Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Immortal King"s HJT log


  • This topic is locked This topic is locked
17 replies to this topic

#1 Immortal King

Immortal King

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:03:48 PM

Posted 26 April 2007 - 08:42 PM

Mod Edit: This log was split, from this thread:
Unknown Pop Ups & Error Loading Message On Reboot

Sorry,

I could subsequently locate the link to hijack this ... and here is the Log generated.

Logfile of HijackThis v1.99.1
Scan saved at 7:00:09 AM, on 27-Apr-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\Program Files\WinZip\WZQKPICK.EXE
D:\Program Files\Metacafe\MetacafeAgent.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
D:\Program Files\HijackThis\HijackThis.exe

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [InCD] "D:\Program Files\Nero\Nero 7\InCD\InCD.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\vfaroivb.dll",setvm
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\fmnlhsnq.dll",realset
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Metacafe.lnk = D:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: Metacafe.lnk = D:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download All Links with IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1173509922128
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1173590274316
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - http://202.138.123.119/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...017/mcfscan.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - D:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

Edited by tg1911, 26 April 2007 - 09:15 PM.


BC AdBot (Login to Remove)

 


m

#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:48 PM

Posted 27 April 2007 - 05:38 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum Immortal King :thumbsup:

Please download Combofix and save to the desktop:
http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.


*********************************

Please go to:
C:\Program Files\HijackThis\HijackThis.exe
Right click on Hijackthis.exe and select 'Rename', rename it to abc.bat
Double click on abc.bat(which is still Hijackthis.exe),post that log into your next reply,along with the C:\ComboFix.txt.
Posted Image
Posted Image

#3 Immortal King

Immortal King
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:03:48 PM

Posted 29 April 2007 - 01:28 PM

Thank you very much for attending to my request.

First of all I seek pardon as I had wrongly aded a reply earlier and caused inconvienience to move my post to the right place.

Well, now as directed pl. find below the logs:

Combofix Log
----------------


"A.J.Bashha" - 07-04-29 23:28:27 Service Pack 2
ComboFix 07-04-28.V - Running from: "E:\IDM Temp\DwnlData\A.J.Bashha\ComboFix_517\"


(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\byvuu.dll
C:\WINDOWS\system32\ddcaa.dll
C:\WINDOWS\system32\efcda.dll
C:\WINDOWS\system32\fmnlhsnq.dll
C:\WINDOWS\system32\gevrfwrg.dll
C:\WINDOWS\system32\hiktkjyp.dll
C:\WINDOWS\system32\pcnpckdb.dll
C:\WINDOWS\system32\uuvyb.bak1
C:\WINDOWS\system32\uuvyb.tmp
C:\WINDOWS\system32\aycdd.bak1
C:\WINDOWS\system32\aycdd.bak2
C:\WINDOWS\system32\aycdd.ini
C:\WINDOWS\system32\aycdd.tmp
C:\WINDOWS\system32\qnshlnmf.ini
C:\WINDOWS\system32\bdkcpncp.ini
C:\WINDOWS\system32\ddcya.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((( Files Created from 2007-03-28 to 2007-04-29 ))))))))))))))))))))))))))))))))))


2007-04-28 13:21 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
2007-04-27 01:11 <DIR> d-------- C:\WINDOWS\McAfee.com
2007-04-25 08:15 <DIR> d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\Lavasoft
2007-04-25 08:11 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-04-24 19:45 0 --a------ C:\WINDOWS\system32\iifrkncv.dll
2007-04-24 10:35 0 --a------ C:\WINDOWS\system32\fsojeprw.dll
2007-04-23 10:34 0 --a------ C:\WINDOWS\system32\egbdjinm.dll
2007-04-23 08:56 <DIR> d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\InterVideo
2007-04-23 08:55 <DIR> d-------- C:\Program Files\InterVideo
2007-04-23 08:54 204,800 --a------ C:\WINDOWS\system32\IVIresizeW7.dll
2007-04-23 08:54 200,704 --a------ C:\WINDOWS\system32\IVIresizeA6.dll
2007-04-23 08:54 20,480 --a------ C:\WINDOWS\system32\IVIresize.dll
2007-04-23 08:54 192,512 --a------ C:\WINDOWS\system32\IVIresizeP6.dll
2007-04-23 08:54 192,512 --a------ C:\WINDOWS\system32\IVIresizeM6.dll
2007-04-23 08:54 188,416 --a------ C:\WINDOWS\system32\IVIresizePX.dll
2007-04-23 08:52 26,678 --a------ C:\WINDOWS\system32\xxyvttu.dll
2007-04-23 08:52 26,678 --a------ C:\WINDOWS\system32\rqrponl.dll
2007-04-23 08:51 26,678 --a------ C:\WINDOWS\system32\awtrppo.dll
2007-04-18 00:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-04-14 08:00 <DIR> d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\pdf995
2007-04-14 07:56 51,716 --a------ C:\WINDOWS\system32\pdf995mon.dll
2007-04-14 07:56 122,880 --a------ C:\WINDOWS\system32\pdfmona.dll
2007-04-14 07:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\pdf995
2007-04-14 07:51 <DIR> d-------- C:\Program Files\pdf995
2007-04-11 20:36 1,289 --a------ C:\WINDOWS\mozver.dat
2007-04-10 06:42 0 --a------ C:\WINDOWS\nsreg.dat
2007-04-02 18:25 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
2007-04-02 18:17 <DIR> d-------- C:\Program Files\Yahoo!
2007-03-31 08:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Metacafe
2007-03-31 08:01 <DIR> d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\Metacafe
2007-03-30 07:01 <DIR> d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\eBookPro6


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-29 23:35 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-04-23 08:55 -------- d--h----- C:\Program Files\installshield installation information
2007-04-13 05:38 155648 --a------ C:\WINDOWS\system32\libssl32.dll
2007-03-25 07:29 -------- d-------- C:\Program Files\quicktime
2007-03-18 16:19 -------- d-------- C:\Program Files\Common Files\nullsoft
2007-03-17 19:13 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-15 00:08 -------- d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\vlc
2007-03-14 08:35 -------- d-------- C:\Program Files\rconnect
2007-03-14 08:28 -------- d-------- C:\Program Files\lgusbconverterdriver
2007-03-13 14:07 -------- d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\idm
2007-03-11 23:53 -------- d-------- C:\Program Files\Common Files\installshield
2007-03-11 10:09 -------- d-------- C:\Program Files\conexant
2007-03-10 23:29 -------- d-------- C:\Program Files\messenger
2007-03-10 11:14 -------- d-------- C:\Program Files\microsoft.net
2007-03-10 07:27 -------- d-------- C:\Program Files\Common Files\odbc
2007-03-10 07:26 62 --ahs---- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\desktop.ini
2007-03-10 07:26 -------- d-------- C:\Program Files\Common Files\speechengines
2007-03-10 05:38 -------- d-------- C:\Program Files\siber systems
2007-03-10 04:54 -------- d-------- C:\Program Files\microsoft activesync
2007-03-10 04:52 -------- d-------- C:\Program Files\Common Files\l&h
2007-03-10 03:13 -------- d-------- C:\Program Files\movie maker
2007-03-10 03:10 -------- d-------- C:\Program Files\windows nt
2007-03-10 02:35 32 --ahs---- C:\WINDOWS\system32\{6a1492e3-584f-4e38-adf5-6f42d8c74291}.dat
2007-03-10 02:35 32 --ahs---- C:\WINDOWS\{945117be-06a6-4e21-8323-f93b698c3a28}.dat
2007-03-10 02:35 14 --a------ C:\WINDOWS\system32\sr2.dat
2007-03-10 02:35 -------- d-------- C:\Program Files\symantec
2007-03-10 02:35 -------- d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\symantec
2007-03-10 02:15 0 -rahs---- C:\MSDOS.SYS
2007-03-10 02:15 0 -rahs---- C:\IO.SYS
2007-03-10 02:15 0 --a------ C:\CONFIG.SYS
2007-03-10 02:15 0 --a------ C:\AUTOEXEC.BAT
2007-03-10 02:15 -------- d-------- C:\Program Files\microsoft frontpage
2007-03-10 02:13 -------- d-------- C:\Program Files\online services
2007-03-10 02:12 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-03-10 02:12 -------- d-------- C:\Program Files\Common Files\mssoap
2007-03-10 02:11 -------- d--h----- C:\Program Files\windowsupdate
2007-03-10 02:11 -------- d-------- C:\Program Files\msn gaming zone
2007-03-08 21:06 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 21:06 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 21:06 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 19:17 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-02-22 05:13 128528 --a------ C:\WINDOWS\system32\metacafe.scr
2007-02-21 21:00 10752 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-02-06 01:47 185344 --a------ C:\WINDOWS\system32\upnphost.dll
2007-02-01 05:56 639066 --a------ C:\WINDOWS\system32\divx.dll
2007-01-30 06:03 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-01-30 06:03 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-01-30 06:03 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-01-30 05:56 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-01-30 05:56 196608 --a------ C:\WINDOWS\system32\dtu100.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{0055C089-8582-441B-A0BF-17B458C2A3A8}"="D:\Program Files\Internet Download Manager\IDMIECC.dll"
"{66020456-CB22-487F-AC2C-09F6417C55B3}"="C:\WINDOWS\system32\awtrppo.dll"
"{724d43a9-0d85-11d4-9908-00400523e39a}"="C:\Program Files\Siber Systems\AI RoboForm\roboform.dll"
"{BDF3E430-B101-42AD-A544-FADC6B084872}"="D:\Program Files\Norton AntiVirus\NavShExt.dll"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"ccRegVfy"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\""
"ATIModeChange"="Ati2mdxx.exe"
"NeroFilterCheck"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe\""
"InCD"="\"D:\\Program Files\\Nero\\Nero 7\\InCD\\InCD.exe\""
"CARPService"="carpserv.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"WatchDog"="C:\\Program Files\\InterVideo\\DVD Check\\DVDCheck.exe"
"Windows Defender"="\"D:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
"IDMan"="D:\\Program Files\\Internet Download Manager\\IDMan.exe /onboot"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Yahoo! Pager"="\"D:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"RoboForm"="\"C:\\Program Files\\Siber Systems\\AI RoboForm\\RoboTaskBarIcon.exe\""

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{66020456-CB22-487F-AC2C-09F6417C55B3}"="C:\WINDOWS\system32\awtrppo.dll"


HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtrppo

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{99e130e4-d939-11db-9774-000d9dcd66cf}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Low Battery Alarm Program.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
C:\WINDOWS\tasks\Symantec NetDetect.job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-04-29 23:39:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 07-04-29 23:39:41 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-04-29 23:39


--------------------------------------------------------------------------------------------------------
--------------------------------------------------------------------------------------------------------

hijackthis Log
----------------

Logfile of HijackThis v1.99.1
Scan saved at 11:46:07 PM, on 29-Apr-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\Program Files\Metacafe\MetacafeAgent.exe
D:\Program Files\Internet Download Manager\IEMonitor.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\RConnect\RConnectDialer.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\HijackThis\abc.bat

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {66020456-CB22-487F-AC2C-09F6417C55B3} - C:\WINDOWS\system32\awtrppo.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [InCD] "D:\Program Files\Nero\Nero 7\InCD\InCD.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Metacafe.lnk = D:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: Metacafe.lnk = D:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download All Links with IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1173509922128
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1173590274316
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - http://202.138.123.119/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...017/mcfscan.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{389825B8-FAFB-469B-B428-9FA86F354D80}: NameServer = 202.138.103.100 202.138.96.2
O20 - Winlogon Notify: awtrppo - C:\WINDOWS\SYSTEM32\awtrppo.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - D:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

-------------------------------------------------------------------------------------------------------------------------

Please direct me further.

Thanks and Regards

Immortal King

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:48 PM

Posted 29 April 2007 - 02:00 PM

Download Avenger from the link below:
http://swandog46.geekstogo.com/avenger.zip
Unzip/extract it to your desktop.

Start up Avenger.
Check the 'Input script manually' option.
Click the Magnifying Glass icon.
In the box that opens,copy and paste ALL the following bold blue text in the Quote box below:

Files to delete:
C:\WINDOWS\system32\iifrkncv.dll
C:\WINDOWS\system32\fsojeprw.dll
C:\WINDOWS\system32\egbdjinm.dll
C:\WINDOWS\system32\xxyvttu.dll
C:\WINDOWS\system32\rqrponl.dll
C:\WINDOWS\system32\awtrppo.dll

Then click on 'Done'.
Click the Traffic Light icon to start the program.
Then press OK at the prompts to reboot your PC.

Post the Avenger output.txt, which you can find at C:\Avenger\.txt into your next reply.
Also post a new Hijackthis log please.
Posted Image
Posted Image

#5 Immortal King

Immortal King
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:03:48 PM

Posted 30 April 2007 - 05:25 AM

As directed pl. find below the logs:

Avenger Log
-------------------

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\twcplcct

*******************

Script file located at: \??\C:\Documents and Settings\fdkjrg^e.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\system32\iifrkncv.dll deleted successfully.
File C:\WINDOWS\system32\fsojeprw.dll deleted successfully.
File C:\WINDOWS\system32\egbdjinm.dll deleted successfully.
File C:\WINDOWS\system32\xxyvttu.dll deleted successfully.
File C:\WINDOWS\system32\rqrponl.dll deleted successfully.
File C:\WINDOWS\system32\awtrppo.dll deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

--------------------------------------------------------------------------------------------------------
--------------------------------------------------------------------------------------------------------

hijackthis Log
--------------------


Logfile of HijackThis v1.99.1
Scan saved at 6:10:28 AM, on 30-Apr-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\QuickTime\qttask.exe
D:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Program Files\WinZip\WZQKPICK.EXE
D:\Program Files\Metacafe\MetacafeAgent.exe
D:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\Program Files\HijackThis\abc.bat

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4A999C5C-8DC7-4381-84F5-32235D4A958F} - C:\WINDOWS\system32\fccdb.dll
O2 - BHO: (no name) - {66020456-CB22-487F-AC2C-09F6417C55B3} - C:\WINDOWS\system32\awtrppo.dll (file missing)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\ultvjhgt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [InCD] "D:\Program Files\Nero\Nero 7\InCD\InCD.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\baqxhgtq.dll",realset
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Metacafe.lnk = D:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: Metacafe.lnk = D:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download All Links with IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1173509922128
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1173590274316
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - http://202.138.123.119/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...017/mcfscan.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: awtrppo - awtrppo.dll (file missing)
O20 - Winlogon Notify: fccdb - C:\WINDOWS\system32\fccdb.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - D:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

-------------------------------------------------------------------------------------------------------------------------

Please direct me further.

Thanks and Regards

Immortal King

PS: I had a pop-up today also after deleting those files indicated by you with the help of Avenger.

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:48 PM

Posted 30 April 2007 - 05:28 AM

Please download VundoFix.exe to your desktop.
Double-click VundoFix.exe to run it.
When VundoFix re-opens,click the "Scan for Vundo" button.
Once it's done scanning,click the "Remove Vundo" button.
You will receive a prompt asking if you want to remove the files, click "YES".
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed,it will prompt that it will reboot your computer,click "OK".
Please post the contents of C:\vundofix.txt into your next reply,along with a new Hijackthis log.

Note:
It is possible that VundoFix encountered a file it could not remove.
In this case,VundoFix will run on reboot,simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
Posted Image
Posted Image

#7 Immortal King

Immortal King
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:03:48 PM

Posted 30 April 2007 - 07:39 AM

Hi,

Here are the required Logs.

vundofix.txt
-----------------

VundoFix V6.3.21

Checking Java version...

Sun Java not detected
Scan started at 5:27:41 PM 30-Apr-07

Listing files found while scanning....

C:\WINDOWS\system32\awtrppo.dll
C:\WINDOWS\system32\baqxhgtq.dll
C:\WINDOWS\system32\bdccf.bak1
C:\WINDOWS\system32\bdccf.ini
C:\WINDOWS\system32\fccdb.dll
C:\WINDOWS\system32\qtghxqab.ini
C:\WINDOWS\system32\ultvjhgt.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\baqxhgtq.dll
C:\WINDOWS\system32\baqxhgtq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bdccf.bak1
C:\WINDOWS\system32\bdccf.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\bdccf.ini
C:\WINDOWS\system32\bdccf.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\fccdb.dll
C:\WINDOWS\system32\fccdb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qtghxqab.ini
C:\WINDOWS\system32\qtghxqab.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ultvjhgt.dll
C:\WINDOWS\system32\ultvjhgt.dll Has been deleted!

Performing Repairs to the registry.
Done!

--------------------------------------------------------------------------------------------------------
--------------------------------------------------------------------------------------------------------

hijackthis Log
--------------------

Logfile of HijackThis v1.99.1
Scan saved at 5:58:01 PM, on 30-Apr-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\QuickTime\qttask.exe
D:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
D:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\Program Files\Metacafe\MetacafeAgent.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
D:\Program Files\HijackThis\abc.bat

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {14DA411A-909B-4012-BC38-F8C2585BEE10} - C:\WINDOWS\system32\fccdb.dll (file missing)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [InCD] "D:\Program Files\Nero\Nero 7\InCD\InCD.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\baqxhgtq.dll",realset
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Metacafe.lnk = D:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: Metacafe.lnk = D:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download All Links with IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1173509922128
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1173590274316
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - http://202.138.123.119/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...017/mcfscan.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6AF3F78F-C859-43CA-B27E-07DF5E300840}: NameServer = 203.145.184.13,202.56.250.5
O20 - Winlogon Notify: awtrppo - awtrppo.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - D:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

----------------------------------------------------------------------------------

This time while rebooting after running VundoFix.exe the following Error Message appeared.

Error loading C:\WINDOWS\System32\bagxhgtg.dll specified module could not be found.

Now please guide me further.

Regards and Thanks

Immortal King

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:48 PM

Posted 30 April 2007 - 07:47 AM

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - {14DA411A-909B-4012-BC38-F8C2585BEE10} - C:\WINDOWS\system32\fccdb.dll (file missing)
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\baqxhgtq.dll",realset
O20 - Winlogon Notify: awtrppo - awtrppo.dll (file missing)

Exit Hijackthis.

**************************

Double click on combofix.exe again and follow the prompts.
When it's finished it will produce a log.
Post the C:\ComboFix.txt into your next reply.
Also post a new Hijackthis log,let me know how your pc is running now.
Posted Image
Posted Image

#9 Immortal King

Immortal King
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:03:48 PM

Posted 30 April 2007 - 08:24 AM

Hi,

Here are the new Logs

ComboFix.txt
-----------------------

"A.J.Bashha" - 07-04-30 18:24:47 Service Pack 2
ComboFix 07-04-28.V - Running from: "E:\Downloads\Programs\"


((((((((((((((((((((((((((((((( Files Created from 2007-03-28 to 2007-04-30 ))))))))))))))))))))))))))))))))))


2007-04-30 17:27 <DIR> d-------- C:\VundoFix Backups
2007-04-30 06:02 <DIR> d-------- C:\avenger
2007-04-29 23:39 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-04-28 13:21 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
2007-04-27 01:11 <DIR> d-------- C:\WINDOWS\McAfee.com
2007-04-25 08:15 <DIR> d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\Lavasoft
2007-04-25 08:11 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-04-23 08:56 <DIR> d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\InterVideo
2007-04-23 08:55 <DIR> d-------- C:\Program Files\InterVideo
2007-04-23 08:54 204,800 --a------ C:\WINDOWS\system32\IVIresizeW7.dll
2007-04-23 08:54 200,704 --a------ C:\WINDOWS\system32\IVIresizeA6.dll
2007-04-23 08:54 20,480 --a------ C:\WINDOWS\system32\IVIresize.dll
2007-04-23 08:54 192,512 --a------ C:\WINDOWS\system32\IVIresizeP6.dll
2007-04-23 08:54 192,512 --a------ C:\WINDOWS\system32\IVIresizeM6.dll
2007-04-23 08:54 188,416 --a------ C:\WINDOWS\system32\IVIresizePX.dll
2007-04-18 00:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-04-14 08:00 <DIR> d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\pdf995
2007-04-14 07:56 51,716 --a------ C:\WINDOWS\system32\pdf995mon.dll
2007-04-14 07:56 122,880 --a------ C:\WINDOWS\system32\pdfmona.dll
2007-04-14 07:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\pdf995
2007-04-14 07:51 <DIR> d-------- C:\Program Files\pdf995
2007-04-11 20:36 1,289 --a------ C:\WINDOWS\mozver.dat
2007-04-10 06:42 0 --a------ C:\WINDOWS\nsreg.dat
2007-04-02 18:25 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
2007-04-02 18:17 <DIR> d-------- C:\Program Files\Yahoo!
2007-03-31 08:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Metacafe
2007-03-31 08:01 <DIR> d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\Metacafe
2007-03-30 07:01 <DIR> d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\eBookPro6


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-30 17:43 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-04-23 08:55 -------- d--h----- C:\Program Files\installshield installation information
2007-04-13 05:38 155648 --a------ C:\WINDOWS\system32\libssl32.dll
2007-03-25 07:29 -------- d-------- C:\Program Files\quicktime
2007-03-18 16:19 -------- d-------- C:\Program Files\Common Files\nullsoft
2007-03-17 19:13 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-15 00:08 -------- d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\vlc
2007-03-14 08:35 -------- d-------- C:\Program Files\rconnect
2007-03-14 08:28 -------- d-------- C:\Program Files\lgusbconverterdriver
2007-03-13 14:07 -------- d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\idm
2007-03-11 23:53 -------- d-------- C:\Program Files\Common Files\installshield
2007-03-11 10:09 -------- d-------- C:\Program Files\conexant
2007-03-10 23:29 -------- d-------- C:\Program Files\messenger
2007-03-10 11:14 -------- d-------- C:\Program Files\microsoft.net
2007-03-10 07:27 -------- d-------- C:\Program Files\Common Files\odbc
2007-03-10 07:26 62 --ahs---- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\desktop.ini
2007-03-10 07:26 -------- d-------- C:\Program Files\Common Files\speechengines
2007-03-10 05:38 -------- d-------- C:\Program Files\siber systems
2007-03-10 04:54 -------- d-------- C:\Program Files\microsoft activesync
2007-03-10 04:52 -------- d-------- C:\Program Files\Common Files\l&h
2007-03-10 03:13 -------- d-------- C:\Program Files\movie maker
2007-03-10 03:10 -------- d-------- C:\Program Files\windows nt
2007-03-10 02:35 32 --ahs---- C:\WINDOWS\system32\{6a1492e3-584f-4e38-adf5-6f42d8c74291}.dat
2007-03-10 02:35 32 --ahs---- C:\WINDOWS\{945117be-06a6-4e21-8323-f93b698c3a28}.dat
2007-03-10 02:35 14 --a------ C:\WINDOWS\system32\sr2.dat
2007-03-10 02:35 -------- d-------- C:\Program Files\symantec
2007-03-10 02:35 -------- d-------- C:\DOCUME~1\AJ5002~1.BAS\APPLIC~1\symantec
2007-03-10 02:15 0 -rahs---- C:\MSDOS.SYS
2007-03-10 02:15 0 -rahs---- C:\IO.SYS
2007-03-10 02:15 0 --a------ C:\CONFIG.SYS
2007-03-10 02:15 0 --a------ C:\AUTOEXEC.BAT
2007-03-10 02:15 -------- d-------- C:\Program Files\microsoft frontpage
2007-03-10 02:13 -------- d-------- C:\Program Files\online services
2007-03-10 02:12 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-03-10 02:12 -------- d-------- C:\Program Files\Common Files\mssoap
2007-03-10 02:11 -------- d--h----- C:\Program Files\windowsupdate
2007-03-10 02:11 -------- d-------- C:\Program Files\msn gaming zone
2007-03-08 21:06 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 21:06 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 21:06 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 19:17 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-02-22 05:13 128528 --a------ C:\WINDOWS\system32\metacafe.scr
2007-02-21 21:00 10752 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-02-06 01:47 185344 --a------ C:\WINDOWS\system32\upnphost.dll
2007-02-01 05:56 639066 --a------ C:\WINDOWS\system32\divx.dll
2007-01-30 06:03 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-01-30 06:03 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-01-30 06:03 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-01-30 05:56 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-01-30 05:56 196608 --a------ C:\WINDOWS\system32\dtu100.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{0055C089-8582-441B-A0BF-17B458C2A3A8}"="D:\Program Files\Internet Download Manager\IDMIECC.dll"
"{724d43a9-0d85-11d4-9908-00400523e39a}"="C:\Program Files\Siber Systems\AI RoboForm\roboform.dll"
"{BDF3E430-B101-42AD-A544-FADC6B084872}"="D:\Program Files\Norton AntiVirus\NavShExt.dll"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"ccRegVfy"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\""
"ATIModeChange"="Ati2mdxx.exe"
"NeroFilterCheck"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe\""
"InCD"="\"D:\\Program Files\\Nero\\Nero 7\\InCD\\InCD.exe\""
"CARPService"="carpserv.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"WatchDog"="C:\\Program Files\\InterVideo\\DVD Check\\DVDCheck.exe"
"Windows Defender"="\"D:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
"IDMan"="D:\\Program Files\\Internet Download Manager\\IDMan.exe /onboot"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Yahoo! Pager"="\"D:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"RoboForm"="\"C:\\Program Files\\Siber Systems\\AI RoboForm\\RoboTaskBarIcon.exe\""

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{99e130e4-d939-11db-9774-000d9dcd66cf}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Low Battery Alarm Program.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
C:\WINDOWS\tasks\Symantec NetDetect.job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-04-30 18:27:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 07-04-30 18:27:06
C:\ComboFix-quarantined-files.txt ... 07-04-30 18:27
C:\ComboFix2.txt ... 07-04-29 23:39

--------------------------------------------------------------------------------------------------------
--------------------------------------------------------------------------------------------------------

hijackthis Log
--------------------

Logfile of HijackThis v1.99.1
Scan saved at 6:30:13 PM, on 30-Apr-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\QuickTime\qttask.exe
D:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
D:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\Program Files\Metacafe\MetacafeAgent.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\NOTEPAD.EXE
D:\Program Files\HijackThis\abc.bat

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [InCD] "D:\Program Files\Nero\Nero 7\InCD\InCD.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Metacafe.lnk = D:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: Metacafe.lnk = D:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download All Links with IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1173509922128
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1173590274316
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - http://202.138.123.119/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...017/mcfscan.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6AF3F78F-C859-43CA-B27E-07DF5E300840}: NameServer = 203.145.184.13,202.56.250.5
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - D:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

==========================================

Thank you for the great guidance extended. Pl. indicate me if have to do anything further to correct my PC.

Immortal King

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:48 PM

Posted 30 April 2007 - 09:03 AM

Your log is clean :thumbsup:
If all's ok,please do the following:

Find and delete:
C:\VundoFix Backups
C:\avenger
C:\QooBox

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
'How to prevent Malware' by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html
Posted Image
Posted Image

#11 Immortal King

Immortal King
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:03:48 PM

Posted 04 May 2007 - 09:13 AM

Hi all those Moderators at Bleeping Computer and especially Malware Assassin, It is really heartening to have my computer cleaned with few fast guidance instructions.

Really impressing and memorble experience. Thanks to all of you engaged in the Service of those desperate and struggling with Malwares and Adwares.

Hats Off to you Guys.

My computer is healthy.. Antivirus like Norton could not solve these problems got solved with very tiny sized wares.

Thanks a lot.

Immortal King :thumbsup:

Ps. Delay in reply occured I was checking the computer to be doubly sure that it is healthy.

#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:48 PM

Posted 04 May 2007 - 09:17 AM

You're most welcome Immortal King,and thanks for the compliments,much appreciated :thumbsup:
Posted Image
Posted Image

#13 Immortal King

Immortal King
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:03:48 PM

Posted 05 May 2007 - 09:57 AM

Hi,

Today I found that my PC is affected with Trojan.Anicmoo and Norton failed to clean it up.

As indicated in your last guidance I had completed 'Creating a Restore Point' and 'Disk Cleanup' immediately on reading your instruction. Please help me.

Regards & Thanks

Immortal King

Ps:

Here is the HijackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 8:25:40 PM, on 05-May-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
D:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\Program Files\Nero\Nero 7\InCD\InCD.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\QuickTime\qttask.exe
D:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\Program Files\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
D:\Program Files\Metacafe\MetacafeAgent.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
D:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\HijackThis\abc.bat

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [InCD] "D:\Program Files\Nero\Nero 7\InCD\InCD.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Metacafe.lnk = D:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = D:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: Metacafe.lnk = D:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download All Links with IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1173509922128
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1173590274316
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - http://202.138.123.119/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...017/mcfscan.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - D:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

Edited by Immortal King, 05 May 2007 - 10:00 AM.


#14 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:09:48 PM

Posted 05 May 2007 - 10:53 AM

Run 'BitDefender Online Scanner' using Internet Explorer:
http://www.bitdefender.com/scan8/ie.html
Read the 'END USER SOFTWARE LICENSE AGREEMENT' then click 'I agree'.
You'll be prompted to install the activex control,please do so.
Once installed,disable your current antivirus program,then click the 'Click here to scan' button.
The virus signatures will then load.
Once loaded the scan will start.
The scan will take quite some time so please be patient.
Once the scan has finished select the 'Detected Problems' tab.
Click on 'Click here to export scan'.
Save the file as an HTML file to your desktop.
Then click on the saved file and allow it to open with your browser.
Go to 'Edit'/'Select All' then copy and paste that log into your next reply.
*Note*
Don't forget to re-enable your antivirus program.
Posted Image
Posted Image

#15 Immortal King

Immortal King
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:03:48 PM

Posted 07 May 2007 - 07:46 AM

Hi,

Here is the Scan Report of BitDefender
===============================================================

BitDefender Online Scanner

Scan report generated at: Mon, May 07, 2007 - 05:11:19


Scan path: A:\;C:\;D:\;E:\;F:\;


Statistics

Time
06:27:59

Files
935683

Folders
14020

Boot Sectors
4

Archives
7914

Packed Files
146618




Results

Identified Viruses
25

Infected Files
60

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
91




Engines Info

Virus Definitions
504399

Engine build
AVCORE v1.0 (build 2397) (i386) (Feb 8 2007 14:24:08)

Scan plugins
14

Archive plugins
38

Unpack plugins
6

E-mail plugins
6

System plugins
1




Scan Settings

First Action
Disinfect

Second Action
Delete

Heuristics
Yes

Enable Warnings
Yes

Scanned Extensions
*;

Exclude Extensions


Scan Emails
Yes

Scan Archives
Yes

Scan Packed
Yes

Scan Files
Yes

Scan Boot
Yes




Scanned File
Status

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\1PLJ30CW\popup[1].htm
Infected with: Trojan.Clicker.CM

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\1PLJ30CW\popup[1].htm
Disinfection failed

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\1PLJ30CW\popup[1].htm
Deleted

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\F154OR6J\popup[2].htm
Infected with: Trojan.Clicker.CM

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\F154OR6J\popup[2].htm
Disinfection failed

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\F154OR6J\popup[2].htm
Deleted

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\FSQLAW04\popup[1].htm
Infected with: Trojan.Clicker.CM

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\FSQLAW04\popup[1].htm
Disinfection failed

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\FSQLAW04\popup[1].htm
Deleted

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\JCUQZPDZ\popup[2].htm
Infected with: Trojan.Clicker.CM

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\JCUQZPDZ\popup[2].htm
Disinfection failed

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\JCUQZPDZ\popup[2].htm
Deleted

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\S96N0LU3\popup[1].htm
Infected with: Trojan.Clicker.CM

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\S96N0LU3\popup[1].htm
Disinfection failed

C:\Documents and Settings\A.J.Bashha\Local Settings\Temporary Internet Files\Content.IE5\S96N0LU3\popup[1].htm
Deleted

D:\Program Files\Norton AntiVirus\Quarantine\1A246431.vir=>(Quarantine-2)
Infected with: Trojan.Vundo.DLP

D:\Program Files\Norton AntiVirus\Quarantine\1A246431.vir=>(Quarantine-2)
Disinfection failed

D:\Program Files\Norton AntiVirus\Quarantine\1A246431.vir=>(Quarantine-2)
Deleted

D:\Program Files\Norton AntiVirus\Quarantine\1D2D309F.dll=>(Quarantine-2)
Infected with: Trojan.Spy.VBStat.B

D:\Program Files\Norton AntiVirus\Quarantine\1D2D309F.dll=>(Quarantine-2)
Deleted

D:\Program Files\Norton AntiVirus\Quarantine\29E636EB.dll=>(Quarantine-2)
Infected with: Trojan.Spy.VBStat.B

D:\Program Files\Norton AntiVirus\Quarantine\29E636EB.dll=>(Quarantine-2)
Deleted

D:\Program Files\Norton AntiVirus\Quarantine\2E250676.ani=>(Quarantine-2)
Infected with: Exploit.Win32.MS05-002.Gen

D:\Program Files\Norton AntiVirus\Quarantine\2E250676.ani=>(Quarantine-2)
Disinfection failed

D:\Program Files\Norton AntiVirus\Quarantine\2E250676.ani=>(Quarantine-2)
Deleted

D:\Program Files\Norton AntiVirus\Quarantine\2E390260.ani=>(Quarantine-2)
Infected with: Exploit.Win32.MS05-002.Gen

D:\Program Files\Norton AntiVirus\Quarantine\2E390260.ani=>(Quarantine-2)
Disinfection failed

D:\Program Files\Norton AntiVirus\Quarantine\2E390260.ani=>(Quarantine-2)
Deleted

D:\Program Files\Norton AntiVirus\Quarantine\37496B4A.dll=>(Quarantine-2)
Infected with: Trojan.Spy.VBStat.B

D:\Program Files\Norton AntiVirus\Quarantine\37496B4A.dll=>(Quarantine-2)
Deleted

D:\Program Files\Norton AntiVirus\Quarantine\379351CB.ani=>(Quarantine-2)
Infected with: Exploit.Win32.MS05-002.Gen

D:\Program Files\Norton AntiVirus\Quarantine\379351CB.ani=>(Quarantine-2)
Disinfection failed

D:\Program Files\Norton AntiVirus\Quarantine\379351CB.ani=>(Quarantine-2)
Deleted

D:\Program Files\Norton AntiVirus\Quarantine\3A21122D.dll=>(Quarantine-2)
Infected with: Trojan.Spy.VBStat.B

D:\Program Files\Norton AntiVirus\Quarantine\3A21122D.dll=>(Quarantine-2)
Deleted

D:\Program Files\Norton AntiVirus\Quarantine\402B1B5B.jpg=>(Quarantine-2)
Infected with: Exploit.Win32.MS05-002.Gen

D:\Program Files\Norton AntiVirus\Quarantine\402B1B5B.jpg=>(Quarantine-2)
Disinfection failed

D:\Program Files\Norton AntiVirus\Quarantine\402B1B5B.jpg=>(Quarantine-2)
Deleted

D:\Program Files\Norton AntiVirus\Quarantine\417101F3.jpg=>(Quarantine-2)
Infected with: Exploit.Win32.MS05-002.Gen

D:\Program Files\Norton AntiVirus\Quarantine\417101F3.jpg=>(Quarantine-2)
Disinfection failed

D:\Program Files\Norton AntiVirus\Quarantine\417101F3.jpg=>(Quarantine-2)
Deleted

D:\Program Files\Norton AntiVirus\Quarantine\61A97069.dll=>(Quarantine-2)
Infected with: Trojan.Spy.VBStat.B

D:\Program Files\Norton AntiVirus\Quarantine\61A97069.dll=>(Quarantine-2)
Deleted

D:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000028.dll=>(Quarantine-2)
Infected with: Trojan.Spy.VBStat.B

D:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000028.dll=>(Quarantine-2)
Deleted

D:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000029.dll=>(Quarantine-2)
Infected with: Trojan.Spy.VBStat.B

D:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000029.dll=>(Quarantine-2)
Deleted

D:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000030.dll=>(Quarantine-2)
Infected with: Trojan.Spy.VBStat.B

D:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000030.dll=>(Quarantine-2)
Deleted

D:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000031.dll=>(Quarantine-2)
Infected with: Trojan.Spy.VBStat.B

D:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000031.dll=>(Quarantine-2)
Deleted

D:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000032.dll=>(Quarantine-2)
Infected with: Trojan.Spy.VBStat.B

D:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000032.dll=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\07086147.htm=>(Quarantine-2)
Infected with: Trojan.Downloader.Js.Psyme.CV

D:\XProgram Files\Norton AntiVirus\Quarantine\07086147.htm=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\07086147.htm=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\07150939.htm=>(Quarantine-2)
Infected with: Trojan.Downloader.Js.Psyme.CV

D:\XProgram Files\Norton AntiVirus\Quarantine\07150939.htm=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\07150939.htm=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\097B5E95.htm=>(Quarantine-2)
Infected with: Trojan.Downloader.Js.Psyme.CV

D:\XProgram Files\Norton AntiVirus\Quarantine\097B5E95.htm=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\097B5E95.htm=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\0FA17984.dll=>(Quarantine-2)
Infected with: Trojan.Peed.LG

D:\XProgram Files\Norton AntiVirus\Quarantine\0FA17984.dll=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\0FA17984.dll=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\1CD66276.htm=>(Quarantine-2)
Infected with: Trojan.Downloader.Js.Psyme.CV

D:\XProgram Files\Norton AntiVirus\Quarantine\1CD66276.htm=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\1CD66276.htm=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\278918DB.php=>(Quarantine-2)
Infected with: Trojan.Downloader.Small.SV

D:\XProgram Files\Norton AntiVirus\Quarantine\278918DB.php=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\278918DB.php=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\313A0043.exe=>(Quarantine-2)
Infected with: Trojan.Clicker.AO

D:\XProgram Files\Norton AntiVirus\Quarantine\313A0043.exe=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\313A0043.exe=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\319517DE.exe=>(Quarantine-2)
Infected with: Trojan.Clicker.AO

D:\XProgram Files\Norton AntiVirus\Quarantine\319517DE.exe=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\319517DE.exe=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\33F65A73.htm=>(Quarantine-2)
Infected with: Trojan.Downloader.Js.Psyme.CV

D:\XProgram Files\Norton AntiVirus\Quarantine\33F65A73.htm=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\33F65A73.htm=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\3C777DE5.php=>(Quarantine-2)
Infected with: Trojan.Agent.Small.H

D:\XProgram Files\Norton AntiVirus\Quarantine\3C777DE5.php=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\3C777DE5.php=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\414D2693.dll=>(Quarantine-2)
Infected with: Trojan.Peed.GX

D:\XProgram Files\Norton AntiVirus\Quarantine\414D2693.dll=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\414D2693.dll=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\4C66565C.dll=>(Quarantine-2)
Infected with: Trojan.Peed.LG

D:\XProgram Files\Norton AntiVirus\Quarantine\4C66565C.dll=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\4C66565C.dll=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\4D30017D.exe=>(Quarantine-2)=>(ZIP Sfx o)=>DVT/PATCH.EXE
Infected with: Trojan.Horse.Downloader2.XQU

D:\XProgram Files\Norton AntiVirus\Quarantine\4D30017D.exe=>(Quarantine-2)=>(ZIP Sfx o)=>DVT/PATCH.EXE
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\4D30017D.exe=>(Quarantine-2)=>(ZIP Sfx o)=>DVT/PATCH.EXE
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\4D30017D.exe=>(Quarantine-2)=>(ZIP Sfx o)
Updated

D:\XProgram Files\Norton AntiVirus\Quarantine\4D30017D.exe=>(Quarantine-2)=>(ZIP Sfx o)=>run.exe
Infected with: GenPack:Trojan.Downloader.Tibs.W

D:\XProgram Files\Norton AntiVirus\Quarantine\4D30017D.exe=>(Quarantine-2)=>(ZIP Sfx o)=>run.exe
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\4D30017D.exe=>(Quarantine-2)=>(ZIP Sfx o)=>run.exe
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\4D30017D.exe=>(Quarantine-2)=>(ZIP Sfx o)
Updated

D:\XProgram Files\Norton AntiVirus\Quarantine\4D30017D.exe=>(Quarantine-2)
Update failed

D:\XProgram Files\Norton AntiVirus\Quarantine\4E1B507B.EXE=>(Quarantine-2)
Infected with: Trojan.Peed.JU

D:\XProgram Files\Norton AntiVirus\Quarantine\4E1B507B.EXE=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\4E1B507B.EXE=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\61A612F9.dll=>(Quarantine-2)
Infected with: Trojan.Zlob.AE

D:\XProgram Files\Norton AntiVirus\Quarantine\61A612F9.dll=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\61A612F9.dll=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm=>(Quarantine-2)=>MagicApplet.class
Infected with: Java.Trojan.Exploit.Bytverify

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm=>(Quarantine-2)=>MagicApplet.class
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm=>(Quarantine-2)=>MagicApplet.class
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm=>(Quarantine-2)
Updated

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm=>(Quarantine-2)=>ProxyClassLoader.class
Infected with: Java.Trojan.Exploit.Bytverify

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm=>(Quarantine-2)=>ProxyClassLoader.class
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm=>(Quarantine-2)=>ProxyClassLoader.class
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm=>(Quarantine-2)
Updated

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm=>(Quarantine-2)=>Installer.class
Infected with: Trojan.Downloader.Java.Openconnection.AO

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm=>(Quarantine-2)=>Installer.class
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm=>(Quarantine-2)=>Installer.class
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm=>(Quarantine-2)
Updated

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.htm
Update failed

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.php=>(Quarantine-2)
Infected with: Trojan.Downloader.Small.SV

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.php=>(Quarantine-2)
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\65E40B0F.php=>(Quarantine-2)
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\6BD90E7C.exe=>(Quarantine-2)=>(ZIP Sfx o)=>run.exe
Infected with: Trojan.Downloader.ALG

D:\XProgram Files\Norton AntiVirus\Quarantine\6BD90E7C.exe=>(Quarantine-2)=>(ZIP Sfx o)=>run.exe
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\6BD90E7C.exe=>(Quarantine-2)=>(ZIP Sfx o)=>run.exe
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\6BD90E7C.exe=>(Quarantine-2)=>(ZIP Sfx o)
Updated

D:\XProgram Files\Norton AntiVirus\Quarantine\6BD90E7C.exe=>(Quarantine-2)
Update failed

D:\XProgram Files\Norton AntiVirus\Quarantine\6D6466C9.exe=>(Quarantine-2)=>(ZIP Sfx o)=>run.exe
Infected with: Trojan.Downloader.ALG

D:\XProgram Files\Norton AntiVirus\Quarantine\6D6466C9.exe=>(Quarantine-2)=>(ZIP Sfx o)=>run.exe
Disinfection failed

D:\XProgram Files\Norton AntiVirus\Quarantine\6D6466C9.exe=>(Quarantine-2)=>(ZIP Sfx o)=>run.exe
Deleted

D:\XProgram Files\Norton AntiVirus\Quarantine\6D6466C9.exe=>(Quarantine-2)=>(ZIP Sfx o)
Updated

D:\XProgram Files\Norton AntiVirus\Quarantine\6D6466C9.exe=>(Quarantine-2)
Update failed

D:\XProgram Files\Torrent101\minime.exe
Infected with: Trojan.FatObfus.Gen

D:\XProgram Files\Torrent101\minime.exe
Disinfection failed

D:\XProgram Files\Torrent101\minime.exe
Deleted

E:\Downloads\Compressed\renwiz\keygen1.exe
Infected with: Trojan.Downloader.INService.XG

E:\Downloads\Compressed\renwiz\keygen1.exe
Disinfection failed

E:\Downloads\Compressed\renwiz\keygen1.exe
Deleted

E:\Downloads\Compressed\renwiz\RenWiz_v1.9_(WWW.CRACK-CD.COM).zip=>keygen1.exe
Infected with: Trojan.Downloader.INService.XG

E:\Downloads\Compressed\renwiz\RenWiz_v1.9_(WWW.CRACK-CD.COM).zip=>keygen1.exe
Disinfection failed

E:\Downloads\Compressed\renwiz\RenWiz_v1.9_(WWW.CRACK-CD.COM).zip=>keygen1.exe
Deleted

E:\Downloads\Compressed\renwiz\RenWiz_v1.9_(WWW.CRACK-CD.COM).zip
Updated

E:\Downloads\Compressed\VistaTheme.rar=>Setup.exe=>(NSIS o)=>zlib_nsis0061
Infected with: Trojan.Wfpdis.A

E:\Downloads\Compressed\VistaTheme.rar=>Setup.exe=>(NSIS o)=>zlib_nsis0061
Disinfection failed

E:\Downloads\Compressed\VistaTheme.rar=>Setup.exe=>(NSIS o)=>zlib_nsis0061
Deleted

E:\Downloads\Compressed\VistaTheme.rar=>Setup.exe=>(NSIS o)
Update failed

E:\IDM Data\DwnlData\A.J.Bashha\d-e0chi1_3046\d-e0chi1.exe2=>run.exe
Infected with: GenPack:Trojan.Downloader.Tibs.W

E:\IDM Data\DwnlData\A.J.Bashha\d-e0chi1_3046\d-e0chi1.exe2=>run.exe
Disinfection failed

E:\IDM Data\DwnlData\A.J.Bashha\d-e0chi1_3046\d-e0chi1.exe2=>run.exe
Deleted

E:\IDM Data\DwnlData\A.J.Bashha\d-e0chi1_3046\d-e0chi1.exe2
Updated

E:\System Volume Information\_restore{6FD72074-D90C-445C-B301-0BD51B99B5EF}\RP44\A0030038.exe=>(ZIP Sfx o)=>DVT/PATCH.EXE
Infected with: Trojan.Horse.Downloader2.XQU

E:\System Volume Information\_restore{6FD72074-D90C-445C-B301-0BD51B99B5EF}\RP44\A0030038.exe=>(ZIP Sfx o)=>DVT/PATCH.EXE
Disinfection failed

E:\System Volume Information\_restore{6FD72074-D90C-445C-B301-0BD51B99B5EF}\RP44\A0030038.exe=>(ZIP Sfx o)=>DVT/PATCH.EXE
Deleted

E:\System Volume Information\_restore{6FD72074-D90C-445C-B301-0BD51B99B5EF}\RP44\A0030038.exe=>(ZIP Sfx o)
Updated

E:\System Volume Information\_restore{6FD72074-D90C-445C-B301-0BD51B99B5EF}\RP44\A0030038.exe=>(ZIP Sfx o)=>run.exe
Infected with: GenPack:Trojan.Downloader.Tibs.W

E:\System Volume Information\_restore{6FD72074-D90C-445C-B301-0BD51B99B5EF}\RP44\A0030038.exe=>(ZIP Sfx o)=>run.exe
Disinfection failed

E:\System Volume Information\_restore{6FD72074-D90C-445C-B301-0BD51B99B5EF}\RP44\A0030038.exe=>(ZIP Sfx o)=>run.exe
Deleted

E:\System Volume Information\_restore{6FD72074-D90C-445C-B301-0BD51B99B5EF}\RP44\A0030038.exe=>(ZIP Sfx o)
Updated

E:\System Volume Information\_restore{6FD72074-D90C-445C-B301-0BD51B99B5EF}\RP44\A0030038.exe
Update failed

E:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000042.exe
Infected with: Trojan.Downloader.INService.XG

E:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000042.exe
Disinfection failed

E:\System Volume Information\_restore{9E761213-E9EB-455D-A612-E129EC222320}\RP1\A0000042.exe
Deleted

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\Director MX2004\MX 2004 crack\crack.rar=>Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Detected with: Adware.Softomate.P

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\Director MX2004\MX 2004 crack\crack.rar=>Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Disinfection failed

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\Director MX2004\MX 2004 crack\crack.rar=>Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Deleted

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\Director MX2004\MX 2004 crack\crack.rar=>Free Popup Blocker.exe=>(NSIS o)
Update failed

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\Director MX2004\MX 2004 crack\crack.rar=>installer.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Clicker.AO

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\Director MX2004\MX 2004 crack\crack.rar=>installer.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\Director MX2004\MX 2004 crack\crack.rar=>installer.exe=>(NSIS o)=>lzma_nsis0001
Deleted

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\Director MX2004\MX 2004 crack\crack.rar=>installer.exe=>(NSIS o)
Update failed

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\MagicFolder\MagicFolder crack\Extract\Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Detected with: Adware.Softomate.P

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\MagicFolder\MagicFolder crack\Extract\Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Disinfection failed

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\MagicFolder\MagicFolder crack\Extract\Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Deleted

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\MagicFolder\MagicFolder crack\Extract\Free Popup Blocker.exe=>(NSIS o)
Update failed

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\MagicFolder\MagicFolder crack\MagicFolder crack.rar=>Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Detected with: Adware.Softomate.P

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\MagicFolder\MagicFolder crack\MagicFolder crack.rar=>Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Disinfection failed

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\MagicFolder\MagicFolder crack\MagicFolder crack.rar=>Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Deleted

E:\TOSHIBA 40 GB\A.J.Bashha\My Documents-OK\Downloads\Programs\CD\MagicFolder\MagicFolder crack\MagicFolder crack.rar=>Free Popup Blocker.exe=>(NSIS o)
Update failed

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\Extract\Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Detected with: Adware.Softomate.P

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\Extract\Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Disinfection failed

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\Extract\Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Deleted

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\Extract\Free Popup Blocker.exe=>(NSIS o)
Update failed

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\Extract\patch_.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Clicker.AO

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\Extract\patch_.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\Extract\patch_.exe=>(NSIS o)=>lzma_nsis0001
Deleted

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\Extract\patch_.exe=>(NSIS o)
Update failed

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\_Hide.My.IP.v1.6.zip.rar=>patch_.exe=>(NSIS o)=>lzma_nsis0001
Infected with: Trojan.Clicker.AO

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\_Hide.My.IP.v1.6.zip.rar=>patch_.exe=>(NSIS o)=>lzma_nsis0001
Disinfection failed

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\_Hide.My.IP.v1.6.zip.rar=>patch_.exe=>(NSIS o)=>lzma_nsis0001
Deleted

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\_Hide.My.IP.v1.6.zip.rar=>patch_.exe=>(NSIS o)
Update failed

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\_Hide.My.IP.v1.6.zip.rar=>Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Detected with: Adware.Softomate.P

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\_Hide.My.IP.v1.6.zip.rar=>Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Disinfection failed

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\_Hide.My.IP.v1.6.zip.rar=>Free Popup Blocker.exe=>(NSIS o)=>lzma_solid_nsis0003
Deleted

E:\TOSHIBA 40 GB\download\RapidShare\rapidshare_premium_pack_2006_v4\Hide.My.IP.v1.6\_Hide.My.IP.v1.6 Crack\_Hide.My.IP.v1.6.zip.rar=>Free Popup Blocker.exe=>(NSIS o)
Update failed

E:\TOSHIBA 40 GB\Harvest\check-0.5.rar=>[EPIDEM.RU] rapidcheck-0.5.exe
Infected with: BehavesLike:Trojan.FirewallBypass

E:\TOSHIBA 40 GB\Harvest\check-0.5.rar=>[EPIDEM.RU] rapidcheck-0.5.exe
Disinfection failed

E:\TOSHIBA 40 GB\Harvest\check-0.5.rar=>[EPIDEM.RU] rapidcheck-0.5.exe
Deleted

E:\TOSHIBA 40 GB\Harvest\check-0.5.rar
Update failed

==============================================================

Awaiting your Guidance

Immortal King




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users