hdkeeton
Topic Starter
Hello all,
I was inspired to make this post by another thread started by a user that seemed to be having a problem with the same trojan. Please see thread: http://forums.whatthetech.com/Trojan_issue_t96719.html
My symptoms are somewhat different than what are explained in that thread. I experienced some weirdness in my web browser while looking at both newegg.com and some other sites. The task bar at the bottom of the screen disappeared, such that I could not click on anything after I closed the internet explorer window. So I did a hard reboot on my computer. Once it restarted, I had the following problems:
1. When I use internet explorer, every so often it brings up a new advertising window without my asking it to (once every few minutes). This appears to be advertising malware.
2. There is a red shield in the bottom of my system tray, telling me that windows automatic update is turned off. When I try to clik it to turn it on, it gives me an error message saying that the Security Center cannot turn it on, and that I need to turn it on from the System panel. When I go to that panel in the system information, it appears that automatic updates are turned on, but this does nothing to the red shield in the system tray.
3. My system restores have either been deleted or masked. In system restore, the only one listed is right after the problem started, but I know I had system restores from before that.
Like the user in the above thread, I ran AVG antivirus, which showed that I was infected by SHeur2.MR (from gadcom.exe) as well as it finding "a registry key with reference to infected file C:\Documents and Settings\….gadcom.exe." AVG said it healed the infection. I also ran Ad-Aware 2007, which found some other malware under a different name (which I unfortunately did not write down), which was also removed by Ad-Aware. Despite both of these, the above symptoms persisted.
Per what was recommended by Rorschach112 in the thread I mentioned, I followed the same instructions there and ran SDFix and Lop S&D; the way that he described. I give the log files below. The problem still seems to exist, even though SDFix removed some sort of infection.
After these first two steps, Rorschach's instructions seem to get specific to the other user, and somewhat more complicated. What I am hoping is that someone can look at my log files and provide me with some specific advice to how to fix this problem on my computer.
I apologize if I am posting this in the wrong forum. I would really appreciate any help anyone can give. My email is [removed], if you need to talk to me directly.
Thank you,
Hunter
SDFix Log File:
SDFix: Version 1.240
Run by [removed] on Sat 11/08/2008 at 09:43 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Resetting SecurityProviders Value
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\system32\pmnkICUo.dll - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk - Deleted
C:\WINDOWS\system32\msansspc.dll - Deleted
Folder C:\Documents and Settings\user\Application Data\gadcom - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-08 21:51:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"="C:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe:*:Enabled:Battlefield 2"
"C:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"="C:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe:*:Enabled:lotroclient.exe"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\Unreal Tournament 3 Demo\\Binaries\\UT3Demo.exe"="C:\\Program Files\\Unreal Tournament 3 Demo\\Binaries\\UT3Demo.exe:*:Enabled:Unreal Tournament 3 Demo"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE"="C:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE:*:Enabled:Microsoft Word"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\Capcom\\Bionic Commando Rearmed\\bcr.exe"="C:\\Program Files\\Capcom\\Bionic Commando Rearmed\\bcr.exe:*:Enabled:Bionic Commando Rearmed"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Tue 13 Sep 2005 1,847,296 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\LAUNCHER.EXE"
Sat 25 Jun 2005 62,464 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\MNYINSTA.DLL"
Fri 22 Apr 2005 95,232 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\RMVSUITE.EXE"
Thu 18 Aug 2005 36,864 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\SETUPLNG.DLL"
Wed 5 Jan 2005 20,480 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\UNREGWTR.EXE"
Mon 27 Oct 2008 8,089 …HR — "C:\Documents and Settings\user\Application Data\SecuROM\UserData\securom_v7_01.bak"
Thu 16 Feb 2006 396,288 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0200.tmp"
Fri 24 Feb 2006 72,192 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0665.tmp"
Fri 24 Feb 2006 72,704 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0771.tmp"
Thu 16 Feb 2006 50,688 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0775.tmp"
Thu 16 Feb 2006 396,800 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0889.tmp"
Thu 16 Feb 2006 391,168 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL1048.tmp"
Thu 16 Feb 2006 395,776 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL1753.tmp"
Thu 16 Feb 2006 392,192 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL2173.tmp"
Wed 22 Feb 2006 98,816 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL2613.tmp"
Thu 16 Feb 2006 390,656 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL3756.tmp"
Mon 28 Aug 2006 151,552 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL3828.tmp"
Thu 8 Jan 2004 45,568 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL0003.tmp"
Fri 9 Jan 2004 60,416 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL0568.tmp"
Fri 9 Jan 2004 75,776 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL1269.tmp"
Fri 9 Jan 2004 50,688 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL1298.tmp"
Fri 9 Jan 2004 53,760 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL1387.tmp"
Fri 9 Jan 2004 61,440 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL1598.tmp"
Fri 9 Jan 2004 63,488 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL2156.tmp"
Fri 9 Jan 2004 47,616 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL2312.tmp"
Fri 9 Jan 2004 62,976 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL2581.tmp"
Fri 9 Jan 2004 46,080 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL2860.tmp"
Fri 9 Jan 2004 60,416 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL3216.tmp"
Fri 9 Jan 2004 49,664 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL3517.tmp"
Fri 9 Jan 2004 56,320 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL4058.tmp"
Wed 26 Feb 2003 35,840 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Clinical\Begay v. begay\~WRL0003.tmp"
Thu 27 Feb 2003 39,424 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Clinical\Begay v. begay\~WRL0125.tmp"
Thu 27 Feb 2003 36,352 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Clinical\Begay v. begay\~WRL1768.tmp"
Thu 27 Feb 2003 40,448 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Clinical\Begay v. begay\~WRL2058.tmp"
Finished!
Lop S&D; Report:
——————–\\ Lop S&D; 4.2.4-9c XP/Vista
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Core™2 CPU 6600 @ 2.40GHz )
BIOS : Default System BIOS
USER : user ( Administrator )
BOOT : Normal boot
Antivirus : AVG Anti-Virus Free 8.0 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:298 Go (Free:182 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
E:\ (USB)
F:\ (USB)
"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( Sat 11/08/2008|21:58 )
——————–\\ Listing folders in APPLIC~1
[12/27/2006|03:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Creative
[06/26/2008|09:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[02/18/2007|11:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[08/02/2006|06:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Ahead
[02/15/2008|08:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[02/15/2008|08:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[10/17/2007|05:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ ATI
[06/27/2008|06:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ avg8
[10/03/2008|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ BCR
[12/27/2006|03:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Creative
[10/29/2006|08:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP
[11/08/2008|08:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[09/10/2007|05:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[06/10/2007|12:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Pure Networks
[12/30/2007|06:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SimCity Societies
[11/08/2008|09:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[12/16/2006|01:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[07/04/2007|05:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WinZip
[08/02/2006|04:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[12/01/2007|04:50] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[12/01/2007|04:50] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft
[11/04/2006|08:57] C:\DOCUME~1\user\APPLIC~1\ ACV
[02/25/2007|10:11] C:\DOCUME~1\user\APPLIC~1\ Adobe
[05/19/2008|08:11] C:\DOCUME~1\user\APPLIC~1\ AdobeUM
[02/15/2008|08:24] C:\DOCUME~1\user\APPLIC~1\ Apple Computer
[10/17/2007|05:35] C:\DOCUME~1\user\APPLIC~1\ ATI
[11/05/2006|10:50] C:\DOCUME~1\user\APPLIC~1\ atitray
[12/10/2007|09:31] C:\DOCUME~1\user\APPLIC~1\ Bioshock
[12/27/2006|04:02] C:\DOCUME~1\user\APPLIC~1\ Creative
[05/10/2008|04:14] C:\DOCUME~1\user\APPLIC~1\ Help
[12/04/2006|01:04] C:\DOCUME~1\user\APPLIC~1\ HP
[11/01/2006|10:31] C:\DOCUME~1\user\APPLIC~1\ ICAClient
[08/02/2006|05:01] C:\DOCUME~1\user\APPLIC~1\ Identities
[12/07/2007|09:06] C:\DOCUME~1\user\APPLIC~1\ Image Zone Express
[11/08/2007|06:39] C:\DOCUME~1\user\APPLIC~1\ InstallShield
[10/22/2007|05:48] C:\DOCUME~1\user\APPLIC~1\ InstallShield Installation Information
[10/29/2006|09:16] C:\DOCUME~1\user\APPLIC~1\ Logitech
[10/29/2006|07:32] C:\DOCUME~1\user\APPLIC~1\ Macromedia
[12/01/2007|04:50] C:\DOCUME~1\user\APPLIC~1\ Microsoft
[05/09/2008|07:05] C:\DOCUME~1\user\APPLIC~1\ Move Networks
[10/29/2006|08:59] C:\DOCUME~1\user\APPLIC~1\ Musicmatch
[06/26/2008|07:38] C:\DOCUME~1\user\APPLIC~1\ rhcnd6j0e38p
[05/12/2007|03:37] C:\DOCUME~1\user\APPLIC~1\ SecuROM
[12/27/2006|04:03] C:\DOCUME~1\user\APPLIC~1\ Smart Recorder
[01/18/2007|11:14] C:\DOCUME~1\user\APPLIC~1\ Sun
[04/14/2007|04:49] C:\DOCUME~1\user\APPLIC~1\ Turbine
[11/08/2008|09:50] C:\DOCUME~1\user\APPLIC~1\ WinRAR
——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks
[05/08/2008 06:07 AM][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[11/08/2008 09:48 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[07/27/2006 07:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini
——————–\\ Listing Folders in C:\Program Files
[11/08/2007|06:39] C:\Program Files\ 2K Games
[06/26/2008|09:02] C:\Program Files\ Ace Utilities
[08/02/2006|04:59] C:\Program Files\ Adobe
[10/03/2008|09:40] C:\Program Files\ AGEIA Technologies
[08/02/2006|06:15] C:\Program Files\ Ahead
[02/15/2008|08:23] C:\Program Files\ Apple Software Update
[11/08/2008|08:10] C:\Program Files\ a-squared Free
[10/17/2007|05:32] C:\Program Files\ ATI Technologies
[06/27/2008|06:39] C:\Program Files\ AVG
[09/23/2007|03:53] C:\Program Files\ Bethesda Softworks
[12/17/2007|09:09] C:\Program Files\ Black Isle
[02/15/2008|08:24] C:\Program Files\ Bonjour
[11/05/2006|05:40] C:\Program Files\ Cacheman
[11/05/2006|05:48] C:\Program Files\ CachemanXP
[10/03/2008|09:40] C:\Program Files\ Capcom
[11/01/2006|10:28] C:\Program Files\ Citrix
[02/15/2008|08:22] C:\Program Files\ Common Files
[08/02/2006|04:42] C:\Program Files\ ComPlus Applications
[11/26/2006|03:48] C:\Program Files\ cpu-z-138
[12/27/2006|03:49] C:\Program Files\ Creative
[06/10/2007|01:59] C:\Program Files\ DIFX
[05/15/2007|08:29] C:\Program Files\ Double Dragon
[11/01/2008|04:20] C:\Program Files\ EA GAMES
[12/30/2007|06:13] C:\Program Files\ Electronic Arts
[10/29/2006|07:33] C:\Program Files\ Encarta
[10/29/2006|04:02] C:\Program Files\ Futuremark
[05/15/2007|05:46] C:\Program Files\ Golden Axe
[12/01/2007|04:50] C:\Program Files\ Grisoft
[06/28/2008|02:54] C:\Program Files\ Guild Wars
[10/29/2006|08:41] C:\Program Files\ Hewlett-Packard
[10/29/2006|08:43] C:\Program Files\ HP
[10/03/2008|10:06] C:\Program Files\ InstallShield Installation Information
[05/09/2008|10:47] C:\Program Files\ Intel
[08/02/2006|05:56] C:\Program Files\ Intel Audio Studio
[10/16/2008|12:06] C:\Program Files\ Internet Explorer
[08/02/2006|05:00] C:\Program Files\ InterVideo
[02/15/2008|08:24] C:\Program Files\ iPod
[02/15/2008|08:24] C:\Program Files\ iTunes
[07/14/2007|04:31] C:\Program Files\ Jade Empire
[01/18/2007|11:14] C:\Program Files\ Java
[12/01/2007|05:00] C:\Program Files\ Lavasoft
[10/03/2008|10:07] C:\Program Files\ Logitech
[06/11/2007|07:53] C:\Program Files\ LucasArts
[09/16/2008|07:58] C:\Program Files\ Messenger
[10/29/2006|07:30] C:\Program Files\ Microsoft ActiveSync
[10/29/2006|07:32] C:\Program Files\ Microsoft Digital Image 2006
[08/02/2006|04:48] C:\Program Files\ microsoft frontpage
[10/29/2006|09:28] C:\Program Files\ Microsoft Location Finder
[06/02/2007|01:33] C:\Program Files\ microsoft money 2006
[08/31/2008|08:51] C:\Program Files\ Microsoft Office
[10/29/2006|07:34] C:\Program Files\ Microsoft Streets and Trips Essentials
[10/29/2006|07:30] C:\Program Files\ Microsoft Works
[10/29/2006|07:00] C:\Program Files\ Microsoft Works Suite 2006
[09/16/2008|07:57] C:\Program Files\ Movie Maker
[01/20/2007|04:10] C:\Program Files\ MP3Gain
[08/31/2008|08:51] C:\Program Files\ MSECache
[08/02/2006|04:41] C:\Program Files\ MSN
[08/02/2006|04:41] C:\Program Files\ MSN Gaming Zone
[08/02/2006|05:37] C:\Program Files\ MSXML 4.0
[10/29/2006|08:59] C:\Program Files\ MUSICMATCH
[09/16/2008|07:56] C:\Program Files\ NetMeeting
[08/02/2006|05:01] C:\Program Files\ NTRU Cryptosystems
[08/02/2006|04:41] C:\Program Files\ Online Services
[05/21/2008|07:16] C:\Program Files\ OpenAL
[08/24/2008|10:24] C:\Program Files\ Orban
[09/16/2008|07:55] C:\Program Files\ Outlook Express
[05/21/2008|07:12] C:\Program Files\ Paradox Interactive
[05/15/2008|08:37] C:\Program Files\ Prime95
[05/10/2008|01:50] C:\Program Files\ Prime95 - 2d Copy
[06/10/2007|12:31] C:\Program Files\ Pure Networks
[02/15/2008|08:23] C:\Program Files\ QuickTime
[11/08/2007|07:35] C:\Program Files\ Ray Adams
[06/22/2008|03:47] C:\Program Files\ Rockstar Games
[12/01/2007|05:11] C:\Program Files\ RootkitRevealer
[12/27/2006|04:11] C:\Program Files\ Sierra
[08/02/2006|05:56] C:\Program Files\ SigmaTel
[07/07/2008|10:05] C:\Program Files\ SpeedFan
[10/03/2008|09:15] C:\Program Files\ Steam
[08/02/2006|05:01] C:\Program Files\ STMicroelectronics
[05/21/2008|08:18] C:\Program Files\ The Witcher
[04/14/2007|04:36] C:\Program Files\ Turbine
[08/02/2006|05:01] C:\Program Files\ Uninstall Information
[10/22/2007|05:47] C:\Program Files\ Unreal Tournament 3 Demo
[08/02/2006|05:01] C:\Program Files\ Wave Systems Corp
[09/16/2008|07:55] C:\Program Files\ Windows Media Player
[09/16/2008|07:55] C:\Program Files\ Windows NT
[08/02/2006|04:43] C:\Program Files\ WindowsUpdate
[10/31/2006|09:24] C:\Program Files\ WinRAR
[07/04/2007|05:36] C:\Program Files\ WinZip
[08/02/2006|04:48] C:\Program Files\ xerox
——————–\\ Listing Folders in C:\Program Files\Common Files
[02/18/2007|11:32] C:\Program Files\Common Files\ Adobe
[08/02/2006|06:11] C:\Program Files\Common Files\ Ahead
[02/15/2008|08:22] C:\Program Files\Common Files\ Apple
[10/29/2006|07:29] C:\Program Files\Common Files\ Designer
[10/29/2006|08:41] C:\Program Files\Common Files\ Hewlett-Packard
[10/29/2006|08:43] C:\Program Files\Common Files\ HP
[08/02/2006|05:00] C:\Program Files\Common Files\ InstallShield
[01/18/2007|11:13] C:\Program Files\Common Files\ Java
[08/02/2006|06:14] C:\Program Files\Common Files\ LightScribe
[10/03/2008|10:07] C:\Program Files\Common Files\ Logitech
[08/31/2008|08:51] C:\Program Files\Common Files\ Microsoft Shared
[08/02/2006|04:42] C:\Program Files\Common Files\ MSSoap
[08/02/2006|06:13] C:\Program Files\Common Files\ Nero
[08/02/2006|09:36] C:\Program Files\Common Files\ ODBC
[06/10/2007|01:59] C:\Program Files\Common Files\ Pure Networks Shared
[08/02/2006|04:42] C:\Program Files\Common Files\ Services
[08/02/2006|09:36] C:\Program Files\Common Files\ SpeechEngines
[09/16/2008|07:55] C:\Program Files\Common Files\ System
[10/03/2008|09:41] C:\Program Files\Common Files\ Wise Installation Wizard
——————–\\ Process
( 42 Processes )
… OK !
——————–\\ Searching with S_Lop
No Lop folder found !
——————–\\ Searching for Lop Files - Folders
C:\DOCUME~1\user\Cookies\user@advertising[1].txt
C:\DOCUME~1\user\Cookies\[removed][1].txt
——————–\\ Searching within the Registry
….. OK !
——————–\\ Checking the Hosts file
Hosts file CLEAN
——————–\\ Searching for hidden files with Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-08 21:59:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0
——————–\\ Searching for other infections
C:\WINDOWS\system32\TBJjkUtv.ini
C:\WINDOWS\system32\TBJjkUtv.ini2
C:\WINDOWS\system32\vtUkjJBT.dll
==> VUNDO <==
——————–\\ Cracks & Keygens ..
C:\DOCUME~1\user\Desktop\Backups\Hunter's Backup\GTA San Andreas Other Files\data\Decision\Craig\crack1.ped
[F:688][D:76]-> C:\DOCUME~1\user\LOCALS~1\Temp
[F:131][D:0]-> C:\DOCUME~1\user\Cookies
[F:2718][D:5]-> C:\DOCUME~1\user\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - Sat 11/08/2008|22:00 - Option : [1]
——————–\\ Scan completed at 22:00:03
I was inspired to make this post by another thread started by a user that seemed to be having a problem with the same trojan. Please see thread: http://forums.whatthetech.com/Trojan_issue_t96719.html
My symptoms are somewhat different than what are explained in that thread. I experienced some weirdness in my web browser while looking at both newegg.com and some other sites. The task bar at the bottom of the screen disappeared, such that I could not click on anything after I closed the internet explorer window. So I did a hard reboot on my computer. Once it restarted, I had the following problems:
1. When I use internet explorer, every so often it brings up a new advertising window without my asking it to (once every few minutes). This appears to be advertising malware.
2. There is a red shield in the bottom of my system tray, telling me that windows automatic update is turned off. When I try to clik it to turn it on, it gives me an error message saying that the Security Center cannot turn it on, and that I need to turn it on from the System panel. When I go to that panel in the system information, it appears that automatic updates are turned on, but this does nothing to the red shield in the system tray.
3. My system restores have either been deleted or masked. In system restore, the only one listed is right after the problem started, but I know I had system restores from before that.
Like the user in the above thread, I ran AVG antivirus, which showed that I was infected by SHeur2.MR (from gadcom.exe) as well as it finding "a registry key with reference to infected file C:\Documents and Settings\….gadcom.exe." AVG said it healed the infection. I also ran Ad-Aware 2007, which found some other malware under a different name (which I unfortunately did not write down), which was also removed by Ad-Aware. Despite both of these, the above symptoms persisted.
Per what was recommended by Rorschach112 in the thread I mentioned, I followed the same instructions there and ran SDFix and Lop S&D; the way that he described. I give the log files below. The problem still seems to exist, even though SDFix removed some sort of infection.
After these first two steps, Rorschach's instructions seem to get specific to the other user, and somewhat more complicated. What I am hoping is that someone can look at my log files and provide me with some specific advice to how to fix this problem on my computer.
I apologize if I am posting this in the wrong forum. I would really appreciate any help anyone can give. My email is [removed], if you need to talk to me directly.
Thank you,
Hunter
SDFix Log File:
SDFix: Version 1.240
Run by [removed] on Sat 11/08/2008 at 09:43 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Resetting SecurityProviders Value
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\system32\pmnkICUo.dll - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk - Deleted
C:\WINDOWS\system32\msansspc.dll - Deleted
Folder C:\Documents and Settings\user\Application Data\gadcom - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-08 21:51:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"="C:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe:*:Enabled:Battlefield 2"
"C:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"="C:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe:*:Enabled:lotroclient.exe"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\Unreal Tournament 3 Demo\\Binaries\\UT3Demo.exe"="C:\\Program Files\\Unreal Tournament 3 Demo\\Binaries\\UT3Demo.exe:*:Enabled:Unreal Tournament 3 Demo"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE"="C:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE:*:Enabled:Microsoft Word"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\Capcom\\Bionic Commando Rearmed\\bcr.exe"="C:\\Program Files\\Capcom\\Bionic Commando Rearmed\\bcr.exe:*:Enabled:Bionic Commando Rearmed"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Tue 13 Sep 2005 1,847,296 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\LAUNCHER.EXE"
Sat 25 Jun 2005 62,464 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\MNYINSTA.DLL"
Fri 22 Apr 2005 95,232 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\RMVSUITE.EXE"
Thu 18 Aug 2005 36,864 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\SETUPLNG.DLL"
Wed 5 Jan 2005 20,480 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\UNREGWTR.EXE"
Mon 27 Oct 2008 8,089 …HR — "C:\Documents and Settings\user\Application Data\SecuROM\UserData\securom_v7_01.bak"
Thu 16 Feb 2006 396,288 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0200.tmp"
Fri 24 Feb 2006 72,192 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0665.tmp"
Fri 24 Feb 2006 72,704 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0771.tmp"
Thu 16 Feb 2006 50,688 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0775.tmp"
Thu 16 Feb 2006 396,800 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0889.tmp"
Thu 16 Feb 2006 391,168 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL1048.tmp"
Thu 16 Feb 2006 395,776 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL1753.tmp"
Thu 16 Feb 2006 392,192 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL2173.tmp"
Wed 22 Feb 2006 98,816 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL2613.tmp"
Thu 16 Feb 2006 390,656 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL3756.tmp"
Mon 28 Aug 2006 151,552 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL3828.tmp"
Thu 8 Jan 2004 45,568 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL0003.tmp"
Fri 9 Jan 2004 60,416 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL0568.tmp"
Fri 9 Jan 2004 75,776 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL1269.tmp"
Fri 9 Jan 2004 50,688 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL1298.tmp"
Fri 9 Jan 2004 53,760 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL1387.tmp"
Fri 9 Jan 2004 61,440 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL1598.tmp"
Fri 9 Jan 2004 63,488 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL2156.tmp"
Fri 9 Jan 2004 47,616 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL2312.tmp"
Fri 9 Jan 2004 62,976 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL2581.tmp"
Fri 9 Jan 2004 46,080 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL2860.tmp"
Fri 9 Jan 2004 60,416 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL3216.tmp"
Fri 9 Jan 2004 49,664 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL3517.tmp"
Fri 9 Jan 2004 56,320 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL4058.tmp"
Wed 26 Feb 2003 35,840 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Clinical\Begay v. begay\~WRL0003.tmp"
Thu 27 Feb 2003 39,424 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Clinical\Begay v. begay\~WRL0125.tmp"
Thu 27 Feb 2003 36,352 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Clinical\Begay v. begay\~WRL1768.tmp"
Thu 27 Feb 2003 40,448 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Clinical\Begay v. begay\~WRL2058.tmp"
Finished!
Lop S&D; Report:
——————–\\ Lop S&D; 4.2.4-9c XP/Vista
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Core™2 CPU 6600 @ 2.40GHz )
BIOS : Default System BIOS
USER : user ( Administrator )
BOOT : Normal boot
Antivirus : AVG Anti-Virus Free 8.0 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:298 Go (Free:182 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
E:\ (USB)
F:\ (USB)
"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( Sat 11/08/2008|21:58 )
——————–\\ Listing folders in APPLIC~1
[12/27/2006|03:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Creative
[06/26/2008|09:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[02/18/2007|11:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[08/02/2006|06:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Ahead
[02/15/2008|08:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[02/15/2008|08:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[10/17/2007|05:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ ATI
[06/27/2008|06:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ avg8
[10/03/2008|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ BCR
[12/27/2006|03:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Creative
[10/29/2006|08:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP
[11/08/2008|08:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[09/10/2007|05:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[06/10/2007|12:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Pure Networks
[12/30/2007|06:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SimCity Societies
[11/08/2008|09:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[12/16/2006|01:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[07/04/2007|05:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WinZip
[08/02/2006|04:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[12/01/2007|04:50] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[12/01/2007|04:50] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft
[11/04/2006|08:57] C:\DOCUME~1\user\APPLIC~1\ ACV
[02/25/2007|10:11] C:\DOCUME~1\user\APPLIC~1\ Adobe
[05/19/2008|08:11] C:\DOCUME~1\user\APPLIC~1\ AdobeUM
[02/15/2008|08:24] C:\DOCUME~1\user\APPLIC~1\ Apple Computer
[10/17/2007|05:35] C:\DOCUME~1\user\APPLIC~1\ ATI
[11/05/2006|10:50] C:\DOCUME~1\user\APPLIC~1\ atitray
[12/10/2007|09:31] C:\DOCUME~1\user\APPLIC~1\ Bioshock
[12/27/2006|04:02] C:\DOCUME~1\user\APPLIC~1\ Creative
[05/10/2008|04:14] C:\DOCUME~1\user\APPLIC~1\ Help
[12/04/2006|01:04] C:\DOCUME~1\user\APPLIC~1\ HP
[11/01/2006|10:31] C:\DOCUME~1\user\APPLIC~1\ ICAClient
[08/02/2006|05:01] C:\DOCUME~1\user\APPLIC~1\ Identities
[12/07/2007|09:06] C:\DOCUME~1\user\APPLIC~1\ Image Zone Express
[11/08/2007|06:39] C:\DOCUME~1\user\APPLIC~1\ InstallShield
[10/22/2007|05:48] C:\DOCUME~1\user\APPLIC~1\ InstallShield Installation Information
[10/29/2006|09:16] C:\DOCUME~1\user\APPLIC~1\ Logitech
[10/29/2006|07:32] C:\DOCUME~1\user\APPLIC~1\ Macromedia
[12/01/2007|04:50] C:\DOCUME~1\user\APPLIC~1\ Microsoft
[05/09/2008|07:05] C:\DOCUME~1\user\APPLIC~1\ Move Networks
[10/29/2006|08:59] C:\DOCUME~1\user\APPLIC~1\ Musicmatch
[06/26/2008|07:38] C:\DOCUME~1\user\APPLIC~1\ rhcnd6j0e38p
[05/12/2007|03:37] C:\DOCUME~1\user\APPLIC~1\ SecuROM
[12/27/2006|04:03] C:\DOCUME~1\user\APPLIC~1\ Smart Recorder
[01/18/2007|11:14] C:\DOCUME~1\user\APPLIC~1\ Sun
[04/14/2007|04:49] C:\DOCUME~1\user\APPLIC~1\ Turbine
[11/08/2008|09:50] C:\DOCUME~1\user\APPLIC~1\ WinRAR
——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks
[05/08/2008 06:07 AM][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[11/08/2008 09:48 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[07/27/2006 07:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini
——————–\\ Listing Folders in C:\Program Files
[11/08/2007|06:39] C:\Program Files\ 2K Games
[06/26/2008|09:02] C:\Program Files\ Ace Utilities
[08/02/2006|04:59] C:\Program Files\ Adobe
[10/03/2008|09:40] C:\Program Files\ AGEIA Technologies
[08/02/2006|06:15] C:\Program Files\ Ahead
[02/15/2008|08:23] C:\Program Files\ Apple Software Update
[11/08/2008|08:10] C:\Program Files\ a-squared Free
[10/17/2007|05:32] C:\Program Files\ ATI Technologies
[06/27/2008|06:39] C:\Program Files\ AVG
[09/23/2007|03:53] C:\Program Files\ Bethesda Softworks
[12/17/2007|09:09] C:\Program Files\ Black Isle
[02/15/2008|08:24] C:\Program Files\ Bonjour
[11/05/2006|05:40] C:\Program Files\ Cacheman
[11/05/2006|05:48] C:\Program Files\ CachemanXP
[10/03/2008|09:40] C:\Program Files\ Capcom
[11/01/2006|10:28] C:\Program Files\ Citrix
[02/15/2008|08:22] C:\Program Files\ Common Files
[08/02/2006|04:42] C:\Program Files\ ComPlus Applications
[11/26/2006|03:48] C:\Program Files\ cpu-z-138
[12/27/2006|03:49] C:\Program Files\ Creative
[06/10/2007|01:59] C:\Program Files\ DIFX
[05/15/2007|08:29] C:\Program Files\ Double Dragon
[11/01/2008|04:20] C:\Program Files\ EA GAMES
[12/30/2007|06:13] C:\Program Files\ Electronic Arts
[10/29/2006|07:33] C:\Program Files\ Encarta
[10/29/2006|04:02] C:\Program Files\ Futuremark
[05/15/2007|05:46] C:\Program Files\ Golden Axe
[12/01/2007|04:50] C:\Program Files\ Grisoft
[06/28/2008|02:54] C:\Program Files\ Guild Wars
[10/29/2006|08:41] C:\Program Files\ Hewlett-Packard
[10/29/2006|08:43] C:\Program Files\ HP
[10/03/2008|10:06] C:\Program Files\ InstallShield Installation Information
[05/09/2008|10:47] C:\Program Files\ Intel
[08/02/2006|05:56] C:\Program Files\ Intel Audio Studio
[10/16/2008|12:06] C:\Program Files\ Internet Explorer
[08/02/2006|05:00] C:\Program Files\ InterVideo
[02/15/2008|08:24] C:\Program Files\ iPod
[02/15/2008|08:24] C:\Program Files\ iTunes
[07/14/2007|04:31] C:\Program Files\ Jade Empire
[01/18/2007|11:14] C:\Program Files\ Java
[12/01/2007|05:00] C:\Program Files\ Lavasoft
[10/03/2008|10:07] C:\Program Files\ Logitech
[06/11/2007|07:53] C:\Program Files\ LucasArts
[09/16/2008|07:58] C:\Program Files\ Messenger
[10/29/2006|07:30] C:\Program Files\ Microsoft ActiveSync
[10/29/2006|07:32] C:\Program Files\ Microsoft Digital Image 2006
[08/02/2006|04:48] C:\Program Files\ microsoft frontpage
[10/29/2006|09:28] C:\Program Files\ Microsoft Location Finder
[06/02/2007|01:33] C:\Program Files\ microsoft money 2006
[08/31/2008|08:51] C:\Program Files\ Microsoft Office
[10/29/2006|07:34] C:\Program Files\ Microsoft Streets and Trips Essentials
[10/29/2006|07:30] C:\Program Files\ Microsoft Works
[10/29/2006|07:00] C:\Program Files\ Microsoft Works Suite 2006
[09/16/2008|07:57] C:\Program Files\ Movie Maker
[01/20/2007|04:10] C:\Program Files\ MP3Gain
[08/31/2008|08:51] C:\Program Files\ MSECache
[08/02/2006|04:41] C:\Program Files\ MSN
[08/02/2006|04:41] C:\Program Files\ MSN Gaming Zone
[08/02/2006|05:37] C:\Program Files\ MSXML 4.0
[10/29/2006|08:59] C:\Program Files\ MUSICMATCH
[09/16/2008|07:56] C:\Program Files\ NetMeeting
[08/02/2006|05:01] C:\Program Files\ NTRU Cryptosystems
[08/02/2006|04:41] C:\Program Files\ Online Services
[05/21/2008|07:16] C:\Program Files\ OpenAL
[08/24/2008|10:24] C:\Program Files\ Orban
[09/16/2008|07:55] C:\Program Files\ Outlook Express
[05/21/2008|07:12] C:\Program Files\ Paradox Interactive
[05/15/2008|08:37] C:\Program Files\ Prime95
[05/10/2008|01:50] C:\Program Files\ Prime95 - 2d Copy
[06/10/2007|12:31] C:\Program Files\ Pure Networks
[02/15/2008|08:23] C:\Program Files\ QuickTime
[11/08/2007|07:35] C:\Program Files\ Ray Adams
[06/22/2008|03:47] C:\Program Files\ Rockstar Games
[12/01/2007|05:11] C:\Program Files\ RootkitRevealer
[12/27/2006|04:11] C:\Program Files\ Sierra
[08/02/2006|05:56] C:\Program Files\ SigmaTel
[07/07/2008|10:05] C:\Program Files\ SpeedFan
[10/03/2008|09:15] C:\Program Files\ Steam
[08/02/2006|05:01] C:\Program Files\ STMicroelectronics
[05/21/2008|08:18] C:\Program Files\ The Witcher
[04/14/2007|04:36] C:\Program Files\ Turbine
[08/02/2006|05:01] C:\Program Files\ Uninstall Information
[10/22/2007|05:47] C:\Program Files\ Unreal Tournament 3 Demo
[08/02/2006|05:01] C:\Program Files\ Wave Systems Corp
[09/16/2008|07:55] C:\Program Files\ Windows Media Player
[09/16/2008|07:55] C:\Program Files\ Windows NT
[08/02/2006|04:43] C:\Program Files\ WindowsUpdate
[10/31/2006|09:24] C:\Program Files\ WinRAR
[07/04/2007|05:36] C:\Program Files\ WinZip
[08/02/2006|04:48] C:\Program Files\ xerox
——————–\\ Listing Folders in C:\Program Files\Common Files
[02/18/2007|11:32] C:\Program Files\Common Files\ Adobe
[08/02/2006|06:11] C:\Program Files\Common Files\ Ahead
[02/15/2008|08:22] C:\Program Files\Common Files\ Apple
[10/29/2006|07:29] C:\Program Files\Common Files\ Designer
[10/29/2006|08:41] C:\Program Files\Common Files\ Hewlett-Packard
[10/29/2006|08:43] C:\Program Files\Common Files\ HP
[08/02/2006|05:00] C:\Program Files\Common Files\ InstallShield
[01/18/2007|11:13] C:\Program Files\Common Files\ Java
[08/02/2006|06:14] C:\Program Files\Common Files\ LightScribe
[10/03/2008|10:07] C:\Program Files\Common Files\ Logitech
[08/31/2008|08:51] C:\Program Files\Common Files\ Microsoft Shared
[08/02/2006|04:42] C:\Program Files\Common Files\ MSSoap
[08/02/2006|06:13] C:\Program Files\Common Files\ Nero
[08/02/2006|09:36] C:\Program Files\Common Files\ ODBC
[06/10/2007|01:59] C:\Program Files\Common Files\ Pure Networks Shared
[08/02/2006|04:42] C:\Program Files\Common Files\ Services
[08/02/2006|09:36] C:\Program Files\Common Files\ SpeechEngines
[09/16/2008|07:55] C:\Program Files\Common Files\ System
[10/03/2008|09:41] C:\Program Files\Common Files\ Wise Installation Wizard
——————–\\ Process
( 42 Processes )
… OK !
——————–\\ Searching with S_Lop
No Lop folder found !
——————–\\ Searching for Lop Files - Folders
C:\DOCUME~1\user\Cookies\user@advertising[1].txt
C:\DOCUME~1\user\Cookies\[removed][1].txt
——————–\\ Searching within the Registry
….. OK !
——————–\\ Checking the Hosts file
Hosts file CLEAN
——————–\\ Searching for hidden files with Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-08 21:59:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0
——————–\\ Searching for other infections
C:\WINDOWS\system32\TBJjkUtv.ini
C:\WINDOWS\system32\TBJjkUtv.ini2
C:\WINDOWS\system32\vtUkjJBT.dll
==> VUNDO <==
——————–\\ Cracks & Keygens ..
C:\DOCUME~1\user\Desktop\Backups\Hunter's Backup\GTA San Andreas Other Files\data\Decision\Craig\crack1.ped
[F:688][D:76]-> C:\DOCUME~1\user\LOCALS~1\Temp
[F:131][D:0]-> C:\DOCUME~1\user\Cookies
[F:2718][D:5]-> C:\DOCUME~1\user\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - Sat 11/08/2008|22:00 - Option : [1]
——————–\\ Scan completed at 22:00:03