Edited by Muzammil, 17 October 2009 - 10:40 AM.
[Resolved] Strange Folders
#1
Posted 15 October 2009 - 11:52 PM
Register to Remove
#2
Posted 19 October 2009 - 10:23 PM
My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
- I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
- The fixes are specific to your problem and should only be used for the issues on this machine.
- Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
- It's often worth reading through these instructions and printing them for ease of reference.
- If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
- Please reply to this thread. Do not start a new topic.
Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
------------------------------------------------------------
Microsoft MVP 2010-2014
#3
Posted 20 October 2009 - 12:32 AM
#4
Posted 20 October 2009 - 07:34 AM
Well... it wasn't what I thought it might be. Let's try this:
Download ComboFix from one of these locations:
Link 1
Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link --> http://forums.whatth...ams_t96260.html
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
------------------------------------------------------------
Microsoft MVP 2010-2014
#5
Posted 20 October 2009 - 09:19 AM
Heres the requested log:
ComboFix 09-10-19.02 - Administrator 10/20/2009 5:09.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3323.2766 [GMT -7:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\28cb16e.msi
c:\windows\system32\autorun.ini
c:\windows\system32\Data
c:\windows\system32\setting.ini
.
((((((((((((((((((((((((( Files Created from 2009-09-20 to 2009-10-20 )))))))))))))))))))))))))))))))
.
2009-10-19 15:02 . 2009-10-19 15:02 -------- d-----w- c:\program files\MSECache
2009-10-19 14:05 . 2009-10-19 14:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-19 14:05 . 2009-09-10 21:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-19 14:05 . 2009-10-19 14:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-19 14:05 . 2009-10-19 14:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-19 14:05 . 2009-09-10 21:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-19 10:49 . 2009-10-19 10:54 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-10-19 10:47 . 2009-10-19 10:47 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-18 11:08 . 2009-10-18 11:08 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-18 11:01 . 2009-10-18 11:01 -------- d-----w- c:\windows\system32\scripting
2009-10-18 11:01 . 2009-10-18 11:01 -------- d-----w- c:\windows\system32\en
2009-10-18 11:01 . 2009-10-18 11:01 -------- d-----w- c:\windows\l2schemas
2009-10-18 11:01 . 2009-10-18 11:01 -------- d-----w- c:\windows\system32\bits
2009-10-17 16:32 . 2007-04-12 21:19 129024 ----a-w- c:\windows\system32\AVERM.dll
2009-10-17 16:13 . 2009-10-19 14:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-17 16:13 . 2009-10-19 14:03 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-17 14:50 . 2008-04-14 00:12 20992 ------w- c:\windows\system32\spupdwxp.exe
2009-10-17 14:49 . 2008-04-14 00:11 37376 ------w- c:\windows\system32\l2gpstore.dll
2009-10-17 13:38 . 2009-10-17 13:38 -------- d-----w- c:\program files\mkv2vob
2009-10-17 13:38 . 2009-10-17 13:38 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-17 13:36 . 2009-10-17 13:38 -------- d-----w- c:\documents and settings\All Users\Application Data\OrbNetworks
2009-10-17 13:36 . 2009-10-17 13:36 -------- d-----w- c:\program files\Orb Networks
2009-10-15 15:02 . 2009-10-15 15:02 -------- d--h--w- c:\windows\PIF
2009-10-15 15:01 . 2009-10-15 15:01 -------- d-----w- c:\program files\ERUNT
2009-10-15 14:57 . 2009-10-16 06:53 -------- d-----w- C:\$AVG
2009-10-15 14:57 . 2009-10-20 03:23 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-10-15 14:57 . 2009-10-15 14:57 -------- d-----w- c:\program files\AVG
2009-10-15 14:56 . 2009-10-15 16:02 -------- d-----w- c:\windows\SxsCaPendDel
2009-10-15 14:46 . 2008-11-06 09:03 -------- d-----w- C:\SDFix
2009-10-15 12:12 . 2004-08-04 07:56 159232 ----a-w- c:\windows\system32\ptpusd.dll
2009-10-15 12:12 . 2001-08-18 05:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-10-15 12:12 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-10-15 11:44 . 2009-10-15 12:06 -------- d-----w- c:\documents and settings\Administrator\Application Data\Apple Computer
2009-10-15 11:44 . 2009-05-18 21:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-10-15 11:44 . 2008-04-17 20:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-10-15 11:44 . 2009-10-15 11:44 -------- d-----w- c:\program files\iPod
2009-10-15 11:44 . 2009-10-15 11:44 -------- d-----w- c:\program files\iTunes
2009-10-15 11:44 . 2009-10-15 11:44 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-15 11:43 . 2009-10-15 11:43 -------- d-----w- c:\program files\Bonjour
2009-10-15 11:43 . 2009-10-15 11:43 -------- d-----w- c:\program files\QuickTime
2009-10-15 11:43 . 2009-10-15 11:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-10-15 11:43 . 2009-10-15 11:43 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple
2009-10-15 11:43 . 2009-10-15 11:43 -------- d-----w- c:\program files\Apple Software Update
2009-10-15 11:42 . 2009-10-15 11:44 -------- d-----w- c:\program files\Common Files\Apple
2009-10-15 11:42 . 2009-10-15 11:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-10-15 09:51 . 2009-10-15 09:53 -------- dc----w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-10-15 09:51 . 2009-10-16 04:18 -------- d-----w- c:\documents and settings\Administrator\Application Data\uniblue
2009-10-15 09:47 . 2009-10-15 09:53 -------- d-----w- c:\program files\Uniblue
2009-10-15 09:46 . 2009-10-15 09:47 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2009-10-15 04:15 . 2009-10-15 04:25 -------- d-----w- c:\documents and settings\Administrator\Phone Browser
2009-10-15 04:11 . 2009-10-15 04:11 -------- d-----w- c:\windows\Downloaded Installations
2009-10-14 17:01 . 2009-10-14 17:01 -------- d-----w- c:\documents and settings\Administrator\Application Data\Samsung
2009-10-14 17:00 . 2006-05-04 05:53 174592 ----a-w- c:\windows\system32\framedyn.dll
2009-10-14 17:00 . 2009-10-14 17:00 -------- d-----w- c:\windows\system32\Samsung_USB_Drivers
2009-10-14 17:00 . 2009-10-14 17:36 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-10-14 16:59 . 2009-10-14 16:59 -------- d-----w- c:\program files\Samsung
2009-10-14 14:49 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2009-10-14 14:48 . 2009-10-14 14:48 -------- d-----w- C:\divx
2009-10-14 14:44 . 2009-10-14 14:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\DivX
2009-10-14 09:52 . 2009-10-15 12:07 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2009-10-13 08:10 . 2009-10-13 08:10 -------- d-----w- c:\windows\Sun
2009-10-13 03:07 . 2008-10-16 21:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-10-13 03:07 . 2008-10-16 21:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-10-12 15:06 . 2009-10-12 15:06 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ESET
2009-10-12 12:33 . 2009-10-17 15:59 -------- d-----w- c:\documents and settings\Administrator\Tracing
2009-10-12 12:19 . 2009-10-12 12:19 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-10-12 12:19 . 2009-08-06 05:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-10-12 12:18 . 2009-10-12 12:18 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-10-12 12:17 . 2009-10-12 12:19 -------- d-----w- c:\program files\Microsoft
2009-10-12 12:17 . 2009-10-12 12:17 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-12 12:17 . 2009-10-12 12:19 -------- d-----w- c:\program files\Windows Live
2009-10-12 12:10 . 2009-10-12 12:10 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-12 10:22 . 2009-10-12 10:22 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Identities
2009-10-12 09:33 . 2009-10-12 09:33 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-10-12 09:29 . 2009-10-12 09:29 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-10-12 09:28 . 2009-10-12 09:28 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-10-12 09:26 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-10-12 09:26 . 2009-10-12 09:26 -------- d-----w- c:\windows\ie8updates
2009-10-12 09:26 . 2009-08-29 08:08 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-10-12 09:26 . 2009-08-29 08:08 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-10-12 09:26 . 2009-08-29 08:08 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-10-12 09:26 . 2009-08-29 08:08 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-10-12 09:26 . 2009-08-29 08:08 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-10-12 09:26 . 2009-08-29 08:08 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-10-12 09:25 . 2009-10-12 09:26 -------- dc-h--w- c:\windows\ie8
2009-10-12 08:12 . 2009-10-12 08:12 -------- d-----w- c:\documents and settings\Administrator\Contacts
2009-10-12 02:31 . 2008-04-14 00:12 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-10-12 02:30 . 2009-10-18 10:59 -------- d-----w- c:\windows\ServicePackFiles
2009-10-11 20:18 . 2009-10-11 20:18 -------- d-----w- c:\windows\system32\LogFiles
2009-10-11 18:26 . 2009-10-11 18:26 -------- d-----w- c:\windows\Performance
2009-10-11 18:24 . 2009-10-11 18:24 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft Corporation
2009-10-11 18:24 . 2009-10-11 18:24 -------- d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-10-11 17:49 . 2009-10-11 17:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-10-11 16:43 . 2009-10-11 16:43 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-11 16:43 . 2009-10-11 16:54 -------- d-----w- c:\program files\Java
2009-10-11 16:40 . 2009-10-11 16:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2009-10-11 16:34 . 2008-04-13 18:45 26112 ----a-w- c:\windows\system32\drivers\usbser.sys
2009-10-11 16:32 . 2008-03-21 20:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-10-11 16:32 . 2009-10-12 07:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nokia
2009-10-11 16:32 . 2009-10-11 16:34 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Suite
2009-10-11 16:32 . 2009-10-11 16:32 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-10-11 16:31 . 2009-10-17 14:52 -------- d-----w- c:\program files\Common Files\Nokia
2009-10-11 16:31 . 2009-10-11 16:31 -------- d-----w- c:\program files\DIFX
2009-10-11 16:31 . 2008-08-26 17:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-10-11 16:31 . 2009-10-11 16:31 -------- d-----w- c:\program files\PC Connectivity Solution
2009-10-11 16:31 . 2009-02-09 15:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-10-11 16:31 . 2009-02-09 15:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-10-11 16:31 . 2009-02-09 15:37 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2009-10-11 16:31 . 2009-02-09 15:37 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-10-11 16:31 . 2009-02-09 15:37 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2009-10-11 16:31 . 2009-02-09 15:32 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2009-10-11 16:31 . 2009-02-09 15:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-10-11 16:31 . 2009-10-17 14:52 -------- d-----w- c:\program files\Nokia
2009-10-11 16:30 . 2009-10-11 16:30 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Yahoo!
2009-10-11 16:30 . 2009-10-11 16:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-10-11 16:17 . 2009-10-11 16:44 -------- d-----w- c:\program files\PS3 Media Server
2009-10-11 11:39 . 2009-10-20 12:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\BitTorrent
2009-10-11 11:39 . 2009-10-11 11:39 -------- d-----w- c:\program files\BitTorrent
2009-10-11 11:35 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-10-11 11:35 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-10-11 11:35 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-10-11 11:35 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-10-11 11:35 . 2009-06-25 08:25 730112 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-10-11 11:35 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-10-11 11:35 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-20 12:05 . 2006-01-01 12:35 23104 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-20 10:58 . 2009-01-11 08:36 -------- d-----w- c:\documents and settings\Administrator\Application Data\DMCache
2009-10-15 14:42 . 2009-10-14 14:43 -------- d-----w- c:\program files\DivX
2009-10-15 04:11 . 2006-01-01 12:37 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-15 04:07 . 2009-01-11 08:36 -------- d-----w- c:\program files\Internet Download Manager
2009-10-14 16:59 . 2006-01-01 12:37 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-14 14:49 . 2006-01-01 13:44 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-10-14 14:43 . 2009-10-14 14:43 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-10-11 16:32 . 2009-10-11 16:32 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-10-11 16:32 . 2009-10-11 16:32 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-09-11 14:18 . 2004-08-04 00:56 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 10:43 . 2009-09-16 12:26 210352 ----a-w- c:\windows\system32\idmmbc.dll
2009-09-04 21:03 . 2004-08-04 00:56 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-04 00:56 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-04 00:56 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-05 09:01 . 2004-08-04 00:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 02:52 . 2009-08-05 02:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 15:13 . 2004-08-03 23:18 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-07-29 04:37 . 2004-08-04 00:56 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2001-08-23 14:00 81920 ------w- c:\windows\system32\fontsub.dll
2009-07-26 23:44 . 2009-07-26 23:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2006-01-01 133104]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-06-23 2815408]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [2009-09-29 653104]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-10-27 3810544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Orb"="c:\program files\Orb Networks\Orb\bin\OrbLauncher.exe" [2009-10-07 573904]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbLauncher.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbSetupWizard.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbControlPanel.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [10/12/2009 5:19 AM 54752]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
.
Contents of the 'Scheduled Tasks' folder
2009-10-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-926492609-839522115-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2006-01-01 08:30]
2009-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-926492609-839522115-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2006-01-01 08:30]
2009-10-20 c:\windows\Tasks\Orb Index when idle.job
- c:\program files\Orb Networks\Orb\bin\OrbLauncher.exe [2009-10-07 23:28]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-20 05:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2000478354-926492609-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ae,a3,cb,9a,71,4c,5f,47,ba,8a,8d,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ae,a3,cb,9a,71,4c,5f,47,ba,8a,8d,\
[HKEY_USERS\S-1-5-21-2000478354-926492609-839522115-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4ecc83b9-93db-4aaf-95d2-af736c279e2a}]
@Denied: (Full) (Everyone)
"Model"=dword:00000124
"Therad"=dword:00000006
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d,
df,1c,2f,3b,8a,0a,32,11,89,01,b5,56,bb,60,ad,54,bf,3a,b3,02,c8,41,36,1e,0a,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):6c,fa,78,84,d5,d0,d5,d6,92,34,73,62,aa,3e,84,0d,6a,07,cb,2e,65,
4a,9b,de,49,66,db,6d,bc,aa,14,dc,f8,63,28,2b,55,19,e0,65,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):19,af,34,41,68,c1,93,a3,e4,04,04,db,c3,73,6a,2d,bf,20,fb,2b,a5,
b3,16,ca,ad,05,44,3f,62,8c,14,02,af,90,1b,94,b8,f6,9a,8a,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e2ae1475-934b-4f61-b0d3-ec7a9d64f9dd}]
@Denied: (Full) (Everyone)
"Model"=dword:0000011e
"Therad"=dword:0000002b
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,51,c4,5c,06,a5,56,2b,b8,a5,dc,ce,c4,12,ad,eb,5f,83,e0,8b,c5,07,bb,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(528)
c:\windows\system32\Ati2evxx.dll
.
Completion time: ~,10time:~,-3
ComboFix-quarantined-files.txt 2009-10-20 12:11
Pre-Run: 71,624,757,248 bytes free
Post-Run: 71,783,723,008 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - CEE03CAFF787EA1AAEB0FF9B991071B0
#6
Posted 20 October 2009 - 10:25 AM
COMBOFIX-Script
- Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
REGLOCKDEL:: [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}] [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4ecc83b9-93db-4aaf-95d2-af736c279e2a}] [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e2ae1475-934b-4f61-b0d3-ec7a9d64f9dd}] Reglock:: [HKEY_USERS\S-1-5-21-2000478354-926492609-839522115-500\Software\Microsoft\Internet Explorer\User Preferences] Registry:: [HKEY_USERS\S-1-5-21-2000478354-926492609-839522115-500\Software\Microsoft\Internet Explorer\User Preferences] "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=-
- Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
------------------------------------------------------------
Microsoft MVP 2010-2014
#7
Posted 20 October 2009 - 10:46 AM
During the execution of that script it asked me to update the CF or not so I clicked yes i hope that doesn't cause any problems in the outcome !
Here is the log:
ComboFix 09-10-19.04 - Administrator 10/20/2009 6:35.3.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3323.2781 [GMT -7:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
.
((((((((((((((((((((((((( Files Created from 2009-09-20 to 2009-10-20 )))))))))))))))))))))))))))))))
.
2009-10-19 15:02 . 2009-10-19 15:02 -------- d-----w- c:\program files\MSECache
2009-10-19 14:05 . 2009-10-19 14:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-19 14:05 . 2009-09-10 21:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-19 14:05 . 2009-10-19 14:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-19 14:05 . 2009-10-19 14:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-19 14:05 . 2009-09-10 21:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-19 10:49 . 2009-10-19 10:54 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-10-19 10:47 . 2009-10-19 10:47 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-18 11:08 . 2009-10-18 11:08 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-18 11:01 . 2009-10-18 11:01 -------- d-----w- c:\windows\system32\scripting
2009-10-18 11:01 . 2009-10-18 11:01 -------- d-----w- c:\windows\system32\en
2009-10-18 11:01 . 2009-10-18 11:01 -------- d-----w- c:\windows\l2schemas
2009-10-18 11:01 . 2009-10-18 11:01 -------- d-----w- c:\windows\system32\bits
2009-10-17 16:32 . 2007-04-12 21:19 129024 ----a-w- c:\windows\system32\AVERM.dll
2009-10-17 16:13 . 2009-10-19 14:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-17 16:13 . 2009-10-19 14:03 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-17 14:50 . 2008-04-14 00:12 20992 ------w- c:\windows\system32\spupdwxp.exe
2009-10-17 14:49 . 2008-04-14 00:11 37376 ------w- c:\windows\system32\l2gpstore.dll
2009-10-17 13:38 . 2009-10-17 13:38 -------- d-----w- c:\program files\mkv2vob
2009-10-17 13:38 . 2009-10-17 13:38 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-17 13:36 . 2009-10-17 13:38 -------- d-----w- c:\documents and settings\All Users\Application Data\OrbNetworks
2009-10-17 13:36 . 2009-10-17 13:36 -------- d-----w- c:\program files\Orb Networks
2009-10-15 15:02 . 2009-10-15 15:02 -------- d--h--w- c:\windows\PIF
2009-10-15 15:01 . 2009-10-15 15:01 -------- d-----w- c:\program files\ERUNT
2009-10-15 14:57 . 2009-10-16 06:53 -------- d-----w- C:\$AVG
2009-10-15 14:57 . 2009-10-20 03:23 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-10-15 14:57 . 2009-10-15 14:57 -------- d-----w- c:\program files\AVG
2009-10-15 14:56 . 2009-10-15 16:02 -------- d-----w- c:\windows\SxsCaPendDel
2009-10-15 14:46 . 2008-11-06 09:03 -------- d-----w- C:\SDFix
2009-10-15 12:12 . 2004-08-04 07:56 159232 ----a-w- c:\windows\system32\ptpusd.dll
2009-10-15 12:12 . 2001-08-18 05:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-10-15 12:12 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-10-15 11:44 . 2009-10-15 12:06 -------- d-----w- c:\documents and settings\Administrator\Application Data\Apple Computer
2009-10-15 11:44 . 2009-05-18 21:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-10-15 11:44 . 2008-04-17 20:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-10-15 11:44 . 2009-10-15 11:44 -------- d-----w- c:\program files\iPod
2009-10-15 11:44 . 2009-10-15 11:44 -------- d-----w- c:\program files\iTunes
2009-10-15 11:44 . 2009-10-15 11:44 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-15 11:43 . 2009-10-15 11:43 -------- d-----w- c:\program files\Bonjour
2009-10-15 11:43 . 2009-10-15 11:43 -------- d-----w- c:\program files\QuickTime
2009-10-15 11:43 . 2009-10-15 11:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-10-15 11:43 . 2009-10-15 11:43 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple
2009-10-15 11:43 . 2009-10-15 11:43 -------- d-----w- c:\program files\Apple Software Update
2009-10-15 11:42 . 2009-10-15 11:44 -------- d-----w- c:\program files\Common Files\Apple
2009-10-15 11:42 . 2009-10-15 11:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-10-15 09:51 . 2009-10-15 09:53 -------- dc----w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-10-15 09:51 . 2009-10-16 04:18 -------- d-----w- c:\documents and settings\Administrator\Application Data\uniblue
2009-10-15 09:47 . 2009-10-15 09:53 -------- d-----w- c:\program files\Uniblue
2009-10-15 09:46 . 2009-10-15 09:47 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2009-10-15 04:15 . 2009-10-15 04:25 -------- d-----w- c:\documents and settings\Administrator\Phone Browser
2009-10-15 04:11 . 2009-10-15 04:11 -------- d-----w- c:\windows\Downloaded Installations
2009-10-14 17:01 . 2009-10-14 17:01 -------- d-----w- c:\documents and settings\Administrator\Application Data\Samsung
2009-10-14 17:00 . 2006-05-04 05:53 174592 ----a-w- c:\windows\system32\framedyn.dll
2009-10-14 17:00 . 2009-10-14 17:00 -------- d-----w- c:\windows\system32\Samsung_USB_Drivers
2009-10-14 17:00 . 2009-10-14 17:36 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-10-14 16:59 . 2009-10-14 16:59 -------- d-----w- c:\program files\Samsung
2009-10-14 14:49 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2009-10-14 14:48 . 2009-10-14 14:48 -------- d-----w- C:\divx
2009-10-14 14:44 . 2009-10-14 14:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\DivX
2009-10-14 09:52 . 2009-10-15 12:07 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2009-10-13 08:10 . 2009-10-13 08:10 -------- d-----w- c:\windows\Sun
2009-10-13 03:07 . 2008-10-16 21:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-10-13 03:07 . 2008-10-16 21:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-10-12 15:06 . 2009-10-12 15:06 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ESET
2009-10-12 12:33 . 2009-10-17 15:59 -------- d-----w- c:\documents and settings\Administrator\Tracing
2009-10-12 12:19 . 2009-10-12 12:19 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-10-12 12:19 . 2009-08-06 05:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-10-12 12:18 . 2009-10-12 12:18 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-10-12 12:17 . 2009-10-12 12:19 -------- d-----w- c:\program files\Microsoft
2009-10-12 12:17 . 2009-10-12 12:17 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-12 12:17 . 2009-10-12 12:19 -------- d-----w- c:\program files\Windows Live
2009-10-12 12:10 . 2009-10-12 12:10 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-12 10:22 . 2009-10-12 10:22 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Identities
2009-10-12 09:33 . 2009-10-12 09:33 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-10-12 09:29 . 2009-10-12 09:29 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-10-12 09:28 . 2009-10-12 09:28 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-10-12 09:26 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-10-12 09:26 . 2009-10-12 09:26 -------- d-----w- c:\windows\ie8updates
2009-10-12 09:26 . 2009-08-29 08:08 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-10-12 09:26 . 2009-08-29 08:08 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-10-12 09:26 . 2009-08-29 08:08 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-10-12 09:26 . 2009-08-29 08:08 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-10-12 09:26 . 2009-08-29 08:08 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-10-12 09:26 . 2009-08-29 08:08 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-10-12 09:25 . 2009-10-12 09:26 -------- dc-h--w- c:\windows\ie8
2009-10-12 08:12 . 2009-10-12 08:12 -------- d-----w- c:\documents and settings\Administrator\Contacts
2009-10-12 02:31 . 2008-04-14 00:12 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-10-12 02:30 . 2009-10-18 10:59 -------- d-----w- c:\windows\ServicePackFiles
2009-10-11 20:18 . 2009-10-11 20:18 -------- d-----w- c:\windows\system32\LogFiles
2009-10-11 18:26 . 2009-10-11 18:26 -------- d-----w- c:\windows\Performance
2009-10-11 18:24 . 2009-10-11 18:24 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft Corporation
2009-10-11 18:24 . 2009-10-11 18:24 -------- d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-10-11 17:49 . 2009-10-11 17:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-10-11 16:43 . 2009-10-11 16:43 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-11 16:43 . 2009-10-11 16:54 -------- d-----w- c:\program files\Java
2009-10-11 16:40 . 2009-10-11 16:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2009-10-11 16:34 . 2008-04-13 18:45 26112 ----a-w- c:\windows\system32\drivers\usbser.sys
2009-10-11 16:32 . 2008-03-21 20:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-10-11 16:32 . 2009-10-12 07:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nokia
2009-10-11 16:32 . 2009-10-11 16:34 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Suite
2009-10-11 16:32 . 2009-10-11 16:32 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-10-11 16:31 . 2009-10-17 14:52 -------- d-----w- c:\program files\Common Files\Nokia
2009-10-11 16:31 . 2009-10-11 16:31 -------- d-----w- c:\program files\DIFX
2009-10-11 16:31 . 2008-08-26 17:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-10-11 16:31 . 2009-10-11 16:31 -------- d-----w- c:\program files\PC Connectivity Solution
2009-10-11 16:31 . 2009-02-09 15:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-10-11 16:31 . 2009-02-09 15:37 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-10-11 16:31 . 2009-02-09 15:37 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2009-10-11 16:31 . 2009-02-09 15:37 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-10-11 16:31 . 2009-02-09 15:37 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2009-10-11 16:31 . 2009-02-09 15:32 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2009-10-11 16:31 . 2009-02-09 15:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-10-11 16:31 . 2009-10-17 14:52 -------- d-----w- c:\program files\Nokia
2009-10-11 16:30 . 2009-10-11 16:30 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Yahoo!
2009-10-11 16:30 . 2009-10-11 16:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-10-11 16:17 . 2009-10-11 16:44 -------- d-----w- c:\program files\PS3 Media Server
2009-10-11 11:39 . 2009-10-20 13:18 -------- d-----w- c:\documents and settings\Administrator\Application Data\BitTorrent
2009-10-11 11:39 . 2009-10-11 11:39 -------- d-----w- c:\program files\BitTorrent
2009-10-11 11:35 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-10-11 11:35 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-10-11 11:35 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-10-11 11:35 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-10-11 11:35 . 2009-06-25 08:25 730112 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-10-11 11:35 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-10-11 11:35 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-20 13:35 . 2009-01-11 08:36 -------- d-----w- c:\documents and settings\Administrator\Application Data\DMCache
2009-10-20 12:05 . 2006-01-01 12:35 23104 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-15 14:42 . 2009-10-14 14:43 -------- d-----w- c:\program files\DivX
2009-10-15 04:11 . 2006-01-01 12:37 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-15 04:07 . 2009-01-11 08:36 -------- d-----w- c:\program files\Internet Download Manager
2009-10-14 16:59 . 2006-01-01 12:37 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-14 14:49 . 2006-01-01 13:44 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-10-14 14:43 . 2009-10-14 14:43 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-10-11 16:32 . 2009-10-11 16:32 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-10-11 16:32 . 2009-10-11 16:32 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-09-11 14:18 . 2004-08-04 00:56 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 10:43 . 2009-09-16 12:26 210352 ----a-w- c:\windows\system32\idmmbc.dll
2009-09-04 21:03 . 2004-08-04 00:56 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-04 00:56 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-04 00:56 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-05 09:01 . 2004-08-04 00:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 02:52 . 2009-08-05 02:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 15:13 . 2004-08-03 23:18 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2009-07-29 04:37 . 2004-08-04 00:56 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2001-08-23 14:00 81920 ------w- c:\windows\system32\fontsub.dll
2009-07-26 23:44 . 2009-07-26 23:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2006-01-01 133104]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-06-23 2815408]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [2009-09-29 653104]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-10-27 3810544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Orb"="c:\program files\Orb Networks\Orb\bin\OrbLauncher.exe" [2009-10-07 573904]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbLauncher.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbSetupWizard.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbControlPanel.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [10/12/2009 5:19 AM 54752]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
.
Contents of the 'Scheduled Tasks' folder
2009-10-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-926492609-839522115-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2006-01-01 08:30]
2009-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-926492609-839522115-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2006-01-01 08:30]
2009-10-20 c:\windows\Tasks\Orb Index when idle.job
- c:\program files\Orb Networks\Orb\bin\OrbLauncher.exe [2009-10-07 23:28]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-20 06:37
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\docume~1\ADMINI~1\LOCALS~1\Temp\catchme.dll 53248 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2000478354-926492609-839522115-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(528)
c:\windows\system32\sxs.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2808)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2009-10-20 6:37
ComboFix-quarantined-files.txt 2009-10-20 13:37
ComboFix2.txt 2009-10-20 12:11
Pre-Run: 71,726,948,352 bytes free
Post-Run: 71,693,758,464 bytes free
- - End Of File - - 58B2D2DA3CD88725DA3D41E2432BF3CC
#8
Posted 20 October 2009 - 10:48 AM
------------------------------------------------------------
Microsoft MVP 2010-2014
#9
Posted 20 October 2009 - 11:27 AM
#10
Posted 20 October 2009 - 11:36 AM
Please look at the ComboFix logs you provided. Specifically, look under the section:
((((((((((((((((((((((((( Files Created from 2009-09-20 to 2009-10-20 )))))))))))))))))))))))))))))))
Do you see any of the "strange folders" listed there?
If not, can you give me a few specific examples of these folders?
------------------------------------------------------------
Microsoft MVP 2010-2014
Register to Remove
#11
Posted 20 October 2009 - 11:44 AM
#12
Posted 20 October 2009 - 12:22 PM
Please download DDS by sUBs from one of the following links and save it to your desktop.
- Disable any script blocking protection (How to Disable your Security Programs)
- Double click DDS icon to run the tool (may take up to 3 minutes to run)
- When done, DDS.txt will open.
- After a few moments, attach.txt will open in a second window.
- Save both reports to your desktop.
- Post the contents of the DDS.txt report in your next reply
- Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
------------------------------------------------------------
Microsoft MVP 2010-2014
#13
Posted 20 October 2009 - 01:05 PM
Attached Files
#14
Posted 20 October 2009 - 07:04 PM
JavaRa ...by: Paul McLain and Fred de Vries
Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions...you won't have Internet access during this particular phase!
- Double-click on JavaRa.exe to start the program.
- From the drop-down menu, choose English or the appropriate language...and click on Select.
- JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
- Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
- A logfile will pop up. Please save it to a convenient location.
- Copy and paste the contents of the JavaRa log, in your next reply.
About your screen shot. Is this only happening on the E: drive or does it happen on all 4 drives?
------------------------------------------------------------
Microsoft MVP 2010-2014
#15
Posted 20 October 2009 - 11:32 PM
The folders are like that in all the drives, while searching through the web i came accross http://www.tomshardw...mbnail-pictures it might solve it
should i go for it and here is the requested log,
JavaRa 1.15 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Tue Oct 20 19:23:07 2009
Found and removed: C:\Program Files\Java\jre1.6.0_10
Found and removed: C:\Documents and Settings\Administrator\Application Data\Sun\Java\jre1.6.0_10
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
------------------------------------
Finished reporting.
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users