Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected With Fccddebt.dll


  • This topic is locked This topic is locked
11 replies to this topic

#1 Lanny25

Lanny25

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:04:05 AM

Posted 10 June 2008 - 09:59 AM

I have been infected with fccddeBt.dll.I have Norton 360 but I have disabled it and am using AVG.Please help me out of this problem.Here is my HJT Log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:25:11 PM, on 10-Jun-08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\System32\svchost.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\PROGRA~1\AVG\AVG8\avgam.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgfws8.exe
D:\Program Files\AVG\AVG8\avgtray.exe
D:\WINDOWS\system32\ctfmon.exe
D:\PROGRA~1\AVG\AVG8\avgnsx.exe
D:\Program Files\Opera 9\Opera.exe
D:\HJT\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - D:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - D:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53523F4E-78CF-499E-BD31-EC0E26BAFC7C} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - D:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - D:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - D:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A0B4FFEA-D466-49A8-9BB0-B7BBD2FCB449} - D:\WINDOWS\system32\fccddeBt.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - D:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - D:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - D:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "D:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [HP Software Update] "D:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "D:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - S-1-5-18 Startup: KeyboardManager.lnk = D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: RTLCPL.lnk = D:\Program Files\Realtek\InstallShield\RTLCPL.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: KeyboardManager.lnk = D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe (User 'Default user')
O4 - .DEFAULT Startup: RTLCPL.lnk = D:\Program Files\Realtek\InstallShield\RTLCPL.exe (User 'Default user')
O4 - Startup: KeyboardManager.lnk = D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe
O4 - Startup: RTLCPL.lnk = D:\Program Files\Realtek\InstallShield\RTLCPL.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = D:\Program Files\RALINK\Common\RaUI.exe
O4 - Global Startup: Run Google Web Accelerator.lnk = D:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
O8 - Extra context menu item: &Download by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - D:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - D:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Student Service (STUDSRV) - Unknown owner - D:\Program Files\Radix\SmartClass\GATESRV.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - D:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 8591 bytes
:thumbsup:

BC AdBot (Login to Remove)

 


m

#2 Baabiouz

Baabiouz

    Finnish Malware Fighter


  • Members
  • 3,355 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:05 PM

Posted 10 June 2008 - 11:15 AM

Hello Lanny25

I will be handling your log to help you get cleaned up. Please give me some time to look it over and I will get back to you as soon as possible. I'm in Hijackthis school and Teachers will check my posts.
Posted Image

#3 Baabiouz

Baabiouz

    Finnish Malware Fighter


  • Members
  • 3,355 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:05 PM

Posted 10 June 2008 - 09:33 PM

Hello

Step #1
Looks you have two internet security programs running at the same time, AVG 8 and Symantec. Please remove either now.

It's recommend to use only one firewall and one antivirus.

Step #2
You have the program Spybot S&D (Teatimer option) running on your machine and that is good. But prior to doing the fix below with Combofix it needs to be turned off. Please do the following:
  • Right click the running icon of Spybot's Teatimer, and choose Exit.
Step #3
Download Combofix from any of the links below, and save it to your desktop. For information regarding this download, please visit this webpage: http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall


Step #4
Please post Combofix log and a fresh HijackThis log back here :thumbsup:
Posted Image

#4 Lanny25

Lanny25
  • Topic Starter

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:04:05 AM

Posted 11 June 2008 - 10:24 AM

Hello Baabiouz.Thanks for an early reply. :thumbup2: :thumbsup: :) I would like to tell you that before I could run Combofix, AVG detected fccddebt.dll as a trojan and sent it to it's Virus vault.Please check my HJT log again to see if I have been disinfected or not and also for that you can give me new and accurate diagnosis according to the change.
Here it is

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:53:38 PM, on 11-Jun-08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\PROGRA~1\AVG\AVG8\avgfws8.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\HP\HP Software Update\HPWuSchd.exe
D:\PROGRA~1\AVG\AVG8\avgam.exe
D:\Program Files\HP\hpcoretech\hpcmpmgr.exe
D:\PROGRA~1\AVG\AVG8\avgtray.exe
D:\WINDOWS\system32\ctfmon.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
D:\PROGRA~1\AVG\AVG8\avgnsx.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\RALINK\Common\RaUI.exe
D:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe
D:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Windows Live\Contacts\wlcomm.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Windows Live\Messenger\usnsvc.exe
D:\Program Files\Opera 9\Opera.exe
D:\HJT\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - D:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - D:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53523F4E-78CF-499E-BD31-EC0E26BAFC7C} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - D:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A0B4FFEA-D466-49A8-9BB0-B7BBD2FCB449} - D:\WINDOWS\system32\fccddeBt.dll (file missing)
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - D:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - D:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HP Software Update] "D:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "D:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [MSConfig] D:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunOnce: [LHTTSFRF] RunDll32 advpack.dll,LaunchINFSection D:\WINDOWS\INF\LHTTSFRF.inf, RemoveCabinet
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - S-1-5-18 Startup: KeyboardManager.lnk = D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: RTLCPL.lnk = D:\Program Files\Realtek\InstallShield\RTLCPL.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: KeyboardManager.lnk = D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe (User 'Default user')
O4 - .DEFAULT Startup: RTLCPL.lnk = D:\Program Files\Realtek\InstallShield\RTLCPL.exe (User 'Default user')
O4 - Startup: KeyboardManager.lnk = D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe
O4 - Startup: RTLCPL.lnk = D:\Program Files\Realtek\InstallShield\RTLCPL.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = D:\Program Files\RALINK\Common\RaUI.exe
O4 - Global Startup: Run Google Web Accelerator.lnk = D:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
O8 - Extra context menu item: &Download by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Student Service (STUDSRV) - Unknown owner - D:\Program Files\Radix\SmartClass\GATESRV.exe (file missing)

--
End of file - 7681 bytes

#5 Baabiouz

Baabiouz

    Finnish Malware Fighter


  • Members
  • 3,355 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:05 PM

Posted 11 June 2008 - 10:37 AM

Hello Lanny25.
There may be more bad files like fccddeBt.dll so please run Combofix :thumbsup:
Posted Image

#6 Lanny25

Lanny25
  • Topic Starter

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:04:05 AM

Posted 11 June 2008 - 11:13 AM

Hello Baabiouz.Here is my Combofix Log

ComboFix 08-06-10.5 - Tanya 2008-06-11 21:30:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.495 [GMT 5.5:30]
Running from: D:\Documents and Settings\Tanya\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-05-11 to 2008-06-11 )))))))))))))))))))))))))))))))
.

2008-06-11 20:29 . 2008-06-11 20:29 <DIR> d--h----- D:\$AVG8.VAULT$
2008-06-10 20:20 . 2008-06-11 20:53 <DIR> d-------- D:\HJT
2008-06-10 20:02 . 2008-06-10 20:02 75,272 --a------ D:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-10 20:02 . 2008-06-10 20:02 12,424 --a------ D:\WINDOWS\system32\drivers\avgrkx86.sys
2008-06-10 20:02 . 2008-06-10 20:02 10,520 --a------ D:\WINDOWS\system32\avgrsstx.dll
2008-06-10 20:01 . 2008-06-11 20:22 <DIR> d-------- D:\WINDOWS\system32\drivers\Avg
2008-06-10 20:01 . 2008-06-10 20:01 96,520 --a------ D:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-10 19:49 . 2008-06-10 19:54 <DIR> d-------- D:\VundoFix Backups
2008-06-10 19:38 . 2008-06-10 19:38 <DIR> d-------- D:\Program Files\AVG
2008-06-10 19:38 . 2008-06-10 19:38 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\avg8
2008-06-10 19:38 . 2008-06-10 19:38 45,568 --a------ D:\WINDOWS\system32\avgfwdx.dll
2008-06-10 19:38 . 2008-06-10 19:38 22,528 --a------ D:\WINDOWS\system32\drivers\avgfwdx.sys
2008-06-10 19:36 . 2008-06-10 19:58 344 --ahs---- D:\WINDOWS\system32\JQqtBcfe.ini
2008-06-08 12:26 . 2008-06-11 20:45 <DIR> d-------- D:\Documents and Settings\Tanya\Tracing
2008-06-08 12:24 . 2008-06-08 12:24 <DIR> d-------- D:\Program Files\Windows Live
2008-06-08 11:08 . 2008-06-08 11:08 <DIR> d-------- D:\Program Files\Overland
2008-06-08 11:08 . 2008-06-08 11:08 208 --a------ D:\WINDOWS\HpBestModeUpdatePatchLog.ini
2008-06-08 11:08 . 2008-06-08 11:08 206 --a------ D:\WINDOWS\HPGdiPlus.ini
2008-06-08 11:00 . 2008-06-08 11:00 214 --a------ D:\WINDOWS\HP_48BitScanUpdatePatch.ini
2008-06-06 19:06 . 2008-06-06 19:06 <DIR> d-------- D:\Program Files\Common Files\HP
2008-06-06 19:05 . 2008-06-06 19:05 <DIR> d-------- D:\WINDOWS\system32\URTTEMP
2008-06-06 18:58 . 2004-01-05 19:59 38,782 --------- D:\WINDOWS\hpomdl03.dat.temp
2008-06-06 18:58 . 2008-03-13 19:47 29,405 --------- D:\WINDOWS\hpoins03.dat.temp
2008-06-02 16:33 . 2008-06-02 16:33 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-02 16:33 . 2008-06-06 17:30 54,156 --ah----- D:\WINDOWS\QTFont.qfn
2008-06-02 16:33 . 2008-06-02 16:33 1,409 --a------ D:\WINDOWS\QTFont.for
2008-06-02 15:58 . 2008-06-02 16:29 <DIR> d--h----- D:\Program Files\Zero G Registry
2008-06-02 15:58 . 2008-06-02 16:33 <DIR> d-------- D:\Program Files\Britannica 7.0
2008-06-02 15:58 . 2008-06-02 15:58 <DIR> d--h----- D:\Documents and Settings\Tanya\InstallAnywhere
2008-05-29 18:51 . 2008-05-29 18:51 <DIR> d-------- D:\Program Files\MathType
2008-05-29 18:51 . 2008-05-29 18:51 <DIR> d-------- D:\Documents and Settings\Tanya\Application Data\Design Science
2008-05-27 15:32 . 2008-05-27 16:48 <DIR> d-------- D:\Documents and Settings\Tanya\Application Data\Symantec
2008-05-26 19:17 . 2008-06-10 20:02 <DIR> d-------- D:\Documents and Settings\Administrator
2008-05-26 15:12 . 2008-05-26 15:12 <DIR> d-------- D:\Program Files\TVAnts
2008-05-26 15:11 . 2008-05-26 15:12 <DIR> d-------- D:\WINDOWS\uninstall\Satellite TV for PC Elite
2008-05-26 15:11 . 2008-05-26 15:11 <DIR> d-------- D:\WINDOWS\uninstall
2008-05-26 15:11 . 2008-05-26 15:11 <DIR> d-------- D:\Program Files\SatelliteTVforPC
2008-05-25 16:12 . 2008-05-25 16:12 <DIR> d-------- D:\Program Files\Microsoft Silverlight
2008-05-22 20:32 . 2008-05-22 20:32 <DIR> d--h----- D:\WINDOWS\PIF
2008-05-21 18:42 . 2008-05-21 18:42 <DIR> d-------- D:\Program Files\QuickTime
2008-05-21 18:42 . 2008-05-21 18:42 <DIR> d-------- D:\Program Files\ImTOO
2008-05-18 16:28 . 2008-05-18 16:29 <DIR> d-------- D:\Program Files\OpenAL
2008-05-18 16:28 . 2008-05-18 16:28 409,600 --a------ D:\WINDOWS\system32\wrap_oal.dll
2008-05-18 16:28 . 2008-05-18 16:28 114,688 --a------ D:\WINDOWS\system32\OpenAL32.dll
2008-05-18 16:26 . 2008-05-18 16:26 <DIR> d-------- D:\Program Files\Penumbra
2008-05-18 14:22 . 2008-05-18 14:22 <DIR> d-------- D:\Program Files\Common Files\Wise Installation Wizard
2008-05-18 14:21 . 2008-05-18 14:32 <DIR> d-------- D:\Program Files\DFX
2008-05-18 14:21 . 2008-05-18 14:22 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\DFX
2008-05-18 14:11 . 2008-05-18 14:21 <DIR> d-------- D:\Program Files\Winamp
2008-05-18 14:11 . 2008-05-18 14:36 <DIR> d-------- D:\Documents and Settings\Tanya\Application Data\Winamp
2008-05-13 17:53 . 2008-06-11 20:37 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Symantec
2008-05-13 17:52 . 2008-06-11 20:37 <DIR> d-------- D:\Program Files\Common Files\Symantec Shared

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-10 12:20 --------- d-----w D:\Documents and Settings\Tanya\Application Data\Orbit
2008-06-10 12:00 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-06 13:39 --------- d-----w D:\Program Files\HP
2008-05-30 11:24 --------- d-----w D:\Program Files\Comodo
2008-05-30 11:24 --------- d-----w D:\Documents and Settings\Tanya\Application Data\Comodo
2008-05-29 11:11 --------- d-----w D:\Documents and Settings\All Users\Application Data\Comodo
2008-05-26 13:45 --------- d-----w D:\Documents and Settings\Tanya\Application Data\uTorrent
2008-05-26 10:08 --------- d-----w D:\Documents and Settings\Tanya\Application Data\StumbleUpon
2008-05-21 13:19 --------- d-----w D:\Program Files\Total Video Converter
2008-05-13 11:49 --------- d-----w D:\Program Files\GlobalMapper9
2008-05-07 00:58 --------- d-----w D:\Program Files\Rapid-USD NoCaptcha -Th3zone.com Sep2007
2008-04-30 13:22 --------- d-----w D:\Documents and Settings\Tanya\Application Data\DivX
2008-04-20 12:43 --------- d-----w D:\Program Files\Free Music Zilla
2008-04-19 12:27 --------- d-----w D:\Program Files\DivX
2008-04-19 11:43 --------- d-----w D:\Program Files\Full Speed
2008-04-15 05:41 73,216 ----a-w D:\WINDOWS\ST6UNST.EXE
2008-04-15 05:41 311,296 ------w D:\WINDOWS\Setup1.exe
2008-04-13 12:26 --------- d-----w D:\Program Files\APOD
2008-04-13 05:35 --------- d-----w D:\Program Files\Cute Translator
2008-04-11 15:42 --------- d-----w D:\Program Files\Illustrate
2008-04-11 15:37 --------- d-----w D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-11 15:36 --------- d-----w D:\Program Files\Spybot - Search & Destroy
2008-04-11 07:50 --------- d-----w D:\Program Files\Power MP3 WMA Converter
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53523F4E-78CF-499E-BD31-EC0E26BAFC7C}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A0B4FFEA-D466-49A8-9BB0-B7BBD2FCB449}]
D:\WINDOWS\system32\fccddeBt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"Yahoo! Pager"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-11-06 19:51 3810544]
"SpybotSD TeaTimer"="D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"MsnMsgr"="D:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-11-07 15:34 3739672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="D:\WINDOWS\system32\NvCpl.dll" [2007-05-22 20:05 8433664]
"HP Software Update"="D:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 17:28 49152]
"HP Component Manager"="D:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18 241664]
"AVG8_TRAY"="D:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-10 20:01 1177368]
"MSConfig"="D:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 00:56 158208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"LHTTSFRF"="advpack.dll" [2008-03-01 18:36 124928 D:\WINDOWS\system32\advpack.dll]

D:\Documents and Settings\Tanya\Start Menu\Programs\Startup\
KeyboardManager.lnk - D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe [2007-03-27 14:39:58 1359872]
RTLCPL.lnk - D:\Program Files\Realtek\InstallShield\RTLCPL.exe [2008-02-23 19:25:54 9715200]

D:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 05:19:24 237568]
Ralink Wireless Utility.lnk - D:\Program Files\RALINK\Common\RaUI.exe [2008-02-23 19:43:54 2101248]
Run Google Web Accelerator.lnk - D:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe [2007-07-09 22:24:38 1134592]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{A0B4FFEA-D466-49A8-9BB0-B7BBD2FCB449}"= D:\WINDOWS\system32\fccddeBt.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
--a------ 2007-01-02 02:52 3739648 D:\Program Files\Google\Google Talk\googletalk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 00:47 31016 D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-05-22 20:05 8433664 D:\WINDOWS\System32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-11-06 19:51 3810544 D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Pml Driver HPZ12"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"D:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"D:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"D:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"D:\\Program Files\\SopCast\\SopCast.exe"=
"D:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"D:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"D:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"D:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"D:\\Program Files\\uTorrent\\uTorrent.exe"=
"D:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"D:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"D:\\Program Files\\Messenger\\msmsgs.exe"=
"D:\\Program Files\\Opera 9\\Opera.exe"=
"D:\\Program Files\\SopCast\\sopvod.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"D:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"D:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R0 AvgRkx86;avgrkx86.sys;D:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-06-10 20:02]
R1 AvgLdx86;AVG AVI Loader Driver x86;D:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-10 20:01]
R2 avg8wd;AVG8 WatchDog;D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-10 20:01]
R2 avgfws8;AVG8 Firewall;D:\PROGRA~1\AVG\AVG8\avgfws8.exe [2008-06-10 20:01]
R2 AvgTdiX;AVG8 Network Redirector;D:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-10 20:02]
R3 Avgfwdx;Avgfwdx;D:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-06-10 19:38]
R3 qkbfiltr;Keyboard Filter Driver;D:\WINDOWS\system32\DRIVERS\qkbfiltr.sys [2007-02-01 07:08]
R3 TDHost;TDHost;D:\WINDOWS\system32\drivers\TDHost.sys [2002-11-26 12:04]
S2 STUDSRV;Student Service;D:\Program Files\Radix\SmartClass\GATESRV.exe []
S3 Avgfwfd;AVG network filter service;D:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-06-10 19:38]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{41914f3c-e620-11dc-bbc2-0010609512df}]
\Shell\AutoRun\command - oufddh.exe
\Shell\explore\Command - oufddh.exe
\Shell\open\Command - oufddh.exe

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-11 21:33:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\wdfmgr.exe
D:\PROGRA~1\AVG\AVG8\avgam.exe
D:\Program Files\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgnsx.exe
D:\Program Files\Google\Web Accelerator\GoogleWebAccClient.exe
D:\Program Files\Windows Live\Contacts\wlcomm.exe
D:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
D:\WINDOWS\system32\msiexec.exe
D:\WINDOWS\system32\dumprep.exe
D:\WINDOWS\system32\dwwin.exe
.
**************************************************************************
.
Completion time: 2008-06-11 21:37:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-11 16:07:29

Pre-Run: 19,664,531,456 bytes free
Post-Run: 19,774,218,240 bytes free

208 --- E O F --- 2008-06-10 12:00:52




Here is my HijackThis Log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:38:52 PM, on 11-Jun-08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\PROGRA~1\AVG\AVG8\avgfws8.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\PROGRA~1\AVG\AVG8\avgam.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgnsx.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\HP\HP Software Update\HPWuSchd.exe
D:\Program Files\HP\hpcoretech\hpcmpmgr.exe
D:\PROGRA~1\AVG\AVG8\avgtray.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\RALINK\Common\RaUI.exe
D:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe
D:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Windows Live\Contacts\wlcomm.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\WINDOWS\system32\msiexec.exe
D:\WINDOWS\explorer.exe
D:\HJT\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - D:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - D:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53523F4E-78CF-499E-BD31-EC0E26BAFC7C} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - D:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: (no name) - {A0B4FFEA-D466-49A8-9BB0-B7BBD2FCB449} - D:\WINDOWS\system32\fccddeBt.dll (file missing)
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - D:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - D:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HP Software Update] "D:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "D:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [MSConfig] D:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunOnce: [LHTTSFRF] RunDll32 advpack.dll,LaunchINFSection D:\WINDOWS\INF\LHTTSFRF.inf, RemoveCabinet
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - S-1-5-18 Startup: KeyboardManager.lnk = D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: RTLCPL.lnk = D:\Program Files\Realtek\InstallShield\RTLCPL.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: KeyboardManager.lnk = D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe (User 'Default user')
O4 - .DEFAULT Startup: RTLCPL.lnk = D:\Program Files\Realtek\InstallShield\RTLCPL.exe (User 'Default user')
O4 - Startup: KeyboardManager.lnk = D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe
O4 - Startup: RTLCPL.lnk = D:\Program Files\Realtek\InstallShield\RTLCPL.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = D:\Program Files\RALINK\Common\RaUI.exe
O4 - Global Startup: Run Google Web Accelerator.lnk = D:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
O8 - Extra context menu item: &Download by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Student Service (STUDSRV) - Unknown owner - D:\Program Files\Radix\SmartClass\GATESRV.exe (file missing)

--
End of file - 7548 bytes

#7 Baabiouz

Baabiouz

    Finnish Malware Fighter


  • Members
  • 3,355 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:05 PM

Posted 12 June 2008 - 11:07 AM

Hello :thumbsup:

Step #1
Please click your Start button then Click on Run and type in the following without the quotes: "notepad" Then copy (Ctrl C) and paste (Ctrl V) the following text in the codebox,
File::
D:\WINDOWS\system32\JQqtBcfe.ini

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53523F4E-78CF-499E-BD31-EC0E26BAFC7C}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A0B4FFEA-D466-49A8-9BB0-B7BBD2FCB449}]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{A0B4FFEA-D466-49A8-9BB0-B7BBD2FCB449}"=-


Save this as CFScript.txt

Posted Image

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply.

Step #2
Please use Windows Xp Search-tool and search this file: (instructions to use Windows Xp Search-tool)

oufddh.exe

If you found it, remove it.

Step #3
Please download ATF-cleaner and save it to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

    If you use Firefox browser:

  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser:

  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
  • Click Exit on the Main menu to close the program.
Step #4
Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Acan" option is selected.
    • Then click on the Scan button.
  • The next screen will ask you to select the drives to scan. Leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Step #5
Please post Mbam log, Combofix log and a fresh HijackThis log back here :)

Edited by Baabiouz, 12 June 2008 - 11:08 AM.

Posted Image

#8 Lanny25

Lanny25
  • Topic Starter

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:04:05 AM

Posted 12 June 2008 - 09:09 PM

Hello.I couldnt find oufddh.exe.Here are the rest logfiles.

MBAM Log File

Malwarebytes' Anti-Malware 1.17
Database version: 851

7:35:56 AM 13-Jun-08
mbam-log-6-13-2008 (07-35-56).txt

Scan type: Quick Scan
Objects scanned: 38423
Time elapsed: 4 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
D:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.


Combofix Logfile


ComboFix 08-06-10.5 - Tanya 2008-06-13 6:53:36.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.402 [GMT 5.5:30]
Running from: D:\Documents and Settings\Tanya\Desktop\ComboFix.exe
Command switches used :: D:\Documents and Settings\Tanya\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
D:\WINDOWS\system32\JQqtBcfe.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\WINDOWS\system32\JQqtBcfe.ini

.
((((((((((((((((((((((((( Files Created from 2008-05-13 to 2008-06-13 )))))))))))))))))))))))))))))))
.

2008-06-13 06:42 . 2008-06-13 06:42 1,374 --a------ D:\WINDOWS\imsins.BAK
2008-06-13 06:41 . 2008-06-13 06:41 <DIR> d-------- D:\WINDOWS\LastGood
2008-06-12 19:55 . 2008-06-12 19:55 <DIR> d-------- D:\WINDOWS\system32\LogFiles
2008-06-12 06:33 . 2008-04-14 16:31 272,128 -----c--- D:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 20:29 . 2008-06-12 17:30 <DIR> d--h----- D:\$AVG8.VAULT$
2008-06-10 20:20 . 2008-06-11 21:38 <DIR> d-------- D:\HJT
2008-06-10 20:02 . 2008-06-10 20:02 75,272 --a------ D:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-10 20:02 . 2008-06-10 20:02 12,424 --a------ D:\WINDOWS\system32\drivers\avgrkx86.sys
2008-06-10 20:02 . 2008-06-10 20:02 10,520 --a------ D:\WINDOWS\system32\avgrsstx.dll
2008-06-10 20:01 . 2008-06-12 15:54 <DIR> d-------- D:\WINDOWS\system32\drivers\Avg
2008-06-10 20:01 . 2008-06-10 20:01 96,520 --a------ D:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-10 19:49 . 2008-06-10 19:54 <DIR> d-------- D:\VundoFix Backups
2008-06-10 19:38 . 2008-06-10 19:38 <DIR> d-------- D:\Program Files\AVG
2008-06-10 19:38 . 2008-06-10 19:38 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\avg8
2008-06-10 19:38 . 2008-06-10 19:38 45,568 --a------ D:\WINDOWS\system32\avgfwdx.dll
2008-06-10 19:38 . 2008-06-10 19:38 22,528 --a------ D:\WINDOWS\system32\drivers\avgfwdx.sys
2008-06-08 12:26 . 2008-06-13 06:38 <DIR> d-------- D:\Documents and Settings\Tanya\Tracing
2008-06-08 12:24 . 2008-06-08 12:24 <DIR> d-------- D:\Program Files\Windows Live
2008-06-08 11:08 . 2008-06-08 11:08 <DIR> d-------- D:\Program Files\Overland
2008-06-08 11:08 . 2008-06-08 11:08 208 --a------ D:\WINDOWS\HpBestModeUpdatePatchLog.ini
2008-06-08 11:08 . 2008-06-08 11:08 206 --a------ D:\WINDOWS\HPGdiPlus.ini
2008-06-08 11:00 . 2008-06-08 11:00 214 --a------ D:\WINDOWS\HP_48BitScanUpdatePatch.ini
2008-06-06 19:06 . 2008-06-06 19:06 <DIR> d-------- D:\Program Files\Common Files\HP
2008-06-06 19:05 . 2008-06-06 19:05 <DIR> d-------- D:\WINDOWS\system32\URTTEMP
2008-06-06 18:58 . 2004-01-05 19:59 38,782 --------- D:\WINDOWS\hpomdl03.dat.temp
2008-06-06 18:58 . 2008-03-13 19:47 29,405 --------- D:\WINDOWS\hpoins03.dat.temp
2008-06-02 16:33 . 2008-06-02 16:33 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-02 16:33 . 2008-06-06 17:30 54,156 --ah----- D:\WINDOWS\QTFont.qfn
2008-06-02 16:33 . 2008-06-02 16:33 1,409 --a------ D:\WINDOWS\QTFont.for
2008-06-02 15:58 . 2008-06-02 16:29 <DIR> d--h----- D:\Program Files\Zero G Registry
2008-06-02 15:58 . 2008-06-02 16:33 <DIR> d-------- D:\Program Files\Britannica 7.0
2008-06-02 15:58 . 2008-06-02 15:58 <DIR> d--h----- D:\Documents and Settings\Tanya\InstallAnywhere
2008-05-29 18:51 . 2008-05-29 18:51 <DIR> d-------- D:\Program Files\MathType
2008-05-29 18:51 . 2008-05-29 18:51 <DIR> d-------- D:\Documents and Settings\Tanya\Application Data\Design Science
2008-05-27 15:32 . 2008-05-27 16:48 <DIR> d-------- D:\Documents and Settings\Tanya\Application Data\Symantec
2008-05-26 19:17 . 2008-06-10 20:02 <DIR> d-------- D:\Documents and Settings\Administrator
2008-05-26 15:12 . 2008-05-26 15:12 <DIR> d-------- D:\Program Files\TVAnts
2008-05-26 15:11 . 2008-05-26 15:12 <DIR> d-------- D:\WINDOWS\uninstall\Satellite TV for PC Elite
2008-05-26 15:11 . 2008-05-26 15:11 <DIR> d-------- D:\WINDOWS\uninstall
2008-05-26 15:11 . 2008-05-26 15:11 <DIR> d-------- D:\Program Files\SatelliteTVforPC
2008-05-25 16:12 . 2008-05-25 16:12 <DIR> d-------- D:\Program Files\Microsoft Silverlight
2008-05-22 20:32 . 2008-05-22 20:32 <DIR> d--h----- D:\WINDOWS\PIF
2008-05-21 18:42 . 2008-05-21 18:42 <DIR> d-------- D:\Program Files\QuickTime
2008-05-21 18:42 . 2008-05-21 18:42 <DIR> d-------- D:\Program Files\ImTOO
2008-05-18 16:28 . 2008-05-18 16:29 <DIR> d-------- D:\Program Files\OpenAL
2008-05-18 16:28 . 2008-05-18 16:28 409,600 --a------ D:\WINDOWS\system32\wrap_oal.dll
2008-05-18 16:28 . 2008-05-18 16:28 114,688 --a------ D:\WINDOWS\system32\OpenAL32.dll
2008-05-18 16:26 . 2008-05-18 16:26 <DIR> d-------- D:\Program Files\Penumbra
2008-05-18 14:22 . 2008-05-18 14:22 <DIR> d-------- D:\Program Files\Common Files\Wise Installation Wizard
2008-05-18 14:21 . 2008-05-18 14:32 <DIR> d-------- D:\Program Files\DFX
2008-05-18 14:21 . 2008-05-18 14:22 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\DFX
2008-05-18 14:11 . 2008-05-18 14:21 <DIR> d-------- D:\Program Files\Winamp
2008-05-18 14:11 . 2008-05-18 14:36 <DIR> d-------- D:\Documents and Settings\Tanya\Application Data\Winamp
2008-05-13 17:53 . 2008-06-11 20:37 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Symantec
2008-05-13 17:52 . 2008-06-11 20:37 <DIR> d-------- D:\Program Files\Common Files\Symantec Shared

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-10 12:20 --------- d-----w D:\Documents and Settings\Tanya\Application Data\Orbit
2008-06-10 12:00 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-06 13:39 --------- d-----w D:\Program Files\HP
2008-05-30 11:24 --------- d-----w D:\Program Files\Comodo
2008-05-30 11:24 --------- d-----w D:\Documents and Settings\Tanya\Application Data\Comodo
2008-05-29 11:11 --------- d-----w D:\Documents and Settings\All Users\Application Data\Comodo
2008-05-26 13:45 --------- d-----w D:\Documents and Settings\Tanya\Application Data\uTorrent
2008-05-26 10:08 --------- d-----w D:\Documents and Settings\Tanya\Application Data\StumbleUpon
2008-05-21 13:19 --------- d-----w D:\Program Files\Total Video Converter
2008-05-13 11:49 --------- d-----w D:\Program Files\GlobalMapper9
2008-05-08 12:28 202,752 ----a-w D:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w D:\WINDOWS\system32\SET35.tmp
2008-05-07 00:58 --------- d-----w D:\Program Files\Rapid-USD NoCaptcha -Th3zone.com Sep2007
2008-04-30 13:22 --------- d-----w D:\Documents and Settings\Tanya\Application Data\DivX
2008-04-23 16:46 3,591,680 ----a-w D:\WINDOWS\system32\SET5B.tmp
2008-04-20 12:43 --------- d-----w D:\Program Files\Free Music Zilla
2008-04-19 12:27 --------- d-----w D:\Program Files\DivX
2008-04-19 11:43 --------- d-----w D:\Program Files\Full Speed
2008-04-15 05:41 73,216 ----a-w D:\WINDOWS\ST6UNST.EXE
2008-04-15 05:41 311,296 ------w D:\WINDOWS\Setup1.exe
2008-04-14 11:01 272,128 ------w D:\WINDOWS\system32\drivers\bthport.sys
2008-04-13 12:26 --------- d-----w D:\Program Files\APOD
2008-04-13 05:35 --------- d-----w D:\Program Files\Cute Translator
2008-04-11 15:42 167,936 ----a-w D:\WINDOWS\system32\SpoonUninstall.exe
2008-03-31 21:25 831,488 ----a-w D:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w D:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w D:\WINDOWS\system32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w D:\WINDOWS\system32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w D:\WINDOWS\system32\DivX.dll
2008-03-31 21:25 161,096 ----a-w D:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-27 08:12 151,583 ----a-w D:\WINDOWS\system32\msjint40.dll
2008-03-21 20:30 524,288 ----a-w D:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w D:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w D:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 129,784 ------w D:\WINDOWS\system32\pxafs.dll
2008-03-21 20:30 120,056 ------w D:\WINDOWS\system32\pxcpyi64.exe
2008-03-21 20:30 118,520 ------w D:\WINDOWS\system32\pxinsi64.exe
2008-03-21 20:30 1,044,480 ----a-w D:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w D:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w D:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w D:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w D:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w D:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w D:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w D:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w D:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w D:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-19 09:47 1,845,248 ----a-w D:\WINDOWS\system32\win32k.sys
.

((((((((((((((((((((((((((((( snapshot@2008-06-11_21.37.18.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-07 04:55:40 1,288,192 ----a-w D:\WINDOWS\$hf_mig$\KB951698\SP2QFE\quartz.dll
+ 2008-05-07 05:12:40 1,288,192 ----a-w D:\WINDOWS\$hf_mig$\KB951698\SP3GDR\quartz.dll
+ 2008-05-07 05:04:15 1,288,192 ----a-w D:\WINDOWS\$hf_mig$\KB951698\SP3QFE\quartz.dll
+ 2007-11-30 11:18:51 17,272 ----a-w D:\WINDOWS\$hf_mig$\KB951698\spmsg.dll
+ 2007-11-30 11:18:51 231,288 ----a-w D:\WINDOWS\$hf_mig$\KB951698\spuninst.exe
+ 2007-11-30 11:18:51 26,488 ----a-w D:\WINDOWS\$hf_mig$\KB951698\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w D:\WINDOWS\$hf_mig$\KB951698\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w D:\WINDOWS\$hf_mig$\KB951698\update\updspapi.dll
- 2008-06-11 16:02:57 2,048 --s-a-w D:\WINDOWS\bootstat.dat
+ 2008-06-13 01:08:04 2,048 --s-a-w D:\WINDOWS\bootstat.dat
+ 2008-04-14 11:01:02 272,128 ------w D:\WINDOWS\Driver Cache\i386\bthport.sys
- 2008-06-11 15:16:26 29,098 ----a-w D:\WINDOWS\hpoins03.dat
+ 2008-06-13 01:08:47 29,098 ----a-w D:\WINDOWS\hpoins03.dat
+ 2008-03-01 13:06:20 124,928 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\advpack.dll
+ 2008-03-01 13:06:21 347,136 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\dxtmsft.dll
+ 2008-03-01 13:06:21 214,528 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\dxtrans.dll
+ 2008-03-01 13:06:21 133,120 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\extmgr.dll
+ 2008-03-01 13:06:21 63,488 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\icardie.dll
+ 2008-02-29 08:55:23 70,656 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ie4uinit.exe
+ 2008-03-01 13:06:21 153,088 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ieakeng.dll
+ 2008-03-01 13:06:21 230,400 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ieaksie.dll
+ 2008-02-15 05:44:25 161,792 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ieakui.dll
+ 2008-03-01 13:06:22 383,488 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ieapfltr.dll
+ 2008-03-01 13:06:22 384,512 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\iedkcs32.dll
+ 2008-03-01 13:06:24 6,066,176 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ieframe.dll
+ 2008-03-01 13:06:24 44,544 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\iernonce.dll
+ 2008-03-01 13:06:25 267,776 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\iertutil.dll
+ 2008-02-22 10:00:51 13,824 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\ieudinit.exe
+ 2008-02-29 08:55:46 625,664 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
+ 2008-03-01 13:06:25 27,648 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\jsproxy.dll
+ 2008-03-01 13:06:26 459,264 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\msfeeds.dll
+ 2008-03-01 13:06:26 52,224 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\msfeedsbs.dll
+ 2008-03-01 13:06:30 3,591,680 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\mshtml.dll
+ 2008-03-01 13:06:28 478,208 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\mshtmled.dll
+ 2008-03-01 13:06:28 193,024 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\msrating.dll
+ 2008-03-01 13:06:29 671,232 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\mstime.dll
+ 2008-03-01 13:06:29 102,912 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\occache.dll
+ 2008-03-01 13:06:29 44,544 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\spuninst\updspapi.dll
+ 2008-03-01 13:06:29 105,984 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\url.dll
+ 2008-03-01 13:06:30 1,159,680 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\urlmon.dll
+ 2008-03-01 13:06:30 233,472 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\webcheck.dll
+ 2008-03-01 13:06:31 826,368 -c----w D:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
- 2008-03-01 13:06:20 124,928 -c----w D:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-04-23 04:16:28 124,928 -c----w D:\WINDOWS\system32\dllcache\advpack.dll
- 2008-03-01 13:06:21 347,136 -c----w D:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-04-23 04:16:28 347,136 -c----w D:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2008-03-01 13:06:21 214,528 -c----w D:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-04-23 04:16:28 214,528 -c----w D:\WINDOWS\system32\dllcache\dxtrans.dll
- 2008-03-01 13:06:21 133,120 -c----w D:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-04-23 04:16:28 133,120 -c----w D:\WINDOWS\system32\dllcache\extmgr.dll
- 2008-03-01 13:06:21 63,488 -c----w D:\WINDOWS\system32\dllcache\icardie.dll
+ 2008-04-23 04:16:28 63,488 -c----w D:\WINDOWS\system32\dllcache\icardie.dll
- 2008-02-29 08:55:23 70,656 -c----w D:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2008-04-22 07:39:58 70,656 -c----w D:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2008-03-01 13:06:21 153,088 -c----w D:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-04-23 04:16:28 153,088 -c----w D:\WINDOWS\system32\dllcache\ieakeng.dll
- 2008-03-01 13:06:21 230,400 -c----w D:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2008-04-23 04:16:28 230,400 -c----w D:\WINDOWS\system32\dllcache\ieaksie.dll
- 2008-02-15 05:44:25 161,792 -c--a-w D:\WINDOWS\system32\dllcache\ieakui.dll
+ 2008-04-20 05:07:51 161,792 -c--a-w D:\WINDOWS\system32\dllcache\ieakui.dll
- 2008-03-01 13:06:22 383,488 -c----w D:\WINDOWS\system32\dllcache\ieapfltr.dll
+ 2008-04-23 04:16:28 383,488 -c----w D:\WINDOWS\system32\dllcache\ieapfltr.dll
- 2008-03-01 13:06:22 384,512 -c----w D:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-04-23 04:16:28 384,512 -c----w D:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2008-03-01 13:06:24 6,066,176 -c----w D:\WINDOWS\system32\dllcache\ieframe.dll
+ 2008-04-23 04:16:28 6,066,176 -c----w D:\WINDOWS\system32\dllcache\ieframe.dll
- 2008-03-01 13:06:24 44,544 -c----w D:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-04-23 04:16:28 44,544 -c----w D:\WINDOWS\system32\dllcache\iernonce.dll
- 2008-03-01 13:06:25 267,776 -c----w D:\WINDOWS\system32\dllcache\iertutil.dll
+ 2008-04-23 04:16:28 267,776 -c----w D:\WINDOWS\system32\dllcache\iertutil.dll
- 2008-02-22 10:00:51 13,824 -c----w D:\WINDOWS\system32\dllcache\ieudinit.exe
+ 2008-04-22 07:39:58 13,824 -c----w D:\WINDOWS\system32\dllcache\ieudinit.exe
- 2008-02-29 08:55:46 625,664 -c----w D:\WINDOWS\system32\dllcache\iexplore.exe
+ 2008-04-22 07:40:18 625,664 -c----w D:\WINDOWS\system32\dllcache\iexplore.exe
- 2008-03-01 13:06:25 27,648 -c----w D:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-04-23 04:16:28 27,648 -c----w D:\WINDOWS\system32\dllcache\jsproxy.dll
- 2008-03-01 13:06:26 459,264 -c----w D:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2008-04-23 04:16:28 459,264 -c----w D:\WINDOWS\system32\dllcache\msfeeds.dll
- 2008-03-01 13:06:26 52,224 -c----w D:\WINDOWS\system32\dllcache\msfeedsbs.dll
+ 2008-04-23 04:16:28 52,224 -c----w D:\WINDOWS\system32\dllcache\msfeedsbs.dll
- 2008-03-01 13:06:30 3,591,680 -c----w D:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-04-23 16:46:30 3,591,680 -c----w D:\WINDOWS\system32\dllcache\mshtml.dll
- 2008-03-01 13:06:28 478,208 -c----w D:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-04-23 04:16:28 478,208 -c----w D:\WINDOWS\system32\dllcache\mshtmled.dll
- 2008-03-01 13:06:28 193,024 -c----w D:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-04-23 04:16:28 193,024 -c----w D:\WINDOWS\system32\dllcache\msrating.dll
- 2008-03-01 13:06:29 671,232 -c----w D:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-04-23 04:16:28 671,232 -c----w D:\WINDOWS\system32\dllcache\mstime.dll
- 2008-03-01 13:06:29 102,912 -c----w D:\WINDOWS\system32\dllcache\occache.dll
+ 2008-04-23 04:16:28 102,912 -c----w D:\WINDOWS\system32\dllcache\occache.dll
- 2008-03-01 13:06:29 44,544 -c----w D:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-04-23 04:16:28 44,544 -c----w D:\WINDOWS\system32\dllcache\pngfilt.dll
- 2007-10-29 22:43:03 1,287,680 -c----w D:\WINDOWS\system32\dllcache\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 -c----w D:\WINDOWS\system32\dllcache\quartz.dll
- 2006-07-13 08:48:58 202,240 -c--a-w D:\WINDOWS\system32\dllcache\rmcast.sys
+ 2008-05-08 12:28:49 202,752 -c--a-w D:\WINDOWS\system32\dllcache\rmcast.sys
- 2008-03-01 13:06:29 105,984 -c----w D:\WINDOWS\system32\dllcache\url.dll
+ 2008-04-23 04:16:28 105,984 -c----w D:\WINDOWS\system32\dllcache\url.dll
- 2008-03-01 13:06:30 1,159,680 -c----w D:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-04-23 04:16:29 1,159,680 -c----w D:\WINDOWS\system32\dllcache\urlmon.dll
- 2008-03-01 13:06:30 233,472 -c----w D:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-04-23 04:16:29 233,472 -c----w D:\WINDOWS\system32\dllcache\webcheck.dll
- 2008-03-01 13:06:31 826,368 -c----w D:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-04-23 04:16:29 826,368 -c----w D:\WINDOWS\system32\dllcache\wininet.dll
- 2008-03-01 13:06:21 133,120 ----a-w D:\WINDOWS\system32\extmgr.dll
+ 2008-04-23 04:16:28 133,120 ----a-w D:\WINDOWS\system32\extmgr.dll
- 2008-02-29 08:55:23 70,656 ----a-w D:\WINDOWS\system32\ie4uinit.exe
+ 2008-04-22 07:39:58 70,656 ----a-w D:\WINDOWS\system32\ie4uinit.exe
- 2008-03-01 13:06:21 153,088 ----a-w D:\WINDOWS\system32\ieakeng.dll
+ 2008-04-23 04:16:28 153,088 ----a-w D:\WINDOWS\system32\ieakeng.dll
- 2008-03-01 13:06:21 230,400 ----a-w D:\WINDOWS\system32\ieaksie.dll
+ 2008-04-23 04:16:28 230,400 ----a-w D:\WINDOWS\system32\ieaksie.dll
- 2008-02-15 05:44:25 161,792 ----a-w D:\WINDOWS\system32\ieakui.dll
+ 2008-04-20 05:07:51 161,792 ----a-w D:\WINDOWS\system32\ieakui.dll
- 2008-03-01 13:06:22 384,512 ----a-w D:\WINDOWS\system32\iedkcs32.dll
+ 2008-04-23 04:16:28 384,512 ----a-w D:\WINDOWS\system32\iedkcs32.dll
- 2008-03-01 13:06:24 44,544 ----a-w D:\WINDOWS\system32\iernonce.dll
+ 2008-04-23 04:16:28 44,544 ----a-w D:\WINDOWS\system32\iernonce.dll
- 2008-02-22 10:00:51 13,824 ----a-w D:\WINDOWS\system32\ieudinit.exe
+ 2008-04-22 07:39:58 13,824 ----a-w D:\WINDOWS\system32\ieudinit.exe
- 2008-05-09 21:35:04 16,863,864 ----a-w D:\WINDOWS\system32\MRT.exe
+ 2008-05-29 23:35:12 17,486,968 ----a-w D:\WINDOWS\system32\MRT.exe
- 2008-03-01 13:06:28 478,208 ----a-w D:\WINDOWS\system32\mshtmled.dll
+ 2008-04-23 04:16:28 478,208 ----a-w D:\WINDOWS\system32\mshtmled.dll
- 2008-03-01 13:06:28 193,024 ----a-w D:\WINDOWS\system32\msrating.dll
+ 2008-04-23 04:16:28 193,024 ----a-w D:\WINDOWS\system32\msrating.dll
- 2008-03-01 13:06:29 671,232 ----a-w D:\WINDOWS\system32\mstime.dll
+ 2008-04-23 04:16:28 671,232 ----a-w D:\WINDOWS\system32\mstime.dll
- 2008-03-01 13:06:29 102,912 ----a-w D:\WINDOWS\system32\occache.dll
+ 2008-04-23 04:16:28 102,912 ----a-w D:\WINDOWS\system32\occache.dll
- 2007-03-06 01:22:36 14,048 ------w D:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ------w D:\WINDOWS\system32\spmsg.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"Yahoo! Pager"="D:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-11-06 19:51 3810544]
"SpybotSD TeaTimer"="D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"MsnMsgr"="D:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-11-07 15:34 3739672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="D:\WINDOWS\system32\NvCpl.dll" [2007-05-22 20:05 8433664]
"HP Component Manager"="D:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18 241664]
"AVG8_TRAY"="D:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-10 20:01 1177368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"LHTTSFRF"="advpack.dll" [2008-03-01 18:36 124928 D:\WINDOWS\system32\advpack.dll]

D:\Documents and Settings\Tanya\Start Menu\Programs\Startup\
KeyboardManager.lnk - D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe [2007-03-27 14:39:58 1359872]
RTLCPL.lnk - D:\Program Files\Realtek\InstallShield\RTLCPL.exe [2008-02-23 19:25:54 9715200]

D:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 05:19:24 237568]
Ralink Wireless Utility.lnk - D:\Program Files\RALINK\Common\RaUI.exe [2008-02-23 19:43:54 2101248]
Run Google Web Accelerator.lnk - D:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe [2007-07-09 22:24:38 1134592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
--a------ 2007-01-02 02:52 3739648 D:\Program Files\Google\Google Talk\googletalk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 00:47 31016 D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-05-22 20:05 8433664 D:\WINDOWS\System32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-11-06 19:51 3810544 D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Pml Driver HPZ12"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"D:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"D:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"D:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"D:\\Program Files\\SopCast\\SopCast.exe"=
"D:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"D:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"D:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"D:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"D:\\Program Files\\uTorrent\\uTorrent.exe"=
"D:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"D:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"D:\\Program Files\\Messenger\\msmsgs.exe"=
"D:\\Program Files\\Opera 9\\Opera.exe"=
"D:\\Program Files\\SopCast\\sopvod.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"D:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"D:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R0 AvgRkx86;avgrkx86.sys;D:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-06-10 20:02]
R1 AvgLdx86;AVG AVI Loader Driver x86;D:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-10 20:01]
R2 avg8wd;AVG8 WatchDog;D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-10 20:01]
R2 avgfws8;AVG8 Firewall;D:\PROGRA~1\AVG\AVG8\avgfws8.exe [2008-06-10 20:01]
R2 AvgTdiX;AVG8 Network Redirector;D:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-10 20:02]
R3 Avgfwdx;Avgfwdx;D:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-06-10 19:38]
R3 qkbfiltr;Keyboard Filter Driver;D:\WINDOWS\system32\DRIVERS\qkbfiltr.sys [2007-02-01 07:08]
R3 TDHost;TDHost;D:\WINDOWS\system32\drivers\TDHost.sys [2002-11-26 12:04]
S2 STUDSRV;Student Service;D:\Program Files\Radix\SmartClass\GATESRV.exe []
S3 Avgfwfd;AVG network filter service;D:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-06-10 19:38]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{41914f3c-e620-11dc-bbc2-0010609512df}]
\Shell\AutoRun\command - oufddh.exe
\Shell\explore\Command - oufddh.exe
\Shell\open\Command - oufddh.exe

*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 06:55:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-13 6:56:38
ComboFix-quarantined-files.txt 2008-06-13 01:26:36
ComboFix2.txt 2008-06-11 16:07:33

Pre-Run: 19,428,581,376 bytes free
Post-Run: 19,422,662,656 bytes free

361 --- E O F --- 2008-06-13 01:14:56


HJT Log File


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:38:55 AM, on 13-Jun-08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\PROGRA~1\AVG\AVG8\avgfws8.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\PROGRA~1\AVG\AVG8\avgam.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgnsx.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\HP\hpcoretech\hpcmpmgr.exe
D:\PROGRA~1\AVG\AVG8\avgtray.exe
D:\WINDOWS\system32\ctfmon.exe
D:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\RALINK\Common\RaUI.exe
D:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe
D:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
D:\Program Files\Windows Live\Contacts\wlcomm.exe
D:\Program Files\Windows Live\Messenger\usnsvc.exe
D:\Program Files\Opera 9\Opera.exe
D:\HJT\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - D:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - D:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - D:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - D:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - D:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HP Component Manager] "D:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [LHTTSFRF] RunDll32 advpack.dll,LaunchINFSection D:\WINDOWS\INF\LHTTSFRF.inf, RemoveCabinet
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - S-1-5-18 Startup: KeyboardManager.lnk = D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: RTLCPL.lnk = D:\Program Files\Realtek\InstallShield\RTLCPL.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: KeyboardManager.lnk = D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe (User 'Default user')
O4 - .DEFAULT Startup: RTLCPL.lnk = D:\Program Files\Realtek\InstallShield\RTLCPL.exe (User 'Default user')
O4 - Startup: KeyboardManager.lnk = D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe
O4 - Startup: RTLCPL.lnk = D:\Program Files\Realtek\InstallShield\RTLCPL.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = D:\Program Files\RALINK\Common\RaUI.exe
O4 - Global Startup: Run Google Web Accelerator.lnk = D:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
O8 - Extra context menu item: &Download by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Student Service (STUDSRV) - Unknown owner - D:\Program Files\Radix\SmartClass\GATESRV.exe (file missing)

--
End of file - 7131 bytes

Thanks :thumbsup:

#9 Baabiouz

Baabiouz

    Finnish Malware Fighter


  • Members
  • 3,355 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:05 PM

Posted 14 June 2008 - 07:32 AM

Hello

I forgot add one thing to CFScript so we need to run it once again. :thumbsup:

Please click your Start button then Click on Run and type in the following without the quotes: "notepad" Then copy (Ctrl C) and paste (Ctrl V) the following text in the codebox,
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{41914f3c-e620-11dc-bbc2-0010609512df}]


Save this as CFScript.txt

Posted Image

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply.
How's your PC working now? :)
Posted Image

#10 Lanny25

Lanny25
  • Topic Starter

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:04:05 AM

Posted 14 June 2008 - 08:51 AM

Hello Baabiouz :)

Here is my Combofix Log

ComboFix 08-06-10.5 - Tanya 2008-06-14 19:12:27.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.486 [GMT 5.5:30]
Running from: D:\Documents and Settings\Tanya\Desktop\ComboFix.exe
Command switches used :: D:\Documents and Settings\Tanya\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-05-14 to 2008-06-14 )))))))))))))))))))))))))))))))
.

2008-06-13 07:03 . 2008-06-13 07:03 <DIR> d-------- D:\Program Files\Malwarebytes' Anti-Malware
2008-06-13 07:03 . 2008-06-13 07:03 <DIR> d-------- D:\Documents and Settings\Tanya\Application Data\Malwarebytes
2008-06-13 07:03 . 2008-06-13 07:03 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-13 07:03 . 2008-06-10 19:02 34,296 --a------ D:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-13 07:03 . 2008-06-10 19:02 15,864 --a------ D:\WINDOWS\system32\drivers\mbam.sys
2008-06-13 06:42 . 2008-06-13 06:42 1,374 --a------ D:\WINDOWS\imsins.BAK
2008-06-12 19:55 . 2008-06-12 19:55 <DIR> d-------- D:\WINDOWS\system32\LogFiles
2008-06-12 06:33 . 2008-04-14 16:31 272,128 -----c--- D:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 20:29 . 2008-06-12 17:30 <DIR> d--h----- D:\$AVG8.VAULT$
2008-06-10 20:20 . 2008-06-13 18:38 <DIR> d-------- D:\HJT
2008-06-10 20:02 . 2008-06-10 20:02 75,272 --a------ D:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-10 20:02 . 2008-06-10 20:02 12,424 --a------ D:\WINDOWS\system32\drivers\avgrkx86.sys
2008-06-10 20:02 . 2008-06-10 20:02 10,520 --a------ D:\WINDOWS\system32\avgrsstx.dll
2008-06-10 20:01 . 2008-06-14 11:49 <DIR> d-------- D:\WINDOWS\system32\drivers\Avg
2008-06-10 20:01 . 2008-06-10 20:01 96,520 --a------ D:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-10 19:49 . 2008-06-10 19:54 <DIR> d-------- D:\VundoFix Backups
2008-06-10 19:38 . 2008-06-10 19:38 <DIR> d-------- D:\Program Files\AVG
2008-06-10 19:38 . 2008-06-10 19:38 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\avg8
2008-06-10 19:38 . 2008-06-10 19:38 45,568 --a------ D:\WINDOWS\system32\avgfwdx.dll
2008-06-10 19:38 . 2008-06-10 19:38 22,528 --a------ D:\WINDOWS\system32\drivers\avgfwdx.sys
2008-06-08 12:26 . 2008-06-14 18:50 <DIR> d-------- D:\Documents and Settings\Tanya\Tracing
2008-06-08 12:24 . 2008-06-08 12:24 <DIR> d-------- D:\Program Files\Windows Live
2008-06-08 11:08 . 2008-06-08 11:08 <DIR> d-------- D:\Program Files\Overland
2008-06-08 11:08 . 2008-06-08 11:08 208 --a------ D:\WINDOWS\HpBestModeUpdatePatchLog.ini
2008-06-08 11:08 . 2008-06-08 11:08 206 --a------ D:\WINDOWS\HPGdiPlus.ini
2008-06-08 11:00 . 2008-06-08 11:00 214 --a------ D:\WINDOWS\HP_48BitScanUpdatePatch.ini
2008-06-06 19:06 . 2008-06-06 19:06 <DIR> d-------- D:\Program Files\Common Files\HP
2008-06-06 19:05 . 2008-06-06 19:05 <DIR> d-------- D:\WINDOWS\system32\URTTEMP
2008-06-06 18:58 . 2004-01-05 19:59 38,782 --------- D:\WINDOWS\hpomdl03.dat.temp
2008-06-06 18:58 . 2008-03-13 19:47 29,405 --------- D:\WINDOWS\hpoins03.dat.temp
2008-06-02 16:33 . 2008-06-02 16:33 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-02 16:33 . 2008-06-06 17:30 54,156 --ah----- D:\WINDOWS\QTFont.qfn
2008-06-02 16:33 . 2008-06-02 16:33 1,409 --a------ D:\WINDOWS\QTFont.for
2008-06-02 15:58 . 2008-06-02 16:29 <DIR> d--h----- D:\Program Files\Zero G Registry
2008-06-02 15:58 . 2008-06-02 16:33 <DIR> d-------- D:\Program Files\Britannica 7.0
2008-06-02 15:58 . 2008-06-02 15:58 <DIR> d--h----- D:\Documents and Settings\Tanya\InstallAnywhere
2008-05-29 18:51 . 2008-05-29 18:51 <DIR> d-------- D:\Program Files\MathType
2008-05-29 18:51 . 2008-05-29 18:51 <DIR> d-------- D:\Documents and Settings\Tanya\Application Data\Design Science
2008-05-27 15:32 . 2008-05-27 16:48 <DIR> d-------- D:\Documents and Settings\Tanya\Application Data\Symantec
2008-05-26 19:17 . 2008-06-10 20:02 <DIR> d-------- D:\Documents and Settings\Administrator
2008-05-26 15:12 . 2008-05-26 15:12 <DIR> d-------- D:\Program Files\TVAnts
2008-05-26 15:11 . 2008-05-26 15:12 <DIR> d-------- D:\WINDOWS\uninstall\Satellite TV for PC Elite
2008-05-26 15:11 . 2008-05-26 15:11 <DIR> d-------- D:\WINDOWS\uninstall
2008-05-26 15:11 . 2008-05-26 15:11 <DIR> d-------- D:\Program Files\SatelliteTVforPC
2008-05-25 16:12 . 2008-05-25 16:12 <DIR> d-------- D:\Program Files\Microsoft Silverlight
2008-05-22 20:32 . 2008-05-22 20:32 <DIR> d--h----- D:\WINDOWS\PIF
2008-05-21 18:42 . 2008-05-21 18:42 <DIR> d-------- D:\Program Files\QuickTime
2008-05-21 18:42 . 2008-05-21 18:42 <DIR> d-------- D:\Program Files\ImTOO
2008-05-18 16:28 . 2008-05-18 16:29 <DIR> d-------- D:\Program Files\OpenAL
2008-05-18 16:28 . 2008-05-18 16:28 409,600 --a------ D:\WINDOWS\system32\wrap_oal.dll
2008-05-18 16:28 . 2008-05-18 16:28 114,688 --a------ D:\WINDOWS\system32\OpenAL32.dll
2008-05-18 16:26 . 2008-05-18 16:26 <DIR> d-------- D:\Program Files\Penumbra
2008-05-18 14:22 . 2008-05-18 14:22 <DIR> d-------- D:\Program Files\Common Files\Wise Installation Wizard
2008-05-18 14:21 . 2008-05-18 14:32 <DIR> d-------- D:\Program Files\DFX
2008-05-18 14:21 . 2008-05-18 14:22 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\DFX
2008-05-18 14:11 . 2008-05-18 14:21 <DIR> d-------- D:\Program Files\Winamp
2008-05-18 14:11 . 2008-05-18 14:36 <DIR> d-------- D:\Documents and Settings\Tanya\Application Data\Winamp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-14 07:45 --------- d-----w D:\Program Files\Opera 9
2008-06-13 13:48 --------- d-----w D:\Documents and Settings\Tanya\Application Data\Orbit
2008-06-11 15:07 --------- d-----w D:\Program Files\Common Files\Symantec Shared
2008-06-11 15:07 --------- d-----w D:\Documents and Settings\All Users\Application Data\Symantec
2008-06-10 12:00 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-06 13:39 --------- d-----w D:\Program Files\HP
2008-05-30 11:24 --------- d-----w D:\Program Files\Comodo
2008-05-30 11:24 --------- d-----w D:\Documents and Settings\Tanya\Application Data\Comodo
2008-05-29 11:11 --------- d-----w D:\Documents and Settings\All Users\Application Data\Comodo
2008-05-26 13:45 --------- d-----w D:\Documents and Settings\Tanya\Application Data\uTorrent
2008-05-26 10:08 --------- d-----w D:\Documents and Settings\Tanya\Application Data\StumbleUpon
2008-05-21 13:19 --------- d-----w D:\Program Files\Total Video Converter
2008-05-13 11:49 --------- d-----w D:\Program Files\GlobalMapper9
2008-05-08 12:28 202,752 ----a-w D:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w D:\WINDOWS\system32\quartz.dll
2008-05-07 00:58 --------- d-----w D:\Program Files\Rapid-USD NoCaptcha -Th3zone.com Sep2007
2008-04-30 13:22 --------- d-----w D:\Documents and Settings\Tanya\Application Data\DivX
2008-04-23 04:16 826,368 ----a-w D:\WINDOWS\system32\wininet.dll
2008-04-20 12:43 --------- d-----w D:\Program Files\Free Music Zilla
2008-04-19 12:27 --------- d-----w D:\Program Files\DivX
2008-04-19 11:43 --------- d-----w D:\Program Files\Full Speed
2008-04-15 05:41 73,216 ----a-w D:\WINDOWS\ST6UNST.EXE
2008-04-15 05:41 311,296 ------w D:\WINDOWS\Setup1.exe
2008-04-14 11:01 272,128 ------w D:\WINDOWS\system32\drivers\bthport.sys
2008-04-11 15:42 167,936 ----a-w D:\WINDOWS\system32\SpoonUninstall.exe
2008-03-31 21:25 831,488 ----a-w D:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w D:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w D:\WINDOWS\system32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w D:\WINDOWS\system32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w D:\WINDOWS\system32\DivX.dll
2008-03-31 21:25 161,096 ----a-w D:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-27 08:12 151,583 ----a-w D:\WINDOWS\system32\msjint40.dll
2008-03-21 20:30 524,288 ----a-w D:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w D:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w D:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 129,784 ------w D:\WINDOWS\system32\pxafs.dll
2008-03-21 20:30 120,056 ------w D:\WINDOWS\system32\pxcpyi64.exe
2008-03-21 20:30 118,520 ------w D:\WINDOWS\system32\pxinsi64.exe
2008-03-21 20:30 1,044,480 ----a-w D:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w D:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w D:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w D:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w D:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w D:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w D:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w D:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w D:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w D:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-19 09:47 1,845,248 ----a-w D:\WINDOWS\system32\win32k.sys
.

((((((((((((((((((((((((((((( snapshot_2008-06-13_ 6.56.29.35 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-13 01:08:04 2,048 --s-a-w D:\WINDOWS\bootstat.dat
+ 2008-06-14 13:19:41 2,048 --s-a-w D:\WINDOWS\bootstat.dat
- 2008-06-13 01:08:47 29,098 ----a-w D:\WINDOWS\hpoins03.dat
+ 2008-06-14 13:20:38 29,098 ----a-w D:\WINDOWS\hpoins03.dat
- 2008-03-01 13:06:20 124,928 ------w D:\WINDOWS\system32\advpack.dll
+ 2008-04-23 04:16:28 124,928 ----a-w D:\WINDOWS\system32\advpack.dll
- 2008-03-01 13:06:21 347,136 ------w D:\WINDOWS\system32\dxtmsft.dll
+ 2008-04-23 04:16:28 347,136 ----a-w D:\WINDOWS\system32\dxtmsft.dll
- 2008-03-01 13:06:21 214,528 ------w D:\WINDOWS\system32\dxtrans.dll
+ 2008-04-23 04:16:28 214,528 ----a-w D:\WINDOWS\system32\dxtrans.dll
- 2008-03-01 13:06:21 63,488 ------w D:\WINDOWS\system32\icardie.dll
+ 2008-04-23 04:16:28 63,488 ----a-w D:\WINDOWS\system32\icardie.dll
- 2008-03-01 13:06:22 383,488 ------w D:\WINDOWS\system32\ieapfltr.dll
+ 2008-04-23 04:16:28 383,488 ----a-w D:\WINDOWS\system32\ieapfltr.dll
- 2008-03-01 13:06:24 6,066,176 ------w D:\WINDOWS\system32\ieframe.dll
+ 2008-04-23 04:16:28 6,066,176 ----a-w D:\WINDOWS\system32\ieframe.dll
- 2008-03-01 13:06:25 267,776 ------w D:\WINDOWS\system32\iertutil.dll
+ 2008-04-23 04:16:28 267,776 ----a-w D:\WINDOWS\system32\iertutil.dll
- 2008-03-01 13:06:25 27,648 ------w D:\WINDOWS\system32\jsproxy.dll
+ 2008-04-23 04:16:28 27,648 ----a-w D:\WINDOWS\system32\jsproxy.dll
- 2008-03-01 13:06:26 459,264 ------w D:\WINDOWS\system32\msfeeds.dll
+ 2008-04-23 04:16:28 459,264 ----a-w D:\WINDOWS\system32\msfeeds.dll
- 2008-03-01 13:06:26 52,224 ------w D:\WINDOWS\system32\msfeedsbs.dll
+ 2008-04-23 04:16:28 52,224 ----a-w D:\WINDOWS\system32\msfeedsbs.dll
- 2008-03-01 13:06:30 3,591,680 ------w D:\WINDOWS\system32\mshtml.dll
+ 2008-04-23 16:46:30 3,591,680 ----a-w D:\WINDOWS\system32\mshtml.dll
- 2008-03-01 13:06:29 44,544 ------w D:\WINDOWS\system32\pngfilt.dll
+ 2008-04-23 04:16:28 44,544 ----a-w D:\WINDOWS\system32\pngfilt.dll
- 2008-03-01 13:06:29 105,984 ------w D:\WINDOWS\system32\url.dll
+ 2008-04-23 04:16:28 105,984 ----a-w D:\WINDOWS\system32\url.dll
- 2008-03-01 13:06:30 1,159,680 ------w D:\WINDOWS\system32\urlmon.dll
+ 2008-04-23 04:16:29 1,159,680 ----a-w D:\WINDOWS\system32\urlmon.dll
- 2008-03-01 13:06:30 233,472 ------w D:\WINDOWS\system32\webcheck.dll
+ 2008-04-23 04:16:29 233,472 ----a-w D:\WINDOWS\system32\webcheck.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"Yahoo! Pager"="D:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-11-06 19:51 3810544]
"SpybotSD TeaTimer"="D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"MsnMsgr"="D:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-11-07 15:34 3739672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="D:\WINDOWS\system32\NvCpl.dll" [2007-05-22 20:05 8433664]
"HP Component Manager"="D:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18 241664]
"AVG8_TRAY"="D:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-10 20:01 1177368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"LHTTSFRF"="advpack.dll" [2008-04-23 09:46 124928 D:\WINDOWS\system32\advpack.dll]

D:\Documents and Settings\Tanya\Start Menu\Programs\Startup\
KeyboardManager.lnk - D:\Program Files\Keyboard Manager\Manager Utility\KeyboardManager.exe [2007-03-27 14:39:58 1359872]
RTLCPL.lnk - D:\Program Files\Realtek\InstallShield\RTLCPL.exe [2008-02-23 19:25:54 9715200]

D:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 05:19:24 237568]
Ralink Wireless Utility.lnk - D:\Program Files\RALINK\Common\RaUI.exe [2008-02-23 19:43:54 2101248]
Run Google Web Accelerator.lnk - D:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe [2007-07-09 22:24:38 1134592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
--a------ 2007-01-02 02:52 3739648 D:\Program Files\Google\Google Talk\googletalk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 00:47 31016 D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-05-22 20:05 8433664 D:\WINDOWS\System32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-11-06 19:51 3810544 D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Pml Driver HPZ12"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"D:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"D:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"D:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"D:\\Program Files\\SopCast\\SopCast.exe"=
"D:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"D:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"D:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"D:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"D:\\Program Files\\uTorrent\\uTorrent.exe"=
"D:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"D:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"D:\\Program Files\\Messenger\\msmsgs.exe"=
"D:\\Program Files\\Opera 9\\Opera.exe"=
"D:\\Program Files\\SopCast\\sopvod.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"D:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"D:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R0 AvgRkx86;avgrkx86.sys;D:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-06-10 20:02]
R1 AvgLdx86;AVG AVI Loader Driver x86;D:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-10 20:01]
R2 avg8wd;AVG8 WatchDog;D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-10 20:01]
R2 avgfws8;AVG8 Firewall;D:\PROGRA~1\AVG\AVG8\avgfws8.exe [2008-06-10 20:01]
R2 AvgTdiX;AVG8 Network Redirector;D:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-10 20:02]
R3 Avgfwdx;Avgfwdx;D:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-06-10 19:38]
R3 qkbfiltr;Keyboard Filter Driver;D:\WINDOWS\system32\DRIVERS\qkbfiltr.sys [2007-02-01 07:08]
R3 TDHost;TDHost;D:\WINDOWS\system32\drivers\TDHost.sys [2002-11-26 12:04]
S2 STUDSRV;Student Service;D:\Program Files\Radix\SmartClass\GATESRV.exe []
S3 Avgfwfd;AVG network filter service;D:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-06-10 19:38]

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-14 19:15:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-14 19:16:09
ComboFix-quarantined-files.txt 2008-06-14 13:46:07
ComboFix2.txt 2008-06-13 01:26:39
ComboFix3.txt 2008-06-11 16:07:33

Pre-Run: 18,169,475,072 bytes free
Post-Run: 18,526,277,632 bytes free

254 --- E O F --- 2008-06-13 01:14:56

My computer is unchanged as I never had a problem with it.My antivirus had started detecting the malware but was unable to remove it.That's why I posted the log.BTW whenever I start my computer or plug in a device with autorun my computer shows me HP 4200 series installation screen.I had installed this software after I was infected but it has been continuing since then.I don't know wheather it's a bug in the installer or due to the malware.

THANKS :thumbsup:

#11 Baabiouz

Baabiouz

    Finnish Malware Fighter


  • Members
  • 3,355 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:12:05 PM

Posted 15 June 2008 - 03:02 PM

Hello

BTW whenever I start my computer or plug in a device with autorun my computer shows me HP 4200 series installation screen.


Have you tried reinstall that program?


Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Next we remove all used tools.

Please download OTCleanIt and save it to desktop.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
Note: If you receive a warning from your firewall or other security programs regarding OTCleanIt attempting to contact the internet, please allow it to do so.
  • Disable and Enable System Restore. - If you are using Windows XP or Vista then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

    You can find instructions on how to enable and re-enable system restore here:

    Windows XP System Restore Guide

    or

    Windows Vista System Restore Guide
Re-enable system restore with instructions from tutorial above
  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.

    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:

    Instructions for Spybot S & D

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
  • Comodo BOCLEAN <= Stop identity thieves from getting personal information. Instantly detects well over 1,000,000 unique, variant and repack malware in total. And it's free.
  • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
    Using Winpatrol to protect your computer from malicious software
Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place

Happy surfing and stay clean!
Posted Image

#12 don77

don77

    Forum Regular


  • Members
  • 3,212 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Boston Mass
  • Local time:04:05 AM

Posted 20 June 2008 - 10:17 PM

This thread will now be closed.
If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you.
Include the address of this thread in your request.
If you should have a new issue, please start a new topic.
This applies only to the original topic starter.
Everyone else please begin a New Topic.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users