Spyware / Malware / Virus Removal
Please Help Me
15 min read
arbradio
Topic Starter
Hello,
Thanks again for the help you gave me last time. It appears as though another one of my students caused a problem on one of our other computers so here i am again. The computer is running very slow, the anti virus is saying it is being attacked and it detected and quarintined 70 viruses when I scanned it Sunday, please help me out, thank you in advance, here is my HiJack this log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:28:31 PM, on 9/21/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\system32\clipsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\tskstsh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Student\My Documents\Downloads\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = %USERNAME%
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SnapFlash Class - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - C:\WINDOWS\system32\jd2002.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [nod32] C:\DOCUME~1\Student\Local Settings\Temp\nodqq.exe
O4 - HKLM\..\Policies\Explorer\Run: [Altap] tskstsh
O4 - HKUS\S-1-5-19\..\RunOnce: [Set] fuset.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Help\Tours" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] rundll32 advpack.dll,DelNodeRunDLL32 "%SystemRoot%\System32\dllcache" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] cmd.exe /c md "%SystemRoot%\System32\dllcache" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_10] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_11] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_12] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_13] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [Set] fuset.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [Set] fuset.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Set] fuset.exe (User 'Default user')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: Save Flash with Flash Catcher - res://C:\WINDOWS\system32\IECatcher.DLL/FlashCatcher.htm
O9 - Extra button: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\WINDOWS\system32\IECatcher.DLL
O9 - Extra 'Tools' menuitem: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\WINDOWS\system32\IECatcher.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msnmsgr.exe
O9 - Extra 'Tools' menuitem: MSN Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msnmsgr.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
–
End of file - 6751 bytes
LDTate
Do you not have an IT department?
arbradio
Thanks for your response.
Our IT department is a guy that is supposedly a computer repair guy however his solution to everything is to run a virus scan or reformat the drives and reload windows. I probably wouldnt be telling you anything that you dont already know if I were to say that reformatting the drive or running a virus scan doesnt always fix the problem. So my dilemma is that because of our inept computer guy I am left holding the ball, and after trying to figure out how to fix it my searching led to hijack this that led me to your site.I am doing my best to keep this small school running smoothly, I dont have any computer training, I am learning as I go, I apologize for placing any burden on you and if it is too much trouble then I would understand if you did not choose to help me out.
So in short I guess the answer to your question would be, I am now the IT department……and due to my ignorance I am here trying to learn what to do in a situation such as the one I am in.
Thanks for your time!
Jeremy
LDTate
I know what you're saying
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
You might want to print these instructions out.
I suggest you do this:
XP Users
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.
Vista Users
To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:
Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.
Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:
If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.
If you are in the Control Panel Home view do the following:
Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.
Please do not delete anything unless instructed to.
Next:
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.
Next:
Please download Malwarebytes' Anti-Malware to your desktop.
Also please describe how your computer behaves at the moment.
Please don't attach the scans / logs, use "copy/paste".
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
You might want to print these instructions out.
I suggest you do this:
XP Users
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.
Vista Users
To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:
Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.
Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:
If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.
If you are in the Control Panel Home view do the following:
Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.
Please do not delete anything unless instructed to.
Next:
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.
Next:
Please download Malwarebytes' Anti-Malware to your desktop.
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
[external image: Posted Image] - When the scan is complete, click OK, then Show Results to view the results.
- [external image: Posted Image]
- Then click Remove Selected .
- When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
- Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also please describe how your computer behaves at the moment.
Please don't attach the scans / logs, use "copy/paste".
arbradio
Thank you for your assistance, I followed your instructions and the log is pasted below.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4704
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
9/27/2010 10:40:22 AM
mbam-log-2010-09-27 (10-40-22).txt
Scan type: Quick scan
Objects scanned: 140476
Time elapsed: 16 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 5
Files Infected: 108
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell\Evidence Eliminator Safe Recycle (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Eeshellx.ShellExt (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Evidence Eliminator (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Evidence Eliminator (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\forceclassiccontrolpanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
Folders Infected:
C:\Program Files\Evidence Eliminator (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Help (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Documents and Settings\Student\Start Menu\Programs\Evidence Eliminator (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\Evidence Eliminator\Ee.exe (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\INSTALL.LOG (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\License.txt (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\ReadMe.txt (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\UNWISE.EXE (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\UNWISE.INI (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Config.dat (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Drives.dat (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Files.dat (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\FilesContents.dat (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Folders.dat (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\FolderScans.dat (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\IECookiesKeep.dat (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\IEDownloadedKeep.dat (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\NSN4CookiesKeep.dat (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\OE5ChoiceList.dat (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\PlugInSelections.dat (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\ScanMasks.dat (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\AbsoluteFTP.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\ACDSEE Photo Viewer v3.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Adaptec Easy CD Creator v4.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Adobe Acrobat Reader v3.0.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Adobe Acrobat Reader v3.1.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Adobe Acrobat Reader v4.0.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Adobe Photoshop v5.0 LE.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Adobe Photoshop v5.5.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Adobe Photoshop v5.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Adobe Photoshop v6.0.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\ASPack.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Cabinet Manager.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Copernic 2000 Pro.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Copernic 2000.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Cute FTP v3.0.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Cute FTP v4.0.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Delphi v3.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Delphi v4.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Delphi v5.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\DiskKeeper v5.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Download Accelerator.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Eudora Mail.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\FTP Explorer.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\GetRight ExplorerBar.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\GetRight v4.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\GoZilla.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Helios TextPad v3.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Helios TextPad v4.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\HelpWriter.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Icon Extractor.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\ICQ 2000a.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\InstallShield Express.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\JASC Paintshop Pro v5.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\JASC Paintshop Pro v6.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\JASC Paintshop Pro v7.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Jet PhotoShell v1.2.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Macromedia Flash v4.0.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\MasterSplitter v2.1.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\McAfee Virus Scan v4.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Microangelo 98.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Micrografx Picture Publisher v7.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Micrografx Picture Publisher v8.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Microsoft FrontPage Express.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Microsoft FrontPage.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Microsoft Help Workshop.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Microsoft HTML Help.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Microsoft Office.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Microsoft Publisher 2000.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Microsoft Send-To Extensions.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Microsoft Windows Paint.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Microsoft Windows WordPad.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Napster Music Community.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\NEATO Labels.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\NeoPlanet v5.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Norton AntiVirus 2000 (v6).eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Norton File Manager.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Norton Utilities 2000.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\NoteTab Pro.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Opera Browser v4.02 Final.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Opera Browser.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\PackageForTheWeb.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Personal Ancestral File.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Real Audio Player v6 v7 v8.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Real Download v4.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\SureThing CD Labeler.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Telnet.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Ulead Gif Animator v4.0.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Ulead Photo Explorer v4.2.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Ulead Photo Viewer v4.0.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Ulead PhotoImpact v5.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Ulead PhotoImpact Viewer v4.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\UltraEdit v4.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\UltraEdit v7.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Web Ferret v3.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\WinOnCD.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\WinRar v2.6.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\WinRar v2.70.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\WinZip v7.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\WinZip v8.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Wise Installer.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Yahoo Player.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\ZipMagic 2000.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Data\Plug-Ins\Zone Alarm.eep (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Program Files\Evidence Eliminator\Help\ee.chm (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Documents and Settings\Student\Start Menu\Programs\Evidence Eliminator\Evidence Eliminator Help.lnk (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Documents and Settings\Student\Start Menu\Programs\Evidence Eliminator\Evidence Eliminator License Agreement.lnk (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Documents and Settings\Student\Start Menu\Programs\Evidence Eliminator\Evidence Eliminator Read Me.lnk (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\Documents and Settings\Student\Start Menu\Programs\Evidence Eliminator\Evidence Eliminator.lnk (Rogue.EvidenceEliminator) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sms.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winamp.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
arbradio
I forgot to mention that The PC still seems to run slo, it took a while to open firefox. and the control panel.
What can I do to prevent these things from happening? and where can I learn how to make these repairs myself? Are there classes I can take at the community college or online?
LDTate
Download ComboFix from one of these locations:
Link 1
Link 2 If using this link, Right Click and select Save As.
* IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.
Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it atleast 20-30 minutes to finish if needed.
Please do not attach the scan results from Combofx. Use copy/paste.
Also please describe how your computer behaves at the moment.
Link 1
Link 2 If using this link, Right Click and select Save As.
* IMPORTANT !!! Save ComboFix.exe to your Desktop
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
- Double click on ComboFix.exe & follow the prompts.
Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.
Note: If you have SP3, use the SP2 package.
If Vista or Windows 7, skip the Recovery Console part
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.
Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it atleast 20-30 minutes to finish if needed.
Please do not attach the scan results from Combofx. Use copy/paste.
Also please describe how your computer behaves at the moment.
arbradio
Hello again, the pc still seems to be operating slowly, freezing, if multiple windows are open it takes forever to perform a task. Thanks again for your help.
here is the combofix log:
ComboFix 10-09-27.03 - Student 09/27/2010 16:49:30.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.254.94 [GMT -6:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Icons
c:\windows\system32\Icons\Ball.png
c:\windows\system32\Icons\Clock.png
c:\windows\system32\Icons\Longhorn 5.png
c:\windows\system32\Icons\Longhorn.png
c:\windows\system32\pthreadVC.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_KKDC
——-\Service_AVPsys
((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-28 )))))))))))))))))))))))))))))))
.
2010-09-27 16:10 . 2010-09-27 16:10 ——– d—–w- c:\documents and settings\Student\Application Data\Malwarebytes
2010-09-27 16:10 . 2010-04-29 21:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-27 16:10 . 2010-09-27 16:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-27 16:10 . 2010-04-29 21:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-27 16:10 . 2010-09-27 16:10 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-09-23 22:37 . 2010-09-23 22:37 ——– d—–w- c:\documents and settings\Student\Application Data\ComodoGroup
2010-09-23 22:29 . 2010-09-23 22:29 ——– d—–w- c:\documents and settings\Student\Application DataComodoGroup
2010-09-22 21:48 . 2010-09-22 21:48 348160 —-a-w- c:\documents and settings\Student\Application Data\LimeWire\browser\xulrunner\msvcr71.dll
2010-09-22 21:48 . 2010-09-22 21:48 499712 —-a-w- c:\documents and settings\Student\Application Data\LimeWire\browser\xulrunner\MSVCP71.DLL
2010-09-22 21:48 . 2010-09-22 21:48 73728 —-a-w- c:\documents and settings\Student\Application Data\LimeWire\browser\xulrunner\xulrunner-stub.exe
2010-09-22 21:48 . 2010-09-22 21:48 102400 —-a-w- c:\documents and settings\Student\Application Data\LimeWire\browser\xulrunner\xulrunner.exe
2010-09-22 21:34 . 2010-09-23 23:00 ——– d—–w- c:\documents and settings\Student\Application Data\LimeWire
2010-09-19 19:38 . 2010-09-19 19:38 ——– d—–w- C:\VritualRoot
2010-09-19 19:37 . 2010-09-28 00:18 663201 —-a-w- c:\windows\system32\drivers\sfi.dat
2010-09-19 19:33 . 2010-09-19 19:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo
2010-09-19 19:32 . 2010-09-19 19:34 ——– d—–w- c:\program files\COMODO
2010-09-17 00:09 . 2010-09-17 00:09 ——– d—–w- c:\documents and settings\Student_2\Local Settings\Application Data\ESET
2010-09-16 22:39 . 2010-09-16 22:39 ——– d—–w- c:\documents and settings\Student_2\Application Data\Nero
2010-09-16 04:29 . 2010-09-16 04:29 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2010-09-15 23:46 . 2010-09-15 23:46 ——– d—–w- c:\documents and settings\Student\Local Settings\Application Data\ESET
2010-09-15 23:34 . 2010-09-15 23:34 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2010-09-15 22:36 . 2010-09-15 22:36 ——– d–h–we c:\documents and settings\All Users\AVP9
2010-09-15 14:25 . 2010-09-15 14:25 ——– d—–w- C:\found.000
2010-09-11 05:41 . 2010-09-11 05:41 285480 —-a-w- c:\windows\system32\guard32.dll
2010-09-11 05:40 . 2010-09-11 05:40 91560 —-a-w- c:\windows\system32\drivers\inspect.sys
2010-09-11 05:40 . 2010-09-11 05:40 25240 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-09-11 05:40 . 2010-09-11 05:40 239240 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-09-11 05:40 . 2010-09-11 05:40 15592 —-a-w- c:\windows\system32\drivers\cmderd.sys
2010-09-08 19:40 . 2006-01-01 01:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2010-09-03 00:16 . 2010-09-03 00:16 ——– d—–w- c:\documents and settings\All Users\Application Data\AVS4YOU
2010-09-03 00:15 . 2010-09-03 00:15 ——– d—–w- c:\documents and settings\Student\Application Data\AVS4YOU
2010-09-03 00:10 . 2008-11-24 18:00 974848 —-a-w- c:\windows\system32\mfc70.dll
2010-09-03 00:10 . 2008-11-24 18:00 487424 —-a-w- c:\windows\system32\msvcp70.dll
2010-09-03 00:10 . 2008-11-24 18:00 344064 —-a-w- c:\windows\system32\msvcr70.dll
2010-09-03 00:10 . 2008-11-24 18:00 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2010-09-03 00:09 . 2008-11-24 18:00 24576 —-a-w- c:\windows\system32\msxml3a.dll
2010-09-03 00:09 . 2010-09-19 19:07 ——– d—–w- c:\program files\Common Files\AVSMedia
2010-09-03 00:09 . 2010-09-19 19:07 ——– d—–w- c:\program files\AVS4YOU
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-27 23:25 . 2007-05-16 20:28 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-09-26 18:33 . 2007-05-18 15:32 ——– d—–w- c:\documents and settings\Student_2\Application Data\U3
2010-09-23 23:00 . 2010-08-15 18:51 ——– d—–w- c:\program files\LimeWire
2010-09-22 21:48 . 2010-09-22 21:47 8462336 —-a-w- c:\documents and settings\Student\Application Data\LimeWire\browser\xulrunner\xul.dll
2010-09-20 00:11 . 2008-08-05 03:35 ——– d—–w- c:\documents and settings\Student\Application Data\U3
2010-09-19 21:44 . 2007-05-18 20:15 ——– d—–w- c:\program files\Registry Cleaner Retail
2010-09-19 19:04 . 2009-10-02 17:31 ——– d—–w- c:\program files\CCleaner
2010-09-16 23:26 . 2007-05-23 11:55 ——– d—–w- c:\documents and settings\Student_2\Application Data\Ahead
2010-09-02 21:45 . 2007-05-18 19:08 ——– d—–w- c:\program files\Common Files\Adobe
2010-08-17 16:01 . 2010-08-17 16:01 503808 —-a-w- c:\documents and settings\Student_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-73aafb0d-n\msvcp71.dll
2010-08-17 16:01 . 2010-08-17 16:01 499712 —-a-w- c:\documents and settings\Student_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-73aafb0d-n\jmc.dll
2010-08-17 16:01 . 2010-08-17 16:01 348160 —-a-w- c:\documents and settings\Student_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-73aafb0d-n\msvcr71.dll
2010-08-17 16:01 . 2010-08-17 16:01 61440 —-a-w- c:\documents and settings\Student_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1a3820a7-n\decora-sse.dll
2010-08-17 16:01 . 2010-08-17 16:01 12800 —-a-w- c:\documents and settings\Student_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1a3820a7-n\decora-d3d.dll
2010-08-15 19:49 . 2010-08-15 19:49 ——– d—–w- c:\program files\Common Files\Java
2010-08-15 19:49 . 2010-08-15 19:49 503808 —-a-w- c:\documents and settings\Student\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5989bd6e-n\msvcp71.dll
2010-08-15 19:49 . 2010-08-15 19:49 499712 —-a-w- c:\documents and settings\Student\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5989bd6e-n\jmc.dll
2010-08-15 19:49 . 2010-08-15 19:49 348160 —-a-w- c:\documents and settings\Student\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5989bd6e-n\msvcr71.dll
2010-08-15 19:49 . 2010-08-15 19:49 12800 —-a-w- c:\documents and settings\Student\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-6e0f975b-n\decora-d3d.dll
2010-08-15 19:49 . 2010-08-15 19:49 61440 —-a-w- c:\documents and settings\Student\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-6e0f975b-n\decora-sse.dll
2010-08-15 19:48 . 2010-08-15 19:48 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-15 19:48 . 2010-08-15 19:48 ——– d—–w- c:\program files\Java
2010-08-04 23:34 . 2007-05-18 19:42 50272 -c–a-w- c:\documents and settings\Student_2\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-03 22:21 . 2007-05-18 19:26 50272 -c–a-w- c:\documents and settings\Student\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
——- Sigcheck ——-
[-] 2006-09-12 . 0EF6B94BFAB8D17209133946A0C31573 . 359808 . . [5.1.2600.2685] . . c:\windows\system32\drivers\tcpip.sys
[-] 2006-01-01 . C8061F289E000703E7672916B7FE1571 . 395776 . . [5.1.2600.2665] . . c:\windows\system32\rpcss.dll
[-] 2006-01-01 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\system32\spoolsv.exe
[-] 2006-01-01 . 0CE2796FA38B9B4301C7EDD03BF2F00F . 3680768 . . [6.00.2900.2722] . . c:\windows\system32\mshtml.dll
[-] 2006-01-01 . 939D1B8DE077337A6EBA221C83961C37 . 2341632 . . [5.1.2600.2622] . . c:\windows\system32\ntoskrnl.exe
[-] 2006-01-01 . 1418A3A6E76E5A2E3F5E43866E793A8B . 249344 . . [5.1.2600.2716] . . c:\windows\system32\tapisrv.dll
[-] 2006-01-01 . DE2DB164BBB35DB061AF0997E4499054 . 577024 . . [5.1.2600.2622] . . c:\windows\system32\user32.dll
[-] 2006-01-01 . E81E1599A2A74C672E4B7465F99C6287 . 841728 . . [6.00.2900.2713] . . c:\windows\system32\wininet.dll
[-] 2006-01-01 . E9FD784FE52ADAF58B3C896C1DCE378E . 2539008 . . [6.00.2900.2180] . . c:\windows\explorer.exe
[-] 2006-01-01 . 5950E4F28FDA9D147576BF6798937397 . 1285120 . . [5.1.2600.2665] . . c:\windows\system32\ole32.dll
[-] 2006-01-01 01:00 . A477391B7A8B0A0DAABADB17CF533A4B . 25088 . . [10.0.3790.3646] . . c:\windows\system32\mspmsnsv.dll
[-] 2006-01-01 . 9461A8867DC1F7CB2A51987DB87EADAE . 2219136 . . [5.1.2600.2622] . . c:\windows\system32\ntkrnlpa.exe
c:\windows\System32\wscntfy.exe … is missing !!
c:\windows\System32\regsvc.dll … is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-17 139264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF14562.cfxxe" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-07-21 126976]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-09-11 2500552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Set"="fuset.exe" [2006-01-01 70656]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-01-01 44544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Altap"="tskstsh" [X]
c:\documents and settings\Student\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-8-19 503808]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 10 (0xa)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2006-07-21 06:15 1848218 -c–a-w- c:\program files\Acronis\TrueImageEnterpriseServer\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2006-07-21 06:12 1106531 -c–a-w- c:\program files\Acronis\TrueImageEnterpriseServer\TrueImageMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Acronis\\TrueImageEnterpriseServer\\TrueImage.exe"=
"c:\\WINDOWS\\lsass.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
R0 CFRMD;CFRMD;c:\windows\System32\drivers\CFRMD.sys [x]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-10-03 19472]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [2010-09-11 15592]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2010-09-11 239240]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2009-09-14 32272]
— Other Services/Drivers In Memory —
*NewlyCreated* - HELPSVC
*NewlyCreated* - WUAUSERV
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-09-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 16:54]
2010-09-27 c:\windows\Tasks\COMODO System Cleaner Update.job
- c:\program files\COMODO\COMODO System-Cleaner\UpdateApplications.exe [2010-03-09 21:41]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
IE: Save Flash with Flash Catcher - c:\windows\system32\IECatcher.DLL/FlashCatcher.htm
FF - ProfilePath - c:\documents and settings\Student\Application Data\Mozilla\Firefox\Profiles\2sq0xh4g.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\KavLinkFilter.dll
FF - plugin: c:\documents and settings\Student\Application Data\Mozilla\Firefox\Profiles\2sq0xh4g.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
—- FIREFOX POLICIES —-
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: network.http.max-persistent-connections-per-server - 3
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-27 18:24
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1368)
c:\windows\system32\SETUPAPI.dll
- - - - - - - > 'lsass.exe'(1448)
c:\windows\system32\guard32.dll
c:\windows\system32\relog_ap.dll
c:\windows\system32\setupapi.dll
- - - - - - - > 'Explorer.EXE'(1548)
c:\windows\system32\guard32.dll
c:\windows\system32\shimgvw.dll
c:\progra~1\COMMON~1\MICROS~1\Web Components\11\OWC11.DLL
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\shdoclc.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\MSCTF.dll
c:\windows\system32\NETSHELL.dll
.
Completion time: 2010-09-27 18:34:37 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-28 00:34
Pre-Run: 57,488,429,056 bytes free
Post-Run: 59,400,839,168 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Unlimited" /noexecute=optin /fastdetect
- - End Of File - - 96D7B26A26199CD7D9A79B3B32A56D65
here is the combofix log:
ComboFix 10-09-27.03 - Student 09/27/2010 16:49:30.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.254.94 [GMT -6:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Icons
c:\windows\system32\Icons\Ball.png
c:\windows\system32\Icons\Clock.png
c:\windows\system32\Icons\Longhorn 5.png
c:\windows\system32\Icons\Longhorn.png
c:\windows\system32\pthreadVC.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_KKDC
——-\Service_AVPsys
((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-28 )))))))))))))))))))))))))))))))
.
2010-09-27 16:10 . 2010-09-27 16:10 ——– d—–w- c:\documents and settings\Student\Application Data\Malwarebytes
2010-09-27 16:10 . 2010-04-29 21:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-27 16:10 . 2010-09-27 16:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-27 16:10 . 2010-04-29 21:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-27 16:10 . 2010-09-27 16:10 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-09-23 22:37 . 2010-09-23 22:37 ——– d—–w- c:\documents and settings\Student\Application Data\ComodoGroup
2010-09-23 22:29 . 2010-09-23 22:29 ——– d—–w- c:\documents and settings\Student\Application DataComodoGroup
2010-09-22 21:48 . 2010-09-22 21:48 348160 —-a-w- c:\documents and settings\Student\Application Data\LimeWire\browser\xulrunner\msvcr71.dll
2010-09-22 21:48 . 2010-09-22 21:48 499712 —-a-w- c:\documents and settings\Student\Application Data\LimeWire\browser\xulrunner\MSVCP71.DLL
2010-09-22 21:48 . 2010-09-22 21:48 73728 —-a-w- c:\documents and settings\Student\Application Data\LimeWire\browser\xulrunner\xulrunner-stub.exe
2010-09-22 21:48 . 2010-09-22 21:48 102400 —-a-w- c:\documents and settings\Student\Application Data\LimeWire\browser\xulrunner\xulrunner.exe
2010-09-22 21:34 . 2010-09-23 23:00 ——– d—–w- c:\documents and settings\Student\Application Data\LimeWire
2010-09-19 19:38 . 2010-09-19 19:38 ——– d—–w- C:\VritualRoot
2010-09-19 19:37 . 2010-09-28 00:18 663201 —-a-w- c:\windows\system32\drivers\sfi.dat
2010-09-19 19:33 . 2010-09-19 19:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo
2010-09-19 19:32 . 2010-09-19 19:34 ——– d—–w- c:\program files\COMODO
2010-09-17 00:09 . 2010-09-17 00:09 ——– d—–w- c:\documents and settings\Student_2\Local Settings\Application Data\ESET
2010-09-16 22:39 . 2010-09-16 22:39 ——– d—–w- c:\documents and settings\Student_2\Application Data\Nero
2010-09-16 04:29 . 2010-09-16 04:29 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2010-09-15 23:46 . 2010-09-15 23:46 ——– d—–w- c:\documents and settings\Student\Local Settings\Application Data\ESET
2010-09-15 23:34 . 2010-09-15 23:34 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2010-09-15 22:36 . 2010-09-15 22:36 ——– d–h–we c:\documents and settings\All Users\AVP9
2010-09-15 14:25 . 2010-09-15 14:25 ——– d—–w- C:\found.000
2010-09-11 05:41 . 2010-09-11 05:41 285480 —-a-w- c:\windows\system32\guard32.dll
2010-09-11 05:40 . 2010-09-11 05:40 91560 —-a-w- c:\windows\system32\drivers\inspect.sys
2010-09-11 05:40 . 2010-09-11 05:40 25240 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-09-11 05:40 . 2010-09-11 05:40 239240 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-09-11 05:40 . 2010-09-11 05:40 15592 —-a-w- c:\windows\system32\drivers\cmderd.sys
2010-09-08 19:40 . 2006-01-01 01:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2010-09-03 00:16 . 2010-09-03 00:16 ——– d—–w- c:\documents and settings\All Users\Application Data\AVS4YOU
2010-09-03 00:15 . 2010-09-03 00:15 ——– d—–w- c:\documents and settings\Student\Application Data\AVS4YOU
2010-09-03 00:10 . 2008-11-24 18:00 974848 —-a-w- c:\windows\system32\mfc70.dll
2010-09-03 00:10 . 2008-11-24 18:00 487424 —-a-w- c:\windows\system32\msvcp70.dll
2010-09-03 00:10 . 2008-11-24 18:00 344064 —-a-w- c:\windows\system32\msvcr70.dll
2010-09-03 00:10 . 2008-11-24 18:00 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2010-09-03 00:09 . 2008-11-24 18:00 24576 —-a-w- c:\windows\system32\msxml3a.dll
2010-09-03 00:09 . 2010-09-19 19:07 ——– d—–w- c:\program files\Common Files\AVSMedia
2010-09-03 00:09 . 2010-09-19 19:07 ——– d—–w- c:\program files\AVS4YOU
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-27 23:25 . 2007-05-16 20:28 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-09-26 18:33 . 2007-05-18 15:32 ——– d—–w- c:\documents and settings\Student_2\Application Data\U3
2010-09-23 23:00 . 2010-08-15 18:51 ——– d—–w- c:\program files\LimeWire
2010-09-22 21:48 . 2010-09-22 21:47 8462336 —-a-w- c:\documents and settings\Student\Application Data\LimeWire\browser\xulrunner\xul.dll
2010-09-20 00:11 . 2008-08-05 03:35 ——– d—–w- c:\documents and settings\Student\Application Data\U3
2010-09-19 21:44 . 2007-05-18 20:15 ——– d—–w- c:\program files\Registry Cleaner Retail
2010-09-19 19:04 . 2009-10-02 17:31 ——– d—–w- c:\program files\CCleaner
2010-09-16 23:26 . 2007-05-23 11:55 ——– d—–w- c:\documents and settings\Student_2\Application Data\Ahead
2010-09-02 21:45 . 2007-05-18 19:08 ——– d—–w- c:\program files\Common Files\Adobe
2010-08-17 16:01 . 2010-08-17 16:01 503808 —-a-w- c:\documents and settings\Student_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-73aafb0d-n\msvcp71.dll
2010-08-17 16:01 . 2010-08-17 16:01 499712 —-a-w- c:\documents and settings\Student_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-73aafb0d-n\jmc.dll
2010-08-17 16:01 . 2010-08-17 16:01 348160 —-a-w- c:\documents and settings\Student_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-73aafb0d-n\msvcr71.dll
2010-08-17 16:01 . 2010-08-17 16:01 61440 —-a-w- c:\documents and settings\Student_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1a3820a7-n\decora-sse.dll
2010-08-17 16:01 . 2010-08-17 16:01 12800 —-a-w- c:\documents and settings\Student_2\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1a3820a7-n\decora-d3d.dll
2010-08-15 19:49 . 2010-08-15 19:49 ——– d—–w- c:\program files\Common Files\Java
2010-08-15 19:49 . 2010-08-15 19:49 503808 —-a-w- c:\documents and settings\Student\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5989bd6e-n\msvcp71.dll
2010-08-15 19:49 . 2010-08-15 19:49 499712 —-a-w- c:\documents and settings\Student\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5989bd6e-n\jmc.dll
2010-08-15 19:49 . 2010-08-15 19:49 348160 —-a-w- c:\documents and settings\Student\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5989bd6e-n\msvcr71.dll
2010-08-15 19:49 . 2010-08-15 19:49 12800 —-a-w- c:\documents and settings\Student\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-6e0f975b-n\decora-d3d.dll
2010-08-15 19:49 . 2010-08-15 19:49 61440 —-a-w- c:\documents and settings\Student\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-6e0f975b-n\decora-sse.dll
2010-08-15 19:48 . 2010-08-15 19:48 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-15 19:48 . 2010-08-15 19:48 ——– d—–w- c:\program files\Java
2010-08-04 23:34 . 2007-05-18 19:42 50272 -c–a-w- c:\documents and settings\Student_2\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-03 22:21 . 2007-05-18 19:26 50272 -c–a-w- c:\documents and settings\Student\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
——- Sigcheck ——-
[-] 2006-09-12 . 0EF6B94BFAB8D17209133946A0C31573 . 359808 . . [5.1.2600.2685] . . c:\windows\system32\drivers\tcpip.sys
[-] 2006-01-01 . C8061F289E000703E7672916B7FE1571 . 395776 . . [5.1.2600.2665] . . c:\windows\system32\rpcss.dll
[-] 2006-01-01 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\system32\spoolsv.exe
[-] 2006-01-01 . 0CE2796FA38B9B4301C7EDD03BF2F00F . 3680768 . . [6.00.2900.2722] . . c:\windows\system32\mshtml.dll
[-] 2006-01-01 . 939D1B8DE077337A6EBA221C83961C37 . 2341632 . . [5.1.2600.2622] . . c:\windows\system32\ntoskrnl.exe
[-] 2006-01-01 . 1418A3A6E76E5A2E3F5E43866E793A8B . 249344 . . [5.1.2600.2716] . . c:\windows\system32\tapisrv.dll
[-] 2006-01-01 . DE2DB164BBB35DB061AF0997E4499054 . 577024 . . [5.1.2600.2622] . . c:\windows\system32\user32.dll
[-] 2006-01-01 . E81E1599A2A74C672E4B7465F99C6287 . 841728 . . [6.00.2900.2713] . . c:\windows\system32\wininet.dll
[-] 2006-01-01 . E9FD784FE52ADAF58B3C896C1DCE378E . 2539008 . . [6.00.2900.2180] . . c:\windows\explorer.exe
[-] 2006-01-01 . 5950E4F28FDA9D147576BF6798937397 . 1285120 . . [5.1.2600.2665] . . c:\windows\system32\ole32.dll
[-] 2006-01-01 01:00 . A477391B7A8B0A0DAABADB17CF533A4B . 25088 . . [10.0.3790.3646] . . c:\windows\system32\mspmsnsv.dll
[-] 2006-01-01 . 9461A8867DC1F7CB2A51987DB87EADAE . 2219136 . . [5.1.2600.2622] . . c:\windows\system32\ntkrnlpa.exe
c:\windows\System32\wscntfy.exe … is missing !!
c:\windows\System32\regsvc.dll … is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-17 139264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF14562.cfxxe" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-07-21 126976]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-09-11 2500552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Set"="fuset.exe" [2006-01-01 70656]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-01-01 44544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Altap"="tskstsh" [X]
c:\documents and settings\Student\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-8-19 503808]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 10 (0xa)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2006-07-21 06:15 1848218 -c–a-w- c:\program files\Acronis\TrueImageEnterpriseServer\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2006-07-21 06:12 1106531 -c–a-w- c:\program files\Acronis\TrueImageEnterpriseServer\TrueImageMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Acronis\\TrueImageEnterpriseServer\\TrueImage.exe"=
"c:\\WINDOWS\\lsass.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
R0 CFRMD;CFRMD;c:\windows\System32\drivers\CFRMD.sys [x]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-10-03 19472]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [2010-09-11 15592]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2010-09-11 239240]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2009-09-14 32272]
— Other Services/Drivers In Memory —
*NewlyCreated* - HELPSVC
*NewlyCreated* - WUAUSERV
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-09-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 16:54]
2010-09-27 c:\windows\Tasks\COMODO System Cleaner Update.job
- c:\program files\COMODO\COMODO System-Cleaner\UpdateApplications.exe [2010-03-09 21:41]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
IE: Save Flash with Flash Catcher - c:\windows\system32\IECatcher.DLL/FlashCatcher.htm
FF - ProfilePath - c:\documents and settings\Student\Application Data\Mozilla\Firefox\Profiles\2sq0xh4g.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\KavLinkFilter.dll
FF - plugin: c:\documents and settings\Student\Application Data\Mozilla\Firefox\Profiles\2sq0xh4g.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
—- FIREFOX POLICIES —-
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: network.http.max-persistent-connections-per-server - 3
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-27 18:24
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1368)
c:\windows\system32\SETUPAPI.dll
- - - - - - - > 'lsass.exe'(1448)
c:\windows\system32\guard32.dll
c:\windows\system32\relog_ap.dll
c:\windows\system32\setupapi.dll
- - - - - - - > 'Explorer.EXE'(1548)
c:\windows\system32\guard32.dll
c:\windows\system32\shimgvw.dll
c:\progra~1\COMMON~1\MICROS~1\Web Components\11\OWC11.DLL
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\shdoclc.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\MSCTF.dll
c:\windows\system32\NETSHELL.dll
.
Completion time: 2010-09-27 18:34:37 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-28 00:34
Pre-Run: 57,488,429,056 bytes free
Post-Run: 59,400,839,168 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Unlimited" /noexecute=optin /fastdetect
- - End Of File - - 96D7B26A26199CD7D9A79B3B32A56D65
arbradio
Hi LDTate,
I just got done reading some of your posts in the forums, the ones I read pertained to slow running computers. I followed all of your instructions there and the pc seems to be running better at this point. Not as good as it probably should but better.
Thanks again for all of your help, it really is very much appreciated. Your not just helping me you are helping every student that uses this computer on a daily basis.
Jeremy

LDTate
What are you using LimeWire for?
LimeWire is a free peer-to-peer file sharing (P2P) client.
You have a couple missing windows OS files.
Did you disable / remove them?
c:\windows\System32\wscntfy.exe … is missing !!
c:\windows\System32\regsvc.dll … is missing !!
Please run a new MBAM scan and post the results.
LimeWire is a free peer-to-peer file sharing (P2P) client.
You have a couple missing windows OS files.
Did you disable / remove them?
c:\windows\System32\wscntfy.exe … is missing !!
c:\windows\System32\regsvc.dll … is missing !!
Windows Security Center Notification - wscntfy.exe
What does it do?
wscntfy.exe - This is a part of windows XP's SP2. This is a little notification that will be in your taskbar and continue to nag you about various security settings like your firewall, automatic updates and virus protection.
regsvc.dll is a process belonging to the Microsoft® Windows® Operating System program . "regsvc.dll is a Remote Registry Service" "from Microsoft Corporation" "belonging to Microsoft® Windows® Operating System"
Please run a new MBAM scan and post the results.
arbradio
Limewire………well everyday I tell everyone here to quit downloading Limewire, and every day I come back and it is loaded onto the computer. I think that the students and staff are using it to acquire music for production projects, when they could record it off of youtube in the same amount of time. Every day I erase it and now it wont even completely uninstall……
Here is the MBAM Log, thanks again for your help.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4704
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
9/29/2010 5:04:49 PM
mbam-log-2010-09-29 (17-04-49).txt
Scan type: Quick scan
Objects scanned: 140284
Time elapsed: 17 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
LDTate
http://spywarefiles.prevx.com/RRIFGC842591…RUNNER.EXE.html
XULRUNNER.EXE<– Malicious Software
Copy/paste the text in the Codebox below into notepad:
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
Drag CFScript.txt into ComboFix.exe
Then post the results log using Copy / Paste
Also please describe how your computer behaves at the moment.
XULRUNNER.EXE<– Malicious Software
Copy/paste the text in the Codebox below into notepad:
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
File:: c:\documents and settings\Student\Application Data\LimeWire\browser\xulrunner\msvcr71.dll Folder:: c:\program files\LimeWire c:\documents and settings\Student\Application Data\LimeWire Registry:: [HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run] "Altap"=-
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
Drag CFScript.txt into ComboFix.exe
Then post the results log using Copy / Paste
Also please describe how your computer behaves at the moment.
arbradio
Hello,
So I downloaded Combofix and did like you said and it failed to install. I deleted and re downloaded it and the same thing happened again.
So what do I do?
Sorry for the delayed response me Grandfather is in the hospital.
LDTate
You already had Combofix installed.
You can remove these leftover files and folders if listed:
C:\ComboFix
C:\QooBox
C:\combofix.txt
C:\combofix-quarantine-files.txt
Now try to download it again.
arbradio
Ok, so I followed your instructions and it still fails to install.
What should I do?
hahaha…I really appreciate your help so much.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI