Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

SKYNET virus and Trojan.FakeAlert.H


  • This topic is locked This topic is locked
3 replies to this topic

#1 violentgray

violentgray

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:35 AM

Posted 07 August 2009 - 07:38 PM

Please help!! I am up to my wits end with this virus/Malware and this is the final step before reload.

I have tried Adaware, Spybot, Malbytes, Super anti-spyware, and the atf cleaner (all during the same session) in safe mode .

I have a DDS log and looking for anyones help or advise.

The SKYNET files keep getting reloaded and I cannot figure out the file/program/registry entry that is doing so.


DDS (Ver_09-07-30.01) - NTFSx86
Run by Administrator at 19:27:44.90 on Fri 08/07/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.588 [GMT -5:00]

FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkService.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HPQ\IAM\bin\asghost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k Cognizance
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
C:\Program Files\DisplayLink Core Software\DisplayLinkUI.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
mSearchAssistant = hxxp://www.google.com/ie
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: HP Credential Manager for ProtectTools: {df21f1db-80c6-11d3-9483-b03d0ec10000} - c:\program files\hpq\iam\bin\ItIeAddIN.dll
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRunOnce: [SpybotDeletingB7838] command.com /c del "c:\windows\system32\drivers\SKYNETrjoowgar.sys_old"
uRunOnce: [SpybotDeletingD134] cmd.exe /c del "c:\windows\system32\drivers\SKYNETrjoowgar.sys_old"
uRunOnce: [SpybotDeletingB8871] command.com /c del "c:\windows\system32\drivers\SKYNETrjoowgar.sys"
uRunOnce: [SpybotDeletingD3192] cmd.exe /c del "c:\windows\system32\drivers\SKYNETrjoowgar.sys"
uRunOnce: [SpybotDeletingB7736] command.com /c del "c:\windows\system32\SKYNETgvmqfvas.dll_old"
uRunOnce: [SpybotDeletingD1084] cmd.exe /c del "c:\windows\system32\SKYNETgvmqfvas.dll_old"
uRunOnce: [SpybotDeletingB6352] command.com /c del "c:\windows\system32\SKYNETgvmqfvas.dll"
uRunOnce: [SpybotDeletingD7747] cmd.exe /c del "c:\windows\system32\SKYNETgvmqfvas.dll"
uRunOnce: [SpybotDeletingB1945] command.com /c del "c:\windows\system32\SKYNETsvppbrsk.dll_old"
uRunOnce: [SpybotDeletingD1908] cmd.exe /c del "c:\windows\system32\SKYNETsvppbrsk.dll_old"
uRunOnce: [SpybotDeletingB6490] command.com /c del "c:\windows\system32\SKYNETsvppbrsk.dll"
uRunOnce: [SpybotDeletingD2973] cmd.exe /c del "c:\windows\system32\SKYNETsvppbrsk.dll"
uRunOnce: [SpybotDeletingB1378] command.com /c del "c:\windows\system32\SKYNETwexjkelw.dat_old"
uRunOnce: [SpybotDeletingD4254] cmd.exe /c del "c:\windows\system32\SKYNETwexjkelw.dat_old"
uRunOnce: [SpybotDeletingB2776] command.com /c del "c:\windows\system32\SKYNETwexjkelw.dat"
uRunOnce: [SpybotDeletingD9543] cmd.exe /c del "c:\windows\system32\SKYNETwexjkelw.dat"
uRunOnce: [SpybotDeletingB3433] command.com /c del "c:\windows\system32\SKYNETylqpqjwb.dat_old"
uRunOnce: [SpybotDeletingD3093] cmd.exe /c del "c:\windows\system32\SKYNETylqpqjwb.dat_old"
uRunOnce: [SpybotDeletingB6141] command.com /c del "c:\windows\system32\SKYNETylqpqjwb.dat"
uRunOnce: [SpybotDeletingD7117] cmd.exe /c del "c:\windows\system32\SKYNETylqpqjwb.dat"
mRun: [PTHOSTTR] c:\program files\hpq\hp protecttools security manager\PTHOSTTR.EXE /Start
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
mRun: [hpbdfawep] c:\program files\hp\dfawep\bin\hpbdfawep.exe 1
mRun: [HPWireless] "c:\program files\hp wireless adapter\HPWLAN.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
mRunOnce: [SpybotDeletingA6000] command.com /c del "c:\windows\system32\drivers\SKYNETrjoowgar.sys_old"
mRunOnce: [SpybotDeletingC6599] cmd.exe /c del "c:\windows\system32\drivers\SKYNETrjoowgar.sys_old"
mRunOnce: [SpybotDeletingA1613] command.com /c del "c:\windows\system32\drivers\SKYNETrjoowgar.sys"
mRunOnce: [SpybotDeletingC6196] cmd.exe /c del "c:\windows\system32\drivers\SKYNETrjoowgar.sys"
mRunOnce: [SpybotDeletingA2912] command.com /c del "c:\windows\system32\SKYNETgvmqfvas.dll_old"
mRunOnce: [SpybotDeletingC4724] cmd.exe /c del "c:\windows\system32\SKYNETgvmqfvas.dll_old"
mRunOnce: [SpybotDeletingA3868] command.com /c del "c:\windows\system32\SKYNETgvmqfvas.dll"
mRunOnce: [SpybotDeletingC9781] cmd.exe /c del "c:\windows\system32\SKYNETgvmqfvas.dll"
mRunOnce: [SpybotDeletingA3490] command.com /c del "c:\windows\system32\SKYNETsvppbrsk.dll_old"
mRunOnce: [SpybotDeletingC7509] cmd.exe /c del "c:\windows\system32\SKYNETsvppbrsk.dll_old"
mRunOnce: [SpybotDeletingA6550] command.com /c del "c:\windows\system32\SKYNETsvppbrsk.dll"
mRunOnce: [SpybotDeletingC8634] cmd.exe /c del "c:\windows\system32\SKYNETsvppbrsk.dll"
mRunOnce: [SpybotDeletingA8804] command.com /c del "c:\windows\system32\SKYNETwexjkelw.dat_old"
mRunOnce: [SpybotDeletingC1213] cmd.exe /c del "c:\windows\system32\SKYNETwexjkelw.dat_old"
mRunOnce: [SpybotDeletingA1418] command.com /c del "c:\windows\system32\SKYNETwexjkelw.dat"
mRunOnce: [SpybotDeletingC6103] cmd.exe /c del "c:\windows\system32\SKYNETwexjkelw.dat"
mRunOnce: [SpybotDeletingA3420] command.com /c del "c:\windows\system32\SKYNETylqpqjwb.dat_old"
mRunOnce: [SpybotDeletingC3775] cmd.exe /c del "c:\windows\system32\SKYNETylqpqjwb.dat_old"
mRunOnce: [SpybotDeletingA6072] command.com /c del "c:\windows\system32\SKYNETylqpqjwb.dat"
mRunOnce: [SpybotDeletingC481] cmd.exe /c del "c:\windows\system32\SKYNETylqpqjwb.dat"
dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\pokerstars.net\PokerStarsUpdate.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
Notify: igfxcui - igfxdev.dll
Notify: OneCard - c:\program files\hpq\iam\bin\AsWlnPkg.dll
LSA: Notification Packages = scecli AsWlnPkg

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\jgvv5jbh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-20 64160]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-6-16 28544]
R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [2007-6-13 91136]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-8-6 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-8-6 74480]
R2 ASChannel;Local Communication Channel;c:\windows\system32\svchost.exe -k Cognizance [2004-8-4 14336]
R2 DisplayLinkService;DisplayLink Service;c:\program files\displaylink core software\DisplayLinkService.exe [2008-11-20 443752]
R2 HPEAPPkt;Realtek EAPPkt Protocol(HP);c:\windows\system32\drivers\HPEAPPkt.sys [2007-10-5 68864]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-8-18 1174152]
R3 DisplayLinkGA;DisplayLinkGA;c:\windows\system32\drivers\DisplayLinkGAport.sys [2008-11-20 20736]
R3 DisplayLinkmirror;DisplayLinkmirror;c:\windows\system32\drivers\DisplayLinkmirrorport.sys [2008-11-20 18816]
R3 hpnuhst;HP NUSB Host;c:\windows\system32\drivers\hpnuhst.sys [2007-10-5 10752]
R3 HPNUHUB;HP NUSB Hub;c:\windows\system32\drivers\hpnuhub.sys [2007-10-5 37120]
R3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [2007-6-13 23180]
S3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\drivers\DisplayLinkUsbPort.sys [2009-5-27 20992]
S3 RTLWUSB;Wireless Adapter;c:\windows\system32\drivers\HPL8187.SYS [2007-10-5 189440]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-8-6 7408]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [2007-10-5 13532]

=============== Created Last 30 ================

2009-08-07 18:34 <DIR> --d----- c:\program files\Trend Micro
2009-08-06 19:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-08-06 19:20 <DIR> --d----- c:\docume~1\admini~1\applic~1\SUPERAntiSpyware.com
2009-08-06 19:20 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-08-04 19:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\13459684
2009-07-31 20:12 <DIR> --d----- c:\docume~1\admini~1\applic~1\Malwarebytes
2009-07-31 20:12 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-31 20:12 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-07-31 20:12 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-07-31 20:12 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-30 17:54 23 a------- c:\windows\47
2009-07-20 19:01 15,688 a------- c:\windows\system32\lsdelete.exe
2009-07-20 18:55 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-07-20 18:54 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-20 18:18 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-07-20 18:18 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy

==================== Find3M ====================

2009-07-19 08:33 3,597,824 -------- c:\windows\system32\dllcache\mshtml.dll
2009-07-19 08:32 6,067,200 -------- c:\windows\system32\dllcache\ieframe.dll
2009-06-29 06:07 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2009-06-29 06:07 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-06-29 03:35 634,632 -------- c:\windows\system32\dllcache\iexplore.exe
2009-06-29 03:33 2,452,872 -------- c:\windows\system32\dllcache\ieapfltr.dat
2009-06-29 03:33 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
2009-06-16 09:55 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 09:55 82,432 a------- c:\windows\system32\fontsub.dll
2009-06-16 09:55 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
2009-06-16 09:55 82,432 -------- c:\windows\system32\dllcache\fontsub.dll
2009-06-03 14:27 1,290,752 a------- c:\windows\system32\quartz.dll
2009-06-03 14:27 1,290,752 -------- c:\windows\system32\dllcache\quartz.dll
2009-05-27 18:24 1,045,776 a------- c:\windows\system32\MSJET35.DLL
2009-05-27 18:24 368,912 a------- c:\windows\system32\VBAR332.DLL
2009-05-27 18:24 252,176 a------- c:\windows\system32\MSRD2X35.DLL
2009-05-27 18:24 123,664 a------- c:\windows\system32\MSJINT35.DLL
2009-05-27 18:24 24,848 a------- c:\windows\system32\MSJTER35.DLL

Attached Files



BC AdBot (Login to Remove)

 


#2 violentgray

violentgray
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:35 AM

Posted 07 August 2009 - 09:01 PM

bump

#3 violentgray

violentgray
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:35 AM

Posted 07 August 2009 - 10:17 PM

All,

I used Combo fix and this was taken care of completely. Please becareful if anyone uses this program. You must disable everything (security, antivirus, all of it). before you click okay .... but it is extremely effective.

Thanks to Bleeping CPU for posting on this ......please close this topic.

#4 Guest_The weatherman_*

Guest_The weatherman_*

  • Guests
  • OFFLINE
  •  

Posted 08 August 2009 - 06:03 PM

Thanks for letting us know violentgray.

ComboFix is intended by its creator to be "used under the guidance and supervision of an expert", NOT for private use. Please read Combofix's Disclaimer. Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users