This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Problem after using Combofix

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i read a post on Removing Trojan Win32-Clicker.delf.cbe on which a solution was posted by "Shelf Life" .

As per the posting i downloaded MBAM & Combofix.

After running MBAM , i could get rid of a few virus but a few remained even after restarting the machine.

Hence , i took the next step of using combofix.

After sucessfully running combofix , all the virus were removed ( even now MBAM does not show any virus )

The problem now is that my internet connection has become quite erratic.

Most of the times , it shows "Internet Connection Error" , then i click refresh a couple of times and i the page pops up. Same is the case with outlook - non responsive but then after a couple of send / receive clicks it just kick starts and gets all the mail.

One consistent flaw which i have noticed is that there is no response to "Ping yahoo.com" , irrespective of internet connection working or not.

Kindly advise if there are some settings to be tweaked .. i tried to lower the security settings but does not seem to work.

Heres log from HJT

_______________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:04:33 PM, on 28-Aug-2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Aladdin\eToken\PKIClient\x32\eTSrv.exe
C:\WINDOWS\IntelliAdminRC3\Agent32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TPHDEXLG.EXE
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rediff.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: DAPBHO Class - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - C:\Program Files\DAP\DAPIEBar.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Wolfram Toolbar - {9E709AEF-74F7-4DA3-A7FC-F3E2D5A8D793} - C:\Program Files\Wolfram Research\WolframToolbar\1.0\WolframBands32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-926495626-1003886262-1936394565-1004\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" (User '?')
O4 - HKUS\S-1-5-21-926495626-1003886262-1936394565-1004\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-926495626-1003886262-1936394565-1004\..\Run: [JFSW2Launch] C:\Documents and Settings\Dhiraj.MAHABIR\Application Data\Transcend\JFSW2\JFSW2Launch.exe (User '?')
O4 - HKUS\S-1-5-21-926495626-1003886262-1936394565-1004\..\Run: [Google Update] "C:\Documents and Settings\Dhiraj.MAHABIR\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (User '?')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.bitstream.com/wfplayer/tdserver.cab
O16 - DPF: {23ACBF1D-D7AF-4236-AD8C-CADF14234B78} (nCodeDGFT_new.DGFTctl) - http://dgftcom.nic.in/(n)CodeDGFT_new.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6F7864F9-DB33-11D3-8166-0060B0F885E6} (VSPTA Class) - https://onsite.safescrypt.com/services/Safe…neCA/vspta3.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://floridakeysmedia.tv/axiscam/Codebas…sCamControl.ocx
O16 - DPF: {9E265649-6E0E-4EEA-9F49-DAE0801440CF} (WebDigiNet Control) - http://122.160.111.150/WebDiginet.CAB
O16 - DPF: {BE90DF74-A983-4BBB-A9C1-F2C90807F548} (AssureSignControl Control) - http://www.mca.gov.in/DCAPortalWeb/dca/jsp…SignControl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = MAHABIR
O17 - HKLM\Software\..\Telephony: DomainName = MAHABIR
O17 - HKLM\System\CCS\Services\Tcpip\..\{7A98F4DF-39CA-46EE-94E0-AC5D4D412C79}: NameServer = 192.168.0.101
O17 - HKLM\System\CCS\Services\Tcpip\..\{BA1F53B8-1E72-466F-B978-A9FC622BCD7F}: NameServer = 192.9.100.1,192.9.100.100
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = MAHABIR
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = MAHABIR
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = MAHABIR
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ETOKSRV (eTSrv) - Aladdin Knowledge Systems, Ltd. - C:\Program Files\Aladdin\eToken\PKIClient\x32\eTSrv.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IntelliAdminRC3 - Unknown owner - C:\WINDOWS\IntelliAdminRC3\Agent32.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
O23 - Service: IS Service (ISSVC) - Unknown owner - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
O23 - Service: ThinkVantage System Update (UCLauncherService) - Unknown owner - C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe

–
End of file - 12765 bytes
___________________________________


thanks
Hi dhirajmaskara,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please:
  • Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
  • Click on Explore
  • Click on Local Disk (C:) in the left-hand window pane
  • Look for ComboFix.txt in the right-hand window pane and right click on it
  • Put your cursor (arrow) on Open With
  • Move your cursor to the new menu that opens and click on Choose Program…
  • Click on Notepad

When file opens, Copy/Paste text here
Hello Tomk

Thank you so much for taking time out to help me fix the problem , appreciate it !

Heres the text you asked for :

____________


ComboFix 09-08-23.01 - dhiraj 4-Aug-2009 17:15.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1526.1085 [GMT 5.5:30]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Symantec Client Firewall *disabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\dhiraj - data\Apollo\NABL RKLS\multi QC\Automated quality control protocols in a multi-analyzer system - US Patent 6984527_files\Desktop_.ini
c:\dhiraj - data\Apollo\NABL RKLS\multi QC\Desktop_.ini
c:\dhiraj - data\Apollo\NABL RKLS\multi QC\Hem I QA QC_files\Desktop_.ini
c:\dhiraj - data\Apollo\NABL RKLS\multi QC\Method of evaluating performance of a hematology analyzer - Patent 6549876_files\Desktop_.ini
c:\dhiraj - data\Apollo\NABL RKLS\multi QC\multi QC rule\Desktop_.ini
c:\dhiraj - data\Apollo\NABL RKLS\multi QC\Westgard QC Application Sysmex 9500 and Hematology_files\Desktop_.ini
c:\dhiraj - data\Apollo\NABL RKLS\multi QC\Westgard QC Multirules and Westgard Rules-2_files\Desktop_.ini
c:\dhiraj - data\Apollo\NABL RKLS\multi QC\westguard rules-3_files\Desktop_.ini
c:\dhiraj - data\Apollo\NABL RKLS\RKL QUALITY MANUAL\Desktop_.ini
c:\dhiraj - data\Apollo\NABL RKLS\VISIT REPORT\Desktop_.ini
c:\recycler\S-1-5-21-0475768609-4028237381-232913281-8804
c:\recycler\S-1-5-21-3907243455-7887058794-785930526-2375
c:\recycler\S-1-5-21-5928644305-9980870262-827723025-1222
c:\windows\Fonts\AcadEref.ttf
c:\windows\Fonts\Wphv07nb.ttf
c:\windows\Installer\1b689b6.msi
c:\windows\Installer\422647c.msp
c:\windows\system32\drivers\gxmxkprt.sys
c:\windows\system32\drivers\kbiwkmvpqwrumu.sys
c:\windows\system32\drivers\wbshuiyn.sys
c:\windows\system32\kbiwkmjhxdpbav.dll
c:\windows\system32\kbiwkmmyxmpfqp.dat
c:\windows\system32\kbiwkmoxyqqaqb.dat
c:\windows\system32\kbiwkmwuxblode.dll
c:\windows\system32\nicbhbr.dll
c:\windows\system32\qsgzoecq.dll
c:\windows\system32\uhnofdp.dll
c:\windows\Tasks\At1.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_BBPDGPBG
——-\Legacy_WBSHUIYN
——-\Service_bbpdgpbg
——-\Service_wbshuiyn


((((((((((((((((((((((((( Files Created from 2009-07-24 to 2009-08-24 )))))))))))))))))))))))))))))))
.

2009-08-24 05:59 . 2009-08-24 05:59 ——– d—–w- c:\documents and settings\dhiraj\Local Settings\Application Data\pjwjlldf
2009-08-24 05:59 . 2009-08-24 05:59 ——– d—–w- c:\documents and settings\dhiraj\Application Data\pjwjlldf
2009-08-23 06:13 . 2009-08-23 06:13 ——– d—–w- c:\windows\ie8updates
2009-08-22 23:41 . 2009-08-22 23:41 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\pjwjlldf
2009-08-22 23:41 . 2009-08-22 23:41 ——– d—–w- c:\documents and settings\NetworkService\Application Data\pjwjlldf
2009-08-22 10:07 . 2009-08-22 10:07 ——– d—–w- c:\documents and settings\dhiraj\Application Data\Malwarebytes
2009-08-22 10:07 . 2009-08-03 08:06 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 10:07 . 2009-08-22 10:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-22 10:07 . 2009-08-22 10:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-22 10:07 . 2009-08-03 08:06 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-22 08:31 . 2009-08-22 08:31 ——– d—–w- c:\program files\NIC
2009-08-22 02:21 . 2009-08-22 02:21 ——– d—–w- c:\program files\Aladdin
2009-08-21 05:03 . 2009-08-21 05:03 68608 —-a-w- c:\windows\system32\drivers\ecbqyvrxmxvxtuij.sys
2009-08-21 04:02 . 2009-08-21 04:02 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-21 03:45 . 2009-08-21 03:45 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2009-08-21 02:59 . 2009-07-03 17:09 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2009-08-21 02:59 . 2009-07-03 17:09 246272 ——w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-21 02:28 . 2009-08-21 02:28 8854 —-a-r- c:\documents and settings\dhiraj\Application Data\Microsoft\Installer\{2C6A2E10-F94D-4750-B946-46B48ECBA57F}\Uninstall_FileSigner_2C6A2E10F94D4750B94646B48ECBA57F.exe
2009-08-21 02:28 . 2009-08-21 02:28 40960 —-a-r- c:\documents and settings\dhiraj\Application Data\Microsoft\Installer\{2C6A2E10-F94D-4750-B946-46B48ECBA57F}\NewShortcut3_2C6A2E10F94D4750B94646B48ECBA57F.exe
2009-08-21 02:28 . 2009-08-21 02:28 3638 —-a-r- c:\documents and settings\dhiraj\Application Data\Microsoft\Installer\{2C6A2E10-F94D-4750-B946-46B48ECBA57F}\NewShortcut21_2C6A2E10F94D4750B94646B48ECBA57F.exe
2009-08-21 02:28 . 2009-08-21 02:28 3638 —-a-r- c:\documents and settings\dhiraj\Application Data\Microsoft\Installer\{2C6A2E10-F94D-4750-B946-46B48ECBA57F}\NewShortcut11_2C6A2E10F94D4750B94646B48ECBA57F.exe
2009-08-21 02:28 . 2009-08-21 02:28 3638 —-a-r- c:\documents and settings\dhiraj\Application Data\Microsoft\Installer\{2C6A2E10-F94D-4750-B946-46B48ECBA57F}\ARPPRODUCTICON.exe
2009-08-21 02:28 . 2009-08-21 02:28 1406 —-a-r- c:\documents and settings\dhiraj\Application Data\Microsoft\Installer\{2C6A2E10-F94D-4750-B946-46B48ECBA57F}\NewShortcut5_2C6A2E10F94D4750B94646B48ECBA57F.exe
2009-08-21 02:28 . 2009-08-21 02:28 1406 —-a-r- c:\documents and settings\dhiraj\Application Data\Microsoft\Installer\{2C6A2E10-F94D-4750-B946-46B48ECBA57F}\NewShortcut2_2C6A2E10F94D4750B94646B48ECBA57F.exe
2009-08-21 02:28 . 2009-08-21 02:28 1406 —-a-r- c:\documents and settings\dhiraj\Application Data\Microsoft\Installer\{2C6A2E10-F94D-4750-B946-46B48ECBA57F}\NewShortcut1_2C6A2E10F94D4750B94646B48ECBA57F_1.exe
2009-08-21 02:28 . 2009-08-21 02:28 ——– d—–w- c:\program files\FileSignerPlus
2009-08-20 18:35 . 2009-08-20 18:35 ——– d-sh–w- c:\documents and settings\dhiraj\IECompatCache
2009-08-20 18:34 . 2009-08-20 18:34 ——– d-sh–w- c:\documents and settings\dhiraj\PrivacIE
2009-08-20 18:31 . 2009-08-20 18:31 ——– d-sh–w- c:\documents and settings\dhiraj\IETldCache
2009-08-20 18:09 . 2009-08-20 18:10 ——– dc-h–w- c:\windows\ie8
2009-08-12 17:26 . 2009-08-12 17:26 ——– d—–w- c:\windows\ServicePackFiles
2009-08-12 16:31 . 2009-06-05 07:42 655872 ——w- c:\windows\system32\dllcache\mstscax.dll
2009-08-12 09:33 . 2009-08-12 09:33 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-12 09:33 . 2009-08-12 09:33 ——– d—–w- c:\program files\MSBuild
2009-08-12 09:33 . 2009-08-12 09:33 ——– d—–w- c:\program files\Reference Assemblies
2009-08-12 09:33 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-12 09:33 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-12 09:33 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-12 09:33 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-12 09:33 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-12 09:33 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-12 09:33 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-12 09:33 . 2009-08-12 09:33 ——– d—–w- C:\68d61042816a94014e
2009-08-12 09:32 . 2009-08-12 09:41 ——– d—–w- c:\windows\SxsCaPendDel
2009-08-12 09:29 . 2009-08-12 09:29 ——– d—–w- c:\program files\MSXML 6.0
2009-08-12 08:05 . 2009-08-12 08:05 ——– d—–w- c:\documents and settings\dhiraj\Application Data\Sonic
2009-08-12 08:04 . 2009-08-12 08:04 ——– d—–w- c:\documents and settings\dhiraj\Application Data\Leadertech
2009-08-05 09:11 . 2009-08-05 09:11 204800 ——w- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-31 19:00 . 2009-07-31 19:00 ——– d—–w- c:\documents and settings\dhiraj\Incomplete
2009-07-31 18:59 . 2009-08-02 18:47 ——– d—–w- c:\documents and settings\dhiraj\Application Data\LimeWire
2009-07-29 12:13 . 2006-12-14 04:30 110592 ——w- c:\documents and settings\dhiraj\Application Data\U3\temp\cleanup.exe
2009-07-29 12:12 . 2007-02-12 12:16 3096576 —h–w- c:\documents and settings\dhiraj\Application Data\U3\temp\Launchpad Removal.exe
2009-07-29 12:12 . 2009-07-29 12:13 ——– d—–w- c:\documents and settings\dhiraj\Application Data\U3
2009-07-27 19:39 . 2009-07-27 19:39 ——– d—–w- c:\program files\FLV Converter
2009-07-27 18:52 . 2009-07-27 18:52 ——– d—–w- c:\program files\KeepV Converter
2009-07-27 18:36 . 2009-07-01 09:46 94854 —-a-w- c:\windows\system32\HKCU_GNU.reg
2009-07-27 18:36 . 2009-02-26 11:04 2004 —-a-w- c:\windows\system32\HKLM_GNU.reg
2009-07-27 18:36 . 2008-02-03 15:56 364544 —-a-w- c:\windows\system32\cdg.dll
2009-07-27 18:36 . 2006-09-27 12:16 348160 —-a-w- c:\windows\system32\cdga.dll
2009-07-27 18:36 . 2006-07-17 16:12 14909 —-a-w- c:\windows\system32\A_reg.reg
2009-07-27 18:31 . 2009-07-27 18:35 ——– d—–w- c:\documents and settings\dhiraj\Application Data\GetRightToGo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-24 12:08 . 2008-10-22 06:47 1590816 –sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-08-24 12:08 . 2008-10-22 06:47 45810720 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-08-24 12:01 . 2008-06-18 18:45 ——– d—–w- c:\program files\Common Files\Akamai
2009-08-24 11:57 . 2008-10-22 06:47 616556 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-24 11:57 . 2008-10-22 06:47 152132 –sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-08-24 11:00 . 2008-10-22 06:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-08-24 06:21 . 2007-08-19 21:15 ——– d—–w- c:\program files\EphPod
2009-08-24 06:21 . 2007-05-19 02:40 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-22 23:38 . 2007-05-19 03:03 5427 —-a-w- c:\windows\system32\EGATHDRV.SYS
2009-08-18 02:08 . 2009-04-18 04:58 ——– d—–w- c:\documents and settings\dhiraj\Application Data\Metacafe
2009-08-18 02:08 . 2008-02-10 16:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Metacafe
2009-08-14 12:59 . 2009-04-11 14:29 192136 ——w- c:\documents and settings\dhiraj\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-12 08:04 . 2007-05-19 02:52 ——– d—–w- c:\program files\Common Files\Sonic Shared
2009-08-05 09:11 . 1980-01-01 07:00 204800 ——w- c:\windows\system32\mswebdvd.dll
2009-07-31 18:59 . 2007-06-17 04:36 ——– d—–w- c:\program files\LimeWire
2009-07-27 18:36 . 2009-07-13 05:02 ——– d—–w- c:\program files\Cucusoft
2009-07-17 18:55 . 1980-01-01 07:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 18:13 . 1980-01-01 07:00 286208 ——w- c:\windows\system32\wmpdxm.dll
2009-07-09 17:36 . 2007-05-19 06:45 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-07-09 17:35 . 2009-07-09 17:35 ——– d—–w- c:\program files\Windows Mobile Device Handbook
2009-07-03 17:09 . 1980-01-01 07:00 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-25 18:36 . 1980-01-01 07:00 95744 —-a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 1980-01-01 07:00 661504 —-a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 1980-01-01 07:00 517120 —-a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 1980-01-01 07:00 48640 —-a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 1980-01-01 07:00 471552 —-a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 1980-01-01 07:00 47104 —-a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 1980-01-01 07:00 225280 —-a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 1980-01-01 07:00 186880 —-a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 1980-01-01 07:00 177152 —-a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 1980-01-01 07:00 16896 —-a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 1980-01-01 07:00 138240 —-a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 1980-01-01 07:00 123392 —-a-w- c:\windows\system32\mqrtdep.dll
2009-06-25 08:17 . 1980-01-01 07:00 729600 ——w- c:\windows\system32\lsasrv.dll
2009-06-25 08:17 . 1980-01-01 07:00 59392 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:17 . 1980-01-01 07:00 56320 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:17 . 1980-01-01 07:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:17 . 1980-01-01 07:00 168448 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:17 . 1980-01-01 07:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-22 11:49 . 1980-01-01 07:00 19968 —-a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 1980-01-01 07:00 117248 —-a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 1980-01-01 07:00 4608 —-a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 1980-01-01 07:00 91776 —-a-w- c:\windows\system32\drivers\mqac.sys
2009-06-22 11:35 . 1980-01-01 07:00 92544 ——w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:55 . 1980-01-01 07:00 82432 ——w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 1980-01-01 07:00 119808 ——w- c:\windows\system32\t2embed.dll
2009-06-12 11:50 . 1980-01-01 07:00 80896 ——w- c:\windows\system32\tlntsess.exe
2009-06-12 11:50 . 1980-01-01 07:00 76288 ——w- c:\windows\system32\telnet.exe
2009-06-10 14:21 . 1980-01-01 07:00 84992 ——w- c:\windows\system32\avifil32.dll
2009-06-10 06:32 . 1980-01-01 07:00 132096 ——w- c:\windows\system32\wkssvc.dll
2009-06-08 08:59 . 2008-01-23 12:37 5194 —-a-w- c:\program files\Exportcerts.txt
2009-06-08 08:59 . 2008-01-23 12:37 34 —-a-w- c:\program files\Exportcerts1.txt
2009-06-05 07:42 . 2004-08-09 17:51 655872 ——w- c:\windows\system32\mstscax.dll
2009-06-03 19:27 . 1980-01-01 07:00 1290752 ——w- c:\windows\system32\quartz.dll
2007-06-02 03:46 . 2007-06-02 03:32 526 ——w- c:\program files\DataCardInfo.ini
2006-02-23 15:01 . 2007-06-02 03:32 0 -c—-w- c:\program files\EW600APICfg.dat
2006-01-11 11:18 . 2007-06-02 03:32 294912 ——w- c:\program files\vWTP.mdb
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-20 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2005-11-07 106496]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2005-12-22 01:42 32768 ——w- c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2005-12-08 21:59 39936 ——w- c:\windows\system32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 06:45 28672 ——w- c:\windows\system32\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-12-01 03:16 24576 ——w- c:\windows\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd csspwntfy

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CONE EXPERT Grey Report.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CONE EXPERT Grey Report.lnk
backup=c:\windows\pss\CONE EXPERT Grey Report.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^REPORTS.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\REPORTS.lnk
backup=c:\windows\pss\REPORTS.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Dhiraj.MAHABIR^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\Dhiraj.MAHABIR\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Dhiraj.MAHABIR^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
path=c:\documents and settings\Dhiraj.MAHABIR\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^dhiraj^Start Menu^Programs^Startup^Metacafe.lnk]
path=c:\documents and settings\dhiraj\Start Menu\Programs\Startup\Metacafe.lnk
backup=c:\windows\pss\Metacafe.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"STCAgent"=2 (0x2)
"btwdins"=2 (0x2)
"ETOKSRV"=2 (0x2)
"DefWatch"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AcPrfMgrSvc"=2 (0x2)
"Autodesk Licensing Service"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4260:TCP"= 4260:TCP:@xpsp2res.dll,-22009

R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [19-May-2007 8:11 AM 85760]
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [19-May-2007 8:11 AM 4736]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [19-May-2007 8:34 AM 4442]
R2 Akamai;Akamai;c:\windows\System32\svchost.exe -k Akamai [01-Jan-1980 12:30 PM 14336]
R2 eTSrv;ETOKSRV;c:\program files\Aladdin\eToken\PKIClient\x32\eTSrv.exe [03-Nov-2008 1:29 PM 7168]
R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [22-Dec-2005 5:44 AM 12544]
R2 IntelliAdminRC3;IntelliAdminRC3;c:\windows\IntelliAdminRC3\Agent32.exe [03-Feb-2009 1:51 PM 2279904]
R2 PrivateDisk;PrivateDisk;c:\program files\IBM ThinkVantage\SafeGuard PrivateDisk\privatediskm.sys [16-Nov-2005 1:41 AM 46142]
R2 smi2;smi2;c:\program files\SMI2\smi2.sys [22-Dec-2005 5:15 AM 3968]
R2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [09-Dec-2005 3:14 AM 3328]
R3 hwcdcmdm0;HUAWEI Mobile Connect - 3G Modem;c:\windows\system32\drivers\ewusbmdm.sys [19-May-2007 12:45 PM 65152]
R3 hwusbser;HUAWEI Mobile Connect - 3G Application Interface;c:\windows\system32\drivers\ewusbser.sys [19-May-2007 12:45 PM 65152]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13-Dec-2007 1:28 PM 24592]
S1 oxser;OX16C95x Serial port driver;c:\windows\system32\drivers\oxser.sys [23-Mar-2008 8:41 PM 49792]
S3 AKSUP;AKSUP;c:\windows\system32\drivers\aksup.sys [15-Apr-2009 4:01 PM 34472]
S3 BTPCCARD;Bluetooth BCSP Transport for Pc Card;c:\windows\system32\drivers\btpcbcsp.sys [01-Jul-2003 12:30 PM 232444]
S3 CSVirtA;Cisco Systems SSL VPN Adapter;c:\windows\system32\DRIVERS\CSVirtA.sys –> c:\windows\system32\DRIVERS\CSVirtA.sys [?]
S3 SavRoam;SAVRoam;c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [19-Aug-2005 5:52 AM 124608]
S3 vvftav303;vvftav303;c:\windows\system32\drivers\vvftav303.sys –> c:\windows\system32\drivers\vvftav303.sys [?]
S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\Drivers\usbVM303.sys –> c:\windows\system32\Drivers\usbVM303.sys [?]
S4 ConeExpertUCOM;ConeExpertUCOM;c:\coexpert\bin\WatchUcom.exe ConeExpertUCOM –> c:\coexpert\bin\WatchUcom.exe ConeExpertUCOM [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - WBSHUIYN
*Deregistered* - wbshuiyn

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-01-25 c:\windows\Tasks\Dhiraj 23102008.job
- c:\windows\system32\ntbackup.exe [1980-01-01 12:00]

2009-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-926495626-1003886262-1936394565-1004.job
- c:\documents and settings\Dhiraj.MAHABIR\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-07 02:17]

2008-09-23 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2007-05-19 08:12]

2009-08-09 c:\windows\Tasks\Scheduled backup of T60.job
- c:\windows\system32\ntbackup.exe [1980-01-01 12:00]
.
- - - - ORPHANS REMOVED - - - -

BHO-{004407FB-0122-4343-868E-3977F28A90Aa} - c:\windows\system32\qsgzoecq.dll
Notify-ScCertProp - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.rediff.com/
IE: &Download with &DAP - c:\progra~1\DAP\dapextie.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {7A98F4DF-39CA-46EE-94E0-AC5D4D412C79} = 192.168.0.101
TCP: {BA1F53B8-1E72-466F-B978-A9FC622BCD7F} = 192.9.100.1,192.9.100.100
DPF: {23ACBF1D-D7AF-4236-AD8C-CADF14234B78} - hxxp://dgftcom.nic.in/(n)CodeDGFT_new.CAB
DPF: {9E265649-6E0E-4EEA-9F49-DAE0801440CF} - hxxp://122.160.111.150/WebDiginet.CAB
DPF: {BE90DF74-A983-4BBB-A9C1-F2C90807F548} - hxxp://www.mca.gov.in/DCAPortalWeb/dca/jsp/mydca/pki/AssureSignControl.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-24 17:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\ccEvtMgr]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SAVRT]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SNDSrvc]
"ImagePath"="-"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\SYMTDI]
"ImagePath"="-"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1560)
c:\windows\system32\vrlogon.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\windows\system32\klogon.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\windows\system32\biologon.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\remote.dll
c:\windows\system32\tphklock.dll
c:\windows\system32\mobilev.acm
c:\program files\ThinkVantage Fingerprint Software\crypto.dll

- - - - - - - > 'lsass.exe'(1616)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\IBM ThinkVantage\Client Security Solution\csspwntfy.dll
c:\windows\system32\WTSAPI32.dll
c:\program files\IBM ThinkVantage\Client Security Solution\ibmtsp.dll
c:\program files\IBM ThinkVantage\Client Security Solution\tcsrpc.dll
c:\program files\IBM ThinkVantage\Client Security Solution\cssuserdatadispatcher.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
c:\program files\Bonjour\mdnsNSP.dll

- - - - - - - > 'explorer.exe'(3464)
c:\windows\system32\WININET.dll
c:\windows\system32\PROCHLP.DLL
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\scardsvr.exe
c:\windows\system32\IPSSVC.EXE
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\TPHDEXLG.exe
c:\windows\system32\TpKmpSvc.exe
c:\program files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
c:\program files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
c:\program files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
c:\program files\ThinkVantage\SystemUpdate\UCLauncherService.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\progra~1\MICROS~3\rapimgr.exe
c:\program files\IBM ThinkVantage\Common\Logger\logmon.exe
.
**************************************************************************
.
Completion time: 2009-08-24 17:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-24 12:11

Pre-Run: 15,823,409,152 bytes free
Post-Run: 15,779,622,912 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect

405 — E O F — 2009-08-23 06:14
dhirajmaskara,

You appear to have two anti-virus and firewall programs running. Symantec and Kaspersky. That is not good. You only want one of them. The Symantec is out of date so I suggest you keep the Kaspersky. Go to Add or Remove programs in your control panel and uninstall it.

Limewire
You have Limewire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm


I would recommend that you uninstall Limewire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Combofix is updated often and you have an old version. Please drag your copy to the recycle bin. Then download a new copy from one of these links.


Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

    COMBOFIX-Script

    • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

      File::
      c:\windows\system32\drivers\ecbqyvrxmxvxtuij.sys
    • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

      [external image: Posted Image]
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
    • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
    • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
    CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


    ESET Online Scanner:

    Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

    Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

    • Please go here then click on: [external image: Posted Image]

      Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
      All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

    • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
    • When prompted allow the Add-On/Active X to install.
    • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
    • Now click on Advanced Settings and select the following:
      • Scan for potentially unwanted applications
      • Scan for potentially unsafe applications
      • Enable Anti-Stealth Technology
    • Now click on: [external image: Posted Image]
    • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
    • When completed the Online Scan will begin automatically.
    • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
    • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
    • Now click on: [external image: Posted Image]
    • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
    • Copy and paste that log as a reply to this topic.

    Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
here the log for Rooter.exe __________________ Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully … . Windows XP . (5.1.2600) Service Pack 2 [32_bits] - x86 Family 6 Model 15 Stepping 6, GenuineIntel . [wscsvc] STOPPED (state:1) : Security Center -> Disabled ! [SharedAccess] RUNNING (state:4) Windows Firewall -> Disabled ! . Internet Explorer 8.0.6001.18702 Mozilla Firefox 3.5.2 (en-US) . C:\ [Fixed-NTFS] .. ( Total:70 Go - Free:9 Go ) D:\ [CD_Rom] T:\ [Network] .. ( Total:24 Go - Free:9 Go ) U:\ [Network] .. ( Total:19 Go - Free:16 Go ) . Scan : 23:09.11 Path : C:\Documents and Settings\dhiraj\Desktop\Rooter.exe User : dhiraj ( Administrator -> YES ) . ———————-\\ Processes . Locked [System Process] (0) ______ System (4) ______ \SystemRoot\System32\smss.exe (1440) ______ \??\C:\WINDOWS\system32\csrss.exe (1536) ______ \??\C:\WINDOWS\system32\winlogon.exe (1560) ______ C:\WINDOWS\system32\services.exe (1604) ______ C:\WINDOWS\system32\lsass.exe (1616) ______ C:\WINDOWS\system32\ibmpmsvc.exe (1824) ______ C:\WINDOWS\system32\svchost.exe (1852) ______ C:\WINDOWS\system32\svchost.exe (1940) ______ C:\WINDOWS\System32\svchost.exe (248) ______ C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (344) ______ C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (524) ______ C:\WINDOWS\system32\svchost.exe (832) ______ C:\WINDOWS\system32\svchost.exe (912) ______ C:\WINDOWS\system32\spoolsv.exe (1316) ______ C:\WINDOWS\System32\SCardSvr.exe (780) ______ C:\WINDOWS\system32\svchost.exe (1088) ______ C:\WINDOWS\system32\IPSSVC.EXE (1144) ______ C:\WINDOWS\System32\svchost.exe (1172) Locked avp.exe (1196) ______ C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (1248) ______ C:\Program Files\Aladdin\eToken\PKIClient\x32\eTSrv.exe (1512) ______ C:\WINDOWS\IntelliAdminRC3\Agent32.exe (1792) ______ C:\PROGRA~1\MICROS~4\MSSQL\binn\sqlservr.exe (1892) ______ C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (904) ______ C:\WINDOWS\system32\svchost.exe (1060) ______ C:\WINDOWS\System32\TPHDEXLG.EXE (1128) ______ C:\WINDOWS\system32\TpKmpSVC.exe (1184) ______ C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe (1244) ______ C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe (1468) ______ C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe (1540) ______ C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe (1876) ______ C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe (2112) ______ C:\WINDOWS\System32\alg.exe (3324) ______ C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe (3348) ______ C:\WINDOWS\Explorer.EXE (2236) ______ C:\WINDOWS\system32\TpShocks.exe (2444) Locked avp.exe (2472) ______ C:\Program Files\Microsoft ActiveSync\wcescomm.exe (2492) ______ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (2516) ______ C:\WINDOWS\system32\ctfmon.exe (2560) ______ C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (2696) ______ C:\PROGRA~1\MICROS~3\rapimgr.exe (2704) ______ C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (3420) ______ C:\WINDOWS\System32\svchost.exe (2820) ______ C:\WINDOWS\system32\wuauclt.exe (1056) ______ C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe (1100) ______ C:\Program Files\Internet Explorer\iexplore.exe (5860) ______ C:\Program Files\Internet Explorer\iexplore.exe (2724) ______ C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE (4840) ______ C:\Program Files\Microsoft Office\Office10\WINWORD.EXE (5524) ______ C:\Program Files\Internet Explorer\iexplore.exe (2624) ______ C:\Documents and Settings\dhiraj\Desktop\Rooter.exe (3716) . ———————-\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 –[ MBR ]– (Start_Offset:32256 | Length:75486749184) \Device\Harddisk0\Partition2 (Start_Offset:75486781440 | Length:4536483840) . ———————-\\ Scheduled Tasks . C:\WINDOWS\Tasks\desktop.ini C:\WINDOWS\Tasks\Dhiraj 23102008.job C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-926495626-1003886262-1936394565-1004.job C:\WINDOWS\Tasks\PMTask.job C:\WINDOWS\Tasks\SA.DAT C:\WINDOWS\Tasks\Scheduled backup of T60.job . ———————-\\ Registry . . ———————-\\ Files & Folders . ———————-\\ Scan completed at 23:09.27 . C:\Rooter$\Rooter_1.txt - (02/09/2009 | 23:09.27) __________________________________ I have downloaded the new Combofix.exe but have not yet run it .. wanted to clarify on : 1. Symantec does not show in the Installed program list 2. Last time ( a week ago i.e. ) when i had ran Combofix , it gave a warning that Symantec is still running 3. I always have 2 copies of avp.exe running in processes Please advise next course of action thanks Dhiraj
dhirajmaskara,

Two instances of AVP.exe in running processes is normal.

I've modified the CFscript:

killall::
File::
c:\windows\system32\drivers\ecbqyvrxmxvxtuij.sys

Folder::
c:\program files\Symantec Client Security\Symantec AntiVirus

Driver::
SavRoam

If you get a warning about Symantec, go ahead and run it anyway.
i ran combofix with the script you gave .. i got the symantec warning and i went ahead. The whole program ran and then rebooted without any problem. At the reboot start up , it gave the following error "Sql Server could not find the default instance (MSSQLSERVER) - please specify the name of an exisiting instance on the invocation of sqlservr.exe" i had got this msg last time also ( a week ago ) .. for which i reinstalled Sql Server ( in fact it just repaired the current installation ) and it started functioning properly. After this i moved on & the winXp startup window open with a dos prompt window heading "Find3M" , the window had text saying " preparing log report …" etc etc .. The machine hung at this point and did not respond to Ctlr + Alt + Del also … after waiting for some time , i had to reboot the machine and now i do not have any log from combofix .. what should i do now ? run it again ?
dhirajmaskara,

Let's see if the logs were saved before hanging.

Please:
  • Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
  • Click on Explore
  • Click on Local Disk (C:) in the left-hand window pane
  • Look for ComboFix.txt in the right-hand window pane and right click on it
  • Put your cursor (arrow) on Open With
  • Move your cursor to the new menu that opens and click on Choose Program…
  • Click on Notepad

When file opens, Copy/Paste text here

By the way, I neglected to point out earlier that the following warning is posted about a thousand times around this forum:

DO NOT use any TOOLS such as Combofix, SmitfraudFix, MBAM, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


You took a major risk by not heeding this warning. Also, you should know that this may be why your log wasn't picked up earlier. There are helpers who will not work a log where this warning was violated.
well , i did read the warning but at the same time assumed that undertaking action step by step as already described by a helper would be same as supervision , at the same time , i was hoping to save some of your time. What i missed was that the software are to be handled differently for different problems. Anyways , i hope you will be able to help me out of this without reinstalling the OS. I could not find any log file on "c:\" but there is one inside "c:\combofix" .. i'm pasting it below but does not look relevant ____________________________________________ ComboFix 09-09-01.07 - dhiraj 3-Sep-2009 1:28:17.2.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1526.648 [GMT 5.5:30] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\dhiraj\Desktop\CFScript.txt.txt AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C} FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Symantec Client Firewall *disabled* {5CB76A43-5FAD-476B-B9FF-26FA61F13187} FILE :: "c:\windows\system32\drivers\ecbqyvrxmxvxtuij.sys" _________________________________________________ should i run eset now ?
dhirajmaskara, That is the file I'm looking for and it is showing that it was still building the log when the computer hung up. Yes. Please go ahead and run Eset and we will see what it tells us before we take a shot at Symantec a different way.
heres the Eset Log ________________________ ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=6 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6050 # api_version=3.0.2 # EOSSerial=db7b359a4931604c80fab173847033fe # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-09-03 09:33:41 # local_time=2009-09-03 03:03:41 (+0530, India Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=1283 63 100 99 273085706562500 # compatibility_mode=3585 63 50 0 0 # scanned=125762 # found=2 # cleaned=0 # scan_time=8516 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ecbqyvrxmxvxtuij.sys.vir a variant of Win32/Olmarik.LF trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP10\A0000752.sys a variant of Win32/Olmarik.LF trojan 00000000000000000000000000000000 I ___________________________________________________ awaiting further instructions
dhirajmaskara,

the scan took around 2.5 hrs .. is that normal or do i have too many files on my comp ?

That's about average. 5 or 6 hours is not unusual.

Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
    (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    SavRoam
    
    :Files
    c:\program files\Symantec Client Security
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
yes , it rebooted the machine .. the log file is as under _______________________________________ All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== SERVICES/DRIVERS ========== Service\Driver SavRoam not found. Service\Driver SavRoam not found. ========== FILES ========== c:\program files\Symantec Client Security moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Administrator.MAHABIR ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: administrator.MAHABIR.000 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: dhiraj ->Temp folder emptied: 58298 bytes ->Temporary Internet Files folder emptied: 1919953 bytes ->Java cache emptied: 438445 bytes ->FireFox cache emptied: 12765811 bytes User: Dhiraj.MAHABIR ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 78991 bytes ->Java cache emptied: 831611 bytes ->Google Chrome cache emptied: 0 bytes User: DHIRAJ~1~MAH User: expert ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 32902 bytes %systemdrive% .tmp files removed: 838 bytes C:\WINDOWS\2146B7E6FC1C42309952E9CA2260AA08.TMP folder deleted successfully. C:\WINDOWS\C521C1263ABD4B7BA7332149AEDECF5A.TMP folder deleted successfully. %systemroot% .tmp files removed: 2631919 bytes %systemroot%\System32 .tmp files removed: 3052561 bytes File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4d0.dat scheduled to be deleted on reboot. Windows Temp folder emptied: 49635 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 20.91 mb OTM by OldTimer - Version 3.0.0.6 log created on 09032009_224155 Files moved on Reboot… File C:\WINDOWS\temp\Perflib_Perfdata_4d0.dat not found! Registry entries deleted on Reboot… _______________________________________________
yes , it rebooted the machine .. the log file is as under _______________________________________ All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== SERVICES/DRIVERS ========== Service\Driver SavRoam not found. Service\Driver SavRoam not found. ========== FILES ========== c:\program files\Symantec Client Security moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Administrator.MAHABIR ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: administrator.MAHABIR.000 ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: dhiraj ->Temp folder emptied: 58298 bytes ->Temporary Internet Files folder emptied: 1919953 bytes ->Java cache emptied: 438445 bytes ->FireFox cache emptied: 12765811 bytes User: Dhiraj.MAHABIR ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 78991 bytes ->Java cache emptied: 831611 bytes ->Google Chrome cache emptied: 0 bytes User: DHIRAJ~1~MAH User: expert ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 32902 bytes %systemdrive% .tmp files removed: 838 bytes C:\WINDOWS\2146B7E6FC1C42309952E9CA2260AA08.TMP folder deleted successfully. C:\WINDOWS\C521C1263ABD4B7BA7332149AEDECF5A.TMP folder deleted successfully. %systemroot% .tmp files removed: 2631919 bytes %systemroot%\System32 .tmp files removed: 3052561 bytes File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4d0.dat scheduled to be deleted on reboot. Windows Temp folder emptied: 49635 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 20.91 mb OTM by OldTimer - Version 3.0.0.6 log created on 09032009_224155 Files moved on Reboot… File C:\WINDOWS\temp\Perflib_Perfdata_4d0.dat not found! Registry entries deleted on Reboot… _______________________________________________

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI