Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

xp antispyware 2010


  • This topic is locked This topic is locked
16 replies to this topic

#1 sting66ray

sting66ray

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:40 AM

Posted 28 February 2010 - 09:40 PM

Hi,

I can't run my computer except in safe mode with command prompt. Malwarebytes won't remove neither will Glary Utilities. I can access regedit, but I can't find the common entries for this infection. What can I do?

dave

BC AdBot (Login to Remove)

 


#2 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,227 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:01:40 PM

Posted 28 February 2010 - 09:47 PM

Please attempt this command and restore the computer to an earlier date:

c:\windows\system\restore\rstrui.exe

Let me know the outcome.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#3 sting66ray

sting66ray
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:40 AM

Posted 28 February 2010 - 10:05 PM

Hi,

While I was waiting I was able to logon to my pc under my wifes log in and I am getting Malwarebytes to update and scan, right now. I will let you konw the result or you can suggest what to do from here.

dave

#4 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,227 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:01:40 PM

Posted 28 February 2010 - 10:08 PM

  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#5 sting66ray

sting66ray
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:40 AM

Posted 28 February 2010 - 10:39 PM

Hi,
Thanks for helping, here is the log. What do you think?

dave







Malwarebytes' Anti-Malware 1.44
Database version: 3808
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

2/28/2010 9:20:45 PM
mbam-log-2010-02-28 (21-20-45).txt

Scan type: Quick Scan
Objects scanned: 135616
Time elapsed: 17 minute(s), 38 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\lighexnt.dll (Spyware.Passwords) -> Delete on reboot.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\lighexnt.dll (Spyware.Passwords) -> Delete on reboot.
C:\WINDOWS\ujuqevemiteduzu.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
C:\Documents and Settings\David Sittler\Local Settings\Application Data\av.exe (ROGUE.Win7Antispyware2010) -> Quarantined and deleted successfully.


#6 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,227 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:01:40 PM

Posted 28 February 2010 - 10:47 PM

Hi, sting66ray smile.gif

I don't believe those detections should affect your logon. I have requested the topic to be moved to the malware forum.

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  1. Please, never rename Combofix unless instructed.
  2. Close any open browsers.
  3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    -----------------------------------------------------------
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      -----------------------------------------------------------
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    -----------------------------------------------------------
  4. Double click on combofix.exe & follow the prompts.
  5. Install the Recovery Console if prompted.
  6. When finished, it will produce a report for you.
  7. Please post the "C:\ComboFix.txt" .
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.

Please do not install any new programs or update anything unless told to do so while we are fixing your problem.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#7 sting66ray

sting66ray
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:40 AM

Posted 01 March 2010 - 12:08 AM

Hi,

Here is the report, what do you make of it? Thank you!!! Seems back to normal now! Whew!


Thanks!

dave


ComboFix 10-02-27.04 - Julie Sittler 02/28/2010 22:05:48.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1271.725 [GMT -6:00]
Running from: C:\Documents and Settings\Julie Sittler\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\David Sittler\Application Data\alot
C:\Documents and Settings\Julie Sittler\Application Data\alot
C:\Documents and Settings\Julie Sittler\Application Data\alot\BrowserSearch\BrowserSearch.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\BrowserSearch\BrowserSearch.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_0\Button_0.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_0\Button_0.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_1\Button_1.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_1\Button_1.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_2\Button_2.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_2\Button_2.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_3\Button_3.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_3\Button_3.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_4\Button_4.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_4\Button_4.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_5\Button_5.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_5\Button_5.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_6\Button_6.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\Button_6\Button_6.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\configurator\configurator.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\configurator\configurator.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\contextMenu\contextMenu.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\contextMenu\contextMenu.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\ErrorSearch\ErrorSearch.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\ErrorSearch\ErrorSearch.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\postInstallLayout\postInstallLayout.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\postInstallLayout\postInstallLayout.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\products\products.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\products\products.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\BrowserSearch\alot_search_defend.html
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_0\images\alot_logo_button.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_0\images\alot_logo_button.png
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_1\images\alot_search_button.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_1\images\alot_search_button.png
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_2\images\default_1008_alot_map_widget_default.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_2\images\default_1008_alot_map_widget_default.png
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_3\images\default_1011_alot_maps_tools.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_3\images\default_1011_alot_maps_tools.png
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_4\images\default_1007_alot_weather_widget.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_4\images\default_1007_alot_weather_widget.png
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_4\images\nclear.png
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_4\images\pcloud.png
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_5\images\default_1012_alot_mrkt_travel.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_5\images\default_1012_alot_mrkt_travel.png
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_6\images\default_1046_alot_mrkt_180.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Button_6\images\default_1046_alot_mrkt_180.png
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\contextMenu\images\alot_menu_icon.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\contextMenu\images\alot_menu_icon.png
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Shared\domains.dat
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Shared\images\alot_brand.png
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Shared\images\alot_splitter.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Shared\images\alot_splitter.png
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Shared\images\spinner.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_bottom.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_btnclose0.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_btnclose1.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_caption.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_error_bg.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_error_close.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_error_icon.bmp
C:\Documents and Settings\Julie Sittler\Application Data\alot\TimerManager\TimerManager.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\TimerManager\TimerManager.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\toolbar.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\toolbar.xml.backup
C:\Documents and Settings\Julie Sittler\Application Data\alot\ToolbarSearch\ToolbarSearch.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\Updater\Updater.xml
C:\Documents and Settings\Julie Sittler\Application Data\alot\Updater\Updater.xml.backup
C:\Program Files\Freeze.com Toolbar
C:\Program Files\Freeze.com Toolbar\autosearch_plugin.dll
C:\Program Files\Freeze.com Toolbar\basis.xml
C:\Program Files\Freeze.com Toolbar\freeze.bmp
C:\Program Files\Freeze.com Toolbar\freeze_us.crc
C:\Program Files\Freeze.com Toolbar\freeze_us.inf
C:\Program Files\Freeze.com Toolbar\frzToolbar_logo.bmp
C:\Program Files\Freeze.com Toolbar\icons.bmp
C:\Program Files\Freeze.com Toolbar\info.txt
C:\Program Files\Freeze.com Toolbar\options.html
C:\Program Files\Freeze.com Toolbar\powered_yahoo_search.bmp
C:\Program Files\Freeze.com Toolbar\tbhelper.dll
C:\Program Files\Freeze.com Toolbar\uninstall.exe
C:\Program Files\Freeze.com Toolbar\update.exe
C:\Program Files\Freeze.com Toolbar\version.txt
C:\Program Files\Freeze.com Toolbar\whiteList_plugin.dll
C:\Program Files\WinPCap
C:\Program Files\WinPCap\daemon_mgm.exe
C:\Program Files\WinPCap\INSTALL.LOG
C:\Program Files\WinPCap\NetMonInstaller.exe
C:\Program Files\WinPCap\npf_mgm.exe
C:\Program Files\WinPCap\rpcapd.exe
C:\Program Files\WinPCap\Uninstall.exe
C:\WINDOWS\EventSystem.log
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\Packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\twain_32.dll
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Service_NPF


((((((((((((((((((((((((( Files Created from 2010-02-01 to 2010-03-01 )))))))))))))))))))))))))))))))
.

2010-03-01 04:00:00 . 2010-03-01 04:03:02 -------- d-----w- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
2010-03-01 02:51:56 . 2009-11-10 16:26:26 767952 ----a-w- C:\WINDOWS\BDTSupport.dll
2010-03-01 02:51:55 . 2009-11-10 16:28:16 149456 ----a-w- C:\WINDOWS\SGDetectionTool.dll
2010-03-01 02:51:55 . 2009-10-28 07:36:02 1152444 ----a-w- C:\WINDOWS\UDB.zip
2010-03-01 02:51:55 . 2008-11-26 18:08:42 131 ----a-w- C:\WINDOWS\IDB.zip
2010-03-01 02:51:54 . 2009-11-10 16:28:10 165840 ----a-w- C:\WINDOWS\PCTBDRes.dll
2010-03-01 02:51:54 . 2009-11-10 16:28:10 1640400 ----a-w- C:\WINDOWS\PCTBDCore.dll
2010-03-01 02:51:31 . 2010-02-05 15:17:56 233136 ----a-w- C:\WINDOWS\system32\drivers\pctgntdi.sys
2010-03-01 02:50:54 . 2009-10-06 22:31:30 87784 ----a-w- C:\WINDOWS\system32\drivers\PCTAppEvent.sys
2010-03-01 02:50:54 . 2009-09-23 22:10:06 207280 ----a-w- C:\WINDOWS\system32\drivers\PCTCore.sys
2010-03-01 02:50:31 . 2010-02-05 15:25:38 70408 ----a-w- C:\WINDOWS\system32\drivers\pctplsg.sys
2010-03-01 02:49:49 . 2010-03-01 04:33:20 -------- d-----w- C:\Program Files\Spyware Doctor
2010-03-01 02:49:49 . 2010-03-01 02:49:49 -------- d-----w- C:\Program Files\Common Files\PC Tools
2010-03-01 02:49:49 . 2010-03-01 02:49:49 -------- d-----w- C:\Documents and Settings\David Sittler\Application Data\PC Tools
2010-03-01 02:49:49 . 2010-03-01 02:49:49 -------- d-----w- C:\Documents and Settings\All Users\Application Data\PC Tools
2010-03-01 02:48:48 . 2010-03-01 04:47:50 -------- d---a-w- C:\Documents and Settings\All Users\Application Data\TEMP
2010-02-26 13:22:19 . 2010-02-26 13:22:19 -------- d-----w- C:\Documents and Settings\Administrator\Application Data\GlarySoft
2010-02-26 13:15:08 . 2010-02-26 13:15:08 -------- d-----w- C:\Program Files\AskBarDis
2010-02-21 03:37:20 . 2010-02-23 01:38:47 1 ----a-w- C:\Documents and Settings\David Sittler\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-02-21 03:36:58 . 2010-02-21 03:36:58 -------- d-----w- C:\Documents and Settings\David Sittler\Application Data\OpenOffice.org
2010-02-19 18:52:12 . 2010-02-24 04:13:14 -------- d-----w- C:\Program Files\OpenOffice.org 3
2010-02-19 18:31:58 . 2010-02-19 18:31:58 152576 ----a-w- C:\Documents and Settings\David Sittler\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-19 03:37:05 . 2010-02-19 18:31:53 79488 ----a-w- C:\Documents and Settings\David Sittler\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-13 17:45:05 . 2010-02-26 13:33:22 120 ----a-w- C:\WINDOWS\Ipiyu.dat
2010-02-13 17:45:05 . 2010-02-26 13:33:17 0 ----a-w- C:\WINDOWS\Lvefediwihepala.bin
2010-02-13 17:45:04 . 2010-02-13 17:45:04 -------- d-----w- C:\Documents and Settings\David Sittler\Local Settings\Application Data\{0AAD0A1A-177F-4471-A54B-C3E121CA8559}
2010-02-13 16:54:26 . 2007-08-02 17:35:46 28672 ----a-w- C:\WINDOWS\system32\drivers\ACRUSBTM.SYS
2010-02-13 16:54:16 . 2010-02-13 16:54:16 -------- d-----w- C:\Program Files\Mouse Setting

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-01 03:28:19 . 2006-03-11 04:18:55 8224 -c--a-w- C:\Documents and Settings\Julie Sittler\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-28 03:42:23 . 2009-02-26 18:38:57 -------- d-----w- C:\Program Files\Glary Utilities
2010-02-27 23:35:21 . 2009-02-20 01:28:41 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-25 03:53:00 . 2005-12-19 23:58:28 116224 -c--a-w- C:\Documents and Settings\David Sittler\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-24 04:13:14 . 2007-12-30 02:14:54 -------- d-----w- C:\Documents and Settings\Julie Sittler\Application Data\Apple Computer
2010-02-24 03:27:41 . 2005-12-05 20:41:00 -------- d--h--w- C:\Program Files\InstallShield Installation Information
2010-02-24 03:22:47 . 2006-08-27 22:18:01 -------- d-----w- C:\Program Files\PCStitch Pro
2010-02-20 07:16:44 . 2005-12-18 23:48:50 -------- d--h--w- C:\Program Files\Zero G Registry
2010-02-20 07:16:43 . 2005-12-18 23:49:09 -------- d-----w- C:\Program Files\Money Matters 2005
2010-02-20 07:14:54 . 2005-12-05 20:38:51 -------- d-----w- C:\Program Files\Java
2010-02-19 18:49:43 . 2008-12-28 15:46:37 411368 ----a-w- C:\WINDOWS\system32\deploytk.dll
2010-02-19 03:18:35 . 2007-12-25 06:09:31 -------- d-----w- C:\Program Files\Common Files\Apple
2010-02-19 03:03:58 . 2005-12-05 20:38:50 -------- d-----w- C:\Program Files\Common Files\Java
2010-02-09 04:59:49 . 2007-03-17 15:27:29 -------- d-----w- C:\Documents and Settings\All Users\Application Data\McAfee
2010-02-06 00:33:14 . 2007-12-25 06:13:23 -------- d-----w- C:\Documents and Settings\David Sittler\Application Data\Apple Computer
2010-01-10 05:35:04 . 2010-01-10 05:35:04 -------- d-----w- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2010-01-08 04:29:05 . 2006-11-25 03:54:50 -------- d-----w- C:\Program Files\Creative
2010-01-07 22:07:14 . 2009-02-20 01:28:44 38224 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07:04 . 2009-02-20 01:28:47 19160 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys
2010-01-05 10:00:29 . 2004-08-10 18:51:29 832512 ----a-w- C:\WINDOWS\system32\wininet.dll
2010-01-05 10:00:21 . 2009-04-11 17:17:11 78336 ----a-w- C:\WINDOWS\system32\ieencode.dll
2010-01-05 10:00:20 . 2004-08-10 18:50:55 17408 ----a-w- C:\WINDOWS\system32\corpol.dll
2010-01-03 18:26:40 . 2007-01-23 00:51:19 -------- d-----w- C:\Documents and Settings\David Sittler\Application Data\InstallShield
2010-01-03 18:25:51 . 2007-01-23 00:41:35 -------- d-----w- C:\Documents and Settings\All Users\Application Data\BVRP Software
2009-12-31 16:50:03 . 2005-12-05 20:18:21 353792 ----a-w- C:\WINDOWS\system32\drivers\srv.sys
2009-12-27 20:10:30 . 2009-12-27 20:10:30 6725632 ----a-w- C:\Documents and Settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\181625-18178.dll
2009-12-27 20:06:36 . 2009-01-11 21:46:24 245760 ----a-w- C:\Documents and Settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\QWPATCH.EXE
2009-12-27 20:00:16 . 2009-12-27 20:00:16 23 --sha-w- C:\WINDOWS\system32\edacded0.dat
2009-12-16 18:43:27 . 2004-08-10 19:01:15 343040 ----a-w- C:\WINDOWS\system32\mspaint.exe
2009-12-14 07:08:23 . 2004-08-10 18:50:56 33280 ----a-w- C:\WINDOWS\system32\csrsrv.dll
2009-12-04 18:22:22 . 2005-12-05 20:18:18 455424 ----a-w- C:\WINDOWS\system32\drivers\mrxsmb.sys
2007-12-27 21:38:02 . 2005-12-19 23:58:17 104 -csh--r- C:\WINDOWS\system32\4EC908632C.sys
2007-12-27 21:38:05 . 2005-12-19 23:58:17 4704 -csha-w- C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 23:20:16 279944 ----a-w- C:\Program Files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2008-10-01 07:40:01 192960 ------w- C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "C:\Program Files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 23:20:16 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2009-01-09 22:13:28 583312 ----a-r- C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2009-01-09 22:13:28 583312 ----a-r- C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2009-01-09 22:13:28 583312 ----a-r- C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgrWired"="C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe" [2004-12-09 19:58:46 86016]
"ACQTMOUSE"="C:\Program Files\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe" [2008-08-01 20:30:28 501760]
"Carbonite Backup"="C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2009-01-09 22:13:26 669840]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2010-01-18 20:14:26 1286608]

C:\Documents and Settings\Julie Sittler\Start Menu\Programs\Startup\
Billminder.lnk - C:\QUICKENW\billmind.exe [2008-8-19 25984]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"DMXLauncher"=C:\Program Files\Dell\Media Experience\DMXLauncher.exe
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe
"Adobe_ID0EYTHM"=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
"EKIJ5000StatusMonitor"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"HostManager"=C:\Program Files\Common Files\AOL\1245897695\ee\AOLSoftware.exe
"Dell QuickSet"=C:\Program Files\Dell\QuickSet\quickset.exe
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
"Pfepo"=rundll32.exe "C:\WINDOWS\ujuqevemiteduzu.dll",Startup
"Malwarebytes Anti-Malware (reboot)"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls]
BCMWnet1 REG_SZ C:\WINDOWS\system32\lighexnt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R0 PCTCore;PCTools KDS;C:\WINDOWS\system32\drivers\PCTCore.sys [2/28/2010 8:50:54 PM 207280]
R2 sdAuxService;PC Tools Auxiliary Service;C:\Program Files\Spyware Doctor\pctsAuxs.exe [2/28/2010 8:49:54 PM 365280]
S2 Browser Defender Update Service;Browser Defender Update Service;C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe [2/28/2010 8:51:56 PM 112592]
S3 ACRUSBTM;ACRUSBTM;C:\WINDOWS\system32\drivers\ACRUSBTM.SYS [2/13/2010 10:54:26 AM 28672]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\drivers\w300mgmt.sys [11/26/2006 9:11:07 PM 87824]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\drivers\w300obex.sys [11/26/2006 9:11:02 PM 85696]

--- Other Services/Drivers In Memory ---

*Deregistered* - PCTSDInjDriver32

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{86466aeb-b5d5-11dd-99ef-00038a000015}]
\Shell\AutoRun\command - E:\InstallSeagateManager.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9321f348-75b3-11dc-95fd-00038a000015}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9321f34a-75b3-11dc-95fd-00038a000015}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cad46b9e-08e9-11de-9a91-0014a45652a8}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de0dd71a-170d-11de-9aa7-0014a45652a8}]
\Shell\AutoRun\command - E:\WDSetup.exe
.
Contents of the 'Scheduled Tasks' folder

2010-03-01 C:\WINDOWS\Tasks\GlaryInitialize.job
- C:\Program Files\Glary Utilities\initialize.exe [2009-02-26 18:39:00 . 2009-02-12 23:10:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://www.msn.com
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/mywaybiz
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
LSP: C:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll
Trusted Zone: aol.com\free
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{BE0027FB-31FF-4661-82BC-83ADCEF28F0F} - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
AddRemove-WebCyberCoach_wtrb - C:\Program Files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
AddRemove-WinPcapInst - C:\Program Files\WinPcap\Uninstall.exe




#8 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,227 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:01:40 PM

Posted 01 March 2010 - 12:23 AM

  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop
QUOTE
File::
C:\WINDOWS\ujuqevemiteduzu.dll
C:\WINDOWS\system32\lighexnt.dll

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Pfepo"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls]
"BCMWnet1"=-




Once saved, referring to the picture above, drag CFScript.txt into ComboFix.exe, and post back the resulting report.

Lets scan for remnants:

Please do an online scan with Kaspersky WebScanner

Kaspersky online scanner uses JAVA tecnology to perform the scan. If you do not have the latest JAVA version, follow the instructions below under Upgrading Java, to download and install the latest version.
  1. Read through the requirements and privacy statement and click on Accept button.
  2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  3. When the downloads have finished, click on Settings.
  4. Make sure the following is checked.
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  5. Click on My Computer under Scan.
  6. Once the scan is complete, it will display the results. Click on View Scan Report.
  7. You will see a list of infected items there. Click on Save Report As....
  8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  9. Please post this log in your next reply.
Attention! Kaspersky Online Scanner 7.0 may fail to start if another anti-virus program is already installed and running on your computer. Please deactivate the anti-virus software installed on your computer prior to starting Kaspersky Online Scanner 7.0.

Upgrading Java :
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 18.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u18-windows-i586.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u18-windows-i586.exe and select "Run as an Administrator.")

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#9 sting66ray

sting66ray
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:40 AM

Posted 02 March 2010 - 12:54 AM

Thanks for your help, here is the log. I will run Kapersky as soon as I can and let you know what happens. Do I need to run combofix on my login as well?

ComboFix 10-03-01.01 - Julie Sittler 03/01/2010 23:07:48.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1271.733 [GMT -6:00]
Running from: c:\documents and settings\Julie Sittler\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Julie Sittler\Desktop\CFScript.text

FILE ::
"c:\windows\system32\lighexnt.dll"
"c:\windows\ujuqevemiteduzu.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\David Sittler\Local Settings\Application Data\{0AAD0A1A-177F-4471-A54B-C3E121CA8559}
c:\documents and settings\David Sittler\Local Settings\Application Data\{0AAD0A1A-177F-4471-A54B-C3E121CA8559}\chrome.manifest
c:\documents and settings\David Sittler\Local Settings\Application Data\{0AAD0A1A-177F-4471-A54B-C3E121CA8559}\chrome\content\_cfg.js
c:\documents and settings\David Sittler\Local Settings\Application Data\{0AAD0A1A-177F-4471-A54B-C3E121CA8559}\chrome\content\overlay.xul
c:\documents and settings\David Sittler\Local Settings\Application Data\{0AAD0A1A-177F-4471-A54B-C3E121CA8559}\install.rdf
.
---- Previous Run -------
.
c:\documents and settings\Julie Sittler\Application Data\alot\BrowserSearch\BrowserSearch.xml
c:\documents and settings\Julie Sittler\Application Data\alot\BrowserSearch\BrowserSearch.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\Button_0\Button_0.xml
c:\documents and settings\Julie Sittler\Application Data\alot\Button_0\Button_0.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\Button_1\Button_1.xml
c:\documents and settings\Julie Sittler\Application Data\alot\Button_1\Button_1.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\Button_2\Button_2.xml
c:\documents and settings\Julie Sittler\Application Data\alot\Button_2\Button_2.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\Button_3\Button_3.xml
c:\documents and settings\Julie Sittler\Application Data\alot\Button_3\Button_3.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\Button_4\Button_4.xml
c:\documents and settings\Julie Sittler\Application Data\alot\Button_4\Button_4.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\Button_5\Button_5.xml
c:\documents and settings\Julie Sittler\Application Data\alot\Button_5\Button_5.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\Button_6\Button_6.xml
c:\documents and settings\Julie Sittler\Application Data\alot\Button_6\Button_6.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\configurator\configurator.xml
c:\documents and settings\Julie Sittler\Application Data\alot\configurator\configurator.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\contextMenu\contextMenu.xml
c:\documents and settings\Julie Sittler\Application Data\alot\contextMenu\contextMenu.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\ErrorSearch\ErrorSearch.xml
c:\documents and settings\Julie Sittler\Application Data\alot\ErrorSearch\ErrorSearch.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\postInstallLayout\postInstallLayout.xml
c:\documents and settings\Julie Sittler\Application Data\alot\postInstallLayout\postInstallLayout.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\products\products.xml
c:\documents and settings\Julie Sittler\Application Data\alot\products\products.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\BrowserSearch\alot_search_defend.html
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_0\images\alot_logo_button.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_0\images\alot_logo_button.png
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_1\images\alot_search_button.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_1\images\alot_search_button.png
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_2\images\default_1008_alot_map_widget_default.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_2\images\default_1008_alot_map_widget_default.png
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_3\images\default_1011_alot_maps_tools.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_3\images\default_1011_alot_maps_tools.png
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_4\images\default_1007_alot_weather_widget.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_4\images\default_1007_alot_weather_widget.png
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_4\images\nclear.png
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_4\images\pcloud.png
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_5\images\default_1012_alot_mrkt_travel.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_5\images\default_1012_alot_mrkt_travel.png
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_6\images\default_1046_alot_mrkt_180.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Button_6\images\default_1046_alot_mrkt_180.png
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\contextMenu\images\alot_menu_icon.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\contextMenu\images\alot_menu_icon.png
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Shared\domains.dat
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Shared\images\alot_brand.png
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Shared\images\alot_splitter.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Shared\images\alot_splitter.png
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Shared\images\spinner.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_bottom.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_btnclose0.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_btnclose1.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_caption.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_error_bg.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_error_close.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\Resources\Shared\images\widget_error_icon.bmp
c:\documents and settings\Julie Sittler\Application Data\alot\TimerManager\TimerManager.xml
c:\documents and settings\Julie Sittler\Application Data\alot\TimerManager\TimerManager.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\toolbar.xml
c:\documents and settings\Julie Sittler\Application Data\alot\toolbar.xml.backup
c:\documents and settings\Julie Sittler\Application Data\alot\ToolbarSearch\ToolbarSearch.xml
c:\documents and settings\Julie Sittler\Application Data\alot\Updater\Updater.xml
c:\documents and settings\Julie Sittler\Application Data\alot\Updater\Updater.xml.backup
c:\program files\Freeze.com Toolbar\autosearch_plugin.dll
c:\program files\Freeze.com Toolbar\basis.xml
c:\program files\Freeze.com Toolbar\freeze.bmp
c:\program files\Freeze.com Toolbar\freeze_us.crc
c:\program files\Freeze.com Toolbar\freeze_us.inf
c:\program files\Freeze.com Toolbar\frzToolbar_logo.bmp
c:\program files\Freeze.com Toolbar\icons.bmp
c:\program files\Freeze.com Toolbar\info.txt
c:\program files\Freeze.com Toolbar\options.html
c:\program files\Freeze.com Toolbar\powered_yahoo_search.bmp
c:\program files\Freeze.com Toolbar\tbhelper.dll
c:\program files\Freeze.com Toolbar\uninstall.exe
c:\program files\Freeze.com Toolbar\update.exe
c:\program files\Freeze.com Toolbar\version.txt
c:\program files\Freeze.com Toolbar\whiteList_plugin.dll
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\INSTALL.LOG
c:\program files\WinPCap\NetMonInstaller.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
c:\windows\EventSystem.log
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll



thanks, dave

#10 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,227 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:01:40 PM

Posted 02 March 2010 - 01:51 AM

The report seems incomplete.

QUOTE
Do I need to run combofix on my login as well?


The answer is no.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#11 sting66ray

sting66ray
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:40 AM

Posted 02 March 2010 - 08:51 PM

Hi ,

I ran it again and here is the report. It should be complete this time. Going to run Kapersky now will post when done. Sorry this is taking so long, my job got in the way!

dave




ComboFix 10-03-02.02 - David Sittler 03/02/2010 19:22:38.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1271.807 [GMT -6:00]
Running from: c:\documents and settings\Julie Sittler\desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2010-02-03 to 2010-03-03 )))))))))))))))))))))))))))))))
.

2010-03-02 20:52 . 2010-03-02 20:52 503808 ----a-w- c:\documents and settings\David Sittler\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6059cf52-n\msvcp71.dll
2010-03-02 20:52 . 2010-03-02 20:52 499712 ----a-w- c:\documents and settings\David Sittler\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6059cf52-n\jmc.dll
2010-03-02 20:52 . 2010-03-02 20:52 348160 ----a-w- c:\documents and settings\David Sittler\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6059cf52-n\msvcr71.dll
2010-03-02 20:52 . 2010-03-02 20:52 61440 ----a-w- c:\documents and settings\David Sittler\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1b7d4416-n\decora-sse.dll
2010-03-02 20:52 . 2010-03-02 20:52 12800 ----a-w- c:\documents and settings\David Sittler\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1b7d4416-n\decora-d3d.dll
2010-03-02 06:23 . 2010-03-02 06:23 -------- d-----w- c:\program files\Sun
2010-03-01 04:00 . 2010-03-01 04:03 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-03-01 02:51 . 2009-11-10 16:26 767952 ----a-w- c:\windows\BDTSupport.dll
2010-03-01 02:51 . 2009-11-10 16:28 149456 ----a-w- c:\windows\SGDetectionTool.dll
2010-03-01 02:51 . 2009-10-28 07:36 1152444 ----a-w- c:\windows\UDB.zip
2010-03-01 02:51 . 2008-11-26 18:08 131 ----a-w- c:\windows\IDB.zip
2010-03-01 02:51 . 2009-11-10 16:28 165840 ----a-w- c:\windows\PCTBDRes.dll
2010-03-01 02:51 . 2009-11-10 16:28 1640400 ----a-w- c:\windows\PCTBDCore.dll
2010-03-01 02:51 . 2010-02-05 15:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-03-01 02:50 . 2009-10-06 22:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-03-01 02:50 . 2009-09-23 22:10 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-03-01 02:49 . 2010-03-02 19:03 -------- d-----w- c:\program files\Spyware Doctor
2010-03-01 02:49 . 2010-03-02 18:59 -------- d-----w- c:\program files\Common Files\PC Tools
2010-03-01 02:48 . 2010-03-02 19:03 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-26 13:22 . 2010-02-26 13:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\GlarySoft
2010-02-26 13:15 . 2010-02-26 13:15 -------- d-----w- c:\program files\AskBarDis
2010-02-21 03:37 . 2010-02-23 01:38 1 ----a-w- c:\documents and settings\David Sittler\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-02-21 03:36 . 2010-02-21 03:36 -------- d-----w- c:\documents and settings\David Sittler\Application Data\OpenOffice.org
2010-02-19 18:52 . 2010-02-24 04:13 -------- d-----w- c:\program files\OpenOffice.org 3
2010-02-19 18:31 . 2010-02-19 18:31 152576 ----a-w- c:\documents and settings\David Sittler\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-19 03:37 . 2010-02-19 18:31 79488 ----a-w- c:\documents and settings\David Sittler\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-13 17:45 . 2010-02-26 13:33 120 ----a-w- c:\windows\Ipiyu.dat
2010-02-13 17:45 . 2010-02-26 13:33 0 ----a-w- c:\windows\Lvefediwihepala.bin
2010-02-13 16:54 . 2007-08-02 17:35 28672 ----a-w- c:\windows\system32\drivers\ACRUSBTM.SYS
2010-02-13 16:54 . 2010-02-13 16:54 -------- d-----w- c:\program files\Mouse Setting

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-02 06:18 . 2005-12-05 20:38 -------- d-----w- c:\program files\Java
2010-03-02 00:23 . 2006-03-11 04:18 116224 -c--a-w- c:\documents and settings\Julie Sittler\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-01 13:59 . 2004-08-04 04:59 96512 ----a-w- c:\windows\system32\drivers\atapi.svs
2010-03-01 13:59 . 2004-08-04 04:59 96512 ------w- c:\windows\system32\drivers\atapi.sys
2010-02-28 03:42 . 2009-02-26 18:38 -------- d-----w- c:\program files\Glary Utilities
2010-02-27 23:35 . 2009-02-20 01:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-25 03:53 . 2005-12-19 23:58 116224 -c--a-w- c:\documents and settings\David Sittler\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-24 04:13 . 2007-12-30 02:14 -------- d-----w- c:\documents and settings\Julie Sittler\Application Data\Apple Computer
2010-02-24 03:27 . 2005-12-05 20:41 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-24 03:22 . 2006-08-27 22:18 -------- d-----w- c:\program files\PCStitch Pro
2010-02-20 07:16 . 2005-12-18 23:48 -------- d--h--w- c:\program files\Zero G Registry
2010-02-20 07:16 . 2005-12-18 23:49 -------- d-----w- c:\program files\Money Matters 2005
2010-02-19 18:49 . 2008-12-28 15:46 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-19 03:18 . 2007-12-25 06:09 -------- d-----w- c:\program files\Common Files\Apple
2010-02-19 03:03 . 2005-12-05 20:38 -------- d-----w- c:\program files\Common Files\Java
2010-02-09 04:59 . 2007-03-17 15:27 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-02-06 00:33 . 2007-12-25 06:13 -------- d-----w- c:\documents and settings\David Sittler\Application Data\Apple Computer
2010-01-10 05:35 . 2010-01-10 05:35 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-01-08 04:29 . 2006-11-25 03:54 -------- d-----w- c:\program files\Creative
2010-01-07 22:07 . 2009-02-20 01:28 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07 . 2009-02-20 01:28 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 10:00 . 2004-08-10 18:51 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2009-04-11 17:17 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-10 18:50 17408 ----a-w- c:\windows\system32\corpol.dll
2010-01-03 18:26 . 2007-01-23 00:51 -------- d-----w- c:\documents and settings\David Sittler\Application Data\InstallShield
2010-01-03 18:25 . 2007-01-23 00:41 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
2009-12-31 16:50 . 2005-12-05 20:18 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-27 20:10 . 2009-12-27 20:10 6725632 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\181625-18178.dll
2009-12-27 20:06 . 2009-01-11 21:46 245760 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\QWPATCH.EXE
2009-12-27 20:00 . 2009-12-27 20:00 23 --sha-w- c:\windows\system32\edacded0.dat
2009-12-16 18:43 . 2004-08-10 19:01 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-10 18:50 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-04 18:22 . 2005-12-05 20:18 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2007-12-27 21:38 . 2005-12-19 23:58 104 -csh--r- c:\windows\system32\4EC908632C.sys
2007-12-27 21:38 . 2005-12-19 23:58 4704 -csha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-03-02_05.34.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-02 19:03 . 2010-03-02 19:03 16384 c:\windows\Temp\Perflib_Perfdata_1fc.dat
+ 2010-03-02 19:04 . 2010-03-02 19:04 16384 c:\windows\Temp\Perflib_Perfdata_1b8.dat
+ 2010-03-02 06:24 . 2010-03-02 06:24 386048 c:\windows\Installer\1531748.msi
+ 2010-03-02 06:19 . 2010-03-02 06:19 434688 c:\windows\Installer\1531743.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 23:20 279944 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2008-10-01 07:40 192960 ------w- c:\program files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2009-01-09 22:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2009-01-09 22:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2009-01-09 22:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgrWired"="c:\program files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe" [2004-12-09 86016]
"ACQTMOUSE"="c:\program files\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe" [2008-08-01 501760]
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2009-01-09 669840]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\documents and settings\Julie Sittler\Start Menu\Programs\Startup\
Billminder.lnk - c:\quickenw\billmind.exe [2008-8-19 25984]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"DMXLauncher"=c:\program files\Dell\Media Experience\DMXLauncher.exe
"igfxtray"=c:\windows\system32\igfxtray.exe
"igfxhkcmd"=c:\windows\system32\hkcmd.exe
"igfxpers"=c:\windows\system32\igfxpers.exe
"Adobe_ID0EYTHM"=c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe"
"EKIJ5000StatusMonitor"=c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
"McENUI"=c:\progra~1\McAfee\MHN\McENUI.exe /hide
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"HostManager"=c:\program files\Common Files\AOL\1245897695\ee\AOLSoftware.exe
"Dell QuickSet"=c:\program files\Dell\QuickSet\quickset.exe
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" /runkey
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2/28/2010 8:50 PM 207280]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2/28/2010 8:51 PM 112592]
S2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe --> c:\program files\Spyware Doctor\pctsAuxs.exe [?]
S3 ACRUSBTM;ACRUSBTM;c:\windows\system32\drivers\ACRUSBTM.SYS [2/13/2010 10:54 AM 28672]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w300mgmt.sys [11/26/2006 9:11 PM 87824]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;c:\windows\system32\drivers\w300obex.sys [11/26/2006 9:11 PM 85696]
.
Contents of the 'Scheduled Tasks' folder

2010-03-02 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-02-26 23:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://www.msn.com
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/mywaybiz
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
Trusted Zone: aol.com\free
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{BE0027FB-31FF-4661-82BC-83ADCEF28F0F} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-02 19:34
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(908)
c:\windows\System32\BCMLogon.dll

- - - - - - - > 'lsass.exe'(964)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll

- - - - - - - > 'explorer.exe'(3660)
c:\windows\system32\WININET.dll
c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-03-02 19:41:25
ComboFix-quarantined-files.txt 2010-03-03 01:41
ComboFix2.txt 2010-03-02 05:48

Pre-Run: 13,954,101,248 bytes free
Post-Run: 13,918,711,808 bytes free

- - End Of File - - 4E4AB1015B39920859D7A55C091F0537


#12 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,227 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:01:40 PM

Posted 02 March 2010 - 09:48 PM

All clear so far.

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#13 sting66ray

sting66ray
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:40 AM

Posted 03 March 2010 - 08:25 AM

Good Morning,
Here is the Kaspersky report:

KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, March 3, 2010
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, March 02, 2010 22:16:55
Records in database: 3689430
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Objects scanned: 169907
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 09:08:47


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Infected: Rootkit.Win32.Tdss.ai 1

Selected area has been scanned.


#14 JSntgRvr

JSntgRvr

    Master Surgeon General


  • Malware Response Team
  • 11,227 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:01:40 PM

Posted 03 March 2010 - 12:04 PM

Everything seems clear. How is the computer doing?

No request for help throughout private messaging will be attended.

If I have helped you, consider making a donation to help me continue the fight against Malware!
btn_donate_SM.gif


#15 sting66ray

sting66ray
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Local time:11:40 AM

Posted 03 March 2010 - 02:06 PM

It seems to be working good, now, thanks to you!! Do I have to do anything with that quarantined file? Is Kaspersky your favorite virus protection software?

Many, Many, Many Thanks!

dave




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users