Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93081 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

[Resolved] Hijack.WindowsUpdates again again!


  • This topic is locked This topic is locked
8 replies to this topic

#1 eak500

eak500

    New Member

  • Authentic Member
  • Pip
  • 5 posts

Posted 26 September 2009 - 07:42 PM

Hi Guys

My com keeps restarting and shows error" the system process 'C:\WINDOWS\system32\services.exe terminated unexpectedly with status code - 1073741819. The system will now shutdown and restart".

then i downloaded "Malwarebytes" to scan and it found 2 Trojans which are "Hijack.WindowUpdate". Malwarebyte can delete it and my restart symptom disappear. So, i guess those Trojans are the cause.However, after Malwarebytes deleted and quarantined, it come back every time i restart and face the same problem(keep restarting).

then, i tried "Avira Antivirus" . i scaned through the whole computer and found few trojans, then i deleted it but in fact those are Malwarebytes file(i realized after that because it shows error message on the destop " Malwarebytes error runtime = 0 " and i cann't open Malwarebytes. then, i remove Malwarebytes, reload and restalll and rescan again.(come back to the same positive where i can delete,quarantined time one time. but Torjan come back everytime i restart.)

Basically, it is very much the same as these 2 links.
http://forums.whatth...s....html&st=15
http://forums.whatth...on_t107128.html


please help!!!!.... i have been searching and trying to fix it for whole day and finally i find the hope here. Thanks in advance.
here is my log from Malwarebytpe.







Here is Root Repeal Log


ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/27 09:23
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================

Drivers
-------------------
Name: 15208973.sys
Image Path: C:\WINDOWS\System32\drivers\15208973.sys
Address: 0xA7BDE000 Size: 87168 File Visible: No Signed: -
Status: -

Name: 32963cb3.sys
Image Path: C:\WINDOWS\System32\drivers\32963cb3.sys
Address: 0xA7BF4000 Size: 87168 File Visible: No Signed: -
Status: -

Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA7BC6000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA5E4000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA5D61000 Size: 49152 File Visible: No Signed: -
Status: -

SSDT
-------------------
#: 031 Function Name: NtConnectPort
Status: Hooked by "<unknown>" at address 0x8a47ade0

#: 035 Function Name: NtCreateEvent
Status: Hooked by "C:\WINDOWS\System32\drivers\15208973.sys" at address 0xa7be4595

#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\ntkrnlpa.exe" at address 0x804d7fce

#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0xba6b8224

#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\system32\ntkrnlpa.exe" at address 0x804d7fd8

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xa8078350

#: 071 Function Name: NtEnumerateKey
Status: Hooked by "C:\WINDOWS\system32\ntkrnlpa.exe" at address 0x804d7fdd

#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "C:\WINDOWS\system32\ntkrnlpa.exe" at address 0x804d7fe2

#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0xba6b8242

#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\system32\ntkrnlpa.exe" at address 0x804d7ff1

#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xba6b8210

#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0xba6b8215

#: 160 Function Name: NtQueryKey
Status: Hooked by "C:\WINDOWS\system32\ntkrnlpa.exe" at address 0x804d7fec

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\system32\ntkrnlpa.exe" at address 0x804d7fe7

#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0xba6b824c

#: 204 Function Name: NtRestoreKey
Status: Hooked by "<unknown>" at address 0xba6b8247

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\Drivers\SYMEVENT.SYS" at address 0xa8078580

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys" at address 0xa7d6c0b0

Hidden Services
-------------------
Service Name: 15208973
Image Path: C:\WINDOWS\System32\drivers\15208973.sys

Service Name: 32963cb3
Image Path: C:\WINDOWS\System32\drivers\32963cb3.sys

==EOF==









Here is the DDS log


DDS (Ver_09-06-26.01) - NTFSx86
Run by Artit.Aowudomsuk at 9:17:23.43 on Sun 09/27/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.2.874.66.1033.18.2038.1175 [GMT 8:00]

AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Strokeit\strokeit.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PPStream\ppsap.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
svchost.exe
C:\Documents and Settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Mobile Broadband Modem\Mobile Broadband Modem.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\WINDOWS\system32\hasplms.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\SolidWorks (3)\COSMOSFloWorks\FloWorks\binCFW\StandAloneSlv.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\StacSV.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Ateksoft\WebCamera Plus\WebCamPlusSrv.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\Intel\WiFi\bin\WLKeeper.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\ARTIT.AOWUDOMSUK\Desktop\Download\Anti Virus\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
mDefault_Page_URL = hxxp://www1.ap.dell.com/content/default.aspx?c=sg&l=en&s=gen
mStart Page = hxxp://www1.ap.dell.com/content/default.aspx?c=sg&l=en&s=gen
uInternet Connection Wizard,ShellNext = hxxp://www1.ap.dell.com/content/default.aspx?c=sg&l=en&s=gen
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
uRun: [StrokeIt] "c:\program files\strokeit\strokeit.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [PPS Accelerator] "c:\program files\ppstream\ppsap.exe"
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [SRS Audio Sandbox] "c:\program files\srs labs\audio sandbox\SRSSSC.exe" /hideme
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe"
mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe"
mRun: [Persistence] "c:\windows\system32\igfxpers.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] "c:\windows\system32\ime\pintlgnt\ImScInst.exe" /SYNC
mRun: [PHIME2002ASync] "c:\windows\system32\ime\tintlgnt\TINTSETP.EXE" /SYNC
mRun: [PHIME2002A] "c:\windows\system32\ime\tintlgnt\TINTSETP.EXE" /IMEName
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
StartupFolder: c:\docume~1\artit~1.aow\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\artit~1.aow\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\artit.aowudomsuk\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\dap\dapextie.htm
IE: &Winamp Search - c:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html
IE: Download &all with DAP - c:\program files\dap\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFECAFE-0013-0001-0021-ABCDEFABCDEF} - hxxp://r2d2.ads.finisar.com:8000/jinitiator/oajinit.exe
DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
TCP: {538B3CE6-D625-4879-9CBE-900048C9F94E} = 203.116.1.78 203.116.254.150
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !saswinlogon - c:\program files\superantispyware\SASWINLO.dll
Notify: gemsafe - c:\program files\gemplus\gemsafe libraries\bin\WLEventNotify.dll
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digiwet.dll
LSA: Authentication Packages = msv1_0 wvauth

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\artit~1.aow\applic~1\mozilla\firefox\profiles\z2wvciu9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sg/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\opera\program\plugins\NPJinit13121.dll
FF - plugin: c:\program files\opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\opera\program\plugins\nprpjplug.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-9-26 11608]
R1 sasdifsv;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-9-15 9968]
R1 saskutil;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-9-15 74480]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
R2 antivirschedulerservice;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-9-26 108289]
R2 antivirservice;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-9-26 185089]
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2006-12-19 79432]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-9-26 55656]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-11-21 192104]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-11-21 169576]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\memeo\autobackup\MemeoBackgroundService.exe [2008-11-8 25824]
R2 Remote Solver for COSMOSFloWorks 2007;Remote Solver for COSMOSFloWorks 2007;c:\program files\solidworks (3)\cosmosfloworks\floworks\bincfw\StandAloneSlv.exe [2007-7-23 675840]
R2 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-3-14 116416]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-3-14 1816768]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [2004-8-11 5120]
R2 Webcamera Plus Service;Webcamera Plus Service;c:\program files\ateksoft\webcamera plus\WebCamPlusSrv.exe [2008-8-7 46592]
R3 AteksoftAudio;WebCamera Plus Audio;c:\windows\system32\drivers\ateksoftaudio.sys [2008-8-7 11776]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2008-12-20 33792]
R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [2006-11-2 97536]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-28 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090926.002\naveng.sys [2009-9-27 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090926.002\navex15.sys [2009-9-27 1323568]
R3 sasenum;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-9-15 7408]
S2 LmHostsBrowser;TCP/IP NetBIOS Helper LmHostsBrowser;c:\windows\system32\accwizj.exe srv --> c:\windows\system32\accwizj.exe srv [?]
S2 ncenqmng;ncenqmng;c:\windows\system32\drivers\lpojb.sys --> c:\windows\system32\drivers\lpojb.sys [?]

=============== Created Last 30 ================

2009-09-27 01:09 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-09-27 01:09 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-09-27 01:09 <DIR> --d----- c:\docume~1\artit~1.aow\applic~1\SUPERAntiSpyware.com
2009-09-26 19:48 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-26 19:48 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-09-26 19:48 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-09-26 15:53 55,656 a------- c:\windows\system32\drivers\avgntflt.sys
2009-09-26 15:53 <DIR> --d----- c:\program files\Avira
2009-09-26 15:53 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-09-26 10:50 <DIR> --d----- c:\program files\MSSOAP
2009-09-26 10:50 <DIR> --d----- c:\program files\Webroot
2009-09-26 10:35 164 a------- c:\windows\install.dat
2009-09-26 09:22 <DIR> --d----- c:\program files\Trend Micro
2009-09-25 21:30 236 a------- C:\gen_jumpex.m3u8
2009-09-24 23:58 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SRS Labs
2009-09-22 19:44 <DIR> --d----- c:\program files\iTunes
2009-09-22 19:44 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-21 12:37 34,308 a------- c:\docume~1\alluse~1\applic~1\mazuki.dll
2009-09-20 11:59 <DIR> --d----- C:\e0d74555ac18879b75
2009-09-20 10:39 <DIR> --d----- c:\program files\MediaMonkey
2009-09-20 10:37 <DIR> --d----- c:\program files\CDex_150
2009-09-20 09:46 87,168 a------- c:\windows\system32\drivers\32963cb3.sys
2009-09-19 13:57 87,168 a------- c:\windows\system32\drivers\15208973.sys
2009-09-05 01:54 94,208 a------- c:\windows\system32\QuickTimeVR.qtx
2009-09-05 01:54 69,632 a------- c:\windows\system32\QuickTime.qts

==================== Find3M ====================

2009-03-30 00:17 30,601 a------- c:\documents and settings\artit.aowudomsuk\x.exe
2007-10-09 23:58 139,264 a------- c:\program files\CPE17AntiAutorun1310.exe

============= FINISH: 9:18:03.71 ===============

Attached Files


    Advertisements

Register to Remove


#2 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,060 posts
  • MVP

Posted 26 September 2009 - 11:00 PM

Hi.

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#3 eak500

eak500

    New Member

  • Authentic Member
  • Pip
  • 5 posts

Posted 27 September 2009 - 02:00 AM

Hi CatByte,

Thanks for help. i run combo fix. Then, i rescan by Malwarebytes. It still found 2 Trojans which are "Hijack.WindowUpdate". then, i clicked remove them as every time.




Here is comboFix log

ComboFix 09-09-25.01 - Artit.Aowudomsuk 09/27/2009 15:21.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.874.66.1033.18.2038.1362 [GMT 8:00]
Running from: c:\documents and settings\ARTIT.AOWUDOMSUK\Desktop\Download\Anti Virus\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\ARTIT.AOWUDOMSUK\x.exe
c:\windows\Installer\bdcbf7.msi
c:\windows\Installer\e2e68.msp
c:\windows\jestertb.dll
c:\windows\system32\4169916776.dat
c:\windows\system32\blat.exe
c:\windows\system32\drivers\15208973.sys
c:\windows\system32\drivers\32963cb3.sys
c:\windows\system32\skinboxer43.dll

----- BITS: Possible infected sites -----

hxxp://MY-SMS.malaysia.ads.finisar.com:80
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_LMHOSTSBROWSER
-------\Legacy_PORT135SIK
-------\Service_LmHostsBrowser
-------\Service_15208973
-------\Service_32963cb3


((((((((((((((((((((((((( Files Created from 2009-08-27 to 2009-09-27 )))))))))))))))))))))))))))))))
.

2009-09-27 01:20 . 2009-09-27 01:23 15 ----a-w- c:\documents and settings\ARTIT.AOWUDOMSUK\settings.dat
2009-09-26 17:09 . 2009-09-26 17:09 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-26 17:09 . 2009-09-26 17:09 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-26 17:09 . 2009-09-26 17:09 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\SUPERAntiSpyware.com
2009-09-26 16:51 . 2009-09-26 16:51 -------- d-----w- c:\program files\ERUNT
2009-09-26 11:48 . 2009-09-10 06:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-26 11:48 . 2009-09-26 11:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-26 11:48 . 2009-09-10 06:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-26 07:53 . 2009-07-28 08:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-26 07:53 . 2009-03-30 02:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-09-26 07:53 . 2009-02-13 04:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-09-26 07:53 . 2009-02-13 04:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-09-26 07:53 . 2009-09-26 07:53 -------- d-----w- c:\program files\Avira
2009-09-26 07:53 . 2009-09-26 07:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-09-26 02:50 . 2009-09-26 02:50 -------- d-----w- c:\program files\MSSOAP
2009-09-26 02:50 . 2009-09-26 02:50 -------- d-----w- c:\program files\Webroot
2009-09-26 02:35 . 2009-09-26 02:36 164 ----a-w- c:\windows\install.dat
2009-09-26 01:22 . 2009-09-26 01:22 -------- d-----w- c:\program files\Trend Micro
2009-09-24 15:58 . 2009-09-24 15:58 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Local Settings\Application Data\SRS Labs
2009-09-24 15:58 . 2009-09-24 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\SRS Labs
2009-09-22 11:44 . 2009-09-22 11:45 -------- d-----w- c:\program files\iTunes
2009-09-22 11:44 . 2009-09-22 11:45 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-20 04:30 . 2009-09-20 04:30 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Local Settings\Application Data\AlbumArtDownloader
2009-09-20 03:59 . 2009-09-20 04:00 -------- d-----w- C:\e0d74555ac18879b75
2009-09-20 02:39 . 2009-09-25 13:30 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Local Settings\Application Data\MediaMonkey
2009-09-20 02:39 . 2009-09-21 15:16 -------- d-----w- c:\program files\MediaMonkey
2009-09-20 02:37 . 2009-09-20 02:38 -------- d-----w- c:\program files\CDex_150
2009-09-03 12:13 . 2009-09-03 12:13 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Local Settings\Application Data\Mozilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-27 07:36 . 2009-08-21 12:39 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox
2009-09-27 06:52 . 2008-06-26 06:44 -------- d-----w- c:\program files\Symantec AntiVirus
2009-09-26 17:08 . 2009-01-17 14:08 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-26 07:16 . 2008-12-20 03:49 -------- d-----w- c:\program files\BitComet
2009-09-23 23:58 . 2009-03-12 17:17 -------- d-----w- c:\program files\PeerGuardian2
2009-09-22 11:57 . 2008-07-03 13:04 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Apple Computer
2009-09-22 11:44 . 2008-07-03 12:54 -------- d-----w- c:\program files\iPod
2009-09-22 11:44 . 2009-08-21 03:17 -------- d-----w- c:\program files\Common Files\Apple
2009-09-22 11:42 . 2008-07-03 13:03 -------- d-----w- c:\program files\QuickTime
2009-09-21 15:53 . 2008-08-05 11:37 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Skype
2009-09-21 13:52 . 2008-08-05 11:38 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\skypePM
2009-09-21 06:41 . 2008-07-07 07:35 206320 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-09-21 04:37 . 2009-09-21 04:37 34308 ----a-w- c:\documents and settings\All Users\Application Data\mazuki.dll
2009-09-20 10:00 . 2008-12-22 00:52 -------- d-----w- c:\program files\Norton Security Scan
2009-09-20 04:30 . 2008-07-02 05:43 61848 ----a-w- c:\documents and settings\ARTIT.AOWUDOMSUK\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-20 04:28 . 2008-06-10 08:04 61848 ----a-w- c:\documents and settings\NetworkService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-15 12:21 . 2009-08-19 11:44 -------- d-----w- c:\program files\PPStream
2009-09-10 15:17 . 2009-08-19 11:41 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\ppstream
2009-09-02 10:13 . 2008-07-03 03:18 -------- d-----w- c:\program files\Opera
2009-08-21 03:18 . 2009-08-21 03:18 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-21 03:17 . 2009-08-21 03:17 -------- d-----w- c:\program files\Apple Software Update
2009-08-20 14:58 . 2009-08-20 14:06 -------- d-----w- c:\program files\RaySource
2009-08-20 14:07 . 2009-08-20 14:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Grid
2009-08-20 14:06 . 2009-08-20 14:06 -------- d-----w- c:\program files\GridService
2009-08-19 11:41 . 2009-08-19 11:41 -------- d-----w- c:\program files\PPS
2009-08-17 09:38 . 2009-01-15 02:31 -------- d-----w- c:\program files\NeoMAP
2009-08-10 04:44 . 2009-08-10 04:44 -------- d-----w- c:\program files\Common Files\NSV
2009-08-08 07:03 . 2009-08-08 07:03 -------- d-----w- c:\program files\Plugins
2009-08-08 06:55 . 2009-08-08 06:12 -------- d-----w- c:\program files\Winamp
2009-08-08 06:24 . 2009-08-08 06:12 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Winamp
2009-08-08 06:14 . 2009-08-08 06:14 -------- d-----w- c:\program files\Winamp Toolbar
2009-08-08 06:14 . 2009-08-08 06:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Winamp Toolbar
2009-08-06 01:20 . 2008-06-10 07:48 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-06 01:20 . 2008-10-24 06:59 -------- d-----w- c:\program files\SAS
2009-08-06 01:20 . 2008-06-10 07:46 -------- d-----w- c:\program files\Java
2009-08-02 10:24 . 2009-08-02 10:24 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-17 14:41 . 2009-07-17 14:41 139 ----a-w- c:\documents and settings\ARTIT.AOWUDOMSUK\Local Settings\Application Data\fusioncache.dat
2007-10-09 15:58 . 2008-07-15 01:35 139264 ----a-w- c:\program files\CPE17AntiAutorun1310.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox\bin\DropboxExt.3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox\bin\DropboxExt.3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox\bin\DropboxExt.3.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StrokeIt"="c:\program files\Strokeit\strokeit.exe" [2005-02-17 21504]
"PPS Accelerator"="c:\program files\PPStream\ppsap.exe" [2009-07-22 210312]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-15 1998576]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-18 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-18 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-18 138008]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-22 136600]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2008-08-20 1368064]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-08 305440]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

c:\documents and settings\ARTIT.AOWUDOMSUK\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Dropbox.lnk - c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox\bin\Dropbox.exe [2009-8-28 26784939]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-6-10 50688]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!saswinlogon]
2009-09-03 07:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gemsafe]
2006-11-16 07:20 73728 ----a-w- c:\program files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^ARTIT.AOWUDOMSUK^Start Menu^Programs^Startup^1-2-Remote Server.lnk]
path=c:\documents and settings\ARTIT.AOWUDOMSUK\Start Menu\Programs\Startup\1-2-Remote Server.lnk
backup=c:\windows\pss\1-2-Remote Server.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^ARTIT.AOWUDOMSUK^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\documents and settings\ARTIT.AOWUDOMSUK\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^ARTIT.AOWUDOMSUK^Start Menu^Programs^Startup^Multiply AutoUploader.lnk]
path=c:\documents and settings\ARTIT.AOWUDOMSUK\Start Menu\Programs\Startup\Multiply AutoUploader.lnk
backup=c:\windows\pss\Multiply AutoUploader.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^ARTIT.AOWUDOMSUK^Start Menu^Programs^Startup^Pc-to-Phone.lnk]
path=c:\documents and settings\ARTIT.AOWUDOMSUK\Start Menu\Programs\Startup\Pc-to-Phone.lnk
backup=c:\windows\pss\Pc-to-Phone.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^ARTIT.AOWUDOMSUK^Start Menu^Programs^Startup^SolidWorks Task Scheduler Engine.lnk]
path=c:\documents and settings\ARTIT.AOWUDOMSUK\Start Menu\Programs\Startup\SolidWorks Task Scheduler Engine.lnk
backup=c:\windows\pss\SolidWorks Task Scheduler Engine.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Symantec AntiVirus"=2 (0x2)
"SPBBCSvc"=3 (0x3)
"SNDSrvc"=3 (0x3)
"DefWatch"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccEvtMgr"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Ateksoft\\WebCamera Plus\\WebCamPlusSrv.exe"=
"c:\\Program Files\\Ateksoft\\WebCamera Plus\\camviewer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Symantec AntiVirus\\VPC32.exe"=
"c:\\WINDOWS\\system32\\logon.scr"=
"c:\\WINDOWS\\system32\\WgaTray.exe"=
"c:\\Program Files\\Ahead\\Nero StartSmart\\NeroStartSmart.exe"=
"c:\\Program Files\\Ahead\\Nero\\nero.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\OUTLOOK.EXE"=
"c:\\Program Files\\Mobile Broadband Modem\\Mobile Broadband Modem.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\WINDOWS\\system32\\igfxpers.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\jusched.exe"=
"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
"c:\\Program Files\\Unlocker\\UnlockerAssistant.exe"=
"c:\\Program Files\\Dell\\QuickSet\\Quickset.exe"=
"c:\\Program Files\\Strokeit\\strokeit.exe"=
"c:\\WINDOWS\\system32\\igfxsrvc.exe"=
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ENABLE
"c:\\Program Files\\DAP\\DAP.EXE"=
"c:\\Program Files\\Digital Line Detect\\DLG.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ENABLE
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Program Files\\Babylon\\Babylon-Pro\\Babylon.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\WINDOWS\\system32\\sndvol32.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\K-Lite Codec Pack\\Media Player Classic\\mplayerc.exe"=
"c:\\Program Files\\K-Lite Codec Pack\\Filters\\divxsm.exe"=
"c:\\Documents and Settings\\ARTIT.AOWUDOMSUK\\Desktop\\Download\\ppstreamsetup.exe"=
"c:\\Program Files\\PPStream\\PPStream.exe"=
"c:\\Program Files\\PPStream\\PPSAP.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"18671:TCP"= 18671:TCP:BitComet 18671 TCP
"18671:UDP"= 18671:UDP:BitComet 18671 UDP

R1 sasdifsv;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 saskutil;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 antivirschedulerservice;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/26/2009 3:53 PM 108289]
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [12/19/2006 2:21 PM 79432]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [11/8/2008 3:38 AM 25824]
R2 Remote Solver for COSMOSFloWorks 2007;Remote Solver for COSMOSFloWorks 2007;c:\program files\SolidWorks (3)\COSMOSFloWorks\FloWorks\binCFW\StandAloneSlv.exe [7/23/2007 9:05 AM 675840]
R2 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [3/14/2007 7:48 PM 116416]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [8/11/2004 5:00 PM 5120]
R2 Webcamera Plus Service;Webcamera Plus Service;c:\program files\Ateksoft\WebCamera Plus\WebCamPlusSrv.exe [8/7/2008 8:48 PM 46592]
R3 AteksoftAudio;WebCamera Plus Audio;c:\windows\system32\drivers\ateksoftaudio.sys [8/7/2008 8:48 PM 11776]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [12/20/2008 9:05 PM 33792]
R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [11/2/2006 12:32 PM 97536]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/28/2009 8:56 AM 102448]
R3 sasenum;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S2 ncenqmng;ncenqmng;c:\windows\system32\drivers\lpojb.sys --> c:\windows\system32\drivers\lpojb.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2009-09-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 04:34]

2009-09-20 c:\windows\Tasks\Norton Security Scan for Artit.Aowudomsuk.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-18 20:18]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = hxxp://www1.ap.dell.com/content/default.aspx?c=sg&l=en&s=gen
uInternet Connection Wizard,ShellNext = hxxp://www1.ap.dell.com/content/default.aspx?c=sg&l=en&s=gen
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Mozilla\Firefox\Profiles\z2wvciu9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sg/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJinit13121.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-SRS Audio Sandbox - c:\program files\SRS Labs\Audio Sandbox\SRSSSC.exe
AddRemove-HijackThis - c:\documents and settings\ARTIT.AOWUDOMSUK\Desktop\HijackThis.exe
AddRemove-Steinberg Nuendo v3.2.0.1128 - c:\progra~1\STEINB~1\NUENDO~1\UNWISE.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-27 15:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(920)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'lsass.exe'(976)
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll

- - - - - - - > 'explorer.exe'(172)
c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox\bin\DropboxExt.3.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\program files\Common Files\Roxio Shared\9.0\DLLShared\DLAAPI_W.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\scardsvr.exe
c:\windows\system32\igfxsrvc.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\windows\system32\hasplms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\windows\system32\stacsv.exe
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
c:\program files\RealVNC\VNC4\winvnc4.exe
c:\program files\Intel\WiFi\bin\WLKEEPER.exe
c:\windows\system32\CCM\clicomp\RemCtrl\Wuser32.exe
c:\windows\system32\CCM\CcmExec.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-09-27 15:43 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-27 07:43

Pre-Run: 22,248,267,776 bytes free
Post-Run: 22,453,448,704 bytes free

341 --- E O F --- 2009-07-13 10:33

Edited by eak500, 27 September 2009 - 02:03 AM.


#4 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,060 posts
  • MVP

Posted 27 September 2009 - 06:06 AM

Hi,

Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Hijack_WindowsUpdates_again_again_t107225.html&view=findpost&p=599126#entry599126

collect::
c:\windows\system32\drivers\lpojb.sys

driver::
ncenqmng

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As... Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save ...

Posted Image
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT



CKScanner
Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <-- very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    Posted Image
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • CKScan Log
  • MBAM Log
  • Kaspersky report

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#5 eak500

eak500

    New Member

  • Authentic Member
  • Pip
  • 5 posts

Posted 27 September 2009 - 05:24 PM

Hi Catbyte,

Here are my logs. one thing need to be noticed. i cann't disable synmatec antivirus. my company locks the disable function. So, i try to disable every synmatec files when computer start up but it seems that there is still some running. Anyway, i try my risk and here are the logs.


ComboFix Log

ComboFix 09-09-25.01 - Artit.Aowudomsuk 09/27/2009 21:45.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.874.66.1033.18.2038.1190 [GMT 8:00]
Running from: c:\documents and settings\ARTIT.AOWUDOMSUK\Desktop\Download\Anti Virus\ComboFix.exe
Command switches used :: c:\documents and settings\ARTIT.AOWUDOMSUK\Desktop\Download\Anti Virus\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NCENQMNG
-------\Service_ncenqmng


((((((((((((((((((((((((( Files Created from 2009-08-27 to 2009-09-27 )))))))))))))))))))))))))))))))
.

2009-09-27 01:20 . 2009-09-27 01:23 15 ----a-w- c:\documents and settings\ARTIT.AOWUDOMSUK\settings.dat
2009-09-26 17:09 . 2009-09-26 17:09 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-26 17:09 . 2009-09-26 17:09 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-26 17:09 . 2009-09-26 17:09 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\SUPERAntiSpyware.com
2009-09-26 16:51 . 2009-09-26 16:51 -------- d-----w- c:\program files\ERUNT
2009-09-26 11:48 . 2009-09-10 06:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-26 11:48 . 2009-09-26 11:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-26 11:48 . 2009-09-10 06:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-26 07:53 . 2009-07-28 08:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-26 07:53 . 2009-03-30 02:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-09-26 07:53 . 2009-02-13 04:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-09-26 07:53 . 2009-02-13 04:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-09-26 07:53 . 2009-09-26 07:53 -------- d-----w- c:\program files\Avira
2009-09-26 07:53 . 2009-09-26 07:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-09-26 02:50 . 2009-09-26 02:50 -------- d-----w- c:\program files\MSSOAP
2009-09-26 02:50 . 2009-09-26 02:50 -------- d-----w- c:\program files\Webroot
2009-09-26 02:35 . 2009-09-26 02:36 164 ----a-w- c:\windows\install.dat
2009-09-26 01:22 . 2009-09-26 01:22 -------- d-----w- c:\program files\Trend Micro
2009-09-24 15:58 . 2009-09-24 15:58 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Local Settings\Application Data\SRS Labs
2009-09-24 15:58 . 2009-09-24 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\SRS Labs
2009-09-22 11:44 . 2009-09-22 11:45 -------- d-----w- c:\program files\iTunes
2009-09-22 11:44 . 2009-09-22 11:45 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-20 04:30 . 2009-09-20 04:30 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Local Settings\Application Data\AlbumArtDownloader
2009-09-20 03:59 . 2009-09-20 04:00 -------- d-----w- C:\e0d74555ac18879b75
2009-09-20 02:39 . 2009-09-25 13:30 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Local Settings\Application Data\MediaMonkey
2009-09-20 02:39 . 2009-09-21 15:16 -------- d-----w- c:\program files\MediaMonkey
2009-09-20 02:37 . 2009-09-20 02:38 -------- d-----w- c:\program files\CDex_150
2009-09-03 12:13 . 2009-09-03 12:13 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Local Settings\Application Data\Mozilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-27 13:58 . 2009-08-21 12:39 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox
2009-09-27 06:52 . 2008-06-26 06:44 -------- d-----w- c:\program files\Symantec AntiVirus
2009-09-26 17:08 . 2009-01-17 14:08 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-26 07:16 . 2008-12-20 03:49 -------- d-----w- c:\program files\BitComet
2009-09-23 23:58 . 2009-03-12 17:17 -------- d-----w- c:\program files\PeerGuardian2
2009-09-22 11:57 . 2008-07-03 13:04 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Apple Computer
2009-09-22 11:44 . 2008-07-03 12:54 -------- d-----w- c:\program files\iPod
2009-09-22 11:44 . 2009-08-21 03:17 -------- d-----w- c:\program files\Common Files\Apple
2009-09-22 11:42 . 2008-07-03 13:03 -------- d-----w- c:\program files\QuickTime
2009-09-21 15:53 . 2008-08-05 11:37 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Skype
2009-09-21 13:52 . 2008-08-05 11:38 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\skypePM
2009-09-21 06:41 . 2008-07-07 07:35 206320 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-09-21 04:37 . 2009-09-21 04:37 34308 ----a-w- c:\documents and settings\All Users\Application Data\mazuki.dll
2009-09-20 10:00 . 2008-12-22 00:52 -------- d-----w- c:\program files\Norton Security Scan
2009-09-20 04:30 . 2008-07-02 05:43 61848 ----a-w- c:\documents and settings\ARTIT.AOWUDOMSUK\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-20 04:28 . 2008-06-10 08:04 61848 ----a-w- c:\documents and settings\NetworkService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-15 12:21 . 2009-08-19 11:44 -------- d-----w- c:\program files\PPStream
2009-09-10 15:17 . 2009-08-19 11:41 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\ppstream
2009-09-02 10:13 . 2008-07-03 03:18 -------- d-----w- c:\program files\Opera
2009-08-21 03:18 . 2009-08-21 03:18 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-21 03:17 . 2009-08-21 03:17 -------- d-----w- c:\program files\Apple Software Update
2009-08-20 14:58 . 2009-08-20 14:06 -------- d-----w- c:\program files\RaySource
2009-08-20 14:07 . 2009-08-20 14:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Grid
2009-08-20 14:06 . 2009-08-20 14:06 -------- d-----w- c:\program files\GridService
2009-08-19 11:41 . 2009-08-19 11:41 -------- d-----w- c:\program files\PPS
2009-08-17 09:38 . 2009-01-15 02:31 -------- d-----w- c:\program files\NeoMAP
2009-08-10 04:44 . 2009-08-10 04:44 -------- d-----w- c:\program files\Common Files\NSV
2009-08-08 07:03 . 2009-08-08 07:03 -------- d-----w- c:\program files\Plugins
2009-08-08 06:55 . 2009-08-08 06:12 -------- d-----w- c:\program files\Winamp
2009-08-08 06:24 . 2009-08-08 06:12 -------- d-----w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Winamp
2009-08-08 06:14 . 2009-08-08 06:14 -------- d-----w- c:\program files\Winamp Toolbar
2009-08-08 06:14 . 2009-08-08 06:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Winamp Toolbar
2009-08-06 01:20 . 2008-06-10 07:48 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-06 01:20 . 2008-10-24 06:59 -------- d-----w- c:\program files\SAS
2009-08-06 01:20 . 2008-06-10 07:46 -------- d-----w- c:\program files\Java
2009-08-02 10:24 . 2009-08-02 10:24 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-17 14:41 . 2009-07-17 14:41 139 ----a-w- c:\documents and settings\ARTIT.AOWUDOMSUK\Local Settings\Application Data\fusioncache.dat
2007-10-09 15:58 . 2008-07-15 01:35 139264 ----a-w- c:\program files\CPE17AntiAutorun1310.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-09-27_07.34.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-27 10:59 . 2009-09-27 10:59 16384 c:\windows\Temp\Perflib_Perfdata_250.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox\bin\DropboxExt.3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox\bin\DropboxExt.3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-06-27 03:02 77824 ----a-w- c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox\bin\DropboxExt.3.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StrokeIt"="c:\program files\Strokeit\strokeit.exe" [2005-02-17 21504]
"PPS Accelerator"="c:\program files\PPStream\ppsap.exe" [2009-07-22 210312]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-15 1998576]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-18 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-18 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-18 138008]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-22 136600]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2008-08-20 1368064]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-08 305440]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

c:\documents and settings\ARTIT.AOWUDOMSUK\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Dropbox.lnk - c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox\bin\Dropbox.exe [2009-8-28 26784939]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-6-10 50688]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!saswinlogon]
2009-09-03 07:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gemsafe]
2006-11-16 07:20 73728 ----a-w- c:\program files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^ARTIT.AOWUDOMSUK^Start Menu^Programs^Startup^1-2-Remote Server.lnk]
path=c:\documents and settings\ARTIT.AOWUDOMSUK\Start Menu\Programs\Startup\1-2-Remote Server.lnk
backup=c:\windows\pss\1-2-Remote Server.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^ARTIT.AOWUDOMSUK^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\documents and settings\ARTIT.AOWUDOMSUK\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^ARTIT.AOWUDOMSUK^Start Menu^Programs^Startup^Multiply AutoUploader.lnk]
path=c:\documents and settings\ARTIT.AOWUDOMSUK\Start Menu\Programs\Startup\Multiply AutoUploader.lnk
backup=c:\windows\pss\Multiply AutoUploader.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^ARTIT.AOWUDOMSUK^Start Menu^Programs^Startup^Pc-to-Phone.lnk]
path=c:\documents and settings\ARTIT.AOWUDOMSUK\Start Menu\Programs\Startup\Pc-to-Phone.lnk
backup=c:\windows\pss\Pc-to-Phone.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^ARTIT.AOWUDOMSUK^Start Menu^Programs^Startup^SolidWorks Task Scheduler Engine.lnk]
path=c:\documents and settings\ARTIT.AOWUDOMSUK\Start Menu\Programs\Startup\SolidWorks Task Scheduler Engine.lnk
backup=c:\windows\pss\SolidWorks Task Scheduler Engine.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Symantec AntiVirus"=2 (0x2)
"SPBBCSvc"=3 (0x3)
"SNDSrvc"=3 (0x3)
"DefWatch"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccEvtMgr"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Ateksoft\\WebCamera Plus\\WebCamPlusSrv.exe"=
"c:\\Program Files\\Ateksoft\\WebCamera Plus\\camviewer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Symantec AntiVirus\\VPC32.exe"=
"c:\\WINDOWS\\system32\\logon.scr"=
"c:\\WINDOWS\\system32\\WgaTray.exe"=
"c:\\Program Files\\Ahead\\Nero StartSmart\\NeroStartSmart.exe"=
"c:\\Program Files\\Ahead\\Nero\\nero.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\OUTLOOK.EXE"=
"c:\\Program Files\\Mobile Broadband Modem\\Mobile Broadband Modem.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\WINDOWS\\system32\\igfxpers.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\jusched.exe"=
"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
"c:\\Program Files\\Unlocker\\UnlockerAssistant.exe"=
"c:\\Program Files\\Dell\\QuickSet\\Quickset.exe"=
"c:\\Program Files\\Strokeit\\strokeit.exe"=
"c:\\WINDOWS\\system32\\igfxsrvc.exe"=
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ENABLE
"c:\\Program Files\\DAP\\DAP.EXE"=
"c:\\Program Files\\Digital Line Detect\\DLG.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ENABLE
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Program Files\\Babylon\\Babylon-Pro\\Babylon.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\WINDOWS\\system32\\sndvol32.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\K-Lite Codec Pack\\Media Player Classic\\mplayerc.exe"=
"c:\\Program Files\\K-Lite Codec Pack\\Filters\\divxsm.exe"=
"c:\\Documents and Settings\\ARTIT.AOWUDOMSUK\\Desktop\\Download\\ppstreamsetup.exe"=
"c:\\Program Files\\PPStream\\PPStream.exe"=
"c:\\Program Files\\PPStream\\PPSAP.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"18671:TCP"= 18671:TCP:BitComet 18671 TCP
"18671:UDP"= 18671:UDP:BitComet 18671 UDP

R1 sasdifsv;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 saskutil;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 antivirschedulerservice;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/26/2009 3:53 PM 108289]
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [12/19/2006 2:21 PM 79432]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 Remote Solver for COSMOSFloWorks 2007;Remote Solver for COSMOSFloWorks 2007;c:\program files\SolidWorks (3)\COSMOSFloWorks\FloWorks\binCFW\StandAloneSlv.exe [7/23/2007 9:05 AM 675840]
R2 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [3/14/2007 7:48 PM 116416]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [8/11/2004 5:00 PM 5120]
R2 Webcamera Plus Service;Webcamera Plus Service;c:\program files\Ateksoft\WebCamera Plus\WebCamPlusSrv.exe [8/7/2008 8:48 PM 46592]
R3 AteksoftAudio;WebCamera Plus Audio;c:\windows\system32\drivers\ateksoftaudio.sys [8/7/2008 8:48 PM 11776]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [12/20/2008 9:05 PM 33792]
R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [11/2/2006 12:32 PM 97536]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/28/2009 8:56 AM 102448]
R3 sasenum;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [11/8/2008 3:38 AM 25824]
.
Contents of the 'Scheduled Tasks' folder

2009-09-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 04:34]

2009-09-20 c:\windows\Tasks\Norton Security Scan for Artit.Aowudomsuk.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-18 20:18]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = hxxp://www1.ap.dell.com/content/default.aspx?c=sg&l=en&s=gen
uInternet Connection Wizard,ShellNext = hxxp://www1.ap.dell.com/content/default.aspx?c=sg&l=en&s=gen
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Mozilla\Firefox\Profiles\z2wvciu9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sg/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJinit13121.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-27 21:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(916)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'lsass.exe'(972)
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll

- - - - - - - > 'explorer.exe'(3768)
c:\documents and settings\ARTIT.AOWUDOMSUK\Application Data\Dropbox\bin\DropboxExt.3.dll
c:\program files\Strokeit\mhook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\program files\Common Files\Roxio Shared\9.0\DLLShared\DLAAPI_W.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\igfxsrvc.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\windows\system32\scardsvr.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\windows\system32\hasplms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\windows\system32\stacsv.exe
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
c:\program files\RealVNC\VNC4\winvnc4.exe
c:\program files\Intel\WiFi\bin\WLKEEPER.exe
c:\windows\system32\CCM\clicomp\RemCtrl\Wuser32.exe
c:\windows\system32\CCM\CcmExec.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-09-27 22:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-27 14:07
ComboFix2.txt 2009-09-27 07:43

Pre-Run: 22,429,573,120 bytes free
Post-Run: 22,407,004,160 bytes free

327 --- E O F --- 2009-07-13 10:33






CKScan Log

CKScanner - Additional Security Risks - These are not necessarily bad
c:\bit\backup_platinum_4_crack(latest)_[_kentuckykiid_].4834431.tpb.torrent
c:\bit\mediamonkey_gold_v3.1.2.1266___keygen_serials.5087046.tpb.torrent
c:\bit\real_vnc_enterprise_edition_working_keygen_by.oriks.4429602.tpb.torrent
c:\bit\srs_audio_sandbox___crack_(amazing_audio_immersion_for_personali.3753797.tp
b.torrent
c:\bit\anonymity4proxy v2.8\anonymity.4.proxy.v2.8.cracked-distinct.zip
c:\bit\anonymity4proxy v2.8\anonymity.4.proxy.v2.8.cracked-distinct\anonymity.4.proxy.v2.8.cracked-distinct\a4proxy.exe
c:\bit\anonymity4proxy v2.8\anonymity.4.proxy.v2.8.cracked-distinct\anonymity.4.proxy.v2.8.cracked-distinct\distinct.nfo
c:\bit\anonymity4proxy v2.8\anonymity.4.proxy.v2.8.cracked-distinct\anonymity.4.proxy.v2.8.cracked-distinct\file_id.diz
c:\bit\backup platinum 4 [ kentuckykiid ]\crack\bp.exe
c:\bit\mediamonkey gold v3.1.2.1266 + keygen+serials\mediamonkey gold v3.1.2.1266 + keygen-seh.rar
c:\bit\mediamonkey gold v3.1.2.1266 + keygen+serials\mediamonkey_3.1.2.1266.exe
c:\bit\mediamonkey gold v3.1.2.1266 + keygen+serials\mediamonkey_languagepack.exe
c:\bit\mediamonkey gold v3.1.2.1266 + keygen+serials\serials.txt
c:\bit\mediamonkey gold v3.1.2.1266 + keygen+serials\keygen\mediamonkey.gold.v3.x.keygen-under.seh.team.exe
c:\bit\real vnc enterprise edition+working keygen by.oriks\keygen.exe
c:\bit\real vnc enterprise edition+working keygen by.oriks\vnc-e4_4_2-x86_x64_win32.exe
c:\documents and settings\artit.aowudomsuk\desktop\dropbox\my dropbox\public\real vnc enterprise edition+working keygen by.oriks\keygen.exe
c:\documents and settings\artit.aowudomsuk\desktop\dropbox\my dropbox\public\real vnc enterprise edition+working keygen by.oriks\vnc-e4_4_2-x86_x64_win32.exe
c:\program files\agile product collaboration\tools\keygen.dll
c:\program files\bitcomet\torrents\mediamonkey gold v3.1.2.1266 + keygen+serials.torrent
c:\program files\bitcomet\torrents\mediamonkey gold v3.1.2.1266 + keygen+serials.xml
scanner sequence 3.ZZ.11
----- EOF -----






MBAM Log

Malwarebytes' Anti-Malware 1.41
Database version: 2865
Windows 5.1.2600 Service Pack 2

9/27/2009 10:27:58 PM
mbam-log-2009-09-27 (22-27-58).txt

Scan type: Quick Scan
Objects scanned: 134254
Time elapsed: 4 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




Kaspersky report

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Monday, September 28, 2009
Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, September 27, 2009 16:01:59
Records in database: 2927771
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
F:\

Scan statistics:
Objects scanned: 130994
Threats found: 2
Infected objects found: 11
Suspicious objects found: 0
Scan duration: 03:39:00


File name / Threat / Threats count
C:\Program Files\RealVNC\VNC4\WinVNC4.exe/C:\Program Files\RealVNC\VNC4\WinVNC4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 1
C:\Documents and Settings\ARTIT.AOWUDOMSUK\Desktop\Download\vnc-4_1_3-x86_win32.zip Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 2
C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 1
C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_15208973_.sys.zip Infected: Backdoor.Win32.NewRest.hx 2
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_32963cb3_.sys.zip Infected: Backdoor.Win32.NewRest.hx 2
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP383\A0133947.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 2

Selected area has been scanned.

#6 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,060 posts
  • MVP

Posted 27 September 2009 - 05:39 PM

Hi,

The items found by Kaspersky are either in quarantine, old system restore points or not a concern. We will be cleaning up the quarantine and old system restore points shortly.

There are a number of cracks and torrent downloads on your system, no doubt this is the source of your infection.
I strongly suggest you delete those files and refrain from using torrents and p2p software.

The reat of your logs are clean.

Please do the following:

Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT



Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Scroll down to the Java SE Runtime Environment (JRE) option.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer.(version 6, update 16)


NEXT

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

Posted Image


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

If there are remaining logs/tools after using this tool > right click and delete them.

Keep MalwareBytes, update and use it regularly.

NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security--What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#7 eak500

eak500

    New Member

  • Authentic Member
  • Pip
  • 5 posts

Posted 28 September 2009 - 09:15 AM

i have done all your recommendation. Thank you very much Catbyte.

#8 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,060 posts
  • MVP

Posted 28 September 2009 - 09:40 AM

You are more than welcome stay safe :wavey: ~CB

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#9 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,060 posts
  • MVP

Posted 28 September 2009 - 09:40 AM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users