Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 91682 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

[Closed] Koobface/v2Captcha and comp shut down


  • This topic is locked This topic is locked
44 replies to this topic

#1 mhasan420

mhasan420

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 28 October 2009 - 10:41 PM

Hello, My Symantec antivirus says that I have Koobface and v2captcha viruses, however, is unable to remove them. I also have another problem and that is my computer just randomly shutting down every now and then esp when under heavy use. I think this latter problem is unrelated because I have been having this problem before the koobface error messages. I followed the instructions in the New Members thread and here is what I found. Root Repeal ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/10/29 09:25 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ------------------- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xAAB51000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF8B4C000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xA96B6000 Size: 49152 File Visible: No Signed: - Status: - SSDT ------------------- #: 031 Function Name: NtConnectPort Status: Hooked by "<unknown>" at address 0xe1f16c30 ==EOF== DDS (Ver_09-10-26.01) - NTFSx86 Run by Saamia Hasan at 9:10:22.26 on 29/10/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.502.207 [GMT 5:00] AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Apoint2K\Apoint.exe svchost.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\WINDOWS\system32\crypserv.exe C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\Program Files\Apoint2K\Apntex.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Documents and Settings\Saamia Hasan\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Saamia Hasan\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Saamia Hasan\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Program Files\Symantec AntiVirus\VPC32.EXE C:\Documents and Settings\Saamia Hasan\My Documents\Downloads\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com.pk/ uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q305&bd=pavilion&pf=laptop BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [Google Update] "c:\documents and settings\saamia hasan\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [PcSync] c:\program files\nokia\nokia pc suite 6\PcSync2.exe /NoDialog mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [vptray] c:\progra~1\symant~1\VPTray.exe mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [Apoint] c:\program files\apoint2k\Apoint.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [DownloadAccelerator] "c:\program files\dap\DAP.EXE" /STARTUP mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent mRun: [ClientGW] mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [PCSuiteTrayApplication] c:\program files\nokia\nokia pc suite 6\LaunchApplication.exe -onlytray mRun: [DataLayer] c:\program files\common files\pcsuite\datalayer\DataLayer.exe mRun: [sysldtray] c:\windows\ld15.exe mRun: [Captcha7] rundll "c:\program files\captcha.dll",captcha mRun: [sysfbtray] c:\windows\freddy72.exe dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm IE: &Download with &DAP - c:\program files\dap\dapextie.htm IE: Download &all with DAP - c:\program files\dap\dapextie2.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {9D614E8E-03AA-11D3-90FC-0040C7157029} - hxxp://www.pakdata.com/download/PDMSInstaller.cab DPF: {CAAE28D1-ADCC-11D1-BD4D-004845401881} - hxxp://www.pakdata.com/download/urduplugin.cab DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14_02-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} - hxxp://mail01.piac.aero/dwa7W.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\dap\dapie.dll Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\dap\dapie.dll Notify: igfxcui - igfxsrvc.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ============= SERVICES / DRIVERS =============== S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2004-8-7 169192] S3 V0090VID;Creative WebCam Vista Plus;c:\windows\system32\drivers\V0090Vid.sys [2009-8-19 138112] =============== Created Last 30 ================ 2009-10-29 01:23:58 2 ----a-w- c:\windows\0101120101465448.xxe 2009-10-29 01:23:56 1 ---h--w- c:\windows\tgm2.dat 2009-10-29 01:23:55 43776 ----a-w- c:\windows\tag14.exe 2009-10-29 01:23:54 2 ----a-w- c:\windows\0101120101465249.xxe 2009-10-29 01:23:51 2 ----a-w- c:\windows\0101120101465349.xxe 2009-10-29 01:23:48 2 ----a-w- c:\windows\0101120101465050.xxe 2009-10-29 01:23:44 2 ----a-w- c:\windows\0101120101465649.xxe 2009-10-28 18:19:03 10766 ----a-w- c:\windows\fs1235.dat 2009-10-28 04:43:04 2 ----a-w- c:\windows\0101120101465248.xxe 2009-10-28 04:43:01 55552 ------w- c:\windows\freddy72.exe 2009-10-28 04:42:57 2 ----a-w- c:\windows\0101120101465055.xxe 2009-10-26 03:41:45 0 ----a-w- c:\windows\rdr_1256528505.exe 2009-10-26 03:41:45 0 ----a-w- c:\windows\rdr_1256528504.exe 2009-10-26 03:41:44 0 ----a-w- c:\windows\rdr_1256528499.exe 2009-10-25 15:50:46 27 ----a-w- c:\windows\bk20856.dat 2009-10-25 14:31:50 17408 ------w- c:\program files\captcha.dll 2009-10-25 14:31:49 56832 ----a-w- c:\windows\freddy71.exe 2009-10-25 14:31:49 2 ----a-w- c:\windows\0101120101464955.xxe 2009-10-25 14:31:49 1 ---h--w- c:\windows\bk23567.dat 2009-10-25 14:31:46 2 ----a-w- c:\windows\010112010146116101.xxe 2009-10-25 14:31:09 40960 ------w- c:\windows\ld15.exe 2009-10-13 17:01:54 67584 ----a-w- c:\windows\un_UrduPlugin.exe 2009-10-13 17:01:54 61440 ----a-w- c:\windows\PDMSInstaller.exe 2009-10-13 17:01:54 0 d-----w- c:\program files\Pakistan Data Management Services 2009-10-04 03:09:42 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll 2009-10-04 03:09:26 0 d-----w- c:\program files\Microsoft SQL Server Compact Edition 2009-10-04 03:06:38 0 d-----w- c:\program files\Microsoft ==================== Find3M ==================== 2009-10-13 17:01:32 8180 ----a-w- c:\windows\fonts\PDMS2_MansehraQP.ttf 2009-10-13 17:01:32 18316 ----a-w- c:\windows\fonts\PDMS1_MansehraQP.ttf 2009-10-13 17:01:32 14344 ----a-w- c:\windows\fonts\PDMSSindhi_MansehraQP.ttf 2009-10-13 17:01:31 53592 ----a-w- c:\windows\fonts\PDMS_MansehraQP.ttf 2009-10-13 17:01:31 32676 ----a-w- c:\windows\fonts\PDMS1_Mansehra.ttf 2009-10-13 17:01:31 16696 ----a-w- c:\windows\fonts\PDMS2_Mansehra.ttf 2009-10-13 17:01:30 26884 ----a-w- c:\windows\fonts\PDMS1_NafeesRaqam.ttf 2009-10-13 17:01:30 11600 ----a-w- c:\windows\fonts\PDMS2_NafeesRaqam.ttf 2009-10-13 17:01:28 15704 ----a-w- c:\windows\fonts\PDMSSindhi_Mansehra.ttf 2009-10-13 17:01:27 64076 ----a-w- c:\windows\fonts\PDMS_Mansehra.ttf 2009-10-13 17:01:22 64404 ----a-w- c:\windows\fonts\PDMS_NafeesRaqam.ttf 2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll 2009-08-29 08:08:21 916480 ----a-w- c:\windows\system32\wininet.dll 2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll 2009-08-17 18:33:52 1193832 ----a-w- c:\windows\system32\FM20.DLL 2009-08-06 14:23:46 274288 ----a-w- c:\windows\system32\mucltui.dll 2009-08-06 14:23:46 215920 ----a-w- c:\windows\system32\muweb.dll 2009-08-05 09:01:48 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-08-04 15:44:46 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-08-04 14:20:08 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-07-20 10:14:52 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009072020090721\index.dat ============= FINISH: 9:11:08.81 =============== Would appreciate any help. Thanks.

Attached Files


    Advertisements

Register to Remove


#2 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 29 October 2009 - 12:24 PM

Hi,

Please do the following:

Download ComboFix from either of these locations:
Link 1
Link 2


VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#3 mhasan420

mhasan420

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 29 October 2009 - 01:18 PM

Here it is:

ComboFix 09-10-28.08 - Saamia Hasan 29/10/2009 23:54.1.1 - NTFSx86
Running from: c:\documents and settings\Saamia Hasan\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\010112010146116101.xxe
c:\windows\0101120101464955.xxe
c:\windows\0101120101465050.xxe
c:\windows\0101120101465055.xxe
c:\windows\0101120101465248.xxe
c:\windows\0101120101465249.xxe
c:\windows\0101120101465349.xxe
c:\windows\0101120101465448.xxe
c:\windows\0101120101465649.xxe
c:\windows\bk23567.dat
c:\windows\freddy71.exe
c:\windows\freddy72.exe
c:\windows\hosts
c:\windows\ld15.exe
c:\windows\rdr_1256528499.exe
c:\windows\rdr_1256528504.exe
c:\windows\rdr_1256528505.exe
c:\windows\rdr_1256841937.exe

.
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-29 )))))))))))))))))))))))))))))))
.

2009-10-29 04:04 . 2009-10-29 04:04 -------- d-----w- c:\program files\ERUNT
2009-10-29 01:23 . 2009-10-29 01:23 1 ---h--w- c:\windows\tgm2.dat
2009-10-29 01:23 . 2009-10-29 01:23 43776 ----a-w- c:\windows\tag14.exe
2009-10-28 18:19 . 2009-10-29 18:54 10766 ----a-w- c:\windows\fs1235.dat
2009-10-25 15:50 . 2009-10-28 18:17 27 ----a-w- c:\windows\bk20856.dat
2009-10-25 14:31 . 2009-10-29 18:45 17408 --sh--r- c:\program files\captcha.dll
2009-10-13 17:01 . 2009-10-13 17:01 -------- d-----w- c:\program files\Pakistan Data Management Services
2009-10-13 17:01 . 2005-10-24 09:14 67584 ----a-w- c:\windows\un_UrduPlugin.exe
2009-10-13 17:01 . 2000-01-14 06:53 61440 ----a-w- c:\windows\PDMSInstaller.exe
2009-10-04 03:10 . 2009-10-06 00:59 -------- d-----w- c:\program files\Microsoft Silverlight
2009-10-04 03:09 . 2006-11-29 08:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-10-04 03:09 . 2009-10-04 03:09 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-10-04 03:06 . 2009-10-04 03:06 -------- d-----w- c:\program files\Microsoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-29 19:00 . 2008-06-28 18:03 -------- d-----w- c:\program files\Symantec AntiVirus
2009-10-29 18:53 . 2008-07-06 11:10 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-29 17:19 . 2009-08-19 11:56 -------- d-----w- c:\documents and settings\Saamia Hasan\Application Data\Skype
2009-10-29 11:35 . 2009-08-19 12:00 -------- d-----w- c:\documents and settings\Saamia Hasan\Application Data\skypePM
2009-10-16 16:48 . 2008-08-03 11:55 112200 ----a-w- c:\documents and settings\Saamia Hasan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-14 16:34 . 2008-06-28 17:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-04 03:10 . 2009-02-17 11:54 -------- d-----w- c:\program files\Windows Live
2009-09-24 22:01 . 2009-09-24 22:01 -------- d-----w- c:\program files\MSXML 4.0
2009-09-24 13:22 . 2008-06-28 18:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-24 13:21 . 2009-09-24 13:21 -------- d-----w- c:\documents and settings\Saamia Hasan\Application Data\PC Suite
2009-09-24 13:21 . 2009-09-24 13:19 -------- d-----w- c:\program files\Nokia
2009-09-24 13:20 . 2009-09-24 13:19 -------- d-----w- c:\program files\Common Files\PCSuite
2009-09-24 13:19 . 2009-09-24 13:19 -------- d-----w- c:\program files\Common Files\Nokia
2009-09-23 05:28 . 2009-09-23 05:27 -------- d-----w- c:\program files\iPhone Configuration Utility
2009-09-15 11:09 . 2009-01-30 17:38 -------- d-----w- c:\program files\DivX
2009-09-15 11:09 . 2009-09-15 11:09 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-09-11 14:18 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-31 03:01 . 2008-06-28 19:01 -------- d-----w- c:\documents and settings\Saamia Hasan\Application Data\Apple Computer
2009-08-31 00:01 . 2008-06-28 19:00 -------- d-----w- c:\program files\iTunes
2009-08-29 08:08 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-04 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-19 12:00 . 2009-08-19 12:00 48 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-08-17 18:33 . 2009-08-17 18:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-06 14:24 . 2008-06-28 17:31 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 14:24 . 2008-06-28 17:31 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 14:24 . 2008-06-28 17:30 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 14:24 . 2007-07-30 18:19 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 14:24 . 2008-06-28 17:30 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 14:24 . 2004-08-04 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 14:23 . 2008-06-28 17:30 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 14:23 . 2009-02-18 10:15 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 14:23 . 2009-02-18 10:15 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 14:23 . 2008-06-28 17:30 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:44 . 2004-08-04 12:00 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Google Update"="c:\documents and settings\Saamia Hasan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-24 133104]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-04-20 847872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-08-06 66680]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2004-08-06 124112]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2005-02-08 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-12-13 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-12-13 126976]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-09-07 213054]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-07-06 3057152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-03-22 167936]
"DataLayer"="c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 1106944]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-08-24 88363]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Device Detector 3.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Device Detector 3.lnk
backup=c:\windows\pss\Device Detector 3.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Saamia Hasan^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Saamia Hasan\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\Saamia Hasan\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Saamia Hasan\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [07/08/2004 03:18 169192]
S3 V0090VID;Creative WebCam Vista Plus;c:\windows\system32\drivers\V0090Vid.sys [19/08/2009 16:27 138112]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - MBR
*NewlyCreated* - PCIIDEX_2
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
*Deregistered* - PCIIDEX_2
.
Contents of the 'Scheduled Tasks' folder

2009-10-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 07:34]

2009-10-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-682003330-1004Core.job
- c:\documents and settings\Saamia Hasan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-24 11:15]

2009-10-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-682003330-1004UA.job
- c:\documents and settings\Saamia Hasan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-24 11:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.pk/
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
DPF: {9D614E8E-03AA-11D3-90FC-0040C7157029} - hxxp://www.pakdata.com/download/PDMSInstaller.cab
DPF: {CAAE28D1-ADCC-11D1-BD4D-004845401881} - hxxp://www.pakdata.com/download/urduplugin.cab
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-sysfbtray - c:\windows\freddy72.exe
HKLM-Run-ClientGW - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-30 00:05
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????6?3?8?6??????? ???B???????????????B? ??????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-10-29 0:07
ComboFix-quarantined-files.txt 2009-10-29 19:07

Pre-Run: 3,507,613,696 bytes free
Post-Run: 4,384,989,184 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - C8D21FC2E2A188F8F5C8BBFCCD90DCA1

#4 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 29 October 2009 - 01:31 PM

Hi,

Please do the following:
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Koobface_v2Captcha_comp_shut_down_t107990.html&view=findpost&p=606780#entry606780

Collect::
c:\windows\tag14.exe
c:\program files\captcha.dll

File::
c:\windows\tgm2.dat
c:\windows\fs1235.dat
c:\windows\bk20856.dat

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As... Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save ...

Posted Image

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.


NEXT


Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:

1. Click Accept, when prompted to download and install the program files and database of malware definitions.


2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan

3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    Posted Image

  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#5 mhasan420

mhasan420

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 29 October 2009 - 07:37 PM

Hi,

I tried running Kaspersky online scan several times but my computer would just shut down in the middle of it. Here are the results for the other two:

ComboFix

ComboFix 09-10-28.08 - Saamia Hasan 30/10/2009 0:39.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.502.209 [GMT 5:00]
Running from: c:\documents and settings\Saamia Hasan\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Saamia Hasan\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

FILE ::
"c:\windows\bk20856.dat"
"c:\windows\fs1235.dat"
"c:\windows\tgm2.dat"

file zipped: c:\program files\captcha.dll
file zipped: c:\windows\tag14.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\captcha.dll
c:\windows\bk20856.dat
c:\windows\fs1235.dat
c:\windows\tag14.exe
c:\windows\tgm2.dat

.
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-29 )))))))))))))))))))))))))))))))
.

2009-10-29 19:39 . 2008-04-13 18:40 96512 -c--a-w- c:\windows\system32\dllcache\atapi.sys
2009-10-29 04:04 . 2009-10-29 04:04 -------- d-----w- c:\program files\ERUNT
2009-10-13 17:01 . 2009-10-13 17:01 -------- d-----w- c:\program files\Pakistan Data Management Services
2009-10-13 17:01 . 2005-10-24 09:14 67584 ----a-w- c:\windows\un_UrduPlugin.exe
2009-10-13 17:01 . 2000-01-14 06:53 61440 ----a-w- c:\windows\PDMSInstaller.exe
2009-10-04 03:10 . 2009-10-06 00:59 -------- d-----w- c:\program files\Microsoft Silverlight
2009-10-04 03:09 . 2006-11-29 08:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-10-04 03:09 . 2009-10-04 03:09 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-10-04 03:06 . 2009-10-04 03:06 -------- d-----w- c:\program files\Microsoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-29 19:32 . 2008-06-28 18:03 -------- d-----w- c:\program files\Symantec AntiVirus
2009-10-29 19:14 . 2008-07-06 11:10 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-29 17:19 . 2009-08-19 11:56 -------- d-----w- c:\documents and settings\Saamia Hasan\Application Data\Skype
2009-10-29 11:35 . 2009-08-19 12:00 -------- d-----w- c:\documents and settings\Saamia Hasan\Application Data\skypePM
2009-10-16 16:48 . 2008-08-03 11:55 112200 ----a-w- c:\documents and settings\Saamia Hasan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-14 16:34 . 2008-06-28 17:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-04 03:10 . 2009-02-17 11:54 -------- d-----w- c:\program files\Windows Live
2009-09-24 22:01 . 2009-09-24 22:01 -------- d-----w- c:\program files\MSXML 4.0
2009-09-24 13:22 . 2008-06-28 18:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-24 13:21 . 2009-09-24 13:21 -------- d-----w- c:\documents and settings\Saamia Hasan\Application Data\PC Suite
2009-09-24 13:21 . 2009-09-24 13:19 -------- d-----w- c:\program files\Nokia
2009-09-24 13:20 . 2009-09-24 13:19 -------- d-----w- c:\program files\Common Files\PCSuite
2009-09-24 13:19 . 2009-09-24 13:19 -------- d-----w- c:\program files\Common Files\Nokia
2009-09-23 05:28 . 2009-09-23 05:27 -------- d-----w- c:\program files\iPhone Configuration Utility
2009-09-15 11:09 . 2009-01-30 17:38 -------- d-----w- c:\program files\DivX
2009-09-15 11:09 . 2009-09-15 11:09 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-09-11 14:18 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-31 03:01 . 2008-06-28 19:01 -------- d-----w- c:\documents and settings\Saamia Hasan\Application Data\Apple Computer
2009-08-31 00:01 . 2008-06-28 19:00 -------- d-----w- c:\program files\iTunes
2009-08-29 08:08 . 2004-08-04 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-04 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-19 12:00 . 2009-08-19 12:00 48 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-08-17 18:33 . 2009-08-17 18:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-06 14:24 . 2008-06-28 17:31 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 14:24 . 2008-06-28 17:31 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 14:24 . 2008-06-28 17:30 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 14:24 . 2007-07-30 18:19 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 14:24 . 2008-06-28 17:30 53472 ------w- c:\windows\system32\wuauclt.exe
2009-08-06 14:24 . 2004-08-04 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 14:23 . 2008-06-28 17:30 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 14:23 . 2009-02-18 10:15 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 14:23 . 2009-02-18 10:15 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 14:23 . 2008-06-28 17:30 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:44 . 2004-08-04 12:00 2189184 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2066048 ------w- c:\windows\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-10-29_19.05.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-29 19:39 . 2008-04-13 18:40 96512 c:\windows\system32\drivers\atapi.sys
- 2004-08-04 12:00 . 2008-04-13 18:40 96512 c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Google Update"="c:\documents and settings\Saamia Hasan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-24 133104]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-04-20 847872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-08-06 66680]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2004-08-06 124112]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2005-02-08 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-12-13 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-12-13 126976]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-09-07 213054]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-07-06 3057152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-03-22 167936]
"DataLayer"="c:\program files\Common Files\PCSuite\DataLayer\DataLayer.exe" [2005-03-31 1106944]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-08-24 88363]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Device Detector 3.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Device Detector 3.lnk
backup=c:\windows\pss\Device Detector 3.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Saamia Hasan^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Saamia Hasan\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\Saamia Hasan\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Saamia Hasan\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [07/08/2004 03:18 169192]
S3 V0090VID;Creative WebCam Vista Plus;c:\windows\system32\drivers\V0090Vid.sys [19/08/2009 16:27 138112]

--- Other Services/Drivers In Memory ---

*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
*Deregistered* - PCIIDEX_2
.
Contents of the 'Scheduled Tasks' folder

2009-10-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 07:34]

2009-10-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-682003330-1004Core.job
- c:\documents and settings\Saamia Hasan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-24 11:15]

2009-10-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-484763869-682003330-1004UA.job
- c:\documents and settings\Saamia Hasan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-24 11:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.pk/
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {9D614E8E-03AA-11D3-90FC-0040C7157029} - hxxp://www.pakdata.com/download/PDMSInstaller.cab
DPF: {CAAE28D1-ADCC-11D1-BD4D-004845401881} - hxxp://www.pakdata.com/download/urduplugin.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-30 00:45
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????6?3?8?6??????? ???B???????????????B? ??????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-10-29 0:48
ComboFix-quarantined-files.txt 2009-10-29 19:48
ComboFix2.txt 2009-10-29 19:07

Pre-Run: 4,398,985,216 bytes free
Post-Run: 4,356,079,616 bytes free

- - End Of File - - 29A3F745D4CACA9209638998F23070D5
Upload was successful

MBAM

Malwarebytes' Anti-Malware 1.41
Database version: 3056
Windows 5.1.2600 Service Pack 3

30/10/2009 01:01:39
mbam-log-2009-10-30 (01-01-39).txt

Scan type: Quick Scan
Objects scanned: 101010
Time elapsed: 6 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\un_UrduPlugin.exe (Backdoor.Bot) -> Quarantined and deleted successfully.

#6 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 29 October 2009 - 10:08 PM

Hi,

Please run this scan instead:

Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#7 mhasan420

mhasan420

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 29 October 2009 - 10:54 PM

Hi, I am having the same problem with ESET. It's just that whenever my computer is in constant use for like 15 minutes it just shuts down. It happens even while watching movies. However, it can go without shutting down for weeks if I don't bring the processor under heavy use. Could it be a hardware problem? MH

#8 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 29 October 2009 - 11:02 PM

Yes it could.... it may be over heating....have you cleaned it out lately...make sure there is no dust inside it. close all the other programs while you are running the scan. Disable all your security programs. have nothing else running other than the online scan...see if that helps

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#9 mhasan420

mhasan420

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 29 October 2009 - 11:10 PM

Hi, I did close all programs etc. while running the scan so I think it is over heating. There is also a lot of dust where I live so that might just be the case. Plus I can feel it going all hot. I don't know if I will be able to clean the laptop myself so will have to take it to some professional. So I should get it clean and get back to you in a week or so?

#10 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 29 October 2009 - 11:14 PM

Hi

Files Infected:
C:\WINDOWS\un_UrduPlugin.exe (Backdoor.Bot) -> Quarantined and deleted successfully.


Looks like Malwarebytes mistakenly identified your UrduPlugin as infected...this happens sometimes (false positive)

Please do the following:

1. Click the Start Menu.
2. Click Run.
3. Type in "mbam.exe /developer", without the quotes.
4. Run the same type of scan you did before and save the logfile and post it.


Now open the MalwareBytes program


Select the Quarantine tab....

locate that item......C:\WINDOWS\un_UrduPlugin.exe

click on it and select > RESTORE


Note: you should be able to blow out a fair bit of that dust yourself.

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015

    Advertisements

Register to Remove


#11 mhasan420

mhasan420

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 29 October 2009 - 11:50 PM

Here it the logfile you requested: Malwarebytes' Anti-Malware 1.41 Database version: 3056 Windows 5.1.2600 Service Pack 3 30/10/2009 10:47:40 mbam-log-2009-10-30 (10-47-40).txt Scan type: Quick Scan Objects scanned: 103501 Time elapsed: 10 minute(s), 40 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

#12 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 29 October 2009 - 11:52 PM

were you able to restore that item? Did you try and look to see how much dust you could clean out yourself?

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#13 mhasan420

mhasan420

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 29 October 2009 - 11:56 PM

I did manage to restore that item. I also managed to remove some dust from underneath the keypad. I have no idea though how much dust is actually inside. Do you want me to try and run the scans again?

#14 CatByte

CatByte

    Classroom Administrator

  • Classroom Admin
  • 21,059 posts
  • MVP

Posted 30 October 2009 - 12:05 AM

Yes please

Microsoft MVP 2010, 2011, 2012, 2013, 2014, 2015


#15 mhasan420

mhasan420

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 30 October 2009 - 12:59 PM

Okay so I took my laptop to a cooler environment and that solved the shut down problem. But Kaspersky got stuck after 49%. I have to go out of the city in a little while for a couple of days so I shall run the other virus scan upon my return and post the log here. Thanks.

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users