This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Braviax and some other stuff :/

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone,

The last week or so I got a problem with my computer after visiting a website.. I got braviax trojan, some PC Antispyware 2010 and a lot of other things :/

I did a lot of runs with Malware Bytes, SB S&D, Spyware doctor, Ad-aware which some of them worked, found some stuff removed them, but on the next restart they all came back. Well whenever I was connected to the NET it was just re-downloading them after bringing down the windows firewall.

So for now I just downloaded Comodo Firewall which stops them for a while but doesn't do anything else. Here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:47:30 μμ, on 4/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\WINDOWS\system32\cryptainersrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\CTFMON.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Συνδέσεις
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [braviax] (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Ε&ξαγωγή στο Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Έρευνα - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [searching] Αναζήτηση από τη γραμμή διευθύνσεων
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu…?1244314583359
O17 - HKLM\System\CCS\Services\Tcpip\..\{42E6E545-9DCB-4DA1-BA95-3EF06119E06C}: NameServer = 195.170.0.1,195.170.2.2
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdagent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service (ipod service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Cryptainer service (ssoftservice) - Cypherix Software (India) Pvt. Ltd. - C:\WINDOWS\SYSTEM32\cryptainersrv.exe
O23 - Service: Windows WorkGroup (svrhost) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\MSINFO\svrhost.exe (file missing)
O23 - Service: SymSnapService - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe

–
End of file - 8700 bytes


Nod also finds some other stuff here (braviax keeps coming every 1 day or so..):
5/9/2009 12:29:06 μμ Startup scanner file C:\WINDOWS\system32\braviax.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
5/9/2009 12:27:30 μμ Startup scanner file C:\WINDOWS\system32\Drivers\Ntfs.sys a variant of Win32/Kryptik.ABX trojan unable to clean
5/9/2009 12:25:59 μμ Real-time file system protection file C:\WINDOWS\system32\drivers\agp440.sys Win32/Wigon.LZ trojan unable to clean NT AUTHORITY\SYSTEM Event occurred during an attempt to access the file by the application: C:\WINDOWS\system32\svchost.exe.


I also got a very slow pc today for some reason :/
Please help me out here :P
Thanks!
Hi jsmith, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

I also got a very slow pc today for some reason

When you installed Comodo, was it with or with the antivirus portion?



Please disable this program and leave it disabled until we are finished as it may interfere with the cleaning.

SPYBOT TEATIMER
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done.
  • (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]


Please read through the instructions to familarize youself with what to expect when the tool runs.


It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to combofix.com as follows: (just substitute combofix.com where is says combo-fix.)

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log. How's the computer?

Thanks
Thank you mate :)

Comodo Firewall only..

I did what you told me to and here are the results/log:


ComboFix 09-09-06.02 - Markella 07/09/2009 1:34.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1253.30.1032.18.767.508 [GMT 3:00]
Running from: c:\documents and settings\[removed]\Επιφάνεια εργασίας\combofix.com
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\azyh.pif
c:\documents and settings\All Users\Application Data\ejokadekoh.inf
c:\documents and settings\All Users\Application Data\ibazivox.ban
c:\documents and settings\All Users\Application Data\ibubuv.sys
c:\documents and settings\All Users\Application Data\wymunatusi.scr
c:\documents and settings\All Users\Application Data\xaqed.bin
c:\documents and settings\All Users\Application Data\ynenujazu.lib
c:\documents and settings\All Users\Documents\alazekyzuw.bin
c:\documents and settings\All Users\Documents\cyti.exe
c:\documents and settings\All Users\Documents\dihymy.reg
c:\documents and settings\All Users\Documents\uqohut.vbs
c:\documents and settings\All Users\Documents\xorefacoge.sys
c:\documents and settings\All Users\Documents\ylofiletu.dl
c:\documents and settings\LocalService\Cookies\abokiqiqyh.pif
c:\documents and settings\LocalService\Local Settings\Application Data\ecid.scr
c:\documents and settings\LocalService\Local Settings\Application Data\idahibetyv.pif
c:\documents and settings\LocalService\Local Settings\Application Data\roroxok.bat
c:\documents and settings\LocalService\Local Settings\Temporary Internet files\covut.dll
c:\documents and settings\LocalService\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\documents and settings\NetworkService\Application Data\azahit.exe
c:\documents and settings\NetworkService\Application Data\kaqajupoz.dl
c:\documents and settings\NetworkService\Application Data\ujepuvivyt.inf
c:\documents and settings\NetworkService\Cookies\rudawyqyha.sys
c:\documents and settings\NetworkService\Local Settings\Application Data\bukeq.ban
c:\documents and settings\NetworkService\Local Settings\Application Data\xexupibuv.inf
c:\documents and settings\NetworkService\Local Settings\Application Data\ybyf.dl
c:\documents and settings\NetworkService\Local Settings\Temporary Internet files\isusabakyk.ban
c:\program files\Common Files\ewyjaba._dl
c:\program files\Common Files\gehaxopu.inf
c:\program files\Common Files\qarefa.ban
c:\program files\Common Files\ruzuxusap.inf
c:\program files\Common Files\sohonydik.pif
c:\program files\Common Files\udekis.com
c:\program files\Common Files\uwivymyv.bin
c:\program files\Common Files\ylulebap.bat
c:\program files\Common Files\ysajakac.ban
c:\windows\Ινδιάνος .bmp
c:\windows\anavuhody.inf
c:\windows\axotikypul.pif
c:\windows\beweva.scr
c:\windows\qavame.dl
c:\windows\system32\drivers\5522e4be.sys
c:\windows\system32\drivers\Sonyhcp.dll
c:\windows\system32\nsprs.dll
c:\windows\system32\ovit.reg
c:\windows\system32\roqohuz.exe
c:\windows\system32\ssprs.dll
c:\windows\system32\uzezijyr.dll
c:\windows\talyvovelo.bat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_5522e4be


((((((((((((((((((((((((( Files Created from 2009-08-06 to 2009-09-06 )))))))))))))))))))))))))))))))
.

2009-09-04 19:45 . 2009-09-04 19:45 ——– d—–w- c:\program files\Trend Micro
2009-08-22 17:46 . 2009-08-22 17:48 ——– d—–w- c:\program files\iTunes
2009-08-21 16:07 . 2009-08-21 16:07 0 —-a-w- c:\windows\system32\drivers\rtvn.sys
2009-08-21 11:40 . 2009-08-21 11:40 ——– d—–w- c:\program files\CCleaner
2009-08-20 13:35 . 2009-08-20 15:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo
2009-08-20 13:35 . 2009-08-26 10:42 179792 —-a-w- c:\windows\system32\guard32.dll
2009-08-20 13:35 . 2009-08-26 10:42 87104 —-a-w- c:\windows\system32\drivers\inspect.sys
2009-08-20 13:35 . 2009-08-26 10:42 25160 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-08-20 13:35 . 2009-08-26 10:42 132168 —-a-w- c:\windows\system32\drivers\cmdguard.sys
2009-08-20 13:33 . 2009-08-20 13:33 ——– d—–w- c:\program files\COMODO
2009-08-19 23:49 . 2004-08-03 22:30 4224 -c–a-w- c:\windows\system32\dllcache\beep.sys
2009-08-18 13:39 . 2009-08-18 13:39 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-18 10:47 . 2009-08-18 10:47 18451 —-a-w- c:\program files\Common Files\uhini.dat
2009-08-18 10:47 . 2009-08-18 10:47 15474 —-a-w- c:\windows\system32\wyhisol.com
2009-08-17 21:59 . 2009-08-17 21:59 ——– d—–w- c:\documents and settings\Markella\Application Data\Malwarebytes
2009-08-17 21:59 . 2009-08-03 10:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-17 21:59 . 2009-08-17 21:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-17 21:58 . 2009-08-03 10:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-17 21:58 . 2009-08-17 21:59 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-17 15:33 . 2004-08-03 22:30 45568 -c–a-w- c:\windows\system32\dllcache\nsepm.dll
2009-08-17 15:32 . 2004-08-03 22:30 39936 -c–a-w- c:\windows\system32\dllcache\hostmib.dll
2009-08-17 15:31 . 2004-05-12 21:39 598071 -c–a-w- c:\windows\system32\dllcache\fpmmc.dll
2009-08-17 15:28 . 2004-08-03 22:30 16384 -c–a-w- c:\windows\system32\dllcache\isignup.exe
2009-08-17 15:24 . 2004-08-03 22:30 32768 -c–a-w- c:\windows\system32\dllcache\icwdl.dll
2009-08-17 15:21 . 2004-08-03 22:30 24576 -c–a-w- c:\windows\system32\dllcache\inetwiz.exe
2009-08-17 15:20 . 2004-08-03 22:30 86016 -c–a-w- c:\windows\system32\dllcache\icwconn2.exe
2009-08-17 15:19 . 2004-08-03 22:30 219648 -c–a-w- c:\windows\system32\dllcache\icwconn1.exe
2009-08-17 13:37 . 2004-08-03 22:30 24661 -c–a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-08-17 13:37 . 2004-08-03 22:30 24661 —-a-w- c:\windows\system32\spxcoins.dll
2009-08-17 13:37 . 2004-08-03 22:30 13312 -c–a-w- c:\windows\system32\dllcache\irclass.dll
2009-08-17 13:37 . 2004-08-03 22:30 13312 —-a-w- c:\windows\system32\irclass.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-06 18:27 . 2007-02-08 09:50 ——– d—–w- c:\documents and settings\Markella\Application Data\uTorrent
2009-09-05 17:05 . 2004-08-03 22:30 73146 —-a-w- c:\windows\system32\perfc008.dat
2009-09-05 17:05 . 2004-08-03 22:30 480304 —-a-w- c:\windows\system32\perfh008.dat
2009-09-02 09:44 . 2004-08-03 23:07 94016 —-a-w- c:\windows\system32\drivers\agp440.sys
2009-08-22 18:04 . 2008-08-13 17:06 ——– d—–w- c:\program files\Safari
2009-08-22 17:47 . 2007-02-02 16:03 ——– d—–w- c:\program files\iPod
2009-08-22 17:46 . 2007-07-13 11:17 ——– d—–w- c:\program files\Common Files\Apple
2009-08-22 13:38 . 2004-08-03 22:30 625952 —-a-w- c:\windows\system32\drivers\ntfs.sys
2009-08-21 16:07 . 2009-08-21 16:07 356 —-a-w- c:\program files\sjbdpu.txt
2009-08-19 14:44 . 2009-08-19 14:44 11529 —-a-w- c:\program files\Common Files\yfuwyjodob._sy
2009-08-18 10:47 . 2009-08-18 10:47 10924 —-a-w- c:\program files\Common Files\todaru._sy
2009-08-17 23:42 . 2007-02-01 14:40 73744 —-a-w- c:\documents and settings\Markella\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-17 15:09 . 2007-02-01 14:26 26092 —-a-w- c:\windows\system32\emptyregdb.dat
2009-08-17 13:35 . 2009-08-17 13:35 0 ——w- c:\windows\SET4E.tmp
2009-07-15 11:05 . 2009-07-15 11:04 ——– d—–w- c:\program files\QuickTime
2008-12-22 21:34 . 2007-02-01 14:49 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-22 21:34 . 2007-02-01 14:49 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-22 21:34 . 2007-02-01 14:49 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-22 21:34 . 2007-02-01 14:49 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-12-22 21:34 . 2007-02-01 14:49 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2007-05-06 18:05 . 2007-05-04 13:04 88 –sh–r- c:\windows\system32\DF3F20FA00.sys
2007-12-21 18:33 . 2007-05-04 13:04 2568 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

——- Sigcheck ——-

[7] DA1F27D85E0D1525F6621372E7B685E9 [5.1.2600.0 (XPClient.010817-1148)] c:\windows\system32\dllcache\beep.sys

[-] 39815F1882474A4EAD82CB6EFFB1469E [——] c:\windows\system32\dllcache\ntfs.sys
[-] 39815F1882474A4EAD82CB6EFFB1469E [——] c:\windows\system32\drivers\ntfs.sys

c:\windows\system32\drivers\beep.sys … is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-04-21 94208]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"D-Link AirPlus XtremeG"="c:\program files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2005-08-04 1294336]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 49152]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-13 177472]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-03-19 2029640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-08-26 1796368]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-05-13 67072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\Markella\Start Menu\¨¦š¨α££˜«˜\„΅΅ε¤ž©ž\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^ID_Γρήγορη_εκκίνηση_πινακοθήκης_HP_ell.lnk]
path=c:\documents and settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\ID_Γρήγορη_εκκίνηση_πινακοθήκης_HP_ell.lnk
backup=c:\windows\pss\ID_Γρήγορη_εκκίνηση_πινακοθήκης_HP_ell.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Markella^Start Menu^Προγράμματα^Εκκίνηση^Picture Motion Browser Media Check Tool.lnk]
path=c:\documents and settings\Markella\Start Menu\Προγράμματα\Εκκίνηση\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"g:\\The Lord of the Rings Online\\lotroclient.exe"=
"g:\\BitLord Downloads\\Programs\\LimeWire\\LimeWire.exe"=
"g:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"g:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"g:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 cmdguard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [20/8/2009 4:35 μμ 132168]
R1 cmdhlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [20/8/2009 4:35 μμ 25160]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [19/3/2009 11:44 πμ 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [19/3/2009 11:45 πμ 93848]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [19/3/2009 11:44 πμ 731840]
R2 ssoftnt4;ssoftnt4;c:\windows\system32\drivers\ssoftnt4.sys [19/10/2007 12:09 μμ 100728]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [4/8/2004 1:30 πμ 5120]
R3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [26/7/2005 3:32 μμ 348352]
R3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [20/12/2007 5:13 μμ 1553896]
S2 svrhost;Windows WorkGroup;c:\program files\Common Files\Microsoft Shared\MSINFO\svrhost.exe –> c:\program files\Common Files\Microsoft Shared\MSINFO\svrhost.exe [?]
S3 ATHFMWDL;D-Link predator Bootloader driver;c:\windows\system32\drivers\Athfmwdl.sys [26/7/2005 3:35 μμ 43392]
S3 sdAuxService;Spyware Doctor Auxiliary Service;c:\program files\Spyware Doctor\svcntaux.exe [8/9/2007 8:11 μμ 708176]
.
Contents of the 'Scheduled Tasks' folder

2009-05-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
IE: Ε&ξαγωγή στο Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: {42E6E545-9DCB-4DA1-BA95-3EF06119E06C} = 195.170.0.1,195.170.2.2
FF - ProfilePath - c:\documents and settings\Markella\Application Data\Mozilla\Firefox\Profiles\lqi6zm2x.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-07 02:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\Documents and Settings\\All Users\\Application Data\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000000
"ProductCode"="{FE9C13F6-6BBD-47D3-B939-F7E061BC4930}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.0.417.0"
"UniqueId"="011FC9374A130C16"
"ScannerBuild"=dword:0000121d
"ScannerVersionId"=dword:00000f6c
"ScannerVersion"="Open window for status."
"FixId"=dword:00000004
.
———————— Other Running Processes ————————
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\Protexis\License Service\PSIService.exe
c:\windows\system32\cryptainersrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Completion time: 2009-09-06 2:40 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-06 23:40

Pre-Run: 10 Κατάλογοι 16.485.867.520 διαθέσιμα byte
Post-Run: 10 Κατάλογοι 16.497.614.848 διαθέσιμα byte

289
Hi jsmith,

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!


Before we go any further we need to install the windows Recovery Console. This is very important. I believe it failed because Comodo firewall was not disabled.

FW: COMODO Firewall *enabled*


I'd like you to try it this way. Disable Comodo as well as your antivirus program.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
Do Not copy the word CODE

SkipFix::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

You should see these images and possible a warning that combofix will continue in reduced function mode.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue


Please post back with the combofix log. See you in a few minutes.

Thanks
Hello oldman960,

Last time I only closed Comodo and that didn't disable it :/
This time I disabled it but I still didn't see the messages about installing it on my pc. I only saw a message about getting a new version of ComboFix which I said no (should I download it?)

Here is the log:


ComboFix 09-09-06.02 - Markella 07/09/2009 12:47.4.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1253.30.1032.18.767.349 [GMT 3:00]
Running from: c:\documents and settings\[removed]\Επιφάνεια εργασίας\combofix.com
Command switches used :: c:\docume~1\Markella\6808~1\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.

((((((((((((((((((((((((( Files Created from 2009-08-07 to 2009-09-07 )))))))))))))))))))))))))))))))
.

2009-09-04 19:45 . 2009-09-04 19:45 ——– d—–w- c:\program files\Trend Micro
2009-08-22 17:46 . 2009-08-22 17:48 ——– d—–w- c:\program files\iTunes
2009-08-21 16:07 . 2009-08-21 16:07 0 —-a-w- c:\windows\system32\drivers\rtvn.sys
2009-08-21 11:40 . 2009-08-21 11:40 ——– d—–w- c:\program files\CCleaner
2009-08-20 13:35 . 2009-08-20 15:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo
2009-08-20 13:35 . 2009-08-26 10:42 179792 —-a-w- c:\windows\system32\guard32.dll
2009-08-20 13:35 . 2009-08-26 10:42 87104 —-a-w- c:\windows\system32\drivers\inspect.sys
2009-08-20 13:35 . 2009-08-26 10:42 25160 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-08-20 13:35 . 2009-08-26 10:42 132168 —-a-w- c:\windows\system32\drivers\cmdguard.sys
2009-08-20 13:33 . 2009-08-20 13:33 ——– d—–w- c:\program files\COMODO
2009-08-19 23:49 . 2004-08-03 22:30 4224 -c–a-w- c:\windows\system32\dllcache\beep.sys
2009-08-18 13:39 . 2009-08-18 13:39 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-18 10:47 . 2009-08-18 10:47 18451 —-a-w- c:\program files\Common Files\uhini.dat
2009-08-18 10:47 . 2009-08-18 10:47 15474 —-a-w- c:\windows\system32\wyhisol.com
2009-08-17 21:59 . 2009-08-17 21:59 ——– d—–w- c:\documents and settings\Markella\Application Data\Malwarebytes
2009-08-17 21:59 . 2009-08-03 10:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-17 21:59 . 2009-08-17 21:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-17 21:58 . 2009-08-03 10:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-17 21:58 . 2009-08-17 21:59 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-17 15:33 . 2004-08-03 22:30 45568 -c–a-w- c:\windows\system32\dllcache\nsepm.dll
2009-08-17 15:32 . 2004-08-03 22:30 39936 -c–a-w- c:\windows\system32\dllcache\hostmib.dll
2009-08-17 15:31 . 2004-05-12 21:39 598071 -c–a-w- c:\windows\system32\dllcache\fpmmc.dll
2009-08-17 15:28 . 2004-08-03 22:30 16384 -c–a-w- c:\windows\system32\dllcache\isignup.exe
2009-08-17 15:24 . 2004-08-03 22:30 32768 -c–a-w- c:\windows\system32\dllcache\icwdl.dll
2009-08-17 15:21 . 2004-08-03 22:30 24576 -c–a-w- c:\windows\system32\dllcache\inetwiz.exe
2009-08-17 15:20 . 2004-08-03 22:30 86016 -c–a-w- c:\windows\system32\dllcache\icwconn2.exe
2009-08-17 15:19 . 2004-08-03 22:30 219648 -c–a-w- c:\windows\system32\dllcache\icwconn1.exe
2009-08-17 13:37 . 2004-08-03 22:30 24661 -c–a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-08-17 13:37 . 2004-08-03 22:30 24661 —-a-w- c:\windows\system32\spxcoins.dll
2009-08-17 13:37 . 2004-08-03 22:30 13312 -c–a-w- c:\windows\system32\dllcache\irclass.dll
2009-08-17 13:37 . 2004-08-03 22:30 13312 —-a-w- c:\windows\system32\irclass.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-06 18:27 . 2007-02-08 09:50 ——– d—–w- c:\documents and settings\Markella\Application Data\uTorrent
2009-09-05 17:05 . 2004-08-03 22:30 73146 —-a-w- c:\windows\system32\perfc008.dat
2009-09-05 17:05 . 2004-08-03 22:30 480304 —-a-w- c:\windows\system32\perfh008.dat
2009-09-02 09:44 . 2004-08-03 23:07 94016 —-a-w- c:\windows\system32\drivers\agp440.sys
2009-08-22 18:04 . 2008-08-13 17:06 ——– d—–w- c:\program files\Safari
2009-08-22 17:47 . 2007-02-02 16:03 ——– d—–w- c:\program files\iPod
2009-08-22 17:46 . 2007-07-13 11:17 ——– d—–w- c:\program files\Common Files\Apple
2009-08-22 13:38 . 2004-08-03 22:30 625952 —-a-w- c:\windows\system32\drivers\ntfs.sys
2009-08-21 16:07 . 2009-08-21 16:07 356 —-a-w- c:\program files\sjbdpu.txt
2009-08-19 14:44 . 2009-08-19 14:44 11529 —-a-w- c:\program files\Common Files\yfuwyjodob._sy
2009-08-18 10:47 . 2009-08-18 10:47 10924 —-a-w- c:\program files\Common Files\todaru._sy
2009-08-17 23:42 . 2007-02-01 14:40 73744 —-a-w- c:\documents and settings\Markella\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-17 15:09 . 2007-02-01 14:26 26092 —-a-w- c:\windows\system32\emptyregdb.dat
2009-08-17 13:35 . 2009-08-17 13:35 0 ——w- c:\windows\SET4E.tmp
2009-07-15 11:05 . 2009-07-15 11:04 ——– d—–w- c:\program files\QuickTime
2008-12-22 21:34 . 2007-02-01 14:49 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-22 21:34 . 2007-02-01 14:49 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-22 21:34 . 2007-02-01 14:49 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-22 21:34 . 2007-02-01 14:49 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-12-22 21:34 . 2007-02-01 14:49 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2007-05-06 18:05 . 2007-05-04 13:04 88 –sh–r- c:\windows\system32\DF3F20FA00.sys
2007-12-21 18:33 . 2007-05-04 13:04 2568 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

——- Sigcheck ——-

[7] DA1F27D85E0D1525F6621372E7B685E9 [5.1.2600.0 (XPClient.010817-1148)] c:\windows\system32\dllcache\beep.sys

[-] 39815F1882474A4EAD82CB6EFFB1469E [——] c:\windows\system32\dllcache\ntfs.sys
[-] 39815F1882474A4EAD82CB6EFFB1469E [——] c:\windows\system32\drivers\ntfs.sys

c:\windows\system32\drivers\beep.sys … is missing !!
.
((((((((((((((((((((((((((((( SnapShot@2009-09-06_23.36.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-07 09:20 . 2009-09-07 09:20 16384 c:\windows\Temp\Perflib_Perfdata_b60.dat
+ 2009-09-07 09:19 . 2009-09-07 09:19 16384 c:\windows\Temp\Perflib_Perfdata_9b4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-04-21 94208]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"D-Link AirPlus XtremeG"="c:\program files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2005-08-04 1294336]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 49152]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-13 177472]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-03-19 2029640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-08-26 1796368]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-05-13 67072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\Markella\Start Menu\¨¦š¨α££˜«˜\„΅΅ε¤ž©ž\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^ID_Γρήγορη_εκκίνηση_πινακοθήκης_HP_ell.lnk]
path=c:\documents and settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\ID_Γρήγορη_εκκίνηση_πινακοθήκης_HP_ell.lnk
backup=c:\windows\pss\ID_Γρήγορη_εκκίνηση_πινακοθήκης_HP_ell.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Markella^Start Menu^Προγράμματα^Εκκίνηση^Picture Motion Browser Media Check Tool.lnk]
path=c:\documents and settings\Markella\Start Menu\Προγράμματα\Εκκίνηση\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"g:\\The Lord of the Rings Online\\lotroclient.exe"=
"g:\\BitLord Downloads\\Programs\\LimeWire\\LimeWire.exe"=
"g:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"g:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"g:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 cmdguard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [20/8/2009 4:35 μμ 132168]
R1 cmdhlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [20/8/2009 4:35 μμ 25160]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [19/3/2009 11:44 πμ 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [19/3/2009 11:45 πμ 93848]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [19/3/2009 11:44 πμ 731840]
R2 ssoftnt4;ssoftnt4;c:\windows\system32\drivers\ssoftnt4.sys [19/10/2007 12:09 μμ 100728]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [4/8/2004 1:30 πμ 5120]
R3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [26/7/2005 3:32 μμ 348352]
R3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [20/12/2007 5:13 μμ 1553896]
S2 svrhost;Windows WorkGroup;c:\program files\Common Files\Microsoft Shared\MSINFO\svrhost.exe –> c:\program files\Common Files\Microsoft Shared\MSINFO\svrhost.exe [?]
S3 ATHFMWDL;D-Link predator Bootloader driver;c:\windows\system32\drivers\Athfmwdl.sys [26/7/2005 3:35 μμ 43392]
S3 sdAuxService;Spyware Doctor Auxiliary Service;c:\program files\Spyware Doctor\svcntaux.exe [8/9/2007 8:11 μμ 708176]
.
Contents of the 'Scheduled Tasks' folder

2009-05-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
IE: Ε&ξαγωγή στο Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: {42E6E545-9DCB-4DA1-BA95-3EF06119E06C} = 195.170.0.1,195.170.2.2
FF - ProfilePath - c:\documents and settings\Markella\Application Data\Mozilla\Firefox\Profiles\lqi6zm2x.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-07 12:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\Documents and Settings\\All Users\\Application Data\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000000
"ProductCode"="{FE9C13F6-6BBD-47D3-B939-F7E061BC4930}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.0.417.0"
"UniqueId"="011FC9374A130C16"
"ScannerBuild"=dword:0000121d
"ScannerVersionId"=dword:00000f6c
"ScannerVersion"="Open window for status."
"FixId"=dword:00000004
.
Completion time: 2009-09-07 12:52
ComboFix-quarantined-files.txt 2009-09-07 09:52
ComboFix2.txt 2009-09-07 09:43
ComboFix3.txt 2009-09-07 09:33
ComboFix4.txt 2009-09-06 23:40

Pre-Run: 10 Κατάλογοι 16.445.632.512 διαθέσιμα byte
Post-Run: 10 Κατάλογοι 16.435.396.608 διαθέσιμα byte

227
Hi jsmith, Let me check into this a bit. Did you have an internet connection when you were trying to install the Recovery Console? Do you have the original XP discs? Thanks

Hi jsmith,

Let me check into this a bit. Did you have an internet connection when you were trying to install the Recovery Console?

Do you have the original XP discs?

Thanks


Hello there,

I had an active internet connection. It does something like validation or backing up some stuff (10 steps or something) but it seems like it never finish.

I don't have original XP but I got the installation disc (if that helps).

Thank you.
Hi jsmith,

Thanks for the additional information.

but I got the installation disc

I suspect these are OEM discs. If that is the case, they won't help.

I have asked the developer if he has some insight into what is going on. Please be patient, we will resolve this and get you on your way. I oplogize for the delay but it is in your best interest to get the Recovery Console installed..

Thanks
A little more information.. When I run it it will load up for a few seconds and then pop ups the agreement. After that I get this message:

[external image: Posted Image]

And I think when it is down the window closes and it starts scanning :/

Thanks!
Hi jsmith,

Apparently it is a language issue.

Do it this way.

Locate combofix.com on your desktop, right click it and select delete. Download a new copy from either of these links. Do not rename it this time.

Link 1
Link 2

Next

Go to Microsoft's website => Greek

Click the Download button and download it directly to your Desktop

📎RCGREEK.JPG

Do not change the name of the file..

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Drag the setup package onto ComboFix.exe and drop it.

    [external image: Posted Image]

    [external image: Posted Image]
  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.
  • At the next prompt, click 'Yes' to run the full ComboFix scan.
  • When the tool is finished, it will produce a report for you.
Please post the C:\ComboFix.txt in your next reply.

Thanks
Worked like a charm this time! Here is the log:


ComboFix 09-09-06.06 - Markella 07/09/2009 21:31.6.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1253.30.1032.18.767.302 [GMT 3:00]
Running from: c:\documents and settings\[removed]\Επιφάνεια εργασίας\ComboFix.exe
Command switches used :: c:\documents and settings\Markella\Επιφάνεια εργασίας\WindowsXP-KB310994-SP2-Pro-BootDisk-ELL.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((( Files Created from 2009-08-07 to 2009-09-07 )))))))))))))))))))))))))))))))
.

2009-09-04 19:45 . 2009-09-04 19:45 ——– d—–w- c:\program files\Trend Micro
2009-08-22 17:46 . 2009-08-22 17:48 ——– d—–w- c:\program files\iTunes
2009-08-21 16:07 . 2009-08-21 16:07 0 —-a-w- c:\windows\system32\drivers\rtvn.sys
2009-08-21 11:40 . 2009-08-21 11:40 ——– d—–w- c:\program files\CCleaner
2009-08-20 13:35 . 2009-08-20 15:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo
2009-08-20 13:35 . 2009-08-26 10:42 179792 —-a-w- c:\windows\system32\guard32.dll
2009-08-20 13:35 . 2009-08-26 10:42 87104 —-a-w- c:\windows\system32\drivers\inspect.sys
2009-08-20 13:35 . 2009-08-26 10:42 25160 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-08-20 13:35 . 2009-08-26 10:42 132168 —-a-w- c:\windows\system32\drivers\cmdguard.sys
2009-08-20 13:33 . 2009-08-20 13:33 ——– d—–w- c:\program files\COMODO
2009-08-19 23:49 . 2004-08-03 22:30 4224 -c–a-w- c:\windows\system32\dllcache\beep.sys
2009-08-18 13:39 . 2009-08-18 13:39 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-18 10:47 . 2009-08-18 10:47 18451 —-a-w- c:\program files\Common Files\uhini.dat
2009-08-18 10:47 . 2009-08-18 10:47 15474 —-a-w- c:\windows\system32\wyhisol.com
2009-08-17 21:59 . 2009-08-17 21:59 ——– d—–w- c:\documents and settings\Markella\Application Data\Malwarebytes
2009-08-17 21:59 . 2009-08-03 10:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-17 21:59 . 2009-08-17 21:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-17 21:58 . 2009-08-03 10:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-17 21:58 . 2009-08-17 21:59 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-17 15:33 . 2004-08-03 22:30 45568 -c–a-w- c:\windows\system32\dllcache\nsepm.dll
2009-08-17 15:32 . 2004-08-03 22:30 39936 -c–a-w- c:\windows\system32\dllcache\hostmib.dll
2009-08-17 15:31 . 2004-05-12 21:39 598071 -c–a-w- c:\windows\system32\dllcache\fpmmc.dll
2009-08-17 15:28 . 2004-08-03 22:30 16384 -c–a-w- c:\windows\system32\dllcache\isignup.exe
2009-08-17 15:24 . 2004-08-03 22:30 32768 -c–a-w- c:\windows\system32\dllcache\icwdl.dll
2009-08-17 15:21 . 2004-08-03 22:30 24576 -c–a-w- c:\windows\system32\dllcache\inetwiz.exe
2009-08-17 15:20 . 2004-08-03 22:30 86016 -c–a-w- c:\windows\system32\dllcache\icwconn2.exe
2009-08-17 15:19 . 2004-08-03 22:30 219648 -c–a-w- c:\windows\system32\dllcache\icwconn1.exe
2009-08-17 13:37 . 2004-08-03 22:30 24661 -c–a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-08-17 13:37 . 2004-08-03 22:30 24661 —-a-w- c:\windows\system32\spxcoins.dll
2009-08-17 13:37 . 2004-08-03 22:30 13312 -c–a-w- c:\windows\system32\dllcache\irclass.dll
2009-08-17 13:37 . 2004-08-03 22:30 13312 —-a-w- c:\windows\system32\irclass.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-06 18:27 . 2007-02-08 09:50 ——– d—–w- c:\documents and settings\Markella\Application Data\uTorrent
2009-09-05 17:05 . 2004-08-03 22:30 73146 —-a-w- c:\windows\system32\perfc008.dat
2009-09-05 17:05 . 2004-08-03 22:30 480304 —-a-w- c:\windows\system32\perfh008.dat
2009-09-02 09:44 . 2004-08-03 23:07 94016 —-a-w- c:\windows\system32\drivers\agp440.sys
2009-08-22 18:04 . 2008-08-13 17:06 ——– d—–w- c:\program files\Safari
2009-08-22 17:47 . 2007-02-02 16:03 ——– d—–w- c:\program files\iPod
2009-08-22 17:46 . 2007-07-13 11:17 ——– d—–w- c:\program files\Common Files\Apple
2009-08-22 13:38 . 2004-08-03 22:30 625952 —-a-w- c:\windows\system32\drivers\ntfs.sys
2009-08-21 16:07 . 2009-08-21 16:07 356 —-a-w- c:\program files\sjbdpu.txt
2009-08-19 14:44 . 2009-08-19 14:44 11529 —-a-w- c:\program files\Common Files\yfuwyjodob._sy
2009-08-18 10:47 . 2009-08-18 10:47 10924 —-a-w- c:\program files\Common Files\todaru._sy
2009-08-17 23:42 . 2007-02-01 14:40 73744 —-a-w- c:\documents and settings\Markella\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-17 15:09 . 2007-02-01 14:26 26092 —-a-w- c:\windows\system32\emptyregdb.dat
2009-08-17 13:35 . 2009-08-17 13:35 0 ——w- c:\windows\SET4E.tmp
2009-07-15 11:05 . 2009-07-15 11:04 ——– d—–w- c:\program files\QuickTime
2008-12-22 21:34 . 2007-02-01 14:49 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-22 21:34 . 2007-02-01 14:49 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-22 21:34 . 2007-02-01 14:49 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-22 21:34 . 2007-02-01 14:49 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-12-22 21:34 . 2007-02-01 14:49 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2007-05-06 18:05 . 2007-05-04 13:04 88 –sh–r- c:\windows\system32\DF3F20FA00.sys
2007-12-21 18:33 . 2007-05-04 13:04 2568 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

——- Sigcheck ——-

[7] DA1F27D85E0D1525F6621372E7B685E9 [5.1.2600.0 (XPClient.010817-1148)] c:\windows\system32\dllcache\beep.sys

[-] 39815F1882474A4EAD82CB6EFFB1469E [——] c:\windows\system32\dllcache\ntfs.sys
[-] 39815F1882474A4EAD82CB6EFFB1469E [——] c:\windows\system32\drivers\ntfs.sys

c:\windows\system32\drivers\beep.sys … is missing !!
.
((((((((((((((((((((((((((((( SnapShot@2009-09-06_23.36.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-07 09:20 . 2009-09-07 09:20 16384 c:\windows\Temp\Perflib_Perfdata_b60.dat
+ 2009-09-07 09:19 . 2009-09-07 09:19 16384 c:\windows\Temp\Perflib_Perfdata_9b4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-04-21 94208]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"D-Link AirPlus XtremeG"="c:\program files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2005-08-04 1294336]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 49152]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-13 177472]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-03-19 2029640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-08-26 1796368]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-05-13 67072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\Markella\Start Menu\¨¦š¨α££˜«˜\„΅΅ε¤ž©ž\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Προγράμματα^Εκκίνηση^ID_Γρήγορη_εκκίνηση_πινακοθήκης_HP_ell.lnk]
path=c:\documents and settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\ID_Γρήγορη_εκκίνηση_πινακοθήκης_HP_ell.lnk
backup=c:\windows\pss\ID_Γρήγορη_εκκίνηση_πινακοθήκης_HP_ell.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Markella^Start Menu^Προγράμματα^Εκκίνηση^Picture Motion Browser Media Check Tool.lnk]
path=c:\documents and settings\Markella\Start Menu\Προγράμματα\Εκκίνηση\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"g:\\The Lord of the Rings Online\\lotroclient.exe"=
"g:\\BitLord Downloads\\Programs\\LimeWire\\LimeWire.exe"=
"g:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"g:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"g:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 cmdguard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [20/8/2009 4:35 μμ 132168]
R1 cmdhlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [20/8/2009 4:35 μμ 25160]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [19/3/2009 11:44 πμ 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [19/3/2009 11:45 πμ 93848]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [19/3/2009 11:44 πμ 731840]
R2 ssoftnt4;ssoftnt4;c:\windows\system32\drivers\ssoftnt4.sys [19/10/2007 12:09 μμ 100728]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [4/8/2004 1:30 πμ 5120]
R3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [26/7/2005 3:32 μμ 348352]
R3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [20/12/2007 5:13 μμ 1553896]
S2 svrhost;Windows WorkGroup;c:\program files\Common Files\Microsoft Shared\MSINFO\svrhost.exe –> c:\program files\Common Files\Microsoft Shared\MSINFO\svrhost.exe [?]
S3 ATHFMWDL;D-Link predator Bootloader driver;c:\windows\system32\drivers\Athfmwdl.sys [26/7/2005 3:35 μμ 43392]
S3 sdAuxService;Spyware Doctor Auxiliary Service;c:\program files\Spyware Doctor\svcntaux.exe [8/9/2007 8:11 μμ 708176]
.
Contents of the 'Scheduled Tasks' folder

2009-05-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
IE: Ε&ξαγωγή στο Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: {42E6E545-9DCB-4DA1-BA95-3EF06119E06C} = 195.170.0.1,195.170.2.2
FF - ProfilePath - c:\documents and settings\Markella\Application Data\Mozilla\Firefox\Profiles\lqi6zm2x.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-07 21:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\Documents and Settings\\All Users\\Application Data\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000000
"ProductCode"="{FE9C13F6-6BBD-47D3-B939-F7E061BC4930}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.0.417.0"
"UniqueId"="011FC9374A130C16"
"ScannerBuild"=dword:0000121d
"ScannerVersionId"=dword:00000f6c
"ScannerVersion"="Open window for status."
"FixId"=dword:00000004
.
Completion time: 2009-09-07 21:52
ComboFix-quarantined-files.txt 2009-09-07 18:52
ComboFix2.txt 2009-09-07 13:57
ComboFix3.txt 2009-09-07 09:52
ComboFix4.txt 2009-09-07 09:43
ComboFix5.txt 2009-09-07 18:27

Pre-Run: 10 Κατάλογοι 16.378.585.088 διαθέσιμα byte
Post-Run: 10 Κατάλογοι 16.369.401.856 διαθέσιμα byte

WindowsXP-KB310994-SP2-Pro-BootDisk-ELL.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

232
Hi jsmith,

Good job. Let's gather some info and try to get the rest.

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time,into the "Suspicious files to scan" box on the top of the page:
  • Please ensure the scan is complete and the results svaed before submitting the next one

    c:\windows\system32\drivers\ntfs.sys
    c:\program files\Common Files\uhini.dat
    c:\windows\system32\wyhisol.com

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :Contents
    c:\program files\sjbdpu.txt
    
    :filefind
    ntfs.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please post back with
  • VirScan results
  • SystemLook log

Thanks
Hello again mate,

Here are the results from VirScan:

VirSCAN.org Scanned Report :
Scanned time : 2009/09/07 22:51:29 (EEST)
Scanner results: 49% Scanner(18/37) found malware!
File Name : ntfs.sys
File Size : 625952 byte
File Type : PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5 : 39815f1882474a4ead82cb6effb1469e
SHA1 : 18deb29689913db192be1c8c4894ea80c9b1968a
Online report : http://virscan.org/report/7ee69ed4bdbe2d17…1582120a92.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20090908010220 2009-09-08 3.90 Virus.Win32.Protector!IK
AhnLab V3 2009.09.08.00 2009.09.08 2009-09-08 0.77 Win32/Ntfs
AntiVir 8.2.1.12 7.1.5.215 2009-09-07 0.09 RKIT/Kobcka.Patched.62595.1
Antiy 2.0.18 20090906.2763992 2009-09-06 0.12 Virus/Win32.Protector.c
Arcavir 2009 200909071223 2009-09-07 0.23 -
Authentium 5.1.1 200909071043 2009-09-07 2.16 -
AVAST! 4.7.4 090906-1 2009-09-06 0.01 Win32:Cutwail-Y [Trj]
AVG 8.5.288 270.13.82/2351 2009-09-07 0.31 Packed.Protector.C
BitDefender 7.81008.4088455 7.27583 2009-09-08 3.58 Rootkit.Kobcka.Patched.Gen
CA (VET) 9.0.0.143 31.6.6721 2009-09-07 7.70 -
ClamAV 0.95.2 9781 2009-09-07 0.08 -
Comodo 3.11 2243 2009-09-07 0.72 -
CP Secure 1.3.0.5 2009.09.07 2009-09-07 0.09 -
Dr.Web 4.44.0.9170 2009.09.07 2009-09-07 5.26 BackDoor.Bulknet.404
F-Prot 4.4.4.56 20090907 2009-09-07 2.10 -
F-Secure 7.02.73807 2009.09.07.12 2009-09-07 8.40 Virus.Win32.Protector.c [AVP]
Fortinet 2.81-3.120 10.802 2009-09-07 0.23 -
GData 19.7683/19.467 20090907 2009-09-07 4.67 Virus.Win32.Protector.c [Engine:A]
ViRobot 20090907 2009.09.07 2009-09-07 0.41 -
Ikarus T3.1.01.72 2009.09.07.73486 2009-09-07 3.92 Virus.Win32.Protector
JiangMin 11.0.800 2009.09.07 2009-09-07 3.67 -
Kaspersky 5.5.10 2009.09.07 2009-09-07 0.06 Virus.Win32.Protector.c
KingSoft 2009.2.5.15 2009.9.7.21 2009-09-07 0.47 -
McAfee 5.3.00 5734 2009-09-07 3.23 Cutwail.gen.e
Microsoft 1.5005 2009.09.07 2009-09-07 5.31 Virus:Win32/Cutwail.G
Norman 6.01.09 6.01.00 2009-09-07 4.01 W32/Rootkit.ATOP
Panda 9.05.01 2009.09.07 2009-09-07 1.71 -
Trend Micro 8.700-1004 6.424.03 2009-09-07 0.03 -
Quick Heal 10.00 2009.09.07 2009-09-07 1.28 W32.Protector.C
Rising 20.0 21.46.04.00 2009-09-07 0.79 -
Sophos 2.90.1 4.45 2009-09-08 3.18 Troj/NTFSKit-B
Sunbelt 5378 5378 2009-09-06 1.33 -
Symantec 1.3.0.24 20090907.002 2009-09-07 0.20 -
nProtect 20090907.01 5349619 2009-09-07 6.32 -
The Hacker 6.3.4.3 v00396 2009-09-03 0.70 -
VBA32 3.12.10.10 20090906.1931 2009-09-06 2.05 -
VirusBuster 4.5.11.10 10.112.30/1850525 2009-09-07 2.44 Win32.Protector.CV





VirSCAN.org Scanned Report :
Scanned time : 2009/09/07 22:53:43 (EEST)
Scanner results: All Scanners reported not find malware!
File Name : uhini.dat
File Size : 18451 byte
File Type : MPEG sequence
MD5 : 201c635b2a3c13e04ca3f8bb2d0a4152
SHA1 : 9cb95a61249654f30b6ab09cc91f58198d814f07
Online report : http://virscan.org/report/e932101ce95067d0…015a6e53e4.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20090908010220 2009-09-08 3.87 -
AhnLab V3 2009.09.08.00 2009.09.08 2009-09-08 0.77 -
AntiVir 8.2.1.12 7.1.5.215 2009-09-07 0.44 -
Antiy 2.0.18 20090906.2763992 2009-09-06 0.12 -
Arcavir 2009 200909071223 2009-09-07 0.02 -
Authentium 5.1.1 200909071043 2009-09-07 1.14 -
AVAST! 4.7.4 090906-1 2009-09-06 0.00 -
AVG 8.5.288 270.13.82/2351 2009-09-07 0.30 -
BitDefender 7.81008.4088455 7.27583 2009-09-08 3.52 -
CA (VET) 9.0.0.143 31.6.6721 2009-09-07 7.78 -
ClamAV 0.95.2 9781 2009-09-07 0.01 -
Comodo 3.11 2243 2009-09-07 0.68 -
CP Secure 1.3.0.5 2009.09.07 2009-09-07 0.01 -
Dr.Web 4.44.0.9170 2009.09.07 2009-09-07 5.28 -
F-Prot 4.4.4.56 20090907 2009-09-07 1.14 -
F-Secure 7.02.73807 2009.09.07.12 2009-09-07 7.93 -
Fortinet 2.81-3.120 10.802 2009-09-07 0.16 -
GData 19.7683/19.467 20090907 2009-09-07 4.69 -
ViRobot 20090907 2009.09.07 2009-09-07 0.41 -
Ikarus T3.1.01.72 2009.09.07.73486 2009-09-07 3.91 -
JiangMin 11.0.800 2009.09.07 2009-09-07 3.56 -
Kaspersky 5.5.10 2009.09.07 2009-09-07 0.02 -
KingSoft 2009.2.5.15 2009.9.7.21 2009-09-07 0.47 -
McAfee 5.3.00 5734 2009-09-07 3.23 -
Microsoft 1.5005 2009.09.07 2009-09-07 5.35 -
Norman 6.01.09 6.01.00 2009-09-07 4.00 -
Panda 9.05.01 2009.09.07 2009-09-07 1.60 -
Trend Micro 8.700-1004 6.424.03 2009-09-07 0.02 -
Quick Heal 10.00 2009.09.07 2009-09-07 1.09 -
Rising 20.0 21.46.04.00 2009-09-07 0.26 -
Sophos 2.90.1 4.45 2009-09-08 3.13 -
Sunbelt 5378 5378 2009-09-06 1.30 -
Symantec 1.3.0.24 20090907.002 2009-09-07 0.05 -
nProtect 20090907.01 5349619 2009-09-07 6.33 -
The Hacker 6.3.4.3 v00396 2009-09-03 0.63 -
VBA32 3.12.10.10 20090906.1931 2009-09-06 1.92 -
VirusBuster 4.5.11.10 10.112.30/1850525 2009-09-07 2.27 -





VirSCAN.org Scanned Report :
Scanned time : 2009/09/07 22:55:36 (EEST)
Scanner results: All Scanners reported not find malware!
File Name : wyhisol.com
File Size : 15474 byte
File Type : data
MD5 : 223faa3fce72eb4e1a1fde228051a1f6
SHA1 : c1ecf41f319b06c8eb01bfcc1f7134c59bcfeeaa
Online report : http://virscan.org/report/cfbad3c4d93aad65…7a092f2fab.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20090908010220 2009-09-08 4.00 -
AhnLab V3 2009.09.08.00 2009.09.08 2009-09-08 0.91 -
AntiVir 8.2.1.12 7.1.5.215 2009-09-07 0.16 -
Antiy 2.0.18 20090906.2763992 2009-09-06 0.12 -
Arcavir 2009 200909071223 2009-09-07 0.02 -
Authentium 5.1.1 200909071043 2009-09-07 1.14 -
AVAST! 4.7.4 090906-1 2009-09-06 0.00 -
AVG 8.5.288 270.13.82/2351 2009-09-07 0.30 -
BitDefender 7.81008.4088455 7.27583 2009-09-08 3.51 -
CA (VET) 9.0.0.143 31.6.6721 2009-09-07 6.99 -
ClamAV 0.95.2 9781 2009-09-07 0.01 -
Comodo 3.11 2244 2009-09-07 0.69 -
CP Secure 1.3.0.5 2009.09.07 2009-09-07 0.01 -
Dr.Web 4.44.0.9170 2009.09.07 2009-09-07 5.30 -
F-Prot 4.4.4.56 20090907 2009-09-07 1.14 -
F-Secure 7.02.73807 2009.09.07.12 2009-09-07 2.01 -
Fortinet 2.81-3.120 10.802 2009-09-07 0.16 -
GData 19.7683/19.467 20090907 2009-09-07 4.72 -
ViRobot 20090907 2009.09.07 2009-09-07 0.41 -
Ikarus T3.1.01.72 2009.09.07.73486 2009-09-07 3.90 -
JiangMin 11.0.800 2009.09.07 2009-09-07 4.50 -
Kaspersky 5.5.10 2009.09.07 2009-09-07 0.02 -
KingSoft 2009.2.5.15 2009.9.7.21 2009-09-07 0.54 -
McAfee 5.3.00 5734 2009-09-07 3.25 -
Microsoft 1.5005 2009.09.07 2009-09-07 5.50 -
Norman 6.01.09 6.01.00 2009-09-07 4.01 -
Panda 9.05.01 2009.09.07 2009-09-07 1.64 -
Trend Micro 8.700-1004 6.424.03 2009-09-07 0.03 -
Quick Heal 10.00 2009.09.07 2009-09-07 1.08 -
Rising 20.0 21.46.04.00 2009-09-07 0.26 -
Sophos 2.90.1 4.45 2009-09-08 3.22 -
Sunbelt 5378 5378 2009-09-06 1.50 -
Symantec 1.3.0.24 20090907.002 2009-09-07 0.06 -
nProtect 20090907.01 5349619 2009-09-07 6.66 -
The Hacker 6.3.4.3 v00396 2009-09-03 0.68 -
VBA32 3.12.10.10 20090906.1931 2009-09-06 1.95 -
VirusBuster 4.5.11.10 10.112.30/1850525 2009-09-07 2.28 -


And here is the SystemLook log:

SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 23:04 on 07/09/2009 by Markella (Administrator - Elevation successful)

========== Contents ==========

c:\program files\sjbdpu.txt - Opened succesfully.

Files to delete:
C:\Documents and Settings\NetworkService\oashdihasidhasuidhiasdhiashdiuasdhasd
C:\Documents and Settings\NetworkService\oashdihasidhasuidhiasdhiashdiuasdhasd


========== filefind ==========

Searching for "ntfs.sys"
C:\cmdcons\NTFS.SYS –a— 574592 bytes [20:15 03/08/2004] [20:15 03/08/2004] B78BE402C3F63DD55521F73876951CDD
C:\WINDOWS\system32\dllcache\ntfs.sys –a–c 625952 bytes [22:30 03/08/2004] [13:38 22/08/2009] 39815F1882474A4EAD82CB6EFFB1469E
C:\WINDOWS\system32\drivers\ntfs.sys –a— 625952 bytes [22:30 03/08/2004] [13:38 22/08/2009] 39815F1882474A4EAD82CB6EFFB1469E

-=End Of File=-


Thanks!
And here are the results:

VirSCAN.org Scanned Report :
Scanned time : 2009/09/07 23:09:16 (EEST)
Scanner results: 65% Scanner(24/37) found malware!
File Name : agp440.sys
File Size : 94016 byte
File Type : PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5 : b061a6e3ba06e8057fb5a6eeeaec9285
SHA1 : f2f0ae8bace5d17e2ed4c585c93253d4a41891b5
Online report : http://virscan.org/report/a2033d6f703248d8…987f6f82a7.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20090908010220 2009-09-08 4.00 Virus.Win32.Cutwail!IK
AhnLab V3 2009.09.08.00 2009.09.08 2009-09-08 0.92 Win32/Ntfs
AntiVir 8.2.1.12 7.1.5.215 2009-09-07 0.45 SPR/Tool.Cutwail.L.11
Antiy 2.0.18 20090906.2763992 2009-09-06 0.12 Virus/Win32.Protector.c
Arcavir 2009 200909071223 2009-09-07 0.05 -
Authentium 5.1.1 200909071043 2009-09-07 1.19 W32/Cutwail.B (Exact)
AVAST! 4.7.4 090906-1 2009-09-06 0.01 Win32:Cutwail [Trj]
AVG 8.5.288 270.13.82/2351 2009-09-07 0.33 Generic14.ADYJ
BitDefender 7.81008.4088455 7.27583 2009-09-08 3.60 Trojan.Generic.2315806
CA (VET) 9.0.0.143 31.6.6721 2009-09-07 7.08 Win32/Cutwail.ATB trojan.
ClamAV 0.95.2 9781 2009-09-07 0.02 -
Comodo 3.11 2244 2009-09-07 0.69 UnclassifiedMalware
CP Secure 1.3.0.5 2009.09.07 2009-09-07 0.06 W32.Protector.c
Dr.Web 4.44.0.9170 2009.09.07 2009-09-07 5.29 BackDoor.Bulknet.408
F-Prot 4.4.4.56 20090907 2009-09-07 1.14 W32/Cutwail.B (exact)
F-Secure 7.02.73807 2009.09.07.12 2009-09-07 8.03 Virus.Win32.Protector.c [AVP]
Fortinet 2.81-3.120 10.802 2009-09-07 0.18 PossibleThreat
GData 19.7683/19.467 20090907 2009-09-07 4.78 Virus.Win32.Protector.c [Engine:A]
ViRobot 20090907 2009.09.07 2009-09-07 0.41 -
Ikarus T3.1.01.72 2009.09.07.73486 2009-09-07 3.94 Virus.Win32.Cutwail
JiangMin 11.0.800 2009.09.07 2009-09-07 5.90 -
Kaspersky 5.5.10 2009.09.07 2009-09-07 0.06 Virus.Win32.Protector.c
KingSoft 2009.2.5.15 2009.9.7.21 2009-09-07 0.49 -
McAfee 5.3.00 5734 2009-09-07 3.23 Cutwail.gen.e
Microsoft 1.5005 2009.09.07 2009-09-07 5.52 Virus:Win32/Cutwail.G
Norman 6.01.09 6.01.00 2009-09-07 4.00 W32/Rootkit.ATJD
Panda 9.05.01 2009.09.07 2009-09-07 2.46 -
Trend Micro 8.700-1004 6.424.03 2009-09-07 0.03 -
Quick Heal 10.00 2009.09.07 2009-09-07 1.17 -
Rising 20.0 21.46.04.00 2009-09-07 0.82 -
Sophos 2.90.1 4.45 2009-09-08 4.34 Mal/Generic-A
Sunbelt 5378 5378 2009-09-06 1.43 -
Symantec 1.3.0.24 20090907.002 2009-09-07 0.09 -
nProtect 20090907.01 5349619 2009-09-07 6.88 Trojan/W32.Agent.94016
The Hacker 6.3.4.3 v00396 2009-09-03 0.69 -
VBA32 3.12.10.10 20090906.1931 2009-09-06 1.92 -
VirusBuster 4.5.11.10 10.112.30/1850525 2009-09-07 2.29 Win32.Protector.CV


Thank you!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI