Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

My Computer Is Hijacked.


  • This topic is locked This topic is locked
11 replies to this topic

#1 MrNeedHelp

MrNeedHelp

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:10 PM

Posted 01 August 2007 - 10:02 AM

Nothing seems to work to get rid of the infection.

I'm not sure whether it's a trojan, spyware, adware or the like

that is nesting in the computer. It identifies itself as a red circel with a white cross

that keeps poping upor a yellow triangle with an exclamation mark

in it that says " Windows Security Alert " OR " Warning Potential Spyware

Operation "and this annoying popup wants me to download spyware remover

or the like. I've read on Yahoo Answers that others seems to have a similar

problem and I've tried some of those solutions in vain. Some of these so called

spyware removers that are supposed to remove all malicious software that has

found it's way into the computer has proven worthless. I tried this software

called "SUPERAntiSpyware" that has been recommended. I used the free version and scanned using

the quick scan as well as the complete scan, but the virus prevails and remains

and it seems to resist the virus remover software and lingers on. I've tried others to but

they also work like cheap perfume.

So what can I really do about this ? Is there any professional computer guru who can exactly

tell me what this virus is and how to remove it 100% and how to prevent further and future

attacks ? Is there any really good and functioning virus removers I can use. Not to be cheap

but I don't want to pay for any removal software as they may be useless. I 'll pay when I see

effect. By the way, who are these bastards who think it's fun to create viruse to destroy

ones hard drives ? Do they have some kind of complex ?

They should be severely punished. Lock em up and throw away the key.

Please anyone, tell me how to find this magic bullet without any wild goose chases.

BC AdBot (Login to Remove)

 


m

#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:08:10 PM

Posted 01 August 2007 - 10:09 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum MrNeedHelp :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

Download Trend Micro HijackThis 2.0.2 to your desktop:
Double click on HJTInstall.exe,it will prompt you to extract hijackthis.exe to C:\Program Files\Trend Micro\HijackThis.
When the install is complete,HijackThis will automatically launch.
When the license agreement appears,select "I Accept" and then click on the "Do a system scan only" button.
When the scan is complete,click on the "Save Log" button,then save it to your desktop.
Copy and paste the entire contents of that log into your next reply.
Posted Image
Posted Image

#3 MrNeedHelp

MrNeedHelp
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:10 PM

Posted 01 August 2007 - 10:29 AM

Thank You. Here It Is.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0:27:11, on 2007/08/02
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\printer.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\EMS Free Surfer Companion\fs30.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSecurity.exe
C:\Program Files\K7 Computing\Common\K7SysTry.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb01.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSMngr.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\K7 Computing\Common\K7EmlPxy.exe
C:\Program Files\K7 Computing\K7TSecurity\K7SysMon\K7SysMon.Exe
C:\Program Files\K7 Computing\K7TSecurity\K7FireWall\K7FWSrvc.exe
C:\Program Files\K7 Computing\K7TSecurity\K7Privacy\K7PSSrvc.exe
C:\Program Files\K7 Computing\K7TSecurity\K7AntiVirus\K7RTScan.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: MyUrlSrcHook Class - {D2A5245A-B682-4C26-A507-173A774B2E70} - C:\WINDOWS\Downlo~1\CNSMIN~1.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [freesurfer] C:\Program Files\EMS Free Surfer Companion\fs30.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [K7TSStart] "C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSecurity.exe"
O4 - HKLM\..\Run: [K7SystemTray] "C:\Program Files\K7 Computing\Common\K7SysTry.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb01.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] ctfmon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] ctfmon.exe (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Download with Go!Zilla - file://C:\Program Files\Go!Zilla\download-with-gozilla.html
O8 - Extra context menu item: Get siteinfo data (fsc) - C:\Program Files\EMS Free Surfer Companion\fslauncher.htm
O8 - Extra context menu item: JWordでウェブ検索(&J) - res://C:\WINDOWS\Downlo~1\CnsMin.dll/203
O8 - Extra context menu item: Super Mapple Digital - カスタム情報記入 - res://C:\PROGRA~1\SUPERM~1.5\MappleBand.dll/110
O8 - Extra context menu item: Super Mapple Digital - 住所検索 - res://C:\PROGRA~1\SUPERM~1.5\MappleBand.dll/109
O8 - Extra context menu item: Super Mapple Digital - 施設検索 - res://C:\PROGRA~1\SUPERM~1.5\MappleBand.dll/112
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun の Java コンソール - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: マップル - {381F73A9-29D0-45B6-88D7-F82C4BCED5D3} - C:\Program Files\Super Mapple Digital Ver.5\MappleBand.dll
O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sotec.co.jp/top.html
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/16b65c9aaf441e...tzip/RdxIE2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1180736538788
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{02777462-5D98-40EC-B654-A9041CD93B97}: NameServer = 202.216.229.30 202.216.224.30
O17 - HKLM\System\CS1\Services\Tcpip\..\{02777462-5D98-40EC-B654-A9041CD93B97}: NameServer = 202.216.229.30 202.216.224.30
O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum.txt
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IomegaAccess - Iomega Corporation - C:\WINDOWS\system32\IomegaAccess.exe
O23 - Service: iPod サービス (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\Common\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7FireWall\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7Privacy\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7AntiVirus\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7AntiSpam\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSMngr.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: ZipToA - Iomega Corporation - C:\WINDOWS\system32\ZipToA.exe

--
End of file - 12011 bytes

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:08:10 PM

Posted 01 August 2007 - 10:57 AM

Please download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.


------------------------------------------------------------

Download SmitfraudFix (by S!Ri), to your desktop.
Double click on Smitfraudfix.cmd
Select option 1 Search, by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy and paste the content of that report into your next reply.

*IMPORTANT*
Do NOT run any other options until you are asked to do so!

Also post a new Hijackthis log.
Posted Image
Posted Image

#5 MrNeedHelp

MrNeedHelp
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:10 PM

Posted 03 August 2007 - 11:19 AM

Mr. Richie.

Here It Is. Sorry of the delay.

1. This is the Combo Fix Software Scan Result................................

2. And The Combo Fix Quarantined Files........................................

3. The Smit Fraud Fix Software didn't Response Well When I Ran It. Why ?




1. This is the Combo Fix Software Scan Result................................


ComboFix 07-08-03.5 - "キャサリン" 2007-08-04 0:41:29.1 [GMT 9:00] - NTFS
Microsoft Windows XP Home Edition 5.1.2600.2.932.1.1041.18.True


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\キャサ~1\APPLIC~1\install.dat
C:\DOCUME~1\キャサ~1\APPLIC~1\WinAntiSpyware 2007
C:\DOCUME~1\キャサ~1\APPLIC~1\WinAntiSpyware 2007\Logs\update.log
C:\DOCUME~1\夕香\APPLIC~1\install.dat
C:\Documents and Settings\キャサ~1.\wn0004.exe
C:\Program Files\screensavers.com
C:\Program Files\screensavers.com\SSSInst\bin\SSSUninst.exe
C:\Program Files\screensavers.com\Wallpaper\swpstart.exe
C:\WINDOWS\cnsinfo.dat
C:\WINDOWS\system32\append.dll
C:\WINDOWS\system32\lzx32.sys
C:\WINDOWS\system32\WinAvX.exe


((((((((((((((((((((((((( Files Created from 2007-07-03 to 2007-08-03 )))))))))))))))))))))))))))))))


2007-08-03 21:47 74,752 --a------ C:\WINDOWS\duekduac.exe
2007-08-03 04:24 <DIR> d-------- C:\{80005DCA-0000-0000-59D7-541024726516}
2007-08-03 01:44 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-08-03 01:11 <DIR> d-------- C:\WINDOWS\system32\FxsTmp
2007-08-03 01:10 8,704 --a--c--- C:\WINDOWS\system32\dllcache\fxsperf.dll
2007-08-03 01:10 8,704 --a------ C:\WINDOWS\system32\fxsperf.dll
2007-08-03 01:10 72,192 --a--c--- C:\WINDOWS\system32\dllcache\fxscom.dll
2007-08-03 01:10 72,192 --a------ C:\WINDOWS\system32\fxscom.dll
2007-08-03 01:10 560,128 --a--c--- C:\WINDOWS\system32\dllcache\fxsst.dll
2007-08-03 01:10 560,128 --a------ C:\WINDOWS\system32\fxsst.dll
2007-08-03 01:10 5,120 --a--c--- C:\WINDOWS\system32\dllcache\fxsres.dll
2007-08-03 01:10 5,120 --a------ C:\WINDOWS\system32\fxsres.dll
2007-08-03 01:10 399,360 --a--c--- C:\WINDOWS\system32\dllcache\fxsxp32.dll
2007-08-03 01:10 399,360 --a------ C:\WINDOWS\system32\fxsxp32.dll
2007-08-03 01:10 397,312 --a--c--- C:\WINDOWS\system32\dllcache\fxstiff.dll
2007-08-03 01:10 397,312 --a------ C:\WINDOWS\system32\fxstiff.dll
2007-08-03 01:10 37,888 --a--c--- C:\WINDOWS\system32\dllcache\fxsevent.dll
2007-08-03 01:10 37,888 --a------ C:\WINDOWS\system32\fxsevent.dll
2007-08-03 01:10 31,744 --a--c--- C:\WINDOWS\system32\dllcache\fxsroute.dll
2007-08-03 01:10 31,744 --a------ C:\WINDOWS\system32\fxsroute.dll
2007-08-03 01:10 285,184 --a--c--- C:\WINDOWS\system32\dllcache\fxscomex.dll
2007-08-03 01:10 285,184 --a------ C:\WINDOWS\system32\fxscomex.dll
2007-08-03 01:10 27,136 --a--c--- C:\WINDOWS\system32\dllcache\fxsdrv.dll
2007-08-03 01:10 27,136 --a------ C:\WINDOWS\system32\fxsdrv.dll
2007-08-03 01:10 266,240 --a--c--- C:\WINDOWS\system32\dllcache\fxssvc.exe
2007-08-03 01:10 266,240 --a------ C:\WINDOWS\system32\fxssvc.exe
2007-08-03 01:10 246,272 --a--c--- C:\WINDOWS\system32\dllcache\fxst30.dll
2007-08-03 01:10 246,272 --a------ C:\WINDOWS\system32\fxst30.dll
2007-08-03 01:10 23,040 --a--c--- C:\WINDOWS\system32\dllcache\fxsmon.dll
2007-08-03 01:10 23,040 --a--c--- C:\WINDOWS\system32\dllcache\fxsext32.dll
2007-08-03 01:10 23,040 --a------ C:\WINDOWS\system32\fxsmon.dll
2007-08-03 01:10 23,040 --a------ C:\WINDOWS\system32\fxsext32.dll
2007-08-03 01:10 216,576 --a--c--- C:\WINDOWS\system32\dllcache\fxscover.exe
2007-08-03 01:10 216,576 --a------ C:\WINDOWS\system32\fxscover.exe
2007-08-03 01:10 187,904 --a--c--- C:\WINDOWS\system32\dllcache\fxswzrd.dll
2007-08-03 01:10 187,904 --a------ C:\WINDOWS\system32\fxswzrd.dll
2007-08-03 01:10 151,552 --a--c--- C:\WINDOWS\system32\dllcache\fxsui.dll
2007-08-03 01:10 151,552 --a------ C:\WINDOWS\system32\fxsui.dll
2007-08-03 01:10 143,360 --a--c--- C:\WINDOWS\system32\dllcache\fxsclnt.exe
2007-08-03 01:10 143,360 --a------ C:\WINDOWS\system32\fxsclnt.exe
2007-08-03 01:10 132,608 --a--c--- C:\WINDOWS\system32\dllcache\fxsclntr.dll
2007-08-03 01:10 132,608 --a------ C:\WINDOWS\system32\fxsclntR.dll
2007-08-03 01:10 111,104 --a--c--- C:\WINDOWS\system32\dllcache\fxscfgwz.dll
2007-08-03 01:10 111,104 --a------ C:\WINDOWS\system32\fxscfgwz.dll
2007-08-03 01:10 11,264 --a--c--- C:\WINDOWS\system32\dllcache\fxssend.exe
2007-08-03 01:10 11,264 --a------ C:\WINDOWS\system32\fxssend.exe
2007-08-03 01:09 452,096 --a--c--- C:\WINDOWS\system32\dllcache\fxsapi.dll
2007-08-03 01:09 452,096 --a------ C:\WINDOWS\system32\fxsapi.dll
2007-08-03 01:00 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-03 00:01 74,752 --a------ C:\WINDOWS\samowr.exe
2007-08-02 00:25 <DIR> d-------- C:\Program Files\Trend Micro
2007-08-01 05:53 37,376 --a------ C:\WINDOWS\system32\vtr135.dll
2007-08-01 05:53 14,848 --a------ C:\WINDOWS\system32\winavxx.exe
2007-08-01 05:53 14,848 --a------ C:\WINDOWS\system32\printer.exe
2007-07-31 01:32 <DIR> d-------- C:\DOCUME~1\キャサ~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-31 00:57 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-31 00:56 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-07-31 00:56 <DIR> d-------- C:\DOCUME~1\夕香\APPLIC~1\SUPERAntiSpyware.com
2007-07-31 00:55 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-28 00:21 5,242,880 --a------ C:\DOCUME~1\キャサ~1\ntuser.dat
2007-07-26 23:33 4,512 --a------ C:\WINDOWS\system32\drivers\NaiFsRec.sys
2007-07-26 06:14 74,240 --a------ C:\WINDOWS\bwxdast.exe
2007-07-26 06:04 37,376 --a------ C:\WINDOWS\system32\atzrdada.dll
2007-07-26 06:04 15,360 --a------ C:\WINDOWS\system32\afqgda.exe
2007-07-18 11:18 4,456,448 --a------ C:\DOCUME~1\夕香\ntuser.dat
2007-07-13 23:59 <DIR> d-------- C:\DOCUME~1\夕香\APPLIC~1\ESTsoft
2007-07-09 00:35 <DIR> d-------- C:\DOCUME~1\キャサ~1\APPLIC~1\ESTsoft
2007-07-09 00:34 <DIR> d-------- C:\Program Files\ZIPESTsoft
2007-07-09 00:34 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ESTsoft
2007-07-09 00:33 5,754,977 --a------ C:\Program Files\ALZip.exe
2007-07-06 23:32 <DIR> d-------- C:\DOCUME~1\夕香\APPLIC~1\Leadertech


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-03 01:11 40992 --a------ C:\WINDOWS\system32\perfc011.dat
2007-08-03 01:11 152942 --a------ C:\WINDOWS\system32\perfh011.dat
2007-08-03 01:08 --------- d-------- C:\Program Files\FinePixViewer
2007-07-20 00:38 --------- d-------- C:\Program Files\Microsoft Publisher
2007-06-27 00:06 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-05-17 00:12 85504 --a--c--- C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-17 00:12 510976 --a--c--- C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-17 00:12 1314816 --a--c--- C:\WINDOWS\system32\dllcache\msoe.dll
2007-05-17 00:11 86528 --a--c--- C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-17 00:11 683520 --a--c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-17 00:11 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-04 21:59 3085312 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 21:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 21:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 21:00]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-10-08 08:31]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-10-08 08:27]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 02:49]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 02:49]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe" [2004-06-03 22:05]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2005-08-26 14:26]
"freesurfer"="C:\Program Files\EMS Free Surfer Companion\fs30.exe" [2005-02-15 14:43]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-01-01 02:39]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 22:32]
"Iomega Startup Options"="C:\Program Files\Iomega\Common\ImgStart.exe" [2000-06-02 10:57]
"Iomega Drive Icons"="C:\Program Files\Iomega\DriveIcons\ImgIcon.exe" [2000-06-13 07:48]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 16:44]
"K7TSStart"="C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSecurity.exe" [2007-03-16 20:53]
"K7SystemTray"="C:\Program Files\K7 Computing\Common\K7SysTry.exe" [2007-03-27 17:19]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-04-27 11:25]
"VSOCheckTask"="c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [2004-07-01 15:15]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2004-08-17 16:55]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 21:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 01:24]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ctfmon.exe"=ctfmon.exe

C:\Documents and Settings\All Users\スタート メニュー\プログラム\スタートアップ\
Camio Viewer.lnk - C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe [2005-08-10 19:32:50]
Exif Launcher 2.lnk - C:\Program Files\FinePixViewer\QuickDCF2.exe [2006-07-23 17:07:14]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2005-04-26 17:34:57]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 05:05:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\hrum.txt

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll, xlibgfl254.dll

R0 K7FWFILT;K7FWFILT;C:\WINDOWS\system32\drivers\K7FWFILT.sys
R0 NaiFsRec;NaiFsRec;C:\WINDOWS\system32\drivers\NaiFsRec.sys
R0 RecAgent;RecAgent;C:\WINDOWS\system32\DRIVERS\RecAgent.sys
R1 Cdr4_xp;Cdr4_xp;C:\WINDOWS\system32\drivers\Cdr4_xp.sys
R1 cdudf_xp;cdudf_xp;C:\WINDOWS\system32\drivers\cdudf_xp.sys
R1 FsVga;FsVga;C:\WINDOWS\system32\DRIVERS\fsvga.sys
R1 K7TdiHlp;K7TDI Helper Service;\??\C:\WINDOWS\system32\drivers\K7TdiHlp.sys
R1 pwd_2k;pwd_2k;C:\WINDOWS\system32\drivers\pwd_2k.sys
R1 SASDIFSV;SASDIFSV;\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
R1 SASKUTIL;SASKUTIL;\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
R1 UdfReadr_xp;UdfReadr_xp;C:\WINDOWS\system32\drivers\UdfReadr_xp.sys
R2 K7EmlPxy;K7Computng - EMail Proxy Server;C:\Program Files\K7 Computing\Common\K7EmlPxy.exe
R2 K7FWSrvc;K7Firewall Services;C:\Program Files\K7 Computing\K7TSecurity\K7FireWall\K7FWSrvc.exe
R2 K7PSSrvc;K7Privacy Services;C:\Program Files\K7 Computing\K7TSecurity\K7Privacy\K7PSSrvc.exe
R2 K7RTScan;K7RealTime AntiVirus Services;C:\Program Files\K7 Computing\K7TSecurity\K7AntiVirus\K7RTScan.exe
R2 K7Sentry;K7Sentry;\??\C:\WINDOWS\system32\drivers\K7Sentry.sys
R2 K7TSMngr;K7TotalSecurity Manager;C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSMngr.exe
R3 mmc_2K;mmc_2K;C:\WINDOWS\system32\drivers\mmc_2K.sys
R3 NaiFiltr;NaiFiltr;\??\C:\Program Files\McAfee.com\VSO\NaiFiltr.sys
R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver;C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys
S3 dvd_2K;dvd_2K;C:\WINDOWS\system32\drivers\dvd_2K.sys
S3 K7SpmSrc;K7SpmSrc;C:\Program Files\K7 Computing\K7TSecurity\K7AntiSpam\K7SpmSrc.exe
S3 M2500;802.11g Wireless Network Driver;C:\WINDOWS\system32\DRIVERS\M2500.sys
S3 Mtlmnt5;Mtlmnt5;C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys
S3 Mtlstrm;Mtlstrm;C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys
S3 NtMtlFax;NtMtlFax;C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys
S3 SASENUM;SASENUM;\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
S3 Slntamr;SmartLink AMR_PCI Driver;C:\WINDOWS\system32\DRIVERS\slntamr.sys
S3 SlNtHal;SlNtHal;C:\WINDOWS\system32\DRIVERS\Slnthal.sys
S3 SlWdmSup;SlWdmSup;C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys
S3 SynTP;Synaptics TouchPad Driver;C:\WINDOWS\system32\DRIVERS\SynTP.sys


Contents of the 'Scheduled Tasks' folder
2007-07-15 02:00:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-01-28 15:06:43 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job - C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-04 00:49:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\D:\\xff730\xff8b0\xff6b0]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\D:\\xff730\xff8b0\xff6b0\U0\x30fbK0]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\D:\\xff730\xff8b0\xff6b0\U0\x30fbK0\\xff620\xff970\x30fb2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\D:\\xff730\xff8b0\xff6b0\U0\x30fbK0\\xff620\xff970\x30fb2\\xff620\x30fb\xff900\x30fb\xff620\xff830\xff970\x30fb\x30fb\xff800\x30fb.]
"Path"="C:\Program Files\Common Files\Konica Uploader"
@="C:\Program Files\Common Files\Konica Uploader\D:\\x30b3\x30cb\x30ab\\x3055\x3084\x304b\\x30a2\x30d7\x30ea2\\x30a2\x30eb\x30d0\x30e0\x30a2\x30c3\x30d7\x30ed\x30fc\x30c0\x30fc.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes]
"\31j\x58a8n0D}0\bT\x30fb[0??"="",,,,,,,,,,,,,""
"Kb ?1?"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\handapst.ani,C:\WINDOWS\Cursors\hand.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\hnodrop.cur,C:\WINDOWS\Cursors\hns.cur,C:\WINDOWS\Cursors\hwe.cur,C:\WINDOWS\Cursors\hnwse.cur,C:\WINDOWS\Cursors\hnesw.cur,C:\WINDOWS\Cursors\hmove.cur,""
"Kb ?2?"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\handapst.ani,C:\WINDOWS\Cursors\handwait.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\handno.ani,C:\WINDOWS\Cursors\handns.ani,C:\WINDOWS\Cursors\handwe.ani,C:\WINDOWS\Cursors\handnwse.ani,C:\WINDOWS\Cursors\handnesw.ani,C:\WINDOWS\Cursors\hmove.cur,""
"P`\xff9cz"=""C:\WINDOWS\Cursors\3dgarro.cur,,C:\WINDOWS\Cursors\dinosaur.ani,C:\WINDOWS\Cursors\dinosau2.ani,C:\WINDOWS\Cursors\cross.cur,,,C:\WINDOWS\Cursors\banana.ani,C:\WINDOWS\Cursors\3dsns.cur,C:\WINDOWS\Cursors\3dgwe.cur,C:\WINDOWS\Cursors\3dsnwse.cur,C:\WINDOWS\Cursors\3dgnesw.cur,C:\WINDOWS\Cursors\3dsmove.cur,""
"\xff6a0\x30fb\x30fb\xff890 ?\xff950\xff610\xff830\xff770\x30fb\x30fb????"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\horse.ani,C:\WINDOWS\Cursors\barber.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\coin.ani,C:\WINDOWS\Cursors\3dgns.cur,C:\WINDOWS\Cursors\3dgwe.cur,C:\WINDOWS\Cursors\3dgnwse.cur,C:\WINDOWS\Cursors\3dgnesw.cur,C:\WINDOWS\Cursors\3dgmove.cur,""
"\xff730\x30fb\xff800\xff6f0\xff7f0?"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\drum.ani,C:\WINDOWS\Cursors\metronom.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\piano.ani,C:\WINDOWS\Cursors\hns.cur,C:\WINDOWS\Cursors\hwe.cur,C:\WINDOWS\Cursors\hnwse.cur,C:\WINDOWS\Cursors\hnesw.cur,C:\WINDOWS\Cursors\hmove.cur,""
"\x7578'Y\xff9d0\xff640\x30fb\xff7f0??"=""C:\WINDOWS\Cursors\larrow.cur,,C:\WINDOWS\Cursors\lappstrt.cur,C:\WINDOWS\Cursors\lwait.cur,C:\WINDOWS\Cursors\lcross.cur,C:\WINDOWS\Cursors\libeam.cur,,C:\WINDOWS\Cursors\lnodrop.cur,C:\WINDOWS\Cursors\lns.cur,C:\WINDOWS\Cursors\lwe.cur,C:\WINDOWS\Cursors\lnwse.cur,C:\WINDOWS\Cursors\lnesw.cur,C:\WINDOWS\Cursors\lmove.cur,""
"D0\x30fbD0\x30fbj0\xff9d0\xff640\x30fb\xff7f0???"=""C:\WINDOWS\Cursors\fillitup.ani,,C:\WINDOWS\Cursors\raindrop.ani,C:\WINDOWS\Cursors\counter.ani,C:\WINDOWS\Cursors\cross.cur,,,C:\WINDOWS\Cursors\wagtail.ani,C:\WINDOWS\Cursors\sizens.ani,C:\WINDOWS\Cursors\sizewe.ani,C:\WINDOWS\Cursors\sizenwse.ani,C:\WINDOWS\Cursors\sizenesw.ani,""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DocFolderPaths]
"\xff6d0\x30fb\xff750\x30fb\x30fb???"="C:\Documents and Settings\\x30ad\x30e3\x30b5\x30ea\x30f3\My Documents"
"\25Y\x5294?"="C:\Documents and Settings\\x5915\x9999\My Documents"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\\xff620\x30fb\xff640\x30fb\xff790\xff880\x30fb\x30fbn0\xff900\xff830\xff6f0\xff620\xff830\xff970 ]
@="{67cf8cbd-e5c0-44f7-9dscanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-04 0:53:49
C:\ComboFix-quarantined-files.txt ... 2007-08-04 00:53

--- E O F ---


2. And The Combo Fix Quarantined Files........................................


2004-03-13 04:35	  142336	--a--c---	C:\Qoobox\Quarantine\C\Program Files\Screensavers.com\Wallpaper\swpstart.exe.vir
2004-10-20 06:58	  14848	--a------	C:\Qoobox\Quarantine\C\WINDOWS\system32\append.dll.vir
2007-01-27 08:22	  0	--a--c---	C:\Qoobox\Quarantine\C\DOCUME~1\夕香\APPLIC~1\Install.dat.vir
2007-01-27 13:50	  0	--a--c---	C:\Qoobox\Quarantine\C\DOCUME~1\キャサ~1\APPLIC~1\Install.dat.vir
2007-01-28 21:02	  28676	--a--c---	C:\Qoobox\Quarantine\C\WINDOWS\cnsinfo.dat.vir
2007-01-28 23:00	  2123	--a--c---	C:\Qoobox\Quarantine\C\DOCUME~1\キャサ~1\APPLIC~1\WinAntiSpyware 2007\Logs\update.log.vir
2007-02-13 00:34	  32566	--a------	C:\Qoobox\Quarantine\C\Program Files\Screensavers.com\SSSInst\bin\SSSUninst.exe.vir
2007-07-26 06:05	  66600	--a------	C:\Qoobox\Quarantine\C\WINDOWS\system32\lzx32.sys.vir
2007-07-27 22:32	  16896	--a------	C:\Qoobox\Quarantine\C\Documents and Settings\キャサ~1\wn0004.exe.vir
2007-07-31 07:03	  15360	--a------	C:\Qoobox\Quarantine\C\WINDOWS\system32\WinAvX.exe.vir


フォルダ パスの一覧
ボリューム シリアル番号は 00C2-7956 です
C:\QOOBOX
\---Quarantine
	+---C
	|   +---Documents and Settings
	|   |   \---キャサ~1
	|   |		   wn0004.exe.vir
	|   |		   
	|   +---DOCUME~1
	|   |   +---キャサ~1
	|   |   |   \---APPLIC~1
	|   |   |	   |   Install.dat.vir
	|   |   |	   |   
	|   |   |	   \---WinAntiSpyware 2007
	|   |   |		   \---Logs
	|   |   |				   update.log.vir
	|   |   |				   
	|   |   \---夕香
	|   |	   \---APPLIC~1
	|   |			   Install.dat.vir
	|   |			   
	|   +---Program Files
	|   |   \---Screensavers.com
	|   |	   +---SSSInst
	|   |	   |   \---bin
	|   |	   |		   SSSUninst.exe.vir
	|   |	   |		   
	|   |	   \---Wallpaper
	|   |			   swpstart.exe.vir
	|   |			   
	|   \---WINDOWS
	|	   |   cnsinfo.dat.vir
	|	   |   
	|	   \---system32
	|			   append.dll.vir
	|			   lzx32.sys.vir
	|			   WinAvX.exe.vir
	|			   
	\---Registry_backups


I don't know if this helps. Iappreciate your help and support.

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:08:10 PM

Posted 03 August 2007 - 02:27 PM

Go here:http://virusscan.jotti.org/
Using the 'Browse' button,browse to:
C:\WINDOWS\system32\printer.exe
Then press the 'Submit' button.
Wait while the file is scanned.
Post the results into your next reply.

If Jotti's too busy,try here:
http://www.virustotal.com/en/virustotalf.html
Click on the 'Analysis' tab.
Using the 'Browse' button,browse to:
C:\WINDOWS\system32\printer.exe
Then click on 'Send File'.
Post the results into your next reply.

--------------------------------------------------

Copy and paste ALL the following blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\duekduac.exe
C:\WINDOWS\samowr.exe
C:\WINDOWS\bwxdast.exe
C:\WINDOWS\system32\vtr135.dll
C:\WINDOWS\system32\winavxx.exe
C:\WINDOWS\system32\atzrdada.dll
C:\WINDOWS\system32\afqgda.exe

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image
Posted Image

#7 MrNeedHelp

MrNeedHelp
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:10 PM

Posted 04 August 2007 - 10:57 AM

Mr. Richie. HERE ARE 3 SCANNED LOGED RESULTS

1. here is the result from the Virustotal Web Site Scan.................

File printer.exe received on 08.04.2007 17:11:24 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED


Result: 10/31 (32.26%)
Loading server information...
Your file is queued in position: 5.
Estimated start time is between 64 and 91 seconds.
Do not close the window untill scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or do not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:


Antivirus Version Last Update Result
AhnLab-V3 2007.8.3.0 2007.08.03 -
AntiVir 7.4.0.57 2007.08.03 TR/Agent.14848.38
Authentium 4.93.8 2007.08.03 -
Avast 4.7.1029.0 2007.08.03 -
AVG 7.5.0.476 2007.08.03 -
BitDefender 7.2 2007.08.04 Generic.Malware.SDYd!wsp.A951E53A
CAT-QuickHeal 9.00 2007.08.04 -
ClamAV 0.91 2007.08.04 -
DrWeb 4.33 2007.08.04 -
eSafe 7.0.15.0 2007.07.31 suspicious Trojan/Worm
eTrust-Vet 31.1.5032 2007.08.04 -
Ewido 4.0 2007.08.03 -
FileAdvisor 1 2007.08.04 -
Fortinet 2.91.0.0 2007.08.04 Misc/WinFixer
F-Prot 4.3.2.48 2007.08.03 -
F-Secure 6.70.13030.0 2007.08.03 -
Ikarus T3.1.1.8 2007.08.04 Win32.SuspectCrc
Kaspersky 4.0.2.24 2007.08.04 -
McAfee 5090 2007.08.03 potentially unwanted program Winfixer
Microsoft 1.2704 2007.08.04 -
NOD32v2 2437 2007.08.03 -
Norman 5.80.02 2007.08.03 -
Panda 9.0.0.4 2007.08.04 Adware/WinAntiVirus2007
Rising 19.34.40.00 2007.08.03 -
Sophos 4.19.0 2007.08.01 -
Sunbelt 2.2.907.0 2007.08.04 Trojan.KillAV
Symantec 10 2007.08.04 Trojan.KillAV
TheHacker 6.1.7.162 2007.08.04 -
VBA32 3.12.2.2 2007.08.04 -
VirusBuster 4.3.26:9 2007.08.04 -
Webwasher-Gateway 6.0.1 2007.08.03 Trojan.Agent.14848.38
Additional information
File size: 14848 bytes
MD5: 0ce7bcc39a9592707967a1ca9e394aec
SHA1: 23b785368dea786c58952576610a3b2d74d19a68
packers: UPX
Sunbelt info: Trojan.KillAV is malware that scans the infected computer for anti-virus processes and attemtps to terminate them.


2. Here is the CFScript file draged onto ComboFix.exe result......................


ComboFix 07-08-03.5 - "夕香" 2007-08-05 0:29:15.4 [GMT 9:00] - NTFS
Microsoft Windows XP Home Edition 5.1.2600.2.932.1.1041.18.True
Command switches used :: C:\Documents and Settings\夕香\デスクトップ\SCFscript.txt
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\bwxdast.exe
C:\WINDOWS\duekduac.exe
C:\WINDOWS\samowr.exe
C:\WINDOWS\system32\afqgda.exe
C:\WINDOWS\system32\atzrdada.dll
C:\WINDOWS\system32\vtr135.dll
C:\WINDOWS\system32\winavxx.exe


((((((((((((((((((((((((( Files Created from 2007-07-04 to 2007-08-04 )))))))))))))))))))))))))))))))


2007-08-03 04:24 <DIR> d-------- C:\{80005DCA-0000-0000-59D7-541024726516}
2007-08-03 01:44 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-08-03 01:11 <DIR> d-------- C:\WINDOWS\system32\FxsTmp
2007-08-03 01:10 8,704 --a--c--- C:\WINDOWS\system32\dllcache\fxsperf.dll
2007-08-03 01:10 8,704 --a------ C:\WINDOWS\system32\fxsperf.dll
2007-08-03 01:10 72,192 --a--c--- C:\WINDOWS\system32\dllcache\fxscom.dll
2007-08-03 01:10 72,192 --a------ C:\WINDOWS\system32\fxscom.dll
2007-08-03 01:10 560,128 --a--c--- C:\WINDOWS\system32\dllcache\fxsst.dll
2007-08-03 01:10 560,128 --a------ C:\WINDOWS\system32\fxsst.dll
2007-08-03 01:10 5,120 --a--c--- C:\WINDOWS\system32\dllcache\fxsres.dll
2007-08-03 01:10 5,120 --a------ C:\WINDOWS\system32\fxsres.dll
2007-08-03 01:10 399,360 --a--c--- C:\WINDOWS\system32\dllcache\fxsxp32.dll
2007-08-03 01:10 399,360 --a------ C:\WINDOWS\system32\fxsxp32.dll
2007-08-03 01:10 397,312 --a--c--- C:\WINDOWS\system32\dllcache\fxstiff.dll
2007-08-03 01:10 397,312 --a------ C:\WINDOWS\system32\fxstiff.dll
2007-08-03 01:10 37,888 --a--c--- C:\WINDOWS\system32\dllcache\fxsevent.dll
2007-08-03 01:10 37,888 --a------ C:\WINDOWS\system32\fxsevent.dll
2007-08-03 01:10 31,744 --a--c--- C:\WINDOWS\system32\dllcache\fxsroute.dll
2007-08-03 01:10 31,744 --a------ C:\WINDOWS\system32\fxsroute.dll
2007-08-03 01:10 285,184 --a--c--- C:\WINDOWS\system32\dllcache\fxscomex.dll
2007-08-03 01:10 285,184 --a------ C:\WINDOWS\system32\fxscomex.dll
2007-08-03 01:10 27,136 --a--c--- C:\WINDOWS\system32\dllcache\fxsdrv.dll
2007-08-03 01:10 27,136 --a------ C:\WINDOWS\system32\fxsdrv.dll
2007-08-03 01:10 266,240 --a--c--- C:\WINDOWS\system32\dllcache\fxssvc.exe
2007-08-03 01:10 266,240 --a------ C:\WINDOWS\system32\fxssvc.exe
2007-08-03 01:10 246,272 --a--c--- C:\WINDOWS\system32\dllcache\fxst30.dll
2007-08-03 01:10 246,272 --a------ C:\WINDOWS\system32\fxst30.dll
2007-08-03 01:10 23,040 --a--c--- C:\WINDOWS\system32\dllcache\fxsmon.dll
2007-08-03 01:10 23,040 --a--c--- C:\WINDOWS\system32\dllcache\fxsext32.dll
2007-08-03 01:10 23,040 --a------ C:\WINDOWS\system32\fxsmon.dll
2007-08-03 01:10 23,040 --a------ C:\WINDOWS\system32\fxsext32.dll
2007-08-03 01:10 216,576 --a--c--- C:\WINDOWS\system32\dllcache\fxscover.exe
2007-08-03 01:10 216,576 --a------ C:\WINDOWS\system32\fxscover.exe
2007-08-03 01:10 187,904 --a--c--- C:\WINDOWS\system32\dllcache\fxswzrd.dll
2007-08-03 01:10 187,904 --a------ C:\WINDOWS\system32\fxswzrd.dll
2007-08-03 01:10 151,552 --a--c--- C:\WINDOWS\system32\dllcache\fxsui.dll
2007-08-03 01:10 151,552 --a------ C:\WINDOWS\system32\fxsui.dll
2007-08-03 01:10 143,360 --a--c--- C:\WINDOWS\system32\dllcache\fxsclnt.exe
2007-08-03 01:10 143,360 --a------ C:\WINDOWS\system32\fxsclnt.exe
2007-08-03 01:10 132,608 --a--c--- C:\WINDOWS\system32\dllcache\fxsclntr.dll
2007-08-03 01:10 132,608 --a------ C:\WINDOWS\system32\fxsclntR.dll
2007-08-03 01:10 111,104 --a--c--- C:\WINDOWS\system32\dllcache\fxscfgwz.dll
2007-08-03 01:10 111,104 --a------ C:\WINDOWS\system32\fxscfgwz.dll
2007-08-03 01:10 11,264 --a--c--- C:\WINDOWS\system32\dllcache\fxssend.exe
2007-08-03 01:10 11,264 --a------ C:\WINDOWS\system32\fxssend.exe
2007-08-03 01:09 452,096 --a--c--- C:\WINDOWS\system32\dllcache\fxsapi.dll
2007-08-03 01:09 452,096 --a------ C:\WINDOWS\system32\fxsapi.dll
2007-08-03 01:00 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-02 00:25 <DIR> d-------- C:\Program Files\Trend Micro
2007-08-01 05:53 14,848 --a------ C:\WINDOWS\system32\printer.exe
2007-07-31 01:32 <DIR> d-------- C:\DOCUME~1\キャサ~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-31 00:57 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-31 00:56 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-07-31 00:56 <DIR> d-------- C:\DOCUME~1\夕香\APPLIC~1\SUPERAntiSpyware.com
2007-07-31 00:55 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-28 00:21 5,242,880 --a------ C:\DOCUME~1\キャサ~1\ntuser.dat
2007-07-26 23:33 4,512 --a------ C:\WINDOWS\system32\drivers\NaiFsRec.sys
2007-07-18 11:18 4,456,448 --a------ C:\DOCUME~1\夕香\ntuser.dat
2007-07-13 23:59 <DIR> d-------- C:\DOCUME~1\夕香\APPLIC~1\ESTsoft
2007-07-09 00:35 <DIR> d-------- C:\DOCUME~1\キャサ~1\APPLIC~1\ESTsoft
2007-07-09 00:34 <DIR> d-------- C:\Program Files\ZIPESTsoft
2007-07-09 00:34 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ESTsoft
2007-07-09 00:33 5,754,977 --a------ C:\Program Files\ALZip.exe
2007-07-06 23:32 <DIR> d-------- C:\DOCUME~1\夕香\APPLIC~1\Leadertech


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-03 01:11 40992 --a------ C:\WINDOWS\system32\perfc011.dat
2007-08-03 01:11 152942 --a------ C:\WINDOWS\system32\perfh011.dat
2007-08-03 01:08 --------- d-------- C:\Program Files\FinePixViewer
2007-07-20 00:38 --------- d-------- C:\Program Files\Microsoft Publisher
2007-06-27 00:06 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-05-17 00:12 85504 --a--c--- C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-17 00:12 510976 --a--c--- C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-17 00:12 1314816 --a--c--- C:\WINDOWS\system32\dllcache\msoe.dll
2007-05-17 00:11 86528 --a--c--- C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-17 00:11 683520 --a--c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-17 00:11 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-04 21:59 3085312 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 21:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 21:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 21:00]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-10-08 08:31]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-10-08 08:27]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 02:49]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 02:49]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe" [2004-06-03 22:05]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2005-08-26 14:26]
"freesurfer"="C:\Program Files\EMS Free Surfer Companion\fs30.exe" [2005-02-15 14:43]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-01-01 02:39]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 22:32]
"Iomega Startup Options"="C:\Program Files\Iomega\Common\ImgStart.exe" [2000-06-02 10:57]
"Iomega Drive Icons"="C:\Program Files\Iomega\DriveIcons\ImgIcon.exe" [2000-06-13 07:48]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 16:44]
"K7TSStart"="C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSecurity.exe" [2007-03-16 20:53]
"K7SystemTray"="C:\Program Files\K7 Computing\Common\K7SysTry.exe" [2007-03-27 17:19]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-04-27 11:25]
"VSOCheckTask"="c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [2004-07-01 15:15]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2004-08-17 16:55]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 21:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 01:24]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ctfmon.exe"=ctfmon.exe

C:\Documents and Settings\夕香\スタート メニュー\プログラム\スタートアップ\
system.exe [2007-08-02 17:36:13]

C:\Documents and Settings\All Users\スタート メニュー\プログラム\スタートアップ\
autorun.exe [2007-08-02 17:36:13]
Camio Viewer.lnk - C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe [2005-08-10 19:32:50]
Exif Launcher 2.lnk - C:\Program Files\FinePixViewer\QuickDCF2.exe [2006-07-23 17:07:14]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2005-04-26 17:34:57]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 05:05:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\hrum.txt

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll, xlibgfl254.dll

R0 K7FWFILT;K7FWFILT;C:\WINDOWS\system32\drivers\K7FWFILT.sys
R0 NaiFsRec;NaiFsRec;C:\WINDOWS\system32\drivers\NaiFsRec.sys
R0 RecAgent;RecAgent;C:\WINDOWS\system32\DRIVERS\RecAgent.sys
R1 Cdr4_xp;Cdr4_xp;C:\WINDOWS\system32\drivers\Cdr4_xp.sys
R1 cdudf_xp;cdudf_xp;C:\WINDOWS\system32\drivers\cdudf_xp.sys
R1 FsVga;FsVga;C:\WINDOWS\system32\DRIVERS\fsvga.sys
R1 K7TdiHlp;K7TDI Helper Service;\??\C:\WINDOWS\system32\drivers\K7TdiHlp.sys
R1 pwd_2k;pwd_2k;C:\WINDOWS\system32\drivers\pwd_2k.sys
R1 SASDIFSV;SASDIFSV;\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
R1 SASKUTIL;SASKUTIL;\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
R1 UdfReadr_xp;UdfReadr_xp;C:\WINDOWS\system32\drivers\UdfReadr_xp.sys
R2 K7EmlPxy;K7Computng - EMail Proxy Server;C:\Program Files\K7 Computing\Common\K7EmlPxy.exe
R2 K7FWSrvc;K7Firewall Services;C:\Program Files\K7 Computing\K7TSecurity\K7FireWall\K7FWSrvc.exe
R2 K7PSSrvc;K7Privacy Services;C:\Program Files\K7 Computing\K7TSecurity\K7Privacy\K7PSSrvc.exe
R2 K7RTScan;K7RealTime AntiVirus Services;C:\Program Files\K7 Computing\K7TSecurity\K7AntiVirus\K7RTScan.exe
R2 K7Sentry;K7Sentry;\??\C:\WINDOWS\system32\drivers\K7Sentry.sys
R2 K7TSMngr;K7TotalSecurity Manager;C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSMngr.exe
R3 mmc_2K;mmc_2K;C:\WINDOWS\system32\drivers\mmc_2K.sys
R3 NaiFiltr;NaiFiltr;\??\C:\Program Files\McAfee.com\VSO\NaiFiltr.sys
R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver;C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys
R3 SASENUM;SASENUM;\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
S3 dvd_2K;dvd_2K;C:\WINDOWS\system32\drivers\dvd_2K.sys
S3 K7SpmSrc;K7SpmSrc;C:\Program Files\K7 Computing\K7TSecurity\K7AntiSpam\K7SpmSrc.exe
S3 M2500;802.11g Wireless Network Driver;C:\WINDOWS\system32\DRIVERS\M2500.sys
S3 Mtlmnt5;Mtlmnt5;C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys
S3 Mtlstrm;Mtlstrm;C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys
S3 NtMtlFax;NtMtlFax;C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys
S3 Slntamr;SmartLink AMR_PCI Driver;C:\WINDOWS\system32\DRIVERS\slntamr.sys
S3 SlNtHal;SlNtHal;C:\WINDOWS\system32\DRIVERS\Slnthal.sys
S3 SlWdmSup;SlWdmSup;C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys
S3 SynTP;Synaptics TouchPad Driver;C:\WINDOWS\system32\DRIVERS\SynTP.sys


Contents of the 'Scheduled Tasks' folder
2007-07-15 02:00:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-01-28 15:06:43 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job - C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-05 00:40:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\D:\\xff730\xff8b0\xff6b0]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\D:\\xff730\xff8b0\xff6b0\U0\x30fbK0]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\D:\\xff730\xff8b0\xff6b0\U0\x30fbK0\\xff620\xff970\x30fb2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\D:\\xff730\xff8b0\xff6b0\U0\x30fbK0\\xff620\xff970\x30fb2\\xff620\x30fb\xff900\x30fb\xff620\xff830\xff970\x30fb\x30fb\xff800\x30fb.]
"Path"="C:\Program Files\Common Files\Konica Uploader"
@="C:\Program Files\Common Files\Konica Uploader\D:\\x30b3\x30cb\x30ab\\x3055\x3084\x304b\\x30a2\x30d7\x30ea2\\x30a2\x30eb\x30d0\x30e0\x30a2\x30c3\x30d7\x30ed\x30fc\x30c0\x30fc.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes]
"\31j\x58a8n0D}0\bT\x30fb[0??"="",,,,,,,,,,,,,""
"Kb ?1?"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\handapst.ani,C:\WINDOWS\Cursors\hand.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\hnodrop.cur,C:\WINDOWS\Cursors\hns.cur,C:\WINDOWS\Cursors\hwe.cur,C:\WINDOWS\Cursors\hnwse.cur,C:\WINDOWS\Cursors\hnesw.cur,C:\WINDOWS\Cursors\hmove.cur,""
"Kb ?2?"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\handapst.ani,C:\WINDOWS\Cursors\handwait.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\handno.ani,C:\WINDOWS\Cursors\handns.ani,C:\WINDOWS\Cursors\handwe.ani,C:\WINDOWS\Cursors\handnwse.ani,C:\WINDOWS\Cursors\handnesw.ani,C:\WINDOWS\Cursors\hmove.cur,""
"P`\xff9cz"=""C:\WINDOWS\Cursors\3dgarro.cur,,C:\WINDOWS\Cursors\dinosaur.ani,C:\WINDOWS\Cursors\dinosau2.ani,C:\WINDOWS\Cursors\cross.cur,,,C:\WINDOWS\Cursors\banana.ani,C:\WINDOWS\Cursors\3dsns.cur,C:\WINDOWS\Cursors\3dgwe.cur,C:\WINDOWS\Cursors\3dsnwse.cur,C:\WINDOWS\Cursors\3dgnesw.cur,C:\WINDOWS\Cursors\3dsmove.cur,""
"\xff6a0\x30fb\x30fb\xff890 ?\xff950\xff610\xff830\xff770\x30fb\x30fb????"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\horse.ani,C:\WINDOWS\Cursors\barber.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\coin.ani,C:\WINDOWS\Cursors\3dgns.cur,C:\WINDOWS\Cursors\3dgwe.cur,C:\WINDOWS\Cursors\3dgnwse.cur,C:\WINDOWS\Cursors\3dgnesw.cur,C:\WINDOWS\Cursors\3dgmove.cur,""
"\xff730\x30fb\xff800\xff6f0\xff7f0?"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\drum.ani,C:\WINDOWS\Cursors\metronom.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\piano.ani,C:\WINDOWS\Cursors\hns.cur,C:\WINDOWS\Cursors\hwe.cur,C:\WINDOWS\Cursors\hnwse.cur,C:\WINDOWS\Cursors\hnesw.cur,C:\WINDOWS\Cursors\hmove.cur,""
"\x7578'Y\xff9d0\xff640\x30fb\xff7f0??"=""C:\WINDOWS\Cursors\larrow.cur,,C:\WINDOWS\Cursors\lappstrt.cur,C:\WINDOWS\Cursors\lwait.cur,C:\WINDOWS\Cursors\lcross.cur,C:\WINDOWS\Cursors\libeam.cur,,C:\WINDOWS\Cursors\lnodrop.cur,C:\WINDOWS\Cursors\lns.cur,C:\WINDOWS\Cursors\lwe.cur,C:\WINDOWS\Cursors\lnwse.cur,C:\WINDOWS\Cursors\lnesw.cur,C:\WINDOWS\Cursors\lmove.cur,""
"D0\x30fbD0\x30fbj0\xff9d0\xff640\x30fb\xff7f0???"=""C:\WINDOWS\Cursors\fillitup.ani,,C:\WINDOWS\Cursors\raindrop.ani,C:\WINDOWS\Cursors\counter.ani,C:\WINDOWS\Cursors\cross.cur,,,C:\WINDOWS\Cursors\wagtail.ani,C:\WINDOWS\Cursors\sizens.ani,C:\WINDOWS\Cursors\sizewe.ani,C:\WINDOWS\Cursors\sizenwse.ani,C:\WINDOWS\Cursors\sizenesw.ani,""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DocFolderPaths]
"\xff6d0\x30fb\xff750\x30fb\x30fb???"="C:\Documents and Settings\\x30ad\x30e3\x30b5\x30ea\x30f3\My Documents"
"\25Y\x5294?"="C:\Documents and Settings\\x5915\x9999\My Documents"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\\xff620\x30fb\xff640\x30fb\xff790\xff880\x30fb\x30fbn0\xff900\xff830\xff6f0\xff620\xff830\xff970 ]
@="{67cf8cbd-e5c0-44f7-9dscanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-05 0:45:20
C:\ComboFix-quarantined-files.txt ... 2007-08-05 00:43
C:\ComboFix2.txt ... 2007-08-04 15:30
C:\ComboFix3.txt ... 2007-08-04 03:30

--- E O F ---


3. Here is the Hijack this result................


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0:52:14, on 2007/08/05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\EMS Free Surfer Companion\fs30.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSecurity.exe
C:\Program Files\K7 Computing\Common\K7SysTry.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSMngr.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\K7 Computing\Common\K7EmlPxy.exe
C:\Program Files\K7 Computing\K7TSecurity\K7SysMon\K7SysMon.Exe
C:\Program Files\K7 Computing\K7TSecurity\K7FireWall\K7FWSrvc.exe
C:\Program Files\K7 Computing\K7TSecurity\K7Privacy\K7PSSrvc.exe
C:\Program Files\K7 Computing\K7TSecurity\K7AntiVirus\K7RTScan.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\夕香\デスクトップ\NOTEPAD.EXE
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
c:\program files\mcafee.com\shared\mcinfo.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [freesurfer] C:\Program Files\EMS Free Surfer Companion\fs30.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [K7TSStart] "C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSecurity.exe"
O4 - HKLM\..\Run: [K7SystemTray] "C:\Program Files\K7 Computing\Common\K7SysTry.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] ctfmon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] ctfmon.exe (User 'Default user')
O8 - Extra context menu item: Download with Go!Zilla - file://C:\Program Files\Go!Zilla\download-with-gozilla.html
O8 - Extra context menu item: JWordでウェブ検索(&J) - res://C:\WINDOWS\Downlo~1\CnsMin.dll/203
O8 - Extra context menu item: Super Mapple Digital - カスタム情報記入 - res://C:\PROGRA~1\SUPERM~1.5\MappleBand.dll/110
O8 - Extra context menu item: Super Mapple Digital - 住所検索 - res://C:\PROGRA~1\SUPERM~1.5\MappleBand.dll/109
O8 - Extra context menu item: Super Mapple Digital - 施設検索 - res://C:\PROGRA~1\SUPERM~1.5\MappleBand.dll/112
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun の Java コンソール - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: マップル - {381F73A9-29D0-45B6-88D7-F82C4BCED5D3} - C:\Program Files\Super Mapple Digital Ver.5\MappleBand.dll
O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sotec.co.jp/top.html
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/16b65c9aaf441e...tzip/RdxIE2.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1180736538788
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{02777462-5D98-40EC-B654-A9041CD93B97}: NameServer = 202.216.229.30 202.216.224.30
O17 - HKLM\System\CS1\Services\Tcpip\..\{02777462-5D98-40EC-B654-A9041CD93B97}: NameServer = 202.216.229.30 202.216.224.30
O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum.txt
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IomegaAccess - Iomega Corporation - C:\WINDOWS\system32\IomegaAccess.exe
O23 - Service: iPod サービス (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\Common\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7FireWall\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7Privacy\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7AntiVirus\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7AntiSpam\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSMngr.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: ZipToA - Iomega Corporation - C:\WINDOWS\system32\ZipToA.exe

--
End of file - 11706 bytes

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:08:10 PM

Posted 04 August 2007 - 12:57 PM

Download KillBox,unzip/extract it to your desktop.
http://download.bleepingcomputer.com/spyware/KillBox.exe
Start up Killbox and place a check in 'Delete on Reboot'.
In the 'Full path of file to delete' box,copy and paste:
C:\WINDOWS\system32\printer.exe
Then press the red button with the white cross.
It will then provide a window for you to confirm the delete.
Next it will ask if you now wish to reboot,select YES.
Allow it to reboot.
If it does'nt reboot automatically,reboot manually.

Copy and paste the following bold blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fix.reg to your desktop.
Then double click on the fix.reg file on your desktopPosted Imageand agree to merge the imformation into the registry,then restart your pc.

REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=-


Run 'BitDefender Online Scanner' using Internet Explorer:
http://www.bitdefender.com/scan8/ie.html
Read the 'END USER SOFTWARE LICENSE AGREEMENT' then click 'I agree'.
You'll be prompted to install the activex control,please do so.
Once installed,disable your current antivirus program,then click the 'Click here to scan' button.
The virus signatures will then load.
Once loaded the scan will start.
The scan will take quite some time so please be patient.
Once the scan has finished select the 'Detected Problems' tab.
Click on 'Click here to export scan'.
Save the file as an HTML file to your desktop.
Then click on the saved file and allow it to open with your browser.
Go to 'Edit'/'Select All' then copy and paste that log into your next reply.
*Note*
Don't forget to re-enable your antivirus program.

Also post a new Hijackthis log.
Posted Image
Posted Image

#9 MrNeedHelp

MrNeedHelp
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:10 PM

Posted 05 August 2007 - 12:36 PM

Aug 05 07

Dear Mr. Richie.


I followed the required steps.

I ran the Bitdefender Scan. It seemed to do it's job but I couldn't print a log on the screen as the program stopped or wouldn't respond when the scan was done.

So I wrote down here below what the information bitdefender program showed.........

Time: 2 H 24 Min

Objects: 148,000

Folders: 6601

Archives: 7168

Packed Files: 715

Bout Sectors: 4


Scan Result

identified Viruses: 4

Infected Files: 20

Suspect Files: 0

Warnings: 0

Disinfected Files: 0

Deleted Files: 20


" Viruses Were Detected But Were Removed " ( the program said )

Here Below Is the Hijack This new log...............................

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:21, on 2007-08-06
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\EMS Free Surfer Companion\fs30.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSecurity.exe
C:\Program Files\K7 Computing\Common\K7SysTry.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSMngr.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\K7 Computing\Common\K7EmlPxy.exe
C:\Program Files\K7 Computing\K7TSecurity\K7FireWall\K7FWSrvc.exe
C:\Program Files\K7 Computing\K7TSecurity\K7Privacy\K7PSSrvc.exe
C:\Program Files\K7 Computing\K7TSecurity\K7SysMon\K7SysMon.Exe
C:\Program Files\K7 Computing\K7TSecurity\K7AntiVirus\K7RTScan.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [freesurfer] C:\Program Files\EMS Free Surfer Companion\fs30.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [K7TSStart] "C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSecurity.exe"
O4 - HKLM\..\Run: [K7SystemTray] "C:\Program Files\K7 Computing\Common\K7SysTry.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] ctfmon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] ctfmon.exe (User 'Default user')
O8 - Extra context menu item: Download with Go!Zilla - file://C:\Program Files\Go!Zilla\download-with-gozilla.html
O8 - Extra context menu item: Get siteinfo data (fsc) - C:\Program Files\EMS Free Surfer Companion\fslauncher.htm
O8 - Extra context menu item: JWordでウェブ検索(&J) - res://C:\WINDOWS\Downlo~1\CnsMin.dll/203
O8 - Extra context menu item: Super Mapple Digital - カスタム情報記入 - res://C:\PROGRA~1\SUPERM~1.5\MappleBand.dll/110
O8 - Extra context menu item: Super Mapple Digital - 住所検索 - res://C:\PROGRA~1\SUPERM~1.5\MappleBand.dll/109
O8 - Extra context menu item: Super Mapple Digital - 施設検索 - res://C:\PROGRA~1\SUPERM~1.5\MappleBand.dll/112
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun の Java コンソール - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: マップル - {381F73A9-29D0-45B6-88D7-F82C4BCED5D3} - C:\Program Files\Super Mapple Digital Ver.5\MappleBand.dll
O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\EMS Free Surfer Companion\FS30.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\k7wslsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sotec.co.jp/top.html
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/16b65c9aaf441e...tzip/RdxIE2.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1180736538788
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum.txt
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IomegaAccess - Iomega Corporation - C:\WINDOWS\system32\IomegaAccess.exe
O23 - Service: iPod サービス (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: K7Computng - EMail Proxy Server (K7EmlPxy) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\Common\K7EmlPxy.exe
O23 - Service: K7Firewall Services (K7FWSrvc) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7FireWall\K7FWSrvc.exe
O23 - Service: K7Privacy Services (K7PSSrvc) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7Privacy\K7PSSrvc.exe
O23 - Service: K7RealTime AntiVirus Services (K7RTScan) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7AntiVirus\K7RTScan.exe
O23 - Service: K7SpmSrc - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\K7AntiSpam\K7SpmSrc.exe
O23 - Service: K7TotalSecurity Manager (K7TSMngr) - K7 Computing Pvt Ltd - C:\Program Files\K7 Computing\K7TSecurity\Common\K7TSMngr.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: ZipToA - Iomega Corporation - C:\WINDOWS\system32\ZipToA.exe

--
End of file - 11261 bytes


Thanks Again. Anyway I haven't seen any adware popups in the last 45 minutes so maybe all this works.

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:08:10 PM

Posted 05 August 2007 - 01:38 PM

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
R3 - Default URLSearchHook is missing
O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum.txt
----------------------------------------------

Your log is clean.
If all's ok,please do the following.

Find and delete:
Combofix.exe
SmitfraudFix
KillBox.exe
fix.reg

C:\!KillBox
C:\QOOBOX

Download ATF Cleaner by Atribune:
http://www.atribune.org/ccount/click.php?id=1

Double-click ATF-Cleaner.exe to run the program.
Click 'Select All' found at the bottom of the list.
Click the 'Empty Selected' button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

If you use Opera browser,do this also:
Click Opera at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

Click 'Exit' on the Main menu to close the program.

------------------------------------------------

Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u2'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java versions.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.

------------------------------------------------

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
'How to prevent Malware' by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html
Posted Image
Posted Image

#11 MrNeedHelp

MrNeedHelp
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:10 PM

Posted 06 August 2007 - 12:17 PM

:thumbsup:

Aug 06 07

Hello & Dear Mr. Richie.

My home computer seems to work normally since yesterday.

No annoying malware popups so far.

I did the latest requirements with new Java and so on.

I also installed the recommended SpywareBlaster and I checked my

McAfee settings and the firewall and so on.

All your fantastic support seems to have worked wonders.

I really appreciate this. People like you are the finest.

I will definitely consider to contribute some money to bleeping computers.

As I'm a Swedish-American living in Tokyo I'll refer your web site to people

over here.

Have a nice week.

Best regards from MrNeedHelp.

#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:08:10 PM

Posted 06 August 2007 - 01:17 PM

You're most welcome MrNeedHelp,glad to help out :thumbsup:

This thread will now be closed.
If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you.
Include the address of this thread in your request.
If you should have a new issue, please start a new topic.
This applies only to the original topic starter.
Everyone else please begin a New Topic.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users