This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HijackThis log

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

My topic was closed due to inactivity. I was capped and was waiting to get my internet speed back to do the Kaspersky scan which wouldnt work while i was capped. I was told to post a Combo fix log and Kaspersky Log once they were all completed and then a HJT log, here they are.

ComboFix 08-12-13.03 - Sachi Eapen 2008-12-14 16:44:14.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1497 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Sachi Eapen\Desktop\CFScript.txt.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-11-14 to 2008-12-14 )))))))))))))))))))))))))))))))
.

2008-12-12 15:40 . 2008-12-12 15:40 d——– c:\documents and settings\Sachi Eapen\Application Data\Red Alert 3 Demo
2008-12-08 17:47 . 2008-12-08 17:47 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-08 17:47 . 2008-12-08 17:47 d——– c:\documents and settings\Sachi Eapen\Application Data\Malwarebytes
2008-12-08 17:47 . 2008-12-08 17:47 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-08 17:47 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-08 17:47 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-06 00:33 . 2008-12-06 00:33 d——– c:\windows\system32\AGEIA
2008-12-06 00:33 . 2008-12-06 00:33 d——– c:\program files\AGEIA Technologies
2008-12-05 11:28 . 2008-05-30 14:11 3,850,760 –a—— c:\windows\system32\D3DX9_38.dll
2008-12-05 11:28 . 2008-05-30 14:11 1,491,992 –a—— c:\windows\system32\D3DCompiler_38.dll
2008-12-05 11:28 . 2008-05-30 14:11 467,984 –a—— c:\windows\system32\d3dx10_38.dll
2008-12-05 11:27 . 2008-12-05 11:27 d——– c:\windows\Logs
2008-12-04 02:39 . 2008-12-04 02:39 d——– c:\program files\Lavasoft
2008-12-04 02:39 . 2008-12-06 00:45 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-04 02:34 . 2008-12-11 06:00 d——– c:\documents and settings\Sachi Eapen\Application Data\BitTorrent
2008-12-04 02:31 . 2008-12-14 14:35 d——– c:\program files\DNA
2008-12-04 02:31 . 2008-12-04 02:31 d——– c:\program files\AskBarDis
2008-12-04 02:31 . 2008-12-14 16:45 d——– c:\documents and settings\Sachi Eapen\Application Data\DNA
2008-12-04 01:57 . 2008-12-04 01:57 d——– c:\program files\iTunes
2008-12-04 01:57 . 2008-12-04 01:57 d——– c:\program files\iPod
2008-12-04 01:53 . 2008-12-04 01:54 d——– c:\program files\QuickTime
2008-12-04 01:35 . 2008-12-04 01:35 54,156 –ah—– c:\windows\QTFont.qfn
2008-12-04 01:35 . 2008-12-04 01:35 1,409 –a—— c:\windows\QTFont.for
2008-12-04 01:14 . 2008-12-04 01:14 d——– c:\windows\system32\scripting
2008-12-04 01:14 . 2008-12-04 01:14 d——– c:\windows\l2schemas
2008-12-04 01:13 . 2008-12-04 01:13 d——– c:\windows\system32\en
2008-12-04 01:13 . 2008-12-04 01:13 d——– c:\windows\system32\bits
2008-12-04 01:10 . 2008-12-04 01:14 d——– c:\windows\ServicePackFiles
2008-11-21 06:44 . 2008-11-21 06:44 42,320 –a—— c:\windows\system32\xfcodec.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-14 06:36 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-12-14 04:38 ——— d—–w c:\documents and settings\Sachi Eapen\Application Data\Skype
2008-12-14 04:36 ——— d—–w c:\documents and settings\Sachi Eapen\Application Data\skypePM
2008-12-11 09:19 201,352 —-a-w c:\windows\system32\PnkBstrB.exe
2008-12-11 09:19 140,216 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-12-10 14:03 ——— d—–w c:\program files\Steam
2008-12-10 12:58 ——— d—–w c:\documents and settings\Sachi Eapen\Application Data\mIRC
2008-12-10 12:50 ——— d—–w c:\program files\mIRC
2008-12-10 11:51 ——— d—–w c:\documents and settings\Sachi Eapen\Application Data\Xfire
2008-12-05 14:51 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-05 14:50 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-05 14:45 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-05 12:00 ——— d—–w c:\program files\Xfire
2008-12-04 15:45 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-03 17:13 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2008-12-03 16:53 ——— d—–w c:\program files\Apple Software Update
2008-12-03 16:49 ——— d—–w c:\documents and settings\Sachi Eapen\Application Data\LimeWire
2008-12-03 16:38 ——— d—–w c:\program files\LimeWire
2008-12-03 16:38 ——— d—–w c:\program files\Incomplete
2008-12-03 15:57 ——— d—–w c:\program files\Common Files\Apple
2008-12-03 15:31 ——— d—–w c:\program files\MSN Messenger
2008-11-24 08:27 ——— d—–w c:\program files\Common Files\Adobe
2008-11-05 23:14 ——— d—–w c:\program files\Norton 360
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 —-a-w c:\windows\system32\wininet.dll
2008-10-16 04:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 04:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 04:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 04:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 04:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 04:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 04:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 04:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-02 00:07 453,152 —-a-w c:\windows\system32\NVUNINST.EXE
2008-09-30 06:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 12:12 1,846,400 —-a-w c:\windows\system32\win32k.sys
2008-04-16 01:34 22,328 —-a-w c:\documents and settings\Sachi Eapen\Application Data\PnkBstrK.sys
2008-02-11 11:49 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-10-29 07:15 2 –shatr c:\windows\winstart.bat
.

((((((((((((((((((((((((((((( snapshot@2008-12-12_ 1.17.26.79 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-26 07:24:28 124,928 -c—-w c:\windows\ie7updates\KB958215-IE7\advpack.dll
+ 2008-08-26 07:24:28 347,136 -c—-w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
+ 2008-08-26 07:24:28 214,528 -c—-w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
+ 2008-08-26 07:24:28 133,120 -c—-w c:\windows\ie7updates\KB958215-IE7\extmgr.dll
+ 2008-08-26 07:24:28 63,488 -c—-w c:\windows\ie7updates\KB958215-IE7\icardie.dll
+ 2008-08-25 08:37:59 70,656 -c—-w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
+ 2008-08-26 07:24:28 153,088 -c—-w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
+ 2008-08-26 07:24:28 230,400 -c—-w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
+ 2008-08-23 05:54:51 161,792 -c—-w c:\windows\ie7updates\KB958215-IE7\ieakui.dll
+ 2008-08-26 07:24:28 383,488 -c—-w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
+ 2008-08-26 07:24:29 384,512 -c—-w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
+ 2008-10-03 17:41:15 6,066,176 -c—-w c:\windows\ie7updates\KB958215-IE7\ieframe.dll
+ 2008-08-26 07:24:29 44,544 -c—-w c:\windows\ie7updates\KB958215-IE7\iernonce.dll
+ 2008-08-26 07:24:29 267,776 -c—-w c:\windows\ie7updates\KB958215-IE7\iertutil.dll
+ 2008-08-25 08:38:00 13,824 -c—-w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
+ 2008-08-23 05:56:15 635,848 -c—-w c:\windows\ie7updates\KB958215-IE7\iexplore.exe
+ 2008-08-26 07:24:30 27,648 -c—-w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
+ 2008-08-26 07:24:30 459,264 -c—-w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
+ 2008-08-26 07:24:30 52,224 -c—-w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
+ 2008-08-27 08:24:32 3,593,216 -c—-w c:\windows\ie7updates\KB958215-IE7\mshtml.dll
+ 2008-08-26 07:24:30 477,696 -c—-w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
+ 2008-08-26 07:24:30 193,024 -c—-w c:\windows\ie7updates\KB958215-IE7\msrating.dll
+ 2008-08-26 07:24:30 671,232 -c—-w c:\windows\ie7updates\KB958215-IE7\mstime.dll
+ 2008-08-26 07:24:30 102,912 -c—-w c:\windows\ie7updates\KB958215-IE7\occache.dll
+ 2008-08-26 07:24:30 44,544 -c—-w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
+ 2008-08-26 07:24:30 105,984 -c—-w c:\windows\ie7updates\KB958215-IE7\url.dll
+ 2008-08-26 07:24:31 1,159,680 -c—-w c:\windows\ie7updates\KB958215-IE7\urlmon.dll
+ 2008-08-26 07:24:31 233,472 -c—-w c:\windows\ie7updates\KB958215-IE7\webcheck.dll
+ 2008-08-26 07:24:31 826,368 -c—-w c:\windows\ie7updates\KB958215-IE7\wininet.dll
+ 2008-12-12 03:53:02 36,710 —-a-r c:\windows\Installer\{DBD1FF41-F438-4D0A-A3F1-999930B5BC52}\ra3.exe
- 2008-08-26 07:24:28 124,928 —-a-w c:\windows\system32\advpack.dll
+ 2008-10-16 20:38:34 124,928 —-a-w c:\windows\system32\advpack.dll
- 2008-08-26 07:24:28 124,928 -c–a-w c:\windows\system32\dllcache\advpack.dll
+ 2008-10-16 20:38:34 124,928 -c–a-w c:\windows\system32\dllcache\advpack.dll
- 2008-08-26 07:24:28 347,136 -c–a-w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 -c–a-w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 -c–a-w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 -c–a-w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-26 07:24:28 133,120 -c–a-w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-16 20:38:35 133,120 -c–a-w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-23 12:36:14 286,720 -c—-w c:\windows\system32\dllcache\gdi32.dll
- 2008-08-26 07:24:28 63,488 -c—-w c:\windows\system32\dllcache\icardie.dll
+ 2008-10-16 20:38:35 63,488 -c—-w c:\windows\system32\dllcache\icardie.dll
- 2008-08-25 08:37:59 70,656 -c–a-w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 -c–a-w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 -c–a-w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 -c–a-w c:\windows\system32\dllcache\ieakeng.dll
- 2008-08-26 07:24:28 230,400 -c–a-w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 -c–a-w c:\windows\system32\dllcache\ieaksie.dll
- 2008-08-23 05:54:51 161,792 -c–a-w c:\windows\system32\dllcache\ieakui.dll
+ 2008-10-15 07:04:53 161,792 -c–a-w c:\windows\system32\dllcache\ieakui.dll
- 2008-08-26 07:24:28 383,488 -c—-w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-10-16 20:38:35 383,488 -c—-w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-08-26 07:24:29 384,512 -c–a-w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 -c–a-w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-03 17:41:15 6,066,176 -c—-w c:\windows\system32\dllcache\ieframe.dll
+ 2008-10-16 20:38:37 6,066,176 -c—-w c:\windows\system32\dllcache\ieframe.dll
- 2008-08-26 07:24:29 44,544 -c–a-w c:\windows\system32\dllcache\iernonce.dll
+ 2008-10-16 20:38:37 44,544 -c–a-w c:\windows\system32\dllcache\iernonce.dll
- 2008-08-26 07:24:29 267,776 -c—-w c:\windows\system32\dllcache\iertutil.dll
+ 2008-10-16 20:38:37 267,776 -c—-w c:\windows\system32\dllcache\iertutil.dll
- 2008-08-25 08:38:00 13,824 -c—-w c:\windows\system32\dllcache\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 -c—-w c:\windows\system32\dllcache\ieudinit.exe
- 2008-08-23 05:56:15 635,848 -c–a-w c:\windows\system32\dllcache\iexplore.exe
+ 2008-10-15 07:06:26 633,632 -c–a-w c:\windows\system32\dllcache\iexplore.exe
- 2008-08-26 07:24:30 27,648 -c–a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 -c–a-w c:\windows\system32\dllcache\jsproxy.dll
- 2006-10-18 10:03:58 100,864 -c–a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-06-17 15:09:22 100,864 -c–a-w c:\windows\system32\dllcache\logagent.exe
- 2008-08-26 07:24:30 459,264 -c—-w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-10-16 20:38:37 459,264 -c—-w c:\windows\system32\dllcache\msfeeds.dll
- 2008-08-26 07:24:30 52,224 -c—-w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-10-16 20:38:37 52,224 -c—-w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-08-27 08:24:32 3,593,216 -c–a-w c:\windows\system32\dllcache\mshtml.dll
+ 2008-10-16 16:08:40 3,593,216 -c–a-w c:\windows\system32\dllcache\mshtml.dll
- 2008-08-26 07:24:30 477,696 -c–a-w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 -c–a-w c:\windows\system32\dllcache\mshtmled.dll
- 2008-08-26 07:24:30 193,024 -c–a-w c:\windows\system32\dllcache\msrating.dll
+ 2008-10-16 20:38:38 193,024 -c–a-w c:\windows\system32\dllcache\msrating.dll
- 2008-08-26 07:24:30 671,232 -c–a-w c:\windows\system32\dllcache\mstime.dll
+ 2008-10-16 20:38:39 671,232 -c–a-w c:\windows\system32\dllcache\mstime.dll
- 2008-08-26 07:24:30 102,912 -c–a-w c:\windows\system32\dllcache\occache.dll
+ 2008-10-16 20:38:39 102,912 -c–a-w c:\windows\system32\dllcache\occache.dll
- 2008-08-26 07:24:30 44,544 -c–a-w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 -c–a-w c:\windows\system32\dllcache\pngfilt.dll
- 2008-04-14 00:12:07 246,814 -c–a-w c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-03 10:02:42 247,326 -c–a-w c:\windows\system32\dllcache\strmdll.dll
- 2008-08-26 07:24:30 105,984 -c–a-w c:\windows\system32\dllcache\url.dll
+ 2008-10-16 20:38:39 105,984 -c–a-w c:\windows\system32\dllcache\url.dll
- 2008-08-26 07:24:31 1,159,680 -c–a-w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 -c–a-w c:\windows\system32\dllcache\urlmon.dll
- 2008-08-26 07:24:31 233,472 -c–a-w c:\windows\system32\dllcache\webcheck.dll
+ 2008-10-16 20:38:39 233,472 -c–a-w c:\windows\system32\dllcache\webcheck.dll
- 2008-08-26 07:24:31 826,368 -c–a-w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 20:38:40 826,368 -c–a-w c:\windows\system32\dllcache\wininet.dll
- 2006-10-18 11:47:20 937,984 -c–a-w c:\windows\system32\dllcache\WMNetMgr.dll
+ 2008-06-17 19:03:08 938,496 -c–a-w c:\windows\system32\dllcache\WMNetmgr.dll
- 2006-10-18 11:47:22 2,450,944 -c–a-w c:\windows\system32\dllcache\wmvcore.dll
+ 2008-06-17 19:03:14 2,458,112 -c–a-w c:\windows\system32\dllcache\WMVCore.dll
- 2008-08-26 07:24:28 347,136 —-a-w c:\windows\system32\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 —-a-w c:\windows\system32\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 —-a-w c:\windows\system32\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 —-a-w c:\windows\system32\dxtrans.dll
- 2008-08-26 07:24:28 133,120 —-a-w c:\windows\system32\extmgr.dll
+ 2008-10-16 20:38:35 133,120 —-a-w c:\windows\system32\extmgr.dll
- 2008-08-26 07:24:28 63,488 —-a-w c:\windows\system32\icardie.dll
+ 2008-10-16 20:38:35 63,488 —-a-w c:\windows\system32\icardie.dll
- 2008-08-25 08:37:59 70,656 —-a-w c:\windows\system32\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 —-a-w c:\windows\system32\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 —-a-w c:\windows\system32\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 —-a-w c:\windows\system32\ieakeng.dll
- 2008-08-26 07:24:28 230,400 —-a-w c:\windows\system32\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 —-a-w c:\windows\system32\ieaksie.dll
- 2008-08-23 05:54:51 161,792 —-a-w c:\windows\system32\ieakui.dll
+ 2008-10-15 07:04:53 161,792 —-a-w c:\windows\system32\ieakui.dll
- 2008-08-26 07:24:28 383,488 —-a-w c:\windows\system32\ieapfltr.dll
+ 2008-10-16 20:38:35 383,488 —-a-w c:\windows\system32\ieapfltr.dll
- 2008-08-26 07:24:29 384,512 —-a-w c:\windows\system32\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 —-a-w c:\windows\system32\iedkcs32.dll
- 2008-10-03 17:41:15 6,066,176 —-a-w c:\windows\system32\ieframe.dll
+ 2008-10-16 20:38:37 6,066,176 —-a-w c:\windows\system32\ieframe.dll
- 2008-08-26 07:24:29 44,544 —-a-w c:\windows\system32\iernonce.dll
+ 2008-10-16 20:38:37 44,544 —-a-w c:\windows\system32\iernonce.dll
- 2008-08-26 07:24:29 267,776 —-a-w c:\windows\system32\iertutil.dll
+ 2008-10-16 20:38:37 267,776 —-a-w c:\windows\system32\iertutil.dll
- 2008-08-25 08:38:00 13,824 —-a-w c:\windows\system32\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 —-a-w c:\windows\system32\ieudinit.exe
- 2008-08-26 07:24:30 27,648 —-a-w c:\windows\system32\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 —-a-w c:\windows\system32\jsproxy.dll
- 2006-10-18 10:03:58 100,864 —-a-w c:\windows\system32\logagent.exe
+ 2008-06-17 15:09:22 100,864 —-a-w c:\windows\system32\logagent.exe
- 2008-11-04 00:10:25 17,318,336 —-a-w c:\windows\system32\MRT.exe
+ 2008-12-09 23:24:38 17,593,280 —-a-w c:\windows\system32\MRT.exe
- 2008-08-26 07:24:30 459,264 —-a-w c:\windows\system32\msfeeds.dll
+ 2008-10-16 20:38:37 459,264 —-a-w c:\windows\system32\msfeeds.dll
- 2008-08-26 07:24:30 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
+ 2008-10-16 20:38:37 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
- 2008-08-27 08:24:32 3,593,216 —-a-w c:\windows\system32\mshtml.dll
+ 2008-10-16 16:08:40 3,593,216 —-a-w c:\windows\system32\mshtml.dll
- 2008-08-26 07:24:30 477,696 —-a-w c:\windows\system32\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 —-a-w c:\windows\system32\mshtmled.dll
- 2008-08-26 07:24:30 193,024 —-a-w c:\windows\system32\msrating.dll
+ 2008-10-16 20:38:38 193,024 —-a-w c:\windows\system32\msrating.dll
- 2008-08-26 07:24:30 671,232 —-a-w c:\windows\system32\mstime.dll
+ 2008-10-16 20:38:39 671,232 —-a-w c:\windows\system32\mstime.dll
- 2008-08-26 07:24:30 102,912 —-a-w c:\windows\system32\occache.dll
+ 2008-10-16 20:38:39 102,912 —-a-w c:\windows\system32\occache.dll
- 2008-08-26 07:24:30 44,544 —-a-w c:\windows\system32\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 —-a-w c:\windows\system32\pngfilt.dll
- 2008-04-14 00:12:38 60,416 —-a-w c:\windows\system32\tzchange.exe
+ 2008-10-23 10:06:59 62,976 —-a-w c:\windows\system32\tzchange.exe
- 2008-08-26 07:24:30 105,984 —-a-w c:\windows\system32\url.dll
+ 2008-10-16 20:38:39 105,984 —-a-w c:\windows\system32\url.dll
- 2008-08-26 07:24:31 1,159,680 —-a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 —-a-w c:\windows\system32\urlmon.dll
- 2008-08-26 07:24:31 233,472 —-a-w c:\windows\system32\webcheck.dll
+ 2008-10-16 20:38:39 233,472 —-a-w c:\windows\system32\webcheck.dll
- 2006-10-18 11:47:20 937,984 —-a-w c:\windows\system32\WMNetMgr.dll
+ 2008-06-17 19:03:08 938,496 —-a-w c:\windows\system32\WMNetmgr.dll
- 2006-10-18 11:47:22 2,450,944 —-a-w c:\windows\system32\wmvcore.dll
+ 2008-06-17 19:03:14 2,458,112 —-a-w c:\windows\system32\WMVCore.dll
+ 2008-12-14 04:35:24 16,384 —-atw c:\windows\temp\Perflib_Perfdata_788.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@="{4433A54A-1AC8-432F-90FC-85F045CF383C}"
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-10-31 12:24 576352 –a—— c:\program files\Common Files\Symantec Shared\Backup\buShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}"
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-10-31 12:24 576352 –a—— c:\program files\Common Files\Symantec Shared\Backup\buShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@="{476D0EA3-80F9-48B5-B70B-05E677C9C148}"
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-10-31 12:24 576352 –a—— c:\program files\Common Files\Symantec Shared\Backup\buShell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-01-17 21686568]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-04 342336]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gainward"="c:\program files\XpertVision\TBPanel.exe" [2007-04-23 2165520]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-27 988512]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"f:\\BitTorrent\\bittorrent.exe"=
"f:\\COD4\\iw3mp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;"c:\program files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [2008-02-19 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-04 99376]
S3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\COH_Mon.sys [2008-01-13 23888]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder

2008-12-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-12-12 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Sachi Eapen.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com.au/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-14 16:45:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-12-14 16:47:04
ComboFix-quarantined-files.txt 2008-12-14 06:46:33

Pre-Run: 11,913,007,104 bytes free
Post-Run: 11,980,120,064 bytes free

345 — E O F — 2008-12-12 13:41:00



Kaspersky Scan

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, December 20, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, December 19, 2008 13:46:35
Records in database: 1486841
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 83688
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 01:37:42


File name / Threat name / Threats count
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.63 1

The selected area was scanned.


HJT Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:52:56 AM, on 20/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\XpertVision\TBPanel.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Trend Micro\scanner\scanner.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [Gainward] C:\Program Files\XpertVision\TBPanel.exe /A
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre…ows-i586-jc.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 10492 bytes
seapen,

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.

Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls

Keep Microsoft Windows Updated - This will ensure your computer has always the latest security updates available installed on your computer. The easiest way to do this is to turn on Automatic Updates. Do this by:
  • From your desktop, right-click on My Computer,
  • click on Properties
  • Select the Automatic Updates tab
  • Click on Automatic
  • Click on Apply button
  • Click on OK to exit.
If there are new updates to install, install them immediately, until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

Download and install the free version of WinPatrol - This program protects your computer in a variety of ways and will work well with your existing security software.
Winpatrol


Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.


Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI