Unsolved
This post is more than 5 years old
60 Posts
0
6228
July 17th, 2010 17:00
TR/Crypt.XPACK.Gen - Avira Antivirus keeps detecting it.
Hi,
I noticed that while my Dell Vostro 1000 computer was sitting idle, my Avira Antivirus would, at random times, detect the TR/Crypt.XPACK.Gen trojan at C:\WINDOWS\system32\drivers\atapi.sys
Avira Antivirus would beep and put up a message for about 10 seconds. I finally caught the message and hit "delete" the problem, but the problem keeps coming back.
I did a full disk scan by Avira Antivirus. Found Nothing.
I did a full disk scan by AVG Antivirus. Found Nothing.
I did a full disk scan by Malwarebytes. Found Nothing.
I did a quick scan using Microsoft Security Essentials. Found Nothing.
I did a full disk scan by Lavasoft Adaware. It found the trojan, but in a different place. C:\System Volume Information\...\A0O21266.sys
But I can't find the directory C:\System Volume Information\ , even showing hidden system files.
Anyways, I told Lavasoft Adaware to delete it.
I left Lavasoft Adaware running on my computer for the afternoon, idle. No beeping messages of the Trojan found.
So I removed Lavasoft Adaware from my system, and brought back Avira Anti-virus. After a couple of hours of idling, the computer beeped. Avira Antivirus found the trojan again.
So I'm at my wit's end. I don't know what to do anymore.
That's why I am here.
If someone could help me, it would be greatly appreciated.
Thanks.
Paul
----------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:51:26 PM, on 7/17/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AnVir Task Manager\AnVir.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Foxit Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [AnVir Task Manager] "C:\Program Files\AnVir Task Manager\AnVir.exe" Minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1201636395109
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1273661980821
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 9014 bytes


kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
July 18th, 2010 09:00
I'm kevinf80 and I will be helping with any issues you may have. Please be aware that some of the logs I may ask for can be very complex and can take a long time to decipher. I am a volunteer here with a job and family so I ask that you be patient when waiting for replies.
Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
Please Print or Save to Notepad all instructions and please follow them carefully and if there's something you don't understand or that will not work please let me know and we will go through it together.
Malware is often buggy and can be very unstable, with that in mind it is advisable to backup any important data before we begin.
Please proceed as follows :-
Step 1
We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
Combofix
Don`t forget Combofix must be saved to your desktop. <--Very important
Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. <--- Very important
Please include the C:\ComboFix.txt in your next reply for further review.
Note: Do not click combofix's window with your mouse while it's running. That action may cause it to stall.
Examples of how to disable realtime protection available at the following link :-
Disable realtime protection
Step 2
Download Security Check by screen317 from HERE or HERE.
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. Press any key when asked.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Let me see logs from Combofix and Security Checks in your reply please.
Kevin
paulmcd123
60 Posts
0
July 19th, 2010 14:00
Hi Kevin. Thanks for replying. Some notes:
1) Closed Avira antivirus (closed umbrella).
2) Closed Zone-Alarm firewall.
3) The Spybot directions look too complicated, so I simply uninstalled it.
4) Didn't see directions for Spyware Blaster, so I uninstalled it.
5) I ran Combofix, but it found that Microsoft Security Essentials was running (I thought I had deleted it). So I uninstalled it, and continued running Combofix.
6) After Combofix finished, I logged in to get Security Check, and ran that (after closing FF and Zonealarm and Avira).
Thanks, Paul
------------------------------------------------------------------------------------------------------------------------------------------------------------
ComboFix 10-07-18.05 - Paul 07/19/2010 16:06:23.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.1340 [GMT -4:00]
Running from: c:\documents and settings\Paul\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\1028_DELL_XPS_Vostro 1000 .MRK
c:\windows\system32\drivers\DELL_XPS_Vostro 1000 .MRK
c:\windows\system32\st325602.dll
.
((((((((((((((((((((((((( Files Created from 2010-06-19 to 2010-07-19 )))))))))))))))))))))))))))))))
.
2010-07-17 22:47 . 2010-07-17 22:47 388096 ----a-r- c:\documents and settings\Paul\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-17 11:13 . 2010-06-01 17:37 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-07-14 12:45 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-13 11:39 . 2010-07-13 11:39 -------- d-----w- c:\documents and settings\Paul\Local Settings\Application Data\Sunbelt Software
2010-07-11 03:41 . 2010-07-11 03:41 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Softland
2010-07-09 17:14 . 2010-07-19 08:47 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-09 16:40 . 2010-07-09 16:40 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-07-09 16:39 . 2010-07-09 16:39 71680 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-07-03 06:07 . 2010-07-03 06:07 -------- d-----w- c:\documents and settings\Paul\Application Data\Auslogics
2010-07-02 21:06 . 2010-07-02 21:06 -------- d-----w- c:\program files\CodeStuff
2010-07-02 20:52 . 2010-07-02 20:52 -------- d-----w- c:\program files\Auslogics
2010-06-28 23:07 . 2010-06-28 23:07 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\PostBuild.exe
2010-06-28 23:07 . 2010-06-28 23:07 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{D36DD326-7280-11D8-97C8-000129760CBE}\PostBuild.exe
2010-06-28 23:05 . 2010-06-28 23:05 36864 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\PostBuild.exe
2010-06-28 23:04 . 2010-06-28 23:04 -------- d-----w- c:\program files\Common Files\CyberLink
2010-06-28 23:03 . 2010-06-28 23:03 29480 ----a-w- c:\windows\system32\msxml3a.dll
2010-06-28 23:03 . 2010-06-28 23:03 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe
2010-06-28 22:59 . 2010-06-28 22:59 36864 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\PostBuild.exe
2010-06-28 22:59 . 2010-06-28 22:59 -------- d-----w- C:\MyWorks
2010-06-28 22:58 . 2010-06-28 22:58 36864 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
2010-06-28 22:57 . 2010-06-28 22:59 -------- d-----w- c:\documents and settings\Paul\Application Data\CyberLink
2010-06-28 22:57 . 2010-06-28 22:57 -------- d-----w- c:\documents and settings\Paul\Local Settings\Application Data\Cyberlink
2010-06-28 22:55 . 2010-06-28 22:55 36864 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{80E158EA-7181-40FE-A701-301CE6BE64AB}\PostBuild.exe
2010-06-28 22:54 . 2010-06-28 22:54 1053232 ----a-w- c:\windows\system32\MFC71u.dll
2010-06-28 22:54 . 2010-06-28 22:54 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\PostBuild.exe
2010-06-28 22:53 . 2007-10-26 14:55 15784 ------w- c:\windows\system32\drivers\CLBStor.sys
2010-06-28 22:53 . 2007-10-26 14:55 162344 ------w- c:\windows\system32\drivers\CLBUDF.sys
2010-06-28 22:53 . 2007-10-26 14:55 131072 ----a-w- c:\windows\IBUnInst.exe
2010-06-28 22:53 . 2010-06-28 23:08 -------- d-----w- c:\program files\CyberLink
2010-06-28 22:53 . 2010-06-28 22:53 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2010-06-28 22:51 . 2010-06-28 22:51 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
2010-06-22 14:30 . 2010-06-22 14:30 -------- d-----w- c:\program files\iPod
2010-06-22 14:30 . 2010-06-22 14:30 -------- d-----w- c:\program files\iTunes
2010-06-22 14:26 . 2010-06-22 14:26 -------- d-----w- c:\program files\QuickTime
2010-06-22 14:24 . 2010-06-22 14:24 -------- d-----w- c:\program files\Apple Software Update
2010-06-22 14:23 . 2010-06-22 14:23 -------- d-----w- c:\program files\Bonjour
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-19 19:44 . 2009-12-08 22:46 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-19 19:43 . 2009-08-12 17:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-19 08:53 . 2010-04-20 04:49 79488 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll
2010-07-19 08:53 . 2010-04-20 04:49 152576 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\jre1.6.0_20\lzma.dll
2010-07-15 23:52 . 2010-04-13 16:03 -------- d-----w- c:\program files\CamStudio
2010-07-15 00:41 . 2009-11-13 22:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-07-14 10:20 . 2009-05-29 18:39 28913650 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-07-13 11:46 . 2009-11-13 22:49 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-07-13 03:51 . 2009-11-14 07:12 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-09 16:39 . 2009-09-24 16:33 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-02 21:22 . 2010-05-25 00:27 -------- d-----w- c:\documents and settings\Paul\Application Data\Media Player Classic
2010-07-02 20:56 . 2009-11-02 21:48 -------- d-----w- c:\program files\CCleaner
2010-06-28 23:12 . 2008-01-29 18:49 25168 ----a-w- c:\documents and settings\Paul\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-28 23:08 . 2008-01-29 17:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-28 23:03 . 2008-01-29 19:01 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-06-28 23:03 . 2008-01-29 19:01 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-06-28 22:54 . 2008-01-29 19:01 1066544 ----a-w- c:\windows\system32\MFC71.dll
2010-06-24 16:34 . 2010-06-24 16:35 3014656 ----a-w- c:\windows\Internet Logs\xDB2.tmp
2010-06-22 14:30 . 2010-02-22 22:27 -------- d-----w- c:\program files\Common Files\Apple
2010-06-16 13:43 . 2010-06-16 13:43 61440 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-44825e10-n\decora-sse.dll
2010-06-16 13:43 . 2010-06-16 13:43 503808 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\msvcp71.dll
2010-06-16 13:43 . 2010-06-16 13:43 499712 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\jmc.dll
2010-06-16 13:43 . 2010-06-16 13:43 348160 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\msvcr71.dll
2010-06-16 13:43 . 2010-06-16 13:43 12800 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-44825e10-n\decora-d3d.dll
2010-06-16 00:01 . 2010-06-16 00:01 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-14 14:31 . 2008-01-29 17:10 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-12 15:52 . 2010-06-12 15:52 -------- d-----w- c:\program files\JRE
2010-06-12 15:52 . 2010-04-20 05:05 -------- d-----w- c:\program files\OpenOffice.org 3
2010-06-09 08:06 . 2010-06-09 08:06 976832 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AdobeARM.exe
2010-06-09 08:06 . 2010-06-09 08:06 70584 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AdobeExtractFiles.dll
2010-06-09 08:06 . 2010-06-09 08:06 331176 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\ReaderUpdater.exe
2010-06-09 08:06 . 2010-06-09 08:06 331176 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AcrobatUpdater.exe
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-05-31 20:34 . 2010-06-01 12:10 702120 ----a-w- c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
2010-05-31 20:34 . 2010-06-01 12:10 868456 ----a-w- c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2010-05-29 12:42 . 2010-05-29 12:42 -------- d-----w- c:\program files\Secunia
2010-05-28 21:22 . 2010-05-28 21:22 -------- d-----w- c:\documents and settings\Paul\Application Data\CheckPoint
2010-05-28 21:22 . 2010-05-28 21:22 -------- d-----w- c:\program files\ZoneAlarm
2010-05-28 21:22 . 2010-05-28 21:22 -------- d-----w- c:\program files\CheckPoint
2010-05-28 21:22 . 2008-01-29 19:48 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-05-28 11:04 . 2010-05-28 11:04 14896 ----a-w- c:\windows\system32\drivers\psi_mf.sys
2010-05-27 00:21 . 2009-05-09 14:38 -------- d-----w- c:\program files\Ricochet Lost Worlds Recharged
2010-05-26 17:03 . 2008-12-05 20:25 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2010-05-26 17:03 . 2009-03-27 13:28 69120 ----a-w- c:\windows\system32\zlcomm.dll
2010-05-26 17:03 . 2009-03-27 13:28 103936 ----a-w- c:\windows\system32\zlcommdb.dll
2010-05-24 23:51 . 2010-05-24 23:51 -------- d-----w- c:\program files\Essentials Codec Pack
2010-05-24 05:55 . 2010-05-24 05:59 227 ----a-w- C:\autoexectest.bat
2010-05-24 04:59 . 2010-05-24 03:51 -------- d-----w- c:\program files\GNU
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-13 20:46 . 2010-04-21 02:39 1 ----a-w- c:\documents and settings\Paul\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-13 19:55 . 2010-05-13 19:56 2649600 ----a-w- c:\windows\Internet Logs\xDB1.tmp
2010-05-06 10:41 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 10:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2009-11-08 18:05 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2009-11-08 18:05 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
2010-05-09 15:50 2517088 ----a-w- c:\program files\ZoneAlarm\tbZone.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-02-04 20:50 1197448 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnVir Task Manager"="c:\program files\AnVir Task Manager\AnVir.exe" [2009-10-13 3102944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 851968]
"PMX Daemon"="ICO.EXE" [2007-03-08 49152]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-05-26 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-26 730600]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
c:\documents and settings\Paul\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2010-5-28 911920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmazonGSDownloaderTray]
2009-04-06 20:35 247296 ----a-w- c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2008-12-20 11:50 2656528 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 19:39 1090952 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 21:07 2260480 ------w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Amazon Download Agent"=2 (0x2)
"AcrSch2Svc"=2 (0x2)
"TryAndDecideService"=3 (0x3)
"Lavasoft Ad-Aware Service"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 CLBStor;InstantBurn Storage Helper Driver;c:\windows\system32\drivers\CLBStor.sys [6/28/2010 6:53 PM 15784]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/3/2009 4:48 PM 108289]
R2 CLBUDF;CyberLink InstantBurn UDF Filesystem;c:\windows\system32\drivers\CLBUDF.sys [6/28/2010 6:53 PM 162344]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [5/26/2010 9:35 AM 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [5/26/2010 9:35 AM 493032]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/17/2010 2:57 PM 136176]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [5/28/2010 7:04 AM 14896]
S4 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [5/9/2009 10:37 AM 319488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-07-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-17 18:57]
2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-17 18:57]
2010-07-19 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-02-04 20:50]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\
FF - prefs.js: browser.startup.homepage - hxxp://us.mg2.mail.yahoo.com/dc/launch?.gx=1&.rand=2q7c5tkfrafdr
FF - component: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npigl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-MSSE - c:\program files\Microsoft Security Essentials\msseces.exe
MSConfigStartUp-Skype - c:\program files\Skype\Phone\Skype.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-19 16:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(952)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
- - - - - - - > 'lsass.exe'(1008)
c:\windows\system32\relog_ap.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2010-07-19 16:16:36
ComboFix-quarantined-files.txt 2010-07-19 20:16
ComboFix2.txt 2009-11-23 15:09
Pre-Run: 43,355,086,848 bytes free
Post-Run: 43,445,223,424 bytes free
- - End Of File - - E346CB3A8737EA8F11A4148EEC01B29E
---------------------------------------------------------------------------------------------------------------------------------------------------
Results of screen317's Security Check version 0.99.4
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:
Windows Firewall Enabled!
Avira AntiVir Personal - Free Antivirus
ZoneAlarm
ZoneAlarm Toolbar
ZoneAlarm Spy Blocker
Avira successfully updated!
```````````````````````````````
Anti-malware/Other Utilities Check:
Malwarebytes' Anti-Malware
HijackThis 2.0.2
CCleaner
Java(TM) 6 Update 18
Java(TM) 6 Update 20
Out of date Java installed!
Adobe Flash Player 10.1.53.64
Adobe Reader 9.3.3
Mozilla Firefox (3.6.6)
````````````````````````````````
Process Check:
objlist.exe by Laurent
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
````````````````````````````````
DNS Vulnerability Check:
Unknown. This method cannot test your vulnerability to DNS cache poisoning.
``````````End of Log````````````
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
July 19th, 2010 16:00
The windows firewall appeared to be enabled, this might have happened when you stopped Zonealarm. It wasn`t a problem, just be aware when Zonealarm is back in service; make sure windows Firewall is OFF.
Proceed as follows:
Step 1
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text inbetween the dooted lines below into it
Folder::
c:\program files\Spybot - Search & Destroy
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
c:\program files\Ask.com
c:\documents and settings\All Users\Application Data\Lavasoft
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Save this as CFScript.txt, in the same location as ComboFix.exe
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Disable realtime protection
Step 2
Please download Malwarebytes Anti-Malware and save it to your desktop.
Alernative D/L mirror
Alternative D/L mirror
MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to ALLOW the changes. Instructions available HERE
Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
On the Scanner tab:
Back at the main Scanner screen:
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.
Step 3
Run an online virus scan with Kaspersky from HERE. This scan is very thorough and may take several hours to run, please allow it to complete.
1. At the main page. Press on " Accept". After reading the contents.
2. At the next window Select Update. Allow the Database to update.
Note: If prompted to run or update your Java, then follow the prompts to do so. Kaspersky requires Java to run.
3. Once the Database has finished, under the Scan icon Select My Computer to start the scan. The scan may take a few minutes to complete.
4. Select Scan Report.
5. If any threats were found they will appear in the report
6. Select "Save error report as"
Then in the file name just type in kaspersky
Under "save as type" select text .txt
Save it to your Desktop.
Copy and post the results of the Kaspersky Online scan. If no threats were found then report that as well.
The following animation may help.
Kaspersky Gif
What i`d like in your reply please :-
Kevin
paulmcd123
60 Posts
0
July 20th, 2010 04:00
Hi Kevin, Notes:
1) CFScript references Spybot Search and Destroy. I had uninstalled Spybot. Is this what you wanted?
2) CFScript also references Lavasoft (Adaware). I had also uninstalled that. Is this what you wanted?
3) When I downloaded Malwarebytes, a "Task Manager program on steroids" called Anvir Task Manager asked me for permission to allow Malwarebytes to load onto my computer. I clicked "yes" and then I turned Anvir Task Manager off.
4) I saw the report from Malwarebytes after running it last night, but now (this morning) I can't find it. I thought it was in the Program Files/Malwarebytes folder. So I did a Search of All Files and Folders for "mbam" and only found an mbam log from December of 2009.
5) It took almost an hour to load the Kaspersky database, and the computer scan ran for so long, I left it running overnight. This morning I saw that it ran for 4:22:01, but there was NO report. Is this right?
If you can tell me what to redo, that would be great. I'm about to run Malwarebytes right now because I know I saw an mbam results file.
BTW, I don't know how to turn off the Windows Firewall. Should I? I guess it saved my butt last night because ZoneAlarm and Avira Antirus were off all night while the computer was on all night. Anything could have attacked my computer.
So all I have right now is the results of Combofix running CFSript. :-(
Thanks, Paul
-------------------------------------------------------------------------------------------------------------
ComboFix 10-07-18.05 - Paul 07/19/2010 21:25:37.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.1367 [GMT -4:00]
Running from: c:\documents and settings\Paul\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Paul\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Lavasoft
c:\documents and settings\All Users\Application Data\Lavasoft\License\adaware.da2
c:\documents and settings\All Users\Application Data\Lavasoft\License\guid.dat
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.100702-1728.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.100702-1742.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.100713-0706.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.100713-0720.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.100702-1745.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.100713-0730.txt
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Resident.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Update downloads.log
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\ProcCache.sbc
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
c:\program files\Spybot - Search & Destroy
c:\program files\Spybot - Search & Destroy\advcheck.dll
c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
((((((((((((((((((((((((( Files Created from 2010-06-20 to 2010-07-20 )))))))))))))))))))))))))))))))
.
2010-07-17 22:47 . 2010-07-17 22:47 388096 ----a-r- c:\documents and settings\Paul\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-17 11:13 . 2010-06-01 17:37 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-07-14 12:45 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-13 11:39 . 2010-07-13 11:39 -------- d-----w- c:\documents and settings\Paul\Local Settings\Application Data\Sunbelt Software
2010-07-11 03:41 . 2010-07-11 03:41 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Softland
2010-07-09 17:14 . 2010-07-19 08:47 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-09 16:40 . 2010-07-09 16:40 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-07-09 16:39 . 2010-07-09 16:39 71680 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-07-03 06:07 . 2010-07-03 06:07 -------- d-----w- c:\documents and settings\Paul\Application Data\Auslogics
2010-07-02 21:06 . 2010-07-02 21:06 -------- d-----w- c:\program files\CodeStuff
2010-07-02 20:52 . 2010-07-02 20:52 -------- d-----w- c:\program files\Auslogics
2010-06-28 23:07 . 2010-06-28 23:07 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\PostBuild.exe
2010-06-28 23:07 . 2010-06-28 23:07 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{D36DD326-7280-11D8-97C8-000129760CBE}\PostBuild.exe
2010-06-28 23:05 . 2010-06-28 23:05 36864 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\PostBuild.exe
2010-06-28 23:04 . 2010-06-28 23:04 -------- d-----w- c:\program files\Common Files\CyberLink
2010-06-28 23:03 . 2010-06-28 23:03 29480 ----a-w- c:\windows\system32\msxml3a.dll
2010-06-28 23:03 . 2010-06-28 23:03 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe
2010-06-28 22:59 . 2010-06-28 22:59 36864 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\PostBuild.exe
2010-06-28 22:59 . 2010-06-28 22:59 -------- d-----w- C:\MyWorks
2010-06-28 22:58 . 2010-06-28 22:58 36864 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
2010-06-28 22:57 . 2010-06-28 22:59 -------- d-----w- c:\documents and settings\Paul\Application Data\CyberLink
2010-06-28 22:57 . 2010-06-28 22:57 -------- d-----w- c:\documents and settings\Paul\Local Settings\Application Data\Cyberlink
2010-06-28 22:55 . 2010-06-28 22:55 36864 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{80E158EA-7181-40FE-A701-301CE6BE64AB}\PostBuild.exe
2010-06-28 22:54 . 2010-06-28 22:54 1053232 ----a-w- c:\windows\system32\MFC71u.dll
2010-06-28 22:54 . 2010-06-28 22:54 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\PostBuild.exe
2010-06-28 22:53 . 2007-10-26 14:55 15784 ------w- c:\windows\system32\drivers\CLBStor.sys
2010-06-28 22:53 . 2007-10-26 14:55 162344 ------w- c:\windows\system32\drivers\CLBUDF.sys
2010-06-28 22:53 . 2007-10-26 14:55 131072 ----a-w- c:\windows\IBUnInst.exe
2010-06-28 22:53 . 2010-06-28 23:08 -------- d-----w- c:\program files\CyberLink
2010-06-28 22:53 . 2010-06-28 22:53 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2010-06-28 22:51 . 2010-06-28 22:51 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
2010-06-22 14:30 . 2010-06-22 14:30 -------- d-----w- c:\program files\iPod
2010-06-22 14:30 . 2010-06-22 14:30 -------- d-----w- c:\program files\iTunes
2010-06-22 14:26 . 2010-06-22 14:26 -------- d-----w- c:\program files\QuickTime
2010-06-22 14:24 . 2010-06-22 14:24 -------- d-----w- c:\program files\Apple Software Update
2010-06-22 14:23 . 2010-06-22 14:23 -------- d-----w- c:\program files\Bonjour
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-19 08:53 . 2010-04-20 04:49 79488 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll
2010-07-19 08:53 . 2010-04-20 04:49 152576 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\jre1.6.0_20\lzma.dll
2010-07-15 23:52 . 2010-04-13 16:03 -------- d-----w- c:\program files\CamStudio
2010-07-14 10:20 . 2009-05-29 18:39 28913650 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-07-13 11:46 . 2009-11-13 22:49 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-07-13 03:51 . 2009-11-14 07:12 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-09 16:39 . 2009-09-24 16:33 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-02 21:22 . 2010-05-25 00:27 -------- d-----w- c:\documents and settings\Paul\Application Data\Media Player Classic
2010-07-02 20:56 . 2009-11-02 21:48 -------- d-----w- c:\program files\CCleaner
2010-06-28 23:12 . 2008-01-29 18:49 25168 ----a-w- c:\documents and settings\Paul\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-28 23:08 . 2008-01-29 17:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-28 23:03 . 2008-01-29 19:01 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-06-28 23:03 . 2008-01-29 19:01 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-06-28 22:54 . 2008-01-29 19:01 1066544 ----a-w- c:\windows\system32\MFC71.dll
2010-06-24 16:34 . 2010-06-24 16:35 3014656 ----a-w- c:\windows\Internet Logs\xDB2.tmp
2010-06-22 14:30 . 2010-02-22 22:27 -------- d-----w- c:\program files\Common Files\Apple
2010-06-16 13:43 . 2010-06-16 13:43 61440 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-44825e10-n\decora-sse.dll
2010-06-16 13:43 . 2010-06-16 13:43 503808 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\msvcp71.dll
2010-06-16 13:43 . 2010-06-16 13:43 499712 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\jmc.dll
2010-06-16 13:43 . 2010-06-16 13:43 348160 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\msvcr71.dll
2010-06-16 13:43 . 2010-06-16 13:43 12800 ----a-w- c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-44825e10-n\decora-d3d.dll
2010-06-16 00:01 . 2010-06-16 00:01 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-14 14:31 . 2008-01-29 17:10 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-12 15:52 . 2010-06-12 15:52 -------- d-----w- c:\program files\JRE
2010-06-12 15:52 . 2010-04-20 05:05 -------- d-----w- c:\program files\OpenOffice.org 3
2010-06-09 08:06 . 2010-06-09 08:06 976832 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AdobeARM.exe
2010-06-09 08:06 . 2010-06-09 08:06 70584 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AdobeExtractFiles.dll
2010-06-09 08:06 . 2010-06-09 08:06 331176 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\ReaderUpdater.exe
2010-06-09 08:06 . 2010-06-09 08:06 331176 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AcrobatUpdater.exe
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
2010-05-31 20:34 . 2010-06-01 12:10 702120 ----a-w- c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
2010-05-31 20:34 . 2010-06-01 12:10 868456 ----a-w- c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2010-05-29 12:42 . 2010-05-29 12:42 -------- d-----w- c:\program files\Secunia
2010-05-28 21:22 . 2010-05-28 21:22 -------- d-----w- c:\documents and settings\Paul\Application Data\CheckPoint
2010-05-28 21:22 . 2010-05-28 21:22 -------- d-----w- c:\program files\ZoneAlarm
2010-05-28 21:22 . 2010-05-28 21:22 -------- d-----w- c:\program files\CheckPoint
2010-05-28 21:22 . 2008-01-29 19:48 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-05-28 11:04 . 2010-05-28 11:04 14896 ----a-w- c:\windows\system32\drivers\psi_mf.sys
2010-05-27 00:21 . 2009-05-09 14:38 -------- d-----w- c:\program files\Ricochet Lost Worlds Recharged
2010-05-26 17:03 . 2008-12-05 20:25 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2010-05-26 17:03 . 2009-03-27 13:28 69120 ----a-w- c:\windows\system32\zlcomm.dll
2010-05-26 17:03 . 2009-03-27 13:28 103936 ----a-w- c:\windows\system32\zlcommdb.dll
2010-05-24 23:51 . 2010-05-24 23:51 -------- d-----w- c:\program files\Essentials Codec Pack
2010-05-24 05:55 . 2010-05-24 05:59 227 ----a-w- C:\autoexectest.bat
2010-05-24 04:59 . 2010-05-24 03:51 -------- d-----w- c:\program files\GNU
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-13 20:46 . 2010-04-21 02:39 1 ----a-w- c:\documents and settings\Paul\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-13 19:55 . 2010-05-13 19:56 2649600 ----a-w- c:\windows\Internet Logs\xDB1.tmp
2010-05-06 10:41 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 10:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2009-11-08 18:05 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2009-11-08 18:05 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-07-19_20.14.02 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 10:00 . 2010-07-19 19:49 67714 c:\windows\system32\perfc009.dat
+ 2004-08-04 10:00 . 2010-07-19 20:42 67714 c:\windows\system32\perfc009.dat
+ 2004-08-04 10:00 . 2010-07-19 20:42 432924 c:\windows\system32\perfh009.dat
- 2004-08-04 10:00 . 2010-07-19 19:49 432924 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
2010-05-09 15:50 2517088 ----a-w- c:\program files\ZoneAlarm\tbZone.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]
[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnVir Task Manager"="c:\program files\AnVir Task Manager\AnVir.exe" [2009-10-13 3102944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 851968]
"PMX Daemon"="ICO.EXE" [2007-03-08 49152]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-05-26 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-26 730600]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
c:\documents and settings\Paul\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2010-5-28 911920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmazonGSDownloaderTray]
2009-04-06 20:35 247296 ----a-w- c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2008-12-20 11:50 2656528 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 19:39 1090952 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Amazon Download Agent"=2 (0x2)
"AcrSch2Svc"=2 (0x2)
"TryAndDecideService"=3 (0x3)
"Lavasoft Ad-Aware Service"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 CLBStor;InstantBurn Storage Helper Driver;c:\windows\system32\drivers\CLBStor.sys [6/28/2010 6:53 PM 15784]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/3/2009 4:48 PM 108289]
R2 CLBUDF;CyberLink InstantBurn UDF Filesystem;c:\windows\system32\drivers\CLBUDF.sys [6/28/2010 6:53 PM 162344]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [5/26/2010 9:35 AM 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [5/26/2010 9:35 AM 493032]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/17/2010 2:57 PM 136176]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [5/28/2010 7:04 AM 14896]
S4 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [5/9/2009 10:37 AM 319488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-07-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-17 18:57]
2010-07-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-17 18:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\
FF - prefs.js: browser.startup.homepage - hxxp://us.mg2.mail.yahoo.com/dc/launch?.gx=1&.rand=2q7c5tkfrafdr
FF - component: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npigl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-19 21:31
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(952)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
- - - - - - - > 'lsass.exe'(1008)
c:\windows\system32\relog_ap.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2010-07-19 21:33:31
ComboFix-quarantined-files.txt 2010-07-20 01:33
ComboFix2.txt 2009-11-23 15:09
Pre-Run: 43,362,095,104 bytes free
Post-Run: 43,347,107,840 bytes free
- - End Of File - - 6C6B1FCCBF70D334E61C931BA41B1649
-----------------------------------------------------------------------------------------------------------------------------
paulmcd123
60 Posts
0
July 20th, 2010 05:00
Hi Kevin,
I reran Malwarebytes just now (7am). Here's the report.
I will now try to rerun Kaspersky.
------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4329
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/20/2010 7:00:53 AM
mbam-log-2010-07-20 (07-00-53).txt
Scan type: Quick scan
Objects scanned: 122350
Time elapsed: 4 minute(s), 30 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
July 20th, 2010 09:00
I`d like to see the other Malwarebytes log if possible please. Open Malwarebytes > Select the "Logs Tab" > from the list of logs look for the one we want by date/time. Select it and then open, that log will open in Notepad.
I asked you to delete the folders from the programs you uninstalled just to tidy up. Also Ask.com, dont let anything to do with Ask anywhere near your computer.
Regarding the Firewall, I`m sure that when you turn Zonealarm on, it turns the Windows Firewall OFF. To check the status of Windows F/W :-
Select Start > Control Panel > Security Center > Under "Mange Security Settings For" select the Windows F/W > from there you can turn it on and off.
Regarding the Kaspersky log, you will not get one if it found nothing, we can double check with ESET just to be certain.
Step 1
Run ESET Online Scan
You can refer to this animation by neomage if needed.
Frequently asked questions available Here
Step 2
Re-open HJT do a scan and save the log.
What i`d like in your reply :-
Kevin.
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
July 20th, 2010 10:00
If your system is responding OK we can cleanup and set you free. Proceed as follows :-
Step 1
Remove Combofix now that we're done with it
Step 2
Step 3
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
-- If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
-- If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
-- The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.
Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
To disable the JQS service if you don't want to use it:
Post a final HJT log and let me know if you have any specific issues.
Kevin
paulmcd123
60 Posts
0
July 20th, 2010 10:00
Hi Kevin,
I reran the Kaspersky program. Again, there was no report because there were no "threats found", no "infected objects found", and no "suspicious objects found". It scanned 194,036 objects in 4:24:37.
I wish this had found something.
So what do I do next?
-Paul
paulmcd123
60 Posts
0
July 20th, 2010 12:00
HI Kevin,
I haven't done what you asked yet. I thought you'd want to see the report of an Avira Antivirus scan that I started around noon. I'll wait for your reply to this before I do the actions you recommended above. - Paul
p.s. I "repaired" the 4 instances.
--------------------------------------------------------------------------------------------------------------------------------------------------------
Avira AntiVir Personal
Report file date: Tuesday, July 20, 2010 12:39
Scanning for 2369320 virus strains and unwanted programs.
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : PAUL-9C407A28F4
Version information:
BUILD.DAT : 9.0.0.422 21701 Bytes 3/9/2010 10:29:00
AVSCAN.EXE : 9.0.3.10 466689 Bytes 10/13/2009 16:26:33
AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 15:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 16:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 15:58:52
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 12:35:52
VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 20:51:49
VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 20:01:57
VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 20:02:04
VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 21:13:32
VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 03:48:55
VBASE006.VDF : 7.10.7.218 2294784 Bytes 6/2/2010 23:54:29
VBASE007.VDF : 7.10.7.219 2048 Bytes 6/2/2010 23:54:29
VBASE008.VDF : 7.10.7.220 2048 Bytes 6/2/2010 23:54:30
VBASE009.VDF : 7.10.7.221 2048 Bytes 6/2/2010 23:54:30
VBASE010.VDF : 7.10.7.222 2048 Bytes 6/2/2010 23:54:30
VBASE011.VDF : 7.10.7.223 2048 Bytes 6/2/2010 23:54:30
VBASE012.VDF : 7.10.7.224 2048 Bytes 6/2/2010 23:54:30
VBASE013.VDF : 7.10.8.37 270336 Bytes 6/10/2010 03:14:26
VBASE014.VDF : 7.10.8.69 138752 Bytes 6/14/2010 12:11:58
VBASE015.VDF : 7.10.8.102 130560 Bytes 6/16/2010 12:11:42
VBASE016.VDF : 7.10.8.135 152064 Bytes 6/21/2010 15:00:24
VBASE017.VDF : 7.10.8.163 432128 Bytes 6/23/2010 15:00:32
VBASE018.VDF : 7.10.8.194 133632 Bytes 6/27/2010 16:36:30
VBASE019.VDF : 7.10.8.220 134656 Bytes 6/29/2010 20:18:22
VBASE020.VDF : 7.10.8.252 171520 Bytes 7/4/2010 22:54:00
VBASE021.VDF : 7.10.9.19 131072 Bytes 7/6/2010 22:55:52
VBASE022.VDF : 7.10.9.36 297472 Bytes 7/7/2010 22:57:55
VBASE023.VDF : 7.10.9.60 150016 Bytes 7/11/2010 00:05:50
VBASE024.VDF : 7.10.9.79 113152 Bytes 7/13/2010 00:05:50
VBASE025.VDF : 7.10.9.99 158720 Bytes 7/16/2010 00:09:57
VBASE026.VDF : 7.10.9.112 155136 Bytes 7/19/2010 00:12:03
VBASE027.VDF : 7.10.9.113 2048 Bytes 7/19/2010 00:12:03
VBASE028.VDF : 7.10.9.114 2048 Bytes 7/19/2010 00:12:03
VBASE029.VDF : 7.10.9.115 2048 Bytes 7/19/2010 00:12:04
VBASE030.VDF : 7.10.9.116 2048 Bytes 7/19/2010 00:12:04
VBASE031.VDF : 7.10.9.126 117248 Bytes 7/20/2010 16:36:52
Engineversion : 8.2.4.22
AEVDF.DLL : 8.1.2.0 106868 Bytes 4/24/2010 04:17:10
AESCRIPT.DLL : 8.1.3.41 1364346 Bytes 7/20/2010 16:38:19
AESCN.DLL : 8.1.6.1 127347 Bytes 5/13/2010 04:17:56
AESBX.DLL : 8.1.3.1 254324 Bytes 4/24/2010 04:17:11
AERDL.DLL : 8.1.8.2 614772 Bytes 7/20/2010 16:38:08
AEPACK.DLL : 8.2.3.2 471414 Bytes 7/20/2010 16:37:57
AEOFFICE.DLL : 8.1.1.7 201081 Bytes 7/20/2010 16:37:50
AEHEUR.DLL : 8.1.2.6 2793846 Bytes 7/20/2010 16:37:47
AEHELP.DLL : 8.1.13.2 242039 Bytes 7/20/2010 16:37:02
AEGEN.DLL : 8.1.3.15 385396 Bytes 7/20/2010 16:36:59
AEEMU.DLL : 8.1.2.0 393588 Bytes 4/24/2010 04:17:07
AECORE.DLL : 8.1.16.2 192887 Bytes 7/20/2010 16:36:54
AEBB.DLL : 8.1.1.0 53618 Bytes 4/24/2010 04:17:06
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 13:47:59
AVPREF.DLL : 9.0.3.0 44289 Bytes 8/26/2009 20:14:02
AVREP.DLL : 8.0.0.7 159784 Bytes 2/22/2010 20:02:37
AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 15:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 3/24/2009 20:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 15:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 20:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 13:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 15:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 5/15/2009 20:39:58
RCTEXT.DLL : 9.0.73.0 86785 Bytes 10/13/2009 17:25:47
Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Start of the scan: Tuesday, July 20, 2010 12:39
Starting search for hidden objects.
'46409' objects were checked, '0' hidden objects were found.
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'ForceField.exe' - '0' Module(s) have been scanned
Scan process 'vsmon.exe' - '0' Module(s) have been scanned
Scan process 'zlclient.exe' - '0' Module(s) have been scanned
Scan process 'taskmgr.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'RichVideo.exe' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ISWSVC.exe' - '0' Module(s) have been scanned
Scan process 'BCMWLTRY.EXE' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
28 processes with 28 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
The registry was scanned ( '56' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP62\A0021268.VIR
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024349.sys
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024350.sys
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024351.sys
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\WINDOWS\ERDNT\cache\atapi.sys
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[WARNING] 'Is the TR/Crypt.XPACK.Gen Trojan'. This detection is probably an error. Please send us this file immediately for further analysis.
C:\WINDOWS\system32\dllcache\atapi.sys
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[WARNING] 'Is the TR/Crypt.XPACK.Gen Trojan'. This detection is probably an error. Please send us this file immediately for further analysis.
C:\WINDOWS\system32\drivers\atapi.sys
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[WARNING] 'Is the TR/Crypt.XPACK.Gen Trojan'. This detection is probably an error. Please send us this file immediately for further analysis.
Begin scan in 'D:\'
Beginning disinfection:
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP62\A0021268.VIR
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '4c75eba5.qua'!
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024349.sys
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '48500d1e.qua'!
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024350.sys
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '4db50496.qua'!
C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024351.sys
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '4db71566.qua'!
End of the scan: Tuesday, July 20, 2010 14:31
Used time: 1:36:17 Hour(s)
The scan has been done completely.
18697 Scanned directories
781502 Files were scanned
7 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
4 Files were moved to quarantine
0 Files were renamed
2 Files cannot be scanned
781493 Files not concerned
4816 Archives were scanned
5 Warnings
6 Notes
46409 Objects were scanned with rootkit scan
0 Hidden objects were found
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
July 20th, 2010 13:00
Hi Paul,
Yep they were contained in old restore points (System restore cache) When we uninstall Combofix with the command I gave in previous reply; aswell as removing itself and all associate files and folders, it also flushes the sys restore cache and creates a new clean restore point for you.
I like to use Kaspersky as my preferred online scan because it only identifies infected files folders etc, it doesn`t remove/quarantine anything. Then I can apply my fix accordingly.
When you run Avira it will remove the infected file/folder etc, as will ESET and other online scans. A poisoned restore point is sometimes preferrable to no restore points at all. We can restore to an infected state if required incase the PC will not boot etc. With no restore points you dont have that option.
Run the cleanup procedure I gave you, post a fresh HJT log and let me know of any specific issues, or if all is ok.
Cheers,
Kevin:emotion-21:
paulmcd123
60 Posts
0
July 20th, 2010 13:00
In the above scan, three files (all named atapi.sys) were singled out, and asked to send the files to Avira Antivirus immediately. I did, and all three atapi.sys files were judged to be part of the TR/Crypt.XPACK.Gen trojan. So I deleted all three files, and then emptied the Recycle Bin. I hope that was the right thing to do.
I'm going to do another Avira Antivirus scan to see if anything else pops up.
-Paul
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
July 20th, 2010 16:00
Hi Paul,
This what I asked you to do
If your system is responding OK we can cleanup and set you free. Proceed as follows :-
Step 1
Remove Combofix now that we're done with it
Step 2
Any tools left on your desktop can be safely removed by deleting them. OK :emotion-21:
Step 3
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
-- If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
-- If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
-- The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.
Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
To disable the JQS service if you don't want to use it:
Post a final HJT log and let me know if you have any specific issues.
Kevin
paulmcd123
60 Posts
0
July 20th, 2010 16:00
Hi Kevin,
1) Here is last night's Malwarebytes log (per your 4:50pm post)
2) I didn't see where you had told me to remove everything about the programs I had deleted (Spybot, SpywareBlaster, and Microsoft Security Essentials), so I did a Search on them and deleted everything pertaining to them. (per your 4:50pm post)
3) Since I've received instructions from you at 5:58pm, am I still supposed to do the instructions from your 4:50pm post (e.g. ESET scan, HJT)? Or should I just skip the 4:50pm instructions and do only the instructions in your 5:58pm post?
Let me know.
Thanks,
Paul
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4328
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7/19/2010 9:52:08 PM
mbam-log-2010-07-19 (21-52-08).txt
Scan type: Quick scan
Objects scanned: 119659
Time elapsed: 3 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
paulmcd123
60 Posts
0
July 21st, 2010 05:00
I am trying to do what you asked.
Combofix Uninstall went fine.
I downloaded OTC.exe (right-click, save link as) to my desktop. It did not have the picture shown in your post. I double clicked the plain white box titled "OTC.exe" on the Desktop. I have been watching an MSDOS box that is black, with the cursor jumping around the box. This has been going on for half-an-hour.
The title of the MSDOS box is "C:\DOCUME - 1\Paul\Desktop\OTC.exe"
I did not see the avatar shown in your post. I did not see a "Cleanup!" button.
Is this what is supposed to happen? I followed your instructions exactly.
Thanks,
Paul
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
July 21st, 2010 14:00
Hi Paul,
Yep there is an issue with the download site, delete the one you`ve got on your desktop. Run CCleaner, then re-boot. Next, download OTC again from HERE and run it as previously instructed.
Kevin