UNSOLVED

paulmcd123

updated

16 years ago

P

paulmcd123

60 Posts

0

6229

July 17th, 2010 17:00

TR/Crypt.XPACK.Gen - Avira Antivirus keeps detecting it.

Hi,

I noticed that while my Dell Vostro 1000 computer was sitting idle, my Avira Antivirus would, at random times, detect the TR/Crypt.XPACK.Gen trojan at C:\WINDOWS\system32\drivers\atapi.sys

Avira Antivirus would beep and put up a message for about 10 seconds. I finally caught the message and hit "delete" the problem, but the problem keeps coming back.

I did a full disk scan by Avira Antivirus. Found Nothing.

I did a full disk scan by AVG Antivirus. Found Nothing.

I did a full disk scan by Malwarebytes. Found Nothing.

I did a quick scan using Microsoft Security Essentials. Found Nothing.

I did a full disk scan by Lavasoft Adaware. It found the trojan, but in a different place. C:\System Volume Information\...\A0O21266.sys

But I can't find the directory C:\System Volume Information\ , even showing hidden system files.

Anyways, I told Lavasoft Adaware to delete it.

I left Lavasoft Adaware running on my computer for the afternoon, idle. No beeping messages of the Trojan found.

So I removed Lavasoft Adaware from my system, and brought back Avira Anti-virus. After a couple of hours of idling, the computer beeped. Avira Antivirus found the trojan again.

So I'm at my wit's end. I don't know what to do anymore.

That's why I am here.

If someone could help me, it would be greatly appreciated.

Thanks.

Paul

----------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:51:26 PM, on 7/17/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AnVir Task Manager\AnVir.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Foxit Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [AnVir Task Manager] "C:\Program Files\AnVir Task Manager\AnVir.exe" Minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1201636395109
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1273661980821
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 9014 bytes

  • kevinf80_1d0ac6

    2 Intern

    1131 Posts

    2984

    0

    Posted July 18th, 2010 09:00

    Hi paulmcd123

    I'm kevinf80 and I will be helping with any issues you may have. Please be aware that some of the logs I may ask for can be very complex and can take a long time to decipher. I am a volunteer here with a job and family so I ask that you be patient when waiting for replies.
    Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
    Please Print or Save to Notepad all instructions and please follow them carefully and if there's something you don't understand or that will not work please let me know and we will go through it together.
    Malware is often buggy and can be very unstable, with that in mind it is advisable to backup any important data before we begin.

    Please proceed as follows :-

    Step 1

    We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

    Combofix

    Don`t forget Combofix must be saved to your desktop. <--Very important

    Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. <--- Very important

    Please include the C:\ComboFix.txt in your next reply for further review.

    Note: Do not click combofix's window with your mouse while it's running. That action may cause it to stall.

    Examples of how to disable realtime protection available at the following link :-

    Disable realtime protection

    Step 2

    Download Security Check by screen317 from HERE or HERE.
    Save it to your Desktop.
    Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. Press any key when asked.
    A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    Let me see logs from Combofix and Security Checks in your reply please.

    Kevin
  • paulmcd123

    60 Posts

    2984

    0

    Posted July 19th, 2010 14:00

    Hi Kevin. Thanks for replying. Some notes:

    1) Closed Avira antivirus (closed umbrella).

    2) Closed Zone-Alarm firewall.

    3) The Spybot directions look too complicated, so I simply uninstalled it.

    4) Didn't see directions for Spyware Blaster,  so I uninstalled it.

    5) I ran Combofix, but it found that Microsoft Security Essentials was running (I thought I had deleted it). So I uninstalled it, and continued running Combofix.

    6) After Combofix finished, I logged in to get Security Check, and ran that (after closing FF and Zonealarm and Avira).

    Thanks, Paul

    ------------------------------------------------------------------------------------------------------------------------------------------------------------

    ComboFix 10-07-18.05 - Paul 07/19/2010  16:06:23.2.2 - x86
    Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1918.1340 [GMT -4:00]
    Running from: c:\documents and settings\Paul\Desktop\ComboFix.exe
    AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
    FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
    .

    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\drivers\1028_DELL_XPS_Vostro   1000 .MRK
    c:\windows\system32\drivers\DELL_XPS_Vostro   1000 .MRK
    c:\windows\system32\st325602.dll

    .
    (((((((((((((((((((((((((   Files Created from 2010-06-19 to 2010-07-19  )))))))))))))))))))))))))))))))
    .

    2010-07-17 22:47 . 2010-07-17 22:47    388096    ----a-r-    c:\documents and settings\Paul\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2010-07-17 11:13 . 2010-06-01 17:37    221568    ------w-    c:\windows\system32\MpSigStub.exe
    2010-07-14 12:45 . 2010-06-14 14:31    744448    -c----w-    c:\windows\system32\dllcache\helpsvc.exe
    2010-07-13 11:39 . 2010-07-13 11:39    --------    d-----w-    c:\documents and settings\Paul\Local Settings\Application Data\Sunbelt Software
    2010-07-11 03:41 . 2010-07-11 03:41    --------    d-----w-    c:\windows\system32\config\systemprofile\Application Data\Softland
    2010-07-09 17:14 . 2010-07-19 08:47    --------    d-----w-    c:\program files\Common Files\Adobe
    2010-07-09 16:40 . 2010-07-09 16:40    --------    d-----w-    c:\program files\Common Files\Adobe AIR
    2010-07-09 16:39 . 2010-07-09 16:39    71680    ----a-w-    c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
    2010-07-03 06:07 . 2010-07-03 06:07    --------    d-----w-    c:\documents and settings\Paul\Application Data\Auslogics
    2010-07-02 21:06 . 2010-07-02 21:06    --------    d-----w-    c:\program files\CodeStuff
    2010-07-02 20:52 . 2010-07-02 20:52    --------    d-----w-    c:\program files\Auslogics
    2010-06-28 23:07 . 2010-06-28 23:07    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\PostBuild.exe
    2010-06-28 23:07 . 2010-06-28 23:07    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{D36DD326-7280-11D8-97C8-000129760CBE}\PostBuild.exe
    2010-06-28 23:05 . 2010-06-28 23:05    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\PostBuild.exe
    2010-06-28 23:04 . 2010-06-28 23:04    --------    d-----w-    c:\program files\Common Files\CyberLink
    2010-06-28 23:03 . 2010-06-28 23:03    29480    ----a-w-    c:\windows\system32\msxml3a.dll
    2010-06-28 23:03 . 2010-06-28 23:03    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe
    2010-06-28 22:59 . 2010-06-28 22:59    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\PostBuild.exe
    2010-06-28 22:59 . 2010-06-28 22:59    --------    d-----w-    C:\MyWorks
    2010-06-28 22:58 . 2010-06-28 22:58    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
    2010-06-28 22:57 . 2010-06-28 22:59    --------    d-----w-    c:\documents and settings\Paul\Application Data\CyberLink
    2010-06-28 22:57 . 2010-06-28 22:57    --------    d-----w-    c:\documents and settings\Paul\Local Settings\Application Data\Cyberlink
    2010-06-28 22:55 . 2010-06-28 22:55    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{80E158EA-7181-40FE-A701-301CE6BE64AB}\PostBuild.exe
    2010-06-28 22:54 . 2010-06-28 22:54    1053232    ----a-w-    c:\windows\system32\MFC71u.dll
    2010-06-28 22:54 . 2010-06-28 22:54    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\PostBuild.exe
    2010-06-28 22:53 . 2007-10-26 14:55    15784    ------w-    c:\windows\system32\drivers\CLBStor.sys
    2010-06-28 22:53 . 2007-10-26 14:55    162344    ------w-    c:\windows\system32\drivers\CLBUDF.sys
    2010-06-28 22:53 . 2007-10-26 14:55    131072    ----a-w-    c:\windows\IBUnInst.exe
    2010-06-28 22:53 . 2010-06-28 23:08    --------    d-----w-    c:\program files\CyberLink
    2010-06-28 22:53 . 2010-06-28 22:53    --------    d-----w-    c:\documents and settings\All Users\Application Data\CyberLink
    2010-06-28 22:51 . 2010-06-28 22:51    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
    2010-06-22 14:30 . 2010-06-22 14:30    --------    d-----w-    c:\program files\iPod
    2010-06-22 14:30 . 2010-06-22 14:30    --------    d-----w-    c:\program files\iTunes
    2010-06-22 14:26 . 2010-06-22 14:26    --------    d-----w-    c:\program files\QuickTime
    2010-06-22 14:24 . 2010-06-22 14:24    --------    d-----w-    c:\program files\Apple Software Update
    2010-06-22 14:23 . 2010-06-22 14:23    --------    d-----w-    c:\program files\Bonjour

    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-19 19:44 . 2009-12-08 22:46    --------    d-----w-    c:\program files\Spybot - Search & Destroy
    2010-07-19 19:43 . 2009-08-12 17:24    --------    d-----w-    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-07-19 08:53 . 2010-04-20 04:49    79488    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll
    2010-07-19 08:53 . 2010-04-20 04:49    152576    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\jre1.6.0_20\lzma.dll
    2010-07-15 23:52 . 2010-04-13 16:03    --------    d-----w-    c:\program files\CamStudio
    2010-07-15 00:41 . 2009-11-13 22:45    --------    d-----w-    c:\documents and settings\All Users\Application Data\Lavasoft
    2010-07-14 10:20 . 2009-05-29 18:39    28913650    ----a-w-    c:\windows\Internet Logs\tvDebug.Zip
    2010-07-13 11:46 . 2009-11-13 22:49    95024    ----a-w-    c:\windows\system32\drivers\SBREDrv.sys
    2010-07-13 03:51 . 2009-11-14 07:12    --------    d---a-w-    c:\documents and settings\All Users\Application Data\TEMP
    2010-07-09 16:39 . 2009-09-24 16:33    --------    d-----w-    c:\documents and settings\All Users\Application Data\NOS
    2010-07-02 21:22 . 2010-05-25 00:27    --------    d-----w-    c:\documents and settings\Paul\Application Data\Media Player Classic
    2010-07-02 20:56 . 2009-11-02 21:48    --------    d-----w-    c:\program files\CCleaner
    2010-06-28 23:12 . 2008-01-29 18:49    25168    ----a-w-    c:\documents and settings\Paul\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-06-28 23:08 . 2008-01-29 17:52    --------    d--h--w-    c:\program files\InstallShield Installation Information
    2010-06-28 23:03 . 2008-01-29 19:01    353576    ----a-w-    c:\windows\system32\msvcr71.dll
    2010-06-28 23:03 . 2008-01-29 19:01    505128    ----a-w-    c:\windows\system32\msvcp71.dll
    2010-06-28 22:54 . 2008-01-29 19:01    1066544    ----a-w-    c:\windows\system32\MFC71.dll
    2010-06-24 16:34 . 2010-06-24 16:35    3014656    ----a-w-    c:\windows\Internet Logs\xDB2.tmp
    2010-06-22 14:30 . 2010-02-22 22:27    --------    d-----w-    c:\program files\Common Files\Apple
    2010-06-16 13:43 . 2010-06-16 13:43    61440    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-44825e10-n\decora-sse.dll
    2010-06-16 13:43 . 2010-06-16 13:43    503808    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\msvcp71.dll
    2010-06-16 13:43 . 2010-06-16 13:43    499712    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\jmc.dll
    2010-06-16 13:43 . 2010-06-16 13:43    348160    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\msvcr71.dll
    2010-06-16 13:43 . 2010-06-16 13:43    12800    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-44825e10-n\decora-d3d.dll
    2010-06-16 00:01 . 2010-06-16 00:01    72504    ----a-w-    c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
    2010-06-14 14:31 . 2008-01-29 17:10    744448    ----a-w-    c:\windows\pchealth\helpctr\binaries\helpsvc.exe
    2010-06-12 15:52 . 2010-06-12 15:52    --------    d-----w-    c:\program files\JRE
    2010-06-12 15:52 . 2010-04-20 05:05    --------    d-----w-    c:\program files\OpenOffice.org 3
    2010-06-09 08:06 . 2010-06-09 08:06    976832    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AdobeARM.exe
    2010-06-09 08:06 . 2010-06-09 08:06    70584    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AdobeExtractFiles.dll
    2010-06-09 08:06 . 2010-06-09 08:06    331176    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\ReaderUpdater.exe
    2010-06-09 08:06 . 2010-06-09 08:06    331176    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AcrobatUpdater.exe
    2010-06-03 02:41 . 2010-06-03 02:41    3600384    ----a-w-    c:\windows\system32\GPhotos.scr
    2010-05-31 20:34 . 2010-06-01 12:10    702120    ----a-w-    c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
    2010-05-31 20:34 . 2010-06-01 12:10    868456    ----a-w-    c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
    2010-05-29 12:42 . 2010-05-29 12:42    --------    d-----w-    c:\program files\Secunia
    2010-05-28 21:22 . 2010-05-28 21:22    --------    d-----w-    c:\documents and settings\Paul\Application Data\CheckPoint
    2010-05-28 21:22 . 2010-05-28 21:22    --------    d-----w-    c:\program files\ZoneAlarm
    2010-05-28 21:22 . 2010-05-28 21:22    --------    d-----w-    c:\program files\CheckPoint
    2010-05-28 21:22 . 2008-01-29 19:48    4212    ---ha-w-    c:\windows\system32\zllictbl.dat
    2010-05-28 11:04 . 2010-05-28 11:04    14896    ----a-w-    c:\windows\system32\drivers\psi_mf.sys
    2010-05-27 00:21 . 2009-05-09 14:38    --------    d-----w-    c:\program files\Ricochet Lost Worlds Recharged
    2010-05-26 17:03 . 2008-12-05 20:25    1238528    ----a-w-    c:\windows\system32\zpeng25.dll
    2010-05-26 17:03 . 2009-03-27 13:28    69120    ----a-w-    c:\windows\system32\zlcomm.dll
    2010-05-26 17:03 . 2009-03-27 13:28    103936    ----a-w-    c:\windows\system32\zlcommdb.dll
    2010-05-24 23:51 . 2010-05-24 23:51    --------    d-----w-    c:\program files\Essentials Codec Pack
    2010-05-24 05:55 . 2010-05-24 05:59    227    ----a-w-    C:\autoexectest.bat
    2010-05-24 04:59 . 2010-05-24 03:51    --------    d-----w-    c:\program files\GNU
    2010-05-18 20:35 . 2010-05-18 20:35    91424    ----a-w-    c:\windows\system32\dnssd.dll
    2010-05-18 20:35 . 2010-05-18 20:35    107808    ----a-w-    c:\windows\system32\dns-sd.exe
    2010-05-13 20:46 . 2010-04-21 02:39    1    ----a-w-    c:\documents and settings\Paul\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
    2010-05-13 19:55 . 2010-05-13 19:56    2649600    ----a-w-    c:\windows\Internet Logs\xDB1.tmp
    2010-05-06 10:41 . 2006-03-04 03:33    916480    ----a-w-    c:\windows\system32\wininet.dll
    2010-05-02 05:22 . 2004-08-04 10:00    1851264    ----a-w-    c:\windows\system32\win32k.sys
    2010-04-29 19:39 . 2009-11-08 18:05    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
    2010-04-29 19:39 . 2009-11-08 18:05    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
    .

    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

    [HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
    2010-05-09 15:50    2517088    ----a-w-    c:\program files\ZoneAlarm\tbZone.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    2010-02-04 20:50    1197448    ----a-w-    c:\program files\Ask.com\GenericAskToolbar.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
    "{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

    [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

    [HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

    [HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AnVir Task Manager"="c:\program files\AnVir Task Manager\AnVir.exe" [2009-10-13 3102944]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
    "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 851968]
    "PMX Daemon"="ICO.EXE" [2007-03-08 49152]
    "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
    "ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-05-26 1043968]
    "ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-26 730600]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

    c:\documents and settings\Paul\Start Menu\Programs\Startup\
    Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2010-5-28 911920]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmazonGSDownloaderTray]
    2009-04-06 20:35    247296    ----a-w-    c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
    2008-12-20 11:50    2656528    ----a-w-    c:\program files\Logitech\QuickCam\Quickcam.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
    2010-04-29 19:39    1090952    ----a-w-    c:\program files\Malwarebytes' Anti-Malware\mbam.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
    2009-03-05 21:07    2260480    ------w-    c:\program files\Spybot - Search & Destroy\TeaTimer.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "Amazon Download Agent"=2 (0x2)
    "AcrSch2Svc"=2 (0x2)
    "TryAndDecideService"=3 (0x3)
    "Lavasoft Ad-Aware Service"=2 (0x2)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Steam\\Steam.exe"=
    "c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    R1 CLBStor;InstantBurn Storage Helper Driver;c:\windows\system32\drivers\CLBStor.sys [6/28/2010 6:53 PM 15784]
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/3/2009 4:48 PM 108289]
    R2 CLBUDF;CyberLink InstantBurn UDF Filesystem;c:\windows\system32\drivers\CLBUDF.sys [6/28/2010 6:53 PM 162344]
    R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [5/26/2010 9:35 AM 26352]
    R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [5/26/2010 9:35 AM 493032]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/17/2010 2:57 PM 136176]
    S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [5/28/2010 7:04 AM 14896]
    S4 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [5/9/2009 10:37 AM 319488]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    getPlusHelper    REG_MULTI_SZ       getPlusHelper
    .
    Contents of the 'Scheduled Tasks' folder

    2010-07-14 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]

    2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-17 18:57]

    2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-17 18:57]

    2010-07-19 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
    - c:\program files\Ask.com\UpdateTask.exe [2010-02-04 20:50]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.bing.com/
    uInternet Settings,ProxyOverride = *.local
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\
    FF - prefs.js: browser.startup.homepage - hxxp://us.mg2.mail.yahoo.com/dc/launch?.gx=1&.rand=2q7c5tkfrafdr
    FF - component: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
    FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
    FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
    FF - plugin: c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npigl.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    .
    - - - - ORPHANS REMOVED - - - -

    MSConfigStartUp-MSSE - c:\program files\Microsoft Security Essentials\msseces.exe
    MSConfigStartUp-Skype - c:\program files\Skype\Phone\Skype.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-07-19 16:13
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ... 

    scanning hidden autostart entries ...

    scanning hidden files ... 

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(952)
    c:\windows\system32\Ati2evxx.dll
    c:\windows\System32\BCMLogon.dll
    c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

    - - - - - - - > 'lsass.exe'(1008)
    c:\windows\system32\relog_ap.dll
    c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
    .
    Completion time: 2010-07-19  16:16:36
    ComboFix-quarantined-files.txt  2010-07-19 20:16
    ComboFix2.txt  2009-11-23 15:09

    Pre-Run: 43,355,086,848 bytes free
    Post-Run: 43,445,223,424 bytes free

    - - End Of File - - E346CB3A8737EA8F11A4148EEC01B29E

    ---------------------------------------------------------------------------------------------------------------------------------------------------

     Results of screen317's Security Check version 0.99.4 
     Windows XP Service Pack 3 
     Internet Explorer 8 
    ``````````````````````````````
    Antivirus/Firewall Check:

     Windows Firewall Enabled! 
     Avira AntiVir Personal - Free Antivirus
     ZoneAlarm     
     ZoneAlarm Toolbar    
     ZoneAlarm Spy Blocker   
     Avira successfully updated!
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

     Malwarebytes' Anti-Malware   
     HijackThis 2.0.2   
     CCleaner    
     Java(TM) 6 Update 18 
     Java(TM) 6 Update 20 
     Out of date Java installed!
     Adobe Flash Player 10.1.53.64 
    Adobe Reader 9.3.3
     Mozilla Firefox (3.6.6)
    ````````````````````````````````
    Process Check: 
    objlist.exe by Laurent

     Avira Antivir avgnt.exe
     Avira Antivir avguard.exe
    ````````````````````````````````
    DNS Vulnerability Check:

     Unknown. This method cannot test your vulnerability to DNS cache poisoning.

    ``````````End of Log````````````

     

     

  • kevinf80_1d0ac6

    2 Intern

    1131 Posts

    2984

    0

    Posted July 19th, 2010 16:00

    Hi paulmcd123,

    The windows firewall appeared to be enabled, this might have happened when you stopped Zonealarm. It wasn`t a problem, just be aware when Zonealarm is back in service; make sure windows Firewall is OFF.

    Proceed as follows:

    Step 1

    1. Close any open browsers.

    2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    3. Open notepad and copy/paste the text inbetween the dooted lines below into it













             -----------------------------------------------------------------------------------------------------------------------------------------

    Folder::
    c:\program files\Spybot - Search & Destroy
    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    c:\program files\Ask.com
    c:\documents and settings\All Users\Application Data\Lavasoft
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

     


























    Save this as CFScript.txt, in the same location as ComboFix.exe

    user posted image

    user posted image

    Refering to the picture above, drag CFScript into ComboFix.exe

    When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

    Disable realtime protection

    Step 2

    Please download Malwarebytes Anti-Malware and save it to your desktop.
    Alernative D/L mirror
    Alternative D/L mirror

    MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to ALLOW the changes. Instructions available HERE
    • Make sure you are connected to the Internet.
    • Double-click on mbam-setup.exe to install the application.
    • When the installation begins, follow the prompts and do not make any changes to default settings.
    • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware

    Then click Finish.

    MBAM will automatically start and you will be asked to update the program before performing a scan.
    • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
    • If you encounter any problems while downloading the definition updates, manually download them from HERE and just double-click on mbam-rules.exe to install.

    On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
    • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
    • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
    • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
    • Click OK to close the message box and continue with the removal process.

    Back at the main Scanner screen:
    • Click on the Show Results button to see a list of any malware that was found.
    • Make sure that everything is checked, and click Remove Selected.
    • When removal is completed, a log report will open in Notepad.
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
    • Exit MBAM when done.

    Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

    Step 3

    Run an online virus scan with Kaspersky from HERE. This scan is very thorough and may take several hours to run, please allow it to complete.
    1. At the main page. Press on " Accept". After reading the contents.
    2. At the next window Select  Update. Allow the Database to update.
    Note: If prompted to run or update your Java, then follow the prompts to do so. Kaspersky requires Java to run.
    3. Once the Database has finished, under the Scan icon Select My Computer to start the scan. The scan may take a few minutes to complete.
    4. Select Scan Report.
    5. If any threats were found they will appear in the report
    6. Select "Save error report as"
    Then in the file name just type in kaspersky
    Under "save as type" select text .txt
    Save it to your Desktop.
    Copy and post the results of the Kaspersky Online scan. If no threats were found then report that as well.

    The following animation may help.

    Kaspersky Gif

    What i`d like in your reply please :-

    • Log from Combofix
    • Log from Malwarebytes
    • Log from Kaspersky


    Kevin






















































  • paulmcd123

    60 Posts

    2984

    0

    Posted July 20th, 2010 04:00

    Hi Kevin, Notes:

    1) CFScript  references Spybot Search and Destroy. I had uninstalled Spybot. Is this what you wanted?

    2) CFScript also references Lavasoft (Adaware). I had also uninstalled that. Is this what you wanted?

    3) When I downloaded Malwarebytes, a "Task Manager program on steroids" called Anvir Task Manager asked me for permission  to allow Malwarebytes to load onto my computer. I clicked "yes" and then I turned Anvir Task Manager off.

    4) I saw the report from Malwarebytes after running it last night, but now (this morning) I can't find it. I thought it was in the Program Files/Malwarebytes folder. So I did a Search of All Files and Folders for "mbam" and only found an mbam log from December of 2009.

    5) It took almost an hour to load the Kaspersky database, and the computer scan ran for so long, I left it running overnight. This morning I saw that it ran for 4:22:01, but there was NO report. Is this right?

    If you can tell me what to redo, that would be great. I'm about to run Malwarebytes right now because I know I saw an mbam results file.

    BTW, I don't know how to turn off the Windows Firewall. Should I? I guess it saved my butt last night because ZoneAlarm and Avira Antirus were off all night while the computer was on all night. Anything could have attacked my computer.

    So all I have right now is the results of Combofix running CFSript. :-(

    Thanks, Paul

    -------------------------------------------------------------------------------------------------------------

    ComboFix 10-07-18.05 - Paul 07/19/2010  21:25:37.3.2 - x86
    Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1918.1367 [GMT -4:00]
    Running from: c:\documents and settings\Paul\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Paul\Desktop\CFScript.txt
    AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
    FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
    .

    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\Lavasoft
    c:\documents and settings\All Users\Application Data\Lavasoft\License\adaware.da2
    c:\documents and settings\All Users\Application Data\Lavasoft\License\guid.dat
    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.100702-1728.log
    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.100702-1742.txt
    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.100713-0706.log
    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Checks.100713-0720.txt
    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.100702-1745.txt
    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Fixes.100713-0730.txt
    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Resident.log
    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Logs\Update downloads.log
    c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\ProcCache.sbc
    c:\program files\Ask.com
    c:\program files\Ask.com\cobrand.ico
    c:\program files\Ask.com\config.xml
    c:\program files\Ask.com\favicon.ico
    c:\program files\Ask.com\GenericAskToolbar.dll
    c:\program files\Ask.com\mupcfg.xml
    c:\program files\Ask.com\SaUpdate.exe
    c:\program files\Ask.com\UpdateTask.exe
    c:\program files\Spybot - Search & Destroy
    c:\program files\Spybot - Search & Destroy\advcheck.dll
    c:\program files\Spybot - Search & Destroy\TeaTimer.exe

    .
    (((((((((((((((((((((((((   Files Created from 2010-06-20 to 2010-07-20  )))))))))))))))))))))))))))))))
    .

    2010-07-17 22:47 . 2010-07-17 22:47    388096    ----a-r-    c:\documents and settings\Paul\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2010-07-17 11:13 . 2010-06-01 17:37    221568    ------w-    c:\windows\system32\MpSigStub.exe
    2010-07-14 12:45 . 2010-06-14 14:31    744448    -c----w-    c:\windows\system32\dllcache\helpsvc.exe
    2010-07-13 11:39 . 2010-07-13 11:39    --------    d-----w-    c:\documents and settings\Paul\Local Settings\Application Data\Sunbelt Software
    2010-07-11 03:41 . 2010-07-11 03:41    --------    d-----w-    c:\windows\system32\config\systemprofile\Application Data\Softland
    2010-07-09 17:14 . 2010-07-19 08:47    --------    d-----w-    c:\program files\Common Files\Adobe
    2010-07-09 16:40 . 2010-07-09 16:40    --------    d-----w-    c:\program files\Common Files\Adobe AIR
    2010-07-09 16:39 . 2010-07-09 16:39    71680    ----a-w-    c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
    2010-07-03 06:07 . 2010-07-03 06:07    --------    d-----w-    c:\documents and settings\Paul\Application Data\Auslogics
    2010-07-02 21:06 . 2010-07-02 21:06    --------    d-----w-    c:\program files\CodeStuff
    2010-07-02 20:52 . 2010-07-02 20:52    --------    d-----w-    c:\program files\Auslogics
    2010-06-28 23:07 . 2010-06-28 23:07    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\PostBuild.exe
    2010-06-28 23:07 . 2010-06-28 23:07    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{D36DD326-7280-11D8-97C8-000129760CBE}\PostBuild.exe
    2010-06-28 23:05 . 2010-06-28 23:05    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\PostBuild.exe
    2010-06-28 23:04 . 2010-06-28 23:04    --------    d-----w-    c:\program files\Common Files\CyberLink
    2010-06-28 23:03 . 2010-06-28 23:03    29480    ----a-w-    c:\windows\system32\msxml3a.dll
    2010-06-28 23:03 . 2010-06-28 23:03    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe
    2010-06-28 22:59 . 2010-06-28 22:59    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\PostBuild.exe
    2010-06-28 22:59 . 2010-06-28 22:59    --------    d-----w-    C:\MyWorks
    2010-06-28 22:58 . 2010-06-28 22:58    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
    2010-06-28 22:57 . 2010-06-28 22:59    --------    d-----w-    c:\documents and settings\Paul\Application Data\CyberLink
    2010-06-28 22:57 . 2010-06-28 22:57    --------    d-----w-    c:\documents and settings\Paul\Local Settings\Application Data\Cyberlink
    2010-06-28 22:55 . 2010-06-28 22:55    36864    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{80E158EA-7181-40FE-A701-301CE6BE64AB}\PostBuild.exe
    2010-06-28 22:54 . 2010-06-28 22:54    1053232    ----a-w-    c:\windows\system32\MFC71u.dll
    2010-06-28 22:54 . 2010-06-28 22:54    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\PostBuild.exe
    2010-06-28 22:53 . 2007-10-26 14:55    15784    ------w-    c:\windows\system32\drivers\CLBStor.sys
    2010-06-28 22:53 . 2007-10-26 14:55    162344    ------w-    c:\windows\system32\drivers\CLBUDF.sys
    2010-06-28 22:53 . 2007-10-26 14:55    131072    ----a-w-    c:\windows\IBUnInst.exe
    2010-06-28 22:53 . 2010-06-28 23:08    --------    d-----w-    c:\program files\CyberLink
    2010-06-28 22:53 . 2010-06-28 22:53    --------    d-----w-    c:\documents and settings\All Users\Application Data\CyberLink
    2010-06-28 22:51 . 2010-06-28 22:51    53319    ----a-w-    c:\documents and settings\All Users\Application Data\TEMP\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
    2010-06-22 14:30 . 2010-06-22 14:30    --------    d-----w-    c:\program files\iPod
    2010-06-22 14:30 . 2010-06-22 14:30    --------    d-----w-    c:\program files\iTunes
    2010-06-22 14:26 . 2010-06-22 14:26    --------    d-----w-    c:\program files\QuickTime
    2010-06-22 14:24 . 2010-06-22 14:24    --------    d-----w-    c:\program files\Apple Software Update
    2010-06-22 14:23 . 2010-06-22 14:23    --------    d-----w-    c:\program files\Bonjour

    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-19 08:53 . 2010-04-20 04:49    79488    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll
    2010-07-19 08:53 . 2010-04-20 04:49    152576    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\jre1.6.0_20\lzma.dll
    2010-07-15 23:52 . 2010-04-13 16:03    --------    d-----w-    c:\program files\CamStudio
    2010-07-14 10:20 . 2009-05-29 18:39    28913650    ----a-w-    c:\windows\Internet Logs\tvDebug.Zip
    2010-07-13 11:46 . 2009-11-13 22:49    95024    ----a-w-    c:\windows\system32\drivers\SBREDrv.sys
    2010-07-13 03:51 . 2009-11-14 07:12    --------    d---a-w-    c:\documents and settings\All Users\Application Data\TEMP
    2010-07-09 16:39 . 2009-09-24 16:33    --------    d-----w-    c:\documents and settings\All Users\Application Data\NOS
    2010-07-02 21:22 . 2010-05-25 00:27    --------    d-----w-    c:\documents and settings\Paul\Application Data\Media Player Classic
    2010-07-02 20:56 . 2009-11-02 21:48    --------    d-----w-    c:\program files\CCleaner
    2010-06-28 23:12 . 2008-01-29 18:49    25168    ----a-w-    c:\documents and settings\Paul\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-06-28 23:08 . 2008-01-29 17:52    --------    d--h--w-    c:\program files\InstallShield Installation Information
    2010-06-28 23:03 . 2008-01-29 19:01    353576    ----a-w-    c:\windows\system32\msvcr71.dll
    2010-06-28 23:03 . 2008-01-29 19:01    505128    ----a-w-    c:\windows\system32\msvcp71.dll
    2010-06-28 22:54 . 2008-01-29 19:01    1066544    ----a-w-    c:\windows\system32\MFC71.dll
    2010-06-24 16:34 . 2010-06-24 16:35    3014656    ----a-w-    c:\windows\Internet Logs\xDB2.tmp
    2010-06-22 14:30 . 2010-02-22 22:27    --------    d-----w-    c:\program files\Common Files\Apple
    2010-06-16 13:43 . 2010-06-16 13:43    61440    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-44825e10-n\decora-sse.dll
    2010-06-16 13:43 . 2010-06-16 13:43    503808    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\msvcp71.dll
    2010-06-16 13:43 . 2010-06-16 13:43    499712    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\jmc.dll
    2010-06-16 13:43 . 2010-06-16 13:43    348160    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6fbf1cb7-n\msvcr71.dll
    2010-06-16 13:43 . 2010-06-16 13:43    12800    ----a-w-    c:\documents and settings\Paul\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-44825e10-n\decora-d3d.dll
    2010-06-16 00:01 . 2010-06-16 00:01    72504    ----a-w-    c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
    2010-06-14 14:31 . 2008-01-29 17:10    744448    ----a-w-    c:\windows\pchealth\helpctr\binaries\helpsvc.exe
    2010-06-12 15:52 . 2010-06-12 15:52    --------    d-----w-    c:\program files\JRE
    2010-06-12 15:52 . 2010-04-20 05:05    --------    d-----w-    c:\program files\OpenOffice.org 3
    2010-06-09 08:06 . 2010-06-09 08:06    976832    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AdobeARM.exe
    2010-06-09 08:06 . 2010-06-09 08:06    70584    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AdobeExtractFiles.dll
    2010-06-09 08:06 . 2010-06-09 08:06    331176    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\ReaderUpdater.exe
    2010-06-09 08:06 . 2010-06-09 08:06    331176    ----a-w-    c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\30295\AcrobatUpdater.exe
    2010-06-03 02:41 . 2010-06-03 02:41    3600384    ----a-w-    c:\windows\system32\GPhotos.scr
    2010-05-31 20:34 . 2010-06-01 12:10    702120    ----a-w-    c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
    2010-05-31 20:34 . 2010-06-01 12:10    868456    ----a-w-    c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
    2010-05-29 12:42 . 2010-05-29 12:42    --------    d-----w-    c:\program files\Secunia
    2010-05-28 21:22 . 2010-05-28 21:22    --------    d-----w-    c:\documents and settings\Paul\Application Data\CheckPoint
    2010-05-28 21:22 . 2010-05-28 21:22    --------    d-----w-    c:\program files\ZoneAlarm
    2010-05-28 21:22 . 2010-05-28 21:22    --------    d-----w-    c:\program files\CheckPoint
    2010-05-28 21:22 . 2008-01-29 19:48    4212    ---ha-w-    c:\windows\system32\zllictbl.dat
    2010-05-28 11:04 . 2010-05-28 11:04    14896    ----a-w-    c:\windows\system32\drivers\psi_mf.sys
    2010-05-27 00:21 . 2009-05-09 14:38    --------    d-----w-    c:\program files\Ricochet Lost Worlds Recharged
    2010-05-26 17:03 . 2008-12-05 20:25    1238528    ----a-w-    c:\windows\system32\zpeng25.dll
    2010-05-26 17:03 . 2009-03-27 13:28    69120    ----a-w-    c:\windows\system32\zlcomm.dll
    2010-05-26 17:03 . 2009-03-27 13:28    103936    ----a-w-    c:\windows\system32\zlcommdb.dll
    2010-05-24 23:51 . 2010-05-24 23:51    --------    d-----w-    c:\program files\Essentials Codec Pack
    2010-05-24 05:55 . 2010-05-24 05:59    227    ----a-w-    C:\autoexectest.bat
    2010-05-24 04:59 . 2010-05-24 03:51    --------    d-----w-    c:\program files\GNU
    2010-05-18 20:35 . 2010-05-18 20:35    91424    ----a-w-    c:\windows\system32\dnssd.dll
    2010-05-18 20:35 . 2010-05-18 20:35    107808    ----a-w-    c:\windows\system32\dns-sd.exe
    2010-05-13 20:46 . 2010-04-21 02:39    1    ----a-w-    c:\documents and settings\Paul\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
    2010-05-13 19:55 . 2010-05-13 19:56    2649600    ----a-w-    c:\windows\Internet Logs\xDB1.tmp
    2010-05-06 10:41 . 2006-03-04 03:33    916480    ----a-w-    c:\windows\system32\wininet.dll
    2010-05-02 05:22 . 2004-08-04 10:00    1851264    ----a-w-    c:\windows\system32\win32k.sys
    2010-04-29 19:39 . 2009-11-08 18:05    38224    ----a-w-    c:\windows\system32\drivers\mbamswissarmy.sys
    2010-04-29 19:39 . 2009-11-08 18:05    20952    ----a-w-    c:\windows\system32\drivers\mbam.sys
    .

    (((((((((((((((((((((((((((((   SnapShot@2010-07-19_20.14.02   )))))))))))))))))))))))))))))))))))))))))
    .
    - 2004-08-04 10:00 . 2010-07-19 19:49    67714              c:\windows\system32\perfc009.dat
    + 2004-08-04 10:00 . 2010-07-19 20:42    67714              c:\windows\system32\perfc009.dat
    + 2004-08-04 10:00 . 2010-07-19 20:42    432924              c:\windows\system32\perfh009.dat
    - 2004-08-04 10:00 . 2010-07-19 19:49    432924              c:\windows\system32\perfh009.dat
    .
    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

    [HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
    2010-05-09 15:50    2517088    ----a-w-    c:\program files\ZoneAlarm\tbZone.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

    [HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

    [HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AnVir Task Manager"="c:\program files\AnVir Task Manager\AnVir.exe" [2009-10-13 3102944]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
    "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-27 851968]
    "PMX Daemon"="ICO.EXE" [2007-03-08 49152]
    "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
    "ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-05-26 1043968]
    "ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-26 730600]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

    c:\documents and settings\Paul\Start Menu\Programs\Startup\
    Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2010-5-28 911920]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmazonGSDownloaderTray]
    2009-04-06 20:35    247296    ----a-w-    c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
    2008-12-20 11:50    2656528    ----a-w-    c:\program files\Logitech\QuickCam\Quickcam.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
    2010-04-29 19:39    1090952    ----a-w-    c:\program files\Malwarebytes' Anti-Malware\mbam.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "Amazon Download Agent"=2 (0x2)
    "AcrSch2Svc"=2 (0x2)
    "TryAndDecideService"=3 (0x3)
    "Lavasoft Ad-Aware Service"=2 (0x2)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Steam\\Steam.exe"=
    "c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    R1 CLBStor;InstantBurn Storage Helper Driver;c:\windows\system32\drivers\CLBStor.sys [6/28/2010 6:53 PM 15784]
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/3/2009 4:48 PM 108289]
    R2 CLBUDF;CyberLink InstantBurn UDF Filesystem;c:\windows\system32\drivers\CLBUDF.sys [6/28/2010 6:53 PM 162344]
    R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [5/26/2010 9:35 AM 26352]
    R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [5/26/2010 9:35 AM 493032]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/17/2010 2:57 PM 136176]
    S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [5/28/2010 7:04 AM 14896]
    S4 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [5/9/2009 10:37 AM 319488]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    getPlusHelper    REG_MULTI_SZ       getPlusHelper
    .
    Contents of the 'Scheduled Tasks' folder

    2010-07-14 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]

    2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-17 18:57]

    2010-07-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-17 18:57]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.bing.com/
    uInternet Settings,ProxyOverride = *.local
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\
    FF - prefs.js: browser.startup.homepage - hxxp://us.mg2.mail.yahoo.com/dc/launch?.gx=1&.rand=2q7c5tkfrafdr
    FF - component: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
    FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
    FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\gyydsbit.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
    FF - plugin: c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npigl.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type",                  5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-07-19 21:31
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ... 

    scanning hidden autostart entries ...

    scanning hidden files ... 

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(952)
    c:\windows\system32\Ati2evxx.dll
    c:\windows\System32\BCMLogon.dll
    c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

    - - - - - - - > 'lsass.exe'(1008)
    c:\windows\system32\relog_ap.dll
    c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
    .
    Completion time: 2010-07-19  21:33:31
    ComboFix-quarantined-files.txt  2010-07-20 01:33
    ComboFix2.txt  2009-11-23 15:09

    Pre-Run: 43,362,095,104 bytes free
    Post-Run: 43,347,107,840 bytes free

    - - End Of File - - 6C6B1FCCBF70D334E61C931BA41B1649
    -----------------------------------------------------------------------------------------------------------------------------

     

     

  • paulmcd123

    60 Posts

    2984

    0

    Posted July 20th, 2010 05:00

    Hi Kevin,

     I reran Malwarebytes just now (7am). Here's the report.

    I will now try to rerun Kaspersky.

    ------------------------------------------------------------------------------------------------------------------------------------------------------------------------

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4329

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    7/20/2010 7:00:53 AM
    mbam-log-2010-07-20 (07-00-53).txt

    Scan type: Quick scan
    Objects scanned: 122350
    Time elapsed: 4 minute(s), 30 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

  • kevinf80_1d0ac6

    2 Intern

    1131 Posts

    2984

    0

    Posted July 20th, 2010 09:00

    Hi Paul,

    I`d like to see the other Malwarebytes log if possible please. Open Malwarebytes > Select the "Logs Tab" > from the list of logs look for the one we want by date/time. Select it and then open, that log will open in Notepad.

    I asked you to delete the folders from the programs you uninstalled just to tidy up. Also Ask.com, dont let anything to do with Ask anywhere near your computer.

    Regarding the Firewall, I`m sure that when you turn Zonealarm on, it turns the Windows Firewall OFF. To check the status of Windows F/W :-

    Select Start > Control Panel > Security Center > Under "Mange Security Settings For" select the Windows F/W > from there you can turn it on and off.

    Regarding the Kaspersky log, you will not get one if it found nothing, we can double check with ESET just to be certain.

    Step 1

    Run ESET Online Scan
    • Hold down Control and click on the following link to open ESET OnlineScan in a new window.ESET OnlineScan
    • Click the user posted image button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

    • Click on user posted image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the user posted image icon on your desktop.

    • Check user posted image
    • Click the user posted image button.
    • Accept any security warnings from your browser.
    • Check user posted image
    • Push the Start button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push user posted image
    • Push user posted image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the user posted image button.
    • Push user posted image

    You can refer to this animation by neomage if needed.
    Frequently asked questions available Here

    Step 2

    Re-open HJT do a scan and save the log.

    What i`d like in your reply :-

    • Requested log from Malwarebytes
    • Log from ESET
    • Log from HJT
    • Update on your system, any specific issue?


    Kevin.
  • kevinf80_1d0ac6

    2 Intern

    1131 Posts

    2984

    0

    Posted July 20th, 2010 10:00

    Hi Paul,

    If your system is responding OK we can cleanup and set you free. Proceed as follows :-

    Step 1

    Remove Combofix now that we're done with it
    • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
    • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")user posted image

    • Please follow the prompts to uninstall Combofix.
    • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
    • It will also reset your system restore cache and create a fresh clean restore point.


    Step 2

    • Download OTC by OldTimer and save it to your Desktop.
    • Double click user posted image icon to start the program. If you are using Vista, please right-click and choose run as administrator
    • Then Click the big user posted image button.
    • You will get a prompt saying "Begining Cleanup Process". Please select Yes.
    • Restart your computer when prompted.It will also remove the OTC application.


    Step 3

    Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
    • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
    • Scroll down to "JDK 6 Update 21 (JDK or JRE).
    • Click the Download JRE button to the right.
    • Select your Platform: "Windows".
    • Select your Language: "Multi-language".
    • Read the License Agreement, and then check the box that says: "Accept License Agreement".
    • Click Continue and the page will refresh.
    • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
    • Close any programs you may have running - especially your web browser.

    Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
    • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.

    -- If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
    -- If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
    -- The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.



    Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
    To disable the JQS service if you don't want to use it:
    • Go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
    • Click Ok and reboot your computer.


    Post a final HJT log and let me know if you have any specific issues.

    Kevin


























  • paulmcd123

    60 Posts

    2984

    0

    Posted July 20th, 2010 10:00

    Hi Kevin,

    I reran the Kaspersky program. Again, there was no report because there were no "threats found", no "infected objects found", and no "suspicious objects found". It scanned 194,036 objects in 4:24:37.

    I wish this had found something.

    So what do I do next?

    -Paul

     

  • paulmcd123

    60 Posts

    2984

    0

    Posted July 20th, 2010 12:00

    HI Kevin,

    I haven't done what you asked yet. I thought you'd want to see the report of an Avira Antivirus scan that I started around noon. I'll wait for your reply to this before I do the actions you recommended above. - Paul

    p.s. I "repaired" the 4 instances.

    --------------------------------------------------------------------------------------------------------------------------------------------------------



    Avira AntiVir Personal
    Report file date: Tuesday, July 20, 2010  12:39

    Scanning for 2369320 virus strains and unwanted programs.

    Licensee        : Avira AntiVir Personal - FREE Antivirus
    Serial number   : 0000149996-ADJIE-0000001
    Platform        : Windows XP
    Windows version : (Service Pack 3)  [5.1.2600]
    Boot mode       : Normally booted
    Username        : SYSTEM
    Computer name   : PAUL-9C407A28F4

    Version information:
    BUILD.DAT       : 9.0.0.422     21701 Bytes    3/9/2010 10:29:00
    AVSCAN.EXE      : 9.0.3.10     466689 Bytes  10/13/2009 16:26:33
    AVSCAN.DLL      : 9.0.3.0       40705 Bytes   2/27/2009 15:58:24
    LUKE.DLL        : 9.0.3.2      209665 Bytes   2/20/2009 16:35:49
    LUKERES.DLL     : 9.0.2.0       12033 Bytes   2/27/2009 15:58:52
    VBASE000.VDF    : 7.10.0.0   19875328 Bytes   11/6/2009 12:35:52
    VBASE001.VDF    : 7.10.1.0    1372672 Bytes  11/19/2009 20:51:49
    VBASE002.VDF    : 7.10.3.1    3143680 Bytes   1/20/2010 20:01:57
    VBASE003.VDF    : 7.10.3.75    996864 Bytes   1/26/2010 20:02:04
    VBASE004.VDF    : 7.10.4.203   1579008 Bytes    3/5/2010 21:13:32
    VBASE005.VDF    : 7.10.6.82   2494464 Bytes   4/15/2010 03:48:55
    VBASE006.VDF    : 7.10.7.218   2294784 Bytes    6/2/2010 23:54:29
    VBASE007.VDF    : 7.10.7.219      2048 Bytes    6/2/2010 23:54:29
    VBASE008.VDF    : 7.10.7.220      2048 Bytes    6/2/2010 23:54:30
    VBASE009.VDF    : 7.10.7.221      2048 Bytes    6/2/2010 23:54:30
    VBASE010.VDF    : 7.10.7.222      2048 Bytes    6/2/2010 23:54:30
    VBASE011.VDF    : 7.10.7.223      2048 Bytes    6/2/2010 23:54:30
    VBASE012.VDF    : 7.10.7.224      2048 Bytes    6/2/2010 23:54:30
    VBASE013.VDF    : 7.10.8.37    270336 Bytes   6/10/2010 03:14:26
    VBASE014.VDF    : 7.10.8.69    138752 Bytes   6/14/2010 12:11:58
    VBASE015.VDF    : 7.10.8.102    130560 Bytes   6/16/2010 12:11:42
    VBASE016.VDF    : 7.10.8.135    152064 Bytes   6/21/2010 15:00:24
    VBASE017.VDF    : 7.10.8.163    432128 Bytes   6/23/2010 15:00:32
    VBASE018.VDF    : 7.10.8.194    133632 Bytes   6/27/2010 16:36:30
    VBASE019.VDF    : 7.10.8.220    134656 Bytes   6/29/2010 20:18:22
    VBASE020.VDF    : 7.10.8.252    171520 Bytes    7/4/2010 22:54:00
    VBASE021.VDF    : 7.10.9.19    131072 Bytes    7/6/2010 22:55:52
    VBASE022.VDF    : 7.10.9.36    297472 Bytes    7/7/2010 22:57:55
    VBASE023.VDF    : 7.10.9.60    150016 Bytes   7/11/2010 00:05:50
    VBASE024.VDF    : 7.10.9.79    113152 Bytes   7/13/2010 00:05:50
    VBASE025.VDF    : 7.10.9.99    158720 Bytes   7/16/2010 00:09:57
    VBASE026.VDF    : 7.10.9.112    155136 Bytes   7/19/2010 00:12:03
    VBASE027.VDF    : 7.10.9.113      2048 Bytes   7/19/2010 00:12:03
    VBASE028.VDF    : 7.10.9.114      2048 Bytes   7/19/2010 00:12:03
    VBASE029.VDF    : 7.10.9.115      2048 Bytes   7/19/2010 00:12:04
    VBASE030.VDF    : 7.10.9.116      2048 Bytes   7/19/2010 00:12:04
    VBASE031.VDF    : 7.10.9.126    117248 Bytes   7/20/2010 16:36:52
    Engineversion   : 8.2.4.22
    AEVDF.DLL       : 8.1.2.0      106868 Bytes   4/24/2010 04:17:10
    AESCRIPT.DLL    : 8.1.3.41    1364346 Bytes   7/20/2010 16:38:19
    AESCN.DLL       : 8.1.6.1      127347 Bytes   5/13/2010 04:17:56
    AESBX.DLL       : 8.1.3.1      254324 Bytes   4/24/2010 04:17:11
    AERDL.DLL       : 8.1.8.2      614772 Bytes   7/20/2010 16:38:08
    AEPACK.DLL      : 8.2.3.2      471414 Bytes   7/20/2010 16:37:57
    AEOFFICE.DLL    : 8.1.1.7      201081 Bytes   7/20/2010 16:37:50
    AEHEUR.DLL      : 8.1.2.6     2793846 Bytes   7/20/2010 16:37:47
    AEHELP.DLL      : 8.1.13.2     242039 Bytes   7/20/2010 16:37:02
    AEGEN.DLL       : 8.1.3.15     385396 Bytes   7/20/2010 16:36:59
    AEEMU.DLL       : 8.1.2.0      393588 Bytes   4/24/2010 04:17:07
    AECORE.DLL      : 8.1.16.2     192887 Bytes   7/20/2010 16:36:54
    AEBB.DLL        : 8.1.1.0       53618 Bytes   4/24/2010 04:17:06
    AVWINLL.DLL     : 9.0.0.3       18177 Bytes  12/12/2008 13:47:59
    AVPREF.DLL      : 9.0.3.0       44289 Bytes   8/26/2009 20:14:02
    AVREP.DLL       : 8.0.0.7      159784 Bytes   2/22/2010 20:02:37
    AVREG.DLL       : 9.0.0.0       36609 Bytes   12/5/2008 15:32:09
    AVARKT.DLL      : 9.0.0.3      292609 Bytes   3/24/2009 20:05:41
    AVEVTLOG.DLL    : 9.0.0.7      167169 Bytes   1/30/2009 15:37:08
    SQLITE3.DLL     : 3.6.1.0      326401 Bytes   1/28/2009 20:03:49
    SMTPLIB.DLL     : 9.2.0.25      28417 Bytes    2/2/2009 13:21:33
    NETNT.DLL       : 9.0.0.0       11521 Bytes   12/5/2008 15:32:10
    RCIMAGE.DLL     : 9.0.0.25    2438913 Bytes   5/15/2009 20:39:58
    RCTEXT.DLL      : 9.0.73.0      86785 Bytes  10/13/2009 17:25:47

    Configuration settings for the scan:
    Jobname.............................: Complete system scan
    Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
    Logging.............................: low
    Primary action......................: interactive
    Secondary action....................: ignore
    Scan master boot sector.............: on
    Scan boot sector....................: on
    Boot sectors........................: C:, D:,
    Process scan........................: on
    Scan registry.......................: on
    Search for rootkits.................: on
    Integrity checking of system files..: off
    Scan all files......................: All files
    Scan archives.......................: on
    Recursion depth.....................: 20
    Smart extensions....................: on
    Macro heuristic.....................: on
    File heuristic......................: medium

    Start of the scan: Tuesday, July 20, 2010  12:39

    Starting search for hidden objects.
    '46409' objects were checked, '0' hidden objects were found.

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'ForceField.exe' - '0' Module(s) have been scanned
    Scan process 'vsmon.exe' - '0' Module(s) have been scanned
    Scan process 'zlclient.exe' - '0' Module(s) have been scanned
    Scan process 'taskmgr.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
    Scan process 'iPodService.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'RichVideo.exe' - '1' Module(s) have been scanned
    Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
    Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'ISWSVC.exe' - '0' Module(s) have been scanned
    Scan process 'BCMWLTRY.EXE' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    28 processes with 28 modules were scanned

    Starting master boot sector scan:
    Master boot sector HD0
        [INFO]      No virus was found!

    Start scanning boot sectors:
    Boot sector 'C:\'
        [INFO]      No virus was found!
    Boot sector 'D:\'
        [INFO]      No virus was found!

    Starting to scan executable files (registry).
    The registry was scanned ( '56' files ).


    Starting the file scan:

    Begin scan in 'C:\'
    C:\hiberfil.sys
        [WARNING]   The file could not be opened!
        [NOTE]      This file is a Windows system file.
        [NOTE]      This file cannot be opened for scanning.
    C:\pagefile.sys
        [WARNING]   The file could not be opened!
        [NOTE]      This file is a Windows system file.
        [NOTE]      This file cannot be opened for scanning.
    C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP62\A0021268.VIR
        [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024349.sys
        [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024350.sys
        [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024351.sys
        [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
    C:\WINDOWS\ERDNT\cache\atapi.sys
        [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
        [WARNING]   'Is the TR/Crypt.XPACK.Gen Trojan'. This detection is probably an error. Please send us this file immediately for further analysis.
    C:\WINDOWS\system32\dllcache\atapi.sys
        [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
        [WARNING]   'Is the TR/Crypt.XPACK.Gen Trojan'. This detection is probably an error. Please send us this file immediately for further analysis.
    C:\WINDOWS\system32\drivers\atapi.sys
        [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
        [WARNING]   'Is the TR/Crypt.XPACK.Gen Trojan'. This detection is probably an error. Please send us this file immediately for further analysis.
    Begin scan in 'D:\'

    Beginning disinfection:
    C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP62\A0021268.VIR
        [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
        [NOTE]      The file was moved to '4c75eba5.qua'!
    C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024349.sys
        [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
        [NOTE]      The file was moved to '48500d1e.qua'!
    C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024350.sys
        [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
        [NOTE]      The file was moved to '4db50496.qua'!
    C:\System Volume Information\_restore{6E0A420F-9BF3-4C2F-BCFD-2BE03F5786A0}\RP70\A0024351.sys
        [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
        [NOTE]      The file was moved to '4db71566.qua'!


    End of the scan: Tuesday, July 20, 2010  14:31
    Used time:  1:36:17 Hour(s)

    The scan has been done completely.

      18697 Scanned directories
     781502 Files were scanned
          7 Viruses and/or unwanted programs were found
          0 Files were classified as suspicious
          0 files were deleted
          0 Viruses and unwanted programs were repaired
          4 Files were moved to quarantine
          0 Files were renamed
          2 Files cannot be scanned
     781493 Files not concerned
       4816 Archives were scanned
          5 Warnings
          6 Notes
      46409 Objects were scanned with rootkit scan
          0 Hidden objects were found

     

  • kevinf80_1d0ac6

    2 Intern

    1131 Posts

    673

    0

    Posted July 20th, 2010 13:00

    Hi Paul,

    Yep they were contained in old restore points (System restore cache) When we uninstall Combofix with the command I gave in previous reply; aswell as removing itself and all associate files and folders, it also flushes the sys restore cache and creates a new clean restore point for you.

    I like to use Kaspersky as my preferred online scan because it only identifies infected files folders etc, it doesn`t remove/quarantine anything. Then I can apply my fix accordingly.

    When you run Avira it will remove the infected file/folder etc, as will ESET and other online scans. A poisoned restore point is sometimes preferrable to no restore points at all. We can restore to an infected state if required incase the PC will not boot etc. With no restore points you dont have that option.

    Run the cleanup procedure I gave you, post a fresh HJT log and let me know of any specific issues, or if all is ok.

    Cheers,

    Kevin:emotion-21: