Spyware / Malware / Virus Removal
[Resolved] Virus infection
7 min read
warp13speed
Topic Starter
I get the following dialog popping up every few minutes:
Security Warning!
Worm.Win32.NetSky detected on your machine. This virus is distributed via the Internet through e-mail and Active-X objects. The worm has its own SMTP engine which means it gathers e-mails from your local computer and re-distributes itself. In worst cases this worm can allow attackers to access your computer, stealing passwords and personal data.
This process should be removed from your system.
Type: Virus
System Affected: Windows 2000, NT, ME, XP, Vista
Security Risk (0-5): 5
Recommendations: Click Yes to remove it from your PC immediately.
I also get this dialog regularly:
Windows has detected an Internet attack attemptβ¦
Somebody's trying to infect your PC with spyware or harmful viruses. Run full system scan now to protect your PC from Internet attacks, hijacking attempts and spyware! Click here to download spyware remover for total protection.
I know these are fake and more harmful to my system so I always cancel them. I have Symantec AntiVirus version 8.00.0374 installed and running.
Please help me get rid of this problem.
RatHat
Hi there,
Welcome to WTT. My name is RatHat, and I will help you get through the process of cleaning the malware from your computer.
OK firstly, I need you to print out each post I make so that you can refer to it while we fix your computer. This is because there will be times when you are unable to be online to read my instructions, and I will want you to do everything very carefully. I also need you to follow my instructions in the order that they are given. If however, you cannot carry out one of them, please continue on with the next and let me know what you were unsuccessful with.
Next, I would like to make sure that you can view hidden files and folders;
Please download Deckard's System Scanner (DSS) and save it to your Desktop.
Regards,
RatHat
Welcome to WTT. My name is RatHat, and I will help you get through the process of cleaning the malware from your computer.
OK firstly, I need you to print out each post I make so that you can refer to it while we fix your computer. This is because there will be times when you are unable to be online to read my instructions, and I will want you to do everything very carefully. I also need you to follow my instructions in the order that they are given. If however, you cannot carry out one of them, please continue on with the next and let me know what you were unsuccessful with.
Next, I would like to make sure that you can view hidden files and folders;
- Click Start.
- Open My Computer.
- Select the Tools menu and click Folder Options.
- Select the View tab.
- Under the Hidden files and folders heading SELECT Show hidden files and folders.
- UNCHECK the Hide protected operating system files (recommended) option.
- UNCHECK the Hide extensions for known file types option.
- Click Yes to confirm.
- Click OK.
Please download Deckard's System Scanner (DSS) and save it to your Desktop.
- Close all other windows before proceeding.
- Double-click on dss.exe and follow the prompts.
- When it has finished, DSS will open two Notepad files: main.txt and extra.txt
- Use Save As to save both Notepad files to your Desktop and post them in your next reply.
Regards,
RatHat
warp13speed
RatHat,
Thank you very much for your reply. Here is the information you asked for.
main.txt
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-03-13 17:21:19
Computer is in Normal Mode.
βββββββββββββββββββββββββββ
β HijackThis (run as Neil.exe) ββββββββββββββββ
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:21:20 PM, on 3/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\APPS\ELLIS\Kids\Licensing System\Components\ILSDAEM.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\Neil\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Neil.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f505.mail.yahoo.com/ym/ShowLetteβ¦ew=a&head;=b
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F3 - REG:win.ini: load=C:\OPLIMIT\ocraware.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Shortcut to Microsoft Outlook.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/β¦b?1175293912031
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdatβ¦b?1176080434828
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://pdl2.webex.com/client/T25L/support/ieatgpc.cab
O21 - SSODL: altvxvm - {4F60FF9E-DD27-40D9-B2D2-D4E3E3C8E52B} - C:\WINDOWS\altvxvm.dll
O21 - SSODL: bokpkov - {98BAEF40-36B7-4C9F-A6C6-4442660315B0} - C:\WINDOWS\bokpkov.dll
O21 - SSODL: AlrtCD - {66e8ddd8-16eb-4aa4-8867-e2afd68ff83a} - C:\WINDOWS\Installer\{66e8ddd8-16eb-4aa4-8867-e2afd68ff83a}\AlrtCD.dll
O21 - SSODL: zip - {1598954a-2b07-46e3-90b0-7725b0d79f2a} - C:\WINDOWS\Installer\{1598954a-2b07-46e3-90b0-7725b0d79f2a}\zip.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ILS Daemon - Unknown owner - C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
β
End of file - 7459 bytes
β Files created between 2008-02-13 and 2008-03-13 ββββββββββ
2008-03-13 17:20:03 0 dβββ C:\Program Files\Trend Micro
2008-03-12 23:20:46 0 dβββ C:\Documents and Settings\Suzanne\Application Data\AntispywareBot
2008-03-12 22:01:33 0 dβββ C:\Documents and Settings\Neil\Application Data\AntispywareBot
2008-03-12 22:01:23 0 dβββ C:\Program Files\AntiSpywareBot
2008-03-11 17:26:18 98304 βaββ C:\WINDOWS\fmsxwqs.exe
2008-03-11 17:26:18 221184 βaββ C:\WINDOWS\bokpkov.dll
2008-03-11 17:26:18 208896 βaββ C:\WINDOWS\altvxvm.dll
Thank you very much for your reply. Here is the information you asked for.
main.txt
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-03-13 17:21:19
Computer is in Normal Mode.
βββββββββββββββββββββββββββ
β HijackThis (run as Neil.exe) ββββββββββββββββ
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:21:20 PM, on 3/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\APPS\ELLIS\Kids\Licensing System\Components\ILSDAEM.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\Neil\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Neil.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f505.mail.yahoo.com/ym/ShowLetteβ¦ew=a&head;=b
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F3 - REG:win.ini: load=C:\OPLIMIT\ocraware.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Shortcut to Microsoft Outlook.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/β¦b?1175293912031
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdatβ¦b?1176080434828
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://pdl2.webex.com/client/T25L/support/ieatgpc.cab
O21 - SSODL: altvxvm - {4F60FF9E-DD27-40D9-B2D2-D4E3E3C8E52B} - C:\WINDOWS\altvxvm.dll
O21 - SSODL: bokpkov - {98BAEF40-36B7-4C9F-A6C6-4442660315B0} - C:\WINDOWS\bokpkov.dll
O21 - SSODL: AlrtCD - {66e8ddd8-16eb-4aa4-8867-e2afd68ff83a} - C:\WINDOWS\Installer\{66e8ddd8-16eb-4aa4-8867-e2afd68ff83a}\AlrtCD.dll
O21 - SSODL: zip - {1598954a-2b07-46e3-90b0-7725b0d79f2a} - C:\WINDOWS\Installer\{1598954a-2b07-46e3-90b0-7725b0d79f2a}\zip.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ILS Daemon - Unknown owner - C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
β
End of file - 7459 bytes
β Files created between 2008-02-13 and 2008-03-13 ββββββββββ
2008-03-13 17:20:03 0 dβββ C:\Program Files\Trend Micro
2008-03-12 23:20:46 0 dβββ C:\Documents and Settings\Suzanne\Application Data\AntispywareBot
2008-03-12 22:01:33 0 dβββ C:\Documents and Settings\Neil\Application Data\AntispywareBot
2008-03-12 22:01:23 0 dβββ C:\Program Files\AntiSpywareBot
2008-03-11 17:26:18 98304 βaββ C:\WINDOWS\fmsxwqs.exe
2008-03-11 17:26:18 221184 βaββ C:\WINDOWS\bokpkov.dll
2008-03-11 17:26:18 208896 βaββ C:\WINDOWS\altvxvm.dll
RatHat
OK, a few things to do, so lets get to it!
Please download Brute Force Uninstaller to your desktop.
Save it to the BFU folder you just created.
Whilst you are still in the BFU folder;
Please read this Combofix tutorial before continuing, then follow the instructions below.
Download ComboFix from Here, Here or Here to your Desktop. (If you already have ComboFix, please delete it and download this new version).
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please download Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please run an online scan with Kaspersky WebScanner. Note: You must use Internet Explorer to run this scan.
Click the Accept button.
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
Please run Deckard's System Scanner (DSS) again. This time it will only produce a single Notepad file; main.txt, please copy and paste the contents in your next reply.
Note:A copy of this file can be found in you root drive, usually C:\Deckard\System Scanner\main.txt
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
So in your next post, please include the following (Use two or three posts to make sure you get all the logs in full):
Also let me know how your computer is behaving now.
Regards,
RatHat
Please download Brute Force Uninstaller to your desktop.
- Right click the BFU.zip on your desktop, and choose Extract All
- Click "Next"
- In the box to choose where to extract the files to,
- Click "Browse"
- Click on the + sign next to "My Computer"
- Click on "Local Disk (C:) or whatever your primary drive is
- Click "Make New Folder"
- Type in BFU
- Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
Save it to the BFU folder you just created.
Whilst you are still in the BFU folder;
- Start the Brute Force Uninstaller by doubleclicking BFU.exe
- Behind the scriptline to execute field click the folder icon [external image: Posted Image] and select Adware.bfu
- Press Execute and let the program do itβs job. (You ought to see a progress bar if you did this correctly.)
- On completion, allow the computer to be rebooted.
Please read this Combofix tutorial before continuing, then follow the instructions below.
Download ComboFix from Here, Here or Here to your Desktop. (If you already have ComboFix, please delete it and download this new version).
- If you are using Firefox, make sure that your download settings are as follows:
- Tools->Options->Main tab
- Set to "Always ask me where to Save the files".
- During the download, rename Combofix to Combo-Fix as follows:
[external image: Posted Image]
[external image: Posted Image]
- It is important you rename Combofix during the download, but not after.
- Please do not rename Combofix to other names, but only to the one indicated.
- Close any open browsers.
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
ββββββββββββββββββββ
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
ββββββββββββββββββββ
- Close any open browsers.
- WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
- Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
- If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
ββββββββββββββββββββ
- Double click on Combo-Fix.exe & follow the prompts.
- When finished, it shall produce a log for you. Save this log to your desktop as Combofix.txt and post it in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please download Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.
- Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select "Perform Quick Scan", then click Scan.
- The scan may take some time to finish,so please be patient.
- When the scan is complete, click OK, then Show Results to view the results.
- Make sure that everything is checked, and click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Copy&Paste the entire report in your next reply.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please run an online scan with Kaspersky WebScanner. Note: You must use Internet Explorer to run this scan.
Click the Accept button.
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
- The program will launch and then begin downloading the latest definition files:
- Once the files have been downloaded click on NEXT
- Now click on Scan Settings
- In the scan settings make that the following are selected:
- Scan using the following Anti-Virus database:
- Scan Options:
Scan Mail Bases - Click OK
- Now under select a target to scan:Select My Computer
- This will program will start and scan your system.
- The scan will take a while so be patient and let it run.
- Once the scan is complete it will display the results if your system has been infected.
- Now click on the Save as Text button:
- Save the file to your desktop as Kaspersky.txt.
- Copy and paste that information in your next post.
Please run Deckard's System Scanner (DSS) again. This time it will only produce a single Notepad file; main.txt, please copy and paste the contents in your next reply.
Note:A copy of this file can be found in you root drive, usually C:\Deckard\System Scanner\main.txt
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
So in your next post, please include the following (Use two or three posts to make sure you get all the logs in full):
- The contents of Combofix.txt
- The contents of the MBAM report
- The contents of Kaspersky.txt
- The DSS Main.txt
Also let me know how your computer is behaving now.
Regards,
RatHat
warp13speed
Combofix.txt
ComboFix 08-03-13.4 - Neil 2008-03-13 20:07:27.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1617 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Desktop\AntiSpywareBot.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\AntiSpywareBot
C:\Documents and Settings\All Users\Start Menu\Programs\AntiSpywareBot\AntiSpywareBot on the Web.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\AntiSpywareBot\AntiSpywareBot.lnk
C:\Documents and Settings\Neil\Application Data\AntispywareBot
C:\Documents and Settings\Neil\Application Data\AntispywareBot\Log\2008 Mar 13 - 05_09_02 PM_171.log
C:\Documents and Settings\Neil\Application Data\AntispywareBot\rs.dat
C:\Documents and Settings\Suzanne\Application Data\AntispywareBot
C:\Documents and Settings\Suzanne\Application Data\AntispywareBot\Log\2008 Mar 13 - 05_06_48 PM_734.log
C:\Documents and Settings\Suzanne\Application Data\AntispywareBot\Log\2008 Mar 13 - 12_54_18 PM_656.log
C:\Documents and Settings\Suzanne\Application Data\AntispywareBot\Log\2008 Mar 13 - 12_56_07 PM_921.log
C:\Documents and Settings\Suzanne\Application Data\AntispywareBot\rs.dat
C:\Program Files\AntiSpywareBot
C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe
C:\Program Files\AntiSpywareBot\AntiSpywareBot.url
C:\Program Files\AntiSpywareBot\DataBase.ref
C:\Program Files\AntiSpywareBot\Difxapi.dll
C:\Program Files\AntiSpywareBot\FilterDrv\AntiSpywareBot.amd64.sys
C:\Program Files\AntiSpywareBot\FilterDrv\AntiSpywareBot.cat
C:\Program Files\AntiSpywareBot\FilterDrv\AntiSpywareBot.inf
C:\Program Files\AntiSpywareBot\FilterDrv\AntiSpywareBot.x86.sys
C:\Program Files\AntiSpywareBot\Launcher.exe
C:\Program Files\AntiSpywareBot\SpyCleaner.dll
C:\Program Files\AntiSpywareBot\TCL.dll
C:\Program Files\AntiSpywareBot\vistaCPtasks.xml
C:\Program Files\AntiSpywareBot\zlib.dll
C:\WINDOWS\rs.txt
C:\WINDOWS\Tasks.\AntiSpywareBot Scheduled Scan.job
.
((((((((((((((((((((((((( Files Created from 2008-02-14 to 2008-03-14 )))))))))))))))))))))))))))))))
.
2008-03-13 18:58 . 2008-03-13 19:03 dβββ C:\BFU
2008-03-13 17:20 . 2008-03-13 17:20 dβββ C:\Program Files\Trend Micro
2008-03-13 17:17 . 2008-03-13 17:17 dβββ C:\Deckard
2008-03-12 23:43 . 2008-03-12 23:43 127 βaββ C:\WINDOWS\system32\MRT.INI
2008-03-12 22:48 . 2008-02-29 10:14 19,696 βaββ C:\WINDOWS\system32\drivers\antispywarebot.sys
2008-03-12 15:08 . 2008-03-12 23:50 54,156 βahββ C:\WINDOWS\QTFont.qfn
2008-03-12 15:08 . 2008-03-12 15:08 1,409 βaββ C:\WINDOWS\QTFont.for
2008-03-11 17:26 . 2008-03-11 13:30 98,304 βaββ C:\WINDOWS\fmsxwqs.exe
2008-02-25 10:15 . 2008-02-25 10:15 dβββ C:\Documents and Settings\Neil\Application Data\webex
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-13 04:59 βββ dββw C:\Program Files\Java
2008-03-13 02:49 βββ dβhβw C:\Program Files\InstallShield Installation Information
2008-03-07 04:46 βββ dββw C:\Program Files\Black Isle
2008-03-03 00:24 βββ dββw C:\Program Files\PokerStars
2008-02-09 16:22 βββ dββw C:\Program Files\Common Files\Adobe
2007-11-28 01:58 44,104 β-a-w C:\Documents and Settings\Suzanne\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-09 19:05 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2006-07-20 21:48 98304]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2006-07-20 21:50 86016]
"Persistence"="C:\WINDOWS\System32\igfxpers.exe" [2006-07-20 21:47 81920]
"GBB36X Configure"="C:\WINDOWS\System32\JMRaidTool.exe" [2006-07-12 03:58 356352]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-07-30 11:35 77824]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 02:56 16261632 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 04:04 2879488 C:\WINDOWS\SkyTel.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05 257088]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2007-11-15 22:51 166304]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2006-10-04 02:48 53760 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2007-04-04 22:06:49 1528880]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-06-24 16:03:29 81920]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"AlrtCD"= {66e8ddd8-16eb-4aa4-8867-e2afd68ff83a} - C:\WINDOWS\Installer\{66e8ddd8-16eb-4aa4-8867-e2afd68ff83a}\AlrtCD.dll [2008-03-11 17:26 18538]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 antispywarebot;antispywarebot;C:\WINDOWS\system32\DRIVERS\antispywarebot.sys [2008-02-29 10:14]
R2 ILS Daemon;ILS Daemon;"C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe" [2005-03-22 12:06]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-15 22:38]
R2 ZuneBusEnum;Zune Bus Enumerator;C:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-15 22:51]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;C:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-15 22:51]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0780295c-df0e-11db-affc-806d6172696f}]
\Shell\AutoRun\command - D:\Run.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-03-08 15:47:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-13 20:09:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes β¦
scanning hidden autostart entries β¦
scanning hidden files β¦
scan completed successfully
hidden files: 0
**************************************************************************
.
βββββββ DLLs Loaded Under Running Processes βββββββ
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
Completion time: 2008-03-13 20:10:14
ComboFix-quarantined-files.txt 2008-03-14 02:10:12
.
2008-02-21 06:41:24 β E O F β
mbam log
Malwarebytes' Anti-Malware 1.08
Database version: 489
Scan type: Quick Scan
Objects scanned: 29401
Time elapsed: 2 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\Installer\{66e8ddd8-16eb-4aa4-8867-e2afd68ff83a}\AlrtCD.dll (Trojan.Alphabet) -> Unloaded module successfully.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{66e8ddd8-16eb-4aa4-8867-e2afd68ff83a} (Trojan.Alphabet) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\AlrtCD (Trojan.Alphabet) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\WINDOWS\Installer\{66e8ddd8-16eb-4aa4-8867-e2afd68ff83a} (Trojan.Alphabet) -> Delete on reboot.
Files Infected:
C:\WINDOWS\Installer\{66e8ddd8-16eb-4aa4-8867-e2afd68ff83a}\AlrtCD.dll (Trojan.Alphabet) -> Delete on reboot.
C:\WINDOWS\fmsxwqs.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Kaspersky.txt
ββββββββββββββββββββββββββ-
KASPERSKY ONLINE SCANNER REPORT
Thursday, March 13, 2008 10:22:09 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 14/03/2008
Kaspersky Anti-Virus database records: 628804
ββββββββββββββββββββββββββ-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 151923
Number of viruses found: 10
Number of infected objects: 88
Number of suspicious objects: 0
Duration of the scan process: 01:03:56
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0000.VBN/MagicApplet.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0000.VBN/Installer.class Infected: Trojan-Downloader.Java.Agent.a skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0000.VBN ZIP: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0000.VBN CryptZ: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0004.VBN/MagicApplet.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0004.VBN/Installer.class Infected: Trojan-Downloader.Java.Agent.a skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0004.VBN ZIP: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0004.VBN CryptZ: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0005.VBN/MagicApplet.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0005.VBN/Installer.class Infected: Trojan-Downloader.Java.Agent.a skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0005.VBN ZIP: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0005.VBN CryptZ: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0B440000.VBN Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Neil\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.50609 Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\12\4ef9724c-7eb6078a/MagicApplet.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\12\4ef9724c-7eb6078a/Installer.class Infected: Trojan-Downloader.Java.Agent.a skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\12\4ef9724c-7eb6078a ZIP: infected - 2 skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d/GetAccess.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d/NewSecurityClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d/NewURLClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d ZIP: infected - 4 skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e/Counter.class Infected: Trojan.Java.ClassLoader.h skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e/Parser.class Infected: Trojan.Java.ClassLoader.d skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e ZIP: infected - 3 skipped
C:\Documents and Settings\Neil\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Neil\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Neil\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Neil\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Neil\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Neil\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Neil\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\65.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\66.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\67.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\68.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\69.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\70.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\71.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\72.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\73.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\74.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\75.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\76.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\77.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\78.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\79.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\80.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\81.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\82.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\83.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\84.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\85.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-52-37\6.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-52-37\7.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Program Files\AntiSpywareBot\AntiSpywareBot.exe.vir Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\QooBox\Quarantine\C\Program Files\AntiSpywareBot\Launcher.exe.vir Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\QooBox\Quarantine\C\Program Files\AntiSpywareBot\SpyCleaner.dll.vir Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\QooBox\Quarantine\C\Program Files\AntiSpywareBot\TCL.dll.vir Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\QooBox\Quarantine\C\Program Files\AntiSpywareBot\zlib.dll.vir Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121243.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121244.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121245.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121246.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121247.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121248.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121249.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121250.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121251.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121252.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121253.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121254.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121255.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121256.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121257.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121258.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121259.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121260.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121261.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121262.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121263.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0122241.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0122242.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP297\A0122251.dll Infected: not-a-virus:AdWare.Win32.Vapsup.cop skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP299\A0123243.dll Infected: not-a-virus:AdWare.Win32.Vapsup.cop skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP300\A0127271.dll Infected: not-a-virus:AdWare.Win32.Vapsup.cop skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP300\A0127272.dll Infected: not-a-virus:AdWare.Win32.Vapsup.cop skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\A0128255.exe Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\A0128258.exe Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\A0128259.dll Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\A0128260.dll Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\A0128261.dll Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\A0129237.dll Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Installer\{1598954a-2b07-46e3-90b0-7725b0d79f2a}\zip.dll Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{59C7D645-0D28-4617-812B-EE5B7B0F5F5A}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\~DF947D.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\0376080c9f011a825d16f6d9\update\update.exe Object is locked skipped
D:\0376080c9f011a825d16f6d9\update\wpdinstallutil.dll Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
main.txt
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-03-13 22:24:08
Computer is in Normal Mode.
βββββββββββββββββββββββββββ
β HijackThis (run as Neil.exe) ββββββββββββββββ
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:24:09 PM, on 3/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\APPS\ELLIS\Kids\Licensing System\Components\ILSDAEM.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Neil\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Neil.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f505.mail.yahoo.com/ym/ShowLetteβ¦ew=a&head=b
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Shortcut to Microsoft Outlook.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/dβ¦can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/β¦b?1175293912031
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdatβ¦b?1176080434828
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwaβ¦ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://pdl2.webex.com/client/T25L/support/ieatgpc.cab
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ILS Daemon - Unknown owner - C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
β
End of file - 7209 bytes
β Files created between 2008-02-13 and 2008-03-13 ββββββββββ
2008-03-13 20:30:25 0 dβββ C:\WINDOWS\system32\Kaspersky Lab
2008-03-13 20:30:25 0 dβββ C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-13 20:30:23 0 dβββ C:\WINDOWS\LastGood
2008-03-13 20:17:08 0 dβββ C:\Documents and Settings\Neil\Application Data\Malwarebytes
2008-03-13 20:17:00 0 dβββ C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-13 20:16:59 0 dβββ C:\Program Files\Malwarebytes' Anti-Malware
2008-03-13 20:06:40 68096 βaββ C:\WINDOWS\system32\zip.exe
2008-03-13 20:06:40 98816 βaββ C:\WINDOWS\system32\sed.exe
2008-03-13 20:06:40 80412 βaββ C:\WINDOWS\system32\grep.exe
2008-03-13 20:06:40 73728 βaββ C:\WINDOWS\system32\fdsv.exe
ComboFix 08-03-13.4 - Neil 2008-03-13 20:07:27.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1617 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Desktop\AntiSpywareBot.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\AntiSpywareBot
C:\Documents and Settings\All Users\Start Menu\Programs\AntiSpywareBot\AntiSpywareBot on the Web.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\AntiSpywareBot\AntiSpywareBot.lnk
C:\Documents and Settings\Neil\Application Data\AntispywareBot
C:\Documents and Settings\Neil\Application Data\AntispywareBot\Log\2008 Mar 13 - 05_09_02 PM_171.log
C:\Documents and Settings\Neil\Application Data\AntispywareBot\rs.dat
C:\Documents and Settings\Suzanne\Application Data\AntispywareBot
C:\Documents and Settings\Suzanne\Application Data\AntispywareBot\Log\2008 Mar 13 - 05_06_48 PM_734.log
C:\Documents and Settings\Suzanne\Application Data\AntispywareBot\Log\2008 Mar 13 - 12_54_18 PM_656.log
C:\Documents and Settings\Suzanne\Application Data\AntispywareBot\Log\2008 Mar 13 - 12_56_07 PM_921.log
C:\Documents and Settings\Suzanne\Application Data\AntispywareBot\rs.dat
C:\Program Files\AntiSpywareBot
C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe
C:\Program Files\AntiSpywareBot\AntiSpywareBot.url
C:\Program Files\AntiSpywareBot\DataBase.ref
C:\Program Files\AntiSpywareBot\Difxapi.dll
C:\Program Files\AntiSpywareBot\FilterDrv\AntiSpywareBot.amd64.sys
C:\Program Files\AntiSpywareBot\FilterDrv\AntiSpywareBot.cat
C:\Program Files\AntiSpywareBot\FilterDrv\AntiSpywareBot.inf
C:\Program Files\AntiSpywareBot\FilterDrv\AntiSpywareBot.x86.sys
C:\Program Files\AntiSpywareBot\Launcher.exe
C:\Program Files\AntiSpywareBot\SpyCleaner.dll
C:\Program Files\AntiSpywareBot\TCL.dll
C:\Program Files\AntiSpywareBot\vistaCPtasks.xml
C:\Program Files\AntiSpywareBot\zlib.dll
C:\WINDOWS\rs.txt
C:\WINDOWS\Tasks.\AntiSpywareBot Scheduled Scan.job
.
((((((((((((((((((((((((( Files Created from 2008-02-14 to 2008-03-14 )))))))))))))))))))))))))))))))
.
2008-03-13 18:58 . 2008-03-13 19:03 dβββ C:\BFU
2008-03-13 17:20 . 2008-03-13 17:20 dβββ C:\Program Files\Trend Micro
2008-03-13 17:17 . 2008-03-13 17:17 dβββ C:\Deckard
2008-03-12 23:43 . 2008-03-12 23:43 127 βaββ C:\WINDOWS\system32\MRT.INI
2008-03-12 22:48 . 2008-02-29 10:14 19,696 βaββ C:\WINDOWS\system32\drivers\antispywarebot.sys
2008-03-12 15:08 . 2008-03-12 23:50 54,156 βahββ C:\WINDOWS\QTFont.qfn
2008-03-12 15:08 . 2008-03-12 15:08 1,409 βaββ C:\WINDOWS\QTFont.for
2008-03-11 17:26 . 2008-03-11 13:30 98,304 βaββ C:\WINDOWS\fmsxwqs.exe
2008-02-25 10:15 . 2008-02-25 10:15 dβββ C:\Documents and Settings\Neil\Application Data\webex
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-13 04:59 βββ dββw C:\Program Files\Java
2008-03-13 02:49 βββ dβhβw C:\Program Files\InstallShield Installation Information
2008-03-07 04:46 βββ dββw C:\Program Files\Black Isle
2008-03-03 00:24 βββ dββw C:\Program Files\PokerStars
2008-02-09 16:22 βββ dββw C:\Program Files\Common Files\Adobe
2007-11-28 01:58 44,104 β-a-w C:\Documents and Settings\Suzanne\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-09 19:05 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2006-07-20 21:48 98304]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2006-07-20 21:50 86016]
"Persistence"="C:\WINDOWS\System32\igfxpers.exe" [2006-07-20 21:47 81920]
"GBB36X Configure"="C:\WINDOWS\System32\JMRaidTool.exe" [2006-07-12 03:58 356352]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-07-30 11:35 77824]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 02:56 16261632 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 04:04 2879488 C:\WINDOWS\SkyTel.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05 257088]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2007-11-15 22:51 166304]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2006-10-04 02:48 53760 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2007-04-04 22:06:49 1528880]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-06-24 16:03:29 81920]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"AlrtCD"= {66e8ddd8-16eb-4aa4-8867-e2afd68ff83a} - C:\WINDOWS\Installer\{66e8ddd8-16eb-4aa4-8867-e2afd68ff83a}\AlrtCD.dll [2008-03-11 17:26 18538]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 antispywarebot;antispywarebot;C:\WINDOWS\system32\DRIVERS\antispywarebot.sys [2008-02-29 10:14]
R2 ILS Daemon;ILS Daemon;"C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe" [2005-03-22 12:06]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-15 22:38]
R2 ZuneBusEnum;Zune Bus Enumerator;C:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-15 22:51]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;C:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-15 22:51]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0780295c-df0e-11db-affc-806d6172696f}]
\Shell\AutoRun\command - D:\Run.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-03-08 15:47:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-13 20:09:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes β¦
scanning hidden autostart entries β¦
scanning hidden files β¦
scan completed successfully
hidden files: 0
**************************************************************************
.
βββββββ DLLs Loaded Under Running Processes βββββββ
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
Completion time: 2008-03-13 20:10:14
ComboFix-quarantined-files.txt 2008-03-14 02:10:12
.
2008-02-21 06:41:24 β E O F β
mbam log
Malwarebytes' Anti-Malware 1.08
Database version: 489
Scan type: Quick Scan
Objects scanned: 29401
Time elapsed: 2 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\Installer\{66e8ddd8-16eb-4aa4-8867-e2afd68ff83a}\AlrtCD.dll (Trojan.Alphabet) -> Unloaded module successfully.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{66e8ddd8-16eb-4aa4-8867-e2afd68ff83a} (Trojan.Alphabet) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\AlrtCD (Trojan.Alphabet) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\WINDOWS\Installer\{66e8ddd8-16eb-4aa4-8867-e2afd68ff83a} (Trojan.Alphabet) -> Delete on reboot.
Files Infected:
C:\WINDOWS\Installer\{66e8ddd8-16eb-4aa4-8867-e2afd68ff83a}\AlrtCD.dll (Trojan.Alphabet) -> Delete on reboot.
C:\WINDOWS\fmsxwqs.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Kaspersky.txt
ββββββββββββββββββββββββββ-
KASPERSKY ONLINE SCANNER REPORT
Thursday, March 13, 2008 10:22:09 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 14/03/2008
Kaspersky Anti-Virus database records: 628804
ββββββββββββββββββββββββββ-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 151923
Number of viruses found: 10
Number of infected objects: 88
Number of suspicious objects: 0
Duration of the scan process: 01:03:56
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0000.VBN/MagicApplet.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0000.VBN/Installer.class Infected: Trojan-Downloader.Java.Agent.a skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0000.VBN ZIP: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0000.VBN CryptZ: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0004.VBN/MagicApplet.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0004.VBN/Installer.class Infected: Trojan-Downloader.Java.Agent.a skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0004.VBN ZIP: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0004.VBN CryptZ: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0005.VBN/MagicApplet.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0005.VBN/Installer.class Infected: Trojan-Downloader.Java.Agent.a skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0005.VBN ZIP: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\082C0005.VBN CryptZ: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0B440000.VBN Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Neil\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.50609 Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\12\4ef9724c-7eb6078a/MagicApplet.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\12\4ef9724c-7eb6078a/Installer.class Infected: Trojan-Downloader.Java.Agent.a skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\12\4ef9724c-7eb6078a ZIP: infected - 2 skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d/GetAccess.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d/NewSecurityClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d/NewURLClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d ZIP: infected - 4 skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e/Counter.class Infected: Trojan.Java.ClassLoader.h skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e/Parser.class Infected: Trojan.Java.ClassLoader.d skipped
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e ZIP: infected - 3 skipped
C:\Documents and Settings\Neil\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Neil\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Neil\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Neil\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Neil\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Neil\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Neil\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\65.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\66.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\67.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\68.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\69.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\70.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\71.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\72.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\73.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\74.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\75.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\76.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\77.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\78.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\79.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\80.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\81.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\82.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\83.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\84.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-50-32\85.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-52-37\6.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Neil\Application Data\AntispywareBot\Quarantine\12-03-2008-22-52-37\7.qit.vir Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\QooBox\Quarantine\C\Program Files\AntiSpywareBot\AntiSpywareBot.exe.vir Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\QooBox\Quarantine\C\Program Files\AntiSpywareBot\Launcher.exe.vir Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\QooBox\Quarantine\C\Program Files\AntiSpywareBot\SpyCleaner.dll.vir Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\QooBox\Quarantine\C\Program Files\AntiSpywareBot\TCL.dll.vir Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\QooBox\Quarantine\C\Program Files\AntiSpywareBot\zlib.dll.vir Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121243.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121244.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121245.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121246.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121247.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121248.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121249.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121250.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121251.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121252.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121253.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121254.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121255.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121256.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121257.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121258.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121259.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121260.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121261.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121262.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0121263.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0122241.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP296\A0122242.exe Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP297\A0122251.dll Infected: not-a-virus:AdWare.Win32.Vapsup.cop skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP299\A0123243.dll Infected: not-a-virus:AdWare.Win32.Vapsup.cop skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP300\A0127271.dll Infected: not-a-virus:AdWare.Win32.Vapsup.cop skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP300\A0127272.dll Infected: not-a-virus:AdWare.Win32.Vapsup.cop skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\A0128255.exe Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\A0128258.exe Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\A0128259.dll Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\A0128260.dll Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\A0128261.dll Infected: not-a-virus:FraudTool.Win32.AntiSpywareBot.a skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\A0129237.dll Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\System Volume Information\_restore{09B68C44-5B6C-41D1-AFFC-969D5C34AB6C}\RP301\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Installer\{1598954a-2b07-46e3-90b0-7725b0d79f2a}\zip.dll Infected: Trojan-Dropper.Win32.Agent.ftv skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{59C7D645-0D28-4617-812B-EE5B7B0F5F5A}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\~DF947D.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\0376080c9f011a825d16f6d9\update\update.exe Object is locked skipped
D:\0376080c9f011a825d16f6d9\update\wpdinstallutil.dll Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
main.txt
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-03-13 22:24:08
Computer is in Normal Mode.
βββββββββββββββββββββββββββ
β HijackThis (run as Neil.exe) ββββββββββββββββ
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:24:09 PM, on 3/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\APPS\ELLIS\Kids\Licensing System\Components\ILSDAEM.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Neil\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Neil.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f505.mail.yahoo.com/ym/ShowLetteβ¦ew=a&head=b
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Shortcut to Microsoft Outlook.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/dβ¦can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/β¦b?1175293912031
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdatβ¦b?1176080434828
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwaβ¦ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://pdl2.webex.com/client/T25L/support/ieatgpc.cab
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ILS Daemon - Unknown owner - C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
β
End of file - 7209 bytes
β Files created between 2008-02-13 and 2008-03-13 ββββββββββ
2008-03-13 20:30:25 0 dβββ C:\WINDOWS\system32\Kaspersky Lab
2008-03-13 20:30:25 0 dβββ C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-13 20:30:23 0 dβββ C:\WINDOWS\LastGood
2008-03-13 20:17:08 0 dβββ C:\Documents and Settings\Neil\Application Data\Malwarebytes
2008-03-13 20:17:00 0 dβββ C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-13 20:16:59 0 dβββ C:\Program Files\Malwarebytes' Anti-Malware
2008-03-13 20:06:40 68096 βaββ C:\WINDOWS\system32\zip.exe
2008-03-13 20:06:40 98816 βaββ C:\WINDOWS\system32\sed.exe
2008-03-13 20:06:40 80412 βaββ C:\WINDOWS\system32\grep.exe
2008-03-13 20:06:40 73728 βaββ C:\WINDOWS\system32\fdsv.exe
RatHat
Please uninstall the following programs:
1. Please open Notepad
2. Now copy/paste the entire content of the codebox below into the Notepad window:
3. Save the above as CFScript.txt
4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
[external image: Posted Image]
5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
Regards,
RatHat
J2SE Runtime Environment 5.0 Update 3
Javaβ’ 6 Update 2
Javaβ’ 6 Update 3
Javaβ’ SE Runtime Environment 6 Update 1
LimeWire 4.12.11
- Go to Start then Settings, then Control Panel
- Choose Add or Remove Programs
- Remove all of the above
1. Please open Notepad
- Click Start , then Run
- Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:
File::
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\12\4ef9724c-7eb6078a
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e
C:\WINDOWS\Installer\{1598954a-2b07-46e3-90b0-7725b0d79f2a}\zip.dll
Folder::
C:\Program Files\\MyWebSearch
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0780295c-df0e-11db-affc-806d6172696f}]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source=-
FriendlyName=-
3. Save the above as CFScript.txt
4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
[external image: Posted Image]
5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
- Combofix.txt
- A new DSSlog.
Regards,
RatHat
warp13speed
FYI
I will not be able to do these things today. I won't be near the machine in question until tomorrow.
RatHat
OK, no problem, post them when you can.
Regards,
RatHat
warp13speed
Combofix.txt
ComboFix 08-03-13.4 - Neil 2008-03-15 9:28:48.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1552 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\Neil\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\12\4ef9724c-7eb6078a
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e
C:\WINDOWS\Installer\{1598954a-2b07-46e3-90b0-7725b0d79f2a}\zip.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\12\4ef9724c-7eb6078a
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e
C:\WINDOWS\Installer\{1598954a-2b07-46e3-90b0-7725b0d79f2a}\zip.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-15 to 2008-03-15 )))))))))))))))))))))))))))))))
.
2008-03-13 20:30 . 2008-03-13 20:30 dβββ C:\WINDOWS\system32\Kaspersky Lab
2008-03-13 20:30 . 2008-03-13 20:30 dβββ C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-13 20:17 . 2008-03-13 20:17 dβββ C:\Documents and Settings\Neil\Application Data\Malwarebytes
2008-03-13 20:17 . 2008-03-13 20:17 dβββ C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-13 20:16 . 2008-03-13 20:17 dβββ C:\Program Files\Malwarebytes' Anti-Malware
2008-03-13 18:58 . 2008-03-13 19:03 dβββ C:\BFU
2008-03-13 17:20 . 2008-03-13 17:20 dβββ C:\Program Files\Trend Micro
2008-03-13 17:17 . 2008-03-13 17:17 dβββ C:\Deckard
2008-03-12 23:43 . 2008-03-12 23:43 127 βaββ C:\WINDOWS\system32\MRT.INI
2008-03-12 22:48 . 2008-02-29 10:14 19,696 βaββ C:\WINDOWS\system32\drivers\antispywarebot.sys
2008-03-12 15:08 . 2008-03-12 23:50 54,156 βahββ C:\WINDOWS\QTFont.qfn
2008-03-12 15:08 . 2008-03-12 15:08 1,409 βaββ C:\WINDOWS\QTFont.for
2008-02-25 10:15 . 2008-02-25 10:15 dβββ C:\Documents and Settings\Neil\Application Data\webex
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-13 02:49 βββ dβhβw C:\Program Files\InstallShield Installation Information
2008-03-07 04:46 βββ dββw C:\Program Files\Black Isle
2008-03-03 00:24 βββ dββw C:\Program Files\PokerStars
2008-02-09 16:22 βββ dββw C:\Program Files\Common Files\Adobe
2007-11-28 01:58 44,104 β-a-w C:\Documents and Settings\Suzanne\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( snapshot@2008-03-13_20.09.59.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-24 18:27:16 213,048 β-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 21:47:20 94,208 β-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 21:49:54 950,272 β-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-03-14 01:20:35 71,512 β-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-03-15 15:25:28 71,512 β-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-14 01:20:35 441,954 β-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-15 15:25:28 441,954 β-a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-09 19:05 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2006-07-20 21:48 98304]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2006-07-20 21:50 86016]
"Persistence"="C:\WINDOWS\System32\igfxpers.exe" [2006-07-20 21:47 81920]
"GBB36X Configure"="C:\WINDOWS\System32\JMRaidTool.exe" [2006-07-12 03:58 356352]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-07-30 11:35 77824]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 02:56 16261632 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 04:04 2879488 C:\WINDOWS\SkyTel.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05 257088]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2007-11-15 22:51 166304]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2006-10-04 02:48 53760 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2007-04-04 22:06:49 1528880]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-06-24 16:03:29 81920]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 antispywarebot;antispywarebot;C:\WINDOWS\system32\DRIVERS\antispywarebot.sys [2008-02-29 10:14]
R2 ILS Daemon;ILS Daemon;"C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe" [2005-03-22 12:06]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-15 22:38]
R2 ZuneBusEnum;Zune Bus Enumerator;C:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-15 22:51]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;C:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-15 22:51]
*Newly Created Service* - APPMGMT
.
Contents of the 'Scheduled Tasks' folder
"2008-03-08 15:47:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-15 09:30:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes β¦
scanning hidden autostart entries β¦
scanning hidden files β¦
scan completed successfully
hidden files: 0
**************************************************************************
.
βββββββ DLLs Loaded Under Running Processes βββββββ
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
Completion time: 2008-03-15 9:30:36
ComboFix-quarantined-files.txt 2008-03-15 15:30:34
ComboFix2.txt 2008-03-14 02:10:14
.
2008-02-21 06:41:24 β E O F β
Main.txt
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-03-15 09:32:14
Computer is in Normal Mode.
βββββββββββββββββββββββββββ
β HijackThis (run as Neil.exe) ββββββββββββββββ
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:32:15 AM, on 3/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\APPS\ELLIS\Kids\Licensing System\Components\ILSDAEM.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Neil\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Neil.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f505.mail.yahoo.com/ym/ShowLetteβ¦ew=a&head=b
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Shortcut to Microsoft Outlook.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/dβ¦can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/β¦b?1175293912031
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdatβ¦b?1176080434828
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwaβ¦ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://pdl2.webex.com/client/T25L/support/ieatgpc.cab
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ILS Daemon - Unknown owner - C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
β
End of file - 6968 bytes
β Files created between 2008-02-15 and 2008-03-15 ββββββββββ
2008-03-15 09:24:16 0 dβββ C:\WINDOWS\system32\appmgmt
2008-03-13 20:30:25 0 dβββ C:\WINDOWS\system32\Kaspersky Lab
2008-03-13 20:30:25 0 dβββ C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-13 20:17:08 0 dβββ C:\Documents and Settings\Neil\Application Data\Malwarebytes
2008-03-13 20:17:00 0 dβββ C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-13 20:16:59 0 dβββ C:\Program Files\Malwarebytes' Anti-Malware
2008-03-13 20:06:40 68096 βaββ C:\WINDOWS\system32\zip.exe
2008-03-13 20:06:40 98816 βaββ C:\WINDOWS\system32\sed.exe
2008-03-13 20:06:40 80412 βaββ C:\WINDOWS\system32\grep.exe
2008-03-13 20:06:40 73728 βaββ C:\WINDOWS\system32\fdsv.exe
ComboFix 08-03-13.4 - Neil 2008-03-15 9:28:48.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1552 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\Neil\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\12\4ef9724c-7eb6078a
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e
C:\WINDOWS\Installer\{1598954a-2b07-46e3-90b0-7725b0d79f2a}\zip.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\12\4ef9724c-7eb6078a
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\30\5d37d31e-3886dc5d
C:\Documents and Settings\Neil\Application Data\Sun\Java\Deployment\cache\6.0\42\6217252a-5e9bbb9e
C:\WINDOWS\Installer\{1598954a-2b07-46e3-90b0-7725b0d79f2a}\zip.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-15 to 2008-03-15 )))))))))))))))))))))))))))))))
.
2008-03-13 20:30 . 2008-03-13 20:30 dβββ C:\WINDOWS\system32\Kaspersky Lab
2008-03-13 20:30 . 2008-03-13 20:30 dβββ C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-13 20:17 . 2008-03-13 20:17 dβββ C:\Documents and Settings\Neil\Application Data\Malwarebytes
2008-03-13 20:17 . 2008-03-13 20:17 dβββ C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-13 20:16 . 2008-03-13 20:17 dβββ C:\Program Files\Malwarebytes' Anti-Malware
2008-03-13 18:58 . 2008-03-13 19:03 dβββ C:\BFU
2008-03-13 17:20 . 2008-03-13 17:20 dβββ C:\Program Files\Trend Micro
2008-03-13 17:17 . 2008-03-13 17:17 dβββ C:\Deckard
2008-03-12 23:43 . 2008-03-12 23:43 127 βaββ C:\WINDOWS\system32\MRT.INI
2008-03-12 22:48 . 2008-02-29 10:14 19,696 βaββ C:\WINDOWS\system32\drivers\antispywarebot.sys
2008-03-12 15:08 . 2008-03-12 23:50 54,156 βahββ C:\WINDOWS\QTFont.qfn
2008-03-12 15:08 . 2008-03-12 15:08 1,409 βaββ C:\WINDOWS\QTFont.for
2008-02-25 10:15 . 2008-02-25 10:15 dβββ C:\Documents and Settings\Neil\Application Data\webex
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-13 02:49 βββ dβhβw C:\Program Files\InstallShield Installation Information
2008-03-07 04:46 βββ dββw C:\Program Files\Black Isle
2008-03-03 00:24 βββ dββw C:\Program Files\PokerStars
2008-02-09 16:22 βββ dββw C:\Program Files\Common Files\Adobe
2007-11-28 01:58 44,104 β-a-w C:\Documents and Settings\Suzanne\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( snapshot@2008-03-13_20.09.59.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-24 18:27:16 213,048 β-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 21:47:20 94,208 β-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 21:49:54 950,272 β-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-03-14 01:20:35 71,512 β-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-03-15 15:25:28 71,512 β-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-14 01:20:35 441,954 β-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-15 15:25:28 441,954 β-a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-09 19:05 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2006-07-20 21:48 98304]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2006-07-20 21:50 86016]
"Persistence"="C:\WINDOWS\System32\igfxpers.exe" [2006-07-20 21:47 81920]
"GBB36X Configure"="C:\WINDOWS\System32\JMRaidTool.exe" [2006-07-12 03:58 356352]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-07-30 11:35 77824]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 02:56 16261632 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 04:04 2879488 C:\WINDOWS\SkyTel.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05 257088]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2007-11-15 22:51 166304]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2006-10-04 02:48 53760 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2007-04-04 22:06:49 1528880]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-06-24 16:03:29 81920]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 antispywarebot;antispywarebot;C:\WINDOWS\system32\DRIVERS\antispywarebot.sys [2008-02-29 10:14]
R2 ILS Daemon;ILS Daemon;"C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe" [2005-03-22 12:06]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2007-11-15 22:38]
R2 ZuneBusEnum;Zune Bus Enumerator;C:\WINDOWS\system32\ZuneBusEnum.exe [2007-11-15 22:51]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;C:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2007-11-15 22:51]
*Newly Created Service* - APPMGMT
.
Contents of the 'Scheduled Tasks' folder
"2008-03-08 15:47:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-15 09:30:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes β¦
scanning hidden autostart entries β¦
scanning hidden files β¦
scan completed successfully
hidden files: 0
**************************************************************************
.
βββββββ DLLs Loaded Under Running Processes βββββββ
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
Completion time: 2008-03-15 9:30:36
ComboFix-quarantined-files.txt 2008-03-15 15:30:34
ComboFix2.txt 2008-03-14 02:10:14
.
2008-02-21 06:41:24 β E O F β
Main.txt
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-03-15 09:32:14
Computer is in Normal Mode.
βββββββββββββββββββββββββββ
β HijackThis (run as Neil.exe) ββββββββββββββββ
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:32:15 AM, on 3/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\APPS\ELLIS\Kids\Licensing System\Components\ILSDAEM.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Neil\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Neil.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f505.mail.yahoo.com/ym/ShowLetteβ¦ew=a&head=b
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Shortcut to Microsoft Outlook.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/dβ¦can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/β¦b?1175293912031
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdatβ¦b?1176080434828
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwaβ¦ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://pdl2.webex.com/client/T25L/support/ieatgpc.cab
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ILS Daemon - Unknown owner - C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
β
End of file - 6968 bytes
β Files created between 2008-02-15 and 2008-03-15 ββββββββββ
2008-03-15 09:24:16 0 dβββ C:\WINDOWS\system32\appmgmt
2008-03-13 20:30:25 0 dβββ C:\WINDOWS\system32\Kaspersky Lab
2008-03-13 20:30:25 0 dβββ C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-13 20:17:08 0 dβββ C:\Documents and Settings\Neil\Application Data\Malwarebytes
2008-03-13 20:17:00 0 dβββ C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-13 20:16:59 0 dβββ C:\Program Files\Malwarebytes' Anti-Malware
2008-03-13 20:06:40 68096 βaββ C:\WINDOWS\system32\zip.exe
2008-03-13 20:06:40 98816 βaββ C:\WINDOWS\system32\sed.exe
2008-03-13 20:06:40 80412 βaββ C:\WINDOWS\system32\grep.exe
2008-03-13 20:06:40 73728 βaββ C:\WINDOWS\system32\fdsv.exe
RatHat
Yes it will.I also wanted to ask if this process should clean all profiles, or just mine?
Can you delete this folder: C:\WINDOWS\privacy_danger
And let me know if you are having any further problems with your computer.
Regards,
RatHat
warp13speed
I cannot find a "privacy_danger" folder in the "C:\Windows" folder.
The computer is running wonderfully. No virus pop-ups for the last 2 days!!
RatHat
OK, no problem, download HijackThis for me and post me a log:
RatHat
- Click here to download HijackThis.exe
- Save HijackThis.exe to your desktop.
- Doubleclick on the HijackThis.exe icon on your desktop.
- By default it will install to C:\Program Files\HijackThis.
- Continue to follow the rest of the prompts from there
- Scan your computer and save a logfile
RatHat
warp13speed
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:50:51 PM, on 3/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\APPS\ELLIS\Kids\Licensing System\Components\ILSDAEM.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Neil\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f505.mail.yahoo.com/ym/ShowLetteβ¦ew=a&head=b
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Shortcut to Microsoft Outlook.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/dβ¦can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/β¦b?1175293912031
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdatβ¦b?1176080434828
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwaβ¦ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://pdl2.webex.com/client/T25L/support/ieatgpc.cab
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ILS Daemon - Unknown owner - C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
β
End of file - 6743 bytes
Scan saved at 4:50:51 PM, on 3/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\APPS\ELLIS\Kids\Licensing System\Components\ILSDAEM.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Neil\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f505.mail.yahoo.com/ym/ShowLetteβ¦ew=a&head=b
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Shortcut to Microsoft Outlook.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/dβ¦can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/β¦b?1175293912031
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdatβ¦b?1176080434828
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwaβ¦ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://pdl2.webex.com/client/T25L/support/ieatgpc.cab
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ILS Daemon - Unknown owner - C:\Program Files\Common Files\Ellis Shared\Components\ELSILSSVR.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
β
End of file - 6743 bytes
RatHat
Please re-open HiJackThis and scan. Check the box next to the entry listed below.
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
OK! Well done, your log is clean again! :thumbsup:
The first thing we need to do is to remove all the tools that you have used. This is so that should you ever be re-infected, you will download updated versions. It will also remove the quarantined Malware from your computer.
Click Here to download OTCleanIt
Double-click OTCleanIt.exe to run it.
Click the Clean up button
Click Yes to the reboot.
OK, lets carry out a few preventative steps to make sure you reduce the risk of further infections.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Now lets Reset and Re-enable your System Restore to remove any infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected, but that's good news).
Turn OFF System Restore.
Turn ON System Restore.
System Restore will now be active again.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Next, lets reset your hidden/system files and folders. System files are hidden for a reason and we don't want to have them openly available and susceptible to accidental deletion.
Reset Hidden/System Files & Folders
Another essential is to keep your computer updated with the latest operating system patches and security fixes. Windows Updates are constantly being revised to combat the newest hacks and threats, Microsoft releases security updates that help your computer from becoming vunerable. It is best if you have these set to download automatically.
Automatic Updates for Windows
In addition to Windows updates, you also need to ensure that your version of Java is the latest.Click here to download the latest version (Java Runtime Environment (JRE) 6 Update 5). Once downloaded, install it and then Reboot your computer.
It is most important that you also uninstall older versions of Java.
OK, now lets download some preventative programs that will help to keep the nasties away! We will start with Anti Spyware programs. I would advise getting a couple of them at least, and running each at least once a month.
Anti Spyware
Note: If you find your system slows down after installing any of these, just uninstall it, or disable it from running at startup.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Next lets look at Firewalls. These help to prevent unauthorised access both to and from the internet or your local network. A firewall is considered a first line of defense in protecting private information. Below are two free firewalls to choose from, if you do not already have one. Note: You only need one firewall one your system.
Personal Firewalls
Nearly done! If you like to use chat, MSN and Yahoo have vunerabilities that can leave you open to infections. There are however a couple of very good, Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN):
Instant Messengers ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Lastly, it is a good idea to clear out all your temp files every now and again. This will help your computer from bogging down and slowing. It also can assist in getting rid of files that may contain malicious code that could re-infect your computer.
Temp File Cleaners
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
I will keep this log open for the next couple of days, so if you have any further problems post another reply here.
OK, all the best, and stay safe!
Best regards,
RatHat
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
OK! Well done, your log is clean again! :thumbsup:
The first thing we need to do is to remove all the tools that you have used. This is so that should you ever be re-infected, you will download updated versions. It will also remove the quarantined Malware from your computer.
Click Here to download OTCleanIt
Double-click OTCleanIt.exe to run it.
Click the Clean up button
Click Yes to the reboot.
OK, lets carry out a few preventative steps to make sure you reduce the risk of further infections.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Now lets Reset and Re-enable your System Restore to remove any infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected, but that's good news).
Turn OFF System Restore.
- On the Desktop, right-click My Computer.
- Click Properties.
- Click the System Restore tab.
- Check Turn off System Restore.
- Click Apply, and then click OK.
Turn ON System Restore.
- On the Desktop, right-click My Computer.
- Click Properties.
- Click the System Restore tab.
- UN-Check Turn off System Restore.
- Click Apply, and then click OK.
System Restore will now be active again.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Next, lets reset your hidden/system files and folders. System files are hidden for a reason and we don't want to have them openly available and susceptible to accidental deletion.
Reset Hidden/System Files & Folders
- Click Start.
- Open My Computer.
- Select the Tools menu and click Folder Options.
- Select the View tab.
- Under the Hidden files and folders heading UNSELECT Show hidden files and folders.
- CHECK the Hide protected operating system files (recommended) option.
- Click Yes to confirm.
- Click OK.
Another essential is to keep your computer updated with the latest operating system patches and security fixes. Windows Updates are constantly being revised to combat the newest hacks and threats, Microsoft releases security updates that help your computer from becoming vunerable. It is best if you have these set to download automatically.
Automatic Updates for Windows
- Click Start.
- Select Settings and then Control Panel.
- Select Automatic Updates.
- Click Automatic (recommended)
- Choose a day and a time when you know the computer will be on and connected to the internet.
- Click Apply then OK.
In addition to Windows updates, you also need to ensure that your version of Java is the latest.Click here to download the latest version (Java Runtime Environment (JRE) 6 Update 5). Once downloaded, install it and then Reboot your computer.
It is most important that you also uninstall older versions of Java.
- Click Start, Control Panel, Add/Remove Programs.
- Delete all Java updates except Java β’ 6 Update 5
OK, now lets download some preventative programs that will help to keep the nasties away! We will start with Anti Spyware programs. I would advise getting a couple of them at least, and running each at least once a month.
Anti Spyware
- SpywareBlaster to help prevent spyware from installing in the first place. A tutorial can be found here.
- SpywareGuard to catch and block spyware before it can execute. A tutorial can be found here.
- IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email. A tutorial can be found here.
- Spybot Search & Destroy a powerful tool which can "search and destroy" nasties that make it onto your system. Now with an Immunize section that will help prevent future infections. A tutorial can be found here.
- AdAware another very powerful tool which searches and kills nasties that infect your system. A tutorial can be found here. AdAware and Spybot Search & Destroy compliment each other very well.
Note: If you find your system slows down after installing any of these, just uninstall it, or disable it from running at startup.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Next lets look at Firewalls. These help to prevent unauthorised access both to and from the internet or your local network. A firewall is considered a first line of defense in protecting private information. Below are two free firewalls to choose from, if you do not already have one. Note: You only need one firewall one your system.
Personal Firewalls
- Online Armor (Free edition) personal firewall
- Comodo is a free fully functional firewall
Nearly done! If you like to use chat, MSN and Yahoo have vunerabilities that can leave you open to infections. There are however a couple of very good, Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN):
Instant Messengers ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Lastly, it is a good idea to clear out all your temp files every now and again. This will help your computer from bogging down and slowing. It also can assist in getting rid of files that may contain malicious code that could re-infect your computer.
Temp File Cleaners
- CleanUP! - Cleans temporary files from IE and Windows, empties the recycle bin and more. Note: Do NOT run this program if you have XP Professional 64 bit edition.
- ATF Cleaner A very powerful cleaning program for XP and Windows 2000 only. Note: You may have this already as part of the fixes you have run.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
I will keep this log open for the next couple of days, so if you have any further problems post another reply here.
OK, all the best, and stay safe!
Best regards,
RatHat
warp13speed
Thank you again. I'm very pleased with your service. I'm curious though, how do you offer this service and not charge for it? I would like to make a small donation as thanks.
Warp13speed
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI