Can you give me the exact location and file name for those?3. There are still 4 or more files in my download folders from Youtube that have the name of videos I tried to download, These are not incomplete downloads as I can usually start those back up. What concerns me is efforts to "Delete" is greeted with a cannot, because it cannot find the disk or source these came from. Is there a way I can get rid of them?
Spyware / Malware / Virus Removal
[Resolved] Cannot delete objects
19 min read
LDTate
I would delete these: zia00156, zia01936 and zia01696
LDTate
Do you still need help with this?
ahmeru2
LD Tate:
I got a message saying that you had posted a reply but I don't see it.
Al
LDTate
I would delete these: zia00156, zia01936 and zia01696
Can you give me the exact location and file name for those?3. There are still 4 or more files in my download folders from Youtube that have the name of videos I tried to download, These are not incomplete downloads as I can usually start those back up. What concerns me is efforts to "Delete" is greeted with a cannot, because it cannot find the disk or source these came from. Is there a way I can get rid of them?
ahmeru2
Yes. I see your messages now, LDTate. Still need help. Just got back from a long trip. Will find and post the locations tomorrow.
Al
LDTate
LDTate
Do you still need help with this?
ahmeru2
LDTate:
Sorry. Had to go out of town and got distracted.
Here is the direction to a growing series of things I cannot remove:
C:\Documents and Settings\Owner\dwhelper\New Folder
which contains a series of unidentified files that cannot be deleted.
A few of these are:
Nikola Tesla
NORTH AMERICAN UNION POLICE
Ripper Area 51
Robert F. Kennedy Jr.
The Sons of Liberty
Interview Edgar Fouche
Pleaidian Beamships
The ILLUMINATI
Occult History Of The 3rd Reich
Iraq Conspiracy
Moon Secrets Revealed
LDTate
Download ComboFix from one of these locations:
Link 1
Link 2
Link 3
* IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.
Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it atleast 20-30 minutes to finish if needed.
Also please describe how your computer behaves at the moment.
Link 1
Link 2
Link 3
* IMPORTANT !!! Save ComboFix.exe to your Desktop
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.
Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it atleast 20-30 minutes to finish if needed.
Also please describe how your computer behaves at the moment.
ahmeru2
LDTate:
As before, When I am prompted to download the missing MS Windows Recovery Console,, it attempts the process then reports "failed". Unable to download files????? How can that be corrected? TateaintLate
Never Mind. Figured out that when I disabled AVG, it disabled my internet connect. All I had to do was "Repair", and the Console was able to download.
Here's the data:
ComboFix 08-11-12.01 - Owner 2008-11-13 14:28:58.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.829 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-13 to 2008-11-13 )))))))))))))))))))))))))))))))
.
2008-11-12 16:30 . 2008-11-12 16:30 d——– c:\program files\MSXML 4.0
2008-11-12 14:55 . 2008-10-24 06:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 14:54 . 2008-09-04 12:15 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-11-09 15:42 . 2008-11-09 15:42 177 –a—— C:\Defaults.ppr
2008-11-08 11:03 . 2008-11-08 11:03 d——– c:\program files\System Security Suite 1.04
2008-11-01 21:45 . 2008-11-01 21:45 d——– c:\documents and settings\Administrator\Application Data\vlc
2008-11-01 21:44 . 2008-11-01 21:44 d——– c:\documents and settings\Administrator\Application Data\Media Player Classic
2008-11-01 20:45 . 2008-11-01 20:45 129,536 –a—-t- c:\windows\system32\DarkSpyKernel.sys
2008-10-29 00:13 . 2008-10-29 00:13 d——– c:\program files\BillP Studios
2008-10-29 00:13 . 2008-10-29 00:13 d——– c:\documents and settings\Owner\Application Data\WinPatrol
2008-10-28 12:38 . 2008-10-28 12:43 65 –a—— c:\windows\system32\BD7820N.dat
2008-10-26 17:43 . 2008-10-26 22:50 d——– c:\documents and settings\Owner\Application Data\dvdcss
2008-10-25 19:52 . 2008-10-25 19:52 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-10-25 19:52 . 2008-10-22 15:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-10-25 19:51 . 2008-10-25 19:52 d——– c:\program files\Malwarebytes' Anti-Malware
2008-10-25 19:51 . 2008-10-25 19:51 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-10-25 19:51 . 2008-10-22 15:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-25 19:11 . 2008-10-25 19:12 d——– c:\program files\ERUNT
2008-10-24 16:37 . 2008-09-08 22:38 88,576 –a—— c:\windows\system32\AntiXPVSTFix.exe
2008-10-24 16:37 . 2008-10-10 07:58 82,944 –a—— c:\windows\system32\o4Patch.exe
2008-10-24 16:37 . 2008-05-18 20:40 82,944 –a—— c:\windows\system32\IEDFix.exe
2008-10-24 16:37 . 2008-10-10 07:58 82,944 –a—— c:\windows\system32\IEDFix.C.exe
2008-10-24 16:37 . 2008-08-18 11:19 82,432 –a—— c:\windows\system32\404Fix.exe
2008-10-24 16:37 . 2004-07-31 17:50 51,200 –a—— c:\windows\system32\dumphive.exe
2008-10-24 05:38 . 2008-10-15 11:34 337,408 —–c— c:\windows\system32\dllcache\netapi32.dll
2008-10-14 23:48 . 2008-08-14 05:11 2,189,184 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-14 23:48 . 2008-08-14 05:09 2,145,280 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-14 23:48 . 2008-08-14 04:33 2,066,048 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-14 23:48 . 2008-08-14 04:33 2,023,936 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-14 23:48 . 2008-09-15 07:12 1,846,400 —–c— c:\windows\system32\dllcache\win32k.sys
2008-10-14 23:48 . 2008-09-08 05:41 333,824 —–c— c:\windows\system32\dllcache\srv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-13 19:15 ——— d—–w c:\documents and settings\Owner\Application Data\Skype
2008-11-13 19:13 ——— d—–w c:\documents and settings\Owner\Application Data\OpenOffice.org2
2008-11-13 18:00 ——— d—–w c:\program files\Mozilla Thunderbird
2008-11-13 01:33 ——— d—–w c:\documents and settings\All Users\Application Data\WholeSecurity
2008-11-12 20:11 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2008-11-12 14:05 ——— d—–w c:\documents and settings\Owner\Application Data\AVG7
2008-11-03 01:14 22,866 -c–a-w c:\documents and settings\Owner\Application Data\wklnhst.dat
2008-11-02 17:30 ——— d—–w c:\program files\Online TV & Radio Stations
2008-11-02 02:11 3,146 —-a-w c:\windows\system32\tmp.reg
2008-10-31 09:42 ——— d—–w c:\documents and settings\All Users\Application Data\SecTaskMan
2008-10-28 16:30 ——— d—–w c:\documents and settings\Owner\Application Data\mjusbsp
2008-10-28 04:38 ——— d—–w c:\program files\ConvertHelper
2008-10-27 23:36 ——— d—–w c:\program files\Opera
2008-10-26 04:44 ——— d—–w c:\program files\Google
2008-10-24 23:22 ——— d—–w c:\program files\XoftSpySE
2008-10-24 11:21 455,296 ——w c:\windows\system32\drivers\mrxsmb.sys
2008-10-21 20:01 ——— d—–w c:\program files\UFU
2008-10-17 15:52 ——— d—–w c:\program files\MWSnap
2008-10-15 15:40 ——— d—–w c:\program files\Abbyy FineReader 6.0 Sprint
2008-10-12 19:43 ——— d—–w c:\program files\TBFDropZone
2008-10-12 18:42 ——— d—–w c:\documents and settings\All Users\Application Data\Lexmark 7600 Series
2008-10-12 18:41 ——— d—–w c:\documents and settings\Owner\Application Data\Lexmark Productivity Studio
2008-10-12 18:39 ——— d—–w c:\program files\Lexmark 7600 Series
2008-10-12 18:33 ——— d—–w c:\program files\Lexmark Toolbar
2008-10-12 18:32 ——— d—–w c:\program files\Lexmark Printable Web
2008-10-12 18:25 ——— d—–w c:\program files\exPressit S.E. 2.2
2008-10-07 06:11 ——— d—–w c:\program files\YouTube Downloader
2008-10-03 21:59 ——— d—–w c:\program files\Snapshot Viewer
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-25 01:05 ——— d—–w c:\program files\Picasa2
2008-09-23 22:22 ——— d—–w c:\documents and settings\Owner\Application Data\7600 Series
2008-09-23 17:27 ——— d—–w c:\documents and settings\All Users\Application Data\7600 Series
2008-09-23 17:09 ——— d—–w c:\program files\Lavasoft
2008-09-23 03:09 ——— d—–w c:\program files\ESTsoft
2008-09-23 03:09 ——— d—–w c:\documents and settings\Owner\Application Data\ESTSoft
2008-09-23 03:09 ——— d—–w c:\documents and settings\All Users\Application Data\ESTsoft
2008-09-20 19:30 ——— d–h–w c:\program files\InstallShield Installation Information
2008-09-20 19:30 ——— d—–w c:\program files\RCA
2008-09-16 18:53 56,912 —-a-w c:\documents and settings\Owner\g2mdlhlpx.exe
2008-09-16 18:53 ——— d—–w c:\program files\Citrix
2008-09-16 12:56 ——— d—–w c:\program files\iTunes
2008-09-16 12:56 ——— d—–w c:\program files\iPod
2008-09-16 12:56 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-16 12:55 ——— d—–w c:\program files\QuickTime Alternative
2008-09-16 12:54 ——— d—–w c:\program files\Common Files\Apple
2008-09-15 12:12 1,846,400 ——w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 —-a-w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-08-29 14:18 87,336 —-a-w c:\windows\system32\dns-sd.exe
2008-08-29 13:53 65,536 —-a-w c:\windows\system32\jdns_sd.dll
2008-08-29 13:53 61,440 —-a-w c:\windows\system32\dnssd.dll
2008-08-20 05:30 666,112 —-a-w c:\windows\system32\wininet.dll
2008-08-14 10:11 2,189,184 ——w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:33 2,066,048 ——w c:\windows\system32\ntkrnlpa.exe
2007-08-19 01:16 41,904,054 -c–a-w c:\program files\CCI00002 (9000 x 1164).bmp
2007-08-19 01:15 134,640,054 -c–a-w c:\program files\CCI00002 (5100 x 6600).bmp
2007-04-29 02:49 23,054 -c—-w c:\program files\wklnhst.dat
2007-03-03 15:08 156 -c—-w c:\program files\ntl.ini
2007-02-24 12:43 1,863 -c—-w c:\program files\ntl.nws
2006-02-23 21:31 14,144,000 -c—-w c:\documents and settings\iTunes 2\iTunes.exe
2006-02-23 20:56 102,400 -c—-w c:\documents and settings\iTunes 2\iTunesMiniPlayer.dll
2006-02-23 20:45 278,528 -c—-w c:\documents and settings\iTunes 2\iTunesHelper.exe
2004-07-15 14:07 434,176 -c—-w c:\documents and settings\iTunes 2\CDDBControlApple.dll
2007-09-25 16:24 44,360 -c–a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2007-09-25 16:24 107,928 -c–a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2004-08-04 12:00 73,728 -csha-w c:\windows\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\FolderProtect0]
@="{D7BC78F3-3624-455C-8C4B-9C77C3BFEE4E}"
[HKEY_CLASSES_ROOT\CLSID\{D7BC78F3-3624-455C-8C4B-9C77C3BFEE4E}]
2006-12-22 15:30 57344 –a–c— i:\spotmau suite\Spotmau WinCares 2007\FolderProtectShellExtension.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\FolderProtect1]
@="{8A814C29-D3CD-4F9E-9770-DF8704503ACA}"
[HKEY_CLASSES_ROOT\CLSID\{8A814C29-D3CD-4F9E-9770-DF8704503ACA}]
2006-12-22 15:30 57344 –a–c— i:\spotmau suite\Spotmau WinCares 2007\FolderProtectShellExtension.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MWSnap"="c:\program files\MWSnap\MWSnap.exe" [2002-07-06 427008]
"cdloader"="c:\documents and settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2008-08-22 50520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-07-07 576320]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 600896]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2005-01-07 864256]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-10-17 590848]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\Ad-Watch.exe" [2008-08-17 2468200]
"SetDefPrt"="c:\program files\Brother\Brmfl04g\BrStDvPt.exe" [2004-11-11 49152]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"lxdwmon.exe"="c:\program files\Lexmark 7600 Series\lxdwmon.exe" [2008-05-21 676520]
"lxdwamon"="c:\program files\Lexmark 7600 Series\lxdwamon.exe" [2008-05-21 16040]
"Spy Protector"="c:\program files\Security Task Manager\SpyProtector.exe" [2007-03-05 114248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-10-05 160592]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-06-24 219136]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
MarketBrowser.lnk.disabled [2007-12-06 838]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.AVRn"= AvidAVICodec.dll
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\POP Peeper
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a–c— 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a–c— 2008-02-22 03:25 144784 c:\program files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"googletalk"=c:\program files\Google\Google Talk\googletalk.exe /autostart
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\ProspectMailer\\ProspectMailer.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\lxdwcoms.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"84:TCP"= 84:TCP:VRS Recording System Web Control Panel
R2 FolderProtectService;FolderProtectService;i:\spotmau suite\Spotmau WinCares 2007\FolderProtectService.exe [2006-12-22 16384]
R3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;c:\windows\system32\Drivers\BrSerIf.sys [2006-01-18 53248]
R3 BrUsbSer;Brother MFC USB Serial WDM Driver;c:\windows\system32\Drivers\BrUsbSer.sys [2006-01-19 11904]
R3 FolderProtectDriver;FolderProtectDriver;i:\spotmau suite\Spotmau WinCares 2007\FolderProtectDriver.sys [2006-12-12 11264]
S2 lxdw_device;lxdw_device;c:\windows\system32\lxdwcoms.exe [2008-05-16 594600]
S2 lxdwCATSCustConnectService;lxdwCATSCustConnectService;c:\windows\System32\spool\DRIVERS\W32X86\3\\lxdwserv.exe [2008-05-16 98984]
S2 MSSQL$PG_DB2;MSSQL$PG_DB2;c:\program files\Microsoft SQL Server\MSSQL$PG_DB2\Binn\sqlservr.exe [2002-12-17 7520337]
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\Drivers\Brfilt.sys [2001-08-17 2944]
S3 brparimg;Brother Multi Function Parallel Image driver;c:\windows\system32\DRIVERS\BrParImg.sys [2001-08-17 3168]
S3 BrParWdm;Brother WDM Parallel Driver;c:\windows\system32\Drivers\BrParwdm.sys [2001-08-17 39552]
S3 BrSerWDM;Brother WDM Serial driver;c:\windows\system32\Drivers\BrSerWdm.sys [2004-11-23 61440]
S3 DarkSpy;DarkSpy;c:\windows\system32\DarkSpyKernel.sys [2008-11-01 129536]
S3 SQLAgent$PG_DB2;SQLAgent$PG_DB2;c:\program files\Microsoft SQL Server\MSSQL$PG_DB2\Binn\sqlagent.EXE [2002-12-17 311872]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;c:\windows\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
.
Contents of the 'Scheduled Tasks' folder
2008-11-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-05-27 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 11:20]
2008-05-27 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 11:20]
2008-11-12 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-05-21 11:42]
2008-11-11 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-05-21 11:42]
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vs9wtk1r.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/firefox?client=firefox-a&rls;=org.mozilla:en-us:official
FF -: plugin - c:\program files\DNA\plugins\npbtdna.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdrmv2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdsplay.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npwmsdrm.dll
FF -: plugin - c:\program files\Picasa2\npPicasa2.dll
FF -: plugin - c:\program files\QuickTime Alternative\Plugins\npqtplugin.dll
FF -: plugin - c:\program files\QuickTime Alternative\Plugins\npqtplugin2.dll
FF -: plugin - c:\program files\QuickTime Alternative\Plugins\npqtplugin3.dll
FF -: plugin - c:\program files\QuickTime Alternative\Plugins\npqtplugin4.dll
FF -: plugin - c:\program files\QuickTime Alternative\Plugins\npqtplugin5.dll
FF -: plugin - c:\program files\Virtual Earth 3D\npVE3D.dll
FF -: plugin - c:\program files\Windows Media Player\npnul32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-13 14:30:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-13 14:30:40
ComboFix-quarantined-files.txt 2008-11-13 19:30:37
ComboFix2.txt 2008-10-28 16:59:55
Pre-Run: 127,347,740,672 bytes free
Post-Run: 127,332,569,088 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
245 — E O F — 2008-11-12 21:32:18
HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 14:54:56, on 11/13/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Lexmark 7600 Series\lxdwmon.exe
C:\Program Files\Lexmark 7600 Series\lxdwMsdMon.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\BrmfBAgS.exe
I:\Spotmau Suite\Spotmau WinCares 2007\FolderProtectService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Documents and Settings\Owner\Desktop\Downloads\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
O2 - BHO: OToolbarHelper Class - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll
O3 - Toolbar: &RoboForm; - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O3 - Toolbar: (no name) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - (no file)
O3 - Toolbar: Clusty - {5538fb62-f725-4433-a965-91314e8d8e4d} - C:\Program Files\Clusty Toolbar\toolbar1.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [lxdwmon.exe] "C:\Program Files\Lexmark 7600 Series\lxdwmon.exe"
O4 - HKLM\..\Run: [lxdwamon] "C:\Program Files\Lexmark 7600 Series\lxdwamon.exe"
O4 - HKLM\..\Run: [Spy Protector] C:\Program Files\Security Task Manager\SpyProtector.exe /autostart
O4 - HKCU\..\Run: [MWSnap] "C:\Program Files\MWSnap\MWSnap.exe"
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: MarketBrowser.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Clusty; meta-search - res://C:\Program Files\Clusty Toolbar\toolbar1.dll/SEARCH.HTML
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Active Whois - {BAB9A4F4-C201-4fcf-A5D3-BA77BC9FBEB2} - C:\Program Files\Active Whois\ieshow.exe
O9 - Extra 'Tools' menuitem: Active Whois - {BAB9A4F4-C201-4fcf-A5D3-BA77BC9FBEB2} - C:\Program Files\Active Whois\ieshow.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Brother BidiAgent Service for Resource manager (brmfbags) - Brother Industries, Ltd. - C:\WINDOWS\system32\BrmfBAgS.exe
O23 - Service: FolderProtectService - Unknown owner - I:\Spotmau Suite\Spotmau WinCares 2007\FolderProtectService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxdwCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdwserv.exe
O23 - Service: lxdw_device - - C:\WINDOWS\system32\lxdwcoms.exe
END
As before, When I am prompted to download the missing MS Windows Recovery Console,, it attempts the process then reports "failed". Unable to download files????? How can that be corrected? TateaintLate
Never Mind. Figured out that when I disabled AVG, it disabled my internet connect. All I had to do was "Repair", and the Console was able to download.
Here's the data:
ComboFix 08-11-12.01 - Owner 2008-11-13 14:28:58.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.829 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-13 to 2008-11-13 )))))))))))))))))))))))))))))))
.
2008-11-12 16:30 . 2008-11-12 16:30 d——– c:\program files\MSXML 4.0
2008-11-12 14:55 . 2008-10-24 06:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 14:54 . 2008-09-04 12:15 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-11-09 15:42 . 2008-11-09 15:42 177 –a—— C:\Defaults.ppr
2008-11-08 11:03 . 2008-11-08 11:03 d——– c:\program files\System Security Suite 1.04
2008-11-01 21:45 . 2008-11-01 21:45 d——– c:\documents and settings\Administrator\Application Data\vlc
2008-11-01 21:44 . 2008-11-01 21:44 d——– c:\documents and settings\Administrator\Application Data\Media Player Classic
2008-11-01 20:45 . 2008-11-01 20:45 129,536 –a—-t- c:\windows\system32\DarkSpyKernel.sys
2008-10-29 00:13 . 2008-10-29 00:13 d——– c:\program files\BillP Studios
2008-10-29 00:13 . 2008-10-29 00:13 d——– c:\documents and settings\Owner\Application Data\WinPatrol
2008-10-28 12:38 . 2008-10-28 12:43 65 –a—— c:\windows\system32\BD7820N.dat
2008-10-26 17:43 . 2008-10-26 22:50 d——– c:\documents and settings\Owner\Application Data\dvdcss
2008-10-25 19:52 . 2008-10-25 19:52 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-10-25 19:52 . 2008-10-22 15:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-10-25 19:51 . 2008-10-25 19:52 d——– c:\program files\Malwarebytes' Anti-Malware
2008-10-25 19:51 . 2008-10-25 19:51 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-10-25 19:51 . 2008-10-22 15:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-25 19:11 . 2008-10-25 19:12 d——– c:\program files\ERUNT
2008-10-24 16:37 . 2008-09-08 22:38 88,576 –a—— c:\windows\system32\AntiXPVSTFix.exe
2008-10-24 16:37 . 2008-10-10 07:58 82,944 –a—— c:\windows\system32\o4Patch.exe
2008-10-24 16:37 . 2008-05-18 20:40 82,944 –a—— c:\windows\system32\IEDFix.exe
2008-10-24 16:37 . 2008-10-10 07:58 82,944 –a—— c:\windows\system32\IEDFix.C.exe
2008-10-24 16:37 . 2008-08-18 11:19 82,432 –a—— c:\windows\system32\404Fix.exe
2008-10-24 16:37 . 2004-07-31 17:50 51,200 –a—— c:\windows\system32\dumphive.exe
2008-10-24 05:38 . 2008-10-15 11:34 337,408 —–c— c:\windows\system32\dllcache\netapi32.dll
2008-10-14 23:48 . 2008-08-14 05:11 2,189,184 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-14 23:48 . 2008-08-14 05:09 2,145,280 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-14 23:48 . 2008-08-14 04:33 2,066,048 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-14 23:48 . 2008-08-14 04:33 2,023,936 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-14 23:48 . 2008-09-15 07:12 1,846,400 —–c— c:\windows\system32\dllcache\win32k.sys
2008-10-14 23:48 . 2008-09-08 05:41 333,824 —–c— c:\windows\system32\dllcache\srv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-13 19:15 ——— d—–w c:\documents and settings\Owner\Application Data\Skype
2008-11-13 19:13 ——— d—–w c:\documents and settings\Owner\Application Data\OpenOffice.org2
2008-11-13 18:00 ——— d—–w c:\program files\Mozilla Thunderbird
2008-11-13 01:33 ——— d—–w c:\documents and settings\All Users\Application Data\WholeSecurity
2008-11-12 20:11 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2008-11-12 14:05 ——— d—–w c:\documents and settings\Owner\Application Data\AVG7
2008-11-03 01:14 22,866 -c–a-w c:\documents and settings\Owner\Application Data\wklnhst.dat
2008-11-02 17:30 ——— d—–w c:\program files\Online TV & Radio Stations
2008-11-02 02:11 3,146 —-a-w c:\windows\system32\tmp.reg
2008-10-31 09:42 ——— d—–w c:\documents and settings\All Users\Application Data\SecTaskMan
2008-10-28 16:30 ——— d—–w c:\documents and settings\Owner\Application Data\mjusbsp
2008-10-28 04:38 ——— d—–w c:\program files\ConvertHelper
2008-10-27 23:36 ——— d—–w c:\program files\Opera
2008-10-26 04:44 ——— d—–w c:\program files\Google
2008-10-24 23:22 ——— d—–w c:\program files\XoftSpySE
2008-10-24 11:21 455,296 ——w c:\windows\system32\drivers\mrxsmb.sys
2008-10-21 20:01 ——— d—–w c:\program files\UFU
2008-10-17 15:52 ——— d—–w c:\program files\MWSnap
2008-10-15 15:40 ——— d—–w c:\program files\Abbyy FineReader 6.0 Sprint
2008-10-12 19:43 ——— d—–w c:\program files\TBFDropZone
2008-10-12 18:42 ——— d—–w c:\documents and settings\All Users\Application Data\Lexmark 7600 Series
2008-10-12 18:41 ——— d—–w c:\documents and settings\Owner\Application Data\Lexmark Productivity Studio
2008-10-12 18:39 ——— d—–w c:\program files\Lexmark 7600 Series
2008-10-12 18:33 ——— d—–w c:\program files\Lexmark Toolbar
2008-10-12 18:32 ——— d—–w c:\program files\Lexmark Printable Web
2008-10-12 18:25 ——— d—–w c:\program files\exPressit S.E. 2.2
2008-10-07 06:11 ——— d—–w c:\program files\YouTube Downloader
2008-10-03 21:59 ——— d—–w c:\program files\Snapshot Viewer
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-25 01:05 ——— d—–w c:\program files\Picasa2
2008-09-23 22:22 ——— d—–w c:\documents and settings\Owner\Application Data\7600 Series
2008-09-23 17:27 ——— d—–w c:\documents and settings\All Users\Application Data\7600 Series
2008-09-23 17:09 ——— d—–w c:\program files\Lavasoft
2008-09-23 03:09 ——— d—–w c:\program files\ESTsoft
2008-09-23 03:09 ——— d—–w c:\documents and settings\Owner\Application Data\ESTSoft
2008-09-23 03:09 ——— d—–w c:\documents and settings\All Users\Application Data\ESTsoft
2008-09-20 19:30 ——— d–h–w c:\program files\InstallShield Installation Information
2008-09-20 19:30 ——— d—–w c:\program files\RCA
2008-09-16 18:53 56,912 —-a-w c:\documents and settings\Owner\g2mdlhlpx.exe
2008-09-16 18:53 ——— d—–w c:\program files\Citrix
2008-09-16 12:56 ——— d—–w c:\program files\iTunes
2008-09-16 12:56 ——— d—–w c:\program files\iPod
2008-09-16 12:56 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-16 12:55 ——— d—–w c:\program files\QuickTime Alternative
2008-09-16 12:54 ——— d—–w c:\program files\Common Files\Apple
2008-09-15 12:12 1,846,400 ——w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 —-a-w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-08-29 14:18 87,336 —-a-w c:\windows\system32\dns-sd.exe
2008-08-29 13:53 65,536 —-a-w c:\windows\system32\jdns_sd.dll
2008-08-29 13:53 61,440 —-a-w c:\windows\system32\dnssd.dll
2008-08-20 05:30 666,112 —-a-w c:\windows\system32\wininet.dll
2008-08-14 10:11 2,189,184 ——w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:33 2,066,048 ——w c:\windows\system32\ntkrnlpa.exe
2007-08-19 01:16 41,904,054 -c–a-w c:\program files\CCI00002 (9000 x 1164).bmp
2007-08-19 01:15 134,640,054 -c–a-w c:\program files\CCI00002 (5100 x 6600).bmp
2007-04-29 02:49 23,054 -c—-w c:\program files\wklnhst.dat
2007-03-03 15:08 156 -c—-w c:\program files\ntl.ini
2007-02-24 12:43 1,863 -c—-w c:\program files\ntl.nws
2006-02-23 21:31 14,144,000 -c—-w c:\documents and settings\iTunes 2\iTunes.exe
2006-02-23 20:56 102,400 -c—-w c:\documents and settings\iTunes 2\iTunesMiniPlayer.dll
2006-02-23 20:45 278,528 -c—-w c:\documents and settings\iTunes 2\iTunesHelper.exe
2004-07-15 14:07 434,176 -c—-w c:\documents and settings\iTunes 2\CDDBControlApple.dll
2007-09-25 16:24 44,360 -c–a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2007-09-25 16:24 107,928 -c–a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2004-08-04 12:00 73,728 -csha-w c:\windows\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\FolderProtect0]
@="{D7BC78F3-3624-455C-8C4B-9C77C3BFEE4E}"
[HKEY_CLASSES_ROOT\CLSID\{D7BC78F3-3624-455C-8C4B-9C77C3BFEE4E}]
2006-12-22 15:30 57344 –a–c— i:\spotmau suite\Spotmau WinCares 2007\FolderProtectShellExtension.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\FolderProtect1]
@="{8A814C29-D3CD-4F9E-9770-DF8704503ACA}"
[HKEY_CLASSES_ROOT\CLSID\{8A814C29-D3CD-4F9E-9770-DF8704503ACA}]
2006-12-22 15:30 57344 –a–c— i:\spotmau suite\Spotmau WinCares 2007\FolderProtectShellExtension.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MWSnap"="c:\program files\MWSnap\MWSnap.exe" [2002-07-06 427008]
"cdloader"="c:\documents and settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2008-08-22 50520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-07-07 576320]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 600896]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2005-01-07 864256]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-10-17 590848]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\Ad-Watch.exe" [2008-08-17 2468200]
"SetDefPrt"="c:\program files\Brother\Brmfl04g\BrStDvPt.exe" [2004-11-11 49152]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"lxdwmon.exe"="c:\program files\Lexmark 7600 Series\lxdwmon.exe" [2008-05-21 676520]
"lxdwamon"="c:\program files\Lexmark 7600 Series\lxdwamon.exe" [2008-05-21 16040]
"Spy Protector"="c:\program files\Security Task Manager\SpyProtector.exe" [2007-03-05 114248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-10-05 160592]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-06-24 219136]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
MarketBrowser.lnk.disabled [2007-12-06 838]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.AVRn"= AvidAVICodec.dll
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\POP Peeper
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a–c— 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a–c— 2008-02-22 03:25 144784 c:\program files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"googletalk"=c:\program files\Google\Google Talk\googletalk.exe /autostart
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\ProspectMailer\\ProspectMailer.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\lxdwcoms.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"84:TCP"= 84:TCP:VRS Recording System Web Control Panel
R2 FolderProtectService;FolderProtectService;i:\spotmau suite\Spotmau WinCares 2007\FolderProtectService.exe [2006-12-22 16384]
R3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;c:\windows\system32\Drivers\BrSerIf.sys [2006-01-18 53248]
R3 BrUsbSer;Brother MFC USB Serial WDM Driver;c:\windows\system32\Drivers\BrUsbSer.sys [2006-01-19 11904]
R3 FolderProtectDriver;FolderProtectDriver;i:\spotmau suite\Spotmau WinCares 2007\FolderProtectDriver.sys [2006-12-12 11264]
S2 lxdw_device;lxdw_device;c:\windows\system32\lxdwcoms.exe [2008-05-16 594600]
S2 lxdwCATSCustConnectService;lxdwCATSCustConnectService;c:\windows\System32\spool\DRIVERS\W32X86\3\\lxdwserv.exe [2008-05-16 98984]
S2 MSSQL$PG_DB2;MSSQL$PG_DB2;c:\program files\Microsoft SQL Server\MSSQL$PG_DB2\Binn\sqlservr.exe [2002-12-17 7520337]
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\Drivers\Brfilt.sys [2001-08-17 2944]
S3 brparimg;Brother Multi Function Parallel Image driver;c:\windows\system32\DRIVERS\BrParImg.sys [2001-08-17 3168]
S3 BrParWdm;Brother WDM Parallel Driver;c:\windows\system32\Drivers\BrParwdm.sys [2001-08-17 39552]
S3 BrSerWDM;Brother WDM Serial driver;c:\windows\system32\Drivers\BrSerWdm.sys [2004-11-23 61440]
S3 DarkSpy;DarkSpy;c:\windows\system32\DarkSpyKernel.sys [2008-11-01 129536]
S3 SQLAgent$PG_DB2;SQLAgent$PG_DB2;c:\program files\Microsoft SQL Server\MSSQL$PG_DB2\Binn\sqlagent.EXE [2002-12-17 311872]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;c:\windows\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
.
Contents of the 'Scheduled Tasks' folder
2008-11-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-05-27 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 11:20]
2008-05-27 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 11:20]
2008-11-12 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-05-21 11:42]
2008-11-11 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-05-21 11:42]
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vs9wtk1r.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/firefox?client=firefox-a&rls;=org.mozilla:en-us:official
FF -: plugin - c:\program files\DNA\plugins\npbtdna.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdrmv2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdsplay.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npwmsdrm.dll
FF -: plugin - c:\program files\Picasa2\npPicasa2.dll
FF -: plugin - c:\program files\QuickTime Alternative\Plugins\npqtplugin.dll
FF -: plugin - c:\program files\QuickTime Alternative\Plugins\npqtplugin2.dll
FF -: plugin - c:\program files\QuickTime Alternative\Plugins\npqtplugin3.dll
FF -: plugin - c:\program files\QuickTime Alternative\Plugins\npqtplugin4.dll
FF -: plugin - c:\program files\QuickTime Alternative\Plugins\npqtplugin5.dll
FF -: plugin - c:\program files\Virtual Earth 3D\npVE3D.dll
FF -: plugin - c:\program files\Windows Media Player\npnul32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-13 14:30:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-13 14:30:40
ComboFix-quarantined-files.txt 2008-11-13 19:30:37
ComboFix2.txt 2008-10-28 16:59:55
Pre-Run: 127,347,740,672 bytes free
Post-Run: 127,332,569,088 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
245 — E O F — 2008-11-12 21:32:18
HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 14:54:56, on 11/13/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Lexmark 7600 Series\lxdwmon.exe
C:\Program Files\Lexmark 7600 Series\lxdwMsdMon.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\BrmfBAgS.exe
I:\Spotmau Suite\Spotmau WinCares 2007\FolderProtectService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Documents and Settings\Owner\Desktop\Downloads\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
O2 - BHO: OToolbarHelper Class - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll
O3 - Toolbar: &RoboForm; - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O3 - Toolbar: (no name) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - (no file)
O3 - Toolbar: Clusty - {5538fb62-f725-4433-a965-91314e8d8e4d} - C:\Program Files\Clusty Toolbar\toolbar1.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [lxdwmon.exe] "C:\Program Files\Lexmark 7600 Series\lxdwmon.exe"
O4 - HKLM\..\Run: [lxdwamon] "C:\Program Files\Lexmark 7600 Series\lxdwamon.exe"
O4 - HKLM\..\Run: [Spy Protector] C:\Program Files\Security Task Manager\SpyProtector.exe /autostart
O4 - HKCU\..\Run: [MWSnap] "C:\Program Files\MWSnap\MWSnap.exe"
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Owner\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: MarketBrowser.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Clusty; meta-search - res://C:\Program Files\Clusty Toolbar\toolbar1.dll/SEARCH.HTML
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Active Whois - {BAB9A4F4-C201-4fcf-A5D3-BA77BC9FBEB2} - C:\Program Files\Active Whois\ieshow.exe
O9 - Extra 'Tools' menuitem: Active Whois - {BAB9A4F4-C201-4fcf-A5D3-BA77BC9FBEB2} - C:\Program Files\Active Whois\ieshow.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Brother BidiAgent Service for Resource manager (brmfbags) - Brother Industries, Ltd. - C:\WINDOWS\system32\BrmfBAgS.exe
O23 - Service: FolderProtectService - Unknown owner - I:\Spotmau Suite\Spotmau WinCares 2007\FolderProtectService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxdwCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdwserv.exe
O23 - Service: lxdw_device - - C:\WINDOWS\system32\lxdwcoms.exe
END
LDTate
I don't see those anywhere.
Are they in a folder / program?
Nikola Tesla
NORTH AMERICAN UNION POLICE
Ripper Area 51
Robert F. Kennedy Jr.
The Sons of Liberty
Interview Edgar Fouche
Pleaidian Beamships
The ILLUMINATI
Occult History Of The 3rd Reich
Iraq Conspiracy
Moon Secrets Revealed
ahmeru2
They are in this "New Folder" on my computer:
C:\Documents and Settings\Owner\dwhelper\New Folder
Other videos actually downloaded that cannot be deleted were moved (by me) to:
C:\Documents and Settings\Owner\Desktop\Al's Documents\Al's Stuff\Plan to Educate\YouTube\"name of video"
LDTate
Make sure you want to delete the folders and everything in them
Copy/paste the text in the Codebox below into notepad:
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
Drag CFScript.txt into ComboFix.exe
Then post the results log and a new HijackThis log.
Also please describe how your computer behaves at the moment.
Copy/paste the text in the Codebox below into notepad:
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
Folder:: C:\Documents and Settings\Owner\dwhelper\New Folder C:\Documents and Settings\Owner\Desktop\Al's Documents\Al's Stuff\Plan to Educate\YouTube
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
Drag CFScript.txt into ComboFix.exe
Then post the results log and a new HijackThis log.
Also please describe how your computer behaves at the moment.
ahmeru2
There's no problem removing the few items I want to keep in "New Folder" leaving only the ones to be removed. I will do that first. This afternoon.
The "Youtube" folder is a different story. There are 50G of video clips in there in probably 40-50 folders. I will have to set up a storage for the good stuff external to the folder named "Youtube" and move them to isolate the ones that can't be moved or deleted.
That will take some time unless you tell me I can also use your method to identify just the suspect video's by name and paste them into notepad.. That would certainly be easier. Is that possible? Or does it have to be the entire Youtube folder that is deleted? Al
ahmeru2
Strange. I submitted reports but they're not showing up as posted. Maybe there's a delay. Will check back later.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI