This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please help review this HijackThis Log! A new vers

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My laptop got infected yesterday with a rouge spyware kept asking me to buy Anti Spyware 2010, and Google was redirected to "clickover.cn.
I got rid of the by MBAM, then by ATF Cleaner and Super AntiSpyware.

However today after using the laptop for 10 min, Google search is still kept being redirected to a new website named "cliccker.cn".

Below is my HijackThis log, please advise instantly if the laptop was infected with a nasty rootkit that requires me to smthing immediately to protect my online bank account and ID details, think I checked my account yesterday night. Many thanks



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:34:02, on 13/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Viet Do\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 64.27.5.223:9000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Wireless Manager] "C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p…IEGetPlugin.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: cru629.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: AffinegyService - Affinegy LLC - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit (mi-raysat_3dsMax2008_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
O23 - Service: mental ray 3.5 Satellite for Autodesk VIZ 2008 (mi-raysat_VIZ2008_32) - Unknown owner - C:\Program Files\Autodesk\VIZ2008\mentalray\satellite\raysat_VIZ2008_32server.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Unknown owner - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

–
End of file - 10020 bytes
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.
Is this a business or personal machine? If it is a business machine, it would be preferable for you to take this through their I.T. Department, as there may be sensitive information on the machine that we do not want to take responsibility for.
Thanks for your response! It's a home computer, and I will be reponsible for any accident. Please give me some instructions!

The summary of symptoms as they are today are as below:
  • Google search and any other search engine is redirected to "CLICCKER.CN", I have looked around and can see someone was also infected with this guy.
  • At startup, there is a rouge "Windows security alerts" telling me that my computer might be at risk as the firewall was turn off. That alert then dissapears after 5 seconds or so. Infact the firewall is always ON, as I check in Control Panel/Windows Security later.
  • In the task bar, the following icons disappear: Volume, Wireless Internet Connection, Power On (Battery or AC), and Safely Remove Hardware. I checked the option for displaying these icons in the Control Panel or Task bar properties, they are always ON. I then had to force the volume icon back to the task bar. Then all icons appeared at a same time.

I have bought a new external driver and started backing up all my data before taking any further action. Please advise me if there is anything I should do to avoid the malware attacking my backup driver and cause reinfection later.

Below is my latest HijackThis Log, please helpppp!!!! Thanks a lot


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:30, on 15/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
C:\Program Files\Autodesk\VIZ2008\mentalray\satellite\raysat_VIZ2008_32server.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Viet Do\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 64.27.5.223:9000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Wireless Manager] "C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p…IEGetPlugin.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: AffinegyService - Affinegy LLC - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit (mi-raysat_3dsMax2008_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
O23 - Service: mental ray 3.5 Satellite for Autodesk VIZ 2008 (mi-raysat_VIZ2008_32) - Unknown owner - C:\Program Files\Autodesk\VIZ2008\mentalray\satellite\raysat_VIZ2008_32server.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Unknown owner - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

–
End of file - 12322 bytes
johntk,

1) Fix HijackThis Lines
  • Open up Hijack This
  • Click the Do a system scan only button
  • Tick the checkbox next to the following items:
    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 64.27.5.223:9000
    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    • O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
  • Ensure all other windows and browsers besides Hijack This are closed, then click Fix Checked

2) DDS
[external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

3) GMER
Please download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and put it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


4) RR
Please download RootRepeal.zip.
Save it to your Desktop. Alternate download links here or here.
Please print these instructions, you will not have an Internet connection!
If you have a 3rd party "unzipping" program…use it to open the zipped file…then skip to Step 5. Otherwise…
  • Right click on RootRepeal.zip and select "Extract All"….
  • Click Next on the "Welcome to the Compressed (zipped) Folders Extraction Wizard."
  • Click on the Browse…button, then click on Desktop, then click OK.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Before running RootRepeal:
    • Disconnect from the Internet as your system will be unprotected while using this tool.
      Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan.
  • Open the RootRepeal folder and double-click on RootRepeal.exe to launch it.
  • When the program opens, click the Report tab at the bottom, then click the Scan button.
  • In the Select Scan, dialog which asks What do you want to include in the scan?, check ALL the boxes.
    🖼Click to load external image (Posted Image)
  • Click OK.
  • In the Select Drives, dialog Please select drives to scan: select all drives showing, then click OK.
    The scan can take some time to finish. Do not use the computer while the scan is running.
    When the scan has completed, a list of files will be generated in the RootRepeal window.
  • Click on the Save Report button and save it as "rootrepeal.txt" to your desktop.
  • Close and exit RootRepeal
  • Double-click on the file rootrepeal.txt… Notepad will open… copy/paste the file contents in your next reply.

Make sure to enable your anti-virus, Firewall and any other security programs you disabled.
Note: If RootRepeal cannot complete a scan and results in a crash report, try repeating the scan in "safe mode".

5) What You Will Need To Post:
  • DDS logs
  • GMER log
  • RR log
Thanks a lot! When I restarted the computer, right now a program called "Windows Antivirus Pro" appeared with a silver icon in the task bar and asking me to purchase! I am going to post quickly. Please advise if all things I ve done need to be done again. I think I trigged the new guy!!!

The Attach.txt will be zipped and attached with my reply, please advise if you cant open it.
Below I m gonna post the DDS.txt, Gmer.txt, and RootRepeal.txt


DDS (Ver_09-07-30.01) - NTFSx86 MINIMAL
Run by [removed] at 13:32:31.84 on 16/08/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2046.1712 [GMT -4:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Documents and Settings\Viet Do\Desktop\dds.pif

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.google.com/
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com/search?q=
mCustomizeSearch = hxxp://www.google.com/search?q=
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Megaupload Toolbar: {4e7bd74f-2b8d-469e-ccb0-b130eedbe97c} - c:\progra~1\megaup~1\MEGAUP~1.DLL
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Adobe Version Cue CS2] "c:\program files\adobe\adobe version cue cs2\controlpanel\VersionCueCS2Tray.exe"
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: []
mRun: [BJCFD] c:\program files\broadjump\client foundation\CFD.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Wireless Manager] "c:\program files\virgin broadband wireless\Wireless Manager.exe" startup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SNM] c:\program files\spynomore\SNM.exe /startup
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - c:\program files\common files\autodesk shared\acstart17.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
IE: &Download All with FlashGet - c:\program files\flashget\jc_all.htm
IE: &Download with FlashGet - c:\program files\flashget\jc_link.htm
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\program files\flashget\FlashGet.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} - hxxp://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================


==================== Find3M ====================

2007-11-16 17:56 88 a–shr– c:\windows\system32\8512A362E6.sys
2007-11-16 18:00 2,516 a–sh— c:\windows\system32\KGyGaAvL.sys
2008-09-23 17:02 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092320080924\index.dat

============= FINISH: 13:34:08.03 ===============


Gmer
GMER 1.0.15.15020 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-16 14:34:54
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

Code 8A6038F0 ZwEnumerateKey
Code 8A606960 ZwFlushInstructionCache
Code 8A6028E6 IofCallDriver
Code 8A60C346 IofCompleteRequest

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \FileSystem\Fastfat \Fat B9CF7D20
Device \FileSystem\Fastfat \Fat B9D07428

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\system32\drivers\SKYNETlyprqptt.sys (*** hidden *** ) [SYSTEM] SKYNETimpulqjk <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk@imagepath \systemroot\system32\drivers\SKYNETlyprqptt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\main@aid 10002
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\main@sid 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\[removed] \systemroot\system32\drivers\SKYNETlyprqptt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\[removed] \systemroot\system32\SKYNETabrnvpmx.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\[removed] \systemroot\system32\SKYNETubrjiqxb.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\[removed] \systemroot\system32\SKYNETgbiexuml.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETimpulqjk\[removed] \systemroot\system32\SKYNETokbmlwhx.dat
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk@imagepath \systemroot\system32\drivers\SKYNETlyprqptt.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\main@aid 10002
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\main@sid 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\[removed] \systemroot\system32\drivers\SKYNETlyprqptt.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\[removed] \systemroot\system32\SKYNETabrnvpmx.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\[removed] \systemroot\system32\SKYNETubrjiqxb.dat
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\[removed] \systemroot\system32\SKYNETgbiexuml.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETimpulqjk\[removed] \systemroot\system32\SKYNETokbmlwhx.dat

—- Files - GMER 1.0.15 —-

File C:\Documents and Settings\Viet Do\Application Data\Autodesk\AutoCAD 2007\R17.0\enu\Support\ToolPalette\Palettes\Beach.bmp 251160 bytes
File C:\Documents and Settings\Viet Do\Application Data\Autodesk\AutoCAD 2007\R17.0\enu\Support\ToolPalette\Palettes\Car.bmp 232236 bytes
File C:\Documents and Settings\Viet Do\Application Data\Autodesk\AutoCAD 2007\R17.0\enu\Support\ToolPalette\Palettes\Desktop.ini 150 bytes
File C:\Documents and Settings\Viet Do\Application Data\Autodesk\AutoCAD 2007\R17.0\enu\Support\ToolPalette\Palettes\Fighter.bmp 251160 bytes
File C:\Documents and Settings\Viet Do\Application Data\Autodesk\AutoCAD 2007\R17.0\enu\Support\ToolPalette\Palettes\Image Editor 0 bytes
File C:\Documents and Settings\Viet Do\Application Data\Autodesk\AutoCAD 2007\R17.0\enu\Support\ToolPalette\Palettes\People.bmp 121856 bytes
File C:\Documents and Settings\Viet Do\Application Data\Autodesk\AutoCAD 2007\R17.0\enu\Support\ToolPalette\Palettes\Rollercoaster.bmp 174992 bytes
File C:\Documents and Settings\Viet Do\Application Data\Autodesk\AutoCAD 2007\R17.0\enu\Support\ToolPalette\Palettes\Sample Pictures 0 bytes
File C:\Documents and Settings\Viet Do\Application Data\Autodesk\AutoCAD 2007\R17.0\enu\Support\ToolPalette\Palettes\Sonyericsson.bmp 80252 bytes
File C:\Documents and Settings\Viet Do\Application Data\Autodesk\AutoCAD 2007\R17.0\enu\Support\ToolPalette\Palettes\Thumbs.db 27136 bytes
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\msvcr71.dll 348160 bytes executable
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\ols.dll 229376 bytes executable
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\ols_config.xml 823 bytes
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\OperaMgr.dll 69632 bytes executable
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\PDFL70.dll 4096000 bytes executable
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\Plug-Ins 0 bytes
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\Plugin.dll 57344 bytes executable
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\Presets 0 bytes
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\required 0 bytes
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\Resources 0 bytes
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\ScCore.dll 344064 bytes executable
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\ssleay32.dll 159744 bytes executable
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\svgre.dll 3014656 bytes executable
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\VersionCue.dll 4153344 bytes executable
File C:\Program Files\Adobe\Adobe Bridge\Resources\fr\VersionCueUI.dll 3166208 bytes executable
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\chartables.bin 578606 bytes
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\classes 0 bytes
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\defaults 0 bytes
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\dialog.ini 75261 bytes
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\english.lng 151002 bytes
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\es262-32.dll 193536 bytes executable
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\hhd.ssr 7746 bytes
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\jsconsole.html 4188 bytes
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\opera.dll 1961984 bytes executable
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\operadef6.ini 93 bytes
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\OUniAnsi.dll 27648 bytes executable
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\Plugins 0 bytes
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\Skin 0 bytes
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\xmlparse.dll 50176 bytes executable
File C:\Program Files\Adobe\Adobe GoLive CS2\Settings\DocumentStore\docs\web\samples-css\coffeeshop\images\zip.dll 40960 bytes executable
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\acpo 0 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\adprefs.ini 523 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\cache4 0 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\global.dat 5523 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\images 0 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\jswarn.dir 2 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\keyboard 0 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\menu 0 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\mouse 0 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\opera.dir 3988 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\opera6.ini 810 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\sessions 0 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\Skin 0 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\toolbar 0 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\urlwarn.dir 2 bytes
File C:\Program Files\Adobe\Adobe Illustrator CS2\Presets\Save for Web Settings\Color Tables\vlink4.dat 487 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\features\Caption.htm 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\features\images 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\features\IndexPage.htm 2429 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\features\SubPage.htm 2867 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\features\Thumbnail.htm 860 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Acrobat 7.0 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Adobe Bridge 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Adobe GoLive CS2 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Adobe Help Center 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Adobe Help Viewer 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Adobe Illustrator CS2 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Adobe InDesign CS2 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Adobe Photoshop CS2 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Adobe Stock Photos 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Adobe Utilities 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Adobe Version Cue CS2 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Reader 8.0 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\jre\lib\zi\Antarctica\Security Update 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.asset_2.0.0\com.adobe.versioncue.controller.metadata.jar 45497 bytes
File C:\WINDOWS\system32\drivers\SKYNETlyprqptt.sys 70656 bytes <– ROOTKIT !!!
File C:\WINDOWS\system32\SKYNETabrnvpmx.dll 44544 bytes
File C:\WINDOWS\system32\SKYNETgbiexuml.dll 20480 bytes
File C:\WINDOWS\system32\SKYNETokbmlwhx.dat 91 bytes
File C:\WINDOWS\system32\SKYNETubrjiqxb.dat 204983 bytes

—- EOF - GMER 1.0.15 —-


RootRepeal

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/16 14:37
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
——————-
Name: aujasnkj.sys
Image Path: C:\DOCUME~1\VIETDO~1\LOCALS~1\Temp\aujasnkj.sys
Address: 0xB9D14000 Size: 83584 File Visible: No Signed: -
Status: -

Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xBA45B000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79B3000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB9D81000 Size: 49152 File Visible: No Signed: -
Status: -

Name: SKYNETlyprqptt.sys
Image Path: C:\WINDOWS\system32\drivers\SKYNETlyprqptt.sys
Address: 0xBA473000 Size: 151552 File Visible: - Signed: -
Status: Hidden from the Windows API!

Hidden/Locked Files
——————-
Path: C:\WINDOWS\system32\SKYNETabrnvpmx.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\SKYNETgbiexuml.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\SKYNETokbmlwhx.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\SKYNETubrjiqxb.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\drivers\SKYNETlyprqptt.sys
Status: Invisible to the Windows API!

Stealth Objects
——————-
Object: Hidden Module [Name: SKYNETgbiexuml.dll]
Process: winlogon.exe (PID: 268) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETgbiexuml.dll]
Process: services.exe (PID: 316) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETgbiexuml.dll]
Process: lsass.exe (PID: 328) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETabrnvpmx.dll]
Process: svchost.exe (PID: 488) Address: 0x008e0000 Size: 53248

Object: Hidden Module [Name: SKYNETgbiexuml.dll]
Process: svchost.exe (PID: 488) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETgbiexuml.dll]
Process: svchost.exe (PID: 576) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETgbiexuml.dll]
Process: MsMpEng.exe (PID: 636) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETgbiexuml.dll]
Process: svchost.exe (PID: 688) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETgbiexuml.dll]
Process: Explorer.EXE (PID: 1000) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETgbiexuml.dll]
Process: MSASCui.exe (PID: 1440) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETgbiexuml.dll]
Process: RootRepeal.exe (PID: 1880) Address: 0x10000000 Size: 32768

Hidden Services
——————-
Service Name: SKYNETimpulqjk
Image Path: C:\WINDOWS\system32\drivers\SKYNETlyprqptt.sys

==EOF==
Hi Raktor, Please note that after posting the reply, the "Windows Antivirus Pro" kept popping up so much that I decided to run a quick MBAM to kill it. It resulted in about 50 infected files. I selected the option of removing all. It said two files could not be completely removed and I needed to restart my computer. When the laptop was restarted, OK this was the worst things that happened in the last few days: None of my program was running, for example when I double clicked on Word or AutoCad shortcuts, it asked me which program I like to open this .exe with!!!! Going to Control Panel, when I double clicked some utilities like "Add and remove programs", it said Application failed because rundll32.exe was not found. I then went to Program Files/MBAM and launched the program from there. After scanning, there were two files infected - Broken.Opencommand/Registry Data/HKEY_CLASS_ROOT/exefiles/shell/open/command/default - RogueTrace/Registry Key/HKEY_USERS/S-1-5-18/SOFTWRE/Windows Antivirus Pro I selected to removed these two and now all programs are back. But still the Google search was redirected to CLICCKER.CN and other adv sites Please advise if I need to run DSS and RootRepeal again. Many thanks

Please do not run any scans or fixes without my direction.


Please read through the instructions to familiarize yourself with what to expect when the tool runs.

Please download Combofix from either of the links below, and save it to your desktop.
You must rename it before saving it. Save it as Combo-Fix.exe.

[external image: Posted Image]

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link:How to Disable your Security Programs
  • Double click on Combo-Fix.exe & follow the prompts. Close all browsers/windows first.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks a lot, below is the ComboFix.text:
(ComboFix informed that it could not connect to the download source for Microsoft Windows Recovery Console software and it automatically continued scanning without installing this)


ComboFix 09-08-10.06 - Viet Do 16/08/2009 22:51.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2046.1597 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Viet Do\Local Settings\Temporary Internet Files\egifidop.dll
c:\documents and settings\Viet Do\Local Settings\Temporary Internet Files\gifahodal._sy
c:\documents and settings\Viet Do\Local Settings\Temporary Internet Files\jelox.bin
c:\documents and settings\Viet Do\Local Settings\Temporary Internet Files\ojezimi.inf
c:\documents and settings\Viet Do\Local Settings\Temporary Internet Files\regejebel.scr
c:\documents and settings\Viet Do\Local Settings\Temporary Internet Files\umoj.scr
c:\documents and settings\Viet Do\Local Settings\Temporary Internet Files\zepem.bin
c:\program files\Bkav2006
c:\program files\Bkav2006\BkavMainDll.Dll
c:\program files\Bkav2006\BkavScanDll0.dll
c:\program files\Bkav2006\ContextMenu.dll
c:\program files\Bkav2006\CoreLib.dll
c:\program files\Bkav2006\FileList
c:\program files\Bkav2006\Help\bkav.css
c:\program files\Bkav2006\Help\chitiet.htm
c:\program files\Bkav2006\Help\chitiete.htm
c:\program files\Bkav2006\Help\HelpBanquyen.htm
c:\program files\Bkav2006\Help\Helpbtg.htm
c:\program files\Bkav2006\Help\Helpdiet.htm
c:\program files\Bkav2006\Help\HelpGth.htm
c:\program files\Bkav2006\Help\HelpLiqu.htm
c:\program files\Bkav2006\Help\HelpLiveUpdate.htm
c:\program files\Bkav2006\Help\Helpnhki.htm
c:\program files\Bkav2006\Help\Helpnhl.htm
c:\program files\Bkav2006\Help\HelpOpt.htm
c:\program files\Bkav2006\Help\HelpVrls.htm
c:\program files\Bkav2006\Help\images\arrow.gif
c:\program files\Bkav2006\Help\images\DangKy.gif
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\Fonts\Vn.Fon
c:\windows\run.log
c:\windows\system32\BkavAuto.vxd
c:\windows\system32\drivers\1028_DELL_XPS_MM061 .MRK
c:\windows\system32\drivers\BkavAuto.sys
c:\windows\system32\drivers\DELL_XPS_MM061 .MRK
c:\windows\system32\drivers\SKYNETlyprqptt.sys
c:\windows\system32\drivers\SysLib.sys
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SKYNETabrnvpmx.dll
c:\windows\system32\SKYNETgbiexuml.dll
c:\windows\system32\SKYNETokbmlwhx.dat
c:\windows\system32\SKYNETubrjiqxb.dat
c:\windows\system32\WanPacket.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SKYNETimpulqjk
——-\Legacy_SKYNETimpulqjk
——-\Legacy_BKAVAUTO
——-\Legacy_NPF
——-\Legacy_SYSLIB


((((((((((((((((((((((((( Files Created from 2009-07-17 to 2009-08-17 )))))))))))))))))))))))))))))))
.

2009-08-15 20:33 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 20:33 . 2009-08-15 20:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-15 20:33 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-15 02:05 . 2009-08-15 02:05 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2009-08-15 00:00 . 2009-08-15 00:00 88191 —-a-w- c:\windows\system32\reg-list.reg
2009-08-14 23:58 . 2009-08-15 20:31 ——– d—–w- c:\program files\Quick Virus Remover
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- c:\program files\MSBuild
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- c:\program files\Reference Assemblies
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- C:\27769dca0c4095ee5aefc9ddb6fda3a0
2009-08-14 12:19 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-14 12:19 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-14 12:19 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-14 12:19 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-14 12:19 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-14 12:19 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-14 12:19 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-14 02:14 . 2009-08-14 02:14 ——– d—–w- c:\program files\ERUNT
2009-08-13 12:19 . 2009-08-13 12:19 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-08-13 03:44 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-13 03:38 . 2008-10-16 18:06 268648 —-a-w- c:\windows\system32\mucltui.dll
2009-08-13 03:38 . 2008-10-16 18:06 208744 —-a-w- c:\windows\system32\muweb.dll
2009-08-13 02:15 . 2009-08-13 02:15 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-13 02:15 . 2009-08-15 20:30 ——– d—–w- c:\documents and settings\Viet Do\Application Data\SUPERAntiSpyware.com
2009-08-13 02:15 . 2009-08-15 20:30 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-08-13 01:47 . 2009-08-13 01:47 ——– d—–w- c:\program files\Windows Defender
2009-08-13 00:19 . 2009-08-13 00:19 ——– d—–w- c:\documents and settings\Viet Do\Application Data\GetRightToGo
2009-08-12 05:06 . 2009-08-12 05:06 ——– d—–w- c:\program files\Microsoft Works
2009-08-12 05:05 . 2009-08-12 05:05 ——– d—–w- c:\program files\Microsoft.NET
2009-08-12 05:03 . 2009-08-12 05:03 ——– d—–w- c:\documents and settings\Viet Do\Local Settings\Application Data\Microsoft Help
2009-08-12 05:03 . 2009-08-13 12:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-12 05:03 . 2009-08-12 05:03 ——– d–h–r- C:\MSOCache
2009-08-12 04:45 . 2009-08-13 03:34 8280064 —-a-w- c:\windows\system32\drivers\SysLib0.sys
2009-08-12 04:00 . 2009-08-12 04:00 1152 —-a-w- c:\windows\system32\windrv.sys
2009-08-12 02:47 . 2009-08-12 02:47 ——– d—–w- c:\documents and settings\Viet Do\Application Data\Malwarebytes
2009-08-12 02:47 . 2009-08-12 02:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-12 02:45 . 2009-08-12 02:45 19667 —-a-w- c:\windows\figofyheso.exe
2009-08-12 02:45 . 2009-08-12 02:45 16266 —-a-w- c:\windows\ozajyjobec.bin
2009-08-12 02:45 . 2009-08-12 02:45 15684 —-a-w- c:\documents and settings\Viet Do\Local Settings\Application Data\juwyjab.dll
2009-08-12 02:45 . 2009-08-12 02:45 14688 —-a-w- c:\windows\elosubupe.vbs
2009-08-12 02:45 . 2009-08-12 02:45 13194 —-a-w- c:\documents and settings\All Users\Application Data\uzace.scr
2009-08-12 02:45 . 2009-08-12 02:45 12807 —-a-w- c:\documents and settings\All Users\Application Data\zejyti.exe
2009-08-12 02:45 . 2009-08-12 02:45 11301 —-a-w- c:\program files\Common Files\cerovenesy.pif
2009-08-12 02:37 . 2009-08-12 02:37 19777 —-a-w- c:\windows\ujuti.vbs
2009-08-12 02:37 . 2009-08-12 02:37 19441 —-a-w- c:\windows\hybita.exe
2009-08-12 02:37 . 2009-08-12 02:37 19352 —-a-w- c:\documents and settings\All Users\Application Data\mulufyfyh.bat
2009-08-12 02:37 . 2009-08-12 02:37 16841 —-a-w- c:\windows\avuhor.sys
2009-08-12 02:37 . 2009-08-12 02:37 16791 —-a-w- c:\documents and settings\Viet Do\Application Data\umaraketi.exe
2009-08-12 02:37 . 2009-08-12 02:37 15509 —-a-w- c:\windows\molegy.vbs
2009-08-12 02:37 . 2009-08-12 02:37 15220 —-a-w- c:\documents and settings\Viet Do\Local Settings\Application Data\bucir.scr
2009-08-12 02:37 . 2009-08-12 02:37 12066 —-a-w- c:\documents and settings\Viet Do\Application Data\ijyw.com
2009-08-12 02:37 . 2009-08-12 02:37 11762 —-a-w- c:\documents and settings\Viet Do\Local Settings\Application Data\garatomo.sys
2009-08-12 01:57 . 2009-08-12 01:57 18444 —-a-w- c:\program files\Common Files\ysevuvexo.bin
2009-08-12 01:57 . 2009-08-12 01:57 17847 —-a-w- c:\windows\fexylajiqe.reg
2009-08-12 01:57 . 2009-08-12 01:57 16799 —-a-w- c:\windows\ulaboj.vbs
2009-08-12 01:57 . 2009-08-12 01:57 14775 —-a-w- c:\windows\gikeh.dll
2009-08-11 01:14 . 2009-08-11 01:14 ——– d—–w- c:\documents and settings\Viet Do\Application Data\M-HTOEFL
2009-08-11 01:14 . 2009-08-11 01:14 ——– d—–w- c:\program files\TOEFL Official Guide
2009-08-07 19:44 . 2009-08-07 19:44 1961720 —-a-w- c:\documents and settings\Viet Do\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c—-w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-04 00:55 . 2009-08-04 00:55 ——– d—–w- c:\program files\Common Files\IviSDK
2009-08-04 00:54 . 2006-05-08 13:55 28672 —-a-w- c:\windows\system32\hcwsched.dll
2009-08-04 00:54 . 2006-01-25 21:38 69632 —-a-w- c:\windows\system32\3DES.dll
2009-08-04 00:54 . 2006-05-08 13:54 65536 —-a-w- c:\windows\system32\dmcrypto.dll
2009-08-04 00:54 . 2009-08-04 00:55 ——– d—–w- c:\windows\system32\hauppauge
2009-08-04 00:54 . 2009-08-04 00:54 ——– d—–w- C:\MyVideos
2009-08-04 00:54 . 2008-05-29 21:00 806985 ——w- c:\windows\system32\hcwtvwnd.dll
2009-08-04 00:54 . 2008-04-22 18:53 163840 —-a-w- c:\windows\system32\hcwChDB.dll
2009-08-04 00:54 . 2008-03-26 18:54 30720 —-a-w- c:\windows\system32\hcwWinTVCI.dll
2009-08-04 00:54 . 2006-10-10 21:47 36921 —-a-w- c:\windows\system32\hcwutl32.dll
2009-08-04 00:54 . 2004-01-26 18:49 90190 —-a-w- c:\windows\system32\Bt848WST.DLL
2009-08-04 00:53 . 2003-11-07 16:45 106559 —-a-w- c:\windows\system32\hcwTVDlg.dll
2009-08-04 00:53 . 2008-05-09 01:13 294968 ——w- c:\windows\system32\hcwpnp32.dll
2009-08-04 00:53 . 2001-07-19 12:44 393216 —-a-w- c:\windows\system32\hcwsnbd9.dll
2009-08-04 00:53 . 2009-08-14 04:28 ——– d—–w- c:\program files\WinTV
2009-08-04 00:53 . 2008-03-11 21:36 106552 —-a-w- c:\windows\system32\hcwi2c32.dll
2009-08-04 00:53 . 2004-12-20 16:11 213050 —-a-w- c:\windows\system32\hcwChan.dll
2009-08-04 00:53 . 1999-04-27 20:26 11264 —-a-w- c:\windows\system32\hcwhook.dll
2009-08-04 00:52 . 2008-04-13 23:46 15232 -c–a-w- c:\windows\system32\dllcache\mpe.sys
2009-08-04 00:52 . 2008-04-13 23:46 15232 —-a-w- c:\windows\system32\drivers\MPE.sys
2009-08-04 00:50 . 2008-04-14 05:12 363520 -c–a-w- c:\windows\system32\dllcache\psisdecd.dll
2009-08-04 00:50 . 2008-04-14 05:12 363520 —-a-w- c:\windows\system32\PsisDecd.dll
2009-08-04 00:50 . 2008-04-13 23:46 11776 -c–a-w- c:\windows\system32\dllcache\bdasup.sys
2009-08-04 00:50 . 2008-04-13 23:46 11776 —-a-w- c:\windows\system32\drivers\BdaSup.sys
2009-08-04 00:41 . 2008-04-11 20:52 43008 —-a-w- c:\windows\system32\hcw72Co.dll
2009-08-04 00:41 . 2008-04-11 20:53 1208448 —-a-w- c:\windows\system32\drivers\hcw72ATV.sys
2009-08-04 00:41 . 2008-04-11 20:52 27904 —-a-w- c:\windows\system32\drivers\hcw72ADFilter.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-17 03:04 . 2008-03-17 19:03 ——– d—–w- c:\documents and settings\Viet Do\Application Data\DNA
2009-08-17 03:04 . 2008-03-17 19:03 ——– d—–w- c:\program files\DNA
2009-08-15 20:30 . 2007-08-24 20:36 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-08-15 01:47 . 2007-07-01 21:51 ——– d—–w- c:\documents and settings\Viet Do\Application Data\Skype
2009-08-15 00:05 . 2007-05-28 14:57 90112 —-a-w- c:\windows\DUMP7242.tmp
2009-08-14 12:39 . 2007-05-28 15:45 61648 —-a-w- c:\documents and settings\Viet Do\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-13 01:42 . 2007-08-19 10:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-13 01:05 . 2007-08-14 19:53 ——– d—–w- c:\program files\Google
2009-08-12 04:24 . 2008-01-21 21:48 ——– d—–w- c:\documents and settings\All Users\Application Data\avg7
2009-08-12 02:45 . 2009-08-12 02:45 11360 —-a-w- c:\program files\Common Files\ymomuvor.inf
2009-08-12 02:37 . 2009-08-12 02:37 17084 —-a-w- c:\program files\Common Files\ubygedoli.dl
2009-08-12 02:37 . 2009-08-12 02:37 19126 —-a-w- c:\program files\Common Files\felera.db
2009-08-05 09:01 . 2004-08-04 10:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 00:55 . 2007-05-28 15:18 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-25 04:48 . 2007-05-28 22:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Autodesk
2009-07-25 04:47 . 2007-05-28 22:21 ——– d—–w- c:\program files\Common Files\Autodesk Shared
2009-07-17 19:01 . 2004-08-04 10:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 10:00 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2006-03-04 03:33 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2004-08-04 10:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 10:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 10:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 10:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 10:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 10:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2004-08-04 10:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 10:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2004-08-04 10:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-04 10:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-08-04 10:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2007-05-28 14:15 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-08-04 10:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-04 11:41 . 2009-06-04 11:41 390664 —-a-w- c:\documents and settings\Viet Do\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-06-03 19:09 . 2004-08-04 10:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2007-11-16 21:56 . 2007-09-16 17:22 88 –sha-r- c:\windows\system32\8512A362E6.sys
2007-11-16 22:00 . 2007-09-16 16:52 2516 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-19 342848]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 856064]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 376912]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-24 185896]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2007-10-16 585728]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTorrent_DNA\\dna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\@Last Software\\SketchUp 4\\SketchUp.exe"=
"c:\\Program Files\\Autodesk\\VIZ2008\\3dsviz.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\SonicWALL\\SonicWALL Global VPN Client\\SWGVpnClient.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2008\\3dsmax.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [09/05/2009 12:43 57320]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [09/05/2009 12:43 238952]
R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [20/03/2008 13:00 101528]
R1 SysLib0;SysLib0;c:\windows\system32\drivers\SysLib0.sys [12/08/2009 00:45 8280064]
R2 mi-raysat_VIZ2008_32;mental ray 3.5 Satellite for Autodesk VIZ 2008;c:\program files\Autodesk\VIZ2008\mentalray\satellite\raysat_VIZ2008_32server.exe [07/03/2007 11:32 65536]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [04/06/2009 23:05 648424]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
S3 hcw72ADFilter;WinTV HVR-950 USB Audio Filter Driver;c:\windows\system32\drivers\hcw72ADFilter.sys [03/08/2009 20:41 27904]
S3 hcw72ATV;WinTV HVR-950 NTSC;c:\windows\system32\drivers\hcw72ATV.sys [03/08/2009 20:41 1208448]
S3 hcw72DTV;WinTV HVR-950 ATSC/QAM;c:\windows\system32\drivers\hcw72DTV.sys [08/07/2008 18:41 1200768]
S3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [20/03/2008 13:00 24876]
.
Contents of the 'Scheduled Tasks' folder

2009-05-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-08-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SNM - c:\program files\SpyNoMore\SNM.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-16 23:03
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1016)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(7164)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
c:\program files\Trusteer\Rapport\bin\rooksbas.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Virgin Broadband Wireless\AffinegyService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
c:\program files\Common Files\Protexis\License Service\PSIService.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wscntfy.exe
c:\program files\Trusteer\Rapport\bin\RapportService.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2009-08-17 23:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-17 03:13

Pre-Run: 41,861,656,576 bytes free
Post-Run: 41,828,032,512 bytes free

357 — E O F — 2009-08-16 07:00
I hate to the bearer of bad news but, your log shows a very dangerous Trojan is residing on your PC.

Trojan.Backdoor
The Trojan attempts to steal passwords, as well as logging key presses and open window titles to text files and periodically sends the collected information to a remote user via HTTP. The Trojan downloads and executes additional files from a remote site. Configuration files may also be downloaded which define further behaviors.

As you can see, it not only includes a key logger, but back door functionality.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or it if it contains any other sensitive information, please get to a known clean computer and change all passwords where applicable and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed, because of it's back door functionality, Your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. If it were on my PC I would not hesitate for a moment to do so. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

Should you decide not to follow that advice, we will of course do our best to clean the computer of any infections that we can see but, as I already stated, we can in no way guarantee it to be trustworthy.

Should you have any questions, please feel free to ask.

Please let us know what you have decided to do. Should you choose to continue, please follow the below instructions.

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    http://forums.whatthetech.com/Please_help_review_HijackThis_Log_new_version_clickover_t106116.html
    
    Collect::
    c:\windows\system32\drivers\SysLib0.sys
    c:\windows\figofyheso.exe
    c:\windows\ozajyjobec.bin
    c:\documents and settings\Viet Do\Local Settings\Application Data\juwyjab.dll
    c:\windows\elosubupe.vbs
    c:\documents and settings\All Users\Application Data\uzace.scr
    c:\documents and settings\All Users\Application Data\zejyti.exe
    c:\program files\Common Files\cerovenesy.pif
    c:\windows\ujuti.vbs
    c:\windows\hybita.exe
    c:\documents and settings\All Users\Application Data\mulufyfyh.bat
    c:\windows\avuhor.sys
    c:\documents and settings\Viet Do\Application Data\umaraketi.exe
    c:\windows\molegy.vbs
    c:\documents and settings\Viet Do\Local Settings\Application Data\bucir.scr
    c:\documents and settings\Viet Do\Application Data\ijyw.com
    c:\documents and settings\Viet Do\Local Settings\Application Data\garatomo.sys
    c:\program files\Common Files\ysevuvexo.bin
    c:\windows\fexylajiqe.reg
    c:\windows\ulaboj.vbs
    c:\windows\gikeh.dll
    c:\program files\Common Files\ymomuvor.inf
    c:\program files\Common Files\ubygedoli.dl
    c:\program files\Common Files\felera.db
    
    Driver:: 
    SysLib0
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Thanks a bunch! I managed to change all passwords and call my banks to give the warnings today. Below is the log of the latest ComboFix run.
Besides I have some questions, please advise:
- I backuped data within 2 days before the first DSS run. I copied all data in separate folders and in My Documents (C driver), EXCEPT Documents and Settings, My Pictures, My Music, etc. I DIDNT backup anything from Program Files or Windows. So, is there any chance that the Backdoor Trojan can reside in backup data and come back again?
- In the first day of infection, I did a complete scan using an Antivirus program for my 2 external drivers. Is there any chance that the Backdoor Trojan can now reside in these external drives (one of which was taken from my previous laptop and still has Windows folder in it)? If yes, what should I do to clean these external drives?

Please advise what I should do next. Thanks a lot,





ComboFix 09-08-10.06 - Viet Do 17/08/2009 20:40.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2046.1521 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Viet Do\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

file zipped: c:\documents and settings\All Users\Application Data\mulufyfyh.bat
file zipped: c:\documents and settings\All Users\Application Data\uzace.scr
file zipped: c:\documents and settings\All Users\Application Data\zejyti.exe
file zipped: c:\documents and settings\Viet Do\Application Data\ijyw.com
file zipped: c:\documents and settings\Viet Do\Application Data\umaraketi.exe
file zipped: c:\documents and settings\Viet Do\Local Settings\Application Data\bucir.scr
file zipped: c:\documents and settings\Viet Do\Local Settings\Application Data\garatomo.sys
file zipped: c:\documents and settings\Viet Do\Local Settings\Application Data\juwyjab.dll
file zipped: c:\program files\Common Files\cerovenesy.pif
file zipped: c:\program files\Common Files\felera.db
file zipped: c:\program files\Common Files\ubygedoli.dl
file zipped: c:\program files\Common Files\ymomuvor.inf
file zipped: c:\program files\Common Files\ysevuvexo.bin
file zipped: c:\windows\avuhor.sys
file zipped: c:\windows\elosubupe.vbs
file zipped: c:\windows\fexylajiqe.reg
file zipped: c:\windows\figofyheso.exe
file zipped: c:\windows\gikeh.dll
file zipped: c:\windows\hybita.exe
file zipped: c:\windows\molegy.vbs
file zipped: c:\windows\ozajyjobec.bin
file zipped: c:\windows\system32\drivers\SysLib0.sys
file zipped: c:\windows\ujuti.vbs
file zipped: c:\windows\ulaboj.vbs
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\mulufyfyh.bat
c:\documents and settings\All Users\Application Data\uzace.scr
c:\documents and settings\All Users\Application Data\zejyti.exe
c:\documents and settings\Viet Do\Application Data\ijyw.com
c:\documents and settings\Viet Do\Application Data\umaraketi.exe
c:\documents and settings\Viet Do\Local Settings\Application Data\bucir.scr
c:\documents and settings\Viet Do\Local Settings\Application Data\garatomo.sys
c:\documents and settings\Viet Do\Local Settings\Application Data\juwyjab.dll
c:\program files\Common Files\cerovenesy.pif
c:\program files\Common Files\felera.db
c:\program files\Common Files\ubygedoli.dl
c:\program files\Common Files\ymomuvor.inf
c:\program files\Common Files\ysevuvexo.bin
c:\windows\avuhor.sys
c:\windows\elosubupe.vbs
c:\windows\fexylajiqe.reg
c:\windows\figofyheso.exe
c:\windows\gikeh.dll
c:\windows\hybita.exe
c:\windows\molegy.vbs
c:\windows\ozajyjobec.bin
c:\windows\system32\drivers\SysLib0.sys
c:\windows\ujuti.vbs
c:\windows\ulaboj.vbs

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_SYSLIB0
——-\Service_SysLib0


((((((((((((((((((((((((( Files Created from 2009-07-18 to 2009-08-18 )))))))))))))))))))))))))))))))
.

2009-08-15 20:33 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 20:33 . 2009-08-15 20:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-15 20:33 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-15 02:05 . 2009-08-15 02:05 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2009-08-15 00:00 . 2009-08-15 00:00 88191 —-a-w- c:\windows\system32\reg-list.reg
2009-08-14 23:58 . 2009-08-15 20:31 ——– d—–w- c:\program files\Quick Virus Remover
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- c:\program files\MSBuild
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- c:\program files\Reference Assemblies
2009-08-14 12:19 . 2009-08-14 12:19 ——– d—–w- C:\27769dca0c4095ee5aefc9ddb6fda3a0
2009-08-14 12:19 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-14 12:19 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-14 12:19 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-14 12:19 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-14 12:19 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-14 12:19 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-14 12:19 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-14 02:14 . 2009-08-14 02:14 ——– d—–w- c:\program files\ERUNT
2009-08-13 12:19 . 2009-08-13 12:19 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-08-13 03:44 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-13 03:38 . 2008-10-16 18:06 268648 —-a-w- c:\windows\system32\mucltui.dll
2009-08-13 03:38 . 2008-10-16 18:06 208744 —-a-w- c:\windows\system32\muweb.dll
2009-08-13 02:15 . 2009-08-13 02:15 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-13 02:15 . 2009-08-15 20:30 ——– d—–w- c:\documents and settings\Viet Do\Application Data\SUPERAntiSpyware.com
2009-08-13 02:15 . 2009-08-15 20:30 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-08-13 01:47 . 2009-08-13 01:47 ——– d—–w- c:\program files\Windows Defender
2009-08-13 00:19 . 2009-08-13 00:19 ——– d—–w- c:\documents and settings\Viet Do\Application Data\GetRightToGo
2009-08-12 05:06 . 2009-08-12 05:06 ——– d—–w- c:\program files\Microsoft Works
2009-08-12 05:05 . 2009-08-12 05:05 ——– d—–w- c:\program files\Microsoft.NET
2009-08-12 05:03 . 2009-08-12 05:03 ——– d—–w- c:\documents and settings\Viet Do\Local Settings\Application Data\Microsoft Help
2009-08-12 05:03 . 2009-08-13 12:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-12 05:03 . 2009-08-12 05:03 ——– d–h–r- C:\MSOCache
2009-08-12 04:00 . 2009-08-12 04:00 1152 —-a-w- c:\windows\system32\windrv.sys
2009-08-12 02:47 . 2009-08-12 02:47 ——– d—–w- c:\documents and settings\Viet Do\Application Data\Malwarebytes
2009-08-12 02:47 . 2009-08-12 02:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-11 01:14 . 2009-08-11 01:14 ——– d—–w- c:\documents and settings\Viet Do\Application Data\M-HTOEFL
2009-08-11 01:14 . 2009-08-11 01:14 ——– d—–w- c:\program files\TOEFL Official Guide
2009-08-07 19:44 . 2009-08-07 19:44 1961720 —-a-w- c:\documents and settings\Viet Do\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c—-w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-04 00:55 . 2009-08-04 00:55 ——– d—–w- c:\program files\Common Files\IviSDK
2009-08-04 00:54 . 2006-05-08 13:55 28672 —-a-w- c:\windows\system32\hcwsched.dll
2009-08-04 00:54 . 2006-01-25 21:38 69632 —-a-w- c:\windows\system32\3DES.dll
2009-08-04 00:54 . 2006-05-08 13:54 65536 —-a-w- c:\windows\system32\dmcrypto.dll
2009-08-04 00:54 . 2009-08-04 00:55 ——– d—–w- c:\windows\system32\hauppauge
2009-08-04 00:54 . 2009-08-04 00:54 ——– d—–w- C:\MyVideos
2009-08-04 00:54 . 2008-05-29 21:00 806985 ——w- c:\windows\system32\hcwtvwnd.dll
2009-08-04 00:54 . 2008-04-22 18:53 163840 —-a-w- c:\windows\system32\hcwChDB.dll
2009-08-04 00:54 . 2008-03-26 18:54 30720 —-a-w- c:\windows\system32\hcwWinTVCI.dll
2009-08-04 00:54 . 2006-10-10 21:47 36921 —-a-w- c:\windows\system32\hcwutl32.dll
2009-08-04 00:54 . 2004-01-26 18:49 90190 —-a-w- c:\windows\system32\Bt848WST.DLL
2009-08-04 00:53 . 2003-11-07 16:45 106559 —-a-w- c:\windows\system32\hcwTVDlg.dll
2009-08-04 00:53 . 2008-05-09 01:13 294968 ——w- c:\windows\system32\hcwpnp32.dll
2009-08-04 00:53 . 2001-07-19 12:44 393216 —-a-w- c:\windows\system32\hcwsnbd9.dll
2009-08-04 00:53 . 2009-08-14 04:28 ——– d—–w- c:\program files\WinTV
2009-08-04 00:53 . 2008-03-11 21:36 106552 —-a-w- c:\windows\system32\hcwi2c32.dll
2009-08-04 00:53 . 2004-12-20 16:11 213050 —-a-w- c:\windows\system32\hcwChan.dll
2009-08-04 00:53 . 1999-04-27 20:26 11264 —-a-w- c:\windows\system32\hcwhook.dll
2009-08-04 00:52 . 2008-04-13 23:46 15232 -c–a-w- c:\windows\system32\dllcache\mpe.sys
2009-08-04 00:52 . 2008-04-13 23:46 15232 —-a-w- c:\windows\system32\drivers\MPE.sys
2009-08-04 00:50 . 2008-04-14 05:12 363520 -c–a-w- c:\windows\system32\dllcache\psisdecd.dll
2009-08-04 00:50 . 2008-04-14 05:12 363520 —-a-w- c:\windows\system32\PsisDecd.dll
2009-08-04 00:50 . 2008-04-13 23:46 11776 -c–a-w- c:\windows\system32\dllcache\bdasup.sys
2009-08-04 00:50 . 2008-04-13 23:46 11776 —-a-w- c:\windows\system32\drivers\BdaSup.sys
2009-08-04 00:41 . 2008-04-11 20:52 43008 —-a-w- c:\windows\system32\hcw72Co.dll
2009-08-04 00:41 . 2008-04-11 20:53 1208448 —-a-w- c:\windows\system32\drivers\hcw72ATV.sys
2009-08-04 00:41 . 2008-04-11 20:52 27904 —-a-w- c:\windows\system32\drivers\hcw72ADFilter.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-18 00:49 . 2008-03-17 19:03 ——– d—–w- c:\documents and settings\Viet Do\Application Data\DNA
2009-08-18 00:49 . 2008-03-17 19:03 ——– d—–w- c:\program files\DNA
2009-08-15 20:30 . 2007-08-24 20:36 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-08-15 01:47 . 2007-07-01 21:51 ——– d—–w- c:\documents and settings\Viet Do\Application Data\Skype
2009-08-15 00:05 . 2007-05-28 14:57 90112 —-a-w- c:\windows\DUMP7242.tmp
2009-08-14 12:39 . 2007-05-28 15:45 61648 —-a-w- c:\documents and settings\Viet Do\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-13 01:42 . 2007-08-19 10:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-13 01:05 . 2007-08-14 19:53 ——– d—–w- c:\program files\Google
2009-08-12 04:24 . 2008-01-21 21:48 ——– d—–w- c:\documents and settings\All Users\Application Data\avg7
2009-08-05 09:01 . 2004-08-04 10:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 00:55 . 2007-05-28 15:18 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-25 04:48 . 2007-05-28 22:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Autodesk
2009-07-25 04:47 . 2007-05-28 22:21 ——– d—–w- c:\program files\Common Files\Autodesk Shared
2009-07-17 19:01 . 2004-08-04 10:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 10:00 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2006-03-04 03:33 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2004-08-04 10:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 10:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 10:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 10:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 10:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 10:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2004-08-04 10:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 10:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2004-08-04 10:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-04 10:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-08-04 10:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2007-05-28 14:15 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-08-04 10:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-04 11:41 . 2009-06-04 11:41 390664 —-a-w- c:\documents and settings\Viet Do\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-06-03 19:09 . 2004-08-04 10:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2007-11-16 21:56 . 2007-09-16 17:22 88 –sha-r- c:\windows\system32\8512A362E6.sys
2007-11-16 22:00 . 2007-09-16 16:52 2516 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-08-17_03.04.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-08-17 03:01 . 2009-08-17 03:01 8192 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
+ 2009-08-18 00:46 . 2009-08-18 00:46 8192 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
+ 2009-08-18 00:46 . 2009-08-18 00:46 8192 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
- 2009-08-17 03:01 . 2009-08-17 03:01 8192 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
+ 2009-08-18 00:46 . 2009-08-18 00:46 442368 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
- 2009-08-17 03:01 . 2009-08-17 03:01 442368 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
- 2009-08-17 03:01 . 2009-08-17 03:01 229376 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
+ 2009-08-18 00:46 . 2009-08-18 00:46 229376 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
+ 2009-08-18 00:46 . 2009-08-18 00:46 229376 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
- 2009-08-17 03:01 . 2009-08-17 03:01 229376 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
+ 2009-08-18 00:46 . 2009-08-18 00:46 11296768 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT
- 2009-08-17 03:01 . 2009-08-17 03:01 11296768 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-19 342848]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 856064]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 376912]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-24 185896]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2007-10-16 585728]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTorrent_DNA\\dna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\@Last Software\\SketchUp 4\\SketchUp.exe"=
"c:\\Program Files\\Autodesk\\VIZ2008\\3dsviz.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\SonicWALL\\SonicWALL Global VPN Client\\SWGVpnClient.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2008\\3dsmax.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [09/05/2009 12:43 57320]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [09/05/2009 12:43 238952]
R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [20/03/2008 13:00 101528]
R2 mi-raysat_VIZ2008_32;mental ray 3.5 Satellite for Autodesk VIZ 2008;c:\program files\Autodesk\VIZ2008\mentalray\satellite\raysat_VIZ2008_32server.exe [07/03/2007 11:32 65536]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [04/06/2009 23:05 648424]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
S3 hcw72ADFilter;WinTV HVR-950 USB Audio Filter Driver;c:\windows\system32\drivers\hcw72ADFilter.sys [03/08/2009 20:41 27904]
S3 hcw72ATV;WinTV HVR-950 NTSC;c:\windows\system32\drivers\hcw72ATV.sys [03/08/2009 20:41 1208448]
S3 hcw72DTV;WinTV HVR-950 ATSC/QAM;c:\windows\system32\drivers\hcw72DTV.sys [08/07/2008 18:41 1200768]
S3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [20/03/2008 13:00 24876]
.
Contents of the 'Scheduled Tasks' folder

2009-05-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-08-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-17 20:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(652)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(6516)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
c:\program files\Trusteer\Rapport\bin\rooksbas.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Virgin Broadband Wireless\AffinegyService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
c:\program files\Common Files\Protexis\License Service\PSIService.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Trusteer\Rapport\bin\RapportService.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2009-08-18 20:57 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-18 00:57
ComboFix2.txt 2009-08-17 03:14

Pre-Run: 41,787,113,472 bytes free
Post-Run: 41,780,195,328 bytes free

346 — E O F — 2009-08-16 07:00
John,

Regarding your backups, we are just about to perform an online virus scan anyway. The best way to make sure they're clean is to plug them in, and make sure they're selected to run in the scan.

Firstly…

1) Manual Upload
Please visit this site and follow the instructions for uploading the C:\QooBox\Quarantine\[4]-[removed] file. (Or something very similar in name)

2) Kaspersky Online
Please do a scan with the Kaspersky Online Scanner

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition
    files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer. <– Ensure here that you are scanning all of your external drives too
  • This will start the program and scan your system.
  • The scan will take a long time, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report

To obtain the report:
  • Click on Save Report As
  • In the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar
  • In Save as type, click the drop arrow and select Text file [*.txt]
  • Click Save

(Note for Internet Explorer users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75%. Once the license has been accepted, reset to 100%.)

3) What You Will Need To Post:
  • Kaspersky log
  • How the PC is performing now
I have already upload the [4]-Submit_2009-08-17_20.39.53.zip to the site provided, with the link to this topic. Kaspersky scanning is in progress. Many thanks.
Below is the Kapersky log. The computer seems to be performing well now, google search is no longer redirecting to other sites. Waiting for further guidance. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Tuesday, August 18, 2009 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, August 18, 2009 04:53:26 Records in database: 2650572 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan statistics: Objects scanned: 328251 Threats found: 11 Infected objects found: 16 Suspicious objects found: 0 Scan duration: 07:32:28 File name / Threat / Threats count C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\SKYNETlyprqptt.sys.vir Infected: Trojan.Win32.TDSS.amve 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETabrnvpmx.dll.vir Infected: Trojan.Win32.Tdss.anus 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETgbiexuml.dll.vir Infected: Trojan.Win32.Tdss.anuv 1 C:\System Volume Information\_restore{B576062A-5477-47FB-9B43-2CF09D0B0DA7}\RP185\A0029832.exe Infected: Trojan-Downloader.Win32.Agent.cmax 1 C:\System Volume Information\_restore{B576062A-5477-47FB-9B43-2CF09D0B0DA7}\RP185\A0029833.exe Infected: Trojan-Downloader.Win32.Agent.cmax 1 C:\System Volume Information\_restore{B576062A-5477-47FB-9B43-2CF09D0B0DA7}\RP189\A0030909.sys Infected: Trojan.Win32.TDSS.amve 1 C:\System Volume Information\_restore{B576062A-5477-47FB-9B43-2CF09D0B0DA7}\RP189\A0030910.dll Infected: Trojan.Win32.Tdss.anus 1 C:\System Volume Information\_restore{B576062A-5477-47FB-9B43-2CF09D0B0DA7}\RP189\A0030911.dll Infected: Trojan.Win32.Tdss.anuv 1 H:\Program Files\Advanced Searchbar\Toolbar.dll Infected: not-a-virus:AdWare.Win32.AmBar.2159 1 H:\Program Files\Common Files\Real\Toolbar\RealBar.dll Infected: not-a-virus:AdWare.Win32.MegaSearch.s 1 H:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL Infected: not-a-virus:AdWare.Win32.MyWay.m 1 H:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch 1 H:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch 1 H:\WINDOWS\Temp\Altnet\mysearch.cab Infected: not-a-virus:AdWare.Win32.MyWay.j 1 H:\WINDOWS\Temp\Altnet\pmexe.cab Infected: not-a-virus:AdWare.Win32.Altnet.h 1 I:\Setup\Camye\fgf150.exe Infected: not-a-virus:AdWare.Win32.Cydoor 1 Selected area has been scanned.
1) P2P Warning
P2P - I see you have P2P software (BTDNA, BitTorrent) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

2) Update Acrobat
Your current version of Adobe Reader is out of date, and may contain security issues. Please uninstall the version you have now from Add/Remove programs, and then download and install the latest Adobe Reader.

3) Update Java
Your version of Java is outdated.

Please download JavaRa to your desktop and unzip it to its own folder

Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
Accept any prompts.
Open JavaRa.exe again and select Search For Updates.
Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

4) CFScript
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File:: 
    I:\Setup\Camye\fgf150.exe
    
    Folder::
    H:\WINDOWS\Temp\Altnet
    H:\Program Files\MyWebSearch
    H:\Program Files\MyWay
    H:\Program Files\Common Files\Real\Toolbar
    H:\Program Files\Advanced Searchbar
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

5) What You Will Need To Post:
  • Combofix log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI