Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected By Trojan.win32.bho.agz


  • Please log in to reply
7 replies to this topic

#1 ih8viruses

ih8viruses

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:58 AM

Posted 31 December 2007 - 04:00 PM

I scanned my computer using avast, kaspersky, ad-aware, spy-bot, mcafee stinger and deleted all of the cookies, temporary internet files etc.

I have tried to manually delete the file in normal and safe mode, as well as doing a start-up scan using avast, however; no matter which program I try or what I do, the file will not delete, avast and Kaspersky were not able to delete it either.


The error message received with Kaspersky is:

File containes trojan program and cannot be disinfected: write access is denied"

Trojan program: trojan.win.bho.agz

File: c:\windows|system32\catsrvp.dll

Here is HijackThis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:47:25 PM, on 12/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\AOL9~1.0\waol.exe
C:\PROGRA~1\AOL9~1.0\shellmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wpabaln.exe
C:\Program Files\Common Files\AOL\1198382247\ee\aolsoftware.exe
c:\program files\common files\aol\1198382247\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1198382247\ee\aolsoftware.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
c:\program files\common files\aol\1198382247\ee\anotify.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe"
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [Whus] "C:\PROGRA~1\COMMON~1\DOBE~1\smss.exe" -vt yazb
O4 - HKCU\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\PROGRA~1\AOL9~1.0\AOL.EXE" -b
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ED0D473-29B8-4770-9ACB-B2D268744F6F}: NameServer = 205.188.146.145
O17 - HKLM\System\CS1\Services\Tcpip\..\{4ED0D473-29B8-4770-9ACB-B2D268744F6F}: NameServer = 205.188.146.145
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows NT\profsycy.html

--
End of file - 3710 bytes

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:58 AM

Posted 01 January 2008 - 08:27 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum ih8viruses
My name is Richie and i'll be helping you to fix your problems.

Download SDFix.exe and save it to your desktop:
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

* Double click on SDFix on your desktop,and install the fix to C:\

Please then reboot your computer into Safe Mode by doing the following:

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.

* In Safe Mode,go to and open the C:\SDFix folder,then double click on RunThis.bat to start the script.
* Type Y to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt into your next reply.


If you have previously downloaded ComboFix,please delete that version now.
Warning
You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert.
It is intended by its creator to be used under the guidance and supervision of an expert,not for private use.
Using this tool incorrectly could render your system/pc inoperable.

Now download Combofix and save to your desktop:
Note
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.
Note
In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.
Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#3 ih8viruses

ih8viruses
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:58 AM

Posted 04 January 2008 - 07:23 AM

HiJackThis Report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:19:29 AM, on 1/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\AOL 9.0\waol.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wpabaln.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Common Files\AOL\1198382247\ee\aolsoftware.exe
c:\program files\common files\aol\1198382247\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1198382247\ee\aolsoftware.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
c:\program files\common files\aol\1198382247\ee\anotify.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {2535E920-20D8-4281-BBC0-047EF3F7725B} - C:\Program Files\MSN Gaming Zone\hoke83122.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: 0 - {9860CA66-2561-429E-D28B-74AE749ECBE6} - C:\Program Files\Windows NT\lavuna.dll (file missing)
O2 - BHO: (no name) - {C084B48B-3C33-4DDF-92AC-CE06493A506A} - C:\Program Files\MSN Gaming Zone\hoke4444.dll (file missing)
O2 - BHO: (no name) - {E1ACA06F-6988-4F28-DE2B-3FE675890CC2} - C:\WINDOWS\system32\cncstgom.dll (file missing)
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [Whus] "C:\PROGRA~1\COMMON~1\DOBE~1\smss.exe" -vt yazb
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4ED0D473-29B8-4770-9ACB-B2D268744F6F}: NameServer = 205.188.146.145
O17 - HKLM\System\CS1\Services\Tcpip\..\{4ED0D473-29B8-4770-9ACB-B2D268744F6F}: NameServer = 205.188.146.145
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: byxvtst - byxvtst.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows NT\profsycy.html

--
End of file - 4602 bytes

SDFix Report:


SDFix: Version 1.122

Run by Shannon on Wed 01/02/2008 at 07:46 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
core
Network Monitor
evqveopi

Path:
system32\drivers\core.sys
system32\drivers\gmmoegic.dat

core - Deleted
Network Monitor - Deleted
evqveopi - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...

Service evqveopi - Deleted after Reboot

Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\system32\drivers\gmmoegic.dat - Deleted
C:\PROGRA~1\WINDOW~1\PROFSY~1.HTM - Deleted
C:\PROGRA~1\WINDOW~1\LAVUNA - Deleted
C:\PROGRA~1\WINDOW~1\LAVUNA~1 - Deleted
C:\WINDOWS\SYSTEM32\CATSRVP.DLL - Deleted
C:\Program Files\Common Files\Yazzle1549OinAdmin.exe - Deleted
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe - Deleted
C:\DOCUME~1\Shannon\LOCALS~1\Temp\removalfile.bat - Deleted
C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\drivers\core.sys - Deleted
C:\WINDOWS\system32\pac.txt - Deleted



Folder C:\Program Files\Network Monitor - Removed
Folder C:\Program Files\Temporary - Removed
Folder C:\Program Files\WinAble - Removed
Folder C:\Temp\tn3 - Removed

Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-02 08:02:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

IPC error: 2 The system cannot find the file specified.
scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Application Loader"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe:*:Enabled:AOLTsMon"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe:*:Enabled:AOLTopSpeed"
"C:\\Program Files\\Common Files\\AOL\\1198382247\\EE\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1198382247\\EE\\AOLServiceHost.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"="C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe:*:Enabled:AOL"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\WINDOWS\\system32\\muzapp.exe"="C:\\WINDOWS\\system32\\muzapp.exe:*:Enabled:MUZ AOD APP player"
"C:\\Program Files\\Common Files\\AOL\\1198382247\\EE\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1198382247\\EE\\aolsoftware.exe:*:Enabled:AOL Services"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Fri 19 Nov 2004 54,872 A..H. --- "C:\Program Files\AOL 9.0\AOLphx.exe"
Fri 19 Nov 2004 31,832 A..H. --- "C:\Program Files\AOL 9.0\rbm.exe"
Thu 1 Nov 2007 230,400 ..SHR --- "C:\WINDOWS\?ystem32\n?pdb.exe"
Tue 25 Dec 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 25 Dec 2007 401 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv19.bak"
Sat 29 Dec 2007 707 A..H. --- "C:\Program Files\Common Files\AOL\IPHSend\IPH.BAK"
Sun 30 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0d4a7c846fe5e74c3056c3e240c1ffeb\BIT14.tmp"
Tue 25 Dec 2007 4,348 ...H. --- "C:\Documents and Settings\Shannon\My Documents\My Music\License Backup\drmv1key.bak"
Tue 25 Dec 2007 401 A..H. --- "C:\Documents and Settings\Shannon\My Documents\My Music\License Backup\drmv1lic.bak"
Tue 25 Dec 2007 312 ...H. --- "C:\Documents and Settings\Shannon\My Documents\My Music\License Backup\drmv2key.bak"
Tue 25 Dec 2007 1,536 A..H. --- "C:\Documents and Settings\Shannon\My Documents\My Music\License Backup\drmv2lic.bak"

Finished!

ComboFix Report:

ComboFix 08-01-02.1 - Shannon 2008-01-02 8:13:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.193 [GMT -5:00]
Running from: C:\Documents and Settings\Shannon\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\Documents and Settings\Shannon\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Shannon\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Shannon\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\Common Files\dobe~1
C:\Program Files\Common Files\dobe~1\?dobe\
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\WINDOWS\system32\aypqdahx.dll
C:\WINDOWS\system32\b1
C:\WINDOWS\system32\haqdbbob.dll
C:\WINDOWS\system32\kmllm.ini
C:\WINDOWS\system32\kmllm.ini2
C:\WINDOWS\system32\mllmk.dll
C:\WINDOWS\system32\mrnblyin.dll
C:\WINDOWS\system32\ovwaqwys.dll
C:\WINDOWS\system32\tsmstxql.dll
C:\WINDOWS\system32\wintsvcc.exe
C:\WINDOWS\ystem3~1
C:\WINDOWS\ystem3~1\n?pdb.exe
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2007-12-04 to 2008-01-04 )))))))))))))))))))))))))))))))
.

2008-01-02 08:11 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-02 07:42 . 2008-01-02 07:42 <DIR> d-------- C:\WINDOWS\ERUNT
2007-12-31 15:44 . 2007-12-31 15:44 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-31 12:43 . 2007-12-31 13:17 91,492 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-12-31 12:43 . 2007-12-31 13:17 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-12-31 12:41 . 2007-12-31 12:41 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-12-31 12:41 . 2008-01-04 07:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-31 12:40 . 2008-01-02 19:19 1,207,840 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-31 12:40 . 2008-01-02 23:03 105,760 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-31 12:40 . 2008-01-02 07:40 15,044 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-31 12:40 . 2008-01-02 07:40 10,436 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-31 12:28 . 2007-12-31 12:28 <DIR> d-------- C:\KAV
2007-12-31 03:28 . 2007-12-31 03:28 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-12-30 03:00 . 2008-01-01 03:00 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-12-30 03:00 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-12-29 18:14 . 2007-12-29 18:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pure Networks
2007-12-29 18:10 . 2007-12-29 18:10 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-12-25 15:38 . 2007-12-25 15:38 <DIR> d-------- C:\My Video
2007-12-25 15:37 . 2007-12-25 15:37 <DIR> d-------- C:\Program Files\XviD
2007-12-25 15:37 . 2007-12-25 15:37 <DIR> d-------- C:\Program Files\Lame MP3 Codec
2007-12-25 15:37 . 2002-12-03 22:13 1,048,576 --a------ C:\WINDOWS\system32\lameACM.acm
2007-12-25 15:37 . 2005-05-03 09:33 299,008 --a------ C:\WINDOWS\system32\LAME_MP3.dll
2007-12-25 15:37 . 2007-12-25 15:37 65,024 --a------ C:\WINDOWS\IFinst26.exe
2007-12-25 15:37 . 2004-12-10 21:29 401 --a------ C:\WINDOWS\system32\lame_acm.xml
2007-12-25 15:34 . 2007-12-25 15:34 <DIR> d-------- C:\Program Files\MarkAny
2007-12-25 15:34 . 2007-12-25 15:34 <DIR> d-------- C:\Documents and Settings\Shannon\Application Data\DataCast
2007-12-25 15:33 . 2007-12-25 15:33 <DIR> d-------- C:\Program Files\Samsung
2007-12-25 15:33 . 2002-10-05 08:04 921,600 --a------ C:\WINDOWS\system32\vorbisenc.dll
2007-12-25 15:31 . 2007-12-25 15:31 <DIR> d-------- C:\Documents and Settings\Shannon\Application Data\InstallShield
2007-12-25 14:12 . 2007-12-26 00:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-25 13:12 . 2007-12-25 13:12 <DIR> d-------- C:\Documents and Settings\Shannon\Application Data\Lavasoft
2007-12-25 13:05 . 2004-08-04 02:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2007-12-25 12:37 . 2008-01-04 07:10 51,279 --a------ C:\VETlog.dmp
2007-12-25 10:35 . 2003-03-18 15:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2007-12-25 10:34 . 2007-12-25 10:34 <DIR> d-------- C:\Program Files\Alwil Software
2007-12-25 05:51 . 2007-12-25 05:51 <DIR> d-------- C:\Program Files\mcafee.com
2007-12-25 03:58 . 2007-12-25 03:58 <DIR> d-------- C:\Documents and Settings\Shannon\Application Data\Viewpoint
2007-12-24 22:55 . 2007-12-25 15:15 <DIR> d-------- C:\Program Files\Google
2007-12-24 22:54 . 2007-12-24 22:54 <DIR> d-------- C:\WINDOWS\system32\to9
2007-12-24 22:54 . 2007-12-24 22:54 <DIR> d-------- C:\WINDOWS\system32\dj2
2007-12-24 22:54 . 2007-12-24 22:54 <DIR> d-------- C:\WINDOWS\system32\bbc9
2007-12-24 22:54 . 2007-12-24 22:54 <DIR> d-------- C:\WINDOWS\system32\ardCo02
2007-12-24 22:54 . 2008-01-02 07:41 <DIR> d--hs---- C:\WINDOWS\Q2Fzc2libw
2007-12-24 22:54 . 2008-01-02 08:02 <DIR> d-------- C:\Temp
2007-12-23 01:02 . 2007-12-25 14:28 <DIR> d---s---- C:\Documents and Settings\Shannon\UserData
2007-12-23 00:06 . 2007-12-23 00:06 <DIR> d-------- C:\Documents and Settings\Shannon\Contacts
2007-12-23 00:05 . 2007-12-23 00:05 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-23 00:02 . 2007-12-23 00:05 <DIR> d-------- C:\Program Files\MSN Messenger
2007-12-22 23:53 . 2007-12-22 23:53 <DIR> d-------- C:\Program Files\Common Files\Scanner
2007-12-22 23:00 . 2007-12-22 23:00 <DIR> d-------- C:\Program Files\Common Files\aolback
2007-12-22 23:00 . 2007-12-22 23:00 <DIR> d-------- C:\Documents and Settings\Shannon\Application Data\AOL
2007-12-22 23:00 . 2007-12-22 23:00 715 --a------ C:\WINDOWS\aolback.exe.lnk
2007-12-22 22:59 . 2007-12-22 22:59 <DIR> d-------- C:\Program Files\Common Files\Nullsoft
2007-12-22 22:59 . 2007-12-22 22:59 <DIR> d-------- C:\Install Winamp
2007-12-22 22:59 . 2007-12-22 22:59 <DIR> d-------- C:\Documents and Settings\Shannon\Application Data\You've Got Pictures Screensaver
2007-12-22 22:59 . 2007-12-22 23:00 <DIR> d-------- C:\aolextras
2007-12-22 22:59 . 2004-11-19 18:49 173,184 --a------ C:\WINDOWS\system32\ygpss.scr
2007-12-22 22:59 . 1999-11-10 14:05 86,016 --a------ C:\WINDOWS\unvise32qt.exe
2007-12-22 22:58 . 2007-12-22 22:58 <DIR> d-------- C:\Program Files\Viewpoint
2007-12-22 22:58 . 2007-12-22 22:58 <DIR> d-------- C:\Program Files\Real
2007-12-22 22:58 . 2007-12-22 22:59 <DIR> d-------- C:\Program Files\QuickTime
2007-12-22 22:58 . 2007-12-22 22:58 <DIR> d-------- C:\Program Files\Common Files\Real
2007-12-22 22:58 . 2007-12-25 13:30 <DIR> d-------- C:\Program Files\AOL Toolbar
2007-12-22 22:58 . 2007-12-25 03:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-22 22:58 . 2007-12-25 14:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2007-12-22 22:57 . 2007-12-23 14:04 <DIR> d-------- C:\Program Files\Common Files\aolshare
2007-12-22 22:57 . 2007-12-22 22:57 <DIR> d-------- C:\Program Files\AOL Deskbar
2007-12-22 22:57 . 2007-12-25 14:09 <DIR> d-------- C:\Program Files\AOL 9.0
2007-12-22 22:57 . 2007-12-22 23:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2007-12-22 22:57 . 2007-12-22 22:57 335 --a------ C:\WINDOWS\nsreg.dat
2007-12-22 22:56 . 2007-12-22 22:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-12-22 22:56 . 2003-02-03 11:24 298 -ra------ C:\WINDOWS\aeiset_a.iss
2007-12-22 22:55 . 2007-12-25 15:33 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2007-12-22 22:55 . 2007-12-22 22:55 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-12-22 22:55 . 2007-12-25 05:52 <DIR> d-------- C:\Program Files\Common Files\AOL
2007-12-22 22:55 . 2007-12-22 22:55 <DIR> d-------- C:\Program Files\Actiontec
2007-12-22 22:55 . 2002-11-07 21:29 86,016 --a------ C:\WINDOWS\aeirem.exe
2007-12-22 22:55 . 2002-09-18 15:29 50,236 --------- C:\WINDOWS\system32\drivers\VVBUSUSB.SYS
2007-12-22 22:55 . 2002-11-07 21:19 45,056 --a------ C:\WINDOWS\aeirmpca.exe
2007-12-22 22:55 . 2002-09-18 15:29 34,560 --------- C:\WINDOWS\system32\drivers\VVBETH.SYS
2007-12-22 22:55 . 2003-02-03 10:26 431 -ra------ C:\WINDOWS\aeiset_d.iss
2007-12-22 22:55 . 2002-10-28 18:58 196 --a------ C:\WINDOWS\aeirem.ini
2007-12-22 12:04 . 2004-08-03 18:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-12-22 12:04 . 2001-08-17 08:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-12-22 12:02 . 2004-08-03 19:56 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2007-12-22 12:00 . 2007-12-22 22:57 <DIR> dr------- C:\Documents and Settings\All Users\Documents

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-23 03:58 8,552 ----a-w C:\WINDOWS\system32\drivers\asctrm.sys
2007-12-23 01:45 --------- d-----w C:\Program Files\microsoft frontpage
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2535E920-20D8-4281-BBC0-047EF3F7725B}]
C:\Program Files\MSN Gaming Zone\hoke83122.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9860CA66-2561-429E-D28B-74AE749ECBE6}]
C:\Program Files\Windows NT\lavuna.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C084B48B-3C33-4DDF-92AC-CE06493A506A}]
C:\Program Files\MSN Gaming Zone\hoke4444.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1ACA06F-6988-4F28-DE2B-3FE675890CC2}]
C:\WINDOWS\system32\cncstgom.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Whus"="C:\PROGRA~1\COMMON~1\DOBE~1\smss.exe" [ ]
"AOL Fast Start"="C:\Program Files\AOL 9.0\AOL.exe" [2005-07-18 21:03 50776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSTray"="C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-02-23 16:32 126976]
"MAAgent"="C:\Program Files\MarkAny\ContentSafer\MAAgent.exe" [2007-01-30 20:36 57344]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-22 22:59 98304]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 12:51 218376]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\Windows NT\profsycy.html
FriendlyName=

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 16:51 192512]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxvtst]
byxvtst.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^msn_0712_upd242315.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\msn_0712_upd242315.exe
backup=C:\WINDOWS\pss\msn_0712_upd242315.exeCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
C:\Program Files\AOL 9.0\AOL.EXE -b

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLAspSunset2]
2007-12-23 00:00 53248 --a------ C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
2007-01-29 11:22 65536 -ra------ C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2006-09-25 19:52 50736 --a------ C:\Program Files\Common Files\AOL\1198382247\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.Exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rebx]
C:\WINDOWS\?ystem32\n?pdb.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
mgrs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)

R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\KIS7EN.EXE

.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-04 07:10:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-04 7:14:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-04 12:13:55
.
2008-01-01 08:02:28 --- E O F ---

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:58 AM

Posted 04 January 2008 - 10:34 AM

You have a Backdoor Trojan present on your pc
A Backdoor is a software program that gives an attacker unauthorized access to a machine and the means for remotely controlling the machine without the user's knowledge. A Backdoor compromises system integrity by making changes to the system that allow it to by used by the attacker for malicious purposes unknown to the user.

They are typically installed without user interaction through security exploits, and may allow an attacker to remotely control the infected machine. Such risks may allow the attacker to install additional malware and use the compromised machine to participate in denial of service attacks, spamming, and bot nets, or to transmit sensitive data to a remote server. The malware may be cloaked and not visible to the user. These risks severely compromise the system by lowering security settings, installing 'backdoors,' infecting system files, or spreading to other networked machines.

If your computer was used for online banking or has credit card information on it, all passwords should be changed immediately to include those used for email, eBay and forums.
You should consider them to be compromised.
They should be changed by using a different computer and not the infected one,if not an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breech.

Since your computer was compromised read:
How to report ID theft, fraud, drive-by installs, hijacking and malware:
http://www.dslreports.com/faq/10451

When Should I Format, How Should I Reinstall:
http://www.dslreports.com/faq/10063

Let me know how you wish to proceed in your next reply.
If you want to go ahead and clean up your system then carry on below.


Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\unvise32qt.exe
C:\WINDOWS\aeiset_a.iss
C:\WINDOWS\aeirem.exe
C:\WINDOWS\aeirmpca.exe
C:\WINDOWS\aeiset_d.iss
C:\WINDOWS\aeirem.ini
Folder::
C:\WINDOWS\system32\to9
C:\WINDOWS\system32\dj2
C:\WINDOWS\system32\bbc9
C:\WINDOWS\system32\ardCo02
C:\WINDOWS\Q2Fzc2libw
C:\Documents and Settings\Shannon\Application Data\Viewpoint
C:\Program Files\Viewpoint
C:\Documents and Settings\All Users\Application Data\Viewpoint
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2535E920-20D8-4281-BBC0-047EF3F7725B}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9860CA66-2561-429E-D28B-74AE749ECBE6}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C084B48B-3C33-4DDF-92AC-CE06493A506A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1ACA06F-6988-4F28-DE2B-3FE675890CC2}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Whus"=-
[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxvtst]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rebx]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image
Posted Image

#5 ih8viruses

ih8viruses
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:58 AM

Posted 04 January 2008 - 07:06 PM

ComboFix Report:

ComboFix 08-01-05.1 - Shannon 2008-01-04 18:54:52.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.166 [GMT -5:00]
Running from: C:\Documents and Settings\Shannon\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Shannon\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\aeirem.exe
C:\WINDOWS\aeirem.ini
C:\WINDOWS\aeirmpca.exe
C:\WINDOWS\aeiset_a.iss
C:\WINDOWS\aeiset_d.iss
C:\WINDOWS\unvise32qt.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\ComponentRegistry.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\DownLoadHist.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\HostRegistry.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\MetaStreamConfig.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\MTSDownloadSites.txt
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\URLCache.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\URLCache.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\-2002561595.mtj&p2=0&p3=14959360332012252582116805644694&p4=0
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\407034558.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\URLCache.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\URLCache.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\UpdateVersionList_v2.mtx
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\UserShell\AOL9\FLFBootStrap.mtx
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\UserShell\AOL9Plus\FLFBootStrap.mtx
C:\Documents and Settings\Shannon\Application Data\Viewpoint
C:\Documents and Settings\Shannon\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\URLCache.ini
C:\Documents and Settings\Shannon\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\URLCache.ini
C:\Documents and Settings\Shannon\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\URLCache.ini
C:\Documents and Settings\Shannon\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\1007280907.mtx
C:\Documents and Settings\Shannon\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\URLCache.ini
C:\Documents and Settings\Shannon\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\UpdateVersionList_v2.mtx
C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream_0305000D.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ClassIDs.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ComponentMgr_0305001C.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ComponentRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLArt.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLShell.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\Cursors.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\DataTracking.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\GifReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\LensFlares.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\ObjectMovie.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\ServiceComponent.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VectorView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPAudio.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPExtras.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\WaveletReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\ZoomView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\DownLoadHist.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\HostRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MetaStreamConfig.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.xpt
C:\Program Files\Viewpoint\Viewpoint Experience Technology\UserShell\AOL9Plus\FLFBootStrap.mtx
C:\WINDOWS\aeirem.exe
C:\WINDOWS\aeirem.ini
C:\WINDOWS\aeirmpca.exe
C:\WINDOWS\aeiset_a.iss
C:\WINDOWS\aeiset_d.iss
C:\WINDOWS\Q2Fzc2libw
C:\WINDOWS\system32\ardCo02
C:\WINDOWS\system32\ardCo02\ardCo021099.exe
C:\WINDOWS\system32\bbc9
C:\WINDOWS\system32\bbc9\xoppzwb91.exe
C:\WINDOWS\system32\dj2
C:\WINDOWS\system32\dj2\axebmbrpl6.exe
C:\WINDOWS\system32\to9
C:\WINDOWS\system32\to9\parreo83122.exe
C:\WINDOWS\unvise32qt.exe

.
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.

2008-01-04 18:36 . 2008-01-04 18:36 <DIR> d-------- C:\WINDOWS\LastGood
2008-01-04 18:33 . 2008-01-04 18:33 <DIR> d-------- C:\LXKZ600
2008-01-02 08:11 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-02 07:42 . 2008-01-02 07:42 <DIR> d-------- C:\WINDOWS\ERUNT
2007-12-31 15:44 . 2007-12-31 15:44 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-31 12:43 . 2007-12-31 13:17 91,492 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-12-31 12:43 . 2007-12-31 13:17 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-12-31 12:41 . 2007-12-31 12:41 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-12-31 12:41 . 2008-01-04 07:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-31 12:40 . 2008-01-05 18:57 1,275,936 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-31 12:40 . 2008-01-05 18:58 106,784 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-31 12:40 . 2008-01-02 07:40 15,044 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-31 12:40 . 2008-01-02 07:40 10,436 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-31 12:28 . 2007-12-31 12:28 <DIR> d-------- C:\KAV
2007-12-31 03:28 . 2007-12-31 03:28 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-12-30 03:00 . 2008-01-01 03:00 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-12-30 03:00 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-12-29 18:14 . 2007-12-29 18:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pure Networks
2007-12-29 18:10 . 2007-12-29 18:10 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-12-25 15:38 . 2007-12-25 15:38 <DIR> d-------- C:\My Video
2007-12-25 15:37 . 2007-12-25 15:37 <DIR> d-------- C:\Program Files\XviD
2007-12-25 15:37 . 2007-12-25 15:37 <DIR> d-------- C:\Program Files\Lame MP3 Codec
2007-12-25 15:37 . 2002-12-03 22:13 1,048,576 --a------ C:\WINDOWS\system32\lameACM.acm
2007-12-25 15:37 . 2005-05-03 09:33 299,008 --a------ C:\WINDOWS\system32\LAME_MP3.dll
2007-12-25 15:37 . 2007-12-25 15:37 65,024 --a------ C:\WINDOWS\IFinst26.exe
2007-12-25 15:37 . 2004-12-10 21:29 401 --a------ C:\WINDOWS\system32\lame_acm.xml
2007-12-25 15:34 . 2007-12-25 15:34 <DIR> d-------- C:\Program Files\MarkAny
2007-12-25 15:34 . 2007-12-25 15:34 <DIR> d-------- C:\Documents and Settings\Shannon\Application Data\DataCast
2007-12-25 15:33 . 2007-12-25 15:33 <DIR> d-------- C:\Program Files\Samsung
2007-12-25 15:33 . 2002-10-05 08:04 921,600 --a------ C:\WINDOWS\system32\vorbisenc.dll
2007-12-25 15:31 . 2007-12-25 15:31 <DIR> d-------- C:\Documents and Settings\Shannon\Application Data\InstallShield
2007-12-25 14:12 . 2007-12-26 00:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-25 13:12 . 2007-12-25 13:12 <DIR> d-------- C:\Documents and Settings\Shannon\Application Data\Lavasoft
2007-12-25 13:05 . 2004-08-04 02:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2007-12-25 12:37 . 2008-01-04 07:10 51,279 --a------ C:\VETlog.dmp
2007-12-25 10:35 . 2003-03-18 15:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2007-12-25 10:34 . 2007-12-25 10:34 <DIR> d-------- C:\Program Files\Alwil Software
2007-12-25 05:51 . 2007-12-25 05:51 <DIR> d-------- C:\Program Files\mcafee.com
2007-12-24 22:55 . 2007-12-25 15:15 <DIR> d-------- C:\Program Files\Google
2007-12-24 22:54 . 2008-01-02 08:02 <DIR> d-------- C:\Temp
2007-12-23 01:02 . 2007-12-25 14:28 <DIR> d---s---- C:\Documents and Settings\Shannon\UserData
2007-12-23 00:06 . 2007-12-23 00:06 <DIR> d-------- C:\Documents and Settings\Shannon\Contacts
2007-12-23 00:05 . 2007-12-23 00:05 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-23 00:02 . 2007-12-23 00:05 <DIR> d-------- C:\Program Files\MSN Messenger
2007-12-22 23:53 . 2007-12-22 23:53 <DIR> d-------- C:\Program Files\Common Files\Scanner
2007-12-22 23:00 . 2007-12-22 23:00 <DIR> d-------- C:\Program Files\Common Files\aolback
2007-12-22 23:00 . 2007-12-22 23:00 <DIR> d-------- C:\Documents and Settings\Shannon\Application Data\AOL
2007-12-22 23:00 . 2007-12-22 23:00 715 --a------ C:\WINDOWS\aolback.exe.lnk
2007-12-22 22:59 . 2007-12-22 22:59 <DIR> d-------- C:\Program Files\Common Files\Nullsoft
2007-12-22 22:59 . 2007-12-22 22:59 <DIR> d-------- C:\Install Winamp
2007-12-22 22:59 . 2007-12-22 22:59 <DIR> d-------- C:\Documents and Settings\Shannon\Application Data\You've Got Pictures Screensaver
2007-12-22 22:59 . 2007-12-22 23:00 <DIR> d-------- C:\aolextras
2007-12-22 22:59 . 2004-11-19 18:49 173,184 --a------ C:\WINDOWS\system32\ygpss.scr
2007-12-22 22:58 . 2007-12-22 22:58 <DIR> d-------- C:\Program Files\Real
2007-12-22 22:58 . 2007-12-22 22:59 <DIR> d-------- C:\Program Files\QuickTime
2007-12-22 22:58 . 2007-12-22 22:58 <DIR> d-------- C:\Program Files\Common Files\Real
2007-12-22 22:58 . 2007-12-25 13:30 <DIR> d-------- C:\Program Files\AOL Toolbar
2007-12-22 22:58 . 2007-12-25 14:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2007-12-22 22:57 . 2007-12-23 14:04 <DIR> d-------- C:\Program Files\Common Files\aolshare
2007-12-22 22:57 . 2007-12-22 22:57 <DIR> d-------- C:\Program Files\AOL Deskbar
2007-12-22 22:57 . 2007-12-25 14:09 <DIR> d-------- C:\Program Files\AOL 9.0
2007-12-22 22:57 . 2007-12-22 23:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2007-12-22 22:57 . 2007-12-22 22:57 335 --a------ C:\WINDOWS\nsreg.dat
2007-12-22 22:56 . 2007-12-22 22:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-12-22 22:55 . 2007-12-25 15:33 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2007-12-22 22:55 . 2007-12-22 22:55 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-12-22 22:55 . 2007-12-25 05:52 <DIR> d-------- C:\Program Files\Common Files\AOL
2007-12-22 22:55 . 2007-12-22 22:55 <DIR> d-------- C:\Program Files\Actiontec
2007-12-22 22:55 . 2002-09-18 15:29 50,236 --------- C:\WINDOWS\system32\drivers\VVBUSUSB.SYS
2007-12-22 22:55 . 2002-09-18 15:29 34,560 --------- C:\WINDOWS\system32\drivers\VVBETH.SYS
2007-12-22 12:04 . 2004-08-03 18:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-12-22 12:04 . 2001-08-17 08:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-12-22 12:02 . 2004-08-03 19:56 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2007-12-22 12:00 . 2007-12-22 22:57 <DIR> dr------- C:\Documents and Settings\All Users\Documents

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-23 03:58 8,552 ----a-w C:\WINDOWS\system32\drivers\asctrm.sys
2007-12-23 01:45 --------- d-----w C:\Program Files\microsoft frontpage
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 22:39 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
.

((((((((((((((((((((((((((((( snapshot@2008-01-04_ 7.12.24.95 )))))))))))))))))))))))))))))))))))))))))
.
+ 2003-03-25 07:47:00 31,744 ----a-w C:\WINDOWS\LastGood\System32\spool\DRIVERS\W32X86\lexmark_z600_series73d8\LXBCSLM.dll
+ 2003-03-25 07:47:00 31,744 ----a-w C:\WINDOWS\system32\LXBCSLM.DLL
+ 2003-03-25 07:47:00 365,568 ----a-w C:\WINDOWS\system32\LXBCSUI.DLL
+ 2003-03-25 07:34:00 1,442,816 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBCCLR1.DLL
+ 2003-03-25 07:34:00 1,442,816 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBCCLR2.DLL
+ 2003-03-25 07:34:00 1,442,816 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBCCLR3.DLL
+ 2003-03-25 07:34:00 129,536 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBCFCIC.DLL
+ 2003-03-25 07:34:00 296,448 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBCSDIC.DLL
+ 2003-03-25 07:47:00 31,744 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBCSLM.DLL
+ 2003-03-25 07:47:00 35,840 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBCSRDR.DLL
+ 2003-03-25 07:47:00 4,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBCSRES.DLL
+ 2003-03-25 07:47:00 365,568 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBCSUI.DLL
+ 2004-08-04 05:56:48 264,704 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIDRV.DLL
+ 2004-08-04 05:56:48 197,120 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIDRVUI.DLL
+ 2004-08-04 05:56:36 619,520 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\UNIRES.DLL
+ 2003-03-25 07:34:00 1,442,816 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_z600_series73d8\LXBCCLR1.DLL
+ 2003-03-25 07:34:00 1,442,816 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_z600_series73d8\LXBCCLR2.DLL
+ 2003-03-25 07:34:00 1,442,816 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_z600_series73d8\LXBCCLR3.DLL
+ 2003-03-25 07:34:00 129,536 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_z600_series73d8\LXBCFCIC.DLL
+ 2003-03-25 07:34:00 296,448 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_z600_series73d8\LXBCSDIC.DLL
+ 2003-03-25 07:47:00 31,744 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_z600_series73d8\LXBCSLM.dll
+ 2003-03-25 07:47:00 35,840 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_z600_series73d8\LXBCSRDR.DLL
+ 2003-03-25 07:47:00 4,608 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_z600_series73d8\LXBCSRES.DLL
+ 2003-03-25 07:47:00 365,568 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_z600_series73d8\LXBCSUI.DLL
+ 2004-08-04 05:56:48 264,704 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_z600_series73d8\UNIDRV.DLL
+ 2004-08-04 05:56:48 197,120 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_z600_series73d8\UNIDRVUI.DLL
+ 2004-08-04 05:56:36 619,520 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\lexmark_z600_series73d8\UNIRES.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="C:\Program Files\AOL 9.0\AOL.exe" [2005-07-18 21:03 50776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSTray"="C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-02-23 16:32 126976]
"MAAgent"="C:\Program Files\MarkAny\ContentSafer\MAAgent.exe" [2007-01-30 20:36 57344]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-22 22:59 98304]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 12:51 218376]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^msn_0712_upd242315.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\msn_0712_upd242315.exe
backup=C:\WINDOWS\pss\msn_0712_upd242315.exeCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
--a------ 2005-07-18 21:03 50776 C:\Program Files\AOL 9.0\AOL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLAspSunset2]
--a------ 2007-12-23 00:00 53248 C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2007-01-29 11:22 65536 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-09-25 19:52 50736 C:\Program Files\Common Files\AOL\1198382247\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 15:54 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-22 22:59 98304 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2007-12-22 22:58 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)

R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\KIS7EN.EXE

*Newly Created Service* - ATWPKT2
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-05 18:58:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-05 19:00:10
ComboFix-quarantined-files.txt 2008-01-05 23:59:50
ComboFix2.txt 2008-01-04 12:14:12
.
2008-01-01 08:02:28 --- E O F ---

HijackThis Report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:01:52 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wpabaln.exe
C:\Program Files\Common Files\AOL\1198382247\ee\aolsoftware.exe
c:\program files\common files\aol\1198382247\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1198382247\ee\aolsoftware.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe

--
End of file - 3202 bytes

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:58 AM

Posted 04 January 2008 - 07:15 PM

Click on Start/Run,copy and paste ComboFix /u into the 'Open:' space,then press Ok.

Posted Image

Please download OTMoveIt by OldTimer:
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Click on the 'Cleanup' button Posted Image
When you do this a text file named cleanup.txt will be downloaded from the internet.
If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so.
When the 'Confirm' box appears click 'Yes'.
Restart your pc when prompted.

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.


Download ATF Cleaner by Atribune:
http://www.atribune.org/ccount/click.php?id=1
Do not run it just yet.

Download\install 'SuperAntiSpyware Home Edition Free Version' from here:
http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.
Once the updates have been installed,exit SuperAntiSpyware.
Do not run it just yet.

Now double-click ATF-Cleaner.exe to run the program.
Click 'Select All' found at the bottom of the list.
Click the 'Empty Selected' button.

If you use Firefox browser, do this also:
Click Firefox at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.

If you use Opera browser,do this also:
Click Opera at the top and choose 'Select All' from the list.
Click the 'Empty Selected' button.
NOTE:
If you would like to keep your saved passwords,please click 'No' at the prompt.
Click 'Exit' on the Main menu to close the program.

Now Start SuperAntiSpyware.
On the main screen click on 'Scan your computer'.
Check: 'Perform Complete Scan'.
Click 'Next' to start the scan.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.
Make sure everything found has a checkmark next to it,then press 'Next'.
Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.

Posted Image
Posted Image

#7 ih8viruses

ih8viruses
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:58 AM

Posted 07 January 2008 - 05:09 PM

Here are the SuperAntiSpyware and HiJackThis Logs. I was able to perform all but 2 of the steps you had listed. I was not able to create a system restore point, nor was I able to run the Combofix /u, and still am unable to do either. I'm not sure if this is from this same problem, or if there is another underlying problem.


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/08/2008 at 08:49 AM

Application Version : 3.9.1008

Core Rules Database Version : 3259
Trace Rules Database Version: 1270

Scan type : Complete Scan
Total Scan Time : 01:12:28

Memory items scanned : 386
Memory threats detected : 0
Registry items scanned : 3470
Registry threats detected : 0
File items scanned : 32458
File threats detected : 83

Adware.Tracking Cookie
C:\Documents and Settings\Shannon\Cookies\shannon@image.masterstats[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@fastclick[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@atdmt[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@ads.pointroll[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@ads.monster[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@ads.ak.facebook[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@server.iad.liveperson[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@burstnet[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@ads4.blastro[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@url[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@service.tremormedia[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@tacoda[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@lynxtrack[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@adsby.zwoops[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@adinterax[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@windowsmedia[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@atwola[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@html[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@server.cpmstar[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@clicks.smartbizsearch[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@consumergain[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@mediamgr.ugo[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@1069679624[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@doubleclick[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@clicksor[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@media.adrevolver[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@aff.primaryads[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@da-tracking[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@toplist[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@adbrite[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@mediatraffic[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@realmedia[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@adrevolver[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@cgi-bin[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@ad[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@azjmp[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@sales.liveperson[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@collective-media[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@www.burstbeacon[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@tribalfusion[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@videoegg.adbureau[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@eas.apm.emediate[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@adserver[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@70062990[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@m2omedia[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@advertising[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@ad.zanox[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@ig[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@spamblockerutility[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@ads.engineseeker[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@2o7[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@partners.tattomedia[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@ad.outerinfoads[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@richmedia.yahoo[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@ads3.blastro[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@publishers.clickbooth[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@socialmedia[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@msnportal.112.2o7[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@112.2o7[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@go[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@questionmarket[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@banner.tattomedia[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@jamster[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@ottawasenators.112.2o7[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@specificclick[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@anad.tacoda[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@phpmv2[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@ads.diet[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@adopt.specificclick[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@eztracks.aavalue[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@adcentriconline[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@adopt.euroclick[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@mediaplex[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@overture[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@jandersencorp.112.2o7[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@adrevolver[1].txt
C:\Documents and Settings\Shannon\Cookies\shannon@statcounter[2].txt
C:\Documents and Settings\Shannon\Cookies\shannon@statse.webtrendslive[1].txt

Unclassified.SpywareBot (Not A Threat)
C:\DOCUMENTS AND SETTINGS\SHANNON\DESKTOP\SPYBOT\SETUP.EXE

Trojan.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{5A7FD88B-1B3E-466F-9B5D-3D1A3F31A8BA}\RP15\A0003596.VBS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{5A7FD88B-1B3E-466F-9B5D-3D1A3F31A8BA}\RP17\A0003665.EXE

Adware.WebBuying Assistant-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{5A7FD88B-1B3E-466F-9B5D-3D1A3F31A8BA}\RP17\A0003684.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{5A7FD88B-1B3E-466F-9B5D-3D1A3F31A8BA}\RP19\A0004787.EXE

HiJackThis Report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:03:19 PM, on 1/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AOL 9.0a\waol.exe
C:\Program Files\Common Files\AOL\1198382247\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AOL 9.0a\shellmon.exe
c:\program files\common files\aol\1198382247\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1198382247\ee\aolsoftware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wpabaln.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0a\AOL.EXE" -b
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe

--
End of file - 3127 bytes

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:07:58 AM

Posted 07 January 2008 - 06:45 PM

Your log is clean,please do the following:

Clear your 'System Restore' points by doing the following:
Right-click on 'My Computer' and select 'Properties'.
Select 'System Restore'.
Select 'Turn Off System Restore On All Drives'.
Select 'Apply'.
You will then get the following warning:
"You have chosen to turn off System Restore.
If you continue,all existing restore points will be deleted,and you will not be able to track or undo changes to your computer.
Do you want to turn off System Restore?".
Then select 'Yes',your 'System Restore' directories will be purged.

Restart your pc.

Turn 'System Restore' back on:

Right click on 'My Computer' and select 'Properties'.
Select 'System Restore'.
Unselect 'Turn Off System Restore On All Drives'.
Select 'Apply',then click 'Ok'.

You should take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:

Simple and easy ways to keep your computer safe and secure on the Internet:
http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/

How to prevent Malware:
http://users.telenet.be/bluepatchy/miekiem...prevention.html

So how did I get infected in the first place:
http://forums.spybot.info/showthread.php?t=279

Malware Cleanup Programs and Preventative Procedures:
http://russelltexas.com/malware/allclear.htm
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users