This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help removing Trojan-Clicker.Win32.Delf.cbe

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My laptop is infected with what Kaspersky IS 7 tells me is : Trojan-Clicker.Win32.Delf.cbe.It detects a .dll file in system32 folder (sayuhxrd.dll) as being infected by this virus and thow i booted from a live CD and manually deleted that file it's back in the same folder,with the same name after restart.I use win XP fully updated and i'am "protected" by KIS 7 also up to date.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:05:36 AM, on 5/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\VisualCron\VisualCronService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.ro
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.ro
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {B2ABC387-3A44-405C-8AB3-97DFE63CA1B3} - c:\windows\system32\iuptgbg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\WINDOWS\sm56hlpr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VisualCron Tray ClientV5] C:\Program Files\VisualCron\VCTray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Save Flash - res://C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (HKCU)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cron Service (CRONw) (CRON) - ActiveState - C:\Perl\bin\perl.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VisualCron - neteject.com - C:\Program Files\VisualCron\VisualCronService.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.32\bin\mysqld.exe

–
End of file - 8415 bytes
hi,

You can try this. Link and directions:

Please download Malwarebytes' Anti-Malware (MBAM) to your desktop:

http://www.malwarebytes.org/mbam.php

Double-click mbam-setup.exe and follow the prompts to install the program.

Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded, select Perform FULL SCAN, then click Scan.

When the scan is complete, click OK, then Show Results to view the results.

Be sure that everything is checked, and click **Remove Selected.**

**A restart of your computer most likely will be required to remove some items.**

When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt

post the MBAM log in your reply.
Ok,after 2 or 3 full scans i stii have 1 infected file and 2 registry key…i can't get them removed..Here's the report from Malwarebytes: Malwarebytes' Anti-Malware 1.36 Database version: 2110 Windows 5.1.2600 Service Pack 3 5/12/2009 1:12:09 AM mbam-log-2009-05-12 (01-12-09).txt Scan type: Full Scan (C:\|D:\|E:\|) Objects scanned: 218269 Time elapsed: 54 minute(s), 29 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b2abc387-3a44-405c-8ab3-97dfe63ca1b3} (Trojan.BHO.H) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{b2abc387-3a44-405c-8ab3-97dfe63ca1b3} (Trojan.BHO.H) -> Delete on reboot. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\system32\iuptgbg.dll (Trojan.BHO.H) -> Delete on reboot. (Thow it trys to delete it after reboot nothing happens)
hi,

ok we will get another download to use. Its called combofix. There is a guide to read first. Read through the guide, download combofix, disable your AV as explained in the guide, double click the icon on your desktop and follow the prompts. post the combofix log in your reply.

the guide:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
This is what i got from ComboFix:

ComboFix 09-05-07.06 - Duxx 05/12/2009 5:20.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1555 [GMT 3:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
.

((((((((((((((((((((((((( Files Created from 2009-04-12 to 2009-05-12 )))))))))))))))))))))))))))))))
.

2009-05-11 22:12 . 2009-05-11 22:12 61440 —-a-w c:\windows\system32\drivers\lvnffr.sys
2009-05-11 20:09 . 2009-05-11 20:09 ——– d—–w c:\documents and settings\Duxx\Application Data\Malwarebytes
2009-05-11 20:09 . 2009-04-06 12:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-11 20:09 . 2009-04-06 12:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-11 20:09 . 2009-05-11 20:09 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-11 20:09 . 2009-05-11 20:09 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-07 22:27 . 2009-05-07 22:27 ——– d—–w c:\documents and settings\Duxx\Application Data\ndfcughx
2009-05-07 22:27 . 2009-05-07 22:27 ——– d—–w c:\documents and settings\Duxx\Local Settings\Application Data\ndfcughx
2009-05-07 21:44 . 2009-05-07 21:44 ——– d—–w c:\documents and settings\NetworkService\Application Data\ndfcughx
2009-05-07 21:44 . 2009-05-07 21:44 ——– d—–w c:\documents and settings\NetworkService\Local Settings\Application Data\ndfcughx
2009-05-07 01:10 . 2009-05-07 01:10 ——– d—–w c:\windows\ie8updates
2009-05-07 01:10 . 2009-02-28 04:55 105984 -c—-w c:\windows\system32\dllcache\iecompat.dll
2009-05-07 01:05 . 2009-03-10 19:18 453512 —-a-w c:\windows\system32\KB905474\wgasetup.exe
2009-05-07 01:05 . 2009-05-07 01:17 ——– d—–w c:\windows\system32\KB905474
2009-05-07 00:56 . 2008-06-13 11:05 272128 -c—-w c:\windows\system32\dllcache\bthport.sys
2009-05-07 00:56 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-05-07 00:56 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-05-07 00:56 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-05-07 00:56 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-05-07 00:56 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-05-07 00:56 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-05-07 00:56 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-05-07 00:56 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-05-07 00:56 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-05-07 00:56 . 2009-02-06 11:06 2145280 -c—-w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-05-07 00:56 . 2009-02-06 11:08 2189056 -c—-w c:\windows\system32\dllcache\ntoskrnl.exe
2009-05-07 00:55 . 2009-02-06 10:32 2023936 -c—-w c:\windows\system32\dllcache\ntkrpamp.exe
2009-05-07 00:55 . 2008-05-08 14:02 203136 -c—-w c:\windows\system32\dllcache\rmcast.sys
2009-05-07 00:55 . 2008-10-24 11:21 455296 -c—-w c:\windows\system32\dllcache\mrxsmb.sys
2009-05-07 00:55 . 2008-12-11 10:57 333952 -c—-w c:\windows\system32\dllcache\srv.sys
2009-05-07 00:54 . 2008-05-01 14:33 331776 -c—-w c:\windows\system32\dllcache\msadce.dll
2009-05-07 00:54 . 2008-04-11 19:04 691712 -c—-w c:\windows\system32\dllcache\inetcomm.dll
2009-05-07 00:53 . 2008-10-15 16:34 337408 -c—-w c:\windows\system32\dllcache\netapi32.dll
2009-05-07 00:53 . 2008-09-04 17:15 1106944 -c—-w c:\windows\system32\dllcache\msxml3.dll
2009-05-07 00:53 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-05-07 00:53 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-05-07 00:03 . 2001-08-23 12:00 403 -c—-w c:\windows\system32\dllcache\npdrmv2.zip
2009-05-07 00:03 . 2001-08-23 12:00 22060 -c—-w c:\windows\system32\dllcache\npds.zip
2009-05-07 00:03 . 2008-04-13 20:57 79872 -c—-w c:\windows\system32\dllcache\msxml6r.dll
2009-05-07 00:03 . 2008-09-10 01:14 1307648 -c—-w c:\windows\system32\dllcache\msxml6.dll
2009-05-07 00:02 . 2008-04-14 03:42 294912 -c—-w c:\windows\system32\dllcache\dlimport.exe
2009-05-06 23:46 . 2009-05-06 23:46 ——– d-sh–w c:\documents and settings\Duxx\UserData
2009-05-06 21:16 . 2009-05-06 21:16 204800 —-a-w c:\windows\system32\inst_e82.exe
2009-05-06 20:55 . 2001-08-17 19:36 12288 -c–a-w c:\windows\system32\dllcache\EXCH_smtpctrs.dll
2009-05-06 20:54 . 2006-02-28 12:00 311359 -c–a-w c:\windows\system32\dllcache\imepadsv.exe
2009-05-06 20:53 . 2001-08-17 19:36 5632 -c–a-w c:\windows\system32\dllcache\EXCH_adsiisex.dll
2009-05-06 20:53 . 2006-02-28 12:00 49664 -c–a-w c:\windows\system32\dllcache\adrot.dll
2009-05-06 20:53 . 2006-02-28 12:00 6144 -c–a-w c:\windows\system32\dllcache\admxprox.dll
2009-05-06 20:53 . 2006-02-28 12:00 7168 -c–a-w c:\windows\system32\dllcache\wamregps.dll
2009-05-06 20:53 . 2006-02-28 12:00 19968 -c–a-w c:\windows\system32\dllcache\inetsloc.dll
2009-05-06 20:53 . 2006-02-28 12:00 7680 -c–a-w c:\windows\system32\dllcache\inetmgr.exe
2009-05-06 20:53 . 2006-02-28 12:00 169984 -c–a-w c:\windows\system32\dllcache\iisui.dll
2009-05-06 20:53 . 2006-02-28 12:00 5632 -c–a-w c:\windows\system32\dllcache\iisrstap.dll
2009-05-06 20:53 . 2006-02-28 12:00 14336 -c–a-w c:\windows\system32\dllcache\iisreset.exe
2009-05-06 20:53 . 2006-02-28 12:00 6144 -c–a-w c:\windows\system32\dllcache\ftpsapi2.dll
2009-05-06 20:53 . 2009-05-07 01:10 ——– d–h–w c:\windows\$hf_mig$
2009-05-06 20:32 . 2009-05-06 21:00 ——– d—–w c:\windows\NV1696544.TMP
2009-05-06 20:24 . 2006-02-28 12:00 13312 -c–a-w c:\windows\system32\dllcache\irclass.dll
2009-05-06 20:24 . 2006-02-28 12:00 13312 —-a-w c:\windows\system32\irclass.dll
2009-05-06 20:24 . 2006-02-28 12:00 24661 -c–a-w c:\windows\system32\dllcache\spxcoins.dll
2009-05-06 20:24 . 2006-02-28 12:00 24661 —-a-w c:\windows\system32\spxcoins.dll
2009-04-28 21:13 . 2006-02-28 12:00 16384 -c–a-w c:\windows\system32\dllcache\isignup.exe
2009-04-28 20:34 . 2009-04-28 21:24 ——– d—–w c:\windows\NV224704.TMP
2009-04-28 02:17 . 2009-04-28 02:17 ——– d–h–w c:\windows\PIF
2009-04-24 22:24 . 2009-04-24 22:25 ——– d—–w c:\program files\NCH Swift Sound
2009-04-23 00:04 . 2009-04-23 00:04 ——– d—–w c:\program files\Hamachi
2009-04-16 02:14 . 2009-03-07 11:25 ——– d—–w C:\xampp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-12 02:22 . 2009-02-09 18:30 958752 –sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-12 02:22 . 2009-02-09 18:30 13345056 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-11 22:12 . 2009-02-09 18:30 184988 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-11 22:12 . 2009-02-09 18:30 93728 –sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-07 23:11 . 2001-08-23 12:00 103424 —-a-w c:\windows\system32\gesvltl.dll
2009-05-06 20:52 . 2001-08-23 12:00 67 –sha-w c:\windows\Fonts\desktop.ini
2009-05-06 20:50 . 2009-02-08 20:56 22720 —-a-w c:\windows\system32\emptyregdb.dat
2009-04-28 21:40 . 2009-02-08 21:05 101640 —-a-w c:\documents and settings\Duxx\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-23 00:04 . 2009-02-09 18:53 25280 —-a-w c:\windows\system32\drivers\hamachi.sys
2009-04-03 06:06 . 2009-04-03 06:06 ——– d—–w c:\program files\VisualCron
2009-04-03 01:25 . 2009-04-03 06:24 89 —-a-w C:\run_mail.bat
2009-04-02 03:30 . 2009-04-02 03:30 ——– d—–w c:\program files\AGEIA Technologies
2009-04-02 03:29 . 2009-04-02 03:29 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-04-02 02:57 . 2009-02-09 17:58 ——– d–h–w c:\program files\InstallShield Installation Information
2009-03-29 08:59 . 2009-03-29 08:59 202 —-a-w c:\windows\PowerReg.dat
2009-03-29 08:59 . 2009-03-29 08:59 ——– d—–w c:\program files\MathSoft
2009-03-26 23:50 . 2009-02-09 22:01 ——– d—–w c:\program files\uTorrent
2009-03-26 05:39 . 2009-03-26 05:39 ——– d—–w c:\program files\MegaDev
2009-03-25 22:07 . 2009-03-25 22:02 ——– d—–w c:\program files\Common Files\Autodesk Shared
2009-03-25 22:07 . 2009-03-25 22:02 ——– d—–w c:\program files\AutoCAD 2010
2009-03-25 20:52 . 2009-03-03 21:57 ——– d—–w c:\program files\PLAYXPERT
2009-03-25 07:29 . 2009-03-25 07:29 ——– d—–w c:\program files\DAEMON Tools
2009-03-24 22:35 . 2009-02-09 18:54 ——– d—–w c:\program files\oDC
2009-03-24 06:51 . 2009-03-24 06:51 27136 —-a-w c:\windows\system32\drivers\nchssvad.sys
2009-03-24 06:50 . 2009-03-24 06:50 ——– d—–w c:\program files\NCH Software
2009-03-22 00:36 . 2009-03-22 00:36 43160 —-a-w c:\windows\system32\AcSignIcon.dll
2009-03-22 00:36 . 2009-03-22 00:36 429720 —-a-w c:\windows\system32\AcSignOpt.exe
2009-03-22 00:36 . 2009-03-22 00:36 29848 —-a-w c:\windows\system32\AcSignExt.dll
2009-03-22 00:31 . 2009-03-22 00:31 14488 —-a-w c:\windows\system32\AcSignExtRes.dll
2009-03-20 17:38 . 2009-03-20 17:38 ——– d—–w c:\program files\Visio
2009-03-20 17:38 . 2009-03-20 17:38 ——– d—–w c:\program files\Rockwell Software
2009-03-20 05:09 . 2009-03-20 05:09 ——– d—–w c:\program files\UnH Solutions
2009-03-18 23:27 . 2009-03-18 23:26 ——– d—–w c:\program files\WIDI 3.3 Pro
2009-03-17 21:27 . 2009-03-17 21:27 ——– d—–w c:\program files\EatCam
2009-03-16 12:18 . 2009-03-25 06:40 69448 —-a-w c:\windows\system32\XAPOFX1_3.dll
2009-03-16 12:18 . 2009-03-25 06:40 517448 —-a-w c:\windows\system32\XAudio2_4.dll
2009-03-16 12:18 . 2009-03-25 06:40 235352 —-a-w c:\windows\system32\xactengine3_4.dll
2009-03-16 12:18 . 2009-03-25 06:40 22360 —-a-w c:\windows\system32\X3DAudio1_6.dll
2009-03-09 13:27 . 2009-03-25 06:40 453456 —-a-w c:\windows\system32\d3dx10_41.dll
2009-03-09 13:27 . 2009-03-25 06:40 1846632 —-a-w c:\windows\system32\D3DCompiler_41.dll
2009-03-09 13:27 . 2009-03-25 06:40 4178264 —-a-w c:\windows\system32\D3DX9_41.dll
2009-03-08 01:34 . 2006-02-28 12:00 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2006-02-28 12:00 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2006-02-28 12:00 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2006-02-28 12:00 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2006-02-28 12:00 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2006-02-28 12:00 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2006-02-28 12:00 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2006-02-28 12:00 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2006-02-28 12:00 45568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2006-02-28 12:00 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2006-02-28 12:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-05 04:48 . 2009-03-05 04:48 233472 —-a-w c:\windows\system32\REX Shared Library.dll
2009-03-05 04:48 . 2009-03-05 04:48 368640 —-a-w c:\windows\system32\ReWire.dll
2009-03-02 23:02 . 2009-02-25 00:05 56532 —ha-w c:\windows\system32\mlfcache.dat
2009-02-19 06:55 . 2009-02-19 06:55 50688 —-a-w c:\windows\system32\wbhelp2.dll
2009-02-11 04:25 . 2009-02-11 04:25 22328 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-02-11 04:25 . 2009-02-11 04:25 22328 —-a-w c:\documents and settings\Duxx\Application Data\PnkBstrK.sys
2009-02-11 04:24 . 2009-02-11 04:24 107832 —-a-w c:\windows\system32\PnkBstrB.exe
2009-02-11 04:24 . 2009-02-11 04:24 66872 —-a-w c:\windows\system32\PnkBstrA.exe
2009-02-11 04:24 . 2009-02-11 04:24 2250024 —-a-w c:\windows\system32\pbsvc.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-05-07_23.15.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-08 21:03 . 2009-05-11 19:59 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-08 21:03 . 2009-05-07 00:49 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-08 21:03 . 2009-05-11 19:59 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-08 21:03 . 2009-05-07 00:49 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-08 21:03 . 2009-05-11 19:59 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-08 21:03 . 2009-05-07 00:49 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B2ABC387-3A44-405C-8AB3-97DFE63CA1B3}]
2001-08-23 12:00 103424 —-a-w c:\windows\system32\iuptgbg.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-04 4363504]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-02-09 270128]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-08-22 167368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-03-29 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-03-29 86016]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-12 815104]
"SMSERIAL"="c:\windows\sm56hlpr.exe" [2006-03-21 544768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"VisualCron Tray ClientV5"="c:\program files\VisualCron\VCTray.exe" [2009-04-01 532008]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-03-29 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-04-28 16861696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Duxx\Start Menu\Programs\Startup\
PowerReg SchedulerV2.exe [2009-3-29 256000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-5-22 2756608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideFastUserSwitching"= 0 (0x0)
"HideShutdownScripts"= 0 (0x0)
"DisableCAD"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLogonScripts"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoVisualStyleChoice"= 0 (0x0)
"NoColorChoice"= 0 (0x0)
"NoSizeChoice"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)
"HideSCANetwork"= 0 (0x0)
"HideSCAPower"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoExpandedNewMenu"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoThemesTab"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"DisallowRun"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"HideClock"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)
"HideSCANetwork"= 0 (0x0)
"HideSCAPower"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoExpandedNewMenu"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave4"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\UltraVNC\\vncviewer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Jocuri\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"d:\\Jocuri\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"d:\\Jocuri\\FarCry2\\Far Cry 2\\bin\\FarCry2.exe"=
"d:\\Jocuri\\FarCry2\\Far Cry 2\\bin\\FC2Launcher.exe"=
"d:\\Jocuri\\FarCry2\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\system32\\sopocx.ocx"=
"%windir%\\system32\\tvu49.ocx"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Electronic Arts\\Burnout™ Paradise The Ultimate Box\\BurnoutLauncher.exe"=
"c:\\Program Files\\Electronic Arts\\Burnout™ Paradise The Ultimate Box\\BurnoutConfigTool.exe"=
"c:\\Program Files\\Electronic Arts\\Burnout™ Paradise The Ultimate Box\\BurnoutParadise.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R0 kitzzjmg;kitzzjmg;c:\windows\system32\drivers\kitzzjmg.sys [2/28/2006 3:00 PM 23424]
R2 VisualCron;VisualCron;c:\program files\VisualCron\VisualCronService.exe [4/1/2009 10:20 PM 1793280]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [2/9/2009 9:05 PM 36864]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [4/4/2007 3:58 PM 24344]
S2 CRON;Cron Service (CRONw);c:\perl\bin\perl.exe "c:\cronw\cronService.pl" –crontab="c:\cronw\crontab.txt" –> c:\perl\bin\perl.exe c:\cronw\cronService.pl [?]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys –> c:\windows\system32\DRIVERS\ManyCam.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6918f3ec-f7c5-11dd-a370-001bfcf02992}]
\Shell\AutoRun\command - G:\BSAutoRun.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-05-11 c:\windows\Tasks\User_Feed_Synchronization-{08A74F14-9E6A-48CB-BCB4-1AC2CF7A261F}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]

2009-05-11 c:\windows\Tasks\x.job
- c:\documents and settings\Administrator\Desktop\x.bat [2009-05-07 02:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.ro
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Save Flash - c:\program files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
FF - ProfilePath - c:\documents and settings\Duxx\Application Data\Mozilla\Firefox\Profiles\yacxpl6m.default\
.
.
——- File Associations ——-
.
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-12 05:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(2008)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\windows\system32\klogon.dll

- - - - - - - > 'lsass.exe'(180)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll

- - - - - - - > 'explorer.exe'(1068)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-05-12 5:24
ComboFix-quarantined-files.txt 2009-05-12 02:24
ComboFix2.txt 2009-05-07 23:17

Pre-Run: 8,542,969,856 bytes free
Post-Run: 8,526,422,016 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
390 — E O F — 2009-05-07 01:21
When you scan with MBAM and you got this;

Files Infected:
c:\WINDOWS\system32\iuptgbg.dll (Trojan.BHO.H) -> Delete on reboot.

(Thow it trys to delete it after reboot nothing happens)


did MBAM prompt you to reboot your computer to finish the removal process? You might try running MBAM in safe mode also. first check it for updates then to reach safe mode you would tap the f8 key during a computer restart and chose the first option from the list; safe mode. once at the safe mode desktop, scan with MBAM and save the log.


This that you have installed:
VisualCron (a task scheduler)

Is this item below related to a task using VisualCron?
c:\documents and settings\Administrator\Desktop\x.bat
—————————————————————————————-

We will try this first;
First disable any AV or antimalware so it wont interfere with hjt.

next:

start HJT, click the "Scan" button. check the items below, close any open windows, then click "Fixed checked"

O2 - BHO: (no name) - {B2ABC387-3A44-405C-8AB3-97DFE63CA1B3} - c:\windows\system32\iuptgbg.dll

reboot, rescan and post another hjt log please.
What i ment by "after reboot nothing happens" was…nothing happens with the infected file after MBAM restarts my PC.


The x.bat from my desktop is a command that calls a php script used to send by e-mail data from xamp.x.bat is long gone anyway since xamp was installed on my pc for testing porpuse only.

Now, this is the MBAM log,after running in safe mode:

Malwarebytes' Anti-Malware 1.36
Database version: 2110
Windows 5.1.2600 Service Pack 3

5/13/2009 6:21:37 AM
mbam-log-2009-05-13 (06-21-37).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 233825
Time elapsed: 1 hour(s), 7 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b2abc387-3a44-405c-8ab3-97dfe63ca1b3} (Trojan.BHO.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{b2abc387-3a44-405c-8ab3-97dfe63ca1b3} (Trojan.BHO.H) -> Delete on reboot.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\iuptgbg.dll (Trojan.BHO.H) -> Delete on reboot.




Now,HJT found that file and i did clicked "Fix checked" but i don't think it "hurt" that infected file very much:



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:39:45 AM, on 5/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\VisualCron\VisualCronService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.ro
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.ro
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {B2ABC387-3A44-405C-8AB3-97DFE63CA1B3} - c:\windows\system32\iuptgbg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\WINDOWS\sm56hlpr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VisualCron Tray ClientV5] C:\Program Files\VisualCron\VCTray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Save Flash - res://C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (HKCU)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cron Service (CRONw) (CRON) - ActiveState - C:\Perl\bin\perl.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VisualCron - neteject.com - C:\Program Files\VisualCron\VisualCronService.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.32\bin\mysqld.exe

–
End of file - 7844 bytes
hi,

We will use combofix to remove some files:

Click Start, then Run and type Notepad and click OK.
Copy/paste the text in the code box below into notepad:

File::
c:\windows\system32\drivers\kitzzjmg.sys
c:\windows\system32\drivers\lvnffr.sys
c:\WINDOWS\system32\iuptgbg.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B2ABC387-3A44-405C-8AB3-97DFE63CA1B3}]

Driver::
kitzzjmg
lvnffr

Name the Notepad file CFScript.txt and Save it to your desktop.
now locate the file you just saved and the combofix icon, both on your desktop
using your mouse drag the CFScript right on top of the combofix icon and release, combofix will run and produce a new log
please post the new combofix log and a new hjt log.

if all goes well MBAM should run ok now.
Hey SL,

This is what combofix returned after auto-restarting my pc (hope that is normal) and scanning:

ComboFix 09-05-13.02 - Duxx 05/14/2009 5:21.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1540 [GMT 3:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Duxx\Desktop\CFScript.txt
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

FILE ::
c:\windows\system32\drivers\kitzzjmg.sys
c:\windows\system32\drivers\lvnffr.sys
c:\windows\system32\iuptgbg.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\kitzzjmg.sys
c:\windows\system32\drivers\lvnffr.sys
c:\windows\system32\iuptgbg.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_KITZZJMG
——-\Service_kitzzjmg


((((((((((((((((((((((((( Files Created from 2009-04-14 to 2009-05-14 )))))))))))))))))))))))))))))))
.

2009-05-11 20:09 . 2009-05-11 20:09 ——– d—–w c:\documents and settings\Duxx\Application Data\Malwarebytes
2009-05-11 20:09 . 2009-04-06 12:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-11 20:09 . 2009-04-06 12:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-11 20:09 . 2009-05-11 20:09 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-11 20:09 . 2009-05-11 20:09 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-07 22:27 . 2009-05-07 22:27 ——– d—–w c:\documents and settings\Duxx\Application Data\ndfcughx
2009-05-07 22:27 . 2009-05-07 22:27 ——– d—–w c:\documents and settings\Duxx\Local Settings\Application Data\ndfcughx
2009-05-07 21:44 . 2009-05-07 21:44 ——– d—–w c:\documents and settings\NetworkService\Application Data\ndfcughx
2009-05-07 21:44 . 2009-05-07 21:44 ——– d—–w c:\documents and settings\NetworkService\Local Settings\Application Data\ndfcughx
2009-05-07 01:10 . 2009-05-07 01:10 ——– d—–w c:\windows\ie8updates
2009-05-07 01:10 . 2009-02-28 04:55 105984 -c—-w c:\windows\system32\dllcache\iecompat.dll
2009-05-07 01:05 . 2009-03-10 19:18 453512 —-a-w c:\windows\system32\KB905474\wgasetup.exe
2009-05-07 01:05 . 2009-05-07 01:17 ——– d—–w c:\windows\system32\KB905474
2009-05-07 00:56 . 2008-06-13 11:05 272128 -c—-w c:\windows\system32\dllcache\bthport.sys
2009-05-07 00:56 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-05-07 00:56 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-05-07 00:56 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-05-07 00:56 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-05-07 00:56 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-05-07 00:56 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-05-07 00:56 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-05-07 00:56 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-05-07 00:56 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-05-07 00:56 . 2009-02-06 11:06 2145280 -c—-w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-05-07 00:56 . 2009-02-06 11:08 2189056 -c—-w c:\windows\system32\dllcache\ntoskrnl.exe
2009-05-07 00:55 . 2009-02-06 10:32 2023936 -c—-w c:\windows\system32\dllcache\ntkrpamp.exe
2009-05-07 00:55 . 2008-05-08 14:02 203136 -c—-w c:\windows\system32\dllcache\rmcast.sys
2009-05-07 00:55 . 2008-10-24 11:21 455296 -c—-w c:\windows\system32\dllcache\mrxsmb.sys
2009-05-07 00:55 . 2008-12-11 10:57 333952 -c—-w c:\windows\system32\dllcache\srv.sys
2009-05-07 00:54 . 2008-05-01 14:33 331776 -c—-w c:\windows\system32\dllcache\msadce.dll
2009-05-07 00:54 . 2008-04-11 19:04 691712 -c—-w c:\windows\system32\dllcache\inetcomm.dll
2009-05-07 00:53 . 2008-10-15 16:34 337408 -c—-w c:\windows\system32\dllcache\netapi32.dll
2009-05-07 00:53 . 2008-09-04 17:15 1106944 -c—-w c:\windows\system32\dllcache\msxml3.dll
2009-05-07 00:53 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-05-07 00:53 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-05-07 00:03 . 2001-08-23 12:00 403 -c—-w c:\windows\system32\dllcache\npdrmv2.zip
2009-05-07 00:03 . 2001-08-23 12:00 22060 -c—-w c:\windows\system32\dllcache\npds.zip
2009-05-07 00:03 . 2008-04-13 20:57 79872 -c—-w c:\windows\system32\dllcache\msxml6r.dll
2009-05-07 00:03 . 2008-09-10 01:14 1307648 -c—-w c:\windows\system32\dllcache\msxml6.dll
2009-05-07 00:02 . 2008-04-14 03:42 294912 -c—-w c:\windows\system32\dllcache\dlimport.exe
2009-05-06 23:46 . 2009-05-06 23:46 ——– d-sh–w c:\documents and settings\Duxx\UserData
2009-05-06 21:16 . 2009-05-06 21:16 204800 —-a-w c:\windows\system32\inst_e82.exe
2009-05-06 20:55 . 2001-08-17 19:36 12288 -c–a-w c:\windows\system32\dllcache\EXCH_smtpctrs.dll
2009-05-06 20:54 . 2006-02-28 12:00 311359 -c–a-w c:\windows\system32\dllcache\imepadsv.exe
2009-05-06 20:53 . 2001-08-17 19:36 5632 -c–a-w c:\windows\system32\dllcache\EXCH_adsiisex.dll
2009-05-06 20:53 . 2006-02-28 12:00 49664 -c–a-w c:\windows\system32\dllcache\adrot.dll
2009-05-06 20:53 . 2006-02-28 12:00 6144 -c–a-w c:\windows\system32\dllcache\admxprox.dll
2009-05-06 20:53 . 2006-02-28 12:00 7168 -c–a-w c:\windows\system32\dllcache\wamregps.dll
2009-05-06 20:53 . 2006-02-28 12:00 19968 -c–a-w c:\windows\system32\dllcache\inetsloc.dll
2009-05-06 20:53 . 2006-02-28 12:00 7680 -c–a-w c:\windows\system32\dllcache\inetmgr.exe
2009-05-06 20:53 . 2006-02-28 12:00 169984 -c–a-w c:\windows\system32\dllcache\iisui.dll
2009-05-06 20:53 . 2006-02-28 12:00 5632 -c–a-w c:\windows\system32\dllcache\iisrstap.dll
2009-05-06 20:53 . 2006-02-28 12:00 14336 -c–a-w c:\windows\system32\dllcache\iisreset.exe
2009-05-06 20:53 . 2006-02-28 12:00 6144 -c–a-w c:\windows\system32\dllcache\ftpsapi2.dll
2009-05-06 20:53 . 2009-05-07 01:10 ——– d–h–w c:\windows\$hf_mig$
2009-05-06 20:32 . 2009-05-06 21:00 ——– d—–w c:\windows\NV1696544.TMP
2009-05-06 20:24 . 2006-02-28 12:00 13312 -c–a-w c:\windows\system32\dllcache\irclass.dll
2009-05-06 20:24 . 2006-02-28 12:00 13312 —-a-w c:\windows\system32\irclass.dll
2009-05-06 20:24 . 2006-02-28 12:00 24661 -c–a-w c:\windows\system32\dllcache\spxcoins.dll
2009-05-06 20:24 . 2006-02-28 12:00 24661 —-a-w c:\windows\system32\spxcoins.dll
2009-04-28 21:13 . 2006-02-28 12:00 16384 -c–a-w c:\windows\system32\dllcache\isignup.exe
2009-04-28 20:34 . 2009-04-28 21:24 ——– d—–w c:\windows\NV224704.TMP
2009-04-28 02:17 . 2009-04-28 02:17 ——– d–h–w c:\windows\PIF
2009-04-24 22:24 . 2009-04-24 22:25 ——– d—–w c:\program files\NCH Swift Sound
2009-04-23 00:04 . 2009-04-23 00:04 ——– d—–w c:\program files\Hamachi
2009-04-16 02:14 . 2009-03-07 11:25 ——– d—–w C:\xampp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-14 02:26 . 2009-02-09 18:30 13581600 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-14 02:26 . 2009-02-09 18:30 970784 –sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-14 02:24 . 2009-02-09 18:30 189068 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-14 02:24 . 2009-02-09 18:30 95120 –sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-14 02:21 . 2006-02-28 12:00 23424 —-a-w c:\windows\system32\drivers\mumisgkh.sys
2009-05-07 23:11 . 2001-08-23 12:00 103424 —-a-w c:\windows\system32\gesvltl.dll
2009-05-06 20:52 . 2001-08-23 12:00 67 –sha-w c:\windows\Fonts\desktop.ini
2009-05-06 20:50 . 2009-02-08 20:56 22720 —-a-w c:\windows\system32\emptyregdb.dat
2009-04-28 21:40 . 2009-02-08 21:05 101640 —-a-w c:\documents and settings\Duxx\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-23 00:04 . 2009-02-09 18:53 25280 —-a-w c:\windows\system32\drivers\hamachi.sys
2009-04-03 06:06 . 2009-04-03 06:06 ——– d—–w c:\program files\VisualCron
2009-04-03 01:25 . 2009-04-03 06:24 89 —-a-w C:\run_mail.bat
2009-04-02 03:30 . 2009-04-02 03:30 ——– d—–w c:\program files\AGEIA Technologies
2009-04-02 03:29 . 2009-04-02 03:29 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-04-02 02:57 . 2009-02-09 17:58 ——– d–h–w c:\program files\InstallShield Installation Information
2009-03-29 08:59 . 2009-03-29 08:59 202 —-a-w c:\windows\PowerReg.dat
2009-03-29 08:59 . 2009-03-29 08:59 ——– d—–w c:\program files\MathSoft
2009-03-26 23:50 . 2009-02-09 22:01 ——– d—–w c:\program files\uTorrent
2009-03-26 05:39 . 2009-03-26 05:39 ——– d—–w c:\program files\MegaDev
2009-03-25 22:07 . 2009-03-25 22:02 ——– d—–w c:\program files\Common Files\Autodesk Shared
2009-03-25 22:07 . 2009-03-25 22:02 ——– d—–w c:\program files\AutoCAD 2010
2009-03-25 20:52 . 2009-03-03 21:57 ——– d—–w c:\program files\PLAYXPERT
2009-03-25 07:29 . 2009-03-25 07:29 ——– d—–w c:\program files\DAEMON Tools
2009-03-24 22:35 . 2009-02-09 18:54 ——– d—–w c:\program files\oDC
2009-03-24 06:51 . 2009-03-24 06:51 27136 —-a-w c:\windows\system32\drivers\nchssvad.sys
2009-03-24 06:50 . 2009-03-24 06:50 ——– d—–w c:\program files\NCH Software
2009-03-22 00:36 . 2009-03-22 00:36 43160 —-a-w c:\windows\system32\AcSignIcon.dll
2009-03-22 00:36 . 2009-03-22 00:36 429720 —-a-w c:\windows\system32\AcSignOpt.exe
2009-03-22 00:36 . 2009-03-22 00:36 29848 —-a-w c:\windows\system32\AcSignExt.dll
2009-03-22 00:31 . 2009-03-22 00:31 14488 —-a-w c:\windows\system32\AcSignExtRes.dll
2009-03-20 17:38 . 2009-03-20 17:38 ——– d—–w c:\program files\Visio
2009-03-20 17:38 . 2009-03-20 17:38 ——– d—–w c:\program files\Rockwell Software
2009-03-20 05:09 . 2009-03-20 05:09 ——– d—–w c:\program files\UnH Solutions
2009-03-18 23:27 . 2009-03-18 23:26 ——– d—–w c:\program files\WIDI 3.3 Pro
2009-03-17 21:27 . 2009-03-17 21:27 ——– d—–w c:\program files\EatCam
2009-03-16 12:18 . 2009-03-25 06:40 69448 —-a-w c:\windows\system32\XAPOFX1_3.dll
2009-03-16 12:18 . 2009-03-25 06:40 517448 —-a-w c:\windows\system32\XAudio2_4.dll
2009-03-16 12:18 . 2009-03-25 06:40 235352 —-a-w c:\windows\system32\xactengine3_4.dll
2009-03-16 12:18 . 2009-03-25 06:40 22360 —-a-w c:\windows\system32\X3DAudio1_6.dll
2009-03-09 13:27 . 2009-03-25 06:40 453456 —-a-w c:\windows\system32\d3dx10_41.dll
2009-03-09 13:27 . 2009-03-25 06:40 1846632 —-a-w c:\windows\system32\D3DCompiler_41.dll
2009-03-09 13:27 . 2009-03-25 06:40 4178264 —-a-w c:\windows\system32\D3DX9_41.dll
2009-03-08 01:34 . 2006-02-28 12:00 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2006-02-28 12:00 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2006-02-28 12:00 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2006-02-28 12:00 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2006-02-28 12:00 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2006-02-28 12:00 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2006-02-28 12:00 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2006-02-28 12:00 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2006-02-28 12:00 45568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2006-02-28 12:00 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2006-02-28 12:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-05 04:48 . 2009-03-05 04:48 233472 —-a-w c:\windows\system32\REX Shared Library.dll
2009-03-05 04:48 . 2009-03-05 04:48 368640 —-a-w c:\windows\system32\ReWire.dll
2009-03-02 23:02 . 2009-02-25 00:05 56532 —ha-w c:\windows\system32\mlfcache.dat
2009-02-19 06:55 . 2009-02-19 06:55 50688 —-a-w c:\windows\system32\wbhelp2.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-07_23.15.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-14 02:26 . 2009-05-14 02:26 16384 c:\windows\temp\Perflib_Perfdata_ebc.dat
+ 2009-02-08 21:03 . 2009-05-11 19:59 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-08 21:03 . 2009-05-07 00:49 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-08 21:03 . 2009-05-11 19:59 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-08 21:03 . 2009-05-07 00:49 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-08 21:03 . 2009-05-11 19:59 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-08 21:03 . 2009-05-07 00:49 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-05-07 01:05 . 2009-05-07 07:16 24699336 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-04 4363504]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-02-09 270128]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-08-22 167368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-03-29 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-03-29 86016]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-12 815104]
"SMSERIAL"="c:\windows\sm56hlpr.exe" [2006-03-21 544768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"VisualCron Tray ClientV5"="c:\program files\VisualCron\VCTray.exe" [2009-04-01 532008]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-03-29 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-04-28 16861696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Duxx\Start Menu\Programs\Startup\
PowerReg SchedulerV2.exe [2009-3-29 256000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-5-22 2756608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideFastUserSwitching"= 0 (0x0)
"HideShutdownScripts"= 0 (0x0)
"DisableCAD"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLogonScripts"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoVisualStyleChoice"= 0 (0x0)
"NoColorChoice"= 0 (0x0)
"NoSizeChoice"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)
"HideSCANetwork"= 0 (0x0)
"HideSCAPower"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoExpandedNewMenu"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoThemesTab"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"DisallowRun"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"HideClock"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)
"HideSCANetwork"= 0 (0x0)
"HideSCAPower"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoExpandedNewMenu"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave4"= serwvdrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\UltraVNC\\vncviewer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Jocuri\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"d:\\Jocuri\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"d:\\Jocuri\\FarCry2\\Far Cry 2\\bin\\FarCry2.exe"=
"d:\\Jocuri\\FarCry2\\Far Cry 2\\bin\\FC2Launcher.exe"=
"d:\\Jocuri\\FarCry2\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\system32\\sopocx.ocx"=
"%windir%\\system32\\tvu49.ocx"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Electronic Arts\\Burnout™ Paradise The Ultimate Box\\BurnoutLauncher.exe"=
"c:\\Program Files\\Electronic Arts\\Burnout™ Paradise The Ultimate Box\\BurnoutConfigTool.exe"=
"c:\\Program Files\\Electronic Arts\\Burnout™ Paradise The Ultimate Box\\BurnoutParadise.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R2 VisualCron;VisualCron;c:\program files\VisualCron\VisualCronService.exe [4/1/2009 10:20 PM 1793280]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\l151x86.sys [2/9/2009 9:05 PM 36864]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [4/4/2007 3:58 PM 24344]
S2 CRON;Cron Service (CRONw);c:\perl\bin\perl.exe "c:\cronw\cronService.pl" –crontab="c:\cronw\crontab.txt" –> c:\perl\bin\perl.exe c:\cronw\cronService.pl [?]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys –> c:\windows\system32\DRIVERS\ManyCam.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - KITZZJMG

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6918f3ec-f7c5-11dd-a370-001bfcf02992}]
\Shell\AutoRun\command - G:\BSAutoRun.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-05-14 c:\windows\Tasks\User_Feed_Synchronization-{08A74F14-9E6A-48CB-BCB4-1AC2CF7A261F}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]

2009-05-14 c:\windows\Tasks\x.job
- c:\documents and settings\Administrator\Desktop\x.bat [2009-05-07 02:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.ro
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Save Flash - c:\program files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
FF - ProfilePath - c:\documents and settings\Duxx\Application Data\Mozilla\Firefox\Profiles\yacxpl6m.default\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-14 05:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(2012)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\windows\system32\klogon.dll

- - - - - - - > 'lsass.exe'(180)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll

- - - - - - - > 'explorer.exe'(1028)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\rundll32.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-05-14 5:29 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-14 02:29
ComboFix2.txt 2009-05-12 02:24
ComboFix3.txt 2009-05-07 23:17

Pre-Run: 8,486,846,464 bytes free
Post-Run: 8,467,947,520 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
420 — E O F — 2009-05-13 00:01



It looks ok to me.This is my HJT log:



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:31:03 AM, on 5/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\VisualCron\VisualCronService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.ro
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.ro
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\WINDOWS\sm56hlpr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VisualCron Tray ClientV5] C:\Program Files\VisualCron\VCTray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Save Flash - res://C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (HKCU)
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cron Service (CRONw) (CRON) - ActiveState - C:\Perl\bin\perl.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VisualCron - neteject.com - C:\Program Files\VisualCron\VisualCronService.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.32\bin\mysqld.exe

–
End of file - 7945 bytes



I'am running MBAM as we speak and i'll get back to you with a detailed log.
Ok,DUDE, you rule.No virus found.Thanks a lot.If you ever find yourself in romania let me know ;) …there's no beer like romanian beer.Anyway this is my MBAM log…guess this is the last one :D : Malwarebytes' Anti-Malware 1.36 Database version: 2110 Windows 5.1.2600 Service Pack 3 5/14/2009 6:48:40 AM mbam-log-2009-05-14 (06-48-40).txt Scan type: Full Scan (C:\|D:\|E:\|) Objects scanned: 218620 Time elapsed: 56 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Again thanks a lot,take care
ok good. your welcome. I like a good beer. Must have body and flavor, no water like beer.
you can remove combofix like this;

start>run and type in:
combofix /u
click ok or enter
note: a space after the x and before the /

Keep MBAM and always check for updates before scanning. Its good practice to keep it updated even if you dont scan alot.

You can make a new restore point. The why and how:

One of the features of Windows ME,XP and Vista is the System Restore option, however if malware infects a computer it is possible that the malware could be backed up in the System Restore folder. Therefore, clearing the restore points is a good idea after malware is removed and your computer appears to be functioning ok.

To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

(winXP)

1. Turn off System Restore. (deletes old possibly infected restore point)
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.(new restore points on a clean system)
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK, then reboot
————————————————————————————–

Some tips to reduce malware risks:

10 Tips for Reducing Your Risk To Malware:
The Short Version:

1) It is essential to Keep your OS,(Windows) browser (IE, FireFox) and other software up to date to "patch" vulnerabilities that could be exploited. This is also true for web based application like Java, Adobe Flash/Reader, QuickTime etc. Check there version status here.

2) Know what you are installing to your computer. Alot of software can come bundled with unwanted add-ons, like adware, toolbars and malware. Do not install any files from ads, popups or random links. Do not fall for fake warnings about virus and trojans being found on your computer and your then prompted to install software to remedy this. See also the signs that you may have malware on your computer.

3) Install and keep updated: one antivirus and two or three anti-malware applications. If not updated they will soon be worthless. Scanning frequency is a function of your computer habits.

4) Refrain from clicking on links or attachments you receive via E-Mail, IM, Chat Rooms or Social Sites, no matter how tempting or legitimate the message may seem.

5) Don't click on ads/pop ups or offers from websites requesting that you need to install software or codecs to your computer.

6) Don't click on offers to "scan" your computer. Install ActiveX Objects with care. Do you trust the website?

7) Set up and use limited accounts for everyday use, rather than administrator accounts. Limited accounts can help prevent *malware from installing.*

8) Install and understand the limitations of a software firewall.

9) Consider using an alternate browser and E-mail client. Internet Explorer and OutLook Express are popular targets for malicious code because they are widely used. See also: Hardening or Securing Internet Explorer.

10) If your habits include: warez, cracks etc or you install files via p2p networks then you are much more likely to encounter malicious code. Do you trust the source? Do you really need another malware source?

A longer version in link below.

Happy Safe Surfing.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI