This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] tavo.exe, kavo.exe, ewatr.cmd problems.... HOW URGENT

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear forumers, am writing because of a problem that happened to my computer ……. for am not sure what to do…. anyway do not know whether I have some malware, trojan or else on my computer. 1) Have installed Lavasoft AdWare Free, have launched a scan but didn’t find anything. 2) Have installed Spybot and it has found only the following 2 problems (apologies for taking note only of the following data… not being a pro I might have missed something to write down): - HKEY_CLASSES_ROOT\CLSID\MADOWN - Win32.rungbu.a 3) Have installed Kaspersky Internet Security and while performing its initial configurations the firewall has put, in its apps restrictions (found in a window coming out while right clicking on kaspersky icon → settings → activity filter or also firewall) kaspersky has put the following files: - kavo.exe - tavo.exe - ewatr.cmd to a nontrustworthy (non.reliable) apps status limiting ALL kinds of activities for the 3 apps (for those who know the software: all 3 have only red Xes). What I can add is that I’ve seen some kaspersky popup messages, while trying to access system32 from the dtp, blocking ewatr.cmd trying to create kavo0.ddl and tavo0.dll (and other files too). - should I go safe, now that I have Adware free + spybot + kasperskyIS2009, or do I need to check for further hidden threats? - Can you please help me removing all those threats? - Is there a simple procedure? (not being a pro am always worried to install tons of extra apps… and get new viruses) - Is there a procedure similar to the one described in the viruslist (http://www.viruslist.com/en/viruses/encyclopedia?virusid=264464) to remove those threats manually and how reliable would it be? Thanks for your help, Mephistofelico
Hi mephistofelico,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

In order to see if you have a problem, I'll need to see a HijackThis log.

Download HijackThis from Here .
  • If using Internet Explorer, Please select RUN
  • If Using Firefox, Download to your Desktop and then Double-Click on Icon to start installation.
  • Choose the default location of C:\Program Files\Trend Micro\HijackThis as the destination. HJT needs to be in its own folder so that the program itself isn't deleted by accident. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!
  • Click the Install button.
  • Accept the license agreement .
  • The progam will place a shortcut on your desktop. This will make it easier for you to access the tool when required.
  • Click Do a system scan and save a log file. A Notepad file will open.
  • To post the text, first you must highlight the entire text and then press the (Ctrl+C) keys which copies it to your clipboard.
  • Now paste the log into this thread using the (Ctrl + V) buttons.


DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS MOST OF THE FILES ARE LEGIT AND VITAL TO THE FUNCTION OF YOUR COMPUTER
Hi Tomk,
thanks very much for your reply…..

have followed your instructions (Hijack download and computer scan), but before reading the log please consider that since I was really looking for a very urgent solution (desperately needed the dtp for my job) I had to trust and follow the instructions at this site (http://wehackvirus.blogspot.com/2008/06/remove-kavoexe.html).

I applied those instructions to both kave.exe and tavo.exe. (…. though couldn’t find anything about ewatr.cmd…and still haven’t a clue what that is…).

FYI, consider that step 6 (and 11) of the above removal instructions suggested me to remove in, in a few steps, from System32 the following files: kavo.exe, kavo0.dll, kavo1.dll, kavo2.dll, kavo3.dll. Because of Kaspersky blocking the tavo.exe and kavo.exe I only had to remove 2 files…..

You will find those instructions attached after the HijackThis log.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21.47.37, on 26/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\File comuni\Portrait Displays\Shared\DTSRVC.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Programmi\Analog Devices\Core\smax4pnp.exe
C:\Programmi\Analog Devices\SoundMAX\Smax4.exe
C:\Programmi\Portrait Displays\HP My Display\DTHtml.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\File comuni\Portrait Displays\Shared\HookManager.exe
C:\Programmi\ASUS WiFi-AP Solo\RtWLan.exe
C:\Programmi\Logitech\SetPoint\SetPoint.exe
C:\Programmi\File comuni\Logishrd\KHAL2\KHALMNPR.EXE
C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\Digsby\lib\digsby-app.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Programmi\Analog Devices\Core\smax4pnp.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [StartCCC] "C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [DT HPW] "C:\Programmi\Portrait Displays\HP My Display\DTHtml.exe" -startup_folder
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [AVP] "C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [RRT-Auto] C:\DOCUME~1\Emilio\IMPOST~1\Temp\Directory temporanea 3 per RRT.zip\RRT.exe auto
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmi\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Aggiungi a PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Aggiungi al banner Blocco pubblicità - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Statistiche sulla protezione del traffico Web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Programmi\File comuni\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programmi\File comuni\Logitech\Bluetooth\LBTServ.exe
O23 - Service: MySql - Unknown owner - C:/FoxServ/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe

–
End of file - 9493 bytes



Instructions from the following site
http://wehackvirus.blogspot.com/2008/06/remove-kavoexe.html:

First of all as the virus hides the hidden files you need a software RRT to unhide them.
1. Open all the drives in new window (Just like here)
2. In an another window go to C:\windows\system32 folder (if your windows is in drive other than C use another drive letter)
3. Open registry editor by going to start->run->regedit (Registry editing could be dangerous if not done properly so be careful)
4. Now run the RRT utility and click on auto remove. Dont close the utility.
5. The utility helps in keeping hidden files unhidden but the virus keeps hiding the system files every few seconds. So you will have to perform this function every few seconds
Find the Tools option at the top of the window -> folder optiond ->view tab -> untick hide protected operating system(recommended) -> click yes on the warning and click apply
6. Now in the C:\windows\system32 folder trace these files and try deleting them using shift + Delete (You may have to redo 5th step to unhide them) kavo.exe, kavo0.dll, kavo1.dll, kavo2.dll, kavo3.dll
You may be able to delete all of them except one. Dont worry we will treat with it later.
7. As I have told you earlier that virus copies it self to all the drives we need to proceed
to the drives now. You will have to repeat step 5 on each drive atleast once. Its assumed that you have all the drives already opened in new different windows.
8. The virus makes a common file with an extension of .bat(example 1.bat) in each drive. Find out the common .bat file in each folder and delete them along with the autorun.inf file. To enable exensions do the following
Find the Tools option at the top of the window -> folder optiond ->view tab -> untick hide extensions
for known file types -> click apply
9. Well now we need to do some registry editing to open registry editor go to start-> run-> type regedit & enter
10. Go the following key & delete value named 'kava'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Now search thw whole of registry with the name 'kava' and delete all instances where you find it in use with word 'kavo'(Use ctrl + F to search & F3 to find next).
11. Now you are almost done. Just log off and log in again into windows (start->log off) and delete the file from the sixth step which you couldn't. You should be able to do it now. Well now you are free from the Kavo.exe virus.


What about my log file?
Is it any good or not?
Do i have any other viruses?

FYI, no my computer seems to be running smoothly. No popup from Kaspersky (always uptodate and at its maximum protection settings) and also SpyBot seems good.

Best Regards,
Emil
Oops, owe you my apologies…. have forgotten to thank you for any further help you'll give me…. hope i was clear enough in what i wrote…… have forgotten to ask you if i have to worry about: O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe What is it? Thanks again, Emil
mephistofelico,

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

This is a legit file. CTFMon is involved with the language/alternative input services in Office XP. CTFMON.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled.

It appears that what you have done so far was helpful. There are no obvious signs of the infection showing. :thumbup:
However, there may be some deeper remnants so I'd like to do a couple more things.

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent HijackThis from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.

  • Open Spybot Search & Destroy.
  • In the Mode menu click Advanced mode if not already selected.
  • Choose Yes at the Warning prompt.
  • Expand the Tools menu.
  • Click Resident.
  • Uncheck the Resident "TeaTimer" (Protection of overall system settings) active. box.
  • In the File menu click Exit to exit Spybot Search & Destroy.

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      O4 - HKLM\..\Run: [RRT-Auto] C:\DOCUME~1\Emilio\IMPOST~1\Temp\Directory temporanea 3 per RRT.zip\RRT.exe auto
      O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Tomk,
wow :pullhair: :pullhair: What a Genius you are….

thought i defeated all malware, but the scan with Malwarebytes found 5 threaths!!!

1 quick question: should i keep Malwarebytes on my dtp? a complete scan is suggested?

the following is the log from Malwarebytes (please note that since i made the mistake to install the SW in Italian i tried to translate
all messages





Malwarebytes' Anti-Malware 1.30
Versione del database: 1324
Windows 5.1.2600 Service Pack 3

27/10/2008 0.17.29
mbam-log-2008-10-27 (00-17-29).txt

Tipo di scansione: Scansione rapida
Elementi scansionati: 46267
Tempo trascorso: 2 minute(s), 24 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 2
Valori di registro infetti: 0
Elementi dato del registro infetti: 1
Cartelle infette: 0
File infetti: 2

Processi delle memoria infetti (infected memory processes):
(Nessun elemento malevolo rilevato) (no malware/elements found)

Moduli della memoria infetti (infected memory modules):
(Nessun elemento malevolo rilevato) (no malware/elements found)

Chiavi di registro infette (infected registry keys):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully.

Valori di registro infetti (infected registry values):
(Nessun elemento malevolo rilevato) (no malware/elements found)

Elementi dato del registro infetti (infected Registry Data elements):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Cartelle infette:
(Nessun elemento malevolo rilevato)(no malware/elements found)

File infetti (infected files):
C:\WINDOWS\system32\kavo.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tavo.exe (Rootkit.Agent) -> Quarantined and deleted successfully.

After the scan, had to reboot the dtp.



Hereafter is the new HijackThis logfile:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0.41.26, on 27/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\File comuni\Portrait Displays\Shared\DTSRVC.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Programmi\Analog Devices\Core\smax4pnp.exe
C:\Programmi\Analog Devices\SoundMAX\Smax4.exe
C:\Programmi\Portrait Displays\HP My Display\DTHtml.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\File comuni\Portrait Displays\Shared\HookManager.exe
C:\Programmi\ASUS WiFi-AP Solo\RtWLan.exe
C:\Programmi\Logitech\SetPoint\SetPoint.exe
C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Programmi\File comuni\Logishrd\KHAL2\KHALMNPR.EXE
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Programmi\Analog Devices\Core\smax4pnp.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [StartCCC] "C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [DT HPW] "C:\Programmi\Portrait Displays\HP My Display\DTHtml.exe" -startup_folder
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [AVP] "C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmi\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Aggiungi a PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Aggiungi al banner Blocco pubblicità - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Statistiche sulla protezione del traffico Web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Programmi\File comuni\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programmi\File comuni\Logitech\Bluetooth\LBTServ.exe
O23 - Service: MySql - Unknown owner - C:/FoxServ/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe

–
End of file - 9006 bytes


As far as dtp behaviour….. i didn't get any particular issue or strange behaviour….. all seemed smooth…..



Thanks for your help,
Emil
mephistofelico,

Let's dig a little deeper.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://www.bleepingcomputer.com/forums/topic114351.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

1 quick question: should i keep Malwarebytes on my dtp? a complete scan is suggested?

Yes keep it. You can do a scan once in-awhile to "check-up" on how things are going. A full scan is a good idea but don't do it now. Wait until I'm done with you.
Tomk,

thanks for your help…


here is the log file for Combofix:

ComboFix 08-10-25.01 - Emilio 2008-10-27 1.24.03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1040.18.3095 [GMT 1:00]
Eseguito da: C:\Documents and Settings\Emilio\Desktop\ComboFix.exe
* Creato nuovo punto di ripristino
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
G:\Autorun.inf

.
((((((((((((((((((((((((( Files Creati Da 2008-09-27 al 2008-10-27 )))))))))))))))))))))))))))))))))))
.

2008-10-27 00:09 . 2008-10-27 00:09 d——– C:\Programmi\Malwarebytes' Anti-Malware
2008-10-27 00:09 . 2008-10-27 00:09 d——– C:\Documents and Settings\Emilio\Dati applicazioni\Malwarebytes
2008-10-27 00:09 . 2008-10-27 00:09 d——– C:\Documents and Settings\All Users\Dati applicazioni\Malwarebytes
2008-10-27 00:09 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-27 00:09 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-26 21:47 . 2008-10-26 21:47 d——– C:\Programmi\Trend Micro
2008-10-24 19:45 . 2008-10-25 22:18 373 –a—— C:\WINDOWS\system32\%LocalXml%
2008-10-24 19:08 . 2008-10-24 19:08 16,244 –a—— C:\WINDOWS\system32\rrt_is.wav
2008-10-24 19:08 . 2008-10-24 19:08 7,302 –a—— C:\WINDOWS\system32\rrt_vf.wav
2008-10-24 19:08 . 2008-10-24 19:08 7,148 –a—— C:\WINDOWS\system32\rrt_tv.wav
2008-10-24 19:08 . 2008-10-24 19:08 6,282 –a—— C:\WINDOWS\system32\rrt_tn.wav
2008-10-24 18:35 . 2008-10-24 19:23 d-a—— C:\Documents and Settings\All Users\Dati applicazioni\TEMP
2008-10-24 14:32 . 2008-10-24 14:33 d——– C:\Documents and Settings\All Users\Dati applicazioni\Lavasoft
2008-10-24 11:29 . 2008-10-24 11:37 96,976 –a—— C:\WINDOWS\system32\drivers\klin.dat
2008-10-24 11:29 . 2008-10-24 11:37 87,855 –a—— C:\WINDOWS\system32\drivers\klick.dat
2008-10-24 11:28 . 2008-10-24 11:28 d——– C:\Programmi\Kaspersky Lab
2008-10-24 11:28 . 2008-10-27 01:25 9,465,376 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-24 11:28 . 2008-10-27 01:25 450,592 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-24 11:28 . 2008-10-27 01:25 76,076 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-24 11:28 . 2008-10-27 01:25 3,668 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-24 10:48 . 2008-10-24 10:48 d——– C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab Setup Files
2008-10-24 09:32 . 2008-10-24 09:32 d——– C:\Documents and Settings\All Users\Dati applicazioni\LogiShrd
2008-10-24 09:29 . 2008-10-24 09:29 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2008-10-24 09:28 . 2008-10-24 09:28 d——– C:\Programmi\File comuni\Logishrd
2008-10-24 09:28 . 2008-10-24 09:28 d——– C:\Documents and Settings\Emilio\Dati applicazioni\InstallShield
2008-10-24 09:28 . 2008-05-02 01:38 301,656 –a—— C:\WINDOWS\system32\BtCoreIf.dll
2008-10-24 09:27 . 2008-10-15 17:36 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-23 21:00 . 2008-10-23 21:00 92 –a—— C:\WINDOWS\wininit.ini
2008-10-23 14:32 . 2008-10-23 14:32 d——– C:\Temp
2008-10-23 09:48 . 2008-10-23 09:48 d——– C:\Program Files
2008-10-23 09:35 . 2008-10-23 09:35 d——– C:\xampplite
2008-10-16 17:02 . 2008-10-16 17:02 306,432 –a—— C:\WINDOWS\system32\TuneUpDefragService.exe
2008-10-16 17:02 . 2007-12-20 09:41 29,440 –a—— C:\WINDOWS\system32\uxtuneup.dll
2008-10-15 08:56 . 2008-08-14 14:22 2,192,896 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 08:56 . 2008-08-14 14:22 2,148,864 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 08:56 . 2008-08-14 14:22 2,069,760 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 08:56 . 2008-08-14 14:22 2,027,520 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 08:56 . 2008-09-15 16:24 1,846,400 —–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 08:56 . 2008-09-08 11:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-10 11:29 . 2008-10-19 00:19 d——– C:\Programmi\FileZilla FTP Client
2008-10-10 11:29 . 2008-10-23 09:04 d——– C:\Documents and Settings\Emilio\Dati applicazioni\FileZilla
2008-10-09 09:36 . 2008-10-27 01:25 d——– C:\Programmi\Microsoft Silverlight
2008-10-08 22:35 . 2008-10-08 22:35 d——– C:\Documents and Settings\Emilio\Dati applicazioni\Digsby
2008-10-08 22:34 . 2008-10-16 14:05 d——– C:\Programmi\Digsby
2008-10-07 00:12 . 2008-10-07 00:13 d——– C:\Programmi\Notepad++
2008-10-07 00:12 . 2008-10-07 00:13 d——– C:\Documents and Settings\Emilio\Dati applicazioni\Notepad++
2008-10-06 12:44 . 2008-10-06 13:09 d——– C:\wamp
2008-10-02 00:54 . 2008-10-02 00:54 d——– C:\Programmi\PDFCreator
2008-10-02 00:54 . 2004-03-09 00:00 662,288 –a—— C:\WINDOWS\system32\MSCOMCT2.OCX
2008-10-02 00:54 . 1998-08-05 07:45 150,528 –a—— C:\WINDOWS\system32\MSCMCIT.DLL
2008-10-02 00:54 . 1998-06-24 00:00 137,000 –a—— C:\WINDOWS\system32\MSMAPI32.OCX
2008-10-02 00:54 . 1998-08-05 07:45 122,128 –a—— C:\WINDOWS\system32\VB6IT.DLL
2008-10-02 00:54 . 2001-10-28 16:42 116,224 –a—— C:\WINDOWS\system32\pdfcmnnt.dll
2008-10-02 00:54 . 1998-08-05 07:45 63,488 –a—— C:\WINDOWS\system32\MSCC2IT.DLL
2008-10-02 00:54 . 1998-07-06 00:00 23,552 –a—— C:\WINDOWS\system32\MSMPIDE.DLL
2008-09-30 22:41 . 2008-10-24 14:41 d——– C:\Programmi\Spybot - Search & Destroy
2008-09-30 22:41 . 2008-10-24 14:41 d——– C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy
2008-09-30 11:43 . 2008-04-13 19:40 43,904 –a—— C:\WINDOWS\system32\drivers\sbp2port.sys
2008-09-30 11:43 . 2008-04-13 19:40 43,904 –a–c— C:\WINDOWS\system32\dllcache\sbp2port.sys
2008-09-30 08:06 . 2008-09-30 08:06 164 –a—— C:\install.dat
2008-09-29 22:08 . 2008-09-30 22:59 d——– C:\Documents and Settings\Emilio\Dati applicazioni\Antispyware

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-26 23:24 ——— d—–w C:\Documents and Settings\All Users\Dati applicazioni\Kaspersky Lab
2008-10-24 18:27 ——— d—–w C:\Programmi\File comuni\Wise Installation Wizard
2008-10-24 08:28 ——— d–h–w C:\Programmi\InstallShield Installation Information
2008-10-24 08:28 ——— d—–w C:\Programmi\File comuni\Logitech
2008-10-22 12:34 ——— d—–w C:\Documents and Settings\Emilio\Dati applicazioni\uTorrent
2008-10-22 12:05 ——— d—–w C:\Programmi\PowerISO
2008-10-16 16:03 ——— d—–w C:\Programmi\TuneUp Utilities 2008
2008-09-25 22:02 ——— d—–w C:\Programmi\MagicISO
2008-09-24 09:43 ——— d—–w C:\Programmi\eMule AdunanzA
2008-09-24 08:10 ——— d—–w C:\Programmi\Foxit Software
2008-09-24 08:02 ——— d—–w C:\Programmi\File comuni\Control Panels
2008-09-24 08:01 ——— d—–w C:\Programmi\File comuni\Adobe
2008-09-24 07:54 ——— d—–w C:\Documents and Settings\All Users\Dati applicazioni\ALM
2008-09-24 07:35 ——— d—–w C:\Programmi\QuickTime
2008-09-24 07:20 ——— d—–w C:\Programmi\Bonjour
2008-09-24 07:08 ——— d—–w C:\Programmi\File comuni\Macrovision Shared
2008-09-23 22:34 ——— d—–w C:\Programmi\uTorrent
2008-09-23 16:14 ——— d—–w C:\Programmi\Microsoft.NET
2008-09-23 16:03 ——— d—–w C:\Programmi\7-Zip
2008-09-23 08:56 ——— d—–w C:\Documents and Settings\Emilio\Dati applicazioni\vlc
2008-09-23 08:54 ——— d—–w C:\Programmi\VideoLAN
2008-09-22 19:51 ——— d—–w C:\Programmi\WinASO
2008-09-22 19:45 ——— d—–w C:\Documents and Settings\Emilio\Dati applicazioni\TuneUp Software
2008-09-22 19:45 ——— d—–w C:\Documents and Settings\All Users\Dati applicazioni\TuneUp Software
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Programmi\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"StartCCC"="C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"DT HPW"="C:\Programmi\Portrait Displays\HP My Display\DTHtml.exe" [2007-01-16 280576]
"ISUSScheduler"="C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
"Acrobat Assistant 8.0"="C:\Programmi\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
ASUS WiFi-AP Solo.lnk - C:\Programmi\ASUS WiFi-AP Solo\RtWLan.exe [2007-11-22 995328]
Logitech SetPoint.lnk - C:\Programmi\Logitech\SetPoint\SetPoint.exe [2007-11-23 805392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\Programmi\File comuni\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Programmi\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Programmi\\uTorrent\\uTorrent.exe"=
"C:\\Documents and Settings\\All Users\\Dati applicazioni\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\Italian\\setup.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 24592]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [2006-09-05 176128]
R3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2006-06-23 13532]
S3 AVPsys;AVPsys;C:\WINDOWS\system32\drivers\cdaudio.sys [2001-08-17 18688]
S3 bsusbser;PHD USB Device for Legacy Serial Communication;C:\WINDOWS\system32\DRIVERS\bsusbser.sys [2006-12-20 94848]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-10-16 306432]
S3 wampapache;wampapache;c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe [2008-01-18 24635]
S3 wampmysqld;wampmysqld;c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe wampmysqld [ ]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenuto della cartella 'Scheduled Tasks'

2008-10-24 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Programmi\TuneUp Utilities 2008\OneClick.exe [2008-01-08 12:31]

2008-10-26 C:\WINDOWS\Tasks\User_Feed_Synchronization-{DA3D4D72-6111-4933-912D-2F56E24CB66F}.job
- C:\WINDOWS\system32\msfeedssync.exe [2007-08-13 18:36]
.
.
——- Supplementare di scansione ——-
.
FireFox -: Profile - C:\Documents and Settings\Emilio\Dati applicazioni\Mozilla\Firefox\Profiles\zu8n8cfk.default\
FF -: plugin - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\browser\nppdf32.dll
FF -: plugin - C:\Programmi\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF -: plugin - C:\Programmi\Microsoft Silverlight\2.0.31005.0\npctrl.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-27 01:27:03
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti …

scansione entrate autostart nascoste …

Scansione files nascosti …


**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]
"ImagePath"="C:/FoxServ/mysql/bin/mysqld-nt.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]
"ImagePath"="C:/FoxServ/mysql/bin/mysqld-nt.exe"
.
———————— Altri processi in esecuzione ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Programmi\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\File comuni\Portrait Displays\Shared\DTSRVC.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Programmi\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Programmi\File comuni\Portrait Displays\Shared\HookManager.exe
C:\ComboFix\catchme.tmp
C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Programmi\File comuni\Logishrd\KHAL2\KHALMNPR.exe
C:\Programmi\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Ora fine scansione: 2008-10-27 1:32:14 - macchina è stato riavviato
ComboFix-quarantined-files.txt 2008-10-27 00:32:12

Pre-Run: 296.418.336.768 byte disponibili
Post-Run: 297,510,592,512 byte disponibili

WindowsXP-KB310994-SP2-Pro-BootDisk-ITA.exe
;
;Warning: Boot.ini is used on Windows XP and earlier operating systems.
;Warning: Use BCDEDIT.exe to modify Windows Vista boot options.
;
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /NOEXECUTE=OPTIN /FASTDETECT /USEPMTIMER

215 — E O F — 2008-10-24 08:39:45


FYI the dtp didn't give any problem while running Combofix.

all those steps made me think to a quick question (will also be good for me to learn something…. if the answer is too long feel free not to answer):

- even though i have Kaspersky Internet Security 2009 with all its firewall/antivirus features i am not completely safe from Malware, Trojan, virus etc…. this is because, even though i have a firewall activated to block all "suspect" activities, a virus (or trojan or malware) might be hidden behind a fully trusted app (such as a windows, Office, flash etc!!!). am i correct?


Thanks,
Emil
mephistofelico,

am i correct?

Close. There are a couple of links to good articles at the end of this post. They should provide a good answer to your question.

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Please re-enable any security that was disabled.

Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls

Keep Microsoft Windows Updated - This will ensure your computer has always the latest security updates available installed on your computer. The easiest way to do this is to turn on Automatic Updates. Do this by:
  • From your desktop, right-click on My Computer,
  • click on Properties
  • Select the Automatic Updates tab
  • Click on Automatic
  • Click on Apply button
  • Click on OK to exit.
If there are new updates to install, install them immediately, until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

Download and install the free version of WinPatrol - This program protects your computer in a variety of ways and will work well with your existing security software.
Winpatrol


Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.


Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Tomk, thanks again for your help…. :thumbup: :thumbup: all should be perfect now….. i did understand all with no problems…… My deepest Regards, Mephistofelico…… :popcorn: :yeah:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI