Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
================================================================================
=======================
Kaspersky Log
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, August 27, 2009
Operating system: Microsoft Windows Vista Ultimate Edition, 32-bit Service Pack 2 (build 6002)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, August 27, 2009 07:38:01
Records in database: 2691050
——————————————————————————–
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Push the large [external image: Posted Image] button.
OTM may ask to reboot the machine. Please do so if asked.
Copy/Paste the contents under the [external image: Posted Image] line here in your next reply.
If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
NEXT
Post a fresh DDS and Attach.txt and advise how your computer is running now and if you have any outstanding issues.
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
E:\Setup\Internet - Network\Yahoo Messenger\Boot tool\D-O-Y_Error_v_1_.1 can 1 bot login.rar moved successfully.
E:\Setup\Internet - Network\Yahoo Messenger\Boot tool\R.I.A.D_5.0.rar moved successfully.
E:\Setup\Internet - Network\Yahoo Messenger\Boot tool\www.tina.vn_boom_nick_yahoo.zip moved successfully.
E:\Setup\Mobile devices\N-70 ME\Games\MobileHeart.com-Mosquitos-1228-1124.zip moved successfully.
E:\Setup\Multimedia\Tools\Portable.Mp3Doctor.5.11.049 sua chua file nhac\Portable.Mp3Doctor.5.11.049.EXE moved successfully.
E:\Setup\Security\Crack - Hack\Cracker toolkit.rar moved successfully.
E:\Setup\Security\Crack - Hack\Perfect keylogger\2003.rar moved successfully.
E:\Setup\Security\Crack - Hack\Perfect keylogger\BPK 2007.rar moved successfully.
E:\Setup\Security\Crack - Hack\tim-kiem-keygen.rar moved successfully.
E:\Setup\Security\Crack - Hack\Toxic-Ps2.2 (trojan).zip moved successfully.
E:\Setup\Utilities\Recovery - Hirent Boot\picture doctor.zip moved successfully.
E:\Setup\Window's\Offices\Fonts va Bo go\Bo go tieng viet\(Unikey).zip moved successfully.
========== COMMANDS ==========
DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 3:11:31.86 on Fri 08/28/2009
Internet Explorer: 8.0.6001.18813
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3068.1993 [GMT 7:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-07-30.01)
Microsoft® Windows Vista™ Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 8/16/2009 9:35:35 AM
System Uptime: 8/28/2009 3:05:21 AM (0 hours ago)
Motherboard: Quanta | | 3603
Processor: Intel® Core™2 Duo CPU T9400 @ 2.53GHz | CPU | 2534/1066mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 80 GiB total, 60.171 GiB free.
D: is FIXED (NTFS) - 80 GiB total, 34.204 GiB free.
E: is FIXED (NTFS) - 128 GiB total, 34.885 GiB free.
F: is FIXED (NTFS) - 10 GiB total, 1.666 GiB free.
G: is CDROM ()
H: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
Adobe AIR
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe Color Video Profiles CS CS4
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Linguistics CS4
Adobe Media Player
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Shockwave Player
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Agere Systems HDA Modem
AVerMedia MCE Encoder x86 [removed]
CCleaner (remove only)
Connect
CyberLink YouCam
DigitalPersona Personal 3.0.1
ESET Smart Security
Foxit Reader
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
HP Active Support Library
HP Help and Support
HP Integrated Module with Bluetooth wireless technology 6.0.1.6200
HP MiniCard Hybrid TV [removed]
HP MULTIPLE MODEM INSTALLER for VISTA
HP Quick Launch Buttons 6.40 H2
HP QuickPlay 3.7
HP QuickTouch 1.00 D2
HP Update
HP User Guides 0102
HP Wireless Assistant
HPNetworkAssistant
IDT Audio
Intel® Matrix Storage Manager
Internet Download Manager
Java™ 6 Update 5
Javidic 2008 Final
JMicron JMB38X Flash Media Controller
K-Lite Mega Codec Pack 5.0.5
kuler
L&H TTS3000 British English
L&H TTS3000 Japanese
Lac Viet mtd9 EVA
LacViet mtdCVH 2005
Malwarebytes' Anti-Malware
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.5.2)
muvee autoProducer 6.1
NOD32 v3.0.642 FiX1.2 by TemDono (31 days remaining forever up
NVIDIA Drivers
PDF Settings CS4
Photoshop Camera Raw
Picasa 3
ProDic 2007
ProtectSmart Hard Drive Protection
QuickPlay SlingPlayer 0.4.6
Razer Copperhead
Realtek 8169 8168 8101E 8102E Ethernet Driver
Spyware Doctor 6.1
Suite Shared Configuration CS4
Synaptics Pointing Device Driver
UltraISO Premium V9.33
Unlocker 1.8.7
Validity Sensors software
WinRAR archiver
Yahoo! Messenger
Your Uninstaller! 2008 Version 6.2
==== Event Viewer Messages From Past Week ========
8/28/2009 3:11:22 AM, Error: netbt [4321] - The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did not allow the name to be claimed by this computer.
8/28/2009 3:07:27 AM, Error: Service Control Manager [7022] - The QuickPlay Task Scheduler (QTS) service hung on starting.
8/28/2009 3:07:20 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Eset Nod32 Boot service to connect.
8/28/2009 3:07:20 AM, Error: Service Control Manager [7000] - The Eset Nod32 Boot service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/28/2009 3:04:19 AM, Error: Service Control Manager [7034] - The MBAMService service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:19 AM, Error: Service Control Manager [7031] - The HP Health Check Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/28/2009 3:04:18 AM, Error: Service Control Manager [7034] - The QuickPlay Task Scheduler (QTS) service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:18 AM, Error: Service Control Manager [7034] - The hpqwmiex service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:18 AM, Error: Service Control Manager [7034] - The Com4QLBEx service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The Validity Fingerprint Service service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The QuickPlay Background Capture Service (QBCS) service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The Intel® Matrix Storage Event Monitor service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The HP Service service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The Biometric Authentication Service service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The Audio Service service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The Andrea ST Filters Service service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The Agere Modem Call Progress Audio service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7031] - The ESET Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
8/27/2009 7:40:34 AM, Error: Service Control Manager [7022] - The QuickPlay Background Capture Service (QBCS) service hung on starting.
8/27/2009 6:37:24 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the PEVSystemStart service to connect.
8/27/2009 6:37:22 AM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
8/27/2009 2:40:33 PM, Error: BROWSER [8020] - The browser was unable to promote itself to master browser. The computer that currently believes it is the master browser is unknown.
8/27/2009 11:39:35 AM, Error: BROWSER [8009] - The browser was unable to promote itself to master browser. The computer that currently believes it is the master browser is PC375266281045.
8/27/2009 1:22:57 PM, Error: BROWSER [8019] - The browser was unable to promote itself to master browser. The browser will continue to attempt to promote itself to the master browser, but will no longer log any events in the event log in Event Viewer.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD CSC DfsC ehdrv NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr tdx Wanarpv6
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:26 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
8/26/2009 6:56:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
8/26/2009 6:56:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
8/26/2009 6:56:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
8/26/2009 6:56:50 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
8/26/2009 6:56:43 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
8/26/2009 3:50:03 AM, Error: EventLog [6008] - The previous system shutdown at 3:48:59 AM on 8/26/2009 was unexpected.
8/25/2009 10:32:07 AM, Error: EventLog [6008] - The previous system shutdown at 10:30:44 AM on 8/25/2009 was unexpected.
8/25/2009 10:26:44 AM, Error: EventLog [6008] - The previous system shutdown at 10:24:48 AM on 8/25/2009 was unexpected.
8/25/2009 10:11:20 AM, Error: Service Control Manager [7034] - The PC Tools Security Service service terminated unexpectedly. It has done this 1 time(s).
8/21/2009 3:14:06 AM, Error: Service Control Manager [7030] - The ESET Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
8/21/2009 2:23:13 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service sdrsvc with arguments "" in order to run the server: {47135EEA-06B6-4452-8787-4A187C64A47E}
8/21/2009 1:06:03 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: spldr Wanarpv6
Please download JavaRa to your desktop and unzip it to its own folder.
Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions
Accept any prompts.
Open JavaRa.exe again and select Search For Updates.
Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
Scroll down to the Java SE Runtime Environment (JRE) option.
Download and install the latest Java Runtime Environment (JRE) version for your computer.(version 6, update 16)
NEXT
Follow these steps to uninstall Combofix
Click START then RUN
Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.
[external image: Posted Image]
NEXT
Now to remove the rest of the tools that we have used in fixing your machine:
Make sure you have an Internet Connection.
Download OTC to your desktop and run it
A list of tool components used in the Cleanup of malware will be downloaded.
If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
Click Yes to begin the Cleanup process and remove these components, including this application.
You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
NEXT
Below I have included a number of recommendations for how to protect your computer against malware infections.
It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them
Then consider a password keeper, to keep all your passwords safe.
Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.
SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
Make Internet Explorer more secure
Click Start > Run
Type Inetcpl.cpl & click OK
Click on the Security tab
Click Reset all zones to default level
Make sure the Internet Zone is selected & Click Custom level
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
Next Click OK, then Apply button and then OK to exit the Internet Properties page.
ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
Green to go
Yellow for caution
Red to stop
WOT has an addon available for both Firefox and IE
For Firefox, I highly recommend this add-on to keep your PC even more secure.
NoScript - for blocking ads and other potential website attacks
Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles: Think Prevention. PC Safety and Security–What Do I Need?.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.
Thank you for your patience, and performing all of the procedures requested.
Please respond one last time so we can consider the thread resolved and close it, thank-you.
Oh, thanks for your hints and agree with those.
Uhm, I tell you something about this. My ocpation relates computers, sometimes it is IT. So, I need to know a little about hack, crack, types of virus, trojan, malware… and things like that to prevent Computers of friends, colleagues, offices… and to know how to remove them.
In reality, I download some above to test ( or practice, as you said ), and maybe try when I have free time. But, I almost haven't had time and conditions to practice or deep research. So, I just put them in Setup Folder
Maybe, the infections at this time from WEB of Friend USBs.
After this, I think I need 2 computers, one is clean for work, and one is for test.
I can't concentrate on my work if my Lap isn't clean, therefor you don't know how I'm pleased and thankful for your help.
When I have a problems with harm softwares, I always find the way to Delete them with my own hands, sometimes with the help from the 4rum and Profesionnal or person who has experience about this. Up to this time, I believe that this is the best forum to help about Infections, and you are the best helper ( with me ) .
Once more, I want to say thank to you for what you help me. I also thank malware teams (person who assist in this 4rum), and special thank you, Catbyte. When I detected this Trojan, tried all the methods to kill and was disappointed, I knew you yourself is the person can help me at time I found out this 4rum, and saw your help the same problems of others, with the name catbytes.
I have learn some more about preventions and detections, and deletions from you. From now on, If I have a problem like this I can't solve, I come back here again to ask your help. Because I remember that name, Expert (######) Catbytes in What the Tech 4rum . . You will help me, won't you ?
I Wish you well and every success, and continue your work in the 4rum. Thank you very much
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI