This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

CatByte,
Here are the two scans.


ComboFix 09-02-02.04 - Admin 2009-02-06 20:24:52.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.874.1.1033.18.511.235 [GMT 7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated)
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
c:\windows\MicroSoft.vbs
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\MicroSoft.vbs

.
((((((((((((((((((((((((( Files Created from 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))))))
.

2009-02-05 03:12 . 2009-02-05 03:12 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-05 03:12 . 2009-02-05 03:12 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-05 03:12 . 2009-02-05 03:12 d——– c:\documents and settings\Admin\Application Data\Malwarebytes
2009-02-05 03:12 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-05 03:12 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-05 03:00 . 2009-02-05 03:00 410,984 –a—— c:\windows\system32\deploytk.dll
2009-02-05 02:31 . 2009-02-05 02:31 d——– c:\program files\Common Files\Adobe AIR
2009-02-05 02:24 . 2009-02-05 02:24 d——– c:\program files\NOS
2009-02-05 02:24 . 2009-02-05 02:24 d——– c:\documents and settings\All Users\Application Data\NOS
2009-02-05 01:48 . 2009-02-05 01:48 d——– c:\windows\system32\CatRoot_bak
2009-02-04 22:19 . 2009-02-04 22:19 d——– c:\documents and settings\All Users\Application Data\TVU Networks
2009-02-04 13:38 . 2009-02-04 13:38 d——– c:\windows\ERUNT
2009-02-04 13:26 . 2009-02-04 13:55 d——– C:\SDFix
2009-02-04 02:09 . 2009-02-04 02:09 d——– c:\program files\Trend Micro
2009-02-03 21:43 . 2009-02-03 22:40 d——– c:\program files\ThreatExpert Memory Scanner
2009-02-03 21:22 . 2009-02-03 21:26 d——– c:\documents and settings\All Users\Application Data\Prevx
2009-02-03 21:22 . 2006-12-08 13:36 9,728 –a—— c:\windows\system32\drivers\pxscinst.dll
2009-02-03 21:22 . 2006-12-08 13:36 7,680 –a—— c:\windows\system32\drivers\pxinst.dll
2009-01-19 14:28 . 2003-11-04 15:10 69,632 –a—— c:\windows\system32\lfgif13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 462,848 –a—— c:\windows\system32\ltkrn13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 450,560 –a—— c:\windows\system32\ltimg13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 401,408 –a—— c:\windows\system32\lfcmp13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 299,008 –a—— c:\windows\system32\ltdis13n.dll
2009-01-19 14:27 . 2004-01-12 02:09 206,336 –a—— c:\windows\system32\ltefx13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 163,840 –a—— c:\windows\system32\ltfil13n.dll
2009-01-19 14:27 . 2004-05-14 16:53 57,344 –a—— c:\windows\system32\lfbmp13n.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 20:00 ——— d—–w c:\program files\Java
2009-02-04 19:28 ——— d—–w c:\program files\Common Files\Adobe
2009-02-04 15:19 ——— d—–w c:\program files\TVUPlayer
2009-02-04 07:44 ——— d—–w c:\program files\ESET
2009-02-03 15:28 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-02-03 13:29 ——— d—–w c:\program files\DNA
2009-02-03 12:49 ——— d—–w c:\program files\Mozilla ActiveX Control v1.7.12
2009-02-03 11:35 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-03 05:36 ——— d—–w c:\program files\Google
2009-01-31 09:04 ——— d—–w c:\documents and settings\Admin\Application Data\ZoomBrowser EX
2009-01-31 09:04 ——— d—–w c:\documents and settings\Admin\Application Data\CameraWindowDC
2009-01-24 13:17 48,913 -c–a-w c:\windows\UninstVeetleTVPlayer.exe
2009-01-14 16:50 ——— d—–w c:\program files\Yahoo!
2009-01-05 08:13 ——— d—–w c:\program files\TVAnts
2009-01-02 21:01 ——— d—–w c:\documents and settings\All Users\Application Data\Launcher
2009-01-02 19:59 ——— d—–w c:\documents and settings\All Users\Application Data\Graboid Inc
2009-01-02 19:59 ——— d—–w c:\documents and settings\Admin\Application Data\MozillaControl
2009-01-02 19:58 ——— d—–w c:\program files\Graboid
2008-12-26 06:58 ——— d—–w c:\program files\Spyware Doctor
2008-12-26 06:56 ——— d—–w c:\documents and settings\Admin\Application Data\PC Tools
2008-12-26 06:20 ——— d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-26 06:16 ——— d—–w c:\program files\Apple Software Update
2008-12-26 06:15 ——— d—–w c:\program files\Common Files\Apple
2008-12-26 06:15 ——— d—–w c:\documents and settings\All Users\Application Data\Apple
2008-12-19 07:02 ——— d—–w c:\program files\Common Files\Teleca Shared
2008-12-19 07:02 ——— d—–w c:\documents and settings\All Users\Application Data\Sony Ericsson
2008-12-15 07:58 47,360 —-a-w c:\documents and settings\Admin\Application Data\pcouffin.sys
2008-12-15 07:58 ——— d—–w c:\documents and settings\Admin\Application Data\Vso
2008-04-19 10:54 1,685,156 -c–a-w c:\program files\pf-setup-en.exe
2008-03-02 08:47 67,696 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-03-02 08:47 54,376 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-03-02 08:47 34,952 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-03-02 08:47 46,720 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-03-02 08:47 172,144 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

——- Sigcheck ——-

2007-10-31 00:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\SoftwareDistribution\Download\146ae5e7b51a37f45e0e5cf03d0d5e3c\sp2gdr\tcpip.sys
2007-10-30 23:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\SoftwareDistribution\Download\146ae5e7b51a37f45e0e5cf03d0d5e3c\sp2qfe\tcpip.sys
2006-04-20 18:51 359808 1dbf125862891817f374f407626967f4 c:\windows\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2gdr\tcpip.sys
2006-04-20 19:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2qfe\tcpip.sys
2008-06-20 17:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp2gdr\tcpip.sys
2008-06-20 17:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp2qfe\tcpip.sys
2008-06-20 18:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3gdr\tcpip.sys
2008-06-20 18:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3qfe\tcpip.sys
2008-03-26 18:39 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\dllcache\TCPIP.SYS
2008-03-26 18:39 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((( snapshot@2009-02-04_20.21.12.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-12 08:06:42 295,606 —-a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
- 2007-07-30 12:19:20 92,504 -c–a-w c:\windows\system32\cdm.dll
+ 2008-10-16 07:09:44 92,696 —-a-w c:\windows\system32\cdm.dll
- 2008-06-30 14:44:18 16,384 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-04 19:24:30 16,384 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-06-30 14:44:18 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-04 19:24:30 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-06-30 14:44:18 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-04 19:24:30 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-07-30 12:19:20 92,504 -c–a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-10-16 07:09:44 92,696 -c–a-w c:\windows\system32\dllcache\cdm.dll
- 2007-07-30 12:19:36 549,720 -c–a-w c:\windows\system32\dllcache\wuapi.dll
+ 2008-10-16 07:12:20 561,688 -c–a-w c:\windows\system32\dllcache\wuapi.dll
- 2007-07-30 12:19:16 53,080 -c–a-w c:\windows\system32\dllcache\wuauclt.exe
+ 2008-10-16 07:09:44 51,224 -c–a-w c:\windows\system32\dllcache\wuauclt.exe
- 2007-07-30 12:19:42 1,712,984 -c–a-w c:\windows\system32\dllcache\wuaueng.dll
+ 2008-10-16 07:13:40 1,809,944 -c–a-w c:\windows\system32\dllcache\wuaueng.dll
- 2007-07-30 12:19:32 325,976 -c–a-w c:\windows\system32\dllcache\wucltui.dll
+ 2008-10-16 07:12:22 323,608 -c–a-w c:\windows\system32\dllcache\wucltui.dll
- 2007-07-30 12:18:40 33,624 -c–a-w c:\windows\system32\dllcache\wups.dll
+ 2008-10-16 07:08:58 34,328 -c–a-w c:\windows\system32\dllcache\wups.dll
- 2007-07-30 12:19:28 203,096 -c–a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 07:13:40 202,776 -c–a-w c:\windows\system32\dllcache\wuweb.dll
- 2007-09-24 15:30:28 135,168 -c–a-w c:\windows\system32\java.exe
+ 2009-02-04 20:00:15 144,792 —-a-w c:\windows\system32\java.exe
- 2007-09-24 15:30:30 135,168 -c–a-w c:\windows\system32\javaw.exe
+ 2009-02-04 20:00:15 144,792 —-a-w c:\windows\system32\javaw.exe
- 2007-09-24 16:31:42 139,264 -c–a-w c:\windows\system32\javaws.exe
+ 2009-02-04 20:00:15 148,888 —-a-w c:\windows\system32\javaws.exe
+ 2008-10-16 07:08:58 34,328 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-10-16 07:09:44 43,544 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
- 2007-07-30 12:19:36 549,720 -c–a-w c:\windows\system32\wuapi.dll
+ 2008-10-16 07:12:20 561,688 —-a-w c:\windows\system32\wuapi.dll
- 2007-07-30 12:19:16 53,080 -c–a-w c:\windows\system32\wuauclt.exe
+ 2008-10-16 07:09:44 51,224 —-a-w c:\windows\system32\wuauclt.exe
- 2007-07-30 12:19:42 1,712,984 —-a-w c:\windows\system32\wuaueng.dll
+ 2008-10-16 07:13:40 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
- 2007-07-30 12:19:32 325,976 -c–a-w c:\windows\system32\wucltui.dll
+ 2008-10-16 07:12:22 323,608 —-a-w c:\windows\system32\wucltui.dll
- 2007-07-30 12:18:40 33,624 -c–a-w c:\windows\system32\wups.dll
+ 2008-10-16 07:08:58 34,328 -c–a-w c:\windows\system32\wups.dll
- 2007-07-30 12:19:12 43,352 -c–a-w c:\windows\system32\wups2.dll
+ 2008-10-16 07:09:44 43,544 -c–a-w c:\windows\system32\wups2.dll
- 2007-07-30 12:19:28 203,096 -c–a-w c:\windows\system32\wuweb.dll
+ 2008-10-16 07:13:40 202,776 —-a-w c:\windows\system32\wuweb.dll
+ 2009-02-06 13:30:09 16,384 —-atw c:\windows\temp\Perflib_Perfdata_5cc.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-01-18 949376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"QuickTime Task"="c:\program files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" [2007-09-22 282624]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-05 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 1 (0x1)
"NoFavoritesMenu"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Admin\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Start Menu^Programs^Startup^Wallpapers from MSN.lnk]
path=c:\documents and settings\Admin\Start Menu\Programs\Startup\Wallpapers from MSN.lnk
backup=c:\windows\pss\Wallpapers from MSN.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Start Menu^Programs^Startup^Zapu.lnk]
path=c:\documents and settings\Admin\Start Menu\Programs\Startup\Zapu.lnk
backup=c:\windows\pss\Zapu.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2007-01-15 16:14 147456 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
–a–c— 2004-08-04 07:56 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
–a–c— 2006-08-08 22:42 208952 c:\windows\ime\IMJP8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2006-01-12 15:40 155648 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a–c— 2006-10-22 12:22 7700480 c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a–c— 2006-10-22 12:22 86016 c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
–a—— 2008-06-16 15:52 167936 c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-09-22 12:56 282624 c:\program files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
–a—— 2007-01-09 22:27 1003520 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2005-01-12 03:01 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
–a—— 2006-07-06 18:53 20034600 c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra—— 2005-10-26 17:17 159744 c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-09-25 01:11 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2008-12-05 15:54 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-01-09 22:21 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
–a—— 2006-05-06 09:29 6656 c:\program files\Unlocker\UnlockerAssistant.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateStar]
–a—— 2007-10-05 18:31 3596976 c:\documents and settings\Admin\Application Data\UpdateStar\UpdateStar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a–c— 2006-10-22 12:22 1622016 c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"StarWindServiceAE"=2 (0x2)
"gusvc"=3 (0x3)
"aawservice"=2 (0x2)
"Bonjour Service"=2 (0x2)
"6to4"=2 (0x2)
"wuauserv"=2 (0x2)
"Apple Mobile Device"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15876:TCP"= 15876:TCP:BitComet 15876 TCP
"15876:UDP"= 15876:UDP:BitComet 15876 UDP
"7270:TCP"= 7270:TCP:BitComet 7270 TCP
"7270:UDP"= 7270:UDP:BitComet 7270 UDP
"49201:TCP"= 49201:TCP:BitComet
"49201:UDP"= 49201:UDP:BitComet
"27153:TCP"= 27153:TCP:BitComet 27153 TCP
"27153:UDP"= 27153:UDP:BitComet 27153 UDP
"16800:TCP"= 16800:TCP:TVAnts
"16800:UDP"= 16800:UDP:TVAnts

R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-01-18 15424]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-02-05 33752]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-06-29 42512]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-12-26 356920]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-02-06 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 14:24]
.
.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &D;&ownload; &with; BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D;&ownload; all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D;&ownload; all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Download with GetRight Pro - c:\program files\GetRight\GRdownload.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Open with GetRight Pro Browser - c:\program files\GetRight\GRbrowse.htm
Trusted Zone: nationet.com\olb2
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\sp80ebjd.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\sp80ebjd.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\sp80ebjd.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\sp80ebjd.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 20:30:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\ESET\nod32krn.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Common Files\Teleca Shared\CapabilityManager.exe
c:\windows\SoftwareDistribution\Download\2bc0b3c55e0c166e04844934d1c7c342\update\update.exe
c:\windows\SoftwareDistribution\Download\56061c71c086888c2a4d68825eaacd28\update\update.exe
.
**************************************************************************
.
Completion time: 2009-02-06 20:41:13 - machine was rebooted [Admin]
ComboFix-quarantined-files.txt 2009-02-06 13:40:22
ComboFix2.txt 2009-02-04 17:28:44
ComboFix3.txt 2009-02-04 13:24:31

Pre-Run: 7,577,812,992 bytes free
Post-Run: 7,557,124,096 bytes free

Current=2 Default=2 Failed=0 LastKnownGood=4 Sets=1,2,3,4
315 — E O F — 2008-03-20 16:31:31


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:45:22 PM, on 2/6/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\2bc0b3c55e0c166e04844934d1c7c342\update\update.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\SoftwareDistribution\Download\963193362d99ddbedffb21408a40248b\update\update.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - URLSearchHook: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbShar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbShar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbShar.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D;&ownload; &with; BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D;&ownload; all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D;&ownload; all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

–
End of file - 6390 bytes
Hello harrydash,

good news, your logs look clean :thumbup:

Just some minor tidying up to do.


First

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • [external image: Posted Image]
The above procedure will reset your System Restore and clear out the backups and quarantines created during the course of this fix.




Now download ToolsCleaner2 to your desktop and run it (by A.Rothstein & Dj Quiou)
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program


    Below I have included a number of recommendations for how to protect your computer against malware infections.
    • Keep Windows updated by regularly checking their website at :
      http://windowsupdate.microsoft.com/
      This will ensure your computer has always the latest security updates available installed on your computer.
    • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
    • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
    • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • Please read read the guide by Rorschach112 on how to prevent malware and about safe computing here
Thank you for your patience, and performing all of the procedures requested.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI