This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Vundo On My Windows Xp Machine

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Now I need you to perform a few tricky manoeuvres : we have to replace your infected tcpis.sys file which has altered by a rootkit and also attempt to restore your ability to operate in Safe Mode. We will do these one at a time.


A. Open Notepad and copy/paste the code box below into a new text file

@echo off
(
copy /y /b C:\WINDOWS\SoftwareDistribution\Download\e534ebaf021731fc8bec5e8193de9bb9\SP2QFE\tcpip.sys C:\WINDOWS\SYSTEM32\DRIVERS
vfind -tf %systemroot%\tcpip.sys
)>>log.txt
notepad log.txt

Save this as replace.bat Choose to "Save type as - All Files"
It should look like this: [external image: Posted Image]
Double click on replace.bat & allow it to run.



B. Download & run this tool > SafeBootKeyRepair-CF from here: http://download.bleepingcomputer.com/sUBs/…eyRepair-CF.exe
It shall only take a short moment for it to finish running. A log shall be produced at C:\SafeBoot_Repair.txt. Please post that in your next reply.


C. Now, please run ComboFix the normal way which is:
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren
Hi I really apologize for not replying sooner. I was always checking only page 1 of the thread - didn't realize that there are two pages! Regards, Khilafat
Hi Trevuren:


Thanks for you continued help.

I have posted the three logs you requested;

Reg export of SafeBoot key after repair:
========================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot]

========================


SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
~~\SafeBoot\Minimal\Base
~~\SafeBoot\Minimal\Boot Bus Extender
~~\SafeBoot\Minimal\Boot file system
~~\SafeBoot\Minimal\dmboot.sys
~~\SafeBoot\Minimal\dmio.sys
~~\SafeBoot\Minimal\dmload.sys
~~\SafeBoot\Minimal\dmserver
~~\SafeBoot\Minimal\File system
~~\SafeBoot\Minimal\Filter
~~\SafeBoot\Minimal\PCI Configuration
~~\SafeBoot\Minimal\Primary disk
~~\SafeBoot\Minimal\RpcSs
~~\SafeBoot\Minimal\SCSI Class
~~\SafeBoot\Minimal\sermouse.sys
~~\SafeBoot\Minimal\System Bus Extender
~~\SafeBoot\Minimal\vga.sys
~~\SafeBoot\Minimal\vgasave.sys
~~\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}
~~\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}
~~\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}
~~\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}
~~\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}
~~\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}

========================

Error: Key: system\currentcontrolset\control\safeboot\minimal does not exist!



=============

COMBOFIX LOG

===================


ComboFix 07-08-11 - "Salil" 2007-08-15 8:09:07.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.174 [GMT -4:00]


((((((((((((((((((((((((( Files Created from 2007-07-15 to 2007-08-15 )))))))))))))))))))))))))))))))


2007-08-12 09:16 135,168 –a—— C:\WINDOWS\SYSTEM32\igfxres.dll
2007-08-11 07:34 11,264 –a—— C:\WINDOWS\SYSTEM32\SpOrder.dll
2007-08-11 07:34 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-08-10 21:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-09 23:04 d——– C:\SAV32CLI
2007-08-09 22:52 75,328 –a—— C:\WINDOWS\SYSTEM32\dkhvjrtf.exe
2007-08-05 19:48 93,696 –a—— C:\WINDOWS\SYSTEM32\drvhak.dll
2007-08-05 19:42 51,200 –a—— C:\WINDOWS\SYSTEM32\rasterx.dll
2007-08-05 19:41 51,200 –a—— C:\WINDOWS\SYSTEM32\fertbuk.dll
2007-08-05 19:40 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-08-05 19:39 89,088 –a—— C:\WINDOWS\SYSTEM32\atl71.dll
2007-08-05 19:39 400,500 –a—— C:\Temp\bass.exe
2007-08-04 17:11 d——– C:\Temp
2007-07-31 20:17 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2008-08-09 22:46 75328 –a—— C:\WINDOWS\system32\amlxuluw.exe
2008-08-09 00:01 ——— d——– C:\Program Files\McAfee.com
2008-08-08 22:03 ——— d——– C:\Program Files\Trend Micro
2008-08-08 20:11 75328 –a—— C:\WINDOWS\system32\uqpllopt.exe
2008-08-06 23:35 93696 –a—— C:\WINDOWS\system32\drvfim.dll
2007-08-10 22:19 ——— d——– C:\Program Files\MSN Gaming Zone
2007-08-10 08:17 ——— d——– C:\Program Files\Dell Support
2007-08-10 07:42 ——— d–h—– C:\DOCUME~1\Salil\APPLIC~1\m
2007-08-10 07:41 ——— d–h—– C:\DOCUME~1\Salil\APPLIC~1\hidn
2007-08-09 23:44 ——— d——– C:\Program Files\Common Files\xing shared
2007-08-09 23:43 ——— d——– C:\Program Files\Common Files\Borland Shared
2007-08-05 19:45 ——— d——– C:\Program Files\Google
2007-07-07 18:24 ——— d——– C:\Program Files\Microsoft Money 2006
2007-06-26 11:13 851968 ——— C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 10:09 658944 ——— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-26 02:08 1104896 ——— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-19 09:31 282112 ——— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-16 12:56 ——— d——– C:\Program Files\Kodak
2007-06-14 14:09 96256 –a—— C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-14 14:09 615424 ——— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-14 14:09 55808 –a—— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-14 14:09 532480 ——— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-14 14:09 474112 ——— C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-14 14:09 449024 ——— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-14 14:09 39424 ——— C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-14 14:09 357888 ——— C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-14 14:09 3058688 ——— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-14 14:09 251392 ——— C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-14 14:09 205312 ——— C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-14 14:09 16384 –a—— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-14 14:09 151040 ——— C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-14 14:09 1494528 ——— C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-14 14:09 146432 ——— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-14 14:09 1054208 ——— C:\WINDOWS\system32\dllcache\danim.dll
2007-06-14 14:09 1023488 ——— C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 10:07 18432 ——— C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-06-13 06:23 1033216 ——— C:\WINDOWS\system32\dllcache\explorer.exe
2007-05-17 07:28 549376 –a—— C:\WINDOWS\system32\oleaut32.dll
2007-05-17 07:28 549376 ——— C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-05-16 11:12 86528 ——— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 –a—— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 ——— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 ——— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 ——— C:\WINDOWS\system32\dllcache\msoe.dll
2005-07-22 22:31 29602 –a—— C:\WINDOWS\prefetch\zo3nealarm.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0EEDB1E5-5765-4a2a-9D72-CB5213D756C0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{49EA22F7-64EB-4243-8198-AE1648E4F087}]
C:\WINDOWS\system32\ssttq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EFEA8B3C-6E43-4184-8E2D-90B97F8465B3}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" []
"sm"="C:\WINDOWS\sa_exe.exe" []
"anti_troj"="C:\WINDOWS\system32\anti_troj.exe" []
"DxDialog"="C:\WINDOWS\system32\dxdlg32.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-24 21:23]
"adeakdjA"="C:\WINDOWS\adeakdjA.exe" []
"{30-0A-AF-F4-ZN}"="C:\windows\system32\ppdsregr.exe" []
"WinCore32.exe"="C:\WINDOWS\system32\WinCore32.exe" []
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2006-02-07 17:16]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"Sonic RecordNow!"="" []
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-27 15:22]
"key2"="C:\WINDOWS\system32\winlog.exe" []
"anti_troj"="C:\WINDOWS\system32\anti_troj.exe" []
"german.exe"="C:\WINDOWS\system32\wintems.exe" []
"Rssvfu"="C:\Program Files\?ppPatch\w?nlogon.exe" []

C:\Documents and Settings\Salil\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2005-04-23 13:23:05]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]
Snapfish Picture Mover.lnk - C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe [2006-12-19 17:08:38]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
Source= C:\Program Files\MSN Gaming Zone\profsyfsy.html
FriendlyName=

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winxry32]
winxry32.dll

SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"

R1 cdrbsvsd;cdrbsvsd;C:\WINDOWS\system32\drivers\cdrbsvsd.sys
R2 ntrtscan;OfficeScanNT RealTime Scan;"C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe"
R2 TM_CFW;Common Firewall Driver;\??\C:\Program Files\Trend Micro\OfficeScan Client\tm_cfw.sys
R2 tmlisten;OfficeScanNT Listener;"C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe"
R2 TmPreFilter;Trend Micro PreFilter;\??\C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
R3 PD0620VID;Creative WebCam Instant;C:\WINDOWS\system32\DRIVERS\P0620Vid.sys
S2 aspimgr;Microsoft ASPI Manager;C:\WINDOWS\system32\aspimgr.exe
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
S2 r_server;Remote Administrator Service;"C:\WINDOWS\system32\r_server.exe" /service


Contents of the 'Scheduled Tasks' folder
2007-08-15 12:06:00 C:\WINDOWS\Tasks\McAfee.com Update Check (KODKANI-Gauri).job - C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
2007-08-15 12:08:00 C:\WINDOWS\Tasks\McAfee.com Update Check (KODKANI-Salil).job - C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
2005-07-01 02:28:00 C:\WINDOWS\Tasks\Run Salil's Calculator.job - C:\WINDOWS\SYSTEM32\CALC.EXE

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-15 08:09:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-15 8:10:55
C:\ComboFix-quarantined-files.txt … 2007-08-15 08:10
C:\ComboFix2.txt … 2007-08-15 08:02
C:\ComboFix3.txt … 2007-08-11 07:06

— E O F —




==================

HJT LOG


=================
================


Logfile of HijackThis v1.99.1
Scan saved at 8:24:39 AM, on 8/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\HKE63E.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\Killer.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Editor plugin - {0EEDB1E5-5765-4a2a-9D72-CB5213D756C0} - fertbuk.dll (file missing)
O2 - BHO: (no name) - {49EA22F7-64EB-4243-8198-AE1648E4F087} - C:\WINDOWS\system32\ssttq.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {EFEA8B3C-6E43-4184-8E2D-90B97F8465B3} - \
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [sm] C:\WINDOWS\sa_exe.exe
O4 - HKLM\..\Run: [anti_troj] C:\WINDOWS\system32\anti_troj.exe
O4 - HKLM\..\Run: [DxDialog] C:\WINDOWS\system32\dxdlg32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [adeakdjA] C:\WINDOWS\adeakdjA.exe
O4 - HKLM\..\Run: [{30-0A-AF-F4-ZN}] C:\windows\system32\ppdsregr.exe SKY009
O4 - HKLM\..\Run: [WinCore32.exe] C:\WINDOWS\system32\WinCore32.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [key2] C:\WINDOWS\system32\winlog.exe
O4 - HKCU\..\Run: [anti_troj] C:\WINDOWS\system32\anti_troj.exe
O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe
O4 - HKCU\..\Run: [Rssvfu] "C:\Program Files\?ppPatch\w?nlogon.exe"
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Snapfish Picture Mover.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupd806.exe
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: winxry32 - winxry32.dll (file missing)
O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe





Best Regards,
Khilafat
OK! That second part did not help iin this case. Let's tackle this another way. We will get rid of the remaining infection, THEN rebuild the SafeBootKey if we can.


A. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:


    O2 - BHO: Editor plugin - {0EEDB1E5-5765-4a2a-9D72-CB5213D756C0} - fertbuk.dll (file missing)
    O2 - BHO: (no name) - {49EA22F7-64EB-4243-8198-AE1648E4F087} - C:\WINDOWS\system32\ssttq.dll (file missing)
    O2 - BHO: (no name) - {EFEA8B3C-6E43-4184-8E2D-90B97F8465B3} - \
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [sm] C:\WINDOWS\sa_exe.exe
    O4 - HKLM\..\Run: [anti_troj] C:\WINDOWS\system32\anti_troj.exe
    O4 - HKLM\..\Run: [DxDialog] C:\WINDOWS\system32\dxdlg32.exe
    O4 - HKLM\..\Run: [adeakdjA] C:\WINDOWS\adeakdjA.exe
    O4 - HKLM\..\Run: [{30-0A-AF-F4-ZN}] C:\windows\system32\ppdsregr.exe SKY009
    O4 - HKLM\..\Run: [WinCore32.exe] C:\WINDOWS\system32\WinCore32.exe
    O4 - HKCU\..\Run: [key2] C:\WINDOWS\system32\winlog.exe
    O4 - HKCU\..\Run: [anti_troj] C:\WINDOWS\system32\anti_troj.exe
    O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe
    O4 - HKCU\..\Run: [Rssvfu] "C:\Program Files\?ppPatch\w?nlogon.exe"
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O20 - Winlogon Notify: winxry32 - winxry32.dll (file missing)
    O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe (file missing)
    O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

http://forums.tomcoyote.org/Vundo_Windows_Xp_Machine_t82115.html&pid=394467&st=15#entry394467

Collect::
C:\WINDOWS\SYSTEM32\dkhvjrtf.exe
C:\WINDOWS\SYSTEM32\drvhak.dll
C:\WINDOWS\SYSTEM32\rasterx.dll
C:\WINDOWS\SYSTEM32\fertbuk.dll
C:\WINDOWS\prefetch\zo3nealarm.exe

File::
C:\Temp\bass.exe
C:\WINDOWS\system32\amlxuluw.exe
C:\WINDOWS\system32\uqpllopt.exe
C:\WINDOWS\system32\drvfim.dll
C:\WINDOWS\TEMP\HKE63E.EXE

Driver::
aspimgr
r_server

DirLook::
C:\DOCUME~1\Salil\APPLIC~1\m
C:\DOCUME~1\Salil\APPLIC~1\hidn

Registry::
[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. Additonally, ComboFix will generate the following files on your desktop
  • A zipped file on your desktop called Submit [Date Time].zip
  • And another file named - CF-Submit.htm
6. ComboFix may need to reboot to finish its work. Let it.

7. When CF has finished running, it will generate the ComboFix.log which will appear on your screen.

8. Next, a window will popup prompting you to "Submit Files for further analysis". Click "OK"

9. Your system's browser will automatically respond by loading the CF-Submit.htm file and open a window :
  • Click the "Browse" button and locate the Submit [Date Time].zip file on your desktop.
  • Click on the file to Select it.
  • Submit the file by clicking "OK"
10. Once the file has been submitted, you may DELETE both files on your desktop.

11. Post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Hi Trevuren,

I followed the instructions you gave. The zip file was submitted to BleepingComputer.com.

Regards,
Khilafat

Here is the ComboFix log followed by HJT log:

ComboFix 07-08-11 - "Salil" 2007-08-15 20:43:38.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.221 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Salil\Desktop\CFScript.txt

FILE::
C:\Temp\bass.exe
C:\WINDOWS\system32\amlxuluw.exe
C:\WINDOWS\system32\uqpllopt.exe
C:\WINDOWS\system32\drvfim.dll
C:\WINDOWS\TEMP\HKE63E.EXE


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Temp\bass.exe
C:\WINDOWS\prefetch\zo3nealarm.exe
C:\WINDOWS\system32\amlxuluw.exe
C:\WINDOWS\SYSTEM32\dkhvjrtf.exe
C:\WINDOWS\system32\drvfim.dll
C:\WINDOWS\SYSTEM32\drvhak.dll
C:\WINDOWS\SYSTEM32\fertbuk.dll
C:\WINDOWS\SYSTEM32\rasterx.dll
C:\WINDOWS\system32\uqpllopt.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_ASPIMGR
——-\LEGACY_R_SERVER
——-\aspimgr
——-\r_server


((((((((((((((((((((((((( Files Created from 2007-07-16 to 2007-08-16 )))))))))))))))))))))))))))))))


2007-08-12 09:16 135,168 –a—— C:\WINDOWS\SYSTEM32\igfxres.dll
2007-08-11 07:34 11,264 –a—— C:\WINDOWS\SYSTEM32\SpOrder.dll
2007-08-11 07:34 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-08-10 21:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-09 23:04 d——– C:\SAV32CLI
2007-08-05 19:40 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-08-05 19:39 89,088 –a—— C:\WINDOWS\SYSTEM32\atl71.dll
2007-08-04 17:11 d——– C:\Temp
2007-07-31 20:17 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2008-08-09 00:01 ——— d——– C:\Program Files\McAfee.com
2008-08-08 22:03 ——— d——– C:\Program Files\Trend Micro
2007-08-10 22:19 ——— d——– C:\Program Files\MSN Gaming Zone
2007-08-10 08:17 ——— d——– C:\Program Files\Dell Support
2007-08-10 07:42 ——— d–h—– C:\DOCUME~1\Salil\APPLIC~1\m
2007-08-10 07:41 ——— d–h—– C:\DOCUME~1\Salil\APPLIC~1\hidn
2007-08-09 23:44 ——— d——– C:\Program Files\Common Files\xing shared
2007-08-09 23:43 ——— d——– C:\Program Files\Common Files\Borland Shared
2007-08-05 19:45 ——— d——– C:\Program Files\Google
2007-07-07 18:24 ——— d——– C:\Program Files\Microsoft Money 2006
2007-06-26 11:13 851968 ——— C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 10:09 658944 ——— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-26 02:08 1104896 ——— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-19 09:31 282112 ——— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-16 12:56 ——— d——– C:\Program Files\Kodak
2007-06-14 14:09 96256 –a—— C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-14 14:09 615424 ——— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-14 14:09 55808 –a—— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-14 14:09 532480 ——— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-14 14:09 474112 ——— C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-14 14:09 449024 ——— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-14 14:09 39424 ——— C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-14 14:09 357888 ——— C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-14 14:09 3058688 ——— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-14 14:09 251392 ——— C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-14 14:09 205312 ——— C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-14 14:09 16384 –a—— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-14 14:09 151040 ——— C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-14 14:09 1494528 ——— C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-14 14:09 146432 ——— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-14 14:09 1054208 ——— C:\WINDOWS\system32\dllcache\danim.dll
2007-06-14 14:09 1023488 ——— C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 10:07 18432 ——— C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-06-13 06:23 1033216 ——— C:\WINDOWS\system32\dllcache\explorer.exe
2007-05-17 07:28 549376 –a—— C:\WINDOWS\system32\oleaut32.dll
2007-05-17 07:28 549376 ——— C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-05-16 11:12 86528 ——— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 –a—— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 ——— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 ——— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 ——— C:\WINDOWS\system32\dllcache\msoe.dll


(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))


—- Directory of C:\DOCUME~1\Salil\APPLIC~1\m —-

2007-08-10 07:43 990 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\evanescence font crack.zip
2007-08-10 07:43 981 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eufa euro 2004 keygen by razor.zip
2007-08-10 07:43 980 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot woerterbuch computertechnik serial number.zip
2007-08-10 07:43 963 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink adresses v2003.1.21 by dbc.zip
2007-08-10 07:43 959 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euclide v2.1 serial by tnt.zip
2007-08-10 07:43 958 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eve online - the second genesis 1.2.1 crack.zip
2007-08-10 07:43 956 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink cheque v1.13.zip
2007-08-10 07:43 952 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\evasion3d meshpaint v1.0 for lightwave3d.zip
2007-08-10 07:43 928 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro millions manager 1.0w crack.zip
2007-08-10 07:43 922 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro cup manager 2004 1.0 crack.zip
2007-08-10 07:43 915 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eugenius v1.7.25 serial number.zip
2007-08-10 07:43 912 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\event manager v2.23.zip
2007-08-10 07:43 911 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etymonix mpeg-2 video codec v1.0 keygen by core.zip
2007-08-10 07:43 909 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro office box 2000 v4.0.zip
2007-08-10 07:43 909 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euklid dynageo v2.2d serial number.zip
2007-08-10 07:43 895 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eventcorder suite v2.0.34.zip
2007-08-10 07:43 893 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eureka v1.0 keygen by core.zip
2007-08-10 07:43 893 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euklid dynageo v2.3 serial number.zip
2007-08-10 07:43 892 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro.calc 1.4 for palmos.zip
2007-08-10 07:43 884 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink adresses v2003.1.21.zip
2007-08-10 07:43 881 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink bibliotheque v1.21.zip
2007-08-10 07:43 879 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro2000.zip
2007-08-10 07:43 871 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurosystems eurovector 2 crack by signmaker.zip
2007-08-10 07:43 869 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\event manager v2.5.zip
2007-08-10 07:43 863 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink eurokey conv2003 v2.10 crack by fff.zip
2007-08-10 07:43 852 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\europa universalis ii 1.02 to 1.03 patch crack.zip
2007-08-10 07:43 849 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\event manager v2.5 serial number.zip
2007-08-10 07:43 847 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eventid net eventreader v1.6.1 patch by ssg.zip
2007-08-10 07:43 842 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink bibliotheque v1.21 crack by fff.zip
2007-08-10 07:43 839 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\event manager v2.23 serial number.zip
2007-08-10 07:43 839 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eusms 4.1 crack.zip
2007-08-10 07:43 829 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot supplements.zip
2007-08-10 07:43 817 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\event calendar v8.0 serial number.zip
2007-08-10 07:43 806 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot woerterbuch computertechnik.zip
2007-08-10 07:43 804 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot woerterbuch medizin.zip
2007-08-10 07:43 803 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink supermarche v1.10 crack by fff.zip
2007-08-10 07:43 799 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink consommation v1.11.zip
2007-08-10 07:43 799 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot technik by amok.zip
2007-08-10 07:43 782 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eudora v4.0 x-mailer and x-sender er patch.zip
2007-08-10 07:43 781 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink inventaire perso v2.01 crack by fff.zip
2007-08-10 07:43 781 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink consommation v1.11 crack by fff.zip
2007-08-10 07:43 776 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot technik.zip
2007-08-10 07:43 770 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eventcorder suite v2.0.42 keygen by nitrous.zip
2007-08-10 07:43 767 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\event calendar v8.0.zip
2007-08-10 07:43 764 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot 3.0 prof..zip
2007-08-10 07:43 761 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eutron planet-share interfax v3.2.x english and italian.zip
2007-08-10 07:43 753 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euritel v2.1.0.zip
2007-08-10 07:43 747 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euclide v1.3 crack.zip
2007-08-10 07:43 745 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eusoftware wizardbrush v5.5.3 keygen by nitrous.zip
2007-08-10 07:43 738 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eventcorder suite v2.0.42.zip
2007-08-10 07:43 736 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eventcorder suite 2.0.41 crack.zip
2007-08-10 07:43 734 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot woerterbuch technik.zip
2007-08-10 07:43 724 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink eurokey conv2003 v2.10.zip
2007-08-10 07:43 715 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\evasion3d x-dof v2.0 for 3dsmax 7.zip
2007-08-10 07:43 705 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\europa universalis se no dk v1.09.zip
2007-08-10 07:43 694 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink adresses 2002.1.10.zip
2007-08-10 07:43 693 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etymonix mpeg-2 video codec v1.0x serial number.zip
2007-08-10 07:43 692 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink supermarche v1.10.zip
2007-08-10 07:43 692 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink inventaire perso v2.01.zip
2007-08-10 07:43 690 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eudora v6.1 serial number.zip
2007-08-10 07:43 670 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink cdtheque v1.50 crack by fff.zip
2007-08-10 07:43 668 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eudora internet suite 2.1 crack.zip
2007-08-10 07:43 667 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\europlus + reward millenium.zip
2007-08-10 07:43 663 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eventcorder suite v2.0.41 serial number.zip
2007-08-10 07:43 663 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euklid dynageo 2.5d crack.zip
2007-08-10 07:43 655 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euchre buddy for pogo 1.6 crack.zip
2007-08-10 07:43 654 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink archives perso v2.00 crack by fff.zip
2007-08-10 07:43 636 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurekalog v4.2.3 enterprise serial by ror.zip
2007-08-10 07:43 634 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eudora v5.2 italian.zip
2007-08-10 07:43 623 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink agenda v2003.1.21 by dbc.zip
2007-08-10 07:43 612 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\ets carbu v1.20 serial by dbc.zip
2007-08-10 07:43 607 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot v3.0 prof upd.zip
2007-08-10 07:43 590 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurokey conversion v2003.2.10.zip
2007-08-10 07:43 589 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink compte v1.11.zip
2007-08-10 07:43 586 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eve v2.0 for window serial number.zip
2007-08-10 07:43 584 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro converter v2.2.zip
2007-08-10 07:43 583 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot woerterbuch umgangssprache serial number.zip
2007-08-10 07:43 581 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euritel v2.1.0 serial number.zip
2007-08-10 07:43 578 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot computer telekommunikation.zip
2007-08-10 07:43 577 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eve v2.2 keygen by tno.zip
2007-08-10 07:43 575 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurokey conversion v2003.2.10 by dbc.zip
2007-08-10 07:43 569 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink agenda v1.50.zip
2007-08-10 07:43 568 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro 2004 - german serial number.zip
2007-08-10 07:43 560 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eve 2.0.zip
2007-08-10 07:43 551 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink cdtheque v1.50.zip
2007-08-10 07:43 535 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euklides v2.2 by enfusia serial number.zip
2007-08-10 07:43 529 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink smart organizer pro v1.5x crack by fff.zip
2007-08-10 07:43 518 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\evasion3d x-dof v2.0 for 3dsmax 7 keygen by paradox.zip
2007-08-10 07:43 516 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euler quaternion pro 1.0 crack.zip
2007-08-10 07:43 512 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eufa euro 2004.zip
2007-08-10 07:43 511 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etude sight reader 1.2.202 crack.zip
2007-08-10 07:43 502 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink compte v1.11 crack by fff.zip
2007-08-10 07:43 485 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro plus nicelabel pro v3.6.4 serial number.zip
2007-08-10 07:43 479 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink cheque v1.13 crack by fff.zip
2007-08-10 07:42 995 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools 2.2 build 55 by core.zip
2007-08-10 07:42 990 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etiumsoft 3d live pool v2.35.zip
2007-08-10 07:42 986 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etextwizard 1.98 build 550 crack.zip
2007-08-10 07:42 964 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etoken universal license generator by hkz.zip
2007-08-10 07:42 960 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v4.2.1.1.zip
2007-08-10 07:42 956 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etienne mp3 manager v1.01 keygen by core.zip
2007-08-10 07:42 951 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\estop! standard edition v3.30 keygen by dt.zip
2007-08-10 07:42 948 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etka seat 06001.zip
2007-08-10 07:42 946 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\esquotes v1.0 by distinct.zip
2007-08-10 07:42 940 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.3.1 serial number.zip
2007-08-10 07:42 937 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.4.zip
2007-08-10 07:42 936 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\estimate master v2.16.zip
2007-08-10 07:42 936 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential tools for visual basic v6.0.97 keygen by core.zip
2007-08-10 07:42 927 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\estos procall v2.05 by eclipse.zip
2007-08-10 07:42 923 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust pestpatrol v5.0 anti-spyware.zip
2007-08-10 07:42 923 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust pestpatrol v5.0 anti-spyware serial number.zip
2007-08-10 07:42 923 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.1.zip
2007-08-10 07:42 919 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v3.5.1 serial number.zip
2007-08-10 07:42 915 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.3 keygen by eclipse.zip
2007-08-10 07:42 900 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft.decoder.v3.0.zip
2007-08-10 07:42 899 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v4.0.zip
2007-08-10 07:42 892 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eti camcorder 2 (nokia 66xx) 2.01 crack.zip
2007-08-10 07:42 878 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1 keygen by again.zip
2007-08-10 07:42 878 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\esms executive outlook 3.4.18 crack.zip
2007-08-10 07:42 875 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.1 keygen by again.zip
2007-08-10 07:42 867 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v3.0 serial number.zip
2007-08-10 07:42 866 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools v3.0 build 87 by tsrh.zip
2007-08-10 07:42 855 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\essentialpim 1.71 crack.zip
2007-08-10 07:42 854 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\estop! standard edition v3.30.zip
2007-08-10 07:42 839 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherdetect packet sniffer 1.2 crack.zip
2007-08-10 07:42 834 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0 unique serial by fff.zip
2007-08-10 07:42 831 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\estos procall v2.05.zip
2007-08-10 07:42 827 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust antivirus v7.zip
2007-08-10 07:42 820 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\essen cyber outlet 2.6 crack.zip
2007-08-10 07:42 816 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0 unique by fff serial number.zip
2007-08-10 07:42 805 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0.1 serial by fff.zip
2007-08-10 07:42 803 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.4 keygen by eclipse.zip
2007-08-10 07:42 795 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherlords ii patch 1.03 crack.zip
2007-08-10 07:42 791 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\estimate master v3.03 by scf.zip
2007-08-10 07:42 787 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherdetect packet sniffer v1.1 patch by lash.zip
2007-08-10 07:42 784 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\espos v1.9 keygen - ucf.zip
2007-08-10 07:42 780 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek wildpackets nx.zip
2007-08-10 07:42 775 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\ethereal - network protocol analyzer 0.10.14 crack.zip
2007-08-10 07:42 775 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\espos 2.2 crack.zip
2007-08-10 07:42 774 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v4.1 demo.zip
2007-08-10 07:42 769 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.5.zip
2007-08-10 07:42 766 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\esoft audio converter v2.3.zip
2007-08-10 07:42 763 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etabs nl v8.4.7 update.zip
2007-08-10 07:42 762 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0.1 by fff serial number.zip
2007-08-10 07:42 757 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.7 serial number.zip
2007-08-10 07:42 753 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0 multilanguage.zip
2007-08-10 07:42 751 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\eternal lines etlin http proxy v1.0.0.26 crack by underpl.zip
2007-08-10 07:42 737 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\esrd stresscheck v5.0.82.zip
2007-08-10 07:42 736 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v3.0.zip
2007-08-10 07:42 735 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.1.4 keygen by ror.zip
2007-08-10 07:42 730 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.3.1.zip
2007-08-10 07:42 730 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\esri shapefile plug-in for gis.net 1.1.3 crack.zip
2007-08-10 07:42 728 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etoken universal license generator.zip
2007-08-10 07:42 728 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek 4.2.1.1.zip
2007-08-10 07:42 727 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\esri arcview v3.3.zip
2007-08-10 07:42 723 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\esrd stresscheck v5.0.76.zip
2007-08-10 07:42 717 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust intrusion detection elite edition v1.5 serial number.zip
2007-08-10 07:42 715 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherlords demo 2 crack.zip
2007-08-10 07:42 699 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools v2.02.zip
2007-08-10 07:42 682 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\esybill 1.0 crack.zip
2007-08-10 07:42 681 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etimusoft 3d live pool v2.3, v2.32, v2.34, v2.35 crack by fff.zip
2007-08-10 07:42 680 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v4.0 serial number.zip
2007-08-10 07:42 680 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\estop! standard edition v3.30 by revenge serial number.zip
2007-08-10 07:42 673 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\espanadir clasific pro v1.5.zip
2007-08-10 07:42 668 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0 unique.zip
2007-08-10 07:42 662 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherscan analyzer 1.2 build 1237 crack.zip
2007-08-10 07:42 660 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools v3.0 build 75.zip
2007-08-10 07:42 654 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etiketten-designer 99 v1.00.7.05b serial by dbc.zip
2007-08-10 07:42 639 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherboss msn messenger conversation monitor & sniffer 1.1 crack.zip
2007-08-10 07:42 637 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etiketten-designer 99 v1.00.7.05b.zip
2007-08-10 07:42 636 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\estos procall v2.06.zip
2007-08-10 07:42 634 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\esoft interactives tower mogul v1.2.0.zip
2007-08-10 07:42 632 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust pestpatrol v5.0 anti spyware serial by yag.zip
2007-08-10 07:42 623 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez firewal 2005 v4.5 serial number.zip
2007-08-10 07:42 618 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\esoft interactives tower mogul v1.2.0 crack by tsrh.zip
2007-08-10 07:42 616 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust pestpatrol v5.0 anti spyware.zip
2007-08-10 07:42 615 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etka 2002 vw, audi.zip
2007-08-10 07:42 611 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\esri arcview v3.3 serial number.zip
2007-08-10 07:42 603 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools 4 build 180 crack.zip
2007-08-10 07:42 602 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etimusoft 3d live pool v2.3, v2.32, v2.34, v2.35.zip
2007-08-10 07:42 600 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etka v6.2 skoda.zip
2007-08-10 07:42 594 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\estimate master v3.03.zip
2007-08-10 07:42 593 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.7.zip
2007-08-10 07:42 591 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etd security scanner v3.0 professional serial by mad max.zip
2007-08-10 07:42 591 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\estsoft alzip v5.2 keygen by eclipse.zip
2007-08-10 07:42 589 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential tools for visual basic v6.0.98.zip
2007-08-10 07:42 585 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek wildpackets nx serial number.zip
2007-08-10 07:42 584 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\estimator v1.65.zip
2007-08-10 07:42 575 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\estimating - invoicing - payroll 2.1.0.5b crack.zip
2007-08-10 07:42 550 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.1.4.zip
2007-08-10 07:42 549 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v4.2.0.2.zip
2007-08-10 07:42 534 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion.zip
2007-08-10 07:42 529 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.1.4 serial number.zip
2007-08-10 07:42 528 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0.1 multilanguage.zip
2007-08-10 07:42 524 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etabs nl v8.4.6 update crack by lnd.zip
2007-08-10 07:42 524 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential tools for visual basic v6.0.98 serial number.zip
2007-08-10 07:42 524 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools v3.2 build 130 multilanguage.zip
2007-08-10 07:42 522 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.3.1 keygen by again.zip
2007-08-10 07:42 513 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.1.4 final serial number.zip
2007-08-10 07:42 513 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools v3.0 build 87 by evaluator.zip
2007-08-10 07:42 503 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.1.4 final.zip
2006-09-25 18:48 230 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\srvlist.oct
2006-09-25 18:37 7710 –a—— C:\DOCUME~1\Salil\APPLIC~1\m\list.oct
C:\DOCUME~1\Salil\APPLIC~1\m\shared\need for speed 5
C:\DOCUME~1\Salil\APPLIC~1\m\shared\medal of honor
C:\DOCUME~1\Salil\APPLIC~1\m\shared\half-life
C:\DOCUME~1\Salil\APPLIC~1\m\shared\command & conquer 3
C:\DOCUME~1\Salil\APPLIC~1\m\shared\codename panzers
C:\DOCUME~1\Salil\APPLIC~1\m\shared\after dark screensaver - star trek tng mac
C:\DOCUME~1\Salil\APPLIC~1\m\shared\1503 a.d

—- Directory of C:\DOCUME~1\Salil\APPLIC~1\hidn —-



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-24 21:23]
"{30-0A-AF-F4-ZN}"="C:\windows\system32\ppdsregr.exe" []
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2006-02-07 17:16]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"Sonic RecordNow!"="" []
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-27 15:22]

C:\Documents and Settings\Salil\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2005-04-23 13:23:05]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]
Snapfish Picture Mover.lnk - C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe [2006-12-19 17:08:38]

SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"

R1 cdrbsvsd;cdrbsvsd;C:\WINDOWS\system32\drivers\cdrbsvsd.sys
R2 ntrtscan;OfficeScanNT RealTime Scan;"C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe"
R2 TM_CFW;Common Firewall Driver;\??\C:\Program Files\Trend Micro\OfficeScan Client\tm_cfw.sys
R2 tmlisten;OfficeScanNT Listener;"C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe"
R2 TmPreFilter;Trend Micro PreFilter;\??\C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
R3 PD0620VID;Creative WebCam Instant;C:\WINDOWS\system32\DRIVERS\P0620Vid.sys
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys


Contents of the 'Scheduled Tasks' folder
2007-08-16 01:21:00 C:\WINDOWS\Tasks\McAfee.com Update Check (KODKANI-Gauri).job - C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
2007-08-16 01:18:00 C:\WINDOWS\Tasks\McAfee.com Update Check (KODKANI-Salil).job - C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
2005-07-01 02:28:00 C:\WINDOWS\Tasks\Run Salil's Calculator.job - C:\WINDOWS\SYSTEM32\CALC.EXE

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-15 21:20:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-15 21:22:14 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-15 21:21
C:\ComboFix2.txt … 2007-08-15 08:10
C:\ComboFix3.txt … 2007-08-15 08:02

— E O F —

===================

HJT LOG

====================




Logfile of HijackThis v1.99.1
Scan saved at 10:07:54 PM, on 8/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\XS2290.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\Killer.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [{30-0A-AF-F4-ZN}] C:\windows\system32\ppdsregr.exe SKY009
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Snapfish Picture Mover.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupd806.exe
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
A. Do you really expect us to help you again when we see the content of the following folder:

Directory of C:\DOCUME~1\Salil\APPLIC~1\m —-


Cracks/Keygens and Warez sites are where you pickup all of this stuff. We have better things to do than to provide assistance to people who run after trouble. So be advised that you may not receive help here again if your system is still full of this junk.



B. We will now try to repair your SafeBootKey so that Safe Mode will be available to you

1. Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For the version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe


2. Please download SafeBoot.zip to your Desktop
  • Click on SafeBoot.zip to open the Zip file.
  • Extract SafeBoot.reg again to your Desktop. It should look like this [external image: Posted Image].
  • Double-click on the icon.
  • You will receive a prompt similar to: "Do you wish to merge the information into the registry?". Answer Yes and wait for a message to appear similar to Merged Successfully.
  • Reboot your machine
Hi Trevuren,

I would appreciate if you could please elaborate your comment below? I understand your concern that some potentially unwanted material is on my computer but still do not understand what you mean by this. Honestly, I don't know what Cracks/Keygens and Warez sites are. What are Cracks/Keygens and Warez? Is it possible they got downloaded on my machine while downloading/or visiting other sites?

I was visiting Url edited for security reasons a site that has free music program videos when I saw the system hang up. I will not be visiting the site again.

I will follow your instructions ASAP when I am home.

Regards,
Khilafat


==================
Do you really expect us to help you again when we see the content of the following folder:

Directory of C:\DOCUME~1\Salil\APPLIC~1\m —-


Cracks/Keygens and Warez sites are where you pickup all of this stuff. We have better things to do than to provide assistance to people who run after trouble. So be advised that you may not receive help here again if your system is still full of this junk.
=========================
Sorry to write again. I was looking at the folder content names that you mentioned and I cannot recognize any of the names in there. I am suspecting that the computer has stuff that we are completely unaware of. Regards, Khilafat
If they are not downloaded by you and contain potential infectious material, I suggest that you allow me to delete them all for you after you try the SafeBootKey Fix. Trevuren
Hi Trevuren, I would appreciate it if they can be deleted. Anycase, I will post the information you requested this evening. Regards, Khilafat
Hi Trevuren,

I followed your instructions. Please let me know if we can delete the bad files that were seen on the machine in my previous log.

Regards
Khilafat

ComboFix 07-08-11 - "Salil" 2007-08-16 20:15:30.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.214 [GMT -4:00]


((((((((((((((((((((((((( Files Created from 2007-07-17 to 2007-08-17 )))))))))))))))))))))))))))))))


2007-08-16 20:04 d——– C:\RegistryBackup_16Aug
2007-08-12 09:16 135,168 –a—— C:\WINDOWS\SYSTEM32\igfxres.dll
2007-08-11 07:34 11,264 –a—— C:\WINDOWS\SYSTEM32\SpOrder.dll
2007-08-11 07:34 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-08-10 21:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-09 23:04 d——– C:\SAV32CLI
2007-08-05 19:40 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-08-05 19:39 89,088 –a—— C:\WINDOWS\SYSTEM32\atl71.dll
2007-08-04 17:11 d——– C:\Temp
2007-07-31 20:17 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2008-08-09 00:01 ——— d——– C:\Program Files\McAfee.com
2008-08-08 22:03 ——— d——– C:\Program Files\Trend Micro
2007-08-10 22:19 ——— d——– C:\Program Files\MSN Gaming Zone
2007-08-10 08:17 ——— d——– C:\Program Files\Dell Support
2007-08-10 07:42 ——— d–h—– C:\DOCUME~1\Salil\APPLIC~1\m
2007-08-10 07:41 ——— d–h—– C:\DOCUME~1\Salil\APPLIC~1\hidn
2007-08-09 23:44 ——— d——– C:\Program Files\Common Files\xing shared
2007-08-09 23:43 ——— d——– C:\Program Files\Common Files\Borland Shared
2007-08-05 19:45 ——— d——– C:\Program Files\Google
2007-07-07 18:24 ——— d——– C:\Program Files\Microsoft Money 2006
2007-06-26 11:13 851968 ——— C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 10:09 658944 ——— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-26 02:08 1104896 ——— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-19 09:31 282112 ——— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-14 14:09 96256 –a—— C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-14 14:09 615424 ——— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-14 14:09 55808 –a—— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-14 14:09 532480 ——— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-14 14:09 474112 ——— C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-14 14:09 449024 ——— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-14 14:09 39424 ——— C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-14 14:09 357888 ——— C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-14 14:09 3058688 ——— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-14 14:09 251392 ——— C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-14 14:09 205312 ——— C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-14 14:09 16384 –a—— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-14 14:09 151040 ——— C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-14 14:09 1494528 ——— C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-14 14:09 146432 ——— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-14 14:09 1054208 ——— C:\WINDOWS\system32\dllcache\danim.dll
2007-06-14 14:09 1023488 ——— C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 10:07 18432 ——— C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-06-13 06:23 1033216 ——— C:\WINDOWS\system32\dllcache\explorer.exe
2007-05-17 07:28 549376 –a—— C:\WINDOWS\system32\oleaut32.dll
2007-05-17 07:28 549376 ——— C:\WINDOWS\system32\dllcache\oleaut32.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-24 21:23]
"{30-0A-AF-F4-ZN}"="C:\windows\system32\ppdsregr.exe" []
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2006-02-07 17:16]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"Sonic RecordNow!"="" []
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-27 15:22]

C:\Documents and Settings\Salil\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2005-04-23 13:23:05]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]
Snapfish Picture Mover.lnk - C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe [2006-12-19 17:08:38]

R1 cdrbsvsd;cdrbsvsd;C:\WINDOWS\system32\drivers\cdrbsvsd.sys
R2 ntrtscan;OfficeScanNT RealTime Scan;"C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe"
R2 TM_CFW;Common Firewall Driver;\??\C:\Program Files\Trend Micro\OfficeScan Client\tm_cfw.sys
R2 tmlisten;OfficeScanNT Listener;"C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe"
R2 TmPreFilter;Trend Micro PreFilter;\??\C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
R3 PD0620VID;Creative WebCam Instant;C:\WINDOWS\system32\DRIVERS\P0620Vid.sys
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys


Contents of the 'Scheduled Tasks' folder
2007-08-17 00:16:00 C:\WINDOWS\Tasks\McAfee.com Update Check (KODKANI-Gauri).job - C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
2007-08-17 00:18:00 C:\WINDOWS\Tasks\McAfee.com Update Check (KODKANI-Salil).job - C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
2005-07-01 02:28:00 C:\WINDOWS\Tasks\Run Salil's Calculator.job - C:\WINDOWS\SYSTEM32\CALC.EXE

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-16 20:18:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************

Completion time: 2007-08-16 20:19:59
C:\ComboFix-quarantined-files.txt … 2007-08-16 20:19
C:\ComboFix2.txt … 2007-08-15 21:22
C:\ComboFix3.txt … 2007-08-15 08:10

— E O F —
]

-==========
HJT REPORT

==============

Logfile of HijackThis v1.99.1
Scan saved at 8:24:18 PM, on 8/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\TEMP\HX635.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\Killer.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [{30-0A-AF-F4-ZN}] C:\windows\system32\ppdsregr.exe SKY009
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Snapfish Picture Mover.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupd806.exe
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe



Regards,
Khilafat
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Folder::
C:\DOCUME~1\Salil\APPLIC~1\m
C:\DOCUME~1\Salil\APPLIC~1\hidn


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI