows installation (usually #1), you should be at the C:\Windows\> prompt.

At the prompt type the following, pressing Enter after each:

batch servcheck.bat c:\windows\servicelook.txt

exit


When you hit Enter after typing exit your computer will reboot.

Then locate and post back here the contents of c:\windows\servicelook.txt please.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 11-28-2009 10:18 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
The command batch servcheck.bat worked...
The command c:\windows\servicelook.txt didnt work...
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 11-28-2009 6:00 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
You got the message that one batch was processed? Usually if there are no results, either the batch file was not quite created correctly, is not in the Windows folder or was not run from the C:\Windows prompt.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 11-28-2009 8:24 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Well I don't know, I did your instructions.

batch servcheck.bat worked and it came up with a long list

The other one didnt work tho, there was no servicelook.txt either.
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 11-29-2009 12:43 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
This part of servcheck.bat:

listsvc

Would create a long list of all the drivers there, and so if the batch only showed that list again you are not quite doing something correctly there. That long list is supposed to end up written to the c:\windows\servicelook.txt.

Are you making sure there is a space in your commands you type:

batch servcheck.bat c:\windows\servicelook.txt

batch space servcheck.bat space c:\windows\servicelook.txt


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 11-30-2009 10:29 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Oh

I thought they were 2 different commands
batch servcheck.bat
c:\windows\servicelook.txt

sorry >.>

Ok here it is:

Abiosdsk Disabled

abp470n5 Manual
abp470n5
abp480n5 Disabled

ACPI Boot
Microsoft ACPI Driver
ACPIEC Disabled

adpu160m Disabled

aec Manual
Microsoft Kernel Acoustic Echo Canceller
AFD System
AFD
Aha154x Disabled

aic78u2 Disabled

aic78xx Disabled

ALCXWDM Manual
Service for Realtek AC97 Audio (WDM)
Alerter Disabled
Alerter
AliIde Disabled

amsint Disabled

ANIO Auto
ANIO Service
ANIWZCSdService Disabled
ANIWZCSd Service
AppMgmt Disabled
Application Management
Arp1394 Manual
1394 ARP Client Protocol
asc Disabled

asc3350p Disabled

asc3550 Disabled

AsyncMac Manual
RAS Asynchronous Media Driver
atapi Boot
Standard IDE/ESDI Hard Disk Controller
Atdisk Disabled

Atmarpc Manual
ATM ARP Client Protocol
AudioSrv Disabled
Windows Audio
audstub Manual
Audio Stub Driver
Beep System

BITS Disabled
Background Intelligent Transfer Service
Browser Disabled
Computer Browser
catchme Manual

cbidf2k Disabled

cd20xrnt Disabled

Cdaudio System

Cdfs Disabled

Cdrom System
CD-ROM Driver
Changer System

CiSvc Disabled
Indexing Service
ClipSrv Disabled
ClipBook
CmdIde Disabled

COMSysApp Disabled
COM+ System Application
Cpqarray Disabled

CryptSvc Disabled
CryptSvc
dac2w2k Disabled

dac960nt Disabled

DcomLaunch Auto
DCOM Server Process Launcher
Dhcp Disabled
DHCP Client
Disk Boot
Disk Driver
dmadmin Disabled
Logical Disk Manager Administrative Service
dmboot Disabled

dmio Disabled

dmload Disabled

dmserver Disabled
Logical Disk Manager
DMusic Manual
Microsoft Kernel DLS Syntheiszer
Dnscache Disabled
DNS Client
dpti2o Disabled

drmkaud Manual
Microsoft Kernel DRM Audio Descrambler
ERSvc Disabled
Error Reporting Service
Eventlog Disabled
Event Log
EventSystem Disabled
COM+ Event System
Fastfat Disabled

FastUserSwitchingCompatibility Disabled
Fast User Switching Compatibility
Fdc Manual
Floppy Disk Controller Driver
Fips System

Flpydisk Manual
Floppy Disk Driver
FltMgr Boot
FltMgr
Fs_Rec System

Ftdisk Boot
Volume Manager Driver
Gpc Manual
Generic Packet Classifier
helpsvc Disabled
Help and Support
HidServ Disabled
Human Interface Device Access
hpn Disabled

HTTP Manual
HTTP
HTTPFilter Disabled
HTTP SSL
i2omgmt System

i2omp Disabled

i8042prt System
i8042 Keyboard and PS/2 Mouse Port Driver
Imapi System
CD-Burning Filter Driver
ImapiService Disabled
IMAPI CD-Burning COM Service
ini910u Disabled

IntelIde Disabled

Ip6Fw Manual
IPv6 Windows Firewall Driver
IpFilterDriver Manual
IP Traffic Filter Driver
IpInIp Manual
IP in IP Tunnel Driver
IpNat Manual
IP Network Address Translator
IPSec System
IPSEC driver
irda Auto
IrDA Protocol
IRENUM Manual
IR Enumerator Service
Irmon Disabled
Infrared Monitor
irsir Manual
Microsoft Serial Infrared Driver
isapnp Boot
PnP ISA/EISA Bus Driver
Kbdclass System
Keyboard Class Driver
kmixer Manual
Microsoft Kernel Wave Audio Mixer
KSecDD Boot

lanmanserver Disabled
Server
lanmanworkstation Disabled
Workstation
lbrtfdc System

LmHosts Disabled
TCP/IP NetBIOS Helper
Messenger Disabled
Messenger
mnmdd System

mnmsrvc Disabled
NetMeeting Remote Desktop Sharing
Modem Manual

Mouclass System
Mouse Class Driver
MountMgr Boot

mraid35x Disabled

MRxDAV Manual
WebDav Client Redirector
MRxSmb System
MRXSMB
MSDTC Disabled
Distributed Transaction Coordinator
Msfs System

MSIServer Disabled
Windows Installer
MSKSSRV Manual
Microsoft Streaming Service Proxy
MSPCLOCK Manual
Microsoft Streaming Clock Proxy
MSPQM Manual
Microsoft Streaming Quality Manager Proxy
mssmbios Manual
Microsoft System Management BIOS Driver
Mup Boot
Mup
NDIS Boot
NDIS System Driver
NdisTapi Manual
Remote Access NDIS TAPI Driver
Ndisuio Manual
NDIS Usermode I/O Protocol
NdisWan Manual
Remote Access NDIS WAN Driver
NDProxy Manual
NDIS Proxy
NetBIOS System
NetBIOS Interface
NetBT System
NetBios over Tcpip
NetDDE Disabled
Network DDE
NetDDEdsdm Disabled
Network DDE DSDM
Netlogon Disabled
Net Logon
Netman Disabled
Network Connections
NIC1394 Manual
1394 Net Driver
Nla Disabled
Network Location Awareness (NLA)
Npfs System

npkcrypt Manual
npkcrypt
Ntfs Disabled

NtLmSsp Disabled
NT LM Security Support Provider
NtmsSvc Disabled
Removable Storage
Null System

nv Manual

nvatabus Boot

NVENETFD Manual
NVIDIA nForce Networking Controller Driver
nvnetbus Manual
NVIDIA Network Bus Enumerator
nvraid Boot
NVIDIA nForce(tm) RAID Class Driver
NVSvc Disabled
NVIDIA Display Driver Service
NwlnkFlt Manual
IPX Traffic Filter Driver
NwlnkFwd Manual
IPX Traffic Forwarder Driver
ohci1394 Boot
Texas Instruments OHCI Compliant IEEE 1394 Host Controller
OMSI download service Disabled
Sony Ericsson OMSI download service
Parport Manual
Parallel port driver
PartMgr Boot

ParVdm Auto

PCI Boot
PCI Bus Driver
PCIDump System

PCIIde Boot

Pcmcia Disabled

PDCOMP Manual

PDFRAME Manual

PDRELI Manual

PDRFRAME Manual

perc2 Disabled

perc2hib Disabled

PlugPlay Disabled
Plug and Play
PolicyAgent Disabled
IPSEC Services
PptpMiniport Manual
WAN Miniport (PPTP)
Processor System
Processor Driver
ProtectedStorage Disabled
Protected Storage
PSched Manual
QoS Packet Scheduler
Ptilink Manual
Direct Parallel Link Driver
ql1080 Disabled

Ql10wnt Disabled

ql12160 Disabled

ql1240 Disabled

ql1280 Disabled

RasAcd System
Remote Access Auto Connection Driver
RasAuto Disabled
Remote Access Auto Connection Manager
Rasirda Manual
WAN Miniport (IrDA)
Rasl2tp Manual
WAN Miniport (L2TP)
RasMan Disabled
Remote Access Connection Manager
RasPppoe Manual
Remote Access PPPOE Driver
Raspti Manual
Direct Parallel
Rdbss System
Rdbss
RDPCDD System

RDPWD Manual

RDSessMgr Disabled
Remote Desktop Help Session Manager
redbook System
Digital CD Audio Playback Filter Driver
RemoteAccess Disabled
Routing and Remote Access
RpcLocator Manual
Remote Procedure Call (RPC) Locator
RpcSs Auto
Remote Procedure Call (RPC)
RSVP Disabled
QoS RSVP
RT73 Manual
D-Link USB Wireless LAN Card Driver
s1018bus Manual
Sony Ericsson Device 1018 driver (WDM)
s1018mdfl Manual
Sony Ericsson Device 1018 USB WMC Modem Filter
s1018mdm Manual
Sony Ericsson Device 1018 USB WMC Modem Driver
s1018mgmt Manual
Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM)
s1018nd5 Manual
Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS)
s1018obex Manual
Sony Ericsson Device 1018 USB WMC OBEX Interface
s1018unic Manual
Sony Ericsson Device 1018 USB Ethernet Emulation (WDM)
SamSs Disabled
Security Accounts Manager
SCardSvr Disabled
Smart Card
Schedule Disabled
Task Scheduler
Secdrv Manual
Secdrv
seclogon Disabled
Secondary Logon
seehcri Manual
Sony Ericsson seehcri Device Driver
SENS Disabled
System Event Notification
serenum Manual
Serenum Filter Driver
Serial System
Serial port driver
Sfloppy System

SharedAccess Disabled
Windows Firewall/Internet Connection Sharing (ICS)
ShellHWDetection Disabled
Shell Hardware Detection
Si3114r5 Boot
SiI-3114 SoftRaid 5 Controller
SiFilter Boot
SATALink driver accelerator
Simbad Disabled

Sparrow Disabled

splitter Manual
Microsoft Kernel Audio Splitter
Spooler Disabled
Print Spooler
sr Disabled
System Restore Filter Driver
srservice Disabled
System Restore Service
Srv Manual
Srv
SSDPSRV Disabled
SSDP Discovery Service
stisvc Disabled
Windows Image Acquisition (WIA)
swenum Manual
Software Bus Driver
swmidi Manual
Microsoft Kernel GS Wavetable Synthesizer
SwPrv Disabled
MS Software Shadow Copy Provider
symc810 Disabled

symc8xx Disabled

sym_hi Disabled

sym_u3 Disabled

sysaudio Manual
Microsoft Kernel System Audio Device
SysmonLog Disabled
Performance Logs and Alerts
TapiSrv Disabled
Telephony
Tcpip System
TCP/IP Protocol Driver
TDPIPE Manual

TDTCP Manual

TermDD System
Terminal Device Driver
TermService Disabled
Terminal Services
Themes Disabled
Themes
TosIde Disabled

TrkWks Disabled
Distributed Link Tracking Client
Udfs Disabled

ultra Disabled

Update Manual
Microcode Update Driver
upnphost Disabled
Universal Plug and Play Device Host
UPS Disabled
Uninterruptible Power Supply
usbehci Manual
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
usbhub Manual
USB2 Enabled Hub
usbohci Manual
Microsoft USB Open Host Controller Miniport Driver
usbstor Manual
USB Mass Storage Driver
VgaSave System

ViaIde Disabled

VolSnap Boot

VSS Disabled
Volume Shadow Copy
W32Time Disabled
Windows Time
Wanarp Manual
Remote Access IP ARP Driver
WDICA Manual

wdmaud Manual
Microsoft WINMM WDM Audio Compatibility Driver
WebClient Disabled
WebClient
winmgmt Disabled
Windows Management Instrumentation
Winsock Manual

WmdmPmSN Disabled
Portable Media Serial Number Service
WmiApSrv Disabled
WMI Performance Adapter
WMPNetworkSvc Disabled
Windows Media Player Network Sharing Service
WpdUsb Manual
WpdUsb
WS2IFSL System

wscsvc Disabled
Security Center
wuauserv Disabled
Automatic Updates
WudfPf Boot
Windows Driver Foundation - User-mode Driver Framework Platform Driver
WudfRd Manual
Windows Driver Foundation - User-mode Driver Framework Reflector
WudfSvc Disabled
Windows Driver Foundation - User-mode Driver Framework
WZCSVC Disabled
Wireless Zero Configuration
xmlprov Disabled
Network Provisioning Service
yukonwxp Manual
NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 12-2-2009 2:21 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Good you got that worked out. But no infection services showing here, and the last Gmer log indicating something loading itself.


Download Gmer's mbr.exe from here and place it on your C drive (so the file is then C:\mbr.exe).

Go to Start - Run, type cmd (and press OK). At the prompt type or copy/paste the following, pressing Enter after each:

cd\
mbr.exe -t


Then type exit and press Enter to close the command window.

The report created in the command window will have been saved to C:\mbr.log. Locate that and post it here please.

-----------------

Open Gmer again. This time just right click in the white space in the display and select Options - Only non MS files. Then click Scan and allow Gmer to run a different scan. Once that completes click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please.
Back to Top
 

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 12-2-2009 7:53 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Can you post another link please, that doesn't work
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 12-3-2009 1:08 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Sorry - some of my pre-made steps include links that don't work in this forum's software. This is the download for that.
Back to Top
 

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 12-4-2009 6:29 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll nvatabus.sys
kernel: MBR read successfully
user & kernel MBR OK
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 12-5-2009 1:57 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
That indicates none of the newer boot level driver files being misused, so okay in that area. I did not answer this earlier:

"I cannot use gpedit.msc"

That would only be with CP Pro, not the Home version you have there.


"When I delete the disable task manager values in regedit"

What did you mean by that please? More curious what steps those were for what results.

Post back on all that, and run and post a new Gmer scan log please. I sense the earlier file it showed might be part of some tool that was run there, that would have been removed once the system reboots.
Back to Top
 

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 12-5-2009 8:03 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
The virus makes these registries

HKEY_CURRENT_USER/software/Microsoft/Windows/Currentversion/Policies/system DisableRegistryTools Reg Dword 0x00000001 (1)
HKEY_CURRENT_USER/software/Microsoft/Windows/Currentversion/Policies/system DisableTaskMgr Reg Dword 0x00000001 (1)

Thus disabling both Task manager and regedit
Here is what I use to get into task manager... i need to somehow delete this registry without being in regedit:
HKEY_CURRENT_USER/software/Microsoft/Windows/Currentversion/Policies/system DisableRegistryTools Reg Dword 0x00000001 (1)

I use regtools.vbs to do this, here is the link with the code:
http://www.dougknox.com/security/scripts/regtools.vbs

That allows me about 2 seconds to quickly go run>regedit before the virus remakes the disableregistrytools
Then when I am in regedit I delete the 2 registries in the picture above. The virus remakes them in about 2 seconds or less, so I have about 2 seconds or less to hit ctrl+alt+del before the virus remakes those registries and disables Task Manager.

That is how I get into Task manager... ok here is you re-scan:

GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-12-05 17:02:28
Windows 5.1.2600 Service Pack 2
Running: l0tkxmho.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kxtdipow.sys


---- Kernel code sections - GMER 1.0.15 ----

? C:\WINDOWS\system32\drivers\flnipn.sys The system cannot find the file specified. !
? C:\DOCUME~1\Owner\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)

---- EOF - GMER 1.0.15 ----
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 12-6-2009 12:49 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Thanks for clearing that up. Gmer shows the malware driver file changed names, which suggests a change during reboot procedure. No malware services being located, to pinpoint what is using the file. Which we truly need right now, to get the repairs going there.

Open Gmer again. This time just right click in the white space in the display and select Options - Only non MS files. Then click Scan and allow Gmer to run a different scan. Once that completes click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please.

---------------

Go here and download reglooks.exe to your Desktop. Doubleclick on it to run it and when it has finished scanning, a log named result.txt will open in Notepad. Copy the log and post it in this thread.
Back to Top
 

urbane
New Member


Date Joined Nov 2009
Total Posts : 30
 
   Posted 12-6-2009 3:31 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Here is GMER:

GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-12-06 12:27:15
Windows 5.1.2600 Service Pack 2
Running: l0tkxmho.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kxtdipow.sys


---- Modules - GMER 1.0.15 ----

Module nvraid.sys (NVIDIA® nForce(TM) RAID Driver/NVIDIA Corporation) BA738000-BA749000 (69632 bytes)
Module Si3114r5.sys (SATA SoftRAID 5 miniport driver/Silicon Image, Inc) BA6F3000-BA720000 (184320 bytes)
Module nvatabus.sys (NVIDIA® nForce(TM) IDE Performance Driver/NVIDIA Corporation) BA6C6000-BA6DB000 (86016 bytes)
Module SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.) BACBC000-BACBF000 (12288 bytes)
Module PxHelp20.sys (Px Engine Device Driver for Windows 2000/XP/Sonic Solutions) BA918000-BA922000 (40960 bytes)
Module \SystemRoot\system32\drivers\ALCXWDM.SYS (Realtek AC'97 Audio Driver (WDM)/Realtek Semiconductor Corp.) B99DF000-B9C10000 (2297856 bytes)
Module \SystemRoot\system32\DRIVERS\nvnetbus.sys (NVIDIA Networking Bus Driver./NVIDIA Corporation) BAD78000-BAD7C000 (16384 bytes)
Module \SystemRoot\system32\DRIVERS\NVNRM.SYS (NVIDIA Network Resource Manager./NVIDIA Corporation) B9958000-B9998000 (262144 bytes)
Module \SystemRoot\system32\DRIVERS\NVSNPU.SYS (NVIDIA Networking Soft-NPU Driver./NVIDIA Corporation) B9925000-B9958000 (208896 bytes)
Module \SystemRoot\system32\DRIVERS\yk51x86.sys (NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller/Marvell) B98EE000-B9925000 (225280 bytes)
Module \SystemRoot\system32\DRIVERS\nv4_mini.sys (NVIDIA Compatible Windows 2000 Miniport Driver, Version 66.93 /NVIDIA Corporation) B963B000-B98EE000 (2830336 bytes)
Module \SystemRoot\system32\DRIVERS\ptilink.sys (Parallel Technologies DirectParallel IO Library/Parallel Technologies, Inc.) BAB90000-BAB95000 (20480 bytes)
Module \SystemRoot\system32\DRIVERS\seehcri.sys (seehcri Driver/Sony Ericsson Mobile Communications) BABA0000-BABA6000 (24576 bytes)
Module \SystemRoot\system32\DRIVERS\NVENETFD.sys (NVIDIA Networking Function Driver./NVIDIA Corporation) B6D74000-B6D7D000 (36864 bytes)
Module \SystemRoot\system32\DRIVERS\Dr71WU.sys (Ralink 802.11 USB Wireless Adapter Driver/Ralink Technology, Corp.) AED7D000-AEDE6000 (430080 bytes)
Module \SystemRoot\System32\nv4_disp.dll (NVIDIA Compatible Windows 2000 Display driver, Version 66.93 /NVIDIA Corporation) BF9D3000-BFD64000 (3739648 bytes)
Module \??\C:\WINDOWS\system32\ANIO.SYS (ANIO (NT5) Driver /Alpha Networks Inc.) AF900000-AF907000 (28672 bytes)
Module \??\C:\WINDOWS\system32\drivers\flnipn.sys BADDE000-BADE0000 (8192 bytes)
Module \??\D:\My_Documents\VanRO\RO\npkcrypt.sys (nProtect KeyCrypt Driver/INCA Internet Co., Ltd.) AF3AF000-AF3B4000 (20480 bytes)
Module \??\C:\DOCUME~1\Owner\LOCALS~1\Temp\kxtdipow.sys (GMER) 9D5CA000-9D5E1000 (94208 bytes)

---- Processes - GMER 1.0.15 ----

Process C:\WINDOWS\explorer.exe (Windows Explorer/Microsoft Corporation) 356
Library C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll (PDF Shell Extension/Adobe Systems, Inc.) 0x10000000
Library C:\WINDOWS\system32\dxmasf.dll 0x6BF50000
Library C:\WINDOWS\system32\lameACM.acm (Lame MP3 codec engine/http://www.mp3dev.org/) 0x039D0000

Process C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Driver Helper Service, Version 66.93/NVIDIA Corporation) 468
Library C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Driver Helper Service, Version 66.93/NVIDIA Corporation) 0x00400000

Process C:\WINDOWS\System32\svchost.exe (Generic Host Process for Win32 Services/Microsoft Corporation) 1072
Library C:\WINDOWS\System32\strmfilt.dll (Stream Filter Library/Microsoft Corporation) 0x6F290000

Process C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Extras Manager/Skype Technologies) 2832
Library C:\Program Files\Skype\Plugin Manager\skypePM.exe (Skype Extras Manager/Skype Technologies) 0x00400000
Library C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll (Skype Extras Manager Utilites/EasyBits Media AS) 0x00970000

Process C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) 3612
Library C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) 0x00400000
Library C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) 0x10000000
Library C:\Program Files\Mozilla Firefox\sqlite3.dll (SQLite Database Library/sqlite.org) 0x00270000
Library C:\Program Files\Mozilla Firefox\MOZCRT19.dll (User-Generated Microsoft (R) C/C++ Runtime Library/Mozilla Foundation) 0x78130000
Library C:\Program Files\Mozilla Firefox\js3250.dll (Netscape 32-bit JavaScript Module/Netscape Communications Corporation) 0x002F0000
Library C:\Program Files\Mozilla Firefox\nspr4.dll (NSPR Library/Mozilla Foundation) 0x004E0000
Library C:\Program Files\Mozilla Firefox\smime3.dll (NSS S/MIME Library/Mozilla Foundation) 0x003E0000
Library C:\Program Files\Mozilla Firefox\nss3.dll (NSS Base Library/Mozilla Foundation) 0x00510000
Library C:\Program Files\Mozilla Firefox\nssutil3.dll (NSS Utility Library/Mozilla Foundation) 0x005B0000
Library C:\Program Files\Mozilla Firefox\plc4.dll (PLC Library/Mozilla Foundation) 0x005D0000
Library C:\Program Files\Mozilla Firefox\plds4.dll (PLDS Library/Mozilla Foundation) 0x005E0000
Library C:\Program Files\Mozilla Firefox\ssl3.dll (NSS SSL Library/Mozilla Foundation) 0x005F0000
Library C:\WINDOWS\system32\USP10.dll (Uniscribe Unicode script processor/Microsoft Corporation) 0x74D90000
Library C:\Program Files\Mozilla Firefox\xpcom.dll (Mozilla Foundation) 0x00610000
Library C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll (Mozilla Foundation) 0x01240000
Library C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll (Mozilla Foundation) 0x015B0000
Library C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\PNRComponent.dll (Skype phone number parser helper library for FireFox browser addon/Skype Technologies S.A.) 0x02450000
Library C:\Program Files\Skype\Toolbars\Shared\SkypePnr.dll (Skype Phone number parser/Skype Technologies S.A.) 0x02600000
Library C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll (Name parser helper object for Skype Firefox addon/Skype Technologies S.A.) 0x02A20000
Library C:\Program Files\Mozilla Firefox\softokn3.dll (NSS PKCS #11 Library/Mozilla Foundation) 0x03310000
Library C:\Program Files\Mozilla Firefox\nssdbm3.dll (Legacy Database Driver/Mozilla Foundation) 0x03340000
Library C:\Program Files\Mozilla Firefox\freebl3.dll (NSS freebl Library/Mozilla Foundation) 0x03360000
Library C:\Program Files\Mozilla Firefox\nssckbi.dll (NSS Builtin Trusted Root CAs/Mozilla Foundation) 0x033B0000
Library C:\Program Files\Skype\Toolbars\Shared\SkypeBrowserOptions.dll (Skype plug-in settings dialog/Skype Technologies S.A.) 0x0A610000
Library C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll 0x06900000

Process C:\Program Files\Skype\Phone\Skype.exe (Skype /Skype Technologies S.A.) 4652
Library C:\Program Files\Skype\Phone\Skype.exe (Skype /Skype Technologies S.A.) 0x00400000
Library C:\WINDOWS\system32\devenum.dll 0x75F40000
Library C:\WINDOWS\system32\msdmo.dll 0x736B0000

Process C:\DOCUME~1\Owner\LOCALS~1\Temp\ccda.exe 4876
Library C:\DOCUME~1\Owner\LOCALS~1\Temp\ccda.exe 0x00400000

Process C:\Documents and Settings\Owner\Desktop\l0tkxmho.exe 5400
Library C:\Documents and Settings\Owner\Desktop\l0tkxmho.exe 0x00400000

---- Services - GMER 1.0.15 ----

Service C:\WINDOWS\system32\drivers\flnipn.sys [MANUAL] abp470n5
Service C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek AC'97 Audio Driver (WDM)/Realtek Semiconductor Corp.) [MANUAL] ALCXWDM
Service C:\WINDOWS\system32\ANIO.SYS (ANIO (NT5) Driver /Alpha Networks Inc.) [AUTO] ANIO
Service C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe (ANIWZCS2 Service Launcher/Wireless Service) [AUTO] ANIWZCSdService
Service C:\ComboFix\catchme.sys [MANUAL] catchme
Service D:\My Documents\VanRO\RO\npkcrypt.sys (nProtect KeyCrypt Driver/INCA Internet Co., Ltd.) [MANUAL] npkcrypt
Service C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Compatible Windows 2000 Miniport Driver, Version 66.93 /NVIDIA Corporation) [MANUAL] nv
Service C:\WINDOWS\system32\DRIVERS\nvatabus.sys (NVIDIA® nForce(TM) IDE Performance Driver/NVIDIA Corporation) [BOOT] nvatabus
Service C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Networking Function Driver./NVIDIA Corporation) [MANUAL] NVENETFD
Service C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Networking Bus Driver./NVIDIA Corporation) [MANUAL] nvnetbus
Service C:\WINDOWS\system32\DRIVERS\nvraid.sys (NVIDIA® nForce(TM) RAID Driver/NVIDIA Corporation) [BOOT] nvraid
Service C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Driver Helper Service, Version 66.93/NVIDIA Corporation) [AUTO] NVSvc
Service C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [AUTO] OMSI download service
Service C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies DirectParallel IO Library/Parallel Technologies, Inc.) [MANUAL] Ptilink
Service C:\WINDOWS\System32\Drivers\PxHelp20.sys (Px Engine Device Driver for Windows 2000/XP/Sonic Solutions) [BOOT] PxHelp20
Service C:\WINDOWS\system32\DRIVERS\Dr71WU.sys (Ralink 802.11 USB Wireless Adapter Driver/Ralink Technology, Corp.) [MANUAL] RT73
Service C:\WINDOWS\system32\DRIVERS\s1018bus.sys (Sony Ericsson Device 1018 Driver/MCCI Corporation) [MANUAL] s1018bus
Service C:\WINDOWS\system32\DRIVERS\s1018mdfl.sys (Sony Ericsson Device 1018 USB WMC Modem Filter Driver/MCCI Corporation) [MANUAL] s1018mdfl
Service C:\WINDOWS\system32\DRIVERS\s1018mdm.sys (Sony Ericsson Device 1018 USB WMC Modem WDM Driver/MCCI Corporation) [MANUAL] s1018mdm
Service C:\WINDOWS\system32\DRIVERS\s1018mgmt.sys (Sony Ericsson Device 1018 USB WMC Device Management Driver/MCCI Corporation) [MANUAL] s1018mgmt
Service C:\WINDOWS\system32\DRIVERS\s1018nd5.sys (Ericsson Mobile Platform S1018 USB WMC Extended Ethernet (NDIS 5 Miniport)/MCCI Corporation) [MANUAL] s1018nd5
Service C:\WINDOWS\system32\DRIVERS\s1018obex.sys (Sony Ericsson Device 1018 USB WMC OBEX Interface Device Driver/MCCI Corporation) [MANUAL] s1018obex
Service C:\WINDOWS\system32\DRIVERS\s1018unic.sys (Sony Ericsson Device 1018 USB Ethernet Emulation/MCCI Corporation) [MANUAL] s1018unic
Service C:\WINDOWS\system32\DRIVERS\secdrv.sys [MANUAL] Secdrv
Service C:\WINDOWS\system32\DRIVERS\seehcri.sys (seehcri Driver/Sony Ericsson Mobile Communications) [MANUAL] seehcri
Service C:\WINDOWS\system32\DRIVERS\Si3114r5.sys (SATA SoftRAID 5 miniport driver/Silicon Image, Inc) [BOOT] Si3114r5
Service C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.) [BOOT] SiFilter
Service C:\WINDOWS\system32\DRIVERS\yk51x86.sys (NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller/Marvell) [MANUAL] yukonwxp

---- EOF - GMER 1.0.15 ----


here is the reglooks:

REGLOOKS logfile - version 0.983
Scan started: Sun 12/06/2009 12:29:25.03

--- INFORMATION ---

Manufacturer: NVIDIA - Model: AWRDACPI
Operating System: Microsoft Windows XP Home Edition -- 5.1.2600 -- Service Pack 2 --
Processor: AMD Athlon(tm) 64 Processor 3500+

Work Station
Bootmode: Normal boot
Total RAM: 2047 MB (free 1468 MB - 71%)

Computername: TYLER
Domain: MSHOME
User: Owner (Administrator account)

Bootdevice: \Device\HarddiskVolume1
Systemdrive: C:
Windowsdirectory: C:\WINDOWS
Systemdirectory: C:\WINDOWS\system32

Internet Explorer Version: 6.0.2900.2180




--- SIGCHECK ---

C:\WINDOWS\explorer.exe -- [1032192] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\appmgmts.dll NOT found
C:\WINDOWS\system32\browser.dll -- [77312] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\comres.dll -- [792064] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\comctl32.dll -- [611328] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\cryptsvc.dll -- [60416] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\ctfmon.exe -- [15360] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\es.dll -- [243200] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\eventlog.dll -- [55808] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\ias.dll NOT found
C:\WINDOWS\system32\imm32.dll -- [110080] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\kernel32.dll -- [983552] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\linkinfo.dll -- [18944] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\lpk.dll -- [22016] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\lsass.exe -- [13312] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\mfc40u.dll -- [924432] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\msgsvc.dll -- [33792] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\mshtml.dll -- [3003392] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\mspmsnsv.dll -- [27136] -- [10/18/2006 09:47 PM] -- sigcheck OK
C:\WINDOWS\system32\mswsock.dll -- [245248] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\netlogon.dll -- [407040] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\netman.dll -- [198144] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\ntkrnlpa.exe -- [2056832] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\ntmssvc.dll -- [435200] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\ntoskrnl.exe -- [2180992] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\pchsvc.dll NOT found
C:\WINDOWS\system32\powrprof.dll -- [17408] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\qmgr.dll -- [382464] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\rasauto.dll -- [89088] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\regsvc.dll -- [59904] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\rpcss.dll -- [395776] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\scecli.dll -- [180224] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\schedsvc.dll -- [190976] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\services.exe -- [108032] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\sfc.dll -- [5120] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\sfcfiles.dll -- [1580544] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\spoolsv.exe -- [57856] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\srsvc.dll -- [170496] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\ssdpsrv.dll -- [71680] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\svchost.exe -- [14336] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\tapisrv.dll -- [246272] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\termsrv.dll -- [295424] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\upnphost.dll -- [185344] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\user32.dll -- [577024] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\userinit.exe -- [24576] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\wininet.dll -- [656384] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\winlogon.exe -- [502272] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\ws2_32.dll -- [82944] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\wscntfy.exe -- [13824] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\wuauclt.exe -- [111104] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\xmlprov.dll -- [129536] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\drivers\acpiec.sys -- [11648] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\drivers\aec.sys -- [142464] -- [08/03/2004 10:39 PM] -- sigcheck OK
C:\WINDOWS\system32\drivers\asyncmac.sys -- [14336] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\drivers\beep.sys -- [4224] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\drivers\ip6fw.sys -- [29056] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\drivers\kbdclass.sys -- [24576] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\drivers\ndis.sys -- [182912] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\drivers\ntfs.sys -- [574592] -- [08/04/2004 11:00 PM] -- sigcheck OK
C:\WINDOWS\system32\drivers\tcpip.sys -- [359040] -- [08/04/2004 11:00 PM] -- sigcheck OK


--- SSODL regkeys ---

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" -- File: %SystemRoot%\system32\SHELL32.dll -- [?]
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" -- File: %SystemRoot%\system32\SHELL32.dll -- [?]
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" -- File: %Systemroot%\system32\webcheck.dll -- [?]
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" -- File: %systemroot%\system32\stobject.dll -- [?]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" -- File: C:\WINDOWS\system32\WPDShServiceObj.dll -- [133632] -- [10/18/2006 09:47 PM]


--- STS regkeys ---

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" -- File: %SystemRoot%\system32\browseui.dll -- [?]
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" -- File: %SystemRoot%\system32\browseui.dll -- [?]


--- USERINIT regkey ---

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
File: C:\WINDOWS\system32\userinit.exe -- [24576] -- [08/04/2004 11:00 PM]


--- SHELL regkey ---

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe"
File: C:\WINDOWS\Explorer.exe -- [1032192] -- [08/04/2004 11:00 PM]


--- SYSTEM regkey ---

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


--- APPINIT_DLLS regkey ---

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
no AppInit_DLLs regkey found


--- NOTIFY regkey ---

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
-- File: C:\WINDOWS\system32\crypt32.dll -- [597504] -- [08/04/2004 11:00 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
-- File: C:\WINDOWS\system32\cryptnet.dll -- [63488] -- [08/04/2004 11:00 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
-- File: C:\WINDOWS\system32\cscdll.dll -- [101888] -- [08/04/2004 11:00 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
-- File: C:\WINDOWS\system32\wlnotify.dll -- [92672] -- [08/04/2004 11:00 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
-- File: C:\WINDOWS\system32\wlnotify.dll -- [92672] -- [08/04/2004 11:00 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
-- File: C:\WINDOWS\system32\sclgntfy.dll -- [20992] -- [08/04/2004 11:00 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
-- File: C:\WINDOWS\system32\WlNotify.dll -- [92672] -- [08/04/2004 11:00 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
-- File: C:\WINDOWS\system32\wlnotify.dll -- [92672] -- [08/04/2004 11:00 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
-- File: C:\WINDOWS\system32\wlnotify.dll -- [92672] -- [08/04/2004 11:00 PM]


--- RUN / LOAD regkeys ---

[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
no run / load keys found


--- SHELLEXECUTEHOOKS regkey ---

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" -- File: shell32.dll -- [?]


--- HKLM AUTORUN regkeys ---

[HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor]
no AutoRun regkey found


--- HKCU AUTORUN regkeys ---

[HKEY_CURRENT_USER\Software\Microsoft\Command Processor]
no AutoRun regkey found


--- HKLM\RUN regkey ---

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan" -- File: SOUNDMAN.EXE -- [?]
"nwiz" -- File: nwiz.exe /installquiet -- [?]
"NVRaidService" -- File C:\WINDOWS\system32\nvraidservice.exe -- [166400] -- [11/02/2004 09:55 AM]
"NvMediaCenter" -- File: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit -- [?]
"NvCplDaemon" -- File: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup -- [?]
"Malwarebytes Anti-Malware (reboot)" -- File: "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript -- [?]
"D-Link D-Link Wireless G DWA-110" -- File: C:\Program Files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe -- [?]
"ANIWZCS2Service" -- File C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe -- [131072] -- [01/19/2007 11:49 AM]
"Adobe Reader Speed Launcher" -- File "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" -- [113520] -- [10/03/2009 04:08 AM]
"Adobe ARM" -- File "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" -- [1009016] -- [09/04/2009 12:08 PM]
"QuickTime Task" -- File: "C:\Program Files\QuickTime\QTTask.exe" -atboottime -- [?]
"WinampAgent" -- File "C:\Program Files\Winamp\winampa.exe" -- [107520] -- [07/02/2009 03:37 AM]


--- HKLM\RUNONCE regkey ---

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
no runonce values found


--- HKLM\RUNONCEEX regkey ---

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
no runonceex values found


--- HKLM\RUNSERVICES regkey ---

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
no runservices values found


--- HKLM\RUNSERVICESONCE regkey ---

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
no runservicesonce values found


--- HKCU\RUN regkey ---

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)" -- File: "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet -- [?]


--- HKCU\RUNONCE regkey ---

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
no runonce values found


--- HKCU\RUNONCEEX regkey ---

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
key not found


--- HKCU\RUNSERVICES regkey ---

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
no runservices values found


--- HKCU\RUNSERVICESONCE regkey ---

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
no runservicesonce values found


--- HKU\.DEFAULT\Run regkeys - Default user ---

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
no run values found


--- HKU\S-1-5-18\Run regkeys - user SYSTEM ---

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
no run values found


--- HKU\S-1-5-19\Run regkeys - User Lokale service ---

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
key not found


--- HKU\S-1-5-20\Run regkeys - User Lokale service ---

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
key not found


--- HKLM\Explorer\Run regkeys ---

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
no run values found


--- HKCU\Explorer\Run regkeys ---

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
no run values found


--- Image File Execution regkeys ---

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
no debuggers found


--- BROWSER HELPER OBJECTS regkeys ---

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
-- CLSID not found
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
-- File: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll -- [75128] -- [02/27/2009 01:07 PM]


--- TOOLBAR regkeys ---

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
no toolbars found


--- HKLM\URLSEARCHHOOKS regkeys ---

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks]
no urlsearchhooks found


--- HKCU\URLSEARCHHOOKS regkeys ---

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} -- File: %SystemRoot%\system32\shdocvw.dll -- [?]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -- CLSID not found


--- SRCEENSAVER regkey ---

[HKEY_CURRENT_USER\Control Panel\Desktop]
scrnsave.exe value not found


--- ALTERNATESHELL regkey ---

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
no AlternateShell value found


--- SECURITYPROVIDERS regkey ---

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
File: C:\WINDOWS\system32\msapsspc.dll -- [86016] -- [08/04/2004 11:00 PM]
File: C:\WINDOWS\system32\schannel.dll -- [144896] -- [08/04/2004 11:00 PM]
File: C:\WINDOWS\system32\digest.dll -- [68608] -- [08/04/2004 11:00 PM]
File: C:\WINDOWS\system32\msnsspc.dll -- [290816] -- [08/04/2004 11:00 PM]


--- Active Setup\Installed Components regkey ---

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
-- File: %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE -- [?]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
-- File: RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP -- [?]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
-- File: %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE -- [?]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
-- File: %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll -- [?]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
-- File: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install -- [?]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
-- File: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT -- [?]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{4b218e3e-bc98-4770-93d3-2731b9329278}]
-- File: %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf -- [?]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
-- File: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser -- [?]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
-- File: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub -- [?]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
-- File: regsvr32.exe /s /n /i:U shell32.dll -- [?]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
-- File: %SystemRoot%\system32\ie4uinit.exe -- [?]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
-- File: %SystemRoot%\system32\ie4uinit.exe -- [?]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}]
-- filepath not found


--- Services regkey ---

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp470n5]
-- File: \??\C:\WINDOWS\system32\drivers\flnipn.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\abp480n5]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\adpu160m]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aec]
-- File: system32\drivers\aec.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78u2]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aic78xx]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\amsint]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ANIO]
-- File: \??\C:\WINDOWS\system32\ANIO.SYS -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ANIWZCSdService]
-- File: C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe -- [126976] -- [01/19/2007 11:49 AM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3350p]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3550]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\atapi]
-- File: system32\DRIVERS\atapi.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\audstub]
-- File: system32\DRIVERS\audstub.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omgmt]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omp]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i8042prt]
-- File: system32\DRIVERS\i8042prt.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\inetaccs]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ini910u]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\irda]
-- File: system32\DRIVERS\irda.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\irsir]
-- File: system32\DRIVERS\irsir.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\isapnp]
-- File: system32\DRIVERS\isapnp.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\npkcrypt]
-- File: \??\D:\My Documents\VanRO\RO\npkcrypt.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ohci1394]
-- File: system32\DRIVERS\ohci1394.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\OMSI download service]
-- File: C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe -- [172032] -- [04/30/2009 12:23 PM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s1018bus]
-- File: system32\DRIVERS\s1018bus.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s1018mdfl]
-- File: system32\DRIVERS\s1018mdfl.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s1018mgmt]
-- File: system32\DRIVERS\s1018mgmt.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s1018nd5]
-- File: system32\DRIVERS\s1018nd5.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s1018obex]
-- File: system32\DRIVERS\s1018obex.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s1018unic]
-- File: system32\DRIVERS\s1018unic.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\seehcri]
-- File: system32\DRIVERS\seehcri.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ultra]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost]
-- File: %SystemRoot%\system32\svchost.exe -k LocalService -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbehci]
-- File: system32\DRIVERS\usbehci.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbhub]
-- File: system32\DRIVERS\usbhub.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbohci]
-- File: system32\DRIVERS\usbohci.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbstor]
-- File: system32\DRIVERS\USBSTOR.SYS -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\yukonwxp]
-- File: system32\DRIVERS\yk51x86.sys -- [?]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{0A088315-C8DE-4EEF-B02E-065DB21B2E51}]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{472CA9A7-544B-4C06-B16E-6AE35D88C7EC}]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{977F7CC0-6ED7-4D79-B0D1-7DD3D9727859}]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{E4B884A5-4CB7-4B70-B230-39FD9A24852E}]
-- filepath not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{F5600E9E-F754-4AEE-81D3-68BA1E3AFE09}]
-- filepath not found


--- SAFEBOOT MINIMAL SERVICES ---

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
no unknown services found


--- SAFEBOOT Network SERVICES ---

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network
no unknown services found


--- BOOTEXECUTE regkey ---

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager]
"BootExecute"= autocheck autochk *\0\0


--- PENDINGFILERENAMEOPERATIONS regkey ---

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager]
PendingFileRenameOperations key not found


--- WOW-CMDLINE regkeys ---

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WOW]
"cmdline" = %SystemRoot%\system32\ntvdm.exe
"cmdline" = %SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386


--- NETSVCS regkey ---

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] -- NETSVCS
0WmdmPmSN


--- DNS SERVER regkeys ---

no "NameServer" values found


--- File associations ---

.BAT files: ("%1" %*)
.COM files: ("%1" %*)
.EXE files: ("%1" %*)
.HLP files: (%SystemRoot%\System32\winhlp32.exe %1)
.INF files: (%SystemRoot%\System32\NOTEPAD.EXE %1)
.INI files: (%SystemRoot%\System32\NOTEPAD.EXE %1)
.JS files: (%SystemRoot%\System32\WScript.exe "%1" %*)
.PIF files: ("%1" %*)
.REG files: (regedit.exe "%1")
.SCR files: ("%1" /S)
.TXT files: (%SystemRoot%\system32\NOTEPAD.EXE %1)
.VBS files: (%SystemRoot%\System32\WScript.exe "%1" %*)


--- STARTUP FOLDERS ---

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\desktop.ini -- [84] -- [11/19/2009 04:26 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini -- [84] -- [11/19/2009 04:26 PM]
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini -- [84] -- [11/19/2009 04:26 PM]
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini -- [84] -- [11/19/2009 04:26 PM]


--- TASK SCHEDULER JOBS ---

C:\WINDOWS\tasks\AppleSoftwareUpdate.job -- [284] -- [12/04/2009 03:25 PM]


Scan completed: Sun 12/06/2009 12:29:50.07
FINISHED
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 12-6-2009 4:35 (GMT +2)    Quote: Need help with virus that takes over admin powersAlert an admin about: Need help with virus that takes over admin powers
Showing in those views clears as the day, but using a service very similar to a legit one:

Service C:\WINDOWS\system32\drivers\flnipn.sys [MANUAL] abp470n5

There is actually a legit "abp480n5". Very good - let's move on it now.


Be sure to continue to temporarily disable any protective software when running the scan tools we use here.


Open notepad (go to Start, Run, type notepad and press Enter) and copy/paste the text in the codebox below into it:

KillAll::
Driver::
abp470n5
Rootkit::
C:\WINDOWS\system32\drivers\flnipn.sys
Folder::
C:\DOCUME~1\Owner\LOCALS~1\Temp


Save this to your desktop as CFScript.txt


You should now have both ComboFix and that CFScript.txt on the desktop. Just left click/hold on the CFScript.txt file, and drag it into ComboFix to start the scan.

ComboFix will now run as it did before. Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.
Back to Top
 
New Topic Post reply to : Need help with virus that takes over admin powers Printable version of : Need help with virus that takes over admin powers
37 posts in this thread.
Viewing Page :
 1  2 
 
Forum Information
Currently it is Friday, July 30, 2010 2:00 PM (GMT +2)
There are a total of 79.134 posts in 17.897 threads.
In the last 3 days there were 8 new threads and 53 reply posts. View Active Threads
Who's Online
This forum has 31950 registered members. Please welcome our newest member, Willow.
33 Guest(s), 1 Registered Member(s) are currently online.  Details
tanisstray
5 Latest Threads
Updates more than 6 days old - BG advised upgrade from v8.7 to v9.0 to solve problem (4)30-07-2010 11:44:42 (Alex S.)
Redirect Virus Mozilla (10)30-07-2010 11:03:56 (tanisstray)
Redirected to different sites from links on Google (3)30-07-2010 09:36:16 (Touch)
Iexplore.exe virus causing problems (18)30-07-2010 09:32:14 (Touch)
9.1 is running! (10)30-07-2010 09:15:55 (katrina0)