This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Fraud.WindowProtection Suite

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I am having these two viruses in my system and having a hard time removing them.

The below 2 viruses are picked up by spybot but failed to remove them by saying "c:\windows\system32\drivers\etc Acess is denied"

1. Fraud.WindowProtectionSuite
2. Microsoft.Window.RedirectHosts.


I did look at the same issue in the forum.

I downloaded combofix and ran the same, below is the log. Any input would be of great help.

ComboFix 09-11-25.05 - kveerappa 11/26/2009 8:54.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3582.2672 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}\chrome.manifest
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}\chrome\content\_cfg.js
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}\chrome\content\overlay.xul
c:\documents and settings\kveerappa\Local Settings\Application Data\{34452892-855C-4C67-A563-4E53F98A154F}\install.rdf
c:\recycler\S-1-5-21-1148212273-670532697-2008175689-500
c:\recycler\S-1-5-21-1547161642-746137067-839522115-500
c:\recycler\S-1-5-21-3436562845-356841921-1497333993-500
c:\recycler\S-1-5-21-3896539928-1599609400-794918191-500
c:\recycler\S-1-5-21-884609397-1866408068-2337108139-500
c:\windows\system32\Cache
c:\windows\system32\flags.ini
c:\windows\system32\mscert.dll
c:\windows\system32\rdolib.dll
c:\windows\system32\uses32.dat
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\windows\Tasks\startAltiris_test.bat
c:\windows\TEMP\logishrd\LVPrcInj01.dll

Infected copy of c:\windows\system32\drivers\ntfs.sys was found and disinfected
Restored copy from - c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys

.
((((((((((((((((((((((((( Files Created from 2009-10-26 to 2009-11-26 )))))))))))))))))))))))))))))))
.

2009-11-26 05:42 . 2009-07-28 20:33 55656 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-26 05:42 . 2009-03-30 14:33 96104 —-a-w- c:\windows\system32\drivers\avipbb.sys
2009-11-26 05:42 . 2009-02-13 16:29 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-11-26 05:42 . 2009-02-13 16:17 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2009-11-26 05:42 . 2009-11-26 05:42 ——– d—–w- c:\program files\Avira
2009-11-26 05:42 . 2009-11-26 05:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2009-11-26 04:57 . 2009-11-26 05:38 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-11-26 04:53 . 2009-11-10 15:28 149456 —-a-w- c:\windows\SGDetectionTool.dll
2009-11-26 04:53 . 2009-11-10 15:26 767952 —-a-w- c:\windows\BDTSupport.dll
2009-11-26 04:53 . 2009-10-28 06:36 1152444 —-a-w- c:\windows\UDB.zip
2009-11-26 04:53 . 2008-11-26 17:08 131 —-a-w- c:\windows\IDB.zip
2009-11-26 04:53 . 2009-11-10 15:28 165840 —-a-w- c:\windows\PCTBDRes.dll
2009-11-26 04:53 . 2009-11-10 15:28 1640400 —-a-w- c:\windows\PCTBDCore.dll
2009-11-26 04:50 . 2009-10-30 16:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-11-26 04:50 . 2009-11-09 16:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-11-26 04:50 . 2009-10-06 21:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-26 04:50 . 2009-09-03 14:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-11-26 04:50 . 2009-11-26 04:53 ——– d—–w- c:\program files\Spyware Doctor
2009-11-26 04:50 . 2009-11-26 04:50 ——– d—–w- c:\program files\Common Files\PC Tools
2009-11-26 04:50 . 2009-11-26 04:50 ——– d—–w- c:\documents and settings\kveerappa\Application Data\PC Tools
2009-11-26 04:50 . 2009-11-26 04:50 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-11-26 04:11 . 2009-11-26 04:11 ——– d—–w- c:\documents and settings\kveerappa\Local Settings\Application Data\Threat Expert
2009-11-26 03:56 . 2009-11-26 14:15 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-25 20:01 . 2009-11-25 20:01 ——– d—–w- c:\documents and settings\athena\Local Settings\Application Data\Mozilla
2009-11-25 19:47 . 2009-11-25 19:47 ——– d—–w- c:\documents and settings\athena\Local Settings\Application Data\Cisco
2009-11-25 19:40 . 2009-11-25 19:40 ——– d-sh–w- c:\documents and settings\athena\PrivacIE
2009-11-25 19:40 . 2009-11-25 19:40 ——– d—–w- c:\documents and settings\athena\Local Settings\Application Data\Google
2009-11-25 19:39 . 2009-11-25 19:39 ——– d—–w- c:\documents and settings\athena\Application Data\Malwarebytes
2009-11-25 19:38 . 2009-11-25 19:38 ——– d-sh–w- c:\documents and settings\athena\IETldCache
2009-11-25 18:47 . 2009-11-25 18:47 ——– d—–w- c:\windows\DWRCS Uploads
2009-11-25 17:58 . 2009-11-25 17:58 51636 —ha-w- c:\windows\system32\mlfcache.dat
2009-11-25 03:54 . 2009-11-25 03:54 ——– d—–w- c:\documents and settings\kveerappa\Application Data\Malwarebytes
2009-11-25 03:54 . 2009-11-25 03:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-25 03:52 . 2009-11-25 03:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-11-25 01:42 . 2009-11-25 18:14 120 —-a-w- c:\windows\Rcikumuqoboxeb.dat
2009-11-25 01:42 . 2009-11-25 14:12 0 —-a-w- c:\windows\Wvopaqoxisigih.bin
2009-11-25 01:09 . 2009-11-25 01:09 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2009-11-23 19:16 . 2009-11-23 19:16 ——– d—–w- c:\documents and settings\kveerappa\691509.tmp
2009-11-23 18:53 . 2009-11-23 18:53 ——– d—–w- c:\documents and settings\kveerappa\808405.tmp
2009-11-11 05:28 . 2009-11-11 05:28 247280 —-a-w- c:\documents and settings\kveerappa\Application Data\Mozilla\plugins\npgoogletalk.dll
2009-11-05 23:25 . 2009-11-05 23:25 593920 —-a-w- c:\documents and settings\kveerappa\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv305hw-0910190-0-main.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-26 05:33 . 2007-10-19 12:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-26 02:57 . 2007-10-18 19:25 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-11-26 02:57 . 2007-10-18 19:26 ——– d—–w- c:\program files\Symantec
2009-11-26 02:50 . 2007-10-18 19:25 ——– d—–w- c:\program files\Symantec AntiVirus
2009-11-26 02:49 . 2007-10-18 19:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-11-25 22:15 . 2008-08-27 08:35 ——– d—–w- c:\documents and settings\kveerappa\Application Data\Yahoo!
2009-11-25 19:39 . 2007-10-18 21:18 102630 —-a-w- c:\windows\system32\nvModes.dat
2009-11-20 17:19 . 2008-08-18 04:25 ——– d—–w- c:\documents and settings\kveerappa\Application Data\U3
2009-10-18 12:32 . 2009-10-18 12:32 ——– d—–w- c:\program files\MSXML 6.0
2009-09-28 13:03 . 2009-09-28 13:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Cisco
2009-09-28 13:03 . 2009-09-28 13:03 ——– d—–w- c:\program files\Cisco
2009-09-04 20:45 . 2004-08-04 07:56 58880 —-a-w- c:\windows\system32\msasn1.dll
2009-09-01 23:01 . 2009-09-01 23:01 127872 —-a-w- c:\documents and settings\kveerappa\Application Data\Move Networks\uninstall.exe
2009-09-01 23:01 . 2009-06-16 06:35 4183416 —-a-w- c:\documents and settings\kveerappa\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-08-29 08:08 . 2004-08-04 07:56 916480 —-a-w- c:\windows\system32\wininet.dll
2005-11-15 10:02 . 2005-11-15 10:02 3638 —-a-r- c:\program files\Common Files\Altiris_Icon.ico
2003-02-22 23:24 . 2003-02-22 23:24 107 —-a-w- c:\program files\zMarker.txt
2009-02-10 12:01 . 2007-10-18 22:05 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-02-10 12:01 . 2007-10-18 22:05 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-02-10 12:01 . 2007-10-18 22:05 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-02-10 12:01 . 2007-10-18 22:05 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-02-10 12:01 . 2007-10-18 22:05 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2008-09-10 13:22 . 2008-09-10 13:22 10856 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

——- Sigcheck ——-

[-] 2007-09-27 . 6E266AAF4168B3569A330C61AB01F6B4 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\P4EXPCheckoutOverlay]
@="{80E008A4-EAE7-4867-AEB0-1A245F070F25}"
[HKEY_CLASSES_ROOT\CLSID\{80E008A4-EAE7-4867-AEB0-1A245F070F25}]
2008-02-06 23:17 557056 —-a-r- c:\devtools\Perforce\p4exp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\P4EXPSyncdOverlay]
@="{ADF262C1-E8FE-49BE-AD63-F77CD4A6CCD9}"
[HKEY_CLASSES_ROOT\CLSID\{ADF262C1-E8FE-49BE-AD63-F77CD4A6CCD9}]
2008-02-06 23:17 557056 —-a-r- c:\devtools\Perforce\p4exp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\P4EXPUpdateOverlay]
@="{C550CDA2-37D7-4838-A9D7-65ECB1EB5AB2}"
[HKEY_CLASSES_ROOT\CLSID\{C550CDA2-37D7-4838-A9D7-65ECB1EB5AB2}]
2008-02-06 23:17 557056 —-a-r- c:\devtools\Perforce\p4exp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-26 4351216]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-22 39408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SgeEcView"="c:\program files\Utimaco\SafeGuard Easy\Ecview.exe" [2007-09-05 24576]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-28 81920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]
"EdWizard"="c:\program files\Utimaco\SafeGuard Easy\EdWizard.exe" [2007-09-05 245760]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-07-20 1228800]
"AeXAgentLogon"="c:\program files\Altiris\Altiris Agent\AeXAgentActivate.exe" [2009-04-30 153416]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"DameWare MRC Agent"="c:\windows\system32\DWRCST.exe" [2009-02-04 78848]
"NVHotkey"="nvHotkey.dll" - c:\windows\system32\nvhotkey.dll [2007-04-28 67584]

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NotLog]
2002-01-22 09:58 110592 —-a-w- c:\windows\system32\SGLogEx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SGLogNotification]
2005-03-31 05:57 69632 —-a-w- c:\windows\system32\SGLogNotification.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor Apache Servers.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor Apache Servers.lnk
backup=c:\windows\pss\Monitor Apache Servers.lnkCommon Startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\devtools\\MKS\\bin\\secshd.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\devtools\\jre1.5.0_14\\bin\\javaw.exe"=
"d:\\devtools\\bea81\\jdk142_05\\bin\\java.exe"=
"c:\\devtools\\jdk1.4.2_02\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\kveerappa\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\kveerappa\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\NX Client for Windows\\nxclient.exe"=
"c:\\Program Files\\NX Client for Windows\\bin\\nxssh.exe"=
"d:\\devtools\\bea101\\jdk150_11\\jre\\bin\\java.exe"=
"d:\\Ariba\\Demo9r1\\Upstream\\Server\\3rdParty\\jre\\NT\\1.5.0\\bin\\java.exe"=
"c:\\devtools\\jdk1.5.0_14\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\devtools\\bea101\\jdk150_11\\bin\\java.exe"=
"d:\\Ariba\\JPMC9r1\\Downstream\\Server\\3rdParty\\jre\\NT\\1.5.0\\bin\\java.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Documents and Settings\\kveerappa\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6129:TCP"= 6129:TCP:Dameware
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"2015:UDP"= 2015:UDP:Windows Media Format SDK (IEXPLORE.EXE)
"2014:UDP"= 2014:UDP:Windows Media Format SDK (IEXPLORE.EXE)
"2017:UDP"= 2017:UDP:Windows Media Format SDK (IEXPLORE.EXE)

R0 AES-256;AES-256;c:\windows\system32\drivers\AES256.sys [9/5/2007 3:20 AM 19712]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [11/25/2009 11:50 PM 207792]
R0 SgeFlt;SgeFlt;c:\windows\system32\drivers\SGEFLT.sys [9/5/2007 3:20 AM 62720]
R1 FSLX;FSLX;c:\windows\system32\drivers\fslx.sys [7/21/2008 12:01 AM 192256]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [11/26/2009 12:42 AM 108289]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [11/25/2009 11:53 PM 112592]
R2 MKSAUTH;MKSAUTH;c:\windows\system32\mksauth.exe [7/25/2007 12:07 PM 94168]
R2 MKSRlogind;MKS Rlogind;c:\devtools\MKS\bin\rlogind.exe [6/7/2007 12:41 PM 69848]
R2 MKSSecureSH;MKS Secure Shell Service;c:\devtools\MKS\bin\secshd.exe [7/16/2007 6:11 PM 360408]
R2 NuTCRACKERService;NuTCRACKER Service;c:\windows\system32\nutsrv4.exe [7/20/2007 3:31 PM 315424]
R2 OracleServiceARIBA1;OracleServiceARIBA1;c:\devtools\ora10.2.0\bin\ORACLE.EXE ARIBA1 –> c:\devtools\ora10.2.0\bin\ORACLE.EXE ARIBA1 [?]
R2 REXECD;REXECD;c:\devtools\MKS\mksnt\rexecd.exe [7/25/2007 12:10 PM 102360]
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [6/17/2009 3:17 PM 434864]
R3 DwMirror;DwMirror;c:\windows\system32\drivers\DamewareMini.sys [2/7/2007 4:30 PM 3712]
S2 OracleDBConsoleARIBA1;OracleDBConsoleARIBA1;c:\devtools\ora10.2.0\BIN\nmesrvc.exe [3/24/2009 10:11 PM 24064]
S2 OracleOraDb10g_home1TNSListener;OracleOraDb10g_home1TNSListener;c:\devtools\ora10.2.0\BIN\TNSLSNR –> c:\devtools\ora10.2.0\BIN\TNSLSNR [?]
S2 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" –> c:\program files\Symantec AntiVirus\SavRoam.exe [?]
S3 CSVirtA;Cisco Systems SSL VPN Adapter;c:\windows\system32\drivers\CSVirtA.sys [3/3/2009 11:20 PM 22136]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [?]
S3 OracleOraHome92Agent;OracleOraHome92Agent;d:\devtools\oracle\ora92\bin\agntsrvc.exe [4/26/2002 6:59 AM 28944]
S3 OracleOraHome92HTTPServer;OracleOraHome92HTTPServer;d:\devtools\oracle\ora92\Apache\Apache\Apache.exe [4/18/2002 11:32 AM 4096]
S3 OracleOraHome92SNMPPeerEncapsulator;OracleOraHome92SNMPPeerEncapsulator;d:\devtools\oracle\ora92\bin\encsvc.exe [2/12/2002 9:53 PM 187392]
S3 OracleOraHome92SNMPPeerMasterAgent;OracleOraHome92SNMPPeerMasterAgent;d:\devtools\oracle\ora92\bin\agntsvc.exe [2/12/2002 9:53 PM 254464]
S3 OracleServiceARIBA;OracleServiceARIBA;d:\devtools\oracle\ora92\bin\ORACLE.EXE ARIBA –> d:\devtools\oracle\ora92\bin\ORACLE.EXE ARIBA [?]
S3 Tomcat6;Apache Tomcat;d:\kris\ProgramFiles\Tomcat 6.0\bin\tomcat6.exe [1/28/2008 5:39 PM 57344]
S4 MKSTelnetd;MKS Telnetd;c:\windows\system32\telnetd.exe [6/7/2007 12:40 PM 114904]
S4 OracleJobSchedulerARIBA1;OracleJobSchedulerARIBA1;c:\devtools\ora10.2.0\Bin\extjob.exe ARIBA1 –> c:\devtools\ora10.2.0\Bin\extjob.exe ARIBA1 [?]
S4 RSHD;RSHD;c:\devtools\MKS\mksnt\rshd.exe [7/25/2007 12:10 PM 114648]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
vvdsvc REG_MULTI_SZ vvdsvc
.
Contents of the 'Scheduled Tasks' folder

2009-11-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1604221776-839522115-64179Core.job
- c:\documents and settings\kveerappa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 08:31]

2009-11-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1604221776-839522115-64179UA.job
- c:\documents and settings\kveerappa\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 08:31]

2009-11-26 c:\windows\Tasks\User_Feed_Synchronization-{289DB8EB-F584-4124-8768-93085DB71593}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://web.ariba.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: %SystemRoot%\system32\nutafun4.dll
TCP: {7C93048F-1CEF-4378-819F-0E6BDDA55A30} = 10.1.1.10,10.1.1.11
DPF: {25C89FF5-4A85-4183-81F2-6C0C1B514297} - hxxps://crm.ariba.com/hi/18382/applets/SiebelAx_HI_Client.cab
DPF: {264AED84-12F1-4CA1-8AA7-EB939AE58D8D} - hxxps://snv-acdcasa/CACHE/stc/1/binaries/stcweb.cab
DPF: {31C799C0-32B1-4EFE-87FC-CF506C14338B} - hxxps://crm.ariba.com/hi/18382/applets/SiebelAx_OutBound_mail.cab
DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} - hxxps://rapgh.ariba.com/CACHE/stc/1/binaries/vpnweb.cab
DPF: {61803B6E-0994-4C05-AC45-1FE2EEDADECB} - hxxps://zinfandel.ariba.com/DemoACM/ariba/resource/en_US/lib/winXP/clientautomation.cab
DPF: {8AFC9162-C354-4022-9E7E-ED4D41A9A284} - hxxp://kveerappa1.ariba.com/DemoAribaASM/ariba/resource/en_US/lib/clientautomation.cab
DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} - hxxps://crm.ariba.com/hi/18382/applets/SiebelAx_Desktop_Integration.cab
DPF: {FDF527BA-DDDA-11D3-AA82-006094EB09CB} - hxxp://help/aspnet_client/Altiris_AppWeaver/6_0_sp3/lib/AeXClipboard.CAB
FF - ProfilePath - c:\documents and settings\kveerappa\Application Data\Mozilla\Firefox\Profiles\3jr8cvzb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p;=
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p;=
FF - prefs.js: network.proxy.ftp - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.gopher - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.http - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.socks - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.ssl - http://iaproxy.jpmorganchase.com
FF - prefs.js: network.proxy.type - 2
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\qfaservices.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -

ShellIconOverlayIdentifiers-{ba930330-a721-11d3-a7b9-00500464ee16} - Sgedrse.Dll
ShellIconOverlayIdentifiers-{2030D939-54A7-4fea-9B06-49EA77EFC87F} - Sgedrse.Dll
HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
AddRemove-Broadcom 802.11b Network Adapter - c:\program files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe verbose
AddRemove-e84c95559d72a4b073d4840a41180d31 - d:\devtools\Tibco\_uninst\uninstallTibco.exe
AddRemove-NVIDIA Drivers - c:\windows\system32\nvudisp.exe UninstallGUI
AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-{D1DB41B3-0415-4D96-B53B-4B02B9AAD23A}-Visible - c:\documents and settings\zeus\Local Settings\Application Data\{D1DB41B3-0415-4D96-B53B-4B02B9AAD23A}\setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-26 09:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OracleOraDb10g_home1TNSListener]
"ImagePath"="c:\devtools\ora10.2.0\BIN\TNSLSNR "

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OracleOraHome92PagingServer]
"ImagePath"="d:\devtools\oracle\ora92/bin/pagntsrv.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OracleOraHome92TNSListener]
"ImagePath"="d:\devtools\oracle\ora92\BIN\TNSLSNR "
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1744)
c:\windows\system32\WININET.dll
c:\windows\system32\SGLogEx.dll
c:\windows\system32\SGLogNotification.dll
c:\windows\system32\GetUserSid.dll

- - - - - - - > 'lsass.exe'(1808)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(5236)
c:\windows\system32\WININET.dll
c:\program files\Utimaco\SafeGuard Easy\SgMsgBhk.dll
c:\devtools\Perforce\p4exp.dll
c:\program files\Utimaco\SafeGuard Easy\SgeDrse.dll
c:\program files\Utimaco\SafeGuard Easy\SgeUtil.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\windows\system32\ConnAPI.DLL
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\windows\system32\CDRTC.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\program files\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Cisco Systems\SSL VPN Client\agent.exe
c:\windows\System32\bcmwltry.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Altiris\Altiris Agent\AeXNSAgent.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
d:\devtools\Apache Group\Apache2\bin\Apache.exe
d:\devtools\Apache Group\Apache2\bin\Apache.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\windows\system32\DWRCS.EXE
c:\program files\Dell\OpenManage\Client\Iap.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\MySQL\MySQL Server 5.1\bin\mysqld.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\windows\system32\nvsvc32.exe
d:\devtools\oracle\ora92\bin\omtsreco.exe
c:\devtools\ora10.2.0\bin\isqlplussvc.exe
c:\devtools\ora10.2.0\bin\ORACLE.EXE
c:\program files\Utimaco\SafeGuard Easy\SgeCtl.exe
c:\windows\system32\SgLogPlayer.exe
c:\windows\system32\StacSV.exe
c:\program files\RealVNC\VNC4\WinVNC4.exe
c:\program files\Utimaco\SafeGuard Easy\WksCfgSrv.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\program files\Altiris\Altiris Agent\AeXAgentUIHost.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-11-26 09:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-26 14:24

Pre-Run: 20,016,668,672 bytes free
Post-Run: 19,984,228,352 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 00779E1F90B3FA4A99686950E5162EE2
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
[external image: Posted Image]
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI