This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] ZoneAlarm keeps shutting down

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I use ZoneAlarm Internet Security Suite version 8.0.298.035 ("ZA") on a computer running Win XP Pro SP3. Something keeps turning off ZA. It is sporadic and I am unable to determine the cause. I only notice that the ZA icon has either disappeared from the Notification area or when I move my cursor to there the icon disappears - in both cases Task Manager confirms that ZA has shut down and I have to restart it. I have prepared the reports in the Quick Start guide and Welcome to New Members - except one. I am unable to generate the RootRepeal report - as soon as I have configured the scan and commenced it (it does appear to start) my computer reboots. I hope some kind person can spare the time to look at my stats and let me know if there is anything ominous lurking on my system.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:09:58 PM, on 24/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\system32\PGPserv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\vsnapvss.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\LinkStash\lsmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PGP Corporation\PGP Desktop\PGPtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\LinkStash\lnkstash.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [LinkStashMonitor] "C:\Program Files\LinkStash\lsmon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Logo Calibration Loader.lnk = C:\Program Files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: PGPtray.exe.lnk = ?
O4 - Global Startup: ProfileReminder.lnk = C:\Program Files\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe
O8 - Extra context menu item: Download Video on This Page - C:\Program Files\Tomato\YouTube Video Downloader\IEPage.html
O8 - Extra context menu item: Download Video This Links To - C:\Program Files\Tomato\YouTube Video Downloader\IELink.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Download Video - {11F19C45-9675-488A-A8E0-8E8234DC245D} - C:\Program Files\Tomato\YouTube Video Downloader\IEPage.html
O9 - Extra 'Tools' menuitem: Download Video on This Page - {11F19C45-9675-488A-A8E0-8E8234DC245D} - C:\Program Files\Tomato\YouTube Video Downloader\IEPage.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229374291328
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229374270453
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: PGPserv - PGP Corporation - C:\WINDOWS\system32\PGPserv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ShadowProtect Service (ShadowProtectSvc) - StorageCraft Technology Corporation - C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: StorageCraft Shadow Copy Provider (VSNAPVSS) - StorageCraft Technology Corporation - C:\WINDOWS\system32\vsnapvss.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

–
End of file - 7625 bytes

DDS Text
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 13:03:20.42 on Mon 24/08/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1578 [GMT 10:00]

AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\system32\PGPserv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\vsnapvss.exe
C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\LinkStash\lsmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PGP Corporation\PGP Desktop\PGPtray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\LinkStash\lnkstash.exe
C:\Documents and Settings\ash\Desktop\dds.scr

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = *.local
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
uRun: [LinkStashMonitor] "c:\program files\linkstash\lsmon.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [AdobeBridge]
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [CTSysVol] c:\program files\creative\sbaudigy ls\surround mixer\CTSysVol.exe /r
mRun: [WD Drive Manager] c:\program files\western digital\wd drive manager\WDBtnMgrUI.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\Hotsync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logoca~1.lnk - c:\program files\gretagmacbeth\i1\eye-one match 3\calibrationloader\CalibrationLoader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pgptra~1.lnk - c:\windows\installer\{6798f012-57c5-49ad-9a9d-4097616f4e1b}\Icon6560581611.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\profil~1.lnk - c:\program files\gretagmacbeth\i1\eye-one match 3\ProfileReminder.exe
IE: Download Video on This Page - c:\program files\tomato\youtube video downloader\IEPage.html
IE: Download Video This Links To - c:\program files\tomato\youtube video downloader\IELink.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {11F19C45-9675-488A-A8E0-8E8234DC245D} - c:\program files\tomato\youtube video downloader\IEPage.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
LSP: c:\windows\system32\PGPlsp.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229374291328
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1229374270453
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
LSA: Notification Packages = scecli PGPpwflt

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\ash\applic~1\mozilla\firefox\profiles\sx4rvg9l.default\
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPOJI610.dll

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 pgpfs;PGP File Sharing;c:\windows\system32\drivers\PGPfsfd.sys [2009-3-4 135736]
R0 PGPwded;PGPwded Storage Filter Service;c:\windows\system32\drivers\PGPwded.sys [2009-3-4 213048]
R0 stcvsm;stcvsm;c:\windows\system32\drivers\stcvsm.sys [2008-10-11 144288]
R1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2009-4-22 150544]
R1 sbmount;StorageCraft Image Mount Driver;c:\windows\system32\drivers\sbmount.sys [2008-10-11 95776]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2008-10-5 353672]
R2 PD91Agent;PD91Agent;c:\program files\raxco\perfectdisk2008\PD91Agent.exe [2008-9-9 693512]
R2 PDIHWCTL;PDIHWCTL;c:\windows\system32\drivers\pdihwctl.sys [2008-10-9 14416]
R2 PGPdisk;PGPdisk;c:\windows\system32\drivers\PGPdisk.sys [2009-3-4 246328]
R2 PGPsdkDriver;PGPsdkDriver;c:\windows\system32\drivers\PGPsdk.sys [2009-3-4 40504]
R2 ShadowProtectSvc;ShadowProtect Service;c:\program files\storagecraft\shadowprotect\ShadowProtectSvc.exe [2008-10-11 1255968]
R2 VSNAPVSS;StorageCraft Shadow Copy Provider;c:\windows\system32\vsnapvss.exe [2008-10-11 70176]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\western digital\wd drive manager\WDBtnMgrSvc.exe [2008-7-24 102400]
S2 aawservice;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" –> c:\program files\lavasoft\ad-aware\aawservice.exe [?]
S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?]
S3 cpuz129;cpuz129;c:\program files\pc wizard 2008\pcwiz32.sys [2008-10-7 9600]
S3 i1display;i1 Display;c:\windows\system32\drivers\i1display.sys [2007-10-18 44344]
S3 PD91Engine;PD91Engine;c:\program files\raxco\perfectdisk2008\PD91Engine.exe [2008-9-9 906504]

============== File Associations ===============

txtfile="c:\program files\jgsoft\editpadlite\EditPadLite.exe" "%1"

=============== Created Last 30 ================

2009-08-24 12:54 –d-h— c:\windows\PIF
2009-08-24 12:07 –d—– c:\program files\Trend Micro
2009-08-22 21:19 –d—– c:\program files\Spybot - Search & Destroy
2009-08-22 21:19 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-08-20 09:04 -cd-h— c:\docume~1\alluse~1\applic~1\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}
2009-08-12 18:38 –d—– C:\!zRecheck
2009-08-11 12:14 –d—– c:\documents and settings\ash\Library
2009-08-10 23:51 –d—– C:\!RealMetArt
2009-08-09 00:09 34,816 a——- C:\Sudoku Table.doc
2009-08-06 13:06 –d—– c:\docume~1\ash\applic~1\Salty Brine
2009-08-06 13:04 874,248 a——- c:\windows\system32\SmartUI2.ocx
2009-08-06 13:04 753,944 a——- c:\windows\system32\wodSmtp.dll
2009-08-06 13:04 413,696 a——- c:\windows\system32\CSHTMLDiffCtl.OCX
2009-08-06 13:04 270,880 a——- c:\windows\system32\MyCommandButton.ocx
2009-08-06 13:04 159,744 a——- c:\windows\system32\stamin32.dll
2009-08-06 13:04 98,304 a——- c:\windows\system32\Loa.dll
2009-08-06 13:04 212,240 a——- c:\windows\system32\RICHTX32.OCX
2009-08-06 13:04 140,488 a——- c:\windows\system32\Comdlg32.ocx
2009-08-06 13:04 –d—– c:\program files\FolderClone
2009-08-05 08:36 –d—– c:\docume~1\alluse~1\applic~1\ViceVersa PRO 2
2009-08-05 08:34 –d—– c:\program files\ViceVersa Pro 2
2009-08-05 01:16 4,096 a–sh— C:\VSM000.IDX
2009-08-04 22:57 –d—– c:\docume~1\ash\applic~1\Malwarebytes
2009-08-04 22:57 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-04 22:57 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-04 22:57 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-04 22:57 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes

==================== Find3M ====================

2009-08-24 13:03 197,094,944 a–sh— c:\windows\system32\drivers\fidbox.dat
2009-08-24 12:32 2,655,416 a–sh— c:\windows\system32\drivers\fidbox.idx
2009-08-23 10:56 4,212 a—h— c:\windows\system32\zllictbl.dat
2009-04-23 22:20 41,552 a——- c:\docume~1\ash\applic~1\GDIPFONTCACHEV1.DAT
2008-10-06 17:12 23 a–sh— c:\windows\system32\ddbfefddaea1_z.dll

============= FINISH: 13:03:57.56 ===============

Attach.txt is attached as Attach.zip (I hope - could not see how to do this clearly - made a stab at it by filling in the "UPLOAD" box)

As requested, the "startuplist.txt" file is not supplied at this time but it has been generated and is available.

Thanks in advance,

Andrew Hart

Attachments:

  • [attachment removed: Attach.zip]

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the Infections Removal forum and wait for help.

Hi Andrew Hart and welcome to What the Tech :)

I'm Dakeyras and I am going to try to assist you with your problem. Please take note of the below:
  • I will start working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine!.
  • The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Refrain from running self fixes as this will hinder the malware removal process.
  • It may prove beneficial if you print of the following instructions or save them to notepad as I post them.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
Next:

  • Please download this tool from Microsoft.
  • Double click on MGADiag.exe to run it.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in. Save this file and post it in your next reply.
Scan with Rooter:

Please download Rooter to your desktop.
  • Double click on Rooter.exe to start the application.
  • Now click on the Scan button.
  • When the scan is completed a text file called Rooter.txt will appear on your desktop, post the contents in your next reply.
  • Now click on Close button to exit Rooter.
Note: The logfile can also be located within this folder Rooter$ at the root of your installed Hard-Drive. EG: C:\Rooter$
  • How is you computer performing now, any further symptoms and or problems encountered?
  • MGADiag' Log.
  • Rooter Log.
  • A new set of DDS logs. <– Post them individually please, IE: one Log per post/reply.
Hi Dakeyras, Thanks for your assistance. I have downloaded and run the programs you suggested and the log files you requested are copied below. I made sure that ZoneAlarm was turned off before running DDS. As to how my computer is running now, it may be too soon to know. I have not noticed ZoneAlarm shutting down since the time of my original post seeking acceptance, but the sporadic nature of this problem is such that it could happen again today or a week from now. So if you learn nothing from the further log files, could you give me an estimate of how long we might be able to continue to correspond before you have to finalise this thread. I realise that you are probably trying to help many others and that our correspondence cannot continue indefinitely. Diagnostic Report (1.9.0011.0): —————————————– WGA Data–> Validation Status: Genuine Validation Code: 0 Cached Validation Code: N/A Windows Product Key: *****-*****-KHTXQ-9GBM6-8XCWG Windows Product Key Hash: 1lcmuR3K5OleNUJx6ZTaqDNh5Gk= Windows Product ID: 55274-OEM-2214311-48746 Windows Product ID Type: 3 Windows License Type: OEM System Builder Windows OS version: 5.1.2600.2.00010100.3.0.pro ID: {A7B0E635-A914-429C-B8F9-0BF687A97D4D}(3) Is Admin: Yes TestCab: 0x0 WGA Version: Registered, 1.9.40.0 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-230-1 Resolution Status: N/A WgaER Data–> ThreatID(s): N/A Version: N/A WGA Notifications Data–> Cached Result: 0 File Exists: Yes Version: 1.9.40.0 WgaTray.exe Signed By: Microsoft WgaLogon.dll Signed By: Microsoft OGA Notifications Data–> Cached Result: 100 Version: 1.7.105.35 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: Microsoft OGA Data–> Office Status: 100 Genuine Microsoft Office XP Professional - 100 Genuine OGA Version: Registered, 1.7.105.35 Signed By: Microsoft Office Diagnostics: 025D1FF3-230-1 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32) Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {A7B0E635-A914-429C-B8F9-0BF687A97D4D}1.9.0011.05.1.2600.2.00010100.3.0.prox32*****-*****-*****-*****-8XCWG55274-OEM-2214311-487463S-1-5-21-1606980848-1965331169-1177238915INTEL_D845EBT2Intel Corp.BT84520A.86A.0024.P10.030808114220030808000000.000000+000158C34AF01842E720C090409E. Australia Standard Time(GMT+10:00)03100 Licensing Data–> N/A HWID Data–> N/A OEM Activation 1.0 Data–> BIOS string matches: yes Marker string from BIOS: 1AACB:GENUINE C&C INC Marker string from OEMBIOS.DAT: N/A, hr = 0x80004005 OEM Activation 2.0 Data–> N/A Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully … . Windows XP . (5.1.2600) Service Pack 3 [32_bits] - x86 Family 15 Model 2 Stepping 7, GenuineIntel . [wscsvc] (Security Center) RUNNING (state:4) [SharedAccess] RUNNING (state:4) Windows Firewall -> Disabled ! . Internet Explorer 7.0.5730.13 . A:\ [Removable] C:\ [Fixed-NTFS] .. ( Total:149 Go - Free:137 Go ) D:\ [Fixed-NTFS] .. ( Total:5 Go - Free:5 Go ) E:\ [Fixed-NTFS] .. ( Total:9 Go - Free:3 Go ) F:\ [Fixed-NTFS] .. ( Total:255 Go - Free:100 Go ) G:\ [Fixed-NTFS] .. ( Total:101 Go - Free:13 Go ) R:\ [CD_Rom] S:\ [CD_Rom] . Scan : 14:31.42 Path : C:\Documents and Settings\ash\Desktop\Rooter.exe User : ash ( Administrator -> YES ) . ———————-\\ Processes . Locked [System Process] (0) ______ System (4) ______ \SystemRoot\System32\smss.exe (492) ______ \??\C:\WINDOWS\system32\csrss.exe (744) ______ \??\C:\WINDOWS\system32\winlogon.exe (768) ______ C:\WINDOWS\system32\services.exe (812) ______ C:\WINDOWS\system32\lsass.exe (824) ______ C:\WINDOWS\system32\svchost.exe (980) ______ C:\WINDOWS\system32\svchost.exe (1048) ______ C:\WINDOWS\System32\svchost.exe (1144) ______ C:\WINDOWS\system32\svchost.exe (1244) ______ C:\WINDOWS\system32\svchost.exe (1404) Locked vsmon.exe (1480) Locked ScanningProcess.exe (1756) ______ C:\WINDOWS\system32\spoolsv.exe (1824) ______ C:\WINDOWS\system32\svchost.exe (1968) ______ C:\WINDOWS\system32\CTsvcCDA.exe (2032) ______ C:\WINDOWS\system32\nvsvc32.exe (196) ______ C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe (236) ______ C:\WINDOWS\system32\PGPserv.exe (372) ______ C:\WINDOWS\system32\HPZipm12.exe (548) ______ C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe (600) ______ C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe (696) ______ C:\WINDOWS\system32\svchost.exe (724) ______ C:\WINDOWS\System32\vssvc.exe (136) ______ C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (1012) ______ C:\WINDOWS\system32\MsPMSPSv.exe (1128) ______ C:\WINDOWS\system32\vsnapvss.exe (1236) ______ C:\WINDOWS\System32\alg.exe (1992) ______ C:\WINDOWS\Explorer.EXE (2952) ______ C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (3296) ______ C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe (3356) ______ C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (3372) ______ C:\WINDOWS\system32\RUNDLL32.EXE (3612) Locked zlclient.exe (3696) ______ C:\Program Files\LinkStash\lsmon.exe (360) ______ C:\WINDOWS\system32\ctfmon.exe (868) ______ C:\Program Files\PGP Corporation\PGP Desktop\PGPtray.exe (3524) ______ C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe (692) ______ C:\Program Files\Mozilla Firefox\firefox.exe (2232) ______ C:\Program Files\LinkStash\lnkstash.exe (2528) ______ C:\Program Files\Microsoft Office\Office10\WINWORD.EXE (2472) ______ C:\Documents and Settings\ash\Desktop\Rooter.exe (4088) . ———————-\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 –[ MBR ]– (Start_Offset:32256 | Length:160031015424) . ———————-\\ Scheduled Tasks . C:\WINDOWS\Tasks\desktop.ini C:\WINDOWS\Tasks\OGADaily.job C:\WINDOWS\Tasks\OGALogon.job C:\WINDOWS\Tasks\SA.DAT . ———————-\\ Registry . . ———————-\\ Files & Folders . ———————-\\ Scan completed at 14:31.49 . C:\Rooter$\Rooter_1.txt - (30/08/2009 | 14:31.49) DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 14:52:21.70 on Sun 30/08/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1577 [GMT 10:00] AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF} FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe C:\WINDOWS\system32\PGPserv.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\vssvc.exe C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\system32\vsnapvss.exe C:\WINDOWS\Explorer.EXE C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\LinkStash\lsmon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\PGP Corporation\PGP Desktop\PGPtray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\LinkStash\lnkstash.exe C:\Documents and Settings\ash\Desktop\dds.scr ============== Pseudo HJT Report =============== uInternet Settings,ProxyOverride = *.local BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll uRun: [LinkStashMonitor] "c:\program files\linkstash\lsmon.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [AdobeBridge] mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [CTSysVol] c:\program files\creative\sbaudigy ls\surround mixer\CTSysVol.exe /r mRun: [WD Drive Manager] c:\program files\western digital\wd drive manager\WDBtnMgrUI.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\Hotsync.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logoca~1.lnk - c:\program files\gretagmacbeth\i1\eye-one match 3\calibrationloader\CalibrationLoader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pgptra~1.lnk - c:\windows\installer\{6798f012-57c5-49ad-9a9d-4097616f4e1b}\Icon6560581611.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\profil~1.lnk - c:\program files\gretagmacbeth\i1\eye-one match 3\ProfileReminder.exe IE: Download Video on This Page - c:\program files\tomato\youtube video downloader\IEPage.html IE: Download Video This Links To - c:\program files\tomato\youtube video downloader\IELink.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {11F19C45-9675-488A-A8E0-8E8234DC245D} - c:\program files\tomato\youtube video downloader\IEPage.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll LSP: c:\windows\system32\PGPlsp.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229374291328 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1229374270453 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll LSA: Notification Packages = scecli PGPpwflt ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\ash\applic~1\mozilla\firefox\profiles\sx4rvg9l.default\ FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava11.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava12.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava13.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava14.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava32.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPOJI610.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 pgpfs;PGP File Sharing;c:\windows\system32\drivers\PGPfsfd.sys [2009-3-4 135736] R0 PGPwded;PGPwded Storage Filter Service;c:\windows\system32\drivers\PGPwded.sys [2009-3-4 213048] R0 stcvsm;stcvsm;c:\windows\system32\drivers\stcvsm.sys [2008-10-11 144288] R1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2009-4-22 150544] R1 sbmount;StorageCraft Image Mount Driver;c:\windows\system32\drivers\sbmount.sys [2008-10-11 95776] R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2008-10-5 353672] R2 PD91Agent;PD91Agent;c:\program files\raxco\perfectdisk2008\PD91Agent.exe [2008-9-9 693512] R2 PDIHWCTL;PDIHWCTL;c:\windows\system32\drivers\pdihwctl.sys [2008-10-9 14416] R2 PGPdisk;PGPdisk;c:\windows\system32\drivers\PGPdisk.sys [2009-3-4 246328] R2 PGPsdkDriver;PGPsdkDriver;c:\windows\system32\drivers\PGPsdk.sys [2009-3-4 40504] R2 ShadowProtectSvc;ShadowProtect Service;c:\program files\storagecraft\shadowprotect\ShadowProtectSvc.exe [2008-10-11 1255968] R2 VSNAPVSS;StorageCraft Shadow Copy Provider;c:\windows\system32\vsnapvss.exe [2008-10-11 70176] R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\western digital\wd drive manager\WDBtnMgrSvc.exe [2008-7-24 102400] S2 aawservice;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" –> c:\program files\lavasoft\ad-aware\aawservice.exe [?] S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?] S3 cpuz129;cpuz129;c:\program files\pc wizard 2008\pcwiz32.sys [2008-10-7 9600] S3 i1display;i1 Display;c:\windows\system32\drivers\i1display.sys [2007-10-18 44344] S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\28.tmp –> c:\windows\system32\28.tmp [?] S3 PD91Engine;PD91Engine;c:\program files\raxco\perfectdisk2008\PD91Engine.exe [2008-9-9 906504] S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys –> c:\windows\system32\drivers\rootrepeal.sys [?] ============== File Associations =============== txtfile="c:\program files\jgsoft\editpadlite\EditPadLite.exe" "%1" =============== Created Last 30 ================ 2009-08-25 21:06 –d—– c:\program files\Sophos 2009-08-24 12:54 –d-h— c:\windows\PIF 2009-08-24 12:07 –d—– c:\program files\Trend Micro 2009-08-22 21:19 –d—– c:\program files\Spybot - Search & Destroy 2009-08-22 21:19 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-08-20 09:04 -cd-h— c:\docume~1\alluse~1\applic~1\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD} 2009-08-12 18:38 –d—– C:\!zRecheck 2009-08-11 12:14 –d—– c:\documents and settings\ash\Library 2009-08-10 23:51 –d—– C:\!RealMetArt 2009-08-09 00:09 34,816 a——- C:\Sudoku Table.doc 2009-08-06 13:06 –d—– c:\docume~1\ash\applic~1\Salty Brine 2009-08-06 13:04 874,248 a——- c:\windows\system32\SmartUI2.ocx 2009-08-06 13:04 753,944 a——- c:\windows\system32\wodSmtp.dll 2009-08-06 13:04 413,696 a——- c:\windows\system32\CSHTMLDiffCtl.OCX 2009-08-06 13:04 270,880 a——- c:\windows\system32\MyCommandButton.ocx 2009-08-06 13:04 159,744 a——- c:\windows\system32\stamin32.dll 2009-08-06 13:04 98,304 a——- c:\windows\system32\Loa.dll 2009-08-06 13:04 212,240 a——- c:\windows\system32\RICHTX32.OCX 2009-08-06 13:04 140,488 a——- c:\windows\system32\Comdlg32.ocx 2009-08-06 13:04 –d—– c:\program files\FolderClone 2009-08-05 01:16 4,096 a–sh— C:\VSM000.IDX 2009-08-04 22:57 –d—– c:\docume~1\ash\applic~1\Malwarebytes 2009-08-04 22:57 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-04 22:57 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-04 22:57 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-04 22:57 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes ==================== Find3M ==================== 2009-08-30 14:49 198,191,648 a–sh— c:\windows\system32\drivers\fidbox.dat 2009-08-30 03:09 2,669,984 a–sh— c:\windows\system32\drivers\fidbox.idx 2009-08-23 10:56 4,212 a—h— c:\windows\system32\zllictbl.dat 2009-04-23 22:20 41,552 a——- c:\docume~1\ash\applic~1\GDIPFONTCACHEV1.DAT 2008-10-06 17:12 23 a–sh— c:\windows\system32\ddbfefddaea1_z.dll ============= FINISH: 14:52:53.21 =============== All done correctly, I trust, Andrew Hart
Hi :)

Please except my sincere apology, somehow I overlooked the email notification that you had replied to this topic.

RE:

So if you learn nothing from the further log files, could you give me an estimate of how long we might be able to continue to correspond before you have to finalise this thread. I realise that you are probably trying to help many others and that our correspondence cannot continue indefinitely.

Even though I provide my assistance on a volunteer basis I will do my up most to resolve the issues you are currently experiencing with your machine.

Before we start:

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start.

ZoneAlarm Internet Security Suite Advice/Query:

Are you using the Anti-Virus component with this application? If so My advice would be to disable this part and install a stand alone Anti-Virus application. Just answer my query for now please in your next reply.

Next:

Older Java installations pose a security risk and provide a means for malware to both infect/re-infect a system. We will update this in due course.

Now please go to Start >> Control Panel >> Add/Remove Programs and remove the following (if present):

J2SE Runtime Environment 5.0 Update 6

To do so, click once on each of the above in turn to highlight and then click on the Remove button.

Note: Take extra care in answering questions posed by any Uninstaller. Some questions may be worded to deceive you into keeping the program.

Download/Run ComboFix:

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Please include the C:\ComboFix.txt in your next reply for further review.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.
This tool is not a toy and not for everyday use. ComboFix SHOULD NOT be used unless requested by a forum helper


When completed the above, please post back the following in the order asked for:
  • How is you computer performing now, any other symptoms and or problems encountered?
  • ComboFix Log.
  • A new DDS Log.
Hi Dakeyras, Yes, I am using the Anti-virus component of ZA. I use ZoneAlarm Internet Security Suite (ZAISS) because it not only provides a one-stop solution to combat viruses and spyware but also one of the best software firewalls in the world. I don't want to use another anti-virus product and so disabling the anti-virus component of ZAISS (if indeed that is possible) is simply not acceptable. The whole point of my turning to this forum for help is to allow me to continue to use each and every component of ZAISS. Regarding Java, I'm afraid I can't uninstall my old Java without replacing it immediately because a number of programs I run (and a number of internet sites I regularly visit) require it to be installed. Is it OK, from your diagnostic point of view, if I do actually immediately replace Java with the latest version? If so, I will then attend to the rest of your requests in your last reply. Andrew Hart
Hi :)

OK I can appreciate your stance concerning the ZA application, from my point of view using bundled all in one security applications does not provide overall adequate protection. However end of the day all I can to is give my free advice and it is your computer after all. If you wish to continue using every feature of the ZoneAlarm Internet Security, that is your prerogative and I will respect that.

Concerning Java, I have a certain way with which I approach malware removal. Personally I do advice keep your online activities to a bare minimum during the course of the malware removal process.

Taking this into account we can update Java now, do make sure to to uninstall the older version first.

New Java Installation:
  • Click here to visit Java's website.
  • Scroll down to Java SE Runtime Environment (JRE) 6 Update 16. Click on Download.
  • Select Windows from the drop-down list for Platform.
  • Select Multi-language from the drop-down list for Language.
  • Check (tick) I agree to the Java SE Runtime Environment 6 License Agreement box and click on Continue.
  • Click on jre-6u16-windows-i586-p.exe link to download it and save this to a convenient location.
  • Double click on jre-6u16-windows-i586-p.exe to install Java.
Next:

Now please carry out my instructions concerning Download/Run ComboFix and post back in your next reply the logs I requested, thank you.
Hi Dakeyras,

Thanks for your quick response and your understanding of my desire to keep using all parts of ZAISS. Point taken about limiting Internet browsing as much as possible while we try to solve possible malware problems.

I have in fact done what you requested initially - that is, uninstalling old JRE 5.0 Update 6 and then running ComboFix and DDS before reinstalling latest version of JRE ver 6 update 16. Unfortunately I forgot to save the DDS report and had to run it a second time - but that was done AFTER I had installed JRE 6/16 - hope this is OK. Please find copies of the reports below. I did remember to close ZAISS before running DDS.

ComboFix 09-09-01.04 - ash 02/09/2009 17:42.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1685 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Installer\25ee9.msp
c:\windows\Installer\25ef8.msp
c:\windows\system32\Data

.
((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.

2009-09-02 03:29 . 2009-09-02 03:29 ——– d—–w- C:\!Dummy4
2009-09-02 03:29 . 2009-09-02 03:29 ——– d—–w- C:\!Dummy3
2009-09-02 03:28 . 2009-09-02 03:28 ——– d—–w- C:\!Dummy2
2009-09-02 03:28 . 2009-09-02 03:28 ——– d—–w- C:\!Dummy1
2009-08-31 07:13 . 2009-08-31 07:13 13502 —-a-r- c:\documents and settings\ash\Application Data\Microsoft\Installer\{AD871377-A1A3-4D7B-AA5E-EB163E1202C6}\ARPPRODUCTICON.exe
2009-08-31 07:13 . 2009-08-31 07:13 ——– d—–w- c:\program files\Kodak
2009-08-31 07:13 . 2009-08-31 07:13 ——– d—–w- C:\PHOTOSHOP50_DIR
2009-08-25 11:06 . 2009-08-25 11:06 ——– d—–w- c:\program files\Sophos
2009-08-24 02:54 . 2009-08-24 02:54 ——– d–h–w- c:\windows\PIF
2009-08-24 02:07 . 2009-08-24 04:06 ——– d—–w- c:\program files\Trend Micro
2009-08-22 11:19 . 2009-08-26 09:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-22 11:19 . 2009-08-22 11:33 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-22 01:31 . 2009-08-22 01:31 ——– d—–w- c:\program files\QuickTime
2009-08-22 01:31 . 2009-08-22 01:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-19 23:02 . 2009-08-19 23:02 ——– d—–w- c:\documents and settings\ash\Local Settings\Application Data\PackageAware
2009-08-11 02:14 . 2009-08-11 02:14 ——– d—–w- c:\documents and settings\ash\Library
2009-08-06 03:06 . 2009-08-06 03:06 ——– d—–w- c:\documents and settings\ash\Application Data\Salty Brine
2009-08-06 03:04 . 2007-11-13 03:09 98304 —-a-w- c:\windows\system32\Loa.dll
2009-08-06 03:04 . 2007-02-11 13:15 753944 —-a-w- c:\windows\system32\wodSmtp.dll
2009-08-06 03:04 . 2005-07-06 23:57 159744 —-a-w- c:\windows\system32\stamin32.dll
2009-08-06 03:04 . 2009-08-06 03:05 ——– d—–w- c:\program files\FolderClone
2009-08-04 12:58 . 2009-08-04 12:58 3942048 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-04 12:57 . 2009-08-04 12:57 ——– d—–w- c:\documents and settings\ash\Application Data\Malwarebytes
2009-08-04 12:57 . 2009-08-03 03:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-04 12:57 . 2009-08-04 12:58 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-04 12:57 . 2009-08-04 12:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-04 12:57 . 2009-08-03 03:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-02 07:48 . 2008-10-05 05:07 200936992 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-02 07:38 . 2008-10-11 06:42 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-02 07:36 . 2008-10-05 05:07 2704592 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-27 12:49 . 2008-10-10 09:04 ——– d—–w- c:\program files\Password Safe
2009-08-23 00:56 . 2008-10-05 05:03 4212 —ha-w- c:\windows\system32\zllictbl.dat
2009-08-22 01:21 . 2008-10-09 08:09 ——– d—–w- c:\program files\HyperSnap 6
2009-08-22 01:12 . 2008-10-10 04:09 ——– d—–w- c:\program files\Easy CD-DA Extractor 12
2009-08-22 01:10 . 2008-11-24 08:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Easy CD-DA Extractor
2009-08-19 23:04 . 2009-08-19 23:04 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}
2009-08-19 23:04 . 2008-10-07 22:22 ——– d—–w- c:\program files\Thumbs7
2009-08-19 23:04 . 2008-10-07 22:23 ——– d—–w- c:\program files\Common Files\Nikon
2009-08-06 17:08 . 2009-08-19 23:04 3208116 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\tp_digicam40.exe
2009-07-30 18:48 . 2009-08-19 23:04 394752 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\OFFLINE\B462DC4F\F536666A\dcraw.exe
2009-07-30 18:48 . 2009-08-19 23:04 365568 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\OFFLINE\F5337325\F536666A\dcraw64.exe
2009-07-30 18:48 . 2009-08-19 23:04 365568 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\OFFLINE\AE93CF7F\F536666A\dcraw64.exe
2009-07-30 18:48 . 2009-08-19 23:04 394752 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\OFFLINE\8FC6884B\F536666A\dcraw.exe
2009-07-05 03:08 . 2008-10-07 10:38 ——– d—–w- c:\program files\cpuz
2009-07-04 12:06 . 2009-08-19 23:04 2619904 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\OFFLINE\8AE82C9B\F536666A\PolyImagePro.dll
2009-07-04 12:06 . 2009-08-19 23:04 2619904 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\OFFLINE\5477498E\F536666A\PolyImagePro.dll
2008-10-06 07:12 . 2008-10-06 07:12 23 –sha-w- c:\windows\system32\ddbfefddaea1_z.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IconOverlayHandlerAccessible]
@="{3DBF5F01-3287-46EB-82CF-45AA5C241162}"
[HKEY_CLASSES_ROOT\CLSID\{3DBF5F01-3287-46EB-82CF-45AA5C241162}]
2009-03-04 09:19 612920 —-a-w- c:\windows\system32\PGPfsshl.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LinkStashMonitor"="c:\program files\LinkStash\lsmon.exe" [2007-11-02 69848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"CTSysVol"="c:\program files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe" [2003-05-01 57344]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-07-24 450560]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2009-03-11 611712]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-03-31 982408]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]
Logo Calibration Loader.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe [2008-10-9 708608]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
PGPtray.exe.lnk - c:\windows\Installer\{6798F012-57C5-49AD-9A9D-4097616F4E1B}\Icon6560581611.exe [2009-4-18 55296]
ProfileReminder.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe [2008-10-9 954368]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli PGPpwflt

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R0 pgpfs;PGP File Sharing;c:\windows\system32\drivers\PGPfsfd.sys [4/03/2009 7:19 PM 135736]
R0 PGPwded;PGPwded Storage Filter Service;c:\windows\system32\drivers\PGPwded.sys [4/03/2009 7:19 PM 213048]
R0 stcvsm;stcvsm;c:\windows\system32\drivers\stcvsm.sys [11/10/2008 5:37 PM 144288]
R1 sbmount;StorageCraft Image Mount Driver;c:\windows\system32\drivers\sbmount.sys [11/10/2008 5:37 PM 95776]
R2 PDIHWCTL;PDIHWCTL;c:\windows\system32\drivers\pdihwctl.sys [9/10/2008 7:06 PM 14416]
R2 PGPdisk;PGPdisk;c:\windows\system32\drivers\PGPdisk.sys [4/03/2009 7:19 PM 246328]
R2 PGPsdkDriver;PGPsdkDriver;c:\windows\system32\drivers\PGPsdk.sys [4/03/2009 7:19 PM 40504]
R2 VSNAPVSS;StorageCraft Shadow Copy Provider;c:\windows\system32\vsnapvss.exe [11/10/2008 5:37 PM 70176]
S2 PD91Agent;PD91Agent;c:\program files\Raxco\PerfectDisk2008\PD91Agent.exe [9/09/2008 1:49 PM 693512]
S2 ShadowProtectSvc;ShadowProtect Service;c:\program files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe [11/10/2008 5:37 PM 1255968]
S2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [24/07/2008 3:22 PM 102400]
S3 cpuz129;cpuz129;c:\program files\PC Wizard 2008\pcwiz32.sys [7/10/2008 8:36 PM 9600]
S3 i1display;i1 Display;c:\windows\system32\drivers\i1display.sys [18/10/2007 5:35 PM 44344]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\28.tmp –> c:\windows\system32\28.tmp [?]
S3 PD91Engine;PD91Engine;c:\program files\Raxco\PerfectDisk2008\PD91Engine.exe [9/09/2008 1:49 PM 906504]
.
Contents of the 'Scheduled Tasks' folder

2009-09-02 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 07:04]

2009-09-02 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 07:04]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-AdobeBridge - (no file)


.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: Download Video on This Page - c:\program files\Tomato\YouTube Video Downloader\IEPage.html
IE: Download Video This Links To - c:\program files\Tomato\YouTube Video Downloader\IELink.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{11F19C45-9675-488A-A8E0-8E8234DC245D} - c:\program files\Tomato\YouTube Video Downloader\IEPage.html
LSP: c:\windows\system32\PGPlsp.dll
FF - ProfilePath - c:\documents and settings\ash\Application Data\Mozilla\Firefox\Profiles\sx4rvg9l.default\
.
.
——- File Associations ——-
.
txtfile="c:\program files\JGsoft\EditPadLite\EditPadLite.exe" "%1"
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-02 17:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\28.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1606980848-1965331169-1177238915-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2009-09-02 17:50
ComboFix-quarantined-files.txt 2009-09-02 07:50

Pre-Run: 149,120,471,040 bytes free
Post-Run: 149,095,358,464 bytes free

177


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 23:36:40.90 on Wed 02/09/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1614 [GMT 10:00]

AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\system32\PGPserv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\vsnapvss.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\LinkStash\lsmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PGP Corporation\PGP Desktop\PGPtray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\ash\Desktop\dds.scr

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = *.local
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [LinkStashMonitor] "c:\program files\linkstash\lsmon.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [CTSysVol] c:\program files\creative\sbaudigy ls\surround mixer\CTSysVol.exe /r
mRun: [WD Drive Manager] c:\program files\western digital\wd drive manager\WDBtnMgrUI.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\Hotsync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logoca~1.lnk - c:\program files\gretagmacbeth\i1\eye-one match 3\calibrationloader\CalibrationLoader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pgptra~1.lnk - c:\windows\installer\{6798f012-57c5-49ad-9a9d-4097616f4e1b}\Icon6560581611.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\profil~1.lnk - c:\program files\gretagmacbeth\i1\eye-one match 3\ProfileReminder.exe
IE: Download Video on This Page - c:\program files\tomato\youtube video downloader\IEPage.html
IE: Download Video This Links To - c:\program files\tomato\youtube video downloader\IELink.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {11F19C45-9675-488A-A8E0-8E8234DC245D} - c:\program files\tomato\youtube video downloader\IEPage.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
LSP: c:\windows\system32\PGPlsp.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229374291328
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1229374270453
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
LSA: Notification Packages = scecli PGPpwflt

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\ash\applic~1\mozilla\firefox\profiles\sx4rvg9l.default\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 pgpfs;PGP File Sharing;c:\windows\system32\drivers\PGPfsfd.sys [2009-3-4 135736]
R0 PGPwded;PGPwded Storage Filter Service;c:\windows\system32\drivers\PGPwded.sys [2009-3-4 213048]
R0 stcvsm;stcvsm;c:\windows\system32\drivers\stcvsm.sys [2008-10-11 144288]
R1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2009-4-22 150544]
R1 sbmount;StorageCraft Image Mount Driver;c:\windows\system32\drivers\sbmount.sys [2008-10-11 95776]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2008-10-5 353672]
R2 PD91Agent;PD91Agent;c:\program files\raxco\perfectdisk2008\PD91Agent.exe [2008-9-9 693512]
R2 PDIHWCTL;PDIHWCTL;c:\windows\system32\drivers\pdihwctl.sys [2008-10-9 14416]
R2 PGPdisk;PGPdisk;c:\windows\system32\drivers\PGPdisk.sys [2009-3-4 246328]
R2 PGPsdkDriver;PGPsdkDriver;c:\windows\system32\drivers\PGPsdk.sys [2009-3-4 40504]
R2 ShadowProtectSvc;ShadowProtect Service;c:\program files\storagecraft\shadowprotect\ShadowProtectSvc.exe [2008-10-11 1255968]
R2 VSNAPVSS;StorageCraft Shadow Copy Provider;c:\windows\system32\vsnapvss.exe [2008-10-11 70176]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\western digital\wd drive manager\WDBtnMgrSvc.exe [2008-7-24 102400]
S2 aawservice;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" –> c:\program files\lavasoft\ad-aware\aawservice.exe [?]
S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?]
S3 cpuz129;cpuz129;c:\program files\pc wizard 2008\pcwiz32.sys [2008-10-7 9600]
S3 i1display;i1 Display;c:\windows\system32\drivers\i1display.sys [2007-10-18 44344]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\28.tmp –> c:\windows\system32\28.tmp [?]
S3 PD91Engine;PD91Engine;c:\program files\raxco\perfectdisk2008\PD91Engine.exe [2008-9-9 906504]

============== File Associations ===============

txtfile="c:\program files\jgsoft\editpadlite\EditPadLite.exe" "%1"

=============== Created Last 30 ================

2009-09-02 23:28 73,728 a——- c:\windows\system32\javacpl.cpl
2009-09-02 23:28 411,368 a——- c:\windows\system32\deploytk.dll
2009-09-02 17:48 -cd—– c:\windows\system32\dllcache\cache
2009-09-02 17:41 229,376 a——- c:\windows\PEV.exe
2009-09-02 17:41 161,792 a——- c:\windows\SWREG.exe
2009-09-02 17:41 98,816 a——- c:\windows\sed.exe
2009-09-02 17:41 –ds—- C:\ComboFix
2009-09-02 13:29 –d—– C:\!Dummy4
2009-09-02 13:29 –d—– C:\!Dummy3
2009-09-02 13:28 –d—– C:\!Dummy2
2009-09-02 13:28 –d—– C:\!Dummy1
2009-08-31 17:13 –d—– c:\program files\Kodak
2009-08-31 17:13 –d—– C:\PHOTOSHOP50_DIR
2009-08-25 21:06 –d—– c:\program files\Sophos
2009-08-24 12:54 –d-h— c:\windows\PIF
2009-08-24 12:07 –d—– c:\program files\Trend Micro
2009-08-22 21:19 –d—– c:\program files\Spybot - Search & Destroy
2009-08-22 21:19 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-08-20 09:04 -cd-h— c:\docume~1\alluse~1\applic~1\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}
2009-08-11 12:14 –d—– c:\documents and settings\ash\Library
2009-08-09 00:09 34,816 a——- C:\Sudoku Table.doc
2009-08-06 13:06 –d—– c:\docume~1\ash\applic~1\Salty Brine
2009-08-06 13:04 874,248 a——- c:\windows\system32\SmartUI2.ocx
2009-08-06 13:04 753,944 a——- c:\windows\system32\wodSmtp.dll
2009-08-06 13:04 413,696 a——- c:\windows\system32\CSHTMLDiffCtl.OCX
2009-08-06 13:04 270,880 a——- c:\windows\system32\MyCommandButton.ocx
2009-08-06 13:04 159,744 a——- c:\windows\system32\stamin32.dll
2009-08-06 13:04 98,304 a——- c:\windows\system32\Loa.dll
2009-08-06 13:04 212,240 a——- c:\windows\system32\RICHTX32.OCX
2009-08-06 13:04 140,488 a——- c:\windows\system32\Comdlg32.ocx
2009-08-06 13:04 –d—– c:\program files\FolderClone
2009-08-05 01:16 4,096 a–sh— C:\VSM000.IDX
2009-08-04 22:57 –d—– c:\docume~1\ash\applic~1\Malwarebytes
2009-08-04 22:57 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-04 22:57 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-04 22:57 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-04 22:57 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes

==================== Find3M ====================

2009-09-02 23:34 201,374,240 a–sh— c:\windows\system32\drivers\fidbox.dat
2009-09-02 23:30 2,713,688 a–sh— c:\windows\system32\drivers\fidbox.idx
2009-08-23 10:56 4,212 a—h— c:\windows\system32\zllictbl.dat
2009-04-23 22:20 41,552 a——- c:\docume~1\ash\applic~1\GDIPFONTCACHEV1.DAT
2008-10-06 17:12 23 a–sh— c:\windows\system32\ddbfefddaea1_z.dll

============= FINISH: 23:37:14.18 ===============


Thanks again for your assistance - it is very much appreciated.

Andrew Hart
Hi :)

Thanks for your quick response and your understanding of my desire to keep using all parts of ZAISS. Point taken about limiting Internet browsing as much as possible while we try to solve possible malware problems.

You're welcome!

I have in fact done what you requested initially - that is, uninstalling old JRE 5.0 Update 6 and then running ComboFix and DDS before reinstalling latest version of JRE ver 6 update 16. Unfortunately I forgot to save the DDS report and had to run it a second time - but that was done AFTER I had installed JRE 6/16 - hope this is OK. Please find copies of the reports below. I did remember to close ZAISS before running DDS.

Thats fine and not a problem.

Custom ComboFix-Script:

A word of warning: Please do not run ComboFix on your own. This tool is not a toy and not for everyday use.
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    File::
    c:\windows\system32\ddbfefddaea1_z.dll
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5353:TCP"=-
    [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa] 
    "Notification Packages"=hex(7):73,63,65,63,6c,69,00,00
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Malwarebytes Anti-Malware:

  • Launch the application, Check for Updates >> Perform a Quick Scan
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Run Kaspersky Online AV Scanner:

Go to this Kaspersky website and perform an online antivirus scan.

Note: Use Internet Explorer for this scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
This online tuturial will help explain how to use the aforementioned online scan.

When completed the above, please post back the following:
  • How is you computer performing now? Any problems encountered and or any further symptoms?
  • ComboFix Log.
  • Malwarebytes Anti-Malware Log.
  • Kaspersky report.
Still here and kicking!

The reports you requested are below.

Please note that with respect to the latest ComboFix test, once commenced it informed me that a newer version was available and did I want to update? I said "No", not wanting to interrupt the test. Regarding the Kaspersky report (2 hours to download and about 1 hour 45 mins to run - phew!!), ZAISS also picked up the same reported infections about a year ago on a full deep scan which included scanning archives, and I think that they might all be false positives. None of the programs in these archives are installed on my computer - they are all simply stored on my E:\ drive. I used the Time and Date changing program about 18 months to 2 years ago but then uninstalled it as I had no further use for it at that time. However, it was very useful and helpful. It caused me no problems whilst installed. I have never installed any of the other programs. If you think that I should delete one or more of these archives then of course I will.

Dakeyras, at some point would you be able to tell me what conclusions you have reached from all the tests and reports you have had me run and generate? Have we made any progress - for example, do you think that I had, or still have, some malware on my system which caused the shutting down of ZAISS, and if so, what was/is it? I am very keen to understand as much as possible, as long as attempting to explain things to me does not cause you too much additional work. BTW, I have still not had any further experience of ZAISS shutting down unexpectedly. No other problems with my system except those caused by running ComboFix ( these are easily fixed - things like deleting cascading menus and changing my default browser from Firefox to Internet Explorer).

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

ComboFix 09-09-01.04 - ash 03/09/2009 9:30.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1642 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\ash\Desktop\CFScript.txt
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

FILE ::
"c:\windows\system32\ddbfefddaea1_z.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\ddbfefddaea1_z.dll

.
((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.

2009-09-02 13:28 . 2009-09-02 13:28 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-09-02 13:28 . 2009-09-02 13:28 ——– d—–w- c:\program files\Java
2009-09-02 13:27 . 2009-09-02 13:27 152576 —-a-w- c:\documents and settings\ash\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-09-02 03:29 . 2009-09-02 03:29 ——– d—–w- C:\!Dummy4
2009-09-02 03:29 . 2009-09-02 03:29 ——– d—–w- C:\!Dummy3
2009-09-02 03:28 . 2009-09-02 03:28 ——– d—–w- C:\!Dummy2
2009-09-02 03:28 . 2009-09-02 03:28 ——– d—–w- C:\!Dummy1
2009-08-31 07:13 . 2009-08-31 07:13 13502 —-a-r- c:\documents and settings\ash\Application Data\Microsoft\Installer\{AD871377-A1A3-4D7B-AA5E-EB163E1202C6}\ARPPRODUCTICON.exe
2009-08-31 07:13 . 2009-08-31 07:13 ——– d—–w- c:\program files\Kodak
2009-08-31 07:13 . 2009-08-31 07:13 ——– d—–w- C:\PHOTOSHOP50_DIR
2009-08-25 11:06 . 2009-08-25 11:06 ——– d—–w- c:\program files\Sophos
2009-08-24 02:54 . 2009-08-24 02:54 ——– d–h–w- c:\windows\PIF
2009-08-24 02:07 . 2009-08-24 04:06 ——– d—–w- c:\program files\Trend Micro
2009-08-22 11:19 . 2009-09-02 14:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-22 11:19 . 2009-08-22 11:33 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-22 01:31 . 2009-08-22 01:31 ——– d—–w- c:\program files\QuickTime
2009-08-22 01:31 . 2009-08-22 01:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-19 23:02 . 2009-08-19 23:02 ——– d—–w- c:\documents and settings\ash\Local Settings\Application Data\PackageAware
2009-08-11 02:14 . 2009-08-11 02:14 ——– d—–w- c:\documents and settings\ash\Library
2009-08-06 03:06 . 2009-08-06 03:06 ——– d—–w- c:\documents and settings\ash\Application Data\Salty Brine
2009-08-06 03:04 . 2007-11-13 03:09 98304 —-a-w- c:\windows\system32\Loa.dll
2009-08-06 03:04 . 2007-02-11 13:15 753944 —-a-w- c:\windows\system32\wodSmtp.dll
2009-08-06 03:04 . 2005-07-06 23:57 159744 —-a-w- c:\windows\system32\stamin32.dll
2009-08-06 03:04 . 2009-08-06 03:05 ——– d—–w- c:\program files\FolderClone
2009-08-04 12:58 . 2009-08-04 12:58 3942048 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-04 12:57 . 2009-08-04 12:57 ——– d—–w- c:\documents and settings\ash\Application Data\Malwarebytes
2009-08-04 12:57 . 2009-08-03 03:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-04 12:57 . 2009-08-04 12:58 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-04 12:57 . 2009-08-04 12:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-04 12:57 . 2009-08-03 03:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-02 23:35 . 2008-10-05 05:07 201949472 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-02 21:59 . 2008-10-11 06:42 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-02 17:29 . 2008-10-05 05:07 2718176 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-27 12:49 . 2008-10-10 09:04 ——– d—–w- c:\program files\Password Safe
2009-08-23 00:56 . 2008-10-05 05:03 4212 —ha-w- c:\windows\system32\zllictbl.dat
2009-08-22 01:21 . 2008-10-09 08:09 ——– d—–w- c:\program files\HyperSnap 6
2009-08-22 01:12 . 2008-10-10 04:09 ——– d—–w- c:\program files\Easy CD-DA Extractor 12
2009-08-22 01:10 . 2008-11-24 08:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Easy CD-DA Extractor
2009-08-19 23:04 . 2009-08-19 23:04 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}
2009-08-19 23:04 . 2008-10-07 22:22 ——– d—–w- c:\program files\Thumbs7
2009-08-19 23:04 . 2008-10-07 22:23 ——– d—–w- c:\program files\Common Files\Nikon
2009-08-06 17:08 . 2009-08-19 23:04 3208116 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\tp_digicam40.exe
2009-07-30 18:48 . 2009-08-19 23:04 394752 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\OFFLINE\B462DC4F\F536666A\dcraw.exe
2009-07-30 18:48 . 2009-08-19 23:04 365568 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\OFFLINE\F5337325\F536666A\dcraw64.exe
2009-07-30 18:48 . 2009-08-19 23:04 365568 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\OFFLINE\AE93CF7F\F536666A\dcraw64.exe
2009-07-30 18:48 . 2009-08-19 23:04 394752 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\OFFLINE\8FC6884B\F536666A\dcraw.exe
2009-07-05 03:08 . 2008-10-07 10:38 ——– d—–w- c:\program files\cpuz
2009-07-04 12:06 . 2009-08-19 23:04 2619904 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\OFFLINE\8AE82C9B\F536666A\PolyImagePro.dll
2009-07-04 12:06 . 2009-08-19 23:04 2619904 -c–a-w- c:\documents and settings\All Users\Application Data\{A2AEA530-E10C-4267-AF8E-5F478C1AC8FD}\OFFLINE\5477498E\F536666A\PolyImagePro.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-09-02_07.48.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-02 22:08 . 2009-09-02 22:08 16384 c:\windows\temp\Perflib_Perfdata_174.dat
+ 2009-09-02 13:25 . 2009-09-02 13:25 8192 c:\windows\ERDNT\2-09-2009\jreV6Up16\Users\00000004\UsrClass.dat
+ 2009-09-02 13:25 . 2009-09-02 13:25 8192 c:\windows\ERDNT\2-09-2009\jreV6Up16\Users\00000002\UsrClass.dat
+ 2009-04-21 14:04 . 2009-09-02 23:23 362416 c:\windows\system32\ZoneLabs\avsys\bases\sfdb.dat
- 2009-04-21 14:04 . 2009-09-02 07:39 362416 c:\windows\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2009-09-02 13:28 . 2009-09-02 13:28 149280 c:\windows\system32\javaws.exe
+ 2009-09-02 13:28 . 2009-09-02 13:28 145184 c:\windows\system32\javaw.exe
+ 2009-09-02 13:28 . 2009-09-02 13:28 145184 c:\windows\system32\java.exe
+ 2009-09-02 13:25 . 2009-09-02 13:25 372736 c:\windows\ERDNT\2-09-2009\jreV6Up16\Users\00000006\UsrClass.dat
+ 2009-09-02 13:25 . 2009-09-02 13:25 253952 c:\windows\ERDNT\2-09-2009\jreV6Up16\Users\00000003\NTUSER.DAT
+ 2009-09-02 13:25 . 2009-09-02 13:25 249856 c:\windows\ERDNT\2-09-2009\jreV6Up16\Users\00000001\NTUSER.DAT
+ 2009-09-02 13:25 . 2005-10-20 02:02 163328 c:\windows\ERDNT\2-09-2009\jreV6Up16\ERDNT.EXE
+ 2009-09-02 13:28 . 2009-09-02 13:28 1757696 c:\windows\Installer\11317f7.msi
+ 2009-04-21 14:00 . 2009-09-02 14:08 13576637 c:\windows\system32\ZoneLabs\spyware.dat
+ 2009-09-02 13:25 . 2009-09-02 13:25 15269888 c:\windows\ERDNT\2-09-2009\jreV6Up16\Users\00000005\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IconOverlayHandlerAccessible]
@="{3DBF5F01-3287-46EB-82CF-45AA5C241162}"
[HKEY_CLASSES_ROOT\CLSID\{3DBF5F01-3287-46EB-82CF-45AA5C241162}]
2009-03-04 09:19 612920 —-a-w- c:\windows\system32\PGPfsshl.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LinkStashMonitor"="c:\program files\LinkStash\lsmon.exe" [2007-11-02 69848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"CTSysVol"="c:\program files\Creative\SBAudigy LS\Surround Mixer\CTSysVol.exe" [2003-05-01 57344]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-07-24 450560]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2009-03-11 611712]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-03-31 982408]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-02 149280]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]
Logo Calibration Loader.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe [2008-10-9 708608]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
PGPtray.exe.lnk - c:\windows\Installer\{6798F012-57C5-49AD-9A9D-4097616F4E1B}\Icon6560581611.exe [2009-4-18 55296]
ProfileReminder.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe [2008-10-9 954368]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=

R0 pgpfs;PGP File Sharing;c:\windows\system32\drivers\PGPfsfd.sys [4/03/2009 7:19 PM 135736]
R0 PGPwded;PGPwded Storage Filter Service;c:\windows\system32\drivers\PGPwded.sys [4/03/2009 7:19 PM 213048]
R0 stcvsm;stcvsm;c:\windows\system32\drivers\stcvsm.sys [11/10/2008 5:37 PM 144288]
R1 sbmount;StorageCraft Image Mount Driver;c:\windows\system32\drivers\sbmount.sys [11/10/2008 5:37 PM 95776]
R2 PD91Agent;PD91Agent;c:\program files\Raxco\PerfectDisk2008\PD91Agent.exe [9/09/2008 1:49 PM 693512]
R2 PDIHWCTL;PDIHWCTL;c:\windows\system32\drivers\pdihwctl.sys [9/10/2008 7:06 PM 14416]
R2 PGPdisk;PGPdisk;c:\windows\system32\drivers\PGPdisk.sys [4/03/2009 7:19 PM 246328]
R2 PGPsdkDriver;PGPsdkDriver;c:\windows\system32\drivers\PGPsdk.sys [4/03/2009 7:19 PM 40504]
R2 ShadowProtectSvc;ShadowProtect Service;c:\program files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe [11/10/2008 5:37 PM 1255968]
R2 VSNAPVSS;StorageCraft Shadow Copy Provider;c:\windows\system32\vsnapvss.exe [11/10/2008 5:37 PM 70176]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [24/07/2008 3:22 PM 102400]
S3 cpuz129;cpuz129;c:\program files\PC Wizard 2008\pcwiz32.sys [7/10/2008 8:36 PM 9600]
S3 i1display;i1 Display;c:\windows\system32\drivers\i1display.sys [18/10/2007 5:35 PM 44344]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\28.tmp –> c:\windows\system32\28.tmp [?]
S3 PD91Engine;PD91Engine;c:\program files\Raxco\PerfectDisk2008\PD91Engine.exe [9/09/2008 1:49 PM 906504]
.
Contents of the 'Scheduled Tasks' folder

2009-09-02 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 07:04]

2009-09-02 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 07:04]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: Download Video on This Page - c:\program files\Tomato\YouTube Video Downloader\IEPage.html
IE: Download Video This Links To - c:\program files\Tomato\YouTube Video Downloader\IELink.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{11F19C45-9675-488A-A8E0-8E8234DC245D} - c:\program files\Tomato\YouTube Video Downloader\IEPage.html
LSP: c:\windows\system32\PGPlsp.dll
FF - ProfilePath - c:\documents and settings\ash\Application Data\Mozilla\Firefox\Profiles\sx4rvg9l.default\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-03 09:35
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\28.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1606980848-1965331169-1177238915-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2009-09-02 9:37
ComboFix-quarantined-files.txt 2009-09-02 23:37
ComboFix2.txt 2009-09-02 07:50

Pre-Run: 148,815,851,520 bytes free
Post-Run: 148,764,798,976 bytes free

189
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, September 3, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, September 03, 2009 02:24:16
Records in database: 2741249
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
R:\
S:\

Scan statistics:
Objects scanned: 71054
Threats found: 4
Infected objects found: 5
Suspicious objects found: 0
Scan duration: 01:43:37


File name / Threat / Threats count
E:\NewDnLds\FileMang\FileFolderTimeDateAttributesChangers\changeattr.zip Infected: Backdoor.Win32.Hupigon.guyf 1
E:\NewDnLds\Privacy-Encryption-Security\MacicalJellyBeans\kf141.zip Infected: not-a-virus:PSWTool.Win32.RAS.a 2
E:\NewDnLds\Surfing\Nirsoft\MailPassView\mailpv1_13.zip Infected: not-a-virus:PSWTool.Win32.MailPassView.a 1
E:\NewDnLds\Surfing\Nirsoft\ProtectedStoragePassView\pspv1_60.zip Infected: not-a-virus:PSWTool.Win32.PassView.160 1

Selected area has been scanned.
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

Malwarebytes' Anti-Malware 1.40
Database version: 2734
Windows 5.1.2600 Service Pack 3

3/09/2009 9:57:00 AM
mbam-log-2009-09-03 (09-57-00).txt

Scan type: Quick Scan
Objects scanned: 109868
Time elapsed: 3 minute(s), 20 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

Regards,

Andrew Hart
Hi :)

It would have been prudent to allow ComboFix to update but no harm done and I do not think it necessary to re-download/run again. This more so because of the nature of the malware we have been dealing with which was causing ZA to close down so it could attempt do download and install more of its ilk.

It had actually changed a specific registry setting also and this was adding to the original problems.

There has been some issues of late regarding the Kaspersky online scan and your persistence with the aforementioned is commendable. What is has actually flagged is known as a FP(false positive) and no further action is required but I will inform Kaspersky of this myself so they can update the database accordingly.

I would like to ask for one final scan to check since you experienced problems with RootRepeal.

F-Secure Blacklight:

Please download Blacklight from here to your desktop.

or

Link to it from the ftp site: ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe
and save it to your desktop from there.

Go to Start–>Run, copy in the following text, and press Enter:

"%userprofile%\desktop\fsbl.exe" /expert

Accept the license agreement.
Click > scan, wait for it to finish, then click Close

There will be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).
Copy and paste the contents of this log into your next reply.

When completed the above, please post back the following:

  • How is you computer performing now? Any problems encountered and or any further symptoms?
  • Blacklight Log.
Hi Dakeyras, Thanks for the heads up about what's been happening with my computer. F-Secure Backlight log as requested. I closed ZAISS before running fsbl.exe. 09/04/09 10:08:11 [Info]: BlackLight Engine 2.2.1092 initialized 09/04/09 10:08:11 [Info]: OS: 5.1 build 2600 (Service Pack 3) 09/04/09 10:08:11 [Note]: 7019 4 09/04/09 10:08:11 [Note]: 7005 0 09/04/09 10:08:23 [Note]: 7006 0 09/04/09 10:08:23 [Note]: 7022 0 09/04/09 10:08:23 [Note]: 7011 912 09/04/09 10:08:23 [Note]: 7035 0 09/04/09 10:08:23 [Note]: 7026 0 09/04/09 10:08:23 [Note]: 7026 0 09/04/09 10:08:23 [Note]: FSRAW library version 1.7.1024 09/04/09 10:11:11 [Note]: 7007 0 Andrew Hart
Hi Dakeyras, Sorry, but there is one further problem with my computer which I have forgotten to mention. For around about the same amount of time I have been experiencing ZAISS shutting down unexpectedly (I can't say exactly - and it may be pure coincidence - but it feels about the same length of time) I have not been able to close Outlook or Word in the usual manner (left click red cross top right of screen). I only discovered this by mistake one day after I thought I had closed Outlook and then tried to shut down my computer - and was told that Outlook was still running and needed to be closed before I could shut down. So I opened Task Manager and saw that both Word and Outlook were still running (I have Office XP Professional installed).) This problem persists - in fact this morning I once again found Word running when I had in fact I had closed it down about 8 hours previously - I had left my computer running over night. The need to go into Task Manager to shut down processes is simply a nuisance but I thought it might possibly be related to my ZoneAlarm problem and hence the need to mention it now. Otherwise, no further erratic (unexpected/unrequested) shut downs of ZAISS. Andrew Hart
Hi :)

Thanks for the heads up about what's been happening with my computer.

You're welcome! The returned results are good.

Next:

What you have described sounds very much like a possible software conflict and one of the applications you have installed is hooked into both you have mentioned.

You could try the advice here:- Outlook Doesn’t Close

Or the actual Microsoft Office XP Professional installation itself is corrupted/in need of repair.

For the above you could try a actual Office Repair.

I actually do not think the problems mentioned are malware related but in the meantime, I think it is prudent to check on the state of your machines Hard-Drive as follows.

Check Hard Disk For Errors:

Press Start->Run, then copy/paste the following command into the box and press OK:

cmd /c chkdsk c: |find /v "percent" >> "%userprofile%\desktop\checkhd.txt"

A blank command window will open on your desktop, then close in a few minutes. This is normal.
A file icon named checkhd.txt should appear on your Desktop. Please post the contents of this file.
Hi Dakeyras, Wow! The speed of your responses continues to impress me. Thank you for being so efficient. CHKDSK report included below. I have not acted upon it and will not do so without your say so and instructions. BTW, although CHKDSK highlighted problems, my hard disk (Seagate 160 GB) is less than 1 year old and should itself still be reliable as a hardware device. In the meantime I am following up the suggestions you so kindly provided relating to Outlook not closing but, once again, I will take no action until you say it is OK to proceed. @@@@@@@@@@@@@@@@@@@@@@@ The type of the file system is NTFS. Volume label is WinXP. WARNING! F parameter not specified. Running CHKDSK in read-only mode. CHKDSK is verifying files (stage 1 of 3)… CHKDSK is verifying indexes (stage 2 of 3)… CHKDSK is recovering lost files. CHKDSK is verifying security descriptors (stage 3 of 3)… CHKDSK is verifying Usn Journal… Usn Journal verification completed. CHKDSK discovered free space marked as allocated in the master file table (MFT) bitmap. Correcting errors in the Volume Bitmap. Windows found problems with the file system. Run CHKDSK with the /F (fix) option to correct these. 156280288 KB total disk space. 11004300 KB in 50624 files. 36848 KB in 6344 indexes. 0 KB in bad sectors. 261216 KB in use by the system. 65536 KB occupied by the log file. 144977924 KB available on disk. 4096 bytes in each allocation unit. 39070072 total allocation units on disk. 36244481 allocation units available on disk. @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ When we are all done, should I leave the folders (ComboFix and Qoobox) and files (numerous) created by ComboFix (on my C:\ drive) in place, or can they be deleted? Not concerned about the space they occupy (negligible) but simply like to have a tidy system. Andrew Hart
Hi :)

OK the Hard-Drive itself is fine, merely requires some restorative maintenance. I advice you carry out the below every two weeks or at least once per month. Doing so will keep the drive in good operating health so to speak,

Next:

Click on Start >> Run and type cleanmgr in the box and press OK.
  • Ensure the boxes for Temporary Files, Temporary Internet Files and Recycle Bin are checked.
  • You can choose to check other boxes if you wish but they are not required.
  • Click on OK then Yes.
Hard-Drive Maintenance/Repair:

Note: for the CHKDSK portion you may refer to this tutorial of mine here and follow the instructions for Graphical Mode if you so wish.
  • Click Start >> Run… then type in CMD and click on OK.
  • At the Command Prompt C:\ > type the following:
  • CD C:\ and hit the Enter/Return key.
  • Now type in DEFRAG C: -F
  • A Analysis report will be displayed and then Windows will start the Defragmention run automatically.
  • This may take some time, when completed the Command Prompt C:\ > will appear.
  • Now type in CHKDSK C: /R and hit the Enter/Return key.
  • When prompted with:

CHKDSK cannot run because the volume is in use by another process
Would you like to schedule this volume to be checked next time the system
restarts (Y/N)

  • Hit the Y key then at the Command Prompt C:\ >
  • Type in EXIT and and hit the Enter/Return key.
  • Now Reboot(Restart) your computer.
Note: Upon Reboot(Restart) the CHKDSK(check-disk) will start and carry out the repairs required.

You should see a screen like this just after the Post(power on self test) screen:

[external image: Posted Image]

Note: Do not touch either the keyboard or Mouse, otherwise the Check-Disk will be cancelled and you computer will continue to boot-up as normal.

Next:

When the above has been completed, let myself know, thank you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI