This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] malmal

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

19049684.exe

Above process running after boot. Easily stopped but fear rootkit is intact.

Wallpaper hacked to info-*.bmp. Easily removed.

I created new gmail account to access this forum on the off chance this will allow some protection.

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/09 00:33
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================

Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB1C2D000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7AED000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB0E5A000 Size: 49152 File Visible: No Signed: -
Status: -

==EOF==


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 0:30:48.85 on Wed 09/09/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.157 [GMT 1:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\sndvol32.exe
svchost
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\mspaint.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner\My Documents\Downloads\MALWARE REMOVAL\dds.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
uWindow Title = Windows Internet Explorer provided by Yahoo!
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mDefault_Page_URL = hxxp://www.yahoo.com
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: HP view: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hp\digital imaging\bin\HPDTLK02.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\hp_owner\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [AlcxMonitor] ALCXMNTR.EXE
mRun: [PS2] c:\windows\system32\ps2.exe
mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [19049684] c:\documents and settings\all users\application data\19049684\19049684.exe
mRun: [PromoReg] c:\windows\temp\_ex-08.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [Bpepim] rundll32.exe "c:\windows\uragimog.dll",e
StartupFolder: c:\documents and settings\hp_owner\start menu\programs\startup\ikowin32.exe
StartupFolder: c:\documents and settings\hp_owner\start menu\programs\startup\sndvol32.exe
IE: Add To HP Organize… - c:\progra~1\hewlet~1\hporga~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1251083586781
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
LSA: Notification Packages = scecli cpsmsrtx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\hp_owner\applic~1\mozilla\firefox\profiles\458k918k.default\
FF - plugin: c:\documents and settings\hp_owner\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\hp_owner\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPOJI610.dll
FF - HiddenExtension: XUL Cache: {0E245123-471F-4EF8-B8D6-A27722726D2F} - c:\documents and settings\hp_owner\local settings\application data\{0E245123-471F-4EF8-B8D6-A27722726D2F}
FF - HiddenExtension: XUL Cache: {9CEA2E74-9BE8-46A6-8C9C-768342A83B2C} - c:\documents and settings\administrator\local settings\application data\{9cea2e74-9be8-46a6-8c9c-768342a83b2c}\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]
S2 bktici;Center Windows;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S2 jnjfrat;Support Helper;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]

=============== Created Last 30 ================

2009-09-08 21:33 –d—– c:\program files\Spybot - Search & Destroy
2009-09-08 21:33 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-09-08 21:10 120 a——- c:\windows\Dkisad.dat
2009-09-08 11:41 –d—– c:\program files\WinPcap
2009-09-08 11:39 –d—– c:\docume~1\alluse~1\applic~1\19049684
2009-09-08 02:42 411,368 a——- c:\windows\system32\deploytk.dll
2009-09-08 02:42 73,728 a——- c:\windows\system32\javacpl.cpl
2009-09-08 01:40 3,701 a——- c:\windows\scad3.INI
2009-09-07 06:54 –d—– c:\program files\LTC
2009-09-06 08:44 –d—– c:\docume~1\hp_owner\applic~1\WinBatch
2009-09-05 22:53 –d—– c:\docume~1\hp_owner\applic~1\MathematicaPlayer
2009-09-05 22:53 –d—– c:\docume~1\alluse~1\applic~1\MathematicaPlayer
2009-09-05 21:24 378,152 a——- c:\windows\system32\ml32i3.dll
2009-09-05 21:24 349,480 a——- c:\windows\system32\mltcpip32.mlp
2009-09-05 21:24 267,560 a——- c:\windows\system32\ml32i2.dll
2009-09-05 21:24 259,368 a——- c:\windows\system32\ml32i1.dll
2009-09-05 21:24 185,640 a——- c:\windows\system32\mlmodule32.dll
2009-09-05 21:24 107,816 a——- c:\windows\system32\mltcp32.mlp
2009-09-05 21:24 103,720 a——- c:\windows\system32\mlshm32.mlp
2009-09-05 21:24 95,528 a——- c:\windows\system32\mlmap32.mlp
2009-09-05 21:23 –d—– c:\program files\Wolfram Research
2009-09-01 00:45 –d—– C:\CM60S
2009-09-01 00:45 363,892 a——- c:\windows\ISUN16.EXE
2009-09-01 00:45 26,768 a——- c:\windows\system\CTL3D.DLL
2009-08-31 21:18 695,642 a——- c:\windows\unins000.exe
2009-08-31 21:18 14,981 a——- c:\windows\unins000.dat
2009-08-31 21:18 –d—– c:\program files\common files\SourceTec
2009-08-31 21:02 67 a——- c:\windows\swf2avi.INI
2009-08-31 21:02 758,018 a——- c:\windows\system32\xvidcore.dll
2009-08-31 21:02 180,224 a——- c:\windows\system32\xvidvfw.dll
2009-08-31 21:02 139,264 a——- c:\windows\system32\xvid.ax
2009-08-31 21:02 –d—– c:\program files\iWisoft Flash SWF to Video Converter
2009-08-30 20:10 –d—– c:\windows\system32\cvirte
2009-08-30 20:10 –d—– c:\program files\SteornLab
2009-08-29 20:52 –d—– c:\program files\Vizimag 3.18
2009-08-28 19:08 368,912 a——- c:\windows\system32\vbar332.dll
2009-08-28 19:08 3,572,224 a——- c:\windows\system32\crpe32.dll
2009-08-28 19:08 1,037,312 a——- c:\windows\system32\msjet35.dll
2009-08-28 19:08 251,664 a——- c:\windows\system32\msrd2x35.dll
2009-08-28 19:08 121,104 a——- c:\windows\system32\msjint35.dll
2009-08-28 19:08 24,336 a——- c:\windows\system32\msjter35.dll
2009-08-28 19:08 17,920 a——- c:\windows\system32\implode.dll
2009-08-28 19:08 416,768 a——- c:\windows\system32\cpeaut32.dll
2009-08-28 19:08 –d—– c:\program files\OrCAD_Demo
2009-08-28 11:27 4 a——- c:\windows\Worddict.xph
2009-08-28 11:27 4 a——- c:\windows\system32\Msxls.dnh
2009-08-28 11:27 –d—– c:\program files\DeltaCad
2009-08-28 10:44 32,397 a——- c:\windows\SGTBox.INI
2009-08-28 10:34 –d—– c:\program files\Canon
2009-08-28 10:33 –d—– c:\temp\ScanGearToolboxCSv223
2009-08-28 10:21 15,104 a——- c:\windows\system32\drivers\usbscan.sys
2009-08-28 10:21 15,104 a——- c:\windows\system32\dllcache\usbscan.sys
2009-08-28 10:17 –d—– c:\temp\CanoScan
2009-08-28 10:17 –d—– C:\Temp
2009-08-27 04:05 –d—– c:\program files\IrfanView
2009-08-25 13:54 –d—– c:\program files\Scope
2009-08-25 13:52 –d—– c:\program files\Scope_131
2009-08-24 04:23 –d—– c:\program files\National Instruments
2009-08-24 04:15 31,768 a——- c:\windows\system32\wucltui.dll.mui
2009-08-24 04:15 23,576 a——- c:\windows\system32\wuaucpl.cpl.mui
2009-08-24 04:15 18,456 a——- c:\windows\system32\wuaueng.dll.mui
2009-08-24 04:15 –d—– c:\windows\system32\SoftwareDistribution
2009-08-23 03:23 –d–r– c:\program files\Skype
2009-08-23 02:20 –d—– c:\program files\Linksys Wireless-G USB Wireless Network Monitor
2009-08-23 01:38 21,504 a——- c:\windows\system32\hidserv.dll
2009-08-23 01:38 21,504 a——- c:\windows\system32\dllcache\hidserv.dll
2009-08-23 01:38 14,848 a——- c:\windows\system32\drivers\kbdhid.sys
2009-08-23 01:38 14,848 a——- c:\windows\system32\dllcache\kbdhid.sys
2009-08-23 01:38 12,160 a——- c:\windows\system32\drivers\mouhid.sys
2009-08-23 01:38 12,160 a——- c:\windows\system32\dllcache\mouhid.sys
2009-08-23 01:37 9,600 a——- c:\windows\system32\drivers\hidusb.sys
2009-08-23 01:37 9,600 a——- c:\windows\system32\dllcache\hidusb.sys
2009-08-23 01:37 31,616 a——- c:\windows\system32\drivers\usbccgp.sys
2009-08-23 01:37 31,616 a——- c:\windows\system32\dllcache\usbccgp.sys

==================== Find3M ====================

2009-09-08 11:38 182,912 a——- c:\windows\system32\drivers\ndis.sys
2009-09-08 11:38 182,912 a——- c:\windows\system32\dllcache\ndis.sys
2009-08-23 02:20 17,119 a——- c:\windows\system32\drivers\AegisP.sys
2009-08-23 01:55 3,645 a——- c:\windows\viassary-hp.reg
2005-11-21 07:56 32 a–sh— c:\windows\sminst\HPCD.SYS
2004-08-04 19:00 164,072 a–shr– c:\windows\system32\bokiybra.dll

============= FINISH: 0:31:13.01 ===============



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 1/25/2009 5:21:23 PM
System Uptime: 9/8/2009 10:46:59 PM (2 hours ago)

Motherboard: ASUSTek Computer INC. | | Salmon
Processor: AMD Athlon™ 64 Processor 3200+ | Socket 754 | 2210/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 106 GiB total, 98.194 GiB free.
D: is FIXED (FAT32) - 5 GiB total, 0.32 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: SiS 900-Based PCI Fast Ethernet Adapter
Device ID: PCI\VEN_1039&DEV_0900&SUBSYS_2A04103C&REV_90\3&61AAA01&0&20
Manufacturer: SiS
Name: SiS 900-Based PCI Fast Ethernet Adapter
PNP Device ID: PCI\VEN_1039&DEV_0900&SUBSYS_2A04103C&REV_90\3&61AAA01&0&20
Service: SISNIC

Class GUID: {4D36E96D-E325-11CE-BFC1-08002BE10318}
Description: Agere Systems PCI Soft Modem
Device ID: PCI\VEN_11C1&DEV_048C&SUBSYS_044C11C1&REV_03\3&61AAA01&0&50
Manufacturer: Agere
Name: Agere Systems PCI Soft Modem
PNP Device ID: PCI\VEN_11C1&DEV_048C&SUBSYS_044C11C1&REV_03\3&61AAA01&0&50
Service: Modem

Class GUID: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F}
Description: VIA OHCI Compliant IEEE 1394 Host Controller
Device ID: PCI\VEN_1106&DEV_3044&SUBSYS_2A04103C&REV_80\3&61AAA01&0&58
Manufacturer: VIA
Name: VIA OHCI Compliant IEEE 1394 Host Controller
PNP Device ID: PCI\VEN_1106&DEV_3044&SUBSYS_2A04103C&REV_80\3&61AAA01&0&58
Service: ohci1394

Class GUID: {4D36E978-E325-11CE-BFC1-08002BE10318}
Description: Communications Port
Device ID: ACPI\PNP0501\1
Manufacturer: (Standard port types)
Name: Communications Port (COM1)
PNP Device ID: ACPI\PNP0501\1
Service: Serial

Class GUID: {4D36E978-E325-11CE-BFC1-08002BE10318}
Description: ECP Printer Port
Device ID: ACPI\PNP0401\3&61AAA01&0
Manufacturer: (Standard port types)
Name: ECP Printer Port (LPT1)
PNP Device ID: ACPI\PNP0401\3&61AAA01&0
Service: Parport

==== System Restore Points ===================

RP1: 8/25/2009 2:14:06 PM - System Checkpoint
RP2: 8/26/2009 5:32:06 PM - System Checkpoint
RP3: 8/27/2009 10:03:35 PM - System Checkpoint
RP4: 8/29/2009 12:53:05 AM - System Checkpoint
RP5: 8/29/2009 9:28:29 AM - Removed SteornLab USB Hall Probe
RP6: 8/30/2009 9:51:47 AM - System Checkpoint
RP7: 8/31/2009 9:50:29 PM - System Checkpoint
RP8: 9/1/2009 10:28:57 PM - System Checkpoint
RP9: 9/2/2009 11:58:44 PM - System Checkpoint
RP10: 9/4/2009 12:23:46 AM - System Checkpoint
RP11: 9/6/2009 8:28:14 AM - Installed NI LabVIEW Run-Time Engine 6.1
RP12: 9/6/2009 8:45:07 AM - Removed HP Software Update
RP13: 9/7/2009 11:20:37 AM - System Checkpoint
RP14: 9/8/2009 2:42:07 AM - Installed Java™ 6 Update 16

==== Installed Programs ======================

Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 6.0.1
Agere Systems PCI Soft Modem
AiO_Scan
AiOSoftware
Bounce Symphony from Hewlett-Packard Desktops (remove only)
BufferChm
CameraDrivers
Canon ScanGear Toolbox CS 2.2
Copy
CP_AtenaShokunin1Config
cp_dwSharkTaleAlbums1
cp_dwSharkTaleCards1
cp_dwShrek2Albums1
cp_dwShrek2Cards1
CP_PLSBusinessFlyers
CreativeProjects
CreativeProjectsTemplates
CueTour
DeltaCad
Destinations
Director
DocProc
DocumentViewer
ERUNT 1.1j
Fax
Google Chrome
Google Talk Plugin
Help and Support Additions
Hotfix for Windows XP (KB915865)
HP Deskjet Preloaded Printer Drivers
HP Diagnostic Assistant
HP Image Zone 4.5.3
HP Image Zone Plus 4.5.3
HP Organize
HP Photosmart Cameras 4.0
HP PSC & OfficeJet 4.0
HP Update
HPIZplus450
HpSdpAppCoreApp
InstantShare
IntelliMover Data Transfer Demo
InterVideo DiscLabel
InterVideo WinDVD Creator
InterVideo WinDVD Player
IrfanView (remove only)
iWisoft Flash SWF to Video Converter 3.3
Java 2 Runtime Environment, SE v1.4.2_03
Java™ 6 Update 16
KBD
Linksys Wireless-G USB Network Adapter
LTspice IV
Mathematica Player (M-WIN-D 7.0.1 1223367)
Microsoft .NET Framework 1.1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Plus! Dancer LE
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Mozilla Firefox (3.5.2)
muvee autoProducer 3.5 magicMoments - HPD
NI LabVIEW Run-Time Engine 6.1
PanoStandAlone
PC-Doctor for Windows
PhotoGallery
PrintScreen
PS2
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
QFolder
QuickProjects
QuickTime
Readme
RealPlayer
Scan
Scope
Shrek 2 Ogre Bowler from Hewlett-Packard Desktops (remove only)
SiS VGA Utilities
SkinsHP1
Skype™ 4.1
Sonic Express Labeler
Sonic RecordNow!
Sothink SWF Catcher for Internet Explorer
Spybot - Search & Destroy
SteornLab USB Hall Probe
Tradewinds from Hewlett-Packard Desktops (remove only)
TrayApp
Unload
Updates from HP
Vizimag 3.18
WebFldrs XP
WebReg
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB890175

==== Event Viewer Messages From Past Week ========

9/8/2009 8:49:06 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82926da0, parameter3 82926f14, parameter4 805c749a.
9/8/2009 8:17:50 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 828b7b88, parameter3 828b7cfc, parameter4 805c749a.
9/8/2009 7:45:28 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82909d78, parameter3 82909eec, parameter4 805c749a.
9/8/2009 7:14:06 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 828efda0, parameter3 828eff14, parameter4 805c749a.
9/8/2009 6:41:41 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82aa2020, parameter3 82aa2194, parameter4 805c749a.
9/8/2009 6:10:19 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82a2d128, parameter3 82a2d29c, parameter4 805c749a.
9/8/2009 5:37:58 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 828c0318, parameter3 828c048c, parameter4 805c749a.
9/8/2009 5:06:36 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82a83da0, parameter3 82a83f14, parameter4 805c749a.
9/8/2009 4:34:14 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 828c3bb8, parameter3 828c3d2c, parameter4 805c749a.
9/8/2009 4:02:52 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 8291fda0, parameter3 8291ff14, parameter4 805c749a.
9/8/2009 3:30:28 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82a9a740, parameter3 82a9a8b4, parameter4 805c749a.
9/8/2009 2:58:06 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 829c41c0, parameter3 829c4334, parameter4 805c749a.
9/8/2009 2:26:43 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82a36938, parameter3 82a36aac, parameter4 805c749a.
9/8/2009 12:50:35 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82896180, parameter3 828962f4, parameter4 805c749a.
9/8/2009 12:23:51 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired.
9/8/2009 12:19:10 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 82995b10, parameter3 82995c84, parameter4 805c749a.
9/8/2009 12:17:44 PM, error: Service Control Manager [7034] - The WUSB54Gv4SVC service terminated unexpectedly. It has done this 1 time(s).
9/8/2009 12:17:44 PM, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s).
9/8/2009 12:17:44 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s).
9/8/2009 12:17:44 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
9/8/2009 10:37:33 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
9/8/2009 10:22:10 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
9/8/2009 10:22:10 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
9/8/2009 10:22:10 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
9/8/2009 10:22:10 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
9/8/2009 10:22:10 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
9/8/2009 10:21:49 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
9/8/2009 10:21:39 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
9/8/2009 1:54:18 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 8293dbe8, parameter3 8293dd5c, parameter4 805c749a.
9/8/2009 1:22:56 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 829864d8, parameter3 8298664c, parameter4 805c749a.
9/7/2009 12:08:43 AM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.
9/7/2009 1:40:26 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.nist.gov,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
9/6/2009 9:18:02 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {F087771F-D74F-4C1A-BB8A-E16ACA9124EA}
9/6/2009 9:18:02 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {6D18AD12-BDE3-4393-B311-099C346E6DF9}
9/6/2009 8:33:16 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
9/6/2009 6:15:13 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
9/2/2009 8:23:28 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
9/2/2009 8:23:23 AM, error: Service Control Manager [7023] - The Support Helper service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
9/2/2009 8:23:23 AM, error: Service Control Manager [7023] - The Center Windows service terminated with the following error: A dynamic link library (DLL) initialization routine failed.

==== End Of File ===========================

Attachments:

[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

1) numberCruncher
Please download numberCruncher to your desktop.
Double-click on numberCruncher.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Should be created where you ran the file)

2) Combofix
Please read through the instructions to familiarize yourself with what to expect when the tool runs.

Please download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link:How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts. Close all browsers/windows first.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

3) What You Will Need To Post:
  • numberCruncher log
  • Combofix log
Thank you Raktor. numberCruncher by Raktor - 09 Build 20090907 Now searching… Checking for numerical processes… Checking for bad processes… Checking for desot.exe… Checking for ddesot.exe… Checking for desote.exe… Checking for tsc.exe… Checking for svchast.exe… Checking for svchasts.exe… Checking for Windows Police Pro.exe… Checking for ANTI_files.exe… Checking for minix32.exe… Checking for Windows Antivirus Pro.exe… Checking for pav.exe… Checking for bad files… Checking for desot.exe file… Checking for ddesot.exe file… Checking for desote.exe file… Checking for tsc.exe file… Checking for svchast.exe file… Checking for svchasts.exe file… Checking for Windows Police Pro.exe file… Checking for ANTI_files.exe file… Checking for minix32.exe file… Checking for Windows Antivirus Pro.exe file… Checking for pav.exe file… Checking for dddesot.dll file… Resetting filetype association for .exe Resetting filetype association for .com Finished.
I fully agree Raktor, that this machine is far from clean.

Thank you again for your kind and generous efforts.




ComboFix 09-09-08.05 - HP_Owner 09/09/2009 8:25.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.201 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\HP_Owner\Application Data\wiaserva.log
c:\documents and settings\HP_Owner\Local Settings\Application Data\{0E245123-471F-4EF8-B8D6-A27722726D2F}
c:\documents and settings\HP_Owner\Local Settings\Application Data\{0E245123-471F-4EF8-B8D6-A27722726D2F}\chrome.manifest
c:\documents and settings\HP_Owner\Local Settings\Application Data\{0E245123-471F-4EF8-B8D6-A27722726D2F}\chrome\content\_cfg.js
c:\documents and settings\HP_Owner\Local Settings\Application Data\{0E245123-471F-4EF8-B8D6-A27722726D2F}\chrome\content\overlay.xul
c:\documents and settings\HP_Owner\Local Settings\Application Data\{0E245123-471F-4EF8-B8D6-A27722726D2F}\install.rdf
c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\ikowin32.exe
c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\sndvol32.exe
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\windows\system32\bokiybra.dll
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\ps2.bat
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\viassary-hp.reg

c:\windows\system32\drivers\ndis.sys . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_BKTICI
——-\Legacy_JNJFRAT
——-\Legacy_NPF
——-\Service_bktici
——-\Service_jnjfrat
——-\Service_npf


((((((((((((((((((((((((( Files Created from 2009-08-09 to 2009-09-09 )))))))))))))))))))))))))))))))
.

2009-09-08 23:25 . 2009-09-08 23:25 ——– d—–w- c:\program files\ERUNT
2009-09-08 20:33 . 2009-09-08 21:20 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-09-08 20:33 . 2009-09-08 21:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-08 20:10 . 2009-09-09 07:02 120 —-a-w- c:\windows\Dkisad.dat
2009-09-08 01:42 . 2009-09-08 01:42 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-09-07 05:54 . 2009-09-07 05:54 ——– d—–w- c:\program files\LTC
2009-09-06 07:44 . 2009-09-06 07:44 ——– d—–w- c:\documents and settings\HP_Owner\Application Data\WinBatch
2009-09-05 21:53 . 2009-09-05 21:53 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\MathematicaPlayer
2009-09-05 21:53 . 2009-09-05 21:53 ——– d—–w- c:\documents and settings\HP_Owner\Application Data\MathematicaPlayer
2009-09-05 21:53 . 2009-09-05 21:53 ——– d—–w- c:\documents and settings\All Users\Application Data\MathematicaPlayer
2009-09-05 20:24 . 2009-03-05 17:53 185640 —-a-w- c:\windows\system32\mlmodule32.dll
2009-09-05 20:24 . 2009-03-05 17:53 378152 —-a-w- c:\windows\system32\ml32i3.dll
2009-09-05 20:24 . 2009-03-05 17:53 267560 —-a-w- c:\windows\system32\ml32i2.dll
2009-09-05 20:24 . 2009-03-05 17:53 259368 —-a-w- c:\windows\system32\ml32i1.dll
2009-09-05 20:23 . 2009-09-05 20:23 ——– d—–w- c:\program files\Wolfram Research
2009-09-05 03:24 . 2009-09-05 03:24 ——– d—–w- c:\windows\Sun
2009-09-04 06:01 . 2009-09-04 06:01 0 —-a-w- c:\windows\nsreg.dat
2009-09-04 06:01 . 2009-09-04 06:01 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Mozilla
2009-08-31 23:45 . 2009-09-06 05:28 ——– d—–w- C:\CM60S
2009-08-31 23:45 . 1998-07-30 13:47 363892 —-a-w- c:\windows\ISUN16.EXE
2009-08-31 23:45 . 1995-07-13 18:43 26768 —-a-w- c:\windows\system\CTL3D.DLL
2009-08-31 20:18 . 2009-08-31 20:18 14981 —-a-w- c:\windows\unins000.dat
2009-08-31 20:18 . 2009-08-31 20:18 ——– d—–w- c:\program files\Common Files\SourceTec
2009-08-31 20:18 . 2009-08-31 20:17 695642 —-a-w- c:\windows\unins000.exe
2009-08-31 20:02 . 2009-05-19 17:32 758018 —-a-w- c:\windows\system32\xvidcore.dll
2009-08-31 20:02 . 2008-12-04 20:46 180224 —-a-w- c:\windows\system32\xvidvfw.dll
2009-08-31 20:02 . 2009-08-31 20:27 ——– d—–w- c:\program files\iWisoft Flash SWF to Video Converter
2009-08-30 19:10 . 2009-08-30 19:10 ——– d—–w- c:\windows\system32\cvirte
2009-08-30 19:10 . 2009-08-30 19:10 ——– d—–w- c:\program files\SteornLab
2009-08-29 19:53 . 2009-08-29 19:53 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\VMGVersxx
2009-08-29 19:52 . 2009-08-29 19:52 ——– d—–w- c:\program files\Vizimag 3.18
2009-08-28 22:47 . 2009-08-28 22:47 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Help
2009-08-28 18:08 . 1996-11-08 02:48 368912 —-a-w- c:\windows\system32\vbar332.dll
2009-08-28 18:08 . 1997-08-28 16:00 3572224 —-a-w- c:\windows\system32\crpe32.dll
2009-08-28 18:08 . 1997-07-10 23:00 251664 —-a-w- c:\windows\system32\msrd2x35.dll
2009-08-28 18:08 . 1997-07-10 23:00 24336 —-a-w- c:\windows\system32\msjter35.dll
2009-08-28 18:08 . 1997-07-10 23:00 121104 —-a-w- c:\windows\system32\msjint35.dll
2009-08-28 18:08 . 1997-07-10 23:00 1037312 —-a-w- c:\windows\system32\msjet35.dll
2009-08-28 18:08 . 1995-02-15 00:11 17920 —-a-w- c:\windows\system32\implode.dll
2009-08-28 18:08 . 2009-08-29 08:28 ——– d—–w- c:\program files\OrCAD_Demo
2009-08-28 18:08 . 1997-08-28 16:00 416768 —-a-w- c:\windows\system32\cpeaut32.dll
2009-08-28 10:27 . 2009-08-28 10:27 ——– d—–w- c:\program files\DeltaCad
2009-08-28 09:34 . 2009-08-28 09:34 ——– d—–w- c:\program files\Canon
2009-08-28 09:33 . 2009-08-28 09:33 ——– d—–w- c:\temp\ScanGearToolboxCSv223
2009-08-28 09:21 . 2004-08-03 21:58 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2009-08-28 09:21 . 2004-08-03 21:58 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2009-08-28 09:17 . 2009-08-28 09:33 ——– d—–w- C:\Temp
2009-08-28 09:17 . 2009-08-28 09:17 ——– d—–w- c:\temp\CanoScan
2009-08-27 03:05 . 2009-08-27 03:05 ——– d—–w- c:\program files\IrfanView
2009-08-25 12:54 . 2009-08-25 12:54 ——– d—–w- c:\program files\Scope
2009-08-25 12:52 . 2009-08-25 12:52 ——– d—–w- c:\program files\Scope_131
2009-08-24 03:23 . 2009-09-06 07:28 ——– d—–w- c:\program files\National Instruments
2009-08-24 03:15 . 2008-10-16 13:09 43544 —-a-w- c:\windows\system32\wups2.dll
2009-08-24 00:36 . 2009-08-24 00:36 ——– d—–w- c:\documents and settings\HP_Owner\Application Data\AdobeUM
2009-08-24 00:36 . 2009-08-24 00:36 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Adobe
2009-08-24 00:36 . 2009-08-24 00:36 ——– d—–w- c:\program files\Common Files\Adobe
2009-08-23 16:14 . 2009-08-23 16:14 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Identities
2009-08-23 02:23 . 2009-09-09 06:06 ——– d—–w- c:\documents and settings\HP_Owner\Application Data\Skype
2009-08-23 02:23 . 2009-08-23 02:23 ——– d—–r- c:\program files\Skype
2009-08-23 02:23 . 2009-08-23 02:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-08-23 01:27 . 2009-09-09 03:32 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Temp
2009-08-23 01:27 . 2009-08-26 01:14 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Google
2009-08-23 01:20 . 2009-08-23 01:20 17119 —-a-w- c:\windows\system32\drivers\AegisP.sys
2009-08-23 01:20 . 2005-01-08 00:05 147328 —-a-w- c:\windows\system32\rt2500usb.sys
2009-08-23 01:20 . 2005-01-08 00:05 147328 —-a-w- c:\windows\system32\drivers\rt2500usb.sys
2009-08-23 01:20 . 2004-04-24 05:43 374752 —-a-w- c:\windows\system32\WUSBGXP.sys
2009-08-23 01:20 . 2004-01-08 00:04 339488 —-a-w- c:\windows\system32\WUSB20XP.sys
2009-08-23 01:20 . 2003-10-13 22:30 94208 —-a-w- c:\windows\system32\GTW32N50.dll
2009-08-23 01:20 . 2003-09-26 05:15 15872 —-a-w- c:\windows\system32\GTNDIS5.sys
2009-08-23 01:20 . 2009-08-23 01:20 ——– d—–w- c:\program files\Linksys Wireless-G USB Wireless Network Monitor
2009-08-23 00:38 . 2004-08-04 07:56 21504 —-a-w- c:\windows\system32\hidserv.dll
2009-08-23 00:38 . 2004-08-04 07:56 21504 —-a-w- c:\windows\system32\dllcache\hidserv.dll
2009-08-23 00:38 . 2004-08-04 05:58 14848 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2009-08-23 00:38 . 2004-08-04 05:58 14848 —-a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-08-23 00:38 . 2001-08-17 20:48 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2009-08-23 00:38 . 2001-08-17 20:48 12160 —-a-w- c:\windows\system32\dllcache\mouhid.sys
2009-08-23 00:37 . 2001-08-17 21:02 9600 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-08-23 00:37 . 2001-08-17 21:02 9600 —-a-w- c:\windows\system32\dllcache\hidusb.sys
2009-08-23 00:37 . 2004-08-04 06:08 31616 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2009-08-23 00:37 . 2004-08-04 06:08 31616 —-a-w- c:\windows\system32\dllcache\usbccgp.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-08 10:38 . 2007-04-30 07:16 182912 —-a-w- c:\windows\system32\drivers\ndis.sys
2009-09-08 01:42 . 2005-02-15 11:18 ——– d—–w- c:\program files\Java
2009-09-06 07:45 . 2005-02-15 11:31 ——– d—–w- c:\program files\HP
2009-08-23 20:08 . 2005-02-15 12:20 ——– d—–w- c:\program files\Symantec
2009-08-23 01:20 . 2005-02-15 11:47 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-23 01:01 . 2005-02-15 12:20 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-08-23 00:55 . 2005-02-15 12:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-23 00:51 . 2009-01-25 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2001-11-30 18:26 . 2001-11-30 18:26 98304 —-a-w- c:\program files\internet explorer\plugins\LVActiveXControl.dll
2005-11-21 06:56 . 2009-01-25 18:54 32 –sha-w- c:\windows\SMINST\HPCD.SYS
.

——- Sigcheck ——-

[-] 2009-09-08 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ndis.sys
[-] 2009-09-08 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ndis.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-23 133104]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-08 149280]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-02-15 180269]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"PS2"="c:\windows\system32\ps2.exe" [2004-10-26 90112]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-02-15 98304]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Bpepim"="c:\windows\uragimog.dll" [2004-08-04 174592]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-30 88363]
"AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-08 57344]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli cpsmsrtx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Documents and Settings\\HP_Owner\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\HP_Owner\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7159:TCP"= 7159:TCP:dxboyfdp

.
Contents of the 'Scheduled Tasks' folder

2009-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3212003977-2378910954-357150617-1009Core.job
- c:\documents and settings\HP_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-23 01:27]

2009-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3212003977-2378910954-357150617-1009UA.job
- c:\documents and settings\HP_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-23 01:27]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-19049684 - c:\documents and settings\All Users\Application Data\19049684\19049684.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Add To HP Organize… - c:\progra~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
FF - ProfilePath - c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\458k918k.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.phy.hk/wiki/englishhtm/RLC.htm|http://forums.whatthetech.com/malmal_t106841.html&gopid=594717#entry594717
FF - plugin: c:\documents and settings\HP_Owner\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\HP_Owner\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: XUL Cache: {9CEA2E74-9BE8-46A6-8C9C-768342A83B2C} - c:\documents and settings\Administrator\Local Settings\Application Data\{9CEA2E74-9BE8-46A6-8C9C-768342A83B2C}\
FF - HiddenExtension: XUL Cache: {897C5F10-2A0A-4C02-887A-A80A19521A91} - c:\documents and settings\HP_Owner\Local Settings\Application Data\{897C5F10-2A0A-4C02-887A-A80A19521A91}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-09 08:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(676)
c:\windows\cpsmsrtx.dll

- - - - - - - > 'explorer.exe'(3664)
c:\windows\cpsmsrtx.dll
c:\windows\uragimog.dll
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-09 8:32 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-09 07:32

Pre-Run: 105,203,998,720 bytes free
Post-Run: 105,091,837,952 bytes free

245
Machine is being used as SMTP node


C:\>netstat

Active Connections

Proto Local Address Foreign Address State
TCP your-4f1261a8e5:1048 hosted-by.leaseweb.com:3954 ESTABLISHED
TCP your-4f1261a8e5:1050 hosted-by.leaseweb.com:3954 ESTABLISHED
TCP your-4f1261a8e5:3701 server.viphoster.su:smtp ESTABLISHED
TCP your-4f1261a8e5:4153 [removed]:smtp ESTABLISHED
TCP your-4f1261a8e5:4158 [removed]:smtp ESTABLISHED
TCP your-4f1261a8e5:4160 mail.lenexpo.ru:smtp ESTABLISHED
TCP your-4f1261a8e5:4184 perun.nnm.netserv.name:smtp ESTABLISHED
TCP your-4f1261a8e5:4191 mx.online.bryansk.ru:smtp ESTABLISHED
TCP your-4f1261a8e5:4219 hosting1.ertelecom.ru:smtp ESTABLISHED
TCP your-4f1261a8e5:4312 relay2.izhavto.ru:smtp ESTABLISHED
TCP your-4f1261a8e5:4317 mx1.it-online.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4318 henry.peterlink.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4330 cannabis.dataforce.net:smtp ESTABLISHED
TCP your-4f1261a8e5:4331 fr1.itc-sib.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4332 mx.infobox.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4334 fr1.itc-sib.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4336 ns1.kirovtelecom.net:smtp ESTABLISHED
TCP your-4f1261a8e5:4342 [removed]:smtp ESTABLISHED
TCP your-4f1261a8e5:4350 mail.kgau.ru:smtp ESTABLISHED
TCP your-4f1261a8e5:4352 mail.kgau.ru:smtp ESTABLISHED
TCP your-4f1261a8e5:4353 net-profit.ru:smtp ESTABLISHED
TCP your-4f1261a8e5:4355 hosting1.ertelecom.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4357 srv02.hgrad.ru:smtp ESTABLISHED
TCP your-4f1261a8e5:4360 ironport1.onlanta.ru:smtp ESTABLISHED
TCP your-4f1261a8e5:4361 gaztech.ch.govorit.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4362 horn.post.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4363 mailx.index20.ru:smtp ESTABLISHED
TCP your-4f1261a8e5:4364 smtp.cgp.dol.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4368 mailx.index20.ru:smtp ESTABLISHED
TCP your-4f1261a8e5:4369 horn.post.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4370 gaztech.ch.govorit.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4372 receiver2.nextmail.ru:smtp ESTABLISHED
TCP your-4f1261a8e5:4374 [removed]:smtp SYN_SENT
TCP your-4f1261a8e5:4375 mail.selenebs.net:smtp ESTABLISHED
TCP your-4f1261a8e5:4376 relay.pdmi.ras.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4379 smtp.cgp.dol.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4380 relay.pdmi.ras.ru:smtp SYN_SENT
TCP your-4f1261a8e5:4383 helene.gazinter.net:smtp SYN_SENT
TCP your-4f1261a8e5:1518 localhost:1519 ESTABLISHED
TCP your-4f1261a8e5:1519 localhost:1518 ESTABLISHED
TCP your-4f1261a8e5:1528 localhost:1529 ESTABLISHED
TCP your-4f1261a8e5:1529 localhost:1528 ESTABLISHED
TCP your-4f1261a8e5:5152 localhost:ingreslock CLOSE_WAIT

C:\>
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    http://forums.whatthetech.com/malmal_t106841.html
    
    Collect::
    c:\windows\cpsmsrtx.dll
    c:\windows\uragimog.dll
    
    Registry:: 
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Notification Packages"=hex(7):73,63,65,63,6c,69,00,00
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Had to attempt drag and drop twice.

First run asked to update and later stopped after error message in window outside ComboFix. This message looped. After closing all the stacked error messages - all the same - I forced reboot using power switch.

Second run results below.

Also set DD-WRT to filter SMTP traffic to thwart the blackhats. In some small way. :D

ComboFix 09-09-08.06 - HP_Owner 09/09/2009 10:05.3.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.176 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Owner\Desktop\CFScript.txt
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\ntndis.sys
.
—- Previous Run ——-
.
c:\documents and settings\HP_Owner\Local Settings\Application Data\{897C5F10-2A0A-4C02-887A-A80A19521A91}
c:\documents and settings\HP_Owner\Local Settings\Application Data\{897C5F10-2A0A-4C02-887A-A80A19521A91}\chrome.manifest
c:\documents and settings\HP_Owner\Local Settings\Application Data\{897C5F10-2A0A-4C02-887A-A80A19521A91}\chrome\content\_cfg.js
c:\documents and settings\HP_Owner\Local Settings\Application Data\{897C5F10-2A0A-4C02-887A-A80A19521A91}\chrome\content\overlay.xul
c:\documents and settings\HP_Owner\Local Settings\Application Data\{897C5F10-2A0A-4C02-887A-A80A19521A91}\install.rdf
c:\windows\cpsmsrtx.dll
c:\windows\uragimog.dll

.
((((((((((((((((((((((((( Files Created from 2009-08-09 to 2009-09-09 )))))))))))))))))))))))))))))))
.

2009-09-08 23:25 . 2009-09-08 23:25 ——– d—–w- c:\program files\ERUNT
2009-09-08 20:33 . 2009-09-08 21:20 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-09-08 20:33 . 2009-09-08 21:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-08 20:10 . 2009-09-09 07:02 120 —-a-w- c:\windows\Dkisad.dat
2009-09-08 01:42 . 2009-09-08 01:42 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-09-07 05:54 . 2009-09-07 05:54 ——– d—–w- c:\program files\LTC
2009-09-06 07:44 . 2009-09-06 07:44 ——– d—–w- c:\documents and settings\HP_Owner\Application Data\WinBatch
2009-09-05 21:53 . 2009-09-05 21:53 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\MathematicaPlayer
2009-09-05 21:53 . 2009-09-05 21:53 ——– d—–w- c:\documents and settings\HP_Owner\Application Data\MathematicaPlayer
2009-09-05 21:53 . 2009-09-05 21:53 ——– d—–w- c:\documents and settings\All Users\Application Data\MathematicaPlayer
2009-09-05 20:24 . 2009-03-05 17:53 185640 —-a-w- c:\windows\system32\mlmodule32.dll
2009-09-05 20:24 . 2009-03-05 17:53 378152 —-a-w- c:\windows\system32\ml32i3.dll
2009-09-05 20:24 . 2009-03-05 17:53 267560 —-a-w- c:\windows\system32\ml32i2.dll
2009-09-05 20:24 . 2009-03-05 17:53 259368 —-a-w- c:\windows\system32\ml32i1.dll
2009-09-05 20:23 . 2009-09-05 20:23 ——– d—–w- c:\program files\Wolfram Research
2009-09-05 03:24 . 2009-09-05 03:24 ——– d—–w- c:\windows\Sun
2009-09-04 06:01 . 2009-09-04 06:01 0 —-a-w- c:\windows\nsreg.dat
2009-09-04 06:01 . 2009-09-04 06:01 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Mozilla
2009-08-31 23:45 . 2009-09-06 05:28 ——– d—–w- C:\CM60S
2009-08-31 23:45 . 1998-07-30 13:47 363892 —-a-w- c:\windows\ISUN16.EXE
2009-08-31 23:45 . 1995-07-13 18:43 26768 —-a-w- c:\windows\system\CTL3D.DLL
2009-08-31 20:18 . 2009-08-31 20:18 14981 —-a-w- c:\windows\unins000.dat
2009-08-31 20:18 . 2009-08-31 20:18 ——– d—–w- c:\program files\Common Files\SourceTec
2009-08-31 20:18 . 2009-08-31 20:17 695642 —-a-w- c:\windows\unins000.exe
2009-08-31 20:02 . 2009-05-19 17:32 758018 —-a-w- c:\windows\system32\xvidcore.dll
2009-08-31 20:02 . 2008-12-04 20:46 180224 —-a-w- c:\windows\system32\xvidvfw.dll
2009-08-31 20:02 . 2009-08-31 20:27 ——– d—–w- c:\program files\iWisoft Flash SWF to Video Converter
2009-08-30 19:10 . 2009-08-30 19:10 ——– d—–w- c:\windows\system32\cvirte
2009-08-30 19:10 . 2009-08-30 19:10 ——– d—–w- c:\program files\SteornLab
2009-08-29 19:53 . 2009-08-29 19:53 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\VMGVersxx
2009-08-29 19:52 . 2009-08-29 19:52 ——– d—–w- c:\program files\Vizimag 3.18
2009-08-28 22:47 . 2009-08-28 22:47 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Help
2009-08-28 18:08 . 1996-11-08 02:48 368912 —-a-w- c:\windows\system32\vbar332.dll
2009-08-28 18:08 . 1997-08-28 16:00 3572224 —-a-w- c:\windows\system32\crpe32.dll
2009-08-28 18:08 . 1997-07-10 23:00 251664 —-a-w- c:\windows\system32\msrd2x35.dll
2009-08-28 18:08 . 1997-07-10 23:00 24336 —-a-w- c:\windows\system32\msjter35.dll
2009-08-28 18:08 . 1997-07-10 23:00 121104 —-a-w- c:\windows\system32\msjint35.dll
2009-08-28 18:08 . 1997-07-10 23:00 1037312 —-a-w- c:\windows\system32\msjet35.dll
2009-08-28 18:08 . 1995-02-15 00:11 17920 —-a-w- c:\windows\system32\implode.dll
2009-08-28 18:08 . 2009-08-29 08:28 ——– d—–w- c:\program files\OrCAD_Demo
2009-08-28 18:08 . 1997-08-28 16:00 416768 —-a-w- c:\windows\system32\cpeaut32.dll
2009-08-28 10:27 . 2009-08-28 10:27 ——– d—–w- c:\program files\DeltaCad
2009-08-28 09:34 . 2009-08-28 09:34 ——– d—–w- c:\program files\Canon
2009-08-28 09:33 . 2009-08-28 09:33 ——– d—–w- c:\temp\ScanGearToolboxCSv223
2009-08-28 09:21 . 2004-08-03 21:58 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2009-08-28 09:21 . 2004-08-03 21:58 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2009-08-28 09:17 . 2009-08-28 09:33 ——– d—–w- C:\Temp
2009-08-28 09:17 . 2009-08-28 09:17 ——– d—–w- c:\temp\CanoScan
2009-08-27 03:05 . 2009-08-27 03:05 ——– d—–w- c:\program files\IrfanView
2009-08-25 12:54 . 2009-08-25 12:54 ——– d—–w- c:\program files\Scope
2009-08-25 12:52 . 2009-08-25 12:52 ——– d—–w- c:\program files\Scope_131
2009-08-24 03:23 . 2009-09-06 07:28 ——– d—–w- c:\program files\National Instruments
2009-08-24 03:15 . 2008-10-16 13:09 43544 —-a-w- c:\windows\system32\wups2.dll
2009-08-24 00:36 . 2009-08-24 00:36 ——– d—–w- c:\documents and settings\HP_Owner\Application Data\AdobeUM
2009-08-24 00:36 . 2009-08-24 00:36 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Adobe
2009-08-24 00:36 . 2009-08-24 00:36 ——– d—–w- c:\program files\Common Files\Adobe
2009-08-23 16:14 . 2009-08-23 16:14 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Identities
2009-08-23 02:23 . 2009-09-09 06:06 ——– d—–w- c:\documents and settings\HP_Owner\Application Data\Skype
2009-08-23 02:23 . 2009-08-23 02:23 ——– d—–r- c:\program files\Skype
2009-08-23 02:23 . 2009-08-23 02:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-08-23 01:27 . 2009-09-09 03:32 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Temp
2009-08-23 01:27 . 2009-08-26 01:14 ——– d—–w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Google
2009-08-23 01:20 . 2009-08-23 01:20 17119 —-a-w- c:\windows\system32\drivers\AegisP.sys
2009-08-23 01:20 . 2005-01-08 00:05 147328 —-a-w- c:\windows\system32\rt2500usb.sys
2009-08-23 01:20 . 2005-01-08 00:05 147328 —-a-w- c:\windows\system32\drivers\rt2500usb.sys
2009-08-23 01:20 . 2004-04-24 05:43 374752 —-a-w- c:\windows\system32\WUSBGXP.sys
2009-08-23 01:20 . 2004-01-08 00:04 339488 —-a-w- c:\windows\system32\WUSB20XP.sys
2009-08-23 01:20 . 2003-10-13 22:30 94208 —-a-w- c:\windows\system32\GTW32N50.dll
2009-08-23 01:20 . 2003-09-26 05:15 15872 —-a-w- c:\windows\system32\GTNDIS5.sys
2009-08-23 01:20 . 2009-08-23 01:20 ——– d—–w- c:\program files\Linksys Wireless-G USB Wireless Network Monitor
2009-08-23 00:38 . 2004-08-04 07:56 21504 —-a-w- c:\windows\system32\hidserv.dll
2009-08-23 00:38 . 2004-08-04 07:56 21504 —-a-w- c:\windows\system32\dllcache\hidserv.dll
2009-08-23 00:38 . 2004-08-04 05:58 14848 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2009-08-23 00:38 . 2004-08-04 05:58 14848 —-a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-08-23 00:38 . 2001-08-17 20:48 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2009-08-23 00:38 . 2001-08-17 20:48 12160 —-a-w- c:\windows\system32\dllcache\mouhid.sys
2009-08-23 00:37 . 2001-08-17 21:02 9600 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-08-23 00:37 . 2001-08-17 21:02 9600 —-a-w- c:\windows\system32\dllcache\hidusb.sys
2009-08-23 00:37 . 2004-08-04 06:08 31616 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2009-08-23 00:37 . 2004-08-04 06:08 31616 —-a-w- c:\windows\system32\dllcache\usbccgp.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-09 09:04 . 2007-04-30 07:16 182912 —-a-w- c:\windows\system32\drivers\ndis.sys
2009-09-09 08:29 . 2009-01-25 17:49 48952 —-a-w- c:\documents and settings\HP_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-08 01:42 . 2005-02-15 11:18 ——– d—–w- c:\program files\Java
2009-09-06 07:45 . 2005-02-15 11:31 ——– d—–w- c:\program files\HP
2009-08-23 20:08 . 2005-02-15 12:20 ——– d—–w- c:\program files\Symantec
2009-08-23 01:20 . 2005-02-15 11:47 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-23 01:01 . 2005-02-15 12:20 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-08-23 00:55 . 2005-02-15 12:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-23 00:51 . 2009-01-25 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2001-11-30 18:26 . 2001-11-30 18:26 98304 —-a-w- c:\program files\internet explorer\plugins\LVActiveXControl.dll
2005-11-21 06:56 . 2009-01-25 18:54 32 –sha-w- c:\windows\SMINST\HPCD.SYS
.

((((((((((((((((((((((((((((( SnapShot@2009-09-09_07.30.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-09 09:09 . 2009-09-09 09:09 16384 c:\windows\temp\Perflib_Perfdata_678.dat
+ 2007-04-30 07:16 . 2009-09-09 09:04 182912 c:\windows\system32\dllcache\ndis.sys
- 2007-04-30 07:16 . 2009-09-08 10:38 182912 c:\windows\system32\dllcache\ndis.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-23 133104]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-08 149280]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-02-15 180269]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"PS2"="c:\windows\system32\ps2.exe" [2004-10-26 90112]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-02-15 98304]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-30 88363]
"AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-08 57344]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Documents and Settings\\HP_Owner\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\HP_Owner\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7159:TCP"= 7159:TCP:dxboyfdp

.
Contents of the 'Scheduled Tasks' folder

2009-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3212003977-2378910954-357150617-1009Core.job
- c:\documents and settings\HP_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-23 01:27]

2009-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3212003977-2378910954-357150617-1009UA.job
- c:\documents and settings\HP_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-23 01:27]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q105&bd;=pavilion&pf;=desktop
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Add To HP Organize… - c:\progra~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
FF - ProfilePath - c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\458k918k.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.phy.hk/wiki/englishhtm/RLC.htm|http://forums.whatthetech.com/malmal_t106841.html&gopid;=594720#entry594720|http://10.0.0.1/Status_Router.asp
FF - plugin: c:\documents and settings\HP_Owner\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\HP_Owner\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: XUL Cache: {9CEA2E74-9BE8-46A6-8C9C-768342A83B2C} - c:\documents and settings\Administrator\Local Settings\Application Data\{9CEA2E74-9BE8-46A6-8C9C-768342A83B2C}\
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Bpepim - c:\windows\uragimog.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-09 10:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-09 10:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-09 09:11
ComboFix2.txt 2009-09-09 07:32

Pre-Run: 105,086,451,712 bytes free
Post-Run: 105,057,341,440 bytes free

223
1) GooredFix
Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

2) MBAM
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

3) ESET
You can use either Internet Explorer or Mozilla FireFox for this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

4) What You Will Need To Post:
  • GooredFix log
  • MBAM log
  • ESET log
GooredFix by jpshortstuff (12.07.09) Log created at 11:08 on 09/09/2009 (HP_Owner) Firefox version 3.5.2 (en-US) ========== GooredScan ========== Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{9CEA2E74-9BE8-46A6-8C9C-768342A83B2C} -> Success! Deleting C:\Documents and Settings\Administrator\Local Settings\Application Data\{9CEA2E74-9BE8-46A6-8C9C-768342A83B2C} -> Success! C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [06:00 04/09/2009] {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} [01:42 08/09/2009] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [01:42 08/09/2009] -=E.O.F=-
Malwarebytes' Anti-Malware 1.40 Database version: 2763 Windows 5.1.2600 Service Pack 2 9/9/2009 11:26:57 AM mbam-log-2009-09-09 (11-26-57).txt Scan type: Quick Scan Objects scanned: 100463 Time elapsed: 3 minute(s), 18 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Raktor, I regret that ESET fails to download the database. It progressed to about 50% and then reports: "Can not get update. Is proxy configured?" Tried restarting executable - get same error.
We'll try this instead.

Please do a scan with the Kaspersky Online Scanner

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition
    files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a long time, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report

To obtain the report:
  • Click on Save Report As
  • In the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar
  • In Save as type, click the drop arrow and select Text file [*.txt]
  • Click Save

(Note for Internet Explorer users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75%. Once the license has been accepted, reset to 100%.)
Persistence pays. Got ESET scan *without* proxy changes. Suspect connection speed variation was interpreted by ESET as proxy.

Thank you for your continued persistence, Raktor.

ESET Online Scanner LOG:

ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=45315
esets_scanner_update returned -1 esets_gle=1
esets_scanner_update returned -1 esets_gle=1
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
all ok
# version=6
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6050
# api_version=3.0.2
# EOSSerial=464ddfce9d95e04d81d3d077dd7b6c43
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2009-09-10 02:51:57
# local_time=2009-09-10 03:51:57 (+0000, GMT Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# scanned=64118
# found=4
# cleaned=0
# scan_time=1949
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\eZulaHotText.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Nurech.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\_bokiybra_.dll.zip Win32/Conficker.X worm 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ndis.sys.vir Win32/Protector.C virus 00000000000000000000000000000000 I
Nope, ESET is fine. The files ESET found are all in quarantine, so nothing to worry about. :) Before we proceed to the end, are you still experiencing any symptoms?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI