This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Your System Has Been Infected

128 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Try combofix then.

Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
I disabled my Norton Anti Virus.. but everytime I try to click the ComboFix icon on my desktop, Norton pops up a little message saying "Your system has been halted and needs to do something about this script: CSCRIPT.cfxxe" Should I click ok to 'stop this script' ?
Argh! I am so sorry.. But I think I've tried starting up ComboFix at least 5 times, and each time Norton pops up, it freezes.. I've restarted my computer multiple times. No avail…
Gosh I'm sad to say..that my computer has always been a little weird..and that ctrl alt delete has never really worked….. Right now..everytime i do alt/ctrl/del a pop up says that the application cannot be executed because it is infected…
  • Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) that you can
  • Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.

    Go to [external image: Posted Image] -> Run -> copy/paste in the following single line command & click OK

    "%userprofile%\desktop\combofix.exe" /killall


    [external image: Posted Image]
  • Click OK and this will start ComboFix in a special way.
  • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • ComboFix.txt

If that doesn't work:

Restart your computer in Safe Mode.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.
This can take several miniutes to load.

Once in safe mode, run MBAM.
So my norton is disabled..is that different than stopping it? Because I tried using the run command.. but the same norton window popped up again.. I'm currently on my Norton options..under script blocking "enable script blocking" is checked..would unchecking do anything?
Sadly no.. And I guess I just realized ..Norton hasn't performed a full scan on this computer since 4/2009? ..And that my subscription expired. (But Norton would always do automatic updates..or checks..and I would always abort it because it would take too long and nothing would be found..). I guess I had it in for me… :( But yes..how exactly do I "stop" Norton?
After we get you clean you can get a free anti-virus / anti-spyware program.

Microsoft Security Essentials


For now do this.

I suggest you do this:

To completely uninstall Symantec AntiVirus?
Problem: The solution to many problems with Symantec AntiVirus is to completely uninstall Symantec AntiVirus, then re-install. You can use these instructions to completely uninstall Symantec AntiVirus.

Solution: In order to completely uninstall Symantec AntiVirus and all related components you need to follow these instructions.
Note: This procedure will remove all Symantec products, not just Symantec AntiVirus.

1.Click on Start | Settings | Control Panel
2.In the control panel double-click on Add / Remove Programs
3.Look through the list of installed programs for any item that says either "Norton" or "Symantec" or "LiveUpdate". (for example "Symantec AntiVirus Corporate Edition" or "Norton AntiVirus 2000")
4.For each "Norton", "Symantec", or "LiveUpdate" item, select the item and click Add / Remove. Follow the instructions, and click Yes or Yes to all when prompted.
When you are done there should be no items in the list that say "Norton", "Symantec", or "LiveUpdate".
5.Click OK to close the Add / Remove Programs window.
6.Reboot your computer if it hasn't already automatically rebooted.
7.Delete the c:\Program Files\Symantec AntiVirus (or c:\Program Files\Norton) folder.
8.Delete the c:\Program Files\Symantec folder.
9.Delete the c:\Program Files\Common Files\Symantec Shared folder.



If uninstalling Symantec AntiVirus using Add / Remove Programs does not work, you can use the directions on this Symantec website to manually remove all elements of Symantec Antivirus from your computer.
http://service1.symantec.com/SUPPORT/tsgen…005033108162039
DownLoad for your version of Windows & save to your desktop as it says)
Click on Norton Removal Tool and follow the instructions.
YAY! I feel like we're getting somewhere now (?) After all my computer fail-ness. *knock on wood* [Update: the annoying pop ups have stopped..for now (dun dun dun) But my background still has the picture. And i'm still restricted from sites such as nytimes and youtube]

And thank you so much for being so helpful and patient with me!


So you said to include "C:\ComboFix.txt" in this reply.. so:


C:\ComboFix.txt

ComboFix 10-01-28.05 - Owner 8/2010 Thu 23:19:23.1.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.949.82.1033.18.510.174 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
Error: Cfiles.dat

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\documents and settings\Owner\Application Data\WinAntiSpyware 2006
c:\documents and settings\Owner\Application Data\WinAntiSpyware 2006\Logs\update.log
c:\documents and settings\Owner\Desktop\Internet Security 2010.lnk
c:\documents and settings\Owner\Local Settings\Application Data\{21C43D0E-6DDE-4C1E-8122-610F786C8807}
c:\documents and settings\Owner\Local Settings\Application Data\{21C43D0E-6DDE-4C1E-8122-610F786C8807}\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{21C43D0E-6DDE-4C1E-8122-610F786C8807}\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{21C43D0E-6DDE-4C1E-8122-610F786C8807}\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{21C43D0E-6DDE-4C1E-8122-610F786C8807}\install.rdf
c:\documents and settings\Owner\Start Menu\Internet Security 2010.lnk
c:\program files\InternetSecurity2010
c:\program files\InternetSecurity2010\IS2010.exe
c:\recycled\NPROTECT
c:\windows\odubereb.dll
c:\windows\system32\11478.exe
c:\windows\system32\15724.exe
c:\windows\system32\16569.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\23876.exe
c:\windows\system32\25070.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\29358.exe
c:\windows\system32\32141.exe
c:\windows\system32\3967.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\tmp12.tmp.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_WINDRIVER
——-\Service_WinDriver


((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-29 )))))))))))))))))))))))))))))))
.

2010-01-27 01:00 . 2010-01-27 01:00 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-01-27 01:00 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-27 01:00 . 2010-01-27 01:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-27 01:00 . 2010-01-27 01:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-27 01:00 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-27 00:15 . 2010-01-28 06:11 0 —-a-w- c:\windows\Hbijemofivut.bin
2010-01-27 00:15 . 2010-01-29 03:06 120 —-a-w- c:\windows\Gqifekesuharucul.dat
2010-01-27 00:12 . 2010-01-28 03:20 25600 —-a-w- c:\windows\system32\helper32.dll
2010-01-27 00:11 . 2010-01-27 00:11 22528 —-a-w- c:\windows\system32\winlogon32.exe
2010-01-27 00:11 . 2010-01-27 00:11 22528 —-a-w- c:\windows\system32\smss32.exe
2009-12-31 15:10 . 2008-09-17 15:07 847360 —-a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ld4162cq.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
2009-12-31 00:42 . 2009-12-31 00:42 144160 —-a-w- c:\documents and settings\Owner\Application Data\Move Networks\uninstall.exe
2009-12-31 00:42 . 2009-12-31 00:42 1440376 —-a-w- c:\documents and settings\Owner\Application Data\Move Networks\MoveMediaPlayerWin_071503000010.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-31 00:42 . 2009-12-10 21:23 4183416 —-a-w- c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-12-22 05:42 . 2004-08-04 17:00 662016 —-a-w- c:\windows\system32\wininet.dll
2009-12-22 05:42 . 2004-08-04 17:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-12-13 02:19 . 2009-12-13 02:19 ——– d—–w- c:\documents and settings\Owner\Application Data\ViiKiiDesktopPlugin.5E22EA0FF243470AB5EDDF282C0A5B52E9909C36.1
2009-12-13 02:18 . 2009-12-13 02:18 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-12-13 02:13 . 2009-12-13 02:19 38784 —-a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-13 02:13 . 2009-12-13 02:19 38784 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-10 19:27 . 2009-12-10 19:27 97144 —-a-w- c:\documents and settings\Owner\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-11-21 16:36 . 2004-08-04 17:00 470528 —-a-w- c:\windows\AppPatch\AcLayers.dll
2007-02-01 03:09 . 2007-02-01 03:09 5467784 —-a-w- c:\program files\CyStudioSetup.exe
2005-10-13 20:52 . 2005-10-13 20:52 32 –sha-w- c:\windows\{6721F1CE-8C6F-4985-B893-36C2D35B4BE4}.dat
2005-10-13 20:52 . 2005-10-13 20:52 32 –sha-w- c:\windows\system32\{AD77ED27-211A-462D-829F-E0868FD1A131}.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-08-26 15:32 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-8087-36EE87E26986}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-26 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-26 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 68856]
"Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-02-23 3537968]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-22 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-22 126976]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_05\bin\jusched.exe" [2005-08-26 36975]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"BigDogPath"="c:\windows\VM_STI.EXE" [2003-01-21 40960]
"EPSON Stylus C88 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE" [2005-01-27 98304]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-04-03 777424]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-29 185896]
"BearShare"="c:\program files\BearShare\BearShare.exe" [2005-09-15 3223552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Picture Package VCD Maker.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2006-11-8 106496]
Picture Package Menu.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2006-11-8 151552]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\Program Files\\Common Files\\AOL\\1138853410\\ee\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1138853410\\EE\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1138853410\\EE\\aim6.exe"=
"c:\\Program Files\\SunFolder\\sunfolder.exe"=
"c:\\Program Files\\Wizet\\MxCommon\\NGLC_Maple.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\AIM6\\AIM6.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:ooVoo TCP 포트 443
"443:UDP"= 443:UDP:ooVoo UDP 포트 443
"37674:TCP"= 37674:TCP:ooVoo TCP 포트 37674
"37674:UDP"= 37674:UDP:ooVoo UDP 포트 37674
"37675:UDP"= 37675:UDP:ooVoo UDP 포트 37675
"57383:TCP"= 57383:TCP:Pando Media Booster
"57383:UDP"= 57383:UDP:Pando Media Booster
"37680:TCP"= 37680:TCP:ooVoo TCP port 37680
"37680:UDP"= 37680:UDP:ooVoo UDP port 37680
"37681:UDP"= 37681:UDP:ooVoo UDP port 37681

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/11/2007 6:51 PM 24652]
S3 cheetah1;cheetah1;\??\c:\documents and settings\Owner\Desktop\ce12\cheetah.sys –> c:\documents and settings\Owner\Desktop\ce12\cheetah.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [1/26/2010 8:00 PM 38224]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [8/28/2007 3:06 PM 130816]
S3 Mkd2Usbf;Mkd2Usbf;c:\windows\system32\drivers\Mkd2UsbF.sys [8/28/2007 3:06 PM 93440]
S3 MooseKOPMA;MooseKOPMA;\??\c:\documents and settings\Owner\Desktop\trainer\trainer\MooseKOPMA.sys –> c:\documents and settings\Owner\Desktop\trainer\trainer\MooseKOPMA.sys [?]
S3 WlanUIB;NETGEAR 802.11b USB Driver;c:\windows\system32\drivers\MA111nd5.sys [3/3/2004 4:27 PM 666624]
S3 zenx1;zenx1;\??\c:\documents and settings\Owner\Desktop\ZenxEngine_LATEST\zenx.sys –> c:\documents and settings\Owner\Desktop\ZenxEngine_LATEST\zenx.sys [?]
S4 WinDefend;Windows Defender Service;c:\program files\Windows Defender\MsMpEng.exe [4/3/2006 6:12 PM 14032]
.
Contents of the 'Scheduled Tasks' folder

2010-01-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-04-03 23:12]

2010-01-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.bearshare.com/
mStart Page = hxxp://www.netian.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
LSP: c:\windows\system32\helper32.dll
DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} - hxxp://www.clubbox.co.kr/neo.fld/NowStarter.cab
DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} - hxxp://s.nx.com/activex/public_new/nxpm.cab
DPF: {7606693A-C18D-4567-AF85-6194FF70761E} - hxxp://app.ipop.co.kr/gom/GomWeb.cab
DPF: {A1D886C6-4039-4451-97A9-515F5BE5D4C2} - hxxp://ahnlabdownload.nefficient.co.kr/asp/cab/mkdplus.cab
DPF: {A977FF0C-8757-4E76-8533-482F91946233} - hxxp://dl.sayclub.com/sayclub/sayctl/sayax.cab
DPF: {AF11AA64-87A5-4146-AF3B-A7BD0F278485} - hxxp://download.soribada.com/down/Soribada/Setup/20061206/SBStart.CAB
DPF: {E1CDC08F-F464-4682-AE6A-7689451387C0} - hxxp://cafeimg.hanmail.net/activex/dmcm.cab?Version=1,0,0,22
DPF: {E78928A6-3D2A-4BF7-A100-F3FBAA351B49} - hxxps://www.vpay.co.kr/kvpfiles/KVPISPCTLD.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ld4162cq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.nytimes.com
FF - plugin: c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ld4162cq.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Tjolofatahixowet - c:\windows\odubereb.dll
ShellExecuteHooks-{076394AD-7FDD-44EF-A075-32C68DBAB99B} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-28 23:29
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1390067357-1788223648-725345543-1003\Software\Microsoft\MessengerService\GroupStateCacheU\*?????
"Name"=hex:00,b3,31,c1,5c,ce,6c,ad,e4,b4,00,00
"Collapsed"=hex:00,00,00,00
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3900)
c:\windows\system32\shdoclc.dll
c:\windows\ime\imkr6_1\imekrcic.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\conime.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2010-01-28 23:34:57 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-29 04:34

Pre-Run: 7,266,533,376 bytes free
Post-Run: 10,583,277,568 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - B1C1C2146216ABE4C0DA98F93151FF97

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI