virusm or something
14 min read
- I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
- The fixes are specific to your problem and should only be used for the issues on this machine.
- Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
- It's often worth reading through these instructions and printing them for ease of reference.
- If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
- Please reply to this thread. Do not start a new topic.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
Lets get going.
Please read carefully and follow these steps.
- Download TDSSKiller and save it to your Desktop.
- Extract its contents to your desktop.
- Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
Click to load external image (Posted Image)
- If an infected file is detected, the default action will be Cure, click on Continue.
Click to load external image (Posted Image)
- If a suspicious file is detected, the default action will be Skip, click on Continue.
Click to load external image (Posted Image)
- It may ask you to reboot the computer to complete the process. Click on Reboot Now.
Click to load external image (Posted Image)
- If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
- If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Please download DDS by sUBs from one of the following links and save it to your desktop.
- DDS.scr
- DDS.pif
- Disable any script blocking protection (How to Disable your Security Programs)
- Double click DDS icon to run the tool (may take up to 3 minutes to run)
- When done, DDS.txt will open.
- After a few moments, attach.txt will open in a second window.
- Save both reports to your desktop.
- Post the contents of the DDS.txt report in your next reply
- Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
In your next reply please post the logs created by both TDSSKiller and both logs from DDS.
Please read through these instructions to familarize yourself with what to expect when this tool runs
Download ComboFix from one of these locations:
Link 1
Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
In your next reply please post the log created by ComboFix.
In your next reply please just copy/paste the logs instead of attaching them as it makes it easier to read for me. Thank you.
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
- Double-click SystemLook.exe to run it.
- Copy the content of the following codebox into the main textfield:
:file C:\msconfig.exe
- Click the Look button to start the scan.
- When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
———-
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
DDS:
mRunServices: [DRam prosessor] msconfig.exe
Firefox::
FF - ProfilePath - c:\documents and settings\xp\Application Data\Mozilla\Firefox\Profiles\w5g1xhcw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2776682&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2776682&SearchSource=13
Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
In your next reply please post the logs created by SystemLook and Combofix.
SystemLook report
SystemLook 04.09.10 by jpshortstuff
Log created at 20:50 on 09/06/2011 by xp
Administrator - Elevation successful
========== file ==========
C:\msconfig.exe - Unable to find/read file.
-= EOF =-
combofix
ComboFix 11-06-09.03 - xp 09.06.2011 21:02:23.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.386.1033.18.3036.2416 [GMT 2:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\xp\Desktop\CFScript.txt
.
.
((((((((((((((((((((((((( Files Created from 2011-05-09 to 2011-06-09 )))))))))))))))))))))))))))))))
.
.
2011-06-08 05:51 . 2011-06-08 05:51 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-06-08 05:51 . 2011-06-08 05:51 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-06-08 05:51 . 2011-06-08 05:51 465880 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-06-08 05:51 . 2011-06-08 05:51 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-06-08 05:51 . 2011-06-08 05:51 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-06-08 05:50 . 2011-06-08 05:50 1892184 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-06-08 05:50 . 2011-06-08 05:50 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-06-08 05:50 . 2011-06-08 05:50 1974616 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-06-05 07:35 . 2011-06-05 07:36 ——– d—–w- c:\documents and settings\xp\Application Data\ActiveState
2011-06-05 07:23 . 2011-06-05 07:23 ——– d—–w- c:\program files\ActiveState Perl Dev Kit 9.0.1
2011-06-04 17:57 . 2011-06-04 17:57 ——– d—–w- c:\documents and settings\xp\Local Settings\Application Data\BVRP Software
2011-06-04 17:51 . 2011-06-04 17:51 ——– d—–w- c:\windows\system32\wbem\Repository
2011-06-04 17:28 . 2011-06-04 17:28 ——– d—–w- c:\program files\ESET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-06 19:28 . 2011-04-06 19:27 91376 —-a-w- c:\windows\system32\bcmwlcoi.dll
2011-04-06 19:28 . 2010-01-25 14:23 1735296 —-a-w- c:\windows\system32\drivers\BCMWL5.SYS
2011-06-08 05:50 . 2011-06-08 05:50 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"RGSC"="c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2010-02-08 306088]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-06 1430824]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-03-10 506936]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-02-18 177720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-01-16 1044480]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\xp\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-1-27 576000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\SIERRA\\Empire Earth\\Empire Earth.exe"=
"c:\\Documents and Settings\\xp\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Electronic Arts\\Need for Speed™ Hot Pursuit\\Launcher.exe"=
"c:\\Program Files\\Electronic Arts\\Need for Speed™ Hot Pursuit\\NFS11.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedIIGame.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedII.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\UPlayBrowser.exe"=
"c:\\Program Files\\EA Sports\\FIFA 11\\Game\\fifa.exe"=
"c:\\Program Files\\Electronic Arts\\SHIFT 2 UNLEASHED\\shift2u.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"427:UDP"= 427:UDP:SLP_Port(427)
.
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [25.1.2010 16:02 24064]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31.1.2010 15:35 691696]
R2 NSHE;Guardant Emulator Driver;c:\windows\system32\drivers\NSHE.SYS [31.1.2010 15:54 97792]
R3 adatadrv;Autodata Protection Service;c:\windows\system32\drivers\adatadrv.sys [27.2.2011 16:41 762112]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [17.8.2010 21:46 222512]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [8.5.2010 16:30 27632]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [8.5.2010 16:30 13224]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [5.11.2010 0:23 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [5.11.2010 0:23 8320]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [8.11.2010 21:00 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [8.11.2010 21:00 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [8.11.2010 21:00 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [8.11.2010 21:00 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [8.11.2010 21:00 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [8.11.2010 21:00 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [8.11.2010 21:00 115752]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\drivers\s1039bus.sys [2.11.2010 20:59 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\drivers\s1039mdfl.sys [2.11.2010 20:59 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\drivers\s1039mdm.sys [2.11.2010 20:59 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1039mgmt.sys [2.11.2010 20:59 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1039nd5.sys [2.11.2010 20:59 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\drivers\s1039obex.sys [2.11.2010 20:59 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1039unic.sys [2.11.2010 20:59 123504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-01-09 14:28 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.siol.net/
uInternet Connection Wizard,ShellNext = iexplore
IE: Free YouTube Download - c:\documents and settings\xp\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\xp\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Google Sidewiki … - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: I&zvozi v Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1
DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://www.mascus.si/imageUploader/ImageUploader6.cab
FF - ProfilePath - c:\documents and settings\xp\Application Data\Mozilla\Firefox\Profiles\w5g1xhcw.default\
FF - prefs.js: browser.search.selectedEngine - BrotherSoft Extreme Customized Web Search
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-09 21:12
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(932)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2216)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-06-09 21:13:53
ComboFix-quarantined-files.txt 2011-06-09 19:13
ComboFix2.txt 2011-06-08 18:48
.
Pre-Run: 35.493.576.704 bytes free
Post-Run: 35.494.461.440 prosto bajtov
.
- - End Of File - - 1EB0C4CC4D081920293026B1715DAC66
- Double-click SystemLook.exe to run it.
- Copy the content of the following codebox into the main textfield:
:filefind msconfig.exe
- Click the Look button to start the scan.
- When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
———-
Please download Malwarebytes' Anti-Malware to your desktop.
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan as shown below.
[external image: Posted Image]
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-
ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan
Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.
- Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan - Click the [external image: Posted Image] button.
- For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
- Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
- Double click on the [external image: Posted Image] icon on your desktop.
- Check [external image: Posted Image]
- Click the Start button.
- Accept any security warnings from your browser.
- Check [external image: Posted Image]
- Make sure that the option "Remove found threats" is Unchecked
- Push the Start button.
- ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time. - When the scan completes, push [external image: Posted Image]
- Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply. - Push the Back button.
- Push Finish
In your next reply please post the logs created by SystemLook, Malwarebytes and ESET Online scan as well as let me know how your system is running now.
**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.
If you would like to continue with the cleaning please let me know and I will be more than happy to help.
———-
Open notepad and copy/paste the text in the quotebox below into it:
http://forums.whatthetech.com/index.php?sh…mp;#entry734410
Collect::
C:\Documents and Settings\xp\Desktop\programi za avte\scan master 1.1 podatki za nalo?t\ScanMasterELM_1[1].1.0_with_Patch.zip
C:\Documents and Settings\xp\Desktop\programi za avte\scan master 1.1 podatki za nalo?t\2.0 demo in ostalo\lauflicht.zip
C:\Documents and Settings\xp\Desktop\programi za avte\scan master 1.1 podatki za nalo?t\2.0 demo in ostalo\ScanMasterELM_DEMO_2[1].0.zip
C:\Documents and Settings\xp\Desktop\programi za avte\scan master 1.1 podatki za nalo?t\2.0 demo in ostalo\ScanMasterFree0[1].4.0.0.zip
C:\Documents and Settings\xp\My Documents\Downloads\DC++.rar
C:\Documents and Settings\xp\My Documents\Downloads\dsgfsg.rar
C:\Documents and Settings\xp\My Documents\Downloads\AutoData 3.24\AutoData324.iso
C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\REVO\Vag com Lemmiwinks.exe
C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\REVO\VAG-REVOFlash_IIa_ECU_TUNING_VW_AUDI_SEAT_SKODA.exe
C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v413.exe
C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v414.exe
C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v413.exe
C:\Documents and Settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v414.exe
C:\Documents and Settings\xp\My Documents\Downloads\Mercedes EPC+WIS.net\Mercedes EWA - WIS.net_1of3.iso
C:\Documents and Settings\xp\My Documents\Downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe
C:\Documents and Settings\xp\My Documents\Downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AboutBox.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfig.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfigInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfo.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfoInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Class.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\CodeFile.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\DataSet.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\EmptyDatabase.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Form.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Interface.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\MDIParent.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Resource.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\ResourceInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Settings.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\SettingsInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\TextFile.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\UserControl.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Visualizer.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\XmlFile.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AppConfigurationInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AssemblyInfoInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Class.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dataset.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dialog.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\EmptyDatabase.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Form.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\LoginForm.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\MDIParent.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Module.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\ResourceInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SettingsInternal.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SplashScreen.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Text.zip
C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\UserControl.zip
C:\Program Files\Windows Media Player\npdrmv2.zip
C:\Program Files\Windows Media Player\npds.zip
C:\System Volume Information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP407\A0140836.exe
C:\System Volume Information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP409\A0142037.dll
H:\dc++ downloadi\Autodata 3 18 new crack time unlimited.rar
H:\dc++ downloadi\Crack to Autodata - Versjon 3.16 (6.200) - Engelsk.rar
H:\Downloads\DC++.rar
H:\Downloads\dsgfsg.rar
H:\Downloads\Assassins.Creed.II-SKIDROW\sr-acii\sr-acii.iso
H:\Downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe
H:\Downloads\Need for Speed Carbon Collectors Edition PC 2006 - Razor1911\rzr-nfsc\rzr-nfsc.iso
H:\Downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe
H:\DUSKO\svjetlana.exe
H:\hipnoza\sladjica.exe
H:\IKONA\zauzeta.exe
H:\insomnia\jkdrolja.exe
H:\KAZAN\marijana.exe
H:\KOLONIJA\letsrok.exe
H:\KOMPLEKSE\lechi.exe
H:\miriskamiona\gostiona.exe
H:\nfs\hot pursiut\rld-nshp.iso
H:\nfs\hot pursiut\Crack\NFSHP_Activator.exe
H:\NIKOLIC\baswala.exe
H:\pridjimi\necedaboli.exe
H:\sejo\kalac.exe
H:\sojcice\obucicarapice.exe
H:\vatraopasna\slobodnaiskusna.exe
H:\VSI DOWNLOADI\Downloads\DC++.rar
H:\VSI DOWNLOADI\Downloads\dsgfsg.rar
H:\VSI DOWNLOADI\ETKA 7.0\ETKA.7.0.Marken.Freischaltung.-11.2006.By.ANTI_AKTE_FORUM\Marken Freischaltung\AKTE7Mfs.rar
H:\VSI DOWNLOADI\Need for Speed Carbon Collectors Edition PC 2006 - Razor1911\rzr-nfsc\rzr-nfsc.iso
H:\zamorepromena\zaletipad.exe
H:\zivac\primitivac.exe
Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you. Post that log in your next reply.
**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
- Ensure you are connected to the internet and click OK on the message box.
In your next reply please post the log created by ComboFix.
ComboFix 11-06-09.03 - xp 14.06.2011 22:17:19.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.386.1033.18.3036.2401 [GMT 2:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\xp\Desktop\CFScript.txt
.
- REDUCED FUNCTIONALITY MODE -
.
file zipped: c:\documents and settings\xp\My Documents\Downloads\DC++.rar
file zipped: c:\documents and settings\xp\My Documents\Downloads\dsgfsg.rar
file zipped: c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\REVO\VAG-REVOFlash_IIa_ECU_TUNING_VW_AUDI_SEAT_SKODA.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\REVO\Vag com Lemmiwinks.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v413.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v414.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v413.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v414.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe
file zipped: c:\documents and settings\xp\My Documents\Downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AboutBox.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfig.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfigInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfo.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfoInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Class.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\CodeFile.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\DataSet.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\EmptyDatabase.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Form.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Interface.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\MDIParent.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Resource.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\ResourceInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Settings.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\SettingsInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\TextFile.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\UserControl.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Visualizer.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\XmlFile.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AppConfigurationInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AssemblyInfoInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Class.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dataset.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dialog.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\EmptyDatabase.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Form.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\LoginForm.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\MDIParent.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Module.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\ResourceInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SettingsInternal.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SplashScreen.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Text.zip
file zipped: c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\UserControl.zip
file zipped: c:\program files\Windows Media Player\npdrmv2.zip
file zipped: c:\program files\Windows Media Player\npds.zip
file zipped: c:\system volume information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP407\A0140836.exe
file zipped: c:\system volume information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP409\A0142037.dll
file zipped: h:\dc++ downloadi\Autodata 3 18 new crack time unlimited.rar
file zipped: h:\dc++ downloadi\Crack to Autodata - Versjon 3.16 (6.200) - Engelsk.rar
file zipped: h:\downloads\DC++.rar
file zipped: h:\downloads\dsgfsg.rar
file zipped: h:\downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe
file zipped: h:\downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe
file zipped: h:\dusko\svjetlana.exe
file zipped: h:\hipnoza\sladjica.exe
file zipped: h:\ikona\zauzeta.exe
file zipped: h:\insomnia\jkdrolja.exe
file zipped: h:\kazan\marijana.exe
file zipped: h:\kolonija\letsrok.exe
file zipped: h:\komplekse\lechi.exe
file zipped: h:\miriskamiona\gostiona.exe
file zipped: h:\nfs\hot pursiut\Crack\NFSHP_Activator.exe
file zipped: h:\nikolic\baswala.exe
file zipped: h:\pridjimi\necedaboli.exe
file zipped: h:\sejo\kalac.exe
file zipped: h:\sojcice\obucicarapice.exe
file zipped: h:\vatraopasna\slobodnaiskusna.exe
file zipped: h:\vsi downloadi\Downloads\DC++.rar
file zipped: h:\vsi downloadi\Downloads\dsgfsg.rar
file zipped: h:\vsi downloadi\ETKA 7.0\ETKA.7.0.Marken.Freischaltung.-11.2006.By.ANTI_AKTE_FORUM\Marken Freischaltung\AKTE7Mfs.rar
file zipped: h:\zamorepromena\zaletipad.exe
file zipped: h:\zivac\primitivac.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\xp\My Documents\Downloads\AutoData 3.24\AutoData324.iso
c:\documents and settings\xp\My Documents\Downloads\DC++.rar
c:\documents and settings\xp\My Documents\Downloads\dsgfsg.rar
c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\REVO\VAG-REVOFlash_IIa_ECU_TUNING_VW_AUDI_SEAT_SKODA.exe
c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\REVO\Vag com Lemmiwinks.exe
c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v413.exe
c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProFree_v414.exe
c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v413.exe
c:\documents and settings\xp\My Documents\Downloads\ECU TUNING\tunerpro\SetupTunerProRT_v414.exe
c:\documents and settings\xp\My Documents\Downloads\Mercedes EPC+WIS.net\Mercedes EWA - WIS.net_1of3.iso
c:\documents and settings\xp\My Documents\Downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe
c:\documents and settings\xp\My Documents\Downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AboutBox.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfig.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfigInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfo.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfoInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Class.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\CodeFile.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\DataSet.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\EmptyDatabase.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Form.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Interface.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\MDIParent.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Resource.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\ResourceInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Settings.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\SettingsInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\TextFile.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\UserControl.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Visualizer.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\XmlFile.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AppConfigurationInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AssemblyInfoInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Class.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dataset.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dialog.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\EmptyDatabase.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Form.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\LoginForm.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\MDIParent.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Module.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\ResourceInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SettingsInternal.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SplashScreen.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Text.zip
c:\program files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\UserControl.zip
c:\program files\Windows Media Player\npdrmv2.zip
c:\program files\Windows Media Player\npds.zip
c:\system volume information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP407\A0140836.exe
c:\system volume information\_restore{A32BC91E-9221-48BF-AAF9-7B0BF7F3FEFF}\RP409\A0142037.dll
h:\dc++ downloadi\Autodata 3 18 new crack time unlimited.rar
h:\dc++ downloadi\Crack to Autodata - Versjon 3.16 (6.200) - Engelsk.rar
h:\downloads\Assassins.Creed.II-SKIDROW\sr-acii\sr-acii.iso
h:\downloads\DC++.rar
h:\downloads\dsgfsg.rar
h:\downloads\NAV.2010-v.17.0.0.136 Incl. TrialReset 2010 v2.5.0\Norton TrialReset 2010 v2.5.0\NortonActivator.exe
h:\downloads\Need for Speed Carbon Collectors Edition PC 2006 - Razor1911\rzr-nfsc\rzr-nfsc.iso
h:\downloads\WinRAR.v.3.91.x64.x86 .Final - Portable - key\Registration\Keygen_FFF\Keygen.exe
h:\dusko\svjetlana.exe
h:\hipnoza\sladjica.exe
h:\ikona\zauzeta.exe
h:\insomnia\jkdrolja.exe
h:\kazan\marijana.exe
h:\kolonija\letsrok.exe
h:\komplekse\lechi.exe
h:\miriskamiona\gostiona.exe
h:\nfs\hot pursiut\Crack\NFSHP_Activator.exe
h:\nfs\hot pursiut\rld-nshp.iso
h:\nikolic\baswala.exe
h:\pridjimi\necedaboli.exe
h:\sejo\kalac.exe
h:\sojcice\obucicarapice.exe
h:\vatraopasna\slobodnaiskusna.exe
h:\vsi downloadi\Downloads\DC++.rar
h:\vsi downloadi\Downloads\dsgfsg.rar
h:\vsi downloadi\ETKA 7.0\ETKA.7.0.Marken.Freischaltung.-11.2006.By.ANTI_AKTE_FORUM\Marken Freischaltung\AKTE7Mfs.rar
h:\vsi downloadi\Need for Speed Carbon Collectors Edition PC 2006 - Razor1911\rzr-nfsc\rzr-nfsc.iso
h:\zamorepromena\zaletipad.exe
h:\zivac\primitivac.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-05-14 to 2011-06-14 )))))))))))))))))))))))))))))))
.
.
2011-06-12 21:38 . 2011-06-12 22:44 ——– d—–w- c:\documents and settings\xp\Local Settings\Application Data\WMTools Downloaded Files
2011-06-11 20:05 . 2011-06-11 20:05 ——– d—–w- c:\documents and settings\xp\Application Data\Malwarebytes
2011-06-11 20:04 . 2011-06-11 20:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-06-11 20:04 . 2011-05-29 07:11 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-11 20:04 . 2011-06-11 20:04 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-11 20:04 . 2011-05-29 07:11 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-08 05:51 . 2011-06-08 05:51 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-06-08 05:51 . 2011-06-08 05:51 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-06-08 05:51 . 2011-06-08 05:51 465880 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-06-08 05:51 . 2011-06-08 05:51 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-06-08 05:51 . 2011-06-08 05:51 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-06-08 05:50 . 2011-06-08 05:50 1892184 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-06-08 05:50 . 2011-06-08 05:50 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-06-08 05:50 . 2011-06-08 05:50 1974616 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-06-05 07:35 . 2011-06-05 07:36 ——– d—–w- c:\documents and settings\xp\Application Data\ActiveState
2011-06-05 07:23 . 2011-06-05 07:23 ——– d—–w- c:\program files\ActiveState Perl Dev Kit 9.0.1
2011-06-04 17:57 . 2011-06-04 17:57 ——– d—–w- c:\documents and settings\xp\Local Settings\Application Data\BVRP Software
2011-06-04 17:51 . 2011-06-04 17:51 ——– d—–w- c:\windows\system32\wbem\Repository
2011-06-04 17:28 . 2011-06-11 20:22 ——– d—–w- c:\program files\ESET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-06 19:28 . 2011-04-06 19:27 91376 —-a-w- c:\windows\system32\bcmwlcoi.dll
2011-04-06 19:28 . 2010-01-25 14:23 1735296 —-a-w- c:\windows\system32\drivers\BCMWL5.SYS
2011-06-08 05:50 . 2011-06-08 05:50 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-06-09_19.12.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-06-14 20:22 . 2011-06-14 20:22 16384 c:\windows\Temp\Perflib_Perfdata_748.dat
+ 2011-06-12 21:13 . 2011-06-12 21:13 105984 c:\windows\assembly\GAC_MSIL\Microsoft.WindowsAPICodePack\1.1.0.0__31bf3856ad364e35\Microsoft.WindowsAPICodePack.dll
+ 2011-06-12 21:13 . 2011-06-12 21:13 542720 c:\windows\assembly\GAC_MSIL\Microsoft.WindowsAPICodePack.Shell\1.1.0.0__31bf3856ad364e35\Microsoft.WindowsAPICodePack.Shell.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"RGSC"="c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2010-02-08 306088]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-02-06 1430824]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-03-10 506936]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-02-18 177720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-01-16 1044480]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\xp\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-1-27 576000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\SIERRA\\Empire Earth\\Empire Earth.exe"=
"c:\\Documents and Settings\\xp\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Electronic Arts\\Need for Speed™ Hot Pursuit\\Launcher.exe"=
"c:\\Program Files\\Electronic Arts\\Need for Speed™ Hot Pursuit\\NFS11.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedIIGame.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedII.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\UPlayBrowser.exe"=
"c:\\Program Files\\EA Sports\\FIFA 11\\Game\\fifa.exe"=
"c:\\Program Files\\Electronic Arts\\SHIFT 2 UNLEASHED\\shift2u.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"427:UDP"= 427:UDP:SLP_Port(427)
.
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [25.1.2010 16:02 24064]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [31.1.2010 15:35 691696]
R2 NSHE;Guardant Emulator Driver;c:\windows\system32\drivers\NSHE.SYS [31.1.2010 15:54 97792]
R3 adatadrv;Autodata Protection Service;c:\windows\system32\drivers\adatadrv.sys [27.2.2011 16:41 762112]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [17.8.2010 21:46 222512]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [8.5.2010 16:30 27632]
S3 CFcatchme;CFcatchme;\??\c:\docume~1\xp\LOCALS~1\Temp\CFcatchme.sys –> c:\docume~1\xp\LOCALS~1\Temp\CFcatchme.sys [?]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [8.5.2010 16:30 13224]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [11.6.2011 22:04 39984]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [5.11.2010 0:23 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [5.11.2010 0:23 8320]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [8.11.2010 21:00 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [8.11.2010 21:00 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [8.11.2010 21:00 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [8.11.2010 21:00 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [8.11.2010 21:00 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [8.11.2010 21:00 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [8.11.2010 21:00 115752]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM);c:\windows\system32\drivers\s1039bus.sys [2.11.2010 20:59 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter;c:\windows\system32\drivers\s1039mdfl.sys [2.11.2010 20:59 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver;c:\windows\system32\drivers\s1039mdm.sys [2.11.2010 20:59 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1039mgmt.sys [2.11.2010 20:59 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1039nd5.sys [2.11.2010 20:59 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface;c:\windows\system32\drivers\s1039obex.sys [2.11.2010 20:59 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1039unic.sys [2.11.2010 20:59 123504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-01-09 14:28 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.siol.net/
uInternet Connection Wizard,ShellNext = iexplore
IE: Free YouTube Download - c:\documents and settings\xp\Application Data\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\xp\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Google Sidewiki … - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: I&zvozi v Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1
DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://www.mascus.si/imageUploader/ImageUploader6.cab
FF - ProfilePath - c:\documents and settings\xp\Application Data\Mozilla\Firefox\Profiles\w5g1xhcw.default\
FF - prefs.js: browser.search.selectedEngine - BrotherSoft Extreme Customized Web Search
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-14 22:23
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(932)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(724)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\MSVCR80.dll
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_slv.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\windows\system32\crypserv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\PnkBstrA.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2011-06-14 23:06:12 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-14 21:06
ComboFix2.txt 2011-06-09 19:13
ComboFix3.txt 2011-06-08 18:48
.
Pre-Run: 35.080.028.160 bytes free
Post-Run: 11.176.620.032 prosto bajtov
.
- - End Of File - - 515C3E02266C76ECBEFEEC47F4745F88
Great job running ComboFix!! Things are looking better, but we have a couple more things to do before we are done…stick with me.
P2P - I see you have P2P software uTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly Identity Theft. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
I would strongly recommend that you uninstall this now. You can do so via Control Panel >> Add or Remove Programs.
———-
You have an older version of Adobe Reader. You can download the current version HERE
———-
Please download JavaRa to your desktop and unzip it to its own
folder
- Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
click Remove Older Versions. - Accept any prompts.
- Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
- Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
Java Runtime Environment (JRE) version for your computer.
Now please run DDS once more and post both the logs created into your next reply.
In your next reply please post the logs created by DDS and let me know how your system is running now.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI