This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Java/TrojanDownloader.Agent.NAN

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

I'm unable to reset my HOST file to it's default as Vista is not allowing me to do so. There are also a couple of files located in the host folder that look suspicious. I am also infected with a variant of Java/TrojanDownloader.Agent.NAN.

📎Infection_NOD32.jpg

📎Host_Location.jpg

GMER
———————————————————

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-07 21:48:05
Windows 6.0.6002 Service Pack 2
Running: 8580wmr9.exe; Driver: C:\Users\Dan\AppData\Local\Temp\kxrdapow.sys


—- Kernel code sections - GMER 1.0.15 —-

init C:\Windows\system32\drivers\st330.sys entry point in "init" section [0x90B4FE00]
init C:\Windows\system32\drivers\lpwdm.sys entry point in "init" section [0x90B55880]
init C:\Windows\system32\drivers\stbus.sys entry point in "init" section [0x90B59192]
C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl entry point in "" section [0xABB3541C]
.clc C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl unknown last code section [0xABB36000, 0x1000, 0xE0000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\Explorer.EXE[676] SHELL32.dll!SHGetFolderPathAndSubDirW + 81C9 76A1B364 4 Bytes [50, 26, 00, 10] {PUSH EAX; ADD ES:[EAX], DL}
.text C:\Program Files\Mozilla Firefox\firefox.exe[1380] ntdll.dll!LdrLoadDll 77709390 5 Bytes JMP 00B613F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[2228] kernel32.dll!SetUnhandledExceptionFilter 75DAA84F 4 Bytes [C2, 04, 00, 00]
.text C:\Program Files\Audacity\audacity.exe[4752] SHELL32.dll!SHGetFolderPathAndSubDirW + 81C9 76A1B364 4 Bytes [50, 26, D0, 02] {PUSH EAX; ROL BYTE ES:[EDX], 0x1}

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 tdrpm174.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 snman380.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 tdrpm174.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 snman380.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 tdrpm174.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 snman380.sys (Acronis Snapshot API/Acronis)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001f3acdd226
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001f3acdd226 (not active ControlSet)

—- EOF - GMER 1.0.15 —-


DDS
——————————————————–

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 21:51:22.50 on 07/05/2010
Internet Explorer: 8.0.6001.18904 BrowserJavaVersion: 1.6.0_20
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.44.1033.18.3000.1451 [GMT 1:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Thomson\ST330\service\st330service.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\Dan\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Audacity\audacity.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Dan\Desktop\dds.pif
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uSearch Bar = Preserve
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=0809&m=aspire_7730
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=0809&m=aspire_7730
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=0809&m=aspire_7730
BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\program files\acer\empowering technology\edatasecurity\x86\ActiveToolBand.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\program files\acer\empowering technology\edatasecurity\x86\eDStoolbar.dll
mRun: [eDataSecurity Loader] c:\program files\acer\empowering technology\edatasecurity\x86\eDSloader.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [PLFSetI] c:\windows\PLFSetI.exe
mRun: [CLMLServer] "c:\program files\acer arcade deluxe\acer arcade deluxe\kernel\clml\CLMLSvc.exe"
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files\acronis\trueimagehome\TimounterMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [LManager] c:\program files\launch manager\QtZgAcer.EXE
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Skytel] Skytel.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
TCP: {5F5C77F2-51C5-46C9-8645-7237001BADD8} = 212.139.132.107 212.139.132.11
Notify: igfxcui - igfxdev.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\dan\appdata\roaming\mozilla\firefox\profiles\c3wkt1ht.default\
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 snapman380;Acronis Snapshots Manager (Build 380);c:\windows\system32\drivers\snman380.sys [2009-8-13 134272]
R0 tdrpman174;Acronis Try&Decide and Restore Points filter (build 174);c:\windows\system32\drivers\tdrpm174.sys [2009-8-13 971552]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-2-6 106208]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\acer arcade deluxe\playmovie\000.fcl [2009-8-12 61424]
R2 CLHNService;CLHNService;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\CLHNService.exe [2009-8-12 81504]
R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2009-2-6 727720]
R2 epfwwfp;epfwwfp;c:\windows\system32\drivers\epfwwfp.sys [2009-2-6 38240]
R2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2008-4-17 24576]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-8-12 304464]
R2 NTIPPKernel;NTIPPKernel;c:\program files\acer arcade deluxe\homemedia\kernel\dmp\NTIPPKernel.sys [2009-8-12 122368]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2009-11-13 92008]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-3-28 210432]
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-4-17 81296]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-8-12 20952]
R3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\drivers\NETw5v32.sys [2008-4-17 3658752]
R3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2009-8-12 30464]
R3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2009-8-12 12672]
R3 stppp;Speedtouch PPP Adapter Adapter;c:\windows\system32\drivers\stppp.sys [2009-8-12 49408]
R3 winbondcir;Winbond IR Transceiver;c:\windows\system32\drivers\winbondcir.sys [2007-3-28 43008]
S2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:\program files\autodesk\3ds max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [2009-3-18 86016]
S3 A310;AVerMedia A310 DVB-T;c:\windows\system32\drivers\AVerA310USB.sys [2008-4-17 25856]
S3 BDASwCap;AVerMedia A310 BDA DVBT Capture Device;c:\windows\system32\drivers\AVerA310Cap.sys [2008-4-17 42880]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-9-3 112128]
S4 ADOK;ADOK;c:\users\dan\appdata\local\temp\adok.exe –> c:\users\dan\appdata\local\temp\ADOK.exe [?]
S4 B;B;c:\users\dan\appdata\local\temp\b.exe –> c:\users\dan\appdata\local\temp\B.exe [?]
S4 CQXXVZ;CQXXVZ;c:\users\dan\appdata\local\temp\cqxxvz.exe –> c:\users\dan\appdata\local\temp\CQXXVZ.exe [?]
S4 HSPUUYZKD;HSPUUYZKD;c:\users\dan\appdata\local\temp\hspuuyzkd.exe –> c:\users\dan\appdata\local\temp\HSPUUYZKD.exe [?]
S4 Partner Service;Partner Service;"c:\programdata\partner\partner.exe" –> c:\programdata\partner\partner.exe [?]
S4 QRORZWSH;QRORZWSH;c:\users\dan\appdata\local\temp\qrorzwsh.exe –> c:\users\dan\appdata\local\temp\QRORZWSH.exe [?]

=============== Created Last 30 ================

2010-05-02 01:47

–d—– c:\program files\iPod
2010-05-02 01:30 –d—– c:\program files\Bonjour
2010-04-17 20:50 411,368 a——- c:\windows\system32\deployJava1.dll
2010-04-13 19:26 172,032 a——- c:\windows\system32\wintrust.dll
2010-04-13 19:25 3,548,040 a——- c:\windows\system32\ntoskrnl.exe
2010-04-13 19:25 3,600,776 a——- c:\windows\system32\ntkrnlpa.exe
2010-04-13 19:25 79,360 a——- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-13 19:25 212,992 a——- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-13 19:25 106,496 a——- c:\windows\system32\drivers\mrxsmb.sys
2010-04-13 19:25 98,304 a——- c:\windows\system32\cabview.dll
2010-04-13 19:25 420,352 a——- c:\windows\system32\vbscript.dll
2010-04-13 19:25 62,464 a——- c:\windows\system32\l3codeca.acm
2010-04-13 19:25 220,672 a——- c:\windows\system32\l3codecp.acm
2010-04-13 19:25 904,576 a——- c:\windows\system32\drivers\tcpip.sys
2010-04-13 19:25 25,088 a——- c:\windows\system32\drivers\tunnel.sys
2010-04-13 19:25 200,704 a——- c:\windows\system32\iphlpsvc.dll
2010-04-08 13:20 107,808 a——- c:\windows\system32\dns-sd.exe
2010-04-08 13:20 91,424 a——- c:\windows\system32\dnssd.dll

==================== Find3M ====================

2010-05-02 01:32 143,360 a——- c:\windows\inf\infstrng.dat
2010-05-02 01:32 51,200 a——- c:\windows\inf\infpub.dat
2010-04-29 15:39 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 15:39 20,952 a——- c:\windows\system32\drivers\mbam.sys
2010-04-03 23:03 86,016 a——- c:\windows\inf\infstor.dat
2010-02-23 07:39 916,480 a——- c:\windows\system32\wininet.dll
2010-02-23 07:33 109,056 a——- c:\windows\system32\iesysprep.dll
2010-02-23 07:33 71,680 a——- c:\windows\system32\iesetup.dll
2010-02-23 05:55 133,632 a——- c:\windows\system32\ieUnatt.exe
2010-02-12 11:32 293,376 a——- c:\windows\system32\browserchoice.exe
2009-10-31 16:04 665,600 a——- c:\windows\inf\drvindex.dat
2008-01-21 03:57 174 a–sh— c:\program files\desktop.ini
2006-11-02 13:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 13:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 13:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 13:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 21:51:43.56 ===============

Attachments:

Hello manicd and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
🖼Click to load external image (Posted Image) You are infected with a trojan know to sometimes have backdoor properties. Backdoor Trojans are very dangerous because they use advanced techniques (backdoors) to steal sensitive information which they send back to the hacker. All passwords should be changed immediately using a different computer and, if necessary, banking and credit card institutions should be notified of the possible security breach.

🖼Click to load external image (Posted Image) Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • ComboFix log
Hi RPMcMurphy & thanks for helping me out with my logs.


ComboFix 10-05-10.05 - Dan 11/05/2010 21:02:53.6.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.44.1033.18.3000.1766 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\WTT - Virus Treatment\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-04-11 to 2010-05-11 )))))))))))))))))))))))))))))))
.

2010-05-11 20:06 . 2010-05-11 20:06 ——– d—–w- c:\users\Dan\AppData\Local\temp
2010-05-11 20:06 . 2010-05-11 20:06 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-05-11 20:06 . 2010-05-11 20:06 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-05-11 20:02 . 2010-05-11 20:02 ——– d—–w- C:\32788R22FWJFW
2010-05-11 18:01 . 2010-01-29 15:40 738816 —-a-w- c:\windows\system32\inetcomm.dll
2010-05-02 00:47 . 2010-05-02 00:47 ——– d—–w- c:\program files\iPod
2010-05-02 00:30 . 2010-05-02 00:30 ——– d—–w- c:\program files\Bonjour
2010-05-02 00:26 . 2010-05-02 00:26 73000 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-04-17 19:51 . 2010-04-17 19:51 ——– d—–w- c:\program files\Common Files\Java
2010-04-17 19:50 . 2010-04-17 19:50 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-04-13 18:26 . 2009-12-23 11:33 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-13 18:25 . 2010-02-18 14:07 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-13 18:25 . 2010-02-18 14:07 3600776 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-13 18:25 . 2010-02-23 11:10 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-13 18:25 . 2010-02-23 11:10 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-13 18:25 . 2010-02-23 11:10 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-13 18:25 . 2010-01-13 17:34 98304 —-a-w- c:\windows\system32\cabview.dll
2010-04-13 18:25 . 2010-03-05 14:01 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-04-13 18:25 . 2010-02-18 14:07 904576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-13 18:25 . 2010-02-18 11:28 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-13 18:25 . 2010-02-18 13:30 200704 —-a-w- c:\windows\system32\iphlpsvc.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-11 19:27 . 2009-11-14 00:31 ——– d—–w- c:\users\Dan\AppData\Roaming\vlc
2010-05-11 18:02 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-05-11 18:02 . 2008-04-17 15:58 ——– d—–w- c:\programdata\Microsoft Help
2010-05-11 10:16 . 2008-04-17 17:28 12 —-a-w- c:\windows\bthservsdp.dat
2010-05-08 12:15 . 2009-10-17 19:25 680 —-a-w- c:\users\Dan\AppData\Local\d3d9caps.dat
2010-05-02 01:47 . 2009-08-12 21:02 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-02 00:48 . 2009-09-17 18:51 ——– d—–w- c:\program files\iTunes
2010-05-02 00:47 . 2009-08-15 21:54 ——– d—–w- c:\program files\Common Files\Apple
2010-05-02 00:31 . 2009-08-15 21:57 ——– d—–w- c:\users\Dan\AppData\Roaming\Apple Computer
2010-04-29 14:39 . 2009-08-12 21:02 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2009-08-12 21:02 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-25 01:15 . 2009-09-20 00:52 ——– d—–w- c:\program files\CCleaner
2010-04-17 19:50 . 2009-08-14 19:23 ——– d—–w- c:\program files\Java
2010-04-12 22:32 . 2009-12-14 20:48 ——– d—–w- c:\users\Dan\AppData\Roaming\dvdcss
2010-04-08 12:20 . 2010-04-08 12:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-04-08 12:20 . 2010-04-08 12:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-04-03 22:12 . 2010-04-03 22:09 ——– d—–w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-03 22:05 . 2010-04-03 22:04 ——– d—–w- c:\program files\QuickTime
2010-04-02 23:52 . 2009-11-01 16:33 ——– d—–w- c:\users\Dan\AppData\Roaming\Ahead
2010-04-02 20:23 . 2010-04-02 20:23 ——– d—–w- c:\program files\OJOsoft
2010-03-31 22:42 . 2009-10-31 00:52 ——– d—–w- c:\program files\Common Files\Ahead
2010-03-31 22:40 . 2010-03-31 22:40 ——– d—–w- c:\program files\Nero
2010-03-31 22:40 . 2009-10-31 03:10 ——– d—–w- c:\programdata\Nero
2010-03-21 01:08 . 2009-08-15 20:31 ——– d—–w- c:\program files\Foxit Software
2010-03-14 18:10 . 2010-03-14 03:08 ——– d—–w- c:\program files\Seagate
2010-03-14 17:35 . 2008-04-17 15:24 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-14 17:35 . 2010-03-14 17:35 ——– d—–w- c:\programdata\Seagate
2010-02-24 22:01 . 2009-08-12 19:50 102760 —-a-w- c:\users\Dan\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-23 06:39 . 2010-03-31 06:38 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-31 06:38 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-02-23 06:33 . 2010-03-31 06:38 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-02-23 04:55 . 2010-03-31 06:38 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-02-12 10:32 . 2010-02-25 20:04 293376 —-a-w- c:\windows\system32\browserchoice.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-05 06:38 121392 —-a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-05 526896]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-05-12 167936]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-02-06 2021400]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-01-20 4359280]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2009-01-20 960536]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-01-20 377232]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-07-27 341312]
"LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2008-07-02 821768]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-28 6111232]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):b7,13,e5,ff,10,1d,ca,01

R2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [2009-03-18 86016]
R3 A310;AVerMedia A310 DVB-T;c:\windows\system32\DRIVERS\AVerA310USB.sys [2008-04-15 25856]
R3 BDASwCap;AVerMedia A310 BDA DVBT Capture Device;c:\windows\system32\drivers\AVerA310Cap.sys [2008-04-15 42880]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-09-02 112128]
R4 ADOK;ADOK;c:\users\Dan\AppData\Local\Temp\ADOK.exe [x]
R4 B;B;c:\users\Dan\AppData\Local\Temp\B.exe [x]
R4 CQXXVZ;CQXXVZ;c:\users\Dan\AppData\Local\Temp\CQXXVZ.exe [x]
R4 HSPUUYZKD;HSPUUYZKD;c:\users\Dan\AppData\Local\Temp\HSPUUYZKD.exe [x]
R4 Partner Service;Partner Service;c:\programdata\Partner\partner.exe [x]
R4 QRORZWSH;QRORZWSH;c:\users\Dan\AppData\Local\Temp\QRORZWSH.exe [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-05-09 61424]
S2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-02-06 727720]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-02-06 38240]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
S2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-03-28 210432]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-04-21 81296]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]
S3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-04-27 3658752]
S3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2009-08-12 30464]
S3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2009-08-12 12672]
S3 stppp;Speedtouch PPP Adapter Adapter;c:\windows\system32\DRIVERS\stppp.sys [2009-08-12 49408]
S3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [2007-03-28 43008]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-05-11 c:\windows\Tasks\User_Feed_Synchronization-{D168ECA3-CC9C-4137-B270-F22A1814A4CA}.job
- c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0809&s;=2&o;=vb32&d;=0809&m;=aspire_7730
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0809&s;=2&o;=vb32&d;=0809&m;=aspire_7730
TCP: {5F5C77F2-51C5-46C9-8645-7237001BADD8} = 212.139.132.107 212.139.132.11
FF - ProfilePath - c:\users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\c3wkt1ht.default\
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
.
——- File Associations ——-
.
.scr=AutoCADScriptFile
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-11 21:06
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\st330service]
"ImagePath"="C:\Program Files/Thomson/ST330/service/st330service.exe -service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(408)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
.
Completion time: 2010-05-11 21:08:47
ComboFix-quarantined-files.txt 2010-05-11 20:08
ComboFix2.txt 2010-05-11 19:56

Pre-Run: 34,180,198,400 bytes free
Post-Run: 34,147,606,528 bytes free

- - End Of File - - 325BBE0151DC2FBBC3568F9D233C580F

manicd,

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above Collect::

http://forums.whatthetech.com/Java_TrojanDownloader_Agent_NAN_t111934.html

KillAll::

Driver::
ADOK
CQXXVZ
HSPUUYZKD
QRORZWSH
Partner Service

Collect::
c:\users\Dan\AppData\Local\Temp\ADOK.exe
c:\users\Dan\AppData\Local\Temp\B.exe
c:\users\Dan\AppData\Local\Temp\CQXXVZ.exe
c:\users\Dan\AppData\Local\Temp\HSPUUYZKD.exe
c:\users\Dan\AppData\Local\Temp\QRORZWSH.exe
c:\programdata\Partner\partner.exe

Folder::
c:\programdata\Partner

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Please include the following in your next post:
  • ComboFix log
RPMcMurphy,

I'm assuming you didn't want me to include http://forums.whatthetech.com/Java_TrojanDownloader_Agent_NAN_t111934.html quoted in the Codebox in the CFScript.txt file?


ComboFix 10-05-13.02 - Dan 13/05/2010 23:15:29.10.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.44.1033.18.3000.1748 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\WTT - Virus Treatment\ComboFix.exe
Command switches used :: c:\users\Dan\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active

.

((((((((((((((((((((((((( Files Created from 2010-04-13 to 2010-05-13 )))))))))))))))))))))))))))))))
.

2010-05-13 22:20 . 2010-05-13 22:21 ——– d—–w- c:\users\Dan\AppData\Local\temp
2010-05-13 22:20 . 2010-05-13 22:20 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-05-13 22:20 . 2010-05-13 22:20 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-05-11 21:08 . 2010-05-11 21:08 181096 —-a-w- c:\users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\c3wkt1ht.default\FlashGot.exe
2010-05-11 18:01 . 2010-01-29 15:40 738816 —-a-w- c:\windows\system32\inetcomm.dll
2010-05-02 00:47 . 2010-05-02 00:47 ——– d—–w- c:\program files\iPod
2010-05-02 00:30 . 2010-05-02 00:30 ——– d—–w- c:\program files\Bonjour
2010-05-02 00:26 . 2010-05-02 00:26 73000 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-04-17 19:51 . 2010-04-17 19:51 ——– d—–w- c:\program files\Common Files\Java
2010-04-17 19:50 . 2010-04-17 19:50 411368 —-a-w- c:\windows\system32\deployJava1.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-13 22:20 . 2008-04-17 17:28 12 —-a-w- c:\windows\bthservsdp.dat
2010-05-13 21:09 . 2009-11-14 00:31 ——– d—–w- c:\users\Dan\AppData\Roaming\vlc
2010-05-11 18:02 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-05-11 18:02 . 2008-04-17 15:58 ——– d—–w- c:\programdata\Microsoft Help
2010-05-08 12:15 . 2009-10-17 19:25 680 —-a-w- c:\users\Dan\AppData\Local\d3d9caps.dat
2010-05-02 01:47 . 2009-08-12 21:02 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-02 00:48 . 2009-09-17 18:51 ——– d—–w- c:\program files\iTunes
2010-05-02 00:47 . 2009-08-15 21:54 ——– d—–w- c:\program files\Common Files\Apple
2010-05-02 00:31 . 2009-08-15 21:57 ——– d—–w- c:\users\Dan\AppData\Roaming\Apple Computer
2010-04-29 14:39 . 2009-08-12 21:02 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2009-08-12 21:02 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-25 01:15 . 2009-09-20 00:52 ——– d—–w- c:\program files\CCleaner
2010-04-17 19:50 . 2009-08-14 19:23 ——– d—–w- c:\program files\Java
2010-04-12 22:32 . 2009-12-14 20:48 ——– d—–w- c:\users\Dan\AppData\Roaming\dvdcss
2010-04-08 12:20 . 2010-04-08 12:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-04-08 12:20 . 2010-04-08 12:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-04-03 22:12 . 2010-04-03 22:09 ——– d—–w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-03 22:05 . 2010-04-03 22:04 ——– d—–w- c:\program files\QuickTime
2010-04-02 23:52 . 2009-11-01 16:33 ——– d—–w- c:\users\Dan\AppData\Roaming\Ahead
2010-04-02 20:23 . 2010-04-02 20:23 ——– d—–w- c:\program files\OJOsoft
2010-03-31 22:42 . 2009-10-31 00:52 ——– d—–w- c:\program files\Common Files\Ahead
2010-03-31 22:40 . 2010-03-31 22:40 ——– d—–w- c:\program files\Nero
2010-03-31 22:40 . 2009-10-31 03:10 ——– d—–w- c:\programdata\Nero
2010-03-21 01:08 . 2009-08-15 20:31 ——– d—–w- c:\program files\Foxit Software
2010-03-05 14:01 . 2010-04-13 18:25 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-24 22:01 . 2009-08-12 19:50 102760 —-a-w- c:\users\Dan\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-23 11:10 . 2010-04-13 18:25 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-23 11:10 . 2010-04-13 18:25 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-02-23 11:10 . 2010-04-13 18:25 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 06:39 . 2010-03-31 06:38 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-31 06:38 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-02-23 06:33 . 2010-03-31 06:38 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-02-23 04:55 . 2010-03-31 06:38 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-02-18 14:07 . 2010-04-13 18:25 904576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-18 14:07 . 2010-04-13 18:25 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-18 14:07 . 2010-04-13 18:25 3600776 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-18 13:30 . 2010-04-13 18:25 200704 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-02-18 11:28 . 2010-04-13 18:25 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-05 06:38 121392 —-a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-05 526896]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-05-12 167936]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-02-06 2021400]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-01-20 4359280]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2009-01-20 960536]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-01-20 377232]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-07-27 341312]
"LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2008-07-02 821768]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-28 6111232]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):b7,13,e5,ff,10,1d,ca,01

R2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [2009-03-18 86016]
R3 A310;AVerMedia A310 DVB-T;c:\windows\system32\DRIVERS\AVerA310USB.sys [2008-04-15 25856]
R3 BDASwCap;AVerMedia A310 BDA DVBT Capture Device;c:\windows\system32\drivers\AVerA310Cap.sys [2008-04-15 42880]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-09-02 112128]
R4 B;B;c:\users\Dan\AppData\Local\Temp\B.exe [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-05-09 61424]
S2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-02-06 727720]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-02-06 38240]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
S2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-03-28 210432]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-04-21 81296]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]
S3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-04-27 3658752]
S3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2009-08-12 30464]
S3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2009-08-12 12672]
S3 stppp;Speedtouch PPP Adapter Adapter;c:\windows\system32\DRIVERS\stppp.sys [2009-08-12 49408]
S3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [2007-03-28 43008]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-05-13 c:\windows\Tasks\User_Feed_Synchronization-{D168ECA3-CC9C-4137-B270-F22A1814A4CA}.job
- c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0809&s;=2&o;=vb32&d;=0809&m;=aspire_7730
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0809&s;=2&o;=vb32&d;=0809&m;=aspire_7730
TCP: {5F5C77F2-51C5-46C9-8645-7237001BADD8} = 212.139.132.107 212.139.132.11
FF - ProfilePath - c:\users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\c3wkt1ht.default\
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-13 23:21
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\st330service]
"ImagePath"="C:\Program Files/Thomson/ST330/service/st330service.exe -service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(1948)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
.
———————— Other Running Processes ————————
.
c:\program files\Thomson\ST330\service\st330service.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Seagate\Basics\Service\SyncServicesBasics.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2010-05-13 23:26:02 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-13 22:25
ComboFix2.txt 2010-05-13 22:01
ComboFix3.txt 2010-05-13 20:25
ComboFix4.txt 2010-05-11 20:37
ComboFix5.txt 2010-05-13 22:14

Pre-Run: 32,596,336,640 bytes free
Post-Run: 32,559,669,248 bytes free

- - End Of File - - A02AEC706CF441385B525610FE45AE29

manicd,

Actually, you did need to include that. Don't worry about it right now though. It looks like you ran ComboFix 3 times today - I need you to do this so I can see what happened:

🖼Click to load external image (Posted Image) Click Start > Run or press Windows Key + R copy/paste the following into the run box that opens and press OK:
ComboFix-quarantined-files.txt

Please post the file that opens.
Hi RPMcMurphy

🖼Click to load external image (Posted Image) Click Start > Run or press Windows Key + R copy/paste the following into the run box that opens and press OK:
ComboFix-quarantined-files.txt
Please post the file that opens.

Sorry this popped up when I done that, so I retrieved the log file from; C:\Qoobox. I hope that's OK?
📎ComboFix.jpg

2010-05-13 20:18:04 . 2010-05-13 20:18:04 1,082 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_QRORZWSH.reg.dat
2010-05-13 20:18:04 . 2010-05-13 20:18:04 1,150 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_Partner Service.reg.dat
2010-05-13 20:18:04 . 2010-05-13 20:18:04 1,426 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_HSPUUYZKD.reg.dat
2010-05-13 20:18:04 . 2010-05-13 20:18:04 1,366 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_CQXXVZ.reg.dat
2010-05-13 20:18:03 . 2010-05-13 20:18:03 1,326 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Service_ADOK.reg.dat
2010-05-13 20:18:03 . 2010-05-13 20:18:03 814 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_HSPUUYZKD.reg.dat
2010-05-13 20:18:03 . 2010-05-13 20:18:03 790 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_CQXXVZ.reg.dat
2010-05-13 20:18:03 . 2010-05-13 20:18:03 774 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_ADOK.reg.dat
2010-05-11 20:30:23 . 2010-05-13 22:15:28 1,241 —-a-w- C:\Qoobox\Quarantine\catchme.txt
2010-05-11 19:53:08 . 2010-05-13 22:18:33 4,905 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2010-05-11 19:48:10 . 2010-05-13 22:15:22 463 —-a-w- C:\Qoobox\Quarantine\catchme.log

manicd,

That was exactly what I wanted. Here are your next instructions:

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above KillAll::

KillAll::

Driver::
B

File::
c:\users\Dan\AppData\Local\Temp\B.exe

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

🖼Click to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • ComboFix log
  • MBAM log
  • Kaspersky log
  • How is the computer running now?

Here are your next instructions:
🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above KillAll::

KillAll::

Driver::
B

File::
c:\users\Dan\AppData\Local\Temp\B.exe

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.


Combofix keeps on asking me to update & has frozen while performing the above instructions; I'll give it another go?
Ok here we go,



CoboFix Log

—————————–
ComboFix 10-05-14.05 - Dan 14/05/2010  21:52:03.12.2 - x86
Microsoft® Windows Vista™ Home Basic   6.0.6002.2.1252.44.1033.18.3000.1910 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Dan\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
 * Resident AV is active


FILE ::
"c:\users\Dan\AppData\Local\Temp\B.exe"
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_B
——-\Service_B


(((((((((((((((((((((((((   Files Created from 2010-04-14 to 2010-05-14  )))))))))))))))))))))))))))))))
.

2010-05-14 20:56 . 2010-05-14 20:58	——–	d—–w-	c:\users\Dan\AppData\Local\temp
2010-05-14 20:56 . 2010-05-14 20:56	——–	d—–w-	c:\users\Public\AppData\Local\temp
2010-05-14 20:56 . 2010-05-14 20:56	——–	d—–w-	c:\users\Default\AppData\Local\temp
2010-05-11 18:01 . 2010-01-29 15:40	738816	—-a-w-	c:\windows\system32\inetcomm.dll
2010-05-02 00:47 . 2010-05-02 00:47	——–	d—–w-	c:\program files\iPod
2010-05-02 00:30 . 2010-05-02 00:30	——–	d—–w-	c:\program files\Bonjour
2010-04-17 19:51 . 2010-04-17 19:51	——–	d—–w-	c:\program files\Common Files\Java
2010-04-17 19:50 . 2010-04-17 19:50	411368	—-a-w-	c:\windows\system32\deployJava1.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-14 20:57 . 2008-04-17 17:28	12	—-a-w-	c:\windows\bthservsdp.dat
2010-05-14 20:32 . 2009-11-14 00:31	——–	d—–w-	c:\users\Dan\AppData\Roaming\vlc
2010-05-11 21:08 . 2010-05-11 21:08	181096	—-a-w-	c:\users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\c3wkt1ht.default\FlashGot.exe
2010-05-11 18:02 . 2006-11-02 11:18	——–	d—–w-	c:\program files\Windows Mail
2010-05-11 18:02 . 2008-04-17 15:58	——–	d—–w-	c:\programdata\Microsoft Help
2010-05-08 12:15 . 2009-10-17 19:25	680	—-a-w-	c:\users\Dan\AppData\Local\d3d9caps.dat
2010-05-02 01:47 . 2009-08-12 21:02	——–	d—–w-	c:\program files\Malwarebytes' Anti-Malware
2010-05-02 00:48 . 2009-09-17 18:51	——–	d—–w-	c:\program files\iTunes
2010-05-02 00:47 . 2009-08-15 21:54	——–	d—–w-	c:\program files\Common Files\Apple
2010-05-02 00:31 . 2009-08-15 21:57	——–	d—–w-	c:\users\Dan\AppData\Roaming\Apple Computer
2010-05-02 00:26 . 2010-05-02 00:26	73000	—-a-w-	c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-04-29 14:39 . 2009-08-12 21:02	38224	—-a-w-	c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2009-08-12 21:02	20952	—-a-w-	c:\windows\system32\drivers\mbam.sys
2010-04-25 01:15 . 2009-09-20 00:52	——–	d—–w-	c:\program files\CCleaner
2010-04-17 19:50 . 2009-08-14 19:23	——–	d—–w-	c:\program files\Java
2010-04-12 22:32 . 2009-12-14 20:48	——–	d—–w-	c:\users\Dan\AppData\Roaming\dvdcss
2010-04-08 12:20 . 2010-04-08 12:20	91424	—-a-w-	c:\windows\system32\dnssd.dll
2010-04-08 12:20 . 2010-04-08 12:20	107808	—-a-w-	c:\windows\system32\dns-sd.exe
2010-04-03 22:12 . 2010-04-03 22:09	——–	d—–w-	c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-03 22:05 . 2010-04-03 22:04	——–	d—–w-	c:\program files\QuickTime
2010-04-02 23:52 . 2009-11-01 16:33	——–	d—–w-	c:\users\Dan\AppData\Roaming\Ahead
2010-04-02 20:23 . 2010-04-02 20:23	——–	d—–w-	c:\program files\OJOsoft
2010-03-31 22:42 . 2009-10-31 00:52	——–	d—–w-	c:\program files\Common Files\Ahead
2010-03-31 22:40 . 2010-03-31 22:40	——–	d—–w-	c:\program files\Nero
2010-03-31 22:40 . 2009-10-31 03:10	——–	d—–w-	c:\programdata\Nero
2010-03-21 01:08 . 2009-08-15 20:31	——–	d—–w-	c:\program files\Foxit Software
2010-03-05 14:01 . 2010-04-13 18:25	420352	—-a-w-	c:\windows\system32\vbscript.dll
2010-02-24 22:01 . 2009-08-12 19:50	102760	—-a-w-	c:\users\Dan\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-23 11:10 . 2010-04-13 18:25	212992	—-a-w-	c:\windows\system32\drivers\mrxsmb10.sys
2010-02-23 11:10 . 2010-04-13 18:25	79360	—-a-w-	c:\windows\system32\drivers\mrxsmb20.sys
2010-02-23 11:10 . 2010-04-13 18:25	106496	—-a-w-	c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 06:39 . 2010-03-31 06:38	916480	—-a-w-	c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-31 06:38	109056	—-a-w-	c:\windows\system32\iesysprep.dll
2010-02-23 06:33 . 2010-03-31 06:38	71680	—-a-w-	c:\windows\system32\iesetup.dll
2010-02-23 04:55 . 2010-03-31 06:38	133632	—-a-w-	c:\windows\system32\ieUnatt.exe
2010-02-18 14:07 . 2010-04-13 18:25	904576	—-a-w-	c:\windows\system32\drivers\tcpip.sys
2010-02-18 14:07 . 2010-04-13 18:25	3548040	—-a-w-	c:\windows\system32\ntoskrnl.exe
2010-02-18 14:07 . 2010-04-13 18:25	3600776	—-a-w-	c:\windows\system32\ntkrnlpa.exe
2010-02-18 13:30 . 2010-04-13 18:25	200704	—-a-w-	c:\windows\system32\iphlpsvc.dll
2010-02-18 11:28 . 2010-04-13 18:25	25088	—-a-w-	c:\windows\system32\drivers\tunnel.sys
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-05 06:38	121392	—-a-w-	c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-05 526896]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-05-12 167936]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-02-06 2021400]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-01-20 4359280]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2009-01-20 960536]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-01-20 377232]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-07-27 341312]
"LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2008-07-02 821768]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-28 6111232]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):b7,13,e5,ff,10,1d,ca,01

R2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [2009-03-18 86016]
R3 A310;AVerMedia A310 DVB-T;c:\windows\system32\DRIVERS\AVerA310USB.sys [2008-04-15 25856]
R3 BDASwCap;AVerMedia A310 BDA DVBT Capture Device;c:\windows\system32\drivers\AVerA310Cap.sys [2008-04-15 42880]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-09-02 112128]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [2008-05-09 61424]
S2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-02-06 727720]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2009-02-06 38240]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-04-29 304464]
S2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-03-28 210432]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-04-21 81296]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-04-29 20952]
S3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-04-27 3658752]
S3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2009-08-12 30464]
S3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2009-08-12 12672]
S3 stppp;Speedtouch PPP Adapter Adapter;c:\windows\system32\DRIVERS\stppp.sys [2009-08-12 49408]
S3 winbondcir;Winbond IR Transceiver;c:\windows\system32\DRIVERS\winbondcir.sys [2007-03-28 43008]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork	REG_MULTI_SZ   	PLA DPS BFE mpssvc
bthsvcs	REG_MULTI_SZ   	BthServ
LocalServiceAndNoImpersonation	REG_MULTI_SZ   	FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-05-14 c:\windows\Tasks\User_Feed_Synchronization-{D168ECA3-CC9C-4137-B270-F22A1814A4CA}.job
- c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=0809&m=aspire_7730
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&s=2&o=vb32&d=0809&m=aspire_7730
TCP: {5F5C77F2-51C5-46C9-8645-7237001BADD8} = 212.139.132.36 212.74.114.213
FF - ProfilePath - c:\users\Dan\AppData\Roaming\Mozilla\Firefox\Profiles\c3wkt1ht.default\
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pre
f", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation",  false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-14 21:58
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …  

scanning hidden autostart entries … 

scanning hidden files …  

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\st330service]
"ImagePath"="C:\Program Files/Thomson/ST330/service/st330service.exe -service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(3028)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
.
———————— Other Running Processes ————————
.
c:\program files\Thomson\ST330\service\st330service.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Seagate\Basics\Service\SyncServicesBasics.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2010-05-14  22:03:06 - machine was rebooted
ComboFix-quarantined-files.txt  2010-05-14 21:03
ComboFix2.txt  2010-05-13 22:26
ComboFix3.txt  2010-05-13 22:01
ComboFix4.txt  2010-05-13 20:25
ComboFix5.txt  2010-05-14 20:00

Pre-Run: 35,126,046,720 bytes free
Post-Run: 35,099,025,408 bytes free

- - End Of File - - E9859A4E07F91C0C2DD489AFBFABA7D0


MBAM Log
—————————–
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4079

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18904

14/05/2010 22:25:33
mbam-log-2010-05-14 (22-25-33).txt

Scan type: Quick scan
Objects scanned: 119534
Time elapsed: 4 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Kaspersky Log
———————–
KASPERSKY ONLINE SCANNER 7.0: scan report
 Saturday, May 15, 2010
 Operating system: Microsoft Windows Vista Home Basic Edition, 32-bit Service Pack 2 (build 6002)
 Kaspersky Online Scanner version: 7.0.26.13
 Last database update: Friday, May 14, 2010 16:05:00
 Records in database: 4111952
——————————————————————————–

Scan settings:
	scan using the following database: extended
	Scan archives: yes
	Scan e-mail databases: yes

Scan area - My Computer:
	C:\
	D:\
	E:\
	G:\

Scan statistics:
	Objects scanned: 109890
	Threats found: 0
	Infected objects found: 0
	Suspicious objects found: 0
	Scan duration: 02:42:38

No threats found. Scanned area is clean.

Selected area has been scanned.


I had a fake Antivirus Pop-Up the over day but apart from that, good.
Could you you briefly explain what those files in my HOST folder are please?
📎Host_Location.jpg

:thumbup:

Edit: Off to bed, back in the morning.
manicd,

The files themselves are normal. The different date formats are odd though. Let's check them just to be sure:

🖼Click to load external image (Posted Image) Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
virscan.org
Virus Total

click on Browse, and upload the following file for analysis:
c:\Windows\System32\drivers\etc\lmhosts.sam
c:\Windows\System32\drivers\etc\networks
c:\Windows\System32\drivers\etc\protocol
c:\Windows\System32\drivers\etc\services


Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.
c:\Windows\System32\drivers\etc\lmhosts.sam

File lmhosts.sam received on 2010.05.15 17:18:14 (UTC)
Antivirus	Version	Last Update	Result
a-squared	4.5.0.50	2010.05.10	-
AhnLab-V3	2010.05.15.00	2010.05.14	-
AntiVir	8.2.1.242	2010.05.14	-
Antiy-AVL	2.0.3.7	2010.05.14	-
Authentium	5.2.0.5	2010.05.15	-
Avast	4.8.1351.0	2010.05.15	-
Avast5	5.0.332.0	2010.05.15	-
AVG	9.0.0.787	2010.05.15	-
BitDefender	7.2	2010.05.15	-
CAT-QuickHeal	10.00	2010.05.15	-
ClamAV	0.96.0.3-git	2010.05.15	-
Comodo	4849	2010.05.15	-
DrWeb	5.0.2.03300	2010.05.15	-
eSafe	7.0.17.0	2010.05.13	-
eTrust-Vet	35.2.7490	2010.05.15	-
F-Prot	4.5.1.85	2010.05.15	-
F-Secure	9.0.15370.0	2010.05.15	-
Fortinet	4.1.133.0	2010.05.15	-
GData	21	2010.05.15	-
Ikarus	T3.1.1.84.0	2010.05.15	-
Jiangmin	13.0.900	2010.05.15	-
Kaspersky	7.0.0.125	2010.05.15	-
McAfee	5.400.0.1158	2010.05.15	-
McAfee-GW-Edition	2010.1	2010.05.15	-
Microsoft	1.5703	2010.05.14	-
NOD32	5117	2010.05.15	-
Norman	6.04.12	2010.05.15	-
nProtect	2010-05-15.01	2010.05.15	-
Panda	10.0.2.7	2010.05.15	-
PCTools	7.0.3.5	2010.05.15	-
Prevx	3.0	2010.05.15	-
Rising	22.47.04.03	2010.05.14	-
Sophos	4.53.0	2010.05.15	-
Sunbelt	6306	2010.05.15	-
Symantec	20101.1.0.89	2010.05.15	-
TheHacker	6.5.2.0.280	2010.05.14	-
TrendMicro	9.120.0.1004	2010.05.15	-
TrendMicro-HouseCall	9.120.0.1004	2010.05.15	-
VBA32	3.12.12.5	2010.05.14	-
ViRobot	2010.5.15.2318	2010.05.15	-
VirusBuster	5.0.27.0	2010.05.15	-
Additional information
File size: 3683 bytes
MD5…: 18413b90e1b291ec3e777a845c37cfee
SHA1..: 241c7d823d1842fc454ccfdd5d9d1965938fac56
SHA256: 000fe9c924b4d155477cad15b4cfd30616c37523b4b848d6ecbd003507a55edf
ssdeep: 96:OD5clTEYBrMD7oYQoHkWo6IGJADrGTq7HXWP:uY1MPQmfoaJ8GTq73W
PEiD..: - PEInfo: - RDS…: NSRL Reference Data Set
- pdfid.: - trid..: Unknown! sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: Microsoft Windows 2000 Publisher
Microsoft Windows Verification Intermediate PCA
Microsoft Root Authority
signing date.: 9:05 PM 7/27/2000
verified…..: -
Antivirus;Version;Last Update;Result a-squared;4.5.0.50;2010.05.10;- AhnLab-V3;2010.05.15.00;2010.05.14;- AntiVir;8.2.1.242;2010.05.14;- Antiy-AVL;2.0.3.7;2010.05.14;- Authentium;5.2.0.5;2010.05.15;- Avast;4.8.1351.0;2010.05.15;- Avast5;5.0.332.0;2010.05.15;- AVG;9.0.0.787;2010.05.15;- BitDefender;7.2;2010.05.15;- CAT-QuickHeal;10.00;2010.05.15;- ClamAV;0.96.0.3-git;2010.05.15;- Comodo;4849;2010.05.15;- DrWeb;5.0.2.03300;2010.05.15;- eSafe;7.0.17.0;2010.05.13;- eTrust-Vet;35.2.7490;2010.05.15;- F-Prot;4.5.1.85;2010.05.15;- F-Secure;9.0.15370.0;2010.05.15;- Fortinet;4.1.133.0;2010.05.15;- GData;21;2010.05.15;- Ikarus;T3.1.1.84.0;2010.05.15;- Jiangmin;13.0.900;2010.05.15;- Kaspersky;7.0.0.125;2010.05.15;- McAfee;5.400.0.1158;2010.05.15;- McAfee-GW-Edition;2010.1;2010.05.15;- Microsoft;1.5703;2010.05.14;- NOD32;5117;2010.05.15;- Norman;6.04.12;2010.05.15;- nProtect;2010-05-15.01;2010.05.15;- Panda;10.0.2.7;2010.05.15;- PCTools;[removed];2010.05.15;- Prevx;3.0;2010.05.15;- Rising;22.47.04.03;2010.05.14;- Sophos;4.53.0;2010.05.15;- Sunbelt;6306;2010.05.15;- Symantec;20101.1.0.89;2010.05.15;- TheHacker;6.5.2.0.280;2010.05.14;- TrendMicro;9.120.0.1004;2010.05.15;- TrendMicro-HouseCall;9.120.0.1004;2010.05.15;- VBA32;[removed];2010.05.14;- ViRobot;2010.5.15.2318;2010.05.15;- VirusBuster;[removed];2010.05.15;- Additional information File size: 3683 bytes MD5…: 18413b90e1b291ec3e777a845c37cfee SHA1..: 241c7d823d1842fc454ccfdd5d9d1965938fac56 SHA256: 000fe9c924b4d155477cad15b4cfd30616c37523b4b848d6ecbd003507a55edf ssdeep: 96:OD5clTEYBrMD7oYQoHkWo6IGJADrGTq7HXWP:uY1MPQmfoaJ8GTq73W
PEiD..: - PEInfo: - RDS…: NSRL Reference Data Set
- pdfid.: - trid..: Unknown! sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: Microsoft Windows 2000 Publisher
Microsoft Windows Verification Intermediate PCA
Microsoft Root Authority
signing date.: 9:05 PM 7/27/2000
verified…..: -

c:\Windows\System32\drivers\etc\networks

File networks received on 2010.05.15 17:23:53 (UTC)
Antivirus	Version	Last Update	Result
a-squared	4.5.0.50	2010.05.10	-
AhnLab-V3	2010.05.15.00	2010.05.14	-
AntiVir	8.2.1.242	2010.05.14	-
Antiy-AVL	2.0.3.7	2010.05.14	-
Authentium	5.2.0.5	2010.05.15	-
Avast	4.8.1351.0	2010.05.15	-
Avast5	5.0.332.0	2010.05.15	-
AVG	9.0.0.787	2010.05.15	-
BitDefender	7.2	2010.05.15	-
CAT-QuickHeal	10.00	2010.05.15	-
ClamAV	0.96.0.3-git	2010.05.15	-
Comodo	4849	2010.05.15	-
DrWeb	5.0.2.03300	2010.05.15	-
eSafe	7.0.17.0	2010.05.13	-
eTrust-Vet	35.2.7490	2010.05.15	-
F-Prot	4.5.1.85	2010.05.15	-
F-Secure	9.0.15370.0	2010.05.15	-
Fortinet	4.1.133.0	2010.05.15	-
GData	21	2010.05.15	-
Ikarus	T3.1.1.84.0	2010.05.15	-
Jiangmin	13.0.900	2010.05.15	-
Kaspersky	7.0.0.125	2010.05.15	-
McAfee	5.400.0.1158	2010.05.15	-
McAfee-GW-Edition	2010.1	2010.05.15	-
Microsoft	1.5703	2010.05.14	-
NOD32	5117	2010.05.15	-
Norman	6.04.12	2010.05.15	-
nProtect	2010-05-15.01	2010.05.15	-
Panda	10.0.2.7	2010.05.15	-
PCTools	7.0.3.5	2010.05.15	-
Prevx	3.0	2010.05.15	-
Rising	22.47.04.03	2010.05.14	-
Sophos	4.53.0	2010.05.15	-
Sunbelt	6307	2010.05.15	-
Symantec	20101.1.0.89	2010.05.15	-
TheHacker	6.5.2.0.280	2010.05.14	-
TrendMicro	9.120.0.1004	2010.05.15	-
TrendMicro-HouseCall	9.120.0.1004	2010.05.15	-
VBA32	3.12.12.5	2010.05.14	-
ViRobot	2010.5.15.2318	2010.05.15	-
VirusBuster	5.0.27.0	2010.05.15	-
Additional information
File size: 407 bytes
MD5…: b65a1232fb4b35827ce7c5e2f8ec8947
SHA1..: a8da4c62aad9eeccbec6600c0e497139bcc4d67c
SHA256: 21de93ed8293dbb9c53b59a5c1af04b1fd997cf7dfbd0ba5f21cb315d845b7a8
ssdeep: 12:QcEzBFdC9o+z1Dm1ld0RSMCLKZzYiUrZFL7Ao6v:QbD89BhKdPMCLK2iUrf7A
o6v
PEiD..: - PEInfo: - RDS…: NSRL Reference Data Set
- pdfid.: - trid..: Unknown! sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: Microsoft Windows 2000 Publisher
Microsoft Windows Verification Intermediate PCA
Microsoft Root Authority
signing date.: 9:05 PM 7/27/2000
verified…..: -

c:\Windows\System32\drivers\etc\protocol

File protocol received on 2010.05.15 17:29:05 (UTC)
Antivirus	Version	Last Update	Result
a-squared	4.5.0.50	2010.05.10	-
AhnLab-V3	2010.05.15.00	2010.05.14	-
AntiVir	8.2.1.242	2010.05.14	-
Antiy-AVL	2.0.3.7	2010.05.14	-
Authentium	5.2.0.5	2010.05.15	-
Avast	4.8.1351.0	2010.05.15	-
Avast5	5.0.332.0	2010.05.15	-
AVG	9.0.0.787	2010.05.15	-
BitDefender	7.2	2010.05.15	-
CAT-QuickHeal	10.00	2010.05.15	-
ClamAV	0.96.0.3-git	2010.05.15	-
Comodo	4849	2010.05.15	-
DrWeb	5.0.2.03300	2010.05.15	-
eSafe	7.0.17.0	2010.05.13	-
eTrust-Vet	35.2.7490	2010.05.15	-
F-Prot	4.5.1.85	2010.05.15	-
F-Secure	9.0.15370.0	2010.05.15	-
Fortinet	4.1.133.0	2010.05.15	-
GData	21	2010.05.15	-
Ikarus	T3.1.1.84.0	2010.05.15	-
Jiangmin	13.0.900	2010.05.15	-
Kaspersky	7.0.0.125	2010.05.15	-
McAfee	5.400.0.1158	2010.05.15	-
McAfee-GW-Edition	2010.1	2010.05.15	-
Microsoft	1.5703	2010.05.14	-
NOD32	5117	2010.05.15	-
Norman	6.04.12	2010.05.15	-
nProtect	2010-05-15.01	2010.05.15	-
Panda	10.0.2.7	2010.05.15	-
PCTools	7.0.3.5	2010.05.15	-
Prevx	3.0	2010.05.15	-
Rising	22.47.04.03	2010.05.14	-
Sophos	4.53.0	2010.05.15	-
Sunbelt	6307	2010.05.15	-
Symantec	20101.1.0.89	2010.05.15	-
TheHacker	6.5.2.0.280	2010.05.14	-
TrendMicro	9.120.0.1004	2010.05.15	-
TrendMicro-HouseCall	9.120.0.1004	2010.05.15	-
VBA32	3.12.12.5	2010.05.14	-
ViRobot	2010.5.15.2318	2010.05.15	-
VirusBuster	5.0.27.0	2010.05.15	-
Additional information
File size: 1358 bytes
MD5…: 7700d22fa108234e623d65fa72d9e29c
SHA1..: 3e38922a5997f05920dd565ebc1d20c9cf105e4d
SHA256: 52cf86496f3859d0f3e58776eccff1d6589792004d2291d3b0ce8d7635be7278
ssdeep: 24:QDD/KKMOSLw23KzxOSjxFlrW1lFQKP8RMhT7lUMsbKP8vNegIyHQbJBUxCjPO
:qD/KKMps23Kzx/xFlrW1lmKP8RCT7lUT
PEiD..: - PEInfo: - RDS…: NSRL Reference Data Set
- pdfid.: - trid..: Unknown! sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

c:\Windows\System32\drivers\etc\services

File services received on 2010.05.15 17:31:28 (UTC)
Antivirus	Version	Last Update	Result
a-squared	4.5.0.50	2010.05.10	-
AhnLab-V3	2010.05.15.00	2010.05.14	-
AntiVir	8.2.1.242	2010.05.14	-
Antiy-AVL	2.0.3.7	2010.05.14	-
Authentium	5.2.0.5	2010.05.15	-
Avast	4.8.1351.0	2010.05.15	-
Avast5	5.0.332.0	2010.05.15	-
AVG	9.0.0.787	2010.05.15	-
BitDefender	7.2	2010.05.15	-
CAT-QuickHeal	10.00	2010.05.15	-
ClamAV	0.96.0.3-git	2010.05.15	-
Comodo	4849	2010.05.15	-
DrWeb	5.0.2.03300	2010.05.15	-
eSafe	7.0.17.0	2010.05.13	-
eTrust-Vet	35.2.7490	2010.05.15	-
F-Prot	4.5.1.85	2010.05.15	-
F-Secure	9.0.15370.0	2010.05.15	-
Fortinet	4.1.133.0	2010.05.15	-
GData	21	2010.05.15	-
Ikarus	T3.1.1.84.0	2010.05.15	-
Jiangmin	13.0.900	2010.05.15	-
Kaspersky	7.0.0.125	2010.05.15	-
McAfee	5.400.0.1158	2010.05.15	-
McAfee-GW-Edition	2010.1	2010.05.15	-
Microsoft	1.5703	2010.05.14	-
NOD32	5117	2010.05.15	-
Norman	6.04.12	2010.05.15	-
nProtect	2010-05-15.01	2010.05.15	-
Panda	10.0.2.7	2010.05.15	-
PCTools	7.0.3.5	2010.05.15	-
Prevx	3.0	2010.05.15	-
Rising	22.47.04.03	2010.05.14	-
Sophos	4.53.0	2010.05.15	-
Sunbelt	6307	2010.05.15	-
Symantec	20101.1.0.89	2010.05.15	-
TheHacker	6.5.2.0.280	2010.05.14	-
TrendMicro	9.120.0.1004	2010.05.15	-
TrendMicro-HouseCall	9.120.0.1004	2010.05.15	-
VBA32	3.12.12.5	2010.05.14	-
ViRobot	2010.5.15.2318	2010.05.15	-
VirusBuster	5.0.27.0	2010.05.15	-
Additional information
File size: 17244 bytes
MD5…: 9f534244b7f8f55d5c0bb498d8d481e7
SHA1..: 3a9de1611fe6d35c54e957a0ae50f02d8c6692a3
SHA256: 9fa97f95070a5be69925913e0046aaa0a728dd1d9ca3e7ec5fed1ff3dcbf6d13
ssdeep: 192:xjixOPIwOldq/rhraE8vvwavk5F/WGiJnhUPwIh6nePAi:Karar0F/WaZh6n
eoi
PEiD..: - PEInfo: - RDS…: NSRL Reference Data Set
- pdfid.: - trid..: Unknown! sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned


Seems to be all clear.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI