Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with AntiSpyware 2010 and Antivirus Pro


  • This topic is locked This topic is locked
14 replies to this topic

#1 lokoryan

lokoryan

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:37 PM

Posted 18 October 2009 - 10:59 PM

Hey guys,

I started out at the "Am I Infected?" forum here: http://www.bleepingcomputer.com/forums/t/252135/infected-and-cant-open-malwarebytes/

The general gist of my problem is that my computer is infected with PC AntiSpyware 2010 and Windows Antivirus Pro. I've tried using Malwarebytes (even changing it's name/extension), but now it doesn't work.

More importantly, I've also used the instructions to get the DDS logs and RootRepeal log and they didn't work. For DDS, the expected black screen popped-up but it was only for a second and then nothing would happen. And for RootRepeal, it was able to start up and it was even scanning before suddenly closing. Now it won't even run when I click on it.

I *was* able to get a win32kdiag log which I've copied & pasted below. Thanks for all of your help!

******************
Win32KDiag
******************

Running from: C:\Documents and Settings\Ryan\Desktop\Win32kDiag.exe

Log file at : C:\Documents and Settings\Ryan\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'...

Found mount point : C:\WINDOWS\$hf_mig$\KB904706\KB904706

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB912812\KB912812

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB916281\KB916281

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB918899\KB918899

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB920213\KB920213

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB922760\KB922760

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB924496\KB924496

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB929338\KB929338

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB931784\KB931784

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB932168\KB932168

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB933729\KB933729

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB941568\KB941568

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\$hf_mig$\KB943460\KB943460

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\assembly\tmp\tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Config\Config

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Connection Wizard\Connection Wizard

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d1\d1

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d2\d2

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d3\d3

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d4\d4

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d5\d5

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d6\d6

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d7\d7

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d8\d8

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ime\imejp\applets\applets

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ime\imejp98\imejp98

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\java\classes\classes

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\java\trustlib\trustlib

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Temporary ASP.NET Files\Bind Logs\Bind Logs

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\msapps\msinfo\msinfo

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\msdownld.tmp\msdownld.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\helpctr\batch\batch

Mount point destination : \Device\__max++>\^

Cannot access: C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe

[1] 2004-08-10 07:00:00 743936 C:\WINDOWS\$NtServicePackUninstall$\helpsvc.exe (Microsoft Corporation)

[1] 2008-04-13 20:12:21 744448 C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe ()

[1] 2008-04-13 20:12:21 744448 C:\WINDOWS\ServicePackFiles\i386\helpsvc.exe (Microsoft Corporation)


Found mount point : C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\helpctr\System\DFS\DFS

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\helpctr\Temp\Temp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\PIF\PIF

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Registration\CRMLog\CRMLog

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\355f788b6de8a3ec79e9aa172e6317f1\backup\backup

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\82c738ec00f0f07f8ea182bc95439593\backup\backup

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\f5a5f59178fa0424f8cbd036eccff011\f5a5f59178fa0424f8cbd036eccff011

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\SxsCaPendDel\SxsCaPendDel

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1025\1025

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1028\1028

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1031\1031

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1037\1037

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1041\1041

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1042\1042

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1054\1054

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\2052\2052

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\3076\3076

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\3com_dmi\3com_dmi

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\appmgmt\MACHINE\MACHINE

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\appmgmt\S-1-5-21-559568621-3846512330-3547244636-1005\S-1-5-21-559568621-3846512330-3547244636-1005

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Google\Plugin\Plugin

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Identities\{4E3254D7-522A-412A-9296-3F4767B3A2CB}\{4E3254D7-522A-412A-9296-3F4767B3A2CB}

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\S-1-5-21-343818398-1004336348-839522115-500\S-1-5-21-343818398-1004336348-839522115-500

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\S-1-5-21-559568621-3846512330-3547244636-500\S-1-5-21-559568621-3846512330-3547244636-500

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Media Player\Media Player

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\MMC\MMC

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\Certificates\Certificates

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CRLs\CRLs

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CTLs\CTLs

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Sun\Java\Deployment\javaws\cache\cache

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Google\Google Desktop\691c4f3c2060\691c4f3c2060

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\CD Burning\CD Burning

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\S-1-5-21-343818398-1004336348-839522115-500\S-1-5-21-343818398-1004336348-839522115-500

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\S-1-5-21-559568621-3846512330-3547244636-500\S-1-5-21-559568621-3846512330-3547244636-500

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\OFFICE\OFFICE

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Musicmatch\Jukebox\Cache\Cache

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\Temp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\My Documents\CCWin\Address Book\Address Book

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\NetHood\NetHood

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\PrintHood\PrintHood

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\dhcp\dhcp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\drivers\disdn\disdn

Mount point destination : \Device\__max++>\^

Cannot access: C:\WINDOWS\system32\eventlog.dll

[1] 2004-08-10 07:00:00 55808 C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll (Microsoft Corporation)

[1] 2008-04-13 20:11:53 56320 C:\WINDOWS\ServicePackFiles\i386\eventlog.dll (Microsoft Corporation)

[1] 2008-04-13 20:11:53 63488 C:\WINDOWS\system32\eventlog.dll ()

[2] 2008-04-13 20:11:53 56320 C:\WINDOWS\system32\logevent.dll (Microsoft Corporation)

[1] 2004-08-10 07:00:00 55808 C:\i386\eventlog.dll (Microsoft Corporation)


Found mount point : C:\WINDOWS\system32\export\export

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\Microsoft\Crypto\RSA\MachineKeys\MachineKeys

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\mui\dispspec\dispspec

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\oobe\html\oemcust\oemcust

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\oobe\html\oemhw\oemhw

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\oobe\html\oemreg\oemreg

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\oobe\sample\sample

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\ShellExt\ShellExt

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\spool\PRINTERS\PRINTERS

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\wbem\mof\bad\bad

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\wbem\mof\good\good

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\wbem\snmp\snmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\wins\wins

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\xircom\xircom

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\UGF0cmljaw\UGF0cmljaw

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp

Mount point destination : \Device\__max++>\^

Finished!

******************

And here is the log.txt I got from the command prompt.

******************
Log.txt
******************

Volume in drive C has no label.
Volume Serial Number is BCB8-1825

Directory of C:\WINDOWS\$NtServicePackUninstall$

08/10/2004 07:00 AM 180,224 scecli.dll

Directory of C:\WINDOWS\$NtServicePackUninstall$

08/10/2004 07:00 AM 407,040 netlogon.dll

Directory of C:\WINDOWS\$NtServicePackUninstall$

08/10/2004 07:00 AM 55,808 eventlog.dll
3 File(s) 643,072 bytes

Directory of C:\WINDOWS\ServicePackFiles\i386

04/13/2008 08:12 PM 181,248 scecli.dll

Directory of C:\WINDOWS\ServicePackFiles\i386

04/13/2008 08:12 PM 407,040 netlogon.dll

Directory of C:\WINDOWS\ServicePackFiles\i386

04/13/2008 08:11 PM 56,320 eventlog.dll
3 File(s) 644,608 bytes

Directory of C:\WINDOWS\system32

04/13/2008 08:12 PM 181,248 scecli.dll

Directory of C:\WINDOWS\system32

04/13/2008 08:12 PM 407,040 netlogon.dll

Directory of C:\WINDOWS\system32

04/13/2008 08:11 PM 63,488 eventlog.dll
3 File(s) 651,776 bytes

Total Files Listed:
9 File(s) 1,939,456 bytes
0 Dir(s) 30,652,284,928 bytes free

******************

Thanks again!

BC AdBot (Login to Remove)

 


#2 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,590 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:37 PM

Posted 19 October 2009 - 12:32 AM

Hi, lokoryan :(

Welcome.

Please follow these steps:

Step 1

Click on Start->Run, copy and paste the following command into the "Run" box (including the quotation marks), and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here in your next reply.

"%userprofile%\desktop\win32kdiag.exe" -f -r

Step 2

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    Posted Image

    Posted Image

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\Combo-Fix.txt" .
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.

Please do not install any new programs or update anything unless told to do so while we are fixing your problem.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#3 lokoryan

lokoryan
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:37 PM

Posted 19 October 2009 - 12:29 PM

Hi JSntgRvr. Thanks for your help!

Okay so first, I c&p the command in the Run box, but nothing happened.

Then I followed your instructions for ComboFix. Immediately the program found something in the rootkit and had to reboot the computer. When my computer rebooted, I was happy to find that the red X that was on my status bar was gone.

ComboFix was still running, mind you, since it's blue window was still on my desktop and I still didn't have a log report. However, it's been like this for about 20 minutes now with the following words:
"GREP" is not recognized as an internal or external command, operable program or batch file."

Just wanted to know if this is normal or if the program got stuck and i should re-click on it, etc.

Thanks.

#4 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,590 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:37 PM

Posted 19 October 2009 - 02:00 PM

Hi, lokoryan
  • Copy the entire contents of the Quote Box below to Notepad.
  • Leave an empty line at the end of the script.
  • Name the file as fix.bat
  • Change the Save as Type to All Files
  • and Save it on the desktop
  • Once saved, double click on the fix.bat file and post the resulting report.

@echo Off
if exist "%temp%\log.txt" del "%temp%\log.txt"
for %%g in (
"C:\WINDOWS\$hf_mig$\KB904706\KB904706"
"C:\WINDOWS\$hf_mig$\KB912812\KB912812"
"C:\WINDOWS\$hf_mig$\KB916281\KB916281"
"C:\WINDOWS\$hf_mig$\KB918899\KB918899"
"C:\WINDOWS\$hf_mig$\KB920213\KB920213"
"C:\WINDOWS\$hf_mig$\KB922760\KB922760"
"C:\WINDOWS\$hf_mig$\KB924496\KB924496"
"C:\WINDOWS\$hf_mig$\KB929338\KB929338"
"C:\WINDOWS\$hf_mig$\KB931784\KB931784"
"C:\WINDOWS\$hf_mig$\KB932168\KB932168"
"C:\WINDOWS\$hf_mig$\KB933729\KB933729"
"C:\WINDOWS\$hf_mig$\KB941568\KB941568"
"C:\WINDOWS\$hf_mig$\KB943460\KB943460"
"C:\WINDOWS\assembly\tmp\tmp"
"C:\WINDOWS\Config\Config"
"C:\WINDOWS\Connection Wizard\Connection Wizard"
"C:\WINDOWS\CSC\d1\d1"
"C:\WINDOWS\CSC\d2\d2"
"C:\WINDOWS\CSC\d3\d3"
"C:\WINDOWS\CSC\d4\d4"
"C:\WINDOWS\CSC\d5\d5"
"C:\WINDOWS\CSC\d6\d6"
"C:\WINDOWS\CSC\d7\d7"
"C:\WINDOWS\CSC\d8\d8"
"C:\WINDOWS\ime\imejp\applets\applets"
"C:\WINDOWS\ime\imejp98\imejp98"
"C:\WINDOWS\java\classes\classes"
"C:\WINDOWS\java\trustlib\trustlib"
"C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Temporary ASP.NET Files\Bind Logs\Bind Logs"
"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs"
"C:\WINDOWS\msapps\msinfo\msinfo"
"C:\WINDOWS\msdownld.tmp\msdownld.tmp"
"C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES"
"C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF"
"C:\WINDOWS\pchealth\helpctr\batch\batch"
"C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint"
"C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles"
"C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs"
"C:\WINDOWS\pchealth\helpctr\System\DFS\DFS"
"C:\WINDOWS\pchealth\helpctr\Temp\Temp"
"C:\WINDOWS\PIF\PIF"
"C:\WINDOWS\Registration\CRMLog\CRMLog"
"C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded"
"C:\WINDOWS\SoftwareDistribution\Download\355f788b6de8a3ec79e9aa172e6317f1\backup\backup"
"C:\WINDOWS\SoftwareDistribution\Download\82c738ec00f0f07f8ea182bc95439593\backup\backup"
"C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\f5a5f59178fa0424f8cbd036eccff011\f5a5f59178fa0424f8cbd036eccff011"
"C:\WINDOWS\Sun\Java\Deployment\Deployment"
"C:\WINDOWS\SxsCaPendDel\SxsCaPendDel"
"C:\WINDOWS\system32\1025\1025"
"C:\WINDOWS\system32\1028\1028"
"C:\WINDOWS\system32\1031\1031"
"C:\WINDOWS\system32\1037\1037"
"C:\WINDOWS\system32\1041\1041"
"C:\WINDOWS\system32\1042\1042"
"C:\WINDOWS\system32\1054\1054"
"C:\WINDOWS\system32\2052\2052"
"C:\WINDOWS\system32\3076\3076"
"C:\WINDOWS\system32\3com_dmi\3com_dmi"
"C:\WINDOWS\system32\appmgmt\MACHINE\MACHINE"
"C:\WINDOWS\system32\appmgmt\S-1-5-21-559568621-3846512330-3547244636-1005\S-1-5-21-559568621-3846512330-3547244636-1005"
"C:\WINDOWS\system32\config\systemprofile\Application Data\Google\Plugin\Plugin"
"C:\WINDOWS\system32\config\systemprofile\Application Data\Identities\{4E3254D7-522A-412A-9296-3F4767B3A2CB}\{4E3254D7-522A-412A-9296-3F4767B3A2CB}"
"C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\S-1-5-21-343818398-1004336348-839522115-500\S-1-5-21-343818398-1004336348-839522115-500"
"C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\S-1-5-21-559568621-3846512330-3547244636-500\S-1-5-21-559568621-3846512330-3547244636-500"
"C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Media Player\Media Player
"C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\MMC\MMC
"C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\Certificates\Certificates"
"C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CRLs\CRLs"
"C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CTLs\CTLs"
"C:\WINDOWS\system32\config\systemprofile\Application Data\Sun\Java\Deployment\javaws\cache\cache"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Google\Google Desktop\691c4f3c2060\691c4f3c2060"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\CD Burning\CD Burning"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\S-1-5-21-343818398-1004336348-839522115-500\S-1-5-21-343818398-1004336348-839522115-500"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\S-1-5-21-559568621-3846512330-3547244636-500\S-1-5-21-559568621-3846512330-3547244636-500"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\OFFICE\OFFICE"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Musicmatch\Jukebox\Cache\Cache"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\Temp"
"C:\WINDOWS\system32\config\systemprofile\My Documents\CCWin\Address Book\Address Book"
"C:\WINDOWS\system32\config\systemprofile\NetHood\NetHood"
"C:\WINDOWS\system32\config\systemprofile\PrintHood\PrintHood"
"C:\WINDOWS\system32\dhcp\dhcp"
"C:\WINDOWS\system32\drivers\disdn\disdn"
"C:\WINDOWS\system32\export\export"
"C:\WINDOWS\system32\Microsoft\Crypto\RSA\MachineKeys\MachineKeys"
"C:\WINDOWS\system32\mui\dispspec\dispspec"
"C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup"
"C:\WINDOWS\system32\oobe\html\oemcust\oemcust"
"C:\WINDOWS\system32\oobe\html\oemhw\oemhw"
"C:\WINDOWS\system32\oobe\html\oemreg\oemreg"
"C:\WINDOWS\system32\oobe\sample\sample"
"C:\WINDOWS\system32\ShellExt\ShellExt"
"C:\WINDOWS\system32\spool\PRINTERS\PRINTERS"
"C:\WINDOWS\system32\wbem\mof\bad\bad"
"C:\WINDOWS\system32\wbem\mof\good\good"
"C:\WINDOWS\system32\wbem\snmp\snmp"
"C:\WINDOWS\system32\wins\wins"
"C:\WINDOWS\system32\xircom\xircom"
"C:\WINDOWS\UGF0cmljaw\UGF0cmljaw"
"C:\WINDOWS\WinSxS\InstallTemp\InstallTemp"
) do (
rd /s/q %%g >nul 2>&1
if exist %%g (echo %%~g .... Unable to Delete>>"%temp%\log.txt") ELSE echo %%~g ..... Deleted Successfully !!>>"%temp%\log.txt"
)
Copy C:\WINDOWS\ServicePackFiles\i386\eventlog.dll C:\
start notepad "%temp%\log.txt"
Exit



1. Please download The Avenger by Swandog46 to your Desktop.
  • Right click on the Avenger.zip folder and select "Extract All..."
  • Follow the prompts and extract the avenger folder to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Begin copying here:
Files to move:
C:\eventlog.dll | C:\WINDOWS\system32\eventlog.dll

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, open the avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avengerís actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your next reply.

Click on Combo-fix and follow the instructions above. Post also the resulting report.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#5 lokoryan

lokoryan
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:37 PM

Posted 19 October 2009 - 03:05 PM

HI JSntgRvr! I think it worked. Here are the logs you requested.

First the fix.bat log, then the Avenger log, and finally the ComboFix log.

1. Fix.Bat Log


C:\WINDOWS\$hf_mig$\KB904706\KB904706 ..... Deleted Successfully !!
C:\WINDOWS\$hf_mig$\KB912812\KB912812 ..... Deleted Successfully !!
C:\WINDOWS\$hf_mig$\KB916281\KB916281 ..... Deleted Successfully !!
C:\WINDOWS\$hf_mig$\KB918899\KB918899 ..... Deleted Successfully !!
C:\WINDOWS\$hf_mig$\KB920213\KB920213 ..... Deleted Successfully !!
C:\WINDOWS\$hf_mig$\KB922760\KB922760 ..... Deleted Successfully !!
C:\WINDOWS\$hf_mig$\KB924496\KB924496 ..... Deleted Successfully !!
C:\WINDOWS\$hf_mig$\KB929338\KB929338 ..... Deleted Successfully !!
C:\WINDOWS\$hf_mig$\KB931784\KB931784 ..... Deleted Successfully !!
C:\WINDOWS\$hf_mig$\KB932168\KB932168 ..... Deleted Successfully !!
C:\WINDOWS\$hf_mig$\KB933729\KB933729 ..... Deleted Successfully !!
C:\WINDOWS\$hf_mig$\KB941568\KB941568 ..... Deleted Successfully !!
C:\WINDOWS\$hf_mig$\KB943460\KB943460 ..... Deleted Successfully !!
C:\WINDOWS\assembly\tmp\tmp ..... Deleted Successfully !!
C:\WINDOWS\Config\Config ..... Deleted Successfully !!
C:\WINDOWS\Connection Wizard\Connection Wizard ..... Deleted Successfully !!
C:\WINDOWS\CSC\d1\d1 ..... Deleted Successfully !!
C:\WINDOWS\CSC\d2\d2 ..... Deleted Successfully !!
C:\WINDOWS\CSC\d3\d3 ..... Deleted Successfully !!
C:\WINDOWS\CSC\d4\d4 ..... Deleted Successfully !!
C:\WINDOWS\CSC\d5\d5 ..... Deleted Successfully !!
C:\WINDOWS\CSC\d6\d6 ..... Deleted Successfully !!
C:\WINDOWS\CSC\d7\d7 ..... Deleted Successfully !!
C:\WINDOWS\CSC\d8\d8 ..... Deleted Successfully !!
C:\WINDOWS\ime\imejp\applets\applets ..... Deleted Successfully !!
C:\WINDOWS\ime\imejp98\imejp98 ..... Deleted Successfully !!
C:\WINDOWS\java\classes\classes ..... Deleted Successfully !!
C:\WINDOWS\java\trustlib\trustlib ..... Deleted Successfully !!
C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Temporary ASP.NET Files\Bind Logs\Bind Logs ..... Deleted Successfully !!
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs ..... Deleted Successfully !!
C:\WINDOWS\msapps\msinfo\msinfo ..... Deleted Successfully !!
C:\WINDOWS\msdownld.tmp\msdownld.tmp ..... Deleted Successfully !!
C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES ..... Deleted Successfully !!
C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF ..... Deleted Successfully !!
C:\WINDOWS\pchealth\helpctr\batch\batch ..... Deleted Successfully !!
C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint ..... Deleted Successfully !!
C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles ..... Deleted Successfully !!
C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs ..... Deleted Successfully !!
C:\WINDOWS\pchealth\helpctr\System\DFS\DFS ..... Deleted Successfully !!
C:\WINDOWS\pchealth\helpctr\Temp\Temp ..... Deleted Successfully !!
C:\WINDOWS\PIF\PIF ..... Deleted Successfully !!
C:\WINDOWS\Registration\CRMLog\CRMLog ..... Deleted Successfully !!
C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded ..... Deleted Successfully !!
C:\WINDOWS\SoftwareDistribution\Download\355f788b6de8a3ec79e9aa172e6317f1\backup\backup ..... Deleted Successfully !!
C:\WINDOWS\SoftwareDistribution\Download\82c738ec00f0f07f8ea182bc95439593\backup\backup ..... Deleted Successfully !!
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\f5a5f59178fa0424f8cbd036eccff011\f5a5f59178fa0424f8cbd036eccff011 ..... Deleted Successfully !!
C:\WINDOWS\Sun\Java\Deployment\Deployment ..... Deleted Successfully !!
C:\WINDOWS\SxsCaPendDel\SxsCaPendDel ..... Deleted Successfully !!
C:\WINDOWS\system32\1025\1025 ..... Deleted Successfully !!
C:\WINDOWS\system32\1028\1028 ..... Deleted Successfully !!
C:\WINDOWS\system32\1031\1031 ..... Deleted Successfully !!
C:\WINDOWS\system32\1037\1037 ..... Deleted Successfully !!
C:\WINDOWS\system32\1041\1041 ..... Deleted Successfully !!
C:\WINDOWS\system32\1042\1042 ..... Deleted Successfully !!
C:\WINDOWS\system32\1054\1054 ..... Deleted Successfully !!
C:\WINDOWS\system32\2052\2052 ..... Deleted Successfully !!
C:\WINDOWS\system32\3076\3076 ..... Deleted Successfully !!
C:\WINDOWS\system32\3com_dmi\3com_dmi ..... Deleted Successfully !!
C:\WINDOWS\system32\appmgmt\MACHINE\MACHINE ..... Deleted Successfully !!
C:\WINDOWS\system32\appmgmt\S-1-5-21-559568621-3846512330-3547244636-1005\S-1-5-21-559568621-3846512330-3547244636-1005 ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Application Data\Google\Plugin\Plugin ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Application Data\Identities\{4E3254D7-522A-412A-9296-3F4767B3A2CB}\{4E3254D7-522A-412A-9296-3F4767B3A2CB} ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\S-1-5-21-343818398-1004336348-839522115-500\S-1-5-21-343818398-1004336348-839522115-500 ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\S-1-5-21-559568621-3846512330-3547244636-500\S-1-5-21-559568621-3846512330-3547244636-500 ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Media Player\Media Player "C:\WINDOWS\system32\config\systemprofile\Application ..... Deleted Successfully !!
Data\Microsoft\MMC\MMC ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\Certificates\Certificates ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CRLs\CRLs ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CTLs\CTLs ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Application Data\Sun\Java\Deployment\javaws\cache\cache ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Google\Google Desktop\691c4f3c2060\691c4f3c2060 ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\CD Burning\CD Burning ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\S-1-5-21-343818398-1004336348-839522115-500\S-1-5-21-343818398-1004336348-839522115-500 ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\S-1-5-21-559568621-3846512330-3547244636-500\S-1-5-21-559568621-3846512330-3547244636-500 ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\OFFICE\OFFICE ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Musicmatch\Jukebox\Cache\Cache ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\Temp ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\My Documents\CCWin\Address Book\Address Book ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\NetHood\NetHood ..... Deleted Successfully !!
C:\WINDOWS\system32\config\systemprofile\PrintHood\PrintHood ..... Deleted Successfully !!
C:\WINDOWS\system32\dhcp\dhcp ..... Deleted Successfully !!
C:\WINDOWS\system32\drivers\disdn\disdn ..... Deleted Successfully !!
C:\WINDOWS\system32\export\export ..... Deleted Successfully !!
C:\WINDOWS\system32\Microsoft\Crypto\RSA\MachineKeys\MachineKeys ..... Deleted Successfully !!
C:\WINDOWS\system32\mui\dispspec\dispspec ..... Deleted Successfully !!
C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup ..... Deleted Successfully !!
C:\WINDOWS\system32\oobe\html\oemcust\oemcust ..... Deleted Successfully !!
C:\WINDOWS\system32\oobe\html\oemhw\oemhw ..... Deleted Successfully !!
C:\WINDOWS\system32\oobe\html\oemreg\oemreg ..... Deleted Successfully !!
C:\WINDOWS\system32\oobe\sample\sample ..... Deleted Successfully !!
C:\WINDOWS\system32\ShellExt\ShellExt ..... Deleted Successfully !!
C:\WINDOWS\system32\spool\PRINTERS\PRINTERS ..... Deleted Successfully !!
C:\WINDOWS\system32\wbem\mof\bad\bad ..... Deleted Successfully !!
C:\WINDOWS\system32\wbem\mof\good\good ..... Deleted Successfully !!
C:\WINDOWS\system32\wbem\snmp\snmp ..... Deleted Successfully !!
C:\WINDOWS\system32\wins\wins ..... Deleted Successfully !!
C:\WINDOWS\system32\xircom\xircom ..... Deleted Successfully !!
C:\WINDOWS\UGF0cmljaw\UGF0cmljaw ..... Deleted Successfully !!
C:\WINDOWS\WinSxS\InstallTemp\InstallTemp ..... Deleted Successfully !!

2. The Avenger Log

Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File move operation "C:\eventlog.dll|C:\WINDOWS\system32\eventlog.dll" completed successfully.

Completed script processing.

*******************

Finished! Terminate.

3. The ComboFix Log

ComboFix 09-10-18.06 - Ryan 10/19/2009 15:26.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.162 [GMT -4:00]
Running from: c:\documents and settings\Ryan\Desktop\Combo-Fix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\atenef.inf
c:\documents and settings\All Users\Application Data\otavecuto.bat
c:\documents and settings\All Users\Application Data\sosujokad.inf
c:\documents and settings\All Users\Documents\ovypegi.reg
c:\documents and settings\Ryan\Application Data\enubipowo.vbs
c:\documents and settings\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\PC_Antispyware2010.lnk
c:\documents and settings\Ryan\Cookies\ifarob._sy
c:\documents and settings\Ryan\Cookies\joduliq.lib
c:\documents and settings\Ryan\Cookies\ofuzifeqys.bin
c:\documents and settings\Ryan\Cookies\onunagaze.reg
c:\documents and settings\Ryan\Cookies\ovurojag.lib
c:\documents and settings\Ryan\Local Settings\Application Data\yhelude.vbs
c:\documents and settings\Ryan\Local Settings\Temporary Internet Files\ajudi._sy
c:\documents and settings\Ryan\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\Ryan\Local Settings\Temporary Internet Files\ibimucada.reg
c:\documents and settings\Ryan\Local Settings\Temporary Internet Files\riwalera.dl
c:\documents and settings\Ryan\Local Settings\Temporary Internet Files\ujobafot.reg
c:\documents and settings\Ryan\Local Settings\Temporary Internet Files\yxakitihoj._dl
c:\documents and settings\Ryan\Local Settings\Temporary Internet Files\zezugowu.exe
c:\documents and settings\Ryan\Start Menu\Programs\PC_Antispyware2010
c:\documents and settings\Ryan\Start Menu\Programs\PC_Antispyware2010\PC_Antispyware2010.lnk
c:\documents and settings\Ryan\Start Menu\Programs\PC_Antispyware2010\Uninstall.lnk
c:\documents and settings\Ryan\Start Menu\Programs\Windows Antivirus Pro
c:\documents and settings\Ryan\Start Menu\Programs\Windows Antivirus Pro\Windows Antivirus Pro.lnk
C:\kvhwftjn.exe
C:\lcbckjms.exe
C:\p2hhr.bat
c:\program files\Common Files\anyb.inf
C:\sdlb.exe
c:\temp\isgTi19
c:\windows\anoxyvux.exe
c:\windows\braviax.exe
c:\windows\bynox.vbs
c:\windows\cru629.dat
c:\windows\geju._sy
c:\windows\itofalega.exe
c:\windows\kb913800.exe
c:\windows\msa.exe
c:\windows\olifuvidur.inf
c:\windows\ppp3.dat
c:\windows\ppp4.dat
c:\windows\register.exe
c:\windows\ruvoxynogu.vbs
c:\windows\system32\_003512_.tmp.dll
c:\windows\system32\_003513_.tmp.dll
c:\windows\system32\_003514_.tmp.dll
c:\windows\system32\_003515_.tmp.dll
c:\windows\system32\_003522_.tmp.dll
c:\windows\system32\_003524_.tmp.dll
c:\windows\system32\_003525_.tmp.dll
c:\windows\system32\_003527_.tmp.dll
c:\windows\system32\_003528_.tmp.dll
c:\windows\system32\_003531_.tmp.dll
c:\windows\system32\_003532_.tmp.dll
c:\windows\system32\_003534_.tmp.dll
c:\windows\system32\_003535_.tmp.dll
c:\windows\system32\_003536_.tmp.dll
c:\windows\system32\_003538_.tmp.dll
c:\windows\system32\_003541_.tmp.dll
c:\windows\system32\_003542_.tmp.dll
c:\windows\system32\_003546_.tmp.dll
c:\windows\system32\_003547_.tmp.dll
c:\windows\system32\_003549_.tmp.dll
c:\windows\system32\_003552_.tmp.dll
c:\windows\system32\_003554_.tmp.dll
c:\windows\system32\_003556_.tmp.dll
c:\windows\system32\_003557_.tmp.dll
c:\windows\system32\_003558_.tmp.dll
c:\windows\system32\_003561_.tmp.dll
c:\windows\system32\_003562_.tmp.dll
c:\windows\system32\_003563_.tmp.dll
c:\windows\system32\_003564_.tmp.dll
c:\windows\system32\_003565_.tmp.dll
c:\windows\system32\_003570_.tmp.dll
c:\windows\system32\_003572_.tmp.dll
c:\windows\system32\_003573_.tmp.dll
c:\windows\system32\_scui.cpl
c:\windows\system32\~.exe
c:\windows\system32\bennuar.old
c:\windows\system32\braviax.exe
c:\windows\system32\cru629.dat
c:\windows\system32\ddDEsot.dll
c:\windows\system32\desot.exe
c:\windows\system32\Drivers\iujpt.sys
c:\windows\system32\drivers\smss.exe
c:\windows\system32\msXMl71.dll
c:\windows\system32\ocefxdej.ini
c:\windows\system32\sonhelp.htm
c:\windows\system32\sysnet.dat
c:\windows\system32\tajf83ikdmf.dll
c:\windows\system32\tapi.nfo
c:\windows\system32\trstpwbb.ini
c:\windows\system32\wisdstr.exe
c:\windows\system32\xotiluj.bat
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\uluv.bat
C:\yihw.exe

Infected copy of c:\windows\system32\drivers\beep.sys was found and disinfected
Restored copy from - c:\i386\beep.sys

c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ANTIPPRO2009_100
-------\Legacy_TDSSSERV
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_AntipPro2009_100

((((((((((((((((((((((((( Files Created from 2009-09-19 to 2009-10-19 )))))))))))))))))))))))))))))))
.

2009-10-19 19:36 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-17 04:55 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-17 04:55 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-17 04:55 . 2009-04-25 04:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-04 16:36 . 2007-09-10 06:32 -------- d-----w- c:\documents and settings\Ryan\Application Data\Skype
2009-08-24 22:15 . 2009-08-24 22:15 14411 ----a-w- c:\program files\Common Files\ipyz.sys
2009-08-24 22:15 . 2009-08-24 22:15 13409 ----a-w- c:\windows\kygemiz.bin
2009-08-24 22:15 . 2009-08-24 22:15 13151 ----a-w- c:\documents and settings\Ryan\Local Settings\Application Data\unet.com
2009-08-24 22:15 . 2009-08-24 22:15 11111 ----a-w- c:\windows\mugiw.pif
2009-08-24 22:15 . 2009-08-24 22:15 10355 ----a-w- c:\documents and settings\Ryan\Local Settings\Application Data\itur.dll
2009-08-24 13:10 . 2007-09-08 02:15 -------- d-----w- c:\documents and settings\Ryan\Application Data\Azureus
2009-08-21 03:46 . 2009-08-21 03:46 -------- d-----w- c:\documents and settings\Ryan\Application Data\Apple Computer
2009-08-13 00:08 . 2009-08-13 00:08 816 ----a-w- c:\program files\vwgitkn.txt
2009-08-12 23:05 . 2009-08-12 23:05 45344 ----a-w- c:\windows\system32\drivers\eqg7a6c.sys
2009-08-11 00:54 . 2007-08-27 05:59 76240 ----a-w- c:\documents and settings\Ryan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2005-08-16 10:18 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2008-02-28 18:30 . 2008-08-17 02:11 8784 ----a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2008-02-28 18:33 . 2008-08-17 02:11 245408 ----a-w- c:\program files\mozilla firefox\plugins\unicows.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2004-08-10 1126400]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-04 68856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-10-17 1197648]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-24 118784]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-1-6 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\program files\TGTSoft\StyleXP\CurrentLogon.EXE"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Clean Access Agent.lnk]
backup=c:\windows\pss\Clean Access Agent.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"aawservice"=2 (0x2)
"WinVNC4"=2 (0x2)
"wuauserv"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\j2re1.4.2_03\\bin\\javaw.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Dell Support\\DSAgnt.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Counter-Strike\\cstrike.exe"=
"c:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\RealVNC\\VNC4\\winvnc4.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"53631:TCP"= 53631:TCP:Azu1
"53631:UDP"= 53631:UDP:Azu2
"22210:TCP"= 22210:TCP:Skype port
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [8/3/2008 9:50 PM 42112]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2/8/2008 8:59 PM 356920]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Ryan\Application Data\Mozilla\Firefox\Profiles\0bq4y3uq.default\
FF - prefs.js: browser.startup.homepage - cnn.com
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRACtrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-OE_OEM - c:\program files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
Notify-NavLogon - (no file)
SafeBoot-TDSSmqct.sys
AddRemove-PC_Antispyware2010 - c:\program files\PC_Antispyware2010\Uninstall.exe
AddRemove-POD-Bot 2.5 - c:\windows\unvise32.exe
AddRemove-Win Antivirus Pro - c:\program files\Windows Antivirus Pro\AntiSpyware_Uninstall.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-19 15:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2504)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\GLI\MTWebClient\CopyHook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\TGTSoft\StyleXP\StyleXPService.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\combo-fix\CF4859.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\windows\system32\wscntfy.exe
c:\program files\Logitech\QuickCam\LU\LULnchr.exe
c:\program files\Common Files\Logitech\LU\LULnchr.exe
c:\program files\Common Files\Logitech\LU\LogitechUpdate.exe
.
**************************************************************************
.
Completion time: 2009-10-19 15:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-19 19:46

Pre-Run: 30,578,163,712 bytes free
Post-Run: 32,351,674,368 bytes free

Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - 0C4813C300FA02AB751CB5EE4419A494

Is there anything else I need to do? Thanks again for everything!

#6 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,590 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:37 PM

Posted 19 October 2009 - 05:55 PM

Hi, lokoryan :(

I would like to take a look at some suspicious files.
  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop

Suspect::
c:\program files\Common Files\ipyz.sys
c:\windows\kygemiz.bin
c:\documents and settings\Ryan\Local Settings\Application Data\unet.com
c:\windows\mugiw.pif
c:\documents and settings\Ryan\Local Settings\Application Data\itur.dll
c:\windows\system32\drivers\eqg7a6c.sys


Posted Image

Once saved, referring to the picture above, drag CFScript.txt into ComboFix.exe, and post back the resulting report along with a Hijackthis log.

===============================================================


Additionally, when CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
Lets scan for remnants:

Please do an online scan with Kaspersky WebScanner

Kaspersky online scanner uses JAVA tecnology to perform the scan. If you do not have the latest JAVA version, follow the instrutions below under Upgrading Java, to download and install the latest vesion.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure the following is checked.
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Attention! Kaspersky Online Scanner 7.0 may fail to start if another anti-virus program is already installed and running on your computer. Please deactivate the anti-virus software installed on your computer prior to starting Kaspersky Online Scanner 7.0.

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 16.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u16-windows-i586.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Make sure the C:\Program Files\JAVA folder is removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u16-windows-i586.exe and select "Run as an Administrator.")

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#7 lokoryan

lokoryan
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:37 PM

Posted 19 October 2009 - 11:05 PM

Thanks JSntgRvr. Here are the results of my scans:

1. ComboFix log

ComboFix 09-10-19.01 - Ryan 10/19/2009 19:14.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.149 [GMT -4:00]
Running from: c:\documents and settings\Ryan\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Ryan\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

file zipped: c:\windows\kygemiz.bin
file zipped: c:\windows\mugiw.pif
file zipped: c:\windows\system32\drivers\eqg7a6c.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Ryan\Cookies\wodoqynu.bat
c:\documents and settings\Ryan\Cookies\yhifesag.bin
c:\documents and settings\Ryan\Cookies\ytoze.db
c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
((((((((((((((((((((((((( Files Created from 2009-09-19 to 2009-10-19 )))))))))))))))))))))))))))))))
.

2009-10-19 19:36 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-17 04:55 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-17 04:55 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-19 21:13 . 2009-04-25 04:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-04 16:36 . 2007-09-10 06:32 -------- d-----w- c:\documents and settings\Ryan\Application Data\Skype
2009-08-24 22:15 . 2009-08-24 22:15 14411 ----a-w- c:\program files\Common Files\ipyz.sys
2009-08-24 22:15 . 2009-08-24 22:15 13409 ----a-w- c:\windows\kygemiz.bin
2009-08-24 22:15 . 2009-08-24 22:15 13151 ----a-w- c:\documents and settings\Ryan\Local Settings\Application Data\unet.com
2009-08-24 22:15 . 2009-08-24 22:15 11111 ----a-w- c:\windows\mugiw.pif
2009-08-24 22:15 . 2009-08-24 22:15 10355 ----a-w- c:\documents and settings\Ryan\Local Settings\Application Data\itur.dll
2009-08-24 13:10 . 2007-09-08 02:15 -------- d-----w- c:\documents and settings\Ryan\Application Data\Azureus
2009-08-21 03:46 . 2009-08-21 03:46 -------- d-----w- c:\documents and settings\Ryan\Application Data\Apple Computer
2009-08-13 00:08 . 2009-08-13 00:08 816 ----a-w- c:\program files\vwgitkn.txt
2009-08-12 23:05 . 2009-08-12 23:05 45344 ----a-w- c:\windows\system32\drivers\eqg7a6c.sys
2009-08-11 00:54 . 2007-08-27 05:59 76240 ----a-w- c:\documents and settings\Ryan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2005-08-16 10:18 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2008-02-28 18:30 . 2008-08-17 02:11 8784 ----a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2008-02-28 18:33 . 2008-08-17 02:11 245408 ----a-w- c:\program files\mozilla firefox\plugins\unicows.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2004-08-10 1126400]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-04 68856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-10-17 1197648]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-24 118784]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-1-6 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\program files\TGTSoft\StyleXP\CurrentLogon.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NavLogon]
[BU]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSmqct.sys]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Clean Access Agent.lnk]
backup=c:\windows\pss\Clean Access Agent.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"aawservice"=2 (0x2)
"WinVNC4"=2 (0x2)
"wuauserv"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\j2re1.4.2_03\\bin\\javaw.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Dell Support\\DSAgnt.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Counter-Strike\\cstrike.exe"=
"c:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\RealVNC\\VNC4\\winvnc4.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"53631:TCP"= 53631:TCP:Azu1
"53631:UDP"= 53631:UDP:Azu2
"22210:TCP"= 22210:TCP:Skype port
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [8/3/2008 9:50 PM 42112]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2/8/2008 8:59 PM 356920]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Ryan\Application Data\Mozilla\Firefox\Profiles\0bq4y3uq.default\
FF - prefs.js: browser.startup.homepage - cnn.com
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRACtrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -

BHO-{5F95F4F5-87CB-4FA3-9AC3-68F67406ACCD} - (no file)

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-19 19:22
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3868)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\GLI\MTWebClient\CopyHook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\TGTSoft\StyleXP\StyleXPService.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\combo-fix\CF26179.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2009-10-19 19:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-19 23:27
ComboFix2.txt 2009-10-19 19:46

Pre-Run: 32,317,689,856 bytes free
Post-Run: 32,289,624,064 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - B3C212070F108782A13CF6C1D81A1654

2. Kaspersky log

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, October 20, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, October 20, 2009 01:56:59
Records in database: 3036757
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Objects scanned: 90993
Threats found: 22
Infected objects found: 32
Suspicious objects found: 0
Scan duration: 03:37:15


File name / Threat / Threats count
C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
C:\Program Files\RealVNC\VNC4\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
C:\Qoobox\Quarantine\C\kvhwftjn.exe.vir Infected: Trojan-Dropper.Win32.Agent.bfmt 1
C:\Qoobox\Quarantine\C\lcbckjms.exe.vir Infected: Trojan.Win32.Sasfis.cqf 1
C:\Qoobox\Quarantine\C\WINDOWS\braviax.exe.vir Infected: Trojan-Downloader.Win32.Agent.cnhj 1
C:\Qoobox\Quarantine\C\WINDOWS\cru629.dat.vir Infected: Backdoor.Win32.Small.ejx 1
C:\Qoobox\Quarantine\C\WINDOWS\msa.exe.vir Infected: Packed.Win32.Krap.ae 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\braviax.exe.vir Infected: Trojan-Downloader.Win32.Agent.cnhj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\cru629.dat.vir Infected: Backdoor.Win32.Small.ejx 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\dddesot.dll.vir Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.lm 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\desot.exe.vir Infected: not-a-virus:FraudTool.Win32.Antivirus2008pro.bq 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\beep.sys.vir Infected: Backdoor.Win32.UltimateDefender.igv 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\msxml71.dll.vir Infected: Packed.Win32.Krap.ae 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tajf83ikdmf.dll.vir Infected: Trojan-Downloader.Win32.Agent.cnhi 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tapi.nfo.vir Infected: Trojan-Downloader.Win32.Small.ameg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\wisdstr.exe.vir Infected: Trojan.Win32.FraudPack.rcj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\_scui.cpl.vir Infected: Trojan.Win32.FraudPack.qys 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\~.exe.vir Infected: Trojan-Downloader.Win32.Agent.cnhj 1
C:\Qoobox\Quarantine\C\yihw.exe.vir Infected: Trojan.Win32.Agent.cvfm 1
C:\Qoobox\Quarantine\[4]-Submit_2009-10-19_19.13.53.zip Infected: Rootkit.Win32.Agent.uok 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J6QSYI9F\main[1].exe Infected: Trojan-Dropper.Win32.WormDrop.h 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O9WWGTBV\ftp[1].exe Infected: Trojan.Win32.Inject.ahoa 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XLGV5A0C\exe[1].exe Infected: Trojan-Downloader.Win32.FraudLoad.ffm 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XLGV5A0C\static[1].exe Infected: Trojan-Spy.Win32.Zbot.gen 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YIAH5FZE\crypt_install[1].exe Infected: Backdoor.Win32.Agent.ajyt 1
C:\WINDOWS\system32\dllcache\beep.sys Infected: Backdoor.Win32.UltimateDefender.igv 1
C:\WINDOWS\system32\drivers\eqg7a6c.sys Infected: Rootkit.Win32.Agent.uok 1
C:\_OTM\MovedFiles\08242009_174208\WINDOWS\svchast.exe Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.iv 1
C:\_OTM\MovedFiles\08242009_174208\WINDOWS\system32\dddesot.dll Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.jh 1
C:\_OTM\MovedFiles\08242009_174208\WINDOWS\system32\desot.exe Infected: not-a-virus:FraudTool.Win32.Antivirus2008pro.bq 1

Selected area has been scanned.

#8 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,590 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:37 PM

Posted 20 October 2009 - 08:17 AM

Hi, lokoryan

Download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

=============================================================

  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop

File::
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J6QSYI9F\main[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O9WWGTBV\ftp[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XLGV5A0C\exe[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XLGV5A0C\static[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YIAH5FZE\crypt_install[1].exe
C:\WINDOWS\system32\dllcache\beep.sys
C:\WINDOWS\system32\drivers\eqg7a6c.sys
c:\program files\Common Files\ipyz.sys
c:\windows\kygemiz.bin
c:\documents and settings\Ryan\Local Settings\Application Data\unet.com
c:\windows\mugiw.pif
c:\documents and settings\Ryan\Local Settings\Application Data\itur.dll
c:\windows\system32\drivers\eqg7a6c.sys

Folder::
C:\_OTM

Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSmqct.sys]

FCopy::
c:\i386\beep.sys | C:\WINDOWS\system32\dllcache\beep.sys


Posted Image

Once saved, referring to the picture above, drag CFScript.txt into ComboFix.exe, and post back the resulting report.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#9 lokoryan

lokoryan
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:37 PM

Posted 20 October 2009 - 09:45 AM

Here's the resulting ComboFix log:

ComboFix 09-10-19.01 - Ryan 10/20/2009 10:28.3.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.218 [GMT -4:00]
Running from: c:\documents and settings\Ryan\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Ryan\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
"c:\documents and settings\Ryan\Local Settings\Application Data\itur.dll"
"c:\documents and settings\Ryan\Local Settings\Application Data\unet.com"
"c:\program files\Common Files\ipyz.sys"
"c:\windows\kygemiz.bin"
"c:\windows\mugiw.pif"
"c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J6QSYI9F\main[1].exe"
"c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O9WWGTBV\ftp[1].exe"
"c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XLGV5A0C\exe[1].exe"
"c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XLGV5A0C\static[1].exe"
"c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YIAH5FZE\crypt_install[1].exe"
"c:\windows\system32\dllcache\beep.sys"
"c:\windows\system32\drivers\eqg7a6c.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\_OTM
c:\_otm\MovedFiles\08242009_174208.log
c:\_otm\MovedFiles\08242009_174208.res
c:\_otm\MovedFiles\08242009_174208\WINDOWS\svchast.exe
c:\_otm\MovedFiles\08242009_174208\WINDOWS\system32\dddesot.dll
c:\_otm\MovedFiles\08242009_174208\WINDOWS\system32\desot.exe
c:\documents and settings\Ryan\Local Settings\Application Data\itur.dll
c:\documents and settings\Ryan\Local Settings\Application Data\unet.com
c:\program files\Common Files\ipyz.sys
c:\windows\kygemiz.bin
c:\windows\mugiw.pif
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J6QSYI9F\main[1].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O9WWGTBV\ftp[1].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XLGV5A0C\exe[1].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XLGV5A0C\static[1].exe
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YIAH5FZE\crypt_install[1].exe
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\drivers\eqg7a6c.sys
c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
--------------- FCopy ---------------

c:\i386\beep.sys --> c:\windows\system32\dllcache\beep.sys
.
((((((((((((((((((((((((( Files Created from 2009-09-20 to 2009-10-20 )))))))))))))))))))))))))))))))
.

2009-10-20 00:46 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-10-19 23:47 . 2009-10-19 23:47 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-19 19:36 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-17 04:55 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-17 04:55 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-19 23:47 . 2006-01-04 15:51 -------- d-----w- c:\program files\Java
2009-10-19 21:13 . 2009-04-25 04:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-11 14:18 . 2008-10-28 20:28 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2005-08-16 10:18 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 16:36 . 2007-09-10 06:32 -------- d-----w- c:\documents and settings\Ryan\Application Data\Skype
2009-08-29 08:08 . 2005-08-16 10:18 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2005-08-16 10:19 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-24 13:10 . 2007-09-08 02:15 -------- d-----w- c:\documents and settings\Ryan\Application Data\Azureus
2009-08-13 00:08 . 2009-08-13 00:08 816 ----a-w- c:\program files\vwgitkn.txt
2009-08-11 00:54 . 2007-08-27 05:59 76240 ----a-w- c:\documents and settings\Ryan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2005-08-16 10:18 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 23:52 . 2009-08-04 23:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 15:13 . 2008-10-28 20:28 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2008-10-28 20:28 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2008-02-28 18:30 . 2008-08-17 02:11 8784 ----a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2008-02-28 18:33 . 2008-08-17 02:11 245408 ----a-w- c:\program files\mozilla firefox\plugins\unicows.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-10-19_19.42.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-20 14:37 . 2009-10-20 14:37 16384 c:\windows\temp\Perflib_Perfdata_70c.dat
+ 2007-01-29 08:58 . 2009-07-14 11:03 46080 c:\windows\system32\tzchange.exe
- 2006-11-08 02:03 . 2009-07-03 17:09 55296 c:\windows\system32\msfeedsbs.dll
+ 2006-11-08 02:03 . 2009-08-29 08:08 55296 c:\windows\system32\msfeedsbs.dll
- 2005-08-16 10:18 . 2009-07-03 17:09 25600 c:\windows\system32\jsproxy.dll
+ 2005-08-16 10:18 . 2009-08-29 08:08 25600 c:\windows\system32\jsproxy.dll
+ 2009-08-02 18:57 . 2009-08-29 08:08 12800 c:\windows\system32\dllcache\xpshims.dll
- 2009-08-02 18:57 . 2009-07-03 17:09 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2007-05-09 23:50 . 2009-08-29 08:08 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2007-05-09 23:50 . 2009-07-03 17:09 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2009-09-04 21:03 . 2009-09-04 21:03 58880 c:\windows\system32\dllcache\msasn1.dll
+ 2006-05-10 05:25 . 2009-08-29 08:08 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2006-05-10 05:25 . 2009-07-03 17:09 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-06-24 23:56 . 2009-06-24 23:56 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
- 2007-04-14 00:58 . 2007-04-14 00:58 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2008-05-28 04:49 . 2008-05-28 04:49 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2008-05-28 04:49 . 2008-05-28 04:49 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2007-04-14 00:57 . 2007-04-14 00:57 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2007-04-14 00:57 . 2007-04-14 00:57 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2008-05-28 04:49 . 2008-05-28 04:49 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2007-04-14 01:30 . 2007-04-14 01:30 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2008-05-28 05:30 . 2008-05-28 05:30 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2004-09-29 23:11 . 2009-06-24 16:56 86016 c:\windows\Microsoft.NET\Framework\v1.0.3705\ToGac.exe
+ 2004-10-07 22:36 . 2009-06-24 16:56 73728 c:\windows\Microsoft.NET\Framework\v1.0.3705\SetRegNI.exe
+ 2005-08-16 10:38 . 2009-06-24 02:01 86016 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorld.dll
- 2005-08-16 10:38 . 2007-01-02 20:29 86016 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorld.dll
- 2005-08-16 10:38 . 2007-01-02 20:29 73728 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorie.dll
+ 2005-08-16 10:38 . 2009-06-24 02:01 73728 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorie.dll
- 2005-08-16 10:38 . 2008-04-13 16:10 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe
+ 2005-08-16 10:38 . 2009-06-24 02:12 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe
- 2005-08-16 10:38 . 2008-04-13 16:10 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_state.exe
+ 2005-08-16 10:38 . 2009-06-24 02:12 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_state.exe
+ 2009-10-20 13:51 . 2009-10-20 13:51 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2009-07-08 10:35 . 2009-07-08 10:35 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2006-02-15 00:23 . 2009-08-12 17:11 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2006-02-15 00:23 . 2009-08-12 17:11 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2006-02-15 00:23 . 2009-08-12 17:11 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2006-02-15 00:23 . 2009-08-12 17:11 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2006-02-15 00:23 . 2009-08-12 17:11 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-02-15 00:23 . 2009-08-12 17:11 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-10-20 13:56 . 2009-07-03 17:09 12800 c:\windows\ie8updates\KB974455-IE8\xpshims.dll
+ 2009-10-20 13:56 . 2009-07-03 17:09 55296 c:\windows\ie8updates\KB974455-IE8\msfeedsbs.dll
+ 2009-10-20 13:56 . 2009-07-03 17:09 25600 c:\windows\ie8updates\KB974455-IE8\jsproxy.dll
+ 2009-10-20 13:47 . 2009-10-20 13:47 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_787b542a\System.Drawing.Design.dll
+ 2009-10-20 13:47 . 2009-10-20 13:47 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_f87f75c5\CustomMarshalers.dll
+ 2009-10-20 13:43 . 2009-10-20 13:43 90112 c:\windows\assembly\NativeImages1_v1.0.3705\System.Drawing.Design\1.0.3300.0__b03f5f7f11d50a3a_d3f8ad8d\System.Drawing.Design.dll
+ 2009-10-20 13:42 . 2009-10-20 13:42 61440 c:\windows\assembly\NativeImages1_v1.0.3705\CustomMarshalers\1.0.3300.0__b03f5f7f11d50a3a_49134293\CustomMarshalers.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 77824 c:\windows\assembly\GAC\SonicMCEBurnEngine\0.9.0.0__17c52700e9a64fd0\SonicMCEBurnEngine.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 77824 c:\windows\assembly\GAC\SonicMCEBurnEngine\0.9.0.0__17c52700e9a64fd0\SonicMCEBurnEngine.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 45056 c:\windows\assembly\GAC\Microsoft.MediaCenter\6.0.3100.0__31bf3856ad364e35\Microsoft.MediaCenter.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 45056 c:\windows\assembly\GAC\Microsoft.MediaCenter\6.0.3100.0__31bf3856ad364e35\Microsoft.MediaCenter.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 53248 c:\windows\assembly\GAC\ehiWUapi\6.0.3000.0__31bf3856ad364e35\ehiWUapi.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 53248 c:\windows\assembly\GAC\ehiWUapi\6.0.3000.0__31bf3856ad364e35\ehiWUapi.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 18944 c:\windows\assembly\GAC\ehiUserXp\6.0.3000.0__31bf3856ad364e35\ehiuserxp.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 18944 c:\windows\assembly\GAC\ehiUserXp\6.0.3000.0__31bf3856ad364e35\ehiuserxp.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 73728 c:\windows\assembly\GAC\ehiExtens\6.0.3000.0__31bf3856ad364e35\ehiExtens.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 73728 c:\windows\assembly\GAC\ehiExtens\6.0.3000.0__31bf3856ad364e35\ehiExtens.dll
+ 2005-08-16 10:38 . 2009-06-29 15:57 8192 c:\windows\Microsoft.NET\Framework\v1.0.3705\IEExec.exe
- 2005-08-16 10:38 . 2007-01-02 20:29 8192 c:\windows\Microsoft.NET\Framework\v1.0.3705\IEExec.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2006-02-15 00:23 . 2009-08-12 17:11 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2009-05-19 22:50 . 2009-05-19 22:50 8192 c:\windows\assembly\GAC\ehiExtCOM\6.0.3000.0__31bf3856ad364e35\ehiExtCOM.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 8192 c:\windows\assembly\GAC\ehiExtCOM\6.0.3000.0__31bf3856ad364e35\ehiExtCOM.dll
+ 2005-08-16 10:19 . 2009-04-02 03:02 604160 c:\windows\system32\wmspdmod.dll
- 2005-08-16 10:18 . 2009-07-03 17:09 206848 c:\windows\system32\occache.dll
+ 2005-08-16 10:18 . 2009-08-29 08:08 206848 c:\windows\system32\occache.dll
- 2006-11-08 02:03 . 2009-07-03 17:09 594432 c:\windows\system32\msfeeds.dll
+ 2006-11-08 02:03 . 2009-08-29 08:08 594432 c:\windows\system32\msfeeds.dll
+ 2005-08-16 10:18 . 2009-06-22 06:44 726528 c:\windows\system32\jscript.dll
- 2005-08-16 10:18 . 2009-03-08 08:33 726528 c:\windows\system32\jscript.dll
+ 2009-10-19 23:47 . 2009-10-19 23:47 149280 c:\windows\system32\javaws.exe
+ 2009-10-19 23:47 . 2009-10-19 23:47 145184 c:\windows\system32\javaw.exe
+ 2009-10-19 23:47 . 2009-10-19 23:47 145184 c:\windows\system32\java.exe
- 2005-08-16 10:18 . 2009-07-03 17:09 184320 c:\windows\system32\iepeers.dll
+ 2005-08-16 10:18 . 2009-08-29 08:08 184320 c:\windows\system32\iepeers.dll
+ 2005-08-16 10:18 . 2009-08-29 08:08 387584 c:\windows\system32\iedkcs32.dll
- 2005-08-16 10:18 . 2009-07-03 11:01 173056 c:\windows\system32\ie4uinit.exe
+ 2005-08-16 10:18 . 2009-08-28 10:35 173056 c:\windows\system32\ie4uinit.exe
+ 2009-04-02 03:02 . 2009-04-02 03:02 604160 c:\windows\system32\dllcache\wmspdmod.dll
+ 2006-05-10 05:25 . 2009-08-29 08:08 916480 c:\windows\system32\dllcache\wininet.dll
+ 2006-08-21 14:52 . 2009-08-26 08:00 247326 c:\windows\system32\dllcache\strmdll.dll
- 2006-08-21 14:52 . 2008-10-03 10:02 247326 c:\windows\system32\dllcache\strmdll.dll
- 2006-10-17 17:04 . 2009-07-03 17:09 206848 c:\windows\system32\dllcache\occache.dll
+ 2006-10-17 17:04 . 2009-08-29 08:08 206848 c:\windows\system32\dllcache\occache.dll
+ 2009-06-25 08:25 . 2009-09-11 14:18 136192 c:\windows\system32\dllcache\msv1_0.dll
- 2009-06-25 08:25 . 2009-06-25 08:25 136192 c:\windows\system32\dllcache\msv1_0.dll
+ 2007-05-09 23:50 . 2009-08-29 08:08 594432 c:\windows\system32\dllcache\msfeeds.dll
- 2007-05-09 23:50 . 2009-07-03 17:09 594432 c:\windows\system32\dllcache\msfeeds.dll
- 2008-05-09 10:53 . 2009-03-08 08:33 726528 c:\windows\system32\dllcache\jscript.dll
+ 2008-05-09 10:53 . 2009-06-22 06:44 726528 c:\windows\system32\dllcache\jscript.dll
+ 2009-08-02 18:57 . 2009-08-29 08:08 246272 c:\windows\system32\dllcache\ieproxy.dll
- 2009-08-02 18:57 . 2009-07-03 17:09 246272 c:\windows\system32\dllcache\ieproxy.dll
+ 2006-05-10 05:25 . 2009-08-29 08:08 184320 c:\windows\system32\dllcache\iepeers.dll
- 2006-05-10 05:25 . 2009-07-03 17:09 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2006-11-07 08:27 . 2009-08-29 08:08 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2006-11-07 08:26 . 2009-08-28 10:35 173056 c:\windows\system32\dllcache\ie4uinit.exe
- 2006-11-07 08:26 . 2009-07-03 11:01 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-05-28 04:49 . 2008-05-28 04:49 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2007-04-14 00:58 . 2007-04-14 00:58 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2007-04-14 00:56 . 2007-04-14 00:56 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2008-05-28 04:48 . 2008-05-28 04:48 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2007-04-14 01:30 . 2007-04-14 01:30 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2008-05-28 05:30 . 2008-05-28 05:30 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2005-08-16 10:38 . 2009-06-24 01:59 303104 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorjit.dll
- 2005-08-16 10:38 . 2004-07-20 00:54 303104 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorjit.dll
- 2005-08-16 10:38 . 2008-04-13 16:09 200704 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_isapi.dll
+ 2005-08-16 10:38 . 2009-06-24 02:12 200704 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_isapi.dll
- 2006-02-15 00:23 . 2009-08-12 17:11 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2006-02-15 00:23 . 2009-08-12 17:11 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2006-02-15 00:23 . 2009-08-12 17:11 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2006-02-15 00:23 . 2009-08-12 17:11 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2006-02-15 00:23 . 2009-08-12 17:11 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2006-02-15 00:23 . 2009-08-12 17:11 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2006-02-15 00:23 . 2009-10-20 13:56 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2007-04-19 17:53 . 2007-04-19 17:53 109408 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\OUTLCTL.DLL
+ 2007-11-15 13:23 . 2007-11-15 13:23 136744 c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_wificfg.exe
+ 2007-11-15 13:23 . 2007-11-15 13:23 185896 c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_tgshell.exe
+ 2007-11-15 13:24 . 2007-11-15 13:24 579112 c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_tgctlsr.dll
+ 2007-11-15 13:24 . 2007-11-15 13:24 370216 c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sdcnetcheck.dll
+ 2009-10-20 13:56 . 2009-07-03 17:09 915456 c:\windows\ie8updates\KB974455-IE8\wininet.dll
+ 2009-10-20 13:56 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB974455-IE8\spuninst\updspapi.dll
+ 2009-10-20 13:56 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB974455-IE8\spuninst\spuninst.exe
+ 2009-10-20 13:56 . 2009-07-03 17:09 206848 c:\windows\ie8updates\KB974455-IE8\occache.dll
+ 2009-10-20 13:56 . 2009-07-03 17:09 594432 c:\windows\ie8updates\KB974455-IE8\msfeeds.dll
+ 2009-10-20 13:56 . 2009-07-03 17:09 246272 c:\windows\ie8updates\KB974455-IE8\ieproxy.dll
+ 2009-10-20 13:56 . 2009-07-03 17:09 184320 c:\windows\ie8updates\KB974455-IE8\iepeers.dll
+ 2009-10-20 13:56 . 2009-07-03 17:09 386048 c:\windows\ie8updates\KB974455-IE8\iedkcs32.dll
+ 2009-10-20 13:56 . 2009-07-03 11:01 173056 c:\windows\ie8updates\KB974455-IE8\ie4uinit.exe
+ 2009-10-20 13:44 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\spuninst\updspapi.dll
+ 2009-10-20 13:44 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst\spuninst.exe
+ 2009-10-20 13:44 . 2009-03-08 08:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
+ 2005-08-16 10:37 . 2009-08-18 14:55 179712 c:\windows\ehome\ehkeyctl.dll
+ 2009-10-20 13:48 . 2009-10-20 13:48 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_337c1df4\System.Drawing.dll
+ 2009-10-20 13:48 . 2009-10-20 13:48 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_f752d8fa\System.Drawing.Design.dll
+ 2009-10-20 13:48 . 2009-10-20 13:48 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_ac7c15d2\CustomMarshalers.dll
+ 2009-10-20 13:43 . 2009-10-20 13:43 847872 c:\windows\assembly\NativeImages1_v1.0.3705\System.Drawing\1.0.3300.0__b03f5f7f11d50a3a_f6a072d0\System.Drawing.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 389120 c:\windows\assembly\GAC\ehRecObj\6.0.3000.0__31bf3856ad364e35\ehRecObj.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 389120 c:\windows\assembly\GAC\ehRecObj\6.0.3000.0__31bf3856ad364e35\ehRecObj.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 122880 c:\windows\assembly\GAC\ehiwmp\6.0.3000.0__31bf3856ad364e35\ehiwmp.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 122880 c:\windows\assembly\GAC\ehiwmp\6.0.3000.0__31bf3856ad364e35\ehiwmp.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 278528 c:\windows\assembly\GAC\ehiVidCtl\6.0.3000.0__31bf3856ad364e35\ehiVidCtl.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 278528 c:\windows\assembly\GAC\ehiVidCtl\6.0.3000.0__31bf3856ad364e35\ehiVidCtl.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 389120 c:\windows\assembly\GAC\ehiProxy\6.0.3000.0__31bf3856ad364e35\ehiProxy.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 389120 c:\windows\assembly\GAC\ehiProxy\6.0.3000.0__31bf3856ad364e35\ehiProxy.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 204800 c:\windows\assembly\GAC\ehiPlay\6.0.3000.0__31bf3856ad364e35\ehiPlay.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 204800 c:\windows\assembly\GAC\ehiPlay\6.0.3000.0__31bf3856ad364e35\ehiPlay.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 167936 c:\windows\assembly\GAC\ehiMsgr\6.0.3000.0__31bf3856ad364e35\ehiMsgr.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 167936 c:\windows\assembly\GAC\ehiMsgr\6.0.3000.0__31bf3856ad364e35\ehiMsgr.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 110592 c:\windows\assembly\GAC\ehExtCOM\6.0.3000.0__31bf3856ad364e35\ehExtCOM.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 110592 c:\windows\assembly\GAC\ehExtCOM\6.0.3000.0__31bf3856ad364e35\ehExtCOM.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 126976 c:\windows\assembly\GAC\ehepgdat\6.0.3000.0__31bf3856ad364e35\ehepgdat.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 126976 c:\windows\assembly\GAC\ehepgdat\6.0.3000.0__31bf3856ad364e35\ehepgdat.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 868352 c:\windows\assembly\GAC\ehepg\6.0.3000.0__31bf3856ad364e35\ehepg.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 868352 c:\windows\assembly\GAC\ehepg\6.0.3000.0__31bf3856ad364e35\ehepg.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 192512 c:\windows\assembly\GAC\ehcommon\6.0.3000.0__31bf3856ad364e35\ehcommon.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 192512 c:\windows\assembly\GAC\ehcommon\6.0.3000.0__31bf3856ad364e35\ehcommon.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 102400 c:\windows\assembly\GAC\ehCIR\6.0.3000.0__31bf3856ad364e35\ehCIR.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 102400 c:\windows\assembly\GAC\ehCIR\6.0.3000.0__31bf3856ad364e35\ehCIR.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 117248 c:\windows\assembly\GAC\BDATunePIA\6.0.3000.0__31bf3856ad364e35\bdatunepia.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 117248 c:\windows\assembly\GAC\BDATunePIA\6.0.3000.0__31bf3856ad364e35\bdatunepia.dll
+ 2009-10-20 00:52 . 2009-08-13 13:55 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll
+ 2005-08-16 10:19 . 2009-05-20 08:56 2458112 c:\windows\system32\WMVCore.dll
- 2005-08-16 10:19 . 2008-06-18 10:03 2458112 c:\windows\system32\WMVCore.dll
- 2005-08-16 10:18 . 2009-07-03 17:09 1208832 c:\windows\system32\urlmon.dll
+ 2005-08-16 10:18 . 2009-08-29 08:08 1208832 c:\windows\system32\urlmon.dll
+ 2005-08-16 10:18 . 2009-07-17 16:22 1435648 c:\windows\system32\query.dll
- 2005-08-16 10:18 . 2008-04-14 00:12 1435648 c:\windows\system32\query.dll
+ 2005-08-16 10:18 . 2009-08-29 08:08 5940224 c:\windows\system32\mshtml.dll
- 2006-10-17 16:57 . 2009-07-03 17:09 1985536 c:\windows\system32\iertutil.dll
+ 2006-10-17 16:57 . 2009-08-29 08:08 1985536 c:\windows\system32\iertutil.dll
+ 2006-12-13 06:42 . 2009-05-20 08:56 2458112 c:\windows\system32\dllcache\WMVCore.dll
- 2006-12-13 06:42 . 2008-06-18 10:03 2458112 c:\windows\system32\dllcache\WMVCore.dll
- 2006-05-10 05:25 . 2009-07-03 17:09 1208832 c:\windows\system32\dllcache\urlmon.dll
+ 2006-05-10 05:25 . 2009-08-29 08:08 1208832 c:\windows\system32\dllcache\urlmon.dll
+ 2009-07-17 16:22 . 2009-07-17 16:22 1435648 c:\windows\system32\dllcache\query.dll
+ 2009-04-15 11:42 . 2009-08-05 00:44 2189184 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-04-15 11:42 . 2009-08-04 14:20 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
- 2009-04-15 11:42 . 2009-02-06 10:32 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-02-07 23:02 . 2009-08-04 14:20 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2009-02-07 23:02 . 2009-02-07 23:02 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2009-04-15 11:42 . 2009-02-06 11:06 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2009-04-15 11:42 . 2009-08-04 15:13 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2006-05-19 15:06 . 2009-08-29 08:08 5940224 c:\windows\system32\dllcache\mshtml.dll
- 2007-05-09 23:50 . 2009-07-03 17:09 1985536 c:\windows\system32\dllcache\iertutil.dll
+ 2007-05-09 23:50 . 2009-08-29 08:08 1985536 c:\windows\system32\dllcache\iertutil.dll
- 2007-04-14 01:35 . 2007-04-14 01:35 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2008-05-28 05:35 . 2008-05-28 05:35 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2007-04-14 01:35 . 2007-04-14 01:35 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2008-05-28 05:35 . 2008-05-28 05:35 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2007-04-14 00:57 . 2007-04-14 00:57 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2008-05-28 04:48 . 2008-05-28 04:48 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2008-05-28 04:48 . 2008-05-28 04:48 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2007-04-14 00:57 . 2007-04-14 00:57 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2007-04-14 00:50 . 2007-04-14 00:50 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2008-05-28 04:43 . 2008-05-28 04:43 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2005-08-16 10:38 . 2009-06-29 15:58 1200128 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Web.dll
- 2005-08-16 10:38 . 2007-01-02 20:40 1200128 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Web.dll
- 2005-08-16 10:38 . 2007-12-17 11:59 2281472 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
+ 2005-08-16 10:38 . 2009-06-24 02:00 2281472 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
+ 2005-08-16 10:38 . 2009-06-24 02:00 2273280 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorsvr.dll
- 2005-08-16 10:38 . 2007-12-17 11:58 2273280 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorsvr.dll
+ 2005-08-16 10:38 . 2009-06-29 15:58 1998848 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorlib.dll
- 2005-08-16 10:38 . 2007-01-02 20:21 1998848 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorlib.dll
+ 2009-08-21 14:14 . 2009-08-21 14:14 8363008 c:\windows\Installer\6170e.msp
+ 2009-08-20 09:02 . 2009-08-20 09:02 5204992 c:\windows\Installer\616f3.msp
+ 2009-09-29 13:08 . 2009-09-29 13:08 6747648 c:\windows\Installer\616d6.msp
+ 2009-09-21 20:53 . 2009-09-21 20:53 5518848 c:\windows\Installer\616ab.msp
+ 2009-05-26 15:10 . 2009-05-26 15:10 3479552 c:\windows\Installer\553d8.msp
+ 2009-10-19 23:47 . 2009-10-19 23:47 1757696 c:\windows\Installer\5536a.msi
+ 2007-06-06 14:53 . 2007-06-06 14:53 1195888 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\FM20.DLL
+ 2009-10-20 13:56 . 2009-07-03 17:09 1208832 c:\windows\ie8updates\KB974455-IE8\urlmon.dll
+ 2009-10-20 13:56 . 2009-07-19 13:18 5937152 c:\windows\ie8updates\KB974455-IE8\mshtml.dll
+ 2009-10-20 13:56 . 2009-07-03 17:09 1985536 c:\windows\ie8updates\KB974455-IE8\iertutil.dll
+ 2009-04-15 11:42 . 2009-08-05 00:44 2189184 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2009-04-15 11:42 . 2009-02-06 10:32 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-04-15 11:42 . 2009-08-04 14:20 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-02-07 23:02 . 2009-02-07 23:02 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-02-07 23:02 . 2009-08-04 14:20 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-04-15 11:42 . 2009-08-04 15:13 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2009-04-15 11:42 . 2009-02-06 11:06 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-10-20 13:47 . 2009-10-20 13:47 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_f2a55fd3\System.dll
+ 2009-10-20 13:48 . 2009-10-20 13:48 4792320 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_428a69d6\System.dll
+ 2009-10-20 13:48 . 2009-10-20 13:48 5513216 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_b60449c7\System.Xml.dll
+ 2009-10-20 13:48 . 2009-10-20 13:48 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_b3272e21\System.Xml.dll
+ 2009-10-20 13:48 . 2009-10-20 13:48 7884800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_0dce11d3\System.Windows.Forms.dll
+ 2009-10-20 13:48 . 2009-10-20 13:48 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_028e6d59\System.Windows.Forms.dll
+ 2009-10-20 13:49 . 2009-10-20 13:49 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_6d4cda3d\System.Drawing.dll
+ 2009-10-20 13:49 . 2009-10-20 13:49 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_327ddf33\System.Design.dll
+ 2009-10-20 13:48 . 2009-10-20 13:48 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_29518783\System.Design.dll
+ 2009-10-20 13:49 . 2009-10-20 13:49 8908800 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_951a591b\mscorlib.dll
+ 2009-10-20 13:48 . 2009-10-20 13:48 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_2068ea1f\mscorlib.dll
+ 2009-10-20 13:42 . 2009-10-20 13:42 1855488 c:\windows\assembly\NativeImages1_v1.0.3705\System\1.0.3300.0__b77a5c561934e089_a56ff436\System.dll
+ 2009-10-20 13:43 . 2009-10-20 13:43 2027520 c:\windows\assembly\NativeImages1_v1.0.3705\System.Xml\1.0.3300.0__b77a5c561934e089_d189d505\System.Xml.dll
+ 2009-10-20 13:43 . 2009-10-20 13:43 2953216 c:\windows\assembly\NativeImages1_v1.0.3705\System.Windows.Forms\1.0.3300.0__b77a5c561934e089_33f71e20\System.Windows.Forms.dll
+ 2009-10-20 13:42 . 2009-10-20 13:42 1454080 c:\windows\assembly\NativeImages1_v1.0.3705\System.Design\1.0.3300.0__b03f5f7f11d50a3a_08ecd882\System.Design.dll
+ 2009-10-20 13:42 . 2009-10-20 13:42 3301376 c:\windows\assembly\NativeImages1_v1.0.3705\mscorlib\1.0.3300.0__b77a5c561934e089_dfbdbf4e\mscorlib.dll
+ 2009-10-20 13:47 . 2009-10-20 13:47 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2007-07-12 07:04 . 2007-07-12 07:04 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2009-10-20 13:47 . 2009-10-20 13:47 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2007-07-12 07:04 . 2007-07-12 07:04 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-10-20 13:42 . 2009-10-20 13:42 1200128 c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
- 2009-05-19 22:38 . 2009-05-19 22:38 1200128 c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
- 2009-05-19 22:50 . 2009-05-19 22:50 1863680 c:\windows\assembly\GAC\EhCM\6.0.3000.0__31bf3856ad364e35\EhCM.dll
+ 2009-10-20 14:04 . 2009-10-20 14:04 1863680 c:\windows\assembly\GAC\EhCM\6.0.3000.0__31bf3856ad364e35\EhCM.dll
+ 2006-01-07 03:37 . 2009-10-02 15:01 25198016 c:\windows\system32\MRT.exe
+ 2006-11-08 02:03 . 2009-08-29 08:08 11069440 c:\windows\system32\ieframe.dll
+ 2007-05-09 23:50 . 2009-08-29 08:08 11069440 c:\windows\system32\dllcache\ieframe.dll
+ 2009-08-11 01:08 . 2009-08-11 01:08 11315712 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp
+ 2008-08-11 15:49 . 2008-08-11 15:49 22457344 c:\windows\Installer\616de.msp
+ 2009-08-10 18:09 . 2009-08-10 18:09 17254912 c:\windows\Installer\616c2.msp
+ 2007-05-08 15:10 . 2007-05-08 15:10 16874376 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6021\MSO.DLL
+ 2009-10-20 13:56 . 2009-07-19 22:48 11067392 c:\windows\ie8updates\KB974455-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2004-08-10 1126400]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-04 68856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-10-17 1197648]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-24 118784]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-19 149280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-1-6 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\program files\TGTSoft\StyleXP\CurrentLogon.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NavLogon]
[BU]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Clean Access Agent.lnk]
backup=c:\windows\pss\Clean Access Agent.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"aawservice"=2 (0x2)
"WinVNC4"=2 (0x2)
"wuauserv"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Dell Support\\DSAgnt.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Counter-Strike\\cstrike.exe"=
"c:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\RealVNC\\VNC4\\winvnc4.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"53631:TCP"= 53631:TCP:Azu1
"53631:UDP"= 53631:UDP:Azu2
"22210:TCP"= 22210:TCP:Skype port
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [8/3/2008 9:50 PM 42112]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2/8/2008 8:59 PM 356920]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Ryan\Application Data\Mozilla\Firefox\Profiles\0bq4y3uq.default\
FF - prefs.js: browser.startup.homepage - cnn.com
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRACtrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -

BHO-{5F95F4F5-87CB-4FA3-9AC3-68F67406ACCD} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-20 10:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(736)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\GLI\MTWebClient\CopyHook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\TGTSoft\StyleXP\StyleXPService.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\combo-fix\CF18135.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2009-10-20 10:43 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-20 14:43
ComboFix2.txt 2009-10-19 23:27
ComboFix3.txt 2009-10-19 19:46

Pre-Run: 31,672,827,904 bytes free
Post-Run: 31,625,228,288 bytes free

Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - 5245052CB9FF92CBC970EFC03BB99E7F

#10 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,590 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:37 PM

Posted 20 October 2009 - 11:57 AM

All seems clear. How is the computer doing?

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#11 lokoryan

lokoryan
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:37 PM

Posted 20 October 2009 - 12:05 PM

It looks as if everything is back to normal! But then again I thought the same before you had me run the Kaspersky scan and apparently there were more problems! But everything does look fine now.

Are there any post-cleanup stuff I need to do? Shall I run Malwarebytes? What should I do with the files that ComboFix stored on my computer?

Thanks for all of your help!

#12 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,590 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:37 PM

Posted 20 October 2009 - 12:24 PM

Hi, lokoryan :(

Applications such as Kaspersky will detect both, active and inactive files, as well as those in quarantine. All seems clear now. We will be doing some housekeeping to remove files in quarantined and those backed-up by Windows.

Reset and Re-enable your System Restore to remove bad files that have been backed up by Windows. The files in System Restore are protected to prevent any programmes changing them. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected.)

To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

(Windows XP)

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK..

Since the tools we used to scan the computer, as well as tools to delete files and folders, are no longer needed, they should be removed, as well as the folders created by these tools.

Follow these steps to uninstall Combofix
  • Click START then RUN
  • Now type "c:\documents and settings\Ryan\Desktop\Combo-Fix.exe" /Uninstall in the runbox and click OK. Note the space between the " and /Uninstall, it needs to be there.
Create a Restore point
  • Click Start, point to All Programs, point to Accessories, point to System Tools, and then click System Restore.
  • In the System Restore dialog box, click Create a restore point, and then click Next.
  • Type a description for your restore point, such as "After Cleanup", then click Create.
The following is a list of free tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
  • Spybot Search & Destroy - A useful tool which can search and annhilate bad files that make it onto your system. Now with an Immunize section that will help prevent future infections.
  • AdAware - Another very powerful tool which searches and kills bad files that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.
  • SpywareBlaster - Great prevention tool to keep bad files from installing on your system.
  • ZonedOut + IE-SpyAd - puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
  • ATF! - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those bad files that like to reside in the temp folders.
  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows.
  • Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Miekiemoes.

Best wishes! Posted Image

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#13 lokoryan

lokoryan
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:12:37 PM

Posted 20 October 2009 - 12:46 PM

I said this about a dozen times already, but thank you again for all of your help!

I did the System Restore and I've uninstalled ComboFix. Shall I uninstall all the the other programs? More specifically: TFC, Avenger, DDS, RootRepeal, Win32KDiag... or are they all okay to be left as is?

And finally, would it be okay for me to run Spybot, Adaware, and/or Malwarebytes now?

#14 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,590 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:37 PM

Posted 20 October 2009 - 02:44 PM

Shall I uninstall all the the other programs? More specifically: TFC, Avenger, DDS, RootRepeal, Win32KDiag... or are they all okay to be left as is?


Yes. There is no need for these.

And finally, would it be okay for me to run Spybot, Adaware, and/or Malwarebytes now?


As you wish. I will leave this topic open for a couple of days should you need further help. :(

Edited by JSntgRvr, 20 October 2009 - 02:45 PM.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#15 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,590 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:37 PM

Posted 24 October 2009 - 01:42 AM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users