Unsolved

This post is more than 5 years old

60 Posts

6228

July 17th, 2010 17:00

TR/Crypt.XPACK.Gen - Avira Antivirus keeps detecting it.

Hi,

I noticed that while my Dell Vostro 1000 computer was sitting idle, my Avira Antivirus would, at random times, detect the TR/Crypt.XPACK.Gen trojan at C:\WINDOWS\system32\drivers\atapi.sys

Avira Antivirus would beep and put up a message for about 10 seconds. I finally caught the message and hit "delete" the problem, but the problem keeps coming back.

I did a full disk scan by Avira Antivirus. Found Nothing.

I did a full disk scan by AVG Antivirus. Found Nothing.

I did a full disk scan by Malwarebytes. Found Nothing.

I did a quick scan using Microsoft Security Essentials. Found Nothing.

I did a full disk scan by Lavasoft Adaware. It found the trojan, but in a different place. C:\System Volume Information\...\A0O21266.sys

But I can't find the directory C:\System Volume Information\ , even showing hidden system files.

Anyways, I told Lavasoft Adaware to delete it.

I left Lavasoft Adaware running on my computer for the afternoon, idle. No beeping messages of the Trojan found.

So I removed Lavasoft Adaware from my system, and brought back Avira Anti-virus. After a couple of hours of idling, the computer beeped. Avira Antivirus found the trojan again.

So I'm at my wit's end. I don't know what to do anymore.

That's why I am here.

If someone could help me, it would be greatly appreciated.

Thanks.

Paul

----------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:51:26 PM, on 7/17/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AnVir Task Manager\AnVir.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Foxit Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [AnVir Task Manager] "C:\Program Files\AnVir Task Manager\AnVir.exe" Minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1201636395109
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1273661980821
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 9014 bytes

2 Intern

 • 

1.1K Posts

July 18th, 2010 09:00

Hi paulmcd123

I'm kevinf80 and I will be helping with any issues you may have. Please be aware that some of the logs I may ask for can be very complex and can take a long time to decipher. I am a volunteer here with a job and family so I ask that you be patient when waiting for replies.
Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
Please Print or Save to Notepad all instructions and please follow them carefully and if there's something you don't understand or that will not work please let me know and we will go through it together.
Malware is often buggy and can be very unstable, with that in mind it is advisable to backup any important data before we begin.

Please proceed as follows :-

Step 1

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

Combofix

Don`t forget Combofix must be saved to your desktop. <--Very important

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. <--- Very important

Please include the C:\ComboFix.txt in your next reply for further review.

Note: Do not click combofix's window with your mouse while it's running. That action may cause it to stall.

Examples of how to disable realtime protection available at the following link :-

Disable realtime protection

Step 2

Download Security Check by screen317 from HERE or HERE.
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. Press any key when asked.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Let me see logs from Combofix and Security Checks in your reply please.

Kevin

60 Posts

July 19th, 2010 14:00

Hi Kevin. Thanks for replying. Some notes:

1) Closed Avira antivirus (closed umbrella).

2) Closed Zone-Alarm firewall.

3) The Spybot directions look too complicated, so I simply uninstalled it.

4) Didn't see directions for Spyware Blaster,  so I uninstalled it.

5) I ran Combofix, but it found that Microsoft Security Essentials was running (I thought I had deleted it). So I uninstalled it, and continued running Combofix.

6) After Combofix finished, I logged in to get Security Check, and ran that (after closing FF and Zonealarm and Avira).

Thanks, Paul

------------------------------------------------------------------------------------------------------------------------------------------------------------

ComboFix 10-07-18.05 - Paul 07/19/2010  16:06:23.2.2 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1918.1340 [GMT -4:00]
Running from: c:\documents and settings\Paul\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\1028_DELL_XPS_Vostro   1000 .MRK
c:\windows\system32\drivers\DELL_XPS_Vostro   1000 .MRK
c:\windows\system32\st325602.dll

.
(((((((((((((((((((((((((   Files Created from 2010-06-19 to 2010-07-19  )))))))))))))))))))))))))))))))
.

2010-07-17 22:47 . 2010-07-17 22:47    388096    ----a-r-    c:\documents and settings\Paul\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-17 11:13 . 2010-06-01 17:37    221568    ------w-    c:\windows\system32\MpSigStub.exe
2010-07-14 12:45 . 2010-06-14 14:31    744448    -c----w-    c:\windows\system32\dllcache\helpsvc.exe
2010-07-13 11:39 . 2010-07-13 11:39    --------    d-----w-    c:\documents and settings\Paul\Local Settings\Application Data\Sunbelt Software
2010-07-11 03:41 . 2010-07-11 03:41    --------    d-----w-    c:\windows\system32\config\systemprofile\Application Data\Softland
2010-07-09 17:14 . 2010-07-19 08:47    --------    d-----w-    c:\program files\Common Files\Adobe
2010-07-09 16:40 . 2010-07-09 16:40    --------    d-----w-    c:\program files\Common Files\Adobe AIR
2010-07-09 16:39 . 2010-07-09 16:39    71680    ----a-w-    c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-07-03 06:07 . 2010-07-03 06:07    --------    d-----w-    c:\documents and settings\Paul\Application Data\Auslogics
2010-07-02 21:06 . 2010-07-02 21:06    --------    d-----w-    c:\program files\CodeStuff
2010-07-02 20:52 . 2010-07-02 20:52    --------    d-----w-    c:\program files\Auslogics
2010-06-28 23:07 . 2010-06-28 23:07    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\PostBuild.exe
2010-06-28 23:07 . 2010-06-28 23:07    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{D36DD326-7280-11D8-97C8-000129760CBE}\PostBuild.exe
2010-06-28 23:05 . 2010-06-28 23:05    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\PostBuild.exe
2010-06-28 23:04 . 2010-06-28 23:04    --------    d-----w-    c:\program files\Common Files\CyberLink
2010-06-28 23:03 . 2010-06-28 23:03    29480    ----a-w-    c:\windows\system32\msxml3a.dll
2010-06-28 23:03 . 2010-06-28 23:03    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe
2010-06-28 22:59 . 2010-06-28 22:59    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\PostBuild.exe
2010-06-28 22:59 . 2010-06-28 22:59    --------    d-----w-    C:\MyWorks
2010-06-28 22:58 . 2010-06-28 22:58    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
2010-06-28 22:57 . 2010-06-28 22:59    --------    d-----w-    c:\documents and settings\Paul\Application Data\CyberLink
2010-06-28 22:57 . 2010-06-28 22:57    --------    d-----w-    c:\documents and settings\Paul\Local Settings\Application Data\Cyberlink
2010-06-28 22:55 . 2010-06-28 22:55    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{80E158EA-7181-40FE-A701-301CE6BE64AB}\PostBuild.exe
2010-06-28 22:54 . 2010-06-28 22:54    1053232    ----a-w-    c:\windows\system32\MFC71u.dll
2010-06-28 22:54 . 2010-06-28 22:54    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\PostBuild.exe
2010-06-28 22:53 . 2007-10-26 14:55    15784    ------w-    c:\windows\system32\drivers\CLBStor.sys
2010-06-28 22:53 . 2007-10-26 14:55    162344    ------w-    c:\windows\system32\drivers\CLBUDF.sys
2010-06-28 22:53 . 2007-10-26 14:55    131072    ----a-w-    c:\windows\IBUnInst.exe
2010-06-28 22:53 . 2010-06-28 23:08    --------    d-----w-    c:\program files\CyberLink
2010-06-28 22:53 . 2010-06-28 22:53    --------    d-----w-    c:\documents and settings\All Users\Application Data\CyberLink
2010-06-28 22:51 . 2010-06-28 22:51    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
2010-06-22 14:30 . 2010-06-22 14:30    --------    d-----w-    c:\program files\iPod
2010-06-22 14:30 . 2010-06-22 14:30    --------    d-----w-    c:\program files\iTunes
2010-06-22 14:26 . 2010-06-22 14:26    --------    d-----w-    c:\program files\QuickTime
2010-06-22 14:24 . 2010-06-22 14:24    --------    d-----w-    c:\program files\Apple Software Update
2010-06-22 14:23 . 2010-06-22 14:23    --------    d-----w-    c:\program files\Bonjour

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-19 19:44 . 2009-12-08 22:46    --------    d-----w-    c:\program files\Spybot - Search & Destroy
2010-07-19 19:43 . 2009-08-12 17:24    --------    d-----w-    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-19 08:53 . 2010-04-20 04:49    79488    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll
2010-07-19 08:53 . 2010-04-20 04:49    152576    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\jre1.6.0_20\lzma.dll
2010-07-15 23:52 . 2010-04-13 16:03    --------    d-----w-    c:\program files\CamStudio
2010-07-15 00:41 . 2009-11-13 22:45    --------    d-----w-    c:\documents and settings\All Users\Application Data\Lavasoft
2010-07-14 10:20 . 2009-05-29 18:39    28913650    ----a-w-    c:\windows\Internet Logs\tvDebug.Zip
2010-07-13 11:46 . 2009-11-13 22:49    95024    ----a-w-    c:\windows\system32\drivers\SBREDrv.sys
2010-07-13 03:51 . 2009-11-14 07:12    --------    d---a-w-    c:\documents and settings\All Users\Application Data\TEMP
2010-07-09 16:39 . 2009-09-24 16:33    --------    d-----w-    c:\documents and settings\All Users\Application Data\NOS
2010-07-02 21:22 . 2010-05-25 00:27    --------    d-----w-    c:\documents and settings\Paul\Application Data\Media Player Classic
2010-07-02 20:56 . 2009-11-02 21:48    --------    d-----w-    c:\program files\CCleaner
2010-06-28 23:12 . 2008-01-29 18:49    25168    ----a-w-    c:\documents and settings\Paul\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-28 23:08 . 2008-01-29 17:52    --------    d--h--w-    c:\program files\InstallShield Installation Information
2010-06-28 23:03 . 2008-01-29 19:01    353576    ----a-w-    c:\windows\system32\msvcr71.dll
2010-06-28 23:03 . 2008-01-29 19:01    505128    ----a-w-    c:\windows\system32\msvcp71.dll
2010-06-28 22:54 . 2008-01-29 19:01    1066544    ----a-w-    c:\windows\system32\MFC71.dll
2010-06-24 16:34 . 2010-06-24 16:35    3014656    ----a-w-    c:\windows\Internet Logs\xDB2.tmp
2010-06-22 14:30 . 2010-02-22 22:27    --------    d-----w-    c:\program files\Common Files\Apple
2010-06-16 13:43 . 2010-06-16 13:43    61440    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-44825e10-n\decora-sse.dll
2010-06-16 13:43 . 2010-06-16 13:43    503808    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\msvcp71.dll
2010-06-16 13:43 . 2010-06-16 13:43    499712    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\jmc.dll
2010-06-16 13:43 . 2010-06-16 13:43    348160    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\msvcr71.dll
2010-06-16 13:43 . 2010-06-16 13:43    12800    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-44825e10-n\decora-d3d.dll
2010-06-16 00:01 . 2010-06-16 00:01    72504    ----a-w-    c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-14 14:31 . 2008-01-29 17:10    744448    ----a-w-    c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-12 15:52 . 2010-06-12 15:52    --------    d-----w-    c:\program files\JRE
2010-06-12 15:52 . 2010-04-20 05:05    --------    d-----w-    c:\program files\OpenOffice.org 3
2010-06-09 08:06 . 2010-06-09 08:06    976832    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AdobeARM.exe
2010-06-09 08:06 . 2010-06-09 08:06    70584    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AdobeExtractFiles.dll
2010-06-09 08:06 . 2010-06-09 08:06    331176    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\ReaderUpdater.exe
2010-06-09 08:06 . 2010-06-09 08:06    331176    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AcrobatUpdater.exe
2010-06-03 02:41 . 2010-06-03 02:41    3600384    ----a-w-    c:\windows\system32\GPhotos.scr
2010-05-31 20:34 . 2010-06-01 12:10    702120    ----a-w-    c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
2010-05-31 20:34 . 2010-06-01 12:10    868456    ----a-w-    c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2010-05-29 12:42 . 2010-05-29 12:42    --------    d-----w-    c:\program files\Secunia
2010-05-28 21:22 . 2010-05-28 21:22    --------    d-----w-    c:\documents and settings\Paul\Application Data\CheckPoint
2010-05-28 21:22 . 2010-05-28 21:22    --------    d-----w-    c:\program files\ZoneAlarm
2010-05-28 21:22 . 2010-05-28 21:22    --------    d-----w-    c:\program files\CheckPoint
2010-05-28 21:22 . 2008-01-29 19:48    4212    ---ha-w-    c:\windows\system32\zllictbl.dat
2010-05-28 11:04 . 2010-05-28 11:04    14896    ----a-w-    c:\windows\system32\drivers\psi_mf.sys
2010-05-27 00:21 . 2009-05-09 14:38    --------    d-----w-    c:\program files\Ricochet Lost Worlds Recharged
2010-05-26 17:03 . 2008-12-05 20:25    1238528    ----a-w-    c:\windows\system32\zpeng25.dll
2010-05-26 17:03 . 2009-03-27 13:28    69120    ----a-w-    c:\windows\system32\zlcomm.dll
2010-05-26 17:03 . 2009-03-27 13:28    103936    ----a-w-    c:\windows\system32\zlcommdb.dll
2010-05-24 23:51 . 2010-05-24 23:51    --------    d-----w-    c:\program files\Essentials Codec Pack
2010-05-24 05:55 . 2010-05-24 05:59    227    ----a-w-    C:\autoexectest.bat
2010-05-24 04:59 . 2010-05-24 03:51    --------    d-----w-    c:\program files\GNU
2010-05-18 20:35 . 2010-05-18 20:35    91424    ----a-w-    c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35    107808    ----a-w-    c:\windows\system32\dns-sd.exe
2010-05-13 20:46 . 2010-04-21 02:39    1    ----a-w-    c:\documents and settings\Paul\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-13 19:55 . 2010-05-13 19:56    2649600    ----a-w-    c:\windows\Internet Logs\xDB1.tmp
2010-05-06 10:41 . 2006-03-04 03:33    916480    ----a-w-    c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 10:00    1851264    ----a-w-    c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2009-11-08 18:05    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2009-11-08 18:05    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
2010-05-09 15:50    2517088    ----a-w-    c:\program files\ZoneAlarm\tbZone.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-02-04 20:50    1197448    ----a-w-    c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnVir Task Manager"="c:\program files\AnVir Task Manager\AnVir.exe" [2009-10-13 3102944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 851968]
"PMX Daemon"="ICO.EXE" [2007-03-08 49152]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-05-26 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-26 730600]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

c:\documents and settings\Paul\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2010-5-28 911920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmazonGSDownloaderTray]
2009-04-06 20:35    247296    ----a-w-    c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2008-12-20 11:50    2656528    ----a-w-    c:\program files\Logitech\QuickCam\Quickcam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 19:39    1090952    ----a-w-    c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 21:07    2260480    ------w-    c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Amazon Download Agent"=2 (0x2)
"AcrSch2Svc"=2 (0x2)
"TryAndDecideService"=3 (0x3)
"Lavasoft Ad-Aware Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 CLBStor;InstantBurn Storage Helper Driver;c:\windows\system32\drivers\CLBStor.sys [6/28/2010 6:53 PM 15784]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/3/2009 4:48 PM 108289]
R2 CLBUDF;CyberLink InstantBurn UDF Filesystem;c:\windows\system32\drivers\CLBUDF.sys [6/28/2010 6:53 PM 162344]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [5/26/2010 9:35 AM 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [5/26/2010 9:35 AM 493032]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/17/2010 2:57 PM 136176]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [5/28/2010 7:04 AM 14896]
S4 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [5/9/2009 10:37 AM 319488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper    REG_MULTI_SZ       getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-07-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]

2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-17 18:57]

2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-17 18:57]

2010-07-19 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-02-04 20:50]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\
FF - prefs.js: browser.startup.homepage - hxxp://us.mg2.mail.yahoo.com/dc/launch?.gx=1&.rand=2q7c5tkfrafdr
FF - component: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npigl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-MSSE - c:\program files\Microsoft Security Essentials\msseces.exe
MSConfigStartUp-Skype - c:\program files\Skype\Phone\Skype.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-19 16:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(952)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

- - - - - - - > 'lsass.exe'(1008)
c:\windows\system32\relog_ap.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2010-07-19  16:16:36
ComboFix-quarantined-files.txt  2010-07-19 20:16
ComboFix2.txt  2009-11-23 15:09

Pre-Run: 43,355,086,848 bytes free
Post-Run: 43,445,223,424 bytes free

- - End Of File - - E346CB3A8737EA8F11A4148EEC01B29E

---------------------------------------------------------------------------------------------------------------------------------------------------

 Results of screen317's Security Check version 0.99.4 
 Windows XP Service Pack 3 
 Internet Explorer 8 
``````````````````````````````
Antivirus/Firewall Check:

 Windows Firewall Enabled! 
 Avira AntiVir Personal - Free Antivirus
 ZoneAlarm     
 ZoneAlarm Toolbar    
 ZoneAlarm Spy Blocker   
 Avira successfully updated!
```````````````````````````````
Anti-malware/Other Utilities Check:

 Malwarebytes' Anti-Malware   
 HijackThis 2.0.2   
 CCleaner    
 Java(TM) 6 Update 18 
 Java(TM) 6 Update 20 
 Out of date Java installed!
 Adobe Flash Player 10.1.53.64 
Adobe Reader 9.3.3
 Mozilla Firefox (3.6.6)
````````````````````````````````
Process Check: 
objlist.exe by Laurent

 Avira Antivir avgnt.exe
 Avira Antivir avguard.exe
````````````````````````````````
DNS Vulnerability Check:

 Unknown. This method cannot test your vulnerability to DNS cache poisoning.

``````````End of Log````````````

 

 

2 Intern

 • 

1.1K Posts

July 19th, 2010 16:00

Hi paulmcd123,

The windows firewall appeared to be enabled, this might have happened when you stopped Zonealarm. It wasn`t a problem, just be aware when Zonealarm is back in service; make sure windows Firewall is OFF.

Proceed as follows:

Step 1

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text inbetween the dooted lines below into it













         -----------------------------------------------------------------------------------------------------------------------------------------

Folder::
c:\program files\Spybot - Search & Destroy
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
c:\program files\Ask.com
c:\documents and settings\All Users\Application Data\Lavasoft
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

 


























Save this as CFScript.txt, in the same location as ComboFix.exe

user posted image

user posted image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Disable realtime protection

Step 2

Please download Malwarebytes Anti-Malware and save it to your desktop.
Alernative D/L mirror
Alternative D/L mirror

MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to ALLOW the changes. Instructions available HERE
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
  • Update Malwarebytes' Anti-Malware
  • Launch Malwarebytes' Anti-Malware

Then click Finish.

MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from HERE and just double-click on mbam-rules.exe to install.

On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.

Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.

Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

Step 3

Run an online virus scan with Kaspersky from HERE. This scan is very thorough and may take several hours to run, please allow it to complete.
1. At the main page. Press on " Accept". After reading the contents.
2. At the next window Select  Update. Allow the Database to update.
Note: If prompted to run or update your Java, then follow the prompts to do so. Kaspersky requires Java to run.
3. Once the Database has finished, under the Scan icon Select My Computer to start the scan. The scan may take a few minutes to complete.
4. Select Scan Report.
5. If any threats were found they will appear in the report
6. Select "Save error report as"
Then in the file name just type in kaspersky
Under "save as type" select text .txt
Save it to your Desktop.
Copy and post the results of the Kaspersky Online scan. If no threats were found then report that as well.

The following animation may help.

Kaspersky Gif

What i`d like in your reply please :-

  • Log from Combofix
  • Log from Malwarebytes
  • Log from Kaspersky


Kevin






















































60 Posts

July 20th, 2010 04:00

Hi Kevin, Notes:

1) CFScript  references Spybot Search and Destroy. I had uninstalled Spybot. Is this what you wanted?

2) CFScript also references Lavasoft (Adaware). I had also uninstalled that. Is this what you wanted?

3) When I downloaded Malwarebytes, a "Task Manager program on steroids" called Anvir Task Manager asked me for permission  to allow Malwarebytes to load onto my computer. I clicked "yes" and then I turned Anvir Task Manager off.

4) I saw the report from Malwarebytes after running it last night, but now (this morning) I can't find it. I thought it was in the Program Files/Malwarebytes folder. So I did a Search of All Files and Folders for "mbam" and only found an mbam log from December of 2009.

5) It took almost an hour to load the Kaspersky database, and the computer scan ran for so long, I left it running overnight. This morning I saw that it ran for 4:22:01, but there was NO report. Is this right?

If you can tell me what to redo, that would be great. I'm about to run Malwarebytes right now because I know I saw an mbam results file.

BTW, I don't know how to turn off the Windows Firewall. Should I? I guess it saved my butt last night because ZoneAlarm and Avira Antirus were off all night while the computer was on all night. Anything could have attacked my computer.

So all I have right now is the results of Combofix running CFSript. :-(

Thanks, Paul

-------------------------------------------------------------------------------------------------------------

ComboFix 10-07-18.05 - Paul 07/19/2010  21:25:37.3.2 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1918.1367 [GMT -4:00]
Running from: c:\documents and settings\Paul\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Paul\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Lavasoft
c:\documents and settings\All Users\Application Data\Lavasoft\License\adaware.da2
c:\documents and settings\All Users\Application Data\Lavasoft\License\guid.dat
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.100702-1728.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.100702-1742.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.100713-0706.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.100713-0720.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.100702-1745.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.100713-0730.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Resident.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Update downloads.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\ProcCache.sbc
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\program files\Spybot - Search & Destroy
c:\program files\Spybot - Search & Destroy\advcheck.dll
c:\program files\Spybot - Search & Destroy\TeaTimer.exe

.
(((((((((((((((((((((((((   Files Created from 2010-06-20 to 2010-07-20  )))))))))))))))))))))))))))))))
.

2010-07-17 22:47 . 2010-07-17 22:47    388096    ----a-r-    c:\documents and settings\Paul\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-17 11:13 . 2010-06-01 17:37    221568    ------w-    c:\windows\system32\MpSigStub.exe
2010-07-14 12:45 . 2010-06-14 14:31    744448    -c----w-    c:\windows\system32\dllcache\helpsvc.exe
2010-07-13 11:39 . 2010-07-13 11:39    --------    d-----w-    c:\documents and settings\Paul\Local Settings\Application Data\Sunbelt Software
2010-07-11 03:41 . 2010-07-11 03:41    --------    d-----w-    c:\windows\system32\config\systemprofile\Application Data\Softland
2010-07-09 17:14 . 2010-07-19 08:47    --------    d-----w-    c:\program files\Common Files\Adobe
2010-07-09 16:40 . 2010-07-09 16:40    --------    d-----w-    c:\program files\Common Files\Adobe AIR
2010-07-09 16:39 . 2010-07-09 16:39    71680    ----a-w-    c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-07-03 06:07 . 2010-07-03 06:07    --------    d-----w-    c:\documents and settings\Paul\Application Data\Auslogics
2010-07-02 21:06 . 2010-07-02 21:06    --------    d-----w-    c:\program files\CodeStuff
2010-07-02 20:52 . 2010-07-02 20:52    --------    d-----w-    c:\program files\Auslogics
2010-06-28 23:07 . 2010-06-28 23:07    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\PostBuild.exe
2010-06-28 23:07 . 2010-06-28 23:07    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{D36DD326-7280-11D8-97C8-000129760CBE}\PostBuild.exe
2010-06-28 23:05 . 2010-06-28 23:05    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\PostBuild.exe
2010-06-28 23:04 . 2010-06-28 23:04    --------    d-----w-    c:\program files\Common Files\CyberLink
2010-06-28 23:03 . 2010-06-28 23:03    29480    ----a-w-    c:\windows\system32\msxml3a.dll
2010-06-28 23:03 . 2010-06-28 23:03    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe
2010-06-28 22:59 . 2010-06-28 22:59    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\PostBuild.exe
2010-06-28 22:59 . 2010-06-28 22:59    --------    d-----w-    C:\MyWorks
2010-06-28 22:58 . 2010-06-28 22:58    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
2010-06-28 22:57 . 2010-06-28 22:59    --------    d-----w-    c:\documents and settings\Paul\Application Data\CyberLink
2010-06-28 22:57 . 2010-06-28 22:57    --------    d-----w-    c:\documents and settings\Paul\Local Settings\Application Data\Cyberlink
2010-06-28 22:55 . 2010-06-28 22:55    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{80E158EA-7181-40FE-A701-301CE6BE64AB}\PostBuild.exe
2010-06-28 22:54 . 2010-06-28 22:54    1053232    ----a-w-    c:\windows\system32\MFC71u.dll
2010-06-28 22:54 . 2010-06-28 22:54    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\PostBuild.exe
2010-06-28 22:53 . 2007-10-26 14:55    15784    ------w-    c:\windows\system32\drivers\CLBStor.sys
2010-06-28 22:53 . 2007-10-26 14:55    162344    ------w-    c:\windows\system32\drivers\CLBUDF.sys
2010-06-28 22:53 . 2007-10-26 14:55    131072    ----a-w-    c:\windows\IBUnInst.exe
2010-06-28 22:53 . 2010-06-28 23:08    --------    d-----w-    c:\program files\CyberLink
2010-06-28 22:53 . 2010-06-28 22:53    --------    d-----w-    c:\documents and settings\All Users\Application Data\CyberLink
2010-06-28 22:51 . 2010-06-28 22:51    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
2010-06-22 14:30 . 2010-06-22 14:30    --------    d-----w-    c:\program files\iPod
2010-06-22 14:30 . 2010-06-22 14:30    --------    d-----w-    c:\program files\iTunes
2010-06-22 14:26 . 2010-06-22 14:26    --------    d-----w-    c:\program files\QuickTime
2010-06-22 14:24 . 2010-06-22 14:24    --------    d-----w-    c:\program files\Apple Software Update
2010-06-22 14:23 . 2010-06-22 14:23    --------    d-----w-    c:\program files\Bonjour

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-19 08:53 . 2010-04-20 04:49    79488    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll
2010-07-19 08:53 . 2010-04-20 04:49    152576    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\jre1.6.0_20\lzma.dll
2010-07-15 23:52 . 2010-04-13 16:03    --------    d-----w-    c:\program files\CamStudio
2010-07-14 10:20 . 2009-05-29 18:39    28913650    ----a-w-    c:\windows\Internet Logs\tvDebug.Zip
2010-07-13 11:46 . 2009-11-13 22:49    95024    ----a-w-    c:\windows\system32\drivers\SBREDrv.sys
2010-07-13 03:51 . 2009-11-14 07:12    --------    d---a-w-    c:\documents and settings\All Users\Application Data\TEMP
2010-07-09 16:39 . 2009-09-24 16:33    --------    d-----w-    c:\documents and settings\All Users\Application Data\NOS
2010-07-02 21:22 . 2010-05-25 00:27    --------    d-----w-    c:\documents and settings\Paul\Application Data\Media Player Classic
2010-07-02 20:56 . 2009-11-02 21:48    --------    d-----w-    c:\program files\CCleaner
2010-06-28 23:12 . 2008-01-29 18:49    25168    ----a-w-    c:\documents and settings\Paul\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-28 23:08 . 2008-01-29 17:52    --------    d--h--w-    c:\program files\InstallShield Installation Information
2010-06-28 23:03 . 2008-01-29 19:01    353576    ----a-w-    c:\windows\system32\msvcr71.dll
2010-06-28 23:03 . 2008-01-29 19:01    505128    ----a-w-    c:\windows\system32\msvcp71.dll
2010-06-28 22:54 . 2008-01-29 19:01    1066544    ----a-w-    c:\windows\system32\MFC71.dll
2010-06-24 16:34 . 2010-06-24 16:35    3014656    ----a-w-    c:\windows\Internet Logs\xDB2.tmp
2010-06-22 14:30 . 2010-02-22 22:27    --------    d-----w-    c:\program files\Common Files\Apple
2010-06-16 13:43 . 2010-06-16 13:43    61440    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-44825e10-n\decora-sse.dll
2010-06-16 13:43 . 2010-06-16 13:43    503808    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\msvcp71.dll
2010-06-16 13:43 . 2010-06-16 13:43    499712    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\jmc.dll
2010-06-16 13:43 . 2010-06-16 13:43    348160    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\msvcr71.dll
2010-06-16 13:43 . 2010-06-16 13:43    12800    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-44825e10-n\decora-d3d.dll
2010-06-16 00:01 . 2010-06-16 00:01    72504    ----a-w-    c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-14 14:31 . 2008-01-29 17:10    744448    ----a-w-    c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-12 15:52 . 2010-06-12 15:52    --------    d-----w-    c:\program files\JRE
2010-06-12 15:52 . 2010-04-20 05:05    --------    d-----w-    c:\program files\OpenOffice.org 3
2010-06-09 08:06 . 2010-06-09 08:06    976832    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AdobeARM.exe
2010-06-09 08:06 . 2010-06-09 08:06    70584    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AdobeExtractFiles.dll
2010-06-09 08:06 . 2010-06-09 08:06    331176    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\ReaderUpdater.exe
2010-06-09 08:06 . 2010-06-09 08:06    331176    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AcrobatUpdater.exe
2010-06-03 02:41 . 2010-06-03 02:41    3600384    ----a-w-    c:\windows\system32\GPhotos.scr
2010-05-31 20:34 . 2010-06-01 12:10    702120    ----a-w-    c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
2010-05-31 20:34 . 2010-06-01 12:10    868456    ----a-w-    c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2010-05-29 12:42 . 2010-05-29 12:42    --------    d-----w-    c:\program files\Secunia
2010-05-28 21:22 . 2010-05-28 21:22    --------    d-----w-    c:\documents and settings\Paul\Application Data\CheckPoint
2010-05-28 21:22 . 2010-05-28 21:22    --------    d-----w-    c:\program files\ZoneAlarm
2010-05-28 21:22 . 2010-05-28 21:22    --------    d-----w-    c:\program files\CheckPoint
2010-05-28 21:22 . 2008-01-29 19:48    4212    ---ha-w-    c:\windows\system32\zllictbl.dat
2010-05-28 11:04 . 2010-05-28 11:04    14896    ----a-w-    c:\windows\system32\drivers\psi_mf.sys
2010-05-27 00:21 . 2009-05-09 14:38    --------    d-----w-    c:\program files\Ricochet Lost Worlds Recharged
2010-05-26 17:03 . 2008-12-05 20:25    1238528    ----a-w-    c:\windows\system32\zpeng25.dll
2010-05-26 17:03 . 2009-03-27 13:28    69120    ----a-w-    c:\windows\system32\zlcomm.dll
2010-05-26 17:03 . 2009-03-27 13:28    103936    ----a-w-    c:\windows\system32\zlcommdb.dll
2010-05-24 23:51 . 2010-05-24 23:51    --------    d-----w-    c:\program files\Essentials Codec Pack
2010-05-24 05:55 . 2010-05-24 05:59    227    ----a-w-    C:\autoexectest.bat
2010-05-24 04:59 . 2010-05-24 03:51    --------    d-----w-    c:\program files\GNU
2010-05-18 20:35 . 2010-05-18 20:35    91424    ----a-w-    c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35    107808    ----a-w-    c:\windows\system32\dns-sd.exe
2010-05-13 20:46 . 2010-04-21 02:39    1    ----a-w-    c:\documents and settings\Paul\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-13 19:55 . 2010-05-13 19:56    2649600    ----a-w-    c:\windows\Internet Logs\xDB1.tmp
2010-05-06 10:41 . 2006-03-04 03:33    916480    ----a-w-    c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 10:00    1851264    ----a-w-    c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2009-11-08 18:05    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2009-11-08 18:05    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
.

(((((((((((((((((((((((((((((   SnapShot@2010-07-19_20.14.02   )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 10:00 . 2010-07-19 19:49    67714              c:\windows\system32\perfc009.dat
+ 2004-08-04 10:00 . 2010-07-19 20:42    67714              c:\windows\system32\perfc009.dat
+ 2004-08-04 10:00 . 2010-07-19 20:42    432924              c:\windows\system32\perfh009.dat
- 2004-08-04 10:00 . 2010-07-19 19:49    432924              c:\windows\system32\perfh009.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
2010-05-09 15:50    2517088    ----a-w-    c:\program files\ZoneAlarm\tbZone.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnVir Task Manager"="c:\program files\AnVir Task Manager\AnVir.exe" [2009-10-13 3102944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 851968]
"PMX Daemon"="ICO.EXE" [2007-03-08 49152]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-05-26 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-26 730600]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

c:\documents and settings\Paul\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2010-5-28 911920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmazonGSDownloaderTray]
2009-04-06 20:35    247296    ----a-w-    c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2008-12-20 11:50    2656528    ----a-w-    c:\program files\Logitech\QuickCam\Quickcam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 19:39    1090952    ----a-w-    c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Amazon Download Agent"=2 (0x2)
"AcrSch2Svc"=2 (0x2)
"TryAndDecideService"=3 (0x3)
"Lavasoft Ad-Aware Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 CLBStor;InstantBurn Storage Helper Driver;c:\windows\system32\drivers\CLBStor.sys [6/28/2010 6:53 PM 15784]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/3/2009 4:48 PM 108289]
R2 CLBUDF;CyberLink InstantBurn UDF Filesystem;c:\windows\system32\drivers\CLBUDF.sys [6/28/2010 6:53 PM 162344]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [5/26/2010 9:35 AM 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [5/26/2010 9:35 AM 493032]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/17/2010 2:57 PM 136176]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [5/28/2010 7:04 AM 14896]
S4 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [5/9/2009 10:37 AM 319488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper    REG_MULTI_SZ       getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-07-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]

2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-17 18:57]

2010-07-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-17 18:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\
FF - prefs.js: browser.startup.homepage - hxxp://us.mg2.mail.yahoo.com/dc/launch?.gx=1&.rand=2q7c5tkfrafdr
FF - component: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npigl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-19 21:31
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(952)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

- - - - - - - > 'lsass.exe'(1008)
c:\windows\system32\relog_ap.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2010-07-19  21:33:31
ComboFix-quarantined-files.txt  2010-07-20 01:33
ComboFix2.txt  2009-11-23 15:09

Pre-Run: 43,362,095,104 bytes free
Post-Run: 43,347,107,840 bytes free

- - End Of File - - 6C6B1FCCBF70D334E61C931BA41B1649
-----------------------------------------------------------------------------------------------------------------------------

 

 

60 Posts

July 20th, 2010 05:00

Hi Kevin,

 I reran Malwarebytes just now (7am). Here's the report.

I will now try to rerun Kaspersky.

------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4329

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

7/20/2010 7:00:53 AM
mbam-log-2010-07-20 (07-00-53).txt

Scan type: Quick scan
Objects scanned: 122350
Time elapsed: 4 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

2 Intern

 • 

1.1K Posts

July 20th, 2010 09:00

Hi Paul,

I`d like to see the other Malwarebytes log if possible please. Open Malwarebytes > Select the "Logs Tab" > from the list of logs look for the one we want by date/time. Select it and then open, that log will open in Notepad.

I asked you to delete the folders from the programs you uninstalled just to tidy up. Also Ask.com, dont let anything to do with Ask anywhere near your computer.

Regarding the Firewall, I`m sure that when you turn Zonealarm on, it turns the Windows Firewall OFF. To check the status of Windows F/W :-

Select Start > Control Panel > Security Center > Under "Mange Security Settings For" select the Windows F/W > from there you can turn it on and off.

Regarding the Kaspersky log, you will not get one if it found nothing, we can double check with ESET just to be certain.

Step 1

Run ESET Online Scan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.ESET OnlineScan
  • Click the user posted image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on user posted image to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the user posted image icon on your desktop.

  • Check user posted image
  • Click the user posted image button.
  • Accept any security warnings from your browser.
  • Check user posted image
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push user posted image
  • Push user posted image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the user posted image button.
  • Push user posted image

You can refer to this animation by neomage if needed.
Frequently asked questions available Here

Step 2

Re-open HJT do a scan and save the log.

What i`d like in your reply :-

  • Requested log from Malwarebytes
  • Log from ESET
  • Log from HJT
  • Update on your system, any specific issue?


Kevin.

2 Intern

 • 

1.1K Posts

July 20th, 2010 10:00

Hi Paul,

If your system is responding OK we can cleanup and set you free. Proceed as follows :-

Step 1

Remove Combofix now that we're done with it
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")user posted image

  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
  • It will also reset your system restore cache and create a fresh clean restore point.


Step 2

  • Download OTC by OldTimer and save it to your Desktop.
  • Double click user posted image icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big user posted image button.
  • You will get a prompt saying "Begining Cleanup Process". Please select Yes.
  • Restart your computer when prompted.It will also remove the OTC application.


Step 3

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to "JDK 6 Update 21 (JDK or JRE).
  • Click the Download JRE button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.

Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.

-- If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
-- If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
-- The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.



Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
To disable the JQS service if you don't want to use it:
  • Go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
  • Click Ok and reboot your computer.


Post a final HJT log and let me know if you have any specific issues.

Kevin


























60 Posts

July 20th, 2010 10:00

Hi Kevin,

I reran the Kaspersky program. Again, there was no report because there were no "threats found", no "infected objects found", and no "suspicious objects found". It scanned 194,036 objects in 4:24:37.

I wish this had found something.

So what do I do next?

-Paul

 

60 Posts

July 20th, 2010 12:00

HI Kevin,

I haven't done what you asked yet. I thought you'd want to see the report of an Avira Antivirus scan that I started around noon. I'll wait for your reply to this before I do the actions you recommended above. - Paul

p.s. I "repaired" the 4 instances.

--------------------------------------------------------------------------------------------------------------------------------------------------------



Avira AntiVir Personal
Report file date: Tuesday, July 20, 2010  12:39

Scanning for 2369320 virus strains and unwanted programs.

Licensee        : Avira AntiVir Personal - FREE Antivirus
Serial number   : 0000149996-ADJIE-0000001
Platform        : Windows XP
Windows version : (Service Pack 3)  [5.1.2600]
Boot mode       : Normally booted
Username        : SYSTEM
Computer name   : PAUL-9C407A28F4

Version information:
BUILD.DAT       : 9.0.0.422     21701 Bytes    3/9/2010 10:29:00
AVSCAN.EXE      : 9.0.3.10     466689 Bytes  10/13/2009 16:26:33
AVSCAN.DLL      : 9.0.3.0       40705 Bytes   2/27/2009 15:58:24
LUKE.DLL        : 9.0.3.2      209665 Bytes   2/20/2009 16:35:49
LUKERES.DLL     : 9.0.2.0       12033 Bytes   2/27/2009 15:58:52
VBASE000.VDF    : 7.10.0.0   19875328 Bytes   11/6/2009 12:35:52
VBASE001.VDF    : 7.10.1.0    1372672 Bytes  11/19/2009 20:51:49
VBASE002.VDF    : 7.10.3.1    3143680 Bytes   1/20/2010 20:01:57
VBASE003.VDF    : 7.10.3.75    996864 Bytes   1/26/2010 20:02:04
VBASE004.VDF    : 7.10.4.203   1579008 Bytes    3/5/2010 21:13:32
VBASE005.VDF    : 7.10.6.82   2494464 Bytes   4/15/2010 03:48:55
VBASE006.VDF    : 7.10.7.218   2294784 Bytes    6/2/2010 23:54:29
VBASE007.VDF    : 7.10.7.219      2048 Bytes    6/2/2010 23:54:29
VBASE008.VDF    : 7.10.7.220      2048 Bytes    6/2/2010 23:54:30
VBASE009.VDF    : 7.10.7.221      2048 Bytes    6/2/2010 23:54:30
VBASE010.VDF    : 7.10.7.222      2048 Bytes    6/2/2010 23:54:30
VBASE011.VDF    : 7.10.7.223      2048 Bytes    6/2/2010 23:54:30
VBASE012.VDF    : 7.10.7.224      2048 Bytes    6/2/2010 23:54:30
VBASE013.VDF    : 7.10.8.37    270336 Bytes   6/10/2010 03:14:26
VBASE014.VDF    : 7.10.8.69    138752 Bytes   6/14/2010 12:11:58
VBASE015.VDF    : 7.10.8.102    130560 Bytes   6/16/2010 12:11:42
VBASE016.VDF    : 7.10.8.135    152064 Bytes   6/21/2010 15:00:24
VBASE017.VDF    : 7.10.8.163    432128 Bytes   6/23/2010 15:00:32
VBASE018.VDF    : 7.10.8.194    133632 Bytes   6/27/2010 16:36:30
VBASE019.VDF    : 7.10.8.220    134656 Bytes   6/29/2010 20:18:22
VBASE020.VDF    : 7.10.8.252    171520 Bytes    7/4/2010 22:54:00
VBASE021.VDF    : 7.10.9.19    131072 Bytes    7/6/2010 22:55:52
VBASE022.VDF    : 7.10.9.36    297472 Bytes    7/7/2010 22:57:55
VBASE023.VDF    : 7.10.9.60    150016 Bytes   7/11/2010 00:05:50
VBASE024.VDF    : 7.10.9.79    113152 Bytes   7/13/2010 00:05:50
VBASE025.VDF    : 7.10.9.99    158720 Bytes   7/16/2010 00:09:57
VBASE026.VDF    : 7.10.9.112    155136 Bytes   7/19/2010 00:12:03
VBASE027.VDF    : 7.10.9.113      2048 Bytes   7/19/2010 00:12:03
VBASE028.VDF    : 7.10.9.114      2048 Bytes   7/19/2010 00:12:03
VBASE029.VDF    : 7.10.9.115      2048 Bytes   7/19/2010 00:12:04
VBASE030.VDF    : 7.10.9.116      2048 Bytes   7/19/2010 00:12:04
VBASE031.VDF    : 7.10.9.126    117248 Bytes   7/20/2010 16:36:52
Engineversion   : 8.2.4.22
AEVDF.DLL       : 8.1.2.0      106868 Bytes   4/24/2010 04:17:10
AESCRIPT.DLL    : 8.1.3.41    1364346 Bytes   7/20/2010 16:38:19
AESCN.DLL       : 8.1.6.1      127347 Bytes   5/13/2010 04:17:56
AESBX.DLL       : 8.1.3.1      254324 Bytes   4/24/2010 04:17:11
AERDL.DLL       : 8.1.8.2      614772 Bytes   7/20/2010 16:38:08
AEPACK.DLL      : 8.2.3.2      471414 Bytes   7/20/2010 16:37:57
AEOFFICE.DLL    : 8.1.1.7      201081 Bytes   7/20/2010 16:37:50
AEHEUR.DLL      : 8.1.2.6     2793846 Bytes   7/20/2010 16:37:47
AEHELP.DLL      : 8.1.13.2     242039 Bytes   7/20/2010 16:37:02
AEGEN.DLL       : 8.1.3.15     385396 Bytes   7/20/2010 16:36:59
AEEMU.DLL       : 8.1.2.0      393588 Bytes   4/24/2010 04:17:07
AECORE.DLL      : 8.1.16.2     192887 Bytes   7/20/2010 16:36:54
AEBB.DLL        : 8.1.1.0       53618 Bytes   4/24/2010 04:17:06
AVWINLL.DLL     : 9.0.0.3       18177 Bytes  12/12/2008 13:47:59
AVPREF.DLL      : 9.0.3.0       44289 Bytes   8/26/2009 20:14:02
AVREP.DLL       : 8.0.0.7      159784 Bytes   2/22/2010 20:02:37
AVREG.DLL       : 9.0.0.0       36609 Bytes   12/5/2008 15:32:09
AVARKT.DLL      : 9.0.0.3      292609 Bytes   3/24/2009 20:05:41
AVEVTLOG.DLL    : 9.0.0.7      167169 Bytes   1/30/2009 15:37:08
SQLITE3.DLL     : 3.6.1.0      326401 Bytes   1/28/2009 20:03:49
SMTPLIB.DLL     : 9.2.0.25      28417 Bytes    2/2/2009 13:21:33
NETNT.DLL       : 9.0.0.0       11521 Bytes   12/5/2008 15:32:10
RCIMAGE.DLL     : 9.0.0.25    2438913 Bytes   5/15/2009 20:39:58
RCTEXT.DLL      : 9.0.73.0      86785 Bytes  10/13/2009 17:25:47

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Tuesday, July 20, 2010  12:39

Starting search for hidden objects.
'46409' objects were checked, '0' hidden objects were found.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'ForceField.exe' - '0' Module(s) have been scanned
Scan process 'vsmon.exe' - '0' Module(s) have been scanned
Scan process 'zlclient.exe' - '0' Module(s) have been scanned
Scan process 'taskmgr.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'RichVideo.exe' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ISWSVC.exe' - '0' Module(s) have been scanned
Scan process 'BCMWLTRY.EXE' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
28 processes with 28 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
    [INFO]      No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
    [INFO]      No virus was found!
Boot sector 'D:\'
    [INFO]      No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '56' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\hiberfil.sys
    [WARNING]   The file could not be opened!
    [NOTE]      This file is a Windows system file.
    [NOTE]      This file cannot be opened for scanning.
C:\pagefile.sys
    [WARNING]   The file could not be opened!
    [NOTE]      This file is a Windows system file.
    [NOTE]      This file cannot be opened for scanning.
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP62\A0021268.VIR
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024349.sys
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024350.sys
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024351.sys
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\WINDOWS\ERDNT\cache\atapi.sys
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [WARNING]   'Is the TR/Crypt.XPACK.Gen Trojan'. This detection is probably an error. Please send us this file immediately for further analysis.
C:\WINDOWS\system32\dllcache\atapi.sys
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [WARNING]   'Is the TR/Crypt.XPACK.Gen Trojan'. This detection is probably an error. Please send us this file immediately for further analysis.
C:\WINDOWS\system32\drivers\atapi.sys
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [WARNING]   'Is the TR/Crypt.XPACK.Gen Trojan'. This detection is probably an error. Please send us this file immediately for further analysis.
Begin scan in 'D:\'

Beginning disinfection:
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP62\A0021268.VIR
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was moved to '4c75eba5.qua'!
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024349.sys
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was moved to '48500d1e.qua'!
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024350.sys
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was moved to '4db50496.qua'!
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024351.sys
    [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    [NOTE]      The file was moved to '4db71566.qua'!


End of the scan: Tuesday, July 20, 2010  14:31
Used time:  1:36:17 Hour(s)

The scan has been done completely.

  18697 Scanned directories
 781502 Files were scanned
      7 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      0 files were deleted
      0 Viruses and unwanted programs were repaired
      4 Files were moved to quarantine
      0 Files were renamed
      2 Files cannot be scanned
 781493 Files not concerned
   4816 Archives were scanned
      5 Warnings
      6 Notes
  46409 Objects were scanned with rootkit scan
      0 Hidden objects were found

 

2 Intern

 • 

1.1K Posts

July 20th, 2010 13:00

Hi Paul,

Yep they were contained in old restore points (System restore cache) When we uninstall Combofix with the command I gave in previous reply; aswell as removing itself and all associate files and folders, it also flushes the sys restore cache and creates a new clean restore point for you.

I like to use Kaspersky as my preferred online scan because it only identifies infected files folders etc, it doesn`t remove/quarantine anything. Then I can apply my fix accordingly.

When you run Avira it will remove the infected file/folder etc, as will ESET and other online scans. A poisoned restore point is sometimes preferrable to no restore points at all. We can restore to an infected state if required incase the PC will not boot etc. With no restore points you dont have that option.

Run the cleanup procedure I gave you, post a fresh HJT log and let me know of any specific issues, or if all is ok.

Cheers,

Kevin:emotion-21:

60 Posts

July 20th, 2010 13:00

In the above scan, three files (all named atapi.sys) were singled out, and asked to send the files to Avira Antivirus immediately. I did, and all three atapi.sys files were judged to be part of the TR/Crypt.XPACK.Gen trojan.  So I deleted all three files, and then emptied the Recycle Bin. I hope that was the right thing to do.

I'm going to do another Avira Antivirus scan to see if anything else pops up.

-Paul

2 Intern

 • 

1.1K Posts

July 20th, 2010 16:00

Hi Paul,

This what I asked you to do



If your system is responding OK we can cleanup and set you free. Proceed as follows :-

Step 1

Remove Combofix now that we're done with it





  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")user posted image
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
  • It will also reset your system restore cache and create a fresh clean restore point.



Step 2


  • Download OTC by OldTimer and save it to your Desktop.
  • Double click user posted image icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big user posted image button.
  • You will get a prompt saying "Begining Cleanup Process". Please select Yes.
  • Restart your computer when prompted.It will also remove the OTC application.

Any tools left on your desktop can be safely removed by deleting them. OK :emotion-21:



Step 3

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:



  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to "JDK 6 Update 21 (JDK or JRE).
  • Click the Download JRE button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.


Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.

  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.


-- If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
-- If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
-- The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.



Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
To disable the JQS service if you don't want to use it:



  • Go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
  • Click Ok and reboot your computer.



Post a final HJT log and let me know if you have any specific issues.

Kevin



60 Posts

July 20th, 2010 16:00

Hi Kevin,

1) Here is  last night's Malwarebytes log (per your 4:50pm post)

2) I didn't see where you had told me to remove everything about the programs I had deleted (Spybot, SpywareBlaster, and Microsoft Security Essentials), so I did a Search on them and deleted everything pertaining to them. (per your 4:50pm post)

3) Since I've received instructions from you at 5:58pm, am I still supposed to do the instructions from your 4:50pm post (e.g. ESET scan, HJT)? Or should I just skip the 4:50pm instructions and do only the instructions in your 5:58pm post?

Let me know.

Thanks,

Paul

 

----------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4328

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

7/19/2010 9:52:08 PM
mbam-log-2010-07-19 (21-52-08).txt

Scan type: Quick scan
Objects scanned: 119659
Time elapsed: 3 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

60 Posts

July 21st, 2010 05:00

I am trying to do what you asked.

Combofix Uninstall went fine.

I downloaded OTC.exe (right-click, save link as) to my desktop. It did not have the picture shown in your post. I double clicked the plain white box titled "OTC.exe" on the Desktop.  I have been watching an MSDOS box that is black, with the cursor jumping around the box. This has been going on for half-an-hour.

The title of the MSDOS box is "C:\DOCUME - 1\Paul\Desktop\OTC.exe"

I did not see the avatar shown in your post. I did not see a "Cleanup!" button.

Is this what is supposed to happen? I followed your instructions exactly.

Thanks,

Paul

 

2 Intern

 • 

1.1K Posts

July 21st, 2010 14:00

Hi Paul,

Yep there is an issue with the download site, delete the one you`ve got on your desktop. Run CCleaner, then re-boot. Next, download OTC again from HERE and run it as previously instructed.

Kevin

No Events found!

Top