This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Vundo.DSJ and Fotomoto.H

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is the panda scan


Incident Status Location


Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\John\Desktop\ComboFix.exe[nircmd.exe]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\John\Desktop\ComboFix.exe[nircmd.cfexe]

Here is combo fix

ComboFix 07-12-17.1 - John 2007-12-24 6:26:49.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1494 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-11-24 to 2007-12-24 )))))))))))))))))))))))))))))))
.

2007-12-24 00:15 . 2007-12-24 02:32 d——– C:\WINDOWS\system32\ActiveScan
2007-12-24 00:15 . 2007-12-24 00:15 d——– C:\WINDOWS\LastGood
2007-12-24 00:15 . 2007-12-24 00:38 30,590 –a—— C:\WINDOWS\system32\pavas.ico
2007-12-24 00:15 . 2007-12-24 00:38 2,550 –a—— C:\WINDOWS\system32\Uninstall.ico
2007-12-24 00:15 . 2007-12-24 00:38 1,406 –a—— C:\WINDOWS\system32\Help.ico
2007-12-21 10:48 . 2007-12-21 10:48 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-12-20 11:23 . 2007-12-20 11:23 d——– C:\Program Files\FLV Player
2007-12-20 11:18 . 2007-12-20 22:47 d——– C:\Documents and Settings\John\dwhelper
2007-12-20 00:01 . 2007-12-20 00:02 d——– C:\Program Files\QuickTime
2007-12-17 19:47 . 2007-12-21 00:52 23 –a—— C:\WINDOWS\popcinfot.dat
2007-12-15 18:49 . 2007-12-15 18:49 d——– C:\Documents and Settings\John\Application Data\TrojanHunter
2007-12-15 13:44 . 2007-12-15 14:13 d——– C:\Documents and Settings\John\Application Data\AdwareAlert
2007-12-15 13:37 . 2007-12-15 13:37 d——– C:\Program Files\Trend Micro
2007-12-15 13:37 . 2007-12-23 01:11 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-14 01:16 . 2006-10-26 19:56 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2007-12-13 15:05 . 2007-12-13 15:05 d——– C:\Program Files\MSBuild
2007-12-13 14:58 . 2007-12-13 14:58 d——– C:\Program Files\Microsoft Visual Studio 8
2007-12-12 18:54 . 2007-12-24 00:12 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-12 18:54 . 2007-12-12 18:54 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-09 14:19 . 2007-12-09 14:19 d——– C:\Documents and Settings\John\Application Data\Grisoft
2007-12-09 14:18 . 2007-12-09 14:18 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-07 11:00 . 2007-12-07 11:00 d——– C:\Program Files\Apache Software Foundation
2007-12-07 10:59 . 2007-12-07 11:01 d——– C:\Program Files\glassfish-v2
2007-12-07 10:57 . 2007-12-07 10:59 d——– C:\Program Files\NetBeans 6.0
2007-12-07 10:56 . 2007-12-07 11:00 d——– C:\Documents and Settings\John\.nbi
2007-12-03 21:12 . 2007-12-03 21:12 d——– C:\Program Files\CCleaner
2007-12-03 19:33 . 2007-12-03 19:33 823,296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-12-03 19:33 . 2007-12-03 19:33 823,296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-12-03 19:33 . 2007-12-03 19:33 802,816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-12-03 19:33 . 2007-12-03 19:33 682,496 –a—— C:\WINDOWS\system32\DivX.dll
2007-11-29 23:14 . 2007-11-29 23:14 d——– C:\Documents and Settings\NetworkService\Application Data\Azureus
2007-11-29 16:30 . 2007-11-29 16:30 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-11-29 16:30 . 2007-11-29 16:30 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-11-29 16:30 . 2007-11-29 16:30 4,816 –a—— C:\WINDOWS\system32\divxsm.tlb
2007-11-29 16:28 . 2007-11-29 16:28 196,608 –a—— C:\WINDOWS\system32\dtu100.dll
2007-11-29 16:28 . 2007-11-29 16:28 81,920 –a—— C:\WINDOWS\system32\dpl100.dll
2007-11-29 16:28 . 2007-11-29 16:28 416 –a—— C:\WINDOWS\system32\dtu100.dll.manifest
2007-11-29 16:28 . 2007-11-29 16:28 416 –a—— C:\WINDOWS\system32\dpl100.dll.manifest
2007-11-28 15:55 . 2007-11-28 15:55 156,992 –a—— C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 15:53 . 2007-11-28 15:53 593,920 –a—— C:\WINDOWS\system32\dpuGUI11.dll
2007-11-28 15:53 . 2007-11-28 15:53 344,064 –a—— C:\WINDOWS\system32\dpus11.dll
2007-11-28 15:53 . 2007-11-28 15:53 294,912 –a—— C:\WINDOWS\system32\dpu11.dll
2007-11-28 15:53 . 2007-11-28 15:53 294,912 –a—— C:\WINDOWS\system32\dpu10.dll
2007-11-28 15:53 . 2007-11-28 15:53 57,344 –a—— C:\WINDOWS\system32\dpv11.dll
2007-11-28 15:53 . 2007-11-28 15:53 53,248 –a—— C:\WINDOWS\system32\dpuGUI10.dll
2007-11-28 15:52 . 2007-11-28 15:52 12,288 –a—— C:\WINDOWS\system32\DivXWMPExtType.dll
2007-11-27 22:08 . 2007-11-27 22:09 d——– C:\Downloads
2007-11-27 07:50 . 2007-11-27 07:50 d——– C:\Program Files\MSXML 4.0
2007-11-26 19:32 . 2007-11-26 19:32 d——– C:\WINDOWS\system32\BWKDLogs
2007-11-26 19:28 . 2007-12-03 20:48 d——– C:\Program Files\Kodak
2007-11-26 19:27 . 2007-12-03 20:55 d——– C:\Documents and Settings\All Users\Application Data\Kodak
2007-11-26 18:55 . 2007-11-26 18:55 d——– C:\Program Files\Microsoft Works
2007-11-26 18:45 . 2007-12-14 01:18 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-26 18:44 . 2007-11-26 18:44 dr-h—– C:\MSOCache
2007-11-25 22:11 . 2007-12-23 16:29 d——– C:\Program Files\Steam
2007-11-25 21:08 . 2007-11-25 21:08 d——– C:\Program Files\Activision
2007-11-25 21:07 . 2007-11-25 21:07 d–hs—- C:\WINDOWS\ftpcache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-24 12:28 81,984 —-a-w C:\WINDOWS\system32\bdod.bin
2007-12-24 08:14 ——— d—–w C:\Program Files\WhatPulse
2007-12-24 07:46 ——— d—–w C:\Program Files\iTunes
2007-12-24 07:40 ——— d—–w C:\Program Files\FlashGet
2007-12-24 06:10 ——— d—–w C:\Documents and Settings\John\Application Data\Xfire
2007-12-23 23:02 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-23 23:00 107,832 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-12-23 22:26 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-20 16:34 ——— d—–w C:\Documents and Settings\John\Application Data\Azureus
2007-12-19 23:39 ——— d—–w C:\Program Files\Xfire
2007-12-18 13:46 ——— d—–w C:\Program Files\MSN Messenger
2007-12-18 13:46 ——— d—–w C:\Program Files\Messenger Plus! Live
2007-12-16 01:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\BitDefender
2007-12-10 04:24 ——— d—–w C:\Documents and Settings\John\Application Data\Uniblue
2007-12-09 19:12 ——— d—–w C:\Program Files\DivX
2007-12-08 09:17 ——— d—–w C:\Program Files\Azureus
2007-11-29 22:30 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2007-11-29 22:30 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 15:25 77,824 —-a-w C:\WINDOWS\system32\xcomm.dll
2007-11-28 11:24 87,952 ——w C:\WINDOWS\system32\drivers\bdfndisf.sys
2007-11-28 05:44 ——— d—–w C:\Documents and Settings\John\Application Data\Bioshock
2007-11-26 04:03 66,872 —-a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-11-17 16:45 ——— d—–w C:\Program Files\Common Files\Adobe
2007-11-16 04:38 ——— d—–w C:\Program Files\Ventrilo
2007-11-16 04:38 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-15 05:12 ——— d—–w C:\Program Files\MessengerPlus! 3
2007-11-15 00:47 ——— d—–w C:\Documents and Settings\John\Application Data\Ventrilo
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-12 06:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\Uniblue
2007-11-09 16:19 ——— d—–w C:\Program Files\iPod
2007-11-06 04:21 ——— d—–w C:\Program Files\Wild Hare
2007-11-06 04:05 ——— d—–w C:\Program Files\netbeans-5.5
2007-11-06 04:04 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-06 03:32 ——— d—–w C:\Program Files\Ubisoft
2007-11-06 01:59 ——— d—–w C:\Program Files\2K Games
2007-11-06 01:04 ——— d—–w C:\Program Files\ATI Technologies
2007-11-06 01:03 ——— d—–w C:\Program Files\Common Files\ATI Technologies
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-28 22:52 ——— d—–w C:\Documents and Settings\John\Application Data\acccore
2007-10-28 22:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-10-28 22:51 ——— d—–w C:\Program Files\AIM6
2007-10-28 22:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-28 22:50 ——— d—–w C:\Program Files\Common Files\AOL
2007-10-27 23:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 03:01 ——— d—–w C:\Program Files\Soldier of Fortune II - Double Helix
2007-10-26 14:56 ——— d—–w C:\Program Files\Codemasters
2007-10-25 22:20 ——— d—–w C:\Program Files\Sun
2007-10-25 22:20 ——— d—–w C:\Program Files\Java
2007-10-25 21:33 ——— d—–w C:\Program Files\WS_FTP
2007-10-24 23:41 ——— d—–w C:\Program Files\Sierra
2007-09-29 03:06 268,800 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2007-09-29 02:47 3,130,720 —-a-w C:\WINDOWS\system32\ati3duag.dll
2007-09-29 02:36 1,593,600 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2007-09-29 02:14 499,712 —-a-w C:\WINDOWS\system32\ati2cqag.dll
2007-09-12 04:49 22,328 —-a-w C:\Documents and Settings\John\Application Data\PnkBstrK.sys
2007-08-08 07:17 15,727,521 —-a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_08_08_00_01_42_full.dmp.zip
2007-08-19 04:37 5,307,936 –sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-19 04:37 317,216 –sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
.

((((((((((((((((((((((((((((( snapshot@2007-12-17_18.24.29.76 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-26 03:24:15 53,248 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2007-12-23 21:23:51 53,248 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2007-11-26 03:24:15 12,800 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2007-12-23 21:23:51 12,800 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2007-11-26 03:24:16 473,600 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2007-12-23 21:23:51 473,600 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2007-11-26 03:24:11 577,024 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-23 21:23:51 577,024 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2007-11-26 03:24:17 145,920 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2007-12-23 21:23:52 145,920 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2007-11-26 03:24:18 159,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2007-12-23 21:23:52 159,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2007-11-26 03:24:18 364,544 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2007-12-23 21:23:52 364,544 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2007-11-26 03:24:19 178,176 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2007-12-23 21:23:53 178,176 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2007-11-26 03:24:14 223,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2007-12-23 21:23:50 223,232 —-a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2006-08-24 14:28:54 141,424 —-a-w C:\WINDOWS\Downloaded Program Files\asinst.dll
+ 2007-12-21 05:42:02 10,134 —-a-r C:\WINDOWS\Installer\{3BD633E0-4BF8-4499-9149-88F0767D449C}\ARPPRODUCTICON.exe
+ 2007-03-29 15:20:50 110,592 —-a-w C:\WINDOWS\system32\ActiveScan\as.dll
+ 2006-10-05 22:15:26 233,472 —-a-w C:\WINDOWS\system32\ActiveScan\ascontrol.dll
+ 2005-06-03 20:03:18 96,256 —-a-w C:\WINDOWS\system32\ActiveScan\asmdat.dll
+ 2003-08-01 17:00:16 36,864 —-a-w C:\WINDOWS\system32\ActiveScan\certdll.dll
+ 2005-05-20 19:42:44 86,016 —-a-w C:\WINDOWS\system32\ActiveScan\instlsp.dll
+ 2007-11-12 15:46:18 26,112 —-a-w C:\WINDOWS\system32\ActiveScan\JID.dll
+ 2006-02-17 00:20:20 4,608 —-a-w C:\WINDOWS\system32\ActiveScan\memvfile.dll
+ 2005-10-26 00:08:32 348,160 —-a-w C:\WINDOWS\system32\ActiveScan\msvcr71.dll
+ 2007-11-26 17:10:36 61,440 —-a-w C:\WINDOWS\system32\ActiveScan\NanoWrapper.dll
+ 2004-05-04 21:01:02 139,264 —-a-w C:\WINDOWS\system32\ActiveScan\pavaleas.dll
+ 2006-07-14 19:04:10 45,056 —-a-w C:\WINDOWS\system32\ActiveScan\pavdr.exe
+ 2006-04-10 16:50:02 159,832 —-a-w C:\WINDOWS\system32\ActiveScan\pavexcom.dll
+ 2006-02-14 19:05:38 94,208 —-a-w C:\WINDOWS\system32\ActiveScan\pavinas.dll
+ 2006-02-17 00:35:38 180,224 —-a-w C:\WINDOWS\system32\ActiveScan\pavoe.dll
+ 2006-10-05 22:15:38 122,880 —-a-w C:\WINDOWS\system32\ActiveScan\pavpz.dll
+ 2007-06-04 17:31:52 57,344 —-a-w C:\WINDOWS\system32\ActiveScan\pavsddl.dll
+ 2006-06-30 20:13:38 8,704 —-a-w C:\WINDOWS\system32\ActiveScan\pfdnnt.exe
+ 2004-02-04 20:08:42 49,152 —-a-w C:\WINDOWS\system32\ActiveScan\port32.dll
+ 2007-10-30 16:04:14 36,864 —-a-w C:\WINDOWS\system32\ActiveScan\Prescan.dll
+ 2006-08-01 19:23:10 69,632 —-a-w C:\WINDOWS\system32\ActiveScan\pscpu.dll
+ 2007-11-21 16:00:06 376,832 —-a-w C:\WINDOWS\system32\ActiveScan\pskahk.dll
+ 2007-10-31 19:05:06 32,768 —-a-w C:\WINDOWS\system32\ActiveScan\PSKAHKPRESCAN.dll
+ 2006-08-17 17:38:14 10,752 —-a-w C:\WINDOWS\system32\ActiveScan\pskalloc.dll
+ 2006-09-04 17:49:54 61,440 —-a-w C:\WINDOWS\system32\ActiveScan\pskas.dll
+ 2006-08-18 14:46:18 779,264 —-a-w C:\WINDOWS\system32\ActiveScan\pskavs.dll
+ 2007-03-26 20:25:34 417,792 —-a-w C:\WINDOWS\system32\ActiveScan\pskcmp.dll
+ 2006-08-09 16:42:24 90,112 —-a-w C:\WINDOWS\system32\ActiveScan\pskfss.dll
+ 2006-07-19 16:55:58 208,896 —-a-w C:\WINDOWS\system32\ActiveScan\pskhtml.dll
+ 2006-01-20 22:57:00 9,728 —-a-w C:\WINDOWS\system32\ActiveScan\pskmas.dll
+ 2006-05-17 15:50:12 14,336 —-a-w C:\WINDOWS\system32\ActiveScan\pskmdfs.dll
+ 2006-08-16 16:58:12 33,280 —-a-w C:\WINDOWS\system32\ActiveScan\pskpack.dll
+ 2006-06-30 20:42:36 266,240 —-a-w C:\WINDOWS\system32\ActiveScan\pskscs.dll
+ 2006-08-17 20:33:14 62,976 —-a-w C:\WINDOWS\system32\ActiveScan\pskutil.dll
+ 2006-08-08 19:13:10 13,312 —-a-w C:\WINDOWS\system32\ActiveScan\pskvfile.dll
+ 2006-08-18 14:53:08 69,632 —-a-w C:\WINDOWS\system32\ActiveScan\pskvfs.dll
+ 2006-08-18 14:49:50 167,936 —-a-w C:\WINDOWS\system32\ActiveScan\pskvm.dll
+ 2007-10-18 15:30:16 105,472 —-a-w C:\WINDOWS\system32\ActiveScan\psnahk.dll
+ 2007-11-23 20:29:08 10,752 —-a-w C:\WINDOWS\system32\ActiveScan\psndsk.dll
+ 2007-10-18 15:30:38 42,496 —-a-w C:\WINDOWS\system32\ActiveScan\psnflg.dll
+ 2007-10-30 17:19:22 98,304 —-a-w C:\WINDOWS\system32\ActiveScan\psnglknt.dll
+ 2007-08-22 14:52:00 20,272 —-a-w C:\WINDOWS\system32\ActiveScan\psnhsh.dll
+ 2007-11-12 21:49:34 11,776 —-a-w C:\WINDOWS\system32\ActiveScan\psnjidsign.dll
+ 2007-08-22 14:52:04 76,080 —-a-w C:\WINDOWS\system32\ActiveScan\psnkrnl.dll
+ 2007-08-22 14:52:06 21,296 —-a-w C:\WINDOWS\system32\ActiveScan\psnmem.dll
+ 2007-10-04 21:26:28 28,672 —-a-w C:\WINDOWS\system32\ActiveScan\PsnPen.dll
+ 2007-10-23 17:40:10 86,016 —-a-w C:\WINDOWS\system32\ActiveScan\psntuc.dll
+ 2007-05-24 17:27:36 27,136 —-a-w C:\WINDOWS\system32\ActiveScan\PSNXprs.dll
+ 2007-04-18 23:16:04 353,840 —-a-w C:\WINDOWS\system32\ActiveScan\psscan.dll
+ 2007-01-22 20:42:48 35,328 —-a-w C:\WINDOWS\system32\ActiveScan\rawvfile.dll
+ 2007-06-08 15:44:36 8,576 —-a-w C:\WINDOWS\system32\ActiveScan\RKPavProc.sys
+ 2007-06-05 16:56:40 44,928 —-a-w C:\WINDOWS\system32\ActiveScan\sdthook.sys
+ 1997-09-18 12:12:32 9,488 —-a-w C:\WINDOWS\system32\ActiveScan\sporder.dll
+ 2006-02-28 23:23:40 69,632 —-a-w C:\WINDOWS\system32\ActiveScan\tcpvfile.dll
+ 2007-09-17 15:14:08 126,976 —-a-w C:\WINDOWS\system32\ActiveScan\Tucan.dll
+ 2006-08-02 18:39:06 73,728 —-a-w C:\WINDOWS\system32\asuninst.exe
+ 2003-03-26 00:53:50 11,776 —-a-w C:\WINDOWS\system32\ZPORT4AS.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
{381FFDE8-2394-4F90-B10D-FC6124A40F8C}

[HKEY_CLASSES_ROOT\clsid\{381ffde8-2394-4f90-b10d-fc6124a40f8c}]
[HKEY_CLASSES_ROOT\BitDefender Toolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WhatPulse"="C:\Program Files\WhatPulse\WhatPulse.exe" [2004-12-05 04:20]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-01-18 16:07]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 18:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 17:28]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\smax4.exe" [2003-05-30 10:42]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 17:24]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 01:06 C:\WINDOWS\system32\ptipbmf.dll]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 10:52]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 15:40]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-18 16:47]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-18 16:37]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2007-11-28 05:24]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-11-01 12:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 09:12]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"powercfg"="c:\windows\system32\powercfg.exe" [2004-08-03 18:56]
"CmUsbSound"="RunDll32 cmcnfgu.cpl" []
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-09-21 12:50:14]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-08-17 00:55:47]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-08-09 11:37:25]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aunw]
C:\WINDOWS\SSTEM~1\explorer.exe -vt yazb

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dxdiag]
2004-08-03 18:56 1298432 –a—— c:\windows\system32\dxdiag.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ftp]
2004-08-03 18:56 42496 –a—— c:\windows\system32\ftp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
C:\Program Files\MessengerPlus! 3\MsgPlus.exe /WinStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Notepad]
2004-08-03 18:56 69120 –a—— c:\windows\notepad.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\systeminfo]
2004-08-06 14:18 68096 –a—— c:\windows\system32\systeminfo.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vnertlm]
C:\Program Files\Common Files\?racle\??oolsv.exe

R1 bdftdif;bdftdif;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys [2007-11-28 04:21]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2007-11-28 05:24]
R3 bdfsfltr;bdfsfltr;C:\WINDOWS\system32\DRIVERS\bdfsfltr.sys [2007-08-02 16:03]
R3 BDSelfPr;BDSelfPr;C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys [2007-08-08 13:12]
R3 cmudaxu;C-Media USB Sound Interface;C:\WINDOWS\system32\drivers\cmudaxu.sys [2005-11-03 00:50]
R3 scan;BitDefender Threat Scanner;C:\WINDOWS\System32\svchost.exe -kbdx []
S3 ASUSHWIO;ASUSHWIO;C:\WINDOWS\system32\drivers\ASUSHWIO.sys []
S3 samhid;samhid;C:\WINDOWS\system32\drivers\samhid.sys [2004-07-14 11:51]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan

*Newly Created Service* - RKPAVPROC
.
Contents of the 'Scheduled Tasks' folder
"2007-12-24 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2007-12-21 14:04:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-22 06:28:00 C:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2007-11-12 06:28:30 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-24 06:29:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\Logitech\SetPoint\GameHook.dll
.
Completion time: 2007-12-24 6:30:34
C:\ComboFix2.txt … 2007-12-19 12:30
C:\ComboFix3.txt … 2007-12-17 18:25
.
2007-12-13 05:30:51 — E O F —
Hi leta,

COMBOFIX-Script
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Folder::
    C:\WINDOWS\SSTEM~1

    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aunw]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vnertlm]

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———————————————-
Run HijackThis again.
———————————————-
Post back:
Combofix report.
A new HijackThis log.
ComboFix 07-12-17.1 - John 2007-12-26 6:35:11.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1401 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\John\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-11-26 to 2007-12-26 )))))))))))))))))))))))))))))))
.

2007-12-24 00:15 . 2007-12-24 02:32 d——– C:\WINDOWS\system32\ActiveScan
2007-12-24 00:15 . 2007-12-24 00:38 30,590 –a—— C:\WINDOWS\system32\pavas.ico
2007-12-24 00:15 . 2007-12-24 00:38 2,550 –a—— C:\WINDOWS\system32\Uninstall.ico
2007-12-24 00:15 . 2007-12-24 00:38 1,406 –a—— C:\WINDOWS\system32\Help.ico
2007-12-21 10:48 . 2007-12-21 10:48 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-12-20 11:23 . 2007-12-20 11:23 d——– C:\Program Files\FLV Player
2007-12-20 11:18 . 2007-12-20 22:47 d——– C:\Documents and Settings\John\dwhelper
2007-12-20 00:01 . 2007-12-20 00:02 d——– C:\Program Files\QuickTime
2007-12-17 19:47 . 2007-12-21 00:52 23 –a—— C:\WINDOWS\popcinfot.dat
2007-12-15 18:49 . 2007-12-15 18:49 d——– C:\Documents and Settings\John\Application Data\TrojanHunter
2007-12-15 13:44 . 2007-12-15 14:13 d——– C:\Documents and Settings\John\Application Data\AdwareAlert
2007-12-15 13:37 . 2007-12-15 13:37 d——– C:\Program Files\Trend Micro
2007-12-14 01:16 . 2006-10-26 19:56 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2007-12-13 15:05 . 2007-12-13 15:05 d——– C:\Program Files\MSBuild
2007-12-13 14:58 . 2007-12-13 14:58 d——– C:\Program Files\Microsoft Visual Studio 8
2007-12-12 18:54 . 2007-12-25 22:04 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-12 18:54 . 2007-12-12 18:54 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-09 14:19 . 2007-12-09 14:19 d——– C:\Documents and Settings\John\Application Data\Grisoft
2007-12-09 14:18 . 2007-12-09 14:18 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-07 11:00 . 2007-12-07 11:00 d——– C:\Program Files\Apache Software Foundation
2007-12-07 10:59 . 2007-12-07 11:01 d——– C:\Program Files\glassfish-v2
2007-12-07 10:57 . 2007-12-07 10:59 d——– C:\Program Files\NetBeans 6.0
2007-12-07 10:56 . 2007-12-07 11:00 d——– C:\Documents and Settings\John\.nbi
2007-12-03 21:12 . 2007-12-03 21:12 d——– C:\Program Files\CCleaner
2007-12-03 19:33 . 2007-12-03 19:33 823,296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-12-03 19:33 . 2007-12-03 19:33 823,296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-12-03 19:33 . 2007-12-03 19:33 802,816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-12-03 19:33 . 2007-12-03 19:33 682,496 –a—— C:\WINDOWS\system32\DivX.dll
2007-11-29 23:14 . 2007-11-29 23:14 d——– C:\Documents and Settings\NetworkService\Application Data\Azureus
2007-11-29 16:30 . 2007-11-29 16:30 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-11-29 16:30 . 2007-11-29 16:30 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-11-29 16:30 . 2007-11-29 16:30 4,816 –a—— C:\WINDOWS\system32\divxsm.tlb
2007-11-29 16:28 . 2007-11-29 16:28 196,608 –a—— C:\WINDOWS\system32\dtu100.dll
2007-11-29 16:28 . 2007-11-29 16:28 81,920 –a—— C:\WINDOWS\system32\dpl100.dll
2007-11-29 16:28 . 2007-11-29 16:28 416 –a—— C:\WINDOWS\system32\dtu100.dll.manifest
2007-11-29 16:28 . 2007-11-29 16:28 416 –a—— C:\WINDOWS\system32\dpl100.dll.manifest
2007-11-28 15:55 . 2007-11-28 15:55 156,992 –a—— C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 15:53 . 2007-11-28 15:53 593,920 –a—— C:\WINDOWS\system32\dpuGUI11.dll
2007-11-28 15:53 . 2007-11-28 15:53 344,064 –a—— C:\WINDOWS\system32\dpus11.dll
2007-11-28 15:53 . 2007-11-28 15:53 294,912 –a—— C:\WINDOWS\system32\dpu11.dll
2007-11-28 15:53 . 2007-11-28 15:53 294,912 –a—— C:\WINDOWS\system32\dpu10.dll
2007-11-28 15:53 . 2007-11-28 15:53 57,344 –a—— C:\WINDOWS\system32\dpv11.dll
2007-11-28 15:53 . 2007-11-28 15:53 53,248 –a—— C:\WINDOWS\system32\dpuGUI10.dll
2007-11-28 15:52 . 2007-11-28 15:52 12,288 –a—— C:\WINDOWS\system32\DivXWMPExtType.dll
2007-11-27 22:08 . 2007-11-27 22:09 d——– C:\Downloads
2007-11-27 07:50 . 2007-11-27 07:50 d——– C:\Program Files\MSXML 4.0
2007-11-26 19:32 . 2007-11-26 19:32 d——– C:\WINDOWS\system32\BWKDLogs
2007-11-26 19:28 . 2007-12-03 20:48 d——– C:\Program Files\Kodak
2007-11-26 19:27 . 2007-12-03 20:55 d——– C:\Documents and Settings\All Users\Application Data\Kodak
2007-11-26 18:55 . 2007-11-26 18:55 d——– C:\Program Files\Microsoft Works
2007-11-26 18:45 . 2007-12-14 01:18 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-26 18:44 . 2007-11-26 18:44 dr-h—– C:\MSOCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-26 12:36 81,984 —-a-w C:\WINDOWS\system32\bdod.bin
2007-12-26 04:25 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-26 04:25 107,832 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-12-26 04:22 ——— d—–w C:\Documents and Settings\John\Application Data\Xfire
2007-12-24 08:14 ——— d—–w C:\Program Files\WhatPulse
2007-12-24 07:46 ——— d—–w C:\Program Files\iTunes
2007-12-24 07:40 ——— d—–w C:\Program Files\FlashGet
2007-12-23 22:29 ——— d—–w C:\Program Files\Steam
2007-12-23 22:26 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-20 16:34 ——— d—–w C:\Documents and Settings\John\Application Data\Azureus
2007-12-19 23:39 ——— d—–w C:\Program Files\Xfire
2007-12-18 13:46 ——— d—–w C:\Program Files\MSN Messenger
2007-12-18 13:46 ——— d—–w C:\Program Files\Messenger Plus! Live
2007-12-16 01:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\BitDefender
2007-12-10 04:24 ——— d—–w C:\Documents and Settings\John\Application Data\Uniblue
2007-12-09 19:12 ——— d—–w C:\Program Files\DivX
2007-12-08 09:17 ——— d—–w C:\Program Files\Azureus
2007-11-29 22:30 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2007-11-29 22:30 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 15:25 77,824 —-a-w C:\WINDOWS\system32\xcomm.dll
2007-11-28 11:24 87,952 ——w C:\WINDOWS\system32\drivers\bdfndisf.sys
2007-11-28 05:44 ——— d—–w C:\Documents and Settings\John\Application Data\Bioshock
2007-11-26 04:03 66,872 —-a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-11-26 03:08 ——— d—–w C:\Program Files\Activision
2007-11-17 16:45 ——— d—–w C:\Program Files\Common Files\Adobe
2007-11-16 04:38 ——— d—–w C:\Program Files\Ventrilo
2007-11-16 04:38 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-15 05:12 ——— d—–w C:\Program Files\MessengerPlus! 3
2007-11-15 00:47 ——— d—–w C:\Documents and Settings\John\Application Data\Ventrilo
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-12 06:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\Uniblue
2007-11-09 16:19 ——— d—–w C:\Program Files\iPod
2007-11-06 04:21 ——— d—–w C:\Program Files\Wild Hare
2007-11-06 04:05 ——— d—–w C:\Program Files\netbeans-5.5
2007-11-06 04:04 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-06 03:32 ——— d—–w C:\Program Files\Ubisoft
2007-11-06 01:59 ——— d—–w C:\Program Files\2K Games
2007-11-06 01:04 ——— d—–w C:\Program Files\ATI Technologies
2007-11-06 01:03 ——— d—–w C:\Program Files\Common Files\ATI Technologies
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-28 22:52 ——— d—–w C:\Documents and Settings\John\Application Data\acccore
2007-10-28 22:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-10-28 22:51 ——— d—–w C:\Program Files\AIM6
2007-10-28 22:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-28 22:50 ——— d—–w C:\Program Files\Common Files\AOL
2007-10-27 23:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 03:01 ——— d—–w C:\Program Files\Soldier of Fortune II - Double Helix
2007-10-26 14:56 ——— d—–w C:\Program Files\Codemasters
2007-09-29 03:06 268,800 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2007-09-29 02:47 3,130,720 —-a-w C:\WINDOWS\system32\ati3duag.dll
2007-09-29 02:36 1,593,600 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2007-09-29 02:14 499,712 —-a-w C:\WINDOWS\system32\ati2cqag.dll
2007-09-12 04:49 22,328 —-a-w C:\Documents and Settings\John\Application Data\PnkBstrK.sys
2007-08-08 07:17 15,727,521 —-a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_08_08_00_01_42_full.dmp.zip
2007-08-19 04:37 5,307,936 –sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-19 04:37 317,216 –sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
{381FFDE8-2394-4F90-B10D-FC6124A40F8C}

[HKEY_CLASSES_ROOT\clsid\{381ffde8-2394-4f90-b10d-fc6124a40f8c}]
[HKEY_CLASSES_ROOT\BitDefender Toolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WhatPulse"="C:\Program Files\WhatPulse\WhatPulse.exe" [2004-12-05 04:20]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-01-18 16:07]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 18:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 17:28]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\smax4.exe" [2003-05-30 10:42]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 17:24]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 01:06 C:\WINDOWS\system32\ptipbmf.dll]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 10:52]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 15:40]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-18 16:47]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-18 16:37]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2007-11-28 05:24]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-11-01 12:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 09:12]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"powercfg"="c:\windows\system32\powercfg.exe" [2004-08-03 18:56]
"CmUsbSound"="RunDll32 cmcnfgu.cpl" []
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-09-21 12:50:14]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-08-17 00:55:47]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-08-09 11:37:25]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dxdiag]
2004-08-03 18:56 1298432 –a—— c:\windows\system32\dxdiag.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ftp]
2004-08-03 18:56 42496 –a—— c:\windows\system32\ftp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
C:\Program Files\MessengerPlus! 3\MsgPlus.exe /WinStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Notepad]
2004-08-03 18:56 69120 –a—— c:\windows\notepad.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\systeminfo]
2004-08-06 14:18 68096 –a—— c:\windows\system32\systeminfo.exe

R1 bdftdif;bdftdif;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys [2007-11-28 04:21]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2007-11-28 05:24]
R3 bdfsfltr;bdfsfltr;C:\WINDOWS\system32\DRIVERS\bdfsfltr.sys [2007-08-02 16:03]
R3 BDSelfPr;BDSelfPr;C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys [2007-08-08 13:12]
R3 cmudaxu;C-Media USB Sound Interface;C:\WINDOWS\system32\drivers\cmudaxu.sys [2005-11-03 00:50]
R3 scan;BitDefender Threat Scanner;C:\WINDOWS\System32\svchost.exe -kbdx []
S3 ASUSHWIO;ASUSHWIO;C:\WINDOWS\system32\drivers\ASUSHWIO.sys []
S3 samhid;samhid;C:\WINDOWS\system32\drivers\samhid.sys [2004-07-14 11:51]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan

.
Contents of the 'Scheduled Tasks' folder
"2007-12-26 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2007-12-21 14:04:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-22 06:28:00 C:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2007-11-12 06:28:30 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-26 06:38:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\Logitech\SetPoint\GameHook.dll
.
Completion time: 2007-12-26 6:39:50
C:\ComboFix2.txt … 2007-12-24 06:30
C:\ComboFix3.txt … 2007-12-19 12:30
.
2007-12-13 05:30:51 — E O F —
=============================================================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:56:51 AM, on 12/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\WhatPulse\WhatPulse.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [powercfg] "c:\windows\system32\powercfg.exe"
O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [WhatPulse] C:\Program Files\WhatPulse\WhatPulse.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://cdn1.acclaimdownloads.com/solidstateion.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

–
End of file - 8974 bytes
Hi leta,

It seemed we've cleaned those bad infection registry entries.

Now i need you to do this please:
(Little Detective work ;) )
This is needed so we are definitely sure the bad folders are removed.
We don't want them to stay on your machine.

Now we need to do a search.
Start > Search > For Files and Folders.
Expand Search Options, check Advanced Options, check Search system folders, Search hidden files and folders, and Search Subfolders.
Paste this into the Search for files and folders named box:

SSTEM

Click search.

Do the same and search for this too:
?racle << this folder might have a strange s at the ? sign.

What ever are your foundings please copy them all, back including the path, example:

C:\WINDOWS\SSTEM~1 << path in red
C:\Program Files\Common Files\?racle << path in red

You may find other folders, which are similar, just post back for me all of them including the path. You can use Notepad to take notes and then copy them back here.
This came up for ?racle: 3 xml files in folder C:\Program Files\glassfish-v2\lib\install\templates\resources\jdbc This came up for SSTEM: Multiple files came up but in the same folder C:\Program Files\Codemasters\Overlord\Language (this is a game)
FindFile

Download FindFile by Atribune from >here<
  • Extract the contents to your Desktop
  • Double click on FileFind.exe to open the program.
  • Enter ??oolsv.exe into the File: box.
  • Click on the Search button.
  • After a while, if any files are found, a list of file locations will appear in the List of Files: box.
  • Click on the Export button.
  • This will create a Notepad file named Export.txt located in the C:\ folder, copy and paste it to your next post please.

When the program is finished and create the report, please follow the same procedure but for this file now:explorer.exe

Post back both reports please.
For ??oolsv.exe: C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe - 57856 Bytes C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe - 57856 Bytes C:\WINDOWS\system32\spoolsv.exe - 57856 Bytes C:\WINDOWS\system32\dllcache\spoolsv.exe - 57856 Bytes For explorer.exe: C:\WINDOWS\explorer.exe - 1033216 Bytes C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe - 1033216 Bytes C:\WINDOWS\$NtUninstallKB938828$\explorer.exe - 1032192 Bytes C:\WINDOWS\system32\dllcache\explorer.exe - 1033216 Bytes
Hi leta,

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • [external image: Posted Image]
  • When shown the disclaimer, Select "2"
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Please also remove FileFind.exe
————————————————-
Congratulations you are clean! :)
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Here are some free programs I recommend that could help you improve your computer's security.

Ad-aware 2007
Download it from here
Find here the tutorial on how to use Adaware properly here

Spybot Search and Destroy 1.5.1
Download it from here. Just choose a mirror and off you go.
Find here the tutorial on how to use Spybot properly here
Find here changes from older version 1.4 here

Install Spyware Guard
Download it from here
Find here the tutorial on how to use Spyware Guard here

Install SpyWare Blaster
Download it from here
Find here the tutorial on how to use Spyware Blaster here

Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here

Install FireTrust SiteHound
Download it from here

Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com

Please check out Tony Klein's article "How did I get infected in the first place?"

Read some information here how to prevent Malware.

Happy safe surfing!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI